Vulnerability Impact Detection via Normalizer and Correlator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability detection methods are inefficient in assessing the impact of software, hardware, and firmware vulnerabilities across diverse IT resources, leading to unreliable reports and delayed mitigation strategies, as they lack real-time correlation with affected assets, making it challenging to implement timely and effective security measures.

Innovation Solution

A system utilizing a normalizer and correlator to process vulnerability reports from various data sources, assigning risk levels and confidence scores based on predefined rules, enabling real-time correlation with asset information to prioritize and address vulnerabilities effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If vulnerability reports are collected from multiple data sources, then the coverage of vulnerability detection is improved, but the reliability of reports deteriorates due to unreliable sources

Engineering Contradiction:
Improvecoverage of vulnerability detectionVSAvoidreliability of vulnerability reports
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a correlator as an intermediary component that sits between vulnerability data sources and the vulnerability management system. The correlator evaluates the reliability of vulnerability reports by analyzing correlations between multiple data sources, cross-referencing information, and assessing the credibility of report sources before passing data to the vulnerability management system. This intermediary layer filters out unreliable reports while maintaining comprehensive coverage from multiple sources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If real-time correlation with affected assets is implemented, then the speed of vulnerability response is improved, but the system complexity increases

Engineering Contradiction:
Improvespeed of vulnerability responseVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability management system into distinct functional components: a normalizer for data standardization, a correlator for reliability assessment and asset correlation, and a vulnerability management system for action execution. The correlator specifically handles real-time correlation with affected assets as a separate module that processes vulnerability reports against asset inventories in real-time, enabling fast response without overwhelming system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive vulnerability assessment is performed, then the accuracy of impact detection is improved, but the time required for assessment increases

Engineering Contradiction:
Improveaccuracy of impact detectionVSAvoidtime required for assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action through the normalizer component that pre-processes and standardizes vulnerability report data before it enters the correlator. The normalizer extracts key information, standardizes formats, and prepares data structures in advance, so that when vulnerability reports arrive, the correlator can immediately perform accurate impact detection without time-consuming data preparation. This preliminary processing enables both high accuracy and fast assessment time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11025660B2Impact-detection of vulnerabilities
Publication Date: 2021.06.01 THREATWATCH INC
  • US11025660B2 patent drawing
  • US11025660B2 patent drawing
  • US11025660B2 patent drawing

AI summary

Various implementations disclosed herein provide a method for detecting impact of the vulnerability by using a normalizer and correlator. In various implementations, the method includes: accessing a first set of data from a first data sources, calculating a risk level value for each of the first set of data based on a first set of rules, sorting the first set of data based on their risk level, accessing the sorted first set of data by a correlator, accessing, by the correlator, a second set of data from second data sources, correlating each of the sorted first set of data to at least a data of the second set of data based a second set of rules, and calculating a confidence score for each data of the sorted first set of data based on a third set of rules.