Exposure management method, exposure management system, computer program, and computer-readable medium
The method and system prioritize vulnerabilities and threats by modeling threat actors and organizational assets, enhancing risk management through attack path simulation, addressing the inefficiencies of current exposure management systems.
Patent Information
- Application Number
- JP2025135981
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-08-19
- Filing Date
- 2025-08-18
- Publication Date
- 2026-03-04
AI Technical Summary
Current exposure management systems fail to effectively prioritize risks associated with an organization's exposure, making it difficult for organizations to focus their efforts on the most critical vulnerabilities and threats.
A method and system that creates models of threat actors and organizational assets, using attack path simulation to identify and integrate attack paths into attack trees and forests, enabling prioritization of vulnerabilities and responses based on specific threat actors and organizational context.
Provides reliable prioritization of vulnerabilities and threats, guiding organizations to address the highest risks efficiently, addressing the cybersecurity talent shortage and increasing threat landscape challenges.
Smart Images

Figure 2026035562000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an exposure management method, an exposure management system, a computer program and a computer readable medium. [Background technology]
[0002] Security and threat detection systems for computers and computer networks are used to detect threats and anomalies in computers and computer networks. Examples of such systems include endpoint protection platforms (EPPs), endpoint detection and response (EDR), and managed detection and response (MDR) products and services. Endpoint protection platforms (EPPs) are deployed on endpoint devices to prevent file-based malware attacks and detect malicious activity. EDR systems focus on detecting and monitoring breaches as they occur and help determine how to respond to detected breaches. EDR systems also provide the investigation and remediation capabilities necessary to respond to dynamic security incidents and alerts. MDR, on the other hand, is a managed cybersecurity service that provides services for threat detection, response, and remediation. The development of efficient and robust threat detection solutions has been made possible, in part, by the emergence of machine learning, big data, and cloud computing.
[0003] Vulnerability management systems have also become more widely used in recent years. These systems primarily focus on identifying and addressing vulnerabilities within an organization's IT infrastructure, applications, and systems. For example, a vulnerability system can systematically scan, assess, and prioritize vulnerabilities to determine which pose the greatest risk to the organization. Based on this information, a vulnerability management system can patch existing vulnerabilities and reduce the attack surface by proactively identifying and mitigating vulnerabilities before they can be exploited by attackers. Risk management and assessment can be furthered by exposure management systems. Exposure management systems not only analyze vulnerabilities but also other factors that contribute to an organization's risk exposure, such as the threat landscape, business impact, and the effectiveness of security controls.
[0004] One technique that can be used in an exposure management system is attack path mapping. Attack path mapping focuses on understanding potential attack vectors and security weaknesses by leveraging knowledge of the tactics, techniques, and procedures (TTPs) that attackers could use to compromise an organization's systems and data. Attack path mapping can involve identifying and analyzing various entry points, vulnerabilities, and attack vectors that attackers could exploit to achieve their objectives. The purpose of attack path mapping is to gain insight into an organization's attack surface and identify potential weaknesses and security gaps that attackers could exploit.
[0005] Current exposure management systems are unable to effectively prioritize the risks associated with each part of an organization's exposure, particularly those specific to that organization. As a result, the information they provide makes it difficult for organizations to properly prioritize their work, focusing their attention first on what truly matters to them. This calls for more efficient and reliable exposure management systems. The availability of such systems is becoming increasingly important given the continually expanding threat landscape and the cybersecurity talent shortage that has plagued the industry for the past few years. Summary of the Invention [Means for solving the problem]
[0006] The following presents a simplified summary to provide a basic understanding of some aspects of various embodiments. This summary is not an exhaustive overview of the invention, nor is it intended to identify key elements or critical components of the invention or to delineate the scope of the invention. The following summary merely presents some concepts of the invention in a simplified form as a prelude to a more detailed description of representative embodiments of the invention.
[0007] According to a first aspect, the present invention relates to a method, e.g., a computer-implemented method, for assessing the exposure of an organization's assets, the assets including at least one host, such as a computer or server. The method includes creating a model of the organization that manages the assets, creating models of multiple threat actors capable of attacking the organization's assets, and generating a reduced set of threat actors associated with the organization based on the created threat actor models and the relevance of specific threat actors to the organization in light of the created threat actor models and the created organization model. The method further includes, for each threat actor in the reduced set, identifying available attack paths against the organization's assets using the attack path simulator, and integrating the identified available attack paths against the organization's assets into an attack tree for the specific threat actor.
[0008] In one embodiment of the present invention, the attack trees of an identified threat actor are aggregated into an attack forest, where the attack forest comprises the attack trees of an identified threat actor.
