IP Library Granted Patent US 11,477,231
Granted Patent B2
US 11,477,231 · App. 16/897,760 · Granted Oct 18, 2022

System and method for vulnerability remediation prioritization

Inventors: Mariam Fahad Bubshait (Damman, SA); Mashael Hassan Alkhalis (Dhahran, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/1433G06F8/65G06N20/00H04L63/145H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,231
App. No.
16/897,760
Granted
Oct 18, 2022
Kind
B2
Abstract

A method may include obtaining internal vulnerability data and external vulnerability data regarding various security vulnerabilities among various network elements for a predetermined organization. The method may include determining various exploitability levels for the security vulnerabilities using a model, the external vulnerability data, and the internal vulnerability data. The model may be generated using a machine-learning algorithm. The method may include determining a vulnerability priority for the plurality of security vulnerabilities using the plurality of exploitability levels and organization-specific criteria. The vulnerability priority may describe a sequence that the security vulnerabilities are remediated. The method may further include transmitting a remediation command to one of the network elements. The remediation command may initiate a remediation procedure at the network element to address the security vulnerability.

Claims (55)

1. A method, comprising:

obtaining, by a computer processor, internal vulnerability data and external vulnerability data regarding a plurality of security vulnerabilities among a plurality of network elements for a predetermined organization;

determining, by the computer processor, a plurality of exploitability levels for the plurality of security vulnerabilities using a model, the external vulnerability data, and the internal vulnerability data, wherein the model is generated using a machine-learning algorithm;

determining, by the computer processor, a vulnerability priority for the plurality of security vulnerabilities using the plurality of exploitability levels and organization-specific criteria, wherein the vulnerability priority describes a sequence that the plurality of security vulnerabilities are remediated; and

transmitting, by the computer processor and based on the vulnerability priority, a remediation command to a network element comprising a security vulnerability among the plurality of security vulnerabilities,

wherein the remediation command initiates a remediation procedure at the network element to address the security vulnerability,

wherein the organization-specific criteria corresponds to a respective confidentiality level, a respective integrity level, and a respective availability level to a respective software application operating among the plurality of network elements, and

wherein the vulnerability priority is determined based on a plurality of vulnerability scores for the plurality of security vulnerabilities based on a respective exploitability level, the respective confidentiality level, the respective integrity level, and the respective availability level.

2. The method of claim 1 ,

wherein the internal vulnerability data is based on one or more cybersecurity attacks towards one or more network elements among the plurality of network elements that are detected by the predetermined organization.

3. The method of claim 1 ,

wherein the external vulnerability data is common vulnerabilities and exposures (CVE) data that describe publicly-available security information, and

wherein the external vulnerability data is obtained from a CVE data feed.

4. The method of claim 1 , wherein the machine-learning algorithm is a k-means clustering algorithm that identifies a cybersecurity attack possibility of a predetermined software application.

5. The method of claim 1 , wherein the remediation procedure comprises an installation of a software update to the network element that eliminates the security vulnerability.

6. The method of claim 1 , further comprising:

determining, by the computer processor, a remediation queue that organizes a plurality of remediation procedures based on the vulnerability priority,

wherein the remediation queue describes a sequence that a plurality of security vulnerabilities are remediated.

7. A system, comprising:

a plurality of network elements comprising a plurality of security vulnerabilities; and

a vulnerability manager comprising a computer processor, wherein the vulnerability manager is coupled to the plurality of network elements and is configured to:

obtain internal vulnerability data and external vulnerability data regarding the plurality of security vulnerabilities for a predetermined organization;

determine a plurality of exploitability levels for the plurality of security vulnerabilities using a model, the external vulnerability data, and the internal vulnerability data, wherein the model is generated using a machine-learning algorithm;

determine a vulnerability priority for the plurality of security vulnerabilities using the plurality of exploitability levels and organization-specific criteria, wherein the vulnerability priority describes a sequence that the plurality of security vulnerabilities are remediated; and

