Asset-Based Security System for Zero-Day Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions are ineffective in breaking the penetration-patch cycle, as they rely on constant updates and are not proactive in preventing zero-day ransomware attacks, which are costly and damaging, and are based on attacker-provided information rather than defender-owned assets.

Innovation Solution

An asset-based security system that monitors critical assets for security requirement violations, generates a reachability graph, and maps security requirements to system calls to prevent violations, operating independently of attack vectors and behaviors, thus providing a proactive and passive defense mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security solutions are used that rely on constant patches and updates, then security coverage can be maintained for known threats, but the system cannot effectively prevent zero-day attacks and requires continuous manual intervention

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidtime for patches and updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by generating a reachability graph during an information collection phase that maps all possible attack paths to critical assets before any attack occurs. This pre-computed security model enables the system to detect and prevent zero-day attacks without requiring post-exploit patches or updates, as the defense mechanism is already in place anticipating potential threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security system serves itself by automatically monitoring its own critical assets and detecting violations of security requirements without external intervention. The system continuously compares actual system state against the pre-generated reachability graph, enabling autonomous detection and prevention of attacks without requiring manual patching or security team involvement for each threat.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If security systems are based on attacker-provided information (attack vectors, behaviors), then detection of known attack patterns is improved, but the system remains reactive and cannot prevent novel zero-day attacks

Engineering Contradiction:
Improveattack detection accuracyVSAvoidability to handle new attack types
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system inverts the traditional security approach by switching from attacker-centric monitoring (tracking attack vectors and behaviors) to defender-centric asset protection (monitoring critical assets and their security requirements). By generating a reachability graph that maps all possible paths to assets from the defender's perspective, the system can detect any violation regardless of the attack type or vector, making it equally effective against both known and zero-day attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If continuous monitoring and patching is performed to maintain security, then protection against known threats is improved, but the cost and complexity of the security system increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs the complex task of security analysis in advance during an information collection phase, generating a complete reachability graph that maps all possible attack paths to critical assets. This pre-computed model simplifies ongoing security operations, as the system only needs to compare actual system state against the pre-generated graph rather than performing complex real-time analysis, thereby reducing operational complexity while maintaining high security protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11347843B2Asset-based security systems and methods
Publication Date: 2022.05.31 KING FAHD UNIVERSITY OF PETROLEUM AND MINERALS
  • US11347843B2 patent drawing
  • US11347843B2 patent drawing
  • US11347843B2 patent drawing

AI summary

Methods, systems, and computer readable media for asset-based security are described. Some implementations relate to a system for asset-based detection of zero-day attacks or other attacks. The system can monitor critical assets for a violation of one or more security requirements and raise an alarm when a violation of one or more of the critical assets is detected. Further, the system can perform an information collection phase in which (a) information about the critical assets corresponding to the one or more security requirement are captured, and (b) generating a reachability graph representing one or more interrelationships between one or more of the critical assets and one or more other objects in the system.