Attack Surface Score Computation for Network Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise networks face challenges in detecting and preventing malicious attacks on workloads due to the lack of effective methods to assess and mitigate vulnerabilities, particularly through open ports, which are common attack vectors.

Innovation Solution

A system and method for determining an attack surface score for workloads by analyzing open ports, unused ports, vulnerability scores, and process hashes, and implementing security policies to reduce vulnerability, such as closing unused ports and quarantining vulnerable packages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are implemented to protect workloads from attacks through open ports, then network security is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of workload vulnerability by analyzing open ports, unused ports, vulnerability scores, and process hashes before attacks occur. This proactive approach enables security policies to be implemented in advance, reducing the need for complex reactive security measures and lowering overall system complexity while maintaining high security standards

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables workloads to self-assess their own vulnerability by automatically analyzing their open ports, unused ports, vulnerability scores, and process hashes. This self-service capability reduces the need for external security management complexity while improving reliability through continuous automated assessment and policy enforcement

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive vulnerability assessment is performed on all workloads, then security coverage is improved, but computational resources and time consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies different assessment depths to different workloads based on their specific characteristics such as open ports, unused ports, vulnerability scores, and process hashes. Rather than uniformly assessing all workloads with the same computational intensity, the system tailors the assessment to each workload's actual security profile, reducing overall computational resource consumption while maintaining comprehensive security coverage

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs vulnerability assessment on critical components (open ports, unused ports, vulnerability scores, process hashes) rather than attempting to assess every possible security parameter. This partial action approach focuses computational resources on the most significant vulnerability vectors, achieving effective security coverage with reduced energy and time consumption

Inventive Principle:
Principle #16Partial or excessive action

3Object-affected harmful factors

If security policies are implemented to close unused ports and quarantine vulnerable packages, then workload vulnerability is reduced, but system operational complexity increases

Engineering Contradiction:
Improveworkload vulnerabilityVSAvoidsystem operation simplicity
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system automatically implements security policies by closing unused ports and quarantining vulnerable packages based on the vulnerability assessment results. This automated self-service approach reduces workload vulnerability without requiring manual operational intervention, thereby reducing system operational complexity while maintaining ease of operation through policy-driven automation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12050698B2Determining application attack surface for network applications
Publication Date: 2024.07.30 CISCO TECHNOLOGY INC
  • US12050698B2 patent drawing
  • US12050698B2 patent drawing
  • US12050698B2 patent drawing

AI summary

Systems, methods, and computer-readable media for attack surface score computation can include the following processes. An attack surface score service receives information identifying open ports associated with an application. The attack surface score service determines an attack surface score for the application based on the information and common attack ports. A policy engine determines whether to implement a policy for reducing vulnerability of the application to attacks to yield a determination. The policy engine implements a vulnerability reduction policy based on the determination.