Automated Vulnerability Tracking System with Cross-Referenced Risk Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing computer vulnerabilities, such as the National Vulnerability Database (NVD), lack comprehensive integration of third-party vendor and technology community reference information, leading to incomplete risk assessments due to manual and unstructured data aggregation, and do not account for factors like available patches, anti-malware detection, and global exploits, resulting in inaccurate risk scoring.

Innovation Solution

A computer-implemented method and system that automatically compiles and cross-references vulnerability information from multiple sources, including NVD, CVE, CPE, CCE, CAPEC, and CWE, with additional secondary sources, to create a structured database with summary data, enabling automated risk assessment and distribution via the internet.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If manual and unstructured data aggregation from multiple sources is used, then comprehensive vulnerability information can be collected, but the process is laborious, unreliable, and prone to error

Engineering Contradiction:
Improvecompleteness of vulnerability informationVSAvoidefficiency of data aggregation
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The system enables automated self-service data collection by having computers automatically search for, retrieve, and compile vulnerability information from multiple sources including NVD, CVE, CPE, CCE, CAPEC, and CWE databases, eliminating the need for manual data aggregation while maintaining comprehensive information coverage

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs multiple functions within a single automated process: searching multiple vulnerability databases, collecting diverse information types (vulnerability descriptions, patches, detection methods, exploitation techniques), cross-referencing data across sources, and generating comprehensive reports, thereby improving both completeness and efficiency simultaneously

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If third-party vendor and technology community reference information is extensively incorporated, then more accurate risk assessment can be achieved, but data integration becomes more complex

Engineering Contradiction:
Improveaccuracy of risk assessmentVSAvoidcomplexity of data integration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system introduces automated computer systems as intermediaries between multiple third-party information sources and the risk assessment process. These computers act as mediators that systematically search, retrieve, and integrate data from diverse sources including vendor advisories, security research communities, and commercial security products, simplifying the integration complexity while maintaining high assessment accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms unstructured and semi-structured third-party information into standardized parameters and formats suitable for quantitative risk assessment. By converting diverse data types into consistent parameters, the system enables accurate risk scoring while managing integration complexity through parameter standardization

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If CVSS base score is used alone for risk assessment, then a standardized severity measure is obtained, but factors like available patches, anti-malware detection, and global exploits are not accounted for

Engineering Contradiction:
Improvesimplicity of risk scoringVSAvoidaccuracy of actual risk to specific system
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system merges the standardized CVSS base score with additional contextual factors including available patches, anti-malware detection capabilities, and global exploit information. By combining these multiple information sources into a unified risk assessment, the system maintains the simplicity of standardized scoring while significantly improving the accuracy of actual risk measurement for specific systems

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9871815B2Method and system for automated computer vulnerability tracking
Publication Date: 2018.01.16 ZETAFENCE
  • US9871815B2 patent drawing
  • US9871815B2 patent drawing
  • US9871815B2 patent drawing

AI summary

There is provided a method and system for tracking, compiling, and distributing information regarding computer vulnerabilities. The method and system involve identifying computer vulnerabilities and associated information from main internet sources. These computer vulnerabilities are then checked against a number of other secondary sources for additional information. The information from the main and secondary sources are compiled into a database detailing the computer vulnerabilities. The database entries are then converted into computer readable format and distributed via the internet.