IP Library Granted Patent US 11,277,430
Granted Patent B2
US 11,277,430 · App. 16/453,212 · Granted Mar 15, 2022

System and method for securing a network

Inventors: Chelsea Vela (San Antonio, TX); Justin Hoffman (Boerne, TX)
Assignee: BOOZ ALLEN HAMILTON INC.
H04L63/1433H04L63/1416H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,430
App. No.
16/453,212
Granted
Mar 15, 2022
Kind
B2
Abstract

A system for generating a cyber-attack to penetrate a network. The system includes an identification module configured to identify at least one vulnerability of the network by examining at least one of a node of the network, data transmission within the network, or data received from a cyber defense mechanism; a generation module configured to generate a cyber-attack based on the at least one vulnerability of the network, and a goal to be achieved by the cyber-attack. The system includes a penetration module configured to penetrate the network with the cyber-attack and determine an effectiveness rating of the penetration; and a feedback module configured to provide a feedback to the identification module based on at least the effectiveness rating of the penetration.

Claims (39)

1. A system for generating a cyber-attack to penetrate a network, the system comprising:

an identification module configured to identify at least one vulnerability of the network by examining at least one of a node of the network, data transmission within the network, or data received from a cyber defense mechanism;

a generation module configured to generate a cyber-attack: based on the at least one vulnerability of the network, and a goal to be achieved by the cyber-attack, wherein the generation module utilizes one or more machine learning techniques to generate the cyber-attack;

a penetration module configured to penetrate the network with the cyber-attack, and determine an effectiveness rating of the penetration, wherein the effectiveness rating of the penetration is based on at least one of a success of the penetration, a technique used for penetration, and the goal to be achieved by the cyber-attack; and

a feedback module configured to provide a feedback to the identification module based on at least the effectiveness rating of the penetration; and

a cyber defense mechanism configured to defend the network using a single defensive mechanism or a combination of defensive mechanisms based on the type of the reported cyber-attack and determining an effectiveness rating of the cyber defense mechanism based on the effectiveness of defending the network, wherein the effectiveness of the cyber defense mechanism is based on a combination of the effectiveness of each cyber defense mechanism to thwart a respective part of the cyber-attack; and providing feedback to the generation module and deployed in enterprise networks to help identify threats.

2. The system of claim 1 , wherein the identification module is configured to identify one or more vulnerabilities in addition to the at least one vulnerability of the network by examining the feedback received from the feedback module.

3. The system of claim 1 , wherein the feedback module is configured to provide the feedback to the cyber defense mechanism.

4. The system of claim 3 , wherein the cyber defense mechanism forms a part of a system for generating a cyber defense mechanism to secure a network.

5. The system of claim 1 , wherein the identification module utilizes one or more machine learning techniques to identify the at least one vulnerability of the network.

6. The system of claim 1 , in combination with one or more nodes, wherein the system resides in the one or more nodes.

7. A node configured to interface with or contain one or more modules of the system of claim 1 .

8. A method for generating a cyber-attack to penetrate a network, the method comprising:

identifying at least one vulnerability of the network by examining at least one of a node of the network, data transmission within the network, or data received from a cyber defense mechanism;

generating a cyber-attack based on the at least one vulnerability of the network, and a goal to be achieved the cyber attack, wherein the generation utilizes one or more machine learning techniques to generate, the cyber-attack;

penetrating the network with the cyber-attack, and determining an effectiveness rating of the penetration, wherein the effectiveness rating of the penetration is based on at least one of a success of the penetration, a technique used for penetration, and the goal to be achieved by the cyber attack;

providing a feedback to the identification module based on at least the effectiveness rating of the penetration; and

a cyber defense mechanism configured to defend the network using a single defensive mechanism or a combination of defensive mechanisms based on the type of the reported cyber-attack and determining an effectiveness rating of the cyber defense mechanism based on the effectiveness of defending the network, wherein the effectiveness of the cyber defense mechanism is based on a combination of the effectiveness of each cyber defense mechanism to thwart a respective part of the cyber-attack; and providing feedback to the generation module and deployed in enterprise networks to help identify threats.

