Process Risk Calculation Based on Attack Path Hardness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computer networks, especially industrial control systems and critical infrastructure networks, face increasing cyber-attacks despite layered security architectures, with traditional attack path analysis techniques failing to consider evolving attacker capabilities and providing incomplete solutions for real-world scenarios.

Innovation Solution

The implementation leverages analytical attack graphs (AAGs) to determine process risk based on the hardness of attack paths, using multi-path and single-path formulas to calculate process risk values, which are then used to adjust security controls within the network, thereby enhancing cybersecurity measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional attack path analysis techniques are used, then analysis simplicity is maintained, but the ability to consider evolving attacker capabilities and provide complete solutions is insufficient

Engineering Contradiction:
Improveability to consider evolving attacker capabilitiesVSAvoidcomplexity of attack path analysis
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the attack path analysis into multiple distinct paths, each representing a different sequence of exploitation steps. By dividing the overall attack scenario into discrete paths with associated hardness values, the system can evaluate each path independently while considering evolving attacker capabilities, thus resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic hardness values for attack paths that can evolve based on changing attacker capabilities and defensive measures. This dynamic approach allows the analysis to adapt to new threats and capabilities over time, improving versatility without requiring complete reanalysis, thereby managing complexity while enhancing adaptability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If multiple security controls are implemented, then cybersecurity protection is improved, but resource consumption and operational complexity increase

Engineering Contradiction:
Improvecybersecurity protection levelVSAvoidsecurity control management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs feedback mechanisms where the calculated process risk values from attack path analysis inform the selection and adjustment of security controls. This feedback loop ensures that security controls are implemented based on actual risk assessments rather than arbitrary decisions, improving protection while reducing unnecessary complexity from redundant or misaligned controls.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes the parameter of security control selection from static, predetermined choices to dynamic selections based on calculated hardness values and process risk assessments. This allows the system to adapt security control parameters to match actual threat levels and resource constraints, improving reliability while managing complexity through data-driven decision-making.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If comprehensive attack path analysis is performed, then vulnerability identification is improved, but calculation time and processing resources increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidcalculation time for risk assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by focusing the comprehensive attack path analysis on critical paths and high-value targets within the enterprise network. Rather than analyzing every possible attack scenario equally, the system identifies and prioritizes paths with higher process risk values, maintaining vulnerability identification accuracy for critical assets while reducing overall calculation time and resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If process risk values are calculated for all configuration items, then security prioritization is improved, but computational load increases

Engineering Contradiction:
Improvesecurity action prioritization efficiencyVSAvoidcomputational resources consumed
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by calculating process risk values selectively for configuration items and attack paths that are most relevant to specific business processes and critical assets. Rather than uniformly analyzing all configuration items, the system focuses computational resources on local areas of highest risk and importance, improving security prioritization efficiency while reducing overall computational load through targeted analysis.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11831675B2Process risk calculation based on hardness of attack paths
Publication Date: 2023.11.28 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11831675B2 patent drawing
  • US11831675B2 patent drawing
  • US11831675B2 patent drawing

AI summary

Implementations are directed to receiving analytical attack graph (AAG) data representative of one or more AAGs, each AAG representing one or more lateral paths between configuration items within an enterprise network, calculating, for each configuration item in a set of configuration items, a process risk value for each impact in a set of impacts achievable within the configuration item, for a first impact, a first process risk value being calculated based on a multi-path formula in response to determining that multiple paths in the AAG lead to the first impact, and, for a second impact, a second process risk value being calculated based on a single-path formula in response to determining that a single path in the AAG leads to the second impact, and determining that at least one process risk value exceeds a threshold process risk value, and in response, adjusting one or more security controls within the enterprise network.