IP Library Granted Patent US 12,335,295
Granted Patent B2
US 12,335,295 · App. 18/302,274 · Granted Jun 17, 2025

System and method for management of system vulnerabilities

Inventors: Tomer Shachar (Beer Sheva, IL); Maxim Balin (Gan-Yavne, IL); Yevgeni Gehtman (Modi'in, IL)
Assignee: Dell Products L.P.
H04L63/1433H04L41/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,335,295
App. No.
18/302,274
Granted
Jun 17, 2025
Kind
B2
Abstract

Methods and systems for managing vulnerabilities presented by data processing systems are disclosed. The vulnerabilities may be managed by identifying components of the data processing systems using different processes depending on the computing resource availabilities of the data processing systems. Once identified, corresponding vulnerabilities for the components may be identified. The identified vulnerabilities may then be managed by performing various actions.

Claims (101)

1. A method for managing deployments, the method comprising:

identifying infrastructure of a deployment for vulnerability analysis;

identifying computing resource availability for the infrastructure;

making a determination, based on the computing resource availability, whether to perform an infrastructure based component analysis for the infrastructure that consumes at least a portion of computing resources of the infrastructure;

in a first instance of the determination where the infrastructure based component analysis is to be performed:

performing the infrastructure based component analysis of the infrastructure to obtain a first component inventory for the infrastructure;

performing the vulnerability analysis using the first component inventory to identify a first at least one vulnerability;

performing a remediation for the infrastructure based on the first at least one vulnerability;

in a second instance of the determination where the infrastructure based component analysis is not to be performed:

performing a historic component analysis of the infrastructure to obtain a second component inventory for the infrastructure, the historic component analysis not consuming any computing resources of the infrastructure;

performing the vulnerability analysis using the second component inventory to identify a second at least one vulnerability; and

performing a remediation for the infrastructure based on the second at least one vulnerability.

2. The method of claim 1 , wherein identifying the computing resource availability for the infrastructure comprises:

identifying types of data processing systems of the infrastructure; and

matching the types of the data processing systems to corresponding quantities of computing resources to identify the computing resource availability.

3. The method of claim 2 , wherein making the determination comprises:

making a comparison between the computing resource availability and a computing resource availability threshold;

in a first instance of the comparison where the computing resource availability exceeds the computing resource availability threshold:

determining to perform the infrastructure based component analysis; and

in a second instance of the comparison where the computing resource availability does not exceed the computing resource availability threshold:

determining to not perform the infrastructure based component analysis.

4. The method of claim 1 , wherein performing the historic component analysis of the infrastructure to obtain the second component inventory for the infrastructure comprises:

obtaining a first component list for the infrastructure, the first component list being based on a design for the infrastructure prior to the infrastructure being deployed;

obtaining a second component list for the infrastructure, the second component list being based on an operator provided report for the infrastructure after the infrastructure being deployed; and

identifying a third component list for the infrastructure using the first component list and the second component list.

5. The method of claim 4 , wherein performing the infrastructure based component analysis of the infrastructure to obtain the first component inventory for the infrastructure comprises:

scanning data processing systems of the infrastructure to obtain a fourth component list.

6. The method of claim 5 , wherein scanning the data processing systems comprises:

sending instructions to the data processing systems of the infrastructure to initiate performance of a self-inventory by the data processing systems;

receiving copies of self-inventories from the data processing systems; and

obtaining the fourth component list using the self-inventories, each of the self-inventories specifying self-identified components of the data processing systems.

7. The method of claim 6 , wherein performing the vulnerability analysis using the second component inventory to identify a second at least one vulnerability comprises:

for each component specified by the third component list:

matching at least one of a type of the component, and a version of the component against vulnerabilities in a vulnerability repository to identify the second at least one vulnerability.

