Partial Attack Path Analysis for Insider Threat Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current attack path analysis approaches prioritize groups of findings that can be exploited by attackers, but fail to account for partial attack paths where attackers deviate from known strategies, leading to opportunistic and persistent threats that evade defenses.
Innovation Solution
A system and method for analyzing partial attack paths using probabilistic, zero-trust, and defense-in-depth analyses to identify and prioritize partial matches, allowing for a stronger defense by mixing and matching parts of different attack paths, focusing on insider threats, and identifying high-leverage points within applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional attack path analysis is used to prioritize security findings, then security teams can focus on groups of findings that match known attack paths, but attackers can deviate from known paths and use partial matches to evade detection
Solution Approach 1:
The patent applies partial matching by allowing attack path detection to match only portions of known attack paths rather than requiring complete matches. The system identifies partial attack paths where security findings represent some but not necessarily all steps of a known attack sequence, enabling detection of attacker deviations while maintaining connection to known threat patterns
Solution Approach 2:
The system dynamically adjusts attack path matching by allowing flexible combination of findings from multiple known attack paths. Rather than static matching against single predefined paths, the system adapts by combining partial matches from different attack paths to identify new hybrid attack sequences that attackers may construct
2Reliability
If security teams analyze all security tool findings comprehensively, then complete coverage is achieved, but security teams become overloaded and productivity decreases
Solution Approach 1:
The system performs partial analysis by focusing computational resources on identifying and analyzing only the portions of attack paths that are actually present in the security findings, rather than exhaustively analyzing all possible attack paths. This selective partial analysis maintains comprehensive coverage of relevant threats while reducing overall computational burden
Solution Approach 2:
The patent segments the security analysis process into distinct phases: collecting security findings, matching against known attack paths, identifying partial matches, and prioritizing results. This segmentation allows security teams to process findings in manageable chunks rather than overwhelming comprehensive analysis, improving team productivity while maintaining coverage
3Measurement precision
If complete attack paths are required for prioritization, then precise threat assessment is achieved, but opportunities to defend against partial or deviating attack paths are missed
Solution Approach 1:
The system prioritizes partial attack paths by calculating risk scores based on the portion of the attack path that is present, rather than requiring complete path matching. This allows threat assessment to be performed on incomplete attack sequences, providing both precise measurement of the detected partial threat and expanded defense coverage against deviating attacks
Data Source
AI summary
In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.


