Semantic Model for Vulnerability Attack Chain Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Defenders lack a concrete approach to prioritize and manage vulnerabilities (CVEs) in the context of attack chains due to the difficulty in classifying them into an attack chain taxonomy, leading to manual efforts that expose networks to potential threats.

Innovation Solution

A semantic model is used to parse textual descriptions of vulnerabilities and map them to stages of an attack chain taxonomy, generating labels based on context and distance functions to determine intrusion techniques, enabling automated vulnerability characterization and prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual classification of vulnerabilities into attack chain taxonomy is performed, then vulnerability prioritization accuracy is improved, but time consumption and labor cost increase significantly

Engineering Contradiction:
Improvevulnerability prioritization accuracyVSAvoidclassification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical classification process with an automated semantic model that uses natural language processing to map vulnerability descriptions to attack chain taxonomy stages. The semantic model parses vulnerability text, extracts features, and automatically determines the appropriate attack stage without human intervention, thereby eliminating time loss while maintaining classification accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The semantic model enables the vulnerability classification system to serve itself by automatically processing vulnerability descriptions and assigning taxonomy labels without requiring manual analyst input. The system uses pre-trained semantic understanding capabilities to autonomously perform the classification task that previously required human experts.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive vulnerability analysis is performed to understand attacker actions, then risk assessment quality is improved, but processing complexity increases

Engineering Contradiction:
Improverisk assessment qualityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability analysis process into distinct components: text parsing, feature extraction, semantic labeling, and taxonomy mapping. By dividing the comprehensive analysis into modular stages, the system maintains high risk assessment quality while reducing overall processing complexity through structured, step-wise evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The semantic model acts as an intermediary layer between raw vulnerability descriptions and the attack chain taxonomy. It translates unstructured vulnerability text into structured semantic labels that map to taxonomy stages, simplifying the connection between detailed vulnerability analysis and high-level risk assessment without losing critical information.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If automated semantic modeling is implemented for vulnerability mapping, then processing efficiency is improved, but model complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidmodel complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The semantic model is pre-trained on extensive vulnerability data and attack chain taxonomy before deployment. This preliminary training phase enables the model to automatically understand and map vulnerability descriptions to attack stages without requiring complex runtime processing, thereby achieving high processing efficiency while the model complexity is contained during the training phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11729198B2Mapping a vulnerability to a stage of an attack chain taxonomy
Publication Date: 2023.08.15 TENABLE INC
  • US11729198B2 patent drawing
  • US11729198B2 patent drawing
  • US11729198B2 patent drawing

AI summary

In an embodiment, a semantic model and a semantic model training method that obtains a textual description of one or more features associated with a first vulnerability that has been used in one or more attacks. Text is parsed from the first textual description in accordance with one or more rules. The system determines a first label for the first vulnerability that is associated with one or more of a plurality of stages of an attack chain taxonomy. The model is generated or refined to map the parsed text to the first label associated with the one or more stages of the attack chain taxonomy.