8. A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing deployments, the operations comprising:

identifying infrastructure of a deployment for vulnerability analysis;

identifying computing resource availability for the infrastructure;

making a determination, based on the computing resource availability, whether to perform an infrastructure based component analysis for the infrastructure that consumes at least a portion of computing resources of the infrastructure;

in a first instance of the determination where the infrastructure based component analysis is to be performed:

performing the infrastructure based component analysis of the infrastructure to obtain a first component inventory for the infrastructure;

performing the vulnerability analysis using the first component inventory to identify a first at least one vulnerability;

performing a remediation for the infrastructure based on the first at least one vulnerability;

in a second instance of the determination where the infrastructure based component analysis is not to be performed:

performing a historic component analysis of the infrastructure to obtain a second component inventory for the infrastructure, the historic component analysis not consuming any computing resources of the infrastructure;

performing the vulnerability analysis using the second component inventory to identify a second at least one vulnerability; and

performing a remediation for the infrastructure based on the second at least one vulnerability.

9. The non-transitory machine-readable medium of claim 8 , wherein identifying the computing resource availability for the infrastructure comprises:

identifying types of data processing systems of the infrastructure; and

matching the types of the data processing systems to corresponding quantities of computing resources to identify the computing resource availability.

10. The non-transitory machine-readable medium of claim 9 , wherein making the determination comprises:

making a comparison between the computing resource availability and a computing resource availability threshold;

in a first instance of the comparison where the computing resource availability exceeds the computing resource availability threshold:

determining to perform the infrastructure based component analysis; and

in a second instance of the comparison where the computing resource availability does not exceed the computing resource availability threshold:

determining to not perform the infrastructure based component analysis.

11. The non-transitory machine-readable medium of claim 8 , wherein performing the historic component analysis of the infrastructure to obtain the second component inventory for the infrastructure comprises:

obtaining a first component list for the infrastructure, the first component list being based on a design for the infrastructure prior to the infrastructure being deployed;

obtaining a second component list for the infrastructure, the second component list being based on an operator provided report for the infrastructure after the infrastructure being deployed; and

identifying a third component list for the infrastructure using the first component list and the second component list.

12. The non-transitory machine-readable medium of claim 11 , wherein performing the infrastructure based component analysis of the infrastructure to obtain the first component inventory for the infrastructure comprises:

scanning data processing systems of the infrastructure to obtain a fourth component list.

13. The non-transitory machine-readable medium of claim 12 , wherein scanning the data processing systems comprises:

sending instructions to the data processing systems of the infrastructure to initiate performance of a self-inventory by the data processing systems;

receiving copies of self-inventories from the data processing systems; and

obtaining the fourth component list using the self-inventories, each of the self-inventories specifying self-identified components of the data processing systems.

14. The non-transitory machine-readable medium of claim 13 , wherein performing the vulnerability analysis using the second component inventory to identify a second at least one vulnerability comprises:

for each component specified by the third component list:

matching at least one of a type of the component, and a version of the component against vulnerabilities in a vulnerability repository to identify the second at least one vulnerability.

15. A deployment manager, comprising:

a processor; and

a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing deployments, the operations comprising:

identifying infrastructure of a deployment for vulnerability analysis;

identifying computing resource availability for the infrastructure;

making a determination, based on the computing resource availability, whether to perform an infrastructure based component analysis for the infrastructure that consumes at least a portion of computing resources of the infrastructure;

in a first instance of the determination where the infrastructure based component analysis is to be performed:

performing the infrastructure based component analysis of the infrastructure to obtain a first component inventory for the infrastructure;

performing the vulnerability analysis using the first component inventory to identify a first at least one vulnerability;

performing a remediation for the infrastructure based on the first at least one vulnerability;

in a second instance of the determination where the infrastructure based component analysis is not to be performed:

performing a historic component analysis of the infrastructure to obtain a second component inventory for the infrastructure, the historic component analysis not consuming any computing resources of the infrastructure;

performing the vulnerability analysis using the second component inventory to identify a second at least one vulnerability; and

performing a remediation for the infrastructure based on the second at least one vulnerability.

16. The deployment manager of claim 15 , wherein identifying the computing resource availability for the infrastructure comprises:

identifying types of data processing systems of the infrastructure; and

matching the types of the data processing systems to corresponding quantities of computing resources to identify the computing resource availability.

