Adaptive Security for Resource-Constrained Devices

By collecting and analyzing threat intelligence data, the method optimizes security measures on resource-constrained devices to efficiently protect against cyberattacks, addressing the limitations of traditional security solutions in IoT devices and other constrained systems.

JP7714646B2Active Publication Date: 2025-07-29KYNDRYL INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023526177
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-10-28
Filing Date
2021-10-07
Publication Date
2025-07-29
Estimated Expiration
2041-10-07

AI Technical Summary

Technical Problem

Devices with computing resource constraints face challenges in effectively protecting against cyberattacks due to limited computing power and memory, which are exacerbated by the increasing number of IoT devices and the high resource demands of traditional security solutions.

Method used

A method and system that collect threat intelligence data in the form of Indicators of Compromise (IoCs), determine the relevance and resource consumption of security countermeasures, and dynamically enable/disable measures to optimize protection using available resources, leveraging threat intelligence and adaptive security management.

Benefits of technology

This approach provides effective cyber threat protection for resource-constrained devices by intelligently allocating resources, balancing computing capabilities with 'good enough' protection, reducing power consumption, and enabling adaptive security measures to counter potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007714646000013
    Figure 0007714646000013
  • Figure 0007714646000014
    Figure 0007714646000014
  • Figure 0007714646000015
    Figure 0007714646000015
Patent Text Reader

Abstract

A method for providing protection for a computing-resource-constrained device against cyber attacks includes collecting threat intelligence data in the form of indicators of compromise (IoCs). The indicators include data related to a cyber attack chain. The method also includes determining the relevance of the cyber attack chain for the device, measuring utilization of security measures with respect to their detection of the IoCs and their respective responses to the plurality of IoCs, measuring resource consumption of the security measures, and determining a benefit value for at least one security measure represented by its utilization and the relevance value of the plurality of IoCs detected therewith.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to security methods, and more specifically to methods for protecting devices with computing resource constraints against cyberattacks. The present disclosure further relates to a security system and a computer program product for protecting devices with computing resource constraints against cyberattacks.

Background Art

[0002] The development of the EDVAC system in 1948 is often cited as the beginning of the computer age. Since then, computer systems have evolved into extremely complex devices. Today's computer systems typically include a combination of advanced hardware and software components, application programs, operating systems, processors, buses, memories, input / output devices, and the like. Advances in semiconductor processing and computer architecture have pushed performance higher and higher, and more advanced computer software has evolved to take advantage of their higher capabilities, resulting in today's much more powerful computer systems compared to just a few years ago.

[0003] Big data is one application of these new capabilities. Big data produces impressive results and enables new and amazing insights to be derived by reading through and reaching the end of amounts of data that were previously unmanageable (e.g., data generated by so-called Internet of Things (IoT) devices), thereby enabling conclusions to be drawn from patterns that would otherwise be incomprehensible.

[0004] However, the cost of big data solutions means that the benefits of insight-based policy-making in IT security are limited to enterprises and organizations that have means to deploy the required hardware, giving them an advantage and protection over others. Big data solutions also tie up increasing amounts of resources (e.g., power, hardware) to run the security infrastructure. Considering the current trend of attaching more IoT devices to fill data lakes within IT centers to enable more big data analytics, this gap is likely to continue to widen.

Summary of the Invention

[0005] According to one aspect, a method may be provided for protecting a device with computing resource constraints against cyberattacks. The method may include collecting threat intelligence data in the form of Indicators of Compromise (IoCs). The indicators include data related to the cyberattack chain. The method also includes determining the relevance of the cyberattack chain for the device and measuring security countermeasures Use with respect to their detection of each of those IoCs and their respective responses to the IoCs. Additionally, the method includes measuring the consumption of at least one resource of the security countermeasures. Further, the method includes determining a benefit value for at least one of the security countermeasures, expressed by its Use and the value of the relevance of the IoCs detected using it.

[0006] According to another aspect, a security system may be provided for protecting a device with computing resource constraints against cyberattacks. The security system may include a memory operably coupled to a processor, and the processor uses program code stored in the memory to collect threat intelligence data in the form of a cyberattack chain including indicators of compromise (IoCs), determine the relevance of the cyberattack chain for the device, and measure the Use of security countermeasures with respect to their respective detection of those IoCs and their respective responses to the IoCs. Further, the processor of the security system uses program code stored in the memory to measure the resource consumption of at least one of the security countermeasures and determine at least one benefit value of the security countermeasure, expressed by that Use and the relevance value of the detected IoC thereby.

[0007] Furthermore, an embodiment may take the form of a computer program product accessible from a computer-usable or computer-readable medium providing program code for use by or in relation to a computer or any instruction execution system. For the purposes of this specification, a computer-usable or computer-readable medium may be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in relation to an instruction execution system, apparatus, or device.

[0008] The drawings included in this application are incorporated in and constitute a part of this specification. These illustrate embodiments of the disclosure and, together with the specification, serve to explain the principles of the disclosure. The drawings are only exemplary of particular embodiments and do not limit the disclosure.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

[0010] The present invention accepts various modifications and alternative forms, and the details are shown in the drawings by way of example and will be described in detail. However, it should be understood that the intention is not to limit the present invention to the specific embodiments described. Rather, the intention is to protect all modifications, equivalents, and alternatives within the spirit and scope of the present invention.

[0011] Aspects of the present disclosure relate to security methods, and more particular aspects relate to protecting devices with computing resource constraints against cyberattacks. The present disclosure is not necessarily limited to such applications, but various aspects of the present disclosure can be understood in this context through discussions of various specific examples.

[0012] In the context of the present disclosure, the following conventions, terms, and / or expressions may be used:

[0013] · The term "computing resource constrained device" may refer to, for example, an edge device in a computing network environment. The device may be equipped with a battery, for example, such that energy-saving techniques are used. It may also include, for example, reducing computing power or shutting down unused peripheral components. Edge devices often include cost-effective hardware that supplies only the minimum amount of computing power required for the current task. Thus, such a device may be configured to have only the amount of computing resources to satisfy the sole purpose of that device. Spare resources are typically not introduced. Therefore, there are constraints on the computing power of such a device.

[0014] · The term "security threat" may represent a possible risk that can be exploited to violate the security of an information technology system and thus may cause a possible harm. This term relates to the technical field of computer security and may describe a potential attack on data in a computer or memory system by an intruder or intruder system, unauthorized access, potential destruction or manipulation, or hijacking of control of a computer, storage, or communication system. A security threat may originate from a cyberattack.

[0015] · The term "cyberattack" may represent an attempt to access computing devices connected to a data network, such as IoT or edge devices (or any other computing device). A cyberattack can occur as a single security threat, i.e., a single cyberattack, or as a series of such single cyberattacks, most of which do not represent a real danger to a particular device.

