Vulnerability Management System for CVE Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack the ability to effectively identify and prioritize vulnerabilities specific to an organization from the Common Vulnerability Exposures (CVE) list, as they do not provide a platform for reviewing the impact of listed vulnerabilities on individual organizations.

Innovation Solution

A vulnerability disclosures management device with a module that establishes a link between an external database and a local database, filters and prioritizes vulnerability data based on risk scores, and allows user input to modify risk scores, enabling the tracking and remediation of significant threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If organizations use the Common Vulnerability Exposures (CVE) list to identify vulnerabilities, then they can access a comprehensive list of vulnerabilities, but they cannot effectively prioritize or filter vulnerabilities relevant to their specific organization

Engineering Contradiction:
Improvenumber of vulnerabilitiesVSAvoidease of prioritization
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The system extracts and filters vulnerability data from the comprehensive CVE list to identify only those vulnerabilities relevant to the organization's specific technology stack and systems. This extraction process separates useful vulnerability information from irrelevant data, enabling prioritization based on organizational context.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies local quality by customizing vulnerability assessment based on the organization's specific environment, including their software applications, hardware infrastructure, and risk tolerance levels. This allows the same CVE list to be differentiated and prioritized according to each organization's unique characteristics.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If organizations manually review all vulnerabilities from the CVE list, then they can assess each vulnerability's impact, but it consumes significant time and resources

Engineering Contradiction:
Improveaccuracy of vulnerability assessmentVSAvoidtime for vulnerability review
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically filtering, scoring, and prioritizing vulnerabilities before they reach the analyst's desk. Vulnerabilities are pre-assessed based on their potential impact on the organization's specific systems, so that when analysts review them, only the most critical items require manual examination.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability management system performs self-service by automatically collecting vulnerability data, comparing it against the organization's asset inventory, calculating risk scores, and generating prioritized lists. This automation handles the bulk of the work, freeing analysts to focus only on complex cases requiring human judgment.

Inventive Principle:
Principle #25Self-service

3Reliability

If organizations receive continuous vulnerability data feeds from external databases, then they stay updated with the latest threats, but they must manage and process large volumes of data

Engineering Contradiction:
Improvecurrentness of vulnerability informationVSAvoidcomplexity of data management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously extracts only the vulnerability data relevant to the organization from external databases like NVD. By filtering based on the organization's technology stack and asset inventory, it extracts only the necessary information while discarding irrelevant data, simplifying the management burden.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements feedback mechanisms where vulnerability data is continuously collected, processed, and the results are fed back into the organization's risk management processes. This continuous feedback loop ensures the organization stays updated with the latest threats while the automated processing handles the data volume management.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If organizations customize risk scores based on their specific organizational context, then they can prioritize vulnerabilities more effectively, but it requires user input and modification processes

Engineering Contradiction:
Improveadaptability to organizational contextVSAvoidcomplexity of risk score modification
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The risk scoring system is dynamic, allowing it to adapt to different organizational contexts through configurable parameters and weights. The system can be adjusted based on organizational priorities, asset criticality, and risk tolerance levels, making it versatile across different organizations while maintaining a consistent user interface and process.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11720687B2Method and apparatus for management of vulnerability disclosures
Publication Date: 2023.08.08 JPMORGAN CHASE BANK NA
  • US11720687B2 patent drawing
  • US11720687B2 patent drawing
  • US11720687B2 patent drawing

AI summary

Various methods, apparatuses/systems, and media for managing vulnerability data are provided. A processor allows ingestion of vulnerability data from an external database into a local database which then makes the vulnerability data available for review via a graphical user interface (GUI). The processor also compares a risk score associated with each vulnerability included in the vulnerability data to a predefined threshold value; modifies, based on a determination that the risk score exceeds the predefined threshold value, the risk score by receiving user input via the GUI in accordance with risk information applicable to systems managed and operated by an organization; and updates a list of vulnerabilities of the vulnerability data stored in the local database by supplementing with the modified risk score without overwriting the risk score associated with each vulnerability initially received from the external database.