Attack path prediction method, attack path prediction device, and program

By automatically generating loose search queries and utilizing trend information, the problems of advanced knowledge requirements and analysis deviations in SOC are solved, and accurate prediction of network attack paths is achieved, cost reduction and analysis accuracy is improved.

CN120344967APending Publication Date: 2025-07-18PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202380084584.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-04-20
Filing Date
2023-10-12
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, SOCs require advanced security knowledge and a large amount of man-hours to analyze cyber attacks, and the analysis results of different operators are biased, so they cannot accurately predict the attack path.

Method used

By obtaining cyber attack event information from the vehicle of the surveillance object, a search query is generated to obtain threat information, and relaxing search conditions when there is insufficient threat information, automatically generating looser queries to obtain more relevant information, and predicting attack paths based on trend information.

Benefits of technology

It realizes that the network attack path can be accurately predicted even under limited threat information, reducing analysis costs and biases, and improving analysis accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120344967A_ABST
    Figure CN120344967A_ABST
Patent Text Reader

Abstract

The attack path prediction method includes: acquiring event information about a network attack on a vehicle (40) to be monitored from a monitor that monitors the vehicle (40) to be monitored (S300); acquiring, on the basis of the event information, one or more pieces of threat information relating to a past network attack on the vehicle (S202); the present invention predicts an attack path for a network attack on a vehicle to be monitored on the basis of one or more pieces of threat information (S205), generates a first search query for acquiring the one or more pieces of threat information on the basis of event information during acquisition of the threat information (S305), and generates a second search query for acquiring the one or more pieces of threat information on the basis of the event information when the number of threat information is less than a predetermined number. A second search query having a looser search condition than the first search query is generated (S305 after S308), and one or more pieces of threat information are acquired using the generated second search query (S306 after S308).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an attack path prediction method, an attack path prediction apparatus, and a program. Background Art

[0002] In recent years, in order to cope with a sharp increase in cyber attacks on IoT (Internet of Things) devices, it has become common to set up an organization called SOC (Security Operation Center), which monitors networks and device equipment 24 hours a day, 365 days a year, detects and analyzes cyber attacks, and provides countermeasure suggestions.

[0003] A database that collects and accumulates a large amount of information on cyber attacks (open source information, vulnerability information, analysis results of malware, information on unauthorized IPs and domains, etc.) for analyzing cyber attacks is called CTI (Cyber Threat Intelligence).

[0004] As a current method of using CTI, it is common for SOC operators to manually create a search query and obtain information related to matching cyber attacks. Creating a search query, selecting and choosing the required information requires advanced security knowledge and a large amount of man-hours. Non-Patent Documents 1 and 2 disclose methods for determining which data the input cyber attack is most relevant to based on pre-defined data. However, cyber attacks are diverse and often do not match the pre-defined data.

[0005] Prior Art Documents

[0006] Non-Patent Documents

[0007] Non-Patent Document 1: MITRE Corporation, Threat Report ATT&CK Mapping (TRAM), 2021.9.30 [searched on April 20, 2023], Internet <URL: https: / / ctid.mitre-engenuity.org / our-work / tram / >

[0008] Non-Patent Document 2: MITRE Corporation, Threat Report ATT&CK Mapping (TRAM), 2021.9.30 [searched on April 20, 2023], Internet <URL: https: / / github.com / center-for-threat-informed-defense / tram> Summary of the Invention

[0009] Problems to be Solved by the Invention

[0010] The use of SOC requires advanced security knowledge and a large amount of operating costs. In addition, there are also cases where multiple SOC operators respectively present different analysis results.

[0011] It is considered that when a cyber attack occurs, if the operator can know information such as how the attacker carried out the cyber attack, to what extent the current system has been invaded or damaged, and what actions the attacker will take next, etc., the deviation of the analysis results between different operators can be reduced, but the current situation is that there is no way to obtain such information.

[0012] Therefore, the present disclosure provides an attack path prediction method, an attack path prediction device, and a program capable of predicting the attack path of a cyber attack.

[0013] Technical Solutions for Solving the Problems

[0014] An attack path prediction method according to one aspect of the present disclosure is a method for predicting the attack path of a cyber attacker, including: obtaining event information about a cyber attack on a monitored vehicle from a monitor who monitors the monitored vehicle; based on the obtained event information, obtaining one or more threat information related to past cyber attacks on vehicles; based on the obtained one or more threat information, predicting the attack path of a cyber attack on the monitored vehicle, in the obtaining of the threat information, generating a first search query for obtaining the one or more threat information based on the event information, and in the case where the number of obtained threat information is less than a predetermined number, further generating a second search query whose search conditions are looser than the first search query based on the event information, and using the generated second search query to obtain the one or more threat information.

[0015] One aspect of the present disclosure relates to an attack path prediction device that predicts the attack path of a network attacker, and includes: a first acquisition unit that acquires event information about a network attack on a monitored vehicle from a monitor who monitors the monitored vehicle; a second acquisition unit that acquires one or more threat information related to past network attacks on vehicles based on the acquired event information; and a prediction unit that predicts the attack path of a network attack on the monitored vehicle based on the acquired one or more threat information. The second acquisition unit generates a first search query for acquiring the one or more threat information based on the event information, and when the number of acquired threat information is less than a predetermined number, further generates a second search query whose search conditions are looser than the first search query based on the event information, and uses the generated second search query to acquire the one or more threat information.

[0016] One aspect of the present disclosure relates to a program for causing a computer to execute the above-described attack path prediction method.

[0017] Advantages of the Invention

[0018] According to one aspect of the present disclosure, an attack path prediction method and the like that can predict the attack path of a network attack can be realized. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 It is a diagram showing the overall structure of an attack path prediction system according to an embodiment.

[0020] Figure 2 It is a block diagram showing the functional structure of a network attack path prediction device according to an embodiment.

[0021] Figure 3 It is a diagram showing an example of event information input by an analyst to a network attack path prediction device according to an embodiment.

[0022] Figure 4 It is a diagram showing an example of threat information stored in a threat information collection server and a threat information sharing server according to an embodiment.

[0023] Figure 5 It is a diagram showing an example of trend information for which a network attack path prediction device according to an embodiment is used to perform trend information analysis.

[0024] Figure 6 It is a timing diagram showing the operation (work) of collecting threat information by a threat information collection server and a threat information sharing server according to an embodiment.

[0025] Figure 7It is a timing chart showing the operations of attack path prediction performed by the attack path prediction device according to the embodiment.

[0026] Figure 8 It is a flowchart showing the operations of input information parsing performed by the input information parsing unit according to the embodiment.

