Agile Security Platform Attack Graph Visualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large computer networks face inefficiencies in resource allocation due to numerous alerts of varying criticality, leading to dilution of efforts on less critical issues and time-consuming data analysis, making it challenging to effectively prioritize and manage cybersecurity threats.

Innovation Solution

An agile security platform that visualizes enterprise networks as graphs, determining node vulnerabilities and potential breach paths, allowing for user-filtered sub-graph generation and display, enabling prioritization of security tasks based on asset value and breach probability, and automating remediation recommendations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security personnel analyze all alerts in large networks, then comprehensive security monitoring is achieved, but resource efficiency deteriorates due to dilution of efforts on less critical issues

Engineering Contradiction:
Improvecomprehensive security monitoringVSAvoidresource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the network into multiple attack graphs, each representing a specific attack scenario or pathway. By dividing the comprehensive security monitoring task into smaller, focused graph analyses, security personnel can efficiently evaluate specific threat scenarios without being overwhelmed by all possible alerts simultaneously. This segmentation enables targeted resource allocation to critical attack paths while maintaining comprehensive coverage across multiple graphs.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If security personnel manually search over large amounts of network data, then detailed analysis is achieved, but time efficiency deteriorates

Engineering Contradiction:
Improvedetailed analysisVSAvoidtime efficiency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates attack graphs that are simplified representations or copies of the complex network data. These graphs capture essential attack pathways, vulnerabilities, and relationships in a structured visual format that is much easier to analyze than raw network data. Security personnel can perform detailed analysis on the graph structure without manually searching through vast amounts of underlying network data, significantly reducing analysis time while maintaining analytical depth.

Inventive Principle:
Principle #26Copying

3Loss of information

If all alerts are displayed for large networks, then complete visibility is achieved, but ease of operation deteriorates due to difficulty in prioritizing critical issues

Engineering Contradiction:
Improvecomplete visibilityVSAvoidprioritization capability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent applies local quality by displaying different types of information in different parts of the attack graph interface. Critical attack pathways, high-risk vulnerabilities, and urgent threats are highlighted or emphasized in specific graph regions, while less critical information is displayed with reduced prominence. This spatial differentiation of information quality enables security personnel to quickly identify and prioritize critical issues while maintaining awareness of the complete security landscape across all displayed graphs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11838310B2Generating attack graphs in agile security platforms
Publication Date: 2023.12.05 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11838310B2 patent drawing
  • US11838310B2 patent drawing
  • US11838310B2 patent drawing

AI summary

Implementations of the present disclosure include providing graph data defining a graph that is representative of an enterprise network, the graph including nodes and edges between nodes, each node representing an asset within the enterprise network, and each edge representing one or more lateral attack paths between assets in the enterprise network, determining, for each node, an incoming value based on attributes of a set of incoming edges and an outgoing value based on attributes of a set of outgoing edges, the attributes including a number of edges and semantic types of the edges, at least one cardinality value of each node being determined based on one or more of the incoming value and the outgoing value of the node, receiving input representative of filter parameters, generating a sub-graph based on attributes of the nodes and the filter parameters, and displaying, by the visualization platform, the sub-graph in a display.