Attack Path Analysis Using Network Configuration State Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity systems fail to leverage network configuration and policy data to detect malicious network activity effectively, relying solely on traffic observation and anomaly detection.

Innovation Solution

A software representation of network configuration and policy data is created, allowing for the simulation of state transitions to identify potential attack paths and generate detection signatures using a fuzzer to explore these transitions, thereby capturing the full logic and conditions of network environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If machine learning models are used to detect malicious network activity based solely on traffic observation and anomaly detection, then detection capability is improved, but network configuration and policy data are not utilized

Engineering Contradiction:
Improvedetection capabilityVSAvoidnetwork configuration and policy data
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent combines machine learning-based anomaly detection with network configuration and policy data analysis. The system merges traffic observation results with configuration data to create a comprehensive detection framework that leverages both approaches simultaneously, resolving the contradiction between using ML alone and utilizing configuration data.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a multi-functional detection platform that can operate in multiple modes: pure machine learning anomaly detection, configuration-based detection, and hybrid detection. This universal approach allows the system to utilize network configuration and policy data while maintaining the effectiveness of machine learning methods.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If network configuration and policy data are integrated into the detection system, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection system into distinct modules: a machine learning component for anomaly detection, a configuration data processing component, and an integration layer. This segmentation allows each component to handle its specific task independently, reducing overall system complexity while maintaining high detection accuracy through coordinated operation of the segments.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4254867B1Method, product, and system for analyzing attack paths in computer network generated using a software representation that embodies network configuration and policy data for security management
Publication Date: 2025.12.17 VECTRA NETWORKS
  • EP4254867B1 patent drawingFigure 1A
  • EP4254867B1 patent drawingFigure 1B
  • EP4254867B1 patent drawingFigure 1C

AI summary

Disclosed is an approach for analyzing attack paths in computer network generated using a software representation that embodies network configuration and policy data for security management. In some embodiments, the approach includes a process to analyze attack paths in a computer network to determine which attack paths might be most productively covered using a corresponding detection signature. In some embodiments, the attack paths are identified using a software representation that embodies network configuration and policy data. The software representation comprises a state machine where different states can be reached using respective transitions or properties. The states correspond to respective entities on the network which may comprise resources that are identifiable for protection in the software representation using crash statements. The software representation can then be stimulated using software analysis tools such to identify sequences of state-to-state transitions that could be used to compromise a protected resource on the computer network.