[0027] Figure 9 It is a flowchart showing the operations of trend information parsing performed by the trend information parsing unit according to the embodiment.

[0028] Figure 10 It is a flowchart showing the operations of attack path prediction performed by the attack path prediction unit according to the embodiment.

[0029] Figure 11 It is a diagram showing an overview screen of the analysis result according to the embodiment.

[0030] Figure 12 It is a diagram showing a detailed screen of the analysis result according to the embodiment. Detailed Embodiment

[0031] The attack path prediction method according to the first aspect of the present disclosure is a method for predicting the attack path of a network attacker, including: obtaining event information about a network attack on a monitored vehicle from a monitor who monitors the monitored vehicle; obtaining one or more threat information related to past network attacks on vehicles based on the obtained event information; predicting the attack path of a network attack on the monitored vehicle based on the obtained one or more threat information. In the obtaining of the threat information, a first search query for obtaining the one or more threat information is generated based on the event information. When the number of obtained threat information is less than a predetermined number, a second search query whose search conditions are looser than the first search query is further generated based on the event information, and the one or more threat information is obtained using the generated second search query.

[0032] Thus, when the threat information whose content is consistent with the event information is less than the predetermined number, the search conditions of the search query for obtaining the threat information are relaxed, so that the search range of the threat information can be expanded. That is, the threat information can be obtained more reliably. Therefore, according to the attack path prediction method, even when the threat information whose content is consistent with the event information is small (for example, does not exist), since the threat information whose content is similar to the event information will be obtained, the attack path of the network attack can also be predicted.

[0033] In addition, for example, the attack path prediction method according to the second aspect of the present disclosure can also, based on the attack path prediction method according to the first aspect, extract one or more named entities included in the event information during the acquisition of the threat information, and generate the first search query based on the one or more extracted named entities.

[0034] Thereby, it is possible to automatically generate a search query using named entities.

[0035] In addition, for example, the attack path prediction method according to the third aspect of the present disclosure can also, based on the attack path prediction method according to the second aspect, the event information includes two or more classification items and string information. During the acquisition of the threat information, extract the one or more named entities included in the string information of the event information, weight each of the two or more classification items based on the one or more named entities, and generate the second search query based on the weighted values of the two or more classification items respectively.

[0036] Thereby, a search query corresponding to the weighted value is generated, so that it is possible to obtain threat information that is more similar to the event information and includes information about network attacks. By using this threat information, it is possible to predict a more appropriate attack path. Therefore, it is possible to predict the attack path of a more appropriate network attack.

[0037] In addition, for example, the attack path prediction method according to the fourth aspect of the present disclosure can also, based on the attack path prediction method according to the third aspect, during the acquisition of the threat information, extract one or more classification items other than the classification item with the lowest weighted value among the two or more classification items, and generate the second search query based on the one or more extracted classification items.

[0038] Thereby, when relaxing the search conditions of the search query, the item with the lowest weighted value is excluded. Therefore, even when the search range of the threat information is expanded, it is possible to obtain threat information that is more similar to the event information. Therefore, it is possible to predict the attack path of a more appropriate network attack.

[0039] In addition, for example, the attack path prediction method according to the fifth aspect of the present disclosure can also, based on the attack path prediction method according to the third or fourth aspect, when the string information does not include a named entity, generate the first search query based on a preset weighted value.

[0040] Thereby, even when the event information does not include a named entity, it is possible to automatically generate a search query.

[0041] In addition, for example, the attack path prediction method according to the sixth aspect of the present disclosure can be based on the attack path prediction method according to any one of the first to fifth aspects. The two or more classification items may include at least two of the vehicle type of the monitored vehicle, the current attack path of the cyber attack on the monitored vehicle, the interface that is the entry point of the cyber attack, and the device that is the target of the cyber attack.

[0042] Thereby, threat information with at least two of the vehicle type, attack path, interface, and target can be obtained. By using such threat information, the attack path of a more appropriate cyber attack can be predicted.

[0043] In addition, for example, the attack path prediction method according to the seventh aspect of the present disclosure can be based on the attack path prediction method according to any one of the first to sixth aspects. For each of the one or more pieces of threat information obtained, trend information indicating the prevalence of the cyber attack on the threat information can be obtained, and in the prediction of the attack path of the cyber attack, the attack path of the cyber attack on the monitored vehicle can be further predicted based on the trend information.

[0044] Thereby, the attack path can be predicted considering the prevalence of the cyber attack. Therefore, for example, in the case where the cyber attack occurring on the monitored vehicle is a prevalent cyber attack, the attack path of the cyber attack can be predicted more accurately.

[0045] The attack path prediction device according to the eighth aspect of the present disclosure is a device that predicts the attack path of a cyber attacker, and includes: a first acquisition unit that acquires event information about a cyber attack on a monitored vehicle from a monitor who monitors the monitored vehicle; a second acquisition unit that acquires one or more pieces of threat information related to past cyber attacks on vehicles based on the acquired event information; and a prediction unit that predicts the attack path of the cyber attack on the monitored vehicle based on the acquired one or more pieces of threat information. The second acquisition unit generates a first search query for acquiring the one or more pieces of threat information based on the event information, and when the number of acquired threat information is less than a predetermined number, further generates a second search query whose search condition is looser than the first search query based on the event information, and uses the generated second search query to acquire the one or more pieces of threat information. In addition, the program according to the ninth aspect of the present disclosure is a program for causing a computer to execute the attack path prediction method according to any one of the first to seventh aspects described above.

[0046] Thereby, the same effect as the above-described attack path prediction method is achieved.

[0047] The attack path prediction method according to the tenth aspect of the present disclosure is a method for predicting the attack path of a network attacker, including: obtaining event information about a network attack on a monitored vehicle from a monitor who monitors the monitored vehicle; obtaining one or more threat information related to past network attacks on vehicles based on the obtained event information; obtaining trend information indicating the prevalence of network attacks on each of the one or more obtained threat information; predicting the attack path of a network attack on the monitored vehicle based on the one or more threat information and the trend information of each of the one or more threat information.

[0048] Thereby, it is possible to predict the attack path in consideration of the prevalence of network attacks. Therefore, according to the attack path prediction method, it is possible to predict the attack path of a network attack considering the prevalence of network attacks.

[0049] In addition, for example, the attack path prediction method according to the eleventh aspect of the present disclosure, on the basis of the attack path prediction method according to the tenth aspect, may also, in obtaining the trend information, extract one or more named entities included in the threat information, obtain unique trend information of each of the one or more extracted named entities, and obtain the trend information for the threat information based on the unique trend information of each of the one or more named entities.

