IP Library › Granted Patent US 12,393,694
Granted Patent B2
US 12,393,694 · App. 18/007,362 · Granted Aug 19, 2025

Computer-implemented method for testing the cybersecurity of a target environment

Inventors: Abdelkader Lahmadi (Le Chesnay, FR); Jérôme Francois (Le Chesnay, FR); Frédéric Beck (Le Chesnay, FR)
Assignee: INSTITUT NATIONAL DE RECHERCHE EN INFORMATIQUE ET EN AUTOMATIQUE (INRIA)
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,393,694
App. No.
18/007,362
Granted
Aug 19, 2025
Kind
B2
Abstract

A computer-implemented method for testing cybersecurity of a target environment. The method includes: receiving data from the target environment, the data including software elements; accessing a database of vulnerabilities, and extracting therefrom a list of vulnerabilities including all of the vulnerabilities associated with an element; and building a list of vulnerability chains on the basis of the list of vulnerabilities. The building includes: for each given vulnerability in the list of vulnerabilities, comparing consequences of the current vulnerability with the means of the given vulnerability; when a similarity is found, defining one or more new chains by adding the given vulnerability to each of the chains in the current list, adding the new chain(s) to the list of vulnerability chains, and repealing the receiving and the accessing with the given vulnerability as the current vulnerability, and the list of vulnerability chains as the current list.

Claims (40)

1. A computer-implemented method for testing cybersecurity of a target environment, comprising operations including:

a) receiving target environment data comprising software elements;

b) accessing a database of vulnerabilities, each vulnerability being defined by a tuple associating a vulnerability identifier, a list of means defining the means used to exploit the vulnerability, and a list of consequences defining the consequences for exploiting the vulnerability, and extracting therefrom a list of vulnerabilities comprising all of the vulnerabilities comprising a vulnerability identifier associated with a software element included in the target environment data;

c) building a list of vulnerability chains based on the list of vulnerabilities by initialising at least one pair comprising an empty list as the current list and one of the vulnerabilities from the list of vulnerabilities as the current vulnerability, and for each couple, by executing the following operations

c)1) for each given vulnerability of the list of vulnerabilities distinct from the current vulnerability and absent from the tuples in the current list, comparing the consequences of the current vulnerability with the means of the given vulnerability, and,

c)2) whenever a similarity between a consequence of the list of consequences of the current vulnerability with a means of the list of means of the given vulnerability is found,

c)2)i) defining one or more new chains by adding to each of the chains of the current list whose last tuple includes the current vulnerability a tuple associating the given vulnerability, a similarity identifier, the consequence of the list of consequences of the current vulnerability, and the means of the list of means of the given vulnerability,

c)2)ii) adding the new chain(s) to the list of vulnerability chains,

c)2)iii) repeating the operations a) and b) with the given vulnerability as the current vulnerability, and the list of vulnerability chains as the current list.

2. The method according to claim 1 , wherein the operation c) includes initializing as many pairs as there are vulnerabilities in the list of vulnerabilities.

3. The method according to claim 1 , wherein the operation c)2) comprises determining a value of similarity between a consequence of the list of consequences of the current vulnerability and a means of the list of means of the given vulnerability, and determining that this value of similarity is strictly greater than a selected threshold.

4. The method according to claim 3 , wherein the selected threshold is zero.

5. The method according to claim 3 , wherein when the consequence of the list of consequences of the current vulnerability is identical to the means of the list of means of the given vulnerability, the similarity value is 1.

6. The method according to claim 1 ,

wherein the target environment data further comprise software element configuration data and software element relationship data, wherein the tuple defining a vulnerability further comprises a list of context data defining the software context in which the vulnerability can be executed, the method further comprising:

d) comparing the lists of context data of the vulnerabilities of each vulnerability chain in the list of vulnerability chains with the configuration data and/or the software element relationship data, and

d)1) storing in a first list the vulnerability chains whose vulnerabilities comprise lists of context data which are all contained in the configuration data and/or the software element relationship data, and

d)2) storing in a second list the vulnerability chains of which only some of the vulnerabilities comprise lists of context data contained in the configuration data and/or the software element relationship data.

7. The method according to claim 6 , further comprising:

e) obtaining exploits corresponding to the vulnerabilities of the vulnerability chains of the first list and of the second list, implementing the exploit chains of the first list and of the second list with these exploits, and returning the chains while classifying them according to whether they belong to the first list or the second list and according to the success rate of their implementation.

