User-System Risk-Profiled Attack Graphs for Proactive Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer security systems fail to effectively identify and mitigate targeted attacks based on user and system risk profiles, allowing attackers to exploit vulnerabilities and execute successful cyberattacks.
Innovation Solution
A method and system for generating an attack path by determining user attributes, system exploitability, and criticality information to create a risk profile, which identifies potential attack routes and vulnerabilities, enabling proactive security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If attackers exploit vulnerability information and user attributes to execute targeted attacks, then attack success rate increases, but security defense capability deteriorates
Solution Approach 1:
The system performs preliminary actions by proactively generating attack paths and identifying vulnerabilities before actual attacks occur. It creates risk profiles and security assessments in advance, enabling organizations to understand potential attack routes and strengthen defenses before being targeted, thus reversing the traditional reactive security model.
Solution Approach 2:
The system applies preliminary anti-action by simulating attacker perspectives and generating countermeasures before attacks happen. It identifies vulnerable assets and potential attack paths, then implements security controls and mitigation strategies in advance to prevent successful exploitation, effectively countering potential threats before they materialize.
2Measurement precision
If comprehensive user and system information is collected to improve security profiling, then risk profile accuracy improves, but information privacy and exposure increase
Solution Approach 1:
The system applies local quality by collecting and processing information at the specific level of individual users and systems rather than broadly across the entire organization. It creates granular risk profiles for specific assets based on their unique characteristics, allowing precise security assessments while minimizing unnecessary data collection on unrelated entities.
Solution Approach 2:
The system uses an intermediary approach by introducing a security assessment platform that mediates between raw data collection and security decision-making. This intermediary layer processes information securely, generates risk profiles without exposing sensitive raw data, and provides security recommendations, thus protecting information privacy while maintaining profiling accuracy.
Data Source
AI summary
Methods and systems for generating an attack path based on user and system risk profiles are presented. A method comprises determining user information associated with a computing device; determining system exploitability information of the computing device; determining system criticality information of the computing device; determining a risk profile for the computing device based on the user information, the system exploitability information, and the system criticality information; and generating an attack path based on the risk profile. The attack path indicates a route through which an attacker accesses the computing device. The system exploitability information is associated with or based on one or more of the vulnerability associated with the computing device, an exposure window associated with the computing device, and a protection window associated with the computing device. The system criticality information is associated with or based on one or more assets and services associated with the computing device.


