Automated Social Media Exploit Tracking for Zero-Day Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods lack efficient and timely detection and response to security breaches resulting from unpatched software vulnerabilities, as initial exploits often go unnoticed by software vendors, leading to potential follow-up attacks.

Innovation Solution

Automated tracking of exploit information related to initially-identified security vulnerabilities through data mining of social networks, analyzing patterns to generate keywords for harvesting additional security-relevant data, and refining detection and communication of alerts to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security vulnerability detection relies on traditional methods, then software vendors may remain unaware of initial exploits, but response time to security breaches is delayed

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary monitoring and analysis of security vulnerability information before formal exploitation occurs. By establishing keyword databases and monitoring patterns in advance, the system can detect and alert about zero-day vulnerabilities and exploits before they are widely deployed, enabling software vendors to prepare remediation measures proactively rather than reactively.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops where detected exploit patterns are fed back into the monitoring system to refine keyword databases and improve detection accuracy. The system analyzes social media data, extracts exploit information, validates it against known vulnerability patterns, and uses this feedback to enhance future detection capabilities, creating a self-improving security monitoring mechanism.

Inventive Principle:
Principle #23Feedback

2Productivity

If detailed exploit information is disclosed publicly, then response time for fixing vulnerabilities is accelerated, but software vendors may not be aware of these publications

Engineering Contradiction:
Improvepatching speedVSAvoidinformation reachability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system acts as an intermediary between public exploit disclosures and software vendors. It monitors social media platforms where exploit information is publicly discussed, extracts relevant technical details, and delivers this information directly to vendors through automated alerts. This intermediary function bridges the information gap, ensuring vendors receive critical exploit details even when traditional communication channels are not utilized.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces manual information gathering and analysis mechanisms with automated computational processes. Instead of relying on vendors to manually search for or receive exploit information through traditional channels, the system uses automated web crawling, natural language processing, and pattern recognition to extract and deliver exploit information, significantly improving both speed and reliability of information delivery.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If automated tracking of security exploits is implemented, then detection speed is improved, but system complexity increases

Engineering Contradiction:
Improvedetection speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system divides the complex task of security exploit detection into distinct modular components: keyword database management, social media data collection, natural language processing, pattern matching, information validation, and alert generation. Each module performs a specific function and can be independently maintained and improved, reducing overall system complexity while maintaining high detection speed through specialized processing in each segment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10127385B2Automated security vulnerability exploit tracking on social media
Publication Date: 2018.11.13 SAP SE
  • US10127385B2 patent drawing
  • US10127385B2 patent drawing
  • US10127385B2 patent drawing

AI summary

Embodiments automate tracking of exploit information related to initially-identified security vulnerabilities, through the data mining of social networks. Certain social network communities (e.g., those frequented by hackers) share information about computer security breaches (zero-day events). Embodiments recognize that further relevant security information may be revealed, in conjunction with and/or subsequent to such initial zero-day vulnerability disclosures. That additional information can include valuable details regarding known (or unknown) vulnerabilities, exploit codes and methodologies, patches, etc. Tracking that additional information can benefit security researchers/experts/law enforcement personnel. Embodiments monitoring social media traffic based upon initial security vulnerability information, perform analysis to detect patterns and create relevant keywords therefrom. Those keywords in turn form a basis for generating social media stream(s) responsible for harvesting additional security-relevant data. Results of further analysis of the social media stream can be fed back in an iterative manner to refine pattern detection, keyword creation, and media stream generation.