Attack Path Mapping to Application Assets in Visualization Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to effectively visualize and understand the impact of attacks on application assets across multiple layers, leading to vulnerabilities that can be exploited by bad actors, resulting in destabilization of security safeguards and potential data corruption or modification.

Innovation Solution

A system and method that map attack paths to application assets in a visualization interface, providing a comprehensive understanding of vulnerabilities across layers by generating visual representations of vulnerable assets, associating them with indicators and remediation options, and prioritizing threats based on risk tolerance levels and remediation costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If attack paths are mapped across multiple application layers, then comprehensive understanding of vulnerabilities is achieved, but system complexity increases

Engineering Contradiction:
Improveunderstanding of attack impactVSAvoidvisualization system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the multi-layered application architecture into distinct layers (presentation layer, application layer, data layer) and maps attack paths through each layer separately. This segmentation allows comprehensive tracking of attack propagation while maintaining manageable complexity by organizing the visualization into structured, layer-specific components rather than a monolithic view.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dimensional approach by visualizing attack paths across multiple layers simultaneously, adding a vertical dimension to the traditional horizontal attack path view. This multi-dimensional visualization maps assets and their relationships across layers, enabling comprehensive understanding without linearly increasing complexity through sequential analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If visual representation of vulnerable assets is generated, then security understanding is improved, but processing time increases

Engineering Contradiction:
Improvevulnerability informationVSAvoidvisualization generation time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-identifying and cataloging assets across application layers before attack path analysis. Assets are tagged with metadata including layer affiliation, asset type, and vulnerability characteristics in advance. This preliminary organization enables rapid generation of visual representations when attacks are detected, as the foundational asset inventory is already structured and ready for quick visualization.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If prioritization of attack paths is implemented, then remediation efficiency is improved, but analysis complexity increases

Engineering Contradiction:
Improveremediation efficiencyVSAvoidanalysis system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements prioritization by changing parameters associated with each attack path, including assigning risk scores, impact levels, and urgency ratings based on the affected assets and layers. These parameter changes enable automated sorting and prioritization of attack paths for remediation. The system transforms unprioritized attack data into ranked lists using configurable parameters, improving remediation efficiency without requiring complex custom analysis logic.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240265112A1Systems and Methods to Map Attack Paths to Applications Assets in a Visualization Interface
Publication Date: 2024.08.08 CISCO TECHNOLOGY INC
  • US20240265112A1 patent drawing
  • US20240265112A1 patent drawing
  • US20240265112A1 patent drawing

AI summary

A system and a method to map attack paths in a visualization interface may include storing in a memory asset inventory indicating application assets, attack vector parameters configured to indicate vulnerabilities of one or more of the application assets, and asset mapping information. A processor may determine multiple vulnerable assets in the application assets based at least in part upon the attack vector parameters. Further, the processor may obtain security parameters from a security framework indicating one or more attack techniques, associate each of the vulnerable assets to one or more of the security parameters, and generate a visual interface showing the vulnerable assets and the security parameters. The processor may determine an attack path connecting the vulnerable assets based at least in part upon the asset mapping information, and map the attack path to the application layers and the security parameters in the visual interface.