Security context based generation of cyber-threat variants

A Graph-based learning approach automates threat variant generation for Advanced Persistent Threats, addressing inefficiencies in manual detection methods by generating evolved and composite variants to enhance proactive threat hunting and security management.

WO2025169004A1PCT designated stage Publication Date: 2025-08-14TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/062846
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-08
Filing Date
2024-12-18
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Conventional detection mechanisms and current hypotheses generation techniques are inefficient in detecting new threat variants of Advanced Persistent Threats (APT), requiring extensive manual effort and expertise, and are inadequate for proactive threat hunting due to the stealthiness and dynamism of attackers.

Method used

A method using a Graph-based learning approach to evaluate security context for attack chain sequences, generating threat variants, including evolved and composite variants, to assist Security Operations Centers (SOCs) in proactive threat hunting and preventative measures.

Benefits of technology

Automatically generates threat variants with minimal expert intervention, reducing investigation time and resources, and enhancing security defenses by providing actionable intelligence for potential threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024062846_14082025_PF_FP_ABST
    Figure IB2024062846_14082025_PF_FP_ABST
Patent Text Reader

Abstract

A method, system and apparatus are disclosed. According to various embodiments, a computing device is provided. The computing device is configured to: evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat where the security context for each of the plurality of techniques indicates one or both of: at least one requirement for the respective technique to occur, and at least one result of the respective technique; and generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence where the first threat variant is based on the respective security context for the at least one technique of the first attack chain sequence.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] SECURITY CONTEXT BASED GENERATION OF CYBER-THREAT

[0002] VARIANTS

[0003] FIELD

[0004] The present disclosure relates to wireless communications, and in particular, to threat generation for security management.

[0005] BACKGROUND

[0006] Security Operations Center (SOC) teams are overwhelmed with a constant barrage of security threats and alerts. It has been reported that SOCs receive millions of alerts that need to be deeply investigated by security experts. The latter requires not only expertise but also a considerable amount of time and effort that might result in alarm fatigue and, consequently, a lack of responsiveness and vigilance toward potential security incidents by missing critical security alerts and / or late investigation. To prevent alarm fatigue, it may be beneficial to bring intelligence and automation to SOCs to prioritize security incidents and alerts, reduce the analysis and investigation time, and proactively elicit threat intelligence.

[0007] Yet, Advanced Persistent Threats (APT) involve multiple attack steps over a long period of time and might stay stealthy in a network without being detected. Certain threat detection is executed in a passive approach to monitor data and systems for potential security issues. It is very efficient at detecting ongoing attacks; however, it is inadequate to investigate the multi-step stealthy and advanced attacks spread over time and between different systems inside the same network. For example, APT41 is a state- sponsored espionage group against telecommunications, high-tech, and healthcare sectors that have been active since mid-2016. The objective of this APT is to establish and maintain strategic access using different techniques and software. According to MITRE ATT&CK, APT41 comprises 59 techniques, 13 software, and 211 relationships. Moreover, APTs evolve all the time, and threat actors dynamically explore new techniques that lead to the same objective. For instance, Google Threat Analysis Group (TAG) disrupted an APT41 campaign using Google Command and Control (GC2), Google Sheets, and Google Drive. The stealthiness and dynamism of the attacker’s behavior make detection more challenging. Threat hunting, on the other hand, is a constant arms race that aims at tackling this issue by proactively programming human reasoning procedures, inspecting the outcomes, and iteratively revising the threat hypotheses and the reasoning procedures based on observations and related knowledge. The process tends to investigate various networks and endpoints data to sleuth and hunt malicious, suspicious, and risky activity that has evaded detection mechanisms.

[0008] Currently, SOCs team manually generate threat hypotheses based on the known attacks and the current system status. Generating hypotheses requires not only extensive security knowledge and expertise, which are elusive, but also time and computing resources. Moreover, a SOC team might receive an Indicator of Compromise (loC) or an Indicator of Attack (loA) for a specific APT. Due to the dynamism and stealthiness of attackers in coming up with alternative attack steps, the same I0C / I0A can be used by multiple APTs. For example, the technique “System Network Configuration Discovery” is part of APT18, APT39, APT41, among others. Moreover, it has been reported that a threat actor might use other’s threat actors’ techniques to escape and deceive detection mechanisms. Conventional detection mechanisms and current hypotheses generation techniques are not efficient enough to detect those new threat variants.

[0009] SUMMARY

[0010] Some embodiments advantageously provide methods, computing systems, computing devices and apparatuses for threat generation for security management.

[0011] In one or more embodiments, possible threat variants are automatically generated with a minimum of security expert intervention. For example, as shown in FIG. 1, based on the system telemetry and pre-defined knowledge base, one or more embodiments apply a Graph-based learning approach to learn the security context and the attack steps. Then, given an Attack chain sequence, the system automatically generates the most relevant threat variants, including evolved threat variants (i.e., incorporating new and similar techniques) and composite threat variants (i.e., transcribing attack sub-sequence from other APTs). The generated threat variants are used by the Threat Hunting module in the Security Management (e.g., SIEM / SOAR) to proactively implement preventative measures and hunt them before they cause damage.

[0012] According to one aspect of the present disclosure, a method implemented in a computing device is provided. Security context is evaluated for each of a plurality of techniques of at least a first attack chain sequence of a first security threat where the security context for each of the plurality of techniques indicates one or both of at least one requirement for the respective technique to occur, and at least one result of the respective technique. A second attack chain sequence is generated where the second attack chain sequence comprises a first threat variant for at least one technique of the first attack chain sequence, where the first threat variant is based on the respective security context for the at least one technique of the first attack chain sequence.

[0013] According to one or more embodiments of this aspect, wherein the at least one requirement of the respective technique to occur comprises one or more of: a level of privilege required to execute the respective technique; a predefined platform for executing the respective technique; at least one predefined type of input for executing the respective technique; and a presence of at least one other technique in the first attack chain sequence that is configured to occur before the respective technique.

[0014] According to one or more embodiments of this aspect, the at least one result of the respective technique comprises one or more of: a function that the respective technique is configured to achieve; at least one action or procedure that is performed when the technique is executed; and a predefined effect of the respective technique on a system.

[0015] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a technique from at least one other attack chain sequence different from the first attack chain sequence.

[0016] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a group of techniques from at least one other attack chain sequence different from the first attack chain sequence.

[0017] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to one or more of: skipping the at least one technique of the first attack chain sequence; and a different sequence in the first attack chain sequence for the at least one technique of the first attack chain sequence.

[0018] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence is generated at least by: generating a graph neural network having a plurality of nodes based on a knowledge base for proactive threat detection where each of the plurality of nodes corresponds to a respective technique associated with a respective security context, and where the knowledge base comprises a plurality of attack chain sequences including the first attack chain sequence; evaluating the plurality of nodes, using a similarity threshold, based on the respective security context; and logically grouping at least two of the plurality of nodes based on the evaluation, the first threat variant for the at least one technique of the first attack chain sequence being based on the grouping.

[0019] According to one or more embodiments of this aspect, the evaluation of the plurality of nodes using a similarity threshold comprises: determining a similarity score of at least two nodes of the plurality of nodes; determining whether the similarity score meets a similarity threshold; the logical grouping of the least two nodes being based on the similarity threshold being met, the at two nodes of the plurality of nodes being interchangeable based on the similarity threshold being met; and the first threat variant for the at least one technique of the first attack chain sequence being based on the interchangeability of the at least two nodes of the plurality of nodes.

