Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

25 results about "Kill chain" patented technology

The term kill chain was originally used as a military concept related to the structure of an attack; consisting of target identification, force dispatch to target, decision and order to attack the target, and finally the destruction of the target. Conversely, the idea of "breaking" an opponent's kill chain is a method of defense or preemptive action. More recently, Lockheed Martin adapted this concept to information security, using it as a method for modeling intrusions on a computer network. The cyber kill chain model has seen some adoption in the information security community. However, acceptance is not universal, with critics pointing to what they believe are fundamental flaws in the model.

Method and device for constructing and recommending equipment system adversarial network of dynamic time sequence event

The invention discloses a dynamic time sequence event equipment system adversarial network construction and recommendation method and device, and relates to the field of killing network design, and the method comprises the steps: constructing an initial detection-command and control-strike warning network; a dynamic time sequence event on the battlefield is continuously monitored, when the event type of the dynamic time sequence event is an equipment state event, the initial detection-command-strike warning network is updated, and when the event type of the dynamic time sequence event is a chained event, a closed detection-command-strike link set containing an enemy target is generated; the closed detection-command-strike link set comprises a plurality of killing chains; based on the multi-dimensional evaluation index system, evaluating each killing chain to obtain an evaluation result corresponding to each killing chain; and according to the evaluation results corresponding to all the killing chains, recommending an optimal interception scheme of an air defense and anti-guide interception action. The method overcomes the problems of large calculation dimension and slow response speed of an existing method.
Owner:BEIJING INST OF TECH

Service-based killer chain analysis construction method

The invention discloses a service-based killer chain analysis construction method, which belongs to the technical field of cooperative combat, and comprises the following steps: constructing a service resource pool, and setting a service discovery mechanism; on the basis of the fusion situation set, a situation switching event is recognized so as to perform local updating, and a three-level situation view is constructed; constructing a directed hyperedge, generating a directed hypergraph in combination with function category constraints, generating a dimensionality reduction state space based on multi-dimensional constraints, and generating an initial combat candidate set; configuring a management node, sending task invitation information to the initial combat candidate set in combination with the subtasks, generating a response scheme, performing adaptive screening, generating an initial killing chain, and performing failure verification; constructing a servitization twinborn body, deducing the initial killing chain, and executing delay at a calculation end so as to perform elimination recombination or delay optimization; a service combination template is constructed, an efficiency feedback mechanism is established, the superposition influence of frequent situation switching and state space catastrophe is cooperatively solved, and the real-time performance of generation of the killing chain is remarkably improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Cps attack path reconstruction method and system based on kill chain model clustering

The application belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on a kill chain model clustering. CPS information layer and physical layer operation data are collected, a feature vector is generated through time window fusion, a feature subspace is divided based on the four stages of the kill chain, candidate clusters are obtained by clustering the data of each stage, high-confidence clusters are screened in combination with time concentration and behavior intensity, a causal diagram is constructed according to time proximity and cross-layer correlation, and complete reconstruction of the attack path is realized; the application adapts to the cross-layer coupling characteristics of CPS, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack tracing and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

A service-based kill chain analysis construction method

The application discloses a kind of service-based kill chain analysis construction methods, belong to the technical field of cooperative combat, including: constructing service resource pool, and set service discovery mechanism;Based on fusion situation set, identify situation switching event, to carry out local update, and construct three-level situation view;Directed hyperedge is constructed, combined with function category constraint, generates directed hypergraph, generates dimensionality reduction state space based on multidimensional constraint, and generates initial combat candidate set;Configuration management node, combined with subtask to the initial combat candidate set sends task invitation information, generates response scheme and carries out adaptation screening, generates initial kill chain, and carries out failure check;Build service twin, deduce the initial kill chain, calculate end execution delay, to carry out elimination reorganization or delay optimization;Build service combination template, and establish efficiency feedback mechanism, cooperatively solve the superimposed influence of frequent situation switching and state space catastrophe, significantly improve kill chain generation real-time performance.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Context-aware security policies and incident identification via automated cloud graph building with security overlays

