Asset Overlay Mapping for Cyber Attack Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing incident response management approaches fail to promptly identify and protect related assets during a cyber attack, leading to delayed action and increased difficulty in stopping information leaks, as they do not effectively connect low-level attack progression with high-level enterprise processes and often require manual processing by a small team of CIR staff.

Innovation Solution

The implementation of asset overlay mapping techniques that determine relationships between assets across multiple systems within an organization, allowing for automatic identification of vulnerable systems and immediate action to prohibit access, thereby preventing further breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If existing incident response approaches are used to gather and filter security events, then the number of events needing manual examination is reduced, but a considerable number of events still require manual processing by CIR staff

Engineering Contradiction:
Improveevent processing efficiencyVSAvoidtime for manual event examination
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent introduces an intermediary system that correlates security events with asset relationships and business processes. This intermediary automatically identifies which systems are vulnerable based on asset mappings, filtering events before they reach CIR staff and significantly reducing manual processing requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing event correlation, asset relationship analysis, and vulnerable system identification without requiring CIR staff intervention. The automated prohibition of access to vulnerable systems further reduces the need for manual response actions.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If CIR personnel examine and analyze information after an event has occurred, then historical evidence can be evaluated, but data loss has already occurred and stopping information leaks becomes difficult

Engineering Contradiction:
Improveattack detection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-establishing asset relationships and mappings across the enterprise before attacks occur. When security events are detected, the system immediately correlates them with pre-defined asset relationships to identify vulnerable systems, enabling rapid response before data loss occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes feedback loops where security events trigger automatic correlation with asset relationships, which then feeds back to identify vulnerable systems and trigger automated protective actions. This continuous feedback mechanism enables real-time response rather than post-event analysis.

Inventive Principle:
Principle #23Feedback

3Reliability

If asset overlay mapping is implemented to identify relationships between assets across multiple systems, then vulnerable systems can be automatically identified and protected, but the complexity of the system increases

Engineering Contradiction:
Improvebreach response effectivenessVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex task of breach response into distinct components: asset relationship mapping, event correlation, vulnerable system identification, and automated protective actions. This segmentation makes the system more manageable and easier to implement despite the increased functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The asset overlay mapping system serves multiple functions: it maps asset relationships, correlates security events, identifies vulnerable systems, and triggers automated responses. This multi-functionality reduces the need for separate systems and tools, managing overall complexity while improving reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If manual processing of security events is performed by a small team of CIR staff, then detailed analysis can be conducted, but the team cannot keep up with the significant number of security events and alerts

Engineering Contradiction:
Improveevent analysis depthVSAvoidevent processing volume
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an intermediary automated system that performs initial event correlation and filtering, reducing the volume of events that require manual analysis by CIR staff. This intermediary preserves the depth of manual analysis for critical events while increasing overall processing volume.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs partial automation by automatically handling event correlation, asset relationship analysis, and vulnerable system identification, while leaving detailed analysis and decision-making to human staff. This partial action approach increases productivity without completely replacing human expertise.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9392013B1Defending against a cyber attack via asset overlay mapping
Publication Date: 2016.07.12 DELL EMC
  • US9392013B1 patent drawing
  • US9392013B1 patent drawing
  • US9392013B1 patent drawing

AI summary

Methods, apparatus and articles of manufacture for defending against a cyber attack via asset overlay mapping are provided herein. A method includes determining which of multiple systems within an organization stores each of multiple assets; determining a set of relationships present between the multiple assets across the multiple systems; identifying, upon an attack of a first of the multiple systems, one or more additional systems of the multiple systems vulnerable to the attack based on at least one relationship, from the determined set of relationships, between one or more of the multiple assets stored on the first system and one or more of the multiple assets stored on the additional systems; and automatically prohibiting access to the one or more additional systems storing the one or more of the multiple assets identified based on the at least one relationship with the assets stored on the first system.