Method for generating mapping information for cloud events and mapping server

The method and mapping server address real-time user action determination in cloud environments by mapping events to tactics and techniques, enhancing security through immediate threat identification.

JP7768949B2Active Publication Date: 2025-11-12ASTRONSECURITY
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2023155444
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-07-07
Filing Date
2023-09-21
Publication Date
2025-11-12
Estimated Expiration
2043-09-21

AI Technical Summary

Technical Problem

Existing cloud computing environments struggle to determine user actions in real time, particularly malicious ones, due to varying event types across different cloud providers and lack of standardized definitions.

Method used

A method and mapping server that generate mapping information for cloud events by using an action database to map events to tactics and techniques, incorporating risk information and leveraging generative AI for undefined events.

Benefits of technology

Enables immediate determination of user behavior type and danger level through tactics and techniques, providing comprehensive and timely security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007768949000001
    Figure 0007768949000001
  • Figure 0007768949000002
    Figure 0007768949000002
  • Figure 0007768949000003
    Figure 0007768949000003
Patent Text Reader

Abstract

To provide a method and mapping server for generating mapping information for determining a user's action through a cloud event.SOLUTION: A method for generating mapping information for a cloud event includes: obtaining a document for any one mapping target event; based on the document, generating at least one of a topic and a keyword for the mapping target event; based on it, selecting one tactic to which the mapping target event is mapped, and selecting a technique to which the mapping target event is mapped; storing mapping information for the mapping target event in a mapping dictionary; and generating mapping information for each event and storing it in the mapping dictionary, thereby generating a mapping dictionary for at least some of the multiple events.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technology for determining user behavior through cloud events, and more particularly to a method for generating mapping information for cloud events that maps events collected through each cloud event received in a cloud computing environment to at least one of a plurality of tactics and at least one of a plurality of techniques. [Background technology]

[0002] Recently, cloud computing services have become commonplace due to the development and maximization of cloud technology. As cloud computing services become commonplace, it is becoming increasingly important to detect and protect against user actions that threaten security in a cloud computing environment.

[0003] In a cloud computing environment, user actions are collected as events through APIs, and the types of events collected vary depending on the type of user action. However, the same user action may be generated as different types of events on different cloud providers, and user actions are not defined according to the type of event.

[0004] Therefore, even if events are collected, it is difficult to determine user actions in real time, and it is particularly difficult to immediately determine a series of malicious user actions.

[0005] Therefore, there is an increasing demand for an immediate determination of whether a user's actions are malicious or not. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Republic of Korea Patent Publication No. 10-2022-008686 (Publication date: 2022.06.23.) Summary of the Invention [Problem to be solved by the invention]

[0007] The present invention aims to provide a method and a mapping server for generating mapping information for cloud events that maps a mapping target event among multiple events to at least one tactic and at least one technique that identifies an action corresponding to the event.

[0008] Another object of the present invention is to provide a method and a mapping server for generating mapping information for cloud events, including risk information for the events to be mapped when generating the mapping information. [Means for solving the problem]

[0009] The method for generating mapping information for cloud events and the mapping server of the present invention are a method in which a mapping server generates mapping information for a plurality of events provided by a cloud service, wherein the mapping server can use an action database including a plurality of techniques, where the plurality of techniques are included in any one of a plurality of tactical groups; 1) obtaining a document for any one of the events to be mapped, where the event to be mapped is any one of the plurality of events; 2) generating at least one of a topic and a keyword for the event to be mapped based on the document; 3) selecting a tactic to which the event to be mapped is to be mapped based on at least one of the topics and keywords; 4) selecting a technique to which the event to be mapped is to be mapped based on at least one of the topic and the keywords, where the selected technique is included in the selected tactic; 5) storing the mapping information for the event to be mapped according to 3) and 4) in a mapping dictionary; and 6) repeating steps 1) to 4) to generate a mapping dictionary for at least some of the plurality of events.

[0010] In one embodiment of the present invention, the method may further include steps of: 7) acquiring information on the inquiry event from the client; 8) searching for a response tactic for responding to the inquiry based on the mapping dictionary; 9) searching for one of a plurality of techniques included in the searched tactics; and 10) providing the client with the response techniques and tactics searched for the inquiry event in the form of mapping information.

[0011] In one embodiment of the present invention, the method may include steps of selecting a plurality of techniques that can be mapped to the event to be mapped in step 4), providing the plurality of techniques to at least one evaluator terminal, acquiring suitability information for the plurality of techniques from the at least one evaluator terminal, aggregating the suitability information to select one technique from the plurality of techniques, and storing the mapping information for the event to be mapped in a mapping dictionary.

