Cyber Threat Analysis System Using Network Model Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber threat analysis tools fail to effectively assess the criticality of vulnerabilities in complex network infrastructures, leading to inefficient remediation efforts and resource misallocation, as they lack the ability to simulate the impact of cyber attacks and prioritize vulnerabilities based on their potential impact on the organization.

Innovation Solution

A cyber threat analysis system that generates a network model, assigns weighting values to network elements, and simulates attack vectors to determine criticality levels, allowing for the identification and prioritization of vulnerabilities with the largest impact on the organization, thereby enabling efficient remediation and cost justification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional cyber threat analysis tools are used to assess vulnerabilities, then the analysis process is simple, but the ability to assess criticality and prioritize vulnerabilities is insufficient

Engineering Contradiction:
Improvecriticality assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the network infrastructure into discrete network elements (nodes and edges) that can be individually modeled and analyzed. This segmentation allows the system to assess criticality of specific vulnerabilities by simulating their impact on individual network elements and propagating effects through the network model, thereby improving measurement precision without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network model as an intermediary representation between the actual network infrastructure and the analysis engine. This model includes nodes representing network elements and edges representing connections, allowing simulation of attack vectors and criticality assessment without directly interacting with the complex live network, thus improving assessment accuracy while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive vulnerability assessment is performed on all network elements, then complete security coverage is achieved, but resource allocation becomes inefficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidremediation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary simulation of attack vectors on the network model to predict potential criticality levels before actual remediation efforts. By pre-assessing which vulnerabilities would have the most severe impact on network operations, the system enables prioritization of remediation resources, achieving both comprehensive security coverage and efficient resource allocation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of vulnerability assessment from binary (vulnerable/not vulnerable) to a continuous criticality scale based on simulated impact. This parameter transformation allows the system to differentiate between high-criticality and low-criticality vulnerabilities, enabling efficient resource allocation while maintaining comprehensive security coverage through prioritized remediation.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If attack impact simulation is performed to determine criticality, then vulnerability prioritization accuracy improves, but analysis time increases

Engineering Contradiction:
Improvevulnerability prioritization accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system creates a simplified network model that copies the essential structure and relationships of the actual network infrastructure. By performing attack simulations on this copied model rather than the live network, the system achieves accurate vulnerability prioritization through criticality assessment while minimizing analysis time and avoiding disruption to production systems.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9241008B2System, method, and software for cyber threat analysis
Publication Date: 2016.01.19 EVERFOX HOLDINGS LLC
  • US9241008B2 patent drawing
  • US9241008B2 patent drawing
  • US9241008B2 patent drawing

AI summary

According to certain embodiments, a cyber threat analysis system generates a network model of a network infrastructure that is used by an organization, assigns a weighting value to each of a plurality of network elements of the network infrastructure according to a relative importance of the each network element to the organization, and generates an attack vector according to a determined vulnerability of the network infrastructure. The attack vector represents one or more illicit actions that may be performed to compromise the network infrastructure. The system may simulate, using a network modeling tool, the attack vector on the network model to determine one or more resulting ramifications of one or more of the plurality of network elements due to the attack vector, and determine a criticality level of the attack vector according to the weighting value of the one or more network elements.