METHOD FOR ANALYSIS OF THE VULNERABILITY OF AN INFORMATION SYSTEM AGAINST A CYBER ATTACK
Patent Information
- Application Number
- DE602022016585
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-09-30
- Filing Date
- 2022-09-28
- Publication Date
- 2025-06-25
- Estimated Expiration
- 2042-09-28
AI Technical Summary
Existing cyber threat risk analysis methods, such as penetration testing, are not scalable, time-fixed, and suffer from auditor bias, and cannot assess the projected effectiveness of security measures.
A computer-implemented method simulating cyber attacks through Monte Carlo simulations to estimate the probability of success, considering the sophistication of both attacker and defender procedures, allowing for scalable and up-to-date vulnerability assessments across an organization's information system.
Enables scalable and harmonized vulnerability assessments that adapt to organizational changes, providing precise impact calculations and recommendations for improving cybersecurity measures.
Description
TECHNICAL FIELD
[0001] The field of the invention is that of cybersecurity and more particularly that of the analysis of the vulnerability of an information system to a computer attack. PRIOR ART
[0002] As part of cyber threat risk analysis, we seek to assess the likelihood that a malicious actor will successfully carry out a computer attack against a given organization. To do this, the classic approach is to carry out a penetration test ("pentest") on the organization's information system (IS), and more specifically a so-called Red Team test, namely an intrusion test under real conditions simulating an attack mode of operation (referred to as "MOA" in what follows).
[0003] Although this approach allows for precise results to be obtained and compared with the reality of the defense put in place by the organization, it nevertheless has characteristics that make it insufficient.
[0004] First, this approach is not scalable. While a Red Team exercise can be carried out on a portion of the information system by simulating a specific operating procedure, it is unthinkable to test all existing operating procedures against the entire information system of a large group.
[0005] Then, it is fixed in time. Indeed, if a Red Team exercise provides a snapshot at a given moment of the state of the defense of an IS against a particular operating mode, any change in the operating mode or the structure of the IS requires an update and therefore the performance of a new intrusion test.
[0006] Furthermore, this approach depends on the auditor performing the penetration test, not the attacker. Each auditor has unique tools, resources, experience, and cybersecurity knowledge, which introduces bias into the penetration test and makes it difficult to standardize results across an organization.
[0007] Finally, while a penetration test can generate security recommendations, it cannot assess their projected effectiveness. Therefore, if you want to know the potential return on investment of a security measure, you must first deploy it and then perform a new penetration test to compare it with the previous one.
[0008] US 7,926,113 B1 describes systems and methods for managing multiple vulnerability scanners distributed across one or more networks. By distributing multiple scanners across a network, the workload of each scanner can be reduced. In addition, the scanners can be placed directly behind firewalls for more in-depth analysis. In addition, the scanners can be placed closer to the networks being scanned. By placing the vulnerability scanners closer, the actual scanning traffic does not traverse the core network switching and routing fabric, thus avoiding potential network outages due to scanning activity. In addition, the shorter distance between the scanners and the scanned targets speeds up scanning times by reducing the distance that packets must travel. STATEMENT OF THE INVENTION
[0009] The invention aims to propose a tool for analyzing risks related to cyber threats that overcomes these drawbacks. To this end, the invention proposes a method for estimating the probability of success of a computer attack without having to carry out the intrusion test, a method that exploits the level of sophistication of the MOAs targeting an organization and the level of sophistication of the security procedures deployed by the organization both in terms of passive defense procedures and in terms of active defense procedures.
[0010] The invention more particularly proposes a computer-implemented method for analyzing the vulnerability of an information system to a computer attack carried out by an attacker, the computer attack propagating along one or more compromise paths, each consisting of a succession of at least one computer asset including an input computer asset. This method comprises, for each of the compromise path(s): carrying out a plurality of simulations of propagation of the computer attack on the compromise path, where each simulation comprises for each of the computer assets of the compromise path the steps consisting of: ∘ determining a first defensive score (SDP) representative of a capacity of a cybersecurity procedure ensuring passive defense of the computer asset to block the computer attack, by carrying out at least one random draw with a selection probability which depends on a sophistication of the cybersecurity procedure ensuring passive defense and an uncertainty on said sophistication;∘ determine a first offensive score (SOP) representative of a capacity of the computer attack to compromise the cybersecurity procedure ensuring the passive defense of the IT asset, by carrying out at least one random draw with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring the passive defense and an uncertainty on said sophistication; ∘ determine a second defensive score (SDR) representative of a capacity of a cybersecurity procedure ensuring an active defense of the IT asset to block the computer attack, by carrying out at least one random draw with a selection probability which depends on a sophistication of the cybersecurity procedure ensuring the active defense and an uncertainty on said sophistication;∘ determine a second offensive score (SOR) representative of a capacity of the computer attack to compromise the cybersecurity procedure ensuring the active defense of the IT asset, by carrying out at least one random draw with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring the active defense and an uncertainty on said sophistication; ∘ determine a failure (ECH) of the IT asset by comparing the first offensive score with the first defensive score and by comparing the second offensive score with the second defensive score; ∘ determine a compromise of the IT asset in the event of a determined failure of said asset and of each of the IT asset(s) upstream of said asset in the compromise path when said asset is not the input IT asset;the determination of a vulnerability indicator of an IT asset of the compromise path based on the number of simulations for which a compromise of said asset was determined.;
[0011] This process allows, on the one hand, to scale up the principle of intrusion testing, since simulations can be carried out in a reasonable time and with harmonized results across all of an organization's information systems and for all known project owners. On the other hand, this process ensures a scalable nature since the results can be kept up to date over time, depending on the evolution of the interest of the project owners in the organization, their sophistication and their repertoires of attack procedures as well as depending on the evolution of the security procedures deployed by the organization.
