Cyber Risk Assessment Using Asset Attack Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk determination systems for software and hardware components are inadequate in accurately assessing and mitigating cyber-attack risks, as they fail to effectively identify and adjust risk levels based on attack paths and communication between assets, leading to incomplete security control implementations.

Innovation Solution

A risk determination system comprising processors and memory, which receives incident information, identifies attack steps, adjusts risk levels, and outputs risk information, ensuring that risk levels are synchronized across assets and optimized security controls are implemented based on threat analysis and risk assessment data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional risk assessment methods are used to analyze software and hardware components, then the analysis process is simple and quick, but the accuracy and completeness of risk identification is insufficient

Engineering Contradiction:
Improverisk identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments risk assessment into discrete attack steps and paths, breaking down complex cyber-attack scenarios into individual actionable steps that can be independently analyzed and evaluated. Each attack step represents a specific action an attacker might take, allowing for granular risk assessment across multiple dimensions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds multiple dimensions to risk assessment by evaluating risks not only based on asset value but also considering attack path feasibility, attack step severity, and communication relationships between assets. This multi-dimensional approach transforms traditional single-factor risk assessment into a comprehensive multi-criteria evaluation system.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive attack path analysis is performed for all assets, then risk identification becomes more accurate, but the time and computational resources required increase significantly

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining attack steps and organizing them into attack paths before actual risk assessment occurs. This preparation work includes establishing the structure of potential attack scenarios, which can then be efficiently applied to multiple assets without repeating the entire analysis process for each one.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements partial action by focusing risk assessment on critical attack paths and high-value assets rather than uniformly analyzing all possible attack scenarios for all assets. This selective approach maintains high security coverage while reducing overall assessment time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of manufacture

If risk levels are adjusted based on attack paths and communication, then security control implementation becomes more precise, but the complexity of risk management increases

Engineering Contradiction:
Improvesecurity control implementation easeVSAvoidrisk management complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The system applies local quality by adjusting risk levels and security controls based on specific local conditions of each asset, including its role in attack paths, communication relationships with other assets, and vulnerability to specific attack steps. This allows tailored security measures for different assets rather than uniform approaches.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms where risk level adjustments based on attack path analysis and asset communication automatically trigger updates to security control implementations. This closed-loop approach ensures that security controls continuously adapt to newly identified risks and maintain appropriate protection levels.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250013754A1Risk determination system and method
Publication Date: 2025.01.09 C2A SEC LTD
  • US20250013754A1 patent drawing
  • US20250013754A1 patent drawing
  • US20250013754A1 patent drawing

AI summary

A risk determination method constituted of: receiving incident information associated with an item, the incident information comprising information regarding detected anomalous behavior in the item or information regarding a detected vulnerability in the item; based at least in part on the received incident information, identifying one or more attack steps of one or more attack paths, each of the one or more attack paths associated with a respective one of a plurality of assets contained within the item; and for each respective asset, adjusting one or more respective risk levels based at least in part on the identified one or more attack steps associated with the respective asset.