ML Security Prioritization via Attack Path Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in predicting and mitigating potential attack paths in enterprise and public cloud environments, where vulnerabilities in assets, applications, and services can be exploited by attackers.

Innovation Solution

The use of machine learning methods and algorithms to analyze contextual security information, including asset management and security tool data, to predict potential attack patterns and propose remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If machine learning models are used to predict attack paths, then security prediction accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity prediction accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The security analysis system is divided into multiple specialized machine learning models: attack path prediction models, vulnerability assessment models, and remediation recommendation models. Each model focuses on a specific aspect of security analysis, improving overall prediction accuracy while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary components such as security data normalization layers and feature extraction modules that bridge raw security data and the machine learning models. These intermediaries prepare and structure data appropriately, enabling accurate predictions without requiring the models themselves to be overly complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive security data is analyzed, then prediction accuracy is improved, but data processing time increases

Engineering Contradiction:
Improveprediction accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary data normalization, filtering, and feature extraction before feeding data to the machine learning models. Security data is pre-processed and structured in advance, allowing the models to work with ready-to-use features and reducing inference time when predictions are needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a tiered analysis approach where the system first performs rapid preliminary assessment using key indicators, then applies comprehensive analysis only to high-risk areas identified in the initial scan. This partial action approach maintains accuracy for critical threats while reducing overall processing time.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If machine learning models provide detailed attack path predictions, then security insight quality is improved, but computational resource consumption increases

Engineering Contradiction:
Improvesecurity insight qualityVSAvoidcomputational resource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The machine learning models focus computational resources on predicting and analyzing only the most critical and likely attack paths rather than exhaustively analyzing all possible paths. The system identifies high-probability attack vectors and concentrates computational power on those specific scenarios, maintaining insight quality while reducing overall resource consumption.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12299133B2Systems and methods for prioritizing security findings using machine learning models
Publication Date: 2025.05.13 SECUREX AI INC
  • US12299133B2 patent drawing
  • US12299133B2 patent drawing
  • US12299133B2 patent drawing

AI summary

Systems and methods for prioritizing various security findings to allow a security platform to focus on a proper subset of (e.g., the most important) one or more software application stacks of an enterprise are described. In one embodiment, a method includes generating a profile for an enterprise that indicates one or more software application stacks and a network architecture for the one or more software application stacks, determining one or more vulnerability features of the one or more software application stacks, generating one or more exploitability scores by a first machine learning model based at least in part on the one or more vulnerability features, determining a proper subset of the one or more software application stacks based at least in part on the one or more exploitability scores, determining one or more vulnerabilities of the proper subset of the one or more software application stacks and one or more vulnerabilities of the network architecture, providing the one or more vulnerabilities of the proper subset of the one or more software application stacks, the one or more vulnerabilities of the network architecture, and the profile as input to a second machine learning model, generating an inference by the second machine learning model that indicates one or more attack paths for an attacker in the proper subset of the one or more software application stacks and the network architecture, and transmitting the inference to a storage location or a security software application.