Vulnerability Management System for Intrusion Protection Filter Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems, such as intrusion detection and protection systems, face inefficiencies due to the need for intensive manual tuning and lack of integration with vulnerability landscapes, leading to inadequate protection in complex and dynamic network environments, and fail to demonstrate compliance with regulatory requirements.

Innovation Solution

A vulnerability management system that analyzes network vulnerabilities and maps them to appropriate filters or signatures within intrusion protection systems, enabling real-time control and optimization of security measures across distributed ecosystems, thereby enhancing protection and compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual tuning of intrusion protection system filters is performed based on vendor recommendations, then the system can be configured with basic protection, but the protection effectiveness is inadequate and does not align with actual enterprise vulnerabilities

Engineering Contradiction:
Improveprotection effectivenessVSAvoidmanual tuning complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically discovers enterprise vulnerabilities through scanning and autonomously configures IPS filters based on the discovered vulnerabilities, eliminating the need for manual security expertise. The vulnerability management system performs self-service by identifying gaps between current IPS coverage and actual vulnerability landscape, then automatically remediates by adding appropriate filters.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors the enterprise vulnerability landscape and provides feedback to the IPS configuration. Vulnerability scans feed into the system, which then adjusts filter settings based on actual vulnerabilities present, creating a closed-loop feedback mechanism that continuously optimizes protection effectiveness.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive vulnerability scanning and filter mapping is implemented across the entire network, then protection coverage is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improveprotection coverageVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability management system performs multiple functions: it scans for vulnerabilities, maps them to IPS filters, manages filter configurations, and provides reporting all through a single integrated platform. This multi-functional approach reduces overall system complexity compared to separate tools for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system acts as an intermediary layer between the vulnerability landscape and the IPS infrastructure. It translates vulnerability data into IPS filter configurations and manages the integration complexity, shielding network administrators from the complexity of direct system-to-system integration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If real-time vulnerability monitoring and automated filter application is implemented, then response time to new threats is reduced, but computational resources and processing power increase

Engineering Contradiction:
Improvethreat response timeVSAvoidcomputational resource consumption
Core Design Contradiction:
SpeedVSUse of energy by moving object

Solution Approach 1:

The system pre-generates a comprehensive mapping of vulnerabilities to IPS filters and maintains this mapping for quick reference. When new vulnerabilities are discovered, the system can rapidly apply appropriate filters by referencing the pre-established mapping, avoiding the need for complex real-time analysis and reducing computational overhead during threat response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8881272B2System and method for selecting and applying filters for intrusion protection system within a vulnerability management system
Publication Date: 2014.11.04 ALERT LOGIC LLC
  • US8881272B2 patent drawing
  • US8881272B2 patent drawing
  • US8881272B2 patent drawing

AI summary

A system for controlling selection of filters for protecting against vulnerabilities of a computer network includes a vulnerability management system analyzes the computer network and determines network vulnerabilities for the computer network. The vulnerability management system is configured to receive real-time data on a status of filters protecting against vulnerabilities of the computer network. A database contains a pre-generated mapping of network vulnerabilities to filters for protecting against the network vulnerabilities. The vulnerability management system enables user control of filters for protecting against vulnerabilities of the computer network based upon the determined network vulnerabilities of the computer network, the pre-generated mapping of network vulnerabilities to the filters for protecting against the network vulnerabilities and the real-time data on the status of the filters.