Automated Vulnerability Tracking System with Cross-Referenced Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing computer vulnerabilities, such as the National Vulnerability Database (NVD), lack comprehensive integration of third-party vendor and technology community reference information, leading to incomplete risk assessments due to manual and unstructured data aggregation, and do not account for factors like available patches, anti-malware detection, and global exploits, resulting in inaccurate risk scoring.
Innovation Solution
A computer-implemented method and system that automatically compiles and cross-references vulnerability information from multiple sources, including NVD, CVE, CPE, CCE, CAPEC, and CWE, with additional secondary sources, to create a structured database with summary data, enabling automated risk assessment and distribution via the internet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If manual and unstructured data aggregation from multiple sources is used, then comprehensive vulnerability information can be collected, but the process is laborious, unreliable, and prone to error
Solution Approach 1:
The system enables automated self-service data collection by having computers automatically search for, retrieve, and compile vulnerability information from multiple sources including NVD, CVE, CPE, CCE, CAPEC, and CWE databases, eliminating the need for manual data aggregation while maintaining comprehensive information coverage
Solution Approach 2:
The system performs multiple functions within a single automated process: searching multiple vulnerability databases, collecting diverse information types (vulnerability descriptions, patches, detection methods, exploitation techniques), cross-referencing data across sources, and generating comprehensive reports, thereby improving both completeness and efficiency simultaneously
2Measurement precision
If third-party vendor and technology community reference information is extensively incorporated, then more accurate risk assessment can be achieved, but data integration becomes more complex
Solution Approach 1:
The system introduces automated computer systems as intermediaries between multiple third-party information sources and the risk assessment process. These computers act as mediators that systematically search, retrieve, and integrate data from diverse sources including vendor advisories, security research communities, and commercial security products, simplifying the integration complexity while maintaining high assessment accuracy
Solution Approach 2:
The system transforms unstructured and semi-structured third-party information into standardized parameters and formats suitable for quantitative risk assessment. By converting diverse data types into consistent parameters, the system enables accurate risk scoring while managing integration complexity through parameter standardization
3Ease of operation
If CVSS base score is used alone for risk assessment, then a standardized severity measure is obtained, but factors like available patches, anti-malware detection, and global exploits are not accounted for
Solution Approach 1:
The system merges the standardized CVSS base score with additional contextual factors including available patches, anti-malware detection capabilities, and global exploit information. By combining these multiple information sources into a unified risk assessment, the system maintains the simplicity of standardized scoring while significantly improving the accuracy of actual risk measurement for specific systems
Data Source
AI summary
There is provided a method and system for tracking, compiling, and distributing information regarding computer vulnerabilities. The method and system involve identifying computer vulnerabilities and associated information from main internet sources. These computer vulnerabilities are then checked against a number of other secondary sources for additional information. The information from the main and secondary sources are compiled into a database detailing the computer vulnerabilities. The database entries are then converted into computer readable format and distributed via the internet.


