IP Library Granted Patent US 12,726,503
Granted Patent B2
US 12,726,503 · App. 18/782,843 · Granted Sep 1, 2026

System and method for emulating a multi-stage attack on a node within a target network

Inventors: Rajesh Sharma (San Diego, CA); Jeremy Miller (San Diego, CA); Stephan Chenette (San Diego, CA); Albert Lopez (San Diego, CA); Shubhi Mittal (San Diego, CA); Andres Gazzoli (San Diego, CA)
Assignee: AttackIQ, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,503
App. No.
18/782,843
Granted
Sep 1, 2026
Kind
B2
Abstract

A method includes: accessing an attack record defining actions representing a previous known attack on a second computer network; initializing an attack graph; for each action, defining a set of behaviors—analogous to the action and executable by an asset on a target network to emulate an effect of the action on the second computer network—and storing the set of behaviors in a node in the attack graph; connecting nodes in the attack graph according to an order of actions in the known attack; scheduling the asset to selectively execute analogous behaviors stored in the set of nodes in the attack graph; accessing alerts generated by a set of security tools deployed on the target network; and characterizing vulnerability of the target network based on alerts, in the set of alerts, indicating detection and prevention of behaviors executed by the asset according to the attack graph.

Claims (105)

1 . A method comprising:

accessing an attack graph comprising a set of nodes connected according to a sequence of actions, executed on a machine in a second computer network, representing a known attack on the second computer network, each node in the set of nodes:

corresponding to an action in the sequence of actions; and

storing a set of behaviors analogous to the action and executable by a target asset to emulate an effect of the action on the machine in the second computer network;

scheduling the target asset connected to a target network to automatically execute analogous behaviors stored in the set of nodes in the attack graph;

accessing a set of alerts generated by a set of security tools deployed on the target network; and

characterizing a vulnerability of the target network based on presence of alerts in the set of alerts indicating detection and prevention of analogous behaviors executed by the target asset.

2 . The method of claim 1 :

wherein accessing the attack graph comprises accessing the attack graph comprising the set of nodes, each node in the set of nodes storing the set of behaviors comprising:

a nominal behavior executable by the target asset to emulate the action; and

a set of alternative behaviors analogous to the nominal behavior and executable by the target asset to emulate an effect of the action; and

wherein scheduling the first asset comprises scheduling the target asset to automatically execute nominal behaviors and alternative behaviors stored in the set of nodes in the attack graph.

3 . The method of claim 1 , further comprising:

accessing an attack record defining the sequence of actions executed on the machine; and

for a first action in the sequence of actions:

based on the attack record, deriving a first effect of the first action on the machine in the second computer network;

based on the attack record, defining a first nominal behavior:

representing the first action executed on the machine during the known attack; and

executable by the target asset to emulate the first action;

defining a first set of alternative behaviors:

analogous to the first nominal behavior; and

executable by the target asset to emulate the first effect at the target asset; and

storing the first nominal behavior and the first set of alternative behaviors in a first node in the set of nodes in the attack graph.

4 . The method of claim 1 , further comprising:

accessing an attack record defining:

the sequence of actions executed on the machine; and

a second sequence of actions executed on a second machine on the second computer network during the known attack on the second computer network;

initializing a second attack graph comprising a second set of nodes;

for each action in the second sequence of actions:

based on the attack record, deriving an effect of the action on the second machine in the second computer network;

based on the attack record, defining a set of behaviors analogous to the action and executable by a second asset to emulate the effect of the action on the second machine in the second computer network: and

storing the set of behaviors according in a node in the second set of nodes in the second attack graph;

connecting the second set of nodes in the second attack graph according to the second sequence of actions by the second machine during known attack; and

scheduling the second asset connected to the target network to execute nominal behaviors and alternative behaviors stored in the second set of nodes in the second attack graph.

5 . The method of claim 1 , wherein accessing the attack graph comprises accessing the attack graph comprising the set of nodes comprising a first node:

corresponding to a first action in the sequence of actions;

storing a first nominal behavior executable by the target asset to emulate the first action;

storing a first set of alternative behaviors analogous to the first nominal behavior and executable by the target asset to emulate a transition from a first start condition, at the machine prior to start of the first action, to a first end condition at the machine following completion of the first action; and

storing a first reversing behavior executable by the target asset to transition from the first end condition to the first start condition.