[0012] Some preferred but non-limiting aspects of this method are as follows: the computer attack carried out by the attacker on an IT asset comprises one or more attack procedures aimed at compromising the cybersecurity procedure ensuring passive defense or the cybersecurity procedure ensuring active defense; the at least one random draw with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring passive defense, respectively active defense, and an uncertainty on said sophistication comprises, for each of the IT assets of the compromise path and for each of the attack procedures aimed at compromising the cybersecurity procedure ensuring passive defense, respectively active defense, the random draw of a first, respectively second, offensiveness indicator with a selection probability which depends on a sophistication of the attack procedure and an uncertainty on said sophistication;and the first, respectively second, offensive score is determined from the first, respectively second, offensiveness indicators drawn for each of the attack procedures aimed at compromising the cybersecurity procedure ensuring active defense, respectively passive defense; the cybersecurity procedure ensuring passive defense, respectively active defense, activated at the level of an IT asset comprises one or more security measures which ensure a cybersecurity function of the passive defense type, respectively of the active defense type, against the attack procedures aimed at compromising the cybersecurity procedure ensuring passive defense, respectively active defense;the at least one random draw with a selection probability that depends on a sophistication of the cybersecurity procedure ensuring passive defense, respectively active defense, and an uncertainty about said sophistication comprises, for each of the IT assets of the compromise path and for each of the security measures that ensure a cybersecurity function of the passive defense type, respectively active defense type, the random draw of a first, respectively second, defense indicator with a selection probability that depends on a sophistication of the security measure and an uncertainty about said sophistication; and the first, respectively second, defensive score is determined from the first, respectively second, defense indicators, drawn for each of said security measures that ensure a cybersecurity function of the passive defense type, respectively active defense type;it further comprises the pseudo-random determination of a capacity of a cybersecurity procedure of the detection type activated at the level of the IT asset to detect the computer attack, of a capacity of a cybersecurity procedure of the response type activated at the level of the IT asset to block the computer attack, of a capacity of the computer attack to compromise the cybersecurity procedure of the detection type, and of a capacity of the computer attack to compromise the cybersecurity procedure of the response type;an absence of defeat of an IT asset is determined: when the first defensive score is higher than the first offensive score, or otherwise, both when the capacity of the detection-type cybersecurity procedure to detect the IT attack is higher than the capacity of the IT attack to compromise the detection-type cybersecurity procedure and when the capacity of the response-type cybersecurity procedure to block the IT attack is higher than the capacity of the IT attack to compromise the response-type cybersecurity procedure; each of the first and second defensive scores is increased by a bonus based on a capacity of an identification-type cybersecurity procedure activated at the IT asset;it further comprises, in a simulation of propagation of the computer attack on a compromise path, the observation that the attack is blocked in the event of failure to determine a failure for at least one of the computer assets of the compromise path; it further comprises the determination that the attack is blocked by the cybersecurity procedure ensuring passive defense or by the cybersecurity procedure ensuring active defense of a computer asset determined as not being defeated; it further comprises the determination of a depth level of the computer attack blocked on a compromise path as being the computer asset preceding the first computer asset of the compromise path for which a failure is not determined;each simulation further comprises a step consisting, for each of the assets in the compromise path, of pseudo-randomly determining a capacity of a cybersecurity procedure of the remediation type activated at the level of the IT asset to remedy the IT attack and a step consisting of calculating an impact of the attack during which an impact associated with an asset for which a compromise is determined is reduced by means of the capacity of the cybersecurity procedure of the remediation type activated at the level of said asset;it further comprises repeating the steps of performing a plurality of simulations and determining an indicator of compromise after modification of a cybersecurity procedure at the level of one of the IT assets of the compromise path and evaluating the impact of said modification by comparing the indicators of compromise determined by the first iteration of said steps and by said reiteration of said steps; it further comprises repeating the steps of performing a plurality of simulations and determining an indicator of compromise for another compromise path including the target asset. ; BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Other aspects, aims, advantages and characteristics of the invention will appear better on reading the following detailed description of preferred embodiments thereof, given by way of non-limiting example, and made with reference to the appended drawings in which: There Figure 1 is a diagram illustrating different steps implemented during a simulation to determine whether an IT asset is compromised by the computer attack; The Figure 2 is a diagram illustrating an example of the propagation of a computer attack along a compromise path as determined during a simulation; The Figure 3 is a diagram illustrating a possible implementation of a comparison of offensive scores and defensive scores to determine a compromise of an IT asset during a simulation. DETAILED DESCRIPTION OF SPECIFIC EMBODIMENTS
[0014] The invention relates to a computer-implemented method for analyzing the vulnerability of an information system to a computer attack carried out by an attacker.
[0015] The information system is made up of a plurality of IT assets, i.e. IT assets also referred to as "support assets" according to the terminology used by ANSSI in the EBIOS RM method. A map of the information system can be produced in the form of a graph whose nodes represent the IT assets (networks, user terminals, applications, etc.) constituting the information system and whose edges represent the possible propagation links of a computer attack between the IT assets (for example, an attacker can propagate from a web application to the server hosting it).
