IP Library › Granted Patent US 11,689,567
Granted Patent B2
US 11,689,567 · App. 16/811,837 · Granted Jun 27, 2023

Mapping an attack tree and attack prediction in industrial control and IIoT environment using hash data analytics

Inventors: Ganesh Patilba Gadhe (Phoenix, AZ); Steven Louie Ypma (Suwanee, GA); Doug Swain (Dover, NH); Virgil Mehalek (Dover, NH)
Assignee: Honeywell International Inc.
H04L63/1466G06F16/903G06F16/9014H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,689,567
App. No.
16/811,837
Granted
Jun 27, 2023
Kind
B2
Abstract

A method, apparatus and computer program product for detecting malicious content and predicting cyberattacks are described herein. In the context of a method, the method receives a hash query comprising a file hash based on one or more files. The method queries a cyberattack case studies information database based on the hash query to generate one or more attack correlation information items associated with at least one of the one or more files. The method also generates and outputs a file security analysis based on the attack correlation information items for authorization of the one or more files.

Claims (58)

1. A computer-implemented method for malicious content detection and attack prediction in an industrial control system, comprising:

receiving a hash query associated with a system from a secure media exchange node, wherein the hash query comprises a file hash generated at the secure media exchange node based at least in part on one or more files received at the secure media exchange node;

generating an attack tree based at least in part on a combination of a first hash for a first file and a second hash for a second file based on a determination that the first hash and the second hash historically were received in a same hash query;

querying a cyberattack case studies information database based on the hash query to generate one or more attack correlation information items associated with at least one of the one or more files by comparing the hash query with file hashes stored in the cyberattack case studies information database;

generating a file security analysis regarding the one or more files based on the one or more attack correlation information items, wherein the file security analysis comprises at least one indication of a predicted malicious content item predicted as previously brought into the system based at least in part on the one or more attack correlation information items,

wherein querying the cyberattack case studies information database further comprises receiving at least one predictive indicator based at least in part on the attack tree, wherein the file security analysis comprises data representing that the file hash indicates the one or more files comprises the first file and the second file; and

outputting the file security analysis to a secure media exchange threat intelligence portal associated with the secure media exchange node for authorization of the one or more files.

2. The computer-implemented method according to claim 1 , wherein the cyberattack case studies information database comprises a historical threat intelligence database configured to store at least one or more historically received file hashes representing one or more malicious content items, and wherein querying the cyberattack case studies information database further comprises:

querying the historical threat intelligence database with the hash query; and

upon determining that the file hash in the hash query matches at least one of the one or more historically received file hashes, generating one or more historical threat indicators representing the one or more malicious content items, wherein the one or more attack correlation information items comprise the one or more historical threat indicators.

3. The computer-implemented method according to claim 2 , wherein the one or more malicious content items are each associated with one of the one or more file hashes.

4. The computer-implemented method according to claim 2 , wherein the one or more malicious content items are one or more of: one or more known viruses, one or more malware tools, or one or more software tools historically utilized in connection with a cyberattack.

5. The computer-implemented method according to claim 1 , wherein the cyberattack case studies information database comprises a cyberattack correlation and prediction database configured to store one or more hashes associated with one or more malicious content items, and wherein querying the cyberattack case studies information database further comprises:

querying the cyberattack correlation and prediction database with the hash query;

receiving one or more predictive indicators, wherein each of the one or more predictive indicators are based on an attack tree mapping associated with the hash file; and

generating the file security analysis based at least on the one or more predictive indicators.

6. The computer-implemented method according to claim 5 , wherein the one or more predictive indicators include one or more of: an indication of one or more attack phases, and an indication of one or more additional file hashes associated with the file hash.

7. The computer-implemented method according to claim 1 , further comprising:

outputting a notification associated with the file security analysis to a user device of a user associated with the secure media exchange node.

8. An apparatus configured to detect malicious content and predict attacks in an industrial control system, the apparatus comprising at least one processor and at least one non-transitory memory including program code, the at least one non-transitory memory and the program code configured to, with the processor, cause the apparatus to at least:

receive a hash query from a secure media exchange node, wherein the hash query comprises a file hash generated at the secure media exchange node based at least in part on one or more files received at the secure media exchange node;

generate an attack tree based at least in part on a combination of a first hash for a first file and a second hash for a second file based on a determination that the first hash and the second hash historically were received in a same hash query;

query a cyberattack case studies information database based on the hash query to generate one or more attack correlation information items associated with at least one of the one or more files by comparing the hash query with file hashes stored in the cyberattack case studies information database;

generate a file security analysis regarding the one or more files based on the one or more attack correlation information items, wherein the file security analysis comprises at least one indication of a predicted malicious content item predicted as previously brought into the system based at least in part on the one or more attack correlation information items,

wherein querying the cyberattack case studies information database further comprises receiving at least one predictive indicator based at least in part on the attack tree, wherein the file security analysis comprises data representing that the file hash indicates the one or more files comprises the first file and the second file; and

output the file security analysis to a secure media exchange threat intelligence portal associated with the secure media exchange node for authorization of the one or more files.

