IP Library › Granted Patent US 12,445,466
Granted Patent B2
US 12,445,466 · App. 18/368,920 · Granted Oct 14, 2025

Asset remediation trend map generation and utilization for threat mitigation

Inventors: Ankur S. Tyagi (Foster City, CA); Mayuresh Vishwas Dani (Fremont, CA)
Assignee: Qualys, Inc.
H04L63/1416H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,466
App. No.
18/368,920
Filed
Sep 15, 2023
Granted
Oct 14, 2025
Kind
B2
Art Unit
2409
USPC
726/23
Abstract

The present disclosure relates to methods, systems, and computer program products for generating an asset remediation trend map used in remediating against an attack campaign. The method comprises receiving attack kill chain data. The attack kill chain data comprises steps for executing an attack campaign on one or more assets associated with a computing device. The method further comprises parsing the attack kill chain data to determine one or more attack execution operations for executing the attack campaign on the one or more assets associated with the computing device. The method determines based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations. In addition, the method sequences the one or more remediation operations to form an asset remediation trend map. In one implementation, the asset remediation trend map indicates steps for remediating the attack campaign.

Claims (69)

1. A method comprising:

receiving, using one or more computing device processors, attack kill chain data, the attack kill chain data comprising first steps for executing an attack campaign associated with one or more assets associated with a computing device;

parsing, using the one or more computing device processors, the attack kill chain data to determine one or more attack execution operations for executing the attack campaign associated with the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on vulnerability data associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determining, using the one or more computing device processors, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequencing, using the one or more computing device processors, the one or more remediation operations, the one or more remediation operations comprising second steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the second steps for remediating the attack campaign are executable using one or more functions of a security system; and

initiating generation of, using the one or more computing device processors, a visual representation of the one or more remediation operations, the visual representation indicating a sequence of the one or more remediation operations for remediating the attack campaign associated with the one or more assets associated with the computing device.

2. The method of claim 1 , wherein the visual representation of the one or more remediation operations indicates operations for resolving the attack campaign or from preventing the attack campaign from subsequently being executed on the one or more assets associated with the computing device.

3. The method of claim 1 , wherein the parsing, using the one or more computing device processors, the attack kill chain data further comprises:

determining successful attack execution operations within the one or more attack execution operations,

determining criticality data for the successful attack execution operations within the one or more attack execution operations, and

determining corresponding remediation operations based on the criticality data,

wherein the initiating generation of the visual representation of the one or more remediation operations is based on the corresponding remediation operations.

4. The method of claim 3 , wherein the determining the criticality data is based on one or more of:

a locational vulnerability assessment including one of a local vulnerability assessment and a remote vulnerability assessment,

a patch availability for each successful attack execution operation, or

a remediation type.

5. The method of claim 1 , wherein the one or more assets comprise one or more of:

a software resource,

a file,

a hardware resource, or

the computing device.

6. The method of claim 1 , wherein the attack kill chain data is based on mapping attack events associated with the one or more assets of the computing device to attack data within a repository of attack data, the mapping being used to determine attack execution operations associated with the attack campaign.

7. The method of claim 1 , wherein the determining the one or more attack execution operations comprises quantifying a successful attack execution operation comprised in the one or more attack execution operations.

8. The method of claim 7 , wherein the quantifying the successful attack execution operation comprises:

determining a parameter for the successful attack execution operation, and

calculating a parametric value for the parameter, the parametric value indicating a criticality of the successful attack execution operation.

9. The method of claim 1 , wherein the visual representation comprises one or more vertices representing the one or more remediation operations, the one or more vertices being organized to reflect a first order for executing the one or more remediation operations, or a second order for executing the one or more remediation operations relative to a third order for executing the one or more remediation operations.

10. A system comprising:

one or more computing system processors; and

memory storing instructions that, when executed by the one or more computing system processors, causes the system to:

receive attack kill chain data, the attack kill chain data comprising first steps for executing an attack campaign associated with one or more assets associated with a computing device;

parse the attack kill chain data to determine one or more attack execution operations for executing the attack campaign associated with the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on vulnerability data associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determine, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequence the one or more remediation operations, the one or more remediation operations comprising second steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the second steps for remediating the attack campaign are executable using one or more functions of a security system; and

initiate generation of a visual representation of the one or more remediation operations, the visual representation comprising one or more vertices representing the one or more remediation operations, the one or more vertices being organized to reflect an order of execution for the one or more remediation operations.

