Software Supply Chain Threat Assessment via Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures lack a comprehensive method to identify and mitigate privilege escalation attack pathways, which are exploited by malicious actors to gain unauthorized access through vulnerabilities in software applications and their supply chains.

Innovation Solution

A system and method that perform a comprehensive cybersecurity threat assessment by analyzing software applications, identifying vulnerabilities, constructing a cyber-physical graph of relationships, and evaluating attack pathways to determine privilege escalation risks, using a computing device with a cyber-physical graph engine and scoring engine to identify and score potential attack paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If comprehensive cybersecurity threat assessment is performed across entire software supply chain, then threat identification capability is improved, but system complexity increases

Engineering Contradiction:
Improvethreat identification capabilityVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the software supply chain into distinct components (software applications, libraries, frameworks, dependencies) and represents them as separate nodes in a graph structure. This segmentation allows the complex assessment to be broken down into manageable parts while maintaining comprehensive coverage of the entire supply chain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a cyber-physical graph as an intermediary data structure that mediates between the complex software supply chain components and the threat assessment process. The graph engine and scoring engine act as intermediaries that process vulnerability information and generate threat scores, simplifying the overall assessment complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive vulnerability analysis of all software components is performed, then security coverage is improved, but analysis time increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-collecting and storing vulnerability information for software components in databases before actual threat assessment is needed. The graph engine pre-processes software supply chain relationships and stores them in a structured format, enabling faster real-time threat evaluation without compromising comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20220210202A1Advanced cybersecurity threat mitigation using software supply chain analysis
Publication Date: 2022.06.30 QOMPLX INC
  • US20220210202A1 patent drawing
  • US20220210202A1 patent drawing
  • US20220210202A1 patent drawing

AI summary

A system and method for determining privilege escalation attack pathways by performing a comprehensive cybersecurity threat assessment of software applications based on the totality of vulnerabilities from all levels of the software supply chain to determine attack paths for a privilege escalation attack. The system and method comprising analyzing the code and/or operation of a software application to determine components comprising the software, identifying the source of such components, determining vulnerabilities associated with those components, compiling a list of such components, creating a directed graph of relationships between the components, their sources, and new exploitation pathways, and evaluating the overall threat associated with the software application based its software vulnerabilities.