System and method for performing network security risk assessment
By providing a network security analysis system, it is able to receive the subject system, determine potential hazard events, generate attack maps, calculate the availability and uncertainty of the action, aggregate the actions to determine vulnerabilities, and generate responses to the vulnerabilities, solve the problems in the prior art that the network security risk assessment is time-consuming, costly and difficult to represent the relevant assessment of the subject system, and realize the practicality of the automatic network security threat assessment and the evaluation of the overall security situation of the system.
Patent Information
- Application Number
- CN202011037940.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-10-08
- Filing Date
- 2020-09-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2040-09-28
AI Technical Summary
Existing cybersecurity risk assessment methods are difficult to naturally represent the actual assessment aspects related to the subject system, and traditional methods are limited in practicality, time-consuming and costly in evaluating the overall security situation of the system.
Provides a network security analysis system that receives subject systems through computing devices, determines potential hazard events, generates attack maps, calculates the availability and uncertainty of actions, aggregates actions to identify vulnerabilities, and generates responses to vulnerabilities.
It realizes automated network security threat assessment, reduces evaluation time and cost, can naturally represent the evaluation aspects related to the subject system, and improves the evaluation practicality of the overall security situation of the system.
Smart Images

Figure BDA0002705723860000081 
Figure BDA0002705723860000112 
Figure BDA0002705723860000121
Abstract
Description
Technical Field
[0001] The field of the present disclosure relates to evaluating potential cybersecurity threats, and more particularly to automatically evaluating potential cybersecurity threats to a subject system and determining potential countermeasures. Background Art
[0002] There are various methods for evaluating cybersecurity risks, but at a basic level, risk assessment generally considers the likelihood and consequences of a harmful event as the main variables for calculating risk. Cybersecurity risk assessment typically utilizes semi-quantitative assessments of likelihood and consequences to derive various risk metrics in the absence of true probabilities of likelihood or true consequence metrics. Most assessment methods deliberately define specific criteria for classifying harmful events into different likelihoods and consequences. These methods convey a false sense of certainty about the likelihood or consequences of a harmful event and may artificially distance harmful events that in fact have similar risk characteristics. In addition, the time required to perform an accurate cybersecurity assessment is very long and requires a great deal of expertise on the subject, thus greatly increasing its corresponding cost. Since uncertainty is not taken as an assessment parameter, cybersecurity assessment is forced to spend a great deal of resources to reduce the uncertainty of all assessment inputs rather than select the few inputs that have the greatest impact on the assessment result. In addition, traditional cybersecurity risk assessment methods often have difficulty naturally representing assessment aspects that are not actually part of the system but are related to the subject system (e.g., the physical security of the subject system). This limits the utility of these methods for assessing the overall security posture of the system. Summary of the Invention
[0003] In one aspect, a cybersecurity analysis system for evaluating potential cybersecurity threats to a subject system is provided. The system includes a computing device that includes at least one processor communicatively coupled to at least one memory device. The at least one processor is programmed to: receive a subject system to be analyzed; determine potential harmful events associated with the subject system; generate an attack graph associated with the potential harmful events, wherein the attack graph includes a plurality of actions; determine an exploitability score for each of the plurality of actions; determine a level of uncertainty for each of the plurality of actions based on the corresponding exploitability score; aggregate the plurality of actions including the corresponding exploitability scores and the corresponding levels of uncertainty to determine one or more vulnerabilities of the subject system; and generate a response to the one or more vulnerabilities of the subject system.
[0004] In another embodiment, a method for assessing potential cybersecurity threats to a subject system is provided. The method is implemented on a computing device including at least one processor communicatively coupled to at least one memory device. The method includes: receiving the subject system to be analyzed; determining potential hazard events associated with the subject system; generating an attack graph associated with the potential hazard events, wherein the attack graph includes a plurality of actions; determining an exploitability score for each of the plurality of actions; determining an uncertainty level for each of the plurality of actions based on the corresponding exploitability score; aggregating the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; and generating a response to the one or more vulnerabilities of the subject system.
[0005] In yet another embodiment, a non-transitory computer-readable medium is provided having computer-executable instructions implemented thereon. When executed by at least one processor coupled to a memory device, the computer-executable instructions cause the processor to receive the subject system to be analyzed. The subject system to be analyzed is at least one of a computer and a computer network. The computer-executable instructions further cause the processor to determine potential hazard events associated with the subject system and generate an attack graph associated with the potential hazard events. The attack graph includes a plurality of actions. The computer-executable instructions further cause the processor to determine an exploitability score for each of the plurality of actions. The exploitability score represents the level of adversary capabilities to execute the corresponding action. Additionally, the computer-executable instructions cause the processor to determine an uncertainty level for each of the plurality of actions based on the corresponding exploitability score. The uncertainty level represents the confidence level associated with the determination of the exploitability score. Additionally, the computer-executable instructions cause the processor to aggregate the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system. Additionally, the computer-executable instructions cause the processor to determine one or more countermeasures based on the one or more vulnerabilities; apply the one or more countermeasures to the attack graph; aggregate the plurality of actions based on the one or more countermeasures; and generate a response to the one or more vulnerabilities of the subject system. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Figure 1 The figure illustrates a block diagram of a process for assessing potential cybersecurity threats to a subject system and determining potential countermeasures according to one embodiment of the present disclosure.
[0007] Figure 2 The figure illustrates an exemplary attack path graph according to one embodiment of the present disclosure.
[0008] Figure 3 The figure illustrates another exemplary attack path graph with countermeasures according to one embodiment of the present disclosure.
[0009] Figure 4 is a simplified block diagram of an example system for evaluating potential cybersecurity threats to a subject system, such as through the process shown Figure 1 in the figure.
[0010] Figure 5 The illustration shows an example configuration of a Figure 4 client computer device as shown in accordance with one embodiment of the present disclosure.
[0011] Figure 6 The illustration shows an example configuration of a Figure 4 server system as shown in accordance with one embodiment of the present disclosure.
[0012] Figure 7 is a flowchart in accordance with one embodiment of the present disclosure that illustrates an example of a process for evaluating potential cybersecurity threats to a subject system and determining potential countermeasures using the Figure 4 system shown in the figure. DETAILED DESCRIPTION
[0013] The embodiments described herein relate to systems and methods for evaluating potential cybersecurity threats and, more particularly, to automatically evaluating potential cybersecurity threats to a subject system and determining potential countermeasures. More specifically, a cybersecurity analysis (“CSA”) computer device is provided for analyzing: (1) one or more subject systems (such as a computer system or a computer network) against potential cybersecurity threats; (2) an attack path model of the subject system to determine the feasibility of potential attack paths and to determine potential countermeasures for reducing the feasibility of those potential attacks.
