APT Scenario Matching for Proactive Security Requirement Recommendation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack effective methods to proactively derive and apply security requirements to defend against advanced persistent threats (APT), which are complex, covert, and evolve rapidly, causing significant damage and difficulty in analysis and defense measure suggestion.

Innovation Solution

A security requirement recommendation system that analyzes an attack scenario using a case-based reasoning technique, matching it with past attack scenarios to extract relevant security requirement information, thereby recommending appropriate security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If detection-focused approaches are used to identify attack penetration, then attack detection capability is improved, but proactive defense capability deteriorates

Engineering Contradiction:
Improveattack detection capabilityVSAvoidproactive defense capability
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by analyzing attack scenarios and deriving security requirements before attacks actually penetrate the system. It uses case-based reasoning to match current attack scenarios with historical cases, proactively identifying potential threats and recommending security measures in advance, thus preventing the need to wait for detection after penetration occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the security analysis process into distinct components: attack scenario input, case matching, security requirement derivation, and recommendation generation. This segmentation allows the system to handle complex security analysis through modular processing, improving both detection precision and proactive response capability.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If comprehensive security requirement data is collected from multiple sources, then security requirement completeness is improved, but data selection complexity deteriorates

Engineering Contradiction:
Improvesecurity requirement completenessVSAvoiddata selection complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system introduces an intermediary mechanism - the case-based reasoning engine with attack scenario models - that mediates between comprehensive security requirement data and specific selection needs. This intermediary automatically matches attack scenarios with relevant security requirements, eliminating the need for manual data selection while maintaining completeness.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates simplified copies of attack scenarios and their corresponding security requirements through structured models. These models serve as reusable templates that can be quickly matched against new scenarios, reducing the complexity of selecting appropriate security requirements from comprehensive data sets.

Inventive Principle:
Principle #26Copying

3Measurement precision

If manual security requirement selection is performed by security experts, then requirement accuracy is improved, but time consumption deteriorates

Engineering Contradiction:
Improverequirement accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service by automatically performing security requirement selection through case-based reasoning. The automated system matches attack scenarios with historical cases and derives security requirements without human intervention, achieving both speed and accuracy through algorithmic analysis rather than manual expert review.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the results of case matching and security requirement derivation can be validated and refined. This feedback loop ensures that automated selections maintain high accuracy by comparing against established case outcomes and allowing for continuous improvement of the reasoning models.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12348570B2Security requirement recommendation system and operation method
Publication Date: 2025.07.01 AJOU UNIV IND ACADEMIC COOP FOUND
  • US12348570B2 patent drawing
  • US12348570B2 patent drawing
  • US12348570B2 patent drawing

AI summary

Provided is an operation method of a security requirement recommendation system including inputting an attack scenario of an advanced persistent threat (APT); and estimating a specific APT attack case similar to the attack scenario based on a case-based problem domain ontology including characteristic models of the APT attack cases, and recommending a security requirement corresponding to the specific APT attack case.