Cyber Risk Mitigation Simulation with Process-Aware Attack Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber security systems struggle to effectively prioritize and mitigate cyber risks in enterprise networks, particularly in complex environments with diverse defense mechanisms, as they fail to consider both observed and non-observed vulnerabilities and evolving attacker capabilities.

Innovation Solution

Implementing a process-aware analytical attack graph (AAG) and a mitigation simulator to generate an augmented AAG that includes both observed and non-observed facts, enabling automated prioritization of remediation actions based on risk assessments and user-defined tolerance profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security monitoring systems are used to detect cyber threats, then security personnel can be alerted to adverse events, but the systems fail to prioritize risks effectively and cannot account for evolving attacker capabilities and non-observed vulnerabilities

Engineering Contradiction:
Improverisk prioritization accuracyVSAvoidsecurity system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by generating analytical attack graphs that model potential attacker paths before actual attacks occur. The simulation environment pre-executes exploit sequences to identify vulnerable assets and prioritize remediation actions in advance, allowing security teams to address risks proactively rather than reactively

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a digital twin or copy of the enterprise network architecture within a simulation environment. This copied representation allows realistic attack simulation without affecting actual production systems, enabling safe testing and analysis of attack vectors while preserving the complexity of the original network topology

Inventive Principle:
Principle #26Copying

2Reliability

If layered architecture with diverse cyber defense mechanisms is deployed to protect critical infrastructure, then direct access to targets becomes more difficult, but the complexity of the network increases and makes comprehensive risk assessment challenging

Engineering Contradiction:
Improvenetwork security reliabilityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex network architecture into discrete assets, attack vectors, and exploitation paths represented in the analytical attack graph. Each layer of the layered architecture is broken down into individual components that can be independently analyzed and simulated, making the overall complex system manageable through systematic decomposition

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analytical attack graph serves as an intermediary representation between the complex layered network architecture and the risk assessment process. It mediates by providing a simplified yet accurate model that captures the essential security relationships without requiring direct analysis of the full network complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If analytical attack graphs are generated to represent potential lateral movements of adversaries, then vulnerable components can be identified, but the graphs do not account for non-observed vulnerabilities and evolving attacker capabilities

Engineering Contradiction:
Improveattack graph adaptabilityVSAvoidautomated exploit simulation
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system dynamically updates the analytical attack graphs by integrating results from automated exploit simulations. As new vulnerabilities are discovered or attacker capabilities evolve, the attack graphs are automatically refreshed to reflect current threat landscapes, ensuring continuous adaptability without manual intervention

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The simulation environment provides feedback loops where exploit execution results feed back into the analytical attack graph generation process. This feedback mechanism allows the system to learn from simulated attacks and continuously improve the accuracy of vulnerability identification and risk prioritization

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12355798B2Automated prioritization of cyber risk mitigation by simulating exploits
Publication Date: 2025.07.08 ACCENTURE GLOBAL SOLUTIONS LTD
  • US12355798B2 patent drawing
  • US12355798B2 patent drawing
  • US12355798B2 patent drawing

AI summary

Implementations include receiving graph data representative of a process-aware analytical attack graph (AAG) representing paths within an enterprise network with respect to observed facts of the enterprise network, the process-aware AAG at least partially defining a digital twin of the enterprise network, receiving data indicating at least one non-observed fact of the enterprise network, generating, from the graph data and the received data, an augmented process-aware AAG representing paths within the enterprise network with respect to the observed facts and the at least one non-observed fact, determining, by a process-aware risk assessment module, a risk assessment based on the augmented process-aware AAG, and providing, by a mitigation simulator module, a mitigation list based on the process-aware AAG and the risk assessment, the mitigation list comprising a prioritized list of observed facts of the process-aware AAG.