Network Vulnerability Assessment Tool Using Intrusion Ratios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In decentralized networks, conventional vulnerability assessment methods are inefficient due to the lack of a unified baseline, leading to inaccurate detection of vulnerabilities and inefficient resource allocation, as they focus on individual server assessments rather than actual intrusion counts across applications.

Innovation Solution

A network vulnerability assessment tool with two servers and a hardware processor that calculates ratios of application intrusions to vulnerabilities, identifying the most critical vulnerabilities by comparing exploitation risks across applications and servers, and flagging them for security improvements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional detection systems assess each server individually, then the assessment can be performed independently without requiring unified baselines, but the accuracy of vulnerability detection decreases and resource allocation becomes inefficient

Engineering Contradiction:
ImproveIndependent server assessment capabilityVSAvoidVulnerability detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent combines individual server vulnerability assessments with centralized intrusion data to create a unified vulnerability detection system. The server assessment module collects vulnerability data from multiple servers, which is then merged with intrusion data from the centralized intrusion data store. This merging allows the system to maintain independent assessment capabilities while achieving unified baseline accuracy through correlated analysis.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback by using detected intrusions to refine vulnerability assessments. The intrusion data from the centralized intrusion data store serves as feedback that helps identify which vulnerabilities are most likely to be exploited. This feedback loop improves detection accuracy by prioritizing vulnerabilities that have actual exploitation attempts, while maintaining the independence of individual server assessments.

Inventive Principle:
Principle #23Feedback

2Device complexity

If vulnerability assessments are performed on each server independently, then resource deployment can be simplified, but the allocation of security resources becomes inefficient due to lack of intrusion context

Engineering Contradiction:
ImproveAssessment system structureVSAvoidSecurity resource allocation efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system segments vulnerability assessment and intrusion detection into separate functional modules. The server assessment module handles vulnerability collection independently on each server, while the centralized intrusion data store collects intrusion data separately. This segmentation maintains simple resource deployment but improves productivity by enabling efficient correlation between vulnerabilities and actual intrusion attempts through the processor's analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The processor acts as an intermediary that correlates vulnerability data from individual server assessments with intrusion data from the centralized store. This intermediary function enables efficient resource allocation by identifying which vulnerabilities require immediate attention based on actual intrusion patterns, without requiring complex changes to the decentralized assessment structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If decentralized networks use multiple parties to perform server assessments, then the network can scale and share resources, but the assessments do not share the same baseline decreasing detection accuracy

Engineering Contradiction:
ImproveNetwork scalability and resource sharingVSAvoidVulnerability detection consistency
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system implements a universal vulnerability data format and assessment methodology that can be applied across all servers in the decentralized network. The server assessment module uses consistent criteria to evaluate vulnerabilities on different servers, while the centralized intrusion data store aggregates data from multiple sources. This universality enables network scalability and resource sharing while maintaining detection consistency through unified analysis principles.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates equipotentiality by establishing a common baseline for vulnerability assessment across all servers. The processor correlates vulnerability data from different servers using the same analytical framework, ensuring that assessments from multiple parties are evaluated on equal footing. This approach maintains the benefits of decentralized multi-party assessment while achieving consistent detection accuracy through unified baseline standards.

Inventive Principle:
Principle #12Equipotentiality

Data Source

PatentUS11290480B2Network vulnerability assessment tool
Publication Date: 2022.03.29 BANK OF AMERICA CORP
  • US11290480B2 patent drawing
  • US11290480B2 patent drawing
  • US11290480B2 patent drawing

AI summary

A system includes a plurality of servers hosting a plurality of software applications, a data lake, and a vulnerability assessment tool. The data lake is configured to store data related to vulnerabilities in the servers and applications. The data lake also stores data on the number of intrusion events detected on each application. The vulnerability assessment tool is configured to generate logic tables relating the data on server vulnerabilities, application vulnerabilities, and application intrusion counts. The vulnerability assessment tool may use the extrapolations from the newly ordered data to flag applications or servers for prioritized security improvements.