IP Library Granted Patent US 12,561,447
Granted Patent B2
US 12,561,447 · App. 18/686,224 · Granted Feb 24, 2026

Continuous vulnerability assessment system

Inventors: Michael Gorelik (Alpine, NJ); Dorel Yaffe (Kiryat Gat, IL)
Assignee: MORPHISEC INFORMATION SECURITY 2014 LTD.
G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,561,447
App. No.
18/686,224
Granted
Feb 24, 2026
Kind
B2
Abstract

The embodiments disclosed herein are directed to a continuous vulnerability assessment system for detecting exploitable vulnerabilities. For example, an agent executes on a plurality of computing devices. Each agent profiles various pieces of software executing on its respective device and obtains various characteristics thereof. For instance, each agent determines, among other things, the length of time certain software executes on the device. Each agent provides descriptors of the determined characteristics to a vulnerability assessment engine. The engine determines a cumulative length of time that each particular piece of software executed across the plurality of computing devices. The engine also determines whether a vulnerability exists with respect to each particular piece of software, assigns a security risk level for the software based at least on the determined vulnerability and the cumulative length of time, and performs an action to mitigate the determined vulnerability based on the security risk level.

Claims (80)

1 . A method performed by a first computing device, comprising:

receiving, from each of a plurality of second computing devices communicatively coupled to the first computing device:

a first characteristic descriptor indicating a length of time that an instance of a software application executed on the computing device; and

a second characteristic descriptor of the instance of the software application;

determining, based on a respective first characteristic descriptor received from each of the plurality of second computing devices, a cumulative length of time that the instances of the software application executed on the plurality of second computing devices in a predetermined time frame;

obtaining, based on the second characteristic descriptor, a vulnerability score for the instance of the software application, wherein the vulnerability score indicates that a vulnerability exists for the instance of the software application;

assigning a security risk level to the instances of the software application based at least on the vulnerability score and the cumulative length of time; and

performing an action to mitigate the determined vulnerability in accordance with the security risk level.

2 . The method of claim 1 , wherein the second characteristic descriptor of the instance of the software application specifies one or more properties of the instance of the software application.

3 . The method of claim 1 , further comprising:

for each of the plurality of second computing devices, receiving, from the second computing device a third characteristic descriptor specifying one or more configuration settings of the instance of the software application.

4 . The method of claim 3 , wherein assigning the security risk level is further based on the one or more configuration settings of the instances of the software application.

5 . The method of claim 3 , wherein the one or more configuration settings of the instance of the software application comprises at least one of:

one or more firewall settings of the instance of the software application;

one or more administrative settings of the instance of the software application; or

one or more encryption settings of the instance of the software application.

6 . The method of claim 1 , performing the action to mitigate the determined vulnerability in accordance with the security risk level comprises at least one of:

providing a notification specifying the security risk level for the instances of the software application;

displaying the security risk level for the instances of the software application via a user interface;

providing a first command to each of the plurality of second computing devices that causes an update to be installed for the instances of the software applications that patches the vulnerability;

providing a second command to each of the plurality of second computing devices that causes one or more configuration settings to be changed for the instances of the software application that mitigates the vulnerability; or

providing a third command to each of the plurality of second computing devices that causes the instances of the software applications to be uninstalled.

7 . The method of claim 1 , wherein assigning the security risk level is further based on at least one of:

a number of the plurality of second computing devices on which the instances of the software application executed;

a frequency at which the instances of the software application is executed on the plurality of second computing devices;

a device type of each of the plurality of second computing devices; or

a type of a user of each of the plurality of second computing devices.

8 . A system, comprising:

one or more processing units; and

a memory coupled to the one or more processing units, the memory storing program code for execution by the one or more processing units, the program code comprising:

a vulnerability assessment engine configured to:

receive, from each of a plurality of second computing devices communicatively coupled to the system:

a first characteristic descriptor indicating a length of time that an instance of a software application executed on the computing device; and

a second characteristic descriptor of the instance of the software application;

determine, based on a respective first characteristic descriptor received from each of the plurality of computing devices, a cumulative length of time that the instances of the software application executed on the plurality of computing devices in a predetermined time frame;

obtain, based on the second characteristic descriptor, a vulnerability score for the instance of the software application, wherein the vulnerability score indicates that a vulnerability exists for the instance of the software application;

assign a security risk level to the instances of the software application based at least on the vulnerability score and the cumulative length of time; and

perform an action to mitigate the determined vulnerability in accordance with the security risk level.

9 . The system of claim 8 , wherein the second characteristic descriptor of the instance of the software application specifies one or more properties of the instance of the software application.

10 . The system of claim 8 , wherein the vulnerability assessment engine is further configured to:

for each of the plurality of computing devices, receive, from the computing device a third characteristic descriptor specifying one or more configuration settings of the instance of the software application.

11 . The system of claim 10 , wherein the vulnerability assessment engine is further configured to assign the security risk level is based on the one or more configuration settings of the instances of the software application.

12 . The system of claim 10 , wherein the one or more configuration settings of the instance of the software application comprises at least one of:

one or more firewall settings of the instance of the software application;

one or more administrative settings of the instance of the software application; or

one or more encryption settings of the instance of the software application.

13 . The system of claim 8 , wherein the vulnerability assessment engine is configured to perform the action to mitigate the determined vulnerability in accordance with the security risk level by performing at least one of:

providing a notification specifying the security risk level for the instances of the software application;

displaying the security risk level for the instances of the software application via a user interface;

providing a first command to each of the plurality of computing devices that causes an update to be installed for the instances of the software applications that patches the vulnerability;

providing a second command to each of the plurality of computing devices that causes one or more configuration settings to be changed for the instances of the software application that mitigates the vulnerability; or

providing a third command to each of the plurality of computing devices that causes the instances of the software applications to be uninstalled.

