Distributed System Risk Prioritization via Lateral Movement Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for assessing and remediating security risks in large distributed systems often prioritize vulnerabilities based on the number of machines affected or the severity score, leading to overlooked low-severity vulnerabilities and underappreciated risks that can cause significant damage through lateral movement.

Innovation Solution

A server system that collects system risk information from multiple machines, identifies logically coupled machines through lateral movement, and generates machine risk assessment values based on a combination of machine risk factors and lateral movement values, presenting a sorted list of machines to prioritize remediation efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If vulnerabilities are prioritized based on the number of machines affected or CVSS score, then the assessment process becomes simple and fast, but the accuracy of risk prioritization deteriorates because low-severity vulnerabilities with lateral movement potential are overlooked

Engineering Contradiction:
Improvespeed of security assessmentVSAvoidaccuracy of risk prioritization
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent changes the parameters used for vulnerability prioritization from traditional metrics (CVSS score, number of affected systems) to a new composite metric that includes lateral movement potential and business impact. This parameter transformation enables the system to accurately prioritize vulnerabilities that would otherwise be overlooked, resolving the contradiction between assessment speed and prioritization accuracy.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a composite risk assessment metric that combines multiple factors: CVSS score, number of affected systems, lateral movement potential, and business impact. This composite approach integrates diverse risk dimensions into a unified prioritization framework, allowing the system to maintain processing efficiency while achieving more accurate risk assessment.

Inventive Principle:
Principle #40Composite materials

2Object-affected harmful factors

If only high CVSS score vulnerabilities are addressed first, then the immediate security threat is reduced, but the overall system security deteriorates because vulnerabilities enabling lateral movement are not addressed

Engineering Contradiction:
Improveimmediate security threatVSAvoidoverall system security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent performs preliminary assessment of lateral movement potential and business impact for all vulnerabilities before final prioritization. This preliminary analysis identifies vulnerabilities that may not have high CVSS scores but could enable critical lateral movement, allowing the system to address them proactively and maintain overall security reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary risk assessment layer that mediates between raw vulnerability data and final remediation priorities. This intermediary layer analyzes lateral movement paths and business impact, transforming the vulnerability list into a prioritized remediation plan that balances immediate threats with long-term security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If administrators are presented with an ever expanding list of security alerts, then all security risks are captured, but the ease of operation deteriorates because users cannot efficiently identify critical risks

Engineering Contradiction:
Improvenumber of security alertsVSAvoidability to identify critical risks
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent segments the vulnerability list into prioritized groups based on calculated risk scores that incorporate lateral movement potential and business impact. This segmentation presents administrators with a structured, prioritized list rather than a flat alphabetical or CVSS-sorted list, making it easier to identify and address critical risks efficiently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a feedback mechanism where the system continuously monitors the distributed system for lateral movement attempts and business impact changes, then updates vulnerability priorities accordingly. This dynamic feedback allows the system to maintain ease of operation by automatically adjusting the alert list based on current system conditions and risk realities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12284204B1System and method for prioritizing distributed system risk remediations
Publication Date: 2025.04.22 TANIUM
  • US12284204B1 patent drawing
  • US12284204B1 patent drawing
  • US12284204B1 patent drawing

AI summary

A server system obtains, for machines in a distributed system, system risk information, such as information identifying open sessions between respective users and respective machines, information identifying vulnerabilities in respective machines; and administrative rights information identifying groups of users having administrative rights to respective machines. The server system determines security risk factors, including risk factors related to lateral movement between logically coupled machines, and generates machine risk assessment values for at least a subset of the machines, based on a weighted combination of the risk factors. A user interface that includes a list of machines, sorted in accordance with the machine risk assessment values is presented to a user. The user interface also includes, for respective machines, links for accessing additional information about risk factors associated with the machine, and for accessing one or more remediation tools for remediating one or more security risks associated with the respective machine.