APT Defense System Kill Chain Threat Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Advanced Persistent Threat (APT) attacks are difficult to detect due to their focused and specific nature, use of zero-day loopholes, and long latency, making them undetectable and threatening national security and citizen rights, as existing security detection methods struggle to identify phases like weaponization and environmental sensing.

Innovation Solution

An APT Defense System (APTDS) that collects and analyzes communication data using a kill chain model to map threat data into detectable phases, performing association analysis and applying prevention strategies tailored to each phase, including loophole scanning, access control, and blacklisting, to effectively prevent APT attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security detection methods are used, then detection simplicity is maintained, but detection capability against APT attacks deteriorates due to focused and specific attack nature, zero-day loopholes, and long latency

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the APT attack process into distinct phases using the kill chain model (reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives). Each phase is detected using specialized indicators and methods tailored to that specific phase, allowing complex APT detection to be broken down into manageable, phase-specific components while maintaining high detection capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces behavioral analytics as an additional dimension beyond traditional signature-based detection. By analyzing user and entity behaviors, communication patterns, and temporal sequences of events, the system detects APT attacks that evade conventional methods. This multi-dimensional approach combines traditional security indicators with behavioral patterns to achieve comprehensive detection without excessive complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If comprehensive communication data analysis is performed to detect all APT phases, then detection precision is improved, but analysis time and computational resources increase

Engineering Contradiction:
Improvethreat detection precisionVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent pre-establishes phase-specific detection indicators and thresholds for each kill chain phase before attacks occur. Detection rules, indicator patterns, and analysis parameters are configured in advance based on known APT behaviors for each phase. When data arrives, the system immediately compares it against these pre-configured indicators, enabling rapid precision detection without performing comprehensive analysis from scratch

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different analysis depths and methods to different data sources and phases. High-value indicators requiring deep analysis are identified and prioritized, while routine data uses standardized quick-check methods. Each kill chain phase receives customized analysis intensity based on its specific detection requirements, optimizing the balance between precision and analysis time

Inventive Principle:
Principle #3Local quality

3Reliability

If phase-specific prevention strategies are implemented for each kill chain phase, then prevention effectiveness is improved, but system complexity and operational overhead increase

Engineering Contradiction:
Improveprevention effectivenessVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a unified prevention platform that handles multiple kill chain phases through a common interface and centralized control. The system provides universal prevention capabilities across all phases (network security, host security, application security, data security) through a single management console, reducing operational complexity while maintaining phase-specific prevention effectiveness. Security policies can be configured and deployed system-wide or phase-specifically through the same interface

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3588898B1Defense against apt attack
Publication Date: 2023.07.12 NEW H3C TECH CO LTD
  • EP3588898B1 patent drawingFigure 1~2
  • EP3588898B1 patent drawingFigure 3~4

AI summary

Methods, systems for preventing an APT attack and non-transitory machine-readable storage mediums are disclosed. In one aspect, communication data is obtained in a network, association analysis is performed for the communication data, threat data is obtained from the communication data based on an association analysis result, each piece of the obtained threat data is mapped to a corresponding APT attack phase based on a kill chain model; and for each piece of the threat data, prevention is performed for a network entity associated with the piece of the threat data based on prevention strategies corresponding to the plurality of APT attack phases.