Organization-Specific Vulnerability Scoring via CVSS Extension

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Common Vulnerability Scoring System (CVSS) has limitations in capturing an organization's specific threat landscape and impact criteria, leading to incomplete risk calculations, subjective assessments, and inability to accurately represent vulnerabilities' potential impact on enterprises and national computing infrastructure.

Innovation Solution

A computer-readable storage medium with program instructions that determines a vulnerability score for an exploitable vulnerability based on an extension of CVSS, incorporating Maximized Confidentiality Impact, Maximized Highest Impact, and other specific metrics to provide a more robust and objective scoring system, including threat actor scores and defense-in-depth metrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If CVSS scoring system is used, then vulnerability severity can be standardized, but organization-specific threat landscape and impact criteria cannot be captured

Engineering Contradiction:
Improveorganization-specific adaptabilityVSAvoidimpact measurement accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by customizing vulnerability scores to reflect organization-specific threat landscapes and impact criteria. Instead of using a universal CVSS score, the system adjusts scoring parameters based on the specific organizational context, such as which assets are most valuable, what threat actors are most relevant, and what impact criteria matter most to that organization. This allows the same vulnerability to receive different scores across different organizations based on their unique risk profiles.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts vulnerability scores based on changing organizational contexts, threat intelligence, and risk criteria. The scoring model can be updated to reflect new threats, changing asset priorities, and evolving security requirements. This dynamic adaptation allows the vulnerability assessment to remain accurate and relevant over time without requiring complete redesign.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If CVSS base metrics are used, then vulnerability scoring can be simplified, but risk calculation becomes incomplete and subjective

Engineering Contradiction:
Improvescoring operation simplicityVSAvoidrisk calculation reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the vulnerability scoring process into multiple independent components: base CVSS metrics, organization-specific impact metrics, threat intelligence factors, and control mitigation adjustments. Each component can be calculated and weighted separately, then combined to produce the final organization-specific vulnerability score. This segmentation maintains operational simplicity while improving reliability by allowing each factor to be optimized independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates feedback mechanisms that allow organizations to validate and adjust vulnerability scores based on actual risk assessments and security outcomes. The scoring model can be refined using historical data on vulnerability exploitation, business impact, and security control effectiveness. This feedback loop ensures the scoring remains reliable and aligned with actual organizational risk conditions.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If standardized CVSS scores are applied, then vulnerability assessment can be automated, but subjective assessments and compliance with security standards become difficult

Engineering Contradiction:
Improvevulnerability assessment automationVSAvoidcompliance precision
Core Design Contradiction:
Extent of automationVSManufacturing precision

Solution Approach 1:

The patent changes the parameters used in vulnerability scoring from fixed CVSS values to organization-specific adjustable parameters. The system maintains automation by using programmed adjustment rules that can be configured to match different security standards and compliance requirements. Organizations can select which parameters to weight and how to adjust them, allowing automated assessment while achieving precision tailored to specific compliance frameworks and security standards.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240236137A1Vulnerability scoring based on organization-specific metrics
Publication Date: 2024.07.11 JPMORGAN CHASE BANK NA
  • US20240236137A1 patent drawing
  • US20240236137A1 patent drawing
  • US20240236137A1 patent drawing

AI summary

In one example, a non-transitory computer-readable storage medium stores executable program instructions that detect, at a remote device node, vulnerability data associated with an exploitable vulnerability of a target enterprise network; retrieve, by a first local device node, the vulnerability data, which may include a CVSS score, determine, by a second local device node, a vulnerability score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest Impact (MHI) metric to capture reputation damage based on an outsized single impact attribute, and on a Modified Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability score VT.