[0020] According to one or more embodiments of this aspect, the at least two nodes that meet the similarity threshold comprise one of: a first node of the plurality of nodes that is determined to be similar to a second node of the plurality of nodes based on the similarity threshold being met; or a first node of the plurality of nodes that is determined to be similar to a group of the plurality of nodes based on the similarity threshold being met.

[0021] According to one or more embodiments of this aspect, at least one node of the plurality of nodes that are not part of the plurality of clusters is not considered in the generating of the second attack chain sequence.

[0022] According to one or more embodiments of this aspect, the knowledge base is augmented at least in part by updating the knowledge base to include the second attack chain sequence, and the graph neural network is updated based on the augmenting of the knowledge base.

[0023] According to another aspect of the present disclosure, a computing device is provided. The computing device is configured to: evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat where the security context for each of the plurality of techniques indicates one or both of: at least one requirement for the respective technique to occur, and at least one result of the respective technique. The computing device is configured to generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence where the first threat variant is based on the respective security context for the at least one technique of the first attack chain sequence. According to one or more embodiments of this aspect, the at least one requirement of the respective technique to occur comprises one or more of: a level of privilege required to execute the respective technique; a predefined platform for executing the respective technique; at least one predefined type of input for executing the respective technique; and a presence of at least one other technique in the first attack chain sequence that is configured to occur before the respective technique.

[0024] According to one or more embodiments of this aspect, the at least one result of the respective technique comprises one or more of: a function that the respective technique is configured to achieve; at least one action or procedure that is performed when the technique is executed; and a predefined effect of the respective technique on a system.

[0025] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a technique from at least one other attack chain sequence different from the first attack chain sequence.

[0026] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a group of techniques from at least one other attack chain sequence different from the first attack chain sequence.

[0027] According to one or more embodiments of this aspect, the first threat variant for the at least one technique of the first attack chain sequence corresponds to one or more of: skipping the at least one technique of the first attack chain sequence, and a different sequence in the first attack chain sequence for the at least one technique of the first attack chain sequence.

[0028] According to one or more embodiments of this aspect, the computing device is further configured to generate the first threat variant for the at least one technique of the first attack chain sequence at least by: generating a graph neural network having a plurality of nodes based on a knowledge base for proactive threat detection where each of the plurality of nodes corresponds to a respective technique associated with a respective security context, and where the knowledge base comprising a plurality of attack chain sequences including the first attack chain sequence; evaluating the plurality of nodes, using a similarity threshold, based on the respective security context; and logically grouping at least two of the plurality of nodes based on the evaluation, the first threat variant for the at least one technique of the first attack chain sequence being based on the grouping. According to one or more embodiments of this aspect, the evaluation of the plurality of nodes using a similarity threshold comprises: determining a similarity score of at least two nodes of the plurality of nodes; determining whether the similarity score meets a similarity threshold; the logical grouping of the least two nodes being based on the similarity threshold being met, the at two nodes of the plurality of nodes being interchangeable based on the similarity threshold being met; and the first threat variant for the at least one technique of the first attack chain sequence being based on the interchangeability of the at least two nodes of the plurality of nodes.

[0029] According to one or more embodiments of this aspect, the at least two nodes that meet the similarity threshold comprise one of: a first node of the plurality of nodes that is determined to be similar to a second node of the plurality of nodes based on the similarity threshold being met; or a first node of the plurality of nodes that is determined to be similar to a group of the plurality of nodes based on the similarity threshold being met.

[0030] According to one or more embodiments of this aspect, at least one node of the plurality of nodes that are not part of the plurality of clusters is not considered in the generating of the second attack chain sequence.

[0031] According to one or more embodiments of this aspect, the computing device is further configured to: augment the knowledge base at least in part by updating the knowledge base to include the second attack chain sequence; and update the graph neural network based on the augmenting of the knowledge base.

[0032] According to another aspect of the present disclosure, a computer readable medium is provided. The computer readable medium comprises processing instructions that, when executed by at least one processor, cause the at least one processor to: evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat, where the security context for each of the plurality of techniques indicates one or both of: at least one requirement for the respective technique to occur; and at least one result of the respective technique; and generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence where the first threat variant is based on the respective security context for the at least one technique of the first attack chain sequence.

[0033] According to one or more embodiments of this aspect, the processing instructions are further configured to cause the at least one processor to perform the method described herein. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] A more complete understanding of the present embodiments, and the attendant advantages and features thereof, will be more readily understood by reference to the following detailed description when considered in conjunction with the accompanying drawings wherein:

[0035] FIG. 1 is a diagram of an example implementation of the present disclosure in a 5G network;

[0036] FIG. 2 is a block diagram of a system according to some embodiments of the present disclosure;

[0037] FIG. 3 is a schematic diagram of an example network architecture illustrating a communication system according to the principles disclosed herein;

[0038] FIG. 4 is a flowchart of an example process in a computing device according to some embodiments of the present disclosure;

[0039] FIG. 5 is a flowchart of another example process in a computing device according to some embodiments of the present disclosure;

[0040] FIG. 6 is a diagram of an Attack chain (x: APT name, numbers represent different techniques) according to the principles disclosed herein;

[0041] FIGs. 7A-7B is a diagram of threat variant generation components according to the principles disclosed herein;

[0042] FIG. 8 is a flow diagram of an example process according to the principles disclosed herein;

[0043] FIG. 9 is a diagram of an example of technique aggregation using the MITRE ATT&CK framework according to the principles disclosed herein;

[0044] FIG. 10 is a diagram of an example security context representation of a technique according to the principles disclosed herein;

[0045] FIG. 11 is a diagram of an example Evolved Variants Generator Representation according to the principles disclosed herein;

[0046] FIG. 12 is a diagram of example adjacent techniques clustering according to the principles disclosed herein;

[0047] FIG. 13 is a diagram of an example adjacent technique fusion according to the principles disclosed herein;

[0048] FIG. 14 is a diagram of an example of resembling sequence matching according to the principles disclosed herein; FIG. 15 is a diagram of an example of transcribing a technique by a sequence from another APT according to the principles disclosed herein;

[0049] FIG. 16 is a diagram of an example of evolved and composite threat variants generated according to the principles disclosed herein; and

[0050] FIG. 17 is a diagram of an example of an aligned threat according to the principles disclosed herein;

[0051] DETAILED DESCRIPTION

[0052] Conventional detection mechanisms and current hypotheses generation techniques are not efficient enough to detect those new threat variants which motivates the need to proactively generate hypotheses for threat variants to reduce the required time and resources to investigate all received security events / alerts and strengthen the security defense line.

[0053] Most existing detection solutions are reactive and triggered upon the reception of an IOC / IOA. They either detect the existence of an attack by correlating it with knowledge artifacts or predict the next step using historical data of known attacks. To date, no method proposes / designs a solution generation of threat variants for the sake of proactive threat hunting. All the investigations are performed manually by security experts, which requires elusive security knowledge and expertise in addition to time and effort.

[0054] In one or more embodiments described herein, threat variants are generated for APTs. One or more embodiments can be integrated with existing security tools (e.g., Ericsson Security Manager - ESM) to assist the SOC team with actionable intelligence and comprehensive insights into current or potential threats. The generated threat variants allow the team to implement preventative measures effectively.

[0055] Before describing in detail example embodiments, it is noted that the embodiments reside primarily in combinations of apparatus components and processing steps related to threat generation for security management. Accordingly, components have been represented where appropriate by conventional symbols in the drawings, showing only those specific details that are pertinent to understanding the embodiments so as not to obscure the disclosure with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.

