IP Library › Granted Patent US 12,726,489
Granted Patent B2
US 12,726,489 · App. 18/074,919 · Granted Sep 1, 2026

Attack risk assessment system of an advanced persistent threat and the operation method

Inventors: Seok Won Lee (Suwon-si, KR); Sihn Hye Park (Suwon-si, KR)
Assignee: AJOU UNIVERSITY INDUSTRY-ACADEMIC COOPERATION FOUNDATION
H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,489
App. No.
18/074,919
Granted
Sep 1, 2026
Kind
B2
Abstract

Provided is an operation method of an attack risk assessment system, which includes: extracting, when an advanced persistent threat attack is detected, an attack component for the advanced persistent threat attack based on risk-aware problem domain ontology for assessing a security risk for an attack; identifying a risk component based on the attack component; deriving a security requirement by a goal based access scheme set for the risk component; and assessing the security risk based on an evidence set through a relationship between a domain asset identified as the risk component and the security requirement.

Claims (45)

1 . An operation method of an attack risk assessment system, the operation method comprising:

extracting, by an attack component extraction processor, when an advanced persistent threat (APT) attack is detected, an attack component of the APT attack based on risk-aware problem domain ontology for assessing a security risk of an attack;

identifying, by a risk element identification processor, a risk component based on the attack component of the APT attack;

deriving, by a security requirement derivation processor, a security requirement corresponding to the risk component using a threat element of the risk component;

identifying, by a domain asset identification processor, specific domain asset influenced by the APT attack by using the risk component;

assessing, by a security risk assessment processor, the security risk by assessing a relationship between the specific domain asset and the security requirement based on predetermined evidence, to produce an assessment result of the security risk;

storing, by the security risk assessment processor, the attack component, the risk component, the security requirement, and the assessment result of the security risk in at least one of ontology server and database server; and

utilizing the attack component, the risk component, the security requirement, and the assessment result of the security risk to defend the APT attack,

wherein, in the assessing the security risk by assessing the relationship between the specific domain asset and the security requirement based on the predetermined evidence, a degree of the security risk is calculated based on a level of satisfaction of the specific domain asset for the security requirement according to information specified in the predetermined evidence, and the degree of security risk decreases as the level of satisfaction of the specific domain asset meeting the security requirement increases,

wherein the predetermined evidence includes a degree of the specific domain asset meeting the security requirement, a method for making the specific domain asset to meet the security requirement, a method for achieving a security goal, and a method for defending against a malicious goal,

wherein domain assets are classified into multiple viewpoints constituting a business process layer, a human layer, a technical layer, and a physical layer,

wherein the attack component includes attack groups, targets, attack goals and tactics, and

wherein the risk-aware problem domain ontology comprises a plurality of analysis models including an attack component model, a risk component model, a security requirement component model, and a domain component model, a plurality of ontologies including domain specified knowledge ontology, APT case knowledge ontology, and general security knowledge ontology.

2 . The operation method of an attack risk assessment system of claim 1 , wherein in the identifying of the risk component, the threat element of the risk component where a security weakness or a vulnerability occurs is identified by using an attack element of the attack component.

3 . The operation method of an attack risk assessment system of claim 1 , wherein the security requirement derived by the security requirement derivation processor meets a malicious goal and a security goal.

4 . The operation method of claim 3 , wherein the security requirement derivation processor identifies the malicious goal and the security goal in the risk component identified by the risk element identification processor.

5 . The operation method of claim 1 , wherein

the business process layer includes information of intangible and tangible activities performed by a corporate, the intangible and tangible activities including corporate management activities that produce services or products for customers,

the human layer includes personal information for a plurality of persons engaging in the corporate, the personal information including personal personnel information, a security degree, and an accessible computing device,

the technical layer includes knowledge technology for producing a product, the knowledge technology including a design technology, a manufacturing technology, and a facility technology for producing the product of the corporate, and

the physical layer includes a computer, a production facility, a manufacturing facility, and a server used by the corporate.

6 . An attack risk assessment system comprising:

an ontology server configured to store risk-aware problem domain ontology specialized for security risk assessment against an advanced persistent threat (APT) attack;

a database server configured to provide information on the APT attack; and

an attack risk assessment apparatus including:

an attack component extraction processor configured to extract an attack component of the APT attack based on the risk-aware problem domain ontology when the APT attack is detected,

a risk element identification processor configured to identify a risk component based on the attack component of the APT attack and information stored in the database server,

a security requirement derivation processor configured to derive a security requirement corresponding to the risk component and meeting a malicious goal and a security goal,

a domain asset identification processor configured to identify specific domain asset influenced by the APT attack by using the risk component, and

a security risk assessment processor configured to:

assess a security risk according to a relationship between the specific domain asset and the security requirement corresponding to the risk component based on predetermined evidence, to produce an assessment result of the security risk,

