Vulnerability Management System Resource Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to efficiently manage vulnerabilities in data processing systems, especially those with limited computing resources, as active scanning processes can consume valuable resources and hinder primary functionalities.
Innovation Solution
The system employs a method that determines the availability of computing resources for infrastructure, deciding between an infrastructure-based component analysis (which consumes resources) or a historic component analysis (which does not consume resources) to identify vulnerabilities and perform remediations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active scanning processes are used to identify vulnerabilities, then vulnerability detection capability is improved, but computing resource consumption increases
Solution Approach 1:
The system dynamically adjusts the vulnerability scanning approach based on real-time assessment of computing resource availability. When resources are abundant, active scanning is performed for comprehensive vulnerability detection. When resources are limited, the system switches to passive monitoring or historical data analysis, thereby adapting the detection methodology to current system conditions and resolving the contradiction between detection capability and resource consumption.
Solution Approach 2:
Instead of performing complete active scanning on all systems continuously, the system applies partial scanning actions selectively based on risk assessment and resource availability. High-priority systems receive more thorough scanning while lower-priority systems undergo lighter inspection, allowing the organization to maintain adequate vulnerability detection across the infrastructure without exhausting computing resources.
2Measurement precision
If infrastructure-based component analysis is performed, then accurate vulnerability identification is achieved, but primary functionalities are hindered
Solution Approach 1:
The system implements periodic vulnerability analysis instead of continuous scanning. Infrastructure-based component analysis is performed at scheduled intervals when system load is lower, rather than continuously. This periodic approach allows comprehensive vulnerability identification to occur without constantly interfering with primary functionalities, as the scanning activities are concentrated in specific time windows rather than being ongoing.
Solution Approach 2:
The system performs preliminary assessments to determine the appropriate depth and scope of component analysis before executing full vulnerability scans. By conducting preliminary evaluations of system state, resource availability, and criticality, the system can adjust the intensity of the subsequent analysis, performing comprehensive scans only when conditions permit, thereby preserving primary functionalities while maintaining vulnerability identification accuracy.
Data Source
AI summary
Methods and systems for managing vulnerabilities presented by data processing systems are disclosed. The vulnerabilities may be managed by identifying components of the data processing systems using different processes depending on the computing resource availabilities of the data processing systems. Once identified, corresponding vulnerabilities for the components may be identified. The identified vulnerabilities may then be managed by performing various actions.


