LLM Asset Attribution for EASM Threat Exposure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional External Attack Surface Management (EASM) systems face challenges in accurately identifying and attributing exposed assets to specific customers and departments due to the complexity of analyzing dynamic IP addresses and unstructured data, leading to inaccuracies and inefficiencies in flagging and addressing security threats.
Innovation Solution
The use of generative artificial intelligence, specifically large language models (LLMs), to analyze responses from the internet, generate assignments, and attribute exposed assets to topics such as business verticals, departments, and customers, enabling rapid identification and reporting of potential threats by correlating internal and external asset information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional EASM systems use traditional data analysis methods to identify exposed assets, then the system structure remains simple, but the measurement precision and reliability of asset attribution are insufficient
Solution Approach 1:
The patent introduces an intermediary classification model (based on LLM) that acts as a mediator between raw device responses and asset attribution results. This model processes unstructured device responses, extracts meaningful features, and generates structured classifications that improve attribution accuracy without requiring complex manual analysis pipelines
Solution Approach 2:
The patent replaces traditional mechanical/manual data analysis methods with an AI-based classification model. Instead of relying on manual inspection or simple rule-based systems, the system uses trained LLMs to automatically analyze device responses, extract features, and perform asset attribution, significantly improving precision while managing complexity through automation
2Productivity
If conventional EASM systems manually analyze device responses to attribute assets, then the system complexity remains low, but the productivity and speed of threat identification are reduced
Solution Approach 1:
The patent implements preliminary action by pre-training classification models on extensive device response data before deployment. The models are prepared in advance with learned features and patterns, enabling them to rapidly process and classify new device responses in real-time operations, thus improving productivity without adding operational complexity
Solution Approach 2:
The classification model performs self-service by automatically analyzing device responses, extracting features, and generating asset attributions without human intervention. The system autonomously processes threats and identifies assets, significantly improving productivity while the centralized model management keeps overall system complexity manageable
3Reliability
If conventional EASM systems use simple analysis methods, then the ease of operation is high, but the reliability and accuracy of security threat flagging are insufficient
Solution Approach 1:
The patent segments the asset attribution process into distinct functional components handled by the classification model: device response reception, feature extraction, classification prediction, and result generation. This segmentation improves reliability by ensuring each step is systematically performed, while the model manages the complexity internally, maintaining ease of operation from the user perspective
Data Source
AI summary
A system and method of using generative AI to identify exposures of computing devices on computing networks to actual and/or potential threats. The method includes collecting a plurality of responses from a plurality of devices to a target device on a private network. The method includes providing the plurality of responses to a classification model trained to assign device descriptions for device responses based on semantic matching of the device responses to database data. The method includes assigning, by the processing device using the classification model, a plurality of device descriptions for the plurality of responses to the target device, each response is respectively associated with one or more device descriptions of the plurality of device descriptions. The method includes generating, based on the plurality of device descriptions, a status report comprising a list of network addresses associated with a group of devices having access to the target device.


