Invention Grant
- Patent Title: Vulnerability remediation complexity (VRC) system
-
Application No.: US16802644Application Date: 2020-02-27
-
Publication No.: US12058161B2Publication Date: 2024-08-06
- Inventor: Johnny Al Shaieb , Jason A. Nikolai , Michael Redford , Steven Ocepek , Jason Bornheimer , Robert Maier
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agent Michael O'Keefe
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F8/65

Abstract:
The subject matter herein provides an automated system and method for software patch management that ranks patches at least in part according to a score indicative of a complexity (e.g., cost) of remediating a vulnerability. This score is sometimes referred to herein as a vulnerability remediation complexity (VRC) score. A VRC score provides an objective measure by which an organization can determine which patches are most likely to be successfully applied, thus enabling implementation of a patching strategy that preferentially applies most critical, but less impact (in terms of remediation cost) patches first to remediate as must risk as possible as quickly as possible. Thus, for example, the approach herein enables the patching to focus on vulnerabilities of highest severity and small remediation cost over those, for example, representing lower severity and higher remediation cost.
Public/Granted literature
- US20210273968A1 Vulnerability remediation complexity (VRC) system Public/Granted day:2021-09-02
Information query