Network Blast Radius Estimation Using a Cyber Risk Knowledge Graph

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional risk assessment methods struggle to capture the complex and subtle relationships among computing entities, leading to an incomplete understanding of cybersecurity vulnerabilities and the potential blast radius of network assets, particularly in interconnected organizational networks.

Innovation Solution

A knowledge graph construct that incorporates organizational models, risk models, and security policy directives to form a comprehensive network asset map, utilizing ontology-based inferences to trace the fallout of hypothetical attacks and provide a detailed risk assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional database models are used for risk assessment, then the system is simple to implement, but the ability to capture complex relationships among computing entities is insufficient

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transitions from traditional flat database models to a knowledge graph structure that adds dimensional layers for representing relationships. The knowledge graph introduces new dimensions including entity types, relationship types, and hierarchical levels of connectivity, enabling comprehensive capture of complex relationships among computing entities while maintaining structured query capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If comprehensive network connectivity information is collected, then the blast radius understanding is improved, but the volume of information becomes overwhelming and difficult to capture

Engineering Contradiction:
Improveinformation completenessVSAvoiddata management complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive network information into structured knowledge graph entities and relationships. By dividing the overwhelming volume of connectivity data into discrete, typed entities (computing entities, network assets, organizational units) and their relationships, the system makes the information manageable, queryable, and analyzable while preserving complete blast radius information.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If traditional risk assessment methods are used, then the assessment process is straightforward, but the understanding of interconnectedness with assets of other organizations is inadequate

Engineering Contradiction:
Improveinterconnectedness assessment accuracyVSAvoidassessment complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent creates a universal knowledge graph framework that can represent multiple types of entities (internal and external organizational assets, network infrastructure, applications) and their relationships in a unified structure. This multi-functional model enables comprehensive interconnectedness assessment across organizational boundaries while providing consistent query and analysis mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12549588B2Systems and methods for estimating vulnerability related to network blast radius of a network asset
Publication Date: 2026.02.10 WELLS FARGO BANK NA
  • US12549588B2 patent drawing
  • US12549588B2 patent drawing
  • US12549588B2 patent drawing

AI summary

An example method includes receiving a network graph and selecting a first network node from the set of network nodes. The example method further includes computing a difficulty score based on the difficulty for an attacker to compromise a second network node in an instance in which the attacker compromises the first network node and computing a cumulative difficulty score for the attacker to compromise the second network node based on a set of difficulty scores for the first network node and each other network node from the set of network nodes. The example method further includes adding the second network node to a set of blast radius nodes and determining a total vulnerability score for the first network node based on the set of blast radius nodes.