Vulnerability Assessment System Correlating Exposed Services and Software Packages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability assessment tools for network devices do not provide a comprehensive view of vulnerabilities, as they either require logging into the host or external scanning, which are inadequate for identifying exposed services associated with vulnerable software packages.

Innovation Solution

A method and system that receive a list of externally exposed services and software package vulnerabilities, determining if exposed services are associated with vulnerable packages, and executing remedial actions, such as issuing alerts or elevating software for further examination, using authentication credentials to connect to the network device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If existing vulnerability assessment tools use external scanning methods, then the assessment can be performed without logging into the host, but the view of vulnerabilities is not comprehensive

Engineering Contradiction:
Improveassessment operation convenienceVSAvoidvulnerability information completeness
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent combines multiple data collection methods (external scanning, internal software package cataloging, and service exposure information) into a unified vulnerability assessment system. This merging allows the system to overcome the limitations of individual methods and provide comprehensive vulnerability information without requiring manual login to each host.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a vulnerability assessment server as an intermediary that collects and correlates data from multiple sources including external scan results, software package vulnerability databases, and service exposure information. This intermediary processes and integrates the information to produce comprehensive vulnerability assessments without requiring direct login to assessed hosts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If existing vulnerability assessment tools log into the host to capture software catalogs, then comprehensive software information can be obtained, but the assessment process becomes more complex and time-consuming

Engineering Contradiction:
Improvesoftware package information completenessVSAvoidassessment time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent pre-populates a vulnerability database with software package information, version details, and known vulnerabilities before the actual assessment. This preliminary preparation allows the system to quickly match discovered software against the pre-analyzed database, significantly reducing assessment time while maintaining comprehensive information accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates and maintains a comprehensive copy of software package vulnerability information in a centralized database, including detailed metadata about each package, its versions, and associated vulnerabilities. This pre-created knowledge base eliminates the need for real-time deep analysis during assessment, reducing time loss while preserving information completeness.

Inventive Principle:
Principle #26Copying

3Ease of operation

If vulnerability assessment tools scan hosts externally, then the assessment can be performed remotely, but the ability to identify exposed services associated with vulnerable software is insufficient

Engineering Contradiction:
Improveremote assessment capabilityVSAvoidvulnerability exposure accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the vulnerability assessment server continuously correlates service exposure information with software package data and vulnerability databases. This feedback loop allows the system to refine its identification of exposed vulnerable services by cross-referencing multiple data sources, improving measurement precision while maintaining remote operation capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent adds a new dimension to external scanning by incorporating service exposure information and software package metadata into the assessment process. This multi-dimensional approach transforms simple port scanning into a comprehensive analysis that identifies which exposed services are associated with vulnerable software packages, significantly improving vulnerability exposure accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11853432B2Assessing vulnerability of service-providing software packages
Publication Date: 2023.12.26 RAPID7 INC
  • US11853432B2 patent drawing
  • US11853432B2 patent drawing
  • US11853432B2 patent drawing

AI summary

Methods and systems for assessing a vulnerability of a network device. The systems and methods described herein combine data regarding locally discovered vulnerabilities and exposed services with data regarding what executables are provided by software installed on the network device.