11. The system of claim 10 , wherein the parse the attack kill chain data further comprises:

determining a successful attack execution operation within the one or more attack execution operations;

quantifying the successful attack execution operation to determine a criticality of the successful attack execution operation; and

determining, based on the quantifying, a corresponding remediation operation, the corresponding remediation operation accounting for the criticality of the successful attack execution operation,

wherein the initiating generation of the visual representation of the one or more remediation operations is based on the corresponding remediation operation.

12. The system of claim 11 , wherein the quantifying is based on one or more criteria selected from a group of criteria comprising:

a locational vulnerability assessment including one of a local vulnerability assessment and a remote vulnerability assessment,

a patch availability for the successful attack execution operation, and

a remediation type.

13. The system of claim 10 , wherein the attack kill chain data is based on mapping attack events associated with the one or more assets of the computing device to data within a repository, the mapping being used to determine attack execution operations associated with the attack campaign.

14. The system of claim 10 , wherein the visual representation comprises at least one indicator that provides a status of a remediation operation comprised in the one or more remediation operations of the visual representation.

15. A method comprising:

receiving, using one or more computing device processors, attack kill chain data, the attack kill chain data comprising first steps for executing an attack campaign associated with one or more assets associated with a computing device;

parsing, using the one or more computing device processors, the attack kill chain data to determine one or more attack execution operations for executing the attack campaign associated with the one or more assets associated with the computing device, wherein the parsing includes determining the one or more attack execution operations based on vulnerability data associated with the one or more attack execution operations or an availability of a security patch associated with the one or more attack execution operations;

determining, using the one or more computing device processors, based on the parsing, one or more remediation operations corresponding to the one or more attack execution operations;

sequencing, using the one or more computing device processors, the one or more remediation operations, the one or more remediation operations comprising second steps for remediating the attack campaign associated with the one or more assets associated with the computing device, wherein the second steps for remediating the attack campaign are executable using one or more functions of a security system, wherein the security system comprises at least one of a hardware resource or a software resource; and

initiating generation of, using the one or more computing device processors, a visual representation of the one or more remediation operations, the visual representation indicating a sequence of the one or more remediation operations for remediating the attack campaign associated with the one or more assets associated with the computing device.

16. The method of claim 15 , wherein the parsing the attack kill chain data further comprises:

determining successful attack execution operations within the one or more attack execution operations;

quantifying the successful attack execution operations to determine a criticality of the successful attack execution operations by:

assigning a weight to each successful attack execution operation of the one or more attack execution operations, thereby generating weighted successful attack execution operations; and

calculating a metric score for each of the weighted successful attack execution operations, the metric score for each of the weighted successful attack execution operations indicating the criticality of each of the weighted successful attack execution operations; and

determining, based on the quantifying, corresponding remediation operations, each corresponding remediation operation indicating the criticality associated with a corresponding quantified successful attack execution operation,

wherein the initiating generation of the visual representation of the one or more remediation operations is based on the corresponding remediation operations.

17. The method of claim 16 , wherein the visual representation includes an indicator that reflects at least one of:

a status of a remediation operation comprised in the one or more remediation operations, or

a progression of the remediation operation comprised in the one or more remediation operations.

18. The method of claim 16 , wherein the security system is based on a remediation type, and wherein the remediation type comprises one or more of:

an antivirus remediation,

firewall remediation,

operating system remediation,

domain remediation, or

access policy remediation.

