Device protection using software update security scores to mitigate software vulnerabilities
Techniques are provided for device protection using software update security scores to mitigate software vulnerabilities. One method comprises obtaining an indication of available software updates for a device; evaluating a security vulnerability of one or more uninstalled software updates of the available software updates for the device; determining a security score for the device based on the security vulnerability of the one or more uninstalled software updates of the available software updates for the device; and initiating an automated action using the security score for the device and/or the one or more security vulnerabilities of the one or more uninstalled software updates. The uninstalled software updates and/or the available software updates may be ranked using respective software update security scores. The security score for the device may be determined by aggregating security scores of the one or more uninstalled software updates.
1 . A method, comprising:
obtaining an indication of one or more available software updates for at least one device;
extracting, using at least one processing device employing pattern matching, one or more security vulnerabilities, of one or more uninstalled software updates of at least one of the one or more available software updates, from a description of at least one of the one or more uninstalled software updates;
evaluating, using the at least one processing device, one or more extracted security vulnerabilities of at least one or more uninstalled software updates of the one or more available software updates for the at least one device;
determining, using the at least one processing device, an aggregate security score for the at least one device based at least in part on an aggregation of respective security scores for the one or more extracted security vulnerabilities of the one or more uninstalled software updates of the one or more available software updates for the at least one device; and
initiating, using the at least one processing device, at least one automated action using one or more of the aggregate security score for the at least one device and the one or more extracted security vulnerabilities of the one or more uninstalled software updates;
wherein the at least one processing device comprises a processor coupled to a memory.
2 . The method of claim 1 , wherein the evaluating the one or more extracted security vulnerabilities of a given one of the one or more uninstalled software updates comprises determining the respective security scores for the one or more extracted security vulnerabilities; and determining an overall security score for the given uninstalled software update based at least in part on the security scores for the one or more extracted security vulnerabilities.
3 . The method of claim 2 , wherein the pattern matching employs one or more regular expressions to extract data indicative of a security vulnerability from the description of the given uninstalled software update.
4 . The method of claim 2 , wherein the security score for a given one of the one or more extracted security vulnerabilities is determined by obtaining security information from a vulnerability database.
5 . The method of claim 1 , further comprising ranking the at least one of (i) the one or more uninstalled software updates and (ii) the one or more available software updates using one or more respective software update security scores.
6 . The method of claim 1 , wherein the one or more available software updates comprise an update of one or more of: a basic input/output system; a device driver; firmware; and a software application.
7 . The method of claim 1 , wherein the at least one automated action using the aggregate security score for the at least one device comprises one or more of generating a notification indicating a respective security score of at least one of the one or more uninstalled software updates; and installing at least one of the one or more uninstalled software updates.
8 . The method of claim 1 , wherein the aggregation comprises one or more of an average and a mean of the respective security scores for the one or more security vulnerabilities of the one or more uninstalled software updates.
9 . The method of claim 1 , wherein a given one of the one or more uninstalled software updates has a plurality of corresponding extracted security vulnerabilities, and wherein the respective security score for a given extracted security vulnerability of the given uninstalled software update is selected as the respective security score for the given uninstalled software update based at least in part on an evaluation of the respective security scores for the plurality of corresponding extracted security vulnerabilities of the given uninstalled software update.
10 . An apparatus comprising:
at least one processing device comprising a processor coupled to a memory;
the at least one processing device being configured to implement the following steps:
obtaining an indication of one or more available software updates for at least one device;
extracting, using at least one processing device employing pattern matching, one or more security vulnerabilities, of one or more uninstalled software updates of at least one of the one or more available software updates, from a description of at least one of the one or more uninstalled software updates;
evaluating, using the at least one processing device, one or more extracted security vulnerabilities of at least one or more uninstalled software updates of the one or more available software updates for the at least one device;
determining, using the at least one processing device, an aggregate security score for the at least one device based at least in part on an aggregation of respective security scores for the one or more extracted security vulnerabilities of the one or more uninstalled software updates of the one or more available software updates for the at least one device; and
initiating, using the at least one processing device, at least one automated action using one or more of the aggregate security score for the at least one device and the one or more extracted security vulnerabilities of the one or more uninstalled software updates.
11 . The apparatus of claim 10 , wherein the evaluating the one or more extracted security vulnerabilities of a given one of the one or more uninstalled software updates comprises determining the respective security scores for the one or more extracted security vulnerabilities; and determining an overall security score for the given uninstalled software update based at least in part on the security scores for the one or more extracted security vulnerabilities.
12 . The apparatus of claim 11 , wherein the security score for a given one of the one or more extracted security vulnerabilities is determined by obtaining security information from a vulnerability database.
13 . The apparatus of claim 10 , further comprising ranking the at least one of (i) the one or more uninstalled software updates and (ii) the one or more available software updates using one or more respective software update security scores.
14 . The apparatus of claim 10 , wherein the at least one automated action using the aggregate security score for the at least one device comprises one or more of generating a notification indicating a respective security score of at least one of the one or more uninstalled software updates; and installing at least one of the one or more uninstalled software updates.
15 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:
obtaining an indication of one or more available software updates for at least one device;
extracting, using at least one processing device employing pattern matching, one or more security vulnerabilities, of one or more uninstalled software updates of at least one of the one or more available software updates, from a description of at least one of the one or more uninstalled software updates;
evaluating, using the at least one processing device, one or more extracted security vulnerabilities of at least one or more uninstalled software updates of the one or more available software updates for the at least one device;
determining, using the at least one processing device, an aggregate security score for the at least one device based at least in part on an aggregation of respective security scores for the one or more extracted security vulnerabilities of the one or more uninstalled software updates of the one or more available software updates for the at least one device; and
initiating, using the at least one processing device, at least one automated action using one or more of the aggregate security score for the at least one device and the one or more extracted security vulnerabilities of the one or more uninstalled software updates.
16 . The non-transitory processor-readable storage medium of claim 15 , wherein the evaluating the one or more extracted security vulnerabilities of a given one of the one or more uninstalled software updates comprises determining the respective security scores for the one or more extracted security vulnerabilities; and determining an overall security score for the given uninstalled software update based at least in part on the security scores for the one or more extracted security vulnerabilities.
17 . The non-transitory processor-readable storage medium of claim 16 , wherein the security score for a given one of the one or more extracted security vulnerabilities is determined by obtaining security information from a vulnerability database.
18 . The non-transitory processor-readable storage medium of claim 16 , wherein the pattern matching employs one or more regular expressions to extract data indicative of a security vulnerability from the description of the given uninstalled software update.
19 . The non-transitory processor-readable storage medium of claim 15 , further comprising ranking the at least one of (i) the one or more uninstalled software updates and (ii) the one or more available software updates using one or more respective software update security scores.
20 . The non-transitory processor-readable storage medium of claim 15 , wherein the at least one automated action using the aggregate security score for the at least one device comprises one or more of generating a notification indicating a respective security score of at least one of the one or more uninstalled software updates; and installing at least one of the one or more uninstalled software updates.