Vulnerability Management System Automatic Scan Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current risk management software programs in computer networks are inefficient in managing and updating vulnerability scans, requiring manual updates and lacking the ability to automatically include new or updated vulnerabilities, leading to task duplication and inefficiencies in identifying and remediating vulnerabilities across diverse network environments.
Innovation Solution
A vulnerability management system that allows for the creation of customizable vulnerability sets using tree-based and rule-based methodologies, enabling automatic updates and inclusion of new vulnerabilities, reducing manual effort and duplication of tasks by permitting users to select criteria for adding new vulnerability checks and dynamically tagging assets based on their characteristics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual updates are used for vulnerability scans, then updates can be controlled individually, but the process is time-consuming and inefficient
Solution Approach 1:
The system enables automatic self-updating of vulnerability scans by detecting new vulnerabilities and automatically creating scan checks for them, eliminating the need for manual intervention in the update process
Solution Approach 2:
The system pre-configures vulnerability sets and scan templates that automatically include new vulnerabilities, so when new vulnerabilities are discovered, the scanning infrastructure is already prepared to detect them without manual reconfiguration
2Reliability
If comprehensive vulnerability checks are performed across all nodes, then all vulnerabilities are identified, but the scanning process becomes extremely complex and resource-intensive
Solution Approach 1:
The system divides the vulnerability scanning process into modular vulnerability sets and reusable scan templates, allowing comprehensive coverage to be achieved through structured organization rather than monolithic complexity
Solution Approach 2:
The system creates universal scan templates and vulnerability sets that can be applied across multiple nodes and scan types, reducing the need to configure separate checks for each vulnerability and simplifying the overall scanning infrastructure
3Measurement precision
If new vulnerabilities are added to scans manually, then scan accuracy is maintained, but task duplication occurs and efficiency decreases
Solution Approach 1:
The system implements automatic feedback loops where new vulnerability data from external sources triggers automated updates to scan configurations, ensuring scan accuracy is maintained through continuous automatic synchronization rather than manual updates
Solution Approach 2:
The system pre-configures vulnerability sets with proper groupings and relationships, so when new vulnerabilities are added, they automatically integrate into the existing scan structure without requiring manual reconfiguration or creating duplicate tasks
Data Source
AI summary
A system and method in one embodiment includes modules for creating a vulnerability set including one or more vulnerabilities, adding the vulnerability set to a program, and updating the program by adding a new vulnerability to the vulnerability set. More specific embodiments include a program that includes a scan, creating the vulnerability set by generating a query including one or more conditions associated with the vulnerabilities, and creating the vulnerability set by selecting one or more vulnerabilities from a plurality of vulnerabilities. Other embodiments include a program that includes a report template, adding a vulnerability set to the report template by generating a query to include a condition associated with the vulnerability set, running a scan, and generating a report including one or more results from the scan meeting the condition associated with the vulnerability set.


