Multidimensional Vulnerability Prioritization for Software Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for updating or patching software applications lack the granularity to accurately identify the impact of software code updates on each application within a computing environment, necessitating a more detailed and accurate approach to application tiering and prioritization.

Innovation Solution

A system that analyzes computer application vulnerabilities through multidimensional correlation and prioritization by generating a data repository, calculating vulnerability and interdependency scores, and generating a prioritization scheme for updating applications, using a graph database and neural networks to continuously monitor and refine the update process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional methods are used for updating software applications, then the update process is simple and quick, but the granularity and accuracy of identifying impact on each application is insufficient

Engineering Contradiction:
Improveaccuracy of identifying impactVSAvoidcomplexity of update process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the application update process by creating a data repository that stores individual application data and metadata separately. Each application is assessed independently across multiple dimensions (users, devices, networks, applications, data), allowing granular identification of impact without requiring a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multidimensional assessment by evaluating application dependencies and vulnerabilities across five distinct dimensions: impacts on users, devices, networks, applications, and data. This dimensional approach enables precise impact identification without proportionally increasing system complexity, as the same infrastructure supports multiple assessment perspectives.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of time

If application updates are performed without prioritization, then the update process is straightforward, but downtime and workflow disruption increase

Engineering Contradiction:
ImprovedowntimeVSAvoidcomplexity of prioritization system
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of application vulnerabilities and interdependencies before updates are executed. By pre-calculating priority scores based on vulnerability severity and dependency relationships across multiple dimensions, the system determines the optimal update sequence in advance, minimizing downtime and workflow disruption during actual update execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors and learns from update outcomes to refine prioritization schemes over time. Historical data from previous updates is fed back into the assessment model, allowing the system to improve its prioritization accuracy and reduce downtime with each iteration without requiring proportional increases in system complexity.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive vulnerability assessment across multiple dimensions is performed, then the accuracy of prioritization improves, but the computational resources and time required increase

Engineering Contradiction:
Improveaccuracy of vulnerability assessmentVSAvoidefficiency of update process
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The comprehensive assessment is segmented into five independent but coordinated dimensions: users, devices, networks, applications, and data. Each dimension can be assessed separately and then integrated, allowing the system to maintain high accuracy while managing computational resources efficiently through modular processing rather than monolithic analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts assessment parameters and weighting factors based on the specific context and historical performance data. By changing parameters such as vulnerability severity weights and dependency thresholds, the system optimizes the balance between assessment accuracy and computational efficiency for different update scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11163889B2System and method for analyzing and remediating computer application vulnerabilities via multidimensional correlation and prioritization
Publication Date: 2021.11.02 BANK OF AMERICA CORP
  • US11163889B2 patent drawing
  • US11163889B2 patent drawing

AI summary

A system provides analysis of computer application vulnerabilities via multidimensional correlation and prioritization. The system may begin by generating a data repository of each application within a computing environment. Once the data repository is generated, the system may assess the dependencies, relationships, and vulnerabilities of the applications and processes used within the system. The system may perform assessments across multiple dimensions and/or metrics (e.g., impacts on users, devices, networks, applications, and/or data). Based on performing said assessments, the system may calculate relatedness and/or dependency scores across the dimensions or metrics, where the scores may be used to generate a prioritization scheme for making changes to application code or applying updates.