Vulnerability Remediation Verification via Token Reconciliation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vulnerability monitoring systems provide weak confirmation of vulnerability correction, relying on passive rescan methods that may not accurately verify if remediation operations have been successfully performed by authorized entities.

Innovation Solution

A system comprising a vulnerability remediation verification subsystem, including vulnerability scanners, remediation processors, and a reconciliation engine, which generates and verifies tokens to ensure that remediation operations are performed by authorized entities and successfully completed before a deadline, providing positive verification of vulnerability correction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If passive rescan methods are used to confirm vulnerability correction, then the verification process is simple and quick, but the confirmation accuracy is weak and may not accurately verify if remediation operations have been successfully performed

Engineering Contradiction:
Improveconfirmation accuracyVSAvoidverification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system generates a vulnerability token before remediation operations are performed, which contains predetermined information about the vulnerability and expected remediation criteria. This preliminary action enables accurate verification by having the verification criteria ready in advance, rather than attempting to verify after the fact with passive rescan methods

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability token acts as an intermediary object that carries verification information between the vulnerability scanning system and the remediation verification process. The token contains embedded criteria that mediate the verification process, enabling accurate confirmation without requiring complex post-remediation analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If passive rescan methods are used, then the verification process is fast and resource-efficient, but it cannot provide positive verification that remediation operations were performed by authorized entities

Engineering Contradiction:
Improveverification reliabilityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes verification criteria and generates the vulnerability token before remediation operations occur. This preliminary setup includes authorized entity information and expected outcomes, enabling rapid reliable verification afterward without time-consuming post-remediation analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The reconciliation engine provides feedback by comparing actual remediation results against the predetermined criteria in the vulnerability token. This feedback mechanism enables rapid determination of whether remediation was successfully performed by authorized entities, without requiring extended verification time

Inventive Principle:
Principle #23Feedback

3Reliability

If conventional vulnerability monitoring systems are used, then the system complexity is low, but they provide very weak confirmation that a vulnerability has been corrected

Engineering Contradiction:
Improvevulnerability correction confirmationVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The verification system is segmented into distinct functional components: vulnerability scanning, token generation with embedded criteria, remediation execution, and reconciliation verification. This segmentation allows each component to perform its specific function reliably while maintaining manageable overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vulnerability token serves as an intermediary that carries all necessary verification information through the system. It mediates between the scanning phase and verification phase, enabling reliable confirmation without requiring the entire monitoring system to become overly complex

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10503909B2System and method for vulnerability remediation verification
Publication Date: 2019.12.10 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10503909B2 patent drawing
  • US10503909B2 patent drawing
  • US10503909B2 patent drawing

AI summary

In remediating a computer vulnerability, operations to be performed to correct the vulnerability are identified. Remediation processors are scheduled to perform the operations. Whether the vulnerability has been corrected is determined by: determining whether the operations have been performed successfully; and determining whether the operations have been performed by authorized remediation processors.