Method for detecting and predicting cyber threats in industrial environments

A network of physical industrial decoys with phased CTI tasks addresses the limitations of existing cyber threat detection methods, enhancing cybersecurity by capturing comprehensive threat intelligence for proactive threat anticipation and response.

WO2026008896A1PCT designated stage Publication Date: 2026-01-08TELEFONICA CYBERSECURITY & CLOUD TECH S L U
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/ES2024/070426
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-05
Publication Date
2026-01-08

AI Technical Summary

Technical Problem

Existing solutions for detecting and predicting cyber threats in industrial environments are inadequate as they rely on virtual or hybrid systems that do not capture the full spectrum of real-world threats, lack error tolerance, and are costly, failing to anticipate attacker strategies and trends effectively.

Method used

A method using a network of physical industrial systems as decoys to capture and analyze cyber threats, employing phased Cyber Threat Intelligence (CTI) tasks to generate advanced intelligence, including information disaggregation, linking, standardization, and aggregation, followed by threat identification, trend and campaign identification, and generation of updated dictionaries and use cases.

Benefits of technology

Enhances cybersecurity by providing high-quality, proactive threat detection and prediction, enabling effective anticipation of cyber threats and trends, improving the robustness and efficiency of cybersecurity measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure ES2024070426_08012026_PF_FP_ABST
    Figure ES2024070426_08012026_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for detecting and predicting cyber threats in industrial environments using cyber threat intelligence (CTI), comprising: I) identifying threats (200) and classifying same through the analysis of TTP measures and IOC / IOA indicators, including a basic and advanced CTI process for unidentified known / similar threats and zero-day vulnerabilities; ii) identifying trends and campaigns (300), detecting patterns and repeated events, analysing attack behaviours and characteristics in order to predict trends and campaigns directed towards specific devices, industrial sectors or clients; iii) generating dictionaries updated with remote access attempts in order to analyse data used in attacks; and iv) generating use cases in order to manage incidents, anticipating changes to known threats. The method is based on multilevel modelling (L1, L2,..., Ln): the input (11) from a threat capture system feeds to a basic CTI (12) at the first level, resulting in initial information (21), relating to both attackers and threats (22), which is input into the advanced CTI (23) at the next level and so on until the last one, in order to obtain the final information (30) relating to cyber attacks and attackers.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD FOR DETECTING AND PREDICTING CYBER THREATS IN INDUSTRIAL ENVIRONMENTS

[0002] DESCRIPTION

[0003] OBJECT OF THE INVENTION

[0004] The present invention falls within the technical field of cyber threat capture systems (cyber threats), trap or decoy systems.

[0005] In particular, the present invention relates to a method for the detection and prediction of cyber threats, applicable in a Cyber ​​Threat Intelligence system, by identifying and anticipating the behaviors and actions of cyber threats in the field of OT (Operational Technology) industrial systems through predictive intelligence.

[0006] BACKGROUND OF THE INVENTION

[0007] Information on cyber threats targeting industrial sectors is scarce and of poor quality. This is because software systems running on personal computers (PCs) are used to virtualize industrial hardware, which typically generates more information about the PCs themselves than about the virtualized industrial systems. Furthermore, virtualized systems are comparable to low-iteration honeypots, meaning they are not easily accessible to attackers, and much of their tactics, techniques, procedures, and tools are lost.

[0008] There are solutions that make use of physical or semi-physical systems, but mostly for the execution of a testbed and / or synthetic tests.

[0009] Solutions have also been found that work with threat information, such as malware or fingerprinting. However, these solutions do not use actual hardware to improve the quality of the generated information and detect behavior. Instead, they are applied to the construction and testing of rules for direct loading into intrusion detection systems (IDS) or intrusion prevention systems (IPS), or for calculating a cyber risk index for a system or company (where "cyber risk" indicates the risk of a company suffering a successful cyberattack). Examples of this include:

[0010] • CN114296406A: Attack and defense visualization system

[0011] Although a physical system is used to simulate the effects of an attack, and this simulation involves understanding the aspects of an attack (attack vector, exploited vulnerability, indicators of attack and compromise, etc.), synthetic threats are used to reproduce planned use cases. The solution proposed in this document does not wait for a pre-planned action, but rather records any action executed by an attacker and applies Cyber ​​Threat Intelligence (CTI) to the information it collects. Therefore, what is analyzed are 100% real-world threats.

