Penetration Testing Vulnerability Metric Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current automated penetration testing systems face challenges in effectively prioritizing attacker steps to block, especially when there are dependencies between different paths of attack, leading to suboptimal security recommendations and high costs in remediation.

Innovation Solution

A method and system that calculate a vulnerability metric for each attacker step, allowing for the selection of the most critical steps to block based on their impact on the overall networked system's vulnerability, even when there are equivalent steps across multiple paths, ensuring cost-effective remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If automated penetration testing systems block all attacker steps across multiple paths, then security coverage is improved, but remediation costs increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidremediation costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies local quality by calculating distinct vulnerability metrics for different attacker steps based on their specific impact on system security. Each attacker step is evaluated individually considering its unique contribution to overall vulnerability, allowing selective remediation of high-impact steps rather than uniform treatment of all steps across multiple attack paths

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters by introducing a vulnerability metric that quantifies the security impact of blocking each attacker step. This metric incorporates factors such as the number of paths affected, the criticality of the attacker step, and the reduction in overall system vulnerability, enabling prioritized remediation based on calculated security benefits rather than exhaustive blocking

Inventive Principle:
Principle #35Parameter changes

2Loss of time

If penetration testing is performed frequently to detect new threats, then detection timeliness is improved, but resource consumption increases

Engineering Contradiction:
Improvedetection timelinessVSAvoidresource consumption
Core Design Contradiction:
Loss of timeVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by focusing penetration testing resources on the most critical attacker steps identified through vulnerability metric calculation. Rather than exhaustively testing all possible attack paths equally, the system identifies and prioritizes a subset of high-impact attacker steps for detailed analysis and remediation, reducing overall resource consumption while maintaining effective threat detection

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent implements feedback through the vulnerability metric calculation system that continuously evaluates attacker steps and provides prioritized recommendations. The system uses results from previous tests to update vulnerability metrics and adjust testing priorities, creating a feedback loop that improves detection efficiency over time without requiring proportional increases in resource consumption

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10382473B1Systems and methods for determining optimal remediation recommendations in penetration testing
Publication Date: 2019.08.13 XM CYBER LTD
  • US10382473B1 patent drawing
  • US10382473B1 patent drawing
  • US10382473B1 patent drawing

AI summary

Methods and systems for providing a recommendation for improving the security of a networked system against attackers. The recommendation may include a recommendation of a single attacker step to be blocked to achieve optimal improvement in security, or of multiple such attacker steps. If the recommendation includes multiple attacker steps, the steps may be ordered such that the first attacker step is more important to block, provides a greater benefit by blocking, or is more cost effective to block than subsequent attacker steps in the ordered list of attacker steps.