[0016] The computer attack aims to propagate from one or more input IT assets on one or more compromise paths, each consisting of a succession of at least one IT asset including an input IT asset. In one possible embodiment, the attack aims to reach one or more target IT assets from the input IT asset(s) by propagating step by step on one or more compromise paths, each consisting of a succession of IT assets (i.e. assets successively connected by edges of the graph) including an input IT asset and a target IT asset. In another possible embodiment, a target IT asset also constitutes an input IT asset, the corresponding compromise path being limited to this asset.
[0017] The computer attack is carried out according to a given Mode of Operation of Attack (MOA), i.e. its technical and contextual identity card grouping together contextual information and all the tactics, techniques and procedures used by the attacker.
[0018] The MOA for which the vulnerability analysis is carried out is typically representative of a risk scenario corresponding to the combination of a type of attack (ransomware or espionage for example), a type of malicious actor (state or criminal for example) and a context of the targeted organization (sector of activity, size, country for example).
[0019] In particular, the MOA considered may be a "representative" and aggregated MOA of the operating modes deployed in reality by the attacker groups relevant to the scenario considered (for example the various advanced persistent threats known as "Advanced Persistent Threats" such as APT28, APT29, or even groups exploiting ransomware such as Sodinokibi).
[0020] For each IT asset in a compromise path, and for each phase of the intrusion kill chain, the IT attack carried out by the attacker may include one or more attack procedures aimed at defeating the IT asset.
[0021] The intrusion kill chain describes the phases of a cyberattack, including the delivery phase (the attacker delivers the weapon to the target via, for example, email attachments, websites, or USB drives), the exploitation phase (the malware code is triggered and acts on the target network to exploit the identified vulnerability), the installation phase (the malware installs an access point, i.e., a backdoor, usable by an external attacker), the command and control phase (the malware provides the attacker with permanent access to the target network), and the target actions phase (the attacker takes actions to achieve their objectives, such as data exfiltration, data destruction, or encryption for ransom).
[0022] Attack procedures may depend not only on the attacker, but also on the nature of the targeted IT asset (e.g., a web server, an office computer, or an industrial control system) and the attacker's intended objective on the asset (e.g., a simple bounce point in the network, data espionage, sabotage, denial of service, etc.). The list of attack procedures executed by the MOA may, for example, be that provided by the MITRE ATT&CK framework ("Adversarial Tactics, Techniques, and Common Knowledge").
[0023] One or more security measures may be activated at the level of each IT asset to provide defense against attack procedures aimed at defeating the IT asset.
[0024] A security measure can provide one or more cybersecurity functions and thus be implemented within one or more cybersecurity procedures, each specifically associated with a security function. Typically, and in accordance with the NIST security framework, each IT asset can implement: a cybersecurity procedure that provides passive defense, for example: ∘ an identification-type cybersecurity procedure, which brings together all the security measures that provide the identification-type cybersecurity function, i.e. measures used to better understand one's environment, one's information system, etc. (for example, listing one's hardware and software assets or carrying out vulnerability scans); and / or ∘ a protection-type cybersecurity procedure, which brings together all the security measures that provide the protection-type cybersecurity function, i.e. countermeasures continuously protecting the information system against attacks (for example, ensuring access control, raising employee awareness, encrypting data, deploying endpoint protection software such as antivirus or access point detection and response); a cybersecurity procedure that ensures active defense, for example: ∘ a detection-type cybersecurity procedure, which brings together all the security measures that ensure the detection-type cybersecurity function, i.e. the measures used to detect a cyber-attack (for example, ensuring the collection of event logs, continuously monitoring anomalies, benefiting from flows of indicators of compromise to be put into detection); and / or ∘ a response-type cybersecurity procedure, which brings together all the security measures that ensure the response-type cybersecurity function, i.e.measures used to proactively respond to a cyber-attack (for example, isolating certain parts of the IS, blacklisting certain indicators of compromise, blocking administration accounts); and / or ∘ a remediation-type cybersecurity procedure, which brings together all the security measures that ensure the remediation-type cybersecurity function, i.e. measures used to restore the information system more quickly after an attack (for example, having backups of data against ransomware, implementing business continuity solutions on environments disconnected from the IS).
[0025] Correspondingly, the attack procedures executed by the MOA that aim to defeat an IT asset may be associated with the corresponding defense measures and in particular be grouped into procedures aimed at compromising a cybersecurity procedure ensuring passive defense and measures aimed at compromising a cybersecurity procedure ensuring active defense. More specifically, the attack procedures may be grouped into procedures aimed at compromising the protection type cybersecurity procedure, procedures aimed at compromising the detection type cybersecurity procedure and procedures aimed at compromising the response type cybersecurity procedure.
[0026] By considering the attack procedures not only according to the attacker, but also according to the nature of the targeted IT asset and the objective sought by the attacker, the invention achieves a granular and precise modeling of the actions performed by the attacker during the compromise attempt (for example, a first asset is only a bounce within the network and only its integrity is then targeted with specific attack procedures, while a second asset must be compromised in confidentiality and other attack procedures to collect and exfiltrate sensitive data are then deployed by the attacker). Such granular and precise modeling extends to the defense measures that prove to be relevant for each IT asset and for each type of attack.The invention thus makes it possible to consider attack and defense techniques specific to each IT asset (for example to take into account the fact that the offensive and defensive catalogs are different between a desktop computer, a smartphone, a production tool, etc.).
