Attack analysis device, attack analysis method, and attack analysis program
The attack analysis device dynamically adjusts analysis priorities based on cyberattack content and impact, addressing the inefficiencies of existing honeypot analysis by prioritizing devices likely to be targeted, thereby enhancing the efficiency of cyber threat response.
Patent Information
- Application Number
- DE112023006285
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-06-27
- Publication Date
- 2026-02-26
AI Technical Summary
Honeypots receive a large volume of cyberattack communications, making chronological analysis time-consuming and labor-intensive, and existing methods fail to prioritize analysis based on the impact of cyberattacks on devices.
An attack analysis device that adjusts analysis priorities dynamically based on the content and impact of cyberattacks, using an analysis priority change unit to prioritize devices likely to be targeted or vulnerable.
Enables efficient, prioritized analysis of high-priority cyberattacks by adjusting priorities according to the content and potential impact of attacks, allowing quicker response to critical threats.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Technical field
[0001] The present disclosure relates to an attack analysis device, an attack analysis method and an attack analysis program. State of the art
[0002] A honeypot is a system that attracts cyberattacks by publishing a terminal on the internet that is intentionally set up to be vulnerable to attacks and observing and analyzing the attracted cyberattacks.
[0003] Honeypots typically receive a large volume of attack communications, so analyzing these communications can take some time. Attack communications are those that indicate cyberattacks. However, if a cyberattack is observed that has a significant impact on a product, it must be analyzed quickly in order to take immediate countermeasures. Reference list patent literature
[0004] Patent Literature 1: JP2022-191649 A Summary of the invention: Technical problem
[0005] A honeypot, which simulates a system, continuously receives a large volume of cyberattack communications. Furthermore, some cyberattacks consist of multiple phases, such as "gathering information and then launching another cyberattack." Therefore, analyzing all cyberattacks in chronological order would be extremely time-consuming and labor-intensive.
[0006] Patent literature 1 discloses a technique for calculating the priority of a cyberattack based on a time-dependent parameter and a non-time-dependent parameter. However, this technology neither uses analysis priorities created taking into account the impact of a cyberattack on a product, nor does it modify the analysis priorities according to the content of an observed cyberattack. Therefore, this technology suffers from the limitation that it cannot perform a prioritized analysis of a cyberattack on a device with a high analysis priority.
[0007] One objective of the present disclosure is to enable prioritized analysis of a high-priority cyberattack on a device by using analysis priorities created taking into account the impact of a cyberattack on a product and by changing the analysis priorities according to the content of an observed cyberattack. Solution to the task
[0008] An attack analysis device according to the present disclosure comprises: an analysis priority change unit for changing an analysis priority according to a target device according to the content of a targeted attack when the target device is exposed to the targeted attack, which is a cyberattack, wherein the target device is a device available to an attack targeting system comprising a plurality of devices, each of which is assigned an analysis priority, where, assuming that the multitude of devices available to the target system constitute a target device group, and the devices contained in the target device group are subject to cyberattacks, the cyberattacks against the devices contained in the target device group are analyzed according to the analysis priorities corresponding to the devices contained in the target device group. Advantageous effects of the invention
[0009] According to the present disclosure, an analysis priority change unit modifies analysis priorities according to the content of a cyberattack. Here, the analysis priorities can be set taking into account the impact of the cyberattack on a product. Therefore, the present disclosure enables, by using analysis priorities created considering the impact of a cyberattack on a product and by modifying the analysis priorities according to the content of an observed cyberattack, a prioritized analysis of a cyberattack on a device with a high analysis priority. Brief description of the drawings Fig. Figure 1 is a representation that shows an example of a configuration of an attack analysis system 90 according to embodiment 1. Fig. Figure 2 is a representation describing the processing of an analysis priority change unit 130 according to embodiment 1, wherein (a) Example 1 and (b) Example 2 are illustrated. Fig. Figure 3 is a representation illustrating an example of a hardware configuration of an attack analysis device 100 according to embodiment 1. Fig. Figure 4 is a flowchart illustrating the processing of an asset information creation unit 120 according to embodiment 1. Fig. Figure 5 is a representation showing specific examples of data stored in an asset database 191 according to embodiment 1. Fig. Figure 6 is a representation showing specific examples of data stored in a database 192 with related information according to embodiment 1. Fig. Figure 7 is a flowchart illustrating