Attack Graph Criticality Analysis for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk analysis methods for cyber-physical systems, which combine Information Technology (IT) and Operational Technology (OT), lack effective tools to quantify the criticality of assets and assess risks in a holistic manner, particularly in Energy Delivery Systems, where lateral movement of attackers within networks poses significant threats.

Innovation Solution

An agile security platform that uses data-driven modeling to assess risk by generating attack graphs that represent enterprise networks, determining asset criticality based on locality, centrality, and damage, and providing indications of path values to prevent attacks through lateral movement paths, while also offering remediation options and prioritization of security investments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If attack graphs are generated to model attacker penetration and assess risks in enterprise networks, then the ability to identify critical assets and lateral movement paths is improved, but the complexity of the security analysis system increases

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The attack graph is segmented into discrete nodes representing assets and edges representing lateral movement paths. Each node is assigned criticality metrics (locality, centrality, damage) that break down the complex risk assessment into manageable components. This segmentation allows precise measurement of individual asset criticality while maintaining overall system view.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transforms qualitative security concepts into quantitative parameters by calculating locality, centrality, and damage metrics for each asset. These parameter changes enable precise risk measurement through mathematical computation rather than subjective assessment, resolving the contradiction between measurement precision and system complexity.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If quantitative criticality metrics are calculated for each asset based on locality, centrality, and damage, then the prioritization of remediation efforts is improved, but the computational resources and time required increase

Engineering Contradiction:
Improveremediation efficiencyVSAvoidanalysis time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary calculation of criticality metrics (locality, centrality, damage) for all assets before remediation activities begin. By pre-computing these metrics and establishing the attack graph structure in advance, the system enables rapid prioritization decisions without time-consuming analysis during actual remediation execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attack graph structure and criticality metrics serve as self-updating information that automatically reflects the current state of the enterprise network. As the network topology or asset criticality changes, the metrics are recalculated to provide current prioritization guidance without requiring manual reassessment, improving remediation efficiency while managing analysis time.

Inventive Principle:
Principle #25Self-service

3Reliability

If the platform provides comprehensive risk assessment and remediation prioritization for enterprise-wide networks, then the security coverage and protection capability are improved, but the resource requirements and system overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by calculating criticality metrics specific to each asset's position and role in the network rather than applying uniform analysis across all assets. Assets with higher locality, centrality, or damage metrics receive more detailed analysis and higher prioritization, allowing comprehensive security coverage to be achieved by focusing computational resources on critical assets rather than treating all assets equally.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3644579B1Criticality analysis of attack graphs
Publication Date: 2022.03.30 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP3644579B1 patent drawingFigure 1
  • EP3644579B1 patent drawingFigure 2
  • EP3644579B1 patent drawingFigure 3

AI summary

Implementations of the present disclosure include providing, by a security platform, graph data defining a graph that is representative of an enterprise network, the graph comprising nodes and edges between nodes, a set of nodes representing respective assets within the enterprise network, each edge representing at least a portion of one or more lateral movement paths between assets in the enterprise network, determining, for each asset, a criticality of the respective asset to operation of a process, determining a lateral movement path between a first node represented by a first asset and a second node represented by second asset within the graph, determining a path value representative of a criticality in preventing an attack through the lateral movement path, and providing an indication of the path value representative of the criticality in preventing an attack through the lateral movement path.