[0016] · The term "cyberattack chain", often also referred to as "cyber kill chain", may represent a sequence of sub-attacks on a computer or similar system. Each stage of the sequence is built on the previous stage. For example, there are theoretical models with seven and eighteen stages respectively of a sequence or chain of cyberattacks. In the course of the present disclosure, the terms "sequence of partial cyberattacks", "cyberattack chain" and "cyber kill chain" may be used synonymously. Such a cyberattack chain can be particularly dangerous for devices with limited computing capabilities, because such devices may not have the computing power or required memory to follow a sequence of partial attacks.

[0017] · The term "threat intelligence data" or "cyber threat intelligence data" may represent information about threats and threat actors from a cyber threat intelligence system that can help mitigate adverse events in the cyber space. Sources of cyber threat intelligence may include open source intelligence, social media intelligence, human intelligence, technical intelligence, or intelligence from the deep and dark web. Providers of cyber threat intelligence data may include IT vendors and government agencies, which may collaborate and exchange intrusion data on cyber risks to protect IT systems from security attacks.

[0018] · The term "indicator of compromise (IoC)" may represent a reliable artifact indicating a computer intrusion, for example, observed on a network or within an operating system, in computer forensics and IT security. Typical IoCs may include virus signatures and IP addresses, MD5 hashes of malware files, and / or URLs or domain names of botnet command and control servers. After IoCs are identified in the process of incident response and computer forensics, they can be used to detect future attacks early using intrusion detection systems and antivirus software. Known indicators can be exchanged within the industry. IoCs can be used to detect cyberattacks early. They can also be used to identify partial cyberattack chains, for example, at an early stage such as during the first or second wave of a chain.

[0019] · The term "relevance of the cyberattack chain" can, for example, represent the importance of a particular cyberattack or security threat of the cyberattack chain against a given device with certain resource constraints. For example, if the device is not operationally active on or against an SQL database, the relevance of a cyberattack chain aimed at weakening the integrity of the SQL database, such as an SQL injection, can be considered low or almost non-existent.

[0020] · The term "security measure" can represent an action or function to counter a cyberattack or to detect such a cyberattack or an attempt thereof. Further, if a security measure reduces a known threat to the assets of a device that is inherently vulnerable to the threat in principle, that security measure can be defined as relevant. The relevance for newly discovered security problems will be extremely high even if no hits / discoveries have been recorded so far. In this case, the value of a given security measure is very likely to be very high in anticipation of an imminent possible attack. More details on the dependencies for the calculation of the value of a security measure are explained in the context of FIG. 2.

[0021] · The term "response to the IoC" can refer to activities that a device and / or its operating software can undertake to counter a security threat. This may include deletion of the received data or signal, or at least separation or suppression.

[0022] · The term "resource consumption" can represent the amount of computing resources and / or energy required to execute a specific, typically pre-defined task.

[0023] · The term "benefit value" may represent the sum of values across all IoCs. This may require a basic relevance (e.g., = 1) for all IoCs not included in the threat intelligence feed. For example, each port scan detected and blocked by a firewall originating from an Internet Protocol (IP) address not listed as an IoC adds a base value to the security countermeasure firewall.

[0024] · The term "susceptibility value" may represent a value that grades the applicability of the cyber - attack chain to the environment by including components of the environment, which may be expressed by the detection of IoCs related to cyber - attacks.

[0025] Cyber - security attacks are, among other things, the greatest concern of IT (Information Technology) departments, enterprises, and government agencies. This concern is likely to further increase because new regulations such as the General Data Protection Regulation (GDPR) can impose high financial costs and penalties on enterprises if they do not properly protect their customers' data. As a result, the role of the Chief Information Security Officer (CISO) is becoming increasingly important.

[0026] One of the important tasks of a CISO is to manage the organization's Security Information and Event Management (SIEM) solution. Today, most of the SIEM solutions available in the market utilize a complex set of correlation rules that must be monitored and tuned by highly skilled personnel to identify and detect potential security threats that could lead to security incidents. These SIEM correlation rule engines require relatively high system resources (e.g., in the form of CPU time and memory requirements), as the correlation words are designed based on regular expression (regex) filters and thresholds to match a set of conditions and cross-dependencies, and the set of conditions and cross-dependencies, in turn, requires that a vast amount of security events be received and written to log files while being checked, estimated, or evaluated in real time. For example, security events and logs generated in a typical IT environment, as well as those generated by endpoint devices of security solutions, can vary between 1k EPS (events per second) and 100k EPS and may need to be correlated across an average of about 150 to 400 separate sets of rules. Thus, most SIEM systems have a very high demand for computer system resources.

[0027] As the number of information technology devices to be deployed and the network grow ever larger, these difficulties are likely to increase further. Worse still, the average computing power available per device does not increase at the same rate, partly because a large number of so-called Internet-of-Things (IoT) devices are connected to the data network. In these IoT devices, typically, the focus is on the lowest possible power consumption for very specific tasks. Thus, the computing resources available in such devices may be sufficient to meet the design goals (i.e., the specific tasks for which they are developed), but may not be so for increasing security requirements.

[0028] In a device with limited resources, the gap between the risk or part of a cyber attack or cyber attack chain and the available resources can potentially be advantageously filled. Thus, some embodiments of the present disclosure provide protection for devices with computing resource constraints against cyber attacks, enabling protection against cyber threats suitable for devices having only limited spare capacity to handle unplanned computing requirements due to cyber attacks. Embodiments can provide a number of advantages, contributions, and technical effects, including effectively activating protection against cyber threats. In some embodiments, a few of the available resources may be intelligently used to address only these potential threats associated with the device. This can be achieved, in some embodiments, by determining relevance level values and benefit values based on IoC. In this way, in a computing environment where low cost and low power consumption are success factors but which can also be targeted by cyber threats, a permanent balance can be achieved, in particular, between the resources invested in computing capabilities and "good enough" protection. This can be particularly beneficial for low-cost, low-power, and lean endpoint devices (e.g., IoT devices deployed in large numbers in modern manufacturing, logistics, smart city, or smart home environments). Some embodiments may be advantageously used, for example, in smart vehicles such as autonomous cars or in surveillance infrastructure.

[0029] Furthermore, by sharing security or protection measures, a group of low-cost and / or low-power devices can share the resources and / or computational results required to protect each individual device, thereby sharing the protection load.

[0030] Moreover, even in an IT system with well-equipped computing facilities, typically assumed to have unlimited resources available for cyber protection, the newly proposed concept can be beneficially used. Here, low power consumption can be a result of implementing the proposed concept in such an IT system. This can be a useful contribution to environmental protection.

[0031] According to one possible embodiment, the method may include assigning a sensitivity value to each of the cyber attack chains based on the benefit value of security measures that contribute to blocking the cyber attack chain. The sensitivity value can then be used to rate the applicability of the cyber attack chain to the environment (e.g., by evaluating the components of the environment), which may be represented by the detection of IoCs related to the cyber attack.