6 . The method of claim 1 , wherein accessing the attack graph comprises accessing the attack graph comprising the set of nodes comprising a first node:

corresponding to a first action in the sequence of actions;

storing a first nominal behavior executable by the target asset to emulate the first action, the first nominal behavior prescribing a first nominal technique and a first nominal procedure; and

storing a first set of alternative behaviors analogous to the first nominal behavior and executable by the target asset to emulate a first effect of the first action, the first set of alternative behaviors comprising a second alternative behavior prescribing the first nominal technique and a second procedure different from the first nominal procedure.

7 . The method of claim 6 , wherein scheduling the target asset comprises scheduling the target asset to execute a script that emulates the first effect of the first action according to the first nominal technique and the second alternative procedure prescribed by the second alternative behavior.

8 . The method of claim 1 :

further comprising, for a first action in the sequence of actions:

defining a first target hierarchy for a first set of behaviors analogous to the first action and executable by the target asset to emulate a first effect of the first action; and

storing the first set of behaviors according to the first target hierarchy in a first node in the set of nodes in the attack graph; and

wherein scheduling the target asset comprises scheduling the target asset on the target network to execute analogous behaviors according to target hierarchies stored in the set of nodes in the attack graph.

9 . The method of claim 8 , wherein defining the first target hierarchy comprises defining the first target hierarchy specifying:

attempted execution, by the target asset, of a first nominal script executable by the target asset to emulate the first action; and

attempted execution, by the target asset responsive to failed execution of the first nominal script, of a second alternative script executable by the target asset to emulate the first effect of the first action.

10 . The method of claim 8 , further comprising, by the target asset:

executing a first nominal script that emulates the first action at a first time according to the first target hierarchy; and

in response to detecting failed execution of the first nominal script, executing a second alternative script that emulates the first effect of the first action at a second time succeeding the first time according to the first target hierarchy.

11 . The method of claim 1 , further comprising, by the target asset:

executing analogous behaviors stored in a first subset of nodes in the attack graph; and

executing reversing behaviors stored in a second subset of nodes in the attack graph.

12 . The method of claim 1 :

wherein accessing the set of alerts comprises accessing a set of detection alerts indicating detection of behaviors occurring on the target network by the set of security tools; and

wherein characterizing the vulnerability of the target network comprises:

scanning the set of detection alerts for a target detection alert corresponding to a target behavior, stored in a node in the set of nodes in the attack graph, attempted by the target asset; and

characterizing the target network as vulnerable in response to absence of the target detection alert in the set of detection alerts.

13 . The method of claim 1 , wherein characterizing the vulnerability of the target network comprises:

correlating a subset of alerts in the set of alerts with behaviors executed by the target asset according to the attack graph; and

calculating the vulnerability of the target network based on a quantity of alerts in the subset of alerts.

14 . The method of claim 1 , further comprising, in response to characterizing the vulnerability of the target network greater than a threshold vulnerability:

scheduling a second asset connected to the target network to execute analogous behaviors stored in the set of nodes in the attack graph, the second asset distinct from the target asset;

accessing a second set of alerts generated by the set of security tools deployed on the target network; and

characterizing a scope of the vulnerability of the target network based on presence of alerts in the second set of alerts indicating detection and prevention of analogous behaviors, stored in nodes in the attack graph, executed by the second asset.

15 . A method comprising:

accessing an attack record defining a sequence of actions executed on a machine in a second computer network;

for each action in the sequence of actions:

based on the attack record, deriving an effect of the action on the machine in the second computer network;

based on the attack record, defining a set of behaviors analogous to the action and executable by a target asset to emulate the effect of the action on the machine in the second computer network; and

storing the set of behaviors in a node in a set of nodes in an attack graph;

connecting the set of nodes in the attack graph according to the sequence of actions representing a known attack on the second computer network; and

scheduling the target asset connected to a target network to automatically execute analogous behaviors stored in the set of nodes in the attack graph.

