Cloud Threat Pathway Risk Scoring for Critical Asset Reachability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional threat detection mechanisms in cloud infrastructure and networks fail to proactively assess the risk of malicious actors by lacking the ability to predict potential paths and sequences of actions leading to critical assets, often relying on post-incident analysis rather than proactive risk evaluation.
Innovation Solution
A method and system that identifies critical assets and calculates potential paths from the perimeter to these assets, assigning risk scores based on the likelihood of an attacker reaching these assets, using a combination of rule-based scoring and generative AI with large language models to simulate attacker progression and predict risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional threat detection mechanisms focus on evaluating risk based on actions already performed by malicious actors, then the system can detect incidents that have occurred, but it fails to proactively assess the real risk associated with where the threat actor may be getting from where the actor is currently located
Solution Approach 1:
The system performs preliminary action by calculating potential attack paths from the attacker's current location to critical assets before the attack actually occurs. This proactive path analysis enables the system to assess real risk and prioritize security responses in advance, rather than waiting for incidents to unfold.
Solution Approach 2:
The system inverts the conventional approach by working backwards from critical assets to the attacker's current position. Instead of following the attacker's progression forward (left to right), the system calculates paths from right to left, identifying which assets the attacker could potentially reach and prioritizing those paths by risk.
2Measurement precision
If the system calculates all possible paths from perimeter to critical assets, then it can identify high-risk flows of actions, but the complexity of analyzing all asset pairs and paths increases significantly
Solution Approach 1:
The system segments the complex analysis by focusing on critical assets (crown jewels) and calculating paths specifically to those assets rather than analyzing all possible asset pairs. This segmentation reduces complexity while maintaining detection precision by concentrating resources on the most valuable targets.
Solution Approach 2:
The system applies local quality by assigning different risk scores to different paths based on their specific characteristics and the criticality of the assets involved. Rather than uniform analysis, each path receives tailored risk assessment based on local conditions such as asset importance and path vulnerability.
Data Source
AI summary
Computerized methods and systems evaluate threats in a cloud environment having a plurality of assets. For each pair of one or more pairs of the assets, one or more identified paths from a first asset of the pair to a second asset of the pair is obtained. A sequence of assets that includes the first and second assets defines each path of the one or more identified paths. For each path of the one or more identified paths, a likelihood that an attacker that is at the first asset will successfully reach the second asset via the path is determined. In certain embodiments, for each pair of the one or more pairs a risk score for the pair is determined based on the determined likelihoods for the one or more identified paths. The risk score is indicative of risk the attacker will reach the second asset from the first asset.


