Compound Threat Detection Using Topology-Guided Penetration Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems struggle to effectively identify and manage compound threat vectors and their linkages, often missing these threats due to seed space explosion in complex computing environments, and lack automation in penetration and fuzzing tests.

Innovation Solution

The implementation of compound threat detection that includes generating and running penetration and fuzzing tests based on topology graphs and environment policies, identifying threat vectors and linkages, and outputting them in a graph format, thereby automating the process and addressing seed space explosion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If penetration tests and fuzzing tests are manually conducted in complex computing environments, then security analysis can be performed, but the seed space explosion makes it difficult to effectively identify and manage compound threat vectors and their linkages

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidcomputing environment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the complex security testing process into distinct components: topology graph generation, penetration test generation, fuzzing test generation, and threat linkage analysis. Each component handles a specific aspect of the security assessment, making the overall complex task manageable and effective despite the seed space explosion in computing environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by generating topology graphs and penetration tests before executing the actual security assessment. This preliminary structuring of the testing framework enables systematic exploration of threat vectors and their linkages, preventing loss of information in complex environments.

Inventive Principle:
Principle #10Preliminary action

2Extent of automation

If automated penetration testing is implemented, then the testing process can be automated, but existing systems lack automation in penetration and fuzzing tests and fail to identify compound threat vectors

Engineering Contradiction:
Improvetesting automationVSAvoidthreat identification completeness
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the results of penetration tests and fuzzing tests are fed back into the analysis engine to identify threat vectors and their linkages. This feedback loop ensures that automated testing maintains reliability by systematically analyzing test results to detect compound threats that would otherwise be missed.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent combines multiple testing methodologies (penetration testing and fuzzing testing) into a composite automated security assessment system. This composite approach leverages the strengths of each method to reliably identify both individual and compound threat vectors, ensuring complete threat identification through automation.

Inventive Principle:
Principle #40Composite materials

3Reliability

If comprehensive security analysis is performed to identify all threat vectors and linkages, then missed threats can be mitigated, but the process becomes time-consuming and manual

Engineering Contradiction:
Improvethreat detection completenessVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic test generation where penetration tests and fuzzing tests are adaptively created based on the topology graph and environment policies. This dynamic approach enables comprehensive security analysis to be performed efficiently by focusing testing efforts on the most relevant threat vectors and their linkages, rather than exhaustively testing all possible scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes key parameters of the testing process by using topology graphs and environment policies to guide test generation. This parameter-driven approach transforms the comprehensive but time-consuming manual analysis into an automated process that maintains detection completeness while significantly reducing testing duration.

Inventive Principle:
Principle #35Parameter changes

4Ease of operation

If manual security testing is used, then the process can be simple to understand, but it lacks automation and cannot effectively manage compound threat vectors in complex environments

Engineering Contradiction:
Improvetesting simplicityVSAvoidthreat analysis efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements self-service automation where the system automatically generates penetration tests and fuzzing tests based on topology graphs and environment policies without requiring manual intervention. This self-service capability maintains ease of operation while dramatically improving productivity by efficiently managing compound threat vectors in complex computing environments.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12513178B2Compound threat detection for a computing system
Publication Date: 2025.12.30 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12513178B2 patent drawing
  • US12513178B2 patent drawing
  • US12513178B2 patent drawing

AI summary

A topology graph for a computing system can be collected. An environment and application policy posture for at least one regulation relevant to the computing system can be collected. A plurality of penetration tests can be generated, the plurality of penetration tests determined based on the at least one topology graph for the computing system and the environment and application policy posture for the at least one regulation relevant to the computing system. The plurality of penetration tests can be run against the computing system, the plurality of penetration tests determining a plurality of threat vectors and at least one threat linkage between at least two of the plurality of threat vectors. The threat vectors and the at least one threat linkage between the at least two of the plurality of threat vectors can be output.