IP Library › Granted Patent US 11,729,197
Granted Patent B2
US 11,729,197 · App. 16/688,915 · Granted Aug 15, 2023

Adaptive vulnerability management based on diverse vulnerability information

Inventors: Pradeep Cruz (Issaquah, WA); Jan Olav Opedal (Ellensburg, WA); Srikrishna Srinivasan (Issaquah, WA); Yanbing Su (Frisco, TX)
Assignee: T-Mobile USA, Inc.
H04L63/1433G06F8/65
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,729,197
App. No.
16/688,915
Granted
Aug 15, 2023
Kind
B2
Abstract

Embodiments include a method for vulnerability management of a computer system. The method includes collecting vulnerability information over a network from a publishing source. The vulnerability information includes a known vulnerability of a first computer asset, where at least some of the vulnerability information is a set of cybersecurity vulnerabilities and exposures (CVEs) published online. Further, at least some of the CVEs is in a human-readable format. The method further includes collecting system information of the computer system subject to the vulnerability management, where the system information includes information about a second computer asset of the computer system. The method further includes processing the collected vulnerability information and the collected system information by interpreting the human-readable CVEs and correlating the interpreted CVEs with the collected system information. A potential vulnerability of the second computer asset is identified based on the correlation between the interpreted CVEs and the collected system information.

Claims (68)

1. A method for adaptive vulnerability management of a computer system, the method comprising:

collecting vulnerability information over a network from a publishing source,

wherein the vulnerability information includes a known vulnerability of a first computer asset,

wherein the vulnerability information includes a set of cybersecurity vulnerabilities and exposures (CVEs) published on a public network,

at least some of the CVEs being in a human-readable format;

collecting system information of the computer system, the computer system being subject to the vulnerability management,

wherein the system information includes information about a second computer asset of the computer system; and

processing the collected vulnerability information and the collected system information by:

interpreting at least some of the human-readable CVEs with natural language processing (NLP) and correlating the interpreted CVEs with the collected system information;

identifying a potential vulnerability of the second computer asset based on a correlation between the interpreted CVEs and the collected system information;

storing, in a cloud-based results database, a subset of the collected vulnerability information,

wherein the subset of the collected vulnerability information does not match the collected system information; and

generating, based on text extracted from the subset of the collected vulnerability information stored in the cloud-based results database, a search index that is accessible from a web-based graphical user interface and enables access to processed analytics of the collected vulnerability information.

2. The method of claim 1 , wherein the first computer asset includes a first hardware asset, a first software asset, or a first configuration of a first computer system, and the second computer asset includes a second hardware asset, a second software asset, or a second configuration of the computer system.

3. The method of claim 1 , wherein processing the collected vulnerability information and the collected system information comprises:

correlating the interpreted CVEs with the collected system in accordance with a machine learning (ML) model, the ML model being trained based on the collected system information of the computer system.

4. The method of claim 1 , wherein the correlating comprises:

calculating a Levenshtein distance of the known vulnerability to the second computer asset;

ranking the Levenshtein distance as a measure of relevance between the known vulnerability and the second computer asset; and

identifying the potential vulnerability based on the rank of the Levenshtein distance to the second computer asset.

5. The method of claim 1 , wherein the correlating comprises:

performing a similarity analysis between the first computer asset and the second computer asset.

6. The method of claim 1 , wherein the correlating comprises:

determining a relevance score of the second computer asset based on the known vulnerability; and

identifying the potential vulnerability based on the relevance score.

7. The method of claim 1 further comprising:

performing a risk classification and prioritization of the potential vulnerability based on a multi-class boosted decision forests algorithm.

8. The method of claim 1 further comprising:

estimating a financial risk of the potential vulnerability by performing a risk valuation of the potential vulnerability based on a Monte Carlo simulation by using a beta-PERT distribution.

9. The method of claim 1 further comprising:

estimating a financial risk of the potential vulnerability by performing a risk valuation of the potential vulnerability.

10. The method of claim 1 , wherein the vulnerability information comprises a file formatted in JavaScript Object Notation (JSON), Hypertext Markup Language (HTML), or Extensible Markup Language (XML).

11. The method of claim 1 , wherein the publishing source comprises a public national vulnerability database (NVD) that obtains the vulnerability information from a vendor of the first computer asset.

12. The method of claim 1 , wherein the publishing source comprises a vendor of the first computer asset and the vulnerability information is obtained directly from the vendor.

13. The method of claim 1 , wherein the potential vulnerability is a first potential vulnerability, and at least some of the CVEs are in a machine-readable format, the method further comprising:

identifying a second potential vulnerability of a third computer asset of the computer system based on the correlation between the machine-readable CVEs and the collected system information.

