首页> 外国专利> PRIORITIZATION OF REMEDIATION ACTIONS FOR ADDRESSING VULNERABILITIES IN AN ENTERPRISE SYSTEM

PRIORITIZATION OF REMEDIATION ACTIONS FOR ADDRESSING VULNERABILITIES IN AN ENTERPRISE SYSTEM

机译:解决企业系统中漏洞的补救措施的优先级

摘要

A method includes identifying two or more vulnerabilities, each vulnerability affecting a set of one or more assets of an enterprise system. The method also includes assigning a weight to each vulnerability, the weight assigned to each of the vulnerabilities being based at least in part on the set of assets affected by that vulnerability, asset criticalities associated with the set of assets affected by that vulnerability, and at least one of (i) an exploitability potential of that vulnerability and (ii) an impact potential of that vulnerability. The method further includes determining an order in which to apply remediation actions in the enterprise system to address at least one of the vulnerabilities based at least in part on the weights assigned to the vulnerabilities, and applying, in accordance with the determined order, at least one of the remediation actions to at least one of the assets in the enterprise system.
机译:一种方法包括识别两个或多个漏洞,每个漏洞影响企业系统的一组一个或多个资产。该方法还包括为每个漏洞分配权重,分配给每个漏洞的权重至少部分基于受该漏洞影响的资产集,与受该漏洞影响的资产集相关的资产临界度以及(i)该漏洞的潜在利用潜力和(ii)该漏洞的潜在影响中的至少一个。该方法还包括:至少部分地基于分配给漏洞的权重,确定在企业系统中应用补救措施以解决至少一个漏洞的顺序;以及根据所确定的顺序,至少应用对企业系统中至少一项资产的补救措施之一。

著录项

  • 公开/公告号US2020351294A1

    专利类型

  • 公开/公告日2020-11-05

    原文格式PDF

  • 申请/专利权人 EMC IP HOLDING COMPANY LLC;

    申请/专利号US201916399199

  • 发明设计人 SASHKA T. DAVIS;GREGORY A. GERBER JR.;

    申请日2019-04-30

  • 分类号H04L29/06;G06F8/65;

  • 国家 US

  • 入库时间 2022-08-21 11:20:54

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号