IP Library Granted Patent US 12,438,901
Granted Patent B2
US 12,438,901 · App. 18/478,960 · Granted Oct 7, 2025

Techniques for identifying network attack paths

Inventors: Austin Lee (Pasadena, CA); Val Komarov (Fairfax, VA); Miguel Ledezma (Alexandria, VA)
Assignee: Rapid7, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,901
App. No.
18/478,960
Granted
Oct 7, 2025
Kind
B2
Abstract

The techniques described herein relate to identifying network attack paths. An example method includes using at least one computer hardware processor to perform obtaining metadata indicating a set of network resources in a plurality of network resources and network connections among network resources in the set of network resources, generating, using the metadata, a relational representation of the set of network resources, generating, using the relational representation, a plurality of network paths between network resources in the set of network resources, and identifying, from among the plurality of network paths and using the relational representation and information indicating one or more of the plurality of network resources that have at least one respective security vulnerability, one or more network attack paths that may be used to exploit one or more security vulnerabilities of network resources in the set of network resources.

Claims (71)

1. A method for identifying exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

using at least one computer hardware processor to perform:

obtaining metadata indicating a set of network resources in the plurality of network resources and network connections among network resources in the set of network resources;

generating, using the metadata, a first relational representation of the set of network resources, the first relational representation comprising at least one network connection table indicating network resources in the set of network resources and network connections among the network resources in the set of network resources;

generating, using the first relational representation, a second relational representation of a plurality of network paths, the second relational representation comprising at least one network path table indicating the plurality of network paths between network resources in the set of network resources, at least one of the plurality of network paths comprising one or more of the set of network resources between a pair of the set of the network resources; and

identifying, from among the plurality of network paths and using the second relational representation and information indicating one or more of the plurality of network resources that have at least one respective security vulnerability, one or more network attack paths that may be used to exploit one or more security vulnerabilities of network resources in the set of network resources.

2. The method of claim 1 , wherein generating the first relational representation of the set of network resources using the metadata comprises generating the at least one network connection table using the metadata.

3. The method of claim 2 , wherein the metadata contains information indicating values of attributes of individual network resources in the set of network resources, information indicating values of attributes of the network connections among the network resources in the set of network resources, and information indicating values of attributes of the plurality of network paths, and wherein generating the at least one network connection table using the metadata comprises:

generating at least one network resource table using the information indicating the values of attributes of the individual network resources in the set of network resources; and

generating the at least one network connection table using the information indicating the values of attributes of the network connections among the network resources in the set of network resources; wherein

generating the second relational representation comprises generating the at least one network path table using the information indicating the values of attributes of the plurality of network paths; and the method further comprising

storing the at least one network resource table, the at least one network connection table, and the at least one network path table in at least one datastore.

4. The method of claim 1 , further comprising storing at least one of the first relational representation or the second relational representation in at least one datastore.

5. The method of claim 1 , further comprising:

after identifying the one or more network attack paths, generating at least one network attack path table storing information specifying the one or more network attack paths; and

storing the at least one network attack path table in at least one datastore.

6. The method of claim 1 , further comprising:

generating a risk score for each of the one or more network attack paths, the risk score representing a degree to which a network attack path may be used to exploit the one or more security vulnerabilities of the network resources in the set of network resources;

storing the risk score for each of the one or more network attack paths in at least one table; and

outputting a ranking of the one or more network attack paths based on their respective risk scores.

7. The method of claim 1 , wherein generating the plurality of network paths comprises applying a graph traversal technique to data stored in the first relational representation.

8. The method of claim 7 , wherein applying the graph traversal technique comprises performing a breadth first search, a depth first search, or a combination of breadth first search and depth first search.

9. The method of claim 1 , wherein a first network path of the plurality of network paths comprises a first network resource in the set of network resources, the one or more security vulnerabilities comprise a first security vulnerability, the method further comprising:

determining that at least one portion of the first relational representation corresponding to the first network resource conforms to a network attack path definition defining the first security vulnerability; and

identifying the first network resource to have the first security vulnerability based on the at least one portion of the first relational representation conforming to the network attack path definition.

