APT Defense System Kill Chain Threat Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Advanced Persistent Threat (APT) attacks are difficult to detect due to their focused and specific nature, use of zero-day loopholes, and long latency, making them undetectable and threatening national security and citizen rights, as existing security detection methods struggle to identify phases like weaponization and environmental sensing.
Innovation Solution
An APT Defense System (APTDS) that collects and analyzes communication data using a kill chain model to map threat data into detectable phases, performing association analysis and applying prevention strategies tailored to each phase, including loophole scanning, access control, and blacklisting, to effectively prevent APT attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security detection methods are used, then detection simplicity is maintained, but detection capability against APT attacks deteriorates due to focused and specific attack nature, zero-day loopholes, and long latency
Solution Approach 1:
The patent segments the APT attack process into distinct phases using the kill chain model (reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives). Each phase is detected using specialized indicators and methods tailored to that specific phase, allowing complex APT detection to be broken down into manageable, phase-specific components while maintaining high detection capability
Solution Approach 2:
The patent introduces behavioral analytics as an additional dimension beyond traditional signature-based detection. By analyzing user and entity behaviors, communication patterns, and temporal sequences of events, the system detects APT attacks that evade conventional methods. This multi-dimensional approach combines traditional security indicators with behavioral patterns to achieve comprehensive detection without excessive complexity
2Measurement precision
If comprehensive communication data analysis is performed to detect all APT phases, then detection precision is improved, but analysis time and computational resources increase
Solution Approach 1:
The patent pre-establishes phase-specific detection indicators and thresholds for each kill chain phase before attacks occur. Detection rules, indicator patterns, and analysis parameters are configured in advance based on known APT behaviors for each phase. When data arrives, the system immediately compares it against these pre-configured indicators, enabling rapid precision detection without performing comprehensive analysis from scratch
Solution Approach 2:
The patent applies different analysis depths and methods to different data sources and phases. High-value indicators requiring deep analysis are identified and prioritized, while routine data uses standardized quick-check methods. Each kill chain phase receives customized analysis intensity based on its specific detection requirements, optimizing the balance between precision and analysis time
3Reliability
If phase-specific prevention strategies are implemented for each kill chain phase, then prevention effectiveness is improved, but system complexity and operational overhead increase
Solution Approach 1:
The patent implements a unified prevention platform that handles multiple kill chain phases through a common interface and centralized control. The system provides universal prevention capabilities across all phases (network security, host security, application security, data security) through a single management console, reducing operational complexity while maintaining phase-specific prevention effectiveness. Security policies can be configured and deployed system-wide or phase-specifically through the same interface
Data Source
Figure 1~2
Figure 3~4
AI summary
Methods, systems for preventing an APT attack and non-transitory machine-readable storage mediums are disclosed. In one aspect, communication data is obtained in a network, association analysis is performed for the communication data, threat data is obtained from the communication data based on an association analysis result, each piece of the obtained threat data is mapped to a corresponding APT attack phase based on a kill chain model; and for each piece of the threat data, prevention is performed for a network entity associated with the piece of the threat data based on prevention strategies corresponding to the plurality of APT attack phases.