the processes of the attack analysis system 90 according to embodiment 1. Fig. Figure 8 is a representation showing specific examples of data stored in an attack information database 190 according to embodiment 1. Fig. Figure 9 is a representation that describes the processing of an analysis priority change unit 130 according to embodiment 1. Fig. Figure 10 is a representation showing an example of a hardware configuration for an attack analysis device 100 according to a modification of embodiment 1. Fig. Figure 11 is a representation that shows an example of a configuration of an attack analysis system 90 according to embodiment 2. Fig. Figure 12 is a representation showing specific examples of data stored in an asset database 191 according to embodiment 2. Fig. Figure 13 is a representation showing specific examples of data stored in a vulnerability information database 193 according to embodiment 2. Fig. Figure 14 is a flowchart illustrating the processes of the attack analysis system 90 according to embodiment 2. Fig. Figure 15 is a representation showing specific examples of data stored in an attack information database 190 according to embodiment 2. Fig. Figure 16 is a representation describing the processing of an analysis priority change unit 130 according to embodiment 2. Description of exemplary implementations
[0010] In the embodiments and drawings, the same elements and equivalent elements are designated by the same reference numerals. Descriptions of elements with the same reference numerals are omitted or simplified where appropriate. Arrows in the illustrations mainly indicate data flows or processing sequences. The term "unit" may also be replaced by "circuit," "stage," "method," "process," or "circuits."
[0011] In this patent application, a cyberattack can simply be referred to as an "attack". Example 1.
[0012] The present embodiment is described in detail below with reference to the drawings. *** Configuration Description ***
[0013] Fig. Figure 1 shows a configuration example of an attack analysis system 90 according to the present embodiment. The attack analysis system 90, as shown in Fig. Figure 1 is equipped with an attack analysis device 100, a honeypot 200, and an external security firm 300. The elements of the attack analysis system 90 are interconnected in such a way that communication via a network is possible.
[0014] The Attack Analysis System 90 uses means to determine the priority of the attack analysis according to an analysis priority corresponding to each device when an attack is observed in Honeypot 200. In the Attack Analysis System 90, an attack consisting of multiple phases is effectively analyzed by changing the analysis priority corresponding to a device likely to be attacked in the future, based on the attack analysis.
[0015] As a concrete example, assume that device 1 contains important information and therefore has a relatively high analysis priority corresponding to device 1. In this case, an attack on device 1 will be analyzed quickly if device 1 is attacked.
[0016] As another concrete example, let us assume that device 2 does not contain any particularly important information and therefore the analysis priority for device 2 is relatively low. In this case, the priority of a countermeasure against the attack on device 2 is relatively reduced if device 2 is attacked.
[0017] As another concrete example, consider a case where, if information about device 3 has been leaked, a further attack could be carried out based on this leaked information. Therefore, in preparation for the next attack, the analysis priority corresponding to device 3 is relatively increased.
[0018] The attack analysis device 100, as in Fig. Figure 1 shows an attack analysis unit 110, an asset information creation unit 120, and an analysis priority change unit 130. Furthermore, the attack analysis device 100 stores an attack information database (DB) 190, an asset database 191, and a database 192 containing related information.
[0019] The Honeypot 200 is equipped with an attack detection unit 210 and other devices. The devices with which the Honeypot 200 is equipped can be emulators or similar devices. The Honeypot 200 corresponds to an attack target system. The Honeypot 200 can also be a system corresponding to a product. The term "device" can be interpreted as "terminal." The attack target system comprises several devices, each with an assigned analysis priority. If the devices belonging to an attack target device group are subjected to cyberattacks, the cyberattacks on the devices belonging to the attack target device group are analyzed according to the analysis priorities assigned to the devices belonging to the attack target device group. The attack target device group consists of several devices with which the attack target system is equipped.
[0020] The attack analysis system 90 can include a system that is currently operating as a target system instead of the honeypot 200. That is, the present embodiment can be used as a technology employed in a security analysis product for a currently operational system.
[0021] The Attack Analysis Unit 110 analyzes attacks on the devices equipped with the Honeypot 200 and stores data indicating the results of the analysis as attack information in the Attack Information Database 190. In this specific example, the Attack Analysis Unit 110 analyzes a communication protocol to determine what type of attack was carried out, from where, and against which end device. The Attack Analysis Unit 110 can also analyze information stolen during the attack, as well as anomalies and other findings in each device caused by the attack.
