IP Library › Granted Patent US 12,732,526
Granted Patent B2
US 12,732,526 · App. 18/762,162 · Granted Sep 8, 2026

Optimizing networks microsegmentation policy for cyber resilience

Inventors: Steven Earl Noel (Woodbridge, VA); Vipin Swarup (McLean, VA); Karin Luisa Johnsgard (Street, MD)
Assignee: The MITRE Corporation
H04L63/1433H04L63/1416H04L63/145H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,526
App. No.
18/762,162
Granted
Sep 8, 2026
Kind
B2
Abstract

Described herein is a system and method for improving cyber resilience for determining an optimal security policy for a network. The system uses an objective function to balance cyberattack risks, accessibility to network resources, resource limitations, minimum mission availability requirements within a network environment, or a combination thereof. The objective function comprises objectives (one or more variables that enhance accessibility to network resources and reduce cyberattack risks) and constraints (one or more variables that characterize resource limitations or minimum mission availability requirements within a network environment). The optimal security policy is selected by solving one or more optimization problems. The optimization problem may be solved by determining candidate security policies that meet the constraints and selecting among candidate security policies having the highest score for a given objective function.

Claims (50)

1 . A method for providing a security access-control policy to a network, the method comprising:

defining a model representing an accessibility of an attacker within the network, one or more availability needs of the network, and candidate security policy rules for the network;

determining one or more constraints associated with at least one of: (a) one or more resource limitations of the network and (b) one or more minimum availability requirements for the network;

determining, based on the model, a plurality of candidate security policies that meet the one or more constraints, and

selecting the security access-control policy from the plurality of candidate security policies based on one or more objectives associated with at least one of: accessibility to network resources and reduction of cyberattack risks.

2 . The method of claim 1 , wherein the accessibility of an attacker within the network, the one or more availability needs of the network, and the candidate security policy rules for the network are represented by an attack matrix, a mission matrix, and a policy rule matrix respectively.

3 . The method of claim 2 , wherein determining, based on the model, the plurality of candidate security policies comprises finding paths in the attack matrix and corresponding paths in the mission matrix.

4 . The method of claim 2 , wherein the one or more objectives comprise minimizing a total weight of one or more blocked mission edges between host pairs in the mission matrix.

5 . The method of claim 1 , wherein the one or more objectives comprise minimizing a number of blocked edges in the model.

6 . The method of claim 1 , wherein selecting the security access-control policy from the plurality of candidate security policies comprises:

forming an optimization problem using the one or more objectives and the one or more constraints; and

solving the optimization problem at least in part by:

determining a score for each candidate security policy in the plurality of candidate security policies in meeting the one or more objectives, and

selecting the security access-control policy from the plurality of candidate security policies based on the score.

7 . The method of claim 6 , wherein defining the model comprises:

determining a hardened attack matrix by applying a policy rule matrix to an attack matrix;

determining a hardened mission matrix by applying the policy rule matrix to a mission matrix,

wherein the optimization problem is formed using the hardened attack matrix and the hardened mission matrix.

8 . The method of claim 6 , further comprising:

forming an additional optimization problem using one or more additional constraints and/or objectives, wherein the one or more additional constraints and/or objectives comprise a constraint or an objective to keep a mission impact within a predetermined budget.

9 . The method of claim 6 , further comprising:

forming an additional optimization problem using an objective to maximize a number of blocked shortest attack paths in the attack matrix.

10 . The method of claim 9 , wherein the blocked shortest attack paths are from one or more attack start hosts to one or more attack goal hosts.

11 . A system for providing a security access-control policy to a network, the system comprising:

one or more processors;

memory; and

instructions stored in the memory which, when executed by the one or more processors, cause the system to:

define a model representing an accessibility of an attacker within the network, one or more availability needs of the network, and candidate security policy rules for the network;

determine one or more constraints associated with at least one of: (a) resource limitations of the network and (b) minimum availability requirements for the network;

determine, based on the model, a plurality of candidate security policies that meet the one or more constraints, and

select the security access-control policy from the plurality of candidate security policies based on one or more objectives associated with at least one of:

accessibility to network resources and reduction of cyberattack risks.

12 . The system of claim 11 , wherein the accessibility of an attacker within the network, the one or more availability needs of the network, and the candidate security policy rules for the network are represented by an attack matrix, a mission matrix, and a policy rule matrix respectively.

13 . The system of claim 12 , wherein determining, based on the model, the plurality of candidate security policies comprises finding paths in the attack matrix and corresponding paths in the mission matrix.

14 . The system of claim 12 , wherein the one or more objectives comprise minimizing a total weight of one or more blocked mission edges between host pairs in the mission matrix.

15 . The system of claim 11 , wherein the one or more objectives comprise minimizing a number of blocked edges in the model.