[0012] • US9405900B2: Rule testing system for the security of industrial environments.

[0013] This system employs physical elements and also applies CTI, but its objective is to use it to generate rules that are refined after each iteration. These rules are then tested on various systems to verify their effectiveness in securing a system. However, the solution described in this document does not perform an analysis based on rules that are debugged before being deployed to a real system. Instead, it relies on a more advanced and in-depth CTI approach to ensure that mitigation and defense measures are effective without the need for subsequent screening or refinement.

[0014] • US20160323318A1: Automatic application system for threat-based rules.

[0015] This system focuses on information and communication technologies (IT), not operational technology (OT). It takes a reactive approach by installing an agent that monitors a personal computer and archives all recorded activity during a cyberattack. It also applies pre-loaded rules to mitigate or neutralize the attack. The solution described in this document is proactive and does not focus on IT elements. Therefore, it also does not apply rules to limit or neutralize an attack, but rather allows the attacker to explore the system while capturing as much information as possible to perform CTI (Computer-Aided Intelligence) and predictive intelligence.

[0016] • US20210176267A1: Industrial-level cyber risk calculation system.

[0017] This system applies machine learning (ML) and a weighting system to assess the risk of a cyber threat. However, it focuses on obtaining a value that indicates the cybersecurity risk to a target. The solution proposed in this document does not evaluate threats, but rather classifies them to obtain more information on how to mitigate or neutralize them if they are detected again in the future, or if more advanced versions of those same threats are encountered.

[0018] As previously mentioned, there are no state-of-the-art solutions that deploy a threat capture and predictive analytics platform using physical industrial systems as decoys. One reason for this is the cost of such systems and their low error tolerance. Furthermore, employing synthetic tests or test benches in these types of solutions fails to capture the reality of the current industrial cyber threat landscape. No matter how extensive and intensive the testing plan, it cannot cover the full spectrum of cyberattacks that can occur in real industrial systems, nor can it anticipate the movements, strategies, trends, or fads of attackers and criminals targeting these systems.

[0019] Therefore, the objective technical problem presented is to provide a mechanism for the capture of cyber threats and their predictive analysis that covers the entire spectrum of possible cyberattacks, using physical industrial systems as decoys, with a greater tolerance for error in these systems, but without increasing costs, in order to effectively anticipate the strategies and emerging trends of attackers.

[0020] DESCRIPTION OF THE INVENTION

[0021] The present invention addresses the aforementioned problem by capturing the necessary information to anticipate cyberattacks and malicious activity against industrial or operational (OT) systems through the detection of early activity patterns and traces. The described solution proposes a method that extracts information from a cyber threat capture system and performs Cyber ​​Threat Intelligence (CTI) tasks in distinct phases. This approach leverages the initial information (collected by the threat capture system) to generate basic cyber threat intelligence through CTI tasks and subsequently uses both this initial information and the basic intelligence to generate advanced intelligence.

[0022] The present invention makes it possible to detect, identify and predict cyber threats and their behavior, taking advantage of the deployment of hardware decoys to expose them to the Internet and, thus, take advantage of the maximum quality and reality of the threats collected, capturing and analyzing all the information relating to activity on the decoys and working with said information from a predictive point of view to anticipate trends, campaigns and detect possible unknown threats.

[0023] One aspect of the invention relates to a computer-implemented method for detecting and predicting cyber threats in industrial environments, as defined in claim 1. Dependent claims define advantageous embodiments.

