IP Library Granted Patent US 11,853,434
Granted Patent B2
US 11,853,434 · App. 17/888,071 · Granted Dec 26, 2023

System and method for creating and executing breach scenarios utilizing virtualized elements

Inventors: Itzhak Kotler (Kfar-Saba, IL); Idan Livni (Gevatayim, IL); Dan Bar-Shalom (Petah Tikva, IL); Guy Bejerano (Reut, IL)
Assignee: SAFEBREACH LTD.
G06F21/577G06F2221/034G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,853,434
App. No.
17/888,071
Granted
Dec 26, 2023
Kind
B2
Abstract

A system for analyzing a computing system for potential breach points, the system comprising a memory device having executable instructions stored therein, and a processing device, in response to the executable instructions, configured to parse a breach scenario file, the breach scenario file comprising a graph including action component nodes connected by edges, determine a root node from the action component nodes, execute the root node with breach point data, generate a root node return value based on the execution of the root node, the root node return value including a modified copy of the breach point data, determine children nodes from the action component nodes connected to the root node, execute the children nodes wherein each execution of the children nodes produces children node return values for a subsequent one of the children nodes, and return a final return value from the execution of the children nodes.

Claims (26)

1. A system for managing breach simulation results generated in a networked production environment, the networked production environment comprising hardware components coupled in a network, the system comprising:

a memory device having executable instructions stored therein; and

a processing device, in response to the executable instructions, configured to:

receive a set of simulation results of a breach scenario workflow from a simulation orchestrator which have been processed by a results analyzer subsystem, wherein the breach scenario workflow includes one or more malicious actions representing a scenario found successful from an attacker point of view that violates a security policy of the networked production environment;

retrieve a stored snapshot of known breaches in the networked production environment with the simulation results, the snapshot comprising an in-memory graph including a plurality of nodes and edges, the nodes in the in-memory graph representing simulator nodes between which a breach simulation was executed, and the edges in the in-memory graph representing simulation results of specific breach scenarios between the simulator nodes;

determine whether any of the simulation results represent a new breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that no such breach scenario is found, updating the in-memory graph to include any simulation results so determined to be a new breach scenario; and determine whether any of the simulation results represent a fixed breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that the simulation results show the breach was fixed, concluding the breach scenario by updating the in-memory graph to reflect the breach scenario was fixed.

2. The system of claim 1 wherein the simulation orchestrator is configured to simulate malicious attacks at the simulation nodes.

3. The system of claim 1 wherein the system is configured to apply or suggest remediation for simulation results determined to represent a new breach scenario.

4. The system of claim 1 wherein the security policy includes constraints on data, flow, and access of a party's or an individual's digital assets and systems.

5. The system of claim 1 wherein the breach scenario workflow is continuously tested.

6. The system of claim 1 wherein the system is configured to emit a breach event in response to simulation results are being determined to be a new breach scenario.

7. The system of claim 1 wherein the system is configured to emit a breach heal event in response to simulation results being determined to represent a fixed breach scenario.

8. A method for managing breach simulation results generated in a networked production environment, the method performed by at least one processor comprising hardware components coupled in a network, the method comprising:

receiving a set of simulation results of a breach scenario workflow from a simulation orchestrator which have been processed by a results analyzer subsystem, wherein the breach scenario workflow includes one or more malicious actions representing a scenario found successful from an attacker point of view that violates a security policy of the networked production environment;

retrieving a stored snapshot of known breaches in the networked production environment with the simulation results, the snapshot comprising an in-memory graph including a plurality of nodes and edges, the nodes in the in-memory graph representing simulator nodes between which a breach simulation was executed, and the edges in the in-memory graph representing simulation results of specific breach scenarios between the simulator nodes; determining whether any of the simulation results represent a new breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that no such breach scenario is found, updating the in-memory graph to include any simulation results so determined to be a new breach scenario; and determining whether any of the simulation results represent a fixed breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that the simulation results show the breach was fixed, concluding the breach scenario by updating the in-memory graph to reflect the breach scenario was fixed.

9. The method of claim 8 wherein the step of receiving the set of simulation results of the breach scenario workflow from the simulation orchestrator comprises receiving a set of simulation results of a breach scenario workflow from a simulation orchestrator that is configured to simulate malicious attacks at the simulation nodes.

10. The method of claim 8 wherein the method further comprises applying or suggesting remediation for simulation results determined to represent a new breach scenario.

11. The method of claim 8 wherein the method further comprises continuously testing the breach scenario workflow.

12. The method of claim 8 wherein the method further comprises emitting a breach event in response to simulation results being determined to be a new breach scenario.

13. The method of claim 8 wherein the method further comprises emitting a breach heal event in response to simulation results being determined to represent a fixed breach scenario.

14. A non-transitory computer-readable medium storing instructions for managing breach simulation results generated in a networked production environment that, when executed by at least one processor comprising hardware components coupled in a network, cause the at least one processor to:

receive a set of simulation results of a breach scenario workflow from a simulation orchestrator which have been processed by a results analyzer subsystem, wherein the breach scenario workflow includes one or more malicious actions representing a scenario found successful from an attacker point of view that violates a security policy of the networked production environment;

retrieve a stored snapshot of known breaches in the networked production environment with the simulation results, the snapshot comprising an in-memory graph including a plurality of nodes and edges, the nodes in the in-memory graph representing simulator nodes between which a breach simulation was executed, and the edges in the in-memory graph representing simulation results of specific breach scenarios between the simulator nodes; determine whether any of the simulation results represent a new breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that no such breach scenario is found, updating the in-memory graph to include any simulation results so determined to be a new breach scenario; and determine whether any of the simulation results represent a fixed breach scenario by searching the in-memory graph for a breach scenario matching the simulation results and, in response to determining that the simulation results show the breach was fixed, concluding the breach scenario by updating the in-memory graph to reflect the breach scenario was fixed.

15. The non-transitory computer-readable medium of claim 14 wherein the simulation orchestrator is configured to simulate malicious attacks at the simulation nodes.

16. The non-transitory computer-readable medium of claim 14 wherein the processor is configured to apply or suggest remediation for simulation results determined to represent a new breach scenario.

17. The non-transitory computer-readable medium of claim 14 wherein the breach scenario workflow is continuously tested.

Assignments (1)
SECURITY INTEREST Recorded Apr 16, 2024
From: SAFEBREACH INC.; SAFEBREACH LTD.
To: AVENUE VENTURE OPPORTUNITIES FUND, L.P., AS AGENT
Reel/Frame 067129/0498 →
Continuity (4)
Continuation 17101086 · Nov 23, 2020
Continuation 15856666 · Dec 28, 2017
Continuation 14691150 · Apr 20, 2015
Related Publication 20230153442A1 · May 18, 2023