Vulnerability Remediation Prioritization via Breach Data Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in efficiently prioritizing and addressing IT security risks due to the large amount of data generated from various security vulnerability assessment tools and third-party auditors, which often lacks necessary information on the likelihood of successful attacks, leading to inadequate defense strategies.
Innovation Solution
A vulnerability threat management platform that correlates vulnerability data with breach data from multiple sources, providing a risk score and ordered list of remediations to help prioritize and address the most critical vulnerabilities effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security vulnerability assessment tools and third-party auditors are used to assess IT assets, then the comprehensiveness of vulnerability detection is improved, but the amount of data generated increases significantly, making it difficult to prioritize critical risks
Solution Approach 1:
The patent combines vulnerability data from multiple assessment tools and third-party auditors into a single unified view. The system correlates data from diverse sources including internal vulnerability scanners and external audit firms, merging them into a consolidated risk assessment that eliminates redundancy and provides a comprehensive yet manageable dataset for prioritization.
Solution Approach 2:
The system creates a universal risk scoring mechanism that can evaluate and prioritize vulnerabilities regardless of their source. The multi-functionality platform handles various data formats from different tools and auditors, applying consistent scoring criteria to transform heterogeneous data into a standardized prioritized risk list.
2Loss of information
If traditional vulnerability data from assessment tools and auditors is used, then vulnerability identification is achieved, but the data lacks information on likelihood of successful attacks, leading to inefficient resource allocation
Solution Approach 1:
The patent introduces an intermediary correlation layer that bridges vulnerability data and exploitability information. The system uses vulnerability identifiers as intermediaries to match assessed vulnerabilities with known exploits from external databases, thereby inferring attack likelihood without directly measuring it. This intermediary mechanism enriches raw vulnerability data with contextual exploitability information.
Solution Approach 2:
The system performs preliminary enrichment of vulnerability data by pre-correlating vulnerability identifiers with exploit databases before final risk assessment. This preliminary action ensures that when vulnerabilities are assessed, they already have associated exploitability metrics attached, eliminating the need for separate analysis steps and improving overall productivity.
3Measurement precision
If enterprises manually analyze vulnerability data to prioritize critical risks, then some risk differentiation is achieved, but additional resources and costs are incurred, and the prioritization remains inaccurate due to lack of exploitability information
Solution Approach 1:
The system enables self-service risk prioritization by automatically correlating vulnerability data with exploitability information from external databases. The platform performs self-correlation where vulnerability identifiers automatically match with known exploits, and the system self-ranks risks based on combined vulnerability and exploitability scores, eliminating the need for manual expert analysis while improving accuracy.
Data Source
AI summary
Techniques for ranking a set of vulnerabilities of a computing asset and set of remediations for a computing asset, and determining a risk score for one or more computing assets are provided. In one technique, vulnerabilities of computing assets in a customer network are received at a vulnerability intelligence platform. Breach data indicating set of breaches that occurred outside customer network is also received. A subset of the set of vulnerabilities that are most vulnerable to a breach is identified based on the breach data. In another technique, multiple vulnerabilities of a computing asset are determined. A risk score is generated for the computing asset based on the vulnerabilities. In another technique, multiple remediations associated with a risk score and multiple vulnerabilities are identified. The remediations are ordered based on the remediations that would reduce the risk score the most if those remediations were applied to remove the corresponding vulnerabilities.


