IP Library › Granted Patent US 11,876,824
Granted Patent B2
US 11,876,824 · App. 17/358,381 · Granted Jan 16, 2024

Extracting process aware analytical attack graphs through logical network analysis

Inventors: Gal Engelberg (Pardes-hana, IL); Dan Klein (Rosh Ha'ayin, IL); Tomer Ram (Netanya, IL); Benny Rochwerger (Tel Aviv, IL)
Assignee: Accenture Global Solutions Limited
H04L63/1433H04L41/22H04L63/145H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,824
App. No.
17/358,381
Granted
Jan 16, 2024
Kind
B2
Abstract

Methods, systems, and computer-readable storage media for receiving a AAG from computer-readable memory, generating from logical network ontology data, asset inventory data, and asset communication data, a logical topology of the enterprise network as a computer-readable data structure, defining, at least partially by executing community detection over the logical topology, a sub-set of groups within the enterprise network, each group representing a process of a plurality of process, each process being at least partially executed by one or more assets within the enterprise network, processing the AAG based on the sub-set of groups and data from one or more contextual data sources to provide the process aware AAG, the process aware AAG defining a mapping between an infrastructure-layer of the enterprise network and a process-layer of the enterprise network, and executing one or more remedial actions in the enterprise network in response to analytics executed on the process aware AAG.

Claims (46)

1. A computer-implemented method for enterprise network security using a process aware analytical attack graph (AAG) based on an AAG representative of potential lateral movement within an enterprise network, the method executed by one or more processors and comprising:

receiving the AAG from computer-readable memory;

generating from logical network ontology data, asset inventory data, and asset communication data, a logical topology of the enterprise network as a computer-readable data structure;

defining a sub-set of groups within the enterprise network, including:

executing community detection over the logical topology; and

determining a quality of respective groups in a set of groups based on a set of measures including conductance and normalized cut,

each group representing a process of a plurality of processes, each process at least partially executed by one or more assets within the enterprise network;

processing the AAG based on the sub-set of groups and data from one or more contextual data sources to provide the process aware AAG, the process aware AAG defining a mapping between an infrastructure-layer of the enterprise network and a process-layer of the enterprise network;

storing the process aware AAG as a computer-readable data structure to computer-readable memory; and

executing one or more remedial actions in the enterprise network in response to analytics executed on the process aware AAG.

2. The computer-implemented method of claim 1 , wherein community detection comprises executing hierarchical clustering over the logical topology to iteratively cluster nodes into groups in a set of groups.

3. The computer-implemented method of claim 1 , wherein the logical topology is representative of the enterprise network based on facts provided from each of the asset inventory data and the asset communication data.

4. The computer-implemented method of claim 1 , wherein the logical ontology comprises nodes representative of assets within the enterprise network and edges representative of communication between assets, each node and each edge associated with a set of properties defining metadata describing a respective asset or a respective edge.

5. The computer-implemented method of claim 1 , wherein the process aware AAG comprises a set of group nodes and a set of asset nodes, each asset node being associated with at least one group node by an edge, each of the group nodes and each of the asset nodes associated with a set of properties defining metadata describing context of a respective group node and asset node.

6. The computer-implemented method of claim 5 , wherein the context comprises one or more of technical impact and financial impact.

7. A non-transitory computer-readable storage medium coupled to one or more processors and having instructions stored thereon which, when executed by the one or more processors, cause the one or more processors to perform operations for enterprise network security using a process aware analytical attack graph (AAG) based on an AAG representative of potential lateral movement within an enterprise network, the operations comprising:

receiving the AAG from computer-readable memory;

generating from logical network ontology data, asset inventory data, and asset communication data, a logical topology of the enterprise network as a computer-readable data structure;

defining a sub-set of groups within the enterprise network, including:

executing community detection over the logical topology; and

determining a quality of respective groups in a set of groups based on a set of measures including conductance and normalized cut,

each group representing a process of a plurality of processes, each process at least partially executed by one or more assets within the enterprise network;

processing the AAG based on the sub-set of groups and data from one or more contextual data sources to provide the process aware AAG, the process aware AAG defining a mapping between an infrastructure-layer of the enterprise network and a process-layer of the enterprise network;

storing the process aware AAG as a computer-readable data structure to computer-readable memory; and

executing one or more remedial actions in the enterprise network in response to analytics executed on the process aware AAG.

8. The non-transitory computer-readable storage medium of claim 7 , wherein community detection comprises executing hierarchical clustering over the logical topology to iteratively cluster nodes into groups in a set of groups.

9. The non-transitory computer-readable storage medium of claim 8 , wherein the logical topology is representative of the enterprise network based on facts provided from each of the asset inventory data and the asset communication data.

10. The non-transitory computer-readable storage medium of claim 7 , wherein the logical ontology comprises nodes representative of assets within the enterprise network and edges representative of communication between assets, each node and each edge associated with a set of properties defining metadata describing a respective asset or a respective edge.

11. The non-transitory computer-readable storage medium of claim 7 , wherein the process aware AAG comprises a set of group nodes and a set of asset nodes, each asset node associated with at least one group node by an edge, each of the group nodes and each of the asset nodes associated with a set of properties defining metadata describing context of a respective group node and asset node.

12. The non-transitory computer-readable storage medium of claim 11 , wherein the context comprises one or more of technical impact and financial impact.

13. A system, comprising:

a computing device; and

a non-transitory computer-readable storage device coupled to the computing device and having instructions stored thereon which, when executed by the computing device, cause the computing device to perform operations for enterprise network security using a process aware analytical attack graph (AAG) based on an AAG representative of potential lateral movement within an enterprise network, the operations comprising:

receiving the AAG from computer-readable memory;

generating from logical network ontology data, asset inventory data, and asset communication data, a logical topology of the enterprise network as a computer-readable data structure;

defining a sub-set of groups within the enterprise network, including:

executing community detection over the logical topology; and

determining a quality of respective groups in a set of groups based on a set of measures including conductance and normalized cut,

each group representing a process of a plurality of processes, each process at least partially executed by one or more assets within the enterprise network;

processing the AAG based on the sub-set of groups and data from one or more contextual data sources to provide the process aware AAG, the process aware AAG defining a mapping between an infrastructure-layer of the enterprise network and a process-layer of the enterprise network;

storing the process aware AAG as a computer-readable data structure to computer-readable memory; and

executing one or more remedial actions in the enterprise network in response to analytics executed on the process aware AAG.

14. The system of claim 13 , wherein community detection comprises executing hierarchical clustering over the logical topology to iteratively cluster nodes into groups in a set of groups.

15. The system of claim 13 , wherein the logical topology is representative of the enterprise network based on facts provided from each of the asset inventory data and the asset communication data.

16. The system of claim 13 , wherein the logical ontology comprises nodes representative of assets within the enterprise network and edges representative of communication between assets, each node and each edge associated with a set of properties defining metadata describing a respective asset or a respective edge.

17. The system of claim 13 , wherein the process aware AAG comprises a set of group nodes and a set of asset nodes, each asset node associated with at least one group node by an edge, each of the group nodes and each of the asset nodes associated with a set of properties defining metadata describing context of a respective group node and asset node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2021
From: ENGELBERG, GAL; KLEIN, DAN; RAM, TOMER; ROCHWERGER, BENNY
To: ACCENTURE GLOBAL SOLUTIONS LIMITED
Reel/Frame 056760/0486 →
Continuity (2)
Provisional Application 63043847 · Jun 25, 2020
Related Publication 20210409426A1 · Dec 30, 2021