[0024] Another aspect of the invention relates to a data processing apparatus comprising at least one processor configured to perform the steps of the method defined above.

[0025] Another aspect of the invention relates to a computer program product comprising instructions that, when the program is executed by a computer, cause it to carry out the method defined above.

[0026] Another aspect of the invention relates to a computer-readable medium comprising instructions that, when executed by the computer, cause it to execute the method defined above.

[0027] The proposed cyber threat detection and prediction method uses physical industrial systems as decoys and deploys a network of them. To reduce costs, it employs several strategies, such as overexposing the decoys across multiple locations worldwide and leveraging the generated information, such as predictively detecting behaviors and trends, which are described in more detail in the various embodiments of the invention presented later. The proposed cyber threat detection and prediction method is implementable in a threat capture system in industrial environments.

[0028] The advantages of the present invention over the prior art are fundamentally:

[0029] The present invention strengthens cybersecurity and adds valuable information for executing processes of converting data into intelligence on computer threats to prevent attacks.

[0030] It is designed to integrate, as part of its threat intelligence (TID) process, the input of information from a network of physical decoys that masquerade as industrial production systems. This entails a greater degree of complexity in the threat capture system, but also an increase in the quality of the TID process geared towards predictive intelligence. The use of real hardware and the decoy network improves the quality of the information collected, as empirical results are obtained. Since the present invention produces greater and better utilization of the captured information, this implies an increase in the effectiveness and efficiency of a platform that deploys decoys with real industrial hardware (such as that described in PCT / ES2023 / 070621). Virtual or hybrid solutions may not address threats in the realistic way that a real system would, and therefore there is no absolute guarantee of the viability of their TID.Furthermore, a virtual or hybrid system cannot be prepared for what it does not know, making it more difficult for it to deal with the most dangerous threats: those currently unknown.

[0031] The phased refinement and strengthening of information allows each procedure to complete its processes and then begin others that ensure its robustness. Other solutions that refine their intelligence in a loop ultimately make it fragile, whereas working with information, generating CTI (Critical Thinking Intelligence), and then adding more information to refine it without losing traceability allows for a broader and more holistic view of what is being analyzed. Generating intelligence from a predictive perspective improves the ability to anticipate events compared to other systems. This allows for proactive security, response, and mitigation measures in the face of unexpected events at a client's facilities.

[0032] These and other advantages can be derived from the description of the invention that is presented in detail below.

[0033] DESCRIPTION OF THE DRAWINGS

[0034] To complement the description being made and in order to help a better understanding of the characteristics of the invention, according to a preferred embodiment thereof, a set of drawings is included as an integral part of said description, in which, for illustrative and non-limiting purposes, the following has been represented:

[0035] Figure 1.- Shows a schematic of a phased modeling of the Cyber ​​Threat Intelligence (CTI) tasks that is followed in the design of a method for the detection and prediction of cyber threats, according to a possible embodiment of the invention.

[0036] Figure 2.- Shows a flowchart of the steps performed by the cyber threat detection and prediction method for the identification of threats, according to a possible embodiment of the invention.

[0037] Figure 3.- Shows a flowchart of the steps performed by the cyber threat prediction method for identifying cyber attack trends, campaigns and targeted cyber campaigns, according to a possible embodiment of the invention.

