Vulnerability Prioritization via Threat Zone Accessibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network scanning tools fail to effectively prioritize vulnerabilities on enterprise networks, often reporting too many critical vulnerabilities and prioritizing incorrectly, especially when some are inaccessible due to firewalls.

Innovation Solution

A method and system that utilize multiple device profilers in different threat zones to assess vulnerability accessibility, calculating risk based on severity, asset value, and threat level metrics, and generating reports to prioritize vulnerabilities accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network scanning tools report all detected vulnerabilities, then the administrator can identify all potential security issues, but the list becomes extremely large and difficult to prioritize effectively

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidadministrator workload
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent extracts and removes inaccessible vulnerabilities from the full vulnerability list by using device profilers in different threat zones to determine accessibility. Only accessible vulnerabilities are presented to the administrator, filtering out those blocked by firewalls or network security measures.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different accessibility assessments to different vulnerabilities based on their location in the network. Vulnerabilities are evaluated individually based on whether they can be accessed from external threat zones, rather than applying a uniform assessment to all vulnerabilities.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If network scanning tools prioritize vulnerabilities by severity, then critical vulnerabilities can be identified, but the prioritization is incorrect when vulnerabilities are inaccessible due to firewalls

Engineering Contradiction:
Improvevulnerability prioritization accuracyVSAvoidprioritization reliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent performs preliminary accessibility assessment using device profilers before final prioritization. The system proactively determines which vulnerabilities are accessible from external threat zones before presenting the prioritized list to the administrator, preventing incorrect prioritization of inaccessible vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces device profilers as intermediary components that assess accessibility between the vulnerability detection system and the prioritization process. These profilers act as mediators to determine whether vulnerabilities can actually be exploited from external threat zones.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple device profilers are deployed in different threat zones to assess accessibility, then accurate prioritization is achieved, but the system complexity increases

Engineering Contradiction:
Improveaccessibility assessment accuracyVSAvoidprofiler deployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability assessment process by deploying device profilers in different threat zones (internal and external). Each profiler assesses vulnerabilities from its specific zone's perspective, providing comprehensive accessibility information without requiring a single complex profiler.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device profilers are designed to perform multiple functions: vulnerability detection, accessibility assessment, and prioritization. This multi-functionality reduces the need for separate specialized tools and simplifies the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8918883B1Prioritizing network security vulnerabilities using accessibility
Publication Date: 2014.12.23 TRIPWIRE INC
  • US8918883B1 patent drawing
  • US8918883B1 patent drawing
  • US8918883B1 patent drawing

AI summary

An enterprise network includes hosts running services. Some of the services have security vulnerabilities. There are one or more threat zones associated with the network. For example, a firewall may create two threat zones, one internal to the firewall and one external to it. A device profiler in the first threat zone profiles the hosts on the network and identifies the vulnerabilities that are present. A device profiler in the second threat zone determines which of the identified vulnerabilities are accessible from its zone. A risk module calculates the risk associated with a vulnerability based on the vulnerability's severity, threat level metrics for the threat zones, and an asset value of the host with the vulnerability. A reporting module prioritizes the vulnerabilities based on their risks.