Network Vulnerability Propagation Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-attack modeling and simulation solutions primarily focus on endpoint devices and security, failing to address how compromised systems affect the broader network and often require active testing that can destabilize mission-critical systems, while also assuming certain devices are trustworthy, thus missing potential attack vectors.

Innovation Solution

A method and system that analyze network infrastructure data to generate architecture and vulnerability expansion models, simulating vulnerability propagation without active testing, and determining criticality ratings for vulnerabilities to identify and address potential attack vectors across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If active testing and attacks are performed on network devices to identify vulnerabilities, then vulnerability detection capability is improved, but system stability and reliability deteriorate due to potential destabilization of mission-critical systems

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidsystem stability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent performs vulnerability identification and architecture modeling in advance through data analysis rather than active testing. The system collects infrastructure data, identifies vulnerabilities, and generates architecture models beforehand, allowing vulnerability assessment without actually executing attacks that could destabilize systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates architecture models that replicate the network structure and vulnerability relationships. Instead of directly testing real systems, the system builds virtual representations (copies) of the network architecture and analyzes vulnerability propagation paths in these models, avoiding direct interference with actual systems.

Inventive Principle:
Principle #26Copying

2Device complexity

If trust is assumed for certain devices in the network, then device complexity and security management is simplified, but security coverage deteriorates by missing potential attack vectors

Engineering Contradiction:
Improvesecurity management complexityVSAvoidattack vector coverage
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the network into discrete components (devices, vulnerabilities, attack vectors) and models their relationships. By breaking down the network architecture into individual elements and their interconnections, the system can systematically analyze vulnerability propagation without assuming trust, while maintaining manageable complexity through structured modeling.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a modeling dimension by creating architecture models that represent network structure and vulnerability relationships. This dimensional transformation allows comprehensive analysis of all devices and potential attack vectors without directly increasing operational complexity, as the model provides a systematic view of the entire network.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Difficulty of detecting and measuring

If comprehensive vulnerability analysis across the entire network is performed, then security coverage is improved, but analysis time and computational resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The patent performs data collection, vulnerability identification, and architecture modeling as preliminary steps before vulnerability expansion analysis. By preparing the architecture model in advance with all vulnerabilities and relationships identified, the system reduces the time required for comprehensive analysis, as the foundational work is already completed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses dynamic modeling to represent vulnerability propagation paths. The architecture model and vulnerability expansion model can dynamically trace attack paths through the network, allowing comprehensive analysis to be performed efficiently by following predefined relationship paths rather than exhaustively analyzing all possible combinations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11283828B2Cyber-attack vulnerability and propagation model
Publication Date: 2022.03.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11283828B2 patent drawing
  • US11283828B2 patent drawing
  • US11283828B2 patent drawing

AI summary

A method, computer program product and computer system to analyze network vulnerability expansion is provided. A processor receives network infrastructure data regarding a network. A processor identifies a plurality of vulnerabilities associated with one or more components of the network. A processor generates a architecture model based, at least in part, on the network infrastructure data and the plurality of vulnerabilities. A processor generates a vulnerability expansion model based, at least in part, on the architecture model. A processor determines a vulnerability expansion based, at least in part, on the vulnerability expansion model and at least one vulnerability of plurality of vulnerabilities being compromised.