[0014] Computer systems and related computer systems, such as the CSA computer device, are described herein. As described herein, all such computer systems include a processor and a memory. However, any processor in the computer devices referred to herein may also refer to one or more processors, where the processors may be in one computing device or in multiple computing devices working in parallel. Additionally, any memory in the computer devices referred to herein may also refer to one or more memories, where the memories may be in one computing device or in multiple computing devices working in parallel.
[0015] As used herein, the term "cybersecurity threat" includes an unauthorized attempt to gain access to a subject system. A cybersecurity threat (also referred to as a cyberattack or cyber threat) attempts to exploit vulnerabilities in a computer system to compromise the computer system. Some cybersecurity threats include attempts to damage or disrupt the subject system. These cybersecurity threats can include, but are not limited to, active intrusion, spyware, malware, viruses, and worms. Cybersecurity threats can take multiple paths (also referred to as attack paths) to compromise a system. These paths can include operating system attacks, misconfiguration attacks, application-level attacks, and shrink wrap code attacks. Cybersecurity threats may be introduced by direct access by an individual or system, via a communication network or connected system, or by remote access computing devices through an associated supply chain.
[0016] As used herein, a processor may include any programmable system that includes a system using a microcontroller, reduced instruction set circuit (RISC), application specific integrated circuit (ASIC), logic circuits, and any other circuit or processor capable of performing the functions described herein. The above examples are for illustration only and are not intended to limit the definition and / or meaning of the term "processor" in any way.
[0017] As used herein, the term "database" may refer to a body of data, a relational database management system (RDBMS), or both. As used herein, a database may include any collection of data that includes hierarchical databases, relational databases, flat file databases, object-relational databases, object-oriented databases, and any other structured collection of records or data stored in a computer system. The above examples are for illustration only and are not intended to limit the definition and / or meaning of the term database in any way. Examples of RDBMSs include, but are not limited to Database, MySQL, DB2, SQL Server, and PostgreSQL. However, any database can be used to implement the systems and methods described herein. (Oracle is a registered trademark of Oracle Corporation, Redwood Shores, California; IBM is a registered trademark of International Business Machines Corporation, Armonk, New York; Microsoft is a registered trademark of Microsoft Corporation, Redmond, Washington; Sybase is a registered trademark of Sybase, Dublin, California.)
[0018] In one embodiment, a computer program is provided and the program is implemented on a computer-readable medium. In an example embodiment, the system is executed on a single computer system without the need to be connected to a server computer. In another embodiment, the system operates in a environment (Windows is a registered trademark of Microsoft Corporation, Redmond, Washington). In yet another embodiment, the system operates in a mainframe environment and server environment (UNIX is a registered trademark of X / Open Company Limited, Reading, Berkshire, UK). The application is flexible and designed to operate in a variety of different environments without compromising any of its major functions. In some embodiments, the system includes multiple components distributed among multiple computing devices. One or more components may be in the form of computer-executable instructions implemented in a computer-readable medium.
[0019] As used herein, an element or step recited in the singular and preceded by the word "a" or "an" should be understood as not excluding a plurality of elements or steps, unless expressly recited to the contrary. Furthermore, references to "example embodiments" or "one embodiment" of the present disclosure are not to be construed as excluding the existence of additional embodiments that also incorporate the recited features.
[0020] As used herein, the terms "software" and "firmware" are interchangeable and include any computer program stored in a memory for execution by a processor, where the memory includes RAM memory, ROM memory, EPROM memory, EEPROM memory, and non-volatile RAM (NVRAM) memory. The above memory types are merely examples and are thus not limited to the types of memory that can be used to store computer programs.
[0021] In addition, as used herein, the term "real-time" refers to at least one of the time of occurrence of an associated event, the time of measurement and collection of predetermined data, the time of processing data, and the time of response of the system to the event and the environment. In the embodiments described herein, these activities and events occur substantially instantaneously.
[0022] The systems and processes are not limited to the specific embodiments described herein. Additionally, the components of each system and each process can be practiced independently of and separated from the other components and processes described herein. Each component and process can also be used in combination with other assemblies and processes.
[0023] Figure 1 The figure illustrates a block diagram of a process 100 for assessing potential cybersecurity threats to a subject system and determining potential countermeasures according to one embodiment of the present disclosure. In an exemplary embodiment, the process 100 is executed by one or more computer devices, such as Figure 4 the illustrated cybersecurity analysis (CSA) server 412.
[0024] In an exemplary embodiment, the CSA server 412 identifies 105 network hazard events. For the purposes of this discussion, a network hazard event refers to an event that is likely to cause damage caused by an adversary, such as a password leak, infection of a specific device, access to a specific device or network, or data loss. Network hazard events can include, but are not limited to, cybersecurity threats. Network hazard events can include abnormal network events (e.g., events caused by user error or random system failures) and adversarial events (e.g., events initiated by an adversary with the intention of causing a negative impact). In an exemplary embodiment, a hazard event is the result of a series of actions (including adversarial actions). These adversarial actions can actually be the hazard event itself or just other actions that cause the hazard event. The hazard event is the final result, which has a negative network impact. In some embodiments, the network hazard events are provided to the CSA server 412 by subject matter experts or other users. In other embodiments, the CSA server 412 receives a list of network hazard events to be analyzed. In other embodiments, the CSA server 412 receives the subject system and identifies 105 network hazard events to be analyzed using the subject system.
[0025] For the purposes of this discussion, the subject system is a security system. This can include computer equipment or a computer network, but also includes individuals associated with the system, the location of the system, and any other physical objects or software that provide access to the system. For example, the subject system can include a computer network. In such a case, the subject system will also include users who can access the computer network, the location of the hardware storage accessed by the computer network, the location where the user works, the supply chain that provides the subject system hardware, and any other hardware or software that an adversary can use to access the subject system. Additionally, the subject system can also be a supply chain, a server room or a vault, a paper document filing system, and / or any other system that needs to be protected against adversarial actions.