16 . The system of claim 11 , wherein selecting the security access-control policy from the plurality of candidate security policies comprises:

forming an optimization problem using the one or more objectives and the one or more constraints; and

solving the optimization problem at least in part by:

determining a score for each candidate security policy in the plurality of candidate security policies in meeting the one or more objectives, and

selecting the security access-control policy from the plurality of candidate security policies based on the score.

17 . The system of claim 16 , wherein defining the model comprises:

determining a hardened attack matrix by applying a policy rule matrix to an attack matrix;

determining a hardened mission matrix by applying the policy rule matrix to a mission matrix,

wherein the optimization problem is formed using the hardened attack matrix and the hardened mission matrix.

18 . The system of claim 16 , wherein the system is further caused to:

form an additional optimization problem using one or more additional constraints and/or objectives, wherein the one or more additional constraints and/or objectives comprise a constraint or an objective to keep a mission impact within a predetermined budget.

19 . The system of claim 16 , wherein the system is further caused to:

form an additional optimization problem using an objective to maximize a number of blocked shortest attack paths in the attack matrix.

20 . The system of claim 19 , wherein the blocked shortest attack paths are from one or more attack start hosts to one or more attack goal hosts.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2024
From: NOEL, STEVEN EARL; SWARUP, VIPIN; JOHNSGARD, KARIN LUISA
To: THE MITRE CORPORATION
Reel/Frame 068288/0739 →
Continuity (2)
Continuation 17474464 · Sep 14, 2021
Related Publication 20240356961A1 · Oct 24, 2024
References Cited (46)
US 8209738B2 · Nicol · 2012 [cited by examiner]
US 8479266B1 · Delker et al. · 2013 [cited by applicant]
US 8584194B1 · Kerr · 2013 [cited by examiner]
US 8799985B2 · Vinberg · 2014 [cited by examiner]
US 9218502B1 · Doermann et al. · 2015 [cited by applicant]
US 9438634B1 · Ross et al. · 2016 [cited by applicant]
US 10009383B2 · Woolward · 2018 [cited by applicant]
US 10298619B2 · Nimmagadda et al. · 2019 [cited by applicant]
US 10375121B2 · Hamou et al. · 2019 [cited by applicant]
US 11689567B2 · Gadhe · 2023 [cited by examiner]
US 12034758B2 · Noel · 2024 [cited by examiner]
US 12341795B2 · Fellows · 2025 [cited by examiner]
US 12452245B1 · Gacek · 2025 [cited by examiner]
US 20090199293A1 · Song et al. · 2009 [cited by applicant]
US 20090271862A1 · Allen · 2009 [cited by applicant]
US 20120084866A1 · Stolfo · 2012 [cited by examiner]
US 20130091539A1 · Khurana · 2013 [cited by examiner]
US 20160072899A1 · Tung et al. · 2016 [cited by applicant]
US 20160359913A1 · Gupta et al. · 2016 [cited by applicant]
US 20180139225A1 · Zhou · 2018 [cited by applicant]
US 20180139241A1 · Jacobsen · 2018 [cited by examiner]
US 20190081873A1 · Kraft · 2019 [cited by examiner]
US 20190312910A1 · Convertino et al. · 2019 [cited by applicant]
US 20200404010A1 · Costante · 2020 [cited by examiner]
US 20210185077A1 · Shavlik · 2021 [cited by applicant]
US 20210352107A1 · Monni et al. · 2021 [cited by applicant]
US 20220377103A1 · Shaw · 2022 [cited by examiner]
US 20230085509A1 · Noel · 2023 [cited by examiner]
US 20230115982A1 · Lin et al. · 2023 [cited by applicant]
US 20230139089A1 · Park · 2023 [cited by applicant]
US 20230300032A1 · Noel et al. · 2023 [cited by applicant]
US 20250294048A1 · Jin · 2025 [cited by examiner]
US 20260056514A1 · Mitchell · 2026 [cited by examiner]
CN 108898010A · 2018 [cited by examiner]
CN 108924169A · 2018 [cited by examiner]
CN 113992355A · 2022 [cited by examiner]
CN 116962076A · 2023 [cited by examiner]
CN 118018278A · 2024 [cited by examiner]
CN 120151035A · 2025 [cited by examiner]
CN 120512278A · 2025 [cited by examiner]
CN 120825344A · 2025 [cited by examiner]
CN 121485956A · 2026 [cited by examiner]
Jin, Zhao-yan. English translation of CN 113992355 A. (Year: 2022). [cited by examiner]
Koskinen, J. (2020). Microsegmentation as part of organization's network architecture, Investigating VMware NSX for vSphere. JAMK University of Applied Sciences., pp. 1-89. [cited by applicant]
Noel et al., U.S. Office Action dated Oct. 12, 2023 directed to U.S. Appl. No. 17/474,464; 7 pages. [cited by applicant]
Yousefi-Azar et al. “Unsupervised Learning for security of Enterprise networks by micro-segmentation,” Cyber Defence Next Generation Technology and Science Conference, Jul. 2020, Brisbane, Queensland, Australia; pp. 1-3. [cited by applicant]