Cyberattack Path Prediction with Adaptive Threat Queries

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The operation of a Security Operation Center (SOC) requires advanced knowledge and significant resources, and manual creation of search queries for cyber threat intelligence (CTI) is inefficient and prone to varying analysis results among operators due to the diverse nature of cyberattacks.

Innovation Solution

An attack path prediction method and device that automatically creates search queries based on incident information, relaxing conditions when insufficient initial matches are found, and incorporates trend information to predict cyberattack paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual search query creation is used for obtaining cyber threat intelligence, then the operator can obtain information related to cyberattacks, but it requires advanced knowledge and significant time investment

Engineering Contradiction:
Improveaccuracy of threat information retrievalVSAvoidtime required for query creation and information selection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-processes and structures cyber threat intelligence data from multiple sources into standardized formats with predefined attributes and relationships. This preliminary organization enables automated query generation without requiring manual intervention during incident response, significantly reducing the time needed to retrieve relevant threat information while maintaining high accuracy through pre-validated data structures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An automated query generation system acts as an intermediary between the incident description and the cyber threat intelligence database. This intermediary automatically translates incident descriptions into optimized search queries using pre-defined templates and algorithms, eliminating the need for operators to manually create complex queries while ensuring consistent and accurate information retrieval.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple SOC operators analyze the same cyberattack, then diverse perspectives can be obtained, but varying analysis results occur due to different knowledge levels and approaches

Engineering Contradiction:
Improvediversity of analysis perspectivesVSAvoidconsistency of analysis results
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system transforms unstructured incident descriptions into standardized parameters and structured data formats with defined schemas. By converting varying operator inputs into consistent parameter representations, the system ensures that all analysts work with the same structured information, eliminating variability in analysis results while preserving the ability to handle diverse incident types through flexible parameter definitions.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

A universal automated analysis system performs multiple functions including query generation, information retrieval, attack path prediction, and next action recommendation. This multi-functional system provides consistent analysis results across all incidents and operators, eliminating the need for multiple human analysts while maintaining comprehensive analysis capabilities through integrated automated processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If automated search query creation is implemented, then operational efficiency is improved, but the system may obtain insufficient threat information with strict search conditions

Engineering Contradiction:
Improveoperational efficiency of threat information retrievalVSAvoidamount of threat information obtained
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The search condition relaxation mechanism dynamically adjusts query parameters based on the quantity and quality of retrieved results. When initial strict queries return insufficient information, the system automatically relaxes search conditions by reducing the number of required matching attributes or expanding search scopes, thereby maintaining high operational efficiency while ensuring sufficient threat information is obtained through adaptive query refinement.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback loop where the results of automated query execution are evaluated against predefined sufficiency criteria. When the retrieved threat information is deemed insufficient, the feedback mechanism triggers automatic query relaxation and re-execution, ensuring that the final result set meets the required information quantity and quality thresholds while minimizing manual intervention and maintaining high productivity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250301007A1Attack path prediction method, attack path prediction device, and recording medium
Publication Date: 2025.09.25 PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
  • US20250301007A1 patent drawing
  • US20250301007A1 patent drawing
  • US20250301007A1 patent drawing

AI summary

An attack path prediction method includes: obtaining incident information related to a cyberattack on a monitoring target vehicle from a monitor monitoring the monitoring target vehicle; obtaining one or more items of threat information related to a past cyberattack, based on the incident information; and predicting the attack path of the cyberattack on the monitoring target vehicle, based on the one or more items of threat information. The obtaining of the threat information includes: creating a first search query for obtaining the one or more items of threat information, based on the incident information; creating a second search query for which a search condition is more relaxed than for the first search query, based on the incident information, when the number of the items of threat information is less than a predetermined number; and obtaining the one or more items of threat information, using the second search query.