[0027] Furthermore, within the scope of the invention, the attack and cybersecurity procedures considered are not limited to CVE vulnerabilities (“Common Vulnerabilities and Exposures”) alone. The exploitation of a CVE vulnerability by an attacker corresponds in fact to a limiting subset of the attack procedures, just as the correction of vulnerabilities is one defense measure among many others (for example deploying terminal protection systems, managing administration accounts, raising employee awareness, etc.) that the invention makes it possible to take into account. The invention thus makes it possible to take into consideration attack procedures that are exploited in most cyberattacks and that do not fall under the exploitation of CVE, such as: the exploitation of “human” vulnerabilities, including targeted phishing that can allow the recovery of identifiers or sensitive data; denials of service; brute force attacks; the establishment of a Command & Control communication system between the attacker and their malware; numerous scanning, lateralization and passive listening techniques within a network; all actions carried out by the attacker after having obtained sufficient privileges, and therefore no longer requiring the exploitation of vulnerabilities (e.g.: encrypting data, exfiltrating data, sabotaging hardware, etc.).
[0028] The invention also allows for consideration of crucial security measures within organizations that are not related to CVE vulnerability correction, such as those mentioned above. Monte Carlo simulations
[0029] The method according to the invention estimates the probability of success of the computer attack carried out by the attacker on the IS for a given phase of the intrusion attack chain. This method is thus preferably repeated for each of the phases (delivery, operation, installation, etc.) of the intrusion attack chain.
[0030] For each phase of the intrusion attack chain, the method according to the invention carries out Monte Carlo simulations in order to estimate the probability of success of the computer attack carried out by the attacker to compromise a given computer asset. The method then comprises more particularly, for each of the compromise paths considered (for example all the possible paths in the graph mapping the IS), the carrying out of a plurality of simulations of propagation of the computer attack on the compromise path, where in each simulation it is determined whether and how the attack has succeeded or not in propagating in the information system.
[0031] In reference to the Figure 1 , each simulation includes the implementation of the following steps for each of the IT assets in the compromise path.
[0032] Each simulation includes, for each IT asset, a TPA step consisting of pseudo-randomly determining: a capability of a cybersecurity procedure providing passive defense (e.g., the protection type procedure) that is activated at the IT asset to block the computer attack, a capability of a cybersecurity procedure providing active defense (e.g., the response type procedure) that is activated at the IT asset to block the computer attack, a capability of the computer attack to compromise the cybersecurity procedure providing passive defense, and a capability of the computer attack to compromise the cybersecurity procedure providing active defense.
[0033] In other words, this TPA step consists of: determining a first defensive score SDP representative of the capacity of a cybersecurity procedure ensuring passive defense of the IT asset to block the computer attack, by carrying out at least one random draw with a selection probability which depends on a sophistication of the cybersecurity procedure ensuring passive defense and an uncertainty on said sophistication; determining a first offensive score SOP representative of the capacity of the computer attack to compromise the cybersecurity procedure ensuring passive defense of the IT asset, by carrying out at least one random draw with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring passive defense and an uncertainty on said sophistication;determining a second defensive score SDR representative of the capacity of a cybersecurity procedure ensuring active defense of the IT asset to block the computer attack, by carrying out at least one random draw with a selection probability which depends on a sophistication of the cybersecurity procedure ensuring active defense and an uncertainty on said sophistication; determining a second offensive score SOR representative of the capacity of the computer attack to compromise the cybersecurity procedure ensuring active defense of the IT asset, by carrying out at least one random draw with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring active defense and an uncertainty on said sophistication. ;
[0034] Each simulation also includes, for each IT asset, an ECH step consisting of determining a failure of the IT asset by comparing, on the one hand, the capacity of the cybersecurity procedure ensuring passive defense to block the IT attack with the capacity of the IT attack to compromise the cybersecurity procedure ensuring passive defense and, on the other hand, the capacity of the cybersecurity procedure ensuring active defense to block the IT attack with the capacity of the IT attack to compromise the cybersecurity procedure ensuring active defense (i.e. by comparing, on the one hand, the first defensive score and the first offensive score and, on the other hand, the second defensive score and the second offensive score).
[0035] And each simulation also includes, for each IT asset, a COMP step consisting of determining a compromise of the IT asset in the event of a determined failure of said asset and of each of the IT assets upstream of said asset in the compromise path when said asset is not the input IT asset.
[0036] At the end of these simulations, the method comprises a step consisting of determining a vulnerability indicator of an IT asset in the compromise path based on the number of simulations for which a compromise of said asset has been determined. This step is for example carried out for the target IT asset. It can be carried out for all or part of the IT assets in the compromise path.
[0037] It has been represented on the Figure 2an example of a compromise path whose input asset is an organization's website and the target asset corresponds to the user terminals of the organization's employees. The attack is likely to propagate from the input asset to the target asset successively via a server and an office network. During a simulation, a failure of the website, a failure of the server and a failure of the user terminals are determined. However, the office network is not failed. We deduce a compromise of the website and the server and an absence of compromise of the office network and the user terminals during this simulation of the attack. At the end of all the simulations, we determine a vulnerability indicator of an asset of the compromise path based on the number of simulations for which a compromise of said asset was determined.For example, if the asset is compromised in 75% of the simulations, its vulnerability indicator is 0.75, which expresses that the probability of success of the attack in reaching and compromising this asset for the MOA considered is 75%.
[0038] It is also possible, following a simulation, to determine that the attack is blocked in the event of failure not being determined for at least one of the IT assets in the compromise path. The method may then comprise determining a depth level of the IT attack blocked on the compromise path as being the IT asset preceding the first IT asset in the compromise path for which failure is not determined. Taking the example of the Figure 2 , the attack compromised even the server.
