IP Library Granted Patent US 12,438,900
Granted Patent B2
US 12,438,900 · App. 18/425,764 · Granted Oct 7, 2025

Risk-based vulnerability remediation timeframe recommendations

Inventors: Michael Roytman (Chicago, IL); Edward T. Bellis (Evanston, IL); Jason Rolleston (San Jose, CA)
Assignee: Kenna Security LLC
H04L63/1433H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,900
App. No.
18/425,764
Granted
Oct 7, 2025
Kind
B2
Abstract

Systems and methods for computing times to remediate for asset vulnerabilities are described herein. In an embodiment, a server computer receives first vulnerability data for a plurality of entities identifying asset vulnerabilities and timing data corresponding to the vulnerability data indicating an amount of time between identification of an asset vulnerability and a result of the asset vulnerability. The server computer identifies a strict subset of the first vulnerability data that belongs to a particular category of a first plurality of categories. The server computer receives second vulnerability data for a particular entity identifying asset vulnerabilities. The server computer identifies a strict subset of the second vulnerability data the belongs to the particular category. Based, at least in part, on the strict subset of the first vulnerability data, the server computer computes a time to remediate the asset vulnerabilities in the strict subset of the second vulnerability data.

Claims (70)

1. A network component comprising one or more processors and one or more computer-readable non-transitory storage media coupled to the one or more processors and including instructions that, when executed by the one or more processors, cause the network component to perform operations comprising:

receiving first vulnerability data identifying first asset vulnerabilities and timing data, wherein the timing data indicates an amount of time between identification of an asset vulnerability and a result of the asset vulnerability;

receiving second vulnerability data identifying second asset vulnerabilities;

configuring a plurality of options for configuring computation times to remediate the second asset vulnerabilities based at least in part on the first vulnerability data, wherein each option of the plurality of options is associated with a different set of metrics;

receiving an option from the plurality of options;

computing the time to remediate the second asset vulnerabilities based at least in part on the first vulnerability data and the set of metrics associated with the option; and

implementing a remediation in response to computing the time to remediate the second asset vulnerabilities.

2. The network component of claim 1 , wherein the first asset vulnerabilities represent resolved asset vulnerabilities.

3. The network component of claim 1 , wherein the result of the asset vulnerability comprises use of the asset vulnerability in an attack.

4. The network component of claim 1 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

5. The network component of claim 1 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing a particular fraction of an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

6. The network component of claim 1 , wherein:

the first vulnerability data belongs to a particular category of a plurality of categories; and

the second vulnerability data belongs to the particular category of the plurality of categories.

7. The network component of claim 6 , wherein the plurality of categories comprises categories that are determined based on one or more parameters from the following list of parameters:

a risk score;

a priority level;

a device type;

a network access level;

a likelihood of exploitation of an asset vulnerability;

a type of asset vulnerability, and

a software type.

8. A method, comprising:

receiving first vulnerability data identifying first asset vulnerabilities and timing data, wherein the timing data indicates an amount of time between identification of an asset vulnerability and a result of the asset vulnerability;

receiving second vulnerability data identifying second asset vulnerabilities;

configuring a plurality of options for configuring computation times to remediate the second asset vulnerabilities based at least in part on the first vulnerability data, wherein each option of the plurality of options is associated with a different set of metrics;

receiving an option from the plurality of options;

computing the time to remediate the second asset vulnerabilities based at least in part on the first vulnerability data and the set of metrics associated with the option; and

implementing a remediation in response to computing the time to remediate the second asset vulnerabilities.

9. The method of claim 8 , wherein the first asset vulnerabilities represent resolved asset vulnerabilities.

10. The method of claim 8 , wherein the result of the asset vulnerability comprises use of the asset vulnerability in an attack.

11. The method of claim 8 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

12. The method of claim 8 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing a particular fraction of an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

13. The method of claim 8 , wherein:

the first vulnerability data belongs to a particular category of a plurality of categories; and

the second vulnerability data belongs to the particular category of the plurality of categories.

14. The method of claim 13 , wherein the plurality of categories comprises categories that are determined based on one or more parameters from the following list of parameters:

a risk score;

a priority level;

a device type;

a network access level;

a likelihood of exploitation of an asset vulnerability;

a type of asset vulnerability, and

a software type.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving first vulnerability data identifying first asset vulnerabilities and timing data, wherein the timing data indicates an amount of time between identification of an asset vulnerability and a result of the asset vulnerability;

receiving second vulnerability data identifying second asset vulnerabilities;

configuring a plurality of options for configuring computation times to remediate the second asset vulnerabilities based at least in part on the first vulnerability data, wherein each option of the plurality of options is associated with a different set of metrics;

receiving an option from the plurality of options;

computing the time to remediate the second asset vulnerabilities based at least in part on the first vulnerability data and the set of metrics associated with the option; and

implementing a remediation in response to computing the time to remediate the second asset vulnerabilities.

16. The one or more computer-readable non-transitory storage media of claim 15 , wherein the first asset vulnerabilities represent resolved asset vulnerabilities.

