IP Library › Granted Patent US 12,476,996
Granted Patent B2
US 12,476,996 · App. 18/478,973 · Granted Nov 18, 2025

Techniques for visualizing network attack paths

Inventors: Val Komarov (Fairfax, VA); Thomas Riley (Boston, MA)
Assignee: Rapid7, Inc.
H04L63/1433H04L41/22H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,996
App. No.
18/478,973
Granted
Nov 18, 2025
Kind
B2
Abstract

An example method includes using at least one computer hardware processor to perform: identifying one or more vulnerable network resources in a plurality of network resources, each of the one or more vulnerable network resources having at least one respective security vulnerability; accessing at least one portion of a relational representation of a set of network resources in the plurality of network resources, identifying, using the at least one portion of the relational representation, one or more network attack paths between the one or more vulnerable network resources and network resources in the set, generating, using the at least one portion of the relational representation, a graph, and generating a GUI comprising a visualization of the graph and information indicating that the one or more attack paths may be used to exploit one or more security vulnerabilities of the set.

Claims (62)

1 . A method for visualizing exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

using at least one computer hardware processor to perform:

identifying one or more vulnerable network resources in the plurality of network resources, each of the one or more vulnerable network resources having at least one respective security vulnerability;

accessing at least one portion of a relational representation of a set of network resources in the plurality of network resources, the relational representation indicating network resources in the set of network resources and network connections among the network resources in the set of network resources, the at least one portion of the relational representation corresponding to the one or more vulnerable network resources;

identifying, using the at least one portion of the relational representation, one or more network attack paths between the one or more vulnerable network resources and at least some network resources in the set of network resources;

generating, using the at least one portion of the relational representation, a graph comprising nodes and edges, the nodes representing the one or more vulnerable network resources and the at least some network resources in the set of network resources along the one or more network attack paths, the edges representing the one or more network attack paths; and

generating a graphical user interface (GUI) comprising a visualization of the graph and information indicating that the one or more attack paths may be used to exploit one or more security vulnerabilities of network resources in the set of network resources,

wherein the method further comprises:

receiving user input indicating a selection of a node in the plurality of nodes, the node displayed in the visualization, the selected node representing one of the one or more vulnerable network resources; and

identifying one or more nodes in the plurality of nodes that have a respective network connection to the selected node, and wherein

generating the GUI comprising the visualization comprises:

displaying at least one GUI element containing content that indicates that the one or more nodes in the plurality of nodes are exploitable based on the one or more nodes having a respective network connection to a node representing a vulnerable network resource.

2 . The method of claim 1 , further comprising:

obtaining metadata indicating the set of network resources in the plurality of network resources and the network connections among the network resources in the set of network resources; and

generating, using the metadata, the relational representation of the set of network resources.

3 . The method of claim 2 , further comprising:

generating, using the relational representation, a plurality of network paths between the network resources in the set of network resources; and

identifying, from among the plurality of network paths and using the relational representation and information indicating one or more of the plurality of network resources that have the at least one respective security vulnerability, at least the one or more network attack paths.

4 . The method of claim 1 , wherein generating the GUI comprising the visualization comprises generating at least one GUI element containing content indicating an explanation for why the one or more network attack paths are identified as the one more network attack paths.

5 . The method of claim 1 , wherein generating the GUI comprising the visualization comprises generating at least one GUI element containing content indicating one or more operations actionable by a user to at least one of mitigate or resolve the at least one respective security vulnerability of the one or more vulnerable network resources.

6 . The method of claim 5 , wherein generating the at least one GUI element comprises identifying at least one of (i) an update to firmware or software of the one or more vulnerable network resources, (ii) one or more changes to security settings of the one or more vulnerable network resources, or (iii) a reconfiguration of at least one portion of the computing environment as the one or more operations.