[0050] Thereby, it is possible to obtain the trend information of threat information using the unique trend information of named entities.

[0051] In addition, for example, the attack path prediction method according to the twelfth aspect of the present disclosure, on the basis of the attack path prediction method according to the eleventh aspect, may also, in obtaining the unique trend information, obtain a history of the unique trend information of the named entity within a predetermined period, and obtain the unique trend information for the named entity based on the obtained history of the unique trend information.

[0052] Thereby, it is possible to obtain the trend information of threat information using the unique trend information of named entities within a predetermined period.

[0053] In addition, for example, the attack path prediction method according to the thirteenth aspect of the present disclosure, on the basis of the attack path prediction method according to the eleventh aspect or the twelfth aspect, may also include the number of search times in which the named entity is searched for the unique trend information of the named entity.

[0054] Accordingly, threat information containing more searched naming entities can be obtained. That is to say, threat information more similar to the event information can be obtained. By using such threat information, the attack path of a more appropriate cyber attack can be predicted.

[0055] In addition, for example, the attack path prediction method according to the 14th aspect of the present disclosure can also be based on the attack path prediction method according to any one of the 10th to 13th aspects. In the prediction of the attack path, based on the trend information of each of the one or more threat information, a predetermined number of threat information is extracted from the one or more threat information, and the attack path is predicted based on the extracted predetermined number of threat information.

[0056] Accordingly, the threat information used to predict the attack path is selected considering the popularity. Therefore, for example, in the case where the cyber attack on the monitored vehicle is a popular cyber attack, the attack path of a more appropriate cyber attack can be predicted.

[0057] In addition, for example, the attack path prediction method according to the 15th aspect of the present disclosure can also be based on the attack path prediction method according to the 14th aspect. For each of the extracted predetermined number of threat information, it is determined whether the threat information contains attack continuation information indicating the existence of a next (subsequent) cyber attack on the monitored vehicle. Based on at least one of the threat information determined to contain the attack continuation information and the threat information determined not to contain the attack continuation information, the attack path is predicted.

[0058] Accordingly, by using the threat information determined to contain the attack continuation information, the attack path (e.g., the next attack) can be predicted more appropriately. In addition, by using the threat information determined not to contain the attack continuation information, it can be predicted that there is no next attack on the monitored vehicle or the cyber attack has ended.

[0059] The attack path prediction device according to the 16th aspect of the present disclosure is a device that predicts the attack path of a network attacker, and includes: a first acquisition unit that acquires event information about a network attack on the monitored vehicle from a monitor who monitors the monitored vehicle; a second acquisition unit that acquires one or more threat information related to past network attacks on vehicles based on the acquired event information; a third acquisition unit that, for each of the one or more threat information acquired, acquires trend information indicating the prevalence of network attacks against the threat information; and a prediction unit that predicts the attack path of a network attack on the monitored vehicle based on the one or more threat information and the trend information of each of the one or more threat information. In addition, the program according to the 17th aspect of the present disclosure is a program for causing a computer to execute the attack path prediction method shown in any one of the above 10th to 15th aspects.

[0060] Thereby, the same effect as the above-described attack path prediction method is achieved.

[0061] In addition, these general or specific technical solutions can be implemented by a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or can be implemented by any combination of a system, a method, an integrated circuit, a computer program, or a recording medium. The program can be pre-stored in the recording medium or can be supplied to the recording medium via a wide area communication network including the Internet and the like.

[0062] Hereinafter, embodiments will be specifically described with reference to the drawings.

[0063] In addition, the embodiments described below all represent general or specific examples. The numerical values, shapes, constituent elements, arrangement positions and connection forms of the constituent elements, steps, order of steps, etc. shown in the following embodiments are examples and are not intended to limit the present disclosure. In addition, among the constituent elements in the following embodiments, the constituent elements not described in the independent claims are described as optional constituent elements.

[0064] In addition, in this specification, numerical values and numerical ranges are not expressions that only represent strict meanings, but mean substantially equivalent ranges, for example, expressions that also include differences of about a few percent (or about 10%).

[0065] In addition, in this specification, unless otherwise specified, ordinal numbers such as "first" and "second" do not mean the number or order of constituent elements, but are used for the purpose of distinguishing between the same kind of constituent elements to avoid confusion.

[0066] (Embodiment)

[0067] Hereinafter, with reference toFigures 1 to 12 , the attack path prediction method and the like involved in this embodiment will be described.

[0068] [1. Structure of the Attack Path Prediction System]

[0069] First, with reference to Figures 1 to 5 , the structure of the attack path prediction system including the network attack path prediction device involved in this embodiment will be described. Figure 1 FIG. is a diagram showing the overall structure of the attack path prediction system 1 involved in this embodiment. Figure 2 FIG. is a block diagram showing the functional structure of the network attack path prediction device 10 involved in this embodiment.

[0070] As Figure 1 shown, the attack path prediction system 1 includes a network attack path prediction device 10, a threat information collection server 20, and a threat information sharing server 30. The attack path prediction system 1 may also include one or more monitored vehicles 40. The attack path prediction system 1 is an information processing system as follows: when a network attack occurs in the monitored vehicle 40 that is currently the monitoring object of the analyst 50, the attack path of the network attack to be implemented in the monitored vehicle 40 in the future is predicted. In addition, the threat information collection server 20, the threat information sharing server 30, and the monitored vehicle 40 are communicably connected via an external network (for example, the Internet). The analyst 50 is, for example, a SOC operator. In addition, the analyst 50 is an example of a monitor.

[0071] The network attack path prediction device 10 is connected to the threat information collection server 20 and executes a process of predicting the attack path of a network attack based on the information input by the analyst 50. The network attack path prediction device 10 is an example of an attack path prediction device.

[0072] As Figure 2 shown, the network attack path prediction device 10 includes an event information input unit 110, a communication unit 120, an input information analysis unit 130, an analysis result screen output unit 140, a trend information analysis unit 150, and an attack path prediction unit 160. The network attack path prediction device 10 has a CPU (Central Processing Unit) and a memory, etc., and each function of the network attack path prediction device 10 is realized by the CPU executing a program stored in the memory.

[0073] The event information input unit 110 receives data input from the analyst 50, stores each data in a buffer, and outputs it to the input information analysis unit 130. The event information input unit 110 obtains event information regarding a cyber attack on the monitored vehicle 40 from the analyst 50 who monitors the monitored vehicle 40 (refer to Figure 3 described later). The event information input unit 110 is constituted by, for example, a user interface such as a button and a mouse. The event information input unit 110 can also receive data input by using, for example, voice, gestures, etc. The event information input unit 110 is an example of the first acquisition unit.

