×

Determining technology-appropriate remediation for vulnerability

  • US 8,635,702 B2
  • Filed: 04/04/2012
  • Issued: 01/21/2014
  • Est. Priority Date: 07/23/2004
  • Status: Active Grant
First Claim
Patent Images

1. An automated computerized method of determining one or more technology-appropriate remediations for a common aspect of vulnerability in a system, the method comprising:

  • receiving one or more vulnerability identifications (VIDs) and descriptions thereof, respectively, that have a common aspect of vulnerability;

    in response to the receiving of the one or more VIDs, determining, by executing instructions on a processor of a computer, a remediation identification (RID) associated with the common aspect of vulnerability;

    in response to the determining of the RID, creating, by executing further instructions on the processor of the computer, based upon the one or more VIDs and the descriptions thereof, a first machine-actionable map between the RID, one or more technology identifications (TIDs), and one or more action identifications (ACTIDs) for actions that remediate the common aspect of vulnerability represented by the RID, where the first machine-actionable map is a representation of the remediation candidate, wherein the creating of the first machine-actionable map includes;

    providing a plurality of machine-actionable second maps, each second map being between a given RID, at least two TIDs for which the given RID can be used, and two or more sets of ACTIDs, the two or more set of ACTIDs corresponding to the at least two TIDs, respectively;

    selecting one or more instances of the plurality of second maps, where the one or more selected instances of second maps represents the first machine-actionable map, the selecting of one or more instances of the plurality of second maps includes;

    indexing into the plurality of second maps using the RID to obtain a first subset of the plurality of second maps;

    determining a list of one or more TIDs that correspond to the one or more VIDs, the determining of the list including;

    determining, for each of the one or more VIDs, a technology genus associated with a given VID; and

    populating the list with TIDs of technology species associated with the technology genus; and

    eliminating members of the first subset that are specific to TIDs which are not present on the list; and

    storing the first machine-actionable map.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×