Agile Security Platform Attack Graph Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems face challenges in understanding and optimizing remediations for enterprise networks due to difficulties in correlating analytical attack graphs with physical environments, leading to suboptimal use of resources and scheduling constraints.

Innovation Solution

An agile security platform that determines asset vulnerabilities and potential breaches by converting analytical attack graphs into physical graphs, using graph data to identify optimal fixes and schedule remediations based on operational constraints, incorporating AI and multi-objective optimization to minimize risk and cost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional analytical attack graphs are used to depict enterprise networks, then security analysis can be performed, but the graphs are difficult to understand in terms of physical components and do not correlate analytical information to physical environments

Engineering Contradiction:
Improvecorrelation precision between analytical and physical informationVSAvoidunderstandability of attack graphs
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent segments the attack graph into two distinct layers: an analytical layer containing security rules, configurations, and attack paths, and a physical layer containing actual network devices, assets, and connections. This segmentation allows each layer to maintain its own characteristics while establishing correlations between them, making the system both analytically rigorous and physically understandable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mapping mechanism that connects analytical attack graph elements to physical network elements. This mapping layer acts as a bridge, allowing security analysts to trace attack paths from the analytical layer back to specific physical devices and assets, thereby correlating abstract security information with concrete physical environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple remediations are identified to enhance network security, then security improvements can be made, but remediations have different costs and impacts making optimal selection difficult

Engineering Contradiction:
Improvenetwork security levelVSAvoidcomplexity of remediation selection
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the remediation selection problem from a complex qualitative decision into a quantifiable optimization problem by introducing parameters such as cost, risk reduction, and implementation effort. These parameters allow different remediation options to be compared and ranked systematically, converting security improvement decisions into measurable trade-offs.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system automatically performs remediation selection and optimization without requiring manual intervention. The security platform independently evaluates multiple remediation options, calculates their impacts and costs, and selects the optimal set of remediations based on predefined criteria, thereby eliminating the complexity of manual remediation selection for users.

Inventive Principle:
Principle #25Self-service

3Reliability

If remediations are scheduled to minimize risk, then security risk can be reduced, but operational constraints prevent optimal scheduling

Engineering Contradiction:
Improverisk minimizationVSAvoidscheduling flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic scheduling that adapts remediation timing based on real-time operational constraints and changing risk conditions. The system continuously monitors operational states and adjusts remediation schedules accordingly, allowing remediations to be postponed, accelerated, or rescheduled based on actual operational needs and risk levels, thereby achieving both risk minimization and operational adaptability.

Inventive Principle:
Principle #15Dynamics

4Measurement precision

If comprehensive security analysis is performed across the enterprise network, then complete vulnerability assessment is achieved, but resource consumption and time requirements increase

Engineering Contradiction:
Improvevulnerability assessment completenessVSAvoidtime for security analysis
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-computing and caching attack paths, vulnerability data, and remediation options during off-peak times or in advance. This preliminary preparation allows the system to quickly retrieve and analyze pre-processed information when security assessments are needed, reducing the time required for comprehensive analysis while maintaining assessment completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11907407B2Generating attack graphs in agile security platforms
Publication Date: 2024.02.20 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11907407B2 patent drawing
  • US11907407B2 patent drawing
  • US11907407B2 patent drawing

AI summary

Implementations of the present disclosure include providing a graph representative of a network, a set of nodes representing respective assets, each edge representing one or more lateral paths between assets, the graph data including configurations affecting at least one impact that has an effect on an asset, determining multiple sets of fixes for configurations, each fix having a cost associated therewith, incorporating fix data of the sets of fixes into the graph, defining a set of fixes including one or more fixes from the multiple sets of fixes by defining an optimization problem that identifies one or more impacts that are to be nullified and executing resolving the optimization problem to define the set of fixes, each fix in the set of fixes being associated with a respective configuration in the graph, and scheduling performance of each fix in the set of fixes based on one or more operational constraints.