Bank of America Corporation
System and Method for Associating a Common Vulnerability and Exposures (CVE) with a Computing Device and Applying a Security Patch

Last updated:

Abstract:

A system is configured for associating a CVE with a particular device profile is disclosed. The system receives a request from a user to associate a CVE with a particular device profile. For each device profile from a plurality of device profiles stored in a memory, the system determines feature importance values for features of each device profile. The features of each device profile include at least an operating system and a CPU architecture. The feature importance value of a corresponding feature of a device profile associated with a CVE indicates a probability of the CVE to affect the device profile with respect to that feature. The system identifies a device profile that has features with a total feature importance value above a feature importance threshold value. The system identifies a particular CVE associated with the identified device profile. The system associates the particular CVE with the particular device profile.

Status:
Application
Type:

Utility

Filling date:

16 Jul 2020

Issue date:

20 Jan 2022