[0012] In one embodiment of the present invention, the mapping information may include information on the risk level of the corresponding mapping target event.

[0013] In one embodiment of the present invention, the risk information may include basic risk information for the corresponding mapping target event itself and information on the linked risk taking into account the corresponding mapping target event and the first event occurring in the sequence.

[0014] In one embodiment of the present invention, when there are a plurality of first events, the information on the link risk level can be matched for each of the first events.

[0015] In one embodiment of the present invention, when a query event scenario including multiple query events is received from a client, risk information for each of the multiple query events can be selected differently depending on the type of technique or tactic for each event included in other query events of a previous time included in the query event scenario.

[0016] In one embodiment of the present invention, the method may include: 11) identifying an undefined event that is not included in the mapping dictionary; 12) receiving risk assessment information for the undefined event from a client terminal; 13) selecting, based on the risk assessment information, either a first method for adding the undefined event to the mapping dictionary or a second method for classifying the undefined event as a non-risk event; and 14) if the first method is selected, storing mapping information to which the undefined event is mapped in the mapping dictionary.

[0017] In one embodiment of the present invention, the step between the step 13) and the step 14) may further include a step of receiving mapping-related information for the undefined event from the client terminal, and in the step 14), the mapping information may be generated based on the mapping-related information.

[0018] In one embodiment of the present invention, the mapping related information may be based on at least one of topic and keyword information for the undefined event.

[0019] In one embodiment of the present invention, the step between step 13) and step 14) further includes a step of requesting mapping-related information for the undefined event from the generative AI server and receiving the mapping-related information from the generative AI server, and in step 14), the mapping information can be generated based on the mapping-related information.

[0020] In one embodiment of the present invention, the step of receiving the mapping-related information may include the steps of generating prompting information including information on the undefined event, the tactic, and the technique, transmitting the prompting information to the generative AI server to obtain answer information, and identifying the mapping-related information from the answer information.

[0021] In one embodiment of the present invention, the step of receiving the mapping-related information further includes a step of selecting at least one candidate tactic and technique based on information on the topic and keywords of the undefined event, which is performed before the step of generating the prompting information, and in the step of generating the prompting information, the information on the tactic and the technique included in the prompting information may be information on the candidate tactic and the candidate technique.

[0022] The mapping server for generating mapping information for cloud events of the present invention generates mapping information for a plurality of events provided by a cloud service, and includes a memory, a mapping dictionary, a plurality of tactics, and an action database including a plurality of techniques included in each of the plurality of tactics, and a processor connected to the memory and the action database and configured to execute instructions included in the memory, wherein the processor is configured to perform the following steps: 1) obtaining a document for any one of the events to be mapped, where the event to be mapped is one of the plurality of events; 2) generating at least one of a topic and keywords for the event to be mapped based on the document; 3) selecting a tactic to which the event to be mapped is to be mapped based on at least one of the topic and keywords; 4) selecting a technique to which the event to be mapped is to be mapped based on at least one of the topic and keywords, where the selected technique is included in the selected tactic; 5) storing the mapping information for the event to be mapped according to 3) and 4) in the mapping dictionary; and 6) repeating steps 1) to 4) to generate a mapping dictionary for at least some of the events.

[0023] In one embodiment of the present invention, the processor may further be configured to perform the steps of: 7) acquiring information on the inquiry event from a client; 8) searching for a response tactic to be used to respond to the inquiry event based on the mapping dictionary; 9) searching for one of a plurality of techniques included in the searched tactics; and 10) providing the client with the response techniques and tactics searched for the inquiry event in the form of mapping information.

[0024] In one embodiment of the present invention, the processor may further perform the steps of selecting information on a plurality of techniques that can be mapped to the event to be mapped in 4), providing the plurality of techniques on at least one evaluator terminal, acquiring suitability information for the plurality of techniques from the at least one evaluator terminal, aggregating the suitability information to select one technique from the plurality of techniques, and storing the mapping information for the event to be mapped in a mapping dictionary.

[0025] In one embodiment of the present invention, the mapping information may include information on the risk level of the corresponding mapping target event.