[0038] PREFERRED EMBODIMENT OF THE INVENTION

[0039] A detailed explanation of a preferred embodiment of the present invention is then provided, with the aid of the aforementioned figures. A method for detecting and predicting cyber threats in industrial environments is described, which enhances the standard processes carried out by a Cyber ​​Threat Intelligence (CTI) platform by dividing them into phases or stages. A monolithic CTI process only utilizes the information initially gathered. In some cases, the monolithic system is recursively refined, using the output of the previous refinement as input.This allows, in theory, for higher quality intelligence than that obtained without applying recursion, but it can also lead to excessive refinement that makes the resulting intelligence too restrictive or overtrains a machine learning (ML) or artificial intelligence (AI) model. However, multi-stage or multi-level modeling, for example, as represented in Figure 1, with n levels L1, L2,..., Ln-i, L1, L2,..., Ln-i, L2,..., Ln-i, L1 ... nThis allows us to leverage not only the information gathered but also the results of the previous CTI process. Furthermore, this modeling distinguishes between cybersecurity threats and events, enabling us to understand the relationship between them and generate cybersecurity events that are richer in information and more complex in nature. Thus, in the first phase, or L1 level, we start with input information 11 for a basic CTI process 12, from which we obtain initial information 21 about both the actors / attackers and the threats. This information then becomes input 22 to be processed by an advanced CTI 23 in the next stage (second level L2 and subsequent levels L). n -i). And so on until reaching the last phase or level L n From which the final information on attackers and cyberattacks is obtained. In short, the information is processed by the CTI platform in multiple stages: L1, L2,..., L n -i, L nSuccessive stages not only imply that the output of one stage is the input of the next, but also that a different STI process is applied at each stage to complete and improve the quality of the information.

[0040] Starting with input information provided by a threat capture system, the following (four) processes are performed, working on that information initially and in this order:

[0041] 1 o Disaggregation process:

[0042] • Separation of information into work pieces: The first action performed is the separation and classification of the input information to subsequently identify the blocks of information that will be worked on in the initial CTI process.

[0043] • Handling of information traces: Information that may arrive incomplete or corrupted (due to a previous standardization issue unrelated to the system described here) is either processed if sufficient to advance the process, or discarded if not. Identification of the origin of the disaggregated information:

[0044] • Linking disaggregated information to its original source: Disaggregated information must remain linked to its source, since part of the STI process uses this information to strengthen the intelligence generated. The linking process essentially consists of maintaining the traceability established in the previous step. This is achieved using unique identifiers provided by the information or assigned by the system itself.

[0045] • Handling orphaned pieces of information: Information that lacks a link, due to being incomplete, is cross-referenced with the complete information to create a dependency on it and allow its continued use throughout the rest of the CTI process. Information standardization:

[0046] In this step, similar information is given the same working basis. This involves two essential tasks:

[0047] • Adjustment of the units of measurement of the information with the same parameters: Identification of information with the same characteristics and use in order to generate blocks on which to do CTI.

[0048] • Standardization of all information to generate the information blocks on which to work: Modification of the values ​​of similar information to avoid errors when performing CTI with that information. For example, using the same unit of measurement for time information. 4o Information aggregation process:

[0049] In the final step, the information is aggregated into blocks that are (initially) processed during the CTI (Computer-Aided Technology) operations. This allows the system to work with the pieces of information both internally (within the block) and externally, and also allows for cross-referencing pieces of different types without losing track of where they belong (to which block).

[0050] The following describes the generation of information from a phased / leveled CTI process that uses information obtained from an industrial or OT cyber threat capture system as input:

[0051] CTI level 1:

[0052] • Threat identification: Geolocation, search in the database of the Indicator of Attack (loA) and the Indicator of Compromise (loC), and search in the database of the TTP (Tactics, Techniques and Procedures).

[0053] • Classification of threat events (cybersecurity events).

[0054] • Metrics: Number of similar events in the last 24 hours.

[0055] • Triage.

[0056] CTI level 2:

[0057] • Advanced threat identification: Identification of the attacking actor and threat association.

[0058] • Advanced metrics: Campaign detection.

[0059] • Holistic results from “day 0”

[0060] • Prospective analysis

[0061] The overall CTI process in this solution involves several phases / levels of work, at least two, depending on the type and variety of information. Although the information may vary due to limitations of the cyber threat capture system, the CTI processes and their phases are stable and always aim to generate the best possible intelligence. Since it may be necessary to apply the same task within the CTI process (to process the initial information and its output or byproduct), the possibility of identifying the same task at different stages or modifying it (creating an "advanced" or "phase 'n'" version) for application in subsequent stages of the CTI process is also considered.To improve the system's analysis and learning, the possibility of re-executing certain tasks is included, such as associating cybersecurity events with trends, campaigns, or targeted campaigns, increasing or decreasing the estimated time range for event association.