[0022] Asset Information Creation Unit 120 creates Asset Database 191.
[0023] When a target device is subjected to a targeted attack, the Analysis Priority Change Unit 130 modifies an analysis priority corresponding to the target device, based on the content of the targeted attack. The target device is a device with which the attack target system is equipped. The targeted attack is a cyberattack. When the target device is subjected to the targeted attack, the Analysis Priority Change Unit 130 can modify an analysis priority corresponding to the target device according to the importance of the data stored in the target device. The Analysis Priority Change Unit 130 can also modify an analysis priority corresponding to any device among the multiple devices provided in the attack target system that is likely to be subjected to an attack based on information stolen during the targeted attack.The stolen information is information that was accessed without authorization.
[0024] As a concrete example, the analysis priority change unit 130 consults the attack information database 190, the asset database 191, and the database 192 for related information as needed to change the analysis priority for each device. Since the number of attacks on honeypot 200 is typically very high, the attacks to be analyzed are limited by setting the analysis priority for each device. The number of devices with a relatively high analysis priority can be determined based on the amount of computing resources, the time that can be spent on attack analysis, and other factors.
[0025] The Attack Information Database 190 stores data representing attack information.
[0026] The asset database DB 191 stores data that identifies assets. As a concrete example, the assets can consist of the devices and the data stored on the devices.
[0027] Database 192, containing related information, stores data that identifies assets. The related information is information that pertains to the assets.
[0028] The attack detection unit 210 detects attacks on the devices with which the honeypot 200 is equipped and notifies the attack analysis device 100 of the results of the detected attacks.
[0029] Fig. Figure 2 is a diagram that describes a concrete example of how to process the analysis priority change unit 130. Here, each client corresponds to a device and each server to a device. It should be noted that before an attack is detected on any device, the analysis priority for each client is set to "low" and the analysis priority for each server is set to "medium".
[0030] Fig. Figure 2 shows (a) a specific example where account information of a service has been leaked due to an attack from a client 1. In this example, the service in question runs on a server 1, so the analysis priority change unit 130 increases the analysis priority for server 1 because there is a high probability that an unauthorized login to server 1 will occur in the future.
[0031] Fig. Figure 2 (b) shows a specific example where address information (path information) of a file server has been leaked due to an attack from Client 1. In this example, the file server in question is running on Server 2, so the Analysis Priority Change Unit 130 increases the Analysis Priority corresponding to Server 2 because there is a high probability of an unauthorized login attempt to Server 2 in the future. If document data has been stolen, Analysis Priority Change Unit 130 may determine that there will be no future attacks based on the stolen document data and that it may not be necessary to change the Analysis Priority for each device.
[0032] Fig. Figure 3 shows an example of a hardware configuration of the attack analysis device 100 according to the present embodiment. The attack analysis device 100 is formed by a single computer. The attack analysis device 100 could consist of multiple computers.
[0033] The attack analysis device 100, as in Fig. Figure 3 shows a computer equipped with hardware such as a processor 11, a memory unit 12, an auxiliary storage device 13, an input / output interface (IF) 14, and a communication device 15. These hardware components are appropriately connected via a signal line 19.
[0034] The processor 11 is an IC (integrated circuit) that performs arithmetic processing and controls the hardware contained in the computer. The processor 11 can be, for example, a CPU (Central Processing Unit), a DSP (Digital Signal Processor), or a GPU (Graphics Processing Unit).
[0035] The attack analysis device 100 can comprise a variety of processors as an alternative to processor 11. These multiple processors share the tasks of processor 11.
[0036] Memory unit 12 is typically a volatile storage device, such as RAM (Random Access Memory). Memory unit 12 is also referred to as the main storage device or primary working memory unit. The data stored in memory unit 12 is stored in auxiliary storage device 13 as needed.
[0037] The auxiliary storage device 13 is typically a non-volatile storage device, such as a ROM (Read Only Memory), an HDD (Hard Disk Drive), or flash memory. The data stored in the auxiliary storage device 13 is written to the storage unit 12 as needed.
[0038] The storage unit 12 and the auxiliary storage device 13 can be configured as one unit.
[0039] Input / Output IF 14 is a connector used to connect input and output devices. For example, Input / Output IF 14 is a USB (Universal Serial Bus) connector. Input devices could include a keyboard and mouse, and output devices could include a display.