[0032] According to another possible embodiment, the method may also include determining a value of effectiveness for each security measure by summing up the contribution of a particular security measure to blocking each of the attack chains as protection for the device, based on the sensitivity value. The value of effectiveness can then be a representation of the likelihood of success of the device's protection against cyber attacks, especially against those coming in waves. Each wave, away from the last one, may not be a threat to the device's data and / or functionality on its own. However, the value of effectiveness can represent the effectiveness of one of the waves (from the attacker's perspective) in rendering the entire attack chain ineffective as a result.

[0033] According to some embodiments, the method may also selectively enable and / or disable security measures such that the effectiveness values of all enabled security measures are optimized for blocking a cyber attack chain using an amount of available computing resources sufficient to meet the resource consumption of the enabled security measures. This can also be seen as a check-and-balance function between the uninterrupted functionality of the device, the device's response time to incoming useful signals, and incoming attack signals. Security measures (e.g., certain security functions) may be disabled if they are determined to be not effective in the current situation and / or if their use is determined to impose too heavy a computational load.

[0034] According to some embodiments of the present method, the determination of the relevance value for a security measure may be based on at least one factor selected from an external evaluation of the attack type, attack types which have always be taken into account, installed hardware and / or software, and installation-specific configurations. Representative examples of "attack types which have always be taken into account" may include, without limitation, SQL (Structured Query Language) injection, cross-site scripting, man-in-the-middle attacks, etc. This may be, for example, a typical attack that re-attacks the functions of a database to collect unauthorized data. In contrast, if no database is installed, some embodiments may be able to indicate not to use the selected security measures since the relevance associated with security measures that function against SQL injection would pose no threat in this scenario. Such enabling and disabling may also be possible for other security measures using the total of the installed hardware and software attached to and / or installed on the device.

[0035] In addition, certain industries are subject to specific government regulations and may in some cases require the use of certain security measures. Examples of such industries include the military sector, the insurance sector, the healthcare industry, and the banking sector.

[0036] According to some embodiments of the present disclosure, the benefit value assigned to a security measure may be determined by multiplying the number of times the security measure has detected an IoC by the relevance value of the corresponding IoC. In some embodiments, the benefit value may more specifically be

Number

[0037] In some embodiments, historical data may also be used to protect the device. In addition, the quality of the received indicators that contribute may play an important role. The higher the quality of the value of the indicator, the more likely a higher number of hits will be registered. This may then be interpreted as part of or as supporting the collective memory of the components of the disclosed security method and system.

[0038] According to some embodiments, the number of times a security measure can detect an IoC may need to exceed a minimum number. In some of these embodiments, the benefit value assigned to the security measure may be determined by the benefit value of the formula.

Number

[0039] According to some embodiments, the method may also include periodically re-determining the benefit value at a given time. Thus, the evaluation regarding the threat level may be performed at any time when necessary. This may vary depending on various environmental parameters such as other protections of the network to which the device is attached, the number of threats known for the type of device, the security level required for a given industry and its regulations, etc.

[0040] According to some embodiments, re-determining may include selectively applying security measures to selected ones of a group of devices. Assume that a plurality of computing-capability-constrained devices are connected to the same network, for example, or are deployed in the same or a similar industrial context. Only selected ones of the plurality may apply pre-defined security measures, while other devices within the same group may apply other selected security measures. This can be assumed because if one of a plurality of devices may be vulnerable to a cyber-attack, others within the same group may also be vulnerable. Thus, protective activities (e.g., security measures) may be shared among devices in the group. As a result, the devices can share the computing power required to protect all of them, so that the number of security measures that need to be applied to individual devices can be significantly reduced. If one of the groups detects a particular cyber-attack, it can notify others by sending a related signal. A security adjustment system connected to a plurality of computing-resource-constrained devices may adjust the use of individual devices for security measures. As a representative example, a virus scanner may be a security measure deployed for one of the devices in the group, while another device in the group may deploy a firewall.

[0041] According to some embodiments, the method may also include re-determining the benefit value when the amount of available resources in the device changes, or when a predefined significant set of the cyberattack chains significantly changes. These embodiments can assist in maintaining the security level of the device at a predefined level so as to reduce the overall risk as much as possible while considering the available resources.

[0042] The following paragraphs describe the detailed description of the embodiments shown in the drawings. All the indications in the figures are schematic. First, a block diagram of a method for providing protection for a device with computing resource constraints against cyberattacks, which is consistent with some embodiments, is given. Then, a security system for providing protection for a device with computing resource constraints against cyberattacks, which is consistent with some embodiments, will be described.

[0043] FIG. 1 shows a block diagram of an embodiment of a method 100 for providing protection for a device with computing resource constraints against cyberattacks. The method 100 can include collecting threat intelligence data in the form of indicators of compromise (IoC) 102. The indicator may include data related to a cyberattack chain.

[0044] The method 100 may also include determining the relevance of cyberattack chains for the device (e.g., using IoC) 104, and measuring the security measures Use with respect to the detection of each IoC and the corresponding response to each IoC 106, and based on this, measuring the resource consumption of the security measures 108. Then, the method 100 Useand determining a benefit value for at least one of the security countermeasures, expressed by these relevance values of the IoC detected thereby 110.

[0045] Additionally, method 100 may further include selectively enabling and disabling security countermeasures 112 such that the effectiveness value of the enabled security countermeasures is optimized for blocking the cyber attack chain using an amount of available computing resources sufficient to meet the resource consumption of the enabled security countermeasures.

[0046] FIG. 2 shows a block diagram 200 that illustrates some components that execute the proposed method and support the proposed security system, consistent with some embodiments. The units and modules discussed in this context focus on the computational costs and values achieved by the disclosed method. In the illustrated embodiments, these measurements need not be performed on each device. Rather, the devices may be grouped by type and exposure to threat situations. Further, enabling and disabling a function does not necessarily mean that the function is turned off / on. In some embodiments, enabling / disabling may be done by assigning a high / low (in LINUX (registered trademark) terms) nice factor, or a relatively low process priority in the WINDOWS (registered trademark) operating system (LINUX (registered trademark) is a trademark of Linus Torvalds in the United States, other countries or both, and WINDOWS (registered trademark) is a registered trademark of Microsoft Corporation in the United States, other countries or both).

[0047] The embodiment of FIG. 2 may include a resource monitor 202, a threat intelligence connector 204, a security connector 206, and a security countermeasure manager 208. The resource monitor 202 may be used to determine available net resources 210 (i.e., resources not currently being used by the operating system or any application) on the host system and, when a distributed architecture is used, on systems deployed remotely. The resource monitor 202 may be built with existing system profiling and benchmarking software (e.g., GeekBench (registered trademark) available from Primate Labs Inc) to determine a given “score” for the capabilities of the system (e.g., the system's resources 214 in the form of available CPU(s), RAM, disk I / O, network capabilities, etc.). However, in some embodiments, other approaches for measuring system performance, such as those commonly used in tests performed by computer hardware publications, etc., may be used. The score achieved may be handled as is or converted to performance points to be used by the security countermeasure manager 208.

