IP Library Granted Patent US 12,556,568
Granted Patent B2
US 12,556,568 · App. 18/110,190 · Granted Feb 17, 2026

Multi-objective computer infrastructure vulnerability prioritization

Inventors: Leomar Comparin Lima (Porto Alegre, BR); Marcio Augusto de Araujo Borges (Porto Alegre, BR); Karine da Rosa Heinen de Azambuja (Capao da Canoa, BR); Felipe Colombelli (Porto Alegre, BR); Vitor Kehl Matter (Nova Petropolis, BR); Sandro Jose Rigo (Porto Alegre, BR); Rodrigo da Rosa Righi (Sao Leopoldo, BR); Gabriel de Oliveira Ramos (Gravatai, BR); Bruno Iochins Grisci (Porto Alegre, BR); Jorge Luis Victoria Barbosa (Sao Leopoldo, BR); Cristiano Andre da Costa (Porto Alegre, BR)
Assignee: Dell Products L.P.
H04L63/1433H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,568
App. No.
18/110,190
Granted
Feb 17, 2026
Kind
B2
Abstract

Techniques are provided for multi-objective computer infrastructure vulnerability prioritization. One method comprises obtaining vulnerabilities associated with computer infrastructure elements; obtaining objectives for ranking the vulnerabilities; determining an initial population of individual solutions for addressing the vulnerabilities, wherein each individual solution comprises a ranked list of vulnerabilities; performing a multi-objective optimization that modifies the initial population of individual solutions to obtain a revised population of individual solutions, wherein each individual solution in the revised population comprises a fitness score and a ranked list of the at least some vulnerabilities; selecting an individual solution in the revised population based on the fitness score; and initiating an automated action to address one or more vulnerabilities in the selected individual solution using the ranked list of at least some vulnerabilities for the selected at least one individual solution.

Claims (41)

1 . A method, comprising:

obtaining a plurality of vulnerabilities associated with computer infrastructure elements;

obtaining a plurality of objectives for ranking the plurality of vulnerabilities;

determining an initial population of individual solutions for addressing at least some of the plurality of vulnerabilities;

performing a multi-objective optimization that modifies the initial population of individual solutions for addressing at least some of the plurality of vulnerabilities to obtain a revised population comprising a Pareto front of individual solutions for addressing at least some of the plurality of vulnerabilities, wherein each of the individual solutions in the revised population comprises: (i) a vector having a ranked position for each of the at least some of the plurality of vulnerabilities, (ii) one or more mitigation actions to address one or more of the plurality of vulnerabilities, and (iii) at least one fitness score, obtained using a fitness function, that characterizes a quality of the respective individual solution for at least some of the plurality of objectives, wherein one or more of the at least some of the plurality of vulnerabilities are mitigated in an order based at least in part on the ranked position for the respective individual solution;

selecting at least one of the individual solutions in the revised population based at least in part on the at least one fitness score associated with the at least one individual solution; and

initiating at least one mitigation action to address one or more of the plurality of vulnerabilities in the selected at least one individual solution using the ranked position of the at least some of the plurality of vulnerabilities for the selected at least one individual solution;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2 . The method of claim 1 , wherein the plurality of objectives is defined by one or more users.

3 . The method of claim 1 , wherein the initial population of individual solutions comprises one or more of: (i) at least one individual solution obtained by ranking the plurality of vulnerabilities according to a given one of the plurality of objectives; (ii) at least one individual solution obtained by ranking the plurality of vulnerabilities according to a rank aggregation; and (iii) at least one individual solution obtained by randomly ranking the plurality of vulnerabilities.

4 . The method of claim 1 , further comprising merging duplicate occurrences of at least one vulnerability in the plurality of vulnerabilities into a single vulnerability occurrence prior to performing the multi-objective optimization to modify the initial population of individual solutions and expanding the single vulnerability occurrence into the duplicate occurrences following the obtaining of the revised population of individual solutions.

5 . The method of claim 1 , further comprising identifying at least one inversion of a ranking of two or more vulnerabilities in at least one of the individual solutions in the revised population and correcting the at least one inversion of the ranking of the two or more vulnerabilities.

6 . The method of claim 1 , further comprising performing a target-based search to identify the plurality of vulnerabilities in at least one of the individual solutions in the revised population to address in order to satisfy a target value.

7 . The method of claim 1 , further comprising assigning a score to at least some of the individual solutions in the revised population using a scalarization approach based at least in part on a weighting of at least some of the plurality of objectives.

8 . The method of claim 7 , wherein the weighting of at least some of the plurality of objectives comprises a weighted sum of each of the at least some of the plurality of objectives, wherein the weighted sum of a given objective is based at least in part on an importance weight of the given objective.

9 . The method of claim 8 , wherein a new weighting of at least some of the plurality of objectives is determined in response to a change in at least one importance weight associated with the plurality of objectives.

10 . The method of claim 1 , wherein the multi-objective optimization employs one or more of a non-dominated sorting genetic algorithm and an adaptive geometry estimation-based multi-objective evolutionary algorithm.

