Attack Scenario Construction Using Alerts and Behavioral Anomalies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyberattack detection methods struggle with 'zero-day' attacks due to lack of known signatures and rely heavily on statistical data, leading to inefficiencies and high false positive rates.

Innovation Solution

A hybrid method that constructs computer attack scenarios by integrating known attack signatures with behavioral analysis, using a system comprising an acquisition, processing, and output module to automatically adapt generic scenarios to a target environment, associating behavioral anomalies with observable variables.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual methods are used to construct attack scenarios, then security experts can create detailed scenarios, but the process is time-consuming and difficult to scale

Engineering Contradiction:
Improveattack scenario detail accuracyVSAvoidscenario construction time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical process of security experts constructing attack scenarios with an automated computer-based system. The system uses processors to automatically generate attack scenarios by ingesting network data, asset information, and vulnerability data, eliminating the time-consuming manual effort while maintaining scenario detail and accuracy through structured data processing and automated logic.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If more security assets and vulnerabilities are monitored, then detection capability improves, but data complexity and processing difficulty increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddata processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex security data processing into distinct modular components: an ingestion component that collects data from multiple sources, an attack scenario construction component that processes the data, and a reporting component that delivers results. This segmentation allows the system to handle diverse security assets and vulnerabilities systematically, improving detection capability while managing data complexity through organized processing stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces attack scenario templates as intermediary structures that mediate between raw security data and final detection results. These templates provide a standardized framework for processing vulnerability and asset data, transforming complex unstructured information into organized attack scenarios that improve detection reliability without proportionally increasing processing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive network data is collected from multiple sources, then scenario accuracy improves, but data ingestion complexity increases

Engineering Contradiction:
Improveattack scenario accuracyVSAvoiddata ingestion complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal data ingestion component capable of collecting information from multiple diverse sources including network devices, vulnerability scanners, and asset management systems. This multi-functional component uses standardized data formats and protocols to handle different data types uniformly, enabling comprehensive data collection for accurate attack scenarios while managing ingestion complexity through a consolidated approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3729768B1Method for automatically constructing computer attack scenarios, computer program product and associated construction system
Publication Date: 2026.04.29 THALES SA
  • EP3729768B1 patent drawingFigure 1~2
  • EP3729768B1 patent drawingFigure 3
  • EP3729768B1 patent drawing

AI summary

This method comprises a preliminary step (101) of acquiring a first dataset comprising a plurality of generic scenarios, a second dataset comprising a plurality of events occurring in the target environment and a third dataset comprising a plurality of alerts. The method further comprises a first step (110) of determining a generic scenario, termed the partial generic scenario, and an alert such that the elementary attack causing this alert corresponds to one or more actions of the partial generic scenario, a second step (120) of determining a plurality of anomalies, each anomaly corresponding to an abnormal event, and a third step (130) of associating, with at least one of the observable variables of the partial generic scenario, the observable value or one of the observable values of one of the determined anomalies.