Vulnerability Prioritization Server Using Domain and User Knowledge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current tools for identifying and prioritizing vulnerabilities in software code with external components are inefficient and require extensive training, lacking user-specific preferences and domain-specific knowledge integration.

Innovation Solution

A method and server configuration that utilize domain-specific knowledge (DSK) and user-specific knowledge (USK) databases to determine utility estimations for vulnerabilities, providing a prioritized list that accounts for user preferences and non-user defined features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If external software components are included to reduce development time and error risk, then productivity and reliability are improved, but the complexity of vulnerability management increases and control over vulnerabilities decreases

Engineering Contradiction:
Improvesoftware development efficiencyVSAvoidvulnerability management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between the user and the vulnerability data. This system automatically collects, stores, and processes vulnerability information from multiple sources, comparing it against the user's software code and preferences. The intermediary handles the complexity of vulnerability management by filtering and prioritizing vulnerabilities based on user-specific criteria, thus resolving the contradiction between improved productivity and increased management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically gathering vulnerability data, analyzing it against the user's codebase, and generating prioritized vulnerability reports without requiring manual intervention. The system serves itself by maintaining databases of vulnerability information and automatically updating and comparing this data, reducing the burden on users while maintaining high productivity and managing complexity internally.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive vulnerability assessment systems are implemented to identify all vulnerabilities, then measurement precision is improved, but the time required for assessment increases

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidvulnerability assessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies parameter changes by dynamically adjusting the assessment criteria and data collection parameters based on user preferences and specific needs. The system changes parameters such as vulnerability severity thresholds, data sources to monitor, and comparison criteria to optimize the balance between comprehensive identification and time efficiency. This allows the system to maintain high measurement precision while adapting the assessment process to minimize time loss.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements partial action by focusing assessment efforts on the most critical vulnerabilities and areas of highest risk, rather than attempting to assess every possible vulnerability with equal depth. By using user preferences and historical data to identify priority areas, the system achieves sufficient measurement precision for decision-making without the time cost of exhaustive assessment of all potential vulnerabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If user-specific preferences are integrated into vulnerability prioritization, then adaptability is improved, but the complexity of the system increases

Engineering Contradiction:
Improveuser preference integrationVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the system into distinct functional modules: a data collection module, a user preference management module, a vulnerability analysis module, and a reporting module. Each module handles specific tasks independently, allowing user preferences to be integrated without overwhelming the entire system. This modular architecture maintains adaptability while managing complexity through clear separation of concerns and defined interfaces between components.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If domain-specific knowledge databases are used to improve vulnerability assessment, then measurement precision is improved, but the initial setup time and resource requirements increase

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidinitial setup time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-collecting and organizing vulnerability data, domain-specific knowledge, and assessment criteria into databases before actual vulnerability assessment begins. The system performs preliminary setup by establishing data collection mechanisms, configuring initial parameters, and preparing reference databases in advance. This preliminary preparation reduces the time required during actual assessment operations while maintaining high measurement precision through pre-validated data and criteria.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250117494A1Method for prioritizing among vulnerabilities in a software code and a server
Publication Date: 2025.04.10 DEBRICKED AB
  • US20250117494A1 patent drawing
  • US20250117494A1 patent drawing
  • US20250117494A1 patent drawing

AI summary

A method for prioritizing among vulnerabilities in a software code for a user by using a server is presented. The method comprises receiving a request, a software identification associated to the software code, and a user identification associated to the user from a user computer, fetching domain specific knowledge (DSK) data from a DSK database by using the software identification, wherein the DSK database comprises non-user defined features related to the vulnerabilities, fetching user specific knowledge (USK) data from a USK database by using the user identification, wherein the USK database comprises user defined features related to the vulnerabilities, determining utility estimations for the vulnerabilities, respectively, by comparing the vulnerabilities with the DSK data and comparing the vulnerabilities with the USK data, and transferring the utility estimations from the server to the user computer such that a prioritized list of vulnerabilities can be achieved.