Vulnerability Contextualization via Asset Merging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cyber security vulnerability scanning solutions fail to translate threats into actionable data, unable to prioritize remediation efforts, and lack integration with technology system management, making it difficult to manage and address vulnerabilities effectively in a rapidly changing cyber threat landscape.
Innovation Solution
A system and method that contextualizes vulnerabilities by merging raw vulnerability data with asset inventories and control exceptions, enabling automated prioritization and remediation, and generating actionable reports to reduce manual identification errors and response time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual vulnerability identification and prioritization methods are used, then labor and manpower requirements increase, but vulnerability management accuracy and efficiency deteriorate
Solution Approach 1:
The patent introduces an automated vulnerability management system that acts as an intermediary between vulnerability scanning and prioritization decisions. This system automatically ingests vulnerability data, enriches it with contextual information from multiple sources (asset inventories, threat intelligence, business data), and generates prioritized vulnerability lists, eliminating the need for manual analysis and significantly improving efficiency while reducing time loss.
Solution Approach 2:
The patent replaces manual mechanical processes (human analysts reviewing and prioritizing vulnerabilities) with an automated computational system. The system uses algorithms to process vulnerability data, apply risk models, and generate prioritized outputs automatically, substituting human labor with machine-based processing that is faster, more consistent, and scalable.
2Measurement precision
If comprehensive vulnerability scanning is performed, then the number of identified vulnerabilities increases, but the difficulty of selecting highly critical vulnerabilities increases
Solution Approach 1:
The automated vulnerability management system serves as an intermediary that processes the comprehensive vulnerability data and applies multiple enrichment sources and risk models to automatically prioritize vulnerabilities. This intermediary layer transforms the complex raw data into manageable, prioritized information, reducing the complexity of selection while maintaining comprehensive identification.
Solution Approach 2:
The patent changes the parameters used to evaluate vulnerabilities by incorporating multiple enrichment sources (threat intelligence, asset criticality, business context) and applying risk models that transform raw vulnerability data into prioritized risk assessments. This parameter transformation converts a complex selection problem into a simplified ranking system based on calculated risk scores.
3Loss of information
If traditional vulnerability scanning solutions are used, then raw vulnerability data is collected, but the ability to translate threats into actionable data and prioritize remediation deteriorates
Solution Approach 1:
The patent merges raw vulnerability data with contextual information from multiple enrichment sources including asset inventories, threat intelligence feeds, business data, and vulnerability metadata. This combination creates a comprehensive view that translates raw vulnerability information into actionable, prioritized data with full contextual understanding, making remediation decisions easier and more informed.
Solution Approach 2:
The automated vulnerability management system acts as an intermediary that processes raw vulnerability data and enriches it with contextual information from multiple sources. This intermediary transforms incomplete raw data into comprehensive, actionable intelligence that includes risk prioritization, remediation recommendations, and contextual business information.
Data Source
AI summary
An embodiment of the disclosure provides a method for contextualizing vulnerabilities. The method is performed by a server including a processor and a non-transitory computer-readable medium with computer-executable instructions stored thereon, such that when the instructions are executed by the processor, the server performs the method including: (a) importing raw vulnerability data from a vulnerability scanner, the raw vulnerability data including one or more vulnerability data wherein each vulnerability data includes a vulnerability identification (ID) and an asset value; (b) importing an asset inventory from an asset database; (c) merging the asset inventory and the raw vulnerability data to obtain contextual vulnerability data, the contextual vulnerability data including one or more vulnerability data linked to a vulnerability ID, an asset value, and an asset owner; (d) categorizing the contextual vulnerability data; and (e) generating a report of the categorized contextual vulnerability data.


