Method for mapping API function to threat action in a plurality of cloud environments

The method addresses the limitations of conventional security solutions by mapping API functions to threat behaviors across multiple cloud environments, enabling effective identification and response to security threats and improving security management efficiency.

JP2025090481AInactive Publication Date: 2025-06-17ASTRONSECURITY
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023208941
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-05
Filing Date
2023-12-12
Publication Date
2025-06-17
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Conventional security solutions are inadequate in identifying and addressing security threats that occur across multiple cloud environments due to their focus on single cloud environments and limitations in mapping API functions to threat behaviors.

Method used

A method for mapping API functions to threat behaviors in multiple cloud environments involves a server that maps API functions from one cloud environment to threat behaviors using an attack technique database, generates feature information based on API descriptions, and identifies matching API functions across different cloud environments.

Benefits of technology

This method enables effective identification and response to security threats across various cloud environments by accurately mapping API functions to threat behaviors, thereby enhancing security management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025090481000001_ABST
    Figure 2025090481000001_ABST
Patent Text Reader

Abstract

To provide a method for effectively identifying and responding to security threats occurring in various cloud environments.SOLUTION: A method for mapping API functions to threat actions in a plurality of cloud environments by a server, comprising the steps for (a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat action included in an attack technique database (wherein the attack technique database includes a plurality of threat actions classified into a plurality of types); (b) generating feature information of the first API function based on explanatory information for the first API function provided by the first cloud server; (c) identifying a second API function that matches the first API function among at least one API function used in a second cloud environment provided by a second cloud server based on the feature information for the first API function; and (d) mapping the second API function to the first threat action.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method of mapping API functions to threat behaviors in multiple cloud environments, and more particularly to a technology for strengthening the security of cloud services and providing a system for identifying and addressing security threats that can occur in various cloud environments.

Background Art

[0002] Recently, due to the development of cloud computing technology, it has become common for companies and individuals to use various cloud services. Such services interact with each other through their respective unique APIs, and such APIs can be a source of security vulnerabilities. However, conventional security solutions mainly focus on a single cloud environment and have limitations in effectively identifying and addressing threats associated with the interactions between various cloud environments. Therefore, the demand for a method of mapping API functions to threat behaviors in multiple cloud environments is increasing.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] An object of the present invention is to provide a method capable of effectively identifying and addressing security threats that occur in various cloud environments. Another object of the present invention is to provide a method of accurately mapping the API functions of cloud services and threat behaviors to improve the efficiency of security management.

Means for Solving the Problems

[0005] A method for mapping API functions to threat behaviors in multiple cloud environments of the present invention is a method for a server to map API functions to threat behaviors in multiple cloud environments, including: a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat behavior included in an attack technique database (wherein the attack technique database includes multiple threat behaviors classified into multiple types); b) generating feature information of the first API function based on description information about the first API function provided by the first cloud server; c) identifying a second API function that matches the first API function among at least one API function used in a second cloud environment provided by a second cloud server based on the feature information of the first API function; and d) mapping the second API function to the first threat behavior.

[0006] In one embodiment of the present invention, the step b) may include transmitting a first request prompt to a generative AI server to summarize the description information about the first API function and request summary information for the first API, receiving the summary information for the first API from the generative AI server in response to the first request prompt, and generating the feature information of the first API function based on the summary information for the first API.

[0007] In one embodiment of the present invention, the step b) further includes identifying a service executed in the first cloud environment when the first API function is executed, and the feature information can be additionally based on information about the service.

[0008] In one embodiment of the present invention, the step c) includes generating feature information of the second API function based on the description information of the second API function provided by the second cloud server; requesting the generation-based AI server for the feature information of the first API function and the similarity information of the feature information of the second API function, and receiving the similarity information from the generation-based AI server; determining that the first API function and the second API function are similar API functions based on the similarity information; and identifying the second API function with an API function matched to the first API function.

[0009] In one embodiment of the present invention, there are a plurality of the generation-based AI servers, the similarity information includes a plurality of similarity information generated from the plurality of generation-based AI servers, and in the step of determining with the similar API functions, the server can compare the plurality of similarity information to determine whether the first API function and the second API function are similar.

[0010] In one embodiment of the present invention, a predetermined weight value can be applied to the plurality of similarity information by the corresponding generation-based AI server.

[0011] In one embodiment of the present invention, the step of generating the feature information of the first and second API functions includes transmitting first and second request prompts for summarizing the description information of the first and second API functions to the generation-based AI server and requesting summary information for the first and second APIs; receiving the summary information for the first and second APIs from the generation-based AI server according to the first and second request prompts; and generating the feature information of the first and second API functions based on the summary information for the first and second APIs.

[0012] In one embodiment of the present invention, the first and second request prompts can include content requesting to generate summary information for the first and second APIs with the same table of contents items.

[0013] In one embodiment of the present invention, the step of identifying the second API function further includes the step of checking a term database in which terms used in the first and second cloud environments are matched with each other. In the step of receiving the similarity information, the server can request the generative AI server to provide information on the term database and generate the similarity information based on the term database.

[0014] In one embodiment of the present invention, it may include the step of checking the occurrence of the first threat behavior based on the event information of the user's second API function in the second cloud environment, the step of checking a response scenario for a threat scenario including the first threat behavior in the first cloud environment, and the step of determining a response solution in the second cloud environment based on the response scenario.

[0015] In one embodiment of the present invention, the step of determining the response solution may include the step of checking a first response API function used in the first cloud environment included in the response scenario, and the step of checking a second response API function corresponding to the first response API function among the API functions used in the second cloud environment.

