User-System Risk-Profiled Attack Graphs for Proactive Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer security systems fail to effectively identify and mitigate targeted attacks based on user and system risk profiles, allowing attackers to exploit vulnerabilities and execute successful cyberattacks.

Innovation Solution

A method and system for generating an attack path by determining user attributes, system exploitability, and criticality information to create a risk profile, which identifies potential attack routes and vulnerabilities, enabling proactive security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attackers exploit vulnerability information and user attributes to execute targeted attacks, then attack success rate increases, but security defense capability deteriorates

Engineering Contradiction:
Improvesecurity defense capabilityVSAvoidattack success rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by proactively generating attack paths and identifying vulnerabilities before actual attacks occur. It creates risk profiles and security assessments in advance, enabling organizations to understand potential attack routes and strengthen defenses before being targeted, thus reversing the traditional reactive security model.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by simulating attacker perspectives and generating countermeasures before attacks happen. It identifies vulnerable assets and potential attack paths, then implements security controls and mitigation strategies in advance to prevent successful exploitation, effectively countering potential threats before they materialize.

Inventive Principle:
Principle #9Preliminary anti-action

2Measurement precision

If comprehensive user and system information is collected to improve security profiling, then risk profile accuracy improves, but information privacy and exposure increase

Engineering Contradiction:
Improverisk profile accuracyVSAvoidinformation privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system applies local quality by collecting and processing information at the specific level of individual users and systems rather than broadly across the entire organization. It creates granular risk profiles for specific assets based on their unique characteristics, allowing precise security assessments while minimizing unnecessary data collection on unrelated entities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses an intermediary approach by introducing a security assessment platform that mediates between raw data collection and security decision-making. This intermediary layer processes information securely, generates risk profiles without exposing sensitive raw data, and provides security recommendations, thus protecting information privacy while maintaining profiling accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12413615B2Attack path and graph creation based on user and system profiling
Publication Date: 2025.09.09 QUALYS
  • US12413615B2 patent drawing
  • US12413615B2 patent drawing
  • US12413615B2 patent drawing

AI summary

Methods and systems for generating an attack path based on user and system risk profiles are presented. A method comprises determining user information associated with a computing device; determining system exploitability information of the computing device; determining system criticality information of the computing device; determining a risk profile for the computing device based on the user information, the system exploitability information, and the system criticality information; and generating an attack path based on the risk profile. The attack path indicates a route through which an attacker accesses the computing device. The system exploitability information is associated with or based on one or more of the vulnerability associated with the computing device, an exposure window associated with the computing device, and a protection window associated with the computing device. The system criticality information is associated with or based on one or more assets and services associated with the computing device.