- Patent Title: Attack path and graph creation based on user and system profiling
-
Application No.: US16516734Application Date: 2019-07-19
-
Publication No.: US11363052B2Publication Date: 2022-06-14
- Inventor: Mayuresh Vishwas Dani , Ankur S. Tyagi , Rishikesh Jayaram Bhide
- Applicant: Qualys, Inc.
- Applicant Address: US CA Foster City
- Assignee: Qualys, Inc.
- Current Assignee: Qualys, Inc.
- Current Assignee Address: US CA Foster City
- Agency: Baker & McKenzie LLP
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
Methods and systems for generating an attack path based on user and system risk profiles are presented. The method comprises determining user information associated with a computing device; determining system exploitability information of the computing device; determining system criticality information of the computing device; determining a risk profile for the computing device based on the user information, the system exploitability information, and the system criticality information; and generating an attack path based on the risk profile. The attack path indicates a route through which an attacker accesses the computing device. The system exploitability information indicates one or more of: the vulnerability associated with the computing device, an exposure window associated with the computing device, and a protection window associated with the computing device. The system criticality information indicates one or more: assets associated with the computing device and services associated with the computing device.
Public/Granted literature
- US20210021629A1 Attack Path and Graph Creation Based on User and System Profiling Public/Granted day:2021-01-21
Information query