[0039] The above is valid for a compromise path and not for the attack in its entirety which can take different paths in parallel (the attacker can for example test several paths and defeat the assets constituting them, before finding or not finding a path which will allow him to reach his target). The depth of the complete attack can then be for example defined as the length of the longest path containing exclusively supporting assets successively compromised on a compromise path.
[0040] The invention thus has the advantage of making it possible to study the depth that the attacker has managed to reach in the IS. Even if he has not managed to achieve his final objective (the compromise of the target IT asset, for example the user terminals in the example of the Figure 3), he was able to succeed in compromising assets along the way. Impacts will therefore still be suffered by the organization and this state of affairs can be modeled by the invention by, for example, associating an impact profile (financial but also material losses, data losses, communications losses, etc.) with the compromise of each asset and thus providing an indicator of the impact of the attack even if it is blocked and does not compromise the target asset.
[0041] The method may further include determining that the attack is blocked by the cybersecurity procedure providing passive defense or by the cybersecurity procedure providing active defense of a computer asset determined not to be defeated. In particular, the method may determine whether the attack is blocked by a protection-type procedure or by the combination of a detection-type procedure or a response-type procedure. Conversely, the method may include determining that the attack is not blocked by one of the cybersecurity procedure providing passive defense and the cybersecurity procedure providing active defense of a computer asset.It is thus possible to determine whether or not the attack is blocked at the level of an IT asset by one or other of the protection or response type cybersecurity procedures or to determine whether or not the attack is detected by the detection type cybersecurity procedure. Recommendations can then be issued for the improvement of one and / or other of the different cybersecurity procedures activated at the level of each IT asset.
[0042] The method according to the invention can thus comprise a step of calculating the impact of the computer attack which delivers an impact indicator, i.e. quantitative data which can be a financial impact but also a simple score, a duration of production incapacity, a human impact for hospitals or defense systems, etc.
[0043] This impact calculation takes into account, on the one hand, the level of depth reached by the attack and the nature of the successful actions on each compromised asset and, on the other hand, the remediation type cybersecurity procedures activated at the level of the compromised assets. Successful actions typically increase the impact indicator depending on their nature (for example, if a first asset is compromised in Integrity and a second asset is compromised in Confidentiality, then the probability that a business impact indicator is higher is N%,), while remediation type cybersecurity procedures can reduce this indicator.
[0044] This impact calculation may notably use a remediation score calculated in a similar manner to the defensive scores described below, by using random draws controlled by the sophistication of each of the security measures that ensure the remediation-type cybersecurity function and the uncertainty about this sophistication. This score makes it possible to reduce the potential impact of a successful offensive action on an asset.
[0045] Thus, the method according to the invention may comprise for each simulation a step consisting, for each of the assets in the compromise path, in pseudo-randomly determining a capacity of a cybersecurity procedure of the remediation type activated at the level of the IT asset to remedy the IT attack and a step consisting in calculating an impact of the attack during which an impact associated with an asset for which a compromise is determined is reduced by means of the capacity of the cybersecurity procedure of the remediation type activated at the level of said asset. An SI impact may then be calculated for each simulation by, for example, summing the impacts associated with each compromised asset.Then, at the end of all the simulations, an impact probability distribution can be calculated from the IS impacts calculated for each of the simulations (for example, 30% of the simulations result in a production incapacity duration of 2 hours, 20% in a production incapacity duration of 5 hours, 10% in a production incapacity duration of 10 hours, etc.).
[0046] The invention has the advantage of providing a precise impact calculation by making it possible not to consider that the impact is only triggered in a binary way (successful attack or not), and above all to be able to break down the total impact of an attack on each action and on each asset. This impact calculation constitutes valuable data for decision-making within organizations, and to direct vigilance on certain assets more than on others.
[0047] In one possible embodiment, the invention further comprises repeating the steps of performing a plurality of simulations and determining an indicator of compromise for another compromise path. The invention thus makes it possible to consider all possible paths that the attack is likely to follow in order to compromise the IS.
[0048] In another possible embodiment, the invention comprises repeating the steps of performing a plurality of simulations and determining an indicator of compromise after modifying a cybersecurity procedure activated at one of the IT assets of the compromise path and evaluating the impact of said modification by comparing the indicators of compromise determined by the first iteration of said steps and by said reiteration of said steps.
[0049] By modification of a cybersecurity procedure, we mean in particular the activation of a new security measure or the deactivation of an existing measure, or the improvement or degradation of the sophistication of a security measure already deployed. The invention thus constitutes a decision-making tool for establishing defense strategies. It makes it possible in particular to evaluate, even before their deployment, the effectiveness (comparison of indicators of compromise, depth levels reached, paths taken) of new security solutions.
[0050] Finally, the method according to the invention can of course be repeated to study the impact of another MOA on the organization's IS.
[0051] An advantage of the invention is that it allows to simulate all the possible reactions of an organization during an attack, and not only the Passive Protection phase corresponding among other things to the correction of known CVE vulnerabilities. The invention thus makes it possible to identify shortcomings in the defensive maturity of an organization on all NIST functions and on all defense measures, generate relevant recommendations that are impossible to calculate with CVEs (for example having an internal SOC, raising employee awareness, etc.) and simulate the potential positive impact of these recommendations on the risk by repeating the process with different capabilities of the cybersecurity procedures. Pseudo-random draw
[0052] A possible embodiment of the TPA step is detailed below, consisting of, for each simulation and each asset in the compromise path, pseudo-randomly determining the different capacities. In this embodiment, the TPA step may in particular comprise the drawing of pseudo-random values forming: the first offensive score SOP representing the ability of the computer attack to compromise the cybersecurity procedure ensuring passive defense of the asset (that of the protection type in the following example); the second offensive score SOR representing the ability of the computer attack to compromise the cybersecurity procedure ensuring active defense of the asset (that of the response type in the following example); the first defensive score SDP representing the ability of the cybersecurity procedure ensuring passive defense of the asset to block the computer attack; the second defensive score SDR representing the ability of the cybersecurity procedure ensuring active defense of the asset to block the computer attack.
