Attack Path Prediction Using Dynamic Risk Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to precisely predict attack paths in computer networks due to reliance on static properties of vulnerabilities, leading to inefficient identification and protection against cyber-attacks.

Innovation Solution

A method and system that utilize both static and dynamic data to calculate likelihood and prediction scores for vulnerabilities, predicting attack paths by correlating static and dynamic risk attributes, including Common Vulnerability Scoring System scores, correlation scores, and attacker skill indicators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional systems use static properties of vulnerabilities to predict attack paths, then the prediction process is simple, but the precision of attack path identification is insufficient

Engineering Contradiction:
Improveattack path identification precisionVSAvoidprediction system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the static vulnerability assessment into a dynamic process by continuously updating risk attributes based on real-time attack detection data. The system evolves from using fixed vulnerability properties to incorporating changing attack patterns, traffic dynamics, and temporal relationships between vulnerabilities, thereby improving prediction precision while managing complexity through adaptive learning

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces multiple new parameters including likelihood scores, prediction scores, static and dynamic risk attributes, and temporal correlations between vulnerabilities. These parameter changes enable more precise attack path identification by quantifying both the inherent vulnerability characteristics and the dynamic attack context, resolving the contradiction between precision and complexity through systematic parameter expansion

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If static and dynamic risk attributes are used to calculate likelihood and prediction scores, then attack path prediction precision is improved, but computational complexity increases

Engineering Contradiction:
Improveattack path prediction precisionVSAvoidcomputational power
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent performs preliminary calculations by pre-computing static risk attributes and vulnerability correlations before attacks occur. By preparing likelihood score components and vulnerability relationship matrices in advance, the system reduces real-time computational burden while maintaining high prediction precision when actual attacks are detected and dynamic attributes are integrated

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs self-service mechanisms through automated score calculation algorithms that dynamically compute prediction scores based on detected attack patterns. The likelihood and prediction scores are automatically updated and refined through feedback from attack detection, reducing the need for extensive manual computational analysis while improving precision through continuous self-optimization

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11438361B2Method and system for predicting an attack path in a computer network
Publication Date: 2022.09.06 HITACHI LTD
  • US11438361B2 patent drawing
  • US11438361B2 patent drawing
  • US11438361B2 patent drawing

AI summary

The present disclosure discloses method and an attack path prediction system for predicting an attack path in a computer network. The attack path prediction system receives static and dynamic data associated with a source node attacked in computer network along with static and dynamic risk attributes of one or more vulnerabilities associated with one or more target nodes reachable from source node. A likelihood score is calculated for each of one or more vulnerabilities associated with one or more target nodes in relation to each of one or more vulnerabilities associated with source node based on static and dynamic risk attributes. Additionally, a prediction score is calculated for each of one or more vulnerabilities associated with target nodes based on corresponding likelihood score and static and dynamic risk attributes. Thereafter, based on prediction score, the attack path is predicted between the source node and one or more target nodes.