[0048] As a representative example, a given reference CPU utilized per second is equal to 1 CPU point, 1 GB of RAM used per second is 1 RAM point, 100 disk I / O operations / second is 1 disk point, and 1 MB / second of data transfer is equal to 1 network point. The resource monitor 202 may determine a vector of independent performance points, e.g., (CPU, RAM, disk I / O, network) = (42, 2, 0.5, 4) performance points. Performance points may be treated as a vector because different security countermeasures consume different combinations of resources and often lack one resource that cannot be compensated for by using another.

[0049] Referring back to FIG. 2, the Threat Intelligence Connector (TIC) 204 can provide data from threat management sources such as the Threat Intelligence Database 212. The Threat Intelligence Database 212 may then provide data that is periodically fed to the Threat Intelligence Connector 204. Here, the threat intelligence data may be fed to the Security Countermeasure Manager 208 to calculate the value of each security countermeasure. The TIC may connect to publicly available open source intelligence feeds (Open Source Intelligence, or OSINT), commercial APIs (e.g., IBM X-Force Exchange® available from Armonk, New York), and custom intelligence sources deployed by the organization (e.g., an internal Security Operations Center (SOC)).

[0050] The Security Connector 206, in some embodiments, serves as the main interface to the application programming interface (API) of the Security System 218 and provides security countermeasures to endpoints / devices. The security connector can be used to query available security countermeasures (e.g., to detect patterns used to identify specially crafted packets, payloads, or sequences of requests); to measure the usage and benefits of security countermeasures per required performance, expressed as a value / cost (frequency of use, number of discoveries); and to identify relevant metadata (e.g., exploits, connections to campaigns (e.g., security attacks), number of common vulnerability identifiers (e.g., Common Vulnerabilities and Exposures (CVE)) protected against Tactics, Techniques and Procedures (TTP)) by leveraging the existing threat intelligence provided by the Threat Intelligence Connector 204, by using the API.

[0051] In addition, the security connector 206 can measure the resource consumption 216 of each security measure using existing tools such as the open source "dstat" tool, using system performance metrics such as I / O cycles, consumed CPU time, and memory usage.

[0052] The ratio / cost of a security measure may, in some embodiments, be defined by the number of signatures identifying a particular CVE (e.g., retrieved from a vendor's database), the number of complaints defined as likely to harm endpoints having a set of existing CEVs (e.g., retrieved from threat intelligence), the number of connections rejected by the host's intrusion protection system, and the like.

[0053] The security connector 206 can also enable / disable specific rules or product features within those functions using existing APIs to enable / disable those functions, and can create / delete rules to dynamically manage the system's rule set.

[0054] The security measure manager 208 can view both the current value of a given security measure (e.g., frequency of use, number of discoveries, current relevance) and the actual cost, from the perspective of the resource consumption of operating a given security measure.

[0055] For the calculation of resource consumption (i.e., cost), the resource consumption may be determined by on-the-fly measurement, by stand-alone measurement performed at low throughput times, or by a combination of both. The on-the-fly evaluation can, for example, look at the ratio performance / resource consumption of a particular security measure each time the associated Bayesian module is executed in the current traffic situation, which generates a CPU load of 5.79%, uses 130 MB of RAM, and takes 150 ms to complete without disk I / O. The cost determination may be executed continuously because a single measurement can lead to an inaccurate evaluation, and statistics regarding the consumption of processes in the actual system are collected, which may be stored in a log file. This log of historical data may be used to map security-related processes that update the average runtime and its standard deviation for each process of interest. Since the configuration on the device can change over time (e.g., other processes with high disk I / O consumption are started), a large weight may be given to the latest entry in the historical log. In some embodiments, the weight function in calculating the weighted average can exhibit exponential growth as shown in FIG. 4.

[0056] The stand-alone evaluation can subject a given security measure to a test set of standardized content to reach a benchmark. These stand-alone evaluations may be performed by the vendor of the security system and then may be treated particularly statically according to the proposed concept when deployed, or may be performed periodically to generate a benchmark for user-provided additions (e.g., RegEX match). In the latter case, historical log data is not required; however, since the benchmark mapping depends on the available resources, the current device consumption should be measurable. However, if only partial operating conditions are used as the benchmark, the remaining data may be dynamically extended using the on-the-fly method.

[0057] These measurements may be performed by using system-specific performance monitoring to collect performance data, for example, when attached to a particular threat and the threat is active, or by using product-specific measurement methods when a product of concern is exposed to them. For example, some security tools provide counters or measure the resource consumption of individual security technologies.

[0058] Continuing to refer to FIG. 2, security system 218 can enable security countermeasures such as, for example, antivirus, antimalware, network intrusion prevention, use of behavior analysis, web proxy data, security information and event monitoring (SIEM), all shown as 220. In some embodiments, the determination of the value of a security countermeasure may be calculated using the determined value of the security countermeasure, direct metrics (usage, number of discoveries, the more the better), and / or indirect metrics (e.g., relevance).

[0059] When reducing known threats to assets within a computing environment that is vulnerable to that threat in principle, the security countermeasure may be marked as relevant. The relevance value for a newly discovered security problem can be extremely high even if no hits / discoveries are currently recorded. In this case, the value of a given security countermeasure is likely to be very high in anticipation of a possible imminent attack.

[0060] In some embodiments, the dependencies for the calculation of the value of a security countermeasure include the following:

[0061] External evaluation (performed at installation and updated periodically): To determine the relevance vector, some embodiments link the metadata of a given security measure (e.g., CVE, attack type, etc.) and can match, for example, current security trends collected from OSNINT and commercial security intelligence. Countermeasures to protect against new exploits are thus rated as very valuable even if not seen in previous use. Also, if a cyber-attack is becoming widespread, its value may be re-evaluated. A particular attack that has been used over a long period (e.g., code SQL injection) can be considered "evergreen" and thus is always considered to be at least moderately valuable regardless of current use.

[0062] · Installed software: This value can take into account whether security measures are applicable to what the organization has actually developed or exposed. For example, if the organization does not have a deployed MySQL server, countermeasures to specifically protect the MySQL system are considered to have a very low value. Some embodiments can utilize data collected from an inventory scanner and / or vulnerability scanner to obtain knowledge about the organization's development structure.

[0063] · Custom configuration: This value may also be derived from the organization's needs, and organizations that use some embodiments may weight specific preferences depending on security exposures and their consequences. For example, some organizations may prefer protection against attacks on a given operating system. This information may be provided automatically as pre-defined parameters and / or using a hardware / software inventory scan.