[0053] The ECH step of determining a failure of the IT asset may then include comparing the first offensive score SOP with the first defensive score SDP and comparing the second offensive score SOR with the second defensive score SDR.
[0054] We have seen previously that the computer attack carried out by the attacker on an IT asset may include one or more attack procedures aimed at compromising the cybersecurity procedure of the IT asset protection type or the cybersecurity procedure of the IT asset response type.
[0055] The at least one random draw carried out in each simulation with a selection probability which depends on a sophistication of the computer attack to compromise the cybersecurity procedure ensuring passive defense, respectively active defense, and an uncertainty on said sophistication can then comprise, for each of the computer assets of the compromise path and for each of the attack procedures aimed at compromising the cybersecurity procedure of the protection type, respectively of the response type, the random draw of a first, respectively second, offensiveness indicator with a selection probability which depends on a sophistication of the attack procedure and an uncertainty on said sophistication. These offensiveness indicators typically take a value between 0 and 1.
[0056] The random selection can for example be carried out by following a normal distribution whose expectation is fixed by the sophistication of the attack procedure and whose standard deviation is fixed by uncertainty on said sophistication. More specifically, the sophistication of the attack procedure depends on the type of malicious actor (for example criminal, state, activist, etc.) and the associated sophistication, the mastery of this attack procedure by the MOA concerned, its known resources, its potential motivation to carry out this attack scenario on this victim, etc. The uncertainty on this sophistication depends on the uncertainty on the data used to calibrate the expectation, for example if the MOA is very documented or not, if many previous attacks can be attributed to it, etc.
[0057] The pseudo-random value forming the first, respectively the second, offensive score is then determined from the first, respectively second, offensiveness indicators drawn for each of the attack procedures aimed at compromising the cybersecurity procedure of the protection type, respectively of the response type, for example by averaging these first, respectively second, offensiveness indicators. The average can be a weighted average to highlight those attack procedures that are most often executed by the MOA. In particular, when the MOA considered is a “representative” MOA resulting from the aggregation of several relevant MOAs, each attack procedure can be weighted according to the proportion of relevant MOAs that use it.
[0058] We have seen previously that the cybersecurity procedure of the protection type, respectively of the response type, activated at the level of an IT asset can comprise one or more security measures which ensure a cybersecurity function of the protection type, respectively of the response type, against attack procedures aimed at compromising the cybersecurity procedure of the protection type, respectively of the response type.
[0059] The at least one random draw carried out in each simulation with a selection probability which depends on a sophistication of the cybersecurity procedure ensuring passive defense, respectively active defense, and an uncertainty on said sophistication can then comprise, for each of the IT assets of the compromise path and for each of the security measures which ensure a cybersecurity function of the protection type, respectively of the response type, the random draw of a first, respectively second, defense indicator with a selection probability which depends on a sophistication of the security measure and an uncertainty on said sophistication. These defense indicators typically take a value between 0 and 1.
[0060] The random draw can for example be carried out by following a normal distribution whose expectation is fixed by the sophistication of the security measure and whose standard deviation is fixed by uncertainty on said sophistication. More specifically, the sophistication of the security measure depends on the level of defensive maturity of the organization for this security measure, which can be evaluated on several dimensions (for example existence of a policy for this measure or not, deployment of this policy, automation of this policy, associated report, etc.). The uncertainty on this sophistication depends on the uncertainty on the data used to calibrate the expectation, for example if little data is available to demonstrate this maturity or if there is a doubt about the implementation of the defensive measure.
[0061] The pseudo-random value forming the first, respectively second, defensive score can then be determined from the first, respectively second, defense indicators drawn for each of the security measures that provide a cybersecurity function of the protection type, respectively of the response type, for example by averaging these first, respectively second, defense indicators. The average can be a weighted average to highlight those security measures that are most effective against the MOA. We have seen previously that each attack procedure can be weighted when considering a “representative” MOA. The weighting of an attack procedure can similarly be applied to the security measures that make it possible to protect against it.In the case where a defense measure can be effective against several attack procedures having different weights, it is possible to sum the relevant weights and normalize the whole thing in fine.
[0062] In a similar manner to what has just been presented, the invention may also comprise, for each of the goods and for each of the simulations, the determination of a pseudo-random value forming a third defensive score representative of a capacity of a cybersecurity procedure of the detection type to detect the attack, of a pseudo-random value forming a third offensive score representative of a capacity of the computer attack to compromise the cybersecurity procedure of the detection type. The invention may also comprise the determination of a fourth defensive score representative of a capacity of a cybersecurity procedure of the identification type.
[0063] An example of determining the defensive score representative of a cybersecurity procedure's ability to block an attack is as follows. This example can also be used to determine other defensive scores.
[0064] We first consider the MOAs relevant to the scenario considered (type of attack and type of malicious actor), these relevant MOAs being intended to be aggregated to determine the “representative” MOA. We assign an intensity (i.e. a weight) to these relevant MOAs based on their interest for the context (for example geographical and sectoral) of the target, noted ρ ( MOA i ).
