Penetration Testing Remediation Prioritization via Attack Path Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automated penetration testing systems face challenges in effectively prioritizing remediation recommendations due to complex attack paths and dependencies between them, leading to suboptimal security measures and high costs.

Innovation Solution

A method and system that assign importance scores to sub-goals based on the number of attack paths they are included in, allowing for the selection of high-priority sub-goals to be protected, which are then blocked to disrupt multiple attack paths effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated penetration testing systems provide multiple remediation recommendations, then the comprehensiveness of security coverage is improved, but the complexity of prioritizing and implementing recommendations increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprioritization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments attack paths into sub-goals and identifies critical sub-goals that are common to multiple attack paths. By breaking down the complex set of recommendations into prioritized sub-goals, the system reduces prioritization complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges multiple attack paths by identifying common sub-goals across them. This consolidation allows the system to provide fewer, more impactful recommendations by combining the protective effects against multiple attack vectors, thereby reducing complexity while improving reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If the system blocks all attack paths, then the security effectiveness is improved, but the cost of remediation increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidremediation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of blocking all attack paths, the patent applies partial action by identifying and blocking only the critical sub-goals that are common to multiple attack paths. This selective approach achieves sufficient security effectiveness while significantly reducing the cost of remediation compared to comprehensive blocking.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent converts the harmful complexity of multiple attack paths into a benefit by identifying common sub-goals across paths. These common sub-goals become the target of remediation, allowing the system to achieve high security effectiveness by addressing the overlapping vulnerabilities that affect multiple paths simultaneously.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Manufacturing precision

If the system provides detailed remediation for each attack path, then the precision of security measures is improved, but the time required for implementation increases

Engineering Contradiction:
Improvesecurity measure precisionVSAvoidimplementation time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent segments the detailed remediation process into prioritized sub-goals. By organizing recommendations hierarchically with critical sub-goals first, the system enables precise security measures to be implemented in a time-efficient manner, focusing on the most impactful areas initially.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary analysis to identify common sub-goals across attack paths before providing detailed remediation recommendations. This preliminary segmentation allows the system to present prioritized recommendations that reduce implementation time while maintaining precision in security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10637883B1Systems and methods for determining optimal remediation recommendations in penetration testing
Publication Date: 2020.04.28 XM CYBER LTD
  • US10637883B1 patent drawing
  • US10637883B1 patent drawing
  • US10637883B1 patent drawing

AI summary

Methods and systems for providing a recommendation for improving the security of a networked system against attackers. The recommendation may include a recommendation of a single sub-goal to be protected to achieve optimal improvement in security, or of multiple such sub-goals. If the recommendation includes multiple sub-goals, the sub-goals may be ordered such that the first sub-goal is more important to protect, provides a greater benefit by being protected, or is more cost effective to protect than subsequent sub-goals in the ordered list of sub-goals.