[0040] The communication device 15 is a receiver / transmitter. The communication device 15 could, as a concrete example, be a communication chip or a NIC (Network Interface Card).
[0041] Each part of the attack analysis device 100 can use the input / output IF 14 and the communication device 15 appropriately when communicating with other devices and the like.
[0042] Auxiliary storage device 13 stores an attack analysis program. The attack analysis program is a program that instructs the computer to implement a function of each unit contained in the attack analysis device 100. The attack analysis program is loaded into memory unit 12 and executed by processor 11. The function of each unit contained in the attack analysis device 100 is implemented by software.
[0043] The data used to execute the attack analysis program, the data obtained through the execution of the attack analysis program, etc., are properly stored in a storage device. Each unit of the attack analysis device 100 utilizes the storage device appropriately. As a specific example, the storage device consists of at least one storage unit 12, an auxiliary storage device 13, a register in the processor 11, and a cache memory in the processor 11. It should be noted that the terms "data" and "information" can have the same meaning. The storage device can be independent of the computer.
[0044] The functions of the storage unit 12 and the auxiliary storage device 13 can be implemented by another storage device.
[0045] The attack analysis program can be stored on a computer-readable, non-volatile recording medium. A concrete example of such a medium is an optical disc or flash memory. The attack analysis program can be provided as a software product. *** Description of a Functional Function ***
[0046] The functional sequence of the attack analysis device 100 corresponds to an attack analysis procedure. Furthermore, a program that implements the operation of the attack analysis device 100 corresponds to the attack analysis program.
[0047] Fig. Figure 4 is a flowchart showing an example of processing by Asset Information Creation Unit 120 during the preparation phase. Referring to Fig. Section 4 describes the processing by the Asset Information Creation Unit 120. (Step S101)
[0048] The Asset Information Creation Unit 120 generates each of the Asset Database 191 and the Database 192 containing related information. Depending on the type of information, the Asset Information Creation Unit 120 can create multiple databases as single databases.
[0049] Fig. Figure 5 shows specific examples of the data stored in Asset Database 191. In this example, the asset information consists of information specifying devices, information specifying the device configurations, information specifying the data stored by the devices, and information specifying the analysis priorities corresponding to the devices. Asset Information Creation Unit 120 stores the asset information in Asset Database 191. Furthermore, Asset Information Creation Unit 120 sets analysis priorities corresponding to the devices and stores these set analysis priorities in Asset Database 191. The analysis priorities can be set by an analyst or similar entity. These analysis priorities can be set taking into account the potential impact of a cyberattack on the product.
[0050] Fig. Figure 6 shows specific examples of data stored in database 192 with related information. Database 192_1 with related information contains related information about the account information. Database 192_2 with related information shows related information about the file server address.
[0051] When the data stored by each device is shared with other devices, the Asset Information Creation Unit stores 120 pieces of information specifying the shared data in database 192 with related information.
[0052] Fig. Figure 7 is a flowchart illustrating an example of the processing of the Attack Analysis System 90 during operation. Referring to Fig. Section 7 describes the processing of the attack analysis system 90. (Step S111)
[0053] The attack detection unit 210 detects attacks on the honeypot 200 and sends data indicating the detected attacks to the attack analysis device 100. (Step S112)
[0054] The attack analysis unit 110 receives data from honeypot 200 indicating the attacks, and by analyzing the log of each attack indicated by the received data, identifies data that was accessed without authorization by each attack, and stores data indicating the identified data in the attack information database 190.
[0055] Subsequently, based on the asset information stored in the asset database 191, which corresponds to an unauthorized access target in each attack, the attack information from the external security firm 300, etc., the attack analysis unit 110 determines the probability of a future attack. The attack analysis unit 110 stores data indicating the results of this determination in the attack information database 190.
[0056] Fig. Figure 8 shows specific examples of data stored in the attack information database 190. For each attack, the data shows the targeted device, the data accessed without authorization, and the likelihood of a future attack.
[0057] It should be noted that in Asset Database 191, it is possible to predetermine for each piece of information whether or not there is a future probability of an attack. As a specific example, Asset Database 191 contains information indicating that an attack is likely in the future against the information displaying the account. If, at that time, unauthorized access occurs to information displaying the account, the Attack Analysis Unit 110 determines that there is a probability of a future attack on a device corresponding to the information displaying the account. (Step S113)
[0058] If an attack is identified as possible in the future in attack information database 190, step S114 is executed next. Otherwise, step S116 is executed next. (Step S114)
[0059] The Analysis Priority Change Unit 130 extracts from the database 192 with related information another device that shares data which has been illicitly accessed by the attack specified in the attack information database 190, which may occur in the future. Fig. Figure 8 shows that the attacks specified in attack information database 190 for possible future execution are unauthorized access to account information of service X and unauthorized access to address information of server 2.
