IP Library Granted Patent US 8,413,237
Granted Patent B2
US 8,413,237 · App. 11/584,598 · Granted Apr 2, 2013

Methods of simulating vulnerability

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,413,237
App. No.
11/584,598
Granted
Apr 2, 2013
Kind
B2
Abstract

Methods of simulating vulnerability are provided. In an example, multi-stage vulnerability across multiple systems may be simulated by first simulating a probing of at least one intermediate entity, the at least one intermediate entity connected to a target system, second simulating a probing of the target system if the first simulated probing is successful and generating an attack graph based on the results of the first and second simulating steps. In another example, multi-system vulnerability may be simulated by receiving a plurality of attributes associated with vulnerabilities of a plurality of systems within a network, the plurality of systems including at least one target system and generating an attack graph including one or more attack chains based at least in part on the received plurality of attributes. In another example, system (e.g., single-system) vulnerability may be simulated by first simulating whether vulnerabilities exploited from a first system state cause a transition to a second system state, the second system state having a higher-privilege level than the first system state within a target system and generating an attack graph based at least in part on the results of the simulation.

Claims (34)

1. A method of simulating multi-stage vulnerability across multiple systems, comprising:

selecting, by a computer processor, models associated with a target system and at least one intermediate entity, the at least one intermediate entity and the target system being associated with different network zones;

retrieving, by the computer processor, a list of vulnerability attributes based on the selected models from a public vulnerability attributes database;

determining, by the computer processor, if at least one vulnerability attribute associated with the list of vulnerability attributes is present on the at least one intermediate entity connected to the target system;

in response to the determining that the at least one vulnerability attribute is present on the at least one intermediate entity, first simulating, by the computer processor, a probing of the at least one intermediate entity;

second simulating, by the computer processor, a probing of the target system based on the list of vulnerability attributes if the first simulated probing is successful; and

generating, by the computer processor, an attack graph based on the results of the first and second simulating steps.

2. The method of claim 1 , wherein the first and second simulating steps are performed in accordance with selected modeling criteria.

3. The method of claim 2 , wherein the selected modeling criteria include a network, at least one network zone within the network, an attacker in communication with the network, the target system connected to the network, at least one intermediary host within each network zone and a list of vulnerability attributes.

4. The method of claim 3 , wherein the list of vulnerability attributes is associated with one or more of the network and the at least one intermediate host.

5. The method of claim 1 , wherein the attack graph is generated by combining a plurality of attack chains.

6. The method of claim 5 , wherein each successful set of first and second simulated probing steps forms one of the plurality of attack chains.

7. The method of claim 5 , wherein each of the plurality of attack chains includes a plurality of exploits which lead an attacker from a no privilege position at the target system to a root privilege position at the target system.

8. The method of claim 1 , further comprising:

repeating the first simulating step for each of a plurality of intermediate entities connected to the target system if (i) more than one network zone separates the target system from an attacker or if (ii) the plurality of intermediate entities reside within a single network zone separating the target system from the attacker,

wherein the second simulating step is only performed if at least one attack chain exists from the attacker to one or more of the plurality of intermediate entities connected to the target system.

9. A method of simulating multi-system vulnerability, comprising:

selecting, by a computer processor, models associated with a plurality of systems within a network;

receiving, by the computer processor, a plurality of attributes associated with vulnerabilities of the plurality of systems within the network based on the selected models the plurality of attributes received from a public vulnerability attributes database, the plurality of systems including at least one target system being one of the plurality of systems within the network and at least one other system being one of the plurality of systems within the network system, the at least one target system and the at least one other system being associated with different network zones;

determining, by the computer processor, if at least one attribute associated with the plurality of attributes is present on the at least one other system; and

in response to the determining that the at least one attribute is present on the at least one other system, generating, by the computer processor, an attack graph including one or more attack chains.

10. The method of claim 9 , wherein each of the attack chains includes a plurality of exploits which, when performed successively, allow an attacker to compromise the target system.

11. A method of simulating system vulnerability, comprising:

selecting, by a computer processor, models associated with a plurality of systems within a network, the plurality of systems including a target system being one of the plurality of systems within the network and at least one other system being one of the plurality of systems within the network system, the target system and the at least one other system being associated with different network zones;

retrieving, by the computer processor, a list of vulnerability attributes based on the selected models from a public vulnerability attributes database;

determining, by the computer processor, if at least one vulnerability attribute associated with the list of vulnerability attributes is present on the at least one other system; and

in response to the determining that the at least one vulnerability attribute is present on the at least one other system, first simulating, by the computer processor, whether vulnerabilities exploited from a first system state cause a transition to a second system state, the second system state having a higher-privilege level than the first system state within the target system and

generating, by the computer processor, an attack graph based at least in part on the results of the simulation.

12. The method of claim 11 , wherein the exploited vulnerability forms at least a portion of an attack chain if the second state has root privileges within the target system.

13. The method of claim 12 , further comprising:

repeating the first simulating step until reaching a system state with higher level privileges than the first state; and

forming an attack chain including each of the exploits causing transitions from the first system state to the system state with root privileges,

wherein the attack graph is generated so as to include the attack chain.

14. The method of claim 11 , wherein the vulnerabilities and exploits associated with the system state transitions are based on information received from the National Vulnerability Database.

Assignments (15)
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jan 22, 2025
From: CACI LGS INNOVATIONS LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 069987/0444 →
CHANGE OF NAME Recorded Nov 4, 2024
From: LGS INNOVATIONS LLC
To: CACI LGS INNOVATIONS LLC
Reel/Frame 069292/0952 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded May 29, 2019
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 049312/0843 →
RELEASE OF SECURITY INTEREST Recorded May 21, 2019
From: BANK OF AMERICA, N.A.
To: LGS INNOVATIONS LLC
Reel/Frame 049247/0557 →
RELEASE OF SECURITY INTEREST Recorded May 2, 2019
From: BANK OF AMERICA, N.A.
To: LGS INNOVATIONS LLC
Reel/Frame 049074/0094 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Jul 19, 2017
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA, N.A.
Reel/Frame 043254/0393 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 033868/0555 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2014
From: ALCATEL LUCENT
To: LGS INNOVATIONS LLC
Reel/Frame 032743/0584 →
SECURITY INTEREST Recorded Apr 1, 2014
From: LGS INNOVATIONS LLC
To: BANK OF AMERICA NA
Reel/Frame 032579/0066 →
RELEASE OF SECURITY INTEREST Recorded Apr 1, 2014
From: CREDIT SUISSE AG
To: ALCATEL LUCENT
Reel/Frame 032578/0952 →
SECURITY AGREEMENT Recorded Jan 30, 2013
From: ALCATEL LUCENT
To: CREDIT SUISSE AG
Reel/Frame 029821/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 16, 2013
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 029635/0958 →
MERGER Recorded Jan 11, 2013
From: LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 029612/0903 →
CONFIRMATORY LICENSE Recorded May 18, 2007
From: LUCENT TECHNOLOGIES INC.
To: NATIONAL SECURITY AGENCY
Reel/Frame 019326/0800 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2006
From: O'ROURKE, PAUL F.; SHANLEY, ROBERT J.
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 018446/0039 →