Attack Path Determination Across Application Layers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Application assets are vulnerable to exploitation by bad actors, who can corrupt or steal data, destabilizing security safeguards across multiple layers of an application, and existing technologies lack effective methods to identify and mitigate these threats comprehensively.

Innovation Solution

A system and method that determine attack paths across multiple application layers by collecting signals from various sources, applying ontological knowledge and semantic relatedness, and using an inference engine to identify and map attack vectors, providing a converged topological view for feedback and analysis, thereby enabling visualization and remediation of vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive attack path analysis across multiple application layers is implemented, then security posture and vulnerability prioritization are improved, but system complexity and computational resources increase

Engineering Contradiction:
Improvesecurity postureVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the attack path analysis by dividing it into multiple application layers (e.g., presentation layer, business logic layer, data layer). Each layer is analyzed independently for vulnerabilities and attack vectors, then the results are integrated to form a comprehensive attack path map. This segmentation reduces the complexity of analyzing the entire system at once while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary attack path analysis system that acts as a mediator between raw vulnerability data and security decision-making. This intermediary layer processes vulnerability information, correlates it across application layers, and presents prioritized attack paths to security teams, simplifying the complexity of raw security data while improving security posture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If detailed vulnerability mapping and attack path determination are performed, then visibility into security risks is improved, but time and computational resources required increase

Engineering Contradiction:
Improvevisibility into security risksVSAvoidanalysis time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-mapping attack vectors and vulnerabilities across application layers before actual security incidents occur. Attack paths are pre-calculated and stored, enabling rapid response when vulnerabilities are discovered without requiring time-consuming analysis during incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual security analysis mechanisms with automated computational systems. Machine learning models and algorithms automatically determine attack paths, correlate vulnerabilities, and prioritize risks, substituting the time-consuming manual analysis process with efficient computational methods that provide detailed visibility without proportional time increases.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240265113A1Systems and Methods to Determine Attack Paths to Application Assets
Publication Date: 2024.08.08 CISCO TECHNOLOGY INC
  • US20240265113A1 patent drawing
  • US20240265113A1 patent drawing
  • US20240265113A1 patent drawing

AI summary

A system and a method to determine attack paths to application assets may include storing in a memory asset inventory indicating multiple application assets, multiple attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information configured to associate each of the application assets to one or more of the application layers. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may determine feasibility parameters that indicate a likelihood of the attack path to occur in the system, generate a visual interface showing the vulnerable assets, determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers in the visual interface based at least in part upon the feasibility parameters.