[0026] In one embodiment of the present invention, the risk information may include basic risk information for the corresponding mapping target event itself and information on the linked risk taking into account the corresponding mapping target event and the first event occurring in the sequence. [Effects of the Invention]

[0027] According to an embodiment of the present invention, the present invention has the advantage of enabling immediate determination of the type of behavior and whether it is dangerous through tactics and techniques, which are mapping information for cloud events occurring in a corresponding account. [Brief explanation of the drawings]

[0028] [Figure 1] 1 illustrates an example of a network environment according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram of a processor of a mapping server according to an embodiment of the present invention. [Figure 3] 1 is a general flowchart of a method for generating mapping information for a cloud event according to an embodiment of the present invention; [Figure 4] 10 is a flowchart illustrating a process when a mapping target event corresponds to a plurality of techniques according to an embodiment of the present invention. [Figure 5] 1 is a diagram illustrating an example of tactics and techniques according to an embodiment of the present invention. [Figure 6] 10 is a flowchart illustrating a process for generating risk level information according to an embodiment of the present invention. [Figure 7] 1 is a diagram illustrating determining a risk level according to the correlation of risk levels in an action scenario according to a first embodiment of the present invention. [Figure 8] 10 is a diagram illustrating determining a risk level according to the correlation of risk levels in an action scenario according to a second embodiment of the present invention. [Figure 9] 1 is a general flowchart of a method for mapping undefined events according to an embodiment of the present invention. [Figure 10] 1 is a general flowchart of a method for receiving mapping-related information from a generative AI server according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0029] Hereinafter, the embodiments disclosed herein will be described in detail with reference to the accompanying drawings, in which the same or similar components will be given the same reference numerals regardless of the drawing numbers, and redundant descriptions thereof will be omitted. Furthermore, in describing the embodiments disclosed herein, if a detailed description of related publicly known technology is deemed to obscure the gist of the embodiments disclosed herein, the detailed description will be omitted.

[0030] Terms including ordinal numbers such as first, second, etc. may be used to describe various components, but the components are not limited by these terms. These terms are used only to distinguish one component from another.

[0031] A singular expression includes a plural expression unless the context clearly dictates otherwise.

[0032] In this application, the steps described may be performed in any order except where a specific causal relationship dictates that the steps be performed in the listed order.

[0033] In this application, the terms "comprise" or "have" and the like are intended to specify the presence of any feature, number, step, operation, component, part, or combination thereof described in the specification, but should be understood as not precluding the possible presence or addition of one or more other features, numbers, steps, operations, components, parts, or combinations thereof.

[0034] The present invention will now be described with reference to the accompanying drawings.

[0035] FIG. 1 is a diagram illustrating an example of a network environment according to an embodiment of the present invention.

[0036] The network environment according to an embodiment of the present invention shown in FIG. 1 may include an API server 10, a document server 20, a client terminal 30, an evaluator terminal 40, and a mapping server 100.

[0037] The API server 10 is a device that executes an API (Application Programming Interface) according to predetermined rules or user requests. When the API server 10 executes an API, an event corresponding to the API is generated. Event information includes the name of the executed API event, the time of API execution, the API executor, and the response syntax of the event. Here, the response syntax refers to the grammar of information generated by the API server 10 executing the API. The API server 10 can provide such a response syntax to a user terminal.

[0038] The API server 10 may include an event recorder that stores information about the execution results of the API. The event recorder may store event information corresponding to the API executed by the corresponding server in the form of a database. For example, if the corresponding server is Amazon Web Services (AWS), the event recorder may be called a CloudTrail.

[0039] The document server 20 is a server that stores documents for events. Here, the documents for events may be document information that describes the document name, definition, function, request syntax format, description of parameters generated or provided by executing the API, and response syntax format, etc. For example, the output format of events may be JSON, YAML, YAML stream, Text, Table, CSV, etc.

[0040] Such event documentation can be provided in the form of a web page or a downloadable document by the document server 20. Such event documentation can be provided by event name, or sorted by event name, and provided in a searchable or list format.

[0041] The document server 20 can be created and managed by the same entity as the API server 10 that executes the API of the document it provides, or by an associated entity. Therefore, the document server 20 can selectively store documents of events that can be executed by the associated API server 10. The associated entity that creates and manages the document server 20 can be understood to be a cloud service provider, such as Amazon, Google, Microsoft, Oracle, or Naver, that operates a crowdfunding service. Meanwhile, the document server 20 can be implemented as being included in the mapping server 100.

[0042] The mapping server 100 may include a memory 110 , a processor 120 , a communication unit 130 and an activity database 140 .

[0043] The memory 110 functions as a storage medium and can store a number of application programs run by the mapping server 100, and data and commands for the operation of the mapping server 100.