[0009] In one embodiment of the present invention, the attack forest of all threat actors is integrated into an attack path map of the organization's assets that represents the organization's attack surface, including the organization's global attack surface.
[0010] In one embodiment of the invention, the attack tree and / or the attack forest are used to prioritize the threat actors and / or prioritize responses to findings, including identified vulnerabilities and / or misconfigurations. In one embodiment of the invention, the attack forest inherits the same priority as the corresponding threat actor.
[0011] In one embodiment of the invention, the threat actor model includes at least one of information about the threat actor, including the threat actor's affiliation, the threat actor's specialty, the threat actor's location, and / or the threat actor's profit expectations. In one embodiment of the invention, the information about the threat actor is received from a threat intelligence source, including a threat intelligence feed and / or a threat intelligence database, such as an internal threat intelligence database and / or an external threat intelligence database.
[0012] In one embodiment of the present invention, a threat actor is included in the reduced set of threat actors associated with the organization if the threat actor's association with the organization meets the criteria defined by the threat actor model and the organization model for that particular threat actor.
[0013] In one embodiment of the present invention, the threat actor model and the organizational model are overlaid to generate the reduced set of threat actors associated with the organization, the overlay including prioritizing the threat actors using threat intelligence data.
[0014] In one embodiment of the present invention, the relevance of the threat actor to the organization is based at least in part on information about the threat actor, including the threat actor's affiliation, the threat actor's expertise, the threat actor's location, and / or the threat actor's profit expectations.
[0015] In one embodiment of the invention, the model of the threat actor and / or the model of the organization includes a list of actions of the threat actor and / or the organization, including actions that the threat actor can take, in the form of a probabilistic model including deterministic rules, Markov chains, and / or behavioral rules of the threat actor and / or the organization.
[0016] In one embodiment of the present invention, creating the organizational model includes collecting at least one of data about a customer organization including location, industry, revenue, employees, related security incidents and reports, size of the organization, market segment, and geographic location. In one embodiment of the present invention, the data for creating the organizational model is collected by at least one of an agent installed on at least one host, an agent and / or EPP sensor installed on the at least one host, an agent and / or XDR sensor installed on the at least one host, a vulnerability management system, a security posture system including a cloud security posture system, and an identity reputation database.
[0017] In one embodiment of the present invention, identifying the attack tree using the attack path simulator includes identifying a target asset, defining the identified target asset as a root node of the attack tree, and identifying attack paths available to an attacker to access the target asset based at least in part on the identified vulnerabilities of the host and / or the network.
[0018] According to a second aspect, the present invention relates to an exposure management system for assessing the exposure of an organization's assets, the assets including at least one host, such as a computer or server. The system is configured to: create a model of the organization managing the assets; create models of multiple threat actors capable of attacking the organization's assets; and generate a reduced set of threat actors associated with the organization based on the created threat actor models and the relevance of specific threat actors to the organization in light of the created threat actor models and the created organization model. The system is further configured to, for each threat actor included in the reduced set, identify available attack paths against the organization's assets using the attack path simulator; and integrate the identified available attack paths against the organization's assets into an attack tree for the specific threat actor.
[0019] In one embodiment of the invention, the exposure management system is configured to perform a method according to any embodiment of the invention.
[0020] According to a third aspect, the invention relates to a computer program comprising instructions which, when executed by a computer, cause the computer to carry out the method according to the invention.
[0021] According to a fourth aspect, the present invention relates to a computer-readable medium storing the computer program according to the invention. [Effects of the Invention]
[0022] The solution of the present invention can guide organizations to effectively prioritize the remediation of assets' highest risk vulnerabilities, as determined based on their true focus, e.g., the specific organization and the threat actors associated with that organization. Thus, the solution of the present invention can provide more reliable prioritization of exposures and vulnerabilities, thereby protecting organizational assets more quickly and reliably than prior art solutions. More efficient and precise prioritization is crucial to addressing the ever-increasing number of cybersecurity vulnerabilities, IT misconfigurations, and similar issues, as well as the chronic shortage of skilled labor inevitably required to triage, verify, and address the many security challenges facing organizations. [Brief explanation of the drawings]
[0023] [Figure 1] FIG. 1 illustrates a schematic diagram of an exemplary network architecture of one embodiment of the present invention. [Figure 2] FIG. 2 illustrates a schematic diagram of an exemplary network architecture of one embodiment of the present invention. [Figure 3] FIG. 3 illustrates a schematic of at least some components of a threat detection solution in accordance with one embodiment of the present invention. [Figure 4] FIG. 4 illustrates an exemplary method according to one embodiment of the present invention. [Figure 5] FIG. 5 illustrates an exemplary computing device, such as a server, according to one embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0024] Various exemplary and non-limiting embodiments of the present invention, together with their organization and method of operation, and their attendant objects and advantages, will best be understood by reading the following description of specific exemplary and non-limiting embodiments in connection with the accompanying drawings.