[0074] The communication unit 120 is constituted by including a communication circuit (communication module) for communicating with the threat information collection server 20.

[0075] The input information analysis unit 130 obtains data from the event information input unit 110, performs named entity extraction, generates a search query based on the extracted named entity, and sends the generated search query to the threat information collection server 20 via the communication unit 120. That is, the input information analysis unit 130 can automatically generate a search query based on the event information. In addition, the input information analysis unit 130 obtains a search result of threat information (refer to Figure 4 described later) from the threat information collection server 20 via the communication unit 120, and outputs the obtained search result to the trend information analysis unit 150. The threat information includes, for example, information regarding past cyber attacks on vehicles that can communicate with the threat information sharing server 30. The threat information can also include, for example, information indicating a history of cyber attacks.

[0076] In this way, the input information analysis unit 130 obtains one or more threat information related to past cyber attacks on one or more vehicles as a search result based on the event information obtained by the event information input unit 110. The one or more vehicles are vehicles that are the objects of collecting threat information by the threat information collection server 20 or the threat information sharing server 30. The monitored vehicle 40 may be included in the one or more vehicles. In addition, the one or more vehicles are, for example, multiple vehicles.

[0077] The input information analysis unit 130 generates a first search query for obtaining one or more threat information based on, for example, event information (e.g., each of a plurality of items (e.g., classification items) included in the event information). When the number of the obtained one or more threat information is less than a predetermined number, the input information analysis unit 130 further generates a second search query whose search conditions are looser than those of the first search query based on the event information, and uses the generated second search query to obtain one or more threat information. In this way, the input information analysis unit 130 may also have a function of relaxing the conditions of the search query for obtaining threat information from the threat information collection server 20. The input information analysis unit 130 is an example of the second acquisition unit.

[0078] The analysis result screen output unit 140 obtains the analysis result from the attack path prediction unit 160, generates an analysis result screen, and presents it to the analyst 50. The analysis result screen output unit 140 is implemented by a display device such as a liquid crystal display, but may also be implemented by a sound generating device that presents the analysis result using voice or the like.

[0079] The trend information analysis unit 150 obtains the search result of the threat information from the input information analysis unit 130, and obtains the matching trend information from the trend information service via the communication unit 120 (refer to Figure 5 described later), and outputs the obtained information to the attack path prediction unit 160. The trend information service is, for example, a service provided by an information search website such as Google Trends, but is not limited thereto. The trend information indicates the popularity of cyberattacks against the threat information. The analysis result of the trend information includes the result obtained by calculating the popularity indicating to what extent the threat information is popular. The trend information analysis unit 150 is an example of the third acquisition unit.

[0080] The attack path prediction unit 160 obtains the search result of the threat information and the analysis result of the trend information from the trend information analysis unit 150, and predicts the attack path of the cyberattack on the monitored vehicle 40 based on the obtained search result of the threat information and the analysis result of the trend information. The attack path prediction unit 160 predicts the attack path based on a predetermined number of threat information with higher scores (e.g., trend values) in the trend information analysis among the threat information included in the search result. In addition, the attack path prediction unit 160 outputs, for example, the information based on the predetermined number of threat information with higher scores as the analysis result of the predicted path to the analysis result screen output unit 140. The attack path prediction unit 160 may also output, for example, at most three threat information with the highest scores and recording the next attack path information as the analysis result of the predicted path to the analysis result screen output unit 140 preferentially. In addition, the attack path prediction unit 160 only needs to predict the attack path based on at least the search result of the threat information. The attack path prediction unit 160 is an example of the prediction unit.

[0081] In addition, the next attack predicted by the cyber attack path prediction device 10 can also be, for example, an attack assumed to be executed several hours to several days after the previous attack.

[0082] Refer again to Figure 1 , the threat information collection server 20 stores information such as threat information used in the processing of the cyber attack path prediction device 10. The threat information collection server 20 obtains this information from the threat information sharing server 30. The threat information collection server 20 can also be, for example, a server managed by an operator that manufactures or sells the cyber attack path prediction device 10.

[0083] The threat information collection server 20 includes: a storage unit such as a hard disk and a semiconductor memory; a control unit such as a CPU that controls writing of information to the storage unit and reading of information from the storage unit; and a communication unit having a communication circuit (communication module) for communicating with the cyber attack path prediction device 10 and the threat information sharing server 30.

[0084] The threat information sharing server 30 obtains and stores log information, vulnerability information, etc. from the monitored vehicle 40. The threat information sharing server 30 is a server that discloses information on the Internet or the like. The threat information sharing server 30 is also referred to as CTI. In Figure 1 , an example in which there is one threat information sharing server 30 is shown, but there may be multiple threat information sharing servers 30. In the attack path prediction system 1, for example, there is a case where multiple threat information sharing servers 30 managed by different operators are set up. In this case, for example, the information of the monitored vehicle 40 stored in each of the multiple threat information sharing servers 30 can be partly common or different from each other.

[0085] The threat information sharing server 30 includes: a storage unit such as a hard disk and a semiconductor memory; a control unit such as a CPU that controls writing of information to the storage unit and reading of information from the storage unit; and a communication unit having a communication circuit (communication module) for communicating with the threat information collection server 20 and the monitored vehicle 40.

[0086] The monitored vehicle 40 is a vehicle that is the object of monitoring by the analyst 50. The monitored vehicle 40 is an automobile, a bus, a motorcycle, etc., but can also be a train, etc. In addition, the monitored vehicle 40 can be an autonomously drivable vehicle or a manually drivable vehicle.

[0087] Here, refer to Figures 3 to 5 , and various information will be described. Figure 3This is a diagram showing an example of the event information input by analyst 50 involved in this embodiment to the cyber attack path prediction device 10.

[0088] As Figure 3 shown, the event information includes vehicle model, attack path, interface, target, and attack content. In addition, as items, these are not limited, as long as the information expressing the event is described. Also, vehicle model, attack path, interface, and target are examples of classification items, and attack content is an example of string information. The event information includes: two or more classification items including at least two of vehicle model, attack path, interface, and target; and one or more string information.

[0089] The vehicle model refers to the vehicle model of the vehicle targeted by the cyber attack. In Figure 3 it, the vehicle model exemplifies Model X of Company A, but is not limited thereto. For example, the vehicle model can also be Model Y of Company B, etc.

