Multi-Engine Attack Chain Following for Automated Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IT environments face inefficiencies and inconsistencies in analyzing security threats, particularly due to the time-consuming and ad hoc nature of manual threat analysis processes, which can lead to improper or missed threat detection, especially with evolving and sophisticated attack methods.

Innovation Solution

A software-based threat analysis platform with dedicated engines that automate various security analysis actions, including navigating URLs, analyzing documents and files, and emulating embedded code, while integrating with external services for enhanced threat detection and providing intuitive results display.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual threat analysis processes are used, then security analysts can investigate threats, but the process is time-consuming and inconsistent leading to improper or missed threat detection

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidthreat analysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The threat analysis process is segmented into distinct automated components including URL analysis, file analysis, macro emulation, and attack chain following. Each component handles specific aspects of threat investigation, enabling parallel processing and eliminating manual bottlenecks while maintaining comprehensive detection coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An automated threat analysis platform serves as an intermediary between detected threats and security analysts. The platform orchestrates multiple analysis engines, manages artifact collection, and presents consolidated results, replacing manual coordination while improving consistency and reducing analysis time

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automated analysis engines are deployed, then threat analysis efficiency improves, but the system complexity increases

Engineering Contradiction:
Improvethreat analysis productivityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The threat analysis platform is designed as a universal system that handles multiple threat types (URLs, files, macros, attack chains) through a single integrated architecture. The standardized engine interface and unified artifact management enable the system to process diverse threats without requiring separate manual procedures for each threat category

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system employs a nested architecture where specialized analysis engines (URL analyzer, file analyzer, macro emulator) are contained within the broader threat analysis platform. Each engine focuses on specific threat aspects while the orchestrating platform provides comprehensive coordination, allowing modular complexity management

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12417286B2Automated attack chain following by a threat analysis platform
Publication Date: 2025.09.16 CISCO TECHNOLOGY INC
  • US12417286B2 patent drawing
  • US12417286B2 patent drawing
  • US12417286B2 patent drawing

AI summary

Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.