US2019373005A1PendingUtilityA1

System and Method for Cyber Security Analysis and Human Behavior Prediction

Assignee: BASSETT GABRIELPriority: Apr 10, 2013Filed: Aug 14, 2019Published: Dec 5, 2019
Est. expiryApr 10, 2033(~6.7 yrs left)· nominal 20-yr term from priority
Inventors:Gabriel Bassett
H04L 63/1441G06F 21/577H04L 63/1416H04L 63/1433
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An improved method for analyzing computer network security has been developed. The method first establishes multiple nodes, where each node represents an actor, an event, a condition, or an attribute related to the network security. Next, an estimate is created for each node that reflects the ease of realizing the event, condition, or attribute of the node. Attack paths are identified that represent a linkage of nodes that reach a condition of compromise of network security. Next, edge probabilities are calculated for the attack paths. The edge probabilities are based on the estimates for each node along the attack path. Next, an attack graph is generated that identifies the easiest conditions of compromise of network security and the attack paths to achieving those conditions. Finally, attacks are detected with physical sensors on the network, that predict the events and conditions. When an attack is detected, security alerts are generated in response to the attacks.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for analyzing information system security, comprising:
 establishing multiple nodes, where each node represents an actor, an event, a condition, or an attribute related to the information system security;   creating an estimate for each node that estimates the ease of realizing the event, condition, or attribute of the node, wherein at least one estimate comprises an attribute of at least one attacker modeled using externally-collected intelligence;   identifying attack paths based on attack vectors that may be used by the threat actor, where the attack paths represent a linkage of nodes that reach a condition of compromise of information system security;   calculating edge probabilities for the attack paths based on the estimates for each node along the attack path, where the node estimates and edge probabilities are determined by calculating a probability of likelihood for the nodes based on Markov Monte Carlo simulations of paths from an attacker to the nodes; and   generating an attack graph that identifies the easiest conditions of compromise of network security and the attack paths to achieving those conditions of compromise based at least on combined estimates of the ease of the attack paths and the application of actor attributes, wherein cyclic attack graphs are accommodated during the generation and use of the attack graph.   
     
     
         2 . The method of  claim 1 , wherein the creating comprises identifying an intervention associated with the event, condition, or attribute. 
     
     
         3 . The method of  claim 1 , wherein events and conditions on the attack graph are connected to observable nodes associated with physical sensors, wherein the physical sensors predict the events and conditions, and further comprising:
 detecting attacks through a correlation of the observable nodes with the physical sensors.   
     
     
         4 . The method of  claim 1 , wherein prioritized security alerts are generated in response to detected attacks. 
     
     
         5 . The method of  claim 1 , wherein benign actors are modeled in addition to threat actors, generating a benign action graph and associated benign paths; and
 wherein the benign paths are compared to an attack graph and associated attack paths to generate alerts by differential analysis of benign versus threat actor scores.   
     
     
         6 . The method of  claim 1 , wherein the attack graph is used to identify which sensors would generate security alerts related to one or more attack paths in which the sensor events associated with one or more attack paths are simulated to train security staff. 
     
     
         7 . The method of  claim 1 , wherein the actors, events, conditions, and attributes are not network security related and, instead, represent predictions of the behavior of the actor. 
     
     
         8 . The method of  claim 1 , wherein the attack graph or subsets thereof are shared among organizations, using a graph exchange format. 
     
     
         9 . The method of  claim 1 , wherein the generated attack graph is used to automate penetration testing by allowing a computer system conducting the testing to progress between events and conditions. 
     
     
         10 . The method of  claim 1 , wherein the attack graph is used to identify an impact to security of a change in the information system. 
     
     
         11 . The method of  claim 1 , wherein the attack graph is used to model potential threats for comparison to the security posture of the information system. 
     
     
         12 . The method of  claim 1 , wherein the attack graph is used to simulate a scenario in which there is a knowledge difference between the threat actor and the organization on what attack paths are available to the threat actor. 
     
     
         13 . The method of  claim 1 , wherein external intelligence is received from an intelligence provider and incorporated into the attack graph. 
     
     
         14 . The method of  claim 1 , wherein processing of sensor information through the attack graph results in a response by way of changing the information system. 
     
     
         15 . The method of  claim 14 , wherein the change is realized using software defined networking. 
     
     
         16 . The method of  claim 1 , wherein the information system is a training environment, modified to create a desired distribution of attack paths. 
     
     
         17 . The method of  claim 1 , wherein at least one interaction between the information system and benign and threat actors is modeled as transactions exchanging goods or services and measured in a unit of economic value. 
     
     
         18 . The method of  claim 17  wherein the at least one interaction between benign and threat actors and the information system modeled as transactions, comprises interactions other than those relevant to the cyber security of the information system. 
     
     
         19 . The method of  claim 1 , wherein the attack graph is used to plan, train or test a strategy involving information security defense.

Join the waitlist — get patent alerts

Track US2019373005A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.