[0016] In one embodiment of the present invention, a step of confirming information for mapping the second API function, which is executed between the step (c) and the step (d), to a second threat behavior included in the attack technique database (wherein the first and second threat behaviors are different threat behaviors from each other), and a step of comparing the mapping accuracy of the first mapping information obtained by mapping the first API function to the first threat behavior and the second mapping information obtained by mapping the second API function to the second threat behavior are further included. When the mapping accuracy of the first mapping information is higher than the mapping accuracy of the second mapping information, the step (d) is executed. When the mapping accuracy of the second mapping information is higher than the mapping accuracy of the first mapping information, instead of the step (d), a step of mapping the first API function to the second threat behavior can be executed.

[0017] In one embodiment of the present invention, the first mapping information includes a plurality of mapping index information for the first API function and the first threat behavior received from a plurality of generative AI servers. The second mapping information includes a plurality of mapping index information for the second API function and the second threat behavior received from a plurality of generative AI servers. In the step of comparing the mapping accuracy, the server can make a determination based on the outlier information of the plurality of mapping index information included in the first and second mapping information.

[0018] In one embodiment of the present invention, the attack technique database can include information on the type of attack technique, explanatory information of the attack technique, and information on the detailed techniques included in the attack technique (wherein the group is a superordinate concept including at least one of the attack techniques, and the attack technique is a superordinate concept including at least one of the detailed techniques).

Advantages of the Invention

[0019] According to one embodiment of the present invention, it is possible to provide a method capable of effectively identifying and responding to security threats occurring in various cloud environments.

[0020] According to an embodiment of the present invention, a method for accurately mapping the API functions of cloud services and threat behaviors and improving the efficiency of security management can be provided.

Brief Description of the Drawings

[0021]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Best Mode for Carrying Out the Invention

[0022] Hereinafter, with reference to the accompanying drawings, the embodiments disclosed in this specification will be described in detail. Regardless of the reference numerals, the same and / or similar components will be given the same reference numerals, and duplicate descriptions thereof will be omitted. In addition, when it is determined that a specific description of related known technologies makes the gist of the embodiments disclosed in this specification unclear in explaining the embodiments disclosed in this specification, the detailed description thereof will be omitted.

[0023] Terms including ordinal numbers such as first, second, etc. can be used to describe various components, but the components are not limited by the terms. The terms are used only for the purpose of distinguishing one component from another.

[0024] Singular expressions include plural expressions unless the context clearly has a different meaning.

[0025] In this application, each step described can be performed regardless of the listed order, unless it should be performed in the order listed according to a special causal relationship.

[0026] In this application, terms such as "including" or "having" are intended to specify the presence of the features, numbers, steps, operations, components, parts, or combinations thereof described in the specification, and do not preclude the presence or addition possibility of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0027] Hereinafter, the present invention will be described with reference to the accompanying drawings.

[0028] FIG. 1 is a drawing illustrating an example of a network environment according to an embodiment of the present invention.

[0029] The network environment according to an embodiment of the present invention illustrated in FIG. 1 may include a server 10, a first cloud server 20, a second cloud server 30, a generative AI server 40, and a user terminal 50.

[0030] The server 10 is a device that analyzes API functions of a plurality of cloud environments including the first cloud server 20 and the second cloud server 30, and provides a user terminal 50 with an API function mapping service that maps the API functions to threat behaviors included in a threat technique database.

[0031] The server 10 according to various embodiments of the present invention can be implemented as a computer device or a plurality of computer devices that provide instructions, codes, files, contents, services, etc. The server 10 according to an embodiment is an electronic device that can communicate with the first cloud server 20, the second cloud server 30, the generative AI server 40, and the user terminal 50 through a network and transmit and receive information. Although the server 10 has been described as one server for convenience of explanation, it may be composed of a plurality of servers, and each server can provide different functions or services from each other.

[0032] The server 10 may include a processor 11, a memory 12, and a communication unit 13. The processor 11 can control the overall operations of the memory 12 and the communication unit 13. According to various embodiments of the present invention, the memory 12 functions as a storage medium and can store a plurality of application programs driven by the server 10, data for the operation of the server 10, and instruction words. In one embodiment, the memory 12 may be provided in the form of various storage devices such as ROM, RAM, flash drive, hard drive, etc. in hardware and / or in the form of web storage. The communication unit 13 can communicate with the user terminal 50 in a wired or wireless manner through a network.

[0033] The processor 11 can control the overall operation of the memory 12 and the communication unit 13 and provide an API function mapping service to the user terminal 50.

[0034] The memory 12 functions as a storage medium and can store a plurality of application programs driven by the server 10, data and instruction words for the operation of the server 10. In one embodiment, the memory 12 can store an application associated with the API function mapping service. Such a memory 12 can be provided in the form of various storage devices such as ROM, RAM, flash drive, hard drive, etc. in hardware, and / or can be provided in the form of web storage.

[0035] The communication unit 13 can communicate with the user terminal 50 through the network in a wired or wireless manner.

[0036] The server 10 of the present invention executes a method of mapping API functions to threat behaviors in a plurality of cloud environments. Specifically, the server 10 maps a first API function used in a first cloud environment provided by a first cloud server to a first threat behavior included in an attack technique database, generates feature information of the first API function based on the description information of the first API function provided by the first cloud server, and based on the feature information of the first API function, identifies a second API function that matches the first API function among at least one API function used in a second cloud environment provided by a second cloud server, and maps the second API function to the first threat behavior.

[0037] In addition, the server 10 can summarize the description information of the first API function to the generative AI server, transmit a first request prompt for requesting summary information for the first API, receive the summary information for the first API from the generative AI server according to the first request prompt, and generate the feature information of the first API function based on the summary information for the first API.

