Automated Security Rule Generation via Attack Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security operations in SOC and CSIRT rely heavily on analyst experience and knowledge, leading to inaccuracies and difficulties in generating practical rules for expert systems, as existing methods require manual creation by operators.

Innovation Solution

A rule generation apparatus and method that collect environment and attack information from a simulation system to automatically generate attack success and failure conditions, history information, and subsequently create rules for security operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rules are created manually by operators to support security operations, then the rules can be tailored to specific security needs, but the process becomes time-consuming and difficult to scale

Engineering Contradiction:
Improveaccuracy of security operationsVSAvoidtime to generate rules
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system automatically generates security rules by having the simulation system execute attacks and collect results, then the rule generation unit autonomously creates rules from this data without requiring manual operator intervention for rule creation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The simulation system pre-executes various attack scenarios and collects attack information, environment information, and history information before rule generation, so that when rules are needed, the data is already prepared and ready for automatic rule creation

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If security operations rely on analyst experience and knowledge, then operations can be performed with available human expertise, but the accuracy is limited by individual analyst capabilities

Engineering Contradiction:
Improveoperation based on human expertiseVSAvoidaccuracy of security operations
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system replaces the mechanical process of manual rule creation by operators with an automated information processing system that collects attack data, analyzes it, and generates rules algorithmically, substituting human manual work with automated computational processes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The simulation system acts as an intermediary between actual security operations and rule generation, providing a controlled environment to collect attack information and history information that feeds into the rule generation process, mediating between real-world security needs and automated rule creation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If manual rule creation is used in expert systems, then rules can be customized for specific security contexts, but it becomes difficult to generate practical rules at scale

Engineering Contradiction:
Improvecustomization of rulesVSAvoiddifficulty to generate rules
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The simulation system autonomously executes attack scenarios, collects results, and provides data to the rule generation unit without manual intervention, making the rule manufacturing process self-serving and automated rather than requiring operators to manually create each rule

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12050694B2Rule generation apparatus, rule generation method, and computer-readable recording medium
Publication Date: 2024.07.30 NEC CORP
  • US12050694B2 patent drawing
  • US12050694B2 patent drawing
  • US12050694B2 patent drawing

AI summary

A rule generation apparatus 100 is an apparatus that automatically generates rules used to analyze an attack, and includes a collection unit 200, an attack success condition generation unit 300, an attack-time history generation unit 400, and a rule generation unit 500.