Context-aware security policies and incident identification, via automated cloud graph building with security overlays, are determined and performed by systems and platforms. Graph nodes, of a graph associated with a computing system, that represent resources associated with the computing system and entities associated with the computing system that have respective associations to the resources are generated. Security attributes are determined and assigned to the graph nodes that represent the entities and resources, and static and dynamic connections between the graph nodes are added to the graph. Additionally, possible connections in the graph between the graph nodes are added based on heuristic relational determinations of the graph nodes. From the graph, security incidents and kill chains are identified, context-aware security policies are generated and validated, and scopes and relationships of applications are identified. Accordingly, security actions are taken for the computing system.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Anti-killer chain construction method based on service-oriented killer chain

The invention relates to the technical field of killer chain construction, in particular to an anti-killer chain construction method based on a service-oriented killer chain, and provides the following scheme: target motion prediction is performed based on real-time state information of a to-be-hit target to obtain a predicted path of the target in a preset time, and a probability cloud model is constructed in a three-dimensional tactical space to obtain a predicted path of the target; and a target influence area is determined after tactical environment constraint correction. And screening candidate service objects from the service resource library according to space, time and capability constraints, and mapping the candidate service objects to each killing chain link in combination with the service type killing chain template corresponding to the target. According to the method, rapid reconstruction of the killing chain can be realized under the conditions of target maneuvering, equipment damage or resource replacement, and the flexibility and continuous strike capability of a combat system are improved.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

CPS attack path reconstruction method and system based on killer chain model clustering

The invention belongs to the technical field of network security, and particularly relates to a CPS attack path reconstruction method and system based on killer chain model clustering. The method comprises the steps of collecting operation data of a CPS information layer and a physical layer, generating feature vectors through time window fusion, dividing feature subspaces based on four stages of a killing chain, clustering data of each stage to obtain candidate clusters, screening high-credibility clusters in combination with time concentration and behavior intensity, and constructing a causal graph according to time proximity and cross-layer correlation. Complete reconstruction of an attack path is realized; the method adapts to CPS cross-layer coupling characteristics, improves the accuracy of attack stage division and path reconstruction, and can provide reliable support for attack traceability and defense strategy formulation.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

A method for generating kill chains and recommending remediation action

A method includes, for each vulnerability in a set of vulnerabilities: deriving a correlation between the vulnerability and an attack technique based on language signals detected in descriptions of the vulnerability; constructing a vulnerability module defining the attack technique and representing the vulnerability; detecting a second vulnerability preceding exploitation of the vulnerability in the corpus of threat intelligence; defining the second vulnerability as an input vulnerability in the vulnerability module; detecting a third vulnerability succeeding exploitation of the vulnerability in the corpus of threat intelligence; defining the third vulnerability as an output vulnerability in the vulnerability module; interpreting an access tier of the vulnerability based on characteristics of the attack technique; accessing a vulnerability risk score for the vulnerability; interpreting a mitigation technique for the attack technique; and annotating the vulnerability module with the access tier, the vulnerability risk score, and the mitigation technique.
Owner:TEGULA LLC

Systems and methods for countering persistent malware

Some embodiments construct an entity map describing a group of inter-related entities and determine whether a computing device comprises malware according to the respective entity map. The entity map includes worker entities (e.g., processes) and resource entities (e.g., files) accessed by the respective worker entities. Some entity maps are persistently stored and recovered in response to a reboot, enabling a complete reconstruction of a kill chain even when malicious activities are distributed among multiple entities and multiple computing sessions. Some embodiments detect infection by comparing a current entity map with a signature map describing at least a fragment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time to generate an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

A dynamic kill chain construction and reconfiguration method and apparatus

The application discloses a dynamic killing chain construction and reconstruction method and device, which acquires real-time situation data and constructs a time-varying heterogeneous graph for representing a connection relationship of heterogeneous nodes and multi-dimensional constraints, performs phased searching in the time-varying heterogeneous graph based on a task demand, generates a candidate killing chain set containing a main chain and a backup chain, executes feasibility screening on the candidate killing chain set to eliminate chains that do not satisfy hard constraints and obtains a feasible chain set, then performs multi-objective collaborative optimization selection on the feasible chain set, outputs a backup chain set and a target main chain, and finally, when a node state change triggering a reconstruction condition is monitored, performs a hierarchical reconstruction operation based on the target main chain, the backup chain set and a time-varying heterogeneous graph updated in real time, and generates an updated killing chain execution scheme.
Owner:BAIYANG TIMES (BEIJING) TECH CO LTD