7 . A network attack path visualization system comprising:

at least one non-transitory computer readable storage medium storing instructions; and

at least one computer hardware processor to execute the instructions to perform a method for visualizing exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

identifying one or more vulnerable network resources in the plurality of network resources, each of the one or more vulnerable network resources having at least one respective security vulnerability;

accessing at least one portion of a relational representation of a set of network resources in the plurality of network resources, the relational representation indicating network resources in the set of network resources and network connections among the network resources in the set of network resources, the at least one portion of the relational representation corresponding to the one or more vulnerable network resources;

identifying, using the at least one portion of the relational representation, one or more network attack paths between the one or more vulnerable network resources and at least some network resources in the set of network resources;

generating, using the at least one portion of the relational representation, a graph comprising nodes and edges, the nodes representing the one or more vulnerable network resources and the at least some network resources in the set of network resources along the one or more network attack paths, the edges representing the one or more network attack paths; and

generating a graphical user interface (GUI) comprising a visualization of the graph and information indicating that the one or more attack paths may be used to exploit one or more security vulnerabilities of network resources in the set of network resources,

wherein the method further comprises:

receiving user input indicating a selection of a node in the plurality of nodes, the node displayed in the visualization, the selected node representing one of the one or more vulnerable network resources; and

identifying one or more nodes in the plurality of nodes that have a respective network connection to the selected node, and wherein

generating the GUI comprising the visualization comprises:

displaying at least one GUI element containing content that indicates that the one or more nodes in the plurality of nodes are exploitable based on the one or more nodes having a respective network connection to a node representing a vulnerable network resource.

8 . The network attack path visualization system of claim 7 , wherein the at least one computer hardware processor is to:

obtain metadata indicating the set of network resources in the plurality of network resources and the network connections among the network resources in the set of network resources; and

generate, using the metadata, the relational representation of the set of network resources.

9 . The network attack path visualization system of claim 8 , wherein the at least one computer hardware processor is to:

generate, using the relational representation, a plurality of network paths between the network resources in the set of network resources; and

identify, from among the plurality of network paths and using the relational representation and information indicating one or more of the plurality of network resources that have the at least one respective security vulnerability, at least the one or more network attack paths.

10 . The network attack path visualization system of claim 7 , wherein the at least one computer hardware processor is to generate the GUI comprising the visualization by generating at least one GUI element containing content indicating an explanation for why the one or more network attack paths are identified as the one more network attack paths.

11 . The network attack path visualization system of claim 7 , wherein the at least one computer hardware processor is to generate the GUI comprising the visualization by generating at least one GUI element containing content indicating one or more operations actionable by a user to at least one of mitigate or resolve the at least one respective security vulnerability of the one or more vulnerable network resources.

12 . The network attack path visualization system of claim 11 , wherein the at least one computer hardware processor is to generate the at least one GUI element by identifying at least one of (i) an update to firmware or software of the one or more vulnerable network resources, (ii) one or more changes to security settings of the one or more vulnerable network resources, or (iii) a reconfiguration of at least one portion of the computing environment as the one or more operations.

13 . At least one non-transitory computer readable storage medium comprising instructions that, when executed by at least one computer hardware processor, causes the at least one computer hardware processor to perform a method for visualizing exploitable security vulnerabilities in a computing environment, the computing environment comprising a plurality of network resources and network connections therebetween, the method comprising:

identifying one or more vulnerable network resources in the plurality of network resources, each of the one or more vulnerable network resources having at least one respective security vulnerability;

accessing at least one portion of a relational representation of a set of network resources in the plurality of network resources, the relational representation indicating network resources in the set of network resources and network connections among the network resources in the set of network resources, the at least one portion of the relational representation corresponding to the one or more vulnerable network resources;

identifying, using the at least one portion of the relational representation, one or more network attack paths between the one or more vulnerable network resources and at least some network resources in the set of network resources;

generating, using the at least one portion of the relational representation, a graph comprising nodes and edges, the nodes representing the one or more vulnerable network resources and the at least some network resources in the set of network resources along the one or more network attack paths, the edges representing the one or more network attack paths; and

generating a graphical user interface (GUI) comprising a visualization of the graph and information indicating that the one or more attack paths may be used to exploit one or more security vulnerabilities of network resources in the set of network resources,

wherein the method further comprises:

receiving user input indicating a selection of a node in the plurality of nodes, the node displayed in the visualization, the selected node representing one of the one or more vulnerable network resources; and

identifying one or more nodes in the plurality of nodes that have a respective network connection to the selected node, and wherein

generating the GUI comprising the visualization comprises:

displaying at least one GUI element containing content that indicates that the one or more nodes in the plurality of nodes are exploitable based on the one or more nodes having a respective network connection to a node representing a vulnerable network resource.

