Attack Graph Risk Assessment with Human Behavior Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current risk assessment methods for cyber security, particularly in information systems, are inadequate as they fail to accurately account for human behavior and free will, limiting their effectiveness in predicting and managing risks associated with human attacks on computer networks.

Innovation Solution

A method involving the creation of an attack graph that represents nodes for actors, events, and conditions, using Markov Monte Carlo simulations to calculate edge probabilities and identify attack paths, with the integration of physical sensors and benign actor modeling to generate security alerts and prioritize risks based on likelihood and impact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional risk assessment methods (vulnerability scanning, CVSS scoring, subjective assignment) are used, then the assessment process is simple and quick, but the accuracy and completeness of risk assessment is limited

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidassessment method complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The risk assessment process is segmented into multiple independent components: vulnerability identification, threat modeling, attack path analysis, and risk calculation. Each component can be independently implemented and validated, allowing the complex assessment to be built from manageable parts while maintaining high accuracy through comprehensive coverage of all risk factors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional approach by modeling risk assessment as a multi-dimensional attack graph with nodes representing system states and edges representing potential attack transitions. This transforms the traditional single-dimension vulnerability scoring into a multi-dimensional state-space analysis, enabling accurate prediction of attack paths and outcomes while providing a structured framework for complex assessments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive risk factors including human behavior are included in the assessment, then the accuracy of predicting human attacks improves, but the complexity of the assessment model increases

Engineering Contradiction:
Improveprediction reliability for human attacksVSAvoidassessment model complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms qualitative human behavior factors into quantifiable parameters that can be integrated into the risk model. By converting behavioral characteristics, motivation levels, and capability assessments into numerical values, the model can systematically incorporate human factors without requiring complex qualitative analysis, thereby improving prediction reliability while maintaining model manageability.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If attack paths and multiple conditions are analyzed, then the completeness of risk assessment improves, but the time and resources required for assessment increase

Engineering Contradiction:
Improverisk assessment completenessVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-calculating attack paths, vulnerability relationships, and threat profiles before actual risk assessment is needed. The attack graph is constructed in advance with all possible attack transitions mapped, allowing rapid query and assessment when needed. This preprocessing significantly reduces assessment time while maintaining complete analysis of all attack paths and conditions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10425429B2System and method for cyber security analysis and human behavior prediction
Publication Date: 2019.09.24 BASSETT GABRIEL
  • US10425429B2 patent drawing
  • US10425429B2 patent drawing
  • US10425429B2 patent drawing

AI summary

An improved method for analyzing computer network security has been developed. The method first establishes multiple nodes, where each node represents an actor, an event, a condition, or an attribute related to the network security. Next, an estimate is created for each node that reflects the ease of realizing the event, condition, or attribute of the node. Attack paths are identified that represent a linkage of nodes that reach a condition of compromise of network security. Next, edge probabilities are calculated for the attack paths. The edge probabilities are based on the estimates for each node along the attack path. Next, an attack graph is generated that identifies the easiest conditions of compromise of network security and the attack paths to achieving those conditions. Finally, attacks are detected with physical sensors on the network, that predict the events and conditions. When an attack is detected, security alerts are generated in response to the attacks.