Process-Aware Attack Graph Mitigation Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer networks are vulnerable to cyber-attacks, and existing defense mechanisms struggle to effectively prioritize and mitigate risks, especially in critical infrastructure networks.

Innovation Solution

The implementation of process-aware analytical attack graphs (AAGs) and a mitigation simulator within an agile security platform to prioritize remedial actions and mitigate cyber security risks in enterprise networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If process-aware analytical attack graphs and mitigation simulator are implemented to prioritize remedial actions, then risk mitigation effectiveness is improved, but system complexity and computational resources increase

Engineering Contradiction:
Improverisk mitigation effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex risk assessment task into distinct functional modules: process-aware analytical attack graph generation module, risk assessment module, and mitigation simulator module. Each module handles a specific aspect of the risk prioritization process, making the overall system more manageable and maintainable while achieving comprehensive risk mitigation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary risk assessment and prioritization before actual security incidents occur. By pre-generating attack graphs and simulating mitigation scenarios, the system prepares prioritized remedial action lists in advance, enabling faster response when real threats materialize without requiring complex real-time decision-making

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive risk assessment across multiple risk aspects is performed, then risk prioritization accuracy is improved, but computational time and resources increase

Engineering Contradiction:
Improverisk prioritization accuracyVSAvoidcomputational time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements a multi-aspect risk assessment that evaluates multiple risk dimensions (confidentiality, integrity, availability, safety) simultaneously. Rather than performing sequential assessments, the system conducts parallel evaluation across all risk aspects, achieving comprehensive accuracy without proportionally increasing total computational time

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If process-aware AAG is used to map nodes to process attributes, then attack path analysis capability is improved, but graph generation complexity increases

Engineering Contradiction:
Improveattack path analysis capabilityVSAvoidgraph generation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The process-aware analytical attack graph uses a universal node structure that can represent multiple types of entities (processes, assets, vulnerabilities, attack vectors) within a single graph framework. This multi-functional node design enables comprehensive attack path analysis across diverse target systems without requiring separate graph generation mechanisms for each entity type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12284200B2Automated prioritization of process-aware cyber risk mitigation
Publication Date: 2025.04.22 ACCENTURE GLOBAL SOLUTIONS LTD
  • US12284200B2 patent drawing
  • US12284200B2 patent drawing
  • US12284200B2 patent drawing

AI summary

Implementations are directed to receiving graph data representative of a process-aware AAG that is representative of potential lateral movement of adversaries within a computer network, receiving risk profile data representative of a risk profile of an enterprise with respect to two or more risk aspects, generating, by a process-aware risk assessment module, a risk assessment based on the process-aware AAG and the risk profile, and generating, by a mitigation simulator module, a mitigation list based on the process-aware AAG, the risk profile, and the risk assessment, the mitigation list comprising a prioritized list of two or more facts of the process-aware AAG. Other implementations of this aspect include corresponding systems, apparatus, and computer programs, configured to perform the actions of the methods, encoded on computer storage devices.