Vulnerability Attack Technique Mapping System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security techniques for cloud computing environments fail to associate attack techniques with vulnerabilities and do not enable security analysts to match vulnerabilities with threat actors or develop targeted threat models.
Innovation Solution
A system comprising a processor and memory that defines mappings between vulnerability data and attack data, estimating the probability of vulnerability exploitation and generating threat, vulnerability management, or risk management models to enhance protection of computing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security techniques are used to assess attacker tactics and techniques, then threat models can be developed, but there is no association between attack techniques and vulnerabilities of computing components
Solution Approach 1:
The system segments the security analysis by creating separate but linked representations: vulnerability data structures for computing components and attack technique data structures for adversary behaviors. These segmented representations are then associated through mapping relationships, allowing detailed analysis of each aspect while maintaining their connections.
Solution Approach 2:
The patent introduces an intermediary mapping mechanism that connects vulnerability data with attack technique data. This mapping structure acts as a mediator that enables association between the two previously unconnected domains, allowing security analysts to trace which attacks exploit which vulnerabilities.
2Productivity
If existing security techniques are used to assess vulnerabilities, then security assessments can be performed, but security analysts cannot match vulnerabilities with threat actors or their attack methodologies
Solution Approach 1:
The system adds a new dimension to security analysis by incorporating threat actor characteristics and methodologies as a separate layer of data. This dimensional expansion allows matching across multiple criteria: vulnerability properties, attack technique properties, and threat actor properties, enabling comprehensive threat actor-vulnerability matching.
3Adaptability or versatility
If existing security techniques are used without vulnerability-attack associations, then general threat models can be created, but targeted threat models for specific vulnerabilities cannot be developed
Solution Approach 1:
The mapping data structure is designed to be universal and multi-functional. It can represent various types of relationships between vulnerabilities and attacks, support different granularity levels, and enable multiple types of analyses (threat modeling, risk assessment, attack path analysis) through the same underlying structure, reducing the need for separate specialized structures.
Data Source
AI summary
Systems, computer-implemented methods, and computer program products that facilitate vulnerability and attack technique association are provided. According to an embodiment, a system can comprise a memory that stores computer executable components and a processor that executes the computer executable components stored in the memory. The computer executable components can comprise a map component that defines mappings between vulnerability data representing a vulnerability of a computing resource and attack data representing at least one attack technique. The computer executable components can further comprise an estimation component that analyzes the mappings to estimate a probability that the vulnerability will be exploited to attack the computing resource.