[0038] In addition, when the first API function is executed, the server 10 can identify the services executed in the first cloud environment.

[0039] Here, the multiple cloud environments refer to different cloud platforms and infrastructures provided by various cloud service providers. Specifically, the multiple cloud environments can each provide a unique API, and this API can have different functions and security characteristics. The multiple cloud environments can be, for example, various cloud services such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.

[0040] Here, the API function is the necessary interface for using cloud services, and includes the command words, protocols, and tools that enable the interaction between users or other applications and cloud services. Specifically, the API function can access various services and resources of the cloud infrastructure, exchange data, and be used to execute complex operations. For example, storage management, allocation of computing resources, execution of database queries, etc. are performed through the API function. Each cloud service provider provides a unique set of APIs designed to be integrated with their own platforms, and such APIs can be utilized in various aspects such as security, performance, and ease of use.

[0041] Here, the attack technique database is based on the MITRE ATT&CK framework. Specifically, the ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework can be a knowledge-based system that includes strategies, tactics, techniques, and procedures widely used in cybersecurity. The attack technique database systematically classifies and organizes various attack methods used in actual cyber threat scenarios, and provides detailed descriptions, usage examples, and defense strategies for each attack method. Through this, server 10 can more accurately identify security threats that can occur in the cloud environment and effectively map vulnerabilities associated with API functions. The ATT&CK framework is continuously updated and can reflect the latest security attack techniques and countermeasures.

[0042] In addition, the attack technique database can include information on the types of attack techniques, descriptive information on attack techniques, and information on detailed techniques included in attack techniques. Here, a group can be a higher-level concept that includes at least one of the said attack techniques, and an attack technique can be a higher-level concept that includes at least one of the said detailed techniques.

[0043] Here, a threat behavior corresponds to an attack technique in the attack technique database. Specifically, it can mean something that corresponds to the "Techniques" part of the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework, which is the attack technique database.

[0044] Here, mapping means the process of correlating the API functions of the cloud environment with cyber security threat behaviors.

[0045] Here, the description information refers to detailed documents and guides for API functions provided by various cloud service providers. Specifically, the description information can include specific descriptions of API functions, usage methods, implementation details, parameters, return values, and so on. For example, the description information can be Amazon's DocumentDB or Microsoft's Azure Cosmos DB.

[0046] Here, the feature information is data that summarizes the core attributes and behavior patterns of each API function. The feature information can include the functional features of the API, usage methods, input and output formats, execution environments, and security elements.

[0047] Here, matching means the process of setting the correspondence relationship between API functions used in one cloud environment and API functions used in different cloud environments. For example, it is to match the management function of a specific database provided by Amazon's DocumentDB with a similar function provided by Azure Cosmos DB.

[0048] Here, the request prompt means a specific information request command sent by server 10 to the generative AI server 40. For example, server 10 requests the generative AI server 40 to summarize the description of the API function for Amazon's DocumentDB and / or generate the feature information of a specific function. The command words and instructions used at this time are the request prompt.

[0049] The first cloud server 20 is the infrastructure and service of a specific cloud service provider, and can provide various API functions and description information to server 10 and user terminal 50. Also, the API functions of the first cloud server 20 can be used to enable various cloud services such as data management, resource allocation, and service management.

[0050] The first cloud server 20 can include a processor 21, a memory 22, and a communication unit 23. Each detailed configuration included in the first cloud server 20 executes substantially the same functions as the configurations of the respective servers included in the server 10. A detailed description of the detailed configuration of the first cloud server 20 is replaced with the description of the server 10.

[0051] The second cloud server 30 is the infrastructure and service of a cloud service provider different from that of the first cloud server 20, and can provide different functions and explanatory information from those of the first cloud server 20. The second cloud server 30 can include a processor 31, a memory 32, and a communication unit 33. Each detailed configuration included in the second cloud server 30 executes substantially the same functions as the respective server configurations included in the first cloud server 20. A detailed description of the detailed configuration of the second cloud server 30 is replaced with the description of the first cloud server 20.

[0052] The generative AI server 40 is an advanced computing system used to process and analyze complex data, and can analyze and process various data associated with API functions by leveraging artificial intelligence, particularly machine learning, and natural language processing (NLP) technologies.

[0053] The generative AI server 40 can include a processor 41, a memory 42, and a communication unit. Each detailed configuration included in the generative AI server 40 executes substantially the same functions as the respective server configurations included in the server 10. A detailed description of the detailed configuration of the generative AI server 40 is replaced with the description of the server 10.

[0054] The user terminal 50 is a device used by a user to access and interact with multiple cloud environments by utilizing the API function mapping service provided by the server 10.

[0055] The user terminal 50 can include a communication unit 51, an input unit 52, an output unit 53, a memory 54, and a processor 55.

[0056] The communication unit 51 can communicate with the server 10 or other terminals in a wired or wireless manner.

[0057] The input unit 52 can receive the input of various information through the operations and input actions of the user. In this way, the input unit can be a touch screen module, a keyboard, a mouse, buttons, a camera, a stylus, a microphone, etc.

[0058] The user terminal 50 can receive the input of user interaction through the input unit 52. Interaction means that the user operates the input unit 52 and inputs information reflecting the user's selection or intention, etc. into the user terminal 50. For example, the interaction can be a touch on the touch screen, a click of the mouse, typing on the keyboard, input of sound from the microphone, image capture by the camera, motion recognition by the motion sensor, etc.

