Unified Vulnerability Management Platform for IT Asset Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IT security teams face challenges in managing the increasing complexity of IT assets, focusing primarily on servers while overlooking other asset types, and struggle to keep up with evolving vulnerabilities and threats due to a reactive and stove-piped approach, which hinders effective security and compliance.
Innovation Solution
The Enterprise Vulnerability Management Application (EVMA) and Process (EVMP) integrate data from multiple scanning tools, normalize vulnerability scores using the NIST CVSS algorithm, and provide a unified platform for prioritization and remediation across all IT assets, offering a vendor-agnostic solution with a modular design for flexible adaptation to changing environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple COTS scanning tools are used to cover different asset types, then vulnerability detection coverage is improved, but system complexity and difficulty of management increase
Solution Approach 1:
The patent combines multiple COTS scanning tools (Nessus, OpenVAS, Qualys, etc.) into a single unified vulnerability management platform that ingests data from all sources through a common interface, consolidating disparate tools into one system while maintaining comprehensive detection coverage
Solution Approach 2:
The platform is designed to universally support multiple asset types (servers, databases, web applications, network devices) and multiple scanning tools through a single interface, making the system adaptable to diverse security needs without requiring separate management approaches for each tool
2Reliability
If vulnerability scanning is conducted across all IT assets including web applications and databases, then comprehensive security coverage is improved, but the time and resources required for scanning and analysis increase
Solution Approach 1:
The system dynamically changes the parameters of vulnerability scoring by integrating CVSS base scores with temporal and environment-specific metrics, allowing prioritization of vulnerabilities based on current threat landscapes and organizational context rather than treating all vulnerabilities equally
Solution Approach 2:
The patent applies different scoring weights and prioritization criteria to different asset types and vulnerability categories, allowing the system to focus resources on the most critical vulnerabilities for each specific asset type rather than applying a uniform approach
3Adaptability or versatility
If a reactive vulnerability management process is used to address newly discovered vulnerabilities, then responsiveness to new threats is improved, but the ability to maintain continuous security and compliance deteriorates
Solution Approach 1:
The system implements continuous feedback loops where vulnerability data is constantly ingested from scanning tools, prioritized using CVSS scoring, and fed into remediation workflows, creating an ongoing cycle that maintains continuous security rather than periodic reactive responses
Solution Approach 2:
The patent establishes continuous vulnerability management processes including ongoing scanning, real-time prioritization updates, and continuous remediation tracking that maintain security posture continuously rather than reacting only when new vulnerabilities are discovered
4Adaptability or versatility
If vendor-specific tools and processes are used for each asset type, then specialization for each asset type is improved, but integration and holistic enterprise view deteriorate
Solution Approach 1:
The system segments vulnerability management by asset type (servers, databases, web applications, network devices) with specialized scanning and scoring approaches for each, while maintaining a unified platform that integrates all segments into a holistic enterprise view
Solution Approach 2:
The patent introduces a central vulnerability management platform as an intermediary that standardizes data ingestion from various asset types and scanning tools, translating diverse vendor-specific formats into a unified CVSS-based scoring system that enables holistic analysis
Data Source
AI summary
An enterprise vulnerability management application (EVMA), enterprise vulnerability management process (EVMP) and system. In one embodiment, the EVMP may include executing computer software code on at least one computer hardware platform to receive login information from a user, inventory current information technology assets of the enterprise, conduct vulnerability scanning of the inventoried information technology assets, analyze vulnerability correlation and prioritization of the information technology assets, remediate one or more vulnerabilities of the information technology assets, and report to the user about the vulnerabilities and remediation undertaken. As part of the analysis, one or more vulnerability scores such as, for example, Common Vulnerability Scoring System (CVSS) scores, may be generated from base score metrics, temporal score metrics and environment score metrics.