10. The method of claim 1 , further comprising:

determining that a network resource in the plurality of network resources is a vulnerable network resource based on the network resource having at least one security vulnerability;

determining that one or more network resources in the set of network resources have a respective network connection to the vulnerable network resource; and

identifying the one or more network resources as exploitable network resources based on the one or more network resources having the respective network connection to the vulnerable network resource.

11. A network attack path identification system comprising:

at least one non-transitory computer readable storage medium storing instructions; and

at least one computer hardware processor to execute the instructions to perform a method for identifying exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

obtaining metadata indicating a set of network resources in the plurality of network resources and network connections among network resources in the set of network resources;

generating, using the metadata, a first relational representation of the set of network resources, the first relational representation comprising at least one network connection table indicating network resources in the set of network resources and network connections among the network resources in the set of network resources;

generating, using the first relational representation, a second relational representation of a plurality of network paths, the second relational representation comprising at least one network path table indicating the plurality of network paths between network resources in the set of network resources, at least one of the plurality of network paths comprising one or more of the set of network resources between a pair of the set of the network resources; and

identifying, from among the plurality of network paths and using the second relational representation and information indicating one or more of the plurality of network resources that have at least one respective security vulnerability, one or more network attack paths that may be used to exploit one or more security vulnerabilities of network resources in the set of network resources.

12. The network attack path identification system of claim 11 , wherein the metadata contains information indicating values of attributes of individual network resources in the set of network resources, information indicating values of attributes of the network connections among the network resources in the set of network resources, and information indicating values of attributes of the plurality of network paths, the at least one computer hardware processor is to:

generate at least one network resource table using the information indicating the values of attributes of the individual network resources in the set of network resources; and

generate the at least one network connection table using the information indicating the values of attributes of the network connections among the network resources in the set of network resources; wherein

generating the second relational representation comprises generating the at least one network path table using the information indicating the values of attributes of the plurality of network paths; and the at least one computer hardware processor is to:

store the at least one network resource table, the at least one network connection table, and the at least one network path table in at least one datastore.

13. The network attack path identification system of claim 11 , wherein the at least one computer hardware processor is to:

after identifying the one or more network attack paths, generate at least one network attack path table storing information specifying the one or more network attack paths; and

cause storage of the at least one network attack path table in at least one datastore.

14. The network attack path identification system of claim 11 , wherein the at least one computer hardware processor is to:

generate a risk score for each of the one or more network attack paths, the risk score representing a degree to which a network attack path may be used to exploit the one or more security vulnerabilities of the network resources in the set of network resources;

cause storage of the risk score for each of the one or more network attack paths in at least one table; and

output a ranking of the one or more network attack paths based on their respective risk scores.

15. The network attack path identification system of claim 11 , wherein a first network path of the plurality of network paths comprises a first network resource in the set of network resources, the one or more security vulnerabilities comprise a first security vulnerability, the at least one computer hardware processor is to:

determine that at least one portion of the first relational representation corresponding to the first network resource conforms to a network attack path definition defining the first security vulnerability; and

identify the first network resource to have the first security vulnerability based on the at least one portion of the first relational representation conforming to the network attack path definition.

16. At least one non-transitory computer readable storage medium comprising instructions that, when executed by at least one computer hardware processor, causes the at least one computer hardware processor to perform a method for identifying exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

obtaining metadata indicating a set of network resources in the plurality of network resources and network connections among network resources in the set of network resources;

generating, using the metadata, a first relational representation of the set of network resources, the first relational representation comprising at least one network connection table indicating network resources in the set of network resources and network connections among the network resources in the set of network resources;

generating, using the first relational representation, a second relational representation of a plurality of network paths, the second relational representation comprising at least one network path table indicating the plurality of network paths between network resources in the set of network resources, at least one of the plurality of network paths comprising one or more of the set of network resources between a pair of the set of the network resources; and

identifying, from among the plurality of network paths and using the second relational representation and information indicating one or more of the plurality of network resources that have at least one respective security vulnerability, one or more network attack paths that may be used to exploit one or more security vulnerabilities of network resources in the set of network resources.

