Real-time Cyber Risk Assessment Using Dynamic Markov Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber risk assessment methods fail to dynamically determine risk in specific regions of a network and project it into the future, lacking the ability to accurately quantify vulnerabilities and exploit likelihoods in real-time due to uncertainties and incomplete measurements.

Innovation Solution

The use of integrated Bayesian, Markov, and state space models to encode quantitative and qualitative knowledge of cyber security vulnerabilities and exploits, creating dynamic representations of vulnerabilities and attack impacts, allowing for real-time risk assessment and defense against potential attacks by determining dependencies and exploit likelihoods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional risk assessment methods are used, then vulnerability identification is performed, but the ability to dynamically determine risk in specific network regions and project it into the future is lost

Engineering Contradiction:
Improverisk assessment accuracyVSAvoiddynamic risk determination capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic risk assessment by continuously updating vulnerability states, exploit likelihoods, and attack impacts in real-time. The system transitions from static vulnerability databases to dynamic models that incorporate live network observations, enabling risk assessment that adapts to changing network conditions and emerging threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that continuously monitor network observations, sensor data, and attack indicators, using this information to update risk assessments. This feedback mechanism enables the system to learn from actual network behavior and improve its risk determination accuracy over time.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive vulnerability scanning is performed, then vulnerability identification improves, but real-time risk quantification is hindered due to uncertainties and incomplete measurements

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidreal-time risk quantification delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-establishing vulnerability databases, attack graphs, and risk models before actual attacks occur. This preparation enables rapid real-time risk quantification when threats emerge, as the system can quickly match observed indicators against pre-built knowledge structures without needing to perform comprehensive scanning during incident response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces intermediary components including risk assessment engines, data fusion modules, and inference systems that mediate between raw sensor data and final risk determinations. These intermediaries process and contextualize observations, enabling real-time risk quantification by filtering and interpreting data through established security knowledge bases.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If integrated Bayesian, Markov, and state space models are used, then dynamic risk representation improves, but system complexity increases

Engineering Contradiction:
Improvedynamic risk representation capabilityVSAvoidmodel integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex risk assessment system into distinct modular components: Bayesian networks for vulnerability modeling, Markov models for attack progression, and state space models for real-time estimation. Each module handles specific aspects of risk assessment independently, making the overall system more manageable while maintaining comprehensive dynamic representation capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The integrated models serve multiple functions simultaneously: they quantify vulnerability likelihoods, predict attack progression, assess real-time risk states, and generate defensive recommendations. This multi-functionality reduces the need for separate specialized systems, managing complexity while enhancing adaptive risk representation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If real-time risk assessment is implemented, then defense capability improves, but computational resources and processing time are consumed

Engineering Contradiction:
Improvereal-time defense capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs partial risk assessment actions focused on the most critical vulnerabilities and attack paths identified through preliminary analysis. By prioritizing assessment resources toward high-impact areas rather than uniformly scanning all possible vulnerabilities, the system achieves real-time defense capability with reduced computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent dynamically adjusts assessment parameters and model complexity based on current network risk states. When risk levels are low, the system uses simplified models with fewer computational operations. When threats are detected, the system transitions to more comprehensive analysis modes, optimizing the balance between real-time response and computational resource usage.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10185832B2Methods and systems for defending cyber attack in real-time
Publication Date: 2019.01.22 UNITED STATES OF AMERICA THE AS REPRESENTED BY THE SEC OF THE ARMY
  • US10185832B2 patent drawing
  • US10185832B2 patent drawing
  • US10185832B2 patent drawing

AI summary

Provided are processes of monitoring or modifying a network of electronically connected assets that dynamically builds relationships and dependencies among detected vulnerabilities in one or more of the assets and sensor measurements so that risk assessment can be achieved more accurately and in real-time. A process includes: identifying a plurality of vulnerabilities on a network of electronically interconnected devices representing one or more critical assets; determining dependencies between each vulnerability in the plurality of vulnerabilities; creating a hidden Markov model representing an attack state of each vulnerability of the plurality of vulnerabilities; determining the exploit likelihood of each of the attack states at a first time; determining the most probable sequences or paths of the attack states; and identifying dynamically the risk of one or more of the critical assets based on the sequences or paths of attack states.