A Dynamic Defense Method and System for APT Network Kill Chain Based on Dual Deep Reinforcement Learning

A dynamic defense method and system for APT network kill chains based on dual deep reinforcement learning is proposed. The system pre-configures a network system including host nodes, security defenders, malicious attackers, and security defense devices. Malicious attackers execute attacks on host nodes according to the network kill chain. Security defenders monitor these attacks and acquire network status. Security defense devices, based on dual deep reinforcement learning algorithms and combined with the network status, dynamically generate optimal defense strategies and feed them back to the security defenders. The security defenders then dynamically respond to the attacks using these optimal strategies to protect against the network kill chain. This approach achieves efficient identification and accurate response to APT attacks, effectively improving system security and resource utilization efficiency. It provides an innovative solution for dynamic defense in complex network environments and significantly enhances the resistance to APT attacks.
Owner:XIAMEN UNIV

Killer chain construction method based on particle swarm optimization

PendingCN122047835AForecastingArtificial lifeLink modelAlgorithm
The invention discloses a killing chain construction method based on a particle swarm algorithm, and belongs to the technical field of cooperative combat systems. The method comprises the following steps: dividing a killing chain construction problem into four links of detection, positioning, interference and strike which are executed in sequence, respectively establishing corresponding task allocation models, and taking maximization of efficiency of each link as a target function; and solving each link model by adopting an improved decimal discrete particle swarm algorithm to obtain an optimal task allocation scheme, and sequentially combining all link schemes to complete the construction of the killing chain. According to the method, the modeling process is simplified, the calculation efficiency is improved, the method is suitable for a large-scale combat scene, an optimization scheme can be quickly generated, and the requirements of actual combat for real-time performance and accuracy are effectively met.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

An effectiveness evaluation method based on modeling of an anti-system-of-systems kill chain

This invention discloses an effectiveness evaluation method based on kill chain modeling of an adversarial system, belonging to the field of system evaluation technology. The method includes the following steps: based on the starting and ending conditions of a given task, analysis is performed in three different dimensions: time, information, and precision. An adversarial interaction network is constructed, and the adversarial effectiveness is analyzed in different dimensions using the analytic hierarchy process (AHP), with scores assigned to the evaluation results in each dimension. The scores of the evaluation results in different dimensions are then weighted and integrated to obtain a comprehensive evaluation result of the adversarial effectiveness. This invention fully considers the influence of each node in the adversarial system on the system's adversarial effectiveness, highlighting the significant impact of the kill chain in the time, information, and precision dimensions on effectiveness. It solves the problem of evaluating the strike effectiveness of kill chains formed by different adversarial methods in complex systems.
Owner:HARBIN ENG UNIV

A method for constructing an anti-kill chain based on a service-type kill chain

The application relates to the technical field of killing chain construction, in particular to a counter-killing chain construction method based on a service type killing chain. The application proposes the following scheme: target motion prediction is carried out based on real-time state information of a to-be-struck target, a predicted path of the target within a preset time is obtained, a probability cloud model is constructed in a three-dimensional tactical space, and a target influence area is determined after being corrected by a tactical environment constraint. Candidate service objects are screened from a service resource library according to space, time and capacity constraints, and the candidate service objects are mapped to each killing chain link in combination with a service type killing chain template corresponding to the target. The application can realize rapid reconstruction of the killing chain under the conditions of target maneuvering, equipment damage or resource replacement, and improve the flexibility and sustained striking capacity of a combat system.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Multi-dimensional equipment system contribution rate evaluation method