[0026] The CSA server 412 creates 110 an attack graph based on the subject system to be analyzed and the network hazard event. By treating a series of adversarial actions as nodes along a simple path, an attack path is created. An attack path is the "recipe" by which an adversary can influence a network hazard event. Any given hazard event can have multiple associated attack paths. The CSA server 412 organizes these attack paths by combining paths with common nodes in order to create 110 an attack graph structure for each hazard event. In an exemplary embodiment, the generated attack graph is a directed acyclic graph that defines an entry point (leaf node) and an end point (root node corresponding to the hazard event). For a given attack graph, the sequence of adversarial events that lead to the occurrence of the hazard event - the hazard event - is found by enumerating each path that starts at each leaf node and ends at the root node. The CSA server 412 attempts to include all reasonable paths to prevent underestimation. In an exemplary embodiment, the CSA server 412 excludes attack paths that are impossible or require the occurrence of impossible events using prior art.
[0027] In at least one embodiment, the CSA server 412 accesses a database of potential adversarial actions and historical attack paths to create 110 an attack graph. In this embodiment, the CSA server 412 receives information about the subject system to be analyzed and automatically creates 110 attack paths and an attack graph for the subject system.
[0028] For the purposes of this discussion, the term likelihood in this context refers to the probability of a harm event occurring. At a high level, the likelihood of a cybersecurity harm event is a function of the following factors (not necessarily independent): 1) Adversary intent: The adversary must choose the targets to exploit, as time and resources typically prevent exploitation of all targets; 2) Adversary capability: A given adversary generally cannot exploit any given target, where it is typically assumed that top-tier nation-state actors pose a significant cybersecurity threat; 3) System security / access: Systems can be isolated and protected by many countermeasures, and while some systems are difficult to penetrate, others are nearly impossible. While likelihood can be seen as a function of three factors, this assessment only considers the attributes of the system. The attributes of the adversary are difficult to determine and are typically only known after the adversary has exploited the system. Thus, generally only the attributes of the system are considered.
[0029] To distinguish the metrics used in this document from the broader concept of likelihood, the term "exploitability" is used. This level of exploitability is intended to express the threshold adversarial capabilities required to trigger a harm event. It is assumed that more exploitable systems are more easily attacked by less capable adversaries. Conversely, less exploitable systems can generally only be successfully attacked by more capable adversaries. In this interpretation, in the presence of some assumed adversary capabilities, exploitability can be seen as the basis for evaluating how securely a system generally resists attacks, regardless of adversarial intent.
[0030] The CSA server 412 determines values for exploitability and uncertainty for each node of each attack graph. In an exemplary embodiment, the system rates exploitability on an integer scale from 1 to 5. Exploitability corresponds to the adversary capabilities required to perform an action. Each node in the attack graph corresponds to a step in the attack. Thus, the CSA server 412 rates each node with an exploitability score. The exploitability score is an assessment of the adversarial capabilities required to perform that action and continue along the path in the attack graph towards a network harm event. The following table describes the correspondence between each exploitability level and the category of adversarial capabilities required.
[0031] Level Description of adversarial capabilities required for nodes 1 Top-level nation-state military / intelligence agencies with human intelligence 2 Lower-level nation-state agencies, organized crime groups, large professional hacking groups 3 Small-scale professional hackers / criminals 4 Professional hackers working alone or mostly alone 5 Individuals with basic technical skills equivalent to a bachelor's degree in engineering
[0032] Table 1
[0033] For this model, it is assumed that an adversary corresponding to the assigned availability level will successfully defeat the node 50% of the time when attempting to exploit it. For example, if a node is assigned an availability level of 3, this means that a small-scale professional hacker / criminal working together will successfully complete the corresponding action 50% of the time when attempting to take action. The fact is a statistical artifact and does not necessarily help in assigning an availability level to a node. For the purposes of this discussion, availability is considered a threshold of possible availability rather than a threshold of certain availability.
[0034] In addition to the availability level of each node, the CSA server 412 assigns an uncertainty level to the nodes. This uncertainty level captures the confidence associated with the availability level assigned by the assessor. If the availability level is considered accurate (e.g., a very high confidence that the assigned availability level corresponds to the actual availability), then the CSA server 412 assigns an uncertainty level of 1. If no knowledge of the required capabilities is available, the CSA server 412 will assign an uncertainty level of 4, indicating equal odds, to each of the 5 availability bins. In the latter case, the availability level is irrelevant as each level is assumed to be of equal odds. The following table describes the 4 uncertainty levels.
[0035]
[0036] Table 2
[0037] In at least one embodiment, the CSA server 412 accesses a database of actions associated with them and the values of availability and uncertainty to determine 115 the values of availability and uncertainty for each node of each attack graph. In this embodiment, the CSA server 412 receives information about the subject system to be analyzed and automatically determines 115 the values of availability and uncertainty for each node.
[0038] The CSA server 412 performs 120 aggregation on the availability of each attack path in the attack graph. After an availability level and an uncertainty level have been assigned to each node in the attack graph, the availability of each attack path through the attack graph can be calculated. In an exemplary embodiment, the CSA server 412 simulates attacks within the attack graph. Each node in the graph can be considered a filter that blocks or allows an attack based on adversary capabilities. A randomly selected adversary capability is applied to the head of each path and then filtered in sequence by each node. Attacks that pass through the attack graph from start to finish are collected in bins by the adversary capabilities to generate a distribution representing the aggregate filtering function for the entire path.
[0039] In some embodiments, the filters along each path can be multiplied together to obtain the same result. When the number of simulation trials approaches infinity, the limit of the aggregated filtering function at the end node is equal to the product of the filtering functions of each node. The latter method is much more computationally efficient. Once all paths for a given hazard event are aggregated into a set of filtering distributions, the maximum value is taken across all of these aggregated path distributions. The maximum value of the path distribution is the distribution at the node corresponding to the hazard event. From this maximum distribution, the aggregated availability and uncertainty levels of the hazard event node can be calculated.
[0040] Effectively, the CSA server 412 analyzes all attack paths for all potential adversaries to determine the distribution. In some embodiments, the CSA server 412 accesses a database of stored attack paths to determine the distribution of those attack paths that have been previously analyzed.
[0041] The aggregated availability level for a particular hazard event is based on the driver nodes in the attack graph. More specifically, the aggregated availability level is driven to its value by a small number of nodes (typically less than 10% of the nodes). By examining the attack graph, the CSA server 412 can identify these nodes. As a basic metric of this concept, the availability density distributions of each node in the attack graph can be added together to provide a view of the availability spread in the attack graph.
