Agile Security Platform Attack Graph Alert Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large computer networks face challenges in effectively prioritizing security alerts due to the dilution effect from numerous alerts, many of which are not critical, leading to inefficient resource allocation and delayed response to real incidents.

Innovation Solution

An agile security platform that utilizes attack graphs to prioritize alerts based on asset vulnerability, value, and breach potential, integrating cyber-intelligence and operational technology systems, and employing AI-driven analytics to optimize alert management and resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security monitoring systems display all alerts in large networks, then complete visibility of security events is achieved, but resource allocation efficiency deteriorates due to alert dilution and inability to prioritize critical issues

Engineering Contradiction:
Improvesecurity monitoring completenessVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the monolithic alert display into prioritized groups based on attack graph analysis. Alerts are divided into critical, high, medium, and low priority categories, allowing security personnel to focus on the most significant threats first while maintaining awareness of all security events through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of alert presentation from uniform display to differentiated prioritization based on multiple factors including attack graph path analysis, asset criticality, vulnerability severity, and attack likelihood. This transforms the alert management system from displaying all alerts equally to presenting them in a risk-based hierarchy that optimizes resource allocation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security personnel respond to all alerts equally, then comprehensive coverage of security events is maintained, but response time to critical incidents deteriorates due to lack of prioritization

Engineering Contradiction:
Improvesecurity event coverageVSAvoidcritical incident response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary analysis of all alerts through attack graph computation before security personnel need to respond. The system pre-calculates attack paths, identifies critical assets, and determines alert priorities in advance, so that when security personnel review alerts, they are already organized by urgency and potential impact, eliminating the need for manual triage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback loops where alert response outcomes and emerging threat intelligence continuously update the attack graphs and prioritization models. This ensures that the prioritization system learns from actual incidents and adapts to new attack patterns, maintaining accurate prioritization over time while ensuring comprehensive coverage.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive attack graph analysis is performed across the entire enterprise network, then complete security risk visibility is achieved, but computational complexity and processing time deteriorate

Engineering Contradiction:
Improvesecurity risk assessment completenessVSAvoidcomputational processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into logical zones or segments for attack graph analysis, focusing computational resources on critical areas. By dividing the network into manageable segments and analyzing attack graphs separately for each segment, the system achieves comprehensive risk visibility without being overwhelmed by the complexity of analyzing the entire network as a single unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial attack graph analysis by focusing computational effort on the most critical assets and high-risk areas of the network rather than uniformly analyzing all assets. The system identifies and prioritizes analysis of assets that represent the greatest security risk, achieving sufficient risk visibility with reduced computational complexity by not over-analyzing low-risk areas.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11757921B2Leveraging attack graphs of agile security platform
Publication Date: 2023.09.12 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11757921B2 patent drawing
  • US11757921B2 patent drawing
  • US11757921B2 patent drawing

AI summary

Implementations of the present disclosure include receiving, from an agile security platform, attack graph (AG) data representative of one or more AGs, each AG representing one or more lateral paths within an enterprise network for reaching a target asset from one or more assets within the enterprise network, processing, by a security platform, data from one or more data sources to selectively generate at least one event, the at least one event representing a potential security risk within the enterprise network, and selectively generating, within the security platform, an alert representing the at least one event, the alert being associated with a priority within a set of alerts, the priority being is based on the AG data.