Multi-Engine Attack Chain Following for Automated Threat Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing IT environments face inefficiencies and inconsistencies in analyzing security threats, particularly due to the time-consuming and ad hoc nature of manual threat analysis processes, which can lead to improper or missed threat detection, especially with evolving and sophisticated attack methods.
Innovation Solution
A software-based threat analysis platform with dedicated engines that automate various security analysis actions, including navigating URLs, analyzing documents and files, and emulating embedded code, while integrating with external services for enhanced threat detection and providing intuitive results display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual threat analysis processes are used, then security analysts can investigate threats, but the process is time-consuming and inconsistent leading to improper or missed threat detection
Solution Approach 1:
The threat analysis process is segmented into distinct automated components including URL analysis, file analysis, macro emulation, and attack chain following. Each component handles specific aspects of threat investigation, enabling parallel processing and eliminating manual bottlenecks while maintaining comprehensive detection coverage
Solution Approach 2:
An automated threat analysis platform serves as an intermediary between detected threats and security analysts. The platform orchestrates multiple analysis engines, manages artifact collection, and presents consolidated results, replacing manual coordination while improving consistency and reducing analysis time
2Productivity
If automated analysis engines are deployed, then threat analysis efficiency improves, but the system complexity increases
Solution Approach 1:
The threat analysis platform is designed as a universal system that handles multiple threat types (URLs, files, macros, attack chains) through a single integrated architecture. The standardized engine interface and unified artifact management enable the system to process diverse threats without requiring separate manual procedures for each threat category
Solution Approach 2:
The system employs a nested architecture where specialized analysis engines (URL analyzer, file analyzer, macro emulator) are contained within the broader threat analysis platform. Each engine focuses on specific threat aspects while the orchestrating platform provides comprehensive coordination, allowing modular complexity management
Data Source
AI summary
Techniques are described for providing a threat analysis platform capable of automating actions performed to analyze security-related threats affecting IT environments. Users or applications can submit objects (e.g., URLs, files, etc.) for analysis by the threat analysis platform. Once submitted, the threat analysis platform routes the objects to dedicated engines that can perform static and dynamic analysis processes to determine a likelihood that an object is associated with malicious activity such as phishing attacks, malware, or other types of security threats. The automated actions performed by the threat analysis platform can include, for example, navigating to submitted URLs and recording activity related to accessing the corresponding resource, analyzing files and documents by extracting text and metadata, extracting and emulating execution of embedded macro source code, performing optical character recognition (OCR) and other types of image analysis, submitting objects to third-party security services for analysis, among many other possible actions.