[0056] As used herein, relational terms, such as “first” and “second,” “top” and “bottom,” and the like, may be used solely to distinguish one entity or element from another entity or element without necessarily requiring or implying any physical or logical relationship or order between such entities or elements. The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the concepts described herein. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises,” “comprising,” “includes” and / or “including” when used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0057] In embodiments described herein, the joining term, “in communication with” and the like, may be used to indicate electrical or data communication, which may be accomplished by physical contact, induction, electromagnetic radiation, radio signaling, infrared signaling or optical signaling, for example. One having ordinary skill in the art will appreciate that multiple components may interoperate and modifications and variations are possible of achieving the electrical and data communication.

[0058] In some embodiments described herein, the term “coupled,” “connected,” and the like, may be used herein to indicate a connection, although not necessarily directly, and may include wired and / or wireless connections.

[0059] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the concepts described herein. As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises,” “comprising,” “includes” and / or “including” when used herein, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0060] The term “network node” used herein can be any kind of network node comprised in a radio network which may further comprise any of base station (BS), radio base station, base transceiver station (BTS), base station controller (BSC), radio network controller (RNC), g Node B (gNB), evolved Node B (eNB or eNodeB), Node B, multistandard radio (MSR) radio node such as MSR BS, multi-cell / multicast coordination entity (MCE), relay node, donor node controlling relay, radio access point (AP), transmission points, transmission nodes, Remote Radio Unit (RRU) Remote Radio Head (RRH), a core network node (e.g., mobile management entity (MME), self-organizing network (SON) node, a coordinating node, positioning node, MDT node, etc.), an external node (e.g., 3rd party node, a node external to the current network), nodes in distributed antenna system (DAS), a spectrum access system (SAS) node, an element management system (EMS), etc. The network node may also comprise test equipment. The term “radio node” used herein may be used to also denote a wireless device (WD) such as a wireless device (WD) or a radio network node.

[0061] In some embodiments, the non-limiting terms wireless device (WD) or a user equipment (UE) are used interchangeably. The WD herein can be any type of wireless device capable of communicating with a network node or another WD over radio signals, such as wireless device (WD). The WD may also be a radio communication device, target device, device to device (D2D) WD, machine type WD or WD capable of machine to machine communication (M2M), low-cost and / or low-complexity WD, a sensor equipped with WD, Tablet, mobile terminals, smart phone, laptop embedded equipped (LEE), laptop mounted equipment (LME), USB dongles, Customer Premises Equipment (CPE), an Internet of Things (loT) device, or a Narrowband loT (NB-IOT) device etc.

[0062] Also, in some embodiments the generic term “radio network node” is used. It can be any kind of a radio network node which may comprise any of base station, radio base station, base transceiver station, base station controller, network controller, RNC, evolved Node B (eNB), Node B, gNB, Multi-cell / multicast Coordination Entity (MCE), relay node, access point, radio access point, Remote Radio Unit (RRU) Remote Radio Head (RRH).

[0063] Note that although terminology from one particular wireless system, such as, for example, 3GPP LTE and / or New Radio (NR), may be used in this disclosure, this should not be seen as limiting the scope of the disclosure to only the aforementioned system. Other wireless systems, including without limitation Wide Band Code Division Multiple Access (WCDMA), Worldwide Interoperability for Microwave Access (WiMax), Ultra Mobile Broadband (UMB) and Global System for Mobile Communications (GSM), may also benefit from exploiting the ideas covered within this disclosure.

[0064] Note further, that functions described herein as being performed by a wireless device or a network node may be distributed over a plurality of wireless devices and / or network nodes. In other words, it is contemplated that the functions of the network node and wireless device described herein are not limited to performance by a single physical device and, in fact, can be distributed among several physical devices. Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure belongs. It will be further understood that terms used herein should be interpreted as having a meaning that is consistent with their meaning in the context of this specification and the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0065] Some embodiments are directed to threat generation for security management.

[0066] Referring again to the drawing figures, in which like elements are referred to by like reference numerals, there is shown in FIG. 2 is a block diagram of a system 10 according to one or more embodiments of the present disclosure. System 10 includes computing system 12 that is configured to perform one or more threat related functions as described herein.

[0067] Computing system 12 includes one or more computing devices 13 (collectively referred to as computing device 13). Computing device 13 comprises hardware 14. Hardware 14 includes communication interface 16 enabling computing device 13 to communicate one or more entities of system 10.

[0068] In the embodiment shown, the hardware 14 of the computing device 13 further includes processing circuitry 18. The processing circuitry 18 may include a processor 20 and a memory 22. In particular, in addition to or instead of a processor, such as a central processing unit, and memory, the processing circuitry 18 may comprise integrated circuitry for processing and / or control, e.g., one or more processors and / or processor cores and / or FPGAs (Field Programmable Gate Array) and / or ASICs (Application Specific Integrated Circuitry) adapted to execute instructions. The processor 20 may be configured to access (e.g., write to and / or read from) the memory 22, which may comprise any kind of volatile and / or nonvolatile memory, e.g., cache and / or buffer memory and / or RAM (Random Access Memory) and / or ROM (Read-Only Memory) and / or optical memory and / or EPROM (Erasable Programmable Read-Only Memory).

[0069] Thus, the computing device 13 further has software 24 stored internally in, for example, memory 22, or stored in external memory (e.g., database, storage array, network storage device, etc.) accessible by the computing device 13 via an external connection. The software 24 may be executable by the processing circuitry 18. The processing circuitry 18 may be configured to control any of the methods and / or processes described herein and / or to cause such methods, and / or processes to be performed, e.g., by computing device 13. Processor 20 corresponds to one or more processors 20 for performing computing device 13 functions described herein. The memory 22 is configured to store data, programmatic software code and / or other information described herein. In some embodiments, the software 24 may include instructions that, when executed by the processor 20 and / or processing circuitry 18, causes the processor 20 and / or processing circuitry 18 to perform the processes described herein with respect to computing device 13. For example, processing circuitry 18 of computing device 13 may include threat unit 26 which is configured to perform one or more functions described herein such as with respect to threat variant generation and / or threat hunting.

[0070] Computing device 13 may be configured to receive data 28 from one or more entities. For example, data 28 may correspond to system telemetry data from a 5G network or other data. Computing device 13 is further configured to communicate with knowledge base 30 where knowledge base 30 comprises, for example, definitions of existing attacks, techniques, and their relationships that could be populated from trusted repositories (e.g., MITRE ATT&CK Framework) or handcrafted by security experts.

[0071] FIG. 3 is an example implementation of computing system 12 in communication system 40, according to an embodiment. Communication system 40 may be a 3GPP-type cellular network that may support standards such as LTE and / or NR (5G). Communication system 40 comprises an access network 42, such as a radio access network, and a core network 44. The access network 42 comprises a plurality of network nodes 46a, 46b, 46c (referred to collectively as network nodes 46), such as NBs, eNBs, gNBs or other types of wireless access points, each defining a corresponding coverage area 48a, 48b, 48c (referred to collectively as coverage areas 48). Each network node 46a, 46b, 46c is connectable to the core network 44 over a wired or wireless connection 50. A first wireless device (WD) 52a located in coverage area 48a is configured to wirelessly connect to, or be paged by, the corresponding network node 46a. A second WD 52b in coverage area 48b is wirelessly connectable to the corresponding network node 46b. While a plurality of WDs 52a, 52b (collectively referred to as wireless devices 52) are illustrated in this example, the disclosed embodiments are equally applicable to a situation where a sole WD is in the coverage area or where a sole WD is connecting to the corresponding network node 46. Note that although only two WDs 52 and three network nodes 46 are shown for convenience, the communication system may include many more WDs 52 and network nodes 46.

