Data-Centric Attack Graphs for Sensitive Risk Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current techniques for generating attack graphs are system-centric and do not effectively calculate risk to sensitive data objects, as they rely solely on reachability properties and lack a data-centric approach, failing to adequately assess vulnerabilities and risks in distributed components of regulated services.

Innovation Solution

A data-centric attack graph is generated, where nodes represent components of a regulated service, and risk scores are propagated along edge paths based on vulnerability and risk metrics, including sensitivity, integrity, and criticality ranks, to identify and mitigate potential threats to sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If system-centric attack graph techniques are used, then the attack graph can be generated using reachability properties, but the risk calculation to sensitive data objects is ineffective and inaccurate

Engineering Contradiction:
Improverisk calculation accuracyVSAvoidattack graph approach complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent inverts the traditional system-centric attack graph approach by implementing a data-centric approach. Instead of starting from system components and determining what can be reached, the patent starts from sensitive data objects and traces back through the data flow to identify which components can access and potentially compromise the data. This inversion fundamentally changes the risk calculation methodology to be directly aligned with protecting sensitive data, thereby improving measurement precision without excessive complexity

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent changes the fundamental parameters of attack graph generation by introducing data flow information as a core parameter alongside traditional reachability properties. The attack graph now incorporates data flow edges that track how sensitive data moves through the system, enabling accurate risk calculation by considering both the accessibility of components and their actual data access paths. This parameter change transforms the attack graph from a generic system model to a data-specific risk assessment tool

Inventive Principle:
Principle #35Parameter changes

2Reliability

If traditional reachability-based attack graphs are used, then the graph structure is simple to generate, but the vulnerability and risk assessment of distributed components is inadequate

Engineering Contradiction:
Improvevulnerability assessment reliabilityVSAvoidattack graph structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested structure where the attack graph contains multiple layers of information: the base layer includes traditional reachability relationships between components, while nested within this are data flow relationships that show how sensitive data moves through components. This nested approach allows the graph to maintain a manageable overall structure while embedding detailed vulnerability and risk information within the data flow paths, thereby improving assessment reliability without making the graph structure overly complex

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The attack graph is constructed as a composite structure combining two distinct types of relationships: reachability edges (showing what components can access) and data flow edges (showing how sensitive data moves). This composite graph structure integrates multiple dimensions of security information into a unified model, enabling comprehensive vulnerability assessment that considers both system architecture and data movement patterns, thereby improving reliability while maintaining structured organization

Inventive Principle:
Principle #40Composite materials

3Measurement precision

If data-centric attack graphs with risk propagation are implemented, then accurate risk calculation to sensitive data is achieved, but the computational complexity and processing requirements increase

Engineering Contradiction:
Improverisk score accuracyVSAvoidcomputational processing power
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent performs preliminary actions by pre-calculating and storing data flow relationships and component vulnerability metrics before the actual risk assessment. The attack graph is constructed in advance with all data flow paths identified and recorded, and component attributes such as sensitivity, integrity, and availability are pre-evaluated. This preliminary preparation reduces the computational burden during actual risk calculation, as the system only needs to propagate scores through pre-mapped paths rather than analyzing all possible attack scenarios from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The risk calculation process is segmented into distinct phases: first, data flow analysis to identify access paths; second, vulnerability assessment of individual components; third, risk score propagation along data flow edges; and fourth, aggregation of risks to sensitive data objects. This segmentation allows each phase to be optimized independently and enables parallel processing of multiple data flows and components, reducing overall computational complexity while maintaining accurate risk scores through systematic breakdown of the calculation process

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10503911B2Automatic generation of data-centric attack graphs
Publication Date: 2019.12.10 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10503911B2 patent drawing
  • US10503911B2 patent drawing
  • US10503911B2 patent drawing

AI summary

Generating an attack graph to protect sensitive data objects from attack is provided. The attack graph that includes nodes representing components in a set of components of a regulated service and edges between nodes representing relationships between related components in the set of components is generated based on vulnerability and risk metrics corresponding to each component. A risk score is calculated for each component represented by a node in the attack graph based on sensitivity rank and criticality rank corresponding to each respective component. Risk scores are aggregated for each component along each edge path connecting a node of a particular component to a node of a related component. In response to determining that an aggregated risk score of a component is greater than or equal to a risk threshold, an action is performed to mitigate a risk to sensitive data corresponding to the component posed by an attack.