Risk-Based Vulnerability Management Using Bayesian Attack-Path Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating attack graphs face challenges such as difficulty in capturing input information, lack of scalability, and lack of usability by non-technical personnel, making it hard to prioritize remediation efforts effectively.

Innovation Solution

An improved approach using natural language processing (NLP) to identify pre- and post-conditions, combined with graph database technology to store attack graphs, and Bayesian networks for risk evaluation, enabling the generation and analysis of attack paths across enterprise networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional attack graph generation methods are used, then comprehensive vulnerability analysis is achieved, but scalability and usability deteriorate

Engineering Contradiction:
Improvevulnerability analysis accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces Bayesian Networks as an intermediary layer between the attack graph data structure and the user interface. This intermediary computes risk scores automatically using probability theory, mediating the complex vulnerability data and presenting simplified risk assessments to users, thereby maintaining analysis accuracy while reducing operational complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the attack graph from a static structural representation to a dynamic risk assessment model by introducing probability parameters. Vulnerabilities are evaluated not just by their existence but by computed risk scores that incorporate likelihood and impact parameters, enabling scalable prioritization without sacrificing analysis depth

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detailed attack graph data is collected, then risk assessment accuracy is improved, but information capture difficulty increases

Engineering Contradiction:
Improverisk assessment precisionVSAvoiddata collection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a unified Bayesian Network model that serves multiple functions simultaneously: it collects vulnerability data, computes risk scores, prioritizes remediation efforts, and generates reports. This multi-functional approach consolidates data collection and analysis into a single framework, improving precision while reducing the difficulty of managing diverse data requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Manufacturing precision

If comprehensive vulnerability data is analyzed, then remediation prioritization accuracy is improved, but processing time increases

Engineering Contradiction:
Improveremediation prioritization accuracyVSAvoidanalysis time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary risk score computations by pre-calculating probability distributions for vulnerabilities based on their inherent characteristics and contextual factors. This preliminary action prepares prioritization data in advance, enabling rapid remediation decisions without sacrificing accuracy, as the heavy computational lifting occurs before actual prioritization is needed

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12388859B2Risk-based vulnerability management
Publication Date: 2025.08.12 MCKESSON CORPORATION
  • US12388859B2 patent drawing
  • US12388859B2 patent drawing
  • US12388859B2 patent drawing

AI summary

Various systems and methods for providing risk-based vulnerability management are described herein. A system is configured to access an attack graph, the attack graph including exploits represented as preconditions and postconditions; access vulnerability information of a plurality of nodes in the network, the vulnerability information including conditions of the plurality of nodes in the network; access a network connectivity graph that represents a logical network topology of the plurality of nodes in the network; identify a set of attack paths in the attack graph by comparing the conditions of the plurality of nodes in the network with preconditions and postconditions in the attack graph; calculate a risk score for each of the set of attack paths in the attack graph; and present the risk score for each of the set of attack paths.