Cyber-Attack Probability Evaluation via Phase Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity systems face challenges in determining the probability of a successful cyber-attack on a target network due to the complexity of understanding attacker actions and the inherent difficulty in modeling multi-stage attacks, which leads to computational scalability issues and impractical simulations.
Innovation Solution
A method is introduced to break down cyber-attacks into distinct phases (initial ingress, lateral movement, and action on objective) and use a probabilistic model to calculate the success of these phases, incorporating attacker characteristics and network defenses, with a lateral movement function that considers increasing confidence and detection probabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a comprehensive model of multi-stage cyber-attacks is created to evaluate attack success probability, then the accuracy of security evaluation is improved, but the computational complexity and scalability deteriorate
Solution Approach 1:
The patent segments the cyber-attack process into distinct phases (initial ingress, lateral movement, action on objective) and models each phase separately with its own probability calculations. This segmentation allows the complex multi-stage attack to be evaluated as a series of manageable components, improving computational scalability while maintaining overall evaluation accuracy.
Solution Approach 2:
The patent introduces a lateral movement function as an intermediary component that bridges the initial ingress phase and the action on objective phase. This function handles the potentially unbounded set of lateral movements attackers might undertake, acting as a mediator that simplifies the computational model by abstracting complex intermediate behaviors into a manageable function.
2Reliability
If detailed attacker actions and network configurations are modeled to improve evaluation accuracy, then the reliability of security assessment is improved, but the difficulty of detection and measurement worsens
Solution Approach 1:
The patent transforms the complex qualitative assessment of attack success into quantitative probability parameters. By assigning numerical probabilities to different attack phases and combining them mathematically, the system converts difficult-to-measure security concepts into measurable parameters that can be systematically evaluated and compared.
3Adaptability or versatility
If the complete set of lateral movements is considered in the attack model, then the comprehensiveness of attack evaluation is improved, but the productivity of security analysis deteriorates
Solution Approach 1:
The patent applies partial action by focusing on the essential lateral movement behaviors that significantly impact attack success probability, rather than attempting to model every possible lateral movement. The lateral movement function captures the most critical patterns of attacker behavior, providing sufficient comprehensiveness for security evaluation while maintaining analysis productivity.
Data Source
AI summary
A method performed on a processor to determine a probability of success of a cyber-attack on a target network such that the defenses of the target network may be evaluated is provided. The method includes (1) calculating a probability that the cyber-attack will successfully ingress to the target network; (2) calculating a probability that the cyber-attack will successfully move laterally in the target network by performing an action; (3) calculating a probability that the cyber-attack will successfully perform an action on objective. The calculated probabilities are combined to determine a probability that the cyber-attack will be successful such that the defenses of the target network may be evaluated.