[0042] In some embodiments, a set of prototype attacks and exploits are stored in the database for comparison. For example, a table lists various attacks (e.g., inserting malicious components in the supply chain, penetrating the development environment, gaining access to a secure facility, etc.) and the values of baseline availability and uncertainty. Assumptions for the baseline availability and uncertainty levels are also provided. These assumptions can be used by the CSA server 412 and / or one or more users to adjust the baseline availability and uncertainty scores according to the needs of the actual application.
[0043] The CSA server 412 identifies the consequences of each network hazard event. In most network risk assessment methods, the consequences are captured on a semi - quantitative scale similar to likelihood. Such consequences are typically related to the mission of the system, where trivial consequences have no impact on the mission, and the most severe consequences are typically understood as complete mission failure and / or system loss. These methods are very effective in most cases and provide a basic understanding of the consequence distribution; however, the proportional differences between the various consequences remain unknown.
[0044] To improve this paradigm, the systems and methods described herein use financial data to estimate the monetized consequences of a hazard event. Compared to semi-quantitative consequences, these monetized consequences can show the proportional differences between different consequences. Although in some cases cost data may be difficult to determine, collecting monetized figures for a business or development project is achievable and should be done.
[0045] Once the monetized consequence data is known, the CSA server 412 applies a set of associated consequences to each hazard event and establishes the most likely consequence. In some industries, a consequence distribution is typically created and the expected value of that distribution is considered the most likely consequence. However, when considering adversarial attacks, it is reasonable to assume that the adversary will attempt the highest-cost consequence that can be expected from a given hazard event. This assumption largely eliminates the concept of a consequence distribution and results in a single value.
[0046] The CSA server 412 analyzes 130 the aggregated results and the identified consequences. In some embodiments, the CSA server 412 analyzes 130 the exploitability score of each path as well as the cost of the consequences. In some embodiments, the CSA server 412 compares the cost of the consequences with the cost of countermeasures to determine whether to use countermeasures to analyze the graph. This analysis can also guide the CSA server 412 in determining where and which countermeasures to use.
[0047] The CSA server 412 applies 135 countermeasures to the network hazard event and returns to steps 110 to 120. Once the baseline attack graph is constructed and the baseline exploitability, uncertainty, and consequences are calculated, the CSA server 412 can apply countermeasures as needed to reduce the overall exploitability of the network hazard event to reduce risk. These countermeasures can be added to the attack graph as additional nodes. Then, the overall exploitability can be recalculated, resulting in a mitigated network hazard event exploitability. The CSA server 412 is configured to consider a countermeasure if the assigned exploitability of the countermeasure node is less than or equal to the current minimum exploitability in all mitigation paths of the hazard event. This principle ensures that no countermeasures that do not actually mitigate any risk or contribute to defense in depth are added, thus saving processing resources and providing a streamlined set of countermeasures.
[0048] In some embodiments, the CSA server 412 considers countermeasures within a set. For example, a set of countermeasures can include countermeasures that balance risk reduction, cost impact, and schedule impact. Another set of countermeasures can include all countermeasures that can be reasonably applied to minimize risk. This gives the assessor (the CSA server 412 or the user) the opportunity to evaluate the countermeasures implemented (which may be a balanced set of countermeasures) compared to all possible sets of countermeasures. If the application of additional countermeasures beyond the balanced set does not substantially reduce risk, it can be determined that the additional countermeasures may be an inefficient use of resources.
[0049] When the CSA server 412 has completed all the analysis, the CSA server 412 generates 140 recommendations for the subject system being analyzed to mitigate cyber hazard events. These recommendations can include the cost / consequence of each hazard event, the cost for mitigation (adding countermeasures), the critical path or the highest availability path, and the risk with and without these countermeasures. This analysis helps the user determine which actions are the easiest and most cost-effective for mitigation.
[0050] Although the above steps of process 100 are described as being performed by the CSA server 412, in some embodiments, these steps can be performed by a combination of the CSA server 412 and one or more users. In some embodiments, the CSA server 412 can perform one or more steps and then provide the results of these steps to the user or subject matter expert for potential adjustment.
[0051] In at least one embodiment, the analysis process can be mathematically expressed, including a truncated normal distribution for availability, multiple normalizations to facilitate the use of the truncated normal distribution, multiple methods for aggregating attack paths into a single availability and uncertainty level for each hazard event, and a metric for countermeasure use.
[0052] The truncated normal distribution can be used to describe availability. The truncated normal distribution is a normal distribution that has been truncated at certain limits a and b. A scale factor is applied to the truncated density function to renormalize the integral of the probability density function to 1. If fμ,σ(x) provides the normal distribution probability density function (PDF), then the truncated normal distribution PDF fμ,σ,a,b(x) is given by Equation 1:
[0053] For x ∈ (a, b), Otherwise, its value is 0 Equation 1 where μ is the mean, σ is the standard deviation, a is the lower truncation, and b is the upper truncation.
[0054] The scales of 1 to 5 described previously are used to quantify the exploitability. Since the exploitability can be considered similar to probability, it is normalized to a scale of 0 to 1 for further calculations. This normalization also naturally achieves the desired stability property of the "standard" operations using real numbers in the attack graph calculation. Equation 2 offsets the center of each exploitability bin by 0.2 from the center of the adjacent exploitability bin and starts the exploitability 1 at 0.1.
[0055]
[0056] Where is the normalized exploitability E is the assigned exploitability level (effectively E ∈ [0.5:5.5], but is assigned such that E ∈ {1, 2, 3, 4, 5}). This normalization generates an aggregated exploitability for the attack paths. In addition to the exploitability of the node itself, this aggregated exploitability is also a function of the path length in part. This represents a problem that the more actions an adversary has to take, the more difficult the attack actually is.
[0057] For each uncertainty level, a standard deviation corresponding to the definition of the level is provided. These standard deviations are shown below. These standard deviations apply only to the normalized exploitability (e.g., ).
[0058] Level (U) <![CDATA[Standard deviation (σ E )]]> 1 0.05 2 0.15 3 0.4 4 100
[0059] Table 3
[0060] The standard deviation for the case of level 4 (uniform distribution) will generally be considered infinite (e.g., σ E = ∞), but in this case an approximation is used, accurate to several decimal places.
[0061] The uncertainty of the exploitability of each node is specified as a scale of 1 to 4 divided into 4 bins. Calculations can be performed using a truncated normal distribution, where the standard deviation is mapped to each uncertainty bin. Once the calculations are complete, the standard deviation values are converted back to a semi-quantized binary domain. The following function allows for interpolation of values using a smooth piecewise function.
