Process-Aware Attack Graph Mitigation Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer networks are vulnerable to cyber-attacks, and existing defense mechanisms struggle to effectively prioritize and mitigate risks, especially in critical infrastructure networks.
Innovation Solution
The implementation of process-aware analytical attack graphs (AAGs) and a mitigation simulator within an agile security platform to prioritize remedial actions and mitigate cyber security risks in enterprise networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If process-aware analytical attack graphs and mitigation simulator are implemented to prioritize remedial actions, then risk mitigation effectiveness is improved, but system complexity and computational resources increase
Solution Approach 1:
The system segments the complex risk assessment task into distinct functional modules: process-aware analytical attack graph generation module, risk assessment module, and mitigation simulator module. Each module handles a specific aspect of the risk prioritization process, making the overall system more manageable and maintainable while achieving comprehensive risk mitigation
Solution Approach 2:
The system performs preliminary risk assessment and prioritization before actual security incidents occur. By pre-generating attack graphs and simulating mitigation scenarios, the system prepares prioritized remedial action lists in advance, enabling faster response when real threats materialize without requiring complex real-time decision-making
2Measurement precision
If comprehensive risk assessment across multiple risk aspects is performed, then risk prioritization accuracy is improved, but computational time and resources increase
Solution Approach 1:
The system implements a multi-aspect risk assessment that evaluates multiple risk dimensions (confidentiality, integrity, availability, safety) simultaneously. Rather than performing sequential assessments, the system conducts parallel evaluation across all risk aspects, achieving comprehensive accuracy without proportionally increasing total computational time
3Adaptability or versatility
If process-aware AAG is used to map nodes to process attributes, then attack path analysis capability is improved, but graph generation complexity increases
Solution Approach 1:
The process-aware analytical attack graph uses a universal node structure that can represent multiple types of entities (processes, assets, vulnerabilities, attack vectors) within a single graph framework. This multi-functional node design enables comprehensive attack path analysis across diverse target systems without requiring separate graph generation mechanisms for each entity type
Data Source
AI summary
Implementations are directed to receiving graph data representative of a process-aware AAG that is representative of potential lateral movement of adversaries within a computer network, receiving risk profile data representative of a risk profile of an enterprise with respect to two or more risk aspects, generating, by a process-aware risk assessment module, a risk assessment based on the process-aware AAG and the risk profile, and generating, by a mitigation simulator module, a mitigation list based on the process-aware AAG, the risk profile, and the risk assessment, the mitigation list comprising a prioritized list of two or more facts of the process-aware AAG. Other implementations of this aspect include corresponding systems, apparatus, and computer programs, configured to perform the actions of the methods, encoded on computer storage devices.


