IP Library Granted Patent US 12,477,001
Granted Patent B2
US 12,477,001 · App. 17/711,884 · Granted Nov 18, 2025

Method, product, and system for analyzing attack paths in computer network generated using a software representation that embodies network configuration and policy data for security management

Inventors: Nicolas Beauchesne (Honolulu, HI); Sohrob Kazerounian (Brookline, MA); William Stow Finlayson, IV (Cherry Hill, NJ); Karl Matthew Lynn (San Jose, CA)
Assignee: Vectra AI, Inc.
H04L63/145H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,001
App. No.
17/711,884
Filed
Apr 1, 2022
Granted
Nov 18, 2025
Kind
B2
Examiner
TSANG, HENRY
Art Unit
2495
USPC
726/22
Abstract

Disclosed is an approach for analyzing attack paths in computer network generated using a software representation that embodies network configuration and policy data for security management. In some embodiments, the approach includes a process to analyze attack paths in a computer network to determine which attack paths might be most productively covered using a corresponding detection signature. In some embodiments, the attack paths are identified using a software representation that embodies network configuration and policy data. The software representation comprises a state machine where different states can be reached using respective transitions or properties. The states correspond to respective entities on the network which may comprise resources that are identifiable for protection in the software representation using crash statements. The software representation can then be stimulated using software analysis tools such to identify sequences of state-to-state transitions that could be used to compromise a protected resource on the computer network.

Claims (41)

1 . A method comprising:

selecting possible attack paths in a computer network for processing, wherein the possible attack paths comprise sequences of state-to-state transitions, the possible attack paths in the computer network were identified by analyzing a software representation of the computer network and causing crash statements in the software representation to be executed, wherein execution of a crash statement in the software representation indicates that a state corresponding to a protected resource has been reached, and the software representation of the computer network was generated based on network configuration data and network policy data; and

processing the possible attack paths by:

identifying a plurality of candidate triggers from the sequences of state-to-state transitions in the possible attack paths, wherein the plurality of candidate triggers comprise at least subsets of respective sequences of state-to-state transitions, and the plurality of candidate triggers include sequences of state-to-state transitions having different numbers of state-to-state transitions;

ranking respective candidate triggers of the plurality of candidate triggers; and

selecting at least some of the respective candidate triggers based on their respective ranks.

2 . The method of claim 1 , wherein the network configuration data specifies access rights allocated to respective groups, the network policy data specifies comprises a set of access rights for group members to access network resources, and the state corresponding to the protected resource comprises a state that represents a potential attacker acquiring privileges to access the protected resource.

3 . The method of claim 1 , further comprising removing candidate triggers having a candidate trigger length less than a minimum threshold from the plurality of candidate triggers.

4 . The method of claim 1 , further comprising removing candidate triggers that are not associated with a corresponding detection signature template from the plurality of candidate triggers.

5 . The method of claim 1 , wherein ranking respective candidate triggers is based on at least a number of protected entities reachable from a last state of the candidate trigger.

6 . The method of claim 1 , wherein at least a threshold number of candidate triggers are selected for each corresponding protected entity.

7 . The method of claim 1 , wherein selection of the respective candidate triggers is performed on a protected entity by protected entity basis.

8 . The method of claim 1 , further comprising generating one or more detection signatures based on the at least some of the respective candidate triggers.

9 . A non-transitory computer readable medium having stored thereon a set of instructions, the set of instructions, when executed by a processor, causing a set of acts comprising:

selecting possible attack paths in a computer network for processing, wherein the possible attack paths comprise sequences of state-to-state transitions, the possible attack paths in the computer network were identified by analyzing a software representation of the computer network and causing crash statements in the software representation to be executed, wherein execution of a crash statement in the software representation indicates that a state corresponding to a protected resource has been reached, and the software representation of the computer network was generated based on network configuration data and network policy data; and

processing the possible attack paths by:

identifying a plurality of candidate triggers from the sequences of state-to-state transitions in the possible attack paths, wherein the plurality of candidate triggers comprise at least subsets of respective sequences of state-to-state transitions, and the plurality of candidate triggers include sequences of state-to-state transitions having different numbers of state-to- state transitions;

ranking respective candidate triggers of the plurality of candidate triggers; and

selecting at least some of the respective candidate triggers based on their respective ranks.

10 . The computer readable medium of claim 9 , wherein the network configuration data specifies access rights allocated to respective groups, the network policy data specifies comprises a set of access rights for group members to access network resources, and the state corresponding to the protected resource comprises a state that represents a potential attacker acquiring privileges to access the protected resource.