[0025] In this specification, the verbs "comprise" and "include" are used as open limitations which do not exclude or require the presence of unrecited features. Features recited in dependent claims are mutually freely combinable, unless expressly stated otherwise.
[0026] Furthermore, it will be understood that as used throughout this specification the use of the singular forms "one" and "an" does not exclude a plurality.
[0027] Embodiments of the present invention are illustrated by way of example, and not by way of limitation, in the figures of the accompanying drawings.
[0028] An exposure management system according to an embodiment of the present invention may include at least one endpoint and a backend system including at least one backend server, where information, such as threat detection related data and exposure related data, can be shared between the endpoints or between the endpoints and the backend system. The threat detection system may include or be connected to an exposure management system or service.
[0029] The solution of the present invention can identify the exposure of resources, such as assets, and based on that, can manage the exposure of systems, networks, or portions thereof. Exposure management can process streams of raw data collected from multiple sources to form and maintain an asset inventory, and can perform awareness analysis, for example, in terms of asset inventory dynamics, general asset characteristics, vulnerability scope and status, and assessment of public assets, supply chain providers, AI providers, etc. Based on this, for example, an awareness summary can be created and enriched with a threat landscape to assess response readiness through dynamic risk scoring and prioritize risk remediation activities at the asset and composite level. Exposure management can provide, for example, at least one of the following outputs: risk remediation priority per asset, risk remediation priority across multiple assets, and dynamic risk score.
[0030] Attack path mapping can be used in exposure management, for example, as a method for analyzing a network environment. Attack path mapping can include identifying and analyzing various entry points, vulnerabilities, and attack vectors that an attacker could exploit to achieve their objectives. Determining potential attack paths can include asset identification, threat modeling, vulnerability analysis, and path analysis.
[0031] Exposure management systems can be used in conjunction with EPP, EDR, or other equivalent systems, which deploy data collection and processing devices, such as agents and sensors, on selected network endpoints, any component of an IT infrastructure. Typically, agents in EPP systems focus on endpoint protection, i.e., data processing, while agents in EDR systems focus on detection, i.e., data collection. Data collection devices monitor activity occurring on the endpoints and transmit collected data to a central backend system, often located in the cloud. In these systems, once the backend receives the data, it may be processed (e.g., aggregated and enriched) before being analyzed and scanned for signs of security breaches or anomalies by the security system provider. Data collected by the solutions of the present invention may be stored in a database or similar information storage model for future use.
[0032] The threat detection component used in the solution of the present invention may include, for example, a processing or analysis service, an external data source, and / or an internal data source. The processing or analysis service may include at least one of the following: a static parser, a dynamic parser, an antivirus engine, an EDR / MDR rules engine, and an AI-based EDR / MDR engine. The external data source may include at least one of the following: a domain lookup database, a virus database, and a virus information source. The internal data source may include at least one of the following: a threat intelligence information source, an incident information source, and an asset information source. The threat detection component may include (in addition to or instead of the aforementioned components) at least one of the following components: a data source, a data collection agent, a data aggregation and normalization component, data storage, an analysis engine, an alert and notification component, a user interface component, a reporting and recording component, an incident response tool, an integration tool, a machine learning and AI algorithm, a rules engine, a scalability and / or redundancy unit, and a threat intelligence feed.
[0033] These components may be specialized mechanisms to perform various types of processing, including (but not limited to): querying reputation services or metadata query databases, parsing complex objects (e.g., installer packages, emails, web pages, documents), analyzing retrieved content (e.g., executables, process dumps, text, images), obtaining behavioral data (e.g., through emulation or sandbox environments), rendering verdicts based on collected information, enhancing awareness summaries with threat landscape information, image tagging, sentiment analysis, machine translation, spell checking, identifying obfuscated data, and summarizing analysis results. These components may be responsible for specialized and well-defined tasks, for example, in cases where the use of large language models is not feasible.
[0034] In one embodiment of the present invention, at least one threat detection component performs a process to prioritize potential responses to identified threats and / or security posture improvements. In one embodiment of the present invention, the output of the threat detection component relates to at least one of the following: identified vulnerabilities, identified critical assets, priorities of identified vulnerabilities, priorities of critical assets, risk values to the business of identified assets and / or vulnerabilities, attack path mapping, visualization and reporting artifacts.
