Partial Attack Path Matching for Security Finding Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current attack path analysis approaches prioritize groups of findings that can be exploited by attackers, but fail to account for partial attack paths where attackers deviate from known strategies, leading to incomplete defenses and alert fatigue in security teams.

Innovation Solution

A system and method for analyzing partial attack paths using probabilistic, zero-trust, and defense-in-depth analyses to identify and prioritize partial matches, allowing for a more robust defense by mixing and matching parts of different attack paths, particularly focusing on insider threats and high-leverage points within applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional attack path analysis is used to prioritize security findings, then security teams can focus on groups of findings that match known attack paths, but the system fails to detect partial attack paths where attackers deviate from known strategies

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect deviations
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies partial matching by allowing security findings to match only portions of known attack paths rather than requiring complete path matches. This enables the system to detect partial attack paths where attackers have deviated from known strategies, improving detection accuracy while maintaining adaptability to novel attack vectors.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If security teams prioritize all security tool findings, then comprehensive coverage is achieved, but security teams become overloaded and experience alert fatigue

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity team efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically prioritizes security findings by calculating attack path scores and identifying critical partial matches, enabling self-service prioritization without manual review of all findings. This maintains comprehensive security coverage while significantly improving security team efficiency by reducing alert fatigue.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If complete attack path matches are required for prioritization, then precision in identifying known attack patterns is improved, but the system cannot identify novel or modified attack paths

Engineering Contradiction:
Improveattack path matching precisionVSAvoiddetection of novel attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by allowing different portions of attack paths to be matched with different levels of precision. Critical segments require precise matching while other segments allow for partial matches, enabling the system to maintain precision for known patterns while adapting to novel attack variations.

Inventive Principle:
Principle #3Local quality

4Device complexity

If the system analyzes only complete attack paths, then analysis complexity is reduced, but the system cannot account for attackers mixing and matching parts of different attack paths

Engineering Contradiction:
Improveanalysis complexityVSAvoiddefense against mixed attacks
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments attack paths into discrete findings and events that can be independently analyzed and recombined. This allows the system to analyze partial matches from different attack paths and identify when attackers mix and match segments, maintaining manageable analysis complexity while improving adaptability to sophisticated attack strategies.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12506753B2Systems and methods for analyzing partial attack paths
Publication Date: 2025.12.23 CISCO TECHNOLOGY INC
  • US12506753B2 patent drawing
  • US12506753B2 patent drawing
  • US12506753B2 patent drawing

AI summary

In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.