11 . An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining a plurality of vulnerabilities associated with computer infrastructure elements;

obtaining a plurality of objectives for ranking the plurality of vulnerabilities;

determining an initial population of individual solutions for addressing at least some of the plurality of vulnerabilities;

performing a multi-objective optimization that modifies the initial population of individual solutions for addressing at least some of the plurality of vulnerabilities to obtain a revised population comprising a Pareto front of individual solutions for addressing at least some of the plurality of vulnerabilities, wherein each of the individual solutions in the revised population comprises: (i) a vector having a ranked position for each of the at least some of the plurality of vulnerabilities, (ii) one or more mitigation actions to address one or more of the plurality of vulnerabilities, and (iii) at least one fitness score, obtained using a fitness function, that characterizes a quality of the respective individual solution for at least some of the plurality of objectives, wherein one or more of the at least some of the plurality of vulnerabilities are mitigated in an order based at least in part on the ranked position for the respective individual solution;

selecting at least one of the individual solutions in the revised population based at least in part on the at least one fitness score associated with the at least one individual solution; and

initiating at least one mitigation action to address one or more of the plurality of vulnerabilities in the selected at least one individual solution using the ranked position of the at least some of the plurality of vulnerabilities for the selected at least one individual solution.

12 . The apparatus of claim 11 , further comprising merging duplicate occurrences of at least one vulnerability in the plurality of vulnerabilities into a single vulnerability occurrence prior to performing the multi-objective optimization to modify the initial population of individual solutions and expanding the single vulnerability occurrence into the duplicate occurrences following the obtaining of the revised population of individual solutions.

13 . The apparatus of claim 11 , further comprising identifying at least one inversion of a ranking of two or more vulnerabilities in at least one of the individual solutions in the revised population and correcting the at least one inversion of the ranking of the two or more vulnerabilities.

14 . The apparatus of claim 11 , further comprising performing a target-based search to identify the plurality of vulnerabilities in at least one of the individual solutions in the revised population to address in order to satisfy a target value.

15 . The apparatus of claim 11 , further comprising assigning a score to at least some of the individual solutions in the revised population using a scalarization approach based at least in part on a weighting of at least some of the plurality of objectives, wherein the weighting of at least some of the plurality of objectives comprises a weighted sum of each of the at least some of the plurality of objectives, wherein the weighted sum of a given objective is based at least in part on an importance weight of the given objective, and wherein a new weighting of at least some of the plurality of objectives is determined in response to a change in at least one importance weight associated with the plurality of objectives.

16 . The apparatus of claim 11 , wherein the initial population of individual solutions comprises one or more of: (i) at least one individual solution obtained by ranking the plurality of vulnerabilities according to a given one of the plurality of objectives; (ii) at least one individual solution obtained by ranking the plurality of vulnerabilities according to a rank aggregation; and (iii) at least one individual solution obtained by randomly ranking the plurality of vulnerabilities.

17 . A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining a plurality of vulnerabilities associated with computer infrastructure elements;

obtaining a plurality of objectives for ranking the plurality of vulnerabilities;

determining an initial population of individual solutions for addressing at least some of the plurality of vulnerabilities;

performing a multi-objective optimization that modifies the initial population of individual solutions for addressing at least some of the plurality of vulnerabilities to obtain a revised population comprising a Pareto front of individual solutions for addressing at least some of the plurality of vulnerabilities, wherein each of the individual solutions in the revised population comprises: (i) a vector having a ranked position for each of the at least some of the plurality of vulnerabilities, (ii) one or more mitigation actions to address one or more of the plurality of vulnerabilities, and (iii) at least one fitness score, obtained using a fitness function, that characterizes a quality of the respective individual solution for at least some of the plurality of objectives, wherein one or more of the at least some of the plurality of vulnerabilities are mitigated in an order based at least in part on the ranked position for the respective individual solution;

selecting at least one of the individual solutions in the revised population based at least in part on the at least one fitness score associated with the at least one individual solution; and

initiating at least one mitigation action to address one or more of the plurality of vulnerabilities in the selected at least one individual solution using the ranked position of the at least some of the plurality of vulnerabilities for the selected at least one individual solution.

18 . The non-transitory processor-readable storage medium of claim 17 , further comprising merging duplicate occurrences of at least one vulnerability in the plurality of vulnerabilities into a single vulnerability occurrence prior to performing the multi-objective optimization to modify the initial population of individual solutions and expanding the single vulnerability occurrence into the duplicate occurrences following the obtaining of the revised population of individual solutions.

19 . The non-transitory processor-readable storage medium of claim 17 , further comprising performing a target-based search to identify the plurality of vulnerabilities in at least one of the individual solutions in the revised population to address in order to satisfy a target value.

