TTP-Based Threat Hunting Using Actor Profiles
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current threat hunting methods based on indicators of compromise (IOCs) are ineffective against threat actors who can easily circumvent detection by modifying their methods, and these methods are often reactive, leading to data leaks, time delays, and increased costs.
Innovation Solution
A computing platform that proactively searches for threat actors using tactics, techniques, and procedures (TTP) based on threat actor profiles, integrating with endpoint detection and response (EDR) systems, security orchestration and automation (SOAR) systems, and metadata evaluation to identify and respond to potential threats before they occur.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If threat hunting is performed based on indicators of compromise (IOCs), then detection of known threats is achieved, but threat actors can easily circumvent detection by modifying their methods such as using different compressors or domains
Solution Approach 1:
The patent transitions from detecting threats based on static IOCs (specific parameters like hash values, domains) to detecting threats based on dynamic TTPs (tactics, techniques, and procedures). This parameter change allows the system to identify threat actors by their behavioral patterns and methods rather than fixed identifiers, making detection more reliable against modified threats.
Solution Approach 2:
The system implements dynamic threat detection by continuously monitoring and analyzing threat actor behaviors, techniques, and procedures. Instead of relying on static IOC databases, the system adapts to changing threat landscapes by tracking evolving attack patterns, making the detection system resilient to threat actor modifications.
2Loss of time
If threat hunts are performed reactively after a breach or cybersecurity incident occurs, then retroactive remediation is achieved, but data leaks, time delays, and increased costs occur
Solution Approach 1:
The patent implements proactive threat hunting by conducting searches for threat actors before breaches or incidents occur. The system continuously monitors networks, analyzes TTPs, and identifies potential threats in advance, enabling security teams to take preliminary actions to prevent incidents rather than reacting after damage has occurred.
Solution Approach 2:
The system establishes continuous feedback loops where threat intelligence, TTP data, and analysis results are constantly updated and fed back into the threat hunting process. This enables the system to learn from emerging threats and adjust detection strategies in real-time, improving both response time and prevention capability.
Data Source
AI summary
Aspects of the disclosure relate to TTP based threat hunting. A computing platform may store a plurality of threat actor profiles, each threat actor profile including TTP information characteristic of the corresponding threat actor. The computing platform may execute, for a first threat actor and on behalf of a plurality of individuals, a threat hunt, where: 1) executing the threat hunt comprises searching for a presence of the first threat actor based on the threat actor profile for the first threat actor, and 2) executing the threat hunt produces metadata corresponding to the first threat actor. The computing platform may send, to a SOAR computing system, commands directing the SOAR computing system to execute SOAR actions for the metadata, which may cause the SOAR computing system to execute the SOAR actions.