9. The method of claim 8 , comprising:

iterating the steps of identifying, generating, penetrating, and providing.

10. A system for generating a cyber defense mechanism to secure a network, the system comprising:

a generation module configured to receive threat intelligence data, which provides information regarding cyber-attacks associated with the network, and generate the cyber defense mechanism to prevent against a cyber-attack associated with the threat intelligence data, wherein the generation module utilities one or more machine learning techniques to generate the cyber defense mechanism;

a rating, module configured to determine whether the cyber defense mechanism is successfully able to prevent the cyber-attack, and rate the cyber defense mechanism based on its effectiveness;

a feedback module configured to provide feedback to the generation module based on at least a rating of the effectiveness of the cyber defense mechanism; and

a cyber defense mechanism configured to defend the network using a single defensive mechanism or a combination of defensive mechanisms based on the type of the reported cyber-attack and determining an effectiveness rating of the cyber defense mechanism based on the effectiveness of defending the network, wherein the effectiveness of the cyber defense mechanism is based on a combination of the effectiveness of each cyber defense mechanism to thwart a respective art of the c her-attack; and providing feedback to the generation module and deployed in enterprise networks to help identify threats.

11. The system of claim 10 , wherein the generation module is configured to receive the threat intelligence data from the feedback module.

12. The system of claim 10 , wherein the feedback module is configured to provide the feedback to a system for generating a cyber-attack.

13. The system of claim 10 , wherein the cyber defense mechanism forms a part of a system for generating a cyber defense mechanism to secure a network.

14. The system of claim 10 , in combination with one or more nodes, wherein the system resides in the one or more nodes.

15. The system of claim 10 , wherein the cyber defense mechanism is a combination of multiple cyber defense mechanisms, each cyber defense mechanism being configured to thwart a part of the cyber-attack.

16. A node configured to interface with or contain one or more modules of the system of claim 10 .

17. A method for generating a cyber defense mechanism to secure a network, the method comprising:

receiving threat intelligence data, which provides information regarding cyber threats associated with the network;

generating the cyber defense mechanism to prevent against a cyber-attack associated with the threat intelligence data, wherein the generation module utilizes one or more machine learning techniques to generate the cyber defense mechanism;

determining whether the cyber defense mechanism is successfully able to prevent the cyber-attack, and

rating the cyber defense mechanism based on its effectiveness; and providing feedback based on at least a rating of the effectiveness rating of the penetration; and

a cyber defense mechanism configured to defend the network using single defensive mechanism or a combination of defensive mechanisms based on the type of the reported cyber-attack and determining an effectiveness rating of the cyber defense mechanism based on the effectiveness of defending the network, wherein the effectiveness of the cyber defense mechanism is based on a combination of the effectiveness of each cyber defense mechanism to thwart a respective art of the cyber-attack; and providing feedback to the generation module and deployed in enterprise networks to help identify threats.

18. The method of claim 17 , comprising:

iterating the steps of receiving, generating, determining, and providing.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT ASSIGNMENT COVER SHEET, NATURE OF CONVEYANCE: CONFIRMING THE LICENSE PREVIOUSLY RECORDED AT REEL: 061967 FRAME: 0676. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 29, 2022
From: BOOZ ALLEN HAMILTON INC.
To: THE GOVERNMENT OF THE UNITED STATES, AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
Reel/Frame 062250/0076 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2022
From: BOOZ ALLEN HAMILTON INC.
To: THE GOVERNMENT OF THE UNITED STATES, AS REPRESENTED BY THE SECRETARY OF THE AIR FORCE
Reel/Frame 061967/0676 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2019
From: VELA, CHELSEA; HOFFMAN, JUSTIN
To: BOOZ ALLEN HAMILTON INC.
Reel/Frame 050613/0313 →
Continuity (2)
Provisional Application 62770893 · Nov 23, 2018
Related Publication 20210273967A1 · Sep 2, 2021