Vulnerability Prioritization via Exploit Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability scanning methods produce large volumes of results with limited prioritization, often relying on outdated exploit data, leading to ineffective remediation efforts as they fail to accurately reflect real-time vulnerability exploitation trends.
Innovation Solution
A method that correlates vulnerability scan data with current exploit data from various sources to generate an exploit prevalence score, prioritizing vulnerabilities based on actual attack frequency and impact, and automatically performs remediation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If vulnerability scanners are used to identify all vulnerabilities, then the quantity of vulnerability results increases, but the ability to prioritize critical threats deteriorates due to false positives and limited scope
Solution Approach 1:
The patent introduces multiple intermediary data sources (exploit databases, threat intelligence feeds, asset management systems, patch management systems) that mediate between the vulnerability scanner and the prioritization process. These intermediaries provide additional context and validation, enabling accurate prioritization of the large volume of vulnerability results while filtering out false positives.
Solution Approach 2:
The system implements feedback loops where vulnerability results are continuously correlated with exploit data, threat intelligence, and remediation status. This feedback mechanism refines prioritization over time, allowing the system to learn from actual exploit patterns and adjust priority assignments dynamically, improving measurement precision while handling large quantities of results.
2Device complexity
If traditional vulnerability prioritization methods are used, then the process is simpler, but the response time to real-time exploit trends deteriorates due to reliance on outdated data
Solution Approach 1:
The system performs preliminary actions by continuously pre-correlating vulnerability data with exploit databases, threat intelligence feeds, and asset information before actual security incidents occur. This advance preparation ensures that when new exploits emerge, the system can immediately prioritize affected vulnerabilities without time-consuming analysis, reducing response time while managing complexity through automated workflows.
Solution Approach 2:
The patent implements continuous correlation and updating of vulnerability prioritization based on real-time exploit data and threat intelligence. Rather than periodic updates, the system maintains continuous useful action by constantly monitoring exploit prevalence, threat landscapes, and remediation progress, ensuring timely response to emerging threats while keeping the process manageable through automation.
3Area of stationary object
If comprehensive vulnerability scanning is performed across the network, then coverage increases, but the ability to focus remediation on critical threats deteriorates due to lack of prioritization
Solution Approach 1:
The patent applies local quality by assigning different priority levels and remediation urgency to different vulnerabilities based on their specific characteristics, exploit prevalence, asset criticality, and current threat landscape. Rather than uniform treatment, each vulnerability receives localized prioritization tailored to its risk profile, enabling focused remediation on critical threats while maintaining comprehensive scan coverage across the entire network.
Solution Approach 2:
The system dynamically changes prioritization parameters based on multiple factors including exploit prevalence scores, threat intelligence data, asset value, and remediation status. These parameter changes enable the system to maintain comprehensive coverage while adapting priority assignments to reflect current risk levels, thereby improving remediation efficiency by focusing resources on the most critical threats at any given time.
Data Source
AI summary
Prioritizing vulnerability scan results is provided. Vulnerability scan results data corresponding to a network of data processing systems are received from a vulnerability scanner. The vulnerability scan results data are parsed to group the vulnerability scan results data by vulnerability identifiers. A corresponding security threat information identifier is associated with each vulnerability identifier. A correlation of each associated security threat information identifier is performed with a set of current vulnerability exploit data that corresponds to that particular security threat information identifier. Current security threat information that affects host data processing systems in the network is determined based on the correlation between each associated security threat information identifier and its corresponding set of current vulnerability exploit data. The current security threat information is prioritized based on a number of corresponding current vulnerability exploit attacks.


