Automated Vulnerability Grouping for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As networked computer systems grow in complexity, they introduce more vulnerabilities, making it difficult to proactively prevent malicious attacks and undesirable events, with existing scanning technologies often resulting in decreased visibility of critical vulnerabilities.

Innovation Solution

A vulnerability response system that enables customized analysis and predictive forecasting of data, allowing for complex reporting and interactivity with time-series data, including a vulnerability response tool that evaluates and groups vulnerabilities for enhanced tracking, prioritization, and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If scanning technologies are used to detect vulnerabilities in growing networked computer systems, then the number of detected vulnerabilities increases, but the visibility of critical vulnerabilities decreases due to the overwhelming quantity of results

Engineering Contradiction:
Improvenumber of vulnerabilities detectedVSAvoidvisibility of critical vulnerabilities
Core Design Contradiction:
Quantity of substanceVSLoss of information

Solution Approach 1:

The patent segments vulnerabilities into different groups based on their characteristics, severity, and impact. By dividing the large set of all vulnerabilities into meaningful subsets (e.g., critical, high, medium, low severity groups), the system enables focused analysis and reporting on specific vulnerability categories, thereby restoring visibility of critical vulnerabilities amidst the overall increase in detected vulnerabilities.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If the number of computer resources is increased to enhance system capabilities, then system functionality improves, but the complexity of managing and securing the system increases

Engineering Contradiction:
Improvesystem capabilitiesVSAvoidcomplexity of vulnerability management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal vulnerability management system that handles diverse vulnerability types across multiple computer resources through a single integrated platform. The system provides multi-functional capabilities including automated scanning, classification, grouping, prioritization, and remediation tracking, thereby simplifying vulnerability management complexity while supporting enhanced system capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the parameters of vulnerability management by introducing automated classification based on severity levels, impact assessment, and prioritization metrics. By transforming raw vulnerability data into structured information with defined parameters (severity scores, priority ratings, risk levels), the system reduces management complexity while enabling effective security control across expanded system capabilities.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive vulnerability scanning is performed across all system resources, then complete vulnerability detection is achieved, but the time and resources required for analysis and remediation increase

Engineering Contradiction:
Improvecompleteness of vulnerability detectionVSAvoidtime for analysis and remediation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by automatically classifying and prioritizing vulnerabilities immediately after detection, before full analysis and remediation begin. The system pre-processes vulnerability data by assigning severity levels, impact categories, and priority rankings, thereby preparing the information in advance for faster analysis and remediation execution, reducing the overall time required while maintaining complete detection coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms that provide continuous information about vulnerability status, remediation progress, and system security posture. By feeding back prioritized vulnerability information to stakeholders and automatically updating risk assessments based on remediation actions, the system enables efficient resource allocation and accelerates the remediation process while maintaining comprehensive detection reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3468145B1Automated vulnerability grouping
Publication Date: 2022.11.30 SERVICENOW INC
  • EP3468145B1 patent drawingFigure 1~2
  • EP3468145B1 patent drawingFigure 3
  • EP3468145B1 patent drawingFigure 4

AI summary

Systems and methods for automatically grouping vulnerabilities into vulnerability groups are provided (406). Vulnerabilities are received in the vulnerability response system (402) and are automatically grouped into one or more vulnerability groups based upon grouping fields defined in a vulnerability group rule (404,406).