Agile Security Platform Analyzing Attack Graphs for Network Hackability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security controls in enterprise networks often prove ineffective in mitigating vulnerabilities, leading to wasted resources and increased risk, as they fail to accurately assess and address the hackability of the network over time.

Innovation Solution

The implementation of an agile security platform that generates analytical attack graphs (AAGs) to determine graph values representing the hackability of the network, allowing for the evaluation of security control effectiveness and enabling the execution of remedial actions such as rolling back or adding security controls based on changing graph values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security controls are implemented to mitigate vulnerabilities, then risk mitigation is improved, but technical resources are wasted when controls are ineffective

Engineering Contradiction:
Improverisk mitigationVSAvoidtechnical resources
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system continuously monitors graph values before and after security control implementation to determine whether controls are effective. This feedback mechanism allows the system to identify ineffective controls and trigger remedial actions, preventing waste of technical resources on controls that do not mitigate risk.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system automatically executes remedial actions such as removing ineffective security controls or implementing alternative controls without requiring manual intervention. This self-service capability ensures that technical resources are efficiently allocated by eliminating ineffective controls and implementing effective ones autonomously.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If graph values are continuously monitored to evaluate security control effectiveness, then security assessment accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system uses graph values as an intermediary metric to assess security control effectiveness. Instead of directly analyzing complex security states, the system monitors changes in graph values which serve as a simplified yet accurate indicator of security posture, reducing the complexity of continuous monitoring while maintaining assessment precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If ineffective security controls are not identified and removed, then risk mitigation is compromised, but resource allocation efficiency decreases

Engineering Contradiction:
Improverisk mitigationVSAvoidresource allocation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the security control portfolio by continuously evaluating graph value changes and automatically executing remedial actions. This dynamic approach ensures that ineffective controls are promptly identified and removed, maintaining both risk mitigation effectiveness and resource allocation efficiency through adaptive resource management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3764263B1Evaluating efficacy of security controls in enterprise networks using graph values
Publication Date: 2024.09.11 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP3764263B1 patent drawingFigure 1
  • EP3764263B1 patent drawingFigure 2
  • EP3764263B1 patent drawingFigure 3

AI summary

Implementations are directed to an agile security platform for enterprise-wide cyber-security and performing actions of receiving, from an agile security platform, analytical attack graph (AAG) data representative of one or more AAGs, each AAG representing one or more lateral paths within an enterprise network for reaching a target asset from one or more assets within the enterprise network, determining, for each instance of a plurality of instances of the AAG, a graph value representing a measure of hackability of the enterprise network at respective times, providing a profile of the enterprise network based on a set of graph values determined for instances of the AAG, the profile representing changes in graph values over time, determining an effectiveness of one or more security controls based on the profile, and selectively executing one or more remedial actions in response to the effectiveness.