[0062] Equation 3 is used as a smooth piecewise function for the semi-quantized input value U ∈ [0, 4], which gives the standard deviation value σ E ∈ [0, 100] assigned according to the above table.
[0063]
[0064] Where σ E is the standard deviation of the normalized exploitability, and U is the assigned exploitability uncertainty level.
[0065] As described above, the exploitability score corresponds to an adversarial ability with an equal probability of completing the actions corresponding to the assigned nodes. This concept further implies that the probability of completing an action should be lower for a disadvantaged opponent and higher for an advantaged opponent. The spread of these probabilities is proportional to the uncertainty. Conceptually, this creates a filter at each node, and the stronger the opponent, the easier it is to pass through this filter. Mathematically, this can be represented by the complementary function of the cumulative density function of exploitability (e.g., the survival function S(x)) (Equation 4):
[0066]
[0067] where is the cumulative density function of the truncated normal distribution (assuming a = 0 and b = 1), is the normalized exploitability level, σ E is the corresponding standard deviation of the normalized uncertainty level shown in the above table, and x represents the normalized exploitability level (e.g., x ∈ [0,1]).
[0068] To aggregate the exploitability along a path, the survival function of each node is formed by using multiplication on the set of nodes N in the path, so as to generate the aggregated S x (x) for path p in the attack graph (Equation 5). px (x) (Equation 5).
[0069]
[0070] where N(p x ) is the set of nodes in path p x , is the survival function of node n ∈ N(p x ), and x represents the normalized exploitability level (e.g., x ∈ [0,1]).
[0071] This can be used to aggregate the distribution of a given hazard event. The maximum function can be used to create the aggregated survival function for each path p x in the set of paths P associated with a specific hazard event (Equation 6).
[0072]
[0073] where S p (x) is the fully aggregated survival function of the hazard event, S px (x) is the survival function of path p x ∈ P, and P is the set of all paths leading to the relevant hazard event.
[0074] Once the S P(x), the aggregated average value and uncertainty can be calculated. These values will be within a normalized scale (e.g., and σ E ∈ [0, 100]) and will need to be converted back to the semi-quantized domain (e.g., E ∈ [0.5:5.5] and U ∈ [0, 4]) respectively.
[0075] To increase the means of resistance, the resistance means depth D(x) is defined as:
[0076]
[0077] where N(P) is the set of unique nodes in the attack graph with the path set P, is the PDF of the truncated normal distribution of the normalized exploitability and standard deviation of the given node n, and x represents the normalized exploitability level (e.g., x ∈ [0, 1]).
[0078] Figure 2 The figure illustrates an exemplary attack path graph 200 according to an embodiment of the present disclosure. In the exemplary embodiment, FIG. 200 reflects a simplified view of various attack paths that an adversary can take to obtain the Wi-Fi password of a wireless local area network. Thus, the network hazard event in this example is the leakage of the router's password. In FIG. 200, each node 205 represents an action, and node A 210 represents the network hazard event itself.
[0079] Each node 205 includes an exploitability score followed by an uncertain number (e.g., 3, 2). The descriptions, exploitability scores, and uncertainty numbers of all the nodes 205 shown in Figure 2 are described below in Table 4.
[0080]
[0081] Table 4
[0082] As Figure 2 shown, each node 205 represents an action that an adversary can take. The exploitability score represents the adversary's ability required to perform the action. The uncertainty level captures the confidence associated with the assignment of the exploitability score. For example, the action of node M is to install malware on the router. The exploitability score for this action is 1, which represents a top-tier nation-state military / intelligence agency. The uncertainty level for this score is 2, representing a 25% uncertainty level.
[0083] Figure 3 The figure illustrates another exemplary attack path graph 300 with resistance means according to an embodiment of the present disclosure. In the exemplary embodiment, FIG. 300 reflects FIG. 200 with the added resistance means 305 (node N) as Figure 2A simplified view (as shown). The countermeasure 305 is a periodic password change, so the associated adversarial action is to prevent the periodic password change. The exploitability score assigned to this action is 1, which means it requires a top-tier nation-state military / intelligence agency. The exploitability score has an uncertainty value of 1, which represents 5% uncertainty, and on this scale it is the most certain. Thus, for most of the attack paths shown, changing the password periodically reduces the risk of using that attack path. However, the impact on the attack path from node M, which is installing malware on a router, is not shown.
[0084] Figure 4 is for evaluating potential cybersecurity threats to a subject system, such as through Figure 1 A simplified block diagram of an example system 400 for evaluating potential cybersecurity threats to a subject system, such as through the process shown. In an exemplary embodiment, the system 400 is used to evaluate potential cybersecurity threats to a subject system and determine potential countermeasures for mitigating these potential cybersecurity threats. Additionally, the system 400 is a cybersecurity management system that includes a Cybersecurity Analysis (CSA) computer device 412 (also referred to as a CSA server), which is configured to analyze cybersecurity threats and determine countermeasures.
[0085] As described in more detail below, the CSA server 412 is programmed to analyze the subject system for potential hazard events. The CSA server 412 is programmed to: a) receive the subject system to be analyzed; b) determine potential hazard events associated with the subject system; c) generate an attack graph associated with the potential hazard events, where the attack graph includes multiple actions; d) determine the exploitability score for each of the multiple actions; e) determine the uncertainty level for each of the multiple actions based on the corresponding exploitability score; f) aggregate the multiple actions including the corresponding exploitability scores and corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; and g) generate a response to the one or more vulnerabilities of the subject system.
[0086] In an example embodiment, the client system 414 is a computer including a web browser or software application that enables the client system 414 to communicate with the CSA server 412 using the Internet, a local area network (LAN), or a wide area network (WAN). In some embodiments, the client system 414 is communicatively coupled to the Internet through a plurality of interfaces including, but not limited to, at least one of a network (such as the Internet, LAN, WAN, or integrated services digital network (ISDN)), a dial-up connection, a digital subscriber line (DSL), a cellular phone connection, a satellite connection, and a cable modem. The client system 414 can be any device capable of accessing a network such as the Internet, including, but not limited to, a desktop computer, a laptop computer, a personal digital assistant (PDA), a mobile phone, a smart phone, a tablet computer, a phablet, or other web-based connectable devices.
[0087] The database server 416 is communicatively coupled to a database 420 that stores data. In one embodiment, the database 420 is a network security database including computer device and network configurations, network security threats, attack paths, countermeasures, and computer device models. In some embodiments, the database 420 is stored remotely from the CSA server 412. In some embodiments, the database 420 is decentralized. In an example embodiment, a person can access the database 420 via the client system 414 by logging in to the CSA server 412.
