Device vulnerability management

Inventors

Patel, Pranav N.Ayyappan Pillai, Ramakrishnan

Assignees

Meditechsafe LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-10992698-B2

Patent

Publication Date

2021-04-27

Expiration Date


Abstract

A computer-implemented process of remediating device security vulnerabilities is carried out by determining identifications of electronic devices associated with an entity and calculating, for each device, a security cyber-vulnerability score. For instance, the cyber-vulnerability score is calculated by generating a device cyber-vulnerability score based upon known threats and vulnerabilities, generating a device level cyber-vulnerability score by augmenting the generated device cyber-vulnerability score based upon at least one device level parameter, generating an environmental cyber-vulnerability score, and computing an overall cyber-vulnerability score based upon the device level cyber-vulnerability score and the environmental cyber-vulnerability score. The computer-implemented process also comprises prioritizing the electronic devices based upon the computed overall cyber-vulnerability score, identifying whether a patch is available for at least one electronic device, and initiating a remediation/mitigation workflow to patch at least one electronic device.

Core Innovation

A computer-implemented process determines an identification of a particular special-purpose electronic medical device in a particular healthcare delivery organization (HDO). The process generates a device cyber-vulnerability score based upon known threats and vulnerabilities affecting a type of product to which the special-purpose electronic medical device pertains, and augments the generated device cyber-vulnerability score based upon a device level parameter specific to the special-purpose electronic medical device.

The process generates an environmental cyber-vulnerability score using a weighted combination that includes usage of the special-purpose electronic medical device in the particular HDO. The environmental cyber-vulnerability score includes medical condition information of a patient the special-purpose electronic medical device may be used on, determining an indicia of medical impact to the patient based on the medical condition information, criticality of the special-purpose electronic medical device, and network exposure of the special-purpose electronic medical device in the particular HDO.

The process computes an overall cyber-vulnerability score based upon a combination of the device-level cyber-vulnerability score and the environmental cyber-vulnerability score. The process determines whether the special-purpose electronic medical device has a high priority based upon the computed overall cyber-vulnerability score, identifies whether a patch or other vulnerability remediation is available, and initiates, in response to identifying availability and high priority, a remediation/mitigation workflow to patch or remediate the special-purpose electronic medical device.

Claims Coverage

The document contains one independent claim. It defines device identity determination, cyber-vulnerability scoring at device level and environmental level, an overall prioritized risk score, patch/remediation availability checking, and conditional initiation of a remediation/mitigation workflow based on high priority.

Device identification in a particular HDO

Determining an identification of the particular special-purpose electronic medical device in the particular HDO.

Device cyber-vulnerability scoring from known threats and vulnerabilities

Generating a device cyber-vulnerability score based upon known threats and vulnerabilities affecting a type of product to which the special-purpose electronic medical device pertains.

Augmented device level cyber-vulnerability scoring using device level parameters

Generating a device level cyber-vulnerability score by augmenting the generated device cyber-vulnerability score based upon a device level parameter specific to the special-purpose electronic medical device.

Environmental cyber-vulnerability scoring using weighted HDO usage and patient-impact indicia

Generating an environmental cyber-vulnerability score based on a weighted combination of usage of the special-purpose electronic medical device in the particular HDO, medical condition information of a patient the particular special-purpose electronic medical device may be used on, determining an indicia of medical impact to the patient based on the medical condition information, criticality of the special-purpose electronic medical device, and network exposure of the special-purpose electronic medical device in the particular HDO.

Overall cyber-vulnerability scoring combining device-level and environmental scores

Computing an overall cyber-vulnerability score based upon a combination of the device-level cyber-vulnerability score and the environmental cyber-vulnerability score.

High-priority determination based on the overall cyber-vulnerability score

Determining whether the special-purpose electronic medical device has a high priority based upon the computed overall cyber-vulnerability score.

Patch or other vulnerability remediation availability identification

Identifying whether a patch or other vulnerability remediation is available for the special-purpose electronic medical device.

Conditional remediation/mitigation workflow initiation for high-priority devices with available remediation

Initiating, in response to identifying that the patch or other vulnerability remediation is available and in response to determining that the special-purpose electronic medical device has a high priority, a remediation/mitigation workflow to patch or remediate the special-purpose electronic medical device.

Across the independent claim, the core coverage is the combination of device identity determination within an HDO, device-level cyber-vulnerability scoring augmented by device-specific parameters, environmental cyber-vulnerability scoring that includes HDO usage and patient medical-impact indicia together with criticality and network exposure, and overall scoring used to prioritize devices for which patch or other remediation is available, followed by conditional initiation of a remediation/mitigation workflow.

Stated Advantages

Prioritizes special-purpose electronic medical devices for remediation by determining high priority based on a computed overall cyber-vulnerability score.

Initiates remediation/mitigation workflows for patching or remediation when a patch or other vulnerability remediation is available for high-priority devices.

Documented Applications

Remediating a device vulnerability for a particular special-purpose electronic medical device in a particular healthcare delivery organization (HDO) by generating cyber-vulnerability scores, determining high priority, identifying patch/remediation availability, and initiating a remediation/mitigation workflow.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.