[0059] The output unit 53 can output various information. The output unit 53 can be a display device, a speaker, a vibration generating device, a tactile generating device, etc. In some cases, the output unit 53 can be a device (such as a Bluetooth headset) that is connected to the user terminal 50 through wired or wireless communication (such as short-range wireless communication like Bluetooth (registered trademark)) and receives and outputs signals.

[0060] The memory 54 functions as a storage medium and can store a plurality of application programs driven by the user terminal 50, data and instruction words for the operation of the user terminal 50. Such a memory can be embodied in the form of various storage devices such as ROM, RAM, flash drive, hard drive, etc. as hardware, and / or can be provided in the form of web storage. In one embodiment, the memory 54 can store an application (hereinafter, "application") associated with the API function mapping service.

[0061] The processor 55 can execute an application that controls the overall operations of the communication unit 51, the input unit 52, the output unit 53, and the memory 54.

[0062] FIG. 2 is a drawing illustrating an example of a process of mapping API functions to threat behaviors in a plurality of cloud environments according to an embodiment of the present invention.

[0063] Referring to FIG. 2, the threat behaviors to which the API functions are mapped in the first cloud environment and the second cloud environment are shown. The first cloud environment includes the first-1 API to the first-13 API, among which the first-2, 1-7, 1-10, and 1-12 APIs are not mapped to any threat behaviors. APIs that are not mapped may not have vulnerabilities discovered within the scope of the currently analyzed threat behaviors and / or may not have been analyzed by the server 10 yet.

[0064] The number of APIs owned by the cloud environment can be different, and multiple API functions can be mapped to one threat behavior.

[0065] Although not shown in the drawing, one API function can also be mapped to multiple threat behaviors. For example, even for the same API function, the threat behaviors to which it is mapped can be different depending on the service for which it is used in the cloud environment.

[0066] Referring to FIG. 2, it can be seen that the first-1 API in the first cloud environment and the second-2 API in the second cloud environment are all mapped to the first threat behavior.

[0067] Therefore, the first-1 API can be mapped to the first threat behavior, and separately, the second-2 API can be mapped to the first threat behavior, generating a mapping result as shown in FIG. 2.

[0068] However, in some cases, first, map the first API (1-1) and the first threat behavior. When the second API (2-2) and the first threat behavior have not been mapped yet, match the first API (1-1) and the second API (2-2) to similar APIs, and then map the second API (2-2) to the first threat behavior. According to such a method, instead of analyzing and mapping the content of the second API (2-2) and the first threat behavior, it is characterized by performing the matching of the first API (1-1) and the second API (2-2). Mapping an API and a threat behavior is to compare functions and behaviors, while matching an API and an API is to compare the same functions. Therefore, matching an API and an API is relatively easy and / or can have a higher accuracy. Thus, according to such a method, there is an advantage that the APIs and threat behaviors in multiple cloud environments can be mapped more easily and accurately.

[0069] Regarding the specific method related to the above-described method, it will be described in detail below with reference to FIGS. 4 to 10.

[0070] Referring additionally to FIG. 2, the third threat behavior has the first API (1-8) and the first API (1-9) in the first cloud environment mapped thereto, and the second API (2-5), the second API (2-6), and the second API (2-7) in the first cloud environment are mapped thereto. Based on each API characteristic information, the second API (2-5), the second API (2-6), and the second API (2-7) are matched to the first API (1-8), and the server 10 can map the second API (2-5), the second API (2-6), and the second API (2-7) to the third threat behavior. However, when the determination result of the similarity between the first API (1-9) and the second API (2-7) is determined to be dissimilar, the server 10 cannot map the second API (2-7) to the third threat behavior.

[0071] FIG. 3 is a drawing illustrating a part of the MITRE ATT&CK cloud matrix, which is an attack technique database according to an embodiment of the present invention.

[0072] Referring to FIG. 3, a part of the cloud matrix in the ATT&CK framework of the MITRE ATT&CK, which is an attack technique database, is illustrated.

[0073] Referring to FIG. 3, "Initial Access", "Execution", "Persistence", and "Privilege Escalation", which correspond to Tactics, are displayed as information on the types of attack techniques in the attack technique database. Each of the Tactics is an attack technique in the present invention and includes 5, 4, 7, and 5 techniques (Techniques) called threat behaviors. Specifically, the tactic "Initial Access" includes techniques corresponding to "Drive-by Compromise", "Exploit Public-Facing Application", "Phishing", "Trusted Relationship", and "Valid Accounts". Also, here, "Phishing" and "Valid Accounts" further include sub-technigues corresponding to detailed techniques.

[0074] FIG. 4 is a flowchart for explaining a method of mapping API functions to threat behaviors in a plurality of cloud environments according to an embodiment of the present invention.

[0075] a) In step, the server 10 maps the first API function used in the first cloud environment provided by the first cloud server 20 to the first threat behavior included in the attack technique database.

[0076] The server 10 analyzes the data and characteristics of the API functions collected from the first cloud server 10 and can identify what security threats the corresponding API functions can be exposed to that correspond to the threat behaviors in the attack technique database. Here, the attack technique database can include a plurality of threat behaviors classified into a plurality of types.

[0077] Server 10 can map to multiple threat behaviors and / or not map to threat behaviors through its API function. For example, when multiple threat behaviors correspond to the API function, the degree of match and the degree of risk can be calculated between each threat behavior and the API function, and a total score reflecting the weighted value for each can be calculated. Threat behaviors with a total score equal to or higher than a predetermined reference score can be mapped, and threat behaviors with a score lower than the reference score can be not mapped.

