Privilege Assurance via Attack Path Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack comprehensive preventative solutions for protecting Active Directory, leaving it vulnerable to attacks despite being a critical target for attackers, as existing methods focus on indirect security approaches and manual, time-consuming processes that fail to effectively manage complex network relationships and permissions.

Innovation Solution

A system and method utilizing local agents to monitor user sessions, log activity, and generate event logs, combined with a directed computational graph module to create a network map and predict potential attack paths, providing real-time risk assessment and alerting mechanisms to enhance privilege assurance in enterprise computer networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If indirect security approaches and manual processes are used to protect Active Directory, then implementation simplicity is maintained, but security effectiveness and comprehensive protection are insufficient

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising local agents, a centralized server, and automated analysis tools that mediate between the existing Active Directory infrastructure and security monitoring requirements. This intermediary layer provides comprehensive security protection without requiring fundamental changes to the underlying directory service architecture, thus improving security effectiveness while maintaining manageable system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by continuously monitoring and analyzing network traffic, user sessions, and directory changes before attacks can succeed. The automated threat detection and response mechanisms are pre-configured to identify and respond to security threats proactively, enhancing security reliability without adding complex manual intervention requirements

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive monitoring and analysis tools are implemented, then security coverage and threat detection capability improve, but resource consumption and system overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial monitoring by focusing security analysis on critical areas such as authentication events, privilege changes, and unusual access patterns rather than attempting to monitor all directory operations equally. This selective approach maintains comprehensive security coverage for high-risk operations while reducing overall resource consumption and system overhead

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If manual security management processes are used, then implementation cost is reduced, but time consumption and response efficiency deteriorate

Engineering Contradiction:
Improveresponse efficiencyVSAvoidtime consumption
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system implements continuous feedback loops where security events are automatically detected, analyzed, and responded to in real-time. The centralized server receives data from multiple local agents, automatically correlates events, generates alerts, and can trigger automated responses, creating a closed-loop feedback system that dramatically improves response efficiency compared to manual security management processes

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The automated analysis and response system performs security management tasks autonomously without requiring continuous manual intervention. The system self-monitors directory changes, self-analyzes threat patterns, and self-responds to detected threats through automated alerting and response mechanisms, thereby improving productivity while reducing the time investment required from security personnel

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250016202A1Privilege assurance of enterprise computer network environments using attack path detection and prediction
Publication Date: 2025.01.09 QOMPLX INC
  • US20250016202A1 patent drawing
  • US20250016202A1 patent drawing
  • US20250016202A1 patent drawing

AI summary

A system and method for the privilege assurance of enterprise computer network environments using attack path detection and prediction. The system uses local session monitors to monitor logon sessions within a network, track session details, and log session and network host details. Cyber-physical graphs are produced and used to identify paths within the network based on the logged information, and to apply risk weighting to the identified paths and determine likely attack paths an attacker may use.