US 12,395,513 B2
System and method for evaluating risk of a vulnerability
Paul Gregory Ellsworth, Sheridan, OR (US)
Assigned to TENABLE, INC., Columbia, MD (US)
Filed by Tenable, Inc., Columbia, MD (US)
Filed on Apr. 15, 2022, as Appl. No. 17/659,429.
Prior Publication US 2023/0336579 A1, Oct. 19, 2023
Int. Cl. H04L 29/00 (2006.01); H04L 9/40 (2022.01)
CPC H04L 63/1433 (2013.01) [H04L 63/20 (2013.01)] 22 Claims
OG exemplary drawing
 
1. A method of prioritizing vulnerabilities in applications of a system, the method comprising:
obtaining risk information corresponding to one or more assets of the system;
scanning the one or more assets for first application information relating to at least two applications installed on the one or more assets;
determining a risk score of a vulnerability or a set of vulnerabilities that is specific to a first application of the at least two applications installed on the one or more assets, the risk score of the vulnerability or the set of vulnerabilities being based on the risk information and the first application information,
wherein the risk score is based on the presence or absence of one or more asset-specific attributes required for successful exploitation of the vulnerability or the set of vulnerabilities,
wherein the risk score is one of a plurality of risk scores, each of the plurality of risk scores associated with a respective vulnerability or a respective set of vulnerabilities associated with the one or more assets; and
sorting the plurality of risk scores to facilitate remediation of associated vulnerabilities in order of riskiness.