Kill Chain Identification via Attack Path Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber-security systems struggle to detect multi-stage attacks that deviate from predefined attack paths, leading to undetected breaches even when most stages are present and detectable.
Innovation Solution
A computer-implemented security method that defines sequences of attack tactics, associates detection rules with attack techniques, correlates detected events with tactics, links events based on criteria, and identifies paths of attack techniques to detect and mitigate high-risk kill chains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If predefined attack paths are used for detection, then detection coverage for known attack patterns is improved, but detection capability for novel or deviating attack paths deteriorates
Solution Approach 1:
The system dynamically adapts its detection approach by switching between template-based detection for known attack paths and anomaly-based detection for novel patterns. The detection mechanism evolves based on observed attack behaviors, allowing it to maintain high reliability for known threats while developing adaptability for new attack vectors through continuous learning and adjustment.
Solution Approach 2:
The system changes detection parameters based on the context and observed attack patterns. By adjusting detection sensitivity, threshold values, and matching criteria dynamically, the system can effectively detect both predefined attack paths and novel variations, resolving the contradiction between reliable detection of known patterns and adaptability to new attacks.
2Reliability
If multiple attack paths are monitored, then detection comprehensiveness is improved, but system complexity increases
Solution Approach 1:
The system segments the complex detection task into manageable components: template-based detection modules for known attack paths, anomaly detection modules for novel patterns, and correlation modules for linking events. This segmentation allows comprehensive monitoring of multiple attack paths while maintaining manageable system complexity through modular architecture.
Solution Approach 2:
The system employs a universal detection framework that can handle multiple attack path types through a single integrated platform. The same system performs both template-based detection for known attacks and anomaly-based detection for novel attacks, eliminating the need for separate specialized systems and reducing overall complexity.
3Measurement precision
If attack detection rules are highly specific, then detection precision for known techniques is improved, but ability to detect variations and generalise deteriorates
Solution Approach 1:
The system applies local quality by using highly specific detection rules for known attack techniques where precision is critical, while employing more general anomaly detection mechanisms for novel patterns. This localized approach allows the system to maintain high precision for known threats while preserving the ability to detect variations and generalise to new attack methods.
Solution Approach 2:
The detection rules dynamically adjust their specificity based on the context. For known attack paths, specific rules provide high precision detection. For novel or ambiguous patterns, the system transitions to more general anomaly detection, allowing it to detect variations and adapt to new techniques while maintaining overall detection precision where applicable.
Data Source
AI summary
A computer implemented security method security method is described, for detecting attacks on a system or network. The method comprises defining a sequence of attack tactics, each attack tactic representing a generalisation of a set of attack techniques, associating one or more attack detection rules with each of the attack techniques, detecting attack events based on the attack detection rules, correlating the detected attack events with the attack tactics based on the attack technique associated with the attack detection rule used to detect the attack events, linking the detected attack events based on one or more criteria, and identifying one or more paths of attack techniques through the sequence in dependence on the linked attack events. The identified paths of attack techniques represent kill chains. The present technique makes it possible to identify new kill chains of known techniques, as well as making it possible to identify high-risk kill chains.