[0044] The processor 120 controls the overall operation of the memory 110, the communication unit 130, and the behavior database 140 and performs a method of generating mapping information for events, thereby providing mapping information for queried events queried by the client terminal 30 and querying the evaluator terminal 40 for mapping information for events.

[0045] The processor 120 can collect event information from the event recorder of the API server 10 and collect documents for events included in the collected event information from the document server 20. The processor 120 can generate mapping information for each event based on the collected event information and documents, and store and manage the mapping information in a mapping dictionary in the behavior database 140.

[0046] Here, the mapping server 100 can be understood as Software-as-a-Service (SaaS) that provides cloud applications, IT infrastructure, and platforms with event mapping services to user terminals through an internet browser.

[0047] The communication unit 130 can communicate with the API server 10, the document server 20, the client terminal 30, and the evaluator terminal 40 via a network in a wired / wireless manner.

[0048] The behavior database 140 stores information on a plurality of tactics and information on a plurality of techniques included in each tactic, and can store a mapping dictionary generated by the processor 120. The mapping dictionary is record information in which a first event analyzed by the processor 120 is matched with mapping information determined in response to the first event, and this record information can be embodied in various forms, such as a table. The mapping information matched to one event includes one of the plurality of tactics and one of the plurality of techniques.

[0049] A tactic is a name that defines a user's normal or malicious behavior (hereinafter referred to as a "tactical behavior"), and a technique is a name that specifies the detailed behavior of the tactic. The processor 120 determines whether a generated event is normal or malicious using the tactic or technique for the API included in the event.

[0050] A plurality of tactics can be arbitrarily set by the creator, and can be set based on the order of attack actions.

[0051] An example of multiple tactics and multiple techniques will be described with reference to Figure 5. Figure 5 is a diagram showing an example of tactics and techniques according to an embodiment of the present invention.

[0052] Referring to Figure 5, the multiple tactics (A) can include reconnaissance, resource development, target approach, execution, and damage inflict. Reconnaissance is the act of collecting and exploring information, resource development is the act of establishing resources (e.g., accounts, infrastructure, etc.) for the target action, target approach is the act of approaching the target action, execution is the act of preparing the target action, and damage inflict corresponds to the target action.

[0053] Techniques (B) are specific actions that fall under tactics. For example, techniques (B) for reconnaissance include host information collection, organizational information collection, and identity information collection. Techniques for resource exploitation include infrastructure detection, account damage, infrastructure damage, and account opening. Techniques for target approach include application exploitation, hardware addition, supply chain compromise, and trust relationships. Execution techniques include account fabrication, software binary fabrication, access token fabrication, and domain policy modification.

[0054] Meanwhile, the behavior database 140 can store information about APIs executed by the API server 10. Such information about APIs can be generated based on event information about APIs collected from the API server 10 and document information about events collected from the document server 20.

[0055] The client terminal 30 refers to a terminal that receives a mapping service that generates mapping information for events provided by the mapping server 100. The client terminal 30 can also call an API by communicating with the API server 10 according to a predetermined rule or a user request. The results of an event executed by the API server 10 in response to a call from the client terminal 30 can be stored in the event recorder of the API server 10.

[0056] The evaluator terminal 40 is a terminal of an evaluator that evaluates which techniques correspond to the event to be mapped, which is requested by the processor 120. In this case, the processor 120 identifies a plurality of candidate techniques for the event to be mapped, and provides the candidate techniques to a plurality of evaluator terminals 40. The evaluator terminal 40 can then evaluate the appropriateness of each candidate technique for the API to be mapped, and provide the appropriateness information for each candidate technique to the processor 120. The appropriateness information is information on the degree of matching (e.g., level, score, etc.) with the event to be mapped.

[0057] 2 is a block diagram of a processor of a mapping server according to an embodiment of the present invention. Referring to FIG. 2, the processor 120 includes a document collection unit 121, an event collection unit 122, and a control unit 123.

[0058] The document collection unit 121 collects documents for events to be mapped from the document server 20, and the event collection unit 122 connects to an event recording unit in the API server 10, where event information for API execution results is stored in the form of a database, and can collect event information corresponding to the executed API at a predetermined period, time interval, or in real time.

[0059] Here, the collection of event information can be determined based on the query request rate of the event recorder of the corresponding server to prevent traffic or data bottleneck errors. Information on the query request rate can also be received from CloudTrail. For example, if the event recorder is AWS CloudTrail, it is limited to two requests per second or less per region and account, and it can take up to 15 minutes for results to be provided via CloudTrail. Therefore, the interval for collecting APIs from CloudTrail can be determined within a range that satisfies the constraints.

