Vulnerability Detection Component for Managed Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in identifying and managing vulnerabilities in client devices used to access enterprise resources, as malicious software and software defects can lead to unauthorized access, and existing solutions lack comprehensive detection and remediation mechanisms.

Innovation Solution

A management service is implemented that requires client devices to install a management component, which in turn installs a vulnerability detection component to scan for vulnerabilities, providing a severity metric for remedial actions, such as removing email access or exiting a quarantine state, based on detected vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprises implement comprehensive vulnerability detection and management measures, then security of enterprise resources is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvesecurity of enterprise resourcesVSAvoidcomplexity of vulnerability management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a management service as an intermediary component that coordinates between client devices, vulnerability detection, and remediation actions. This centralized intermediary simplifies the overall system architecture by providing a single point of control rather than requiring complex peer-to-peer coordination between multiple security components.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The vulnerability management system is segmented into distinct functional components: a management service for coordination, a vulnerability detection component for scanning, and a remediation component for applying fixes. This segmentation allows each component to be optimized independently and reduces the complexity any single component must handle.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If vulnerability scans are performed frequently to detect new threats, then detection precision is improved, but loss of time and productivity increase

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoidtime lost to scanning operations
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements periodic vulnerability scanning at scheduled intervals rather than continuous scanning. This allows the system to maintain detection precision by regularly checking for vulnerabilities while minimizing productivity loss by keeping devices operational between scan cycles.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The vulnerability detection component operates autonomously on client devices, performing scans without requiring manual intervention or taking devices offline. This self-service approach maintains detection precision while minimizing impact on productivity.

Inventive Principle:
Principle #25Self-service

3Reliability

If remedial actions are taken immediately upon vulnerability detection, then reliability is improved, but device complexity and operational disruption increase

Engineering Contradiction:
Improvesecurity posture of enterprise resourcesVSAvoidoperational continuity of client devices
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system prepares remediation packages in advance and stages them for deployment. Rather than immediately disrupting operations, the remediation component can apply fixes during scheduled maintenance windows or when devices are naturally idle, maintaining security posture while preserving operational continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remediation process is made dynamic and adaptive, allowing the system to adjust the timing and method of applying fixes based on device usage patterns and criticality. This enables security improvements to be implemented without causing unnecessary operational disruption.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11816222B2Detecting vulnerabilities in managed client devices
Publication Date: 2023.11.14 OMNISSA LLC
  • US11816222B2 patent drawing
  • US11816222B2 patent drawing
  • US11816222B2 patent drawing

AI summary

The disclosure relates to detecting vulnerabilities in managed client devices. A system determines whether a vulnerability scan of a computing device is required to be performed. The system installs a vulnerability detection component in the computing device in response to determining that the vulnerability scan is required to be performed. The system requests the vulnerability detection component to perform the vulnerability scan of the computing device. The system transmits a result of the vulnerability scan to a remote management service for the computing device.