Vulnerability Management System Automatic Scan Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk management software programs in computer networks are inefficient in managing and updating vulnerability scans, requiring manual updates and lacking the ability to automatically include new or updated vulnerabilities, leading to task duplication and inefficiencies in identifying and remediating vulnerabilities across diverse network environments.

Innovation Solution

A vulnerability management system that allows for the creation of customizable vulnerability sets using tree-based and rule-based methodologies, enabling automatic updates and inclusion of new vulnerabilities, reducing manual effort and duplication of tasks by permitting users to select criteria for adding new vulnerability checks and dynamically tagging assets based on their characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual updates are used for vulnerability scans, then updates can be controlled individually, but the process is time-consuming and inefficient

Engineering Contradiction:
Improvevulnerability scan update efficiencyVSAvoidtime for manual vulnerability updates
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automatic self-updating of vulnerability scans by detecting new vulnerabilities and automatically creating scan checks for them, eliminating the need for manual intervention in the update process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures vulnerability sets and scan templates that automatically include new vulnerabilities, so when new vulnerabilities are discovered, the scanning infrastructure is already prepared to detect them without manual reconfiguration

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive vulnerability checks are performed across all nodes, then all vulnerabilities are identified, but the scanning process becomes extremely complex and resource-intensive

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidscan configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the vulnerability scanning process into modular vulnerability sets and reusable scan templates, allowing comprehensive coverage to be achieved through structured organization rather than monolithic complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates universal scan templates and vulnerability sets that can be applied across multiple nodes and scan types, reducing the need to configure separate checks for each vulnerability and simplifying the overall scanning infrastructure

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If new vulnerabilities are added to scans manually, then scan accuracy is maintained, but task duplication occurs and efficiency decreases

Engineering Contradiction:
Improvevulnerability scan accuracyVSAvoidscan update throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements automatic feedback loops where new vulnerability data from external sources triggers automated updates to scan configurations, ensuring scan accuracy is maintained through continuous automatic synchronization rather than manual updates

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system pre-configures vulnerability sets with proper groupings and relationships, so when new vulnerabilities are added, they automatically integrate into the existing scan structure without requiring manual reconfiguration or creating duplicate tasks

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9811667B2System and method for grouping computer vulnerabilities
Publication Date: 2017.11.07 MCAFEE LLC
  • US9811667B2 patent drawing
  • US9811667B2 patent drawing
  • US9811667B2 patent drawing

AI summary

A system and method in one embodiment includes modules for creating a vulnerability set including one or more vulnerabilities, adding the vulnerability set to a program, and updating the program by adding a new vulnerability to the vulnerability set. More specific embodiments include a program that includes a scan, creating the vulnerability set by generating a query including one or more conditions associated with the vulnerabilities, and creating the vulnerability set by selecting one or more vulnerabilities from a plurality of vulnerabilities. Other embodiments include a program that includes a report template, adding a vulnerability set to the report template by generating a query to include a condition associated with the vulnerability set, running a scan, and generating a report including one or more results from the scan meeting the condition associated with the vulnerability set.