[0035] FIG. 1 illustrates an example of an environment in which the solution of the present invention can be used. The solution of FIG. 1 illustrates a system configuration in which a local host 101 and a remote entity or server 102 are connected via a network 103. Here, the host 101 exemplifies any computer or communication system, including a single device, a network node, or a combination thereof, on which malware scanning or collection of threat detection-related information is performed. Processing related to scanning and / or analyzing threat detection-related data or exposure management may be performed on the host and / or the server. For example, the host 101 may include a personal computer, a personal communication device, a network-enabled device, a client, a firewall, a mail server, a proxy server, a database server, etc. The server 102 exemplifies any computer or communication system, including a single device, a network node, or a combination thereof, on which malware scanning or analysis of threat detection data is performed on the host 101 or which provides risk assessment data and / or reputation data necessary to perform malware scanning or threat detection-related analysis on the host 101. For example, the server 102 may include a security-related entity or back-end entity of a security provider, or may be implemented in a cloud environment. For example, the server may control exposure management operations, or the host may perform operations related to exposure management, for example, under the direction of the server 102 .
[0036] According to an exemplary embodiment of the present invention, malware scanning and / or analysis of threat detection data on host 101 and / or server 102 may be accomplished using a malware analysis environment, such as a virtual machine or emulator environment, deployed on the host and / or server. For example, a malware scanning agent or sensor, e.g., threat detection software, may be installed or deployed on host 101 and used for exposure management, malware scanning, and / or threat detection data analysis. In one embodiment of the present invention, the sensor or agent on the computer may be used to intercept files and determine system configuration values and / or network operations invoked by applications. The sensor may be used to monitor the operation of a device, such as a computer, and information collected by the sensor may be used to detect malicious behavior of applications, files, and / or processes, or to detect vulnerabilities and / or misconfigurations.
[0037] In one embodiment of the present invention, the threat detection environment, service, and / or software can detect application starts and stops, detect all abnormal processes, and add monitoring to required applications and processes. Also, if the service is launched early, it can detect and track most of the user's applications. In one embodiment of the present invention, when the threat detection software or service launches, it can perform an inventory of running applications.
[0038] Network 103 is an example of any computer or communications network, including, for example, a wired or wireless local area network such as a LAN, WLAN, or Ethernet, or a wired or wireless wide area network such as WiMAX, GSM, UMTS, or LTE. Accordingly, host 101 and server 102 may or may not be located in different locations. For example, network 103 may be any type of TCP / IP-based network. In this case, communication between host 101 and server 102 over network 103 may be achieved using, for example, a standard or proprietary protocol carried over TCP / IP, in which a malware scanning agent on host 101 and a malware analysis sandbox or application on server 102 may be represented at the application layer.
[0039] FIG. 2 schematically illustrates an example of a network architecture in one embodiment in which the solution of the present invention may be used. FIG. 2 schematically illustrates a portion of a first local computer network 201, in which computer systems, such as an EPP, EDR, and / or exposure management system, are installed. Other computer systems capable of implementing embodiments of the present invention may be used instead of or in addition to the EPP, EDR, and / or exposure management system used in this example. The first local computer network is connected via network 203 to a security service network, which in one embodiment is a security backend system or server 202. This network may be similar to network 103 of FIG. 1. The backend system or server 202 may be similar to server 102 of FIG. 1. The backend system or server 202 may form a node on the security service computer network relative to the first local computer network. The security service computer network is managed by a provider of a threat detection and / or exposure management system and may be separated from network 203 by a gateway or other interface (not shown) or other network element suitable for backend 202. The first local computer network 201 may also be separated from the network 203 by a gateway 204 or other interface. Other network configurations are possible.
[0040] The first local computer network 201 may be comprised of multiple interconnected network nodes 205a-205h, each representing a component within the first local computer network 201, such as a computer, smartphone, tablet, laptop, or other network-enabled hardware. In one embodiment of the present invention, a node may be any device on the network, but is not a gateway. Each of the network nodes 205a-205h shown in the first local computer network may represent an endpoint, such as an EDR endpoint or an EPP endpoint, and has installed thereon a security agent module 206a-206h, which may include a data collection device or sensor. The network nodes 205a-205h may be similar to the local host 101 in FIG. 1. In some embodiments of the present invention, a security agent module may be installed in other components of the computer network, such as a gateway or other interface. In the example of FIG. 2, the security agent module 204a is installed in the gateway 204. Security agent modules 206a-206h and 204a collect various types of data at nodes 205a-205h or gateway 204, such as program or file hashes, files stored on nodes 205a-205h, network traffic logs, process logs, binaries or files extracted from memory (e.g., DLLs, EXEs, or memory forensic artifacts), and / or logs of monitoring actions performed by programs or scripts running on nodes 205a-205h or gateway 204 (e.g., TCP dumps). The collected data may be stored in a database or similar model for information storage for future use or transmitted for further analysis. Any type of threat detection model may be built and stored in a database at backend / server 202 and / or a second server.The nodes 205a-205h and the server 202 typically include a hard drive, a processor, and RAM.