17. The deployment manager of claim 16 , wherein making the determination comprises:

making a comparison between the computing resource availability and a computing resource availability threshold;

in a first instance of the comparison where the computing resource availability exceeds the computing resource availability threshold:

determining to perform the infrastructure based component analysis; and

in a second instance of the comparison where the computing resource availability does not exceed the computing resource availability threshold:

determining to not perform the infrastructure based component analysis.

18. The deployment manager of claim 17 , wherein performing the historic component analysis of the infrastructure to obtain the second component inventory for the infrastructure comprises:

obtaining a first component list for the infrastructure, the first component list being based on a design for the infrastructure prior to the infrastructure being deployed;

obtaining a second component list for the infrastructure, the second component list being based on an operator provided report for the infrastructure after the infrastructure being deployed; and

identifying a third component list for the infrastructure using the first component list and the second component list.

19. The deployment manager of claim 15 , wherein performing the infrastructure based component analysis of the infrastructure to obtain the first component inventory for the infrastructure comprises:

scanning data processing systems of the infrastructure to obtain a fourth component list.

20. The deployment manager of claim 19 , wherein scanning the data processing systems comprises:

sending instructions to the data processing systems of the infrastructure to initiate performance of a self-inventory by the data processing systems;

receiving copies of self-inventories from the data processing systems; and

obtaining the fourth component list using the self-inventories, each of the self-inventories specifying self-identified components of the data processing systems.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2023
From: SHACHAR, TOMER; BALIN, MAXIM; GEHTMAN, YEVGENI
To: DELL PRODUCTS L.P.
Reel/Frame 063533/0386 →
Continuity (1)
Related Publication 20240356953A1 · Oct 24, 2024
References Cited (31)
US 9098333B1 · Obrecht · 2015 [cited by examiner]
US 9137110B1 · Adogla · 2015 [cited by examiner]
US 9215158B1 · Adogla · 2015 [cited by examiner]
US 9619772B1 · Adogla · 2017 [cited by examiner]
US 11671486B1 · McCullagh · 2023 [cited by examiner]
US 11676087B2 · Hogg · 2023 [cited by examiner]
US 20060101520A1 · Schumaker · 2006 [cited by examiner]
US 20060191012A1 · Banzhof · 2006 [cited by examiner]
US 20100257132A1 · Collard · 2010 [cited by examiner]
US 20120304300A1 · LaBumbard · 2012 [cited by examiner]
US 20140006336A1 · Khan · 2014 [cited by examiner]
US 20140337982A1 · Crosby · 2014 [cited by examiner]
US 20170017795A1 · DiGiambattista · 2017 [cited by examiner]
US 20170147338A1 · Jackson · 2017 [cited by examiner]
US 20180068241A1 · Varkey · 2018 [cited by examiner]
US 20180196402A1 · Glaser · 2018 [cited by examiner]
US 20180336356A1 · Papaxenopoulos · 2018 [cited by examiner]
US 20180341519A1 · Vyas · 2018 [cited by examiner]
US 20180351987A1 · Patel · 2018 [cited by examiner]
US 20190250898A1 · Yang · 2019 [cited by examiner]
US 20190327324A1 · Buffone · 2019 [cited by examiner]
US 20190342324A1 · Nawy · 2019 [cited by examiner]
US 20190361466A1 · Obropta, Jr. · 2019 [cited by examiner]
US 20190384632A1 · Parikh · 2019 [cited by examiner]
US 20200012571A1 · Singhal · 2020 [cited by examiner]
US 20200019465A1 · Khan · 2020 [cited by examiner]
US 20210327018A1 · Carranza · 2021 [cited by examiner]
US 20240039927A1 · Narayan · 2024 [cited by examiner]
US 20240054230A1 · Bouchard · 2024 [cited by examiner]
US 20240134997A1 · Madala · 2024 [cited by examiner]
US 20240356953A1 · Shachar · 2024 [cited by examiner]