Knowledge Graph Mapping for Cybersecurity Gap Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cybersecurity frameworks struggle to identify and prioritize gaps in detection and prevention measures due to evolving threat landscapes and complex network environments, making it challenging to effectively mitigate and resolve cyber threats.
Innovation Solution
A knowledge graph schema is used to encode and map prevention and detection measures with a cybersecurity framework, enabling automated identification and prioritization of security gaps by correlating tactics, techniques, and sub-techniques, and predicting malicious actor behavior.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network security frameworks are used to understand and categorize adversary TTPs, then the ability to evaluate defensive capabilities is improved, but the ability to identify gaps in security measures deteriorates
Solution Approach 1:
The patent introduces an automated analysis system that acts as an intermediary between the network security framework and the evaluation process. This system automatically maps adversary TTPs to security controls, identifies gaps, and generates prioritized recommendations, thereby resolving the contradiction by enabling both precise evaluation and effective gap identification through automation
2Difficulty of detecting and measuring
If manual investigations of cybersecurity incidents are conducted, then detection capability is improved, but consistency and adequacy of investigations deteriorate when scaled
Solution Approach 1:
The system enables self-service automated investigation by automatically analyzing security incidents, mapping them to the network security framework, identifying relevant security controls, and generating gap analysis reports without requiring manual intervention. This maintains high detection capability while ensuring consistent and adequate investigations through standardized automated processes
Solution Approach 2:
The patent transforms the investigation process from manual to automated by changing key parameters including analysis speed, consistency, and scalability. The automated system processes incidents systematically with uniform application of the security framework, ensuring reliable and consistent results across all investigations regardless of volume
3Adaptability or versatility
If the cybersecurity framework is expanded to cover more tactics and techniques, then coverage of threat landscape is improved, but complexity of identifying and prioritizing gaps deteriorates
Solution Approach 1:
The system dynamically adapts to the expanding cybersecurity framework by automatically adjusting its analysis parameters, mapping relationships, and prioritization algorithms. As new tactics and techniques are added to the framework, the system automatically incorporates them into its gap analysis without requiring manual reconfiguration, thereby maintaining versatility while managing complexity through dynamic automation
Data Source
AI summary
Disclosed are systems for detecting gaps in security measures performed in a network security environment. A system can: receive prevention data from a prevention system that generates and provides prevention measures to a third party system in a network security environment to prevent potential vulnerabilities, receive detection data from a detection system that generates and provides detection measures to the third party system to block the potential vulnerabilities, receive a framework taxonomy that includes relationships between vulnerabilities, tactics, techniques, and sub-techniques, and generate a knowledge graph based on mapping the prevention data, the detection data, and the tactics, techniques, and sub-techniques of the framework taxonomy. The system can also traverse the knowledge graph, iteratively detect gaps in the prevention measures or the detection measures based on traversing the knowledge graph, and return information about the detected gaps.


