Adaptive Attack Surface Clustering for Dynamic Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attack surface reduction (ASR) techniques face challenges in identifying truly unused services versus those used infrequently, leading to potential negative business impacts when disabling services that are occasionally used.

Innovation Solution

Adaptive clustering of machines and users based on event feedback and user requests, using methods like hierarchical agglomerative clustering and penalty score determination, to dynamically adjust ASR settings and minimize vulnerabilities while maintaining business efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If services are excluded to reduce attack surface, then security is improved, but business functionality may be negatively impacted

Engineering Contradiction:
ImprovesecurityVSAvoidbusiness functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the organization's endpoints into multiple clusters based on their service usage patterns and characteristics. By dividing endpoints into distinct clusters (e.g., Cluster A, Cluster B, Cluster C), the system can apply different ASR policies to each cluster, allowing services to be excluded in some clusters while maintained in others, thus balancing security improvements with business functionality requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying customized ASR policies to different endpoint clusters based on their specific characteristics and service usage patterns. Each cluster receives tailored security configurations that match its functional requirements, rather than applying a uniform policy across all endpoints. This allows security measures to be optimized locally for each cluster's specific needs.

Inventive Principle:
Principle #3Local quality

2Reliability

If ASR policies are applied universally across the organization, then security coverage is maximized, but adaptability to specific endpoint needs is reduced

Engineering Contradiction:
Improvesecurity coverageVSAvoidendpoint-specific customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the organization's endpoints into multiple clusters based on their service usage patterns, device characteristics, and functional requirements. This segmentation enables the system to maintain comprehensive security coverage across all clusters while simultaneously providing customized ASR policies for each cluster, thus achieving both broad security coverage and endpoint-specific adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal clustering framework that can accommodate diverse endpoint types and organizational structures. The clustering mechanism itself is universal and applicable to any organization, while within this universal framework, each cluster can be customized with specific ASR policies. This multi-functional approach allows the same system to provide both organization-wide security standards and cluster-specific adaptations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If clustering is performed with fine granularity, then endpoint-specific security is optimized, but system complexity increases

Engineering Contradiction:
Improveendpoint-specific securityVSAvoidclustering system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges endpoints with similar characteristics into clusters, reducing the overall complexity of managing individual endpoint configurations. By combining multiple endpoints into unified clusters with common service usage patterns, the system simplifies policy management while still maintaining endpoint-specific security optimization through cluster-level customization.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements dynamic clustering that can adapt to changing organizational needs and endpoint characteristics. The clustering system is not static but can be reconfigured as endpoints are added, removed, or change their service usage patterns over time. This dynamic approach optimizes endpoint-specific security while managing system complexity through automated adaptation rather than manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3921994B1Adaptation of attack surface reduction clusters
Publication Date: 2023.08.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3921994B1 patent drawingFigure 1
  • EP3921994B1 patent drawingFigure 2
  • EP3921994B1 patent drawingFigure 3

AI summary

A computing system performs adaptive clustering of machines (e.g., computing devices) and/or machine users in an organization for attack surface reduction (ASR) responsively to event feedback including system-based exclusion events and user-based requests for exclusion. The cluster adaptation may be applied to conventional vector-quantization clustering algorithms, for example K-Means, expectation-maximization (EM) clustering, or affinity clustering, to provide adaptable clusters of machines or users. The adaptation enables aggregation or disaggregation of endpoints into clusters to minimize negative business impacts on the organization while maximizing security in view of changes in the organization that occur dynamically such as varying roles for users, new applications and updates being released, and the like.