Vulnerability Attack Technique Mapping System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security techniques for cloud computing environments fail to associate attack techniques with vulnerabilities and do not enable security analysts to match vulnerabilities with threat actors or develop targeted threat models.

Innovation Solution

A system comprising a processor and memory that defines mappings between vulnerability data and attack data, estimating the probability of vulnerability exploitation and generating threat, vulnerability management, or risk management models to enhance protection of computing resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing security techniques are used to assess attacker tactics and techniques, then threat models can be developed, but there is no association between attack techniques and vulnerabilities of computing components

Engineering Contradiction:
Improvethreat model accuracyVSAvoidvulnerability-attack association
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the security analysis by creating separate but linked representations: vulnerability data structures for computing components and attack technique data structures for adversary behaviors. These segmented representations are then associated through mapping relationships, allowing detailed analysis of each aspect while maintaining their connections.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mapping mechanism that connects vulnerability data with attack technique data. This mapping structure acts as a mediator that enables association between the two previously unconnected domains, allowing security analysts to trace which attacks exploit which vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If existing security techniques are used to assess vulnerabilities, then security assessments can be performed, but security analysts cannot match vulnerabilities with threat actors or their attack methodologies

Engineering Contradiction:
Improvesecurity assessment efficiencyVSAvoidthreat actor-vulnerability matching
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system adds a new dimension to security analysis by incorporating threat actor characteristics and methodologies as a separate layer of data. This dimensional expansion allows matching across multiple criteria: vulnerability properties, attack technique properties, and threat actor properties, enabling comprehensive threat actor-vulnerability matching.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If existing security techniques are used without vulnerability-attack associations, then general threat models can be created, but targeted threat models for specific vulnerabilities cannot be developed

Engineering Contradiction:
Improvethreat model targetingVSAvoiddata structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The mapping data structure is designed to be universal and multi-functional. It can represent various types of relationships between vulnerabilities and attacks, support different granularity levels, and enable multiple types of analyses (threat modeling, risk assessment, attack path analysis) through the same underlying structure, reducing the need for separate specialized structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11924239B2Vulnerability and attack technique association
Publication Date: 2024.03.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11924239B2 patent drawing
  • US11924239B2 patent drawing
  • US11924239B2 patent drawing

AI summary

Systems, computer-implemented methods, and computer program products that facilitate vulnerability and attack technique association are provided. According to an embodiment, a system can comprise a memory that stores computer executable components and a processor that executes the computer executable components stored in the memory. The computer executable components can comprise a map component that defines mappings between vulnerability data representing a vulnerability of a computing resource and attack data representing at least one attack technique. The computer executable components can further comprise an estimation component that analyzes the mappings to estimate a probability that the vulnerability will be exploited to attack the computing resource.