Reconnaissance Agents Validate Network Node Compromisability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current penetration testing systems face challenges in reliably validating the success of login attempts using user credentials, as they may lock network nodes, and simulated systems assume access without proof, leading to potentially pessimistic conclusions about network node compromisability.

Innovation Solution

A method and system that determine if a network node is compromisable by verifying user credentials access through reconnaissance agents, ensuring the node is reachable from an already-compromised node, without risking lockouts, by using reconnaissance agents to detect login events and extract credentials, and confirming access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If actual attack penetration testing is performed to validate user credentials, then measurement precision of node compromisability is improved, but network node stability deteriorates due to potential lockouts

Engineering Contradiction:
Improvevalidation accuracyVSAvoidnode stability
Core Design Contradiction:
Measurement precisionVSStability of the object's composition

Solution Approach 1:

The patent introduces a simulated attack environment as an intermediary between the actual penetration testing system and the target network nodes. Reconnaissance agents operate in this simulated environment to validate user credentials and test attack paths without directly interacting with production systems, thereby maintaining measurement precision while preventing node lockouts and stability issues

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates copies of network nodes and their security configurations in a simulated attack environment. These copies replicate the structural and functional characteristics of actual nodes, allowing penetration testers to validate credentials and assess compromisability accurately without affecting the stability or security state of the original production nodes

Inventive Principle:
Principle #26Copying

2Stability of the object's composition

If simulated penetration testing is used to avoid lockouts, then network node stability is maintained, but measurement precision deteriorates due to unproven access assumptions

Engineering Contradiction:
Improvenode stabilityVSAvoidvalidation accuracy
Core Design Contradiction:
Stability of the object's compositionVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where reconnaissance agents in the simulated environment continuously monitor and report on credential validity, access paths, and node compromisability. This feedback loop allows the system to maintain stable production nodes while progressively refining validation accuracy through iterative testing and analysis of simulated attack scenarios

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary validation of user credentials and attack paths in the simulated environment before any actual attacks are considered. By pre-testing credentials, validating access rights, and confirming attack feasibility in the simulation, the system ensures measurement precision is established beforehand, eliminating the need for uncertain assumptions during production testing

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive penetration testing is performed to identify all vulnerabilities, then reliability of security assessment is improved, but loss of time increases due to the lengthy testing process

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic penetration testing cycles where reconnaissance agents systematically rotate through different network nodes, credentials, and attack vectors in the simulated environment. This periodic approach allows comprehensive coverage of all vulnerabilities over time while maintaining manageable testing intervals, preventing the need for excessively long continuous testing sessions that would cause significant delays in security assessment

Inventive Principle:
Principle #19Periodic action

4Measurement precision

If manual penetration testing by expert consultants is performed, then measurement precision is improved, but productivity deteriorates due to high costs and limited availability

Engineering Contradiction:
Improvetesting accuracyVSAvoidtesting efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements self-service penetration testing capabilities where the organization's own reconnaissance agents and simulated attack environment perform comprehensive security assessments automatically. The system autonomously validates credentials, identifies vulnerabilities, and generates security reports without requiring external expert consultants, thereby maintaining high measurement precision through automated analysis while dramatically improving productivity by eliminating consultant availability constraints and reducing costs

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11206281B2Validating the use of user credentials in a penetration testing campaign
Publication Date: 2021.12.21 XM CYBER LTD
  • US11206281B2 patent drawing
  • US11206281B2 patent drawing
  • US11206281B2 patent drawing

AI summary

Carrying out a penetration testing campaign in a networked system by a penetration testing system, for determining a way for an attacker to compromise the networked system, comprises determining that the attacker can obtain user credentials of a first user, determining that when using the user credentials the first user has access rights to a first network node of the networked system, determining that a second network node of the networked system is compromisable by the attacker during the penetration testing campaign, determining that the first network node was accessed from the second network node, and based on the foregoing, determining that the first network node is compromisable by the attacker during the penetration testing campaign, and determining the way for the attacker to compromise the networked system which includes a step of compromising the first network node using the user credentials of the first user.