[0090] The attack path refers to the order in which the vehicle architecture (system structure) is invaded or damaged in a cyber attack. The attack path here represents the order of the cyber attack up to the current moment, and in the future, it may be possible to further continue the cyber attack on other ECUs (Electronic Control Unit) from ADAS (Advanced Driver - Assistance Systems). In Figure 3 it, as the order of being invaded or damaged, the order of WiFi (registered trademark, the same hereinafter), GW (gateway), ADAS is exemplified, but is not limited thereto. As other examples of the order of being invaded or damaged, there may also be cases such as WiFi, GW, the ECU functioning as OBD (On - Board Diagnostics), other ECUs, etc.

[0091] The interface refers to the vehicle architecture that becomes the entry point of the cyber attack. The interface is the entry point (invasion point) of the cyber attack in the monitored vehicle 40, and corresponds to, for example, any one of the multiple ECUs mounted on the monitored vehicle 40. As this ECU, for example, an ECU for external communication used to communicate with the outside of the vehicle, an ECU having a gateway function, etc. are assumed. In Figure 3 it, an ECU that communicates according to the communication standard of WiFi is exemplified, but is not limited thereto. As other examples of the interface, an ECU that communicates according to the communication standard of Bluetooth (registered trademark), EV (EV = Electric Vehicle), on - board diagnostic device, etc. can be exemplified.

[0092] A target refers to a vehicle architecture that is the objective of a cyber-attack. The target is the result predicted by analyst 50. In Figure 3 , ADAS is illustrated, but not limited thereto. As other examples of targets, IVI (In-Vehicle Infotainment), ECUs of body systems, ECUs of autonomous driving systems, etc. can be illustrated. In addition, since the target is based on the prediction of analyst 50, there may be cases where the prediction of analyst 50 is incorrect. Also, analyst 50 may not input to the target column in cases where it is difficult to predict the target.

[0093] The attack content refers to any string representing a cyber-attack. The attack content is, for example, a string input by analyst 50.

[0094] The classification items are information used to obtain threat information from the threat information collection server 20, and the attack content is information used to set weight coefficients for each of the multiple classification items. In addition, the classification items may also include, for example, attack tools indicating the tools used in cyber-attacks.

[0095] Figure 4 It is a diagram showing an example of the threat information stored in the threat information collection server 20 and the threat information sharing server 30 according to the present embodiment.

[0096] Threat information is text that describes the impact and cause of an attack, etc., parsed by an analyst based on the logs and communication information of the attacked vehicle after a cyber-attack loss on the vehicle is discovered. Threat information is described, for example, in the description format of the Structured Threat Information eXpression (STIX).

[0097] As Figure 4 shown, in the Structured Threat Information eXpression (STIX), for example, information including the method of attack, the countermeasure method of attack, the vulnerability of the attack target, the severity of the vulnerability, the date when the attack was discovered, information about the attacked vehicle, the tools used in the attack, the IP address of the attacker, the domain name, etc. in a cyber-attack is recorded.

[0098] In Figure 4 , the method of attack, the IP address of the attacker, and the domain name of the attacker are recorded in the threat information. By previously recording the item of the cyber kill chain (kill_chain_phases) in the method of attack, the method of the next attack can be predicted. For example, the attack path in the cyber kill chain can be predicted.

[0099] Figure 5FIG. 0 is a diagram showing an example of trend information for the network attack path prediction device 10 according to the present embodiment to analyze trend information.

[0100] As Figure 5 shown, the so-called trend value indicates how many times a specific keyword has been searched on the Internet during a corresponding period or time period. The higher the value, the more actively the keyword has been searched. The trend value may also include the number of searches for the named entity in a search website or the like. The number of searches may be the number of searches worldwide or the number of searches in a predetermined country or region.

[0101] Figure 5 FIG. 9 is a graph showing the trend value for a specific keyword, obtained by specifying a specific country and period. In Figure 5 , an example is shown in which the trend value for a specific malware in Japan from 2018 to 2022 is obtained.

[0102] Figure 5 The graph shown in FIG. 15 includes the trend values (number of searches) of the named entity at multiple time points during a predetermined period. In addition, based on the trend values at multiple time points, the trend value for the named entity is obtained. The trend value of the named entity is an example of unique trend information.

[0103] [2. Operation of Attack Path Prediction System]

[0104] Next, with reference to Figures 6 to 12 , the operation (operation) of the attack path prediction system configured as described above will be described. First, with reference to Figure 6 , the operation of collecting threat information will be described. Figure 6 FIG. 27 is a timing diagram showing the operation (attack path prediction method) of the threat information collection server 20 and the threat information sharing server 30 according to the present embodiment to collect threat information.

[0105] (S101) The threat information sharing server 30 collects information (threat information) parsed from the vehicle's logs, communication information, etc. for the monitored vehicle 40, and converts it into a structured threat information expression STIX for storage. For example, the threat information sharing server 30 obtains threat information from the vehicle by outputting a threat information collection request to the monitored vehicle 40, but the obtaining method is not limited thereto. For example, the threat information may be periodically sent from the monitored vehicle 40 to the threat information sharing server 30.

[0106] (S102) The threat information collection server 20 sends a sharing request of the structured threat information expression STIX collected from the monitored vehicle 40 to the threat information sharing server 30, performs format conversion such as adding tags to the threat information if necessary, and saves it. The threat information collection server 20 obtains threat information from one or more threat information sharing servers 30 that save the desired information among the multiple threat information sharing servers 30. The process of step S102 can be executed regularly or according to the input of the analyst 50 or the like. Figure 6 (Threat information sharing request in

[0107] Next, refer to Figure 7 and explain the operation of predicting the attack path of the network attack. Figure 7 is a timing diagram showing the operation of attack path prediction (attack path prediction method) executed by the network attack path prediction device 10 according to the present embodiment.

[0108] (S201) The input information analysis unit 130 obtains data (event information) from the event information input unit 110 and performs named entity extraction using the obtained data. In step S201, one or more named entities included in the event information are extracted. In Figure 3 's example, the input information analysis unit 130 extracts, for example, "Company A Model X" shown in the attack content as a named entity corresponding to the vehicle model, extracts "WiFi", "GW", and "ADAS" as named entities for the attack path, and extracts "WiFi" as a named entity corresponding to the interface.

[0109] In addition, the method of named entity extraction is not particularly limited. For example, general learning models such as the BERT (Bidirectional Encoder Representations from Transformers) model can be used, or a model created independently can also be used.

[0110] (S202) The input information analysis unit 130 searches for threat information using the named entities extracted in step S201. The input information analysis unit 130 automatically generates a search query (an example of the first search query) using the named entities. The input information analysis unit 130 sends the generated search query to the threat information collection server 20 via the communication unit 120 and receives the matching threat information. The received threat information is output to the trend information analysis unit 150. The received threat information is an example of one or more threat information. Thus, according to the network attack path prediction device 10, a search query is automatically generated, so that threat information and the like can be collected even when the analyst 50 does not have advanced security knowledge.

