Process-Aware Analytical Attack Graphs for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computer networks, especially industrial control systems and critical infrastructure networks, face challenges in defending against cyber-attacks due to their segregated and layered architectures, which traditional attack path analysis methods fail to adequately address, leading to incomplete solutions for real attack scenarios and difficulties in assessing the impact of cyber-attacks on enterprise operations.

Innovation Solution

The implementation of process-aware analytical attack graphs (AAGs) generated through logical network analysis, which abstract enterprise processes and provide a mapping between the infrastructure and process layers, enabling contextual understanding of attack paths and their financial and technical impacts, facilitating prioritization of remedial actions and enhancing cyber-security resilience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If traditional attack path analysis methods are used on segregated and layered network architectures, then analysis simplicity is maintained, but attack path completeness and accuracy deteriorate

Engineering Contradiction:
Improveanalysis simplicityVSAvoidattack path completeness
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the network analysis into multiple layers (infrastructure layer and process layer) and uses community detection to divide the logical topology into groups representing different processes. This segmentation allows the system to handle complex layered architectures by breaking them down into manageable process-oriented units, thereby maintaining analysis simplicity while improving attack path completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a process layer as an additional dimension beyond the traditional infrastructure layer. By mapping assets and vulnerabilities to process contexts, the system transforms the analysis from a purely network-topology view to a multi-dimensional view that includes business process context, thereby achieving more complete and accurate attack path analysis without overwhelming complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If detailed network topology analysis is performed to improve attack path accuracy, then measurement precision improves, but computational complexity and time consumption increase

Engineering Contradiction:
Improveattack path accuracyVSAvoidanalysis time consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts and separates process context information from the detailed network topology analysis. By using community detection to identify process groups and then mapping vulnerabilities to these process groups, the system extracts the essential business context needed for accurate attack path analysis without performing exhaustive analysis of every network connection, thereby reducing time consumption while maintaining accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial action by focusing analysis on process-relevant assets and vulnerabilities rather than analyzing the entire network topology in detail. The community detection and process mapping approaches allow the system to concentrate computational resources on the most critical process-related attack paths, achieving sufficient accuracy without the time cost of complete network analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If process context is integrated into attack graph analysis, then security assessment accuracy improves, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the infrastructure layer and process layer into a unified process-aware attack graph. By combining network topology data with process context through systematic mapping relationships, the system achieves comprehensive security assessment accuracy. The merging is structured through defined mapping relationships between assets, vulnerabilities, and processes, which manages the complexity through organized integration rather than chaotic combination.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses process groups (identified through community detection) as intermediaries between the infrastructure layer and the attack graph analysis. These process groups serve as mediators that connect network assets to business processes, allowing the system to integrate process context without directly complicating the attack graph structure. The intermediaries provide a structured layer that simplifies the integration of multiple data types.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If comprehensive vulnerability assessment across all assets is performed, then security coverage improves, but resource consumption and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial action by prioritizing vulnerability assessment based on process criticality. Instead of uniformly assessing all assets, the system uses process-aware attack graphs to identify and focus on vulnerabilities that have the most significant impact on critical business processes. This approach achieves comprehensive security coverage for high-priority assets while reducing resource consumption on lower-priority assets, thereby optimizing the balance between coverage and resource usage.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the assessment parameters from uniform network-wide scanning to process-weighted prioritization. By incorporating process context and criticality into the vulnerability assessment parameters, the system dynamically adjusts which assets receive detailed assessment resources. This parameter change allows comprehensive coverage of critical process-related vulnerabilities while reducing resource consumption on non-critical assets.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11876824B2Extracting process aware analytical attack graphs through logical network analysis
Publication Date: 2024.01.16 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11876824B2 patent drawing
  • US11876824B2 patent drawing
  • US11876824B2 patent drawing

AI summary

Methods, systems, and computer-readable storage media for receiving a AAG from computer-readable memory, generating from logical network ontology data, asset inventory data, and asset communication data, a logical topology of the enterprise network as a computer-readable data structure, defining, at least partially by executing community detection over the logical topology, a sub-set of groups within the enterprise network, each group representing a process of a plurality of process, each process being at least partially executed by one or more assets within the enterprise network, processing the AAG based on the sub-set of groups and data from one or more contextual data sources to provide the process aware AAG, the process aware AAG defining a mapping between an infrastructure-layer of the enterprise network and a process-layer of the enterprise network, and executing one or more remedial actions in the enterprise network in response to analytics executed on the process aware AAG.