IP Library › Granted Patent US 11,777,961
Granted Patent B2
US 11,777,961 · App. 17/751,236 · Granted Oct 3, 2023

Asset remediation trend map generation and utilization for threat mitigation

Inventors: Ankur S. Tyagi (Foster City, CA); Mayuresh Vishwas Dani (Fremont, CA)
Assignee: QUALYS, INC.
H04L63/1416H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,961
App. No.
17/751,236
Filed
May 23, 2022
Granted
Oct 3, 2023
Kind
B2
Art Unit
2419
USPC
726/23
Abstract

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.

Claims (69)

1. A method comprising:

receiving, using one or more computing device processors, attack kill chain data, the attack kill chain data comprising steps for executing an attack campaign on one or more assets associated with a computing device;

parsing, using the one or more computing device processors, the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on a vulnerability assessment associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determining, using the one or more computing device processors, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequencing, using the one or more computing device processors, the one or more remediation operations to form an asset remediation trend map, the asset remediation trend map indicating steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the steps comprise using one or more features of a security system based on remediation type of the one or more remediation operations; and

initiating generation of, using the one or more computing device processors, a visual representation of the asset remediation trend map, the visual representation indicating a sequence of the one or more remediation operations for remediating the attack campaign associated with the one or more assets associated with the computing device.

2. The method of claim 1 , wherein the asset remediation trend map indicates operations for resolving the attack campaign or from preventing the attack campaign from subsequently being executed on the one or more assets associated with the computing device.

3. The method of claim 1 , wherein parsing, using the one or more computing device processors, the attack kill chain data further comprises:

determining successful attack execution operations within the one or more attack execution operations,

determining criticality data for the successful attack execution operations within the one or more attack execution operations,

determining corresponding remediation operations based on the criticality data, and

initiating generation of the asset remediation trend map based on the corresponding remediation operations.

4. The method of claim 3 , wherein the determining the criticality data is based on one or more of:

a locational vulnerability assessment including one of a local vulnerability assessment and a remote vulnerability assessment,

a patch availability for each successful attack execution operation, or

the remediation type.

5. The method of claim 1 , wherein the one or more assets comprise one or more of:

a software resource,

a file,

a hardware resource, or

the computing device.

6. The method of claim 1 , wherein the attack kill chain data is based on mapping attack events associated with the one or more assets of the computing device to attack data within a repository of attack data, the mapping being used to determine attack execution operations associated with the attack campaign.

7. The method of claim 1 , wherein determining the one or more attack execution operations comprises quantifying a successful attack execution operation comprised in the one or more attack execution operations.

8. The method of claim 7 , wherein quantifying the successful attack execution operation comprises:

determining a parameter for the successful attack execution operation, and

calculating a parametric value for the determined parameter, the parametric value indicating a criticality of the successful attack execution operation.

9. The method of claim 1 , wherein the visual representation comprises one or more vertices representing the one or more remediation operations, the one or more vertices being organized to reflect a first order for executing the one or more remediation operations, or a second order for executing the one or more remediation operations relative to a third order for executing the one or more remediation operations.

10. A system comprising:

one or more computing system processors; and

memory storing instructions that, when executed by the one or more computing system processors, causes the system to:

receive attack kill chain data, the attack kill chain data comprising steps for executing an attack campaign on one or more assets associated with a computing device;

parse the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on a vulnerability assessment associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determine, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequence the one or more remediation operations to form an asset remediation trend map, the asset remediation trend map indicating steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the steps comprise using one or more features of a security system based on remediation type of the one or more remediation operations; and

initiate generation of a visual representation of the asset remediation trend map, the visual representation comprising one or more vertices representing the one or more remediation operations, the one or more vertices being organized to reflect an order of execution for the one or more remediation operations.

11. The system of claim 10 , wherein to parse the attack kill chain data further comprises:

determining a successful attack execution operation within the one or more attack execution operations;

quantifying the successful attack execution operation to determine a criticality of the successful attack execution operation;

determining, based on the quantifying, a corresponding remediation operation, the corresponding remediation operation accounting for the criticality associated with the quantified successful attack execution operation; and

initiating generation of the asset remediation trend map based on the corresponding remediation operation.

12. The system of claim 11 , wherein the quantifying is based on one or more criteria selected from a group of criteria comprising:

a locational vulnerability assessment including one of a local vulnerability assessment and a remote vulnerability assessment,

a patch availability for each successful attack execution operation, and

the remediation type.

13. The system of claim 10 , wherein the attack kill chain data is based on mapping attack events associated with the one or more assets of the computing device to data within a repository, the mapping being used to determine attack execution operations associated with the attack campaign.

14. The system of claim 10 , wherein the visual representation comprises at least one indicator that provides a status of a remediation operation comprised in the one or more remediation operations of the asset remediation trend map.

15. A method comprising:

receiving, using one or more computing device processors, attack kill chain data, the attack kill chain data comprising steps for executing an attack campaign on one or more assets associated with a computing device;

parsing, using the one or more computing device processors, the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on a vulnerability assessment associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determining, using the one or more computing device processors, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequencing, using the one or more computing device processors, the one or more remediation operations to form an asset remediation trend map, the asset remediation trend map indicating steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the steps comprise using one or more features of a security system based on remediation type of the one or more remediation operations, wherein the security system comprises at least one of a hardware resource or a software resource; and

initiating generation of, using the one or more computing device processors, a visual representation of the asset remediation trend map, the visual representation indicating a sequence of the one or more remediation operations for remediating the attack campaign associated with the one or more assets associated with the computing device.

16. The method of claim 15 , wherein to parse the attack kill chain data further comprises:

determining successful attack execution operations within the one or more attack execution operations;

quantifying the successful attack execution operations to determine a criticality of the successful attack execution operations by:

assigning a weight to each successful attack execution operation of the one or more attack execution operations; and

calculating a metric score for each weighted successful attack execution operation, the metric score for each weighted successful attack execution operation indicating a criticality of said attack execution operation;

determining, based on the quantifying, corresponding remediation operations, each corresponding remediation operation indicating the criticality associated with a corresponding quantified successful attack execution operation; and

initiating generation of the asset remediation trend map based on the corresponding remediation operations.

17. The method of claim 15 , wherein the asset remediation trend map includes an indicator that reflects at least one of:

a status of a remediation operation comprised in the one or more remediation operations, or

a progression of the remediation operation comprised in the one or more remediation operations.

18. The method of claim 15 , wherein the remediation type comprises one or more of:

an antivirus remediation,

firewall remediation,

operating system remediation,

domain remediation, or

access policy remediation.

19. The method of claim 15 , wherein the attack kill chain data includes an ordered indication of the one or more attack execution operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2022
From: TYAGI, ANKUR S.; DANI, MAYURESH VISHWAS
To: QUALYS, INC.
Reel/Frame 061420/0126 →
Continuity (2)
Continuation 16384560 · Apr 15, 2019
Related Publication 20220294810A1 · Sep 15, 2022
Cited By (1)
US 12,682,073