Patent · US Active

Automatic generation of data-centric attack graphs

US10503911B2 · kind B2 · utility

10Cited by
11References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 20, 2018
Grant dateDec 10, 2019
Priority date
Expiry dateJul 20, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Generating an attack graph to protect sensitive data objects from attack is provided. The attack graph that includes nodes representing components in a set of components of a regulated service and edges between nodes representing relationships between related components in the set of components is generated based on vulnerability and risk metrics corresponding to each component. A risk score is calculated for each component represented by a node in the attack graph based on sensitivity rank and criticality rank corresponding to each respective component. Risk scores are aggregated for each component along each edge path connecting a node of a particular component to a node of a related component. In response to determining that an aggregated risk score of a component is greater than or equal to a risk threshold, an action is performed to mitigate a risk to sensitive data corresponding to the component posed by an attack.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.