[0111] (S203) The trend information analysis unit 150 connects to a trend information service in order to obtain trend information regarding the threat information obtained from the input information analysis unit 130. The trend information analysis unit 150 communicates via the communication unit 120 with a server or the like that provides the trend information service.

[0112] (S204) The trend information analysis unit 150 obtains trend information (e.g., a trend value) regarding the threat information obtained from the input information analysis unit 130 from the trend information service. The trend information analysis unit 150 outputs the threat information and the trend information to the attack path prediction unit 160.

[0113] (S205) The attack path prediction unit 160 obtains the threat information and the trend information from the trend information analysis unit 150, and predicts an attack path with reference to the obtained threat information and trend information. In step S205, the attack path prediction unit 160, for example, preferentially selects and outputs, as the analysis result of the predicted path, at most three pieces of threat information with the highest score in the analysis result of the trend information among the threat information, which record the next attack path information. The attack path prediction unit 160 outputs the threat information, the trend value, and the information indicating the attack path as the information to be displayed by the analysis result screen output unit 140.

[0114] Thus, according to the network attack path prediction device 10, by simply inputting (event information) which represents the characteristics of the network attack occurring in the monitored vehicle 40 by the analyst 50, the network attack can be classified by pattern, relevant threat information can be automatically searched from the threat information collection server 20, and the attack path and the actions that the attacker is likely to take next can be predicted. As a result, for example, even an analyst 50 without security knowledge can perform advanced event analysis aware of the attacker's actions in a short time, and the network attack path prediction device 10 can help reduce the operation cost of the SOC and improve the accuracy of event analysis. For example, it can also help reduce the deviation of the analysis results of each analyst 50.

[0115] Next, with reference to Figure 8 , the processing performed by the input information analysis unit 130 will be described. Figure 8 is a flowchart showing the operation (attack path prediction method) of input information analysis performed by the input information analysis unit 130 according to the present embodiment. In Figure 8 , it shows Figure 7 the details of the processing in steps S201 and S202 shown.

[0116] (S300) The event information input unit 110 obtains from the event information input unit 110 as Figure 3Such event information is used as input data.

[0117] (S301) The input information analysis unit 130 performs named entity extraction using, for example, the BERT model or the like on the event information, and sets the number of items of the extracted named entities to n. The input information analysis unit 130 extracts named entities from the string information included in the event information. For example, when named entities corresponding to the vehicle model, the target of the attack ( Figure 3 the target shown), and the attack tool are extracted from the event information, the number of items n = 3. The number of items n is the number of classification items of the extracted named entities. In addition, a table that establishes a correspondence relationship between the named entity and the classification item corresponding to the named entity is pre-stored in a storage unit (not shown), and the input information analysis unit 130 can also use this table to calculate the number of items n.

[0118] (S302) The input information analysis unit 130 determines whether the number of extracted items n is greater than 0. When the number of items n is greater than 0 (step S302: Yes), the input information analysis unit 130 executes step S303, and when the number of items n is 0 or less (for example, 0) (step S302: No), the input information analysis unit 130 executes step S304. In addition, the case where the number of items n is greater than 0 means that the event information contains information for generating a search query for searching for threat information.

[0119] (S303) The input information analysis unit 130 calculates a weight coefficient (weight value) for each of the n classification items. As a calculation method, for example, a method of calculating according to the ratio of each classification item in the string included in the event information (for example, Figure 3 the attack content shown) can be exemplified. In this calculation method, for example, the number of named entities corresponding to the vehicle model, the attack target, and the attack tool in the string is counted, and the number of named entities included in the classification item in all the named entities is calculated as the ratio. For example, a weight coefficient of a classification item with a higher ratio is set to a higher weight than that of a classification item with a lower ratio. When named entities corresponding to the vehicle model, the attack target, and the attack tool are extracted from the event information, and the respective ratios are 0.1, 0.2, and 0.3, these values can also be used as the weight coefficients as they are. In addition, the process of step S303 can also be executed after it is determined as "No" in step S307. Additionally, the calculation method is not limited to the above method.

[0120] (S304) When the input event information does not contain a named entity, the input information analysis unit 130 uses a statically defined search query to search for threat information on the threat information collection server 20. Here, the statically generated query refers to a query generated with the weight coefficients of the predefined initial values. In this way, even when the event information does not contain the named entity for generating the search query, the input information analysis unit 130 automatically generates a search query. It can also be said that the input information analysis unit 130 generates the first search query based on the preset weight coefficients when the string information does not contain a named entity. In addition, the weight coefficients of the predefined initial values are stored in a storage unit (not shown). The weight coefficients of the initial values include the weight coefficients of each classification item included in the event information.

[0121] (S305) The input information analysis unit 130 generates a search query (the first search query) for threat information based on n weight coefficients. For example, the input information analysis unit 130 automatically generates a search query by connecting all n classification items with an AND (logical "and") condition. For example, when the vehicle type = A, the attack target = B, and the attack tool = C, the search query is as follows.

[0122] Vehicle type = A AND Attack target = B AND Attack tool = C

[0123] (S306) The input information analysis unit 130 uses the search query generated in step S305 to search for threat information on the threat information collection server 20, and sets the number of hit items to m. For example, when the threat information collection server 20 stores threat information that satisfies each of the vehicle type = A, the attack target = B, and the attack tool = C, the number of items m = 3. When the threat information collection server 20 stores threat information that satisfies two of the vehicle type = A, the attack target = B, and the attack tool = C, the number of items m = 2.

[0124] (S307) The input information analysis unit 130 determines whether the number of items n = m. When n = m (S307: Yes), the input information analysis unit 130 executes step S309. When n ≠ m (S307: No), the input information analysis unit 130 executes step S308.

[0125] (S308) The input information analysis unit 130 excludes one classification item with the lowest priority from the search conditions, and decrements the value of the number of items n (n = n - 1). Then, it proceeds to step S305, and the input information analysis unit 130 newly generates a search query (the second search query) based on the classification items (one or more classification items) after decrementing the number of items n and the weight coefficients of the classification items. For example, the input information analysis unit 130 generates a search query based on two classification items out of three classification items excluding the classification item with the lowest weight coefficient and the weight coefficients of the two classification items. In this way, the input information analysis unit 130 generates the second search query based on the weight coefficients of two or more classification items included in the event information. Thus, the conditions for threat information search will be relaxed.