[0064] As an example, threat intelligence in the known STIX (Structured Threat Information eXpression) format provides a rich set of attributes for evaluating values related to security measures, such as publication date, reliability, impact, probability, severity, detection motivation (rated from accidental 1 to revenge 9), industrial sector (insurance, mining, retail, etc.). In a specific implementation, a (sub)set of attributes is selected to create a multiplication factor. For example, the relevance to an IoC can be calculated as follows. [Number] In one embodiment, the value assigned to a security measure when an IoC is found (sporting) is determined as follows. [Number] Thus, 1 is selected as the base value to include the contribution of threats that have not yet been observed. In another implementation, the value assigned to a security measure when an IoC is found (spotting) is calculated as follows. [Number] In some embodiments, the contribution of the value may be given only for a plurality of bits above the base factor.

[0065] The overall value of the security measure can thus be defined as the sum of the values across all IoCs. This may be normalized against the base relevance (e.g., =1) for all IoCs not included in the threat intelligence feed. For example, each port scan detected and blocked by a firewall originating from an IP address not listed as an IoC can add a base value to the security measure firewall.

[0066] The following representative example focuses more on cyberattack chains, also known as "security cyberattack chains". While cost / value and resource data are provided, the system here has the task of finding the optimal combination of effective security measures that maximize the protection value and use the available resources most efficiently.

[0067] One approach to leveraging knowledge of value / cost per security measure is to focus on high-value measures per cost and throttle other measures. However, this approach may be vulnerable to changes in the attacker's approach. For optimal protection, some embodiments include a forward-looking approach (i.e., using predicted attacks) rather than a backward-looking approach (i.e., using data observed in the past). For this purpose, the scoring model may be extended not only to consider the effectiveness of individual methods but also to view the cyberattack chain. A cyberattack chain is a sequence of individual attacks and is also referred to as Tactics, Techniques, and Procedures (TTP) used as part of an attack campaign. By expanding the view to the cyberattack chain, some embodiments can handle several relatively small low-risk attacks that, when combined, may result in something of a greater risk.

[0068] The following representative examples are considered: For threat intelligence, TIC provides information about two ongoing campaigns in the form of two cyberattack chains that include corresponding Indicators of Compromise (IoC) and Common Vulnerability Identifiers (CVE). The security system can consider the following measures (Anti-Virus / Anti-Malware (AV / AM), Network Intrusion Prevention System (NIPS), User Behavior Analysis (UBA), Web Proxy (WP)).

[0069] The following table shows how each of the security countermeasures provided can function in the process of each cyber attack chain:

[0070]

Table 1

[0071] Generally, for each of the n cyber attack chains or cyber attacks provided by the TIC, a list of countermeasures may be stored along with the corresponding IoCs.

Number

Number

[0072]

[0073] One feature and advantage of the scoring model in some embodiments is to assess individual cyber attack chains based on the countermeasures utilized, their completeness / occurrence, and their indication strength. Since a cyber attack chain is composed of different steps (TPP, see above), the first step may be to identify and rate the prevalence of the steps. As a result, FIG. 5 shows an extended flowchart 500 of the steps of an embodiment of such an embodiment. However, FIGS. 3 and 4 should be considered before referring to FIG. 5. ​​FIG. 3 is a graph 300 showing the efficient use of resources to obtain sufficient results, which is consistent with some embodiments. The embodiments graphed in FIG. 3 are defined as maximum possible security (without considering costs such as computing costs), rather than aiming for the optimal security level for an environment with security constraints. Instead of using a set of static security controls, the purpose is to provide a system that can manage strictly limited system resources in a results-oriented manner.

[0074] In some embodiments, the system can treat a given system resource (e.g., CPU, capacity, memory, disk space, IO, network throughput, etc.) as a "budget" to be "consumed" (i.e., utilized) for managed and most effective security measures. In other words, the available resources can be used to optimize the efficiency of security measures.

[0075] Each security measure (e.g., pattern scan, deep packet analysis, sandboxing, etc.) may be measured by the resources required to perform past performance, the estimated current relevance, the estimated future relevance according to threat intelligence sources, and performance alignment. The system can then actively manage the security measures utilized by consuming the budget of available resources based on the received measurement results. In this way, some embodiments can optimize the limited budget for security success and the predefined requirements and the needs of the owning organization.

[0076] As a result, some embodiments can enable the deployment of an efficient and adaptive security blanket that depends on a resource budget and, as more low-power devices (e.g., routers, network switches, end-user hardware (e.g., mobile phones), and / or IoT devices, etc.) are added, depends on the currently estimated risk of incoming attack types that may increase over time. The resulting protection strength may not match the quality and scope of a system with a high-performance unlimited budget, but a dynamically optimized system can come close enough to provide better protection than a static approach.

[0077] This optimization is shown graphically in FIG. 3 using the measured results (y-axis) against the resources invested (x-axis). There may be a static approach available that would not allow the measured results without a minimum amount of resources invested. However, on the other hand, adaptive security can be achieved by efficiently using limited resources. This causes both the static and adaptive approaches to converge to complete security coverage at high resources. Use to complete security coverage.

[0078] FIG. 4 is a graph showing a graph 400 illustrating the weighted function effect of security-related process profiling for on-the-fly evaluation, consistent with some embodiments. In this graph 400, the weighting factor (y-axis) increases over time (x-axis), forming a parabola 402 and reaching a specific value 404 for the current time.

[0079] Figure 5 shows a sequence of operations consistent with some embodiments of the present disclosure. In Figure 5, the TIC first loads threat intelligence data in the form of cyber attack chain information into the security countermeasure manager (SMM) 502. Second, if the basic value >0 (referenced above) is selected in the implementation, the cyber attack chain may be prepared in advance 504 for each IoC for which its value is determined as follows.

Number

[0080] Third, when the attacker applies the TTP, the security countermeasure may be executed 506. Fourth, as described above, the value / cost ratio for each security countermeasure may be determined 508. In some embodiments, the value / cost ratio may be determined for each countermeasure rather than at the individual IoC level. Fifth, using the information about the IoC, the individual steps in each cyber attack chain may be identified 510, and using them, the individual security countermeasures that detected the IoC are assigned to their respective cyber attack chains.