[0062] With all this, predictive intelligence focuses on CTI tasks and the product of processes 1-4 described above, as described below, distinguishing four main tasks: i) threat identification, ii) trend and campaign identification, iii) generation of updated dictionaries, and iv) generation of new use cases to address cybersecurity events. i. Threat Identification 200:

[0063] Figure 2 shows a basic diagram of the threat identification process. This task aims to identify the threats recorded in the system. Thanks to this identification, trends in cybercriminal activity or the disclosure of zero-day threats / vulnerabilities can be detected predictively. This helps cybersecurity teams in their triage process, allowing them to act as quickly as possible where it is most needed. The following steps are distinguished within the threat identification task 200: o Basic processing 210:

[0064] An attempt is made to identify similar threats previously recorded by comparing TTP (Tactics, Techniques, and Procedures) and LoA-LoC (Attack Indicator-Compromise Indicator) metrics with a database containing similar data extracted from past events. Depending on whether this search for relationships is successful, the threat is considered known or unknown based on a comparison between a level of match and an associated percentile. This match with a previously recorded threat has an associated percentile (0%-100%), indicating whether a) the threat is not previously recorded, b) it is only "similar" to other identified threats, or c) it is a previously recorded threat.

[0065] Once the similarity of the threat detailed in the analyzed event is determined, the procedure differs depending on whether it is an identified threat or similar to others, or an unknown threat. Threats with a match level below the associated percentile (manually adjustable value) are directly marked as potential zero-day vulnerabilities. This indicator forces the analyzed threat to proceed to the "Advanced Processing for Unidentified and Zero-Day Threats" stage 240 without going through the "Advanced Processing for Known or Similar Threats" stage 230. Advanced Processing for Known or Similar Threats 230:

[0066] Events already flagged as a trend are reviewed based on information about actors and previously identified threats. If relationships are found, the event is supplemented with relevant information, and the event's basic data is linked to the actors and threats used in this advanced process. This enriches and strengthens the identification of subsequent events. If no relationships are found, advanced processing for unidentified threats is executed. Advanced processing for unidentified threats and zero-day threats (240): This processing can be initiated from basic processing or from advanced processing for threats that have not been associated with existing threats. In other words, when the objective of identifying the threat (250) has not been achieved after the previous basic and advanced processing phases, a positive result is not obtained.Then, the process moves to this next advanced processing step, where an attempt is made to associate each previously detected and identified event with a list of identified TTPs for A) Advanced Persistent Threat groups (APTs), and B) known attackers, threat actors, or malicious actors. If no match is found, the information is associated with an unknown attacker, pending later identification of the perpetrator.

[0067] Following this, regardless of whether the vulnerability is known or unknown, the information resulting from this advanced CTI processing is uploaded / registered to the corresponding CTI database. Furthermore, if the detected event is a potential candidate for an unknown vulnerability, the system issues an alert so that a group of analysts can analyze the threat information and confirm whether it is indeed an unknown vulnerability.

[0068] i. Identifying trends and campaigns 300:

[0069] Figure 3 shows a basic outline of the trend and campaign identification process. This task focuses on identifying recurring events and searching for patterns that help identify: Trends within the overall cybersecurity ecosystem; actions planned by a single attacker or group of attackers (campaigns); and actions planned by a single attacker or group of attackers that specifically target one or more devices (based on their characteristics), industry sectors, or customers (targeted campaigns).

[0070] This task focuses on analyzing the characteristics of recorded events. It identifies the origins and types of cybersecurity events to locate similar events within a specific timeframe and link them to other known events. Based on the data provided by the recorded metrics, the strength / intensity of each trend is also measured and recorded, with the understanding that trends and campaigns can always resurface in the future.