[0072] Also, it is contemplated that a WD 52 can be in simultaneous communication and / or configured to separately communicate with more than one network node 46 and more than one type of network node 46. For example, a WD 52 can have dual connectivity with a network node 46 that supports LTE and the same or a different network node 46 that supports NR. As an example, WD 52 can be in communication with an eNB for LTE / E-UTRAN and a gNB for NR / NG-RAN.

[0073] Further, computing system 12 may be in communication with one or more entities of access network 42 and / or core network 44 such that computing system 12 may receive data (e.g., system telemetry, other data) for performing one or more threat functions described herein.

[0074] Although FIGS. 2 and 3 show a unit such as threat unit 26 as being within a respective processor, it is contemplated that this unit may be implemented such that a portion of the unit is stored in a corresponding memory within the processing circuitry. In other words, the units may be implemented in hardware or in a combination of hardware and software within the processing circuitry.

[0075] FIG. 4 is a flowchart of an example process in a computing device 13. One or more blocks described herein may be performed by one or more elements of computing device 13 such as by one or more of processing circuitry 18 (including the threat unit 26), processor 20, and / or communication interface 16. Computing device 13 is configured to evaluate security context for at least a first Attack chain sequence of a first security threat, as described herein (Block S100). Computing device 13 is configured to generate at least one potential threat variant based on the evaluated security context, as described herein (Block s 102).

[0076] According to one or more embodiments, the evaluating of the security context for the first Attack chain sequence is based on system telemetry and a predefined knowledge base of security threats.

[0077] According to one or more embodiments, the at least one potential threat variant comprises at least one evolved threat variant that incorporates a technique different from the first security threat.

[0078] According to one or more embodiments, the computing device is further configured to evaluate security context for a plurality of Attack chain sequences associated with a plurality of security threats, the plurality of security threats comprising the first security threat, and the at least one potential threat variant comprises at least one composite threat variant that transcribes an attack sub-sequence from the plurality of security threats. According to one or more embodiments, the computing device is further configured to at least one of: implement at least one protective measure in response to the generation of the at least one potential threat variant; or search for the at least one potential threat variant in response to the generation of the at least one potential threat variant.

[0079] According to one or more embodiments, the generation of the at least one potential threat variant comprises generating at least one attack step using a graph machine learning.

[0080] FIG. 5 is a flowchart of another example process in a computing device 13. One or more blocks described herein may be performed by one or more elements of computing device 13 such as by one or more of processing circuitry 18 (including the threat unit 26), processor 20, and / or communication interface 16. Computing device 13 is configured to evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat, the security context for each of the plurality of techniques indicating one or both of: at least one requirement for the respective technique to occur, and at least one result of the respective technique, as described herein. Computing device 13 is configured to generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence where the first threat variant is based on the respective security context for the at least one technique of the first attack chain sequence.

[0081] According to one or more embodiments, the at least one requirement of the respective technique to occur comprises one or more of: a level of privilege required to execute the respective technique; a predefined platform for executing the respective technique; at least one predefined type of input for executing the respective technique; and a presence of at least one other technique in the first attack chain sequence that is configured to occur before the respective technique.

[0082] According to one or more embodiments, the at least one result of the respective technique comprises one or more of: a function that the respective technique is configured to achieve; at least one action or procedure that is performed when the technique is executed; and a predefined effect of the respective technique on a system.

[0083] According to one or more embodiments, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a technique from at least one other attack chain sequence different from the first attack chain sequence.

[0084] According to one or more embodiments, the first threat variant for the at least one technique of the first attack chain sequence corresponds to a group of techniques from at least one other attack chain sequence different from the first attack chain sequence. According to one or more embodiments, the first threat variant for the at least one technique of the first attack chain sequence corresponds to one or more of: skipping the at least one technique of the first attack chain sequence, and a different sequence in the first attack chain sequence for the at least one technique of the first attack chain sequence.

[0085] According to one or more embodiments, the computing device 13 is further configured to generate the first threat variant for the at least one technique of the first attack chain sequence at least by: generating a graph neural network having a plurality of nodes based on a knowledge base for proactive threat detection where each of the plurality of nodes corresponds to a respective technique associated with a respective security context and the knowledge base comprises a plurality of attack chain sequences including the first attack chain sequence; evaluating the plurality of nodes, using a similarity threshold, based on the respective security context; and logically grouping at least two of the plurality of nodes based on the evaluation where the first threat variant for the at least one technique of the first attack chain sequence is based on the grouping.

[0086] According to one or more embodiments, the evaluation of the plurality of nodes using a similarity threshold comprises: determining a similarity score of at least two nodes of the plurality of nodes; determining whether the similarity score meets a similarity threshold; the logical grouping of the least two nodes being based on the similarity threshold being met, the at two nodes of the plurality of nodes being interchangeable based on the similarity threshold being met; and the first threat variant for the at least one technique of the first attack chain sequence being based on the interchangeability of the at least two nodes of the plurality of nodes.

[0087] According to one or more embodiments, the at least two nodes that meet the similarity threshold comprise one of: a first node of the plurality of nodes that is determined to be similar to a second node of the plurality of nodes based on the similarity threshold being met; or a first node of the plurality of nodes that is determined to be similar to a group of the plurality of nodes based on the similarity threshold being met.

[0088] According to one or more embodiments, at least one node of the plurality of nodes that are not part of the plurality of clusters is not considered in the generating of the second attack chain sequence.

[0089] According to one or more embodiments, the computing device 13 is further configured to: augment the knowledge base at least in part by updating the knowledge base to include the second attack chain sequence; and update the graph neural network based on the augmenting of the knowledge base. Having described the general process flow of arrangements of the disclosure and having provided examples of hardware and software arrangements for implementing the processes and functions of the disclosure, the sections below provide details and examples of arrangements for threat generation for security management.

[0090] Some embodiments provide threat generation for security management. One or more functions described below may be performed by one or more of computing system 12, computing device 13, etc. such as by processing circuitry 18, processor 20, communication interface 16, threat unit 26, etc.

[0091] Threat Variant

[0092] A threat hypothesis is a potential scenario that may lead to a security breach or compromise (i.e., APT). It is a kill-chain model or speculation of sequences of how a threat actor could exploit a weakness in the system to then gain unauthorized access, steal data, or disrupt system operations. Currently, a threat hypothesis can be generated based on knowledge of known attack vectors, system vulnerabilities, or Tactics, Techniques and Procedures (TTPs).

[0093] Each Attack chain is modeled by a multi-set (as the same technique can appear multiple times) and represented by a directed graph where nodes are techniques, edges represent transition relationships, and node features represent the technique’s security context within the APT in question or under investigation. In the context of APTs, there is a finite set Y of tactics and a finite set F of techniques. A technique t is usually associated with one or more tactics. This relationship can be represented by a mapping function I / J : r -> 2Y, where 2Yis the power set of Y. To model an APT definition as a multiset, first a set E is defined where each element is a tuple consisting of a technique and a tactic that it is associated with: E = {(t, T) | t E F, T E ?^(t)}. An APT then can be modeled as a multi-set X = {t1(t2, ■ ■ ■ , tn) over E. Techniques within the multi-set are also represented as a directed graph G = (IV, E) where nodes (IV) are techniques with the multi-set X and edges ( ) represent transition relationships between each two techniques. FIG. 6 provides an illustrative example of an Attack Chain (x: APT name, numbers represent different techniques) where an APT x that consists of 10 techniques.

