System and method for selective management of vulnerabilities
Methods and systems for managing vulnerabilities that may be exhibited by data processing systems are disclosed. The vulnerabilities may be managed by identifying components of the data processing systems and conditions impacting the data processing systems. The conditions may be used to establish a hierarchy for the vulnerabilities. Remediation for the vulnerabilities may be selectively performed based on the locations of the vulnerabilities within the hierarchy.
1 . A method for managing deployments, the method being performed by a deployment manager and comprising:
identifying an infrastructure of the deployments for vulnerability analysis;
identifying components of the infrastructure;
identifying conditionally exploitable vulnerabilities based on the components;
identifying conditions of the infrastructure based on the conditionally exploitable vulnerabilities for the components;
classifying the conditionally exploitable vulnerabilities based on the conditions of the infrastructure to obtain an exploitable vulnerabilities hierarchy for the infrastructure by adding each conditionally exploitable vulnerability of the conditionally exploitable vulnerabilities to one of three groups, the three groups comprising:
exploitable vulnerabilities exhibited by the infrastructure;
potentially exploitable vulnerabilities exhibited by the infrastructure; and
unexploitable vulnerabilities exhibited by the infrastructure; and
performing, using the deployments, a remediation for the infrastructure based on the exploitable vulnerabilities hierarchy, wherein the remediation is performed based on the exploitable vulnerabilities hierarchy for the deployment manager to exclude performance of one or more actions that waste limited computing resources of the deployments and the deployment manager as a result of the one or more actions being determined by the deployment manager, via using the exploitable vulnerabilities hierarchy and information available for use by the deployment manager during the classifying, as being unlikely to prevent at least one of the conditionally exploitable vulnerabilities within the exploitable vulnerabilities hierarchy from being exploited,
wherein the one or more actions that are excluded for the remediation are associated with at least the conditionally exploitable vulnerabilities classified as the unexploitable vulnerabilities exhibited by the infrastructure,
wherein a level of risk tolerance, for the infrastructure of the deployments, specifies one or more of the three groups that an entity associated with the infrastructure is willing to tolerate from being exploited, and
wherein the deployment manager determines a number of actions to be executed in the remediation based on the level of the risk tolerance.
2 . The method of claim 1 , wherein the conditionally exploitable vulnerabilities are vulnerabilities presented by the components when corresponding conditions are met.
3 . The method of claim 2 , wherein the corresponding conditions comprise at least one selected from a group consisting of:
a version of one of the components of the infrastructure;
presence of a type of a component of the infrastructure;
presence of a type of user environment of the infrastructure;
presence of a version of a user environment of the infrastructure; and
presence of a collection of types of components of the infrastructure.
4 . The method of claim 1 , wherein the deployment manager determines the one or more actions to be excluded from being performed as part of the remediation for the infrastructure based further on the level of the risk tolerance that is assigned for the infrastructure of the deployments.
5 . The method of claim 1 , wherein a first portion of the number of actions comprises all remediation actions associated with conditionally exploitable vulnerabilities in a first group of the three groups.
6 . The method of claim 5 , wherein, as available computing resources allow, a remaining portion of the number of actions, separate from the first portion, comprises remediation actions associated with conditionally exploitable vulnerabilities in a second group of the three groups.
7 . The method of claim 6 , wherein one or more of the remediation actions included in the number of actions is selected based on computing resource limitations of another entity that participates in the remediation, the another entity being separate from the infrastructure.
8 . The method of claim 1 , wherein the conditionally exploitable vulnerabilities that are grouped in the exploitable vulnerabilities group of the three groups are known to be exploitable.
9 . The method of claim 1 , wherein the conditionally exploitable vulnerabilities that are grouped in the potentially exploitable vulnerabilities group of the three groups are vulnerabilities that are neither known to be exploitable nor known to not be exploitable based at least on the information available for use by the deployment manager during the classifying.
10 . The method of claim 9 , wherein the conditionally exploitable vulnerabilities are grouped in the potentially exploitable vulnerabilities group of the three groups due to lack of information regarding the conditions of the infrastructure necessary for a definitive determination regarding exploitability.
11 . The method of claim 1 , wherein the conditionally exploitable vulnerabilities that are grouped in the unexploitable vulnerabilities group of the three groups are vulnerabilities that are previously known to be unexploitable based at least on the information available for use by the deployment manager during the classifying.
