Automated Vulnerability Reporting via User-Device Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for identifying and managing vulnerable computers in networks are inefficient, as they require time-consuming scans to identify both devices and associated users, and do not effectively provide actionable information to reduce virus risks.

Innovation Solution

A system and method that associates client device information with user information, using a scanning tool to identify vulnerabilities and cross-reference user identification data to generate reports and notifications, enabling targeted actions to remediate vulnerabilities and improve network reliability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network computers are scanned to identify vulnerable devices and associated users, then network security risk management is improved, but the process becomes time consuming and inefficient

Engineering Contradiction:
Improvenetwork security risk managementVSAvoidtime consuming process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing user-device association databases and pre-configuring vulnerability scanning parameters before actual security assessments. This allows the scanning process to quickly match identified vulnerable devices with pre-stored user information, eliminating the need for time-consuming manual user identification during the scanning process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary association database that stores the relationship between users and their devices. This intermediary structure enables the scanning system to quickly resolve device identifiers to user identities without direct manual intervention, significantly reducing the time required to associate vulnerable devices with their users while maintaining accurate security risk management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed scanning is performed to identify vulnerable devices and users, then measurement precision of vulnerabilities is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidscanning system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The scanning system is segmented into specialized modules: a vulnerability detection module that identifies security issues, an association module that matches devices to users using pre-stored data, and a reporting module that generates notifications. This segmentation allows each component to perform its function with high precision while keeping individual module complexity manageable, as each handles a specific aspect of the overall process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs self-service mechanisms where the association database automatically resolves device-user mappings without manual intervention, and the reporting system automatically generates and delivers notifications. This self-service capability maintains high measurement precision for vulnerability identification while reducing the operational complexity that would otherwise be required to manage detailed scanning results manually.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8528094B1Automated information association and reporting
Publication Date: 2013.09.03 BANK OF AMERICA CORP
  • US8528094B1 patent drawing
  • US8528094B1 patent drawing
  • US8528094B1 patent drawing

AI summary

A system, method and apparatus for associating data is presented. An association system generally includes a vulnerability information system, user identification system and association tool. The vulnerability information system performs a scan of client devices to identify vulnerable devices. The vulnerability information is transmitted to the association tool where it is cross referenced with user identification information received from the user identification system. The association tool identifies the user associated with the vulnerable devices and this information may be stored to generate historical trend information. In addition, the information may be displayed graphically or may be used to generate reports and identify metrics that can be monitored in order to improve reliability, efficiency and the like.