Virtual Patching System for Immediate Vulnerability Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing patching methods for security vulnerabilities are inefficient, requiring extensive time and resources for continuous updates across numerous computer systems, leaving networks at risk until all systems are fully protected, and relying on behavioral blocking techniques that offer limited protection.

Innovation Solution

A virtual patching system that collects information on vulnerabilities, identifies host interfaces, and analyzes data to prevent unwanted access, allowing for immediate protection without the need for individual patch distribution and installation, using methods like black box testing, binary differentiation, and debugger analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional patching methods are used to protect vulnerabilities, then security protection is provided, but the process becomes extremely time-consuming and inefficient due to individual patch installation requirements across all computer systems

Engineering Contradiction:
Improvesecurity protectionVSAvoidpatching time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

An intermediary system (virtual patching system) is introduced between the vulnerability and the exploit. This system monitors host interfaces and blocks malicious data without requiring modification of the underlying vulnerable applications, thus providing immediate protection without the time-consuming traditional patching process

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of physically patching each system individually, the protection is copied and applied uniformly across all systems through a centralized virtual patching mechanism that monitors and blocks exploits at the interface level, providing simultaneous protection to all connected systems

Inventive Principle:
Principle #26Copying

2Reliability

If traditional patching is implemented across a large network, then security protection is achieved, but the network remains at risk for quite some time until all systems are fully protected

Engineering Contradiction:
Improvesecurity protectionVSAvoidprotection deployment speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The virtual patching system performs preliminary protection by monitoring and blocking exploit attempts before they can reach vulnerable applications. This preliminary action provides immediate security coverage while traditional patches are being prepared and distributed, eliminating the security gap that exists during the patching window

Inventive Principle:
Principle #10Preliminary action

3Productivity

If behavioral blocking techniques are used to avoid continuous patching, then patching inefficiency is reduced, but protection is limited and many vulnerabilities go unprotected

Engineering Contradiction:
Improvepatching efficiencyVSAvoidprotection coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The protection approach is segmented into two complementary layers: behavioral blocking for known exploit patterns and signature-based detection for specific vulnerabilities. This segmentation allows the system to maintain high productivity through behavioral blocking while achieving comprehensive reliability by adding signature-based protection for known vulnerabilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual patching system uses a composite approach combining behavioral blocking techniques with signature-based detection, analogous to composite materials that combine different properties. This composite methodology provides both the efficiency of behavioral blocking and the comprehensive coverage of signature-based protection

Inventive Principle:
Principle #40Composite materials

4Reliability

If patches are distributed to thousands of computers, then security protection is provided, but the process becomes very inefficient and requires extensive resources

Engineering Contradiction:
Improvesecurity protectionVSAvoidpatching process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual patching system merges the protection function into a centralized monitoring system that watches multiple host interfaces simultaneously. This combining approach provides security protection for thousands of computers through a single system rather than requiring individual patch management for each machine, dramatically reducing process complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8132164B1System, method and computer program product for virtual patching
Publication Date: 2012.03.06 MCAFEE LLC
  • US8132164B1 patent drawing
  • US8132164B1 patent drawing
  • US8132164B1 patent drawing

AI summary

A system, method, and computer program product are provided for virtual patching. Initially, information associated with at least one vulnerability of a computer application is collected. Further, at least one host interface is identified that is capable of being used to access the vulnerability. In use, data sent to the at least one host interface is analyzed to determine whether the data is unwanted, based on the information.