[0094] A threat variant, on the other hand, refers to a different version or a subtype of the primary threat hypothesis (e.g., a new threat polymorphism). Unlike existing solutions (e.g., Mandiant}, where variants are defined when threat actors leverage different malware (which does already exist) from the same family, there are defined threat variants as a representation of how the threat may evolve over time to use new attack techniques (do not exist, e.g., 0-day) to achieve (same / similar) malicious goal(s). For example, if the primary threat hypothesis involves a ransomware attack, a threat variant could refer to a different type of ransomware attack, perhaps utilizing a different delivery method, targeting a different part of the system, or using a variant of the ransomware that behaves in a different manner but share the same objective. Currently, the threat variants are generated manually by the security experts using their knowledge. The idea would be to consider not just the known ways a threat has materialized but also how the threat may evolve and use many different techniques resulting in the variants of the initial threat.

[0095] For a suspected APT name (x), which might be active in the network / domain, with an attack chain (i.e., sequence of techniques) (X = {Zq, , tn}), a threat variant could be:

[0096] • Evolved Variant (cZ): a sequence of techniques (£)) that involves original techniques from X or new techniques that have not been observed in X but are similar with an almost identical objective, and thus interchangeable. The number of techniques in D could be more than X (e.g., the attacker uses multiple steps to reach the objective of one technique in X) or smaller e.g., the attacker uses only one technique not defined in X and skip other techniques from X).

[0097] • Composite Variant (Z): a sequence of technique (L) that adopts one or more subsequence of techniques from other APTs (e.g., APT T). A composite variant is a combination of multiple APTs.

[0098] A threat hypothesis generation is based on definitions of existing attacks (i.e., knowledge base, which is also used to train the graph learning model) and system status (i.e., system telemetry). The threat variant generation is based on assuming there could be new attacks never seen / happened before, resulted from pollination of different yet similar techniques. Therefore, threat hypothesis generation and attack detection are about existing attacks, while threat variants detection is about investigating the new 0-day threats based on pollination and knowledge about the previous attacks.

[0099] One or more embodiments described herein provides a new system to use the definition of attacks in the knowledge base in order to automate the generation of threat variants (including evolved and composite variants).

[0100] System Overview

[0101] One or more embodiments (summarized in FIGs. 7A-7B) describe a solution that automates the generation of threat variant hypotheses. The solution is built using a knowledge base of existing (or interesting) attacks (e.g., APTs). The legend in FIG. 7A regarding “Eliminated Techniques,” “New Techniques,” “New relationship” and “Techniques from APT” may also apply to other figures described herein. For example, FIG. 13 (discussed below) may indicate new technique(s) by using the hex format illustrated in FIG. 7A with respect to “New Techniques.” It applies graph-based machine learning (e.g., Graph Neural Network, Graph Attention Network) to understand / leam threat behavior and infrastructure, and then generate new potential threat variants. One or more embodiments described herein having at least three steps: security context evaluation: understanding the security context of techniques using graph learning, prediction step: using graph learning to predict new relationships and techniques, and pruning step: eliminating relationships and techniques and end up with the most probable threat variant.

[0102] One or more embodiments extract the attack chain from the knowledge base and aggregate the techniques per attack stage. The knowledge base is a database that contains definitions of existing attacks, techniques, and their relationships that could be populated from trusted repositories (e.g., MITRE ATT&CK Framework) or handcrafted by security experts. Due to the nature of APTs and the attacker’s behavior, it may be assumed that the knowledge base does not contain all the observable techniques, which drives the need to generate potential variants. The generated threat variants are sent to the SOC team for proactive investigation or to prepare a set of prevention mechanisms.

[0103] FIG. 8 depicts the workflow diagram of one or more embodiments that includes threat variants (evolved and composite variants) generation. FIG. 8 includes various steps described below.

[0104] Once a security expert (or other designated person) provides the interested APT name (X), the pre-processor agent extracts the APT X’s attack chain KC1 from the knowledge base (Step 1) and then aggregates techniques per attack stage (e.g., tactics) for KC1 (Step 2). One aspect of the present disclosure relates to learning security context based on pre- and post-condition features Step (3) see details in the Security Context Evaluator section, and then automatically generates threat variants (Steps 4), see details in the Evolved Variants Generator (EVG) section and the Composite Variants Generator (CVG) section. Indeed, the Security Context Evaluator generates the security context for each node in KC1 and the relationships between different nodes in KC1 and other related nodes RC1 (i.e., these nodes are not in KC1) using GNN module (Step 3). • In order to generate evolved threat variants, the EVG measures the similarity score between different nodes for KC1 and RC1 and defines a set of nodes from RC1 closest to KC1 nodes, called RCl-Selected (Step 4.1.1); clusters the similar nodes for KC1 and RCl-Selected using ML clustering algorithms such as KNN (Step 4.1.2); and then selects fusion of the nodes from RCl-Selected to KC1 which the similarity is superior to some pre-defined threshold (Step 4.1.3).

[0105] • In order to generate composite threat variants, the CVG measures the similarity score between different nodes for KC1 and subgraphs in RC1, and defines a set of subgraphs from RC1 closest to KC1 nodes, called RC2-Selected (Step 4.2.1); and then selects to compose the nodes from RC2-Selected to KC1 which the similarity is superior to some pre-defined threshold (Step 4.2.2).

[0106] In the following, various components of the present disclosure are described.

[0107] Pre-Processing Unit

[0108] Given an APT name, the agent is responsible for processing the Attack chain. This includes extracting the associated chain (Step 1) as well as aggregating techniques per attack stage (Step 2), as described below:

[0109] 1. Attack chain Extraction: The agent queries the knowledge base to extract all possible techniques that could be used in the Attack chain.

[0110] 2. Techniques Aggregation: Once all techniques are extracted from the knowledge base, the agent uses the MITRE ATT&CK framework to aggregate different techniques to different tactics (i.e., attack stage). The same technique can be used at multiple stages (e.g., active scanning can be used during Reconnaissance and Discovery as well), in this scenario the same technique is replicated in both stages with different security contexts (different pre- and post-conditions).

[0111] FIG. 9 is a diagram of an example technique aggregation using the MITRE ATT&CK framework.

[0112] Once the techniques are aggregated, the security context vector for each technique is generated. The pre-processing unit then feeds the aggregated sequence to the Evolved Variants Generator Agent (Step 3) and Composite Variants Generator Agent (Step 4) to generate evolved variants and composite variants, respectively.

[0113] Security Context Evaluator

[0114] A technique represents a specific behavior or action that an adversary may take in a network / system to achieve their objectives. The MITRE ATT&CK Framework is widely used in cybersecurity to understand adversary behavior and to develop strategies for detecting and mitigating threats. Each technique is categorized under a specific tactic and is given a unique identifier. The technique provides detailed information about what the technique is, examples of how it can be used, what data can be collected, how to detect it, and possible mitigation strategies. Tactics represent the "why” of an adversary's action while techniques represent the "how".

[0115] A security context for a given technique is represented by multiple features in the format of a vector. The vector reflects pre- and post-condition (requirements and outcome, respectively). FIG. 10 illustrates an example of security context for a general technique.

[0116] A technique’s security context contains the following features / factors:

[0117] • Pre-condition (requirements): such as a. required privileges', level of privileges required to execute a technique (e.g., regular user, administrator / root), b. platform applicability, the platform used to execute the technique (e.g., Windows, Linux, cross-platform), c. data sources: specific types of inputs used to execute the technique e.g., log events, network traffic, registry data), dependencies: conditions or dependencies on certain configurations (e.g., system configuration, network configuration, presence of certain software), d. associated procedures: conjunction with other techniques forming a chain of techniques (e.g., occurrence / presence of previous techniques in the chain).

[0118] • Post-condition (outcome): such as a. objective: the goal / purpose of the technique is designed to achieve (e.g., maintain access, persistence, execution), b. method: specific actions / procedures that are carried out when the technique is executed (e.g., execute a command, exploit a vulnerability, manipulate settings), c. impact: effect / consequence of the technique on the system / network (e.g., change system setting, disrupt service, consumption of resources).