[0071] Predictive event analysis in threat capture systems helps to proactively address the occurrence of these events in real-world systems. Furthermore, it helps anticipate future threat mutations and respond accordingly. It can also identify unexpected behaviors that may constitute an APT (advanced persistent threat).

[0072] Depending on whether related threats are identified or not, the task of identifying trends and campaigns 300 comprises the following steps: or Basic processing 310:

[0073] It includes a timestamp record of each threat event, analysis of the source and destination of threat events, identification of target devices in the attack, threat and TTP analysis, and threat taxonomy.

[0074] First, each recorded event is associated with a typology collected within the taxonomy of cyber incidents published by the European Union Agency for Cybersecurity, ENISA.

[0075] Subsequently, a timestamp is recorded and logged within a time range (before and after) defined by the analyst to provide greater or lesser granularity to the task. This range can be on the order of hours or days and can be modified in successive executions of this task to include more or fewer events and improve the result obtained in the event association. All events recorded within this range (and their associated threats) are analyzed, looking for similarities with respect to their LoA, LoC, origins (based on geolocation, for example, with the GeolP tool, or based on the use of similar network infrastructure), and their TTP. The destinations of these events are also recorded in order to find specific patterns during advanced processing. Advanced Processing 320:

[0076] It includes an analysis of the target devices of the attack, the behavior of the attacks / attackers, threat association, trends and malicious actors, and volume analysis.

[0077] First, a pattern analysis is performed on the event targets. For example, if the analyzed events target a specific type of device, or a specific firmware version, it can be inferred that it is a campaign targeting that particular device. Analyzing event targets also allows for the proactive detection of campaigns targeting device manufacturers, specific industry sectors, and specific customers, if any of the decoys exposed on the network are characterized as if they were their actual production system (logo, corporate colors, text, etc.). In the case of campaigns against specific manufacturers or devices, threats occurring on the manufacturer's or brand's devices (and firmware or operating system version) are identified that are not appearing on other devices on the network.

[0078] A search is also conducted in the catalog of previously detected threats to identify whether the recorded activity may be related to previous actions (the trend was preceded by other activities before its detection). Past behavior is also examined in the historical databases of the analyzed information to try to predict the future behavior of this trend and any subsequent related actions.

[0079] Another action is to identify a specific characteristic within the analyzed events: the use of the same tool or set of tools; the same TTPs; the same type of event; the same vulnerability attempt; similar origins (physically or logically); etc. This aims to associate the event signature with an identified malicious actor or several attackers ("Threat Actors") who may be acting in concert. This association is also relevant for detecting potential mutations or evolutions of a campaign, whether targeted or not.

[0080] On the other hand, the intensity of the trend is measured, expressing the value in a number from 1 to 5 inclusive, where “5” is a very strong trend at a global level.

[0081] At this point in the process, if there is a clear association with one or more malicious actors or origins (330), the analyzed events are identified as a campaign (350). Furthermore, if a pattern is clearly identified in the destination (360) or target of these events (device(s) based on their characteristics, the industrial sector represented by the exposed decoy, the client referenced by a decoy, etc.), the analyzed events are identified as a targeted campaign (370). If these two conditions are not met, the analyzed events will be marked as a trend (340) within the overall cybersecurity landscape. iii. Generation of updated dictionaries:

[0082] This task logs all attempts to access remote services or main sites on devices that have them, to analyze the data and identify which terms are most frequently used in authentication attempts or whether a specific threat uses a particular dictionary (which helps identify the threat). This function can also be used to identify leaked keys from a customer's production systems by checking whether those keys are among those used by attackers in threat capture systems. The task of generating updated dictionaries, in turn, comprises: Basic processing:

[0083] The basic process for generating dictionaries involves collecting authentication information from the threat capture system and integrating it into a log. This authentication information or data can be a username / password combination or only one of these two elements. In either case, it is logged as if it were an access attempt.