20 . The non-transitory processor-readable storage medium of claim 17 , further comprising assigning a score to at least some of the individual solutions in the revised population using a scalarization approach based at least in part on a weighting of at least some of the plurality of objectives, wherein the weighting of at least some of the plurality of objectives comprises a weighted sum of each of the at least some of the plurality of objectives, wherein the weighted sum of a given objective is based at least in part on an importance weight of the given objective, and wherein a new weighting of at least some of the plurality of objectives is determined in response to a change in at least one importance weight associated with the plurality of objectives.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: LIMA, LEOMAR COMPARIN; BORGES, MARCIO AUGUSTO DE ARAUJO; DE AZAMBUJA, KARINE DA ROSA HEINEN; COLOMBELLI, FELIPE; MATTER, VITOR KEHL; RIGO, SANDRO JOSE; RIGHI, RODRIGO DA ROSA; RAMOS, GABRIEL DE OLIVEIRA; GRISCI, BRUNO IOCHINS; BARBOSA, JORGE LUIS VICTORIA; DA COSTA, CRISTIANO ANDRE
To: DELL PRODUCTS L.P.
Reel/Frame 062711/0105 →
Continuity (1)
Related Publication 20240275807A1 · Aug 15, 2024
References Cited (24)
US 11550919B2 · Dhillon et al. · 2023 [cited by applicant]
US 20210264031A1 · Dhillon · 2021 [cited by examiner]
US 20220277097A1 · Cabot · 2022 [cited by examiner]
US 20230085509A1 · Noel · 2023 [cited by examiner]
US 20230186311A1 · Vimal · 2023 [cited by examiner]
US 20230205509A1 · Baral · 2023 [cited by examiner]
WO WO2023283357A1 · 2023 [cited by examiner]
Ismet Burak Kadron, Chaofan Shou, Emily O'Mahony, Yilmaz Vural, Tevfik Bultan; “Targeted Black-Box Side-Channel Mitigation for IoT”; IoT '22: Proceedings of the 12th International Conference on the Internet of Things; A… [cited by examiner]
Beck et al.; “Using Neural Networks to Aid CVSS Risk Aggregation—an Empirically Validated Approach”; Journal of Innovation in Digital Ecosystems, 3(2):148-154, 2016. [cited by applicant]
Deb et al.; A Fast and Elitist Multiobjective Genetic Algorithm: NSGA-II; IEEE Transactions on Evolutionary Computation, 6(2):182-197, 2002. [cited by applicant]
Farris et al.; “Vulcon: A System for Vulnerability Prioritization, Mitigation, and Management”; ACM Transactions on Privacy and Security (TOPS), 21(4):1-28, 2018. [cited by applicant]
Jiang et al.; “Vrank: A Context-Aware Approach to Vulnerability Scoring and Ranking in SOA”; In 2012 IEEE Sixth International Conference on Software Security and Reliability, pp. 61-70. IEEE, 2012. [cited by applicant]
Le et al.; “A Survey on Data-Driven Software Vulnerability Assessment and Prioritization”; arXiv preprint arXiv:2107.08364, 2021. [cited by applicant]
Lin, Shili; “Rank Aggregation Methods”; Wiley Interdisciplinary Reviews: Computational Statistics, 2(5):555-570, 2010. [cited by applicant]
Panichella, Annibale; “An Adaptive Evolutionary Algorithm Based on Non-Euclidean Geometry for Many-Objective Optimization”; In Proceedings of the Genetic and Evolutionary Computation Conference, pp. 595-603, 2019. [cited by applicant]
Roijers et al.; “Multi-Objective Decision Making”; Synthesis Lectures on Artificial Intelligence and Machine earning, 11(1):1-129, 2017. [cited by applicant]
Singh et al.; “Quantifying Security Risk by Critical Network Vulnerabilities Assessment”; International Journal of Computer Applications, 156(13):26-33, 2016. [cited by applicant]
Spanos et al.; “WIVSS: a New Methodology for Scoring Information Systems Vulnerabilities”; In Proceedings of the 17th Pan-Hellenic Conference on Informatics, pp. 83-90, 2013. [cited by applicant]
Tripwire. “Tripwire 2019 Vulnerability Management Survey”; 2019. URL https://www.tripwire. com/state-of-security/wp-content/uploads/sites/3/ Tripwire-Dimensional-Research-VM-Survey.pdf. [cited by applicant]
Viduto et al.; “A Novel Risk Assessment and Optimisation Model for a Multi-Objective Network Security Countermeasure Selection Problem”; Decision Support Systems, 53(3):599-610, 2012. [cited by applicant]
Wang et al.; “Ranking Attacks Based on Vulnerability Analysis”; In 2010 43rd Hawaii International Conference on System Sciences, pp. 1-10. IEEE, 2010. [cited by applicant]
Yin et al.; “Apply Transfer Learning to Cybersecurity: Predicting Exploitability of Vulnerabilities by Dscription”; Knowledge-Based Systems, 210:106529, 2020. [cited by applicant]
Colombelli et al., “Multi-Objective Prioritization for Data Center Vulnerability Remediation,” 2022 IEEE Congress on Evolutionary Computation (CEC), Padua, Italy, 01-08, (2022). [cited by applicant]
“What is an Attack Vector? Understand How Hackers Exploit Attack Surfaces and the Common Types of Attack Vectors”; 2025 Cyber Threat Predictions; https://www.fortinet.com/resources/cyberglossary/attack-vector; downloade… [cited by applicant]