Vulnerability Exploitation for Device Patching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complex ecosystem of modern mobile devices, involving multiple parties, often leads to slow and ineffective vulnerability patching due to disorganization and lack of incentives, resulting in unresolved security flaws.

Innovation Solution

A system comprising a vulnerability tool with an assessment component, exploit engine, and update component that identifies and exploits vulnerabilities to grant escalated privileges, enabling the application of patches through a reference monitor, even in closed systems where necessary privileges are absent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the conventional multi-party ecosystem approach is used for vulnerability patching, then device security coverage is comprehensive, but the patching speed becomes extremely slow and vulnerabilities remain unresolved

Engineering Contradiction:
Improvedevice security coverageVSAvoidpatching speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent converts the identified vulnerability from a harmful security flaw into a beneficial mechanism for privilege escalation. By exploiting the vulnerability through controlled means, the system gains the necessary privileges to apply patches that would otherwise be inaccessible, thus transforming the security risk into a patching opportunity.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

Instead of following the conventional top-down patching approach where privileged parties distribute updates, the patent inverts the process by using vulnerability exploitation from the bottom up to gain privileges. This reverse approach allows the patching mechanism to work against the grain of the traditional security model, enabling updates without relying on the cooperation of multiple ecosystem parties.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If privileged parties control the patching process, then system security is maintained, but patching becomes ineffective when parties lack incentives

Engineering Contradiction:
Improvesystem securityVSAvoidpatching effectiveness
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables the device to perform self-patching by automatically exploiting its own vulnerabilities to gain the necessary privileges. This self-service mechanism eliminates the dependency on external privileged parties who may lack incentives, allowing the system to patch itself autonomously without human intervention or coordination with ecosystem stakeholders.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a reference monitor as an intermediary component that mediates between the vulnerability exploitation process and the patching mechanism. This intermediary ensures that the exploitation is controlled and safe, while still enabling the necessary privilege escalation to apply patches, thus maintaining security while improving effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If exploitation is used to gain privileges, then patching access is enabled, but the system complexity increases

Engineering Contradiction:
Improvepatching accessVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the patching functionality from the privileged domain and makes it accessible through the unprivileged user space by utilizing vulnerability exploitation. This separation allows the complex privilege escalation logic to be isolated from the core patching mechanism, enabling patching access without permanently increasing system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary vulnerability assessment and exploitation preparation before the actual patching process. By pre-identifying exploitable vulnerabilities and preparing the exploitation payload in advance, the system reduces the complexity of the real-time patching operation, making the overall process more manageable and less intrusive.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9607156B2System and method for patching a device through exploitation
Publication Date: 2017.03.28 CISCO TECHNOLOGY INC
  • US9607156B2 patent drawing
  • US9607156B2 patent drawing
  • US9607156B2 patent drawing

AI summary

A system and method that includes identifying a vulnerability in a computing device; accessing a vulnerability exploitation mapped to the identified vulnerability; at the computing device, executing the vulnerability exploitation and entering an operating mode of escalated privileges; and while in the operating mode of escalated privileges, updating the system with a vulnerability resolution.