Open Software Vulnerability Prioritization via Accessibility and Code Circulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for prioritizing vulnerability information of open software do not effectively differentiate between vulnerabilities based on external accessibility and attack code circulation, leading to inadequate urgency assessment and handling.

Innovation Solution

A processing device and method that determine the priority of open software vulnerabilities by considering whether the software is externally accessible and if attack code is in circulation, assigning higher priority to externally accessible or code-in-circulation vulnerabilities, using a control unit and user interface to input and output this information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability information is prioritized based on traditional criteria only, then the prioritization process is simple, but the accuracy of urgency assessment is insufficient

Engineering Contradiction:
Improveurgency assessment accuracyVSAvoidprioritization process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The prioritization process is segmented into multiple independent assessment dimensions: external accessibility evaluation, attack code circulation status, vulnerability type classification, and severity level assessment. Each dimension is evaluated separately and then integrated to determine the final priority, improving assessment accuracy while maintaining manageable complexity through modular processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces new assessment parameters (external accessibility, attack code circulation status) alongside traditional parameters (vulnerability type, severity level). By expanding the parameter set and changing the assessment dimensions, the system achieves more accurate urgency assessment without being constrained by traditional single-criteria prioritization methods

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all vulnerabilities are treated with equal urgency, then the handling process is simple, but the effectiveness of vulnerability management is reduced

Engineering Contradiction:
Improvevulnerability management effectivenessVSAvoidhandling process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different handling approaches based on local characteristics of each vulnerability. Vulnerabilities are classified into distinct categories (externally accessible vs. internally accessible, attack code circulating vs. not circulating) and assigned differentiated priority levels and handling procedures. This localized quality approach ensures that each vulnerability receives appropriate attention based on its specific risk profile

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the operational parameters of vulnerability handling by introducing priority levels and corresponding differentiated response procedures. Instead of uniform handling, the system adjusts handling intensity, response time requirements, and resource allocation based on the assessed priority, thereby improving management effectiveness while maintaining operational clarity through structured parameters

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If priority assessment considers multiple factors including external accessibility and attack code circulation, then the prioritization accuracy is improved, but the information processing complexity increases

Engineering Contradiction:
Improvepriority assessment accuracyVSAvoidinformation processing overhead
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system extracts and evaluates only the most critical information elements: external accessibility status, attack code circulation status, vulnerability type, and severity level. By focusing on these key extracted features rather than processing all available vulnerability data, the system achieves high priority assessment accuracy while minimizing information processing overhead and avoiding unnecessary complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12013948B2Processing device and processing method
Publication Date: 2024.06.18 ASSURED INC
  • US12013948B2 patent drawing
  • US12013948B2 patent drawing
  • US12013948B2 patent drawing

AI summary

A processing device that determines a vulnerability of open software in a system, the processing device comprising: a control unit that outputs priority of the vulnerability based on at least one of first information indicating whether the open software is externally accessible, and second information indicating whether an attack code for the vulnerability of the open software is in circulation, wherein the control unit assigns higher priority to the vulnerability of the open software externally accessible compared to the vulnerability of the open software externally inaccessible, or assigns higher priority to the vulnerability where the attack code is in circulation compared to the vulnerability where the attack code is not in circulation.