8. A non-transitory computer readable data storage medium on which a computer program is recorded, which comprises instructions that when executed by a processor of a computer system configure the computer system to implement a method for testing cybersecurity of a target environment, comprising operations including:

a) receiving target environment data comprising software elements;

b) accessing a database of vulnerabilities, each vulnerability being defined by a tuple associating a vulnerability identifier, a list of means defining the means used to exploit the vulnerability, and a list of consequences defining the consequences for exploiting the vulnerability, and extracting therefrom a list of vulnerabilities comprising all of the vulnerabilities comprising a vulnerability identifier associated with a software element included in the target environment data;

c) building a list of vulnerability chains based on the list of vulnerabilities by initialising at least one pair comprising an empty list as the current list and one of the vulnerabilities from the list of vulnerabilities as the current vulnerability, and for each couple, by executing the following operations

c)1) for each given vulnerability of the list of vulnerabilities distinct from the current vulnerability and absent from the tuples in the current list, comparing the consequences of the current vulnerability with the means of the given vulnerability, and,

c)2) whenever a similarity between a consequence of the list of consequences of the current vulnerability with a means of the list of means of the given vulnerability is found,

c)2)i) defining one or more new chains by adding to each of the chains of the current list whose last tuple includes the current vulnerability a tuple associating the given vulnerability, a similarity identifier, the consequence of the list of consequences of the current vulnerability, and the means of the list of means of the given vulnerability,

c)2)ii) adding the new chain(s) to the list of vulnerability chains,

c)2)iii) repeating the operations a) and b) with the given vulnerability as the current vulnerability, and the list of vulnerability chains as the current list.

9. A computer system comprising:

a processor; and

a non-transitory computer readable medium coupled to the processor and comprising instructions stored thereon instructions which when executed by the processor configure the computer system to implement a method for testing cybersecurity of a target environment, comprising operations including:

a) receiving target environment data comprising software elements;

b) accessing a database of vulnerabilities, each vulnerability being defined by a tuple associating a vulnerability identifier, a list of means defining the means used to exploit the vulnerability, and a list of consequences defining the consequences for exploiting the vulnerability, and extracting therefrom a list of vulnerabilities comprising all of the vulnerabilities comprising a vulnerability identifier associated with a software element included in the target environment data;

c) building a list of vulnerability chains based on the list of vulnerabilities by initialising at least one pair comprising an empty list as the current list and one of the vulnerabilities from the list of vulnerabilities as the current vulnerability, and for each couple, by executing the following operations

c)1) for each given vulnerability of the list of vulnerabilities distinct from the current vulnerability and absent from the tuples in the current list, comparing the consequences of the current vulnerability with the means of the given vulnerability, and,

c)2) whenever a similarity between a consequence of the list of consequences of the current vulnerability with a means of the list of means of the given vulnerability is found,

c)2)i) defining one or more new chains by adding to each of the chains of the current list whose last tuple includes the current vulnerability a tuple associating the given vulnerability, a similarity identifier, the consequence of the list of consequences of the current vulnerability, and the means of the list of means of the given vulnerability,

c)2)ii) adding the new chain(s) to the list of vulnerability chains,

c)2)iii) repeating the operations a) and b) with the given vulnerability as the current vulnerability, and the list of vulnerability chains as the current list.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2023
From: LAHMADI, ABDELKADER; FRANCOIS, JÉRÔME; BECK, FRÉDÉRIC
To: INSTITUT NATIONAL DE RECHERCHE EN INFORMATIQUE ET EN AUTOMATIQUE (INRIA)
Reel/Frame 063728/0678 →
Priority Claims (1)
FR 2008218 · Jul 31, 2020 · national
Continuity (1)
Related Publication 20230222223A1 · Jul 13, 2023
References Cited (12)
US 7013395B1 · Swiler et al. · 2006 [cited by applicant]
US 9069930B1 · Hart · 2015 [cited by applicant]
US 10114954B1 · Bellis · 2018 [cited by examiner]
US 20140189873A1 · Elder · 2014 [cited by examiner]
US 20230185921A1 · Karas · 2023 [cited by examiner]
WO 2007143226A2 · 2007 [cited by applicant]
WO WO2010042979A1 · 2010 [cited by examiner]
International Search Report dated Nov. 16, 2021 for corresponding International Application No. PCT/FR2021/051410, filed Jul. 28, 2021. [cited by applicant]
Written Opinion of the International Searching Authority dated Nov. 16, 2021 for corresponding International Application No. PCT/FR2021/051410, filed Jul. 28, 2021. [cited by applicant]
Lin Zhaowen et al., “Real-Time Intrusion Alert Correlation System Based on Prerequisites and Consequence”, Wireless Communications Networking and Mobile Computing (WICOM), 2010 6th International Conference on, IEEE, Pis… [cited by applicant]
French Search Report and Written Opinion dated Apr. 26, 2021 for corresponding French Application No. 2008218, filed Jul. 31, 2020. [cited by applicant]
Sheyner et al., “Automated generation and analysis of attack graphs”, In Proceedings of the 2002 IEEE Symposium on Security and Privacy, SP '02, pp. 273-, Washington, DC, USA, 2002. [cited by applicant]