Automated Security Rule Generation via Attack Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security operations in SOC and CSIRT rely heavily on analyst experience and knowledge, leading to inaccuracies and difficulties in generating practical rules for expert systems, as existing methods require manual creation by operators.
Innovation Solution
A rule generation apparatus and method that collect environment and attack information from a simulation system to automatically generate attack success and failure conditions, history information, and subsequently create rules for security operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rules are created manually by operators to support security operations, then the rules can be tailored to specific security needs, but the process becomes time-consuming and difficult to scale
Solution Approach 1:
The system automatically generates security rules by having the simulation system execute attacks and collect results, then the rule generation unit autonomously creates rules from this data without requiring manual operator intervention for rule creation
Solution Approach 2:
The simulation system pre-executes various attack scenarios and collects attack information, environment information, and history information before rule generation, so that when rules are needed, the data is already prepared and ready for automatic rule creation
2Ease of operation
If security operations rely on analyst experience and knowledge, then operations can be performed with available human expertise, but the accuracy is limited by individual analyst capabilities
Solution Approach 1:
The system replaces the mechanical process of manual rule creation by operators with an automated information processing system that collects attack data, analyzes it, and generates rules algorithmically, substituting human manual work with automated computational processes
Solution Approach 2:
The simulation system acts as an intermediary between actual security operations and rule generation, providing a controlled environment to collect attack information and history information that feeds into the rule generation process, mediating between real-world security needs and automated rule creation
3Adaptability or versatility
If manual rule creation is used in expert systems, then rules can be customized for specific security contexts, but it becomes difficult to generate practical rules at scale
Solution Approach 1:
The simulation system autonomously executes attack scenarios, collects results, and provides data to the rule generation unit without manual intervention, making the rule manufacturing process self-serving and automated rather than requiring operators to manually create each rule
Data Source
AI summary
A rule generation apparatus 100 is an apparatus that automatically generates rules used to analyze an attack, and includes a collection unit 200, an attack success condition generation unit 300, an attack-time history generation unit 400, and a rule generation unit 500.


