Vulnerability Drift Analytics for Historical Status Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vulnerability management techniques fail to effectively prioritize, track, and visually represent software vulnerabilities, relying heavily on user adherence to best practices and technical understanding of accumulated vulnerabilities over time.
Innovation Solution
Implementing vulnerability drift analytics to aggregate and analyze vulnerability reports, generate metrics, and create graphical representations to track and visualize changes in vulnerability status over time, using a system that includes processors, memory, and communication interfaces to manage software vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If conventional vulnerability management techniques are used, then users can identify vulnerabilities through scanning solutions, but users lack the capability to effectively prioritize, track, and understand accumulated vulnerabilities over time
Solution Approach 1:
The patent introduces an intermediary vulnerability management system that sits between the scanning solutions and users. This system aggregates vulnerability data from multiple sources, maintains historical records, calculates drift metrics, and presents processed information through graphical interfaces. The intermediary handles the complexity of vulnerability tracking and analysis, freeing users from directly managing raw vulnerability data while providing actionable insights through drift summaries and visual representations.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring vulnerability status changes over time and providing drift summaries that highlight significant changes. The historical record maintenance and comparative analysis create a feedback loop where past vulnerability data informs current risk assessments and remediation priorities, enabling users to understand vulnerability accumulation patterns and make informed decisions.
2Reliability
If vulnerability data is collected and analyzed over time, then better vulnerability prioritization and tracking can be achieved, but the system complexity increases
Solution Approach 1:
The vulnerability management system is segmented into distinct functional modules: data collection module that aggregates vulnerability reports from multiple scanning solutions, historical record maintenance module that stores and manages vulnerability data over time, drift analysis module that calculates metrics and identifies significant changes, and visual presentation module that displays vulnerability status through graphical interfaces. This segmentation allows each component to specialize in specific tasks, improving overall reliability while managing complexity through modular design.
Solution Approach 2:
The system is designed as a universal vulnerability management platform that can handle multiple vulnerability sources, application types, and analysis requirements through a single integrated architecture. The drift analysis engine and graphical interface provide multi-functional capabilities that serve various vulnerability management needs, reducing the need for multiple specialized systems and thereby managing complexity while maintaining high reliability.
Data Source
AI summary
A method for providing vulnerability management by using drift analytics is disclosed. The method includes aggregating vulnerability reports that correspond to an application based on a predetermined configuration, the predetermined configuration including a predetermined schedule; appending the vulnerability reports to a historical record that corresponds to the application, the historical record including previously collected vulnerability reports; determining metrics for the application by using the corresponding historical record; generating a drift summary for the application based on the determined metrics and the corresponding historical record; comparing the drift summary with a previously generated drift summary to identify changes, the changes relating to a vulnerability status; and generating a drift report for the application based on the identified changes.