[0081] As a sixth activity, the value / cost ratio may be determined for each cyber attack chain 512. This can occur in the following sub-activities: (a) The first countermeasure can detect the first IoC included in the cyber attack chain. (b) The value / cost ratio of the first countermeasure can be assigned to the cyber attack chain. (c) If the same countermeasure identifies the same IoC in another cyber attack chain, a bonus factor may be assigned to the countermeasure. For example, some embodiments can use the square root of the number of cyber attack chains that include the IoC. That is, if the IoC is detected only in this cyber attack chain, then the factor is 1 (i.e., no bonus), and if the IoC is detected in this cyber attack chain and three other cyber attack chains, the factor is sqrt(4) = 2. (d) If a first countermeasure repeatedly detects the same IoC (e.g., in either the same or different phases) within the same cyber attack chain, or detects other IoCs, a value may be added, but the cost does not change (e.g., because the overall resource consumption of the security countermeasure is observed, not per IoC). If other IoCs are discovered across cyber attack chains, a bonus factor may be applied per IoC per number of cyber attack chains. (e) If a second countermeasure identifies one or more IoCs in a cyber attack chain, the value of each countermeasure may be added, and the cost may be added. In some embodiments, no ratio is used here. In this way, as the cyber attack chain progresses, i.e., as the attacker gains an advantage, additional attention (e.g., in the form of resources) may be directed towards this cyber attack chain. This is expressed by a bonus factor similar to the above. For example, the bonus factor for the value is the number of countermeasures triggered by the cyber attack chain.

[0082] Seventhly, after a predetermined interval, the determination of the value / cost per security countermeasure may be ended 514.

[0083] Eighth, cyber attack chains may be evaluated. Each cyber attack chain may have values for each phase and a calculated cost. By disabling / enabling 516 security measures, the values / costs of each cyber attack chain change, and the overall value / cost changes. By disabling / enabling security measures, the overall value for the currently available limited resources is optimized (see the example below).

[0084] Ninth, the overall situation may be re-evaluated 516 after an interval. (a) After a predetermined time (e.g., n days), (b) after the set of cyber attack chains provided by the TIC has changed significantly, e.g., a certain percentage of the cyber attack chains are replaced with new cyber attack chains and / or a certain percentage of the IoCs of the existing cyber attack chains have changed, and / or (c) when the amount of available resources (average over a time span) has changed, this re-evaluation may be triggered 518. The determination occurs in the process activity 520. If re-evaluation is not required, - in the case of -Y, the process returns to the beginning - case (N).

[0085] For re-evaluation, security measures that were previously disabled should be re-enabled, but not necessarily simultaneously and not necessarily on all devices. When value / cost measurements are made on resource-constrained devices (see the first sentence of this chapter), depending on the current resource situation, enabling new security measures may require disabling currently implemented security measures and / or limiting their resource consumption. If the re-evaluation is triggered by a change in the amount of available resources in 9(c) and the conditions in 9(a) and 9(b) are not met, i.e., assuming the value / cost ratio for the security measures is the same, the method can continue the activity described under "Eighth". Otherwise, the method may continue with the first activity 502.

[0086] In the context of the above-described step-by-step approach, the following considerations should also be taken into account. The intent of 6(c) is that, in some embodiments, the same countermeasures for detecting IoCs present within a number of cyber-attack chains may consume resources only once for detection (and protection actions, such as removing an attached file containing a virus), but may disrupt various attack scenarios and thus be more valuable. This added value can be expressed as a bonus factor (e.g., here "n" to the power of the number of cyber-attack chains containing the IoC, where "n" is between 0.5 (moderate amplification) and 1 (high amplification)).

[0087] As an example for 6(d), cost may be defined as (CPU, RAM, I / O) performance points. An anti-malware scanner may consume (10, 5, 1). IOC1 has a relevance of 7 and may be discovered only in this cyber-attack chain, while IoC2 has a relevance of 5 and may be discovered in three other cyber-attack chains. In this example,

Number

[0088] In Activity 6(e), the bonus factor may be the nth power of the number of different security countermeasures invoked by the cyber attack chain, where n can be adjusted by varying n between 0.5 and 2. As an example, consider the cyber attack chain "malware". Even though countermeasures were appropriate to disrupt the cyber attack chain at an early stage, additional and / or other countermeasures may be required to counter it at later phases of the cyber attack chain. In this example, an employee may receive a malicious link via a personal email account (thereby bypassing the protected organization's mail system), and a web proxy may block the website. However, if the attacker creates a new website name / IP address, the web proxy may not block access, and an antivirus measure may prevent the installation of malware. This example is shown in Table 2:

[0089] [[Table 2]]

[0090] Since the same security countermeasure AV / AM is identifying IoCs in Phases 1 and 3, the values for Phases 1 and 3 are added (120 + 10), and since resource consumption occurs only once, there is no further cost. By disabling AV / AM, the value / cost in this example drops to 20 / (3,4,0). By disabling the web proxy, the value / cost in this example drops to 130 / (10,5,1) for this cyber attack chain.

[0091] In a typical environment, some embodiments may have 3 - dimensional or 4 - dimensional cost vectors for security countermeasures with n = 5, and may have hundreds of cyber attack chains provided by threat intelligence. To reduce the effort of finding the current combination of security countermeasures, the following can be considered:

[0092] ·When adding the costs of n security measures, the total resource consumption of each area can be compared with the available resources. In many environments, one of the resources (e.g., CPU) is the bottleneck. If so, the optimization process focuses heavily on this resource.

[0093] ·How the value per countermeasure is considered in each cyber - attack chain, i.e., how much each countermeasure contributes to each cyber - attack chain. Table 3 shows an exemplary case:

[0094]

Table 3

[0095] The value 0 in Table 3 means that the countermeasure does not contribute because it is not used to detect IoCs within the cyber - attack chain. For each countermeasure, the cost may be independent of its contribution to the cyber - attack chain. However, the value may depend on the IoCs provided by threat intelligence (along with these different value factors) and the actually detected IoCs. Depending on the available free resources, a countermeasure may be enabled / disabled. For example, if CPU resources are available but I / O reaches its usage limit, Countermeasure 1 AV / AM may be enabled and run with a high priority on a Windows® system (or a high nice factor on a UNIX® system).

[0096] FIG. 6 shows a block diagram of the elements of a proposed security device 600 that conforms to some embodiments. The embodiment of the security system in FIG. 6 includes a memory 602 operably coupled to a processor 604. The processor 604 can be configured as follows using the program code stored in the memory: · For example, the collection unit 606 collects threat intelligence data in the form of a cyber - attack chain including indicators of compromise (IoCs); · The determination unit 608 determines the relevance of the cyber - attack chain for the device; and · By the first or utilization measurement module 610a, with respect to these detections of each IoC and their respective responses to the IoCs, measure the Use security countermeasures. The security device 600 may be configured to measure the resource consumption of the security countermeasures by using the program code stored in the processor 604 and the memory by a second or resource consumption measurement module 612 (the first and second measurement modules may be the same or integrated), and · By the benefit value determination unit 614, determine the benefit value for each security countermeasure represented by Use that and the value of their relevance of the detected IoCs.

[0097] The units and modules may be communicatively and / or operably coupled. This applies in particular to the memory 602, the processor 604, the collection unit 606, the determination unit 608, the utilization measurement module 610, and the resource consumption measurement module 612. Alternatively, some or all may be connected to the internal bus system 616 of the security system.

