Vulnerability Remediation Prioritization via Breach Data Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in efficiently prioritizing and addressing IT security risks due to the large amount of data generated from various security vulnerability assessment tools and third-party auditors, which often lacks necessary information on the likelihood of successful attacks, leading to inadequate defense strategies.

Innovation Solution

A vulnerability threat management platform that correlates vulnerability data with breach data from multiple sources, providing a risk score and ordered list of remediations to help prioritize and address the most critical vulnerabilities effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security vulnerability assessment tools and third-party auditors are used to assess IT assets, then the comprehensiveness of vulnerability detection is improved, but the amount of data generated increases significantly, making it difficult to prioritize critical risks

Engineering Contradiction:
Improvecomprehensiveness of vulnerability detectionVSAvoidamount of vulnerability data
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent combines vulnerability data from multiple assessment tools and third-party auditors into a single unified view. The system correlates data from diverse sources including internal vulnerability scanners and external audit firms, merging them into a consolidated risk assessment that eliminates redundancy and provides a comprehensive yet manageable dataset for prioritization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal risk scoring mechanism that can evaluate and prioritize vulnerabilities regardless of their source. The multi-functionality platform handles various data formats from different tools and auditors, applying consistent scoring criteria to transform heterogeneous data into a standardized prioritized risk list.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If traditional vulnerability data from assessment tools and auditors is used, then vulnerability identification is achieved, but the data lacks information on likelihood of successful attacks, leading to inefficient resource allocation

Engineering Contradiction:
Improveinformation completeness on attack likelihoodVSAvoidefficiency of security risk reduction
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent introduces an intermediary correlation layer that bridges vulnerability data and exploitability information. The system uses vulnerability identifiers as intermediaries to match assessed vulnerabilities with known exploits from external databases, thereby inferring attack likelihood without directly measuring it. This intermediary mechanism enriches raw vulnerability data with contextual exploitability information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary enrichment of vulnerability data by pre-correlating vulnerability identifiers with exploit databases before final risk assessment. This preliminary action ensures that when vulnerabilities are assessed, they already have associated exploitability metrics attached, eliminating the need for separate analysis steps and improving overall productivity.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If enterprises manually analyze vulnerability data to prioritize critical risks, then some risk differentiation is achieved, but additional resources and costs are incurred, and the prioritization remains inaccurate due to lack of exploitability information

Engineering Contradiction:
Improveaccuracy of risk prioritizationVSAvoidcomplexity of data analysis process
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service risk prioritization by automatically correlating vulnerability data with exploitability information from external databases. The platform performs self-correlation where vulnerability identifiers automatically match with known exploits, and the system self-ranks risks based on combined vulnerability and exploitability scores, eliminating the need for manual expert analysis while improving accuracy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10305925B2Ordered computer vulnerability remediation reporting
Publication Date: 2019.05.28 CISCO TECHNOLOGY INC
  • US10305925B2 patent drawing
  • US10305925B2 patent drawing
  • US10305925B2 patent drawing

AI summary

Techniques for ranking a set of vulnerabilities of a computing asset and set of remediations for a computing asset, and determining a risk score for one or more computing assets are provided. In one technique, vulnerabilities of computing assets in a customer network are received at a vulnerability intelligence platform. Breach data indicating set of breaches that occurred outside customer network is also received. A subset of the set of vulnerabilities that are most vulnerable to a breach is identified based on the breach data. In another technique, multiple vulnerabilities of a computing asset are determined. A risk score is generated for the computing asset based on the vulnerabilities. In another technique, multiple remediations associated with a risk score and multiple vulnerabilities are identified. The remediations are ordered based on the remediations that would reduce the risk score the most if those remediations were applied to remove the corresponding vulnerabilities.