[0119] Given the security context, the multi-set for an APT is then extended to E =

[0120] Evolved Variants Generator (EVG)

[0121] This agent is responsible for generating evolved variants by finding similar techniques that could be used instead of the known techniques in the Attack chain, and then predicting their relationships within the APT in question (FIG. 11). One aspect of the instant approach is that this is the first time that the variant generation process considers the security context for each technique by capturing the pre- and post-condition for each technique. Compared with existing technologies, the present disclosure is the first of its kind that automatically generates evolved variants.

[0122] The agent is composed of two main steps:

[0123] 1. Adjacent Techniques Clustering: The agent calculates a new feature representation for each technique within the same attack stage (i.e., tactic) that will be used later to extract similarity and perform clustering. Given a technique t E X, and for each technique t' E Tactics(t), where t' X, the agent computes the transformed features htlfor technique t' and its neighbors: ht, = features(t') * Wx

[0124] The process of calculating the transformed features is repeated for each technique in the attack chain to obtain their new feature representations (i.e., security context). The output features are then fed to a clustering algorithm (e.g., Densitybased Clustering Algorithm, K-Nearest Neighbors algorithm) to cluster techniques with similar features into the same cluster. Features might include tactics, platforms, required permissions, impact, dependencies, and commonalities in tools. The similarity is based on the security context and not deterministic on the distance. This helps in finding similar and interchangeable techniques e.g., two techniques might be similar in sharing multiple common features but are different in the platform applicability, thus they are not interchangeable).

[0125] The objective of clustering is to minimize the intra-cluster distance (i.e., between techniques within the same tactic) and maximize the inter-cluster distance (i.e., distance between tactics) based on the technique’s security context. FIG. 12 illustrates an example of adjacent technique clustering. For ease of understanding, the nodes with “New Technique” formatting from the legend in FIG. 7 represent similar techniques for one or more nodes in a respective portion of APT X that are indicated by bold lines. For example, the Discovery Portion of APT X in FIG. 12 shows two similar techniques (i.e., Query Registry and Remote System Discovery) to one or more nodes in the Discovery Portion of APT X. Some techniques might have more than one similar technique in their clusters, while others have an empty cluster (e.g., “Spearphishing Attachment”). This is due to changes in their security context, even if two techniques are meant to be similar, their security contexts are different and therefore they cannot be clustered up. In addition, techniques “Windows Management Instrumentation” and “Command and Scripting Interpreter: Windows Command Shell” are clustered up with “Command and Scripting Interpreter: PowerShell”, yet the former has a higher similarity score (e.g., smaller distance with “Command and Scripting Interpreter: PowerShell”) compared with technique “Command and Scripting Interpreter: Windows Command Shell”. Adjacent Techniques Fusion: Once the adjacent techniques are clustered per each technique t E X , the agent applies link prediction algorithm to find new relations with the clustered techniques. By leveraging the feature representations i.e., security context), the learned technique embeddings can be used to infer the probability of a link existing between any two techniques. This is achieved by computing the similarity score between the embeddings of the two techniques. This score can be computed by applying a learned function such as a neural network that tends to aggregate the security context features from the technique’s neighbors. Once the technique’s embedding is calculated, similarity techniques such as Pearson, Cosine, and Dot product similarity can be used. To further refine the similarity score, an attention mechanism can be used to weigh the contribution of neighbors differently. A high similarity score would suggest a high probability of a link existing between the nodes, while a low score would suggest the opposite.

[0126] For two techniques f and tj, the agent retrieves the embedding security context, named and hj, respectively. The agent then computes the similarity score p(ht, hj~) using a GNN layer using an aggregation function (i.e., mean, sum, max). Once the similarity score is calculated, the agent applies a sigmoid function to map it to a probability value P(tt, tj) = sigmoid p(hi, hj). This gives a number between 0 and 1 representing the predicted probability of a link between technique f and technique tj .

[0127] Using the probabilities calculated through link prediction as explained before, the system considers the most probable techniques to replace the existing ones in X and generate evolved variants (based on a pre-defined threshold). The threshold is set empirically by the experts and is outside the scope of this document. FIG. 13 depicts an example of possible evolved threat techniques with shaded background are the fusion techniques within the new variant. The bolded arrows may represent new parts and / or new relationship(s) of the variant of APT X. The APT can use a very new technique (e.g., “Trusted Relationship” and not the already known technique e.g., “Drive-by Compromise” of APT X). In addition, although “Scheduled Task / Job” had three similar techniques clustered up (“Scheduled Task / Job: Cron”, “Event Triggered Execution”, and “Systemd Timers”), only “Event Triggered Execution” has been used in the new variant as it is most close - based on security context, to the technique in question.

[0128] Composite Variants Generator (CVG)

[0129] In response to the enhancement of security defense mechanisms, or as a strategic component of their stealth operations, attackers may adopt techniques and behaviors commonly attributed to other threat actors. The agent is responsible for generating composite threats by finding any potential merge / transcription between the APT in question and other APTs in the knowledge base (the SOC team can further narrow down the list of APTs by selecting interested APTs). For example, the threat actor of APT X would use other techniques from APT Y in order to bypass / deceive the detection mechanisms. The generation process considers not only the techniques’ security context but also a sub-kill-chain S from other APTs. A sub-kill-chain can be defined as a sequence of techniques {t1(t2, ■ ■ ■ , such that there is an edge between and ti+1for all 1 < i < I. The sub-kill-chain sequence can also be represented by aggregating the feature vectors of its constituent techniques, generating a vector s. In order to generate composite threats, the agent performs the following steps:

[0130] 1. Resembling Sequence Matching: Given an interested APTs y, and for each technique in the APT X, the composite variants agent calculates the similarity score with any potential sequence within the same stage (i.e., tactic) in the APT y. This will lead to finding any resemblance among a technique t G X with a sequence in the APT y that could be substituted with. FIG. 14 illustrates an example of resembling sequence matching. The technique “Data Encoding” at the Command and Control phase from APT X has a matching with sequence {“Data Compression”, “Data Obfuscation”, “Obfuscated Files or Information: Steganography”} from APT Y. This is due to the fact that the sub-sequence will lead to the same objective of “Data Encoding” by compressing data, adding noise, and then sending the data while preventing the detection of hidden information. This sub-sequence of techniques is not totally new, but it has already been used by other attacks (e.g., APT T). 2. Sequence Transcription: Once the resembling sequences are generated, for each technique t E X , the agent applies link prediction as explained in the Pre- Processing Unit section to calculate the probability aiming at substituting the technique t with a resembling sequence. Due to the security context attached to each technique, the resembling sequence shares similar pre- and post-condition as the original technique t that will substitute with. FIG. 15 illustrates an example of a transcribe sequence { “Data Compression”, “Data Obfuscation”, “Obfuscated Files or Information: Steganography”} from APT Y into APT X in place of technique “Data Compression”, leading to generate new composite threat that combines two APTs out of which the Command and Control stage is based from APT Y.

[0131] The final output of the solution is a list of evolved and composite variants. FIG. 16 illustrates an example of two examples of threat variants (evolved and composite) of the initial APT shown in FIG. 6. These variants are further sent to the SOC team for testing and validation.

[0132] Aligned Threat Generation

[0133] As a corollary to the present disclosure, another way of variant generation is described: aligned threat generation (not presented in FIGs. 7A-7B).

[0134] The presented solution is also able to generate aligned threats. In fact, an aligned threat (g) is a sequence of techniques (G) that involves only techniques from the original attack chain (X). The difference between g and x is that g might have different order of techniques (e.g., new relationships between techniques) or a smaller number of techniques (e.g., some techniques have been skipped).

