Cyberattack Path Prediction with Adaptive Threat Queries
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The operation of a Security Operation Center (SOC) requires advanced knowledge and significant resources, and manual creation of search queries for cyber threat intelligence (CTI) is inefficient and prone to varying analysis results among operators due to the diverse nature of cyberattacks.
Innovation Solution
An attack path prediction method and device that automatically creates search queries based on incident information, relaxing conditions when insufficient initial matches are found, and incorporates trend information to predict cyberattack paths.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual search query creation is used for obtaining cyber threat intelligence, then the operator can obtain information related to cyberattacks, but it requires advanced knowledge and significant time investment
Solution Approach 1:
The system pre-processes and structures cyber threat intelligence data from multiple sources into standardized formats with predefined attributes and relationships. This preliminary organization enables automated query generation without requiring manual intervention during incident response, significantly reducing the time needed to retrieve relevant threat information while maintaining high accuracy through pre-validated data structures.
Solution Approach 2:
An automated query generation system acts as an intermediary between the incident description and the cyber threat intelligence database. This intermediary automatically translates incident descriptions into optimized search queries using pre-defined templates and algorithms, eliminating the need for operators to manually create complex queries while ensuring consistent and accurate information retrieval.
2Adaptability or versatility
If multiple SOC operators analyze the same cyberattack, then diverse perspectives can be obtained, but varying analysis results occur due to different knowledge levels and approaches
Solution Approach 1:
The system transforms unstructured incident descriptions into standardized parameters and structured data formats with defined schemas. By converting varying operator inputs into consistent parameter representations, the system ensures that all analysts work with the same structured information, eliminating variability in analysis results while preserving the ability to handle diverse incident types through flexible parameter definitions.
Solution Approach 2:
A universal automated analysis system performs multiple functions including query generation, information retrieval, attack path prediction, and next action recommendation. This multi-functional system provides consistent analysis results across all incidents and operators, eliminating the need for multiple human analysts while maintaining comprehensive analysis capabilities through integrated automated processes.
3Productivity
If automated search query creation is implemented, then operational efficiency is improved, but the system may obtain insufficient threat information with strict search conditions
Solution Approach 1:
The search condition relaxation mechanism dynamically adjusts query parameters based on the quantity and quality of retrieved results. When initial strict queries return insufficient information, the system automatically relaxes search conditions by reducing the number of required matching attributes or expanding search scopes, thereby maintaining high operational efficiency while ensuring sufficient threat information is obtained through adaptive query refinement.
Solution Approach 2:
The system implements a feedback loop where the results of automated query execution are evaluated against predefined sufficiency criteria. When the retrieved threat information is deemed insufficient, the feedback mechanism triggers automatic query relaxation and re-execution, ensuring that the final result set meets the required information quantity and quality thresholds while minimizing manual intervention and maintaining high productivity.
Data Source
AI summary
An attack path prediction method includes: obtaining incident information related to a cyberattack on a monitoring target vehicle from a monitor monitoring the monitoring target vehicle; obtaining one or more items of threat information related to a past cyberattack, based on the incident information; and predicting the attack path of the cyberattack on the monitoring target vehicle, based on the one or more items of threat information. The obtaining of the threat information includes: creating a first search query for obtaining the one or more items of threat information, based on the incident information; creating a second search query for which a search condition is more relaxed than for the first search query, based on the incident information, when the number of the items of threat information is less than a predetermined number; and obtaining the one or more items of threat information, using the second search query.