[0041] Any type of data useful for exposure management or detecting and monitoring security threats, such as security breaches or system intrusions, may be collected by security agent modules 206a-206h and 204a during their lifecycle. The types of data observed and collected may be configured according to rules defined by the threat detection system provider during installation of the threat detection system and / or during deployment of the threat detection model components. In one embodiment, suspicious or malicious events, misconfigurations, and / or vulnerabilities among the monitored events may be detected by one or more detection mechanisms. In one embodiment, the detection mechanisms used to detect suspicious or malicious events may include machine learning models, scanning engines, heuristic rules, statistical anomaly detection, fuzzy logic-based models, and predefined rules.
[0042] In one embodiment of the present invention, at least some of security agent modules 206a-206h may be capable of making their own decisions about the types of data to observe and collect. For example, security agent modules 206a-206h and 204a may collect data regarding the behavior of programs running on endpoints and observe new programs as they are started. If appropriate resources are available, the collected data may be permanently or temporarily stored and / or further transmitted by security agent modules 206a-206h and 204a to an appropriate storage location on the respective network node or first local computer network 201. For example, server 202 may control exposure management operations, and / or network nodes 205a-205h and / or security agent modules 206a-206h may perform tasks related to exposure management, e.g., following instructions from server 202.
[0043] Security agent modules 206a-206h and 204a are configured to transmit information, such as collected data, or instructions to and from threat detection system and / or exposure management backend 202 over network 203 (e.g., the Internet), allowing a threat detection system provider to manage the system remotely without having personnel on-site at the organization managing first local computer network 201.
[0044] In one embodiment of the present invention, security agent modules 206a-206h and 204a may be configured to establish an internal network, e.g., an internal swarm intelligence network, including security agent modules of multiple interconnected network nodes 205a-205h within local computer network 201. Security agent modules 206a-206h and 204a may be further configured to collect data related to their respective network nodes 205a-205h and share information based on the collected data within the established internal network. In one embodiment, the swarm intelligence network is comprised of multiple semi-independent security nodes (security agent modules) that can function independently. Therefore, the number of instances in a swarm intelligence network may vary. Furthermore, multiple swarm intelligence networks that interact with each other may exist within a single local computer network.
[0045] The security agent modules 206a-206h and 204a, or back-end systems, may be configured to further utilize the collected data and information received from the internal network for activities related to exposure management and / or for generating and adapting models related to the corresponding network nodes 205a-205h and / or their users, for example.
[0046] To analyze an organization's or network's threats and exposure, it is important to consider what threat actors may target the organization. Threat actors typically have certain preferences regarding the types of organizations they target. These preferences may depend on a variety of factors, such as the threat actor's affiliation, expertise, location, and profit expectations. In practice, this may lead to a tendency to use specialized attack infrastructure, focus on targeting specific vulnerabilities, and utilize specific tactics, techniques, and procedures (TTPs), resulting in the use of malware implants and other tools.
[0047] On the other hand, government and commercial organizations, for example, operate within specific contexts defined by their missions, objectives, industry sectors, locations, business processes, critical assets, and personnel. Each organization's information and communications technology (ICT) environment is dependent on these contexts. From an exposure management perspective, this means that threat actors targeting an organization likely have unique intrusion scenarios that depend on their mode of operation (mode of operation), the organization's visibility, and the state of the ICT environment.
[0048] In such a situation, it becomes extremely difficult to effectively guide an organization to focus its attention on what truly matters to it. The solution of the present invention can take this into account. In one embodiment of the present invention, for each specific threat actor, a set of prioritized attack forests relevant to the organization can be formed or determined. Within the attack forest, a set of prioritized attack trees can be formed or determined using, for example, threat intelligence, threat actor models, and organizational information. Thus, the solution of the present invention provides end users and organizations with the ability to counter and respond to specific threat actors, as well as the ability to independently observe, analyze, and prioritize actions to improve the overall attack surface from threat actors.