[0088] Figure 5 The illustration depicts an example configuration of a Figure 4 client system 414 according to one embodiment of the present disclosure. A user computer device 502 is operated by a user 501. The user computer device 502 can include, but is not limited to, the client system 414 (as Figure 4 illustrated). The user computer device 502 includes a processor 505 for executing instructions. In some embodiments, executable instructions are stored in a memory region 510. The processor 505 can include one or more processing units (e.g., in a multi-core configuration). The memory region 510 is any device that allows information such as executable instructions and / or transaction data to be stored and retrieved. The memory region 510 can include one or more computer-readable media.
[0089] The user computer device 502 also includes at least one media output component 515 for presenting information to the user 501. The media output component 515 is any component capable of communicating information to the user 501. In some embodiments, the media output component 515 includes an output adapter (not shown), such as a video adapter and / or an audio adapter. The output adapter is operatively coupled to the processor 505 and is operatively coupled to an output device such as a display device (e.g., a cathode ray tube (CRT), a liquid crystal display (LCD), a light emitting diode (LED) display, or an “electronic ink” display) or an audio output device (e.g., speakers or headphones). In some embodiments, the media output component 515 is configured to present a graphical user interface (e.g., a web browser and / or a client application) to the user 501. The graphical user interface may include, for example, an interface for viewing the analysis results of one or more subject systems. In some embodiments, the user computer device 502 includes an input device 520 for receiving input from the user 501. The user 501 may use the input device 520 to (non-limitingly) select a computer system for which to view the analysis. The input device 520 may include, for example, a keyboard, a pointing device, a mouse, a stylus, a touch-sensitive panel (e.g., a touchpad or a touch screen), a gyroscope, an accelerometer, a position detector, a biometric input device, and / or an audio input device. A single component such as a touch screen may function both as an output device of the media output component 515 and as the input device 520.
[0090] The user computer device 502 may also include a communication interface 525 that is communicatively coupled to a remote device such as the CSA server 412, as Figure 4 shown. The communication interface 525 may include, for example, a wired or wireless network adapter and / or a wireless data transceiver for use with a mobile telecommunications network.
[0091] For example, stored in the memory region 510 are computer-readable instructions for providing a user interface to the user 501 via the media output component 515 and optionally receiving and processing input from the input device 520. In other possibilities, the user interface may include a web browser and / or a client application. The web browser enables a user (such as the user 501) to display media and generally other information embedded in a web page or website from the CSA server 412 and interact with it. The client application allows the user 501 to interact with, for example, the CSA server 412. For example, the instructions may be stored by a cloud service, and the output of the execution of the instructions is sent to the media output component 515.
[0092] The processor 505 executes computer-executable instructions for implementing various aspects of the present disclosure. In some embodiments, the processor 505 is programmed by executing computer-executable instructions or otherwise to be transformed into a dedicated microprocessor.
[0093] Figure 6 The illustration depicts an example configuration of the Figure 4 server system 412 according to one embodiment of the present disclosure. The server computer device 601 may include, but is not limited to, a database server 416 and a CSA server 412 (both shown in Figure 4 ). The server computer device 601 also includes a processor 605 for executing instructions. The instructions may be stored in the memory region 610. The processor 605 may include one or more processing units (e.g., in a multi-core configuration).
[0094] The processor 605 is operatively coupled to a communication interface 615 such that the server computer device 601 is capable of communicating with remote devices such as another server computer device 601, another CSA server 412, or a client system 414 (as Figure 4 shown). For example, the communication interface 615 may receive requests from the client system 414 via the Internet, as Figure 4 shown.
[0095] The processor 605 may also be operatively coupled to a storage device 634. The storage device 634 is any computer-operable hardware suitable for storing and / or retrieving data such as, but not limited to, data associated with the database 420 (as Figure 4 shown). In some embodiments, the storage device 634 is integrated in the server computer device 601. For example, the server computer device 601 may include one or more hard disk drives as the storage device 634. In other embodiments, the storage device 634 is external to the server computer device 601 and may be accessed by multiple server computer devices 601. For example, the storage device 634 may include a storage area network (SAN), a network-attached storage (NAS) system, and / or multiple storage units such as hard disks and / or solid state drives in a redundant array of inexpensive disks (RAID) configuration.
[0096] In some embodiments, the processor 605 is operably coupled to a storage device 634 via a storage interface 620. The storage interface 620 is any component capable of providing the processor 605 access to the storage device 634. The storage interface 620 may include, for example, an Advanced Technology Attachment (ATA) adapter, a Serial ATA (SATA) adapter, a Small Computer System Interface (SCSI) adapter, a RAID controller, a SAN adapter, a network adapter, and / or any component that provides the processor 605 access to the storage device 634.
[0097] The processor 605 executes computer-executable instructions for implementing various aspects of the present disclosure. In some embodiments, the processor 605 is transformed into a dedicated microprocessor by executing computer-executable instructions or by other means. For example, the processor 605 is programmed using instructions such as Figure 7 those shown.
[0098] Figure 7 is a flowchart according to an embodiment of the present disclosure, which illustrates an example of a process 700 for evaluating potential cybersecurity threats to a subject system and determining potential countermeasures using the system 400 as Figure 4 shown. The process 700 may be implemented by a computing device, such as the CSA server 412 as Figure 4 shown.
[0099] In an exemplary embodiment, the CSA server 412 receives 705 the subject system to be analyzed. The subject system may be, but is not limited to, a computer device, an Internet of Things device, or a computer network, as well as the hardware, software, and personnel that an adversary may compromise in order to access the subject system. In an exemplary embodiment, the CSA server 412 may receive information about the subject system to be analyzed, including but not limited to the brand, model, configuration, current settings, other connected devices, and any other information required to correctly identify the subject system. In some embodiments, the CSA server 412 may look up the subject system in a database such as the database 420 as Figure 4 shown.
[0100] In an exemplary embodiment, the CSA server 412 determines 710 potential hazard events associated with the subject system. In some embodiments, the CSA server 412 retrieves potential hazard events from the database 420. The potential hazard events may be determined 710 based on similar subject systems and previously performed analyses. Although only a single potential hazard event is mentioned, in an exemplary embodiment, the CSA server 412 may determine all potential hazard events that may be associated with the received subject system and perform the analysis described herein for each potential hazard event.
