Cyber Impact Modeling via Network-Business Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for cyber situational awareness and mission assurance lack the ability to effectively connect cyber assets with their role in an organization's mission, failing to provide comprehensive risk assessment and vulnerability implications, thus not adequately addressing the complexities and interconnections of cyber assets in modern cyber infrastructure.

Innovation Solution

A system and method called IMPACT (Impact Modeling and Prediction of Attacks on Cyber Targets) that enhances cyber situational awareness by creating a network model and business model to assess mission risk, utilizing intrusion detection, penetration testing, and attack/protection trees to simulate attacks and evaluate defensive priorities, thereby linking IT infrastructure vulnerabilities with their impact on organizational missions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If current techniques are used for cyber situational awareness, then basic understanding of cyber assets is provided, but the ability to connect cyber assets with their role in organizational mission and provide comprehensive risk assessment is insufficient

Engineering Contradiction:
Improvecomprehensive risk assessment informationVSAvoidsystem complexity for connecting cyber assets to mission
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The system segments the cyber infrastructure analysis into distinct models: network model (topology, assets, vulnerabilities), business model (processes, resources, missions), and correlation model (mapping relationships). This segmentation allows comprehensive risk assessment without overwhelming complexity by breaking down the problem into manageable, interconnected components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The correlation model acts as an intermediary that connects the network model and business model, mapping cyber assets to business processes and missions. This intermediary layer enables comprehensive risk assessment by translating technical vulnerability data into mission impact information without requiring direct complex integration between network and business systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If detailed vulnerability analysis is performed on individual systems, then comprehensive vulnerability detection is achieved, but the ability to assess mission risk and prioritize defensive measures is limited

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoidease of assessing mission risk and prioritizing defenses
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements feedback loops where vulnerability analysis results from the network model are fed into the correlation model, which then provides mission risk assessments back to guide prioritization of defensive measures. This feedback mechanism transforms detailed vulnerability data into actionable mission risk information, making it easier to prioritize defenses based on actual mission impact.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The integrated system performs multiple functions: it detects vulnerabilities at the individual system level, assesses mission risk through correlation analysis, and prioritizes defensive measures based on mission criticality. This multi-functionality allows the same system to provide both detailed vulnerability precision and ease of mission risk assessment without requiring separate tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive modeling of cyber infrastructure and business processes is created, then mission risk assessment capability is improved, but system complexity and resource requirements increase

Engineering Contradiction:
Improvemission risk assessment reliabilityVSAvoidcomplexity of network and business models
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The comprehensive modeling approach is divided into separate network and business models with distinct purposes and data structures. The network model captures technical infrastructure details while the business model captures organizational processes and missions. This segmentation maintains reliability of mission risk assessment by ensuring each model focuses on its domain expertise while reducing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The correlation model serves as an intermediary that manages the complexity of connecting comprehensive network and business models. It establishes and maintains the mapping relationships between cyber assets and business processes, enabling reliable mission risk assessment without requiring direct complex integration between the detailed network and business models, thus managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If attack simulation and defensive priority evaluation are implemented, then decision support for resource allocation is enhanced, but computational requirements and analysis time increase

Engineering Contradiction:
Improvedecision support quality for resource allocationVSAvoidtime for attack simulation and analysis
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing the network model, business model, and correlation model before attack simulation is needed. These models capture the static structure and relationships of the cyber infrastructure and business processes in advance, so that when attack simulation is required, the system can quickly evaluate defensive priorities based on pre-computed vulnerability and correlation data, reducing analysis time while maintaining decision support quality.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10977587B2System and method for providing impact modeling and prediction of attacks on cyber targets
Publication Date: 2021.04.13 NORTHROP GRUMMAN SYSTEMS CORP
  • US10977587B2 patent drawing
  • US10977587B2 patent drawing
  • US10977587B2 patent drawing

AI summary

Embodiments of a system and method are disclosed to provide impact modeling and prediction of attacks on cyber targets (IMPACT). An embodiment of the system and method creates a network model to describe the IT resources of an organization, creates a business model to describe the origination's mission, and creates a correlation model that correlates the network model and the business model to describe how the origination's mission relies on the IT resources. Proper analysis may show which cyber resources are of tactical importance in a cyber attack. Such analysis also reveals which IT resources contribute most to the organization's mission. These results may then be used to formulate IT security strategies and explore their trade-offs, which leads to better incident response.