16 . The method of claim 15 , further comprising:

accessing a set of alerts generated by a set of security tools deployed on the target network; and

characterizing a vulnerability of the target network based on presence of alerts in the set of alerts indicating detection and prevention of analogous behaviors executed by the target asset.

17 . The method of claim 15 , wherein deriving the effect of the action, defining the set of behaviors, and storing the set of behaviors for each action in the sequence of actions comprises, for a first action in the sequence of actions:

based on the attack record, deriving a first effect of the first action on the machine in the second computer network;

based on the attack record, defining a first nominal behavior:

representing the first action executed on the machine during the known attack; and

executable by the target asset to emulate the first action;

defining a first set of alternative behaviors:

analogous to the first nominal behavior; and

executable by the target asset to emulate the first effect at the target asset; and

storing the first nominal behavior and the first set of alternative behaviors in a first node in the set of nodes in the attack graph.

18 . The method of claim 17 , wherein storing the first nominal behavior and the first set of alternative behaviors comprises storing the first set of alternative behaviors executable by the target asset to emulate a transition from a first start condition, at the machine prior to start of the first action, to a first end condition at the machine following completion of the first action.

19 . A method comprising:

scheduling a target asset connected to a target network to automatically execute analogous behaviors stored in an attack graph comprising a set of nodes connected according to a sequence of actions representing a known attack on a second computer network, each node in the set of nodes:

corresponding to an action in the sequence of actions; and

storing a set of behaviors analogous to the action and executable by the target asset to emulate an effect of the action on a machine in the second computer network; and

characterizing a vulnerability of the target network based on presence of alerts in a set of alerts, generated by a set of security tools deployed on the target network, indicating detection and prevention of analogous behaviors executed by the target asset.

20 . The method of claim 19 , further comprising, for a first action in the sequence of actions:

based on an attack record defining the sequence of actions executed on the machine, deriving a first effect of the first action on the machine in the second computer network;

based on the attack record, defining a first nominal behavior:

representing the first action executed on the machine during the known attack; and

executable by the target asset to emulate the first action;

defining a first set of alternative behaviors:

analogous to the first nominal behavior; and

executable by the target asset to emulate the first effect at the target asset; and