[0101] In an exemplary embodiment, the CSA server 412 generates 715 an attack graph associated with a potential hazard event. The attack graph includes a plurality of actions and may be similar to Figure 2 the attack graph shown therein. Each of the plurality of actions represents an adversarial action.
[0102] In an exemplary embodiment, the CSA server 412 determines 720 an exploitability score for each of the plurality of actions in a potential hazard event. The exploitability score represents the level of adversary capability to perform the corresponding action. The CSA server 412 determines 725 an uncertainty level for each of the plurality of actions based on the corresponding exploitability score. The uncertainty level represents the confidence level associated with the determination of the exploitability score. In some embodiments, the CSA server 412 retrieves the exploitability score and the uncertainty level from a previously performed analysis. In other embodiments, the CSA server 412 calculates the exploitability score and the uncertainty level based on one or more rules and historical values.
[0103] In an exemplary embodiment, the CSA server 412 aggregates 730 the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system. In some embodiments, the CSA server 412 performs a mathematical analysis of the exploitability scores and the uncertainty levels. In some embodiments, the attack graph includes a plurality of attack paths. Each attack path includes one or more of the plurality of actions. The CSA server 412 aggregates each of the plurality of attack paths based on one or more actions associated with the corresponding attack path. In these embodiments, one or more vulnerabilities are based on at least one of the plurality of attack paths.
[0104] In an exemplary embodiment, the CSA server 412 generates 735 a response to one or more vulnerabilities of the subject system. In some embodiments, the response is a report regarding potential vulnerabilities and their associated risk levels and the subject system. In other embodiments, the response may include potential countermeasures and the costs associated with those countermeasures.
[0105] In some embodiments, the CSA server 412 may determine one or more countermeasures based on one or more vulnerabilities. These countermeasures may be determined based on information in the database 420. The CSA server 412 applies the one or more countermeasures to the attack graph and re-performs the above analysis to determine the effectiveness of the one or more countermeasures. The CSA server 412 re-aggregates the plurality of actions based on the one or more countermeasures.
[0106] In some embodiments, the CSA server 412 determines a plurality of potential hazard events of the subject system. The CSA server 412 generates an attack graph for each of the plurality of potential hazard events. Then, the CSA server 412 aggregates a plurality of actions of each of the plurality of attack graphs based on the corresponding plurality of exploitability scores and a plurality of uncertainty levels to determine one or more vulnerabilities of the subject system.
[0107] At least one technical solution to the technical problems provided by the present system may include: (i) improving the security system; (ii) reducing the time and cost of protecting the subject system; (iii) capturing considerations outside the subject system that affect the subject system (as discussed above); (iv) identifying the most cost-effective means of resistance; and (v) analyzing the security of the system based on potential countermeasure actions.
[0108] The methods and systems described herein can be implemented using computer programming or engineering techniques, including computer software, firmware, hardware, or any combination or subset thereof. As described above, at least one technical problem of existing systems is that the systems need a cost-effective and reliable way to analyze potential adversarial cybersecurity threats to computer systems. The systems and methods described herein solve this technical problem. In addition, at least one technical solution to the technical problems provided by the present system may include: (i) improving the security system; (ii) increasing the understanding of potential attack paths of the system; (iii) determining the effectiveness of different means of resistance in different systems; and (iv) improving the time and efficiency of performing an assessment on the system or the subject system.
[0109] The methods and systems described herein can be implemented using computer programming or engineering techniques, including computer software, firmware, hardware, or any combination or subset thereof, wherein the technical effects can be achieved by performing at least one of the following steps: (a) receiving a subject system to be analyzed; (b) determining potential hazard events associated with the subject system; (c) generating an attack graph associated with the potential hazard events, wherein the attack graph includes a plurality of actions; (d) determining an exploitability score for each of the plurality of actions; (e) determining an uncertainty level for each of the plurality of actions based on the corresponding exploitability score; (f) aggregating the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; and (g) generating a response to the one or more vulnerabilities of the subject system.
[0110] The technical effect can also be achieved by performing at least one of the following steps: (a) receiving a subject system to be analyzed, where the subject system to be analyzed is at least one of a computer and a computer network; (b) determining potential hazard events associated with the subject system; (c) generating an attack graph associated with the potential hazard events, where the attack graph includes a plurality of actions, where the attack graph includes a plurality of attack paths, where each attack path includes one or more actions among the plurality of actions, and where each of the plurality of actions is an adversarial action; (d) determining an exploitability score for each of the plurality of actions, where the exploitability score represents the level of opponent ability to perform the corresponding action; (e) determining an uncertainty level for each of the plurality of actions based on the corresponding exploitability score, where the uncertainty level represents the confidence level associated with the determination of the exploitability score; (f) aggregating the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; (g) aggregating each of the plurality of attack paths based on one or more actions associated with the corresponding attack path; (h) determining one or more countermeasures based on the one or more vulnerabilities; (i) applying the one or more countermeasures to the attack graph; (j) aggregating the plurality of actions based on the one or more countermeasures; and (k) generating a response to the one or more vulnerabilities of the subject system, where the one or more vulnerabilities are based on at least one of the plurality of attack paths.
[0111] In addition, the technical effect can also be achieved by performing at least one of the following steps: (a) determining a plurality of potential hazard events of the subject system; (b) generating an attack graph for each of the plurality of potential hazard events; and (c) aggregating the plurality of actions of each of the plurality of attack graphs based on the corresponding plurality of exploitability scores and the corresponding plurality of uncertainty levels to determine one or more vulnerabilities of the subject system.
[0112] The computer-implemented methods discussed herein may include additional, fewer, or alternative actions, including those discussed in other parts of this document. These methods may be implemented via one or more local or remote processors, transceivers, servers, and / or sensors (such as processors, transceivers, servers, and / or sensors installed on a vehicle or mobile device or associated with smart infrastructure or a remote server), and / or via computer-executable instructions stored on one or more non-transitory computer-readable media. Additionally, the computer systems discussed herein may include additional, fewer, or alternative functions, including those discussed in other parts of this document. The computer systems discussed herein may include or be implemented via computer-executable instructions stored on one or more non-transitory computer-readable media.
