Network Vulnerability Graph for Risk Pathway Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network security systems face challenges in effectively identifying and prioritizing vulnerabilities in large computer networks, often leading to overwhelming and costly security tasks, as they fail to provide comprehensive risk assessments and can be detrimental to system reliability and performance.

Innovation Solution

A risk management system that generates a network graph based on identified vulnerabilities, determining pathway risks by considering likelihoods and impacts, and selectively identifies action items to reduce risk, focusing on critical pathways rather than all possible vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security systems attempt to identify and address all vulnerabilities in large computer networks, then comprehensive security coverage is achieved, but the complexity and cost of security tasks become overwhelming

Engineering Contradiction:
Improvesecurity coverageVSAvoidsecurity task complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple zones based on asset criticality and vulnerability severity, allowing security teams to focus on high-priority segments first. The system divides vulnerabilities into different risk categories and prioritizes remediation efforts accordingly, reducing the overwhelming complexity of addressing all vulnerabilities simultaneously across the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes the parameter of risk assessment by calculating risk scores based on multiple factors including asset criticality, vulnerability severity, exploitation likelihood, and business impact. This transforms the static problem of addressing all vulnerabilities into a dynamic prioritization process where resources are allocated based on changing risk parameters.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If conventional systems prioritize vulnerabilities based on generic severity scores, then processing is simplified, but the accuracy of risk assessment deteriorates

Engineering Contradiction:
Improveprioritization processingVSAvoidrisk assessment accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent transforms the single-parameter generic severity score approach into a multi-parameter risk assessment model that incorporates asset criticality, vulnerability severity, exploitation likelihood, and business impact. This allows the system to maintain ease of operation through automated scoring while significantly improving measurement precision by considering multiple relevant factors.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system incorporates feedback mechanisms where risk assessments are continuously refined based on actual exploitation attempts, patch deployment status, and changing threat landscapes. This feedback loop improves the accuracy of risk prioritization over time while maintaining the streamlined processing approach.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12015631B2Diagnosing and managing network vulnerabilities
Publication Date: 2024.06.18 ATTACKIQ
  • US12015631B2 patent drawing
  • US12015631B2 patent drawing
  • US12015631B2 patent drawing

AI summary

The present disclosure generally relates to systems, methods, and computer-readable media for identifying instances of vulnerabilities on a computing network and generating a graph representing pathways that an attacking entity may take with respect to accessing one or more sensitive assets. For example, one or more systems disclosed herein collect network information and vulnerability information to generate a graph including nodes and edges representing at least a portion of the computing network associated with different vulnerabilities. The systems described herein may use graph theory to generate or otherwise identify pathways that an attacker is likely to use in accessing the sensitive asset(s). The systems additionally may further evaluate the pathways and associated likelihoods/risks to intelligently select one or more action items associated with a reduction of risk to the networking system.