The invention discloses a multi-dimensional equipment system contribution rate evaluation method, which comprises the following steps of: 1, acquiring network topology structure information of an equipment system, and collecting the total number of combat resources and detection information of a sensor on an incoming target; step 2, establishing a calculation model of the total number of killing chains of the equipment system based on a system network topology structure; 3, establishing an incoming attack target value evaluation index system, and evaluating the strategic / tactical value of the incoming attack target; step 4, simulating a combat scene, and obtaining the number of resources consumed by each device and hit / damage of an incoming attack target; 5, evaluating a contribution rate evaluation index of the equipment in a system combat effectiveness dimension, and evaluating a relative contribution rate of the equipment in a resource consumption and target value hitting dimension based on a relative increment model; step 6, establishing an equipment comprehensive contribution rate calculation model, and evaluating the comprehensive contribution rate of each piece of equipment; and step 7, outputting a comprehensive contribution rate evaluation result of each equipment system. Influences of indexes such as combat effectiveness, combat consumption and combat income can be considered, and managers are helped to comprehensively evaluate the contribution rate of the equipment system.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Power grid malicious code attack chain construction method and system based on multi-dimensional intention features

The present application relates to the technical field of network security, in particular to a power grid malicious code attack chain construction method and system based on multi-dimensional intention characteristics. The present application extracts the industrial control operation field, context load field, timestamp field and subject identifier, and then converts them into sparse vectors, dense vectors and real number vectors, and fuses the above three vectors into a multi-dimensional intention characteristic tensor. Secondly, each multi-dimensional intention characteristic tensor is accurately given a final tactical intention label and an atomic intention node is constructed. Thirdly, the atomic intention node is divided into a session sequence by introducing a dynamic time window, and the atomic intention node is time-series aggregated according to the subject identifier consistency and the damage chain association relationship. Finally, by constructing an initial heterogeneous graph and performing logical pruning, the redundant nodes and edges unrelated to the attack evolution path are removed, and the final heterogeneous graph generated in a structured form presents the whole process of a malicious code attack completely and intuitively.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD

System and method for dealing with persistent malicious software

Some embodiments construct entity mappings describing groups of cross-correlated entities and determine whether a computing device includes malware according to the respective entity mappings. The entity mapping includes worker entities (e.g., processors) and resource entities (e.g., files) accessed by the respective worker entities. Some entity mappings are persisted and restored in response to a restart, enabling complete reconstruction of the killer chain even when malicious activities are distributed in multiple entities and multiple computing sessions. Some embodiments detect an infection by comparing a current entity map to a signature map describing at least one segment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

Simulation modeling and verification method and device for killing network

The invention discloses a simulation modeling and verification method for a killing net. The method comprises the following steps: constructing a killing net component element model; the killing net component element model comprises a mobile platform model, a sensor model, a communication equipment model, a weapon system model, a data processing module model and a command mechanism model; constructing a killing net system model based on the killing net composition element model; and performing simulation processing on the killing network system model by using a simulation platform to obtain evaluation result information. The invention provides a specific, complete and systematic method for model construction, killing network construction, killing chain combination, killing chain analysis and the like for killing network modeling simulation, can be used for killing network concept demonstration verification and killing network efficiency analysis, and provides means and basis for killing network concept evolution and killing network system construction demonstration.
Owner:BEIJING HUARU TECH

System and method for dealing with persistent malicious software

Some embodiments construct entity mappings describing groups of cross-correlated entities and determine whether a computing device includes malware according to the respective entity mappings. The entity mapping includes worker entities (e.g., processors) and resource entities (e.g., files) accessed by the respective worker entities. Some entity mappings are persisted and restored in response to a restart, enabling complete reconstruction of the killer chain even when malicious activities are distributed in multiple entities and multiple computing sessions. Some embodiments detect an infection by comparing a current entity map to a signature map describing at least one segment of a known attack.
Owner:BITDEFENDER IPR MANAGEMENT

