Distributed System Risk Prioritization via Lateral Movement Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for assessing and remediating security risks in large distributed systems often prioritize vulnerabilities based on the number of machines affected or the severity score, leading to overlooked low-severity vulnerabilities and underappreciated risks that can cause significant damage through lateral movement.
Innovation Solution
A server system that collects system risk information from multiple machines, identifies logically coupled machines through lateral movement, and generates machine risk assessment values based on a combination of machine risk factors and lateral movement values, presenting a sorted list of machines to prioritize remediation efforts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If vulnerabilities are prioritized based on the number of machines affected or CVSS score, then the assessment process becomes simple and fast, but the accuracy of risk prioritization deteriorates because low-severity vulnerabilities with lateral movement potential are overlooked
Solution Approach 1:
The patent changes the parameters used for vulnerability prioritization from traditional metrics (CVSS score, number of affected systems) to a new composite metric that includes lateral movement potential and business impact. This parameter transformation enables the system to accurately prioritize vulnerabilities that would otherwise be overlooked, resolving the contradiction between assessment speed and prioritization accuracy.
Solution Approach 2:
The patent creates a composite risk assessment metric that combines multiple factors: CVSS score, number of affected systems, lateral movement potential, and business impact. This composite approach integrates diverse risk dimensions into a unified prioritization framework, allowing the system to maintain processing efficiency while achieving more accurate risk assessment.
2Object-affected harmful factors
If only high CVSS score vulnerabilities are addressed first, then the immediate security threat is reduced, but the overall system security deteriorates because vulnerabilities enabling lateral movement are not addressed
Solution Approach 1:
The patent performs preliminary assessment of lateral movement potential and business impact for all vulnerabilities before final prioritization. This preliminary analysis identifies vulnerabilities that may not have high CVSS scores but could enable critical lateral movement, allowing the system to address them proactively and maintain overall security reliability.
Solution Approach 2:
The patent introduces an intermediary risk assessment layer that mediates between raw vulnerability data and final remediation priorities. This intermediary layer analyzes lateral movement paths and business impact, transforming the vulnerability list into a prioritized remediation plan that balances immediate threats with long-term security reliability.
3Quantity of substance
If administrators are presented with an ever expanding list of security alerts, then all security risks are captured, but the ease of operation deteriorates because users cannot efficiently identify critical risks
Solution Approach 1:
The patent segments the vulnerability list into prioritized groups based on calculated risk scores that incorporate lateral movement potential and business impact. This segmentation presents administrators with a structured, prioritized list rather than a flat alphabetical or CVSS-sorted list, making it easier to identify and address critical risks efficiently.
Solution Approach 2:
The patent implements a feedback mechanism where the system continuously monitors the distributed system for lateral movement attempts and business impact changes, then updates vulnerability priorities accordingly. This dynamic feedback allows the system to maintain ease of operation by automatically adjusting the alert list based on current system conditions and risk realities.
Data Source
AI summary
A server system obtains, for machines in a distributed system, system risk information, such as information identifying open sessions between respective users and respective machines, information identifying vulnerabilities in respective machines; and administrative rights information identifying groups of users having administrative rights to respective machines. The server system determines security risk factors, including risk factors related to lateral movement between logically coupled machines, and generates machine risk assessment values for at least a subset of the machines, based on a weighted combination of the risk factors. A user interface that includes a list of machines, sorted in accordance with the machine risk assessment values is presented to a user. The user interface also includes, for respective machines, links for accessing additional information about risk factors associated with the machine, and for accessing one or more remediation tools for remediating one or more security risks associated with the respective machine.


