Penetration Testing Node Classification for Privilege Escalation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current penetration testing systems, especially simulation-based ones, struggle to accurately assess the compromisability of network nodes, often assuming privilege escalation is always possible, leading to inaccurate conclusions about network system vulnerabilities.

Innovation Solution

A simulated penetration testing method that assigns network nodes to classes based on current compromisability, including red (fully controllable), blue (not compromisable), and purple (partially compromisable but not fully controllable) classes, allowing for precise determination of vulnerabilities and reporting on how an attacker can compromise the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If simulation-based penetration testing is used to assess network nodes, then the testing process is automated and efficient, but the accuracy of vulnerability assessment deteriorates due to incorrect assumptions about privilege escalation

Engineering Contradiction:
Improvetesting efficiencyVSAvoidvulnerability assessment accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent segments the assessment of network node compromisability into distinct components: initial vulnerability exploitation and privilege escalation possibilities. By separating these assessments, the system can accurately determine whether a node is truly compromisable (red) versus merely having initial access points (purple), resolving the inaccuracy caused by blanket assumptions about privilege escalation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of node classification from a simple binary state to a multi-state system (red, purple, blue) that reflects different levels of compromisability. This parameter change allows the system to distinguish between nodes where privilege escalation is possible versus those where it is not, thereby improving measurement precision while maintaining automated efficiency.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If automated penetration testing is implemented, then human errors in testing are reduced, but the ability to accurately assess complex privilege escalation scenarios deteriorates

Engineering Contradiction:
Improvetesting consistencyVSAvoidprivilege escalation assessment accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously updates its assessment of node compromisability based on test results. When initial exploitation succeeds, the system feeds back to reassess whether full compromise is possible, rather than relying on static assumptions. This feedback loop enables automated systems to handle complex privilege escalation scenarios accurately.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces dynamic re-assessment of node classification throughout the testing process. Rather than assigning fixed classifications, the system dynamically updates node status (blue/purple/red) based on discovered vulnerabilities and escalation paths, allowing automated testing to adapt to complex scenarios while maintaining consistency.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If privilege escalation is assumed to always be possible, then the testing process is simplified, but the accuracy of security vulnerability reporting deteriorates

Engineering Contradiction:
Improvetesting process complexityVSAvoidvulnerability reporting accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the vulnerability assessment into two distinct questions: (1) Can the node be initially compromised? and (2) Can full control be achieved after initial compromise? This segmentation eliminates the need to assume privilege escalation is always possible, providing accurate reporting while keeping the testing process structured and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses simulation to copy and model the attacker's progression through the system, assessing privilege escalation possibilities in the simulated environment rather than making assumptions. This copying approach provides accurate vulnerability reporting without requiring complex real-world testing for each scenario.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10462177B1Taking privilege escalation into account in penetration testing campaigns
Publication Date: 2019.10.29 XM CYBER LTD
  • US10462177B1 patent drawing
  • US10462177B1 patent drawing
  • US10462177B1 patent drawing

AI summary

A simulated penetration testing system that assigns network nodes of the tested networked system to classes based on current information about the compromisability of the nodes at a current state of a penetration testing campaign, the classes consisting of (i) a red class for nodes known to be compromisable by the attacker in a way that gives the attacker full control of the nodes, (ii) a blue class for nodes that are not known to be compromisable by the attacker, and (iii) a purple class for nodes known to be compromisable by the attacker in a way that does not give the attacker full control of the purple-class-member network node. The campaign tests whether an attacker would be able to achieve full control of a target node by using privilege escalation techniques and one or more access rights achieved by compromising the target node.