storing the first nominal behavior and the first set of alternative behaviors in a first node in the set of nodes in the attack graph.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: GAZZOLI, ANDRES; SHARMA, RAJESH; MILLER, JEREMY; CHENETTE, STEPHAN; LOPEZ, ALBERT; MITTAL, SHUBHI
To: ATTACKIQ, INC.
Reel/Frame 068299/0046 →
Continuity (6)
Continuation 18141888 · May 1, 2023
Continuation 17832106 · Jun 3, 2022
Continuation In Part 17083275 · Oct 28, 2020
Provisional Application 63196320 · Jun 3, 2021
Provisional Application 63008451 · Apr 10, 2020
Related Publication 20240380778A1 · Nov 14, 2024
References Cited (77)
US 6907396B1 · Muttik · 2005 [cited by examiner]
US 7904962B1 · Jajodia · 2011 [cited by examiner]
US 9886581B2 · Olson · 2018 [cited by examiner]
US 9892260B2 · Kotler · 2018 [cited by examiner]
US 9990499B2 · Chan · 2018 [cited by examiner]
US 10200259B1 · Pukish · 2019 [cited by examiner]
US 10313382B2 · Noel · 2019 [cited by examiner]
US 10425429B2 · Bassett · 2019 [cited by examiner]
US 10855715B2 · Martin · 2020 [cited by examiner]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 11336669B2 · Bazalgette · 2022 [cited by examiner]
US 11444974B1 · Shakhzadyan · 2022 [cited by examiner]
US 20040083129A1 · Herz · 2004 [cited by examiner]
US 20060053490A1 · Herz · 2006 [cited by examiner]
US 20070011319A1 · McClure · 2007 [cited by examiner]
US 20080271146A1 · Rooney · 2008 [cited by examiner]
US 20090007270A1 · Futoransky · 2009 [cited by examiner]
US 20090320137A1 · White · 2009 [cited by examiner]
US 20100074141A1 · Nguyen · 2010 [cited by examiner]
US 20100138925A1 · Barai · 2010 [cited by examiner]
US 20110023118A1 · Wright · 2011 [cited by examiner]
US 20120151596A1 · McClure · 2012 [cited by examiner]
US 20140033310A1 · Cheng · 2014 [cited by examiner]
US 20140237599A1 · Gertner · 2014 [cited by examiner]
US 20140325634A1 · Iekel-Johnson · 2014 [cited by examiner]
US 20150020199A1 · Neil · 2015 [cited by examiner]
US 20150106324A1 · Puri · 2015 [cited by examiner]
US 20150128246A1 · Feghali · 2015 [cited by examiner]
US 20150188935A1 · Vasseur · 2015 [cited by examiner]
US 20150244734A1 · Olson · 2015 [cited by examiner]
US 20150295948A1 · Hassell · 2015 [cited by examiner]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20160261631A1 · Vissamsetty · 2016 [cited by examiner]
US 20160308895A1 · Kotler · 2016 [cited by examiner]
US 20170006055A1 · Strom · 2017 [cited by examiner]
US 20170126712A1 · Crabtree · 2017 [cited by examiner]
US 20170171230A1 · Leiderfarb · 2017 [cited by examiner]
US 20170220964A1 · Datta Ray · 2017 [cited by examiner]
US 20170223046A1 · Singh · 2017 [cited by examiner]
US 20170223052A1 · Stutz · 2017 [cited by examiner]
US 20170279832A1 · Di Pietro · 2017 [cited by examiner]
US 20170289187A1 · Noel · 2017 [cited by examiner]
US 20170310703A1 · Ackerman · 2017 [cited by examiner]
US 20180004942A1 · Martin · 2018 [cited by examiner]
US 20180103052A1 · Choudhury · 2018 [cited by examiner]
US 20180152468A1 · Nor · 2018 [cited by examiner]
US 20180309779A1 · Benyo · 2018 [cited by examiner]
US 20190158520A1 · DiValentin · 2019 [cited by examiner]
US 20190245883A1 · Gorodissky · 2019 [cited by examiner]
US 20190258953A1 · Lang · 2019 [cited by examiner]
US 20190319974A1 · Hasumi · 2019 [cited by examiner]
US 20200067969A1 · Abbaszadeh · 2020 [cited by examiner]
US 20200128047A1 · Biswas · 2020 [cited by examiner]
US 20200177616A1 · Hadar · 2020 [cited by examiner]
US 20200244673A1 · Stockdale · 2020 [cited by examiner]
US 20200280577A1 · Segal · 2020 [cited by examiner]
US 20200314141A1 · Vajipayajula · 2020 [cited by examiner]
US 20200358805A1 · Segal · 2020 [cited by examiner]
US 20200410092A1 · Mishra · 2020 [cited by examiner]
US 20200412767A1 · Crabtree · 2020 [cited by examiner]
US 20210006582A1 · Yamada · 2021 [cited by examiner]
US 20210064762A1 · Salji · 2021 [cited by examiner]
US 20210105294A1 · Kruse · 2021 [cited by examiner]
US 20210144159A1 · Sanghvi · 2021 [cited by examiner]
US 20210194905A1 · Fong · 2021 [cited by examiner]
US 20210194924A1 · Heinemeyer · 2021 [cited by examiner]
US 20210203686A1 · Kazato · 2021 [cited by examiner]
US 20210258334A1 · Sayag · 2021 [cited by examiner]
US 20210314341A1 · Moskovich · 2021 [cited by examiner]
US 20220060498A1 · Head, Jr. · 2022 [cited by examiner]
US 20220078210A1 · Crabtree · 2022 [cited by examiner]
US 20220182406A1 · Inokuchi · 2022 [cited by examiner]
US 20220400130A1 · Kapoor · 2022 [cited by examiner]
US 20230018096A1 · Ueda · 2023 [cited by examiner]
US 20230308472A1 · Boyer · 2023 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]