11 . The computer readable medium of claim 9 , wherein the set of acts further comprise removing candidate triggers having a candidate trigger length less than a minimum threshold from the plurality of candidate triggers.

12 . The computer readable medium of claim 9 , wherein the set of acts further comprise removing candidate triggers that are not associated with a corresponding detection signature template from the plurality of candidate triggers.

13 . The computer readable medium of claim 9 , wherein ranking respective candidate triggers is based on at least a number of protected entities reachable from a last state of the candidate trigger.

14 . The computer readable medium of claim 9 , wherein at least a threshold number of candidate triggers are selected for each corresponding protected entity.

15 . The computer readable medium of claim 9 , wherein selection of the respective candidate triggers is performed on a protected entity by protected entity basis.

16 . The computer readable medium of claim 9 , wherein the set of acts further comprise generating one or more detection signatures based on the at least some of the respective candidate triggers.

17 . A computing system comprising:

a memory storing a set of instructions; and

a processor to execute the set of instructions to perform a set of acts comprising:

selecting possible attack paths in a computer network for processing, wherein the possible attack paths comprise sequences of state-to-state transitions, the possible attack paths in the computer network were identified by analyzing a software representation of the computer network and causing crash statements in the software representation to be executed, wherein execution of a crash statement in the software representation indicates that a state corresponding to a protected resource has been reached, and the software representation of the computer network was generated based on network configuration data and network policy data; and

processing the possible attack paths by:

identifying a plurality of candidate triggers from the sequences of state-to-state transitions in the possible attack paths, wherein the plurality of candidate triggers comprise at least subsets of respective sequences of state-to-state transitions, and the plurality of candidate triggers include sequences of state-to-state transitions having different numbers of state-to-state transitions;

ranking respective candidate triggers of the plurality of candidate triggers; and

selecting at least some of the respective candidate triggers based on their respective ranks.

18 . The computing system of claim 17 , wherein the network configuration data specifies access rights allocated to respective groups, the network policy data specifies comprises a set of access rights for group members to access network resources, and the state corresponding to the protected resource comprises a state that represents a potential attacker acquiring privileges to access the protected resource.

19 . The computing system of claim 17 , wherein the set of acts further comprise removing candidate triggers having a candidate trigger length less than a minimum threshold from the plurality of candidate triggers.

20 . The computing system of claim 17 , wherein the set of acts further comprise removing candidate triggers that are not associated with a corresponding detection signature template from the plurality of candidate triggers.

21 . The computing system of claim 17 , wherein ranking respective candidate triggers is based on at least a number of protected entities reachable from a last state of the candidate trigger.

22 . The computing system of claim 17 , wherein at least a threshold number of candidate triggers are selected for each corresponding protected entity.

23 . The computing system of claim 17 , wherein selection of the respective candidate triggers is performed on a protected entity by protected entity basis.

24 . The computing system of claim 17 , wherein the set of acts further comprise generating one or more detection signatures based on the at least some of the respective candidate triggers.

