Cyber Attribution Confidence Analysis Using Multi-Stage Indicator Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyber threat attribution for Advanced Persistent Threats (APTs) is challenging due to constantly changing indicators such as hash values, IP addresses, and domains, making it difficult to determine attribution confidence levels and identify information gaps.

Innovation Solution

A system and method for analyzing campaign intrusion set data to extract key indicators, compare them with activity group data, and determine attribution confidence levels using a multi-stage comparison process, while identifying gaps for higher confidence attribution and assisting in threat hunting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional cyber threat attribution methods are used, then attribution can be made quickly, but the confidence level is low due to constantly changing indicators

Engineering Contradiction:
Improveattribution confidence levelVSAvoidattribution time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting and analyzing multiple types of data (intrusion set data, activity group data, indicator data) before making attribution determinations. The multi-stage comparison process systematically evaluates evidence in advance, building a confidence level before final attribution is made, thereby improving measurement precision without excessive time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attribution process is segmented into multiple stages: collecting intrusion set data, collecting activity group data, extracting indicators, comparing indicators, and determining confidence levels. This segmentation allows systematic evaluation of different evidence types independently, improving overall attribution confidence while managing time through structured progression.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If multiple indicators are analyzed to improve attribution accuracy, then confidence level increases, but the complexity of the analysis process increases

Engineering Contradiction:
Improveattribution confidence levelVSAvoidanalysis process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The complex analysis process is segmented into distinct stages: data collection, indicator extraction, comparison, and confidence determination. Each stage handles specific tasks independently, making the overall complex process more manageable and systematic while maintaining high attribution confidence through comprehensive multi-indicator analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses an intermediary multi-stage comparison process that bridges the gap between raw indicator data and final attribution confidence levels. This intermediary process systematically evaluates multiple indicators (hash values, IP addresses, domains, TTPs) against activity group profiles, reducing analysis complexity while improving measurement precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive data collection is performed to fill information gaps, then attribution confidence improves, but the time and resources required increase

Engineering Contradiction:
Improveattribution confidence levelVSAvoiddata processing volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts only the key indicators and capabilities relevant to attribution from large volumes of intrusion set data and activity group data. By taking out and focusing on critical elements (TTPs, indicators, capabilities) rather than processing all available data, the system improves attribution confidence while managing data processing volume efficiently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary data collection and organization, structuring intrusion set data and activity group data before comparison. This preliminary action prepares the data in advance, allowing efficient processing during the comparison stage and reducing the effective data volume that requires intensive analysis, thereby improving confidence levels without excessive resource consumption.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11343264B2System and method for determining the confidence level in attributing a cyber campaign to an activity group
Publication Date: 2022.05.24 WARIKOO ARUN
  • US11343264B2 patent drawing
  • US11343264B2 patent drawing
  • US11343264B2 patent drawing

AI summary

A system and method is provided for determining the confidence level in attributing a cyber campaign to an activity group. The system and method allows for determining information gaps that need to be filled in order to perform attribution with higher degree of confidence. The system and method is able to extract quantitative data from the campaign intrusion set data and perform a multi-stage analysis and comparison with quantitative data extracted from threat intelligence feeds/platforms and/or vendor intelligence reports. This allows for identifying an activity groups that may be attributed for the campaign with the associated level of confidence.