Agile Security Platform Attack Graph Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security systems face challenges in understanding and optimizing remediations for enterprise networks due to difficulties in correlating analytical attack graphs with physical environments, leading to suboptimal use of resources and scheduling constraints.
Innovation Solution
An agile security platform that determines asset vulnerabilities and potential breaches by converting analytical attack graphs into physical graphs, using graph data to identify optimal fixes and schedule remediations based on operational constraints, incorporating AI and multi-objective optimization to minimize risk and cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional analytical attack graphs are used to depict enterprise networks, then security analysis can be performed, but the graphs are difficult to understand in terms of physical components and do not correlate analytical information to physical environments
Solution Approach 1:
The patent segments the attack graph into two distinct layers: an analytical layer containing security rules, configurations, and attack paths, and a physical layer containing actual network devices, assets, and connections. This segmentation allows each layer to maintain its own characteristics while establishing correlations between them, making the system both analytically rigorous and physically understandable.
Solution Approach 2:
The patent introduces an intermediary mapping mechanism that connects analytical attack graph elements to physical network elements. This mapping layer acts as a bridge, allowing security analysts to trace attack paths from the analytical layer back to specific physical devices and assets, thereby correlating abstract security information with concrete physical environments.
2Reliability
If multiple remediations are identified to enhance network security, then security improvements can be made, but remediations have different costs and impacts making optimal selection difficult
Solution Approach 1:
The patent transforms the remediation selection problem from a complex qualitative decision into a quantifiable optimization problem by introducing parameters such as cost, risk reduction, and implementation effort. These parameters allow different remediation options to be compared and ranked systematically, converting security improvement decisions into measurable trade-offs.
Solution Approach 2:
The system automatically performs remediation selection and optimization without requiring manual intervention. The security platform independently evaluates multiple remediation options, calculates their impacts and costs, and selects the optimal set of remediations based on predefined criteria, thereby eliminating the complexity of manual remediation selection for users.
3Reliability
If remediations are scheduled to minimize risk, then security risk can be reduced, but operational constraints prevent optimal scheduling
Solution Approach 1:
The patent implements dynamic scheduling that adapts remediation timing based on real-time operational constraints and changing risk conditions. The system continuously monitors operational states and adjusts remediation schedules accordingly, allowing remediations to be postponed, accelerated, or rescheduled based on actual operational needs and risk levels, thereby achieving both risk minimization and operational adaptability.
4Measurement precision
If comprehensive security analysis is performed across the enterprise network, then complete vulnerability assessment is achieved, but resource consumption and time requirements increase
Solution Approach 1:
The patent performs preliminary actions by pre-computing and caching attack paths, vulnerability data, and remediation options during off-peak times or in advance. This preliminary preparation allows the system to quickly retrieve and analyze pre-processed information when security assessments are needed, reducing the time required for comprehensive analysis while maintaining assessment completeness.
Data Source
AI summary
Implementations of the present disclosure include providing a graph representative of a network, a set of nodes representing respective assets, each edge representing one or more lateral paths between assets, the graph data including configurations affecting at least one impact that has an effect on an asset, determining multiple sets of fixes for configurations, each fix having a cost associated therewith, incorporating fix data of the sets of fixes into the graph, defining a set of fixes including one or more fixes from the multiple sets of fixes by defining an optimization problem that identifies one or more impacts that are to be nullified and executing resolving the optimization problem to define the set of fixes, each fix in the set of fixes being associated with a respective configuration in the graph, and scheduling performance of each fix in the set of fixes based on one or more operational constraints.


