← USPTO Patent Grants

Dynamic prioritization of vulnerability risk assessment findings

Grant US12579281B2 Kind: B2 Mar 17, 2026

Assignee

International Business Machines Corporation

Inventors

Johnny Al Shaieb, Steven Ocepek, Jason A. Nikolai, Melody Leu, Andrew C. Herlands, Michael Redford, Elio Andres Sanabria Echeverria

Abstract

Mechanisms are provided for assessing control checks and components of a vulnerability management system (VMS) for a computing infrastructure. A security vulnerability risk gap assessment of the VMS is executed to generate result data for a plurality of control checks. For each control check, the mechanisms: classify the control check into a maturity level having a corresponding maturity level value; classify each of a plurality of vulnerability assessment security control rating (VASCR) elements into a predetermined classification having corresponding classification values for the control check; and combine the maturity level value and the VASCR element classification values to generate a prioritization score. A graphical user interface output is generated comprising a representation of a prioritized ranked listing of control checks based on the prioritization scores associated with each of the control checks in the plurality of control checks.

CPC Classifications

G06F 21/577 G06F 21/552 G06F 2221/034 G06F 21/554 H04L 63/1441 H04L 63/1408 H04L 63/1433

Filing Date

2023-12-12

Application No.

18536521

Claims

19