Vulnerability Remediation Prioritization in Enterprise Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise systems face challenges in monitoring and remediating vulnerabilities due to the increasing number of assets, which requires effective prioritization of vulnerabilities and assets for patch management and mitigation, considering factors like asset criticality, exploitability, and impact potential.

Innovation Solution

A method that assigns weights to vulnerabilities and assets based on their criticality, exploitability, and impact potential, determining a partial order for remediation actions, including prioritizing which assets and network segments to patch first, and selecting assets for additional remediation when patches are not available, using a vulnerability weighting module, asset weighting module, and remediation action prioritization module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If the number of assets in an enterprise system grows, then the system's functionality and capacity increase, but the number of vulnerabilities increases and monitoring/remediation becomes more difficult

Engineering Contradiction:
Improvenumber of assetsVSAvoidcomplexity of monitoring and remediating vulnerabilities
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the enterprise system into multiple network segments and divides vulnerabilities into different groups based on their characteristics and affected assets. This segmentation allows the system to manage and prioritize vulnerabilities in smaller, more manageable units rather than treating all vulnerabilities uniformly across the entire enterprise system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces multiple parameters for vulnerability assessment including exploitability potential, impact potential, asset criticality, and remediation urgency. By changing from a single vulnerability count metric to a multi-parameter evaluation system, the patent enables more nuanced prioritization and management of vulnerabilities as the system scales.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all vulnerabilities are remediated immediately, then security risk is minimized, but resource allocation becomes inefficient and productivity decreases

Engineering Contradiction:
Improvesecurity risk mitigationVSAvoidremediation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements partial action by prioritizing remediation of only the most critical vulnerabilities first, rather than attempting to remediate all vulnerabilities simultaneously. The system identifies and addresses high-priority vulnerabilities based on their exploitability and impact potential, while lower-priority vulnerabilities are scheduled for later remediation when resources are available.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary assessment and prioritization of vulnerabilities before remediation begins. By pre-evaluating vulnerabilities based on multiple parameters and establishing a prioritization framework in advance, the system prepares remediation strategies beforehand, enabling more efficient resource allocation during the actual remediation process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If remediation actions are applied without prioritization, then all assets receive equal attention, but critical assets may not receive timely protection

Engineering Contradiction:
Improveuniform remediation approachVSAvoidtimely protection of critical assets
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning different priority levels and remediation strategies to different vulnerabilities based on their specific characteristics and the criticality of the affected assets. Critical assets receive higher priority and more urgent remediation attention, while less critical assets are addressed with standard remediation timelines, allowing differentiated quality of protection across the system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11201891B2Prioritization of remediation actions for addressing vulnerabilities in an enterprise system
Publication Date: 2021.12.14 EMC IP HLDG CO LLC
  • US11201891B2 patent drawing
  • US11201891B2 patent drawing
  • US11201891B2 patent drawing

AI summary

A method includes identifying two or more vulnerabilities, each vulnerability affecting a set of one or more assets of an enterprise system. The method also includes assigning a weight to each vulnerability, the weight assigned to each of the vulnerabilities being based at least in part on the set of assets affected by that vulnerability, asset criticalities associated with the set of assets affected by that vulnerability, and at least one of (i) an exploitability potential of that vulnerability and (ii) an impact potential of that vulnerability. The method further includes determining an order in which to apply remediation actions in the enterprise system to address at least one of the vulnerabilities based at least in part on the weights assigned to the vulnerabilities, and applying, in accordance with the determined order, at least one of the remediation actions to at least one of the assets in the enterprise system.