Vulnerability Lockdown Module for Computer Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems remain vulnerable to exploitation between the time a vulnerability is identified and when a patch is released or installed, due to delays in software updates and potential system instability caused by patch implementation.

Innovation Solution

A vulnerability lockdown module that dynamically changes the computer system's configuration to restrict affected functionalities, such as requiring multifactor authentication, increasing logging, or disabling vulnerable services, based on the type and severity of the vulnerability, to mitigate risks until patches can be applied.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software patches are delayed or implementation is postponed, then system stability is maintained, but security vulnerability exposure increases

Engineering Contradiction:
Improvesystem stabilityVSAvoidvulnerability exploitation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the vulnerability mitigation approach into two distinct modes: lockdown mode for maximum security and permissive mode for operational flexibility. This segmentation allows the system to apply different security postures to different operational contexts, resolving the contradiction between stability and security by offering both as separate, selectable states.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary configuration changes by establishing a lockdown mode before a vulnerability patch is officially released or tested. This preliminary action proactively mitigates vulnerability exploitation risk while the system remains in lockdown mode, allowing the organization to maintain system stability without immediately implementing untested patches.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If a lockdown mode is implemented to restrict system functionality, then security against vulnerability exploitation is improved, but system productivity and usability deteriorate

Engineering Contradiction:
Improvevulnerability exploitation riskVSAvoidsystem functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system dynamically transitions between lockdown mode and permissive mode based on operational needs and vulnerability severity. This dynamic capability allows the system to restrict functionality only when necessary for security, while maintaining full productivity when the lockdown is not required, thus resolving the contradiction between security and productivity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The lockdown mode applies selective restrictions to specific system components, services, or functions that are vulnerable to exploitation, rather than imposing blanket restrictions on the entire system. This local quality approach minimizes the impact on overall system productivity while effectively mitigating vulnerability risks in the affected areas.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If configuration changes are made to implement lockdown mode, then security posture is improved, but system complexity and operational difficulty increase

Engineering Contradiction:
Improvevulnerability exploitation riskVSAvoidconfiguration management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system automatically manages the complexity of configuration changes required for lockdown mode through self-service mechanisms. The system can autonomously transition between modes, manage configuration state, and coordinate with patch management processes, thereby reducing the operational burden on users while maintaining improved security posture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The lockdown mode mechanism serves multiple functions simultaneously: it restricts vulnerable functionality, provides a security posture indicator, coordinates with patch management, and enables dynamic transitions. This multi-functionality consolidates what would otherwise require multiple separate configuration management systems into a single unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11803647B2Computer system vulnerability lockdown mode
Publication Date: 2023.10.31 TRUIST BANK
  • US11803647B2 patent drawing
  • US11803647B2 patent drawing
  • US11803647B2 patent drawing

AI summary

Targeted lockdown of a computer system for an identified vulnerability is provided. The targeted lockdown includes configuring a vulnerability lockdown module implemented on a computer system to perform targeted actions to change a configuration of the computer system. The targeted actions may be configured based at least in part on a type of data stored on the computer system and a potential severity of an impact on the computer system if the vulnerability is exploited. The vulnerability lockdown module may implement a vulnerability lockdown mode by causing the computer system to perform the targeted actions to change the configuration of the computer system by restricting functionality of portions of the computer system affected by the identified vulnerability. The targeted actions performed by the computer system may include altering a way in which a user interacts with the computer system.