Asset Remediation Trend Map for Attack Campaign Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The computer security industry faces challenges in leveraging information from security reports and data across multiple security products, leading to a lack of holistic views of attack campaigns and inadequate remediation strategies, particularly for weakly protected assets, due to the isolation of security logs and the absence of an automated end-to-end validation and remediation cycle.

Innovation Solution

A method for generating an asset remediation trend map by parsing attack kill chain data to determine remediation operations, sequencing them, and creating a visual representation to indicate steps for remediating attack campaigns, which includes quantifying successful attack execution operations based on criteria like vulnerability assessments and remediation types, and using a repository like the MITRE ATT&CK framework to map attack events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If security logs from multiple security products are used in isolation, then each security product can independently detect and report threats, but a holistic view of attack campaigns cannot be achieved

Engineering Contradiction:
Improveholistic view of attack campaignsVSAvoidintegration of multiple security products
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent merges security logs from multiple diverse security products into a unified security report that provides a holistic view of attack campaigns. The system correlates data from antivirus, web application firewalls, intrusion prevention systems, and other security products to create an integrated representation of attack scenarios, enabling comprehensive threat analysis rather than isolated product views.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an intermediary processing layer that receives logs from multiple security products, correlates them using attack kill chain frameworks, and generates unified security reports. This intermediary system bridges the gap between isolated security product outputs and holistic attack campaign understanding, enabling correlated analysis without requiring direct integration between all security products.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users focus only on highly severe vulnerabilities, then critical threats can be addressed promptly, but weakly protected assets remain vulnerable to attack campaigns

Engineering Contradiction:
Improveprotection of critical assetsVSAvoidvulnerability of weakly protected assets
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the attack campaign into discrete steps using attack kill chain frameworks, allowing users to identify and remediate vulnerabilities at each stage. By breaking down the attack progression into individual operations (reconnaissance, weaponization, delivery, exploitation, etc.), the system enables targeted remediation of both severe and weakly protected assets based on their specific role in the attack chain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables preliminary identification of weakly protected assets by analyzing the complete attack kill chain sequence. By understanding the full progression of attack operations, the system can proactively identify and flag assets that are weakly protected at various stages of the attack chain, allowing users to remediate these vulnerabilities before they are exploited in a coordinated attack campaign.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If automated end-to-end validation and remediation cycles are not implemented, then security controls can be deployed, but feedback loops for continuous improvement are missing

Engineering Contradiction:
Improvemanual security remediation processVSAvoidsecurity optimization efficiency
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The patent implements automated feedback loops that track the effectiveness of remediation operations by monitoring subsequent security events and attack patterns. The system continuously validates whether remediation actions successfully mitigated identified threats and uses this feedback to optimize security controls and remediation strategies over time, creating a closed-loop security improvement cycle.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent enables self-service automated remediation operations that can independently execute security hardening, patch deployment, and configuration changes based on identified vulnerabilities and attack patterns. The system autonomously performs remediation actions and validates their effectiveness, reducing manual intervention while improving security response productivity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11777961B2Asset remediation trend map generation and utilization for threat mitigation
Publication Date: 2023.10.03 QUALYS
  • US11777961B2 patent drawing
  • US11777961B2 patent drawing
  • US11777961B2 patent drawing

AI summary

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.