[0060] As a concrete example, the account information of service X for a customer 1, which is in Fig. Figure 8 shows data used in Server 1, as shown in database 192_1 with related information. Therefore, the analysis priority change unit 130 determines that there is a probability that Server 1 will be attacked in the future.
[0061] As another concrete example, the address information of the [company name] is [example]. Fig. The data shown for Server 2, used to access the file server within Server 2, as represented in database 192_2 with related information, is therefore determined by the analysis priority change unit 130, indicating a probability that Server 2 will be attacked in the future. (Step S115)
[0062] The Analysis Priority Change Unit 130 changes, as needed, the analysis priority corresponding to a device exposed to any attack identified in the Attack Information Database 190 as possibly occurring in the future, and the analysis priority corresponding to any device extracted from the Database 192 containing related information in step S114.
[0063] Fig. 9 is a representation that shows the Fig. 5, Fig. 6 and Fig. 8 corresponds and describes concrete examples of the processing to change the analysis priority.
[0064] As a concrete example, Client 1 corresponds to the device exposed to an attack that was defined in the attack information database 190 for a potential future incident. Therefore, the analysis priority change unit 130 increases the analysis priority for Client 1. Furthermore, Server 1 runs Service X, which uses the account information leaked as a result of the attack on Client 1. Therefore, the analysis priority change unit 130 also increases the analysis priority for Server 1.
[0065] As another concrete example, the analysis priority change unit 130 increases the analysis priority according to Client 1, which was accessed without authorization, and the analysis priority according to Server 2, which can be accessed using the address information leaked as a result of the attack on Client 1. (Step S116)
[0066] If the attack analysis system 90 continues attack monitoring, step S111 is executed again. Otherwise, the attack analysis system 90 terminates processing this flowchart.
[0067] Additionally, the Analysis Priority Change Unit 130 can change the analysis priority as needed. For example, if the risk of a potential future attack on a particular device is reduced due to the implementation of countermeasures for that device, the Analysis Priority Change Unit 130 will revert the analysis priority for that device back to its original value. *** Description of the effect of embodiment 1 ***
[0068] According to the present embodiment, it is possible to use an analysis priority that is set according to the target content and to change the analysis priority according to the content of the attack. By setting an analysis priority for each device that is the target of the attack analysis, the attack analysis can be made more efficient. Furthermore, by changing the analysis priority according to the attack content, it is possible to determine the analysis priority and the countermeasure priority according to the attack situation.
[0069] By using the present embodiment, it is possible to prioritize the analysis of an attack on a device with a comparatively high analysis priority among the several observed attacks.
[0070] Furthermore, according to the present embodiment, it is possible to change the analysis priority according to the device that is likely to be the target of an attack if, based on an observed attack, a device is identified that is likely to be the target of a future attack. Therefore, according to the present embodiment, it is possible to manage an attack consisting of several stages, for example, by carrying out one attack and then carrying out another attack, using the previous attack as a starting point. As a specific example regarding an attack consisting of several phases, orThe stages, such as "collecting information and then carrying out another attack," in a phase where it is determined that information is being collected, the analysis priority for a device that may be the target of an attack in the next phase is increased, so that if the device is then hit by the attack in the next phase, the attack on that device can be quickly analyzed. *** Other Configurations ***< Modification 1 >
[0071] Fig. Figure 10 shows an example of the hardware configuration of an attack analysis device 100 according to the present modification.
[0072] The attack analysis device 100 comprises a processing circuit 18 instead of: a processor 11; a processor 11 and a memory unit 12; a processor 11 and an auxiliary storage device 13; or a processor 11, a memory unit 12 and an auxiliary storage device 13.
[0073] The processing circuit 18 is a piece of hardware that implements at least some of the units with which the attack analysis device 100 is equipped.
[0074] The processing circuit 18 can be dedicated hardware or a processor that executes a program stored in the memory unit 12.
[0075] If the processing circuit 18 is dedicated hardware, then the processing circuit 18 is, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or a combination of these.
