IP Library Granted Patent US 12,212,585
Granted Patent B2
US 12,212,585 · App. 17/711,868 · Granted Jan 28, 2025

Method, product, and system for analyzing a computer network to identify attack paths using a software representation that embodies network configuration and policy data for security management

Inventors: Nicolas Beauchesne (Honolulu, HI); Sohrob Kazerounian (Brookline, MA); William Stow Finlayson, IV (Cherry Hill, NJ); Karl Matthew Lynn (San Jose, CA)
Assignee: Vectra AI, Inc.
H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,585
App. No.
17/711,868
Granted
Jan 28, 2025
Kind
B2
Abstract

Disclosed is an approach for analyzing a computer network to identify attack paths using a software representation that embodies network configuration and policy data for security management. The software representation comprises a state machine where different states can be reached using respective transitions or properties which are possible as determined based on the network configuration and network policy data. The states correspond to respective entities on the network which may comprise resources that are identifiable for protection in the software representation using crash statements. The software representation can then be stimulated using software analysis tools such as fuzzers to identify sequences of state-to-state transitions that could be used to compromise a protected resource on the computer network.

Claims (41)

1. A method comprising:

identifying a software representation of a computing network, wherein the software representation was generated based on network configuration data and network policy data for the computer network;

analyzing the software representation to identify possible attack paths in the computer network by:

identifying one or more entities to protect from malicious activity;

inserting one or more crash statements into the software representation at one or more locations corresponding to the one or more entities to protect from malicious activity; and

executing the software representation using a fuzzer to generate inputs for the software representation having the one or more crash statements, wherein possible attack paths are represented by sequences of function calls identified in corresponding crash reports and crash reports are generated in response to an input from the fuzzer, the fuzzer is one of a plurality of fuzzer instances that generate inputs for one or more instances of the software representation, the plurality of fuzzer instances execute in parallel, the fuzzer executes using at least one of a random, mutation, concolic, or symbolic execution process, a second fuzzer of the plurality of fuzzer instances executes using at least one of a random, mutation, concolic, or symbolic execution process different from the fuzzer.

2. The method of claim 1 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

3. The method of claim 1 , wherein an attack path comprises at least a sequence of state changes that may be used to reach a target state from a starting state, wherein the target state corresponds to an entity to be protected.

4. The method of claim 1 , wherein the one or more entities comprise at least one file server, active directory, token service, or other authentication service.

5. The method of claim 1 , wherein execution of at least one crash statement is dependent on satisfaction of a condition.

6. The method of claim 1 , further comprising compiling the software representation into an executable form after inserting the one or more crash statements.

7. The method of claim 1 , wherein the plurality of fuzzer instances are distributed across a plurality of computing devices.

8. The method of claim 1 , further comprising determining, based on one or more metrics, whether a termination condition has been met for the execution of the software representation using the fuzzer.

9. A non-transitory computer readable medium having stored thereon a set of instructions, the set of instructions, when executed by a processor, causing a set of acts comprising:

identifying a software representation of a computing network, wherein the software representation was generated based on network configuration data and network policy data for the computer network;

analyzing the software representation to identify possible attack paths in the computer network by:

identifying one or more entities to protect from malicious activity;

inserting one or more crash statements into the software representation at one or more locations corresponding to the one or more entities to protect from malicious activity; and

executing the software representation using a fuzzer to generate inputs for the software representation having the one or more crash statements, wherein possible attack paths are represented by sequences of function calls identified in corresponding crash reports and crash reports are generated in response to an input from the fuzzer, the fuzzer is one of a plurality of fuzzer instances that generate inputs for one or more instances of the software representation, the plurality of fuzzer instances execute in parallel, the fuzzer executes using at least one of a random, mutation, concolic, or symbolic execution process, a second fuzzer of the plurality of fuzzer instances executes using at least one of a random, mutation, concolic, or symbolic execution process different from the fuzzer.

10. The computer readable medium of claim 9 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

11. The computer readable medium of claim 9 , wherein an attack path comprises at least a sequence of state changes that may be used to reach a target state from a starting state, wherein the target state corresponds to an entity to be protected.

12. The computer readable medium of claim 9 , wherein the one or more entities comprise at least one file server, active directory, token service, or other authentication service.

13. The computer readable medium of claim 9 , wherein execution of at least one crash statement is dependent on satisfaction of a condition.

14. The computer readable medium of claim 9 , wherein the set of acts further comprise compiling the software representation into an executable form after inserting the one or more crash statements.

15. The computer readable medium of claim 9 , wherein the plurality of fuzzer instances are distributed across a plurality of computing devices.

16. The computer readable medium of claim 9 , wherein the set of acts further comprise comprising determining, based on one or more metrics, whether a termination condition has been met for the execution of the software representation using the fuzzer based on one or more metrics.

17. A computing system comprising:

a memory storing a set of instructions; and

a processor to execute the set of instructions to perform a set of acts comprising:

identifying a software representation of a computing network, wherein the software representation was generated based on network configuration data and network policy data for the computer network;

analyzing the software representation to identify possible attack paths in the computer network by:

identifying one or more entities to protect from malicious activity;

inserting one or more crash statements into the software representation at one or more locations corresponding to the one or more entities to protect from malicious activity; and

executing the software representation using a fuzzer to generate inputs for the software representation having the one or more crash statements, wherein possible attack paths are represented by sequences of function calls identified in corresponding crash reports and crash reports are generated in response to an input from the fuzzer, the fuzzer is one of a plurality of fuzzer instances that generate inputs for one or more instances of the software representation, the plurality of fuzzer instances execute in parallel, the fuzzer executes using at least one of a random, mutation, concolic, or symbolic execution process, a second fuzzer of the plurality of fuzzer instances executes using at least one of a random, mutation, concolic, or symbolic execution process different from the fuzzer.

