Dynamic Cyber Attack Vector Prioritization via Network Graph Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for detecting and mitigating cyber attack vectors in networks are inefficient, often overloading security teams with unnecessary workload and failing to account for network context, leading to incorrect prioritization and sub-optimal resource allocation.

Innovation Solution

A system and method that scans and maps networks to generate directed graphs representing permissions and connectivity, dynamically verifies attack vectors, and prioritizes mitigation resources based on the likelihood and feasibility of attacks, using a logic that mimics attacker thought processes to focus security efforts on the most probable threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional methods are used to detect and mitigate cyber attack vectors, then security coverage is provided, but security teams are overloaded with unnecessary workload and resource allocation is sub-optimal

Engineering Contradiction:
Improvesecurity team efficiencyVSAvoidworkload volume
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The patent extracts and eliminates false positive attack vectors through dynamic verification that checks actual network context, permissions, and connectivity before marking something as a threat. This removes unnecessary items from the security team's workload while maintaining true threat detection.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameters of attack vector evaluation from static to dynamic by continuously verifying network context, user permissions, and connectivity states. This allows the system to distinguish between real threats and false positives based on current network conditions rather than fixed rules.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If static attack vector analysis is performed, then initial threat identification is achieved, but network context and dynamic conditions are not accounted for

Engineering Contradiction:
Improveattack vector verification accuracyVSAvoidnetwork context adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic verification that continuously updates attack vector analysis based on changing network conditions, user permissions, and connectivity states. This transforms static threat identification into a dynamic process that adapts to real-time network context.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where dynamic verification results feed back into attack vector rankings and prioritization. This continuous feedback mechanism ensures that network context and current conditions are accounted for in threat assessment.

Inventive Principle:
Principle #23Feedback

3Quantity of substance

If all attack vectors are analyzed without prioritization, then comprehensive coverage is achieved, but resource allocation becomes inefficient

Engineering Contradiction:
Improveattack vector coverageVSAvoidresource allocation efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent segments attack vectors into priority levels based on dynamic verification results and network context. This segmentation allows the system to maintain comprehensive coverage while efficiently allocating resources to high-priority threats first, eliminating the need to treat all vectors equally.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of attack vector evaluation by introducing dynamic rankings based on network context, permissions, and connectivity. This allows comprehensive analysis while creating priority tiers that guide efficient resource allocation to the most critical threats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11563770B2System, device, and method of determining cyber attack vectors and mitigating cyber attacks
Publication Date: 2023.01.24 TENABLE INC
  • US11563770B2 patent drawing
  • US11563770B2 patent drawing
  • US11563770B2 patent drawing

AI summary

System, device, and method of determining cyber-attack vectors and mitigating cyber-attacks. A method includes: scanning and mapping a network, and collecting data about network elements; generating a Permissions Directed-Graph, which indicates permissions that each network element has; generating a Network Connectivity Directed-Graph, which indicates accessible direct-communication routes between network elements; obtaining a list of attack techniques; applying a Static Verification process on the list of attack techniques, to generate an initial version of an Attacks Directed-Graph which maps particular attacks to network elements that are represented in the Permissions Directed-Graph and in the Network Connectivity Directed-Graph; performing a Dynamic Verification process, and constructing an updated list of dynamically-verified Attack Vectors that were verified as available within a particular operational context; generating a ranking for each dynamically-verified Attack Vector; prioritizing the dynamically-verified Attack Vectors, and prioritizing threat mitigation resources; activating threat mitigation resources based on the prioritization outputs.