[0078] b) In this step, server 10 generates the feature information of the first API function based on the explanatory information for the first API function provided by the first cloud server 20.

[0079] When the first API function is executed, server 10 can identify the service executed in the first cloud environment and reflect the information about the service in the feature information. Here, the service means a specific function or operation provided in the cloud environment. Specifically, the service can include cloud-based application programs, data management systems, computing resources, network functions, etc. For example, when the first API function is used in a cloud-based database management service, the first API function executes operations such as data query, update, and deletion, and server 10 can categorize what role the corresponding API function plays in database management, what types of data it interacts with, etc., and generate feature information.

[0080] Server 10 can summarize the description information about the API functions in the generative AI server 40, transmit a request prompt for requesting summary information about the API functions, receive the summary information about the API from the generative AI server 40 based on the request prompt, and generate feature information based on the summary information. Here, the summary information can briefly include the basic operating principle of the API, usage method, security characteristics, etc. For example, Server 10 can transmit a request prompt "Please summarize the main functions and security aspects of this API" for a specific API function of the first cloud server 20. The generative AI server 40 can respond to this request and provide information that briefly summarizes the main features, usage scenarios, potential security vulnerabilities, etc. of the corresponding API function. For example, when the description information for the first and second API functions is provided in different formats like Amazon's DocumentDB and Azure Cosmos DB, Server 10 can set the same table of contents items for comparison of the description information. Specifically, the same table of contents items can be categories that include the core information of each API, such as the main functions, usage methods, security characteristics, etc. of the API.

[0081] Server 10 can request the generative AI server 40 to generate summary information about the first and second APIs with the same table of contents items in the request prompt.

[0082] In step b-1), Server 10 generates the feature information of the second API function based on the description information of the second API function provided by the second cloud server 30.

[0083] The time when Server 10 generates the feature information of the second API function can be before the time when it generates the first API feature information. Or it can be the time when trying to identify the second API function that matches the first API function. For example, Server 10 may generate and database the feature information for all the APIs used in the second cloud environment provided by the second cloud server before generating the first API feature information.

[0084] c) In step (c), based on the feature information of the first API function, the server 10 identifies a second API function that matches the first API function among at least one API function used in the second cloud environment provided by the second cloud server 30.

[0085] The server 10 can identify a second API function that is similar to and / or associated with the first API function among the API functions used in the second cloud environment provided by the second cloud server 30. For example, if the API of the first cloud environment provides a function associated with data analysis, the server 10 can find an API that provides a similar data analysis function in the second cloud environment. Specifically, it can be identified by comparing and analyzing the functions, data processing methods, security requirements, etc. of the APIs.

[0086] Also, the server 10 can identify a second API function that is similar to and / or associated with the first API function based on the feature information of the API functions used in the second cloud environment provided by the second cloud server 30. For example, when the feature information of the first API function includes category information corresponding to cloud infrastructure database management services, an API function that includes category information corresponding to cloud infrastructure database management services among the feature information of the API functions used in the second cloud environment can be identified as the second API function.

[0087] Here, the feature information of the first and second APIs can be the same and / or composed of similar contents. In the process of the server 10 comparing the first and second APIs, it can compare the contents of the corresponding items of each other and determine the similarity of the first and second APIs.

[0088] Server 10 requests the generative AI server 40 for the similarity information of the feature information of the first API function and the feature information of the second API, and can identify it as an API function that matches the second API function to the first API function based on the similarity information received from the generative AI server 40. Here, the similarity information is data indicating the similarity between the first API function and the second API function. For example, the similarity information can include the results of comparative analysis of the features, functions, operating principles, security requirements, etc. of the two API functions.

[0089] Server 10 can request similarity information from multiple generative AI servers, generate multiple pieces of similarity information, compare the multiple pieces of similarity information, and determine whether the first API function and the second API function are similar. For example, scores can be calculated respectively based on the similarity information received from multiple generative AI servers, and whether the first API function and the second API function are similar can be determined through the average score of the total scores.

[0090] Also, multiple pieces of similarity information can be provided with predetermined weighting values by the corresponding generative AI servers. For example, if the first AI server has a weighting value of 0.5 and the calculated similarity score is 10 points, it can be added up to 5 points reflecting the weighting value when adding up multiple similarity scores.

[0091] In step d), server 10 maps the second API function to the first threat behavior.

[0092] Server 10 analyzes the feature information of the second API function and the first threat behavior in the attack technique database, and can determine which security vulnerabilities and risk factors can be associated with the corresponding API function.

[0093] Here, the second API function can be mapped to the first threat behavior for the first time through step d) without being mapped to different threat behaviors from the conventional ones. However, in some cases, the second API function has already been mapped to different threat behaviors (for example, the second threat behavior) in the conventional manner, and the threat behavior mapped through step d) can be changed to the first threat behavior.

[0094] FIG. 5 is a drawing for explaining an example of executing steps a) to d) of FIG. 4 described above.

[0095] Referring to FIG. 5, the server 10 can map the "GetObject" of Amazon S3, which is the first API function, in the first cloud environment to the threat behavior "Exfiltration Over Alternative Protocol (T1048)" included in the attack technique database (step a).

[0096] Referring to FIG. 5, for the "GetObject" which is the first API function, "AW_cloud_API331_document.pdf" provided in the first cloud environment is displayed in the description information. The description information can be provided from the cloud environment in various formats according to the purpose and nature of the information. For example, the description information of the second cloud environment can be provided in the form of a link as shown in FIG. 5. The server 10 can generate the feature information of the "GetObject" which is the first API function based on the description information. The feature information of the first API function can be separated and generated by category such as function, security, performance, scalability, and interchangeability. (step b).