19. The method of claim 16 , wherein the attack kill chain data includes an ordered indication of the one or more attack execution operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: TYAGI, ANKUR S.; DANI, MAYURESH VISHWAS
To: QUALYS, INC.
Reel/Frame 064997/0983 →
Continuity (3)
Continuation 17751236 · May 23, 2022
Continuation 16384560 · Apr 15, 2019
Related Publication 20240007487A1 · Jan 4, 2024
References Cited (103)
US 8646076B1 · Lim · 2014 [cited by examiner]
US 9654485B1 · Neumann · 2017 [cited by examiner]
US 9894090B2 · Hebert · 2018 [cited by examiner]
US 10095866B2 · Gong et al. · 2018 [cited by applicant]
US 10154047B2 · Muddu · 2018 [cited by examiner]
US 10200259B1 · Pukish · 2019 [cited by examiner]
US 10382473B1 · Ashkenazy et al. · 2019 [cited by applicant]
US 10454953B1 · Amin · 2019 [cited by examiner]
US 10594714B2 · Crabtree · 2020 [cited by examiner]
US 10826933B1 · Ismael · 2020 [cited by examiner]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 10944766B2 · Mishra · 2021 [cited by examiner]
US 10956566B2 · Shu · 2021 [cited by examiner]
US 11277429B2 · Ababtain · 2022 [cited by examiner]
US 11356484B2 · Sander · 2022 [cited by examiner]
US 11405419B2 · Chen et al. · 2022 [cited by applicant]
US 11411977B2 · Chiu · 2022 [cited by examiner]
US 11601442B2 · Sekar · 2023 [cited by examiner]
US 11637844B2 · Shenoy · 2023 [cited by examiner]
US 11991203B2 · Vaidya · 2024 [cited by examiner]
US 12235960B2 · Klonowski · 2025 [cited by examiner]
US 20060129670A1 · Mayer · 2006 [cited by examiner]
US 20070067848A1 · Gustave · 2007 [cited by examiner]
US 20120210434A1 · Curtis · 2012 [cited by examiner]
US 20130117848A1 · Golshan · 2013 [cited by examiner]
US 20130298244A1 · Kumar · 2013 [cited by examiner]
US 20140237545A1 · Mylavarapu · 2014 [cited by examiner]
US 20150244732A1 · Golshan et al. · 2015 [cited by applicant]
US 20150244734A1 · Olson et al. · 2015 [cited by applicant]
US 20150381649A1 · Schultz · 2015 [cited by examiner]
US 20160070674A1 · Hershey et al. · 2016 [cited by applicant]
US 20160164916A1 · Satish et al. · 2016 [cited by applicant]
US 20160226893A1 · Warikoo et al. · 2016 [cited by applicant]
US 20160226905A1 · Baikalov · 2016 [cited by examiner]
US 20160308898A1 · Teeple et al. · 2016 [cited by applicant]
US 20170006055A1 · Strom · 2017 [cited by examiner]
US 20170063912A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063920A1 · Thomas et al. · 2017 [cited by applicant]
US 20170201530A1 · Mead · 2017 [cited by examiner]
US 20170300690A1 · Ladnai · 2017 [cited by examiner]
US 20170324768A1 · Crabtree · 2017 [cited by examiner]
US 20170359220A1 · Weith · 2017 [cited by examiner]
US 20170359306A1 · Thomas · 2017 [cited by examiner]
US 20180004942A1 · Martin · 2018 [cited by examiner]
US 20180020017A1 · Subramanya · 2018 [cited by examiner]
US 20180032724A1 · Tang · 2018 [cited by examiner]
US 20180039776A1 · Loman · 2018 [cited by examiner]
US 20180048667A1 · Tang et al. · 2018 [cited by applicant]
US 20180152470A1 · Lu · 2018 [cited by examiner]
US 20180205754A1 · North · 2018 [cited by examiner]
US 20180234445A1 · Bhatt et al. · 2018 [cited by applicant]
US 20180248893A1 · Israel et al. · 2018 [cited by applicant]
US 20180270268A1 · Gorodissky · 2018 [cited by examiner]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20180324207A1 · Reybok, Jr. et al. · 2018 [cited by applicant]
US 20180351783A1 · Patrich et al. · 2018 [cited by applicant]
US 20180359264A1 · Sweet et al. · 2018 [cited by applicant]
US 20190014086A1 · Meyer · 2019 [cited by examiner]
US 20190050563A1 · Sander · 2019 [cited by examiner]
US 20190081963A1 · Waghorn · 2019 [cited by examiner]
