Vulnerability Identification System for Automated Software Audits
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security audits for computer systems are time-consuming, labor-intensive, and fail to provide real-time evaluations of software vulnerabilities, often missing newly discovered vulnerabilities and requiring manual resolution processes.
Innovation Solution
A vulnerability identification and resolution (VIR) system that uses a processor and memory device to query a database for security vulnerabilities associated with selected computing assets, providing rapid and accurate identification and resolution tools for operators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual security audits are performed by operators, then vulnerabilities can be identified and evaluated, but the process becomes time-consuming and labor-intensive
Solution Approach 1:
The system performs self-service by automatically querying vulnerability databases and comparing them against the organization's software inventory without requiring manual operator intervention. The computer automatically retrieves vulnerability information, matches it with installed applications, and generates reports, eliminating the need for human operators to manually conduct audits while maintaining high accuracy through systematic database queries and automated comparison algorithms.
Solution Approach 2:
The patent replaces the mechanical manual process of operator-based vulnerability assessment with an automated computerized system. Instead of operators manually reviewing software lists and vulnerability databases, the system uses automated querying, data retrieval, and comparison mechanisms to identify vulnerabilities, thereby reducing audit time while preserving identification accuracy through structured automated processes.
2Reliability
If manual vulnerability assessment is performed, then vulnerabilities can be detected, but the audit frequency is limited by operator availability
Solution Approach 1:
The system enables continuous self-service vulnerability assessments by automatically querying vulnerability databases and comparing them with the software inventory on demand. This eliminates the constraint of operator availability, allowing the system to perform audits at any frequency required by security policies or in response to new vulnerability discoveries, thereby maintaining high detection capability while dramatically increasing audit frequency and responsiveness.
Solution Approach 2:
The patent implements continuous vulnerability assessment capability where the system can continuously query vulnerability databases, retrieve updated information, and compare it against the software inventory without interruption. This continuous operation ensures that vulnerabilities are detected promptly and audit frequency is no longer limited by human availability, enabling real-time or near-real-time security monitoring and rapid response to emerging threats.
3Reliability
If conventional manual audits are used, then vulnerabilities can be identified, but newly discovered vulnerabilities go undiscovered during the audit
Solution Approach 1:
The system maintains continuous connection to vulnerability databases, ensuring that the latest vulnerability information is always available for comparison. When conducting audits, the system queries the database to retrieve current vulnerability data, ensuring that even newly discovered vulnerabilities are captured. This continuous data retrieval eliminates the time lag inherent in manual audits where vulnerability lists may become outdated, thereby improving vulnerability coverage while maintaining timely and objective assessment.
Solution Approach 2:
The system performs preliminary queries of vulnerability databases before conducting the actual vulnerability matching process. By pre-retrieving the latest vulnerability information and maintaining an updated cache of vulnerability data, the system ensures that when audits are performed, the most current vulnerability information is already available, preventing newly discovered vulnerabilities from being missed and eliminating time subjectivity in the assessment process.
4Productivity
If automated querying systems are implemented, then real-time vulnerability evaluation is achieved, but system complexity increases
Solution Approach 1:
The patent implements a multi-functional vulnerability assessment system that combines database querying, data retrieval, vulnerability matching, report generation, and resolution tracking in a single integrated platform. This universal system performs multiple security functions through unified architecture, achieving real-time evaluation capabilities without proportionally increasing complexity. The system serves as both a detection tool and a resolution management platform, consolidating functions that would otherwise require separate systems.
Solution Approach 2:
The system merges the vulnerability detection, assessment, and resolution processes into a single integrated workflow. By combining database querying, vulnerability matching, and remediation tracking in one system, the patent achieves real-time evaluation without the complexity of multiple separate tools. The integrated architecture allows data to flow seamlessly from vulnerability identification through assessment to resolution tracking, improving productivity while managing complexity through unified design rather than multiple discrete components.
Data Source
AI summary
A vulnerability identification and resolution (VIR) computer device for identifying security vulnerabilities in a computer system is provided. The VIR computer device includes a memory device for storing data including data representing computing assets installed in the computer system and a processor in communication with the memory device. The VIR computer device is programmed to receive an asset identifier identifying a computing asset selected for evaluation and execute a query on at least one database storing security vulnerabilities, the query searching for security vulnerability data associated with the selected computing asset. The VIR computer device is further programmed to receive the security vulnerability data at the VIR computer device in response to the query.


