Analytical Attack Graph Modeling for Scalable Cyber-Attack Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-attack process discovery in computer networks faces challenges such as scalability, resource-intensive graph processing, limited versatility, and incomplete attack path data, making it difficult to prioritize security threats effectively.

Innovation Solution

The implementation processes analytical attack graphs (AAGs) to convert them into tactic graphs, generating compact process models that include hardness scores, enabling faster and more versatile cyber-attack path analysis, applicable across multiple networks, and supporting machine learning for real-time security risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If analytical attack graphs are used to represent all possible attack paths, then comprehensive attack coverage is achieved, but processing power and time requirements increase significantly

Engineering Contradiction:
Improveattack path coverageVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent segments the complete attack graph into multiple subgraphs based on attack path similarity and structural characteristics. Each subgraph represents a portion of the attack space, allowing parallel processing and reducing the computational burden on single processing units while maintaining comprehensive coverage through aggregation of results from all subgraphs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic subgraph generation that adapts to the specific network topology and attack scenarios being analyzed. Subgraphs are created and processed dynamically based on the complexity and size of the attack graph, allowing the system to optimize processing resources according to the actual analysis needs rather than using a fixed segmentation approach.

Inventive Principle:
Principle #15Dynamics

2Loss of information

If detailed analytical attack graphs are constructed, then complete attack path information is captured, but the system lacks real-time adaptability

Engineering Contradiction:
Improveattack path informationVSAvoidreal-time adaptability
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary analysis by pre-processing the attack graph to identify and segment potential attack paths into subgraphs before actual attack detection occurs. This preliminary structuring enables faster real-time analysis when attacks are detected, as the segmentation logic and subgraph structures are already established and can be quickly queried without requiring full graph reconstruction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of graph representation by transforming the complete attack graph into multiple smaller subgraphs with modified structural parameters. This transformation maintains the essential attack path information while changing the scale and organization of the data structure, enabling more efficient real-time processing and adaptation to different attack scenarios.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all attack paths are analyzed equally, then comprehensive security assessment is provided, but priority-based security measures cannot be implemented

Engineering Contradiction:
Improvesecurity assessment completenessVSAvoidsecurity measure prioritization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by assigning different priority levels and security characteristics to different subgraphs based on their attack path characteristics, network criticality, and potential impact. Rather than treating all attack paths uniformly, the system enables differentiated security responses where high-priority subgraphs receive more intensive monitoring and faster response mechanisms, while lower-priority subgraphs use standard processing.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4124975B1Discovering cyber-attack process model based on analytical attack graphs
Publication Date: 2026.05.20 ACCENTURE GLOBAL SOLUTIONS LTD
  • EP4124975B1 patent drawingFigure 1
  • EP4124975B1 patent drawingFigure 2
  • EP4124975B1 patent drawingFigure 3

AI summary

Implementations of the present disclosure include receiving analytical attack graph data representative of an analytical attack graph, the analytical attack graph including: one or more rule nodes each representing a network configuration rule; and one or more impact nodes each representing an impact of one or more respective network configuration rules; converting the analytical attack graph to a tactic graph including one or more tactic nodes, each tactic node representing at least one rule node and at least one impact node; determining one or more paths of the tactic graph that lead to a particular network impact; generating a process model based on the paths that lead to the particular network impact, the process model representing network activity for execution of a process that leads to the particular network impact; and executing one or more remedial actions based on the process model to mitigate cyber-security risk to the enterprise network.