Software Update Audit Subsystem Using Group Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in managing and reporting software updates and patches across computer networks, particularly in ensuring network security and employee productivity, due to complexities in group memberships, operating system changes, and varying security/hotfix requirements.
Innovation Solution
A software update and patch audit subsystem that utilizes system grouping and audit specification criteria to select computers that pass or fail security audits, maintaining database tables and views to produce reports on compliance, and allowing customizable security audit specifications for different groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive security audits are performed across the entire network, then security compliance is improved, but system complexity and time required increase
Solution Approach 1:
The patent divides the network into multiple groups organized in a tree structure, allowing security audits to be segmented by group level. Each group can have customized audit specifications, and the system processes audits at different levels (individual computers, groups, and the entire network), reducing overall complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The system pre-configures audit specifications for different groups and computers before actual audits are performed. Group administrators can define required hotfixes and patches in advance, and the system stores these specifications in the database, enabling efficient automated auditing without requiring complex real-time decision-making during the audit process.
2Loss of information
If detailed audit reports are generated for all computers, then compliance monitoring is improved, but time required and processing resources increase
Solution Approach 1:
The report generation process is segmented by group level, allowing users to request reports for specific groups rather than the entire network. The system can generate summary reports at the group level showing compliance status, and only drill down to individual computer details when necessary, significantly reducing processing time while maintaining information completeness.
Solution Approach 2:
The system provides flexible report scope options allowing users to request audits for specific groups, departments, or the entire network. This partial action approach enables users to obtain detailed compliance information only for the portions of the network they need, reducing overall processing time while maintaining complete information availability when required.
3Adaptability or versatility
If customized audit specifications are created for each group, then adaptability to different security requirements is improved, but system complexity increases
Solution Approach 1:
The patent implements a hierarchical tree structure where each group can have its own customized audit specifications independent of other groups. This segmentation allows different security requirements to be defined at different levels (company-wide, department-level, or group-specific) without affecting other parts of the network, making the system adaptable while managing complexity through structured organization.
Solution Approach 2:
The system provides a universal audit framework that can accommodate multiple types of audits (security audits, patch audits, compliance audits) within a single integrated platform. The same database structure and processing mechanisms handle different audit types by applying group-specific specifications, reducing overall system complexity while maintaining high adaptability.
Data Source
AI summary
A Computer Information Database System includes a software update and patch audit subsystem that manages computer profile data using system grouping and audit specification criteria. The subsystem thus selects a particular group of computers using the grouping criteria, and further selects from within the group the computers that pass or fail the applicable audit requirements. A given computer passes the requirements if the computer has installed thereon the specified software updates and patches that are applicable to the computer operating system platform. Otherwise, the computer fails. The audit subsystem may instead select particular computers using the audit specification criteria and then using the grouping criteria further select the subset of these computers that belong to a particular group. Further, the audit specification criteria may be set differently for the respective groups. Also, the grouping criteria and/or the security audit criteria may change without adversely impacting the operations of the subsystem. The audit system uses database tables and views that include value-to-match fields for either or both of the grouping and the audit specification criteria, and also software update or patch specific information and/or operating system specific information. One table includes group and operating system information for the respective computers, another table includes entries for the respective updates and patches that are installed on the respective computers, and another table includes entries that together specify the security audit specifications for the respective groups. Using the tables, the system produces views that relate, for example, to failing computers, what updates or patches the respective failing computers are missing, which or how many computers are failing within a particular group.