calculate a degree of the security risk based on a level of satisfaction of the specific domain asset for the security requirement according to the information specified in the predetermined evidence, wherein the degree of security risk decreases as the level of satisfaction of the specific domain asset meeting the security requirement increases,

store the attack component, the risk component, the security requirement, and the assessment result of the security risk in at least one of the ontology server and the database server, and

utilize the attack component, the risk component, the security requirement, and the assessment result of the security risk to defend the APT attack,

wherein the predetermined evidence includes a degree of the specific domain asset meeting the security requirement, a method for making the specific domain asset to meet the security requirement, a method for achieving the security goal, and a method for defending against the malicious goal,

wherein domain assets are classified into multiple viewpoints constituting a business process layer, a human layer, a technical layer, and a physical layer,

wherein the risk-aware problem domain ontology comprises a plurality of analysis models including an attack component model, a risk component model, a security requirement component model, and a domain component model, a plurality of ontologies including domain specified knowledge ontology, APT case knowledge ontology, and general security knowledge ontology, and

wherein the attack component includes attack groups, targets, attack goals and tactics.

7 . The attack risk assessment system of claim 6 , wherein

the business process layer includes information of intangible and tangible activities performed by a corporate, the intangible and tangible activities including corporate management activities that produce services or products for customers,

the human layer includes personal information for a plurality of persons engaging in the corporate, the personal information including personal personnel information, a security degree, and an accessible computing device,

the technical layer includes knowledge technology for producing a product, the knowledge technology including a design technology, a manufacturing technology, and a facility technology for producing the product of the corporate, and

the physical layer includes a computer, a production facility, a manufacturing facility, and a server used by the corporate.

8 . The attack risk assessment system of claim 6 , wherein the security requirement derivation processor identifies the malicious goal and the security goal in the risk component identified by the risk element identification processor.

9 . The attack risk assessment system of claim 6 , wherein the database server uses public knowledge base and threat intelligence managing the information on the APT attack.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE'S NAME PREVIOUSLY RECORDED AT REEL: 61978 FRAME: 700. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Jul 6, 2026
From: LEE, SEOK WON; PARK, SIHN HYE
To: AJOU UNIVERSITY INDUSTRY-ACADEMIC COOPERATION FOUNDATION
Reel/Frame 075993/0070 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2022
From: LEE, SEOK WON; PARK, SIHN HYE
To: AJOU UNIVERSITY INDUSTRY-ACADEMIC COOPERATON FOUNDATION
Reel/Frame 061978/0700 →
Priority Claims (1)
KR 10-2021-0171952 · Dec 3, 2021 · national
Continuity (1)
Related Publication 20230179608A1 · Jun 8, 2023
References Cited (31)
US 6895383B2 · Heinrich · 2005 [cited by examiner]
US 9330262B2 · Salehie · 2016 [cited by examiner]
US 9530016B1 · Pomerantz · 2016 [cited by examiner]
US 11146583B2 · Nhlabatsi · 2021 [cited by examiner]
US 11347843B2 · Suwad · 2022 [cited by examiner]
US 11397808B1 · Prabhu · 2022 [cited by examiner]
US 11683333B1 · Dominessy · 2023 [cited by examiner]
US 11722522B2 · Pandurangi · 2023 [cited by examiner]
US 20070067845A1 · Wiemer · 2007 [cited by examiner]
US 20140090071A1 · Salehie · 2014 [cited by examiner]
US 20140108089A1 · Abercrombie · 2014 [cited by examiner]
US 20140380485A1 · Ayyagari · 2014 [cited by examiner]
US 20160036838A1 · Jain · 2016 [cited by examiner]
US 20160132896A1 · Guerin · 2016 [cited by examiner]
US 20170235848A1 · Van Dusen · 2017 [cited by examiner]
US 20170351980A1 · Binder · 2017 [cited by examiner]
US 20190306719A1 · Chari · 2019 [cited by examiner]
US 20200050986A1 · Vescio · 2020 [cited by examiner]
US 20200201989A1 · Shu · 2020 [cited by examiner]
US 20200267186A1 · Tarameshloo · 2020 [cited by examiner]
US 20230132703A1 · Marsenic · 2023 [cited by examiner]
US 20230222223A1 · Lahmadi · 2023 [cited by examiner]
US 20230231871A1 · Jiao · 2023 [cited by examiner]
CN 107172022A · 2017 [cited by examiner]
CN 112131882A · 2020 [cited by examiner]
CN 113364766A · 2021 [cited by examiner]
HU 227652B1 · 2011 [cited by examiner]
KR 1020070061009A · 2007 [cited by applicant]
KR 101511832B1 · 2015 [cited by applicant]
KR 1020210064857A · 2021 [cited by applicant]
Kim, Bong-Jae, “Understanding and recommending security requirements from problem domain ontology: a three-layered approach” (Master's thesis), The Graduate School, Ajou University (2016) Retrieved from: https://dspace.… [cited by applicant]