Network Attack Surface Management via ML Inferred Security Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional honeypot systems generate many false alerts and fail to effectively mitigate targeted attacks by advanced attackers who use lateral movement techniques to exploit network vulnerabilities, lacking the ability to proactively identify and eliminate potential attack vectors.

Innovation Solution

A system that utilizes a data collector, machine learning engine, and security rules engine to map and infer security rules, visualize network activities, and automatically eliminate credential-based security rule violations, employing decoy attack vectors and deception management to detect and respond to attacker movements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If conventional honeypot systems are used to detect attacker movements, then attacker detection capability is improved, but false alert rate increases and reliability decreases

Engineering Contradiction:
Improveattacker detection capabilityVSAvoidfalse alert rate
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The system performs preliminary mapping of the network attack surface before attackers can exploit it. The attack surface map is constructed in advance, identifying all potential entry points, lateral movement paths, and target assets. This proactive approach allows the system to distinguish between legitimate security scanning and actual attacker movements, reducing false alerts while maintaining high detection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously updates the attack surface map based on real-time network monitoring and feedback from security events. When new vulnerabilities are discovered or network topology changes, the map is dynamically refreshed. This feedback mechanism ensures that detection rules remain accurate and reduce false positives while maintaining high attacker detection rates.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive network monitoring is implemented to identify all attack vectors, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the network monitoring function into distinct components: attack surface mapping module, vulnerability assessment module, real-time monitoring module, and threat analysis module. Each module handles a specific aspect of security monitoring, making the overall system more manageable and maintainable while achieving comprehensive coverage through coordinated operation of these specialized components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attack surface map serves multiple functions simultaneously: it acts as a vulnerability inventory, a network topology diagram, a threat intelligence database, and a basis for generating detection rules. This multi-functionality reduces system complexity by consolidating what would otherwise require separate systems into a single unified platform that provides comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If manual security rule creation is used to protect against attack vectors, then security precision is improved, but productivity decreases

Engineering Contradiction:
Improvesecurity rule precisionVSAvoidsecurity rule deployment speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system automatically generates security rules by analyzing the attack surface map and identifying potential attack vectors. The rule generation engine autonomously creates detection and prevention rules based on discovered vulnerabilities, network topology, and threat intelligence, eliminating the need for manual rule creation while maintaining high precision through algorithmic analysis of security requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors security events and feedback from detected threats to automatically refine and update security rules. When new attack patterns are identified or vulnerabilities are exploited, the system learns from these events and automatically adjusts detection rules, maintaining high precision while enabling rapid response to emerging threats without manual intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11303667B2Organization attack surface management
Publication Date: 2022.04.12 PROOFPOINT ISRAEL HOLDINGS LTD
  • US11303667B2 patent drawing
  • US11303667B2 patent drawing
  • US11303667B2 patent drawing

AI summary

A system for sanitizing an organization's network against attacker breach, including a data collector, gathering information about network hosts, an analyzer constructing the organization's network topology, a machine learning engine categorizing the hosts into organizational units and identifying key assets of the organization, a security rules engine mapping real-time data, and inferring security rules that prescribe on which specific hosts which specific credentials are permitted to be stored, and a user interface including an analyst dashboard enabling an analyst to visualize in real-time activities within the organizations' network, to automatically infer security rules for the network, to activate the security rules in the network, and to eliminate potential attack vectors for which the activated security rules are violated, and an attacker view visualizing the organization's network, identifying security rule violations across the organization's network, and enabling removal of credential-based security rule violations by use of actions.