IP Library › Granted Patent US 12,554,859
Granted Patent B2
US 12,554,859 · App. 18/342,441 · Granted Feb 17, 2026

Generating 3-dimensional models and connections to provide vulnerability context

Inventors: Nikki Elyse Robinson (Davidsonville, MD); Dimple Gajra (Austin, TX); Caroline Chen Lee (Watertown, MA)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/577G06F30/10G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,554,859
App. No.
18/342,441
Granted
Feb 17, 2026
Kind
B2
Abstract

Provided are techniques for generating 3-dimensional (3D) models and connections to provide vulnerability context. For a first vulnerability of a first asset, first vulnerability data comprising first vulnerability attributes is retrieved. A second vulnerability of a second asset is identified based on the second vulnerability having second vulnerability data comprising second vulnerability attributes that include one or more common vulnerability attributes with the first vulnerability attributes. Anchor points for the first vulnerability and the second vulnerability are created based on the one or more common vulnerability attributes. A first 3-dimensional (3D) model is generated for the first vulnerability that incorporates the first vulnerability attributes, and a second 3D model is generated for the second vulnerability that incorporates the second vulnerability attributes. The first 3D model and the second 3D model are displayed with one or more connections based on the anchor points.

Claims (43)

1 . A computer-implemented method, comprising operations for:

for a first vulnerability of a first asset, retrieving first vulnerability attributes including a first score for the first vulnerability;

determining one or more common vulnerability attributes between the first vulnerability attributes of the first vulnerability and second vulnerability attributes of a second vulnerability of a second asset including a second score for the second vulnerability using stored vulnerability data;

creating anchor points for the first vulnerability and the second vulnerability based on the one or more common vulnerability attributes;

generating a first 3-dimensional (3D) model for the first vulnerability that incorporates the first vulnerability attributes of the first vulnerability using the anchor points;

generating a second 3D model for the second vulnerability that incorporates the second vulnerability attributes of the second vulnerability using the anchor points;

displaying, in a vulnerability dashboard, the first 3D model and the second 3D model with one or more connections between the anchor points and with the first vulnerability attributes and the second vulnerability attributes; and

in response to receiving input, modifying the displaying of the first 3D model and the second 3D model by moving one of the first 3D model and the second 3D model individually in the vulnerability dashboard.

2 . The computer-implemented method of claim 1 , wherein the first vulnerability attributes and the second vulnerability attributes each include at least one vulnerability attribute selected from a group consisting of: a type of vulnerability, the vulnerability score, a vulnerability source, systems affected, an owner, a vulnerability impact, a patch, a publish date, and remediation actions to take.

3 . The computer-implemented method of claim 1 , wherein the first 3D model incorporating the first vulnerability attributes includes a geometric dimension corresponding to each of the first vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding first vulnerability attribute.

4 . The computer-implemented method of claim 1 , wherein the second 3D model incorporating the second vulnerability attributes includes a geometric dimension corresponding to each of the second vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding second vulnerability attribute.

5 . The computer-implemented method of claim 1 , wherein moving at least one of the first 3D model and the second 3D model individually in the vulnerability dashboard comprises individually rotating or individually repositioning.

6 . The computer-implemented method of claim 1 , wherein a third 3D model is generated for a plurality of vulnerabilities.

7 . The computer-implemented method of claim 1 , wherein the first asset and the second asset are each selected from a group consisting of: a hardware asset and a software asset.

8 . A computer program product, the computer program product comprising a computer readable storage medium having program instructions embodied therewith, the program instructions executable by a processor to cause the processor to perform operations for:

for a first vulnerability of a first asset, retrieving first vulnerability attributes including a first score for the first vulnerability;

determining one or more common vulnerability attributes between the first vulnerability attributes of the first vulnerability and second vulnerability attributes of a second vulnerability of a second asset including a second score for the second vulnerability using stored vulnerability data;

creating anchor points for the first vulnerability and the second vulnerability based on the one or more common vulnerability attributes;

generating a first 3-dimensional (3D) model for the first vulnerability that incorporates the first vulnerability attributes of the first vulnerability using the anchor points;

generating a second 3D model for the second vulnerability that incorporates the second vulnerability attributes of the second vulnerability using the anchor points;

displaying, in a vulnerability dashboard, the first 3D model and the second 3D model with one or more connections between the anchor points and with the first vulnerability attributes and the second vulnerability attributes; and

in response to receiving input, modifying the displaying of the first 3D model and the second 3D model by moving one of the first 3D model and the second 3D model individually in the vulnerability dashboard.

9 . The computer program product of claim 8 , wherein the first vulnerability attributes and the second vulnerability attributes each include at least one vulnerability attribute selected from a group consisting of: a type of vulnerability, the vulnerability score, a vulnerability source, systems affected, an owner, a vulnerability impact, a patch, a publish date, and remediation actions to take.

10 . The computer program product of claim 8 , wherein the first 3D model incorporating the first vulnerability attributes includes a geometric dimension corresponding to each of the first vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding first vulnerability attribute.

11 . The computer program product of claim 8 , wherein the second 3D model incorporating the second vulnerability attributes includes a geometric dimension corresponding to each of the second vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding second vulnerability attribute.

12 . The computer program product of claim 8 , wherein moving at least one of the first 3D model and the second 3D model individually in the vulnerability dashboard comprises individually rotating or individually repositioning.

13 . The computer program product of claim 8 , wherein a third 3D model is generated for a plurality of vulnerabilities.

14 . The computer program product of claim 8 , wherein the first asset and the second asset are each selected from a group consisting of: a hardware asset and a software asset.

