Continuous Attack Path Analysis in Directory Services

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Directory Services solutions fail to continuously analyze all possible attack paths due to cascading permissions and lack of real-time data aggregation, leading to incomplete exposure risk assessments and inadequate alerting for potential security threats, particularly in large networks where manual point-in-time scans are insufficient and unable to prioritize critical attack paths for remediation.

Innovation Solution

The system, known as BloodHound Enterprise, continuously collects and analyzes data from multiple sources using a graph database to identify all possible attack paths and choke points, providing real-time alerts and prioritizing remediations based on impact and severity, thereby focusing security efforts on the most critical vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If point-in-time scans are used to analyze attack paths, then the analysis is simpler and less resource-intensive, but the security assessment is incomplete and outdated due to constant changes in Directory Services assets and user credentials

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements continuous monitoring and analysis of attack paths by establishing persistent data collection mechanisms that continuously gather Directory Services asset data, user credential data, and permission data. The system performs continuous graph database updates and recurrent attack path analyses, ensuring the security assessment remains current and reliable despite constant changes in the enterprise environment

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system incorporates feedback mechanisms where the continuous analysis results are fed back into the graph database, which then triggers updated analyses. The system monitors changes in Directory Services assets and user credentials, and automatically re-analyzes attack paths when changes are detected, creating a closed-loop system that maintains accurate security assessments

Inventive Principle:
Principle #23Feedback

2Loss of information

If all possible attack paths are analyzed continuously, then complete exposure risk assessment is achieved, but the computational resources and system complexity increase significantly

Engineering Contradiction:
Improveexposure risk assessment completenessVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent segments the attack path analysis by identifying and prioritizing choke points - critical nodes and edges in the attack graph that represent the most significant security risks. By focusing analysis on these segmented critical elements rather than uniformly analyzing all possible paths, the system achieves comprehensive risk assessment while reducing computational resource consumption

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by differentiating the importance of various graph elements, assigning higher analysis priority to choke points and critical attack paths. The continuous analysis focuses computational resources on areas of highest risk, maintaining complete exposure risk assessment while optimizing resource utilization through localized intensive analysis of critical segments

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If generic alerting is used for all security issues, then comprehensive coverage is provided, but administrative and security personnel are overloaded with non-prioritized alerts

Engineering Contradiction:
Improvealerting coverageVSAvoidalert management efficiency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent changes the parameters of alerting by prioritizing alerts based on the calculated attack path risk scores and choke point significance. Instead of uniform alerting, the system adjusts alert parameters such as priority level, notification timing, and detail depth based on the assessed risk, providing comprehensive coverage while enabling efficient alert management through risk-based differentiation

Inventive Principle:
Principle #35Parameter changes

4Ease of manufacture

If nested permissions are granted in Directory Services, then assets can inherit access rights efficiently, but the Russian Doll effect creates excessive permission exposure and multiple attack paths

Engineering Contradiction:
Improvepermission management efficiencyVSAvoidpermission exposure risk
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by continuously analyzing and identifying excessive nested permissions before they can be exploited by attackers. The system proactively detects the Russian Doll effect of nested permissions, flags permission exposure risks in advance, and enables security teams to remediate unnecessary permission inheritance before it creates security vulnerabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the harmful effect of excessive nested permissions into a benefit by using the continuous analysis to identify and eliminate unnecessary permission exposures. The same nested permission structure that creates security risks also provides the data needed for the system to automatically identify and remediate the risks, turning the potential vulnerability into an opportunity for automated security improvement

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS11539725B2System and method for continuous collection, analysis and reporting of attack paths choke points in a directory services environment
Publication Date: 2022.12.27 SPECTER OPS INC
  • US11539725B2 patent drawing
  • US11539725B2 patent drawing
  • US11539725B2 patent drawing

AI summary

A system and method for analyzing directory service environment attack path choke points for an enterprise may continuously collect data about the attack paths and provide alerts.