Network Vulnerability Propagation Modeling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-attack modeling and simulation solutions primarily focus on endpoint devices and security, failing to address how compromised systems affect the broader network and often require active testing that can destabilize mission-critical systems, while also assuming certain devices are trustworthy, thus missing potential attack vectors.
Innovation Solution
A method and system that analyze network infrastructure data to generate architecture and vulnerability expansion models, simulating vulnerability propagation without active testing, and determining criticality ratings for vulnerabilities to identify and address potential attack vectors across the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If active testing and attacks are performed on network devices to identify vulnerabilities, then vulnerability detection capability is improved, but system stability and reliability deteriorate due to potential destabilization of mission-critical systems
Solution Approach 1:
The patent performs vulnerability identification and architecture modeling in advance through data analysis rather than active testing. The system collects infrastructure data, identifies vulnerabilities, and generates architecture models beforehand, allowing vulnerability assessment without actually executing attacks that could destabilize systems.
Solution Approach 2:
The patent creates architecture models that replicate the network structure and vulnerability relationships. Instead of directly testing real systems, the system builds virtual representations (copies) of the network architecture and analyzes vulnerability propagation paths in these models, avoiding direct interference with actual systems.
2Device complexity
If trust is assumed for certain devices in the network, then device complexity and security management is simplified, but security coverage deteriorates by missing potential attack vectors
Solution Approach 1:
The patent segments the network into discrete components (devices, vulnerabilities, attack vectors) and models their relationships. By breaking down the network architecture into individual elements and their interconnections, the system can systematically analyze vulnerability propagation without assuming trust, while maintaining manageable complexity through structured modeling.
Solution Approach 2:
The patent adds a modeling dimension by creating architecture models that represent network structure and vulnerability relationships. This dimensional transformation allows comprehensive analysis of all devices and potential attack vectors without directly increasing operational complexity, as the model provides a systematic view of the entire network.
3Difficulty of detecting and measuring
If comprehensive vulnerability analysis across the entire network is performed, then security coverage is improved, but analysis time and computational resources increase
Solution Approach 1:
The patent performs data collection, vulnerability identification, and architecture modeling as preliminary steps before vulnerability expansion analysis. By preparing the architecture model in advance with all vulnerabilities and relationships identified, the system reduces the time required for comprehensive analysis, as the foundational work is already completed.
Solution Approach 2:
The patent uses dynamic modeling to represent vulnerability propagation paths. The architecture model and vulnerability expansion model can dynamically trace attack paths through the network, allowing comprehensive analysis to be performed efficiently by following predefined relationship paths rather than exhaustively analyzing all possible combinations.
Data Source
AI summary
A method, computer program product and computer system to analyze network vulnerability expansion is provided. A processor receives network infrastructure data regarding a network. A processor identifies a plurality of vulnerabilities associated with one or more components of the network. A processor generates a architecture model based, at least in part, on the network infrastructure data and the plurality of vulnerabilities. A processor generates a vulnerability expansion model based, at least in part, on the architecture model. A processor determines a vulnerability expansion based, at least in part, on the vulnerability expansion model and at least one vulnerability of plurality of vulnerabilities being compromised.


