Unified Vulnerability Management Platform for IT Asset Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IT security teams face challenges in managing the increasing complexity of IT assets, focusing primarily on servers while overlooking other asset types, and struggle to keep up with evolving vulnerabilities and threats due to a reactive and stove-piped approach, which hinders effective security and compliance.

Innovation Solution

The Enterprise Vulnerability Management Application (EVMA) and Process (EVMP) integrate data from multiple scanning tools, normalize vulnerability scores using the NIST CVSS algorithm, and provide a unified platform for prioritization and remediation across all IT assets, offering a vendor-agnostic solution with a modular design for flexible adaptation to changing environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple COTS scanning tools are used to cover different asset types, then vulnerability detection coverage is improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvevulnerability detection coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple COTS scanning tools (Nessus, OpenVAS, Qualys, etc.) into a single unified vulnerability management platform that ingests data from all sources through a common interface, consolidating disparate tools into one system while maintaining comprehensive detection coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The platform is designed to universally support multiple asset types (servers, databases, web applications, network devices) and multiple scanning tools through a single interface, making the system adaptable to diverse security needs without requiring separate management approaches for each tool

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If vulnerability scanning is conducted across all IT assets including web applications and databases, then comprehensive security coverage is improved, but the time and resources required for scanning and analysis increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidscanning and analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically changes the parameters of vulnerability scoring by integrating CVSS base scores with temporal and environment-specific metrics, allowing prioritization of vulnerabilities based on current threat landscapes and organizational context rather than treating all vulnerabilities equally

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies different scoring weights and prioritization criteria to different asset types and vulnerability categories, allowing the system to focus resources on the most critical vulnerabilities for each specific asset type rather than applying a uniform approach

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If a reactive vulnerability management process is used to address newly discovered vulnerabilities, then responsiveness to new threats is improved, but the ability to maintain continuous security and compliance deteriorates

Engineering Contradiction:
Improveresponsiveness to new threatsVSAvoidcontinuous security and compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements continuous feedback loops where vulnerability data is constantly ingested from scanning tools, prioritized using CVSS scoring, and fed into remediation workflows, creating an ongoing cycle that maintains continuous security rather than periodic reactive responses

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes continuous vulnerability management processes including ongoing scanning, real-time prioritization updates, and continuous remediation tracking that maintain security posture continuously rather than reacting only when new vulnerabilities are discovered

Inventive Principle:
Principle #20Continuity of useful action

4Adaptability or versatility

If vendor-specific tools and processes are used for each asset type, then specialization for each asset type is improved, but integration and holistic enterprise view deteriorate

Engineering Contradiction:
Improveasset-type specializationVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments vulnerability management by asset type (servers, databases, web applications, network devices) with specialized scanning and scoring approaches for each, while maintaining a unified platform that integrates all segments into a holistic enterprise view

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central vulnerability management platform as an intermediary that standardizes data ingestion from various asset types and scanning tools, translating diverse vendor-specific formats into a unified CVSS-based scoring system that enables holistic analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8789192B2Enterprise vulnerability management
Publication Date: 2014.07.22 LEIDOS INNOVATIONS TECHNOLOGY INC
  • US8789192B2 patent drawing
  • US8789192B2 patent drawing
  • US8789192B2 patent drawing

AI summary

An enterprise vulnerability management application (EVMA), enterprise vulnerability management process (EVMP) and system. In one embodiment, the EVMP may include executing computer software code on at least one computer hardware platform to receive login information from a user, inventory current information technology assets of the enterprise, conduct vulnerability scanning of the inventoried information technology assets, analyze vulnerability correlation and prioritization of the information technology assets, remediate one or more vulnerabilities of the information technology assets, and report to the user about the vulnerabilities and remediation undertaken. As part of the analysis, one or more vulnerability scores such as, for example, Common Vulnerability Scoring System (CVSS) scores, may be generated from base score metrics, temporal score metrics and environment score metrics.