transmit, based on the vulnerability priority, a remediation command to a network element among the plurality of network elements,

wherein the network element comprises a security vulnerability among the plurality of security vulnerabilities,

wherein the remediation command initiates a remediation procedure at the one of the plurality of network elements to address the security vulnerability,

wherein the organization-specific criteria corresponds to a respective confidentiality level, a respective integrity level, and a respective availability level to a respective software application operating among the plurality of network elements, and

wherein the vulnerability priority is determined based on a plurality of vulnerability scores for the plurality of security vulnerabilities based on a respective exploitability level, the respective confidentiality level, the respective integrity level, and the respective availability level.

8. The system of claim 7 , further comprising:

a security vulnerability databases comprising the internal vulnerability data,

wherein the internal vulnerability data is based on one or more cybersecurity attacks towards one or more network elements among the plurality of network elements that are detected by the predetermined organization.

9. The system of claim 7 ,

wherein the external vulnerability data is common vulnerabilities and exposures (CVE) data that describe publicly-available security information, and

wherein the external vulnerability data is obtained from a CVE data feed.

10. The system of claim 7 , the vulnerability manager is further configured to:

determine a remediation queue that organizes a plurality of remediation procedures based on the vulnerability priority,

wherein the remediation queue describes a sequence that a plurality of security vulnerabilities are remediated.

11. The system of claim 7 , wherein the remediation procedure comprises an installation of a software update to the network element that eliminates the security vulnerability.

12. A non-transitory computer readable medium storing instructions, the instructions comprising functionality for:

obtaining internal vulnerability data and external vulnerability data regarding a plurality of security vulnerabilities among a plurality of network elements for a predetermined organization;

determining a plurality of exploitability levels for the plurality of security vulnerabilities using a model, the external vulnerability data, and the internal vulnerability data, wherein the model is generated using a machine-learning algorithm;

determining a vulnerability priority for the plurality of security vulnerabilities using the plurality of exploitability levels and organization-specific criteria, wherein the vulnerability priority describes a sequence that the plurality of security vulnerabilities are remediated; and

transmitting, based on the vulnerability priority, a remediation command to a network element comprising a security vulnerability among the plurality of security vulnerabilities,

wherein the remediation command initiates a remediation procedure at the network element to address the security vulnerability,

wherein the organization-specific criteria corresponds to a respective confidentiality level, a respective integrity level, and a respective availability level to a respective software application operating among the plurality of network elements, and

wherein the vulnerability priority is determined based on a plurality of vulnerability scores for the plurality of security vulnerabilities based on a respective exploitability level, the respective confidentiality level, the respective integrity level, and the respective availability level.

13. The non-transitory computer readable medium of claim 12 ,

wherein the internal vulnerability data is based on one or more cybersecurity attacks towards one or more network elements among the plurality of network elements that are detected by the predetermined organization.

14. The non-transitory computer readable medium of claim 12 ,

wherein the external vulnerability data is common vulnerabilities and exposures (CVE) data that describe publicly-available security information, and

wherein the external vulnerability data is obtained from a CVE data feed.

15. The non-transitory computer readable medium of claim 12 , wherein the machine-learning algorithm is a k-means clustering algorithm that identifies a cybersecurity attack possibility of a predetermined software application.

16. The non-transitory computer readable medium of claim 12 , wherein the remediation procedure comprises an installation of a software update to the network element that eliminates the security vulnerability.

17. The non-transitory computer readable medium of claim 12 , wherein the internal vulnerability data and the external vulnerability data are obtained from a security vulnerability database on a network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2021
From: BUBSHAIT, MARIAM FAHAD; ALKHALIS, MASHAEL HASSAN
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 055497/0898 →
Continuity (1)
Related Publication 20210392153A1 · Dec 16, 2021
Cited By (2)
US 12,579,281 US 12,647,443