TTP-Based Threat Hunting Using Actor Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current threat hunting methods based on indicators of compromise (IOCs) are ineffective against threat actors who can easily circumvent detection by modifying their methods, and these methods are often reactive, leading to data leaks, time delays, and increased costs.

Innovation Solution

A computing platform that proactively searches for threat actors using tactics, techniques, and procedures (TTP) based on threat actor profiles, integrating with endpoint detection and response (EDR) systems, security orchestration and automation (SOAR) systems, and metadata evaluation to identify and respond to potential threats before they occur.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If threat hunting is performed based on indicators of compromise (IOCs), then detection of known threats is achieved, but threat actors can easily circumvent detection by modifying their methods such as using different compressors or domains

Engineering Contradiction:
Improvedetection reliabilityVSAvoidthreat actor adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions from detecting threats based on static IOCs (specific parameters like hash values, domains) to detecting threats based on dynamic TTPs (tactics, techniques, and procedures). This parameter change allows the system to identify threat actors by their behavioral patterns and methods rather than fixed identifiers, making detection more reliable against modified threats.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements dynamic threat detection by continuously monitoring and analyzing threat actor behaviors, techniques, and procedures. Instead of relying on static IOC databases, the system adapts to changing threat landscapes by tracking evolving attack patterns, making the detection system resilient to threat actor modifications.

Inventive Principle:
Principle #15Dynamics

2Loss of time

If threat hunts are performed reactively after a breach or cybersecurity incident occurs, then retroactive remediation is achieved, but data leaks, time delays, and increased costs occur

Engineering Contradiction:
Improveresponse timeVSAvoidincident prevention reliability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements proactive threat hunting by conducting searches for threat actors before breaches or incidents occur. The system continuously monitors networks, analyzes TTPs, and identifies potential threats in advance, enabling security teams to take preliminary actions to prevent incidents rather than reacting after damage has occurred.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes continuous feedback loops where threat intelligence, TTP data, and analysis results are constantly updated and fed back into the threat hunting process. This enables the system to learn from emerging threats and adjust detection strategies in real-time, improving both response time and prevention capability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240098105A1Tactics, techniques, and procedures (TTP) based threat hunting
Publication Date: 2024.03.21 TRUSTWAVE HOLDINGS INC
  • US20240098105A1 patent drawing
  • US20240098105A1 patent drawing
  • US20240098105A1 patent drawing

AI summary

Aspects of the disclosure relate to TTP based threat hunting. A computing platform may store a plurality of threat actor profiles, each threat actor profile including TTP information characteristic of the corresponding threat actor. The computing platform may execute, for a first threat actor and on behalf of a plurality of individuals, a threat hunt, where: 1) executing the threat hunt comprises searching for a presence of the first threat actor based on the threat actor profile for the first threat actor, and 2) executing the threat hunt produces metadata corresponding to the first threat actor. The computing platform may send, to a SOAR computing system, commands directing the SOAR computing system to execute SOAR actions for the metadata, which may cause the SOAR computing system to execute the SOAR actions.