[0098] Embodiments of the present disclosure may be implemented using substantially any type of computer, regardless of whether the platform is suitable for storing and / or executing program code. FIG. 7 shows, as an example, a computer system 700 suitable for executing program code related to the proposed method.

[0099] Computer system 700 is an example of a suitable computer system, and regardless of whether computer system 700 can implement any of the functionality described below and / or can execute it, it is not intended to imply any limitation on the scope of use or functionality of the disclosed embodiments described herein. In computer system 700, there are components, and the components are operable in a number of other general-purpose or special-purpose computing system environments or configurations. Examples of well-known computing systems, environments, and / or configurations suitable for use with computer system / server 700 include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems or devices, etc.

[0100] Computer system / server 700 may be described in the general context of computer system-executable instructions, such as program modules, executed by computer system 700. Generally, program modules may include routines, programs, objects, components, logic, data structures, etc. that perform particular tasks or implement particular abstract data types. Computer system / server 700 may be implemented in a distributed cloud computing environment where tasks are performed by remote processing devices linked through a communications network. In a distributed cloud computing environment, program modules may be located in both local and remote computer system storage media including memory storage devices.

[0101] As shown in FIG. 7, computer system / server 700 may be in the form of a general-purpose computing device. The components of computer system / server 700 may include, but are not limited to, one or more processors or processing units 702, system memory 704, and a bus 706 that couples various system components including system memory 704 to processor 702. Bus 706 may represent one or more of several types of bus structures including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, and a processor or local bus using any of a variety of bus architectures. By way of example, and without limitation, such architectures may include Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Extended ISA (EISA) bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus. Computer system / server 700 may also, in some embodiments, include various computer system readable media. Such media may be any available media that is accessible by computer system / server 700 and may include both volatile and nonvolatile media, removable and non-removable media.

[0102] System memory 704 may include computer system readable media in the form of volatile memory such as random access memory (RAM) 708 and / or cache memory 710. The computer system / server 700 may further include other removable / non-removable volatile / non-volatile computer system storage media. By way of example only, storage system 712 may be provided for reading from and writing to a non-removable non-volatile magnetic medium (not shown, typically referred to as a “hard drive”). Although not shown, a magnetic disk drive for reading from and writing to a removable non-volatile magnetic disk (e.g., a floppy disk (registered trademark)), and an optical disk drive for reading from or writing to a removable non-volatile optical disk such as a CD-ROM, DVD-ROM or other optical media may be provided. In such instances, each may be connected to bus 706 by one or more data media interfaces. As will be depicted and described later, memory 704 may include at least one program product having a set (e.g., at least one) of program modules configured to execute the functions of embodiments of the present disclosure.

[0103] The program / utility has a set (at least one) of program modules 716 and, by way of example, may be stored in memory 704 and includes, but is not limited to, an operating system, one or more application programs, other program modules, and program data, the same as is the case for operating system, one or more application programs, other program modules, and program data. The operating system, one or more application programs, other program modules, and program data or some combination thereof may then include an implementation of a networking environment. Program modules 716 can execute the functions and / or methodologies of embodiments of the present disclosure as described herein.

[0104] The computer system / server 700 may also communicate with one or more external devices 718 such as a keyboard, a pointing device, a display 720, one or more devices that enable a user to interact with the computer system / server 700, and / or any device that enables the computer system / server 700 to communicate with one or more other computing devices (e.g., a network card, a modem, etc.). Such communication may occur via an input / output (I / O) interface 714. Further, the computer system / server 700 can communicate with one or more networks such as a local area network (LAN), a wide area network (WAN), and / or a public network (e.g., the Internet) via a network adapter 722. As shown, the network adapter 722 can communicate with other components of the computer system / server 700 via a bus 706. Although not shown, other hardware and / or software components can be used in combination with the computer system / server 700. Examples include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archive storage systems.

[0105] In addition, a security system 600 for providing protection for devices with computing resource constraints against cyberattacks may be attached to the bus system 706. Alternatively, the security system 600 may be implemented using the computer system / server 700.

[0106] The descriptions of the various embodiments of the present disclosure are presented for purposes of illustration, but are not intended to be exhaustive or to limit the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to assist in explaining the principles of the embodiments, the practical application, or technical improvements found in the marketplace, and / or to enable those of ordinary skill in the art to understand the embodiments disclosed herein.

[0107] The present disclosure may be embodied as a system, method, and / or computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to execute aspects of the present disclosure.

[0108] The medium may be an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system for a propagation medium. Examples of computer-readable media may include semiconductor or solid state memory, magnetic tape, removable computer diskette, random access memory (RAM), read-only memory (ROM), rigid magnetic disk, and optical disk. Current examples of optical disks may include compact disk read-only memory (CD-ROM), compact disk read / write (CD-R / W), DVD, Blue-Ray Disk, and the like.

[0109] A computer-readable storage medium may be a tangible device that holds and stores instructions for use by an instruction execution device such as a processing unit. The computer-readable storage medium may be, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. Exemplary, non-limiting examples of more specific computer-readable storage media include a portable computer diskette, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick (registered trademark), a floppy disk (registered trademark), a punch card, or a mechanically encoded device such as a raised structure within a groove having recorded instructions, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium is not itself a propagated signal such as a radio wave, a freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through a fiber optic cable), or an electrical signal transmitted through a wire that is interpreted as a transient signal per se.

[0110] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computers / processing devices or to an external computer or external storage device via a network such as, for example, the Internet, a local area network, a wide area network and / or a wireless network or combinations thereof. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers or combinations thereof. A network adapter card or network interface in the computer(s) / processing device(s) can receive the computer-readable program instructions from the network and transfer the computer-readable program instructions for storage on a computer-readable storage medium within the respective computing / processing device(s).

[0111] Computer-readable program instructions for carrying out the operations of this disclosure may, without limitation, be assembly instructions, instruction set architecture (ISA) instructions, machine language instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, the one or more programming languages including object-oriented languages such as Smalltalk®, C++, or the like, and conventional procedural languages such as the C programming language or similar programming languages. The computer-readable program instructions may execute as a stand-alone software package, entirely on the user's computer, partly on the user's computer, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet service provider). In some embodiments, an electrical circuit may execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions to adapt the electrical circuit to carry out aspects of this disclosure, the electrical circuit including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA).

[0112] Aspects of the present disclosure will be described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions. These computer readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, implement means for implementing the functions / acts specified in the flowchart and / or block or both blocks or combinations of blocks. These computer readable program instructions may also be stored in a computer readable storage medium that can direct a computer, programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including instructions which implement aspects of the function / act specified in the flowchart and / or block or combinations of blocks.

[0113] The computer readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer implemented process, such that the instructions which execute on the computer, other programmable data processing apparatus, or other device implement the aspects of the function / act specified in the flowchart and / or block or combinations of blocks.