[0060] The control unit 123 can generate mapping information for a mapping target event in cooperation with the document collection unit 121, the event collection unit 122, and the behavior database 140. Of course, the control unit 123 can map risk information for the tactic of the mapping information along with the mapping information. The risk information can include basic risk information for the corresponding mapping target event itself and linked risk information taking into account the corresponding mapping target event and the first event generated in the sequence.

[0061] 3 is a general flowchart of a method for generating mapping information for an API according to an embodiment of the present invention. Referring to FIG. 3, in step S301, processor 120 receives a mapping target event generated in a first account from API server 10. Then, in step S302, processor 120 obtains a document for the received mapping target event from document server 20.

[0062] In step S303, the processor 120 generates at least one of a topic and a keyword using the API name, definition, function, request syntax, and description of parameters generated or provided by executing the API included in the document for the event to be mapped. For example, if the event to be mapped is an account update event, the processor 120 will generate a topic called "account update" and keywords called "account" and "update."

[0063] In step S304, the processor 120 selects one tactic from the plurality of tactics stored in the behavior database 140 based on the topic or keyword generated in step S303. In the next step S305, the processor 120 selects at least one technique corresponding to the topic or keyword generated in step S303 from the plurality of techniques included in the selected tactic.

[0064] When steps S304 and S305 are performed, in step S305, the processor 120 sets the tactic selected in step S303 and the technique selected in step S304 as mapping information for the mapping target event, matches the mapping target event and the mapping information for the mapping target event, and stores them in the mapping dictionary.

[0065] Therefore, if steps S301 to S306 are performed for multiple mapping target events, the mapping dictionary will record mapping information for multiple events in the overall event, and over time, assuming that no new events are generated, a mapping dictionary will be generated that records mapping information for the overall event.

[0066] 4 is a flowchart illustrating a processing procedure when a mapping target event corresponds to a plurality of techniques according to an embodiment of the present invention. Referring to FIG. 4, in step S305, the processor 120 selects (identifies) a technique corresponding to a topic or keyword of the mapping target event from among a plurality of techniques included in the selected tactic.

[0067] In step S401, the processor 120 determines whether two or more techniques were identified in step S305. If one technique was identified as a result of the determination, the processor 120 performs step S306, but if two or more techniques were identified, the processor 120 provides the multiple techniques identified in step S305 along with the topics and keywords of the events to be mapped to the multiple designated evaluator terminals 40 in step S402.

[0068] In this way, if the topic, keywords, and multiple techniques are provided on each evaluator's terminal 40, each evaluator can grasp the topic and keywords, select one of the multiple techniques that best matches the topic or keyword, and display or tag it as "appropriate," or display the degree to which each of the multiple techniques matches the topic or keyword, i.e., the appropriateness, as a score or appropriateness level, etc. Here, the degree of appropriateness can be information such as "appropriate," an appropriateness score, an appropriateness level, etc.

[0069] In the next step S403, processor 120 acquires (receives) information on the appropriateness of a plurality of techniques from each of the terminals 40 of the plurality of evaluators. Then, in step S404, processor 120 selects the one technique that is most frequently labeled or tagged as "appropriate," or selects the one technique with the highest average score or level assigned to each technique.

[0070] Then, the processor 120 stores the one technique selected in step S404 and the one tactic selected in step S304 as mapping information for the event to be mapped in the mapping dictionary, as in step S306.

[0071] 6 is a flowchart showing a process for generating risk level information according to an embodiment of the present invention. Referring to FIG. 6, in step S601, processor 120 receives a first event (including a first API) generated by a first account. In the next step S602, processor 120 selects one tactic for the first event and one of a plurality of techniques included in the tactic, as described above, and generates mapping information.

[0072] In step S603, the processor 120 determines an event scenario for the first account. The event scenario is a chronological list of events. In the event scenario, a first event occurs in the first account on July 1, 2022, a second event occurs on July 2 of the same year, and a third event occurs on August 31 of the same year. If a fourth event occurs currently (September 15 of the same year), the event scenario includes the first event, the second event, the third event, and the fourth event in chronological order. Through this event scenario, it is possible to determine the tactics or techniques to be used for corresponding events in the chronological order of the events that occurred.