[0049] In a solution of the present invention, the exposure of an organization's assets is assessed, the assets including at least one host, such as a computer or server. The method includes creating a model of the organization that manages the assets, creating models of multiple threat actors capable of attacking the organization's assets, and generating a reduced set of threat actors associated with the organization based on and / or taking into account the created threat actor models and the organization model. The method further includes, for each threat actor in the reduced set, identifying available attack paths against the organization's assets using an attack path simulator, and integrating the identified available attack paths into an attack tree for the particular threat actor against the organization's assets.
[0050] In one embodiment of the present invention, the attack trees of an identified threat actor are aggregated into an attack forest, which includes at least a portion of the identified attack trees of that threat actor. In one embodiment of the present invention, the attack forests of all threat actors may be aggregated to construct an attack path map that represents the attack surface of an organization's assets. The attack trees and / or attack forests may be used to prioritize threat actors or prioritize responses to findings, such as identified vulnerabilities or misconfigurations. In one embodiment of the present invention, the attack forest may inherit the same priority as the corresponding threat actor. Findings, such as vulnerabilities and misconfigurations, may be resolved through remediation and / or patching, and misconfigurations may be corrected through accurate and secure configurations and settings. In one embodiment of the present invention, vulnerabilities may be remediated and / or patched in the order of their identified priority, and misconfigurations may be similarly corrected.
[0051] In one embodiment of the present invention, a reduced set of threat actors is formed by including threat actors that meet predetermined criteria for a particular organization. For example, threat actors associated with the organization are included in the reduced set, and threat actors not associated with the organization are excluded from the reduced set. For example, a threat actor is included in the reduced set if its association with the organization meets criteria defined by its specific threat actor model and the organization model. In one embodiment of the present invention, a reduced set of threat actors associated with an organization can be generated by overlaying a threat actor model with an organization model, which may include prioritizing threat actors using threat intelligence data.
[0052] In one embodiment of the present invention, the relevance that a threat actor has to an organization is based, at least in part, on information about the threat actor, such as the threat actor's affiliation, expertise, location, and / or interest expectations.
[0053] The threat actor model may include at least one of the following information about the threat actor: the threat actor's affiliation, expertise, location, and / or expected profit. Information about the threat actor may be received, for example, from a threat intelligence feed and / or a threat intelligence database (such as an internal threat intelligence database and / or an external threat intelligence database). In one embodiment of the present invention, the threat actor model and / or organizational model may include a list of threat actor and / or organizational behaviors and / or behavioral rules, including actions that the threat actor can perform, expressed in the form of a probabilistic model such as a Markov chain or deterministic rules.
[0054] In one embodiment of the present invention, creating the organizational model includes collecting at least one of the following data about the customer organization: location, industry, revenue, employees, related security incidents and reports, organizational size, market segment, and geographic location. The information or data for creating the organizational model may be collected, for example, by at least one of the following: an agent installed on at least one host, an EPP sensor and / or agent installed on at least one host, an XDR sensor and / or agent installed on at least one host, a vulnerability management system, a security posture system such as a cloud security posture system, or an identity reputation database.
[0055] In one embodiment of the present invention, identifying an attack tree with the attack path simulator includes identifying a target asset, defining it as a root node of the attack tree, and identifying attack paths available to an attacker to access the target asset, where, for example, the identification of the attack paths may be based at least in part on identified vulnerabilities of the host and / or network.
[0056] In one embodiment of the present invention, building an attack tree may include identifying a target host and defining it as the root node of the attack tree. Building the attack tree may continue by identifying specific goals an attacker may have. For example, the goal may be to gain unauthorized access to a system, tamper with data, or cause a denial of service (DoS) attack. Building the attack tree may continue by creating a root node of the attack tree that represents the identified goal, for example, by using a descriptive keyword or phrase as the root node label. Also, based on the identified vulnerabilities, etc., attack paths available to an attacker to access the target host may be identified. Different attack paths may be identified that an attacker could take to reach the goal. These paths represent a series of steps an attacker could take to exploit a vulnerability. For each attack path, child nodes connected to the root node may be created. Each attack path may be further subdivided into smaller attack trees or sub-attack trees. These sub-attack trees may represent individual elements, actions, or vulnerabilities that an attacker may exploit. In one embodiment of the present invention, this step may be repeated recursively until a level of detail sufficient for analysis is reached. Each node in the attack tree can be labeled with a specific attack technique, strategy, or vulnerability that an attacker could use or exploit. This can identify potential weaknesses in a system and reveal areas where additional protection is needed. The attack tree can be analyzed to assess the likelihood and impact of each attack path. This analysis allows users or organizations to prioritize risks, identify critical vulnerabilities, and plan appropriate countermeasures.
