Vulnerability Prioritization via Threat Zone Accessibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network scanning tools fail to effectively prioritize vulnerabilities on enterprise networks, often reporting too many critical vulnerabilities and prioritizing incorrectly, especially when some are inaccessible due to firewalls.
Innovation Solution
A method and system that utilize multiple device profilers in different threat zones to assess vulnerability accessibility, calculating risk based on severity, asset value, and threat level metrics, and generating reports to prioritize vulnerabilities accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network scanning tools report all detected vulnerabilities, then the administrator can identify all potential security issues, but the list becomes extremely large and difficult to prioritize effectively
Solution Approach 1:
The patent extracts and removes inaccessible vulnerabilities from the full vulnerability list by using device profilers in different threat zones to determine accessibility. Only accessible vulnerabilities are presented to the administrator, filtering out those blocked by firewalls or network security measures.
Solution Approach 2:
The patent applies different accessibility assessments to different vulnerabilities based on their location in the network. Vulnerabilities are evaluated individually based on whether they can be accessed from external threat zones, rather than applying a uniform assessment to all vulnerabilities.
2Measurement precision
If network scanning tools prioritize vulnerabilities by severity, then critical vulnerabilities can be identified, but the prioritization is incorrect when vulnerabilities are inaccessible due to firewalls
Solution Approach 1:
The patent performs preliminary accessibility assessment using device profilers before final prioritization. The system proactively determines which vulnerabilities are accessible from external threat zones before presenting the prioritized list to the administrator, preventing incorrect prioritization of inaccessible vulnerabilities.
Solution Approach 2:
The patent introduces device profilers as intermediary components that assess accessibility between the vulnerability detection system and the prioritization process. These profilers act as mediators to determine whether vulnerabilities can actually be exploited from external threat zones.
3Measurement precision
If multiple device profilers are deployed in different threat zones to assess accessibility, then accurate prioritization is achieved, but the system complexity increases
Solution Approach 1:
The patent segments the vulnerability assessment process by deploying device profilers in different threat zones (internal and external). Each profiler assesses vulnerabilities from its specific zone's perspective, providing comprehensive accessibility information without requiring a single complex profiler.
Solution Approach 2:
The device profilers are designed to perform multiple functions: vulnerability detection, accessibility assessment, and prioritization. This multi-functionality reduces the need for separate specialized tools and simplifies the overall system architecture.
Data Source
AI summary
An enterprise network includes hosts running services. Some of the services have security vulnerabilities. There are one or more threat zones associated with the network. For example, a firewall may create two threat zones, one internal to the firewall and one external to it. A device profiler in the first threat zone profiles the hosts on the network and identifies the vulnerabilities that are present. A device profiler in the second threat zone determines which of the identified vulnerabilities are accessible from its zone. A risk module calculates the risk associated with a vulnerability based on the vulnerability's severity, threat level metrics for the threat zones, and an asset value of the host with the vulnerability. A reporting module prioritizes the vulnerabilities based on their risks.