17. The at least one non-transitory computer readable storage medium of claim 16 , wherein the metadata contains information indicating values of attributes of individual network resources in the set of network resources, information indicating values of attributes of the network connections among the network resources in the set of network resources, and information indicating values of attributes of the plurality of network paths, the instructions to cause the at least one computer hardware processor to:

generate at least one network resource table using the information indicating the values of attributes of the individual network resources in the set of network resources; and

generate the at least one network connection table using the information indicating the values of attributes of the network connections among the network resources in the set of network resources; wherein

generating the second relational representation comprises generating the at least one network path table using the information indicating the values of attributes of the plurality of network paths; and the instructions further cause the at least one computer hardware processor to:

store the at least one network resource table, the at least one network connection table, and the at least one network path table in at least one datastore.

18. The at least one non-transitory computer readable storage medium of claim 16 , wherein the instructions cause the at least one computer hardware processor to:

after identifying the one or more network attack paths, generate at least one network attack path table storing information specifying the one or more network attack paths; and

cause storage of the at least one network attack path table in at least one datastore.

19. The at least one non-transitory computer readable storage medium of claim 16 , wherein the instructions cause the at least one computer hardware processor to:

generate a risk score for each of the one or more network attack paths, the risk score representing a degree to which a network attack path may be used to exploit the one or more security vulnerabilities of the network resources in the set of network resources;

cause storage of the risk score for each of the one or more network attack paths in at least one table; and

output a ranking of the one or more network attack paths based on their respective risk scores.

20. The at least one non-transitory computer readable storage medium of claim 16 , wherein a first network path of the plurality of network paths comprises a first network resource in the set of network resources, the one or more security vulnerabilities comprise a first security vulnerability, the instructions to cause the at least one computer hardware processor to:

determine that at least one portion of the first relational representation corresponding to the first network resource conforms to a network attack path definition defining the first security vulnerability; and