14. The method of claim 1 , wherein the publishing source comprises is a vendor of the first computer asset, and collecting the vulnerability information comprises:

automatically obtaining vulnerability information periodically over the network from a website administered by the vendor.

15. The method of claim 1 further comprising:

periodically extracting vulnerability information from an online portal.

16. The method of claim 1 , wherein the second computer asset is a software asset, the method further comprising:

obtaining a software patch over the network for the software asset.

17. The method of claim 1 further comprising:

receiving an indication that the potential vulnerability was validated as a vulnerability based on a manual review.

18. A vulnerability management system for a computer system, the system comprising:

a network interface through which to obtain vulnerability information for computer assets over a network from network portals, wherein the network portals are for vendors of the computer assets;

a storage facility configured to store inventory information of computer assets for the computer system and instructions for managing vulnerabilities of the computer system; and

one or more processors configured to identify a vulnerability of the computer system based on the vulnerability information and the inventory information, where execution of the instructions causes the vulnerability management system to:

cause the network interface to automatically collect vulnerability information periodically over the network from the network portals;

perform a matching process of the collected vulnerability information to the inventory information of computer assets for the computer system;

identify a vulnerability of the computer system as a match between a known vulnerability included in the inventory information and a computer asset listed in the inventory information of the computer system;

classify a risk of the vulnerability based on a decision algorithm;

estimate a financial risk of the vulnerability based on a risk valuation of the vulnerability; p 2 store, in a cloud-based results database, a subset of the collected vulnerability information,

wherein the subset of the collected vulnerability information does not match the inventory information; and

generate, based on text extracted from the subset of the collected vulnerability information stored in the cloud-based results database, a search index that is accessible from a web-based graphical user interface and enables access to processed analytics of the collected vulnerability information.

19. The system of claim 18 , wherein the vulnerability is identified based on a calculation of a Levenshtein distance between the known vulnerability and the computer asset.

20. At least one non-transitory computer-readable storage medium carrying instructions that, when executed by a vulnerability management system, cause the vulnerability management system to perform operations for identifying a vulnerability of a computer asset, the operations comprising:

collect vulnerability information including cybersecurity, vulnerabilities and exposures (CVEs) over a network from online sources, wherein at least some of the CVEs is in a human-readable format;

collect feature information of the computer asset subject to vulnerability management;

process the collected CVEs and the collected feature information by:

interpreting the human-readable CVEs using natural language processing (NLP) to understand a known vulnerability of a known computer asset;

calculating a Levenshtein distance between the known computer asset and the computer asset;

ranking the Levenshtein distance as a measure of relevance of the known computer asset to the computer asset; and

identifying a potential vulnerability of the computer asset based on the rank of the Levenshtein distance;

perform a risk assessment of the potential vulnerability to determine a risk to a computer system that includes the computer asset;

store, in a cloud-based results database, a subset of the collected vulnerability information,

wherein the subset of the collected vulnerability information does not match the collected feature information; and

generate, based on text extracted from the subset of the collected vulnerability information stored in the cloud-based results database, a search index that is accessible from a web-based graphical user interface and enables access to processed analytics of the collected vulnerability information.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Aug 23, 2022
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: IBSV LLC; LAYER3 TV, LLC; PUSHSPRING, LLC; T-MOBILE CENTRAL LLC; T-MOBILE USA, INC.; ASSURANCE WIRELESS USA, L.P.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; SPRINTCOM LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM LLC
Reel/Frame 062595/0001 →
SECURITY AGREEMENT Recorded Apr 2, 2020
From: T-MOBILE USA, INC.; ISBV LLC; T-MOBILE CENTRAL LLC; LAYER3 TV, INC.; PUSHSPRING, INC.; BOOST WORLDWIDE, LLC; CLEARWIRE COMMUNICATIONS LLC; CLEARWIRE IP HOLDINGS LLC; CLEARWIRE LEGACY LLC; SPRINT COMMUNICATIONS COMPANY L.P.; SPRINT INTERNATIONAL INCORPORATED; SPRINT SPECTRUM L.P.; ASSURANCE WIRELESS USA, L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 053182/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: CRUZ, PRADEEP; OPEDAL, JAN OLAV; SRINIVASAN, SRIKRISHNA; SU, YANBING
To: T-MOBILE USA, INC.
Reel/Frame 051618/0104 →
Continuity (1)
Related Publication 20210152588A1 · May 20, 2021
Cited By (2)
US 12,587,556 US 12,726,504