[0113] As used herein, the term "non-transitory computer-readable medium" is intended to represent any tangible computer-based device implemented in any method or technology for short-term and long-term storage of information such as computer-readable instructions, data structures, program modules and sub-modules, or other data in any device. Thus, the methods described herein may be encoded as executable instructions implemented in a tangible non-transitory computer-readable medium, including but not limited to storage devices and / or memory devices. When executed by a processor, such instructions cause the processor to perform at least a portion of the methods described herein. Additionally, as used herein, the term "non-transitory computer-readable medium" includes all tangible computer-readable media, including but not limited to non-transitory computer storage devices (including but not limited to volatile and non-volatile media, as well as removable and non-removable media such as firmware, physical and virtual storage, CD-ROM, DVD, and any other digital source such as a network or the Internet) and digital means not yet developed, with the sole exception being transitory propagated signals.
[0114] This written description uses examples to disclose various embodiments, including the best mode, and also enables those skilled in the art to practice the various embodiments, including making and using any device or system and performing any incorporated methods. The patentable scope of this disclosure is defined by the claims and may include other examples that occur to those skilled in the art. Such other examples are intended to be within the scope of the claims if they have structural elements that do not differ from the literal language of the claims, or if they contain equivalent structural elements that do not differ substantially from the literal language of the claims.
Claims
1. A cybersecurity analysis system for evaluating potential cybersecurity threats to a subject system, the system comprising: A computing device including at least one processor in communication with at least one memory device, wherein the at least one processor is programmed to: Receive a subject system to be analyzed; Determine potential hazard events associated with the subject system; Generate an attack graph associated with the potential hazard events, wherein the attack graph includes a plurality of actions and the potential hazard events that are the endpoints of the attack graph; Determine an exploitability score for each of the plurality of actions; Based on the corresponding exploitability score, determine an uncertainty level for each of the plurality of actions; Aggregate the plurality of actions including the corresponding exploitability score and the corresponding uncertainty level based on the corresponding exploitability score and the corresponding uncertainty level to determine one or more vulnerabilities of the subject system; and Generate a response to the one or more vulnerabilities of the subject system.
2. The system according to claim 1, wherein the subject system to be analyzed is at least one of a computer or a computer network.
3. The system according to claim 1, wherein the exploitability score represents the level of adversary capabilities to perform the corresponding action.
4. The system according to claim 1, wherein the uncertainty level represents the confidence level associated with the determination of the exploitability score.
5. The system according to claim 1, wherein the at least one processor is further programmed to: Determine one or more countermeasures based on the one or more vulnerabilities; Apply the one or more countermeasures to the attack graph; and Aggregate the plurality of actions based on the one or more countermeasures.
6. The system according to claim 1, wherein the at least one processor is further programmed to: Determine a plurality of potential hazard events of the subject system; Generate a plurality of attack graphs based on each of the plurality of potential hazard events; and Aggregate the plurality of actions of each of the plurality of attack graphs based on the corresponding plurality of exploitability scores and the corresponding plurality of uncertainty levels to determine one or more vulnerabilities of the subject system.
7. The system according to claim 1, wherein the attack graph includes a plurality of attack paths, and wherein each attack path includes one or more actions from the plurality of actions.
8. The system according to claim 7, wherein the at least one processor is further programmed to aggregate each of the plurality of attack paths based on the one or more actions associated with the corresponding attack path.
9. The system according to claim 7, wherein the one or more vulnerabilities are based on at least one of the plurality of attack paths.
10. The system according to claim 1, wherein each of the plurality of actions is an adversarial action.
11. A method for evaluating potential cybersecurity threats to a subject system, the method implemented on a computing device including at least one processor in communication with at least one memory device, the method comprising: Receive a subject system to be analyzed; Determine potential hazard events associated with the subject system; Generate an attack graph associated with the potential hazard events, wherein the attack graph includes a plurality of actions and the potential hazard events that are the endpoints of the attack graph; Determine an exploitability score for each of the plurality of actions; Determine an uncertainty level for each of the plurality of actions based on the corresponding exploitability score; Aggregate the plurality of actions including the corresponding exploitability scores and the corresponding uncertainty levels based on the corresponding exploitability scores and the corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; And Generate a response to the one or more vulnerabilities of the subject system.
12. The method according to claim 11, wherein the subject system to be analyzed is at least one of a computer or a computer network.
13. The method according to claim 11, wherein the exploitability score represents the level of adversary capabilities for performing the corresponding action.
14. The method according to claim 11, wherein the uncertainty level represents the confidence level associated with the determination of the exploitability score.
15. The method according to claim 11, further comprising: Determine one or more countermeasures based on the one or more vulnerabilities; Apply the one or more countermeasures to the attack graph; And Aggregate the plurality of actions based on the one or more countermeasures.
16. The method according to claim 11, further comprising: Determine a plurality of potential hazard events of the subject system; Generate a plurality of attack graphs based on each of the plurality of potential hazard events; And Aggregate the plurality of actions of each of the plurality of attack graphs based on the corresponding plurality of exploitability scores and the corresponding plurality of uncertainty levels to determine one or more vulnerabilities of the subject system.
17. The method according to claim 11, wherein each attack graph of the plurality of attack graphs includes a plurality of attack paths, wherein each attack path includes one or more of the plurality of actions, and wherein the method further comprising: Aggregate each of the plurality of attack paths based on the one or more actions associated with the corresponding attack path.
18. The method according to claim 17, wherein the one or more vulnerabilities are based on at least one of the plurality of attack paths.
19. The method according to claim 11, wherein each of the plurality of actions is an adversarial action.
20. A non-transitory computer-readable medium having computer-executable instructions implemented thereon, wherein, When executed by at least one processor coupled to a memory device, the computer-executable instructions cause the processor to: Receive a subject system to be analyzed, wherein the subject system to be analyzed is at least one of a computer or a computer network; Determine potential hazard events associated with the subject system; Generate an attack graph associated with the potential hazard event, wherein the attack graph includes a plurality of actions and the potential hazard event as an end point of the attack graph; Determine an exploitability score for each of the plurality of actions, wherein the exploitability score represents the level of adversary capabilities to perform the corresponding action; Determine an uncertainty level for each of the plurality of actions based on the corresponding exploitability score, wherein the uncertainty level represents the confidence level associated with the determination of the exploitability score; Aggregate the plurality of actions including the corresponding exploitability scores and corresponding uncertainty levels based on the corresponding exploitability scores and corresponding uncertainty levels to determine one or more vulnerabilities of the subject system; Determine one or more countermeasures based on the one or more vulnerabilities; Apply the one or more countermeasures to the attack graph; Aggregate the plurality of actions based on the one or more countermeasures; And Generate a response to the one or more vulnerabilities of the subject system.
Citation Information
Patent Citations
System and method for risk detection and analysis in a computer network
US20050193430A1