17. The one or more computer-readable non-transitory storage media of claim 15 , wherein the result of the asset vulnerability comprises use of the asset vulnerability in an attack.

18. The one or more computer-readable non-transitory storage media of claim 15 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

19. The one or more computer-readable non-transitory storage media of claim 15 , wherein:

the result of the asset vulnerability comprises remediation of the asset vulnerability; and

computing the time to remediate comprises computing a particular fraction of an average of the amount of time between the identification of the asset vulnerability and the remediation of the asset vulnerability for each of the first asset vulnerabilities.

20. The one or more computer-readable non-transitory storage media of claim 15 , wherein:

the first vulnerability data belongs to a particular category of a plurality of categories; and

the second vulnerability data belongs to the particular category of the plurality of categories.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2026
From: KENNA SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 074392/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2024
From: ROYTMAN, MICHAEL; BELLIS, EDWARD T.; ROLLESTON, JASON
To: KENNA SECURITY, INC.
Reel/Frame 066288/0869 →
CHANGE OF NAME Recorded Jan 30, 2024
From: KENNA SECURITY, INC.
To: KENNA SECURITY LLC
Reel/Frame 066379/0101 →
Continuity (3)
Continuation 17241952 · Apr 27, 2021
Provisional Application 63016187 · Apr 27, 2020
Related Publication 20240171603A1 · May 23, 2024
References Cited (49)
US 8966639B1 · Roytman et al. · 2015 [cited by applicant]
US 10050999B1 · Rossman · 2018 [cited by examiner]
US 10410158B1 · Yumer et al. · 2019 [cited by applicant]
US 10735451B1 · Baker · 2020 [cited by examiner]
US 11470106B1 · Lin · 2022 [cited by examiner]
US 11503064B1 · Aloisio · 2022 [cited by examiner]
US 11611590B1 · Amar · 2023 [cited by examiner]
US 20090024663A1 · McGovern · 2009 [cited by examiner]
US 20150237062A1 · Roytman et al. · 2015 [cited by applicant]
US 20150237065A1 · Roytman et al. · 2015 [cited by applicant]
US 20160255115A1 · Mital et al. · 2016 [cited by applicant]
US 20170061132A1 · Hovor et al. · 2017 [cited by applicant]
US 20180351987A1 · Patel et al. · 2018 [cited by applicant]
US 20190166155A1 · Steele · 2019 [cited by examiner]
US 20190245881A1 · Ward et al. · 2019 [cited by applicant]
US 20190289029A1 · Chawla et al. · 2019 [cited by applicant]
US 20190362078A1 · Inagaki et al. · 2019 [cited by applicant]
US 20200162497A1 · Iyer et al. · 2020 [cited by applicant]
US 20200236129A1 · Barkovic · 2020 [cited by examiner]
US 20200311630A1 · Risoldi · 2020 [cited by examiner]
US 20200366706A1 · Sexton et al. · 2020 [cited by applicant]
US 20210019135A1 · Hwang et al. · 2021 [cited by applicant]
US 20210111966A1 · Qaadri · 2021 [cited by examiner]
US 20210203673A1 · Dos Santos et al. · 2021 [cited by applicant]
US 20210243217A1 · Stelmar Netto et al. · 2021 [cited by applicant]
US 20210258335A1 · DeFelice · 2021 [cited by examiner]
US 20210297441A1 · Olalere · 2021 [cited by examiner]
US 20220035929A1 · Hicks et al. · 2022 [cited by applicant]
US 20220247776A1 · Hecht · 2022 [cited by examiner]
US 20220255926A1 · Crabtree · 2022 [cited by examiner]
US 20220263845A1 · Crabtree · 2022 [cited by examiner]
US 20220263852A1 · Crabtree · 2022 [cited by examiner]
US 20220272118A1 · Trivellato · 2022 [cited by examiner]
US 20220277078A1 · Tyagi · 2022 [cited by examiner]
US 20220294810A1 · Tyagi · 2022 [cited by examiner]
US 20220303304A1 · Gupta · 2022 [cited by examiner]
US 20220321595A1 · Colquhoun · 2022 [cited by examiner]
US 20220329616A1 · O'Hearn · 2022 [cited by examiner]
US 20220368702A1 · Robbins · 2022 [cited by examiner]
US 20220368717A1 · Mylavarapu · 2022 [cited by examiner]
US 20220377093A1 · Crabtree · 2022 [cited by examiner]
US 20220400130A1 · Kapoor et al. · 2022 [cited by applicant]
US 20230004468A1 · Hicks · 2023 [cited by examiner]
US 20230008173A1 · Crabtree · 2023 [cited by examiner]
US 20230019941A1 · Doyle · 2023 [cited by examiner]
US 20230033317A1 · Lin · 2023 [cited by examiner]
US 20230070546A1 · Mosby · 2023 [cited by examiner]
US 20230075355A1 · Twigg · 2023 [cited by examiner]
US 20230118388A1 · Crabtree · 2023 [cited by examiner]