Domain-Specific Language for Threat Defense

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methodologies for threat analysis and mitigation lack a formal language based on information sources like the attack classification and risk assessment framework, and are not domain-specific, making them vulnerable to threat-actor infiltration and exploitation.

Innovation Solution

A method for generating a domain-specific language (DSL) file that defends against attack execution operations by determining a framework based on an attack repository, creating primitives that describe attack execution operations and defense measures, and combining these into a DSL file executable within a specific domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing threat analysis methodologies are used, then threat analysis can be performed, but they lack domain-specificity and are vulnerable to threat-actor infiltration

Engineering Contradiction:
Improvesecurity defense effectivenessVSAvoiddomain-specificity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates domain-specific language files that are tailored to particular domains (e.g., mobile, enterprise, cloud). Each DSL file contains domain-specific primitives and defense steps that are locally optimized for that domain's characteristics, making the defense both reliable and adaptably domain-specific.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments threat analysis into discrete, structured components including attack execution operations, primitives with identifiers and descriptors, and defense steps. This segmentation allows the system to be both reliable (through systematic coverage) and adaptable (through domain-specific customization).

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If general-purpose security systems are used, then broad coverage is achieved, but they can be maliciously used by threat-actors outside intended domains

Engineering Contradiction:
Improvebroad coverageVSAvoidthreat-actor exploitation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

By making security systems domain-specific through DSL files, the patent ensures that each system is optimized for its intended domain while being unusable outside that domain. This prevents threat-actors from exploiting general-purpose systems in unintended contexts while maintaining broad coverage across multiple domains through separate DSL files.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If formal language based on attack framework is implemented, then threat modeling precision is improved, but system complexity increases

Engineering Contradiction:
Improvethreat modeling precisionVSAvoidlanguage specification complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the formal language into structured primitives with specific descriptors (attack type, vulnerability type, stability parameter, intensity data) and organized defense steps. This segmentation makes the complex formal language manageable and implementable while maintaining high threat modeling precision.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12301625B2Domain specific language for defending against a threat-actor and adversarial tactics, techniques, and procedures
Publication Date: 2025.05.13 QUALYS
  • US12301625B2 patent drawing
  • US12301625B2 patent drawing
  • US12301625B2 patent drawing

AI summary

The present disclosure describes defending against an attack execution operation. According to one aspect of the subject matter described in this disclosure, a method for generating a domain-specific language (DSL) file is disclosed. The method may comprise determining, a framework based on an attack repository, determining a first primitive based on the framework, and determining a second primitive based on the framework. In one implementation, the first primitive and the second primitive are fundamental structures or constructs within a DSL. The method further comprises combining the first primitive and the second primitive into a DSL file. In one implementation, the DSL file is executed to defend against a first attack execution operation executed by a threat-actor.