Process Risk Calculation Based on Attack Path Hardness
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern computer networks, especially industrial control systems and critical infrastructure networks, face increasing cyber-attacks despite layered security architectures, with traditional attack path analysis techniques failing to consider evolving attacker capabilities and providing incomplete solutions for real-world scenarios.
Innovation Solution
The implementation leverages analytical attack graphs (AAGs) to determine process risk based on the hardness of attack paths, using multi-path and single-path formulas to calculate process risk values, which are then used to adjust security controls within the network, thereby enhancing cybersecurity measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional attack path analysis techniques are used, then analysis simplicity is maintained, but the ability to consider evolving attacker capabilities and provide complete solutions is insufficient
Solution Approach 1:
The patent segments the attack path analysis into multiple distinct paths, each representing a different sequence of exploitation steps. By dividing the overall attack scenario into discrete paths with associated hardness values, the system can evaluate each path independently while considering evolving attacker capabilities, thus resolving the contradiction between adaptability and complexity.
Solution Approach 2:
The patent implements dynamic hardness values for attack paths that can evolve based on changing attacker capabilities and defensive measures. This dynamic approach allows the analysis to adapt to new threats and capabilities over time, improving versatility without requiring complete reanalysis, thereby managing complexity while enhancing adaptability.
2Reliability
If multiple security controls are implemented, then cybersecurity protection is improved, but resource consumption and operational complexity increase
Solution Approach 1:
The patent employs feedback mechanisms where the calculated process risk values from attack path analysis inform the selection and adjustment of security controls. This feedback loop ensures that security controls are implemented based on actual risk assessments rather than arbitrary decisions, improving protection while reducing unnecessary complexity from redundant or misaligned controls.
Solution Approach 2:
The patent changes the parameter of security control selection from static, predetermined choices to dynamic selections based on calculated hardness values and process risk assessments. This allows the system to adapt security control parameters to match actual threat levels and resource constraints, improving reliability while managing complexity through data-driven decision-making.
3Measurement precision
If comprehensive attack path analysis is performed, then vulnerability identification is improved, but calculation time and processing resources increase
Solution Approach 1:
The patent applies partial action by focusing the comprehensive attack path analysis on critical paths and high-value targets within the enterprise network. Rather than analyzing every possible attack scenario equally, the system identifies and prioritizes paths with higher process risk values, maintaining vulnerability identification accuracy for critical assets while reducing overall calculation time and resource consumption.
4Productivity
If process risk values are calculated for all configuration items, then security prioritization is improved, but computational load increases
Solution Approach 1:
The patent applies local quality by calculating process risk values selectively for configuration items and attack paths that are most relevant to specific business processes and critical assets. Rather than uniformly analyzing all configuration items, the system focuses computational resources on local areas of highest risk and importance, improving security prioritization efficiency while reducing overall computational load through targeted analysis.
Data Source
AI summary
Implementations are directed to receiving analytical attack graph (AAG) data representative of one or more AAGs, each AAG representing one or more lateral paths between configuration items within an enterprise network, calculating, for each configuration item in a set of configuration items, a process risk value for each impact in a set of impacts achievable within the configuration item, for a first impact, a first process risk value being calculated based on a multi-path formula in response to determining that multiple paths in the AAG lead to the first impact, and, for a second impact, a second process risk value being calculated based on a single-path formula in response to determining that a single path in the AAG leads to the second impact, and determining that at least one process risk value exceeds a threshold process risk value, and in response, adjusting one or more security controls within the enterprise network.


