Probabilistic Vulnerability Prediction for Network Asset Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large interconnected networks face challenges in predicting the vulnerability of all computer systems due to the lack of current vulnerability data, leading to overburdened security administrators and inability to prioritize threat data effectively, as periodic vulnerability testing is costly and time-consuming, resulting in incomplete and outdated vulnerability assessments.

Innovation Solution

A probabilistic system that predicts the vulnerability of similar assets using asset criticality, vulnerability severity, and platform information to create a timeline-based patching profile, calculating probabilities based on data from vulnerability reports, even when asset information is partially or completely unknown, allowing for prioritization of threat responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If periodic vulnerability testing is conducted for all systems, then vulnerability data completeness is improved, but network overload and cost increase

Engineering Contradiction:
Improvevulnerability data completenessVSAvoidnetwork overload
Core Design Contradiction:
Loss of informationVSLoss of energy

Solution Approach 1:

Instead of testing all systems periodically, the patent applies partial action by selecting a representative sample of systems for vulnerability assessment. The probabilistic model then extrapolates vulnerability status to untested systems based on the sampled data, achieving comprehensive coverage without the full cost and network overload of universal testing.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent creates a virtual copy of vulnerability status information through probabilistic prediction. Rather than directly testing every system, the system models vulnerability probabilities based on sampled data and asset characteristics, generating predictive vulnerability status information that represents the entire network without actual testing of all systems.

Inventive Principle:
Principle #26Copying

2Measurement precision

If vulnerability testing is performed continuously for all systems, then current vulnerability status accuracy is improved, but time and cost consumption increase

Engineering Contradiction:
Improvecurrent vulnerability status accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary vulnerability assessment on a representative sample of systems and uses this preliminary data to predict vulnerability status for all systems. This preliminary action on sampled systems enables continuous or near-continuous knowledge of network vulnerability state without requiring continuous testing of every system, thus reducing time consumption while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses its own predictive model to generate vulnerability status information without requiring external continuous testing. The probabilistic model serves itself by using sampled data and asset characteristics to automatically predict vulnerability states, eliminating the need for time-consuming continuous manual or automated testing of all systems.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If vulnerability data is collected for all systems, then threat correlation capability is improved, but system complexity and overhead increase

Engineering Contradiction:
Improvethreat correlation capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by collecting and analyzing vulnerability data only for specific representative systems rather than all systems uniformly. The probabilistic model then generalizes this local data to predict vulnerability status across the entire network, maintaining threat correlation capability while reducing the volume of data collection and system complexity.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If security administrators manually analyze all threat data, then threat response accuracy is improved, but administrator workload increases

Engineering Contradiction:
Improvethreat response accuracyVSAvoidadministrator workload
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements feedback by automatically generating prioritized threat responses based on predicted vulnerability probabilities. The system continuously refines its predictions by analyzing threat data and updating vulnerability probability assessments, creating a feedback loop that improves accuracy while reducing manual analysis workload. Security administrators receive pre-sorted threat information that requires less manual processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10270799B2Methods and systems for predicting vulnerability state of computer system
Publication Date: 2019.04.23 BULL SA
  • US10270799B2 patent drawing
  • US10270799B2 patent drawing
  • US10270799B2 patent drawing

AI summary

A system uses a probabilistic technique to determine the vulnerability of similar assets based on the data provided on some assets. The probabilistic technique includes stages of preparing data followed by calculating probability; a preparing data stage, including gathering the latest vulnerability reports of all assets in a system with the help of known scanners; creating open vulnerabilities; enriching the obtained data of open vulnerabilities; creating all vulnerabilities; enriching the obtained data of all vulnerabilities. Following this stage, probability calculation may be done for three cases, when asset information is known, when asset information is partially unknown, and when asset information is completely unknown based on the data taken from open vulnerabilities and all vulnerabilities categorized into blocks of 6 months based on the time at which they have been reported to NIST/MITRE.