[0097] Referring to FIG. 5, the server 10 can determine and match the similarity and relevance between the first API function and the second API function based on the feature information of the first API function and the feature information of the second API function (step c).

[0098] Referring to FIG. 5, the server 10 can map the second API function to the same threat behavior as the threat behavior obtained by mapping the second API function to the first API function according to the matching result of the first API function and the second API function (step (d)).

[0099] FIG. 6 is a table for explaining a method of identifying an API function to be matched based on the characteristic information of the API function according to an embodiment of the present invention. FIG. 6 is a drawing for explaining an example in which step (c) of FIG. 4 is executed.

[0100] Referring to FIG. 6, it is an example of a method for determining the similarity between the first API function and the second API function based on the characteristic information of the first API function and the second API function in FIG. 5, calculating a similarity score, and determining the similarity.

[0101] Referring to FIG. 6, since the first API function and the second API function provide a basic function of searching for data in cloud storage and can be used in web applications, mobile applications, data backup, archiving, etc., the similarity score is calculated as high as 10 points in terms of functional similarity.

[0102] Referring to FIG. 6, it can be confirmed that the first API function and the second API function have a total similarity score of 41 points, with a functional similarity of 10 points, a security and compliance similarity of 6 points, a performance and scalability similarity of 7 points, an interchangeability similarity of 9 points, and a data format and structure similarity of 9 points, and the similarity judgment result is determined as "similar".

[0103] FIG. 7 is a flowchart for explaining a method of comparing the mapping accuracy between the mapping information obtained by mapping the API function and the threat behavior according to an embodiment of the present invention.

[0104] The embodiment of FIG. 7 relates to a state in which a second threat behavior has already been mapped to the second API function.

[0105] The a), b), b-1), c), and d) steps in FIG. 7 are substantially the same as the same steps in FIG. 4. The detailed description regarding this is replaced by the description with reference to FIG. 4.

[0106] In step 710, server 10 checks the information mapped by the second API function to the second threat behavior included in the attack technique database. The order of executing step 710 is not limited to that illustrated in FIG. 7. For example, step 710 can also be executed before the a) step.

[0107] Server 10 can check the information on how the second API function maps to the second threat behavior included in the attack technique database. For example, if the second API function provides a function associated with user authentication, server 10 can analyze how the second API function can be mapped to authentication bypass, credential stuffing, or other authentication-related attack techniques. Also, through such analysis, server 10 can determine whether the second API function is vulnerable to a certain security threat to a certain extent or what security measures are required to address the corresponding threat.

[0108] In step 715, server 10 determines whether the first threat behavior and the second threat behavior are the same.

[0109] Server 10 can determine whether the first threat behavior and the second threat behavior identified previously are the same. If it is determined that they are the same, server 10 can confirm that the first API function and the second API function share similar security vulnerabilities in their respective cloud environments.

[0110] If server 10 determines that the first threat behavior and the second threat behavior are not the same, step 720 can be executed.

[0111] In step 720, server 10 compares the mapping accuracies of the first mapping information obtained by mapping the first API function and the first threat behavior, and the second mapping information obtained by mapping the second API function and the second threat behavior. Here, the mapping accuracy is a measure indicating how accurately the correlation between the API function and the threat behavior is identified and mapped.

[0112] Specifically, the mapping accuracy can be determined by correlation (how closely the mapped threat behavior is linked to the actual operation mode and security aspects of the API function), threat scenario suitability (the degree of match between the threat behavior mapped to a specific API function and the usage scenario of that API), consistency with the attack technique database (the consistency between the characteristics of the threat behavior recorded in the attack technique database and the mapped API function), and so on.

[0113] Server 10 can analyze the correlation between the first API function and the first threat behavior using the first mapping information. Specifically, characteristics of the corresponding API function, security vulnerabilities, degree of exposure to attacks, etc. can be considered. At the same time, server 10 can also perform the same analysis on the correlation between the second API function and the second threat behavior using the second mapping information.

[0114] In step 730, server 10 maps the first API function to the second threat behavior.

[0115] If the mapping accuracy of the first mapping information is higher, server 10 can execute step d) and map the second API function to the first threat behavior. Also, if the mapping accuracy of the second mapping information is higher, the first API function can be mapped to the second threat behavior.

[0116] Figure 8 is a table for explaining a method of comparing mapping accuracies among multiple mapping index information according to an embodiment of the present invention.

[0117] Referring to FIG. 8, the server 10 can receive the mapping accuracy scores between a plurality of generative AI servers (the first generative AI, the second generative AI, and the third generative AI), the API functions corresponding to the administrator review, and the threat behaviors. The mapping accuracy scores can be calculated by reflecting the predetermined weighting values corresponding to the plurality of generative AI servers and the administrator review.

[0118] Referring to FIG. 8, in the first table, the mapping accuracy score between the first API function and the first threat behavior was calculated to be 8.3 points, and the mapping accuracy score between the second API function and the second threat behavior was calculated to be 7.6 points. Here, the weighting value can be provided to the scores for the plurality of generative AIs for the mapping accuracy.

[0119] Here, in the calculation of the mapping accuracy score between the second cloud and the second API function, it can be seen that the mapping accuracy score of the second generative AI is 3 points, and the server 10 detected the mapping accuracy score of the second generative AI as an outlier. In such a case, it can be determined that the mapping accuracy between the second cloud and the second API function is low, and the mapping information can be corrected by mapping the second API function to the first threat behavior.