15 . A computer system, comprising:

one or more processors, one or more computer-readable memories and one or more computer-readable, tangible storage devices; and

program instructions, stored on at least one of the one or more computer-readable, tangible storage devices for execution by at least one of the one or more processors via at least one of the one or more computer-readable memories, to perform operations comprising:

for a first vulnerability of a first asset, retrieving first vulnerability attributes including a first score for the first vulnerability;

determining one or more common vulnerability attributes between the first vulnerability attributes of the first vulnerability and second vulnerability attributes of a second vulnerability of a second asset including a second score for the second vulnerability using stored vulnerability data;

creating anchor points for the first vulnerability and the second vulnerability based on the one or more common vulnerability attributes;

generating a first 3-dimensional (3D) model for the first vulnerability that incorporates the first vulnerability attributes of the first vulnerability using the anchor points;

generating a second 3D model for the second vulnerability that incorporates the second vulnerability attributes of the second vulnerability using the anchor points;

displaying, in a vulnerability dashboard, the first 3D model and the second 3D model with one or more connections between the anchor points and with the first vulnerability attributes and the second vulnerability attributes; and

in response to receiving input, modifying the displaying of the first 3D model and the second 3D model by moving one of the first 3D model and the second 3D model individually in the vulnerability dashboard.

16 . The computer system of claim 15 , wherein the first vulnerability attributes and the second vulnerability attributes each include at least one vulnerability attribute selected from a group consisting of: a type of vulnerability, the vulnerability score, a vulnerability source, systems affected, an owner, a vulnerability impact, a patch, a publish date, and remediation actions to take.

17 . The computer system of claim 15 , wherein the first 3D model incorporating the first vulnerability attributes includes a geometric dimension corresponding to each of the first vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding first vulnerability attribute.

18 . The computer system of claim 15 , wherein the second 3D model incorporating the second vulnerability attributes includes a geometric dimension corresponding to each of the second vulnerability attributes, and wherein a magnitude of each geometric dimension depends on the magnitude of the corresponding second vulnerability attribute.

19 . The computer system of claim 15 , wherein moving at least one of the first 3D model and the second 3D model individually in the vulnerability dashboard comprises individually rotating or individually repositioning.

20 . The computer system of claim 15 , wherein a third 3D model is generated for a plurality of vulnerabilities.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2023
From: ROBINSON, NIKKI ELYSE; GAJRA, DIMPLE; LEE, CAROLINE CHEN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 064086/0822 →
Continuity (1)
Related Publication 20250005165A1 · Jan 2, 2025
References Cited (29)
US 10592405B2 · Duer et al. · 2020 [cited by applicant]
US 20110277034A1 · Hanson · 2011 [cited by examiner]
US 20170098087A1 · Li · 2017 [cited by examiner]
US 20190166149A1 · Gerrick · 2019 [cited by applicant]
US 20210240496A1 · Hamdi · 2021 [cited by examiner]
US 20210240591A1 · Hamdi · 2021 [cited by examiner]
US 20210243223A1 · Arora et al. · 2021 [cited by applicant]
US 20220131887A1 · Ngweta · 2022 [cited by examiner]
US 20220237764A1 · Mullet · 2022 [cited by examiner]
US 20220345483A1 · Shua · 2022 [cited by examiner]
US 20230300165A1 · Fricano · 2023 [cited by examiner]
US 20250023714A1 · Kumar · 2025 [cited by examiner]
CN 103699787A · 2014 [cited by applicant]
CN 106097299A · 2016 [cited by applicant]
CN 104156507B · 2017 [cited by applicant]
CN 104881606B · 2017 [cited by applicant]
CN 106897510B · 2020 [cited by applicant]
CN 114529676A · 2022 [cited by applicant]
CN 113259334B · 2022 [cited by applicant]
JP 2015219665A · 2015 [cited by applicant]
“10 + Best Software for AR and VR Design in 2023”, Just Creative, Mar. 30, 2023, 23 pp., [online][retrieved May 8, 2023] https://justcreative.com/best-software-for-ar-and-vr-design/. [cited by applicant]
“Designing VR & AR simplified”, Tvori, 9 pp., [online][retrieved May 8, 2023] https://tvori.co/tvori. [cited by applicant]
“Unlock your Creativity”, Unity, 12 pp., [online][retrieved May 8, 2023] https://unity.com/download. [cited by applicant]
“Augmented Reality it's everything you imagined”, Adobe, 14 pp., [online][retrieved May 30, 2023]https://www.adobe.com/in/products/aero.html?clickref=1100lwiimkAb&mv=affiliate&mv2=pz&as_camptype=adobeaero&as_channel=aff… [cited by applicant]
“Develop AR Experiences with Vuforia Engine”, PTC Products, 6 pp., [online][retrieved May 8, 2023] https://www.ptc.com/en/products/vuforia/vuforia-engine. [cited by applicant]
“Painting from a new perspective”, Google, 12 pp., [online][retrieved May 8, 2023] https://www.tiltbrush.com. [cited by applicant]
“Common Vulnerabilities and Exposures”, Wikipedia, 6 pp., [online][retrieved Jun. 8, 2023] https://en.wikipedia.org/wiki/Common_Vulnerabilities_and_Exposures. [cited by applicant]
“Geometeric Dimensioning and talerancing”, Wikipedia, 6 pp., [online][retrieved Jun. 7, 2023] https://en.wikipedia.org/wiki/Geometric_dimensioning_and_tolerancing. [cited by applicant]
“Process”, CVE, 3 pp., [online][retrieved Jun. 8, 2023] https://www.cve.org/About/Process. [cited by applicant]