[0076] As an alternative to processing circuit 18, the attack analysis device 100 can include multiple processing circuits. These multiple processing circuits share the role of processing circuit 18.
[0077] In the attack analysis device 100, some of the functions can be implemented by dedicated hardware, and the remaining functions can be implemented by software or firmware.
[0078] The processing circuit 18 is implemented as a concrete example by hardware, software, firmware or a combination thereof.
[0079] The processor 11, the memory unit 12, the auxiliary storage device 13, and the processing circuit 18 are collectively referred to as the "processing circuit." That is, the functions of the function-defining elements of the attack analysis device 100 are implemented by a processing circuit.
[0080] The attack detection device 100 according to a further embodiment can also have a similar configuration to the present modification. Example 2.
[0081] The following describes situations that differ from the embodiment described above, with reference to the drawings. *** Configuration Description ***
[0082] Fig. Figure 11 shows a configuration example of an attack analysis system 90 according to the present embodiment. An attack analysis device 100 according to the present embodiment further stores a vulnerability information database 193, as shown in Fig. Figure 11 shows that the attack analysis device 100 can store a database 192 containing related information.
[0083] The attack analysis device 100 according to the present embodiment has a function for changing the analysis priority of another device with the same vulnerability when each device in the honeypot 200 is exploited and attacked due to its vulnerability. A concrete example: If an attack is detected that exploits the vulnerability of software a installed on client 1, it is assumed that client 2, on which the same software a is installed, is likely to be attacked in the future, so the analysis priority for client 2 is increased.
[0084] When a targeted attack is caused by a targeted vulnerability, an analysis priority change unit 130 according to the present embodiment changes an analysis priority corresponding to each device exhibiting the targeted vulnerability among a plurality of devices available to an attack targeting system that are not the target device. The target vulnerability is a vulnerability in the target device.
[0085] The vulnerability information database 193 stores information that provides insight into the vulnerabilities of devices, software, etc. *** Description of a Functional Function ***
[0086] The following describes the differences in the processing of an Asset Information Creation Unit 120 during preparation compared to embodiment 1. (Step S101)
[0087] In addition to a process according to step S101 according to embodiment 1, the asset information creation unit 120 performs the following processing.
[0088] In addition to asset information, the Asset Information Creation Unit 120 stores information about the versions of each FW (Firmware) and the versions of each SW (Software) installed on each device in the Asset Database 191. Fig. Figure 12 shows specific examples of data stored in an asset database 191.
[0089] In addition, the Asset Information Creation Unit 120 creates the Vulnerability Information Database 193 based on information from an external security firm 300. Fig. Figure 13 shows specific examples of data stored in the vulnerability information database 193. The data shows the vulnerabilities of the firmware and software, by version, installed on each device.
[0090] Fig. Figure 14 is a flowchart illustrating an example of the processing of the attack analysis system 90 during operation. Referring to Fig. Section 14 describes the processing of the attack analysis system 90. In addition to the processing of the attack analysis system 90 according to embodiment 1, the attack analysis system 90 can also perform the following processing. (Step S212)
[0091] An attack analysis unit 110 receives data from the honeypot 200 indicating the attacks, and by analyzing the log of each attack indicated by the received data, identifies data that was accessed without authorization by each attack access, and stores data indicating the identified data in an attack information database 190.
[0092] Subsequently, based on the asset information stored in the asset database 191, which corresponds to an unauthorized access target in each attack, as well as the attack information from the external security firm 300, etc., the attack analysis unit 110 identifies a vulnerability that was exploited in each attack. The attack analysis unit 110 stores data indicating the results of this identification in the attack information database 190.
[0093] Fig. Figure 15 shows specific examples of data stored in the attack information database 190. (Step S213)
[0094] The analysis priority change unit 130 refers to the attack information database 190 and the vulnerability information database 193 to determine whether a vulnerability identified by the attack analysis unit 110 also exists in another device.
[0095] If it is determined that the vulnerability exists in another device, step S214 is executed next. Otherwise, step S116 is executed next. (Step S214)
[0096] The analysis priority change unit 130 refers to the attack information database 190 and the vulnerability information database 193 and extracts another device with the vulnerability identified by the attack analysis unit 110 as a related device.
