Attack Path Discovery Engine for Automated Security Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security management systems lack comprehensive computing logic and infrastructure to automatically discover attack paths in computing environments, relying on manual generation which is time-consuming, prone to errors, and not scalable for large systems.
Innovation Solution
Implementing an attack path discovery engine within a security management system that utilizes an attack path discovery framework and computation model to automatically identify attack paths by traversing a computing environment graph, incorporating elements like entry points, advancement steps, and targets defined in an attack path template.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual attack path generation is used, then security analysis can be performed with existing expertise, but the process becomes time-consuming and not scalable for large systems
Solution Approach 1:
The system enables self-service automated attack path discovery by implementing an attack path discovery engine that automatically traverses computing environment graphs and generates attack paths without requiring manual analyst intervention for each path generation task
Solution Approach 2:
The patent transforms the attack path discovery process by changing parameters from manual analysis to automated computational analysis, using defined attack operations and template elements to systematically generate attack paths across the computing environment
2Reliability
If manual attack path generation is used, then expert knowledge can be applied, but the process is hard to maintain and biased towards expert knowledge
Solution Approach 1:
The attack path discovery process is segmented into discrete template elements (entry point element, advancement step element, target element) and defined attack operations, making the system modular, maintainable, and independent of individual expert knowledge
Solution Approach 2:
The attack path discovery engine provides universal functionality by using a standardized framework that can discover attack paths across diverse computing environments and scenarios without requiring custom manual analysis for each case
3Productivity
If automated attack path discovery is implemented, then scalability is improved, but comprehensive computing logic and infrastructure are required
Solution Approach 1:
The system performs preliminary action by pre-defining attack operations and template elements that capture common attack patterns, enabling the discovery engine to efficiently generate attack paths by combining these predefined components rather than analyzing each path from scratch
Data Source
AI summary
Methods, systems, and computer storage media for providing attack path discovery management using an attack path discovery engine of a security management system. Attack path discovery management supports automatic attack path discovery that involves identifying and mapping potential pathways that attackers could use to infiltrate computing environments. In operation, an attack path discovery computation model comprising an entry point element, an advancement step element, and a target element, is accessed. A computing environment graph comprising computing components of a computing environment is accessed. Based on the entry point element, an entry point is identified in the computing graph; based on the advancement step element, an advancement step is identified in the computing environment graph; and based on the target element, a target is identified in the computing environment graph. An attack path is generated based on the entry point, the advancement steps, and the target. The attack path is communicated.