[0057] Figure 3 illustrates an example of one embodiment of the present invention. The solution can use internal and external threat intelligence along with threat actor behavior models to build a modeled threat actor inventory. Threat actor behavior models can be represented in a variety of ways, including as deterministic rules, probabilistic models such as Markov chains, and / or a set of Drools rules that represent common attacker behaviors.
[0058] Context and data surrounding a client organization can be collected by technical tools, and this collected information can be used to build a model of the organization. Examples of context about a client organization include, but are not limited to, the organization's size, market segment, geographic location, and primary language (e.g., as described above). Data collected by technical tools can refer to data about a client organization generated by tools deployed within the organization, such as threat detection tools.
[0059] A reduced set of threat actors relevant to the organization is generated, for example, by overlaying a threat actor data model with an organizational model (threat actor matching model in Figure 3). The set of threat actors generated in this step can be prioritized by threat intelligence information. For each threat actor (e.g., associated threat actors and / or threat actors included in the reduced set), all available attack paths can be collected, for example, via a threat actor simulation platform. The simulated attack paths are then integrated into an attack tree and further assembled into an attack forest. The collection of attack forests can be used by customers, users, and / or organizations to precisely counter specific threat actors and substantially improve their security posture. Attack forests can be aggregated to build a global view (e.g., an aggregate attack forest), allowing end users to maintain visibility into their entire attack surface.
[0060] 4 illustrates an example method according to an embodiment of the present invention. The example method includes creating a model of an organization that manages assets and creating and / or determining models of multiple threat actors capable of attacking the organization's assets. Given the created threat actor model and the created organizational model, the method generates a reduced set of threat actors associated with the organization based on the relevance of specific threat actors to the organization. For each threat actor in the reduced set, the method further includes identifying available attack paths against the organization's assets using an attack path simulator and integrating the identified available attack paths into an attack tree for a specific threat actor.
[0061] Figure 5 illustrates an example of a computing device, such as a host, endpoint, and / or server, according to an embodiment of the present invention. Computing device 510 may represent, for example, local entity or host 101 of Figure 1, or may represent remote entity or server 102 of Figure 1. Computing device 510 may be configured to perform the procedures and / or perform the functions described in any of Figures 1-4.
[0062] The computing device may include at least one processor 511 and at least one memory 512 (and possibly at least one interface 513), which may be operatively connected or coupled, for example, by a bus 514. The processor 511 of the computing device 510 is configured to read and execute computer program code stored in the memory 512. The processor may be a CPU (Central Processing Unit), an MPU (Microprocessing Unit), or the like, or a combination thereof. The memory 512 of the computing device 510 is configured to store computer program code, such as various programs, computer / processor-executable instructions, macros, applets, etc., or portions thereof. Such computer program code, when executed by the processor 511, enables the computing device 510 to operate according to embodiments of the present invention. The memory 512 may be a RAM (Random Access Memory), a ROM (Read Only Memory), a hard disk, a secondary storage device, etc., or a combination of two or more thereof. The interface 513 of the computing device 510 is configured to interface with other computing devices and / or a user of the computing device 510. That is, the interface 513 may represent a communications interface (including, for example, a modem, antenna, transmitter, receiver, transceiver, etc.) and / or a user interface (display, touch screen, keyboard, mouse, signal lights, speaker, etc.).
[0063] According to some embodiments of the present invention, electronic files containing executable portions (e.g., any type of application file) can be analyzed, e.g., for malware analysis. Thus, exemplary embodiments of the present invention are applicable to such electronic files, e.g., Android® Application Package (APK) files, Portable Executable (PE) files, Microsoft Windows® Installer (MSI) files, or other file formats capable of distributing and / or installing application software or middleware on a computer.
[0064] In one embodiment, if a malicious file, application, activity, vulnerability, and / or misconfiguration is detected, additional actions may be taken to protect the computer or computer network, such as, for example, changing the configuration of a computer or other network node. Configuration changes may include, for example, preventing one or more nodes (which may be computers or other devices) from powering down to preserve information in RAM, enabling a firewall on one or more nodes to immediately shut off attackers, slowing or blocking network connectivity for one or more network nodes, deleting or quarantining suspicious files, collecting logs from the network node, executing a set of commands on the network node, alerting users of one or more nodes that a threat or anomaly has been detected and their workstations are under investigation, and / or sending a system update or software patch from the security backend to the node, and / or correcting the misconfiguration. In one embodiment of the present invention, one or more of these actions may be initiated automatically.