[0084] The recorded information is used to generate metrics that identify the most frequently used terms and whether they occur in the username or password field. The most frequently used username / password pairs are also recorded. Advanced processing:

[0085] As indicated during the description of the overall solution process, the information always remains linked to the original event, so that it also serves to identify threats by their characteristics, such as access attempts recorded in a threat capture system.

[0086] Once the basic processing information is collected, an investigation is conducted to determine if there is any relationship between username / password pairs and threats, malicious actors, or already identified APT groups. If no relationship is detected (or it is inconclusive), each pair is identified as “generic.” However, if a conclusive relationship exists, each pair is identified with the registered threat, attackers, or APT groups. Therefore, this information is also useful for identifying their future activity. iv. Generation of new use cases to address cybersecurity events:

[0087] Use cases are an essential tool in managing cybersecurity incidents or events. For this reason, it is crucial to quickly obtain information about new threats, or mutations or evolutions of known ones, so that cyber incident management teams know how to act as effectively and efficiently as possible. The task of generating use cases involves: Basic processing:

[0088] For each recorded threat and event, a search is performed in the event and threat databases. If identified, the corresponding TTPs (Threat, Trap, Protocol) are analyzed. In this way, by using trusted sources, such as the matrices from the international organization MITRE for monitoring and analyzing incidents detected in the industrial world, mitigation measures can be found to guide a cybersecurity team in addressing the analyzed threats or events. Advanced processing:

[0089] After registering countermeasures for generating use cases, the database of malicious actors and APT groups is reviewed to strengthen knowledge about associated TTPs. This allows for anticipating a possible mutation in the threat along the lines of the mutation pattern in which the identified author typically makes mutations. By making this association, use cases can be generated (written) proactively, attempting to anticipate the attackers' actions.

[0090] Currently, the analysis and predictive nature of the generated intelligence are based on inferences and certain steps, such as adjusting the time range for trend detection, campaigns, and targeted campaigns, which require manual intervention by a human. However, the use of AI (Artificial Intelligence) and ML (Machine Learning) algorithms at various points in the solution allows it to function more autonomously and provide even more information to work with. For example:

[0091] - Application of ML in the selection of the time range for the detection of trends, campaigns and targeted campaigns.

[0092] - Application of AI so that the system can make the necessary balances within the time range and obtain the optimal information.

[0093] - Application of ML to improve the classification of threats and events in their relevant matrices and taxonomies.

[0094] - Application of AI to detect unknown threats with greater reliability, moving from percentile-based confidence to YES / NO-based confidence.

[0095] - Application of AI to improve the system's learning times when generating use cases for detected threats and hypothetical use cases for possible mutations of the analyzed threats.

[0096] - AI application for the system to find which users / passwords can be more robust based on the user / password input registered in the decoys.

[0097] - Application of ML to speed up statistical analysis of data.

Claims

CLAIMS 1. A computer-implemented method for detecting and predicting cyber threats in industrial environments, wherein the method processes input information provided by a cyber threat capture system that detects cybersecurity events, wherein the information processing is performed through a cyber threat intelligence (CTI) platform, characterized in that the information processing by the CTI platform comprises a plurality of successive stages (Li, l_2, ... , Ln-i , Ln) where a different CTI process is applied at each stage and where the CTI process of each stage yields output information and the output information is input to the next stage, until reaching the last stage (L n) to a final threat and attacker information (30) used to predict cyber threats, and wherein the CTI process of each stage comprises the following steps executed by one or more processors: threat identification (200), comprising at least steps i)-iii) of: i) basic processing (210) of cybersecurity events comprising: identifying a threat as a threat previously registered in the CTI platform by comparing measures of tactics, techniques and procedures, TTP, an indicator of attack, loA, and an indicator of compromise, loC, with a database of cybersecurity events recorded at an earlier time; classifying the identified threat as a known threat, a similar threat or an unknown threat (220) and if the identified threat is classified as an unknown threat, proceeding directly to step iii); (i) advanced processing for known or similar threats (230), comprising determining whether there is a relationship between the threat identified in the basic processing (210) and events marked as trending in the cybersecurity event database and, if there is a relationship, completing the cybersecurity event database with information about the threat identified in the basic processing (210) and, if there is no relationship, passing the threat identified in basic processing (210) to step iii); iii) advanced processing for unidentified threats and zero-day vulnerabilities (240), comprising searching for information about the threat identified in basic processing (210) within a list of TTP measures for advanced persistent threat groups, APTs, and / or measures for malicious actors known to the CTI platform, and, if the search is successful, associating the detected event with the measures found in the search; identification of trends and campaigns (300), comprising at least the steps of: basic processing (310) comprising recording each event detected by the cyber threat capture system with a timestamp of the event, origin and destination of the event, and identifying target devices of the event and classifying the event according to a threat taxonomy;advanced processing (320), comprising: identifying patterns with respect to the identified target devices of the events, if there is an association with a campaign (350) based on the origin and / or malicious actors (330); identifying patterns with respect to the destination (360), if there is an association with a targeted campaign (370); and if there is none of the above associations, identifying the recorded events with timestamps within a specified time frame as a trend (340).