[0065] For each MOA, we retrieve the list of attack procedures and assign a weight to each of these techniques: plus one attack procedure T j is mastered by the MOA i , plus the associated weight 0 ≤ w ( MOA i , T j) ≤ 1 is close to 1. We thus determine a weight matrix: W = w MOA 1 T 1 ⋯ w MOA 1 T m ⋮ ⋱ ⋮ w MOA n T 1 ⋯ w MOA n T m
[0066] Each attack procedure is itself linked to the security measures associated with the IT asset in question which make it possible to protect against it. This link is weighted by the effectiveness 0 ≤ ε ( T i , D j ) ≤ 1 of the safety measure D j on the attack procedure T i . We thus determine an efficiency matrix: E = ε T 1 D 1 ⋯ ε T 1 D p ⋮ ⋱ ⋮ ε T m D 1 ⋯ ε T m D p
[0067] By combining these two matrices, we obtain a weighting matrix of the effectiveness of each security measure associated with the IT asset considered for each of the MOAs: K = W × E = κ 1 , 1 ⋯ κ 1 , p ⋮ ⋱ ⋮ κ n , 1 ⋯ κ n , p , with k i,j = ∑ k = 1 m w MOA i T k × ε T k D j the weight of the security measure D j against the MOA i .
[0068] The final weighting η ( D j ) of the security measure D jfor the scenario and context considered is then calculated as follows taking into account the intensity of targeting ρ calculated above for each of the MOAs: η D j = ∑ i = 1 n ρ MOA i × κ i , j .
[0069] The defensive score representative of a capacity of the cybersecurity procedure of the protection type to block the attack can then be expressed as the following weighted average of the random values GO ( D i ) being drawn with selection probabilities that depend on the sophistication of the security measures of the protection type ( i ∈ { Protection}) and uncertainty about these sophistications: ∑ i ∈ Protection η D i × VA D i ∑ i ∈ Protection η D i . Score confrontation
[0070] An example of preferential implementation of the confrontation of offensive and defensive scores during the ECH stage to determine a possible failure of a computer asset during a simulation is illustrated in the Figure 3. In this example, determining whether an IT asset has been compromised also includes comparing the ability of the IT attack to compromise the detection-type cybersecurity procedure enabled at the IT asset with the ability of that detection-type cybersecurity procedure to detect the attack.
[0071] More specifically, an absence of failure of an IT asset is determined: when the capacity of the protection-type cybersecurity procedure to block the computer attack is greater than the capacity of the computer attack to compromise this protection-type cybersecurity procedure, or otherwise, both when the capacity of the detection-type cybersecurity procedure to detect the computer attack is greater than the capacity of the computer attack to compromise this detection-type cybersecurity procedure and when the capacity of the response-type cybersecurity procedure to block the computer attack is greater than the capacity of the computer attack to compromise this response-type cybersecurity procedure.
[0072] As shown in the Figure 3, it can first be checked whether the first defensive score SDP is higher than the first offensive score SOP (its scores being linked to the cyber protection function). If so ("Y"), the asset is not defeated (NECH block). If not ("N"), it is checked whether the third defensive score SDD is higher than the third offensive score SOD (its scores being linked to the cyber detection function). If not ("N"), the asset is defeated (ECH block). If so ("Y"), it is checked whether the second defensive score SDR is higher than the second offensive score SOR (its scores being linked to the cyber response function). If not ("N"), the asset is defeated (ECH block). If so ("Y"), the asset is not defeated (NECH block).
[0073] In one possible implementation, each of the capabilities of the protection-type cybersecurity procedure, respectively the response-type, can benefit from a bonus based on a capability of an identification-type cybersecurity procedure activated at the IT asset level. The capability of the detection-type cybersecurity procedure can also benefit from such a bonus. These bonuses reinforce the fact that knowing your network and assets well implies better overall defensive maturity.
[0074] Thus, for example, a check is not determined when the following logical function is satisfied: (BP*SDI + (1-BP)*SDP>SOP) OR ((BD*SDI + (1-BD)*SDD>SOD) AND (BR*SDI + (1-BR)*SDR>SOR)) =1, with SDI the fourth defensive score related to the identification cyber function, BP a value between 0 and 1 providing a bonus to the defensive score related to the identification cyber function, BD a value between 0 and 1 providing a bonus to the defensive score related to the detection cyber function and BR a value between 0 and 1 providing a bonus to the defensive score related to the response cyber function. In a possible realization BP=BD=BR.
[0075] The invention is not limited to the method described above but also extends to a data processing unit configured to implement this method as well as to a computer program product comprising instructions which, when the program is executed by a computer, lead the latter to implement this method.
