Cyber Resilience Chaos Stress Testing via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity testing methods are insufficient in mimicking real-world cyberattacks, failing to adequately assess operational resilience and financial impacts, which is critical for ensuring reliable and safe services in the face of increasing cyber threats.

Innovation Solution

A system utilizing machine learning algorithms and chaos engineering to stress test computer networks, identify vulnerabilities, minimize blast radius, and calculate financial impacts, providing reports for remediation to enhance operational cybersecurity resiliency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If minimally invasive testing methods are used, then system stability is maintained, but the ability to realistically assess operational resilience deteriorates

Engineering Contradiction:
Improveoperational resilience assessmentVSAvoidtesting invasiveness
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary identification of vulnerabilities and potential attack vectors before conducting chaos stress tests. Machine learning algorithms analyze system architecture, code patterns, and configuration data to pre-map vulnerable points, enabling targeted attacks that are both realistic and controlled, thus assessing operational resilience without unnecessary system disruption

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer between the chaos stress testing system and the target software system. This intermediary monitors system state in real-time, controls the scope of attacks through blast radius management, and coordinates between attack simulation and system response measurement, enabling realistic testing while maintaining system stability through controlled intervention

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive vulnerability scanning is performed, then security coverage is improved, but testing time and computational resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts testing parameters including scan depth, attack intensity, and target selection based on initial vulnerability assessments and risk priorities. Machine learning models prioritize vulnerabilities by severity and exploitability, allowing the system to focus computational resources on high-impact areas rather than performing exhaustive uniform scanning across all system components

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies different testing strategies to different parts of the system based on their vulnerability profiles and criticality. High-value targets receive more intensive chaos stress testing while lower-priority components undergo lighter assessment. The blast radius control mechanism locally limits attack propagation to specific system zones, enabling comprehensive security coverage without uniformly increasing testing time across the entire system

Inventive Principle:
Principle #3Local quality

3Reliability

If chaos stress testing is conducted without blast radius control, then operational resilience is thoroughly tested, but system stability and service continuity deteriorate

Engineering Contradiction:
Improveoperational resilience measurementVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system implements continuous feedback loops during chaos stress testing where machine learning models monitor system response in real-time and dynamically adjust attack parameters. When signs of system instability or cascading failures are detected, the feedback mechanism automatically reduces attack intensity or isolates affected components, enabling thorough resilience testing while maintaining overall system stability through adaptive control

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent segments the target system into isolated zones with controlled blast radii, where chaos stress tests can be conducted in specific compartments without affecting the entire system. Containment mechanisms and circuit breakers are implemented to prevent local failures from propagating globally, allowing operational resilience to be tested in controlled segments while preserving system-wide stability and service continuity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11336675B2Cyber resilience chaos stress testing
Publication Date: 2022.05.17 BANK OF AMERICA CORP
  • US11336675B2 patent drawing
  • US11336675B2 patent drawing
  • US11336675B2 patent drawing

AI summary

A plurality of communicatively coupled, networked assets may be threatened or attacked by a cybersecurity attack. The operational resiliency of the computer network determines whether the cybersecurity attack leads to a shutdown of one or more assets, or even the entire computer network. Machines and processes are disclosed to improve operational cybersecurity resiliency of software on the computer network. Machine learning is used to identify potential vulnerabilities from a vulnerability database. Chaos stress testing using a machine learning algorithm can be performed on software to exploit the vulnerabilities. A blast radius can be set to minimize any potential negative side effects of the testing. Software can be remediated to account for responses to the testing by reconfiguring to prevent exploitation of the vulnerabilities. A financial impact of the exploited vulnerabilities can be calculated and reports can be generated.