[0065] Although the present invention has been described based on preferred embodiments as set forth above, it should be understood that these embodiments are merely examples and that the scope of the claims is not limited to these embodiments. It is anticipated that those skilled in the art will be able to implement modifications and alternatives within the scope of the appended claims in light of the above disclosure. Each feature disclosed or illustrated in this specification can be incorporated into the present invention alone or in appropriate combination with other features disclosed or illustrated in this specification. The examples and examples shown in the above description are not exhaustive unless expressly stated otherwise.
Claims
1. 1. An exposure management method for assessing exposure of assets of an organization, comprising: The assets include at least one host (101, 205a-205h) including a computer or server (102, 202); The exposure management method includes: creating a model of the organization that manages the assets; creating models of multiple threat actors capable of attacking assets of the organization; generating a reduced set of threat actors associated with the organization based on the relevance of particular threat actors to the organization in light of the created threat actor model and the created organization model; For each threat actor in the reduced set of threat actors: Identifying available attack paths against assets of the organization using an attack path simulator; Integrating the identified available attack vectors against the organizational assets into an attack tree for a particular threat actor; Exposure management methods.
2. Integrates a threat actor's attack tree into an attack forest the attack forest includes an attack tree for one threat actor; The exposure management method of claim 1 .
3. Integrating the attack forest of all threat actors into an attack path map of the organization's assets that represents the organization's attack surface, including the organization's global attack surface; 3. The exposure management method according to claim 1 or 2.
4. using the attack tree and / or the attack forest to prioritize the threat actors and / or to prioritize responses to findings, including identified vulnerabilities and / or misconfigurations; and / or The attack forest inherits the same priority as the corresponding threat actor; The exposure management method according to any one of claims 1 to 3.
5. The model of a threat actor includes at least one of the following information about the threat actor: the threat actor's affiliation, the threat actor's expertise, the threat actor's location, and / or the threat actor's profit expectations; and / or the information regarding threat actors is received from threat intelligence sources including threat intelligence feeds and / or threat intelligence databases including internal threat intelligence databases and / or external threat intelligence databases; The exposure management method according to any one of claims 1 to 4.
6. If the threat actor's association with the organization meets criteria defined by the threat actor model for the particular threat actor and the organization's model, the threat actor is included in the reduced set of threat actors associated with the organization; The exposure management method according to any one of claims 1 to 5.
7. overlaying the threat actor model and the organization model to generate the reduced set of threat actors associated with the organization; the overlaying includes prioritizing the threat actors using threat intelligence data; The exposure management method according to any one of claims 1 to 6.
8. the association the threat actor has with the organization is based at least in part on information about the threat actor, including the threat actor's affiliation, the threat actor's expertise, the threat actor's location, and / or the threat actor's interest; The exposure management method according to any one of claims 1 to 7.
9. the threat actor model and / or the organization model includes a list of actions of the threat actor and / or the organization, including actions that the threat actor can take, in the form of a probabilistic model, including deterministic rules, Markov chains, and / or rules of behavior of the threat actor and / or the organization; The exposure management method according to any one of claims 1 to 8.
10. and / or, wherein the creation of the organizational model comprises collecting at least one of data about the customer organization including location, industry, revenue, employees, related security incidents and reports, the size of the organization, market segment, and geographic location; the data for creating the model of the organization is collected by at least one of an agent installed on at least one host (206a-206h), an agent and / or an EPP sensor installed on the at least one host, an agent and / or an XDR sensor installed on the at least one host, a vulnerability management system, a security posture system including a cloud security posture system, and an identity reputation database; The exposure management method according to any one of claims 1 to 9.
11. identifying the attack tree using the attack path simulator, Identifying a target asset and defining the identified target asset as a root node of the attack tree; identifying attack paths available to an attacker to access the target asset based at least in part on the identified vulnerabilities of the host (101, 205a-205h) and / or network (201); Including, The exposure management method according to any one of claims 1 to 10.
12. 1. An exposure management system for assessing exposure of assets of an organization, comprising: the assets include at least one host (101, 205a-205h) including a computer or server (102, 202); The exposure management system includes: creating a model of the organization that manages the assets; creating models of multiple threat actors capable of attacking assets of the organization; Given the threat actor model created and the organization model created, generating a reduced set of threat actors associated with the organization based on the relevance of particular threat actors to the organization; For each threat actor in the reduced set of threat actors: identifying available attack paths against the organization's assets using an attack path simulator; Integrating the identified available attack vectors against the organizational assets into an attack tree for a particular threat actor; It is configured as follows: Exposure Management System.
13. An exposure management system configured to carry out the exposure management method of any one of claims 2 to 11.
14. A computer program comprising instructions for causing a computer to execute the exposure management method according to any one of claims 1 to 11.
15. A computer readable medium storing the computer program of claim 14.