[0135] In order to generate aligned threats, new links are predicted (as explained in Section 2.7.1.3) between techniques used within the attack chain. The prediction is confined to each attack stage, meaning that the new predicted links should be not crossattack stages.

[0136] Once predicted links are generated among involved techniques in the attack chain sequence, the solution keeps only links that reach a pre-defined threshold. Techniques connected to links with lower values than the threshold are eliminated. By doing so, techniques that can be skipped by the attacker are eliminated. FIG. 17 illustrates an example of an aligned threat generated for APT x, where a new link has been predicted between techniques (Scripting — Command and Scripting Interpreter: Power Shell) and (System Network Configuration Discovery — Network Service Discovery) where techniques "Command and Scripting Interpreter: PowerShell’, "Scripting”, and "File and Directory Discovery” have been eliminated.

[0137] Thus, one or more embodiments not only anticipates potential attack vectors but also adapts to the evolving landscape of cyber threats, ensuring that the defense mechanisms remain a step ahead. In fact, the generated threat variants serve as a vital resource for both red and blue teams. Red teams can leverage these variants to rigorously test the security of systems, simulating attacks to identify vulnerabilities before they can be exploited by actual adversaries. Concurrently, blue teams can utilize the information to proactively plan and prepare defense mechanisms and strategies. This collaborative use of threat variants ensures that both offensive and defensive security teams are equipped with the knowledge and tools necessary to enhance the organization’s cybersecurity posture and resilience against sophisticated cyber- attacks.

[0138] Therefore, one or more embodiments described herein provide one or more of the following:

[0139] • The automated system is configured to generate potential threat variants for a given APT or loC taking into account the security context of the attack chain without relying on manual scrutinization of the knowledge base and security experts’ intervention, o Understanding and learning the security context of the attack chain using Graph machine learning and pre- and post- conditions of involved techniques, given the dynamic changes of system telemetry and knowledge base.

[0140] • Generating new attack steps using graph machine learning based on the knowledge base by applying link prediction, clustering, and sequence matching and transcription. o Understand the security context based on the involved techniques and their relationship from the knowledge base to generate threat variants. o Find similar yet interchangeable techniques in the knowledge base based on the security context. o Automate the generation of evolved threat variants by augmenting the attack chain with other similar APT. o Automate the generation of composite threat variants by transcribing attack sub- sequence from other similar APTs.

[0141] One or more embodiments described herein provide one or more of the following advantages: o Enforce the threat hunting capabilities by providing a fully automated solution to scrutinize telemetry and compiling the security knowledge base, o Strengthen the security defense line by proactively generating new variants of potential APTs that might exist in the system, o Enhance the SOC capabilities by automatically investigating all potential attack steps that might occur, o Reduce the required time and resources to investigate all received security events / alerts, o Simulate new threat variants to test the security of the infrastructure.

[0142] Some Examples

[0143] Embodiment Al. A computing device 13 configured to configured to, and / or comprising processing circuitry 18 configured to: evaluate security context for at least a first Attack chain sequence of a first security threat; and generate at least one potential threat variant based on the evaluated security context.

[0144] Embodiment A2. The computing device 13 of Embodiment Al, wherein the evaluating of the security context for the first Attack chain sequence is based on system telemetry and a predefined knowledge base 30 of security threats.

[0145] Embodiment A3. The computing device 13 of any one of Embodiments Al and A2, wherein the at least one potential threat variant comprises at least one evolved threat variant that incorporates a technique different from the first security threat.

[0146] Embodiment A4. The computing device 13 of any one of Embodiments Al- A3, wherein the computing device 13 is further configured to evaluate security context for a plurality of Attack chain sequences associated with a plurality of security threats, the plurality of security threats comprising the first security threat; and the at least one potential threat variant comprises at least one composite threat variant that transcribes an attack sub-sequence from the plurality of security threats.

[0147] Embodiment A5. The computing device 13 of any one of Embodiments Al- A4, wherein the computing device 13 is further configured to at least one of: implement at least one protective measure in response to the generation of the at least one potential threat variant; or search for the at least one potential threat variant in response to the generation of the at least one potential threat variant. Embodiment A6. The computing device 13 of any one of Embodiments Al- A5, wherein the generation of the at least one potential threat variant comprises generating at least one attack step using a graph machine learning.

[0148] Embodiment Bl. A method implemented by a computing device 13, the method comprising: evaluating security context for at least a first Attack chain sequence of a first security threat; and generating at least one potential threat variant based on the evaluated security context.

[0149] Embodiment B2. The method of Embodiment B l, wherein the evaluating of the security context for the first Attack chain sequence is based on system telemetry and a predefined knowledge base of security threats.

[0150] Embodiment B3. The method of any one of Embodiments B 1 and B2, wherein the at least one potential threat variant comprises at least one evolved threat variant that incorporates a technique different from the first security threat.

[0151] Embodiment B4. The method of any one of Embodiments B 1-B3, further comprising evaluating security context for a plurality of Attack chain sequences associated with a plurality of security threats, the plurality of security threats comprising the first security threat; and the at least one potential threat variant comprises at least one composite threat variant that transcribes an attack sub-sequence from the plurality of security threats.

[0152] Embodiment B5. The method of any one of Embodiments B 1-B4, further comprising at least one of: implement at least one protective measure in response to the generation of the at least one potential threat variant; or search for the at least one potential threat variant in response to the generation of the at least one potential threat variant.

[0153] Embodiment B6. The method of any one of Embodiments B 1-B5, wherein the generation of the at least one potential threat variant comprises generating at least one attack step using a graph machine learning.

[0154] As will be appreciated by one of skill in the art, the concepts described herein may be embodied as a method, data processing system, computer program product and / or computer storage media storing an executable computer program. Accordingly, the concepts described herein may take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects all generally referred to herein as a “circuit” or “module.” Any process, step, action and / or functionality described herein may be performed by, and / or associated to, a corresponding module, which may be implemented in software and / or firmware and / or hardware. Furthermore, the disclosure may take the form of a computer program product on a tangible computer usable storage medium having computer program code embodied in the medium that can be executed by a computer. Any suitable tangible computer readable medium may be utilized including hard disks, CD-ROMs, electronic storage devices, optical storage devices, or magnetic storage devices.

[0155] Some embodiments are described herein with reference to flowchart illustrations and / or block diagrams of methods, systems and computer program products. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer (to thereby create a special purpose computer), special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0156] These computer program instructions may also be stored in a computer readable memory or storage medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instruction means which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0157] The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0158] It is to be understood that the functions / acts noted in the blocks may occur out of the order noted in the operational illustrations. For example, two blocks shown in succession may in fact be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality / acts involved. Although some of the diagrams include arrows on communication paths to show a primary direction of communication, it is to be understood that communication may occur in the opposite direction to the depicted arrows.

[0159] Computer program code for carrying out operations of the concepts described herein may be written in an object oriented programming language such as Python, Java® or C++. However, the computer program code for carrying out operations of the disclosure may also be written in conventional procedural programming languages, such as the "C" programming language. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer. In the latter scenario, the remote computer may be connected to the user's computer through a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0160] Many different embodiments have been disclosed herein, in connection with the above description and the drawings. It will be understood that it would be unduly repetitious and obfuscating to literally describe and illustrate every combination and subcombination of these embodiments. Accordingly, all embodiments can be combined in any way and / or combination, and the present specification, including the drawings, shall be construed to constitute a complete written description of all combinations and subcombinations of the embodiments described herein, and of the manner and process of making and using them, and shall support claims to any such combination or subcombination.

