ATTACK PATH MONITORING AND RISK MITIGATION IN IDENTITY SYSTEMS
A method includes identifying, by at least one processing device, a set of attack paths within a computing environment, each attack path connecting a source object to a target object through one or more control relationships having respective control relationship costs, wherein each cost indicates the difficulty for an attacker to progress from a first object to a second object via the associated control relationship. The method further includes determining, for each attack path based on the control relationship costs, a respective attack path cost, and determining, for each attack path based at least in part on the attack path costs, a respective attack path risk metric, wherein a lower attack path cost corresponds to a higher attack path risk metric. The method also includes performing attack path risk mitigation based on the attack path risk metrics.
1 . A method comprising:
identifying, by at least one processing device, a set of attack paths within a computing environment, each attack path of the set of attack paths connecting a source object to a target object through one or more control relationships associated with one or more respective control relationship costs, wherein each of the one or more respective control relationship costs is indicative of a cost for an attacker to progress from a first object to a second object via its associated control relationship;
determining, by the at least one processing device and for each attack path of the set of attack paths based on the one or more respective control relationship costs, a respective attack path cost of a set of attack path costs;
determining, by the at least one processing device and for each attack path of the set of attack paths based at least in part on the set of attack path costs, a respective attack path risk metric of a set of attack path risk metrics, wherein a lower attack path cost of the set of attack path costs corresponds to a higher attack path risk metric of the set of attack path risk metrics; and
performing, by the at least one processing device, attack path risk mitigation based on the set of attack path risk metrics.
2 . The method of claim 1 , wherein each of the one or more respective control relationship costs is determined based on at least one of: difficulty of traversal via its associated control relationship, observability of traversal via its associated control relationship, or one or more artifacts generated by traversal via its associated control relationship.
3 . The method of claim 2 , wherein the difficulty of traversal comprises at least one of: ease of exploitation or a number of extra steps for exploitation.
4 . The method of claim 2 , wherein the observability of traversal is determined based on a number of changes or artifacts generated for traversal via its associated control relationship.
5 . The method of claim 2 , wherein the one or more artifacts comprise at least one of: one or more event logs or metadata tracking object changes.
6 . The method of claim 1 , wherein the respective attack path cost for each attack path is determined as a cumulative cost of the one or more respective control relationship costs for the one or more control relationships of the attack path.
7 . The method of claim 1 , further comprising identifying, from the set of attack paths, at least one zero-cost attack path having an attack path cost of zero, wherein the zero-cost attack path indicates that no artifacts are generated and no changes are required for traversal.
8 . The method of claim 1 , wherein the attack path risk metric for each attack path is further based on at least one of: initial exploitability of the source object of the attack path or criticality of the target object of the attack path.
9 . The method of claim 8 , wherein the initial exploitability of the source object is determined based on at least one of: a set of configuration rules of the source object, a location of the source object, whether the source object is exposed to a wide area network, a role associated with the source object, or security solutions deployed with respect to the source object.
10 . The method of claim 1 , wherein performing attack path monitoring and risk mitigation comprises:
determining, for each attack path of the set of attack paths, a risk impact on a computing environment risk metric based on the attack path risk metric;
identifying at least one attack path among the set of attack paths having a greatest risk impact on the computing environment; and
addressing the at least one attack path having the greatest risk impact.
11 . The method of claim 1 , wherein the control relationship cost for at least one control relationship is zero, indicating that the control relationship requires no effort to exploit and generates no artifacts.
12 . A system comprising:
a memory; and
at least one processing device communicatively coupled to the memory, to perform operations comprising:
identifying a set of attack paths within a computing environment, each attack path of the set of attack paths connecting a source object to a target object through one or more control relationships associated with one or more respective control relationship costs, wherein each of the one or more respective control relationship costs is indicative of a cost for an attacker to progress from a first object to a second object via its associated control relationship;
determining, for each attack path of the set of attack paths based on the one or more respective control relationship costs, a respective attack path cost of a set of attack path costs;
determining, for each attack path of the set of attack paths based at least in part on the set of attack path costs, a respective attack path risk metric of a set of attack path risk metrics, wherein a lower attack path cost of the set of attack path costs corresponds to a higher attack path risk metric of the set of attack path risk metrics; and
performing attack path risk mitigation based on the set of attack path risk metrics.
13 . The system of claim 12 , wherein each of the one or more respective control relationship costs is determined based on at least one of: difficulty of traversal via its associated control relationship, observability of traversal via its associated control relationship, or one or more artifacts generated by traversal via its associated control relationship.
14 . The system of claim 12 , wherein the respective attack path cost for each attack path is determined as a cumulative cost of the one or more respective control relationship costs for the one or more control relationships of the attack path.
15 . The system of claim 12 , wherein the operations further comprise identifying, from the set of attack paths, at least one zero-cost attack path having a respective attack path cost of zero.
16 . The system of claim 12 , wherein the respective attack path risk metric for each attack path is further based on at least one of: initial exploitability of the source object of the attack path or criticality of the target object of the attack path.
17 . A non-transitory computer readable storage medium comprising instructions that, when executed by at least one processor, cause the at least one processor to perform operations comprising:
identifying a set of attack paths within a computing environment, each attack path of the set of attack paths connecting a source object to a target object through one or more control relationships associated with one or more respective control relationship costs, wherein each of the one or more respective control relationship costs is indicative of a cost for an attacker to progress from a first object to a second object via its associated control relationship;
determining, for each attack path of the set of attack paths based on the one or more respective control relationship costs, a respective attack path cost of a set of attack path costs;
determining, for each attack path of the set of attack paths based at least in part on the set of attack path costs, a respective attack path risk metric of a set of attack path risk metrics, wherein a lower attack path cost of the set of attack path costs corresponds to a higher attack path risk metric of the set of attack path risk metrics; and
performing attack path risk mitigation based on the set of attack path risk metrics.
18 . The non-transitory computer readable storage medium of claim 17 , wherein each of the one or more respective control relationship costs is determined based on at least one of: difficulty of traversal via its associated control relationship, observability of traversal via its associated control relationship, or one or more artifacts generated by traversal via its associated control relationship.
19 . The non-transitory computer readable storage medium of claim 17 , wherein the operations further comprise identifying, from the set of attack paths, at least one zero-cost attack path having a respective attack path cost of zero, wherein the at least one zero-cost attack path is identified as a high-risk attack path.
20 . The non-transitory computer readable storage medium of claim 17 , wherein performing attack path monitoring and risk mitigation comprises at least one of: removing at least one attack path, modifying at least one attack path by altering at least one control relationship, or reducing initial exploitability of a source object of at least one attack path.