9. The apparatus according to claim 8 , wherein the cyberattack case studies information database comprises a historical threat intelligence database configured to store at least one or more historically received file hashes representing one or more malicious content items, and wherein the at least one non-transitory memory and the program code that is configured to, with the processor, cause the apparatus to at least query the cyberattack case studies information database is further configured to:

query the historical threat intelligence database with the hash query; and

upon determining that the file hash in the hash query matches at least one of the one or more historically received file hashes, generate one or more historical threat indicators representing the one or more malicious content items, wherein the one or more attack correlation information items comprise the one or more historical threat indicators.

10. The apparatus according to claim 9 , wherein the one or more malicious content items are each associated with one of the one or more file hashes.

11. The apparatus according to claim 9 , wherein the one or more malicious content items are one or more of: one or more known viruses, one or more malware tools, or one or more software tools historically utilized in connection with a cyberattack.

12. The apparatus according to claim 8 , wherein the cyberattack case studies information database comprises a cyberattack correlation and prediction database configured to store one or more hashes associated with one or more malicious content items, and wherein the at least one non-transitory memory and the program code that is configured to, with the processor, cause the apparatus to at least query the cyberattack case studies information database is further configured to:

query the cyberattack correlation and prediction database with the hash query;

receive one or more predictive indicators, wherein each of the one or more predictive indicators are based on an attack tree mapping associated with the hash file; and

generate the file security analysis based at least on the one or more predictive indicators.

13. The apparatus according to claim 12 , wherein the one or more predictive indicators include one or more of: an indication of one or more attack phases, and an indication of one or more additional file hashes associated with the file hash.

14. The apparatus according to claim 8 , wherein the memory including the program code is further configured to, with the processor, cause the apparatus to:

output a notification associated with the file security analysis to a user device of a user associated with the secure media exchange node.

15. A computer program product comprising at least one non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising an executable portion configured to:

receive a hash query from a secure media exchange node, wherein the hash query comprises a file hash generated at the secure media exchange node based at least in part on one or more files received at the secure media exchange node;

generate an attack tree based at least in part on a combination of a first hash for a first file and a second hash for a second file based on a determination that the first hash and the second hash historically were received in a same hash query;

query a cyberattack case studies information database based on the hash query to generate one or more attack correlation information items associated with at least one of the one or more files by comparing the hash query with file hashes stored in the cyberattack case studies information database;

generate a file security analysis regarding the one or more files based on the one or more attack correlation information items, wherein the file security analysis comprises at least one indication of a predicted malicious content item predicted as previously brought into the system based at least in part on the one or more attack correlation information items,

wherein querying the cyberattack case studies information database further comprises receiving at least one predictive indicator based at least in part on the attack tree, wherein the file security analysis comprises data representing that the file hash indicates the one or more files comprises the first file and the second file; and

output the file security analysis to a secure media exchange threat intelligence portal associated with the secure media exchange node for authorization of the one or more files.

16. The computer program product according to claim 15 , wherein the cyberattack case studies information database comprises a historical threat intelligence database configured to store at least one or more historically received file hashes representing one or more malicious content items, and wherein the computer-readable program code portions comprising an executable portion configured to query the cyberattack case studies information database are further configured to:

query the historical threat intelligence database with the hash query; and

upon determining that the file hash in the hash query matches at least one of the one or more historically received file hashes, generate one or more historical threat indicators representing the one or more malicious content items, wherein the one or more attack correlation information items comprise the one or more historical threat indicators.

17. The computer program product according to claim 15 , wherein the cyberattack case studies information database comprises a cyberattack correlation and prediction database configured to store one or more hashes associated with one or more malicious content items, and wherein the computer-readable program code portions comprising an executable portion configured to query the cyberattack case studies information database are further configured to:

query the cyberattack correlation and prediction database with the hash query;

receive one or more predictive indicators, wherein each of the one or more predictive indicators are based on an attack tree mapping associated with the hash file; and

generate the file security analysis based at least on the one or more predictive indicators.

18. The computer program product according to claim 15 , wherein the computer-readable program code portions comprising the executable portion are further configured to:

output a notification associated with the file security analysis to a user device of a user associated with the secure media exchange node.

19. The computer-implemented method according to claim 1 , the computer-implemented method further comprising:

identifying a first phase associated with the one or more attack correlation information items based on an attack tree mapping associated with the hash file; and

predicting the at least one indication of the predicted malicious content item associated with a second phase, wherein the second phase is before the first phase in the attack tree mapping.

20. The computer-implemented method according to claim 1 , wherein the predicted malicious content item comprises a non-malicious content item determined to be associated with at least one malicious content item based at least in part on historical file hashes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2020
From: GADHE, GANESH PATILBA; YPMA, STEVEN LOUIE; SWAIN, DOUG; MEHALEK, VIRGIL
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 052141/0253 →
Continuity (1)
Related Publication 20210281604A1 · Sep 9, 2021
Cited By (2)
US 12,518,012 US 12,732,526