US 20190098037A1 · Shenoy, Jr. · 2019 [cited by examiner]
US 20190141058A1 · Hassanzadeh et al. · 2019 [cited by applicant]
US 20190222604A1 · Vaidya · 2019 [cited by examiner]
US 20190238583A1 · Vaidya · 2019 [cited by examiner]
US 20190245883A1 · Gorodissky · 2019 [cited by examiner]
US 20190245894A1 · Epple · 2019 [cited by examiner]
US 20190260776A1 · Zargar · 2019 [cited by examiner]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20190342307A1 · Gamble et al. · 2019 [cited by applicant]
US 20190342324A1 · Nawy · 2019 [cited by examiner]
US 20190347423A1 · Sanossian · 2019 [cited by examiner]
US 20200014711A1 · Rego et al. · 2020 [cited by applicant]
US 20200045069A1 · Nanda et al. · 2020 [cited by applicant]
US 20200097663A1 · Sato et al. · 2020 [cited by applicant]
US 20200134175A1 · Marwah et al. · 2020 [cited by applicant]
US 20200135049A1 · Atencio et al. · 2020 [cited by applicant]
US 20200137104A1 · Hassanzadeh et al. · 2020 [cited by applicant]
US 20200143052A1 · Mazumder · 2020 [cited by examiner]
US 20200177608A1 · Okunlola · 2020 [cited by examiner]
US 20200177615A1 · Grabois et al. · 2020 [cited by applicant]
US 20200177617A1 · Hadar et al. · 2020 [cited by applicant]
US 20200177619A1 · Hadar · 2020 [cited by examiner]
US 20200220885A1 · Will et al. · 2020 [cited by applicant]
US 20200314118A1 · Levin et al. · 2020 [cited by applicant]
US 20200314141A1 · Vajipayalula et al. · 2020 [cited by applicant]
US 20200358804A1 · Crabtree et al. · 2020 [cited by applicant]
US 20210029144A1 · Merza · 2021 [cited by examiner]
US 20210092152A1 · Satish · 2021 [cited by examiner]
US 20210112092A1 · Chen · 2021 [cited by examiner]
US 20210117544A1 · Kurtz · 2021 [cited by examiner]
US 20210224385A1 · Ross · 2021 [cited by examiner]
US 20210409426A1 · Engelberg et al. · 2021 [cited by applicant]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
US 20250167975A1 · Badrinarayanan · 2025 [cited by examiner]
US 20250175913A1 · . · 2025 [cited by examiner]
Wikipedia, Tactics, Techniques and Procedures (TTP), https://en.wikipedia.org/wiki/Terrorist_Tactics,_Techniques,_and_Procedures, last updated Sep. 30, 2019. [cited by applicant]
Azeria, Tactics, Techniques and Procedures (TTP), https://azeria-labs.com/tactics-techniques-and-procedures-ttps/, 2017. [cited by applicant]
The Mitre Corporation, Att&ck Matrix, Defines commonly known adversarial behavior (TTPs), https://attack.mitre.org/, 2015. [cited by applicant]
The Mitre Corporation, Pre-Att&ck Matrix: Subset of Att&ck Matrix focusing on TTPs related to steps taken “before” launching an attack, https://attack.mitre.org/matrices/pre/, 2015. [cited by applicant]
The Mitre Corporation, Att&ck Matrix for Enterprise: Subset of Att&ck Matrix focusing on TTPs related to steps taken “during” an attack, primarily targeting enterprise users, https://attack.mitre.org/matrices/enterprise… [cited by applicant]
The Mitre Corporation, Att&ck Matrix Matrices for Mobile: Subset of Att&ck Matrix focusing on TTPs related to steps taken “during” an attack, primarily focusing on mobile users, https://attack.mitre.org/matrices/mobile/… [cited by applicant]
Wikipedia, Cyber Kill Chain: Refers to sequence of tactics used by adversaries to achieve a goal. Multiple definitions from different sources but we are following Att&ck Matrix as it is the most verbose, https://en.wiki… [cited by applicant]
Wikipedia, The Unified Kill Chain: Refers to sequence of tactics used by adversaries to achieve a goal. Multiple definitions from different sources but we are following Att&ck Matrix as it is the most verbose, https://e… [cited by applicant]