Organization-Specific Vulnerability Scoring via CVSS Extension
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Common Vulnerability Scoring System (CVSS) has limitations in capturing an organization's specific threat landscape and impact criteria, leading to incomplete risk calculations, subjective assessments, and inability to accurately represent vulnerabilities' potential impact on enterprises and national computing infrastructure.
Innovation Solution
A computer-readable storage medium with program instructions that determines a vulnerability score for an exploitable vulnerability based on an extension of CVSS, incorporating Maximized Confidentiality Impact, Maximized Highest Impact, and other specific metrics to provide a more robust and objective scoring system, including threat actor scores and defense-in-depth metrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If CVSS scoring system is used, then vulnerability severity can be standardized, but organization-specific threat landscape and impact criteria cannot be captured
Solution Approach 1:
The patent applies local quality by customizing vulnerability scores to reflect organization-specific threat landscapes and impact criteria. Instead of using a universal CVSS score, the system adjusts scoring parameters based on the specific organizational context, such as which assets are most valuable, what threat actors are most relevant, and what impact criteria matter most to that organization. This allows the same vulnerability to receive different scores across different organizations based on their unique risk profiles.
Solution Approach 2:
The system dynamically adjusts vulnerability scores based on changing organizational contexts, threat intelligence, and risk criteria. The scoring model can be updated to reflect new threats, changing asset priorities, and evolving security requirements. This dynamic adaptation allows the vulnerability assessment to remain accurate and relevant over time without requiring complete redesign.
2Ease of operation
If CVSS base metrics are used, then vulnerability scoring can be simplified, but risk calculation becomes incomplete and subjective
Solution Approach 1:
The patent segments the vulnerability scoring process into multiple independent components: base CVSS metrics, organization-specific impact metrics, threat intelligence factors, and control mitigation adjustments. Each component can be calculated and weighted separately, then combined to produce the final organization-specific vulnerability score. This segmentation maintains operational simplicity while improving reliability by allowing each factor to be optimized independently.
Solution Approach 2:
The system incorporates feedback mechanisms that allow organizations to validate and adjust vulnerability scores based on actual risk assessments and security outcomes. The scoring model can be refined using historical data on vulnerability exploitation, business impact, and security control effectiveness. This feedback loop ensures the scoring remains reliable and aligned with actual organizational risk conditions.
3Extent of automation
If standardized CVSS scores are applied, then vulnerability assessment can be automated, but subjective assessments and compliance with security standards become difficult
Solution Approach 1:
The patent changes the parameters used in vulnerability scoring from fixed CVSS values to organization-specific adjustable parameters. The system maintains automation by using programmed adjustment rules that can be configured to match different security standards and compliance requirements. Organizations can select which parameters to weight and how to adjust them, allowing automated assessment while achieving precision tailored to specific compliance frameworks and security standards.
Data Source
AI summary
In one example, a non-transitory computer-readable storage medium stores executable program instructions that detect, at a remote device node, vulnerability data associated with an exploitable vulnerability of a target enterprise network; retrieve, by a first local device node, the vulnerability data, which may include a CVSS score, determine, by a second local device node, a vulnerability score VT by determining a first subscore VT1, where the first subscore VT1 is based on a Maximized Confidentiality Impact (MCI) metric that is a modified privacy metric to capture the privacy impact of the exploitable vulnerability, where the first subscore VT1 is also based on a Maximized Highest Impact (MHI) metric to capture reputation damage based on an outsized single impact attribute, and on a Modified Confidentiality (MC) metric, Modified Integrity (MI) metric and Modified Availability (MA) as provided by CVSS; and remediate the exploitable vulnerability based on the vulnerability score VT.