[0126] In addition, although an example of decrementing the value of the number of items n in step S308 has been described, it is not limited thereto. For example, it is also possible to subtract the value obtained by subtracting the number of items m hit in step S306 from the current number of items n from the number of items n (n = n - (n - m)). That is to say, in step S308, the number of items n can also be set to the number of items m hit in step S306.

[0127] (S309) The input information analysis unit 130 obtains threat information that matches the search conditions from the threat information collection server 20 via the communication unit 120, and outputs the obtained threat information (threat information that matches the search query) to the attack path prediction unit 160.

[0128] Next, refer to Figure 9 , and the processing performed by the trend information analysis unit 150 will be described. Figure 9 It is a flowchart showing the operation (attack path prediction method) of trend information analysis performed by the trend information analysis unit 150 according to the present embodiment.

[0129] (S400) The trend information analysis unit 150 obtains the threat information output from the input information analysis unit 130. In addition, the trend information analysis unit 150 performs named entity extraction on the obtained threat information. The method of named entity extraction can also be the same as that in the event information.

[0130] (S401) The trend information analysis unit 150 connects to the trend information service via the external network. The trend information analysis unit 150 communicates with a server or the like that provides the trend information service via the communication unit 120.

[0131] (S402) The trend information analysis unit 150 averages the trend values of threat information within a certain period to obtain T. For example, when the threat information records three items: malware name, vehicle model name, and the name of the attacked system (or the attacked ECU), the trend values of each item are obtained. If the trend values of each item are 50, 60, and 70 respectively, then the trend value T of this threat information = 60. In this way, the trend information analysis unit 150 obtains the trend information of each of one or more named entities included in the threat information, and based on the trend information (unique trend information) of each of the one or more named entities, obtains the trend information (trend value) for this threat information. The trend information for threat information includes the trend value, but is not limited to this, as long as it includes information indicating the degree of trend.

[0132] (S403) The trend information analysis unit 150 outputs the trend value T obtained in step S402 to the attack path prediction unit 160.

[0133] Next, refer to Figure 10 , and the processing performed by the attack path prediction unit 160 will be described. Figure 10 It is a flowchart showing the operation (attack path prediction method) of attack path prediction performed by the attack path prediction unit 160 according to this embodiment. In addition, the processing of steps S501 to S505 is performed for all threat information.

[0134] (S500) The attack path prediction unit 160 obtains the threat information hit by the search output from the trend information analysis unit 150 and their respective trend values T. In step S500, it can also be said that the threat information and their respective trend values T are input to the attack path prediction unit 160.

[0135] (S501) The attack path prediction unit 160 selects one of the threat information hit by the search.

[0136] (S502) The attack path prediction unit 160 refers to the trend value T of the threat information selected in step S501, and determines whether the value of the trend value T is within the top three among the trend values T of all the threat information hit by the search. If it is determined that the size is within the top three (S502: Yes), step S503 is executed. If it is determined that the size is not within the top three (S502: No), it returns to step S501. In addition, the third place is an example and can be appropriately set by the analyst 50 or the like. Step S503 is an example of extracting a predetermined number of threat information from one or more threat information based on trend information.

[0137] (S503) The attack path prediction unit 160 refers to a certain cyber kill chain recorded in the threat information and confirms whether there is a next attack (next attack information (an example of attack continuation information)) in the corresponding threat information. The attack path prediction unit 160 can also be said to determine, in step S503, whether the threat information contains attack continuation information indicating a next cyber attack on the monitored vehicle 40.

[0138] When there is a next attack (S503: Yes), the attack path prediction unit 160 executes step S504. When there is no next attack (S503: No), the attack path prediction unit 160 executes step S505. For example, when the cyber kill chain in the threat information is reconnaissance, the attack path prediction unit 160 searches for cyber kill chains such as weaponization and distribution after the reconnaissance activity associated with the threat information. If it can be found, it is regarded as having a next attack.

[0139] (S504) The attack path prediction unit 160 appends and saves the threat information to buffer A (not shown) provided in the network attack path prediction device 10. The threat information saved in buffer A is an example of the threat information determined to contain attack continuation information.

[0140] (S505) The attack path prediction unit 160 appends and saves the threat information to buffer B (not shown) provided in the network attack path prediction device 10. The threat information saved in buffer B is an example of the threat information determined not to contain attack continuation information.

[0141] If the attack path prediction unit 160 regards there as being a next attack, it predicts that the next attack will be the next attack that will occur in the monitored vehicle 40. For example, when there are 3 pieces of threat information saved in buffer A, the attack path prediction unit 160 can also predict the next attacks included in the 3 pieces of threat information as the next attacks that will occur in the monitored vehicle 40. In addition, when there are 3 pieces of threat information saved in buffer B, the attack path prediction unit 160 can also predict that there is no next attack on the monitored vehicle 40. Thus, the attack path prediction unit 160 predicts the attack path of the cyber attack on the monitored vehicle 40 based on a predetermined number of threat information.

[0142] In addition, the attack path prediction unit 160 only needs to predict the attack path based on the threat information saved in at least one of buffer A and B.

[0143] (S506) The attack path prediction unit 160 preferentially outputs threat information from buffer A to the analysis result screen output unit 140. When there is data saved in buffer B, after outputting the threat information in buffer A, the threat information in buffer B is output to the analysis result screen output unit 140. The threat information saved in buffers A and B is used for the display of the attack step display part 2400, the vehicle architecture display part 2500, and the threat information display part 2800 described later. Figure 12 of the attack step display part 2400, the vehicle architecture display part 2500, and the threat information display part 2800.

[0144] In addition, the attack path prediction unit 160 is not limited to preferentially outputting threat information from buffer A to the analysis result screen output unit 140. For example, it can also preferentially output threat information from the buffer with the larger amount of data among buffer A and B to the analysis result screen output unit 140. Additionally, the attack path prediction unit 160 may not perform the determination in step S503. The attack path prediction unit 160 can, for example, output threat information to the analysis result screen output unit 140 in descending order of trend values, or randomly output the top three threat information to the analysis result screen output unit 140.

[0145] Next, referring to Figure 11 and Figure 12 , the information displayed on the analysis result screen output unit 140 will be described. Figure 11 is a diagram showing the overview screen 1100 of the analysis result related to this embodiment.

[0146] As Figure 11 shown, the overview screen 1100 of the analysis result is, for example, a web page displayed on a web application, including a filtering part 1200, a selection part 1300, a saving part 1400, a deleting part 1500, a checkbox part 1600, a sorting part 1700, a trend value display part 1800, and a page display part 1900.