[0073] In step S604, processor 120 determines whether there is at least one second event (or a corresponding tactic or technique) in the determined event scenario that has a risk correlation with the first event or the corresponding tactic or technique. The second event is determined using a previously stored risk table, which records the type of each event that has a risk correlation and the level of risk (basic risk information or linked risk information) for each event with a risk. The risk information can be recorded as a risk level or a risk score.

[0074] In step S605, the processor 120 determines whether a second event exists. If a second event exists, the processor 120 obtains information on the degree of risk of the first event being linked to the second event in step S606.

[0075] In step S606, the processor 120 includes the information on the link risk determined in step S605 in the mapping information, and in step S607, stores the mapping information in the mapping dictionary.

[0076] Below, we will explain in detail how to understand the degree of risk using Figures 7 and 8.

[0077] FIG. 7 is a diagram illustrating how risk levels are determined based on the correlation of risk levels in an action scenario according to the first embodiment of the present invention.

[0078] 7(a), there is a first event scenario having the sequence of a first event (including a first API), a second event (including a second API), and a fifth event (including a fifth API). If there is no risk correlation between the events (or tactics or techniques) of the first event scenario, the processor 120 assigns basic risk level information to each event. For example, the first and second events are assigned level 1, which is the lowest risk level, and the fifth event is assigned level 2, which is the basic risk level based on the tactic to which the fifth API is mapped.

[0079] However, in a second event scenario having the sequence of a first event (including a first API), a third event (including a third API), and a fifth event (including a fifth API) as shown in (b) of Figure 7, if the first event has a dangerous correlation with the fifth event, or if the third event has a dangerous correlation with the fifth event, the processor 120 assigns a risk level of 4 to the fifth event and determines that the risk is higher than that of the first event scenario.

[0080] Therefore, even though the fifth event is the same as in (a) and (b) of Figure 7, the fifth event can be assigned different risk levels or risk scores depending on whether there is a risk connection with the type of event (type of tactic or type of technique) that occurred immediately before.

[0081] 8 is a diagram illustrating how a risk level is determined depending on risk correlation in an action scenario according to a second embodiment of the present invention. Referring to FIG. 8, the more risk correlation there is in an event scenario, the higher the risk level can be assigned.

[0082] Referring to (a) of Figure 8, in a third event scenario having the order of the first event (including the first API), the third event (including the third API), the fifth event (including the fifth API), and the seventh event (including the seventh API), the seventh event has a dangerous correlation with the fifth event, so it was assigned a risk level of 3, which is information on the risk of correlation, and the remaining first, third, and fifth events were assigned basic risk information.

[0083] In contrast, referring to (b) of Figure 8, in the third event scenario having the sequence of the first event (including the first API), the second event (including the second API), the fifth event (including the fifth API), and the seventh event (including the seventh API), the fifth event has a dangerous correlation with the second event, so it is assigned a risk level of 2, which is information on the degree of risk of the correlation, and the seventh event is assigned a higher risk level of 5 than in (a) of Figure 8, because the risk level of the fifth event is higher than in (a) of Figure 8.

[0084] Therefore, if risk associations are frequent in an event scenario, the same event may be assigned a high risk level.

[0085] FIG. 9 is a general flowchart of a method for mapping undefined events according to an embodiment of the present invention.

[0086] In step S910, the processor 120 identifies undefined events that are not included in the mapping dictionary.

[0087] Here, an undefined event is code or software that does not generate a separate execution flow or event. Specifically, it can be a software component that does not generate its own execution flow or event, but is activated by a request from another application or other code. For example, libraries, middleware, and Lambda layers can be used.

[0088] In step S920, the processor 120 receives risk assessment information for the undefined event from the client terminal 30.

[0089] Here, the risk assessment information may include information about the risk that the undefined event poses to the system. For example, the information may include the type of the undefined event, the scope of possible impact, and the existence and severity of vulnerabilities. Alternatively, the information may include information about the client's classification of the undefined event as risky or non-risky.

[0090] In step S930, the processor 120 selects one of a first method for adding the undefined event to the mapping dictionary and a second method for classifying the undefined event as a non-risk event based on the risk assessment information.

[0091] Here, the first method is a method in which, if an undefined event is determined to be dangerous in the system based on the risk assessment information, the undefined event is analyzed, and related tactics and techniques are selected and added to the mapping dictionary.