[0120] Also, referring to FIG. 8, in the second table, the mapping accuracy score between the first API function and the first threat behavior was calculated to be 9.5 points, and the mapping accuracy score between the second API function and the second threat behavior was calculated to be 9.2 points. Here, it can be determined that both mapping accuracies are high.

[0121] In such a case, it may be appropriate to modify the mapping information for the first and second API functions. Referring to the second table, the similarity score between the first API function and the second API function displayed at the bottom of the table is shown. In the second table, the similarity score between the first API function and the second API function is 6.5 points, and it can be determined that the degree of similarity is lower than the reference value. In such a case, the server 10 determines that the mapping between the API and the threat behavior is properly executed, and the matching between the APIs is inappropriate, and thus cannot modify the mapping information.

[0122] FIG. 9 is a flowchart for explaining a method for determining a countermeasure solution based on a corresponding scenario of a threat scenario including a threat behavior according to an embodiment of the present invention.

[0123] In step 910, the server 10 can detect the event information of the second API function of the user in the second cloud environment.

[0124] Then, the server 10 can confirm that the second API function corresponds to the first threat behavior. Specifically, the server 10 monitors the log data, usage pattern, network traffic, system warnings, etc. of the second API function, determines whether it matches the first threat behavior, and if there is a mode that matches the first threat behavior, it can be confirmed by the occurrence of the first threat behavior.

[0125] In step 920, the server 10 confirms the corresponding scenario for the threat scenario including the first threat behavior in the first cloud environment.

[0126] The server 10 can confirm the corresponding scenario for the threat scenario including the first threat behavior in the first cloud environment. When the server 10 confirms the corresponding scenario that can be executed in the first cloud environment, it can execute the corresponding scenario in the second cloud environment based on the corresponding scenario.

[0127] Here, a response scenario means a series of devices and strategies developed to respond to specific threat behaviors. For example, a response scenario can correspond to a detailed description, an illustrative example of use, and a defense strategy for each attack method stored in the MITRE ATT&CK, which is an attack technique database.

[0128] Server 10 can confirm a response scenario for a corresponding threat behavior in a different cloud environment excluding the second cloud environment for a threat behavior similar to a threat behavior that can occur in the second cloud environment. For example, Server 10 examines security incident records, threat analysis reports, response protocols, etc. of the first cloud environment for the first threat behavior that occurred in the first cloud environment and is similar to the first threat behavior that occurred in the second cloud environment, and / or can grasp specific measures taken when the first threat behavior occurred, such as strengthening network traffic monitoring, modifying vulnerable API functions, activating a security warning system, etc.

[0129] In step 930, Server 10 determines a response solution in the second cloud environment based on the response scenario.

[0130] Server 10 can confirm a response scenario for a threat scenario including the first threat behavior in the first cloud environment, and determine, as a response solution, a response scenario applicable in the second cloud environment among the confirmed response scenarios.

[0131] In step 931, Server 10 confirms the first response API function used in the first cloud environment included in the response scenario.

[0132] Server 10 can analyze the nature, usage, security functions, etc. of the API functions used in the response scenario of the first cloud environment. Specifically, it can be a list of API functions used to respond to specific threats in the first cloud environment and detailed information on how each API function mitigated and / or responded to the corresponding threat.

[0133] For example, if the response API function used to address the data leakage threat in the first cloud environment includes data encryption, enhanced access control, or traffic monitoring, etc., the server 10 can analyze the details of such an API function and identify an API function applicable to addressing similar security threats in the second cloud environment.

[0134] In step 933, the server 10 checks for a second response API function corresponding to the first response API function among the API functions used in the second cloud environment.

[0135] The server 10 can identify a second response API function that corresponds to or is similar to the first response API function of the first cloud environment among the API functions used within the second cloud environment and can execute the same or similar functions.

[0136] The server 10 analyzes the core characteristics and functions of the first response API function and can find an API within the second cloud environment that provides similar and / or identical functions. For example, if there is an API responsible for data encryption in the first cloud environment, the server 10 can find an API that provides a similar encryption function in the second cloud environment.

[0137] FIG. 10 is a diagram illustrating an example of a process for determining a response solution based on a response scenario for a threat scenario including threat behaviors according to an embodiment of the present invention.

[0138] Referring to FIG. 10, the first cloud environment can be Amazon Web Services (AWS), and the second cloud environment can be Microsoft Azure.

[0139] Referring to FIG. 10, the server 10 can confirm that in the second cloud environment, the second API function corresponds to "Exfiltration" based on the event information of the user's second API function, and in the first cloud environment, for the corresponding threat scenario, the response scenarios include "Enhanced network monitoring", "Analysis of encrypted communication channels", "Logging and monitoring of the AWS CloudTrail infrastructure", "Enhanced user privilege management", "Automated response to the AWS Lambda infrastructure", and "Data access control through the Amazon S3 bucket policy".

[0140] The server 10 can explore threat scenarios associated with the first threat behavior and corresponding solutions in the second cloud environment. However, in some cases, such threat scenarios and corresponding solutions may not be available in the second cloud environment. Also, in some cases, although such threat scenarios and corresponding solutions are available in the second cloud environment, it may be possible to additionally refer to threat scenarios and corresponding solutions in different cloud environments. In such cases, the following methods can be executed.

[0141] Referring to FIG. 10, the server 10 can confirm the response scenarios including the first threat behavior in the first cloud environment. And the server 10 can identify the targets that can be executed in the second cloud environment with the confirmed response scenarios. Referring to FIG. 10, the server 10 confirmed 6 response scenarios in the first cloud environment, and among them, 3 response scenarios can also be applied in the second cloud environment.

[0142] The server 10 can execute the corresponding solutions for the first threat behavior in the second cloud environment with the 3 response scenarios confirmed in such a way.

