Generative systems and methods for adaptive vulnerability management
Systems and methods are disclosed comprising instructions to collect vulnerability information over a network from a publishing source, collect network asset information of a communications network, generate a self-executing scanner agent configured to automatically scan the communications network for a known vulnerability based on an input including the collected vulnerability information and the collected network asset information, deploy the scanner agent at any network assets of the communications network that match a particular type of network asset indicated in the collected vulnerability information, generate a record including an indication of a particular network asset of the communications network in association with the known vulnerability in response to the scanner agent executing and detecting the known vulnerability in the particular network asset, and store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
1 . A method for generating custom scanner agents for vulnerability management of a computer system, the method comprising:
collecting vulnerability information over a network from a publishing source,
wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and
wherein the CVEs include a known vulnerability for a particular type of network asset;
collecting network asset information of a communications network, the communications network being subject to the vulnerability management, wherein the network asset information includes information about multiple types of network assets deployed in the communications network;
generating, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;
deploying the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;
in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generating a record including an indication of the particular network asset in association with the known vulnerability; and
storing the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
2 . The method of claim 1 further comprising:
configuring a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;
configuring a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and
configuring a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.
3 . The method of claim 1 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the method further comprising:
calculating a correlation value between the known vulnerability and a second type of network asset of the communications network;
discovering a potential vulnerability for the second type of network asset based on the correlation value;
generating a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and
training the generative AI system based on the records aggregated at the data repository and the potential vulnerability.
4 . The method of claim 3 , wherein calculating the correlation value comprises:
calculating a similarity score between the first type of network asset and the second type of network asset; or
calculating a relevance score for the second type of network asset relative to the known vulnerability; and
identifying the potential vulnerability based on the similarity score or the relevance score.
5 . The method of claim 1 , wherein the publishing source comprises:
a public national vulnerability database (NVD) that obtains the vulnerability information from a vendor of the particular type of network asset; or
a vendor of the particular type of network asset and the vulnerability information is obtained directly from the vendor.
6 . The method of claim 5 , wherein the publishing source comprises a vendor of the particular type of network asset, and collecting the vulnerability information comprises:
automatically obtaining vulnerability information periodically from a website administered by the vendor.
7 . The method of claim 1 , wherein the particular network asset is a software asset, the method further comprising:
deploying a software patch for the software asset to remove a risk of the known vulnerability.
8 . The method of claim 1 further comprising:
estimating a financial risk of the known vulnerability to an operator of the communications network by performing a risk valuation of the known vulnerability on the particular network asset.
9 . A vulnerability management system comprising:
at least one hardware processor; and
at least one non-transitory memory storing instructions, which, when executed by the at least one hardware processor, cause the vulnerability management system to:
collect vulnerability information over a network from a publishing source, wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and
wherein the CVEs include a known vulnerability for a particular type of network asset;
collect network asset information of a communications network, the communications network being subject to the vulnerability management system,
wherein the network asset information includes information about multiple types of network assets deployed in the communications network;
generate, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;
deploy the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;
in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generate a record including an indication of the particular network asset in association with the known vulnerability; and
store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
10 . The vulnerability management system of claim 9 further caused to:
configure a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;
configure a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and
configure a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.
11 . The vulnerability management system of claim 9 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the system further caused to:
calculate a correlation value between the known vulnerability and a second type of network asset of the communications network;
discover a potential vulnerability for the second type of network asset based on the correlation value;
generate a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and
train the generative AI system based on the records aggregated at the data repository and the potential vulnerability.
12 . The vulnerability management system of claim 11 , wherein calculating the correlation value comprises causing the system to:
calculate a similarity score between the first type of network asset and the second type of network asset; or
calculate a relevance score for the second type of network asset relative to the known vulnerability; and
identify the potential vulnerability based on the similarity score or the relevance score.
13 . The vulnerability management system of claim 9 , wherein the publishing source comprises:
a public national vulnerability database (NVD) that obtains the vulnerability information from a vendor of the particular type of network asset; or
a vendor of the particular type of network asset and the vulnerability information is obtained directly from the vendor.
14 . The vulnerability management system of claim 13 , wherein the publishing source comprises a vendor of the particular type of network asset, and collecting the vulnerability information comprises causing the system to:
automatically obtain vulnerability information periodically from a website administered by the vendor.
15 . At least one non-transitory, computer-readable storage medium carrying instructions, which, when executed by a vulnerability management system, cause the vulnerability management system to perform operations for identifying a vulnerability of a computer asset, the operations comprising:
collecting vulnerability information over a network from a publishing source,
wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and
wherein the CVEs include a known vulnerability for a particular type of network asset;
collecting network asset information of a communications network, the communications network being subject to the vulnerability management system,
wherein the network asset information includes information about multiple types of network assets deployed in the communications network;
generating, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;
deploying the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;
in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generating a record including an indication of the particular network asset in association with the known vulnerability; and
storing the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
16 . The non-transitory, computer-readable storage medium of claim 15 , wherein the system is further caused to:
configure a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;
configure a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and
configure a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.
17 . The non-transitory, computer-readable storage medium of claim 15 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the system further caused to:
calculate a correlation value between the known vulnerability and a second type of network asset of the communications network;
discover a potential vulnerability for the second type of network asset based on the correlation value;
generate a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and
train the generative AI system based on the records aggregated at the data repository and the potential vulnerability.
18 . The non-transitory, computer-readable storage medium of claim 17 , wherein calculating the correlation value comprises causing the system to:
calculate a similarity score between the first type of network asset and the second type of network asset; or
calculate a relevance score for the second type of network asset relative to the known vulnerability; and
identify the potential vulnerability based on the similarity score or the relevance score.
19 . The non-transitory, computer-readable storage medium of claim 15 , wherein the particular network asset is a software asset, the system further caused to:
deploy a software patch for the software asset to remove a risk of the known vulnerability.
20 . The non-transitory, computer-readable storage medium of claim 15 , wherein the system is further caused to:
estimate a financial risk of the known vulnerability to an operator of the communications network by performing a risk valuation of the known vulnerability on the particular network asset.