2. The method according to claim 1, wherein classifying the identified threat as known threat, similar threat or unknown threat (220) is done on the basis of comparing a level of agreement with a percentile associated with the recorded threat that is identified in the basic processing (210).

3. The method according to any of the preceding claims, wherein the advanced processing for unidentified threats and zero-day vulnerabilities (240) further comprises recording the information in a database (260) of the CTI platform.

4. The method according to any of the preceding claims, wherein the advanced processing for unidentified threats and zero-day vulnerabilities (240), if the search is negative, comprises issuing a warning indicating that the detected event is a candidate for an unknown vulnerability.

5. The method according to any of the preceding claims, wherein the identification of trends and campaigns (300) further comprises analyzing characteristics of recorded events to detect repeated events in the specified time space and linking them to known events.

6. The method according to any of the preceding claims, wherein the identification of trends and campaigns (300) further comprises measuring an intensity level of each trend to predict a reappearance of trends.

7. The method according to any of the preceding claims, further comprising generating dictionaries with information resulting from basic processing and advanced processing, wherein the basic processing comprises: logging access attempts to the threat capture system, remote services, and main sites of identified target devices; analyzing authentication data used in the logged access attempts; generating metrics based on the analyzed data to determine terms including the most frequently used username / password pairs in the access attempts; and wherein the advanced processing comprises: linking the information resulting from the basic processing to an original event to identify threats by characteristics including the access attempts logged in the threat capture system; and determining whether there is a relationship between the username / password pairs and the threats, malicious actors, and APT groups already identified.

8. The method according to any of the preceding claims, further comprising generating use cases by means of basic processing and advanced processing, wherein the basic processing comprises: performing a search of the TTP measures recorded in the databases of events and threats from the CTI platform to compare them with the TTPs registered in trusted sources and obtain mitigation measures from the trusted sources for a cyberattack management team, and where the advanced processing comprises: running a search for malicious actors and APT groups associated with the registered TTP measures to determine mutation patterns of the malicious actors and APT groups; generating use cases for the cyberattack management team to predict changes in the identified threats based on the mutation patterns.

9. A computer program product comprising instructions that, when the program is executed by a computer, cause the computer to carry out the method of claims 1-8.

10. A computer-readable medium comprising instructions that, when executed by a computer, cause the computer to carry out the method of claims 1-8.

Citation Information

Patent Citations

  • APT information determination method and device, storage medium and electronic device

    CN110224975A

  • Advanced continuous threat information analysis method and device and computer equipment

    CN117478383A

  • A method for analyzing the technical and tactical homology of APT organizations based on threat intelligence

    CN117520563B

  • Automatic generation of attack patterns for threat detection

    US20230370479A1

  • Systems and methods for using machine learning models for improved and customized cyber threat intelligence

    US20240214409A1