Software Supply Chain Threat Assessment via Graph Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures lack a comprehensive method to identify and mitigate privilege escalation attack pathways, which are exploited by malicious actors to gain unauthorized access through vulnerabilities in software applications and their supply chains.
Innovation Solution
A system and method that perform a comprehensive cybersecurity threat assessment by analyzing software applications, identifying vulnerabilities, constructing a cyber-physical graph of relationships, and evaluating attack pathways to determine privilege escalation risks, using a computing device with a cyber-physical graph engine and scoring engine to identify and score potential attack paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive cybersecurity threat assessment is performed across entire software supply chain, then threat identification capability is improved, but system complexity increases
Solution Approach 1:
The system segments the software supply chain into distinct components (software applications, libraries, frameworks, dependencies) and represents them as separate nodes in a graph structure. This segmentation allows the complex assessment to be broken down into manageable parts while maintaining comprehensive coverage of the entire supply chain.
Solution Approach 2:
The patent introduces a cyber-physical graph as an intermediary data structure that mediates between the complex software supply chain components and the threat assessment process. The graph engine and scoring engine act as intermediaries that process vulnerability information and generate threat scores, simplifying the overall assessment complexity.
2Reliability
If comprehensive vulnerability analysis of all software components is performed, then security coverage is improved, but analysis time increases
Solution Approach 1:
The system performs preliminary actions by pre-collecting and storing vulnerability information for software components in databases before actual threat assessment is needed. The graph engine pre-processes software supply chain relationships and stores them in a structured format, enabling faster real-time threat evaluation without compromising comprehensive security coverage.
Data Source
AI summary
A system and method for determining privilege escalation attack pathways by performing a comprehensive cybersecurity threat assessment of software applications based on the totality of vulnerabilities from all levels of the software supply chain to determine attack paths for a privilege escalation attack. The system and method comprising analyzing the code and/or operation of a software application to determine components comprising the software, identifying the source of such components, determining vulnerabilities associated with those components, compiling a list of such components, creating a directed graph of relationships between the components, their sources, and new exploitation pathways, and evaluating the overall threat associated with the software application based its software vulnerabilities.


