IP Library Granted Patent US 12,464,006
Granted Patent B2
US 12,464,006 · App. 18/027,765 · Granted Nov 4, 2025

System and method for graphical reticulated attack vectors for internet of things aggregate security (gravitas)

Inventors: Jacob Brown (Toronto, CA); Tanujay Saha (Princeton, NJ); Niraj K. Jha (Princeton, NJ)
Assignee: The Trustees of Princeton University
H04L63/1433H04L63/1416H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,006
App. No.
18/027,765
Filed
Mar 22, 2023
Granted
Nov 4, 2025
Kind
B2
Art Unit
2434
USPC
726/23
Abstract

According to various embodiments, a system for detecting security vulnerabilities in at least one of cyber-physical systems (CPSs) and Internet of Things (IoT) devices is disclosed. The system includes one or more processors configured to construct an attack directed acyclic graph (DAG) unique to each CPS or IoT device of the devices. The processors are further configured to generate an aggregate attack DAG from a classification of each device and a location of each device in network topology specified by a system administrator. The processors are also configured to calculate a vulnerability score and exploit risk score for each node in the aggregate attack DAG. The processors are further configured to optimize placement of defenses to reduce an adversary score of the aggregate attack DAG.

Claims (51)

1 . A system for detecting security vulnerabilities in at least one of cyber-physical systems (CPSs) and Internet of Things (IoT) devices, the system comprising one or more processors configured to:

construct an attack directed acyclic graph (DAG) unique to each CPS or IoT device of the devices, each attack DAG comprising a first plurality of nodes, each node of the first plurality representing a system-level operation of the device, a plurality of paths, each path representing an attack vector of the device, and a second plurality of nodes, each node of the second plurality representing an exploit goal of the device;

generate an aggregate attack DAG from a classification of each device and a location of each device in network topology specified by a system administrator, where classification comprises at least one of a purpose and physical limitation of the device;

calculate a vulnerability score and exploit risk score for each node in the aggregate attack DAG; and

optimize placement of defenses to reduce an adversary score of the aggregate attack DAG.

2 . The system of claim 1 , wherein the first plurality of nodes further comprises root nodes and the second plurality of nodes further comprises leaf nodes.

3 . The system of claim 1 , wherein a location of each device in network topology comprises whether each device has a wired or wireless connection to other devices in a local network.

4 . The system of claim 1 , wherein a location of each device in network topology comprises whether each device can connect to an external network.

5 . The system of claim 1 , wherein the processors are further configured to generate a set of potential defenses to be applied during optimization.

6 . The system of claim 1 , wherein the processors are further configured to generate an aggregate attack DAG from permissions for each device specified by the system administrator.

7 . The system of claim 6 , wherein the permissions comprise at least one of login permissions and execute command permissions.

8 . The system of claim 1 , wherein the processors are further configured to calculate each vulnerability score based on exploitability factors of the device and adjust the vulnerability score based on any defenses applied.

9 . The system of claim 1 , wherein each vulnerability score is calculated once.

10 . The system of claim 1 , wherein the processors are further configured to calculate each exploit risk score with a probabilistic union function based on corresponding vulnerability scores.

11 . The system of claim 1 , wherein each exploit risk score is recalculated when a new defense is added.

12 . The system of claim 1 , wherein the processors are further configured to optimize placement of defenses to minimize objection functions specified by the system administrator.

13 . The system of claim 1 , wherein the adversary score is based on an adversary model specified by the system administrator and a function of the exploit risk scores for each node in the aggregate attack DAG.

14 . A method for detecting security vulnerabilities in at least one of cyber-physical systems (CPSs) and Internet of Things (IoT) devices, the method comprising:

constructing an attack directed acyclic graph (DAG) unique to each CPS or IoT device of the devices, each attack DAG comprising a first plurality of nodes, each node of the first plurality representing a system-level operation of the device, a plurality of paths, each path representing an attack vector of the device, and a second plurality of nodes, each node of the second plurality representing an exploit goal of the device;

generating an aggregate attack DAG from a classification of each device and a location of each device in network topology specified by a system administrator, where classification comprises at least one of a purpose and physical limitation of the device;

calculating a vulnerability score and exploit risk score for each node in the aggregate attack DAG; and

optimizing placement of defenses to reduce an adversary score of the aggregate attack DAG.

15 . The method of claim 14 , wherein the first plurality of nodes further comprises root nodes and the second plurality of nodes further comprises leaf nodes.

