Mapping Remediations to Vulnerabilities via Machine-Actionable Structures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability remediation methods rely on human intervention and do not effectively address the nuances of implementing remediations across different technologies, as the suggested remediations are typically presented in prose and not in a machine-actionable format, failing to account for variations in technologies such as UNIX vs. Motorola architecture or Windows 32-bit vs. 64-bit systems.
Innovation Solution
A system and method that maps remediations to vulnerabilities by assessing susceptibility, implementing remediations, and creating a machine-actionable map between remediations and vulnerabilities, using a server with databases for assets and remediations, and lightweight sensors to automatically implement remediations in a technology-specific manner, facilitating the translation of remediation information into a machine-actionable format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remediation information is presented in prose format, then it is easy to understand for humans, but it is not machine-actionable and requires human intervention
Solution Approach 1:
The patent introduces an intermediary system that translates between human-readable prose format and machine-actionable structured data. This intermediary automatically parses vulnerability descriptions, extracts remediation steps, and converts them into structured formats that machines can execute, thereby bridging the gap between human understanding and machine automation without requiring manual re-entry of information.
Solution Approach 2:
The system enables self-service by allowing remediation information to be automatically processed and executed without human intervention. The structured data format includes machine-executable instructions that can be automatically applied to systems, and the system can autonomously determine when and how to apply remediations based on vulnerability assessments, freeing operators from manual remediation tasks.
2Device complexity
If a single remediation is applied to address one vulnerability, then the remediation process is simple, but it does not account for multiple vulnerabilities that may be addressed by the same remediation
Solution Approach 1:
The patent implements a many-to-many mapping system where a single remediation can be associated with multiple vulnerabilities, and a single vulnerability can have multiple remediations. The structured data format includes relationships that allow one remediation object to reference multiple vulnerability objects, enabling operators to apply a single remediation action to address multiple vulnerabilities simultaneously, thereby increasing remediation efficiency without significantly increasing process complexity.
3Ease of manufacture
If remediation information is standardized across all technologies, then it is easier to manage, but it fails to account for technology-specific nuances such as UNIX vs. Motorola architecture or Windows 32-bit vs. 64-bit systems
Solution Approach 1:
The patent implements a hierarchical data structure where global standardized elements coexist with local technology-specific elements. The structured format includes fields for technology-specific parameters, architecture-type indicators, and version information that allow remediation instructions to be customized for specific platforms (UNIX, Motorola, Windows 32-bit, 64-bit) while maintaining a consistent overall framework. This enables the system to manage information standardly at the structural level while preserving necessary local variations for different technologies.
Data Source
AI summary
A method of mapping a remediation to a plurality of vulnerabilities may include: assessing susceptibility of an non-remediated machine to a first vulnerability, which results in a first set of two or more vulnerabilities to which the machine is susceptible; implementing the remediation upon the machine; assessing susceptibility of the remediated machine to the first vulnerability, which results in a second set of vulnerabilities to which the machine is susceptible; and creating a machine-actionable map between the remediation and two or more members of the first set based upon differences between the first and second sets.