18. The computing system of claim 17 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

19. The computing system of claim 17 , wherein an attack path comprises at least a sequence of state changes that may be used to reach a target state from a starting state, wherein the target state corresponds to an entity to be protected.

20. The computing system of claim 17 , wherein the one or more entities comprise at least one file server, active directory, token service, or other authentication service.

21. The computing system of claim 17 , wherein execution of at least one crash statement is dependent on satisfaction of a condition.

22. The computing system of claim 17 , wherein the set of acts further comprise compiling the software representation into an executable form after inserting the one or more crash statements.

23. The computing system of claim 17 , wherein the plurality of fuzzer instances arc distributed across a plurality of computing devices.

24. The computing system of claim 17 , wherein the set of acts further comprise comprising determining, based on one or more metrics, whether a termination condition has been met for the execution of the software representation using the fuzzer based on one or more metrics.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: BEAUCHESNE, NICOLAS; KAZEROUNIAN, SOHROB; FINLAYSON IV, WILLIAM STOW; LYNN, KARL MATTHEW
To: VECTRA AI, INC.
Reel/Frame 059478/0050 →
Continuity (1)
Related Publication 20230319068A1 · Oct 5, 2023
References Cited (61)
US 6651099B1 · Dietz et al. · 2003 [cited by applicant]
US 7305383B1 · Kubesh et al. · 2007 [cited by applicant]
US 8272061B1 · Lotem et al. · 2012 [cited by applicant]
US 9432394B1 · Lahiri · 2016 [cited by examiner]
US 10148685B2 · Hassanzadeh et al. · 2018 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20080044018A1 · Scrimsher et al. · 2008 [cited by applicant]
US 20130097125A1 · Marvasti et al. · 2013 [cited by applicant]
US 20130283360A1 · Hui et al. · 2013 [cited by applicant]
US 20130340083A1 · Petrica · 2013 [cited by examiner]
US 20140279808A1 · Strassner · 2014 [cited by applicant]
US 20150033340A1 · Giokas · 2015 [cited by applicant]
US 20160301704A1 · Hassanzadeh et al. · 2016 [cited by applicant]
US 20170161498A1 · Yavo · 2017 [cited by applicant]
US 20190109872A1 · Dhakshinamoorthy · 2019 [cited by examiner]
US 20200022003A1 · Bizzarri et al. · 2020 [cited by applicant]
US 20200028861A1 · Pritzkau et al. · 2020 [cited by applicant]
US 20200177618A1 · Hassanzadeh et al. · 2020 [cited by applicant]
US 20200193031A1 · Avraham et al. · 2020 [cited by applicant]
US 20200304534A1 · Rakesh et al. · 2020 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20210243208A1 · Rubin et al. · 2021 [cited by applicant]
US 20210243226A1 · El Gamal et al. · 2021 [cited by applicant]
US 20210248443A1 · Shu et al. · 2021 [cited by applicant]
US 20210336971A1 · Robbins et al. · 2021 [cited by applicant]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220014561A1 · Caceres et al. · 2022 [cited by applicant]
US 20220269591A1 · McShane · 2022 [cited by examiner]
US 20220368702A1 · Robbins et al. · 2022 [cited by applicant]
US 20230050691A1 · Gu et al. · 2023 [cited by applicant]
US 20230262073A1 · Sheu et al. · 2023 [cited by applicant]
CA 2926579 · 2016 [cited by applicant]
CN 105262771 · 2016 [cited by applicant]
CN 107277039 · 2017 [cited by applicant]
CN 111049827 · 2020 [cited by applicant]
EP 3726803 · 2020 [cited by applicant]
EP 4254865A1 · 2023 [cited by applicant]
EP 4254866A1 · 2023 [cited by applicant]
EP 4254867A2 · 2023 [cited by applicant]
EP 4254869A2 · 2023 [cited by applicant]
EP 4254868A3 · 2023 [cited by applicant]
WO WO2015013376A2 · 2015 [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191319.7 dated Aug. 17, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191317.1 dated Aug. 3, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191320.5 dated Sep. 28, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191322.1 dated Oct. 2, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191321.3 dated Oct. 2, 2023. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,850 dated Mar. 27, 2024. [cited by applicant]
D. Kreutz, F. M. V. Ramos, P. E. Verfssimo, C. E. Rothenberg, S. Azodolmolky and S. Uhlig, “Software-Defined Networking: A Comprehensive Survey,” in Proceedings of the IEEE, vol. 103, No. 1, pp. 14-76 (Jan. 2015) (Year:… [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,884 dated Feb. 2, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,903 dated Jan. 8, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Feb. 15, 2024. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 23199257.9 dated Mar. 6, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,903 dated May 7, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,811 dated Jul. 11, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,884 dated May 23, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,903 dated Sep. 26, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,884 dated Nov. 1, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,850 dated Oct. 24 2024. [cited by applicant]