16 . The method of claim 14 , wherein a location of each device in network topology comprises whether each device has a wired or wireless connection to other devices in a local network.

17 . The method of claim 14 , wherein a location of each device in network topology comprises whether each device can connect to an external network.

18 . The method of claim 14 , further comprising generating a set of potential defenses to be applied during optimization.

19 . The method of claim 14 , further comprising generating an aggregate attack DAG from permissions for each device specified by the system administrator.

20 . The method of claim 19 , wherein the permissions comprise at least one of login permissions and execute command permissions.

21 . The method of claim 14 , further comprising calculating each vulnerability score based on exploitability factors of the device and adjusting the vulnerability score based on any defenses applied.

22 . The method of claim 14 , wherein each vulnerability score is calculated once.

23 . The method of claim 14 , further comprising calculating each exploit risk score with a probabilistic union function based on corresponding vulnerability scores.

24 . The method of claim 14 , wherein each exploit risk score is recalculated when a new defense is added.

25 . The method of claim 14 , further comprising optimizing placement of defenses to minimize objection functions specified by the system administrator.

26 . The method of claim 14 , wherein the adversary score is based on an adversary model specified by the system administrator and a function of the exploit risk scores for each node in the aggregate attack DAG.

27 . A non-transitory computer-readable medium having stored thereon a computer program for execution by a processor configured to perform a method for detecting security vulnerabilities in at least one of cyber-physical systems (CPSs) and Internet of Things (IoT) devices, the method comprising:

constructing an attack directed acyclic graph (DAG) unique to each CPS or IoT device of the devices, each attack DAG comprising a first plurality of nodes, each node of the first plurality representing a system-level operation of the device, a plurality of paths, each path representing an attack vector of the device, and a second plurality of nodes, each node of the second plurality representing an exploit goal of the device;

generating an aggregate attack DAG from a classification of each device and a location of each device in network topology specified by a system administrator, where classification comprises at least one of a purpose and physical limitation of the device;

calculating a vulnerability score and exploit risk score for each node in the aggregate attack DAG; and

optimizing placement of defenses to reduce an adversary score of the aggregate attack DAG.

28 . The non-transitory computer-readable medium of claim 27 , wherein the first plurality of nodes further comprises root nodes and the second plurality of nodes further comprises leaf nodes.

29 . The non-transitory computer-readable medium of claim 27 , wherein a location of each device in network topology comprises whether each device has a wired or wireless connection to other devices in a local network.

30 . The non-transitory computer-readable medium of claim 27 , wherein a location of each device in network topology comprises whether each device can connect to an external network.

31 . The non-transitory computer-readable medium of claim 27 , wherein the method further comprises generating a set of potential defenses to be applied during optimization.

32 . The non-transitory computer-readable medium of claim 27 , wherein the method further comprises generating an aggregate attack DAG from permissions for each device specified by the system administrator.

33 . The non-transitory computer-readable medium of claim 32 , wherein the permissions comprise at least one of login permissions and execute command permissions.

34 . The non-transitory computer-readable medium of claim 27 , wherein the method further comprises calculating each vulnerability score based on exploitability factors of the device and adjusting the vulnerability score based on any defenses applied.

35 . The non-transitory computer-readable medium of claim 27 , wherein each vulnerability score is calculated once.

36 . The non-transitory computer-readable medium of claim 27 , wherein the method further comprises calculating each exploit risk score with a probabilistic union function based on corresponding vulnerability scores.

37 . The non-transitory computer-readable medium of claim 27 , wherein each exploit risk score is recalculated when a new defense is added.

38 . The non-transitory computer-readable medium of claim 27 , wherein the method further comprises optimizing placement of defenses to minimize objection functions specified by the system administrator.

39 . The non-transitory computer-readable medium of claim 29 , wherein the adversary score is based on an adversary model specified by the system administrator and a function of the exploit risk scores for each node in the aggregate attack DAG.