14 . The least one non-transitory computer readable storage medium of claim 13 , wherein the instructions cause the at least one computer hardware processor to:

obtain metadata indicating the set of network resources in the plurality of network resources and the network connections among the network resources in the set of network resources; and

generate, using the metadata, the relational representation of the set of network resources.

15 . The least one non-transitory computer readable storage medium of claim 14 , wherein the instructions cause the at least one computer hardware processor to:

generate, using the relational representation, a plurality of network paths between the network resources in the set of network resources; and

identify, from among the plurality of network paths and using the relational representation and information indicating one or more of the plurality of network resources that have the at least one respective security vulnerability, at least the one or more network attack paths.

16 . The least one non-transitory computer readable storage medium of claim 13 , wherein the instructions cause the at least one computer hardware processor to generate the GUI comprising the visualization by generating at least one GUI element containing content indicating an explanation for why the one or more network attack paths are identified as the one more network attack paths.

17 . The least one non-transitory computer readable storage medium of claim 13 , wherein the instructions cause the at least one computer hardware processor to generate the GUI comprising the visualization by generating at least one GUI element containing content indicating one or more operations actionable by a user to at least one of mitigate or resolve the at least one respective security vulnerability of the one or more vulnerable network resources.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2024
From: KOMAROV, VAL; RILEY, THOMAS
To: RAPID7, INC.
Reel/Frame 068382/0768 →
Continuity (1)
Related Publication 20250112949A1 · Apr 3, 2025
References Cited (37)
US 11575696B1 · Ithal et al. · 2023 [cited by applicant]
US 20060184690A1 · Milliken · 2006 [cited by examiner]
US 20200177616A1 · Hadar · 2020 [cited by examiner]
US 20210258334A1 · Sayag · 2021 [cited by examiner]
US 20210288995A1 · Attar · 2021 [cited by examiner]
US 20220245260A1 · Priller · 2022 [cited by examiner]
US 20230179623A1 · Moolchandani et al. · 2023 [cited by applicant]
US 20230275909A1 · Shivamoggi · 2023 [cited by examiner]
US 20240031391A1 · Baikalov · 2024 [cited by examiner]
US 20240054227A1 · Dahmen et al. · 2024 [cited by applicant]
US 20240146755A1 · Ungureanu · 2024 [cited by examiner]
US 20240265113A1 · Napper · 2024 [cited by examiner]
US 20250097268A1 · Lahav · 2025 [cited by examiner]
US 20250112948A1 · Lee et al. · 2025 [cited by applicant]
[No Author Listed], Amazon S3 Access Points can now be used to securely delegate access permissions for shared datasets to other AWS accounts. Nov. 30, 2022. 3 pages. https://aws.amazon.com/about-aws/whats-new/2022/11/a… [cited by applicant]
[No Author Listed], A confused deputy vulnerability in AWS AppSync. Datadog Security Labs. Nov. 21, 2022. 13 pages. https://securitylabs.datadoghq.com/articles/appsync-vulnerability-disclosure/ (Last accessed Sep. 29, 2… [cited by applicant]
[No Author Listed], GruCloud. Publicly available at least as early as Sep. 29, 2023. 4 pages. https://www.grucloud.com/ (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Lateral Movement. Mitre ATT&CK. Oct. 17, 2018. 6 pages. https://attack.mitre.org/tactics/TA0008/ (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], External memory graph traversal. Wikipedia. Jan. 30, 2023. 4 pages. https://en.wikipedia.org/wiki/External_memory_graph_traversal (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Graph traversal. Wikipedia. Jul. 23, 2023. 4 pages. https://en.wikipedia.org/wiki/Graph_traversal (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Iterative deepening depth-first search. Wikipedia. Sep. 11, 2023. 7 pages. https://en.wikipedia.org/wiki/Iterative_deepening_depth-first_search (Last accessed Sep. 29, 2023). [cited by applicant]
