Probabilistic Vulnerability Prediction for Network Asset Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large interconnected networks face challenges in predicting the vulnerability of all computer systems due to the lack of current vulnerability data, leading to overburdened security administrators and inability to prioritize threat data effectively, as periodic vulnerability testing is costly and time-consuming, resulting in incomplete and outdated vulnerability assessments.
Innovation Solution
A probabilistic system that predicts the vulnerability of similar assets using asset criticality, vulnerability severity, and platform information to create a timeline-based patching profile, calculating probabilities based on data from vulnerability reports, even when asset information is partially or completely unknown, allowing for prioritization of threat responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If periodic vulnerability testing is conducted for all systems, then vulnerability data completeness is improved, but network overload and cost increase
Solution Approach 1:
Instead of testing all systems periodically, the patent applies partial action by selecting a representative sample of systems for vulnerability assessment. The probabilistic model then extrapolates vulnerability status to untested systems based on the sampled data, achieving comprehensive coverage without the full cost and network overload of universal testing.
Solution Approach 2:
The patent creates a virtual copy of vulnerability status information through probabilistic prediction. Rather than directly testing every system, the system models vulnerability probabilities based on sampled data and asset characteristics, generating predictive vulnerability status information that represents the entire network without actual testing of all systems.
2Measurement precision
If vulnerability testing is performed continuously for all systems, then current vulnerability status accuracy is improved, but time and cost consumption increase
Solution Approach 1:
The patent performs preliminary vulnerability assessment on a representative sample of systems and uses this preliminary data to predict vulnerability status for all systems. This preliminary action on sampled systems enables continuous or near-continuous knowledge of network vulnerability state without requiring continuous testing of every system, thus reducing time consumption while maintaining accuracy.
Solution Approach 2:
The system uses its own predictive model to generate vulnerability status information without requiring external continuous testing. The probabilistic model serves itself by using sampled data and asset characteristics to automatically predict vulnerability states, eliminating the need for time-consuming continuous manual or automated testing of all systems.
3Adaptability or versatility
If vulnerability data is collected for all systems, then threat correlation capability is improved, but system complexity and overhead increase
Solution Approach 1:
The patent applies local quality by collecting and analyzing vulnerability data only for specific representative systems rather than all systems uniformly. The probabilistic model then generalizes this local data to predict vulnerability status across the entire network, maintaining threat correlation capability while reducing the volume of data collection and system complexity.
4Measurement precision
If security administrators manually analyze all threat data, then threat response accuracy is improved, but administrator workload increases
Solution Approach 1:
The patent implements feedback by automatically generating prioritized threat responses based on predicted vulnerability probabilities. The system continuously refines its predictions by analyzing threat data and updating vulnerability probability assessments, creating a feedback loop that improves accuracy while reducing manual analysis workload. Security administrators receive pre-sorted threat information that requires less manual processing.
Data Source
AI summary
A system uses a probabilistic technique to determine the vulnerability of similar assets based on the data provided on some assets. The probabilistic technique includes stages of preparing data followed by calculating probability; a preparing data stage, including gathering the latest vulnerability reports of all assets in a system with the help of known scanners; creating open vulnerabilities; enriching the obtained data of open vulnerabilities; creating all vulnerabilities; enriching the obtained data of all vulnerabilities. Following this stage, probability calculation may be done for three cases, when asset information is known, when asset information is partially unknown, and when asset information is completely unknown based on the data taken from open vulnerabilities and all vulnerabilities categorized into blocks of 6 months based on the time at which they have been reported to NIST/MITRE.