[0092] Here, the second method is a method in which, if an undefined event is determined not to be dangerous in the system based on the risk assessment information, the undefined event is classified without additional processing or analysis and is not mapped to a mapping tactic or technique. For example, if risk assessment information is received from the client terminal 30 for a specific undefined event that states, "This data is related to the normal operation of the system, so there is no need to consider it as a threat," the undefined event is not added to the mapping dictionary and can be excluded from security analysis and monitoring.

[0093] Steps S931 and S932 may be included between steps S930 and S940. Steps S931 and S932 may be combined and applied.

[0094] In step S931, the processor 120 receives mapping-related information for an undefined event from the client terminal 30.

[0095] Here, the mapping-related information is information necessary for mapping an undefined event to a specific tactic or technique, and may be based on at least one of topic and keyword information for the undefined event. The processor 120 may generate mapping information based on the mapping-related information received from the client terminal 30.

[0096] In step S932, the processor 120 requests mapping-related information for the undefined event from the generative AI server and receives the mapping-related information from the generative AI server.

[0097] Generative AI can generate mapping-related information for undefined events based on its learning data and algorithms, and can also generate mapping information based on the generated mapping-related information.

[0098] In step S940, if the first method is selected, the processor 120 stores mapping information to which the undefined event is mapped in the mapping dictionary. The processor 120 generates mapping information based on the mapping-related information received in steps S931 and S932, and stores the generated mapping information in the mapping dictionary.

[0099] FIG. 10 is a general flowchart of a method for receiving mapping-related information from a generative AI server according to an embodiment of the present invention.

[0100] In step S1010, the processor 120 selects at least one candidate tactic and candidate technique based on the topic and keyword information of the undefined event. For example, if the topic and keyword information for the undefined event is "unacceptable file upload," "user," "file upload," and "unacceptable file," the candidate tactic may be "Impact," and the candidate technique may be "Data Destruction" or "Denial of Service" based on the MITRE ATT&CK framework.

[0101] In step S1020, processor 120 generates prompting information including information for undefined events, tactics, and techniques.

[0102] Here, the prompting information is information required when making a request to the generative AI server. Also, the information on the tactics and techniques may be information on the candidate tactics and techniques selected in step S1010. For example, the processor 120 may analyze the undefined event, extract information on potentially related tactics and techniques, and include the information in the prompting information.

[0103] In step S1030, the processor 120 transmits the prompting information to the generative AI server and obtains the answer information.

[0104] The generative AI server returns answer information for tactics and techniques suitable for the undefined event based on the prompting information, where the answer information may include mapping information for the undefined event.

[0105] At step S1040, the processor 120 identifies mapping-related information from the response information.

[0106] The technical features disclosed in each embodiment of the present invention are not limited to the corresponding embodiment, and as long as they are not mutually incompatible, the technical features disclosed in each embodiment can be combined and applied to different embodiments.

[0107] Therefore, although each embodiment will be described focusing on its respective technical features, as long as the technical features are not mutually exclusive, they can be combined and applied.

[0108] The present invention is not limited to the above-described embodiments and the accompanying drawings, and various modifications and variations can be made within the scope of those skilled in the art. Therefore, the scope of the present invention should be determined not only by the claims of this specification but also by equivalents of the claims. [Explanation of symbols]

[0109] 10: API server 20: Document Server 30: Client terminal 40: Evaluator's terminal 100: Mapping server 110: Memory 120: Processor 130: Communications Department 140: Behavior Database

Claims

1. In a method in which a mapping server generates mapping information, The mapping server includes a memory, a communication unit, an action database, and a processor coupled to the memory and the action database and configured to execute instructions contained in the memory, wherein the action database includes information on a plurality of tactics and information on a plurality of techniques included in each tactic; receiving, by the processor, a mapping target event from an API server via the communication unit, and obtaining a document relating to the mapping target event from a document server via the communication unit; generating, by the processor, at least one of topics and keywords related to the event to be mapped based on API information included in the document; selecting, by the processor, a tactic to which the event to be mapped, included in the behavior database, based on at least one of the topic and the keyword, wherein the plurality of tactics are each categorized based on a user behavior type; selecting, by the processor, at least one technique corresponding to at least one of the topic and the keyword from among a plurality of techniques included in the selected tactic, wherein the plurality of techniques included in the selected tactic include a detailed action type related to the selected tactic; the processor setting the selected tactic and the selected technique as mapping information for the mapping target event; and the processor storing the mapped events and the mapping information in a mapping dictionary; the processor identifying an undefined event that is not included in the mapping dictionary, wherein the undefined event is distinguished from the mapped event; receiving, by the processor, risk assessment information relating to the undefined event from a client terminal; the processor selecting, based on the risk assessment information, one of a first method of adding the undefined event to the mapping dictionary and a second method of classifying the undefined event as a no-risk event; and The method for generating mapping information further includes the step of storing, in the mapping dictionary, mapping information to which the undefined event is mapped, by the processor when the first method is selected.

