AI-driven defensive cybersecurity strategy analysis and recommendation system
A system and method for automated cybersecurity defensive strategy analysis that predicts the evolution of new cybersecurity attack strategies and makes recommendations for cybersecurity improvements to networked systems based on a cost/benefit analysis. The system and method use machine learning algorithms to run simulated attack and defense strategies against a model of the networked system created using a directed graph. Recommendations are generated based on an analysis of the simulation results against a variety of cost/benefit indicators. The recommendation engine runs continuously, makes suggestions, and takes adjustably autonomous actions to go further and actuate parts of the system using an orchestration service employing a distributed computational graph and actuation plugins based on generated plans. Actions are validated as required or as prudent from appropriate simulation modeling services.
1 . A system for automated cybersecurity defensive strategy analysis and recommendations, comprising:
a plurality of programming instructions stored in a memory of, and operating on a processor of, a computing device, wherein the plurality of programming instructions, when operating on the processor, cause the computing device to:
generate a cyber-physical graph of a target network by requesting packet capture data from endpoint agents and network packet capturing devices deployed on networked devices of the target network, wherein the cyber-physical graph is a directed graph comprising nodes representing network devices, users, and resources, and edges representing physical and logical connections between the nodes, and wherein the cyber-physical graph further incorporates deployed software version information and access privilege relationships is from the captured packet data;
perform real-time attack tests on a simulated model of the target network that is based on the cyber-physical graph by:
executing iterative adversarial attack simulations on the cyber-physical graph by composing attack sequences and applying said attack sequences to the cyber-physical graph, wherein the adversarial attack simulations are based, at least in part, on the deployed software version information and the access privilege relationships incorporated in the cyber-physical graph;
updating a probability of success for each attack sequence based on a reward signal received for a successful exploitation of a node or edge in the cyber-physical graph; and
outputting simulation results of the adversarial attack simulations, wherein the simulation results comprise probability distributions over the probability of success for each attack sequence;
generate a cybersecurity improvement recommendation for the target network by:
generating new hypothetical controls for the target network;
analyzing the new hypothetical controls using the simulation results based on cost of implementation of the new hypothetical controls and benefit to be gained from implementation of the new hypothetical controls; and
incorporating the new hypothetical controls in a subsequent iterative adversarial attack simulation to determine whether the new hypothetical controls will be successful; and
upon determining that the new hypothetical controls will be successful, automatically reconfigure the target network using a distributed computational graph to send configuration data implementing the cybersecurity improvement recommendation to affected network devices.
2 . The system of claim 1 , wherein the packet capture data is requested from endpoint agents and network packet capturing devices deployed on the network devices.
3 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining one or more vectors of attack for the adversarial attack simulations.
4 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining a blast radius for the adversarial attack simulations.
5 . The system of claim 1 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determination of exploitable software by generating software exploitability scores that are determined at least by one or more of the following properties: address space layout randomization, data execution prevention, stack hardening, compilation options, or any combination thereof.
6 . The system of claim 5 , wherein the exploitability scores are compared to deep web, dark web, and internet data obtained via public data collection and scans.
7 . The system of claim 1 , wherein the real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph are triggered in response to a change event that causes a modification of the cyber-physical graph.
8 . The system of claim 3 , wherein the cybersecurity improvement recommendations include an identification of a vulnerable node based on the one or more determined vectors of attack.
9 . The system of claim 1 , wherein the plurality of programming instructions further cause the computing device to produce data to describe a set of metrics from the adversarial attack simulations, wherein the set of metrics comprises the following properties: observability, detectability, control effectiveness, compliance effectiveness, and response/mitigation ability.
10 . The system of claim 9 , wherein the set of metrics are also used to determine the attack sequences.
11 . A method for automated cybersecurity defensive strategy analysis and recommendations, comprising the steps of:
generating a cyber-physical graph of a target network by requesting packet capture data from endpoint agents and network packet capturing devices deployed on networked devices of the target network, wherein the cyber-physical graph is a directed graph comprising nodes representing network devices, users, and resources, and edges representing physical and logical connections between the nodes, and wherein the cyber-physical graph further incorporates deployed software version information and access privilege relationships from the captured packet data;
performing real-time attack tests on a simulated model of the target network that is based on the cyber-physical graph by:
executing iterative adversarial attack simulations on the cyber-physical graph by composing attack sequences and applying said attack sequences to the cyber-physical graph, wherein the adversarial attack simulations are based, at least in part, on the deployed software version information and the access privilege relationships incorporated in the cyber-physical graph;
updating a probability of success for each attack sequence based on a reward signal received for a successful exploitation of a node or edge in the cyber-physical graph; and
outputting simulation results of the adversarial attack simulations, wherein the simulation results comprise probability distributions over the probability of success for each attack sequence;
generating a cybersecurity improvement recommendation for the target network by:
generating new hypothetical controls for the target network;
analyzing the new hypothetical controls using the simulation results based on cost of implementation of the new hypothetical controls and benefit to be gained from implementation of the new hypothetical controls; and
incorporating the new hypothetical controls in a subsequent iterative adversarial attack simulation to determine whether the new hypothetical controls will be successful; and
upon determining that the new hypothetical controls will be successful, automatically reconfiguring the target network using a distributed computational graph to send configuration data implementing the cybersecurity improvement recommendation to affected network devices.
12 . The method of claim 11 , wherein the packet capture data is requested from endpoint agents and network packet capturing devices deployed on the network devices.
13 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining one or more vectors of attack for the adversarial attack simulations.
14 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determining a blast radius for the adversarial attack simulations.
15 . The method of claim 11 , wherein the performing real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph further includes determination of exploitable software by generating software exploitability scores that are determined at least by one or more of the following properties: address space layout randomization, data execution prevention, stack hardening, compilation options, or any combination thereof.
16 . The method of claim 15 , wherein the exploitability scores are compared to deep web, dark web, and internet data obtained via public data collection and scans.
17 . The method of claim 11 , wherein the real-time attack tests on the simulated model of the target network that is based on the cyber-physical graph are triggered in response to a change event that causes a modification of the cyber-physical graph.
18 . The method of claim 13 , wherein the cybersecurity improvement recommendations include an identification of a vulnerable node based on the one or more determined vectors of attack.
19 . The method of claim 11 , further comprising producing data to describe a set of metrics from the adversarial attack simulations, wherein the set of metrics comprises the following properties: observability, detectability, control effectiveness, compliance effectiveness, and response/mitigation ability.
20 . The method of claim 19 , wherein the set of metrics are also used to determine the vectors of attack.