Vulnerability Management System for Network Component Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing and remediating vulnerabilities in their network components due to the large number of devices and applications, leading to potential security threats and inefficiencies in monitoring and control processes.

Innovation Solution

A system and method for monitoring network components to identify vulnerabilities, implementing remediation plans, suppressing reporting for acceptable vulnerabilities, and taking consequence actions such as freezing or removing non-compliant components, while allowing remote monitoring and control to enhance security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If organizations manually monitor and manage network components for vulnerabilities, then they can identify and address security issues, but the process becomes inefficient and time-consuming due to the large number of network components

Engineering Contradiction:
Improvevulnerability management efficiencyVSAvoidtime for monitoring and control processes
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automated self-monitoring of network components where the vulnerability management system automatically detects, assesses, and remediates vulnerabilities without requiring manual intervention for each component, thereby improving efficiency and reducing time loss

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary vulnerability assessments and remediation actions automatically before vulnerabilities can be exploited, establishing a proactive security posture that reduces the time required for reactive manual intervention

Inventive Principle:
Principle #10Preliminary action

2Reliability

If organizations implement strict vulnerability remediation for all network components, then security is improved, but operational efficiency decreases due to excessive restrictions on acceptable uses

Engineering Contradiction:
Improvenetwork securityVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different remediation strictness levels to different network components based on their specific risk profiles, criticality, and vulnerability characteristics, allowing strict remediation for high-risk components while permitting acceptable uses for low-risk components

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts remediation parameters such as freeze duration, suppression thresholds, and consequence actions based on vulnerability severity, component criticality, and organizational policies, enabling flexible security management that balances security and operational efficiency

Inventive Principle:
Principle #35Parameter changes

3Speed

If organizations remotely control network components to remediate vulnerabilities, then security response capability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity response speedVSAvoidmonitoring and control system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system implements a universal remote control mechanism that can perform multiple vulnerability remediation actions (freeze, suppress, remove, update) through a single integrated platform, reducing the need for multiple specialized tools and simplifying the overall system architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system introduces an intermediary vulnerability management platform that mediates between security requirements and network component operations, simplifying the control interface while maintaining comprehensive security capabilities through automated decision-making logic

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11089042B2Vulnerability consequence triggering system for application freeze and removal
Publication Date: 2021.08.10 BANK OF AMERICA CORP
  • US11089042B2 patent drawing
  • US11089042B2 patent drawing
  • US11089042B2 patent drawing

AI summary

The invention relates generally to monitoring and managing network components, such as monitoring the network components to determine the vulnerabilities of the network components, implementing remediation plans for the vulnerabilities, instituting remediation exceptions for the vulnerabilities, and taking consequence actions for the vulnerabilities. When implementing the remediation plan, at least a portion of the network component may be frozen such that a user cannot operate at least a portion of the network component until the vulnerability is remediated. After implementing the remediation plan, monitoring of the network components and the remediation plan continues in order to identify triggers. If a trigger is identified, the consequence action may be implemented, which may prevent operation of the network components by disconnecting or blocking them from the network, uninstalling the network component, deactivating or powering down the network component.