Attack Scenario Construction Using Alerts and Behavioral Anomalies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyberattack detection methods struggle with 'zero-day' attacks due to lack of known signatures and rely heavily on statistical data, leading to inefficiencies and high false positive rates.
Innovation Solution
A hybrid method that constructs computer attack scenarios by integrating known attack signatures with behavioral analysis, using a system comprising an acquisition, processing, and output module to automatically adapt generic scenarios to a target environment, associating behavioral anomalies with observable variables.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual methods are used to construct attack scenarios, then security experts can create detailed scenarios, but the process is time-consuming and difficult to scale
Solution Approach 1:
The patent replaces the manual mechanical process of security experts constructing attack scenarios with an automated computer-based system. The system uses processors to automatically generate attack scenarios by ingesting network data, asset information, and vulnerability data, eliminating the time-consuming manual effort while maintaining scenario detail and accuracy through structured data processing and automated logic.
2Reliability
If more security assets and vulnerabilities are monitored, then detection capability improves, but data complexity and processing difficulty increase
Solution Approach 1:
The patent segments the complex security data processing into distinct modular components: an ingestion component that collects data from multiple sources, an attack scenario construction component that processes the data, and a reporting component that delivers results. This segmentation allows the system to handle diverse security assets and vulnerabilities systematically, improving detection capability while managing data complexity through organized processing stages.
Solution Approach 2:
The patent introduces attack scenario templates as intermediary structures that mediate between raw security data and final detection results. These templates provide a standardized framework for processing vulnerability and asset data, transforming complex unstructured information into organized attack scenarios that improve detection reliability without proportionally increasing processing complexity.
3Measurement precision
If comprehensive network data is collected from multiple sources, then scenario accuracy improves, but data ingestion complexity increases
Solution Approach 1:
The patent implements a universal data ingestion component capable of collecting information from multiple diverse sources including network devices, vulnerability scanners, and asset management systems. This multi-functional component uses standardized data formats and protocols to handle different data types uniformly, enabling comprehensive data collection for accurate attack scenarios while managing ingestion complexity through a consolidated approach.
Data Source
Figure 1~2
Figure 3
AI summary
This method comprises a preliminary step (101) of acquiring a first dataset comprising a plurality of generic scenarios, a second dataset comprising a plurality of events occurring in the target environment and a third dataset comprising a plurality of alerts. The method further comprises a first step (110) of determining a generic scenario, termed the partial generic scenario, and an alert such that the elementary attack causing this alert corresponds to one or more actions of the partial generic scenario, a second step (120) of determining a plurality of anomalies, each anomaly corresponding to an abnormal event, and a third step (130) of associating, with at least one of the observable variables of the partial generic scenario, the observable value or one of the observable values of one of the determined anomalies.