14 . The system of claim 8 , wherein the vulnerability assessment engine is further configured to assign the security risk level based on at least one of:

a number of the plurality of computing devices on which the instances of the software application executed;

a frequency at which the instances of the software application is executed on the plurality of computing devices;

a device type of each of the plurality of computing devices; or

a type of a user of each of the plurality of computing devices.

15 . A computer-readable storage medium having program instructions recorded thereon that, when executed by a processor of a first computing device, perform a method, the method comprising:

receiving, from each of a plurality of second computing devices communicatively coupled to the first computing device:

a first characteristic descriptor indicating a length of time that an instance of a software application executed on the second computing device; and

a second characteristic descriptor of the instance of the software application;

determining, based on a respective first characteristic descriptor received from each of the plurality of second computing devices, a cumulative length of time that the instances of the software application executed on the plurality of second computing devices in a predetermined time frame;

obtaining, based on the second characteristic descriptor, a vulnerability score for the instance of the software application, wherein the vulnerability score indicates that a vulnerability exists for the instance of the software application;

assigning a security risk level to the instances of the software application based at least on the vulnerability score and the cumulative length of time; and

performing an action to mitigate the determined vulnerability in accordance with the security risk level.

16 . The computer-readable storage medium of claim 15 , wherein the second characteristic descriptor of the instance of the software application specifies one or more properties of the instance of the software application.

17 . The computer-readable storage medium of claim 15 , the method further comprising:

for each of the plurality of second computing devices, receiving, from the second computing device a third characteristic descriptor specifying one or more configuration settings of the instance of the software application.

18 . The computer-readable storage medium of claim 17 , assigning the security risk level is further based on the one or more configuration settings of the instances of the software application.

19 . The computer-readable storage medium of claim 15 , wherein performing the action to mitigate the determined vulnerability in accordance with the security risk level comprises at least one of:

providing a notification specifying the security risk level for the instances of the software application;

displaying the security risk level for the instances of the software application via a user interface;

providing a first command to each of the plurality of second computing devices that causes an update to be installed for the instances of the software applications that patches the vulnerability;

providing a second command to each of the plurality of second computing devices that causes one or more configuration settings to be changed for the instances of the software application that mitigates the vulnerability; or

providing a third command to each of the plurality of second computing devices that causes the instances of the software applications to be uninstalled.

20 . The computer-readable storage medium of claim 15 , wherein assigning the security risk level is further based on at least one of:

a number of the plurality of second computing devices on which the instances of the software application executed;

a frequency at which the instances of the software application is executed on the plurality of second computing devices;

a device type of each of the plurality of second computing devices; or

a type of a user of each of the plurality of second computing devices.

Assignments (2)
SECURITY INTEREST Recorded Oct 1, 2024
From: MORPHISEC INFORMATION SECURITY 2014 LTD
To: HERCULES CAPITAL, INC.
Reel/Frame 068758/0581 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2024
From: GORELIK, MICHAEL; YAFFE, DOREL
To: MORPHISEC INFORMATION SECURITY 2014 LTD.
Reel/Frame 066568/0629 →
Continuity (2)
Provisional Application 63237032 · Aug 25, 2021
Related Publication 20240394379A1 · Nov 28, 2024
References Cited (20)
US 7325252B2 · Bunker, V · 2008 [cited by applicant]
US 7451488B2 · Cooper · 2008 [cited by applicant]
US 8181173B2 · Childress · 2012 [cited by applicant]
US 8789195B2 · Bianco · 2014 [cited by applicant]
US 8850512B2 · Price · 2014 [cited by examiner]
US 8938803B1 · Roberts · 2015 [cited by examiner]
US 10599850B1 · Loihl · 2020 [cited by examiner]
US 10860369B2 · Du · 2020 [cited by examiner]
US 20090178142A1 · Lieblich · 2009 [cited by examiner]
US 20090293121A1 · Bigus · 2009 [cited by applicant]
US 20130275581A1 · Yu · 2013 [cited by examiner]
US 20140237599A1 · Gertner · 2014 [cited by examiner]
WO WO2023026132A1 · 2023 [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/IB2022/057634, European Patent Office, Munich, mailed on Feb. 12, 2022, 10 pages. [cited by applicant]
Patil, Rajendra, and Chirag Modi. “Designing an efficient framework for vulnerability assessment and patching (VAP) in virtual environment of cloud computing.” The Journal of Supercomputing 75.5 (2019): 2862-2889. [cited by applicant]
Du, Xiaoning, et al. “Leopard: Identifying vulnerable code for vulnerability assessment through program metrics.” 2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE). IEEE, 2019. [cited by applicant]
Farris, Katheryn A., et al. “Vulcon: A system for vulnerability prioritization, mitigation, and management.” ACM Transactions on Privacy and Security (TOPS) 21.4 (2018): 1-28. [cited by applicant]
Cukier, Michel, and Susmit Panjwani. “Prioritizing vulnerability remediation by determining attacker-targeted vulnerabilities.” IEEE Security & Privacy 7.1 (2009): 42-48. [cited by applicant]
Jacobs, Jay, et al. “Exploit prediction scoring system (EPSS).” arXiv preprint arXiv:1908.04856 (2019). [cited by applicant]
Jacobs, Jay, et al. “Improving vulnerability remediation through better exploit prediction.” Journal of Cybersecurity 6.1 (2020). [cited by applicant]