[0097] As in Fig. 13 and Fig. As shown in Figure 15, for example, the software loaded on Client 1 was exploited due to its vulnerability and accessed without authorization. Furthermore, software a, which is identical to the version loaded on Client 1, is also loaded on Client 2. Therefore, Analysis Priority Change Unit 130 determines that Client 2 might be subject to a similar attack in the future as the attack on Client 1 and extracts Client 2 as a related device. (Step S215)
[0098] The analysis priority change unit 130 changes, if necessary, the analysis priority corresponding to each associated device extracted in step S214.
[0099] Fig. 16 is a representation that shows the Fig. 12, Fig. 13 and Fig.15 corresponds to and describes concrete examples of the processing for changing the analysis priority. In this example, the analysis priority change unit 130 increases the analysis priority of Client 1, which was accessed without authorization, as well as the analysis priority of Client 2, which has the same vulnerability as Client 1, which was accessed without authorization. *** Description of the effect of embodiment 2 ***
[0100] According to the present embodiment, the analysis priority corresponding to each device with the same vulnerability as the vulnerability of the attacked target device can be increased before an attack on that device is observed. *** Other versions ***
[0101] The above-mentioned embodiments can be freely combined; any component of each embodiment can be modified; or any component of each embodiment can be omitted.
[0102] Furthermore, the embodiments are not limited to those shown in embodiments 1 and 2, and various modifications can be made as needed. The procedures described using flowcharts, etc., can be modified accordingly. Reference symbol list
[0103] 11: Processor; 12: Memory unit; 13: Auxiliary storage device; 14: Input / output interface; 15: Communication device; 18: Processing circuit; 19: Signal line; 90: Attack analysis system; 100: Attack analysis device; 110: Attack analysis unit; 120: Asset information creation unit; 130: Analysis priority change unit; 190: Attack information database; 191: Asset database; 192: Related information database; 193: Vulnerability information database; 200: Honeypot; 210: Attack detection unit; 300: External security firm. QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] JP 2022-191649 A
[0004]
Claims
[1] Attack analysis device comprising: an analysis priority change unit for changing an analysis priority according to a target device according to the content of a targeted attack when the target device is exposed to the targeted attack, which is a cyberattack, wherein the target device is a device available to an attack targeting system comprising a plurality of devices, each of which is provided with an analysis priority, where, assuming that the multitude of devices available to the target system constitute a target device group, and the devices contained in the target device group are subject to cyberattacks, the cyberattacks against the devices contained in the target device group are analyzed according to the analysis priorities corresponding to the devices contained in the target device group. [2] Attack analysis device according to claim 1, wherein, when the target device is subjected to a targeted attack, the analysis priority change unit changes an analysis priority according to the target device according to the meaning of the data stored in the target device. [3] Attack analysis device according to claim 1 or 2, wherein the analysis priority change unit changes an analysis priority according to each device among the plurality of devices available to the target system which is likely to be subject to an attack carried out on the basis of information stolen in the targeted attack. [4] Attack analysis device according to any one of claims 1 to 3, wherein, when the targeted attack is caused by a target vulnerability which is a vulnerability of the target device, the analysis priority change unit changes an analysis priority which is assigned to each device with this target vulnerability among the plurality of devices available to the attack target system which are not the target device. [5] Attack analysis device according to any one of claims 1 to 4, wherein the attack target system is a honeypot. [6] Attack analysis procedures, which include: Changing an analysis priority corresponding to a target device by a computer, according to the content of a targeted attack, when the target device is subjected to a targeted attack in the form of a cyberattack, wherein the target device is a device available to an attack targeting system comprising a plurality of devices, each assigned an analysis priority, where, assuming that the multitude of devices available to the target system constitute a target device group, and the devices contained in the target device group are subject to cyberattacks, the cyberattacks against the devices contained in the target device group are analyzed according to the analysis priorities corresponding to the devices contained in the target device group. [7] Attack analysis program that causes an attack analysis device, which is a computer, to execute, an analysis priority change process for changing an analysis priority according to a target device according to the content of a targeted attack when the target device is exposed to the targeted attack, which is a cyberattack, wherein the target device is a device available to an attack targeting system comprising a plurality of devices, each assigned an analysis priority, where, assuming that the multitude of devices available to the target system constitute a target device group, and the devices contained in the target device group are subject to cyberattacks, the cyberattacks against the devices contained in the target device group are analyzed according to the analysis priorities corresponding to the devices contained in the target device group.
Citation Information
Patent Citations
Cybersecurity management device, cybersecurity management method and cybersecurity management system
JP2022191649A