Network Blast Radius Estimation Using a Cyber Risk Knowledge Graph
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional risk assessment methods struggle to capture the complex and subtle relationships among computing entities, leading to an incomplete understanding of cybersecurity vulnerabilities and the potential blast radius of network assets, particularly in interconnected organizational networks.
Innovation Solution
A knowledge graph construct that incorporates organizational models, risk models, and security policy directives to form a comprehensive network asset map, utilizing ontology-based inferences to trace the fallout of hypothetical attacks and provide a detailed risk assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional database models are used for risk assessment, then the system is simple to implement, but the ability to capture complex relationships among computing entities is insufficient
Solution Approach 1:
The patent transitions from traditional flat database models to a knowledge graph structure that adds dimensional layers for representing relationships. The knowledge graph introduces new dimensions including entity types, relationship types, and hierarchical levels of connectivity, enabling comprehensive capture of complex relationships among computing entities while maintaining structured query capabilities.
2Loss of information
If comprehensive network connectivity information is collected, then the blast radius understanding is improved, but the volume of information becomes overwhelming and difficult to capture
Solution Approach 1:
The patent segments the comprehensive network information into structured knowledge graph entities and relationships. By dividing the overwhelming volume of connectivity data into discrete, typed entities (computing entities, network assets, organizational units) and their relationships, the system makes the information manageable, queryable, and analyzable while preserving complete blast radius information.
3Measurement precision
If traditional risk assessment methods are used, then the assessment process is straightforward, but the understanding of interconnectedness with assets of other organizations is inadequate
Solution Approach 1:
The patent creates a universal knowledge graph framework that can represent multiple types of entities (internal and external organizational assets, network infrastructure, applications) and their relationships in a unified structure. This multi-functional model enables comprehensive interconnectedness assessment across organizational boundaries while providing consistent query and analysis mechanisms.
Data Source
AI summary
An example method includes receiving a network graph and selecting a first network node from the set of network nodes. The example method further includes computing a difficulty score based on the difficulty for an attacker to compromise a second network node in an instance in which the attacker compromises the first network node and computing a cumulative difficulty score for the attacker to compromise the second network node based on a set of difficulty scores for the first network node and each other network node from the set of network nodes. The example method further includes adding the second network node to a set of blast radius nodes and determining a total vulnerability score for the first network node based on the set of blast radius nodes.


