Vulnerability Assessment System Correlating Exposed Services and Software Packages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vulnerability assessment tools for network devices do not provide a comprehensive view of vulnerabilities, as they either require logging into the host or external scanning, which are inadequate for identifying exposed services associated with vulnerable software packages.
Innovation Solution
A method and system that receive a list of externally exposed services and software package vulnerabilities, determining if exposed services are associated with vulnerable packages, and executing remedial actions, such as issuing alerts or elevating software for further examination, using authentication credentials to connect to the network device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If existing vulnerability assessment tools use external scanning methods, then the assessment can be performed without logging into the host, but the view of vulnerabilities is not comprehensive
Solution Approach 1:
The patent combines multiple data collection methods (external scanning, internal software package cataloging, and service exposure information) into a unified vulnerability assessment system. This merging allows the system to overcome the limitations of individual methods and provide comprehensive vulnerability information without requiring manual login to each host.
Solution Approach 2:
The patent introduces a vulnerability assessment server as an intermediary that collects and correlates data from multiple sources including external scan results, software package vulnerability databases, and service exposure information. This intermediary processes and integrates the information to produce comprehensive vulnerability assessments without requiring direct login to assessed hosts.
2Loss of information
If existing vulnerability assessment tools log into the host to capture software catalogs, then comprehensive software information can be obtained, but the assessment process becomes more complex and time-consuming
Solution Approach 1:
The patent pre-populates a vulnerability database with software package information, version details, and known vulnerabilities before the actual assessment. This preliminary preparation allows the system to quickly match discovered software against the pre-analyzed database, significantly reducing assessment time while maintaining comprehensive information accuracy.
Solution Approach 2:
The patent creates and maintains a comprehensive copy of software package vulnerability information in a centralized database, including detailed metadata about each package, its versions, and associated vulnerabilities. This pre-created knowledge base eliminates the need for real-time deep analysis during assessment, reducing time loss while preserving information completeness.
3Ease of operation
If vulnerability assessment tools scan hosts externally, then the assessment can be performed remotely, but the ability to identify exposed services associated with vulnerable software is insufficient
Solution Approach 1:
The patent implements a feedback mechanism where the vulnerability assessment server continuously correlates service exposure information with software package data and vulnerability databases. This feedback loop allows the system to refine its identification of exposed vulnerable services by cross-referencing multiple data sources, improving measurement precision while maintaining remote operation capability.
Solution Approach 2:
The patent adds a new dimension to external scanning by incorporating service exposure information and software package metadata into the assessment process. This multi-dimensional approach transforms simple port scanning into a comprehensive analysis that identifies which exposed services are associated with vulnerable software packages, significantly improving vulnerability exposure accuracy.
Data Source
AI summary
Methods and systems for assessing a vulnerability of a network device. The systems and methods described herein combine data regarding locally discovered vulnerabilities and exposed services with data regarding what executables are provided by software installed on the network device.


