Agile Security Platform Attack Path Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional techniques for detecting and addressing cyber threats in critical infrastructure networks are inadequate, as they fail to consider the complexity of multi-stage attacks and do not provide comprehensive solutions for real-world scenarios, leading to incomplete risk assessments and inadequate defense mechanisms.
Innovation Solution
An agile security platform that determines asset vulnerability and potential breach paths in enterprise networks by using a state graph to analyze attack paths, incorporating threat intelligence and security controls, and generating alerts based on path stealthiness and hardness values, thereby prioritizing remediation actions and enhancing cyber resilience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional intrusion detection techniques are used to monitor individual attack footprints, then detection capability is provided, but the techniques fail to capture the complexity of multi-stage attacks and provide incomplete risk assessments
Solution Approach 1:
The patent segments the attack detection process into multiple components: individual attack footprint detection, attack path construction, and holistic risk assessment. By dividing the complex multi-stage attack into detectable segments and reassembling them into complete attack paths, the system achieves both precise detection of individual events and comprehensive assessment of overall risk.
Solution Approach 2:
The patent transitions from detecting attacks in a single dimension (individual intrusion events) to multiple dimensions by constructing attack paths that incorporate sequence, relationships between events, and contextual information. This dimensional expansion enables the system to capture the full complexity of multi-stage attacks while maintaining detection precision.
2Reliability
If comprehensive attack path analysis is implemented to capture multi-stage attack complexity, then risk assessment completeness is improved, but system complexity and computational requirements increase
Solution Approach 1:
The patent performs preliminary actions by pre-defining attack patterns, footprints, and path construction rules before actual attack detection. This preparation work enables the system to efficiently analyze complex multi-stage attacks without requiring excessive computational resources during real-time operation, as the analytical framework is already established.
Solution Approach 2:
The patent creates simplified representations (copies) of complex attack paths and relationships. By modeling attack paths as structured data objects with standardized attributes and relationships, the system manages complexity through abstraction, making comprehensive analysis tractable while maintaining complete risk assessment capability.
3Speed
If traditional security monitoring is used to detect individual intrusions, then real-time alerting is provided, but the system cannot determine the full scope or end state of ongoing attacks
Solution Approach 1:
The patent implements feedback mechanisms where detected attack footprints are continuously fed into the attack path construction process. As new events are detected, the system updates existing attack paths and generates new ones, creating a dynamic feedback loop that maintains real-time alerting while progressively revealing the full scope and evolution of ongoing attacks.
Solution Approach 2:
The patent ensures continuous analysis of attack events by maintaining persistent attack path structures that are continuously updated as new information becomes available. This continuous action enables the system to provide real-time alerts while simultaneously building a complete picture of attack scope, preventing information loss through uninterrupted analytical processing.
Data Source
AI summary
Implementations of the present disclosure include providing a state graph representative of a set of action states within a network, each action state representing an attack that can be performed by an adversary within the network, determining a path stealthiness value for each attack path of a set of attack paths within the network, path stealthiness values being determined based on a mapping that maps each action state to one or more technique-tactic pairs and one or more security controls, determining a path hardness value for each attack path of the set of attack paths within the network, path hardness values being determined based on a state correlation matrix that correlates action states relative to each other, and a decay factor that represents a reduction in effort required to repeatedly perform an action of an action state, and selectively generating one or more alerts based on one or more of path stealthiness values and path hardness values.