[No Author Listed], Intro to Content-Defined Chunking. Joshleeb Blog. Mar. 4, 2023. 7 pages. https://joshleeb.com/posts/content-defined-chunking.html (Last accessed Sep. 29, 2023). [cited by applicant]
Aksoy et al., Directional Laplacian centrality for cyber situational awareness. Digital Threats: Research and Practice (DTRAP). Oct. 15, 2021;2(4):1-28. [cited by applicant]
Chen, IAM-Deescalate: An Open Source Tool to Help Users Reduce the Risk of Privilege Escalation. Unit 42. Jul. 25, 2022. 12 pages. https://unit42.paloaltonetworks.com/iam-deescalate/ (Last accessed Sep. 29, 2023). [cited by applicant]
Costica, A new vision for cloud security unites builders and defenders. Wiz Blog. Jun. 7, 2022. 8 pages. https://www.wiz.io/blog/uniting-builders-and-defenders-a-new-vision-for-cloud-security (Last accessed Sep. 29, 202… [cited by applicant]
Curwin et al., Identify and remediate attack paths. Microsoft Azure Defender for Cloud. Aug. 10, 2023. 9 pages. https://learn.microsoft.com/en-US/azure/defender-for-cloud/how-to-manage-attack-path (Last accessed Sep. 29… [cited by applicant]
Curwin et al., Reference list of attack paths and cloud security graph components. Microsoft Azure Defender for Cloud. Sep. 5, 2023. https://learn.microsoft.com/en-US/azure/defender-for-cloud/attack-path-reference (Last… [cited by applicant]
Fan et al., The Case Against Specialized Graph Analytics Engines. CIDR. Jan. 4, 2015. 10 pages. [cited by applicant]
Hagberg et al., Exploring network structure, dynamics, and function using NetworkX. Proceedings of the 7 [cited by applicant]
Haque, Using GraphQL with Python—A Complete Guide. Apollo Blog. May 11, 2021. 34 pages. https://www.apollographql.com/blog/graphql/python/complete-api-guide/ (Last accessed Sep. 29, 2023). [cited by applicant]
Kedrosky, Real Life Examples of AWS and Azure Privilege Escalation. Sonrai Security. Aug. 24, 2022. 11 pages. https://sonraisecurity.com/blog/real-life-examples-of-privilege-escalation-in-aws-and-azure/ (Last accessed S… [cited by applicant]
Maor, Understanding Attack Paths and Attack Path Analysis in a Stateful Cloud Environment Graph. Lightspin. Jun. 30, 2021. 9 pages. https://blog.lightspin.io/attack-vector-vs-attack-path-in-security-risk-analysis (Last … [cited by applicant]
Perotti, AWS IAM Exploitation. Security Risk Advisors. Apr. 29, 2019. 26 pages. https://sra.io/blog/aws-iam-exploitation/ (Last accessed Sep. 29, 2023). [cited by applicant]
Pisha, Wiz becomes the first CNAPP to deliver integrated Data Security Posture Management. Wiz Blog. Nov. 21, 2022. 9 pages. https://www.wiz.io/blog/wiz-becomes-first-cnapp-to-deliver-integrated-data-security-posture-ma… [cited by applicant]
Robbins, Managed Identity Attack Paths, Part 1: Automation Accounts. Medium. Jun. 6, 2022. 26 pages. https://posts.specterops.io/managed-identity-attack-paths-part-1-automation-accounts-82667d17187a (Last accessed Sep. … [cited by applicant]
Sonntag, Lateral movement risks in the cloud and how to prevent them—Part 1: the network layer (VPC). Wiz Blog. Oct. 13, 2022. 11 pages. https://www.wiz.io/blog/lateral-movement-risks-in-the-cloud-and-how-to-prevent-the… [cited by applicant]
Xu, Graph Databases Burst into the Mainstream. KD Nuggets. 2018. 8 pages. https://www.kdnuggets.com/2018/02/graph-databases-burst-into-the-mainstream.html (Last accessed Sep. 29, 2023). [cited by applicant]