Claims
1. A computer-implemented method for analyzing the vulnerability of an information system to a cyber attack led by a hacker, the cyber attack propagating over one or more compromise paths each consisting of a succession of at least one computer asset including a starting computer asset, the method for each of the compromise path(s) comprising: • carrying out a plurality of simulations of propagation of the cyber attack on the compromise path, wherein each simulation for each of the computer assets on the compromise path comprises the steps of: ∘ determining a first defensive score (SDP) representing a capability of a cyber security procedure providing passive defence of the computer asset to block the cyber attack, by performing at least one random sampling with a selection probability dependent upon a sophistication of the cyber security procedure providing passive defence and upon an uncertainty on said sophistication; ∘ determining a first offensive score (SOP) representing a capability of the cyber attack to compromise the cyber security procedure providing passive defence of the computer asset, by performing at least one random sampling with a selection probability dependent upon a sophistication of the cyber attack to compromise the cyber security procedure providing passive defence and upon an uncertainty on said sophistication; ∘ determining a second defensive score (SDR) representing a capability of a cyber security procedure providing active defence of the computer asset to block the cyber attack, by performing at least one random sampling with a selection probability dependent upon a sophistication of the cyber security procedure proving active defence and upon an uncertainty on said sophistication; o∘ determining a second offensive score (SOR) representing a capability of the cyber attack to compromise the cyber security procedure providing active defence of the computer asset, by performing at least one random sampling with a selection probability dependent upon a sophistication of the cyber attack to compromise the cyber security procedure providing active defence and upon an uncertainty on said sophistication; ∘ determining a downfall (ECH) of the computer asset by comparing the first offensive score with the first defensive score, and by comparing the second offensive score with the second defensive score; ∘ determining compromise (COMP) of the computer asset in the event of determined downfall of said asset and of each of the computer asset(s) upstream of said asset on the compromise path when said asset is not the starting computer asset; • determining a vulnerability indicator of a computer asset on the compromise path, on the basis of the number of simulations in which compromise of said asset has been determined.
2. The method according to claim 1, wherein: • the cyber attack led by the hacker on a computer asset comprises one or more attack procedures intended to compromise the cyber security procedure providing passive defence, or the cyber security procedure providing active defence; • the at least one random sampling with a selection probability dependent upon a sophistication of the cyber attack to compromise the cyber security procedure providing passive defence, respectively active defence, and upon an uncertainty on said sophistication comprises, for each of the computer assets on the compromise path and for each of the attack procedures intended to compromise the cyber security procedure providing passive defence, respectively active defence, the random sampling of a first, respectively second, indicator of offensiveness with a selection probability dependent upon a sophistication of the cyber attack and upon an uncertainty on said sophistication; and • the first, respectively second, offensive score is determined from the first, respectively second, indicators of offensiveness sampled for each of the attack procedures intended to compromise the cyber security procedure providing active defence, respectively passive defence.
3. The method according to claim 2, wherein: • the cyber security procedure providing passive defence, respectively active defence, activated at a computer asset comprises one or more security measures ensuring a cyber security function of passive defence type, respectively active defence type, against attack procedures intended to compromise the cyber security procedure providing passive defence, respectively active defence; • the at least one random sampling with a selection probability dependent upon a sophistication of the cyber security procedure providing passive defence, respectively active defence, and upon an uncertainty on said sophistication comprises, for each of the computer assets on the compromise path and for each of the security measures ensuring a cyber security function of passive defence type, respectively active defence type, the random sampling of a first, respectively second, defence indicator with a selection probability dependent upon a sophistication of the security measure and upon an uncertainty on said sophistication; and • the first, respectively second, defensive score is determined from the first, respectively second, defence indicators sampled for each of said security measures ensuring a cyber security function of passive defence type, respectively active defence type.
4. The method according to one of claims 1 to 3, further comprising the pseudo-random determination of a capability of a cyber security procedure of detection type activated at the computer asset to detect the cyber attack, of a capability of a cyber security procedure of response type activated at the computer asset to block the cyber attack, of a capability of the cyber attack to compromise the cyber security procedure of detection type, and of a capability of the cyber attack to compromise the cyber security procedure of response type.
5. The method according to claim 4 wherein the non-downfall of a computer asset is determined: • when the first defensive score is higher than the first offensive score, or • if not, both when the capability of the cyber security procedure of detection type to detect the cyber attack is greater than the capability of the cyber attack to compromise the cyber security procedure of detection type and when the capability of the cyber security procedure of response type to block the cyber attack is greater than the capability of the cyber attack to compromise the cyber security procedure of response type.
6. The method according to one of claims 1 to 5, wherein each of the first and second defensive score is increased by a bonus based on a capability of a cyber security procedure of identification type activated at the computer asset.
7. The method according to one of claims 1 to 6, further comprising, in a simulation of propagation of the cyber attack on a compromise path, the ascertaining that the attack is blocked in the event of non-determination of downfall for at least one of the computer assets on the compromise path.
8. The method according to claim 7, further comprising the determination that the attack is blocked by the cyber security procedure providing passive defence or by the cyber security procedure providing active defence of a computer asset determined as not being in downfall.
9. The method according to claim 7, further comprising determination of a depth level of the cyber attack blocked on a compromise path, determined as being the computer asset preceding the first computer asset on the compromise path for which downfall is not determined.
10. The method according to one of claims 1 to 9, wherein each simulation further comprises a step, for each of the assets on the compromise path, to determine pseudo-randomly a capability of a cyber security procedure of remediation type activated at the computer asset to remedy the cyber attack, and a step to calculate an impact of the attack in which an impact associated with an asset determined as being compromised is reduced by means of the capability of the cyber security procedure of remediation type activated at said asset.
11. The method according to one of claims 1 to 10, further comprising reiteration of the steps to carry out a plurality of simulations and to determine an indicator of compromise after modifying a cyber security procedure at one of the computer assets on the compromise path, and to evaluate the impact of said modification by comparison of the indicators of compromise determined by the first iteration of said steps and by said reiteration of said steps.
12. The method according to one of claims 1 to 10, further comprising reiteration of the steps to carry out a plurality of simulations and to determine an indicator of compromise for another compromise path including the target asset.
13. A data processing unit configured to implement the method according to one of claims 1 to 12.
14. A computer programme product comprising instructions which, when executed by a computer, lead to implementation by the latter of the method according to one of claims 1 to 12.