Assignments (2)
CONFIRMATORY LICENSE Recorded Feb 24, 2025
From: PRINCETON UNIVERSITY
To: NATIONAL SCIENCE FOUNDATION
Reel/Frame 070303/0308 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: BROWN, JACOB; SAHA, TANUJAY; JHA, NIRAJ K
To: THE TRUSTEES OF PRINCETON UNIVERSITY
Reel/Frame 066146/0268 →
Continuity (2)
Provisional Application 63081390 · Sep 22, 2020
Related Publication 20230328094A1 · Oct 12, 2023
References Cited (46)
US 11296937B2 · Nolan · 2022 [cited by examiner]
US 20070143824A1 · Shahbazi · 2007 [cited by applicant]
US 20070214497A1 · Montgomery et al. · 2007 [cited by applicant]
US 20160077897A1 · Tsang · 2016 [cited by examiner]
US 20170046519A1 · Cam · 2017 [cited by applicant]
US 20180191751A1 · El-Moussa · 2018 [cited by examiner]
US 20220150268A1 · Herwono · 2022 [cited by examiner]
WO 2020219157A1 · 2020 [cited by applicant]
International Search Report and Written Opinion for corresponding PCT Application No. PCT/US2020/051022, dated Dec. 27, 2021. [cited by applicant]
Zhanget al., “Aggregating vulnerability metrics in enterprise networks using attack graphs”, Journal of Computer Security, Jul. 2021. [cited by applicant]
Saha, Tanujay et al., “SHARKS: Smart Hacks, Attacks, RisKs, and Security in Internet of Things based on Machine Learning”, IEEE Transactions on Emerging Topics in Computing, vol. 10, pp. 870-885, Jan. 13, 2021. [cited by applicant]
First Inc., Common vulnerability scoring system version 3.1 specification document, 2019, available online: https://www.first.org/cvss/v3.1/specification-document. [cited by applicant]
Ur-Rehman, A. et al., “Vulnerability modelling for hybrid IT systems,” 2019 IEEE International Conference on Industrial Technology (ICIT), pp. 1186-1191, Feb. 1, 2019. [cited by applicant]
Aksu, M. Ugar et al., “A Quantitative CVSS-Based Cyber Security Risk Assessment Methodology For IT Systems,” 2017 International Carnahan Conference on Security Technology (ICCST), pp. 1-8, 2017. [cited by applicant]
Ou, Xinming and Singhal, Anoop, “Quantitative Security Risk Assessment of Enterprise Networks,” Springer, 2012. [cited by applicant]
Noel, S. et al., “Measuring security risk of networks using attack graphs”, International Journal of Next-Generation Computing, vol. 1, No. 1, pp. 135-147, Jul. 2010. [cited by applicant]
Malowidzki, Marek et al., “TAG: Topological attack graph analysis tool,” 2019 3rd Cyber Security in Networking Conference (CSNet), pp. 158-160, 2019. [cited by applicant]
Mosenia, Arsalan and Jha, Niraj K., “A comprehensive study of security of Internet-of-Things,” IEEE Transactions on Emerging Topics in Computing, vol. 5, No. 4, pp. 586-602, 2017. [cited by applicant]
Bosche, Ann et al., “Unlocking Opportunities in the Internet of Things”, Bain & Company, Aug. 7, 2018, available online: https://www.bain.com/insights/unlocking-opportunities-in-the-internet-of-things/. [cited by applicant]
Akmandor, Ayten Ozge and Jha, Niraj K., “Smart health care: An edge-side computing perspective,” IEEE Consumer Electronics Magazine, vol. 7, No. 1, pp. 29-37, 2018. [cited by applicant]
Stojkoska, Biljana L. Risteka and Trivodaliev, Kire V., “A review of Internet of Things for smart home: Challenges and solutions,” Journal of Cleaner Production, vol. 140, pp. 1454-1464, 2017. [cited by applicant]
Zhang, Ruonan and Liu, Xinbao, “IoT-based maintenance process design for fusion reactor remote handling system,” Journal of Fusion Energy, vol. 33, No. 6, pp. 653-657, 2014. [cited by applicant]
Yun, Miao and Yuxin, Bu, “Research on the architecture and key technology of Internet of Things (IoT) applied on smart grid,” Proceedings from the IEEE International Conference on Advances in Energy Engineering, pp. 69-… [cited by applicant]
Al-Ali, A.R. and Aburukba, Raafat, “Role of Internet of Things in the smart grid technology”, Journal of Computer and Communications, vol. 3, No. 5, pp. 229-233, Jan. 1, 2015. [cited by applicant]
Datta, Soumya Kanti et al., “Integrating Connected Vehicles in Internet of Things Ecosystems: Challenges and Solutions”, IEEE 17th International Symposium on A World of Wireless, Mobile and Multimedia Networks (WoWMoM),… [cited by applicant]