12 . A non-transitory machine-readable medium having instructions stored therein, which when executed by a processor, cause the processor to perform operations for managing deployments, the operations comprising:
identifying an infrastructure of the deployments for vulnerability analysis;
identifying components of the infrastructure;
identifying conditionally exploitable vulnerabilities based on the components;
identifying conditions of the infrastructure based on the conditionally exploitable vulnerabilities for the components;
classifying the conditionally exploitable vulnerabilities based on the conditions of the infrastructure to obtain an exploitable vulnerabilities hierarchy for the infrastructure by adding each conditionally exploitable vulnerability of the conditionally exploitable vulnerabilities to one of three groups, the three groups consisting of:
exploitable vulnerabilities exhibited by the infrastructure;
potentially exploitable vulnerabilities exhibited by the infrastructure; and
unexploitable vulnerabilities exhibited by the infrastructure; and
performing, using the deployments, a remediation for the infrastructure based on the exploitable vulnerabilities hierarchy, wherein the remediation is performed based on the exploitable vulnerabilities hierarchy for the deployment manager to exclude performance of one or more actions that waste limited computing resources of the deployments and the deployment manager as a result of the one or more actions being determined by the deployment manager, via using the exploitable vulnerabilities hierarchy and information available for use by the deployment manager during the classifying, as being unlikely to prevent at least one of the conditionally exploitable vulnerabilities within the exploitable vulnerabilities hierarchy from being exploited,
wherein the one or more actions that are excluded for the remediation are associated with at least the conditionally exploitable vulnerabilities classified as the unexploitable vulnerabilities exhibited by the infrastructure,
wherein a level of risk tolerance, for the infrastructure of the deployments, specifies one or more of the three groups that an entity associated with the infrastructure is willing to tolerate from being exploited, and
wherein the deployment manager determines a number of actions to be executed in the remediation based on the level of the risk tolerance.
13 . The non-transitory machine-readable medium of claim 12 , wherein the conditionally exploitable vulnerabilities are vulnerabilities presented by the components when corresponding conditions are met.
14 . The non-transitory machine-readable medium of claim 13 , wherein the corresponding conditions comprise at least one selected from a group consisting of:
a version of one of the components of the infrastructure;
presence of a type of a component of the infrastructure;
presence of a type of user environment of the infrastructure;
presence of a version of a user environment of the infrastructure; and
presence of a collection of types of components of the infrastructure.
15 . The non-transitory machine-readable medium of claim 12 , wherein the conditionally exploitable vulnerabilities that are grouped in the exploitable vulnerabilities group of the three groups are known to be exploitable.
16 . The non-transitory machine-readable medium of claim 12 , wherein the conditionally exploitable vulnerabilities that are grouped in the potentially exploitable vulnerabilities group of the three groups are vulnerabilities that are neither known to be exploitable nor known to not be exploitable based at least on the information available for use by the deployment manager during the classifying.
17 . The non-transitory machine-readable medium of claim 16 , wherein the conditionally exploitable vulnerabilities are grouped in the potentially exploitable vulnerabilities group of the three groups due to lack of information regarding the conditions of the infrastructure necessary for a definitive determination regarding exploitability.
18 . The non-transitory machine-readable medium of claim 12 , wherein the conditionally exploitable vulnerabilities that are grouped in the unexploitable vulnerabilities group of the three groups are vulnerabilities that are previously known to be unexploitable based at least on the information available for use by the deployment manager during the classifying.
19 . A deployment manager for deployments, comprising:
a processor; and
a memory coupled to the processor to store instructions, which when executed by the processor, cause the processor to perform operations for managing the deployment, the operations comprising:
identifying an infrastructure of the deployments for vulnerability analysis;
identifying components of the infrastructure;
identifying conditionally exploitable vulnerabilities based on the components;
identifying conditions of the infrastructure based on the conditionally exploitable vulnerabilities for the components;
classifying the conditionally exploitable vulnerabilities based on the conditions of the infrastructure to obtain an exploitable vulnerabilities hierarchy for the infrastructure by adding each conditionally exploitable vulnerability of the conditionally exploitable vulnerabilities to one of three groups, the three groups comprising:
exploitable vulnerabilities exhibited by the infrastructure;
potentially exploitable vulnerabilities exhibited by the infrastructure; and
unexploitable vulnerabilities exhibited by the infrastructure; and
performing, using the deployments, a remediation for the infrastructure based on the exploitable vulnerabilities hierarchy, wherein the remediation is performed based on the exploitable vulnerabilities hierarchy for the deployment manager to exclude performance of one or more actions that waste limited computing resources of the deployments and the deployment manager as a result of the one or more actions being determined by the deployment manager, via using the exploitable vulnerabilities hierarchy and information available for use by the deployment manager during the classifying, as being unlikely to prevent at least one of the conditionally exploitable vulnerabilities within the exploitable vulnerabilities hierarchy from being exploited,
wherein the one or more actions that are excluded for the remediation are associated with at least the conditionally exploitable vulnerabilities classified as the unexploitable vulnerabilities exhibited by the infrastructure,
wherein a level of risk tolerance, for the infrastructure of the deployments, specifies one or more of the three groups that an entity associated with the infrastructure is willing to tolerate from being exploited, and
wherein the deployment manager determines a number of actions to be executed in the remediation based on the level of the risk tolerance.
20 . The deployment manager of claim 19 , wherein the conditionally exploitable vulnerabilities are vulnerabilities presented by the components when corresponding conditions are met.