Kill Chain Identification via Attack Path Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-security systems struggle to detect multi-stage attacks that deviate from predefined attack paths, leading to undetected breaches even when most stages are present and detectable.

Innovation Solution

A computer-implemented security method that defines sequences of attack tactics, associates detection rules with attack techniques, correlates detected events with tactics, links events based on criteria, and identifies paths of attack techniques to detect and mitigate high-risk kill chains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If predefined attack paths are used for detection, then detection coverage for known attack patterns is improved, but detection capability for novel or deviating attack paths deteriorates

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection capability for novel attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection approach by switching between template-based detection for known attack paths and anomaly-based detection for novel patterns. The detection mechanism evolves based on observed attack behaviors, allowing it to maintain high reliability for known threats while developing adaptability for new attack vectors through continuous learning and adjustment.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes detection parameters based on the context and observed attack patterns. By adjusting detection sensitivity, threshold values, and matching criteria dynamically, the system can effectively detect both predefined attack paths and novel variations, resolving the contradiction between reliable detection of known patterns and adaptability to new attacks.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple attack paths are monitored, then detection comprehensiveness is improved, but system complexity increases

Engineering Contradiction:
Improvedetection comprehensivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the complex detection task into manageable components: template-based detection modules for known attack paths, anomaly detection modules for novel patterns, and correlation modules for linking events. This segmentation allows comprehensive monitoring of multiple attack paths while maintaining manageable system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs a universal detection framework that can handle multiple attack path types through a single integrated platform. The same system performs both template-based detection for known attacks and anomaly-based detection for novel attacks, eliminating the need for separate specialized systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If attack detection rules are highly specific, then detection precision for known techniques is improved, but ability to detect variations and generalise deteriorates

Engineering Contradiction:
Improvedetection precisionVSAvoidgeneralisation capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system applies local quality by using highly specific detection rules for known attack techniques where precision is critical, while employing more general anomaly detection mechanisms for novel patterns. This localized approach allows the system to maintain high precision for known threats while preserving the ability to detect variations and generalise to new attack methods.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The detection rules dynamically adjust their specificity based on the context. For known attack paths, specific rules provide high precision detection. For novel or ambiguous patterns, the system transitions to more general anomaly detection, allowing it to detect variations and adapt to new techniques while maintaining overall detection precision where applicable.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250190553A1Security method for identifying kill chains
Publication Date: 2025.06.12 BRITISH TELECOM PLC
  • US20250190553A1 patent drawing
  • US20250190553A1 patent drawing
  • US20250190553A1 patent drawing

AI summary

A computer implemented security method security method is described, for detecting attacks on a system or network. The method comprises defining a sequence of attack tactics, each attack tactic representing a generalisation of a set of attack techniques, associating one or more attack detection rules with each of the attack techniques, detecting attack events based on the attack detection rules, correlating the detected attack events with the attack tactics based on the attack technique associated with the attack detection rule used to detect the attack events, linking the detected attack events based on one or more criteria, and identifying one or more paths of attack techniques through the sequence in dependence on the linked attack events. The identified paths of attack techniques represent kill chains. The present technique makes it possible to identify new kill chains of known techniques, as well as making it possible to identify high-risk kill chains.