[0114] Flowcharts and / or block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions that include one or more executable instructions for implementing a particular logical function(s). In some alternative implementations, the functions noted in the blocks may occur out of the order shown in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may be executed in the reverse order, depending upon the functionality involved. It should also be noted that each block of the block diagrams and / or flowchart diagrams, and combinations of blocks in the block diagrams and / or flowchart diagrams, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.

[0115] The terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting of the present disclosure. As used herein, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. Further, as used herein, the terms “comprise” and / or “comprising” specify the presence of the stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0116] It is intended to include any structure, material, or act for performing a function in combination with other claimed elements, such that equivalent structures, materials, acts, and all means or step-plus-function elements in the following claims perform the function, as particularly claimed. The description of the present disclosure has been presented for purposes of illustration and description, but is not intended to be exhaustive or to limit the disclosure to the forms disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the present disclosure. Embodiments were chosen and described in order to explain the principles of the present disclosure and its practical application, and to enable others of ordinary skill in the art to understand the present disclosure with various modifications as suitable for the particular intended use.

[0117] Accordingly, the description of the various embodiments of the present disclosure is presented for purposes of illustration, but is not intended to be exhaustive or to limit the disclosure to the embodiments disclosed. Many changes and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein were chosen to explain the principles of the embodiments, the practical application, or a technical improvement found in the marketplace, or to enable others of ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A method for protecting a resource-constrained device against cyberattacks, comprising: collecting threat intelligence data, wherein the threat intelligence data includes indicators of compromise (IoCs), and the IoCs include data related to a cyberattack chain; determining the relevance of the IoCs for the device; measuring the utilization of security measures based on the number of detections of the IoCs, regarding the detection of the IoCs and their respective responses to the IoCs; measuring the resource consumption of the security measures among computing resources; determining a benefit value for the security measures, wherein the benefit value is determined based at least in part on the utilization and the relevance of the IoCs detected using the security measures; A method comprising the above steps.

2. The method according to claim 1, further comprising assigning a sensitivity value to each of the cyberattack chains, wherein the sensitivity value is based on the benefit value of the security measures contributing to the prevention of the cyberattack chain.

3. The method according to claim 2, further comprising determining an effectiveness value for each security measure by summing the contributions to the prevention of each cyberattack chain as protection for the device, based at least in part on the sensitivity value.

4. The method according to any one of claims 1 to 3, further comprising selectively enabling and disabling the security measures such that the effectiveness value of the enabled security measures is optimized for preventing the cyberattack chain using an amount of available computing resources sufficient to meet the resource consumption of the enabled security measures.

5. The determination of the benefit value for the security measures is based on: an external evaluation of the attack type, the installed hardware and / or software, and installation-specific configurations The method according to any one of claims 1 to 4, based on factors selected from the above.

6. The method according to any one of claims 1 to 5, wherein the benefit value assigned to the security measure is determined by multiplying the number of times the security measure has detected an IoC by the value of the relevance of the corresponding IoC.

7. The method according to claim 6, wherein the number of times the security measure has detected the IoC is greater than a predefined minimum number of times.

8. The method according to any one of claims 1 to 7, further comprising re-determining the benefit value at a predetermined time.

9. The method according to claim 8, wherein the re-determining includes selectively applying a security measure to a selected group of devices.

10. The method according to any one of claims 1 to 9, further comprising re-determining the benefit value when the amount of available resources in the device changes, or when a predefined critical set of the cyber attack chain changes.

11. A security system for providing protection for devices with computing resource constraints against cyber attacks, comprising a memory operably coupled to a processor, the processor using program code stored in the memory to collect threat intelligence data, the threat intelligence data including indicators of compromise (IoCs), the IoCs including data related to a cyber attack chain, collecting; determine the relevance of the IoCs for the device; measure the utilization of security measures based on the number of detections of the IoCs and their respective responses to the IoCs; measure the resource consumption of the security measures among the computing resources; determine a benefit value for the security measures, the benefit value being determined based at least in part on the utilization and the relevance of the IoCs detected using the security measures A security system configured to perform.

12. The processor is further configured to assign a sensitivity value to each of the cyber attack chains using the program code stored in the memory, the sensitivity value being based on the benefit value of the security measure that contributes to the prevention of the cyber attack chain, the security system according to claim 11.

13. The processor is further configured to determine a value of effectiveness for each security measure by summing the contributions to the prevention of each of the cyber attack chains as protection for the device, based on the sensitivity value, using the program code stored in the memory, the security system according to claim 12.

14. The processor is further configured to selectively enable and disable the security measures using the program code stored in the memory such that the effectiveness value of the enabled security measures is optimized for preventing the cyber attack chain using an amount of available computing resources sufficient to satisfy the resource consumption of the enabled security measures, the security system according to any one of claims 11 to 13.

15. The determination of the benefit value for the security measure is an external evaluation of the attack type, the installed hardware and / or software, and installation-specific configuration based on a factor selected from, the security system according to any one of claims 11 to 14.

16. The benefit value assigned to the security measure is determined by multiplying the number of times the security measure has detected an IoC by the relevance value of the corresponding IoC, the security system according to any one of claims 11 to 15.

17. The number of times the security measure has detected the IoC is greater than a predefined minimum number of times, the security system according to claim 16.

18. The processor is configured to re-determine the benefit value periodically using the program code stored in the memory, the security system according to any one of claims 11 to 17.

19. The security system according to any one of claims 11 to 18, wherein the processor is configured to re-determine the profit value when the amount of available resources in the device changes or when a predefined important set of the cyber attack chain changes, using the program code stored in the memory. [

20. ] A computer program for providing protection for a device with computing resource constraints against cyber attacks, the computer program including one or more computer-readable storage media having program instructions to be implemented, the program instructions being executable by one or more computing systems or controllers, and the one or more computing systems or controllers are caused to collect threat intelligence data in the form of a cyber attack chain including indicators of compromise (IoCs) by the one or more computing systems or controllers, the threat intelligence data including indicators of compromise (IoCs), the IoCs including data related to the cyber attack chain, and determine the relevance of the IoCs for the device by the one or more computing systems or controllers, measure the utilization of security measures with respect to the detection of the IoCs and their respective responses to the IoCs based on the number of detections of the IoCs by the one or more computing systems or controllers, measure the resource consumption of the security measures among the computing resources by the one or more computing systems or controllers, determine a profit value for the security measures by the one or more computing systems or controllers, the profit value being determined based at least in part on the utilization and the relevance of the IoCs detected using the security measures A computer program that causes the above to be executed.

Citation Information

Patent Citations

  • Information processing device and program

    JP2015130152A

  • Security measure planning support system and method

    JP2018077597A

  • Detecting sensitive data exposure via logging

    US20200336497A1