Network Vulnerability Prioritization via Bayesian Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network infrastructure vulnerabilities are difficult to prioritize effectively for mitigation, especially in large systems with limited administrative resources, as existing methods lack efficient ways to determine which vulnerabilities contribute most to the probability of a successful security breach.

Innovation Solution

A network graph representation using Bayesian networks is employed to identify vulnerabilities and their associated probabilities, allowing administrators to focus on mitigating the vulnerabilities that contribute most to the risk of a security breach, with recommendations for controls to address these vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrators attempt to mitigate all vulnerabilities in a large network infrastructure, then security coverage is improved, but administrative resources and time are excessively consumed

Engineering Contradiction:
Improvesecurity coverageVSAvoidadministrative resources
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network infrastructure into multiple assets and represents them as a network graph with nodes and edges. Each asset is evaluated independently for vulnerabilities and security breach probabilities, allowing administrators to divide and conquer the large-scale security assessment task rather than treating the entire network as a single unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the evaluation parameters by calculating a 'contribution amount' metric that quantifies how much each vulnerability contributes to the overall security breach probability. This parameter transformation enables prioritization of vulnerabilities based on their actual impact rather than treating all vulnerabilities equally, thus optimizing administrative resource allocation.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If administrators focus on mitigating only critical vulnerabilities, then administrative efficiency is improved, but security coverage may be compromised

Engineering Contradiction:
Improveadministrative efficiencyVSAvoidsecurity coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent transforms the vulnerability assessment by calculating contribution amounts that reflect each vulnerability's impact on security breach probability. This parameter change allows administrators to objectively identify and prioritize critical vulnerabilities based on quantitative analysis rather than subjective judgment, ensuring that focusing on high-impact vulnerabilities does not compromise overall security coverage.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent provides feedback mechanisms by calculating and presenting security breach probabilities and vulnerability contribution amounts to administrators. This feedback loop enables administrators to make informed decisions about which vulnerabilities to address first, ensuring that efficiency gains do not come at the expense of security coverage.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If detailed vulnerability analysis is performed on all assets, then measurement precision is improved, but device complexity and computational load increase

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network into discrete assets represented as nodes in a network graph, with vulnerabilities and controls as separate elements. This segmentation allows for systematic and precise vulnerability analysis of each asset while maintaining overall system manageability through the structured graph representation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a network graph as an intermediary structure that organizes assets, vulnerabilities, and controls in a manageable framework. This intermediary representation simplifies the complexity of detailed vulnerability analysis across the entire network by providing a structured view that facilitates systematic assessment without overwhelming computational burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10333963B2Identifying a vulnerability of an asset of a network infrastructure to mitigate
Publication Date: 2019.06.25 QUANTUM FORT INC
  • US10333963B2 patent drawing
  • US10333963B2 patent drawing
  • US10333963B2 patent drawing

AI summary

A first vulnerability that is associated with one or more nodes of a network graph that represent one or more assets of a network infrastructure may be identified. Furthermore, a second vulnerability that is associated with one or more nodes of the network graph may be identified. A determination may be made as to whether the first vulnerability or the second vulnerability contributes more to a probability of a security breach associated with the network infrastructure. A notification may be provided to mitigate the vulnerability that contributes more to the probability of the security breach associated with the network infrastructure.