Vulnerability Threat Assessment Using Real-World Exploitation Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability assessment methods, such as CVSS, are inaccurate as they only consider inherent characteristics of vulnerabilities and do not account for actual threat events and exploitation difficulties, leading to incomplete threat degree assessments.

Innovation Solution

A vulnerability assessment method and device that gather information on threat events and vulnerability exploitation difficulty, including defense effectiveness and code exploitation maturity, to accurately assess threat degrees and prioritize fixes based on these factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If CVSS scoring system is used to assess vulnerability threat degree, then the assessment process is simple and standardized, but the assessment accuracy is insufficient because it only considers inherent characteristics of vulnerabilities

Engineering Contradiction:
Improveassessment process simplicityVSAvoidthreat degree assessment accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent combines multiple assessment dimensions including CVSS inherent characteristics, actual threat event data, and vulnerability exploitation difficulty into a unified assessment framework. This merging of multiple data sources and assessment criteria enables comprehensive threat degree evaluation while maintaining systematic processing, thus improving accuracy without completely abandoning the simplicity of standardized approaches.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary assessment layer that processes and integrates data from multiple sources (CVSS scores, threat event logs, exploitation difficulty metrics) before producing the final threat degree assessment. This intermediary processing mechanism reconciles the simplicity of standardized scoring with the complexity of real-world threat evaluation, achieving both ease of operation and measurement precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If only inherent vulnerability characteristics are considered for assessment, then the assessment process is efficient and quick, but the threat degree assessment is incomplete and inaccurate

Engineering Contradiction:
Improveassessment efficiencyVSAvoidthreat degree assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent performs preliminary collection and organization of multiple types of data (inherent characteristics, threat event data, exploitation difficulty) before the actual assessment. This preliminary preparation enables the assessment system to efficiently access and integrate relevant information during the assessment process, maintaining high productivity while ensuring comprehensive and accurate threat degree evaluation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a multi-functional assessment framework that can process and evaluate multiple types of vulnerability data simultaneously. This universal assessment mechanism handles diverse data sources (CVSS scores, threat events, exploitation metrics) through a unified process, achieving both efficiency through standardized processing and accuracy through comprehensive data consideration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If real-world threat event data and exploitation difficulty are incorporated into assessment, then the threat degree assessment accuracy is improved, but the assessment complexity increases

Engineering Contradiction:
Improvethreat degree assessment accuracyVSAvoidassessment system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability assessment into distinct modular components: inherent characteristic assessment, threat event analysis, exploitation difficulty evaluation, and integrated threat degree calculation. This segmentation allows each component to be developed and maintained independently, reducing overall system complexity while enabling comprehensive and accurate assessment through the integration of specialized modules.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250013744A1Vulnerability assessment method and analysis device
Publication Date: 2025.01.09 HUAWEI TECH CO LTD
  • US20250013744A1 patent drawing
  • US20250013744A1 patent drawing
  • US20250013744A1 patent drawing

AI summary

The technology of this application relates to a vulnerability assessment method and an analysis device. The analysis device obtains a plurality of pieces of vulnerability information of a computer device. The vulnerability information includes an identifier of a vulnerability, and each piece of vulnerability information indicates one vulnerability on the computer device. A plurality of vulnerabilities indicated by the plurality of pieces of vulnerability information may be on one computer device or different computer devices. The analysis device assesses, based on information about a threat event that is reported by a security device and/or vulnerability exploitation difficulty, threat degrees of the plurality of vulnerabilities to the computer device.