Nova Patents
IL276972A

An intelligent adversary simulator

Abstract

This record has no abstract on file.

IL276972A, drawing sheet 1
Sheet 1 of 7

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

20 claims: 2 independent, 18 dependent

  1. 1
    An apparatus, comprising:an intelligent-adversary simulator is configured to construct a graph of a virtualized instance of a network including i) devices connecting to the virtualized instance of the network as well as ii) connections and pathways through the virtualized instance of the network, where the virtualized instance of the network is based on an actual network under analysis, where the graph of the virtualized instance of the network is constructed in order to run a simulated cyber-attack scenario on the virtualized instance of the network in order to identify one or more critical devices connecting to the virtualized instance of the network from a security standpoint, and then put this information into a generated report;and thus, help prioritize which critical devices connecting to the virtualized instance of the network should have a priority to allocate security resources to them based on the simulated cyber-attack scenario, where, during a simulation, the intelligent-adversary simulator is configured to calculate one or more paths of least resistance for a cyber threat in the cyber-attack scenario to compromise 1) a virtualized instance of a source device, originally compromised by the cyber threat, 2) through to other virtualized instances of components of the virtualized network, 3) until reaching an end goal of the cyberattack scenario in the virtualized network, all based on historic knowledge of connectivity and behaviour patterns of users and devices within the actual network under analysis, a formatting module is configured to generate the report with the identified critical devices connecting to the virtualized instance of the network that should have the priority to allocate security resources to them, one or more processing units are configured to execute software instructions associated with the intelligent-adversary simulator and the formatting module, and one or more non-transitory storage mediums are configured to store at least software associated with the intelligent-adversary simulator, and where the intelligent-adversary simulator is configured to calculate the paths of least resistance from the virtualized instance of the source device through to other virtualized instances of components of the virtualized network until reaching an end goal of the cyber-attack scenario;but not calculate every theoretically possible path from the virtualized instance of the source device to the end goal of the cyber-attack scenario, each time a hop is made from one device in the virtualized network to another device in the virtualized network in order to reduce an amount of computing cycles needed by the one or more processing units as well as an amount of memory storage needed in the one or more non-transitory storage mediums.
  2. 11
    A method for threat hunting for cyber threat, comprising:constructing a graph of a virtualized instance of a network including i) devices connecting to the virtualized instance of the network as well as ii) connections and pathways through the virtualized instance of the network with an intelligent-adversary simulator, where the virtualized instance of the network is based on an actual network under analysis, where the graph of the virtualized instance of the network is constructed in order to run a simulated cyber-attack scenario on the virtualized instance of the network in order to identify one or more critical devices connecting to the virtualized instance of the network from a security standpoint, and then put this information into a generated report;and thus, help prioritize which critical devices connecting to the virtualized instance of the network should have a priority to allocate security resources to them based on the simulated cyber-attack scenario, where, during a simulation, the intelligent-adversary simulator is configured to calculate one or more paths of least resistance for a cyber threat in the cyber-attack scenario to compromise 1) a virtualized instance of a source device, originally compromised by the cyber threat, 2) through to other virtualized instances of components of the virtualized network, 3) until reaching an end goal of the cyber-attack scenario in the virtualized network, all based on historic knowledge of connectivity and behaviour patterns of users and devices within the actual network under analysis, generating the report with the identified critical devices connecting to the virtualized instance of the network that should have the priority to allocate security resources to them, and calculating the paths of least resistance from the virtualized instance of the source device through to other virtualized instances of components of the virtualized network until reaching an end goal of the cyber-attack scenario;but not calculate every theoretically possible path from the virtualized instance of the source device to the end goal of the cyber-attack scenario, each time a hop is made from one device in the virtualized network to another device in the virtualized network in order to reduce an amount of computing cycles needed by the one or more processing units as well as an amount of memory storage needed in the one or more non-transitory storage mediums.