[0143] The technical features disclosed in each embodiment of the present invention are not limited to the corresponding embodiment only. As long as they are not mutually exclusive, the technical features disclosed in each embodiment can be combined and applied to different embodiments.

[0144] Therefore, each embodiment will be described centering on its respective technical features. However, as long as the technical features are not mutually incompatible, they can be combined and applied to each other.

[0145] The present invention is not limited to the above-described embodiments and the attached drawings, and various modifications and variations are possible from the perspective of those having ordinary knowledge in the field to which the present invention pertains. Therefore, the scope of the present invention should be determined not only by the claims in this specification but also by those equivalent to this claim.

Explanation of Reference Numerals

[0146] 10 Server 20 First Cloud Server 30 Second Cloud Server 40 Generation AI Server 50 User Terminal

Claims

1. A method for a server to map API functions to threat behaviors in multiple cloud environments, comprising: a) mapping a first API function used in a first cloud environment provided by a first cloud server to a first threat behavior included in an attack technique database (wherein the attack technique database includes multiple threat behaviors classified into multiple types); b) generating feature information of the first API function based on description information about the first API function provided by the first cloud server; c) identifying a second API function that matches the first API function among at least one API function used in a second cloud environment provided by a second cloud server based on the feature information of the first API function; d) mapping the second API function to the first threat behavior. A method for mapping API functions to threat behaviors in multiple cloud environments.

2. The step b) includes: transmitting a first request prompt to a generative AI server to summarize description information about the first API function and request summary information for the first API; receiving, from the generative AI server, the summary information for the first API according to the first request prompt; generating the feature information of the first API function based on the summary information for the first API. A method for mapping API functions to threat behaviors in multiple cloud environments according to Claim 1.

3. The step b) further includes: identifying a service executed in the first cloud environment when the first API function is executed, and the feature information is further based on information about the service. A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 2.

4. The step c) includes: generating feature information of the second API function based on the description information of the second API function provided by the second cloud server; requesting the generating AI server for similarity information between the feature information of the first API function and the feature information of the second API function, and receiving the similarity information from the generating AI server; determining that the first API function and the second API function are similar API functions based on the similarity information; identifying the second API function with an API function matched to the first API function. A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 1.

5. There are a plurality of the generating AI servers, and the similarity information includes a plurality of similarity information generated from the plurality of generating AI servers. In the step of determining with the similar API functions, the server compares the plurality of similarity information to determine whether the first API function and the second API function are similar. A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 4.

6. A predetermined weight value is applied to the plurality of similarity information by the corresponding generating AI server. A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 5.

7. The step of generating the feature information of the first and second API functions includes: summarizing the description information of the first and second API functions to the generating AI server, and transmitting first and second request prompts for requesting summary information for the first and second APIs; Receiving summary information for the first and second APIs from the generation-based AI server according to the first and second request prompts; Generating feature information of the first and second API functions based on the summary information for the first and second APIs, including; The method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 4.

8. The first and second request prompts include content requesting to generate summary information for the first and second APIs by the same table of contents items. The method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 7.

9. The step of identifying the second API function is Further including the step of checking a term database in which terms used in the first and second cloud environments are matched with each other, In the step of receiving the similarity information, the server provides information on the term database in the generation-based AI server and requests to generate the similarity information based on the term database. The method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 4.

10. Confirming the occurrence of the first threat behavior based on the event information of the user's second API function in the second cloud environment; Confirming a corresponding scenario for the threat scenario including the first threat behavior in the first cloud environment; Determining a corresponding solution in the second cloud environment based on the corresponding scenario, including. The method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 1.

11. The step of determining the corresponding solution is A step of verifying a first corresponding API function used in a first cloud environment included in the corresponding scenario; Including a step of verifying a second corresponding API function corresponding to the first corresponding API function among the API functions used in the second cloud environment; A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 10.

12. Executed between the step c) and the step d), A step of verifying information for mapping the second API function to a second threat behavior included in the attack technique database (wherein the first and second threat behaviors are different threat behaviors from each other); Further including a step of comparing the mapping accuracy of the first mapping information mapping the first API function and the first threat behavior and the second mapping information mapping the second API function and the second threat behavior; When the mapping accuracy of the first mapping information is higher than the mapping accuracy of the second mapping information, the step d) is executed; When the mapping accuracy of the second mapping information is higher than the mapping accuracy of the first mapping information, instead of the step d), a step of mapping the first API function to the second threat behavior is executed; A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 1.

13. The first mapping information includes a plurality of mapping index information for the first API function and the first threat behavior received from a plurality of generative AI servers; The second mapping information includes a plurality of mapping index information for the second API function and the second threat behavior received from a plurality of generative AI servers; In the step of comparing the mapping accuracy, the server determines based on the outlier information of the plurality of mapping index information included in the first and second mapping information; A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 12.

14. The attack technique database includes information on the type of attack technique, description information of the attack technique, and information on detailed techniques included in the attack technique (wherein the type is a superordinate concept including at least one of the attack techniques, and the attack technique is a superordinate concept including at least one of the detailed techniques). A method for mapping API functions to threat behaviors in a plurality of cloud environments according to claim 1.

Citation Information

Patent Citations

  • Topology-based management of second-day operations

    JP2017534109A

  • Cloud security topology visualization device and integrated cloud workload operation and security management system using the same

    JP7121437B1

  • Rest API Scanning for Security Testing

    US20220006829A1

  • Systems and methods for identifying, deterring and / or delaying attacks to a network using shadow networking techniques

    KR1020150008158A