Topology-Aware Security Risk Assessment for Software Components

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for assessing security risks in computer networks lack visibility into network topology, leading to inefficient prioritization of software updates and vulnerability management.

Innovation Solution

A system that determines security risk levels based on network topology and client device conditions, including software versions, vulnerabilities, and internet accessibility, and transmits instructions for risk mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If current techniques rely on scanned data without network topology visibility, then security scanning can be performed, but risk prioritization and software update prioritization become inefficient

Engineering Contradiction:
Improvesoftware update prioritization efficiencyVSAvoidnetwork topology visibility
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces a network entity as an intermediary that collects network topology information and correlates it with vulnerability scan data. This intermediary processes and enriches the raw scanned data with contextual network relationship information, enabling efficient risk prioritization while maintaining the simplicity of scan-based security assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If network topology information is incorporated into security assessment, then risk prioritization improves, but system complexity increases

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security assessment system into distinct functional modules: a network entity for collecting and storing topology information, a vulnerability scanning component, and a risk prioritization engine. This segmentation allows each component to handle specific tasks independently, improving assessment accuracy while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4614884A1Security risk level assessment of assets and software components
Publication Date: 2025.09.10 SOLARWINDS WORLDWIDE LLC
  • EP4614884A1 patent drawingFigure 1
  • EP4614884A1 patent drawingFigure 2
  • EP4614884A1 patent drawingFigure 3

AI summary

Systems, methods, apparatuses, and computer program products for determining a security risk of a computer network based upon a topology of the computer network. One method may include receiving, by a network entity, an indication of at least one network condition from at least one client device; determining, by the network entity, at least one risk level associated with the at least one client device according to the at least one received network condition; and transmitting, by the network entity, at least one instruction to the at least one client device to perform at least one action associated with resolving the at least one risk level.