EP1559008B1

Method for risk detection and analysis in a computer network

Abstract

A method, system and computer program product for evaluating an IDP entity, the method includes evaluating an effect of at least one IDP rule applied by the IDP entity on legitimate traffic, based upon a network model; evaluating an effect of at least one IDP rule applied by the IDP entity based upon a network model and an attack model; determining an effectiveness of the IDP entity in response to the evaluated effects.

EP1559008B1, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Expired 26 September 2023, 3 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

19 claims: 1 independent, 18 dependent

  1. 1
    A method for automatically performing risk assessment in a computer network, the method comprising:generating a network topology model for the computer network that includes a set of network nodes, a set of services associated with the set of network nodes, and a set of actual vulnerabilities associated with the set of network nodes;using the network topology model to generate an attack graph comprising one or more graph nodes wherein each graph node represents a state of a single service in the computer network;wherein generating the attack graph comprises using a moving front-line algorithm that comprises: selecting one or more first graph nodes;determining, for a second graph node, whether the constraints on the state of service associated with the second graph node are satisfied by the state of the one or more first graph nodes;and adding an edge connecting the one or more first graph nodes to the second graph node if the constraints on the state of service associated with the second graph node is satisfied by the state of the one or more first graph nodes;and determining one or more potential attacks from one or more start points to one or more end points in the network topology model based on the attack graph.