Security Metric Generation Using ML and Directed Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating an overall security metric for distributed systems are challenging due to subjectivity and specificity issues, as they often require defining target system components and entry points, making it difficult to achieve consensus and objective measures across vendors and customers.

Innovation Solution

A Machine Learning (ML) model is trained using analogical models and directed graphs to generate a quantitative security metric for a target system, which is non-specific to any given component or point of attack, by comparing the target system to reference systems with available security metric values, allowing for a flexible and objective representation of system security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If attack graph methods are used to generate security metrics, then the security evaluation can be performed, but the metric becomes specific to particular target components and entry points, limiting its general applicability

Engineering Contradiction:
Improvesecurity metric accuracyVSAvoidmetric general applicability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies universality by creating a security metric framework that works across multiple target components and entry points simultaneously. Instead of generating separate metrics for each specific attack scenario, the system produces a unified security metric that can be applied universally across the distributed system, making the metric both accurate and generally applicable.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the security evaluation into modular components that can be independently calculated and then aggregated. By breaking down the complex attack graph analysis into separable elements (vulnerabilities, attack paths, defense mechanisms), the system can generate comprehensive security metrics without being constrained to specific target-entry point combinations.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If penetration testing is used to obtain objective security measures, then accurate security assessment can be achieved, but the process becomes prohibitively expensive and time-consuming

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-calculating and storing security-related data such as vulnerability information, attack paths, and defense mechanism characteristics. This preparatory work allows the system to generate security metrics quickly without requiring time-consuming penetration testing at the time of assessment, while still maintaining accuracy through pre-gathered objective data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by creating simplified models or representations of the actual system security state based on pre-collected data. Instead of performing full penetration tests, the system uses copied security information from vulnerability databases, attack graphs, and system configurations to generate accurate security metrics at a fraction of the time and cost.

Inventive Principle:
Principle #26Copying

3Measurement precision

If system security data is collected for metric generation, then accurate security evaluation can be performed, but access to live systems is required, increasing complexity and resource requirements

Engineering Contradiction:
Improvesecurity metric accuracyVSAvoidsystem access requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary layer that collects and processes security data without requiring direct access to live systems during metric generation. The system uses intermediate representations such as attack graphs, vulnerability databases, and configuration files as mediators between the actual system state and the security metric calculation, eliminating the need for continuous live system access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250016191A1Generating a Security Metric Using a Machine Learning Model
Publication Date: 2025.01.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250016191A1 patent drawing
  • US20250016191A1 patent drawing
  • US20250016191A1 patent drawing

AI summary

A method (400) for generating a security metric for a target system is disclosed. The security metric provides a quantitative representation of the security of the target system, which representation is non-specific to any given component of the system or point of attack. The method involves generation of an analogical model of the target system (410), and mapping of the analogical model to a directed graph of the target system (430). A distance metric is then calculated (440) between the directed graph of the target system and directed graphs of a plurality of reference systems. The method further comprises inputting a tensor comprising the calculated distance metrics to a trained ML model (450), wherein the ML model has been trained using a training data set that is based on the same plurality of reference systems (450a) and wherein the ML model is operable to process the input tensor and to generate an output comprising a value of the security metric for the target system (450b). Also disclosed is a method (300) for training an ML model to generate a security metric.