Virtual Asset Vulnerability Management via Segmented Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for vulnerability management and verification of virtual assets in cloud computing environments are inadequate, as they often rely on ad-hoc, manual, and resource-intensive approaches, and are limited to the specific connectivity and operational scenarios of the production environment, failing to detect vulnerabilities in changed conditions, and are vulnerable to malicious entity control.

Innovation Solution

A system and method that involves creating a test virtual asset in a testing environment, identifying and remediating vulnerabilities, and deploying a new virtual asset configured to monitor and protect against security threats, with a virtual asset agent that can self-repair and establish secure communication channels, allowing for comprehensive vulnerability analysis and verification across various connectivity and operational scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive vulnerability analysis and verification is performed in the production computing environment with connectivity restrictions, then security verification is improved, but the ability to detect vulnerabilities under different connectivity conditions deteriorates

Engineering Contradiction:
Improvesecurity verificationVSAvoidvulnerability detection across different connectivity conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments vulnerability analysis into two distinct phases: (1) preliminary vulnerability analysis performed before deployment to identify potential security issues, and (2) continuous monitoring performed after deployment to detect new threats. This segmentation allows comprehensive security verification while adapting to different connectivity conditions at appropriate stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary vulnerability analysis and verification before deploying virtual assets to the production environment. This preliminary action identifies and remediates vulnerabilities in advance, ensuring security is established before connectivity restrictions are imposed, while still allowing post-deployment monitoring for new threats.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If virtual assets are individually verified in the production environment after deployment, then security verification is improved, but resource consumption and cost increase significantly

Engineering Contradiction:
Improvesecurity verificationVSAvoidhardware, software, and human administrator resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system merges vulnerability scanning and verification functions into a unified automated platform that operates across multiple virtual assets simultaneously. This consolidation reduces redundant resource consumption by sharing scanning infrastructure, centralizing vulnerability data, and automating verification processes across the entire portfolio rather than individually verifying each asset.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates and uses virtual copies of assets for testing and verification purposes. By deploying test virtual assets that mirror production assets, the system can perform comprehensive vulnerability analysis on copies without impacting production resources, thereby reducing the need for dedicated verification hardware and software in the live environment.

Inventive Principle:
Principle #26Copying

3Ease of operation

If ad-hoc and manual vulnerability management approaches are used, then flexibility in addressing specific vulnerabilities is improved, but productivity and response time deteriorate

Engineering Contradiction:
Improveflexibility in vulnerability managementVSAvoidvulnerability response speed
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system implements dynamic vulnerability management that automatically adapts scanning parameters, frequency, and depth based on asset criticality, change detection, and threat intelligence. This dynamic approach maintains operational flexibility by adjusting verification intensity to match actual risk levels while significantly improving productivity through automated response workflows that eliminate manual intervention for routine vulnerabilities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11411984B2Replacing a potentially threatening virtual asset
Publication Date: 2022.08.09 INTUIT INC
  • US11411984B2 patent drawing
  • US11411984B2 patent drawing
  • US11411984B2 patent drawing

AI summary

Big data analysis methods and machine learning based models are used to provide offer recommendations to consumers that are probabilistically determined to be relevant to a given consumer. Machine learning based matching of user attributes and offer attributes is first performed to identify potentially relevant offers for a given consumer. A de-duplication process is then used to identify and eliminate any offers represented in the offer data that the consumer has already seen, has historically shown no interest in, has already accepted, that are directed to product or service types the user/consumer already owns, for which the user does not qualify, or that are otherwise deemed to be irrelevant to the consumer.