IP Library › Granted Patent US 12,506,753
Granted Patent B2
US 12,506,753 · App. 18/350,105 · Granted Dec 23, 2025

Systems and methods for analyzing partial attack paths

Inventors: Hendrikus G. P. Bosch (Aalsmeer, NL); Jeffrey M. Napper (Delft, NL); Willem Jonker (Groningen, NL); Stefano Simonetto (Enschede, NL)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,753
App. No.
18/350,105
Granted
Dec 23, 2025
Kind
B2
Abstract

In one embodiment, a method includes ingesting security tool findings associated with an application and identifying events associated with the application. The method also includes comparing the security tool findings and the events against known attack paths and determining partial attack path matches between the security tool findings and the events and the known attack paths. The method further includes performing a risk analysis of the partial attack path matches and prioritizing the partial attack path matches based on the risk analysis.

Claims (94)

1 . A partial attack path analysis tool, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the partial attack path analysis tool to perform operations comprising:

ingesting security tool findings associated with an application;

identifying events associated with the application;

comparing the security tool findings and the events against known attack paths;

determining partial attack path matches between the security tool findings and the events and the known attack paths;

performing a risk analysis of the partial attack path matches; and

prioritizing the partial attack path matches based on the risk analysis.

2 . The partial attack path analysis tool of claim 1 , wherein the security tool findings are associated with at least one of the following:

Common Vulnerabilities and Exposures (CVEs);

Common Weakness Enumerations (CWEs);

Open Worldwide Application Security Project (OWASP) vulnerabilities; and

Center for Information Security (CIS) benchmarks.

3 . The partial attack path analysis tool of claim 1 , wherein the events are associated with at least one of the following:

security alerts;

application telemetry; or

cloud telemetry.

4 . The partial attack path analysis tool of claim 1 , wherein performing the risk analysis further comprises:

determining a length of each of the partial attack path matches; and

prioritizing the partial attack path matches based on the length of each of the partial attack path matches.

5 . The partial attack path analysis tool of claim 1 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with insider threats;

determining a length of each of the partial attack path matches associated with the insider threats; and

prioritizing the partial attack path matches associated with the insider threats based on the length of each of the partial attack path matches associated with the insider threats.

6 . The partial attack path analysis tool of claim 1 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with one or more customer assets; and

prioritizing the partial attack path matches associated with the one or more customer assets.

7 . The partial attack path analysis tool of claim 6 , wherein the customer assets comprise one or more of the following:

credentials;

Application Programming Interface (API) endpoints;

databases;

data records;

central processing unit (CPU) resources; and

an application.

8 . A method, comprising:

ingesting security tool findings associated with an application;

identifying events associated with the application;

comparing the security tool findings and the events against known attack paths;

determining partial attack path matches between the security tool findings and the events and the known attack paths;

performing a risk analysis of the partial attack path matches; and

prioritizing the partial attack path matches based on the risk analysis.

9 . The method of claim 8 , wherein the security tool findings are associated with at least one of the following:

Common Vulnerabilities and Exposures (CVEs);

Common Weakness Enumerations (CWEs);

Open Worldwide Application Security Project OWASP vulnerabilities; or

Center for Information Security (CIS) benchmarks.

10 . The method of claim 8 , wherein the events are associated with at least one of the following:

security alerts;

application telemetry; or

cloud telemetry.

11 . The method of claim 8 , wherein performing the risk analysis further comprises:

determining a length of each of the partial attack path matches; and

prioritizing the partial attack path matches based on the length of each of the partial attack path matches.

12 . The method of claim 8 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with insider threats;

determining a length of each of the partial attack path matches associated with the insider threats; and

prioritizing the partial attack path matches associated with the insider threats based on the length of each of the partial attack path matches associated with the insider threats.

13 . The method of claim 8 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with one or more customer assets; and

prioritizing the partial attack path matches associated with the one or more customer assets.

14 . The method of claim 13 , wherein the customer assets comprise one or more of the following:

credentials;

Application Programming Interface (API) endpoints;

databases;

data records;

central processing unit (CPU) resources; and

an application.

15 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

ingesting security tool findings associated with an application;

identifying events associated with the application;

comparing the security tool findings and the events against known attack paths;

determining partial attack path matches between the security tool findings and the events and the known attack paths;

performing a risk analysis of the partial attack path matches; and

prioritizing the partial attack path matches based on the risk analysis.

16 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the security tool findings are associated with at least one of the following:

Common Vulnerabilities and Exposures (CVEs);

Common Weakness Enumerations (CWEs);

Open Worldwide Application Security Project OWASP vulnerabilities; or

Center for Information Security (CIS) benchmarks.

17 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the events are associated with one or more of the following:

security alerts;

application telemetry; and

cloud telemetry.

18 . The one or more computer-readable non-transitory storage media of claim 15 , wherein performing the risk analysis further comprises:

determining a length of each of the partial attack path matches; and

prioritizing the partial attack path matches based on the length of each of the partial attack path matches.

19 . The one or more computer-readable non-transitory storage media of claim 15 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with insider threats;

determining a length of each of the partial attack path matches associated with the insider threats; and

prioritizing the partial attack path matches associated with the insider threats based on the length of each of the partial attack path matches associated with the insider threats.

20 . The one or more computer-readable non-transitory storage media of claim 15 , wherein performing the risk analysis further comprises:

identifying the partial attack path matches associated with one or more customer assets; and

prioritizing the partial attack path matches associated with the one or more customer assets.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2023
From: BOSCH, HENDRIKUS G. P.; NAPPER, JEFFREY M.; JONKER, WILLEM; SIMONETTO, STEFANO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064214/0050 →
Continuity (1)
Related Publication 20250023887A1 · Jan 16, 2025
References Cited (12)
US 12255909B2 · Sethi · 2025 [cited by examiner]
US 20070113285A1 · Flowers et al. · 2007 [cited by applicant]
US 20130031635A1 · Lotem · 2013 [cited by examiner]
US 20170032130A1 · Durairaj et al. · 2017 [cited by applicant]
US 20170346839A1 · Peppe et al. · 2017 [cited by applicant]
US 20200177618A1 · Hassanzadeh · 2020 [cited by examiner]
US 20210367962A1 · Kurowski · 2021 [cited by examiner]
US 20220124115A1 · Grabois et al. · 2022 [cited by applicant]
US 20220277078A1 · Tyagi et al. · 2022 [cited by applicant]
US 20230396641A1 · Hebbagodi · 2023 [cited by examiner]
US 20240171614A1 · Crabtree · 2024 [cited by examiner]
US 20250013754A1 · Davidovich · 2025 [cited by examiner]