Vulnerability Management System for Terminal Risk Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for addressing vulnerabilities across multiple terminals are inefficient, as they require individualized countermeasures and lack clarity on remaining risks and applicable countermeasures, leading to high operational costs and ambiguity in decision-making.

Innovation Solution

An information processing apparatus and method that receives countermeasure inputs, identifies applicable countermeasures for each terminal, and provides the number of terminals still vulnerable after applying selected countermeasures, enabling visualization of applicable countermeasures and remaining risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individualized countermeasures are planned for each terminal, then vulnerability coverage is improved, but operational cost increases significantly

Engineering Contradiction:
Improvevulnerability coverageVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments terminals into groups based on their vulnerability profiles and divides countermeasures into categories (patch application, configuration changes, awareness). This segmentation allows the system to apply standardized countermeasures to terminal groups rather than customizing each terminal individually, reducing operational complexity while maintaining comprehensive vulnerability coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal countermeasure planning framework that can be applied across multiple terminal types and vulnerability scenarios. By establishing a general decision-support system that handles various vulnerability types through standardized processes, the system achieves multi-functionality without requiring separate specialized plans for each terminal.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple applicable countermeasures are considered, then solution flexibility is improved, but decision-making clarity deteriorates

Engineering Contradiction:
Improvesolution flexibilityVSAvoiddecision-making clarity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system incorporates feedback mechanisms that continuously monitor terminal vulnerability states and countermeasure effectiveness. By providing real-time feedback on remaining vulnerabilities and countermeasure impacts, the system enables managers to make clearer decisions about which countermeasures to prioritize, reducing decision-making ambiguity while maintaining solution flexibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The countermeasure planning system is designed to be dynamic, allowing managers to adjust and reprioritize countermeasures based on changing vulnerability landscapes and operational constraints. This dynamic approach maintains flexibility in solution selection while providing clear guidance through continuous updates on risk reduction effectiveness.

Inventive Principle:
Principle #15Dynamics

3Reliability

If comprehensive countermeasure planning is implemented, then vulnerability management thoroughness is improved, but time consumption increases

Engineering Contradiction:
Improvevulnerability management thoroughnessVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-classifying terminals into vulnerability groups and pre-preparing countermeasure templates based on common vulnerability patterns. This preliminary classification and preparation work reduces the time needed for actual countermeasure planning and execution, as the system can quickly match pre-defined countermeasures to terminal groups rather than analyzing each terminal from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial countermeasures to terminal groups that achieve sufficient risk reduction without requiring exhaustive treatment of every possible vulnerability scenario. By focusing on the most impactful countermeasures for each terminal group rather than attempting complete coverage, the system achieves thorough vulnerability management with reduced time consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10922417B2Information processing apparatus, information processing method, and program
Publication Date: 2021.02.16 NEC CORP
  • US10922417B2 patent drawing
  • US10922417B2 patent drawing
  • US10922417B2 patent drawing

AI summary

An information processing apparatus (10) includes a selection reception unit (110) that receives an input indicating that at least one countermeasure is selected from among a plurality of countermeasures against vulnerability, a remaining terminal identification unit (120) that reads out terminal-specific countermeasure information, indicating a countermeasure applicable for each terminal against the vulnerability, from a storage unit that stores the terminal-specific countermeasure information, and identifies a remaining terminal which is a terminal that would be left with the vulnerability on the basis of the read-out terminal-specific countermeasure information, and a remaining terminal information providing unit (130) that provides the number of identified remaining terminals.