identify the first network resource to have the first security vulnerability based on the at least one portion of the first relational representation conforming to the network attack path definition.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2024
From: LEE, AUSTIN; KOMAROV, VAL; LEDEZMA, MIGUEL
To: RAPID7, INC.
Reel/Frame 068382/0688 →
Continuity (1)
Related Publication 20250112948A1 · Apr 3, 2025
References Cited (26)
US 11575696B1 · Ithal · 2023 [cited by examiner]
US 20230179623A1 · Moolchandani · 2023 [cited by examiner]
US 20240054227A1 · Dahmen · 2024 [cited by examiner]
[No Author Listed], Amazon S3 Access Points can now be used to securely delegate access permissions for shared datasets to other AWS accounts. Nov. 30, 2022. 3 pages. https://aws.amazon.com/about-aws/whats-new/2022/11/a… [cited by applicant]
[No Author Listed], A confused deputy vulnerability in AWS AppSync. Datadog Security Labs. Nov. 21, 2022. 13 pages. https://securitylabs.datadoghq.com/articles/appsync-vulnerability-disclosure/ (Last accessed Sep. 29, 2… [cited by applicant]
[No Author Listed], GruCloud. Publicly available at least as early as Sep. 29, 2023. 4 pages. https://www.grucloud.com/ (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Lateral Movement. Mitre ATT&CK. Oct. 17, 2018. 6 pages. https://attack.mitre.org/tactics/TA0008/ (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], External memory graph traversal. Wikipedia. Jan. 30, 2023. 4 pages. https://en.wikipedia.org/wiki/External_memory_graph_traversal (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Graph traversal. Wikipedia. Jul. 23, 2023. 4 pages. https://en.wikipedia.org/wiki/Graph_traversal (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Iterative deepening depth-first search. Wikipedia. Sep. 11, 2023. 7 pages. https://en.wikipedia.org/wiki/Iterative_deepening_depth-first_search (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Intro to Content-Defined Chunking. Joshleeb Blog. Mar. 4, 2023. 7 pages. https://joshleeb.com/posts/content-defined-chunking.html (Last accessed Sep. 29, 2023). [cited by applicant]
Aksoy et al., Directional Laplacian centrality for cyber situational awareness. Digital Threats: Research and Practice (DTRAP). Oct. 15, 2021;2(4):1-28. [cited by applicant]
Chen, IAM-Deescalate: An Open Source Tool to Help Users Reduce the Risk of Privilege Escalation. Unit 42. Jul. 25, 2022. 12 pages. https://unit42.paloaltonetworks.com/iam-deescalate/ (Last accessed Sep. 29, 2023). [cited by applicant]
Costica, A new vision for cloud security unites builders and defenders. Wiz Blog. Jun. 7, 2022. 8 pages. https://www.wiz.io/blog/uniting-builders-and-defenders-a-new-vision-for-cloud-security (Last accessed Sep. 29, 202… [cited by applicant]
Curwin et al., Identify and remediate attack paths. Microsoft Azure Defender for Cloud. Aug. 10, 2023. 9 pages. https://learn.microsoft.com/en-US/azure/defender-for-cloud/how-to-manage-attack-path (Last accessed Sep. 29… [cited by applicant]
Curwin et al., Reference list of attack paths and cloud security graph components. Microsoft Azure Defender for Cloud. Sep. 5, 2023. https://learn.microsoft.com/en-US/azure/defender-for-cloud/attack-path-reference (Last… [cited by applicant]
Fan et al., The Case Against Specialized Graph Analytics Engines. CIDR. Jan. 4, 2015. 10 pages. [cited by applicant]
Hagberg et al., Exploring network structure, dynamics, and function using NetworkX. Proceedings of the 7 [cited by applicant]
Haque, Using GraphQL with Python—A Complete Guide. Apollo Blog. May 11, 2021. 34 pages. https://www.apollographql.com/blog/graphql/python/complete-api-guide/ (Last accessed Sep. 29, 2023). [cited by applicant]
Kedrosky, Real Life Examples of AWS and Azure Privilege Escalation. Sonrai Security. Aug. 24, 2022. 11 pages. https://sonraisecurity.com/blog/real-life-examples-of-privilege-escalation-in-aws-and-azure/ (Last accessed S… [cited by applicant]
Maor, Understanding Attack Paths and Attack Path Analysis in a Stateful Cloud Environment Graph. Lightspin. Jun. 30, 2021. 9 pages. https://blog.lightspin.io/attack-vector-vs-attack-path-in-security-risk-analysis (Last … [cited by applicant]
Perotti, AWS IAM Exploitation. Security Risk Advisors. Apr. 29, 2019. 26 pages. https://sra.io/blog/aws-iam-exploitation/ (Last accessed Sep. 29, 2023). [cited by applicant]
Pisha, Wiz becomes the first CNAPP to deliver integrated Data Security Posture Management. Wiz Blog. Nov. 21, 2022. 9 pages. https://www.wiz.io/blog/wiz-becomes-first-cnapp-to-deliver-integrated-data-security-posture-ma… [cited by applicant]
Robbins, Managed Identity Attack Paths, Part 1: Automation Accounts. Medium. Jun. 6, 2022. 26 pages. https://posts.specterops.io/managed-identity-attack-paths-part-1-automation-accounts-82667d17187a (Last accessed Sep. … [cited by applicant]
Sonntag, Lateral movement risks in the cloud and how to prevent them—Part 1: the network layer (VPC). Wiz Blog. Oct. 13, 2022. 11 pages. https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-the… [cited by applicant]
Xu, Graph Databases Burst into the Mainstream. KD Nuggets. 2018. 8 pages. https://www.kdnuggets.com/2018/02/graph-databases-burst-into-the-mainstream.html (Last accessed Sep. 29, 2023). [cited by applicant]