Thierer, Adam and Castillo, Andrea, “Projecting the growth and economic impact of the Internet of Things”, Mercatus Center, George Mason University, Arlington, VA, Economic Perspectives, 2015, available online: https://… [cited by applicant]
Stavridis, James and Weinstein, Dave, “The Internet of Things Is a Cyberwar Nightmare”, Foreign Policy, Nov. 3, 2016, available online: https://foreignpolicy.com/2016/11/03/the-internet-of-things-is-a-cyber-war-nightmar… [cited by applicant]
Lewis, James Andrew, “Managing Risk for the Internet of Things”, Center for Strategic and International Studies, Feb. 17, 2016, available online: https://csis-website-prod.s3.amazonaws.com/s3fs-public/legacy_files/files… [cited by applicant]
Markey, Edward J. and Blumenthal, Richard, Letter to acting administrator James Owen concerning cybersecurity issues with internet-connected cars, United States Senate, available online: https://www.markey.senate.gov/im… [cited by applicant]
Margolis, J. et al., “An in-depth analysis of the Mirai botnet,” in Proceedings of the International Conference on Software Security and Assurance, pp. 6-12, 2017. [cited by applicant]
Saha, Tanujay and Sehwag, Vikash, “TV-PUF: a fast lightweight analog physical unclonable function,” 2016 IEEE International Symposium on Nanoelectronic and Information Systems (iNIS), pp. 182-186, Dec. 1, 2016. [cited by applicant]
Mckay, Kerry A. et al., “Report on Lightweight Cryptography”, National Institute of Standards and Technology, U.S. Department of Commerce, Mar. 2017. [cited by applicant]
Nia, Arsalan Mohsen et al., “Physiological information leakage: A new frontier in health information security,” IEEE Transactions on Emerging Topics in Computing, vol. 4, No. 3, pp. 321-334, 2016. [cited by applicant]
Matrosov, Aleksandr et al., “Stuxnet under the microscope,” ESET LLC, available online: https://www.esetnod32.ru/company/viruslab/analytics/doc/Stuxnet_Under_the_Microscope.pdf. [cited by applicant]
Juels, Ari et al., “The blocker tag: Selective blocking of RFID tags for consumer privacy,” Proceedings of the ACM Conference on Computer and Communications Security, pp. 103-111, Jan. 1, 2003. [cited by applicant]
Huang, Ling et al., “Adversarial Machine Learning,” Proceedings of 4th ACM Workshop on Artificial Intelligence and Security, pp. 43-58, Oct. 21, 2011. [cited by applicant]
IBM Security, “Penetration testing: Protect critical assets using an attacker's mindset,” IBM Corporation, 2019, available online: https://www.ibm.com/downloads/cas/MY6L2O89. [cited by applicant]
Ou, Xinming et al., “MulVAL: A logic-based network security analyzer”, USENIX Security Symposium, vol. 8, pp. 113-128, Jul. 31, 2005. [cited by applicant]
Jajodia, Sushil and Noel, Steven, “Topological vulnerability analysis”, Cyber Situational Awareness, pp. 139-154, 2010. [cited by applicant]
Al Ghazo, Alaa T. et al., “A2G2V: Automatic attack graph generation and visualization and its applications to computer and SCADA networks,” IEEE Transactions on Systems, Man, and Cybernetics: Systems, pp. 1-11, 2019. [cited by applicant]
Barrére, Martin and Lupu, Emil C., “Naggen: a Network Attack Graph GENeration Tool”, 2017 IEEE Conference on Communications and Network Security (CNS), pp. 378-379, Oct. 1, 2017. [cited by applicant]
Kordy, Barbara et al., “DAG-Based Attack and Defense Modeling: Don't Miss the Forest for the Attack Trees,” Computer Science Review, vol. 13-14, pp. 1-38, Mar. 29, 2013. [cited by applicant]
Hahm, Oliver et al., “Operating Systems for Low-End Devices in the Internet of Things: a Survey,” IEEE Internet of Things Journal, vol. 3, No. 5, p. 1, Dec. 4, 2015. [cited by applicant]
Dulaunoy, A. et al., CVE-search project, CVE-Search, available online: http://cve-search.org. [cited by applicant]
OpenVAS—Open Vulnerability Assessment Scanner, Greenbone Networks GmbH, available online: https://www.openvas.org/. [cited by applicant]
Hernandez, Grant et al., “A smart Nest thermostat: A spy in your home,” Black Hat USA, 2014, available online: https://www.blackhat.com/docs/us-14/materials/us-14-Jin-Smart-Nest-Thermostat-A-Smart-Spy-In-Your-Home-WP.pd… [cited by applicant]