[0161] Abbreviations that may be used in the preceding description include:

[0162] Abbreviation Explanation

[0163] APT Advanced Persistent Threats

[0164] GC2 Google Command and Control loA Indicator of Attack loC Indicator of Compromise

[0165] SOC Security Operations Center

[0166] TAG Threat Analysis Group It will be appreciated by persons skilled in the art that the embodiments described herein are not limited to what has been particularly shown and described herein above. In addition, unless mention was made above to the contrary, it should be noted that all of the accompanying drawings are not to scale. A variety of modifications and variations are possible in light of the above teachings without departing from the scope of the following claims.

Claims

CLAIMS:

1. A method implemented in a computing device (13), the method comprising: evaluating (S104) security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat, the security context for each of the plurality of techniques indicating one or both of: at least one requirement for the respective technique to occur; and at least one result of the respective technique; and generating (S106) a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence, the first threat variant being based on the respective security context for the at least one technique of the first attack chain sequence.

2. The method of Claim 1, wherein the at least one requirement of the respective technique to occur comprises one or more of: a level of privilege required to execute the respective technique; a predefined platform for executing the respective technique; at least one predefined type of input for executing the respective technique; and a presence of at least one other technique in the first attack chain sequence that is configured to occur before the respective technique.

3. The method of any one of Claims 1-2, wherein the at least one result of the respective technique comprises one or more of: a function that the respective technique is configured to achieve; at least one action or procedure that is performed when the technique is executed; and a predefined effect of the respective technique on a system.

4. The method of any one of Claims 1-3, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to a technique from at least one other attack chain sequence different from the first attack chain sequence.

5. The method of any one of Claims 1-3, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to a group of techniques from at least one other attack chain sequence different from the first attack chain sequence.

6. The method of any one of Claims 1-3, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to one or more of: skipping the at least one technique of the first attack chain sequence; and a different sequence in the first attack chain sequence for the at least one technique of the first attack chain sequence.

7. The method of any one of Claims 1-6, further comprising generating the first threat variant for the at least one technique of the first attack chain sequence at least by: generating a graph neural network having a plurality of nodes based on a knowledge base (30) for proactive threat detection, each of the plurality of nodes corresponding to a respective technique associated with a respective security context, the knowledge base (30) comprising a plurality of attack chain sequences including the first attack chain sequence; evaluating the plurality of nodes, using a similarity threshold, based on the respective security context; and logically grouping at least two of the plurality of nodes based on the evaluation, the first threat variant for the at least one technique of the first attack chain sequence being based on the grouping.

8. The method of Claim 7, wherein the evaluation of the plurality of nodes using a similarity threshold comprises: determining a similarity score of at least two nodes of the plurality of nodes; determining whether the similarity score meets a similarity threshold; the logical grouping of the least two nodes being based on the similarity threshold being met, the at two nodes of the plurality of nodes being interchangeable based on the similarity threshold being met; andthe first threat variant for the at least one technique of the first attack chain sequence being based on the interchangeability of the at least two nodes of the plurality of nodes.

9. The method of Claim 8, wherein the at least two nodes that meet the similarity threshold comprise one of: a first node of the plurality of nodes that is determined to be similar to a second node of the plurality of nodes based on the similarity threshold being met; or a first node of the plurality of nodes that is determined to be similar to a group of the plurality of nodes based on the similarity threshold being met.

10. The method of Claim 7, wherein at least one node of the plurality of nodes that are not part of the plurality of clusters is not considered in the generating of the second attack chain sequence.

11. The method of Claim 7, further comprising: augmenting the knowledge base (30) at least in part by updating the knowledge base (30) to include the second attack chain sequence; and updating the graph neural network based on the augmenting of the knowledge base (30).

12. A computing device (13) configured to: evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat, the security context for each of the plurality of techniques indicating one or both of: at least one requirement for the respective technique to occur; and at least one result of the respective technique; and generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence, the first threat variant being based on the respective security context for the at least one technique of the first attack chain sequence.

13. The computing device (13) of Claim 12, wherein the at least one requirement of the respective technique to occur comprises one or more of:a level of privilege required to execute the respective technique; a predefined platform for executing the respective technique; at least one predefined type of input for executing the respective technique; and a presence of at least one other technique in the first attack chain sequence that is configured to occur before the respective technique.

14. The computing device (13) of any one of Claims 12-13, wherein the at least one result of the respective technique comprises one or more of: a function that the respective technique is configured to achieve; at least one action or procedure that is performed when the technique is executed; and a predefined effect of the respective technique on a system.

15. The computing device (13) of any one of Claims 12-14, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to a technique from at least one other attack chain sequence different from the first attack chain sequence.

16. The computing device (13) of any one of Claims 12-14, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to a group of techniques from at least one other attack chain sequence different from the first attack chain sequence.

17. The computing device (13) of any one of Claims 12-14, wherein the first threat variant for the at least one technique of the first attack chain sequence corresponds to one or more of: skipping the at least one technique of the first attack chain sequence; and a different sequence in the first attack chain sequence for the at least one technique of the first attack chain sequence.

18. The computing device (13) of any one of Claims 12-17, wherein the computing device (13) is further configured to generate the first threat variant for the at least one technique of the first attack chain sequence at least by:generating a graph neural network having a plurality of nodes based on a knowledge base (30) for proactive threat detection, each of the plurality of nodes corresponding to a respective technique associated with a respective security context, the knowledge base (30) comprising a plurality of attack chain sequences including the first attack chain sequence; evaluating the plurality of nodes, using a similarity threshold, based on the respective security context; and logically grouping at least two of the plurality of nodes based on the evaluation, the first threat variant for the at least one technique of the first attack chain sequence being based on the grouping.

19. The computing device (13) of Claim 18, wherein the evaluation of the plurality of nodes using a similarity threshold comprises: determining a similarity score of at least two nodes of the plurality of nodes; determining whether the similarity score meets a similarity threshold; the logical grouping of the least two nodes being based on the similarity threshold being met, the at two nodes of the plurality of nodes being interchangeable based on the similarity threshold being met; and the first threat variant for the at least one technique of the first attack chain sequence being based on the interchangeability of the at least two nodes of the plurality of nodes.

20. The computing device (13) of Claim 19, wherein the at least two nodes that meet the similarity threshold comprise one of: a first node of the plurality of nodes that is determined to be similar to a second node of the plurality of nodes based on the similarity threshold being met; or a first node of the plurality of nodes that is determined to be similar to a group of the plurality of nodes based on the similarity threshold being met.

21. The computing device (13) of Claim 18, wherein at least one node of the plurality of nodes that are not part of the plurality of clusters is not considered in the generating of the second attack chain sequence.

22. The computing device (13) of Claim 18, wherein the computing device (13) is further configured to: augment the knowledge base at least in part by updating the knowledge base (30) to include the second attack chain sequence; and update the graph neural network based on the augmenting of the knowledge base (30).

23. A computer readable medium (22) comprising processing instructions that, when executed by at least one processor (20), cause the at least one processor (20) to: evaluate security context for each of a plurality of techniques of at least a first attack chain sequence of a first security threat, the security context for each of the plurality of techniques indicating one or both of: at least one requirement for the respective technique to occur; and at least one result of the respective technique; and generate a second attack chain sequence that comprises a first threat variant for at least one technique of the first attack chain sequence, the first threat variant being based on the respective security context for the at least one technique of the first attack chain sequence.

24. The computer readable medium (22) of Claim 23, wherein the processing instructions are further configured to cause the at least one processor to perform the method of any one of Claims 2-11.

Citation Information

Patent Citations

  • ATTCK-based industrial internet attack chain association method and system

    CN115514582A

  • Adaptive system for network and security management

    US20230396637A1