Multi-dimensional evaluation method for vulnerability of combat system

The invention discloses a combat system vulnerability multi-dimensional evaluation method, and belongs to the technical field of complex system safety evaluation. According to the method, a combat system is decomposed into a physical layer, a logic layer and a cross-layer coupling layer for multi-dimensional modeling; the physical layer calculates topological indexes such as degree centrality and betweenness centrality based on a complex network theory; the logic layer searches a killing chain through a Ullmann algorithm based on a killing chain theory and quantifies indexes such as the chain number and the average path length; and the cross-layer coupling layer analyzes the element failure cascade effect and the capability recovery degree. And integrating multi-dimensional evaluation results through intersection and union set operation to form a vulnerability interval based on the average path length of the killing chain. According to the method, the problems of one-sided single-dimensional evaluation and lack of cross-layer coupling analysis in the prior art are solved, the multi-dimensional quantitative evaluation of the combat system vulnerability is realized, and a scientific basis is provided for system destroy-resistant optimization and key node protection.
Owner:KINGDOM AUTO CONTROL TECH LTD CHANGSHA

A new operational concept analysis method based on kill chain

The application discloses a new combat concept analysis method based on a killing chain, belongs to the technical field of command cooperation, and aims to solve the problems of static solidification of the existing killing chain, insufficient target adaptability, and lagging behind of weak link replacement. The core includes: collecting the core features of the moving target to generate the execution ID of the associated total information; combining the target prediction track data and the environmental interference data to generate the environmental influence factor to predict the target prediction track; constructing a link combat device database, screening the device constraint adaptation device pool through function adaptation and space-time constraint, and constructing a dynamic killing chain after differential processing; real-time monitoring of the track deviation degree updates the killing chain, and the weak link is identified through information accessibility evaluation and an alternative device list is generated. The application realizes dynamic adaptation of the killing chain to dynamic changes and target characteristics, quickly replaces the weak link, and significantly improves the execution continuity and reliability.
Owner:未分类(SHANGHAI) TECHNOLOGY CO LTD

Threat detection method and system based on multi-stage attack process matching

The invention discloses a threat detection method and system based on multi-stage attack process matching. The method comprises the following steps: preprocessing heterogeneous traffic in a novel power system, obtaining security alarm information, carrying out association analysis, constructing a coherent attack behavior sequence, and distributing a credibility index for each attack behavior. Uncertainties and conflict evidence present in the alarm data are processed and analyzed. And dynamically generating an attack sequence diagram according to the attack behavior sequence, traversing and reconstructing all possible attack scheme paths according to a time sequence, and selecting a potential attack path with the highest belief value. Through attack stage matching, the most credible attack sequence diagram and the most reasonable attack reduction path are searched, the optimal result pair is identified, and the current killing chain stage of an attacker is determined. According to the method, security analysis is carried out through multi-source information sources, heterogeneous information can be effectively integrated, uncertainty can be processed, an attack scheme can be accurately identified and restored, and complete attack situation awareness is realized.
Owner:STATE GRID HENAN ELECTRIC POWER ELECTRIC POWER SCI RES INST +4

System and method for presenting security measures

The security measures presenting system presents information indicating security measures by displaying the information on a display device. The security measures presenting system is configured of a computer which includes at least an arithmetic device and a storage device, and is mutually connected to an input device and the display device outside the computer in a manner capable of mutual data communication. The storage device stores rule information with respect to a rule concerning security, the rule information including at least a target system indicating a targeted system to which a security measure is to be applied, and required items for a component included in the target system; and measure information indicating a kill chain phase which represents an execution phase of an attack, an attack technique which represents an attack method to be used in the kill chain phase, and measures for defending and / or alleviating the attack technique.
Owner:HITACHI LTD

Methods and systems for automatic grading, impact analysis and mapping to the CIA triad

In one aspect, In one aspect, a computerized method for automatic grading, impact analysis and mapping to the CIA triad, comprising: identifying a value of a plurality of data stores; associating the value back to an attack scenario such that a measure of impact with respect to attack progression or susceptibility now has a pecuniary value and generating a grading score; associating the grading score mapped to Confidentiality, Integrity and Availability (CIA) Triad; associating an attack progression with the pecuniary value and priority; identifying a progression of the attack; determining a time that is available for a response before a damage occurs to a system under attack; determining a stage of the attack in an attack kill chain, wherein for every stage of the attack as the progress happens, associating the pecuniary value and an impact for such a stage; and automatically calculates an overall data threat grade of the system.
Owner:THEOM INC