2. The step of the processor selecting at least one technique corresponding to at least one of the topic and the keyword from among a plurality of techniques included in the selected tactic includes: providing the processor with the topic and at least one of the keywords and the plurality of techniques to at least one evaluator terminal; The processor acquires appropriateness information for the plurality of techniques from the at least one evaluator terminal, where the appropriateness information includes matching level information of each of the plurality of techniques to at least one of the topic and the keywords; the processor selecting one technique from the plurality of techniques based on the suitability information. The method for generating mapping information according to claim 1 .

3. The processor may further determine whether there is at least one first event having a risk association with the mapping target event based on a pre-stored risk level table. The method for generating mapping information according to claim 1 .

4. When there is at least one first event having a risk association with the mapping target event, the processor determines information on the association risk level of the mapping target event with the first event based on the pre-stored risk level table; the processor including information about the determined linkage risk in the mapping information; and the processor further storing the mapping information in the mapping dictionary. The method for generating mapping information according to claim 3 .

5. When there are a plurality of first events, the information on the link risk level is matched for each of the first events. The method for generating mapping information according to claim 4.

6. The processor further includes receiving mapping-related information for the undefined event from the client terminal, the mapping information is generated based on the mapping-related information; The method for generating mapping information according to claim 1 .

7. the mapping information is based on at least one of topic and keyword information for the undefined event; The method for generating mapping information according to claim 6.

8. The processor further includes selecting at least one candidate tactic and candidate technique based on topic and keyword information of the undefined event. The method for generating mapping information for cloud events according to claim 1 .

9. On the mapping server: memory; Communications Department; An action database, wherein the action database includes information on a plurality of tactics and information on a plurality of techniques included in each tactic; and a processor coupled to said memory and said behavior database and configured to execute instructions contained in said memory; The above processors are receiving a mapping target event from the API server via a communication unit; obtaining a document relating to the event to be mapped from a document server via a communication unit; generating at least one of topics and keywords related to the event to be mapped based on API information included in the retrieved document; selecting, based on at least one of the topic and the keyword, one tactic corresponding to the event to be mapped from among a plurality of tactics stored in a behavior database, wherein the plurality of tactics are each classified based on a behavior type of the user; selecting at least one technique corresponding to at least one of the topic and the keyword from among a plurality of techniques included in the selected tactic, wherein the plurality of techniques included in the selected tactic includes a detailed behavioral type of the tactic; setting the selected tactics and the selected techniques as mapping information for the event to be mapped; storing the mapped events and the mapping information in a mapping dictionary; and identifying undefined events that are not included in the mapping dictionary, where the undefined events are different from the mapped events; receiving risk assessment information regarding the undefined event from the client terminal; selecting, based on the received risk assessment information, either a first method of adding the undefined event to the mapping dictionary or a second method of classifying the undefined event as a non-risk event; If the first method is selected, storing mapping information corresponding to the undefined event in a mapping dictionary; configured to: Mapping server.

10. The above processors are The stage of selecting information on the technique; providing at least one of the topics and keywords and the plurality of techniques on at least one evaluator terminal; acquiring suitability information for the plurality of techniques from the at least one evaluator terminal, wherein the suitability information includes matching level information indicating how well each technique matches at least one of a topic and a keyword; and further configured to perform the step of selecting one technique from the plurality of techniques based on the suitability information. The mapping server of claim 9.

11. The processor is further configured to determine whether there is at least one first event having a risk association with the mapped event based on a pre-stored risk table. The mapping server of claim 9.

12. The processor further determines, when there is at least one first event having a risk association with the mapping target event, information of a grid connection risk of the mapping target event related to the first event based on a pre-stored risk table; Including information of the determined linkage risk in the mapping information; and storing the mapping information in a mapping dictionary; The mapping server of claim 11.

Citation Information

Patent Citations

  • Information display system and information display method

    JP2009048652A

  • Attack determination apparatus, attack determination method and attack determination program

    JP2013232716A

  • Incident management system

    JP2017173941A

  • Risk assessment measure planning system and risk assessment measure planning method

    JP2020166650A

  • Method for detecting fraudulence of access request

    JP2023022613A