Vulnerability Prioritization via Exploit Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability scanning methods produce large volumes of results with limited prioritization, often relying on outdated exploit data, leading to ineffective remediation efforts as they fail to accurately reflect real-time vulnerability exploitation trends.

Innovation Solution

A method that correlates vulnerability scan data with current exploit data from various sources to generate an exploit prevalence score, prioritizing vulnerabilities based on actual attack frequency and impact, and automatically performs remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If vulnerability scanners are used to identify all vulnerabilities, then the quantity of vulnerability results increases, but the ability to prioritize critical threats deteriorates due to false positives and limited scope

Engineering Contradiction:
Improvequantity of vulnerability resultsVSAvoidprioritization accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent introduces multiple intermediary data sources (exploit databases, threat intelligence feeds, asset management systems, patch management systems) that mediate between the vulnerability scanner and the prioritization process. These intermediaries provide additional context and validation, enabling accurate prioritization of the large volume of vulnerability results while filtering out false positives.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback loops where vulnerability results are continuously correlated with exploit data, threat intelligence, and remediation status. This feedback mechanism refines prioritization over time, allowing the system to learn from actual exploit patterns and adjust priority assignments dynamically, improving measurement precision while handling large quantities of results.

Inventive Principle:
Principle #23Feedback

2Device complexity

If traditional vulnerability prioritization methods are used, then the process is simpler, but the response time to real-time exploit trends deteriorates due to reliance on outdated data

Engineering Contradiction:
Improveprioritization process complexityVSAvoidresponse time to exploit trends
Core Design Contradiction:
Device complexityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously pre-correlating vulnerability data with exploit databases, threat intelligence feeds, and asset information before actual security incidents occur. This advance preparation ensures that when new exploits emerge, the system can immediately prioritize affected vulnerabilities without time-consuming analysis, reducing response time while managing complexity through automated workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous correlation and updating of vulnerability prioritization based on real-time exploit data and threat intelligence. Rather than periodic updates, the system maintains continuous useful action by constantly monitoring exploit prevalence, threat landscapes, and remediation progress, ensuring timely response to emerging threats while keeping the process manageable through automation.

Inventive Principle:
Principle #20Continuity of useful action

3Area of stationary object

If comprehensive vulnerability scanning is performed across the network, then coverage increases, but the ability to focus remediation on critical threats deteriorates due to lack of prioritization

Engineering Contradiction:
Improvescan coverage areaVSAvoidremediation efficiency
Core Design Contradiction:
Area of stationary objectVSProductivity

Solution Approach 1:

The patent applies local quality by assigning different priority levels and remediation urgency to different vulnerabilities based on their specific characteristics, exploit prevalence, asset criticality, and current threat landscape. Rather than uniform treatment, each vulnerability receives localized prioritization tailored to its risk profile, enabling focused remediation on critical threats while maintaining comprehensive scan coverage across the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes prioritization parameters based on multiple factors including exploit prevalence scores, threat intelligence data, asset value, and remediation status. These parameter changes enable the system to maintain comprehensive coverage while adapting priority assignments to reflect current risk levels, thereby improving remediation efficiency by focusing resources on the most critical threats at any given time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11621975B2Prioritizing vulnerability scan results
Publication Date: 2023.04.04 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11621975B2 patent drawing
  • US11621975B2 patent drawing
  • US11621975B2 patent drawing

AI summary

Prioritizing vulnerability scan results is provided. Vulnerability scan results data corresponding to a network of data processing systems are received from a vulnerability scanner. The vulnerability scan results data are parsed to group the vulnerability scan results data by vulnerability identifiers. A corresponding security threat information identifier is associated with each vulnerability identifier. A correlation of each associated security threat information identifier is performed with a set of current vulnerability exploit data that corresponds to that particular security threat information identifier. Current security threat information that affects host data processing systems in the network is determined based on the correlation between each associated security threat information identifier and its corresponding set of current vulnerability exploit data. The current security threat information is prioritized based on a number of corresponding current vulnerability exploit attacks.