Assignments (2)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: BEAUCHESNE, NICOLAS; KAZEROUNIAN, SOHROB; FINLAYSON IV, WILLIAM STOW; LYNN, KARL MATTHEW
To: VECTRA AI, INC.
Reel/Frame 059478/0060 →
Continuity (1)
Related Publication 20230319100A1 · Oct 5, 2023
References Cited (88)
US 6321338B1 · Porras et al. · 2001 [cited by applicant]
US 6651099B1 · Dietz et al. · 2003 [cited by applicant]
US 7305383B1 · Kubesh et al. · 2007 [cited by applicant]
US 8272061B1 · Lotem et al. · 2012 [cited by applicant]
US 9432394B1 · Lahiri et al. · 2016 [cited by applicant]
US 10148685B2 · Hassanzadeh et al. · 2018 [cited by applicant]
US 10528868B2 · Gillespie · 2020 [cited by applicant]
US 11922712B2 · Tsibulevskiy et al. · 2024 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20080044018A1 · Scrimsher et al. · 2008 [cited by applicant]
US 20130097125A1 · Marvasti · 2013 [cited by examiner]
US 20130283360A1 · Hui et al. · 2013 [cited by applicant]
US 20130340083A1 · Petrica et al. · 2013 [cited by applicant]
US 20140279808A1 · Strassner · 2014 [cited by applicant]
US 20150033340A1 · Giokas · 2015 [cited by applicant]
US 20160301704A1 · Hassanzadeh · 2016 [cited by examiner]
US 20170161498A1 · Yavo · 2017 [cited by applicant]
US 20180232523A1 · Copty et al. · 2018 [cited by applicant]
US 20190109872A1 · Dhakshinamoorthy et al. · 2019 [cited by applicant]
US 20190182287A1 · Hanley et al. · 2019 [cited by applicant]
US 20190228098A1 · Daly et al. · 2019 [cited by applicant]
US 20190266071A1 · Copty et al. · 2019 [cited by applicant]
US 20200022003A1 · Bizzarri et al. · 2020 [cited by applicant]
US 20200028861A1 · Pritzkau · 2020 [cited by examiner]
US 20200073783A1 · Hortala et al. · 2020 [cited by applicant]
US 20200177618A1 · Hassanzadeh et al. · 2020 [cited by applicant]
US 20200193031A1 · Avraham et al. · 2020 [cited by applicant]
US 20200304534A1 · Rakesh et al. · 2020 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20210243208A1 · Rubin et al. · 2021 [cited by applicant]
US 20210243226A1 · El Gamal et al. · 2021 [cited by applicant]
US 20210248443A1 · Shu et al. · 2021 [cited by applicant]
US 20210336971A1 · Robbins et al. · 2021 [cited by applicant]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220014561A1 · Caceres et al. · 2022 [cited by applicant]
US 20220269591A1 · Mcshane et al. · 2022 [cited by applicant]
US 20220319219A1 · Tsibulevskiy et al. · 2022 [cited by applicant]
US 20220368702A1 · Robbins · 2022 [cited by examiner]
US 20230050691A1 · Gu · 2023 [cited by examiner]
US 20230262073A1 · Sheu et al. · 2023 [cited by applicant]
CA 2926579 · 2016 [cited by applicant]
CN 105262771 · 2016 [cited by applicant]
CN 107277039 · 2017 [cited by applicant]
CN 109597767 · 2019 [cited by applicant]
CN 109815009 · 2019 [cited by applicant]
CN 111049827 · 2020 [cited by applicant]
EP 3726803 · 2020 [cited by applicant]
EP 4254865A1 · 2023 [cited by applicant]
EP 4254866A1 · 2023 [cited by applicant]
EP 4254867A2 · 2023 [cited by applicant]
EP 4254869A2 · 2023 [cited by applicant]
EP 4254868A3 · 2023 [cited by applicant]
WO WO2015013376A2 · 2015 [cited by applicant]
WO 2020046981 · 2020 [cited by applicant]
WO 2022043512 · 2022 [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191319.7 dated Aug. 17, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191320.5 dated Sep. 28, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191322.1 dated Oct. 2, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191321.3 dated Oct. 2, 2023. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,903 dated May 7, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 15, 2024. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 23199257.9 dated Mar. 6, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,850 dated Mar. 27, 2024. [cited by applicant]
D. Kreutz, F. M. V. Ramos, P. E. Verfssimo, C. E. Rothenberg, S. Azodolmolky and S. Uhlig, “Software-Defined Networking: A Comprehensive Survey,” in Proceedings of the IEEE, vol. 103, No. 1, pp. 14-76 (Jan. 2015) (Year:… [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,903 dated Jan. 8, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Feb. 15, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 18, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,811 dated Jul. 11, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Aug. 23, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,903 dated Sep. 26, 2024. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191317.1 dated Aug. 3, 2023. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,850 dated Oct. 24, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,850 dated Mar. 12, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,811 dated Feb. 21, 2025. [cited by applicant]
Moser et al., “Exploring Multiple Execution Paths for Malware Analysis”, 2007 IEEE Symposium on Security and Privacy (SP '07), Date of Conference May 20-23, (Year: 2007). [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/128,549 dated Mar. 17, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,850 dated Apr. 9, 2025. [cited by applicant]
Examination Report for EP Patent Appln. No. 22191322.1 dated Jul. 11, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,850 dated Jun. 24, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/108,383 dated Apr. 17, 2025. [cited by applicant]
L. Zhao, P. Cao, Y. Duan, H. Yin and J. Xuan, “Probabilistic Path Prioritization for Hybrid Fuzzing,” In IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 3, pp. 1955-1973, May 1-Jun. 2022. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,811 dated Apr. 21, 2025. [cited by applicant]
Jeon et al., “Automated Crash Filtering Using Interprocedural Static Analysis for Binary Codes”, 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC), Date of Conference: Jul. 4-8 (Year: 2017). [cited by applicant]
Final Office Action for U.S. Appl. No. 18/128,549 dated Aug. 11, 2025. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/108,383 dated Oct. 7, 2025. [cited by applicant]