[0147] The filtering part 1200 is a part (a part of the screen) for filtering so that only the analysis results containing the input arbitrary string are displayed when the arbitrary string is input.

[0148] The selection part 1300 is a part for filtering each item by selecting the corresponding string.

[0149] The saving part 1400 is a part for saving the overview screen 1100 of the analysis result as a CSV file or the like by pressing.

[0150] The deleting part 1500 is a part for deleting the events selected in the checkbox part 1600 by pressing.

[0151] The checkbox section 1600 is a section for saving or deleting the selected information together by pressing the save section 1400 or the delete section 1500 after a selection event.

[0152] The sorting section 1700 is a section for switching between ascending and descending order by pressing.

[0153] The trend value display section 1800 is a section for displaying the analysis result of the trend information of the corresponding event.

[0154] The page display section 1900 is a section for displaying the analysis results of the next predetermined number of items (e.g., the next 10 items) by pressing.

[0155] Figure 12 It is a diagram showing the detailed screen 2100 of the analysis result related to this embodiment.

[0156] As Figure 12 shown, the detailed screen 2100 of the analysis result is, for example, a web page displayed on a web application, including a home display section 2200, an analysis result display section 2300, an attack step display section 2400, a vehicle architecture display section 2500, object display sections 2600 and 2700, and a threat information display section 2800.

[0157] The home display section 2200 is a section for returning to the overview screen 1100 of the analysis result by pressing.

[0158] The analysis result display section 2300 is a section for initially selecting "1" which is the threat information with the highest degree of association (e.g., weight coefficient or trend value) as the analysis result, and displaying the respective analysis results by pressing "1", "2", or "3".

[0159] The attack step display section 2400 is a section for displaying threat information for each attack step.

[0160] The vehicle architecture display section 2500 is a section for displaying threat information for each vehicle architecture.

[0161] The object display sections 2600 and 2700 are sections for representing each object of the threat information, and for making the threat information display section 2800 display the threat information by pressing. The object shown in bold indicates the current attack progress.

[0162] The threat information display section 2800 displays the corresponding threat information when the object display section 2600 or 2700 is pressed.

[0163] InFigure 12 In Figure 12 , it is shown that the attack step is step 2, and as the vehicle architecture in step 2, the cyber attack proceeds to ADAS. According to this threat information, it can be known that there is no next attack in step 2. In this case, the initial object of the vehicle architecture in step 3 becomes the next attack object.

[0164] By presenting the Figure 11 or Figure 12 information shown to analyst 50, it is possible to assist analyst 50 in path prediction. It is considered that such a display is particularly effective for an inexperienced analyst 50.

[0165] (Other embodiments)

[0166] As described above, based on the embodiments, the cyber attack path prediction device 10 and the like related to one or more aspects have been described, but the present disclosure is not limited to these embodiments. As long as it does not deviate from the gist of the present disclosure, aspects obtained by making various modifications that can be conceived by those skilled in the art to these embodiments, and aspects constructed by combining the constituent elements in different embodiments can also be included in the present disclosure.

[0167] For example, in the above-described embodiment, an example in which the attack path prediction system 1 includes two servers, namely, the threat information collection server 20 and the threat information sharing server 30, has been described. However, as long as at least one of the threat information collection server 20 and the threat information sharing server 30 is included in the attack path prediction system 1, it is sufficient.

[0168] In addition, in the above-described embodiment, an example in which a trend value (numerical value) is obtained as the popularity of a named entity has been described. However, it is not limited thereto. For example, whether it is currently popular (judgment result), low, medium, high, etc. can also be obtained as the popularity.

[0169] In addition, the cyber attack in the above-described embodiment refers to an attack on a device (e.g., ECU, etc.) mounted on a vehicle, using a security vulnerability to leak or tamper with information, thereby causing an abnormality in the operation of the device. The cyber attack can also be either an attack via a network or an attack not via a network. Examples of an attack not via a network include data writing using a USB (Universal Serial Bus) memory, etc., but it is not limited thereto.

[0170] In addition, in the above-described embodiment, each constituent element can be constituted by dedicated hardware, or can be realized by executing a software program suitable for each constituent element. Each constituent element can also be realized by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.

[0171] In addition, the order in which the steps in the flowchart are executed is illustrated for specifically explaining the present disclosure, and it may also be an order other than the above. In addition, a part of the above steps may be executed simultaneously (in parallel) with other steps, and a part of the above steps may not be executed.

[0172] In addition, as an example of the division of the functional blocks in the block diagram, multiple functional blocks may be implemented as one functional block, one functional block may be divided into multiple, or a part of the functions may be transferred to other functional blocks. In addition, it may be that a single piece of hardware or software processes the functions of multiple functional blocks having similar functions in a parallel or time-division manner.

[0173] In addition, the network attack path prediction device according to the above-described embodiment may be implemented as a single device or may be implemented by multiple devices. In the case where the network attack path prediction device is implemented by multiple devices, each component included in the network attack path prediction device may be distributed among the multiple devices in any manner. In the case where the network attack path prediction device is implemented by multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless communication or may be wired communication. In addition, between the devices, wireless communication and wired communication may also be combined.

[0174] In addition, each component described in the above embodiment may also be implemented as software, and typically, may also be implemented as an LSI (Large Scale Integration) which is an integrated circuit. They may be made into a single chip individually or may be made into a single chip in a manner including a part or all of them. Although it is assumed to be a system LSI here, depending on the degree of integration, it is sometimes also referred to as an IC, a system LSI, a super large LSI, or an extra large LSI. In addition, the method of integrating into an integrated circuit is not limited to an LSI, and may also be implemented by a dedicated circuit (a general circuit that executes a dedicated program) or a general-purpose processor. An FPGA (Field Programmable Gate Array) that can be programmed after the LSI is manufactured, or a reconfigurable processor that can reconfigure the connection or setting of the circuit cells inside the LSI may also be used. Furthermore, if due to the progress of semiconductor technology or other derived technologies, there appears an integrated circuit technology that replaces the LSI, then of course, that technology can also be used for integrating the components.

[0175] A system LSI is a super multi-functional LSI manufactured by integrating multiple processing units on one chip. Specifically, it is a computer system including a microprocessor, a ROM (Read Only Memory), a RAM (Random Access Memory), etc. A computer program is stored in the ROM. The microprocessor operates according to the computer program, and thereby, the system LSI realizes its functions.

[0176] In addition, one aspect of the present disclosure may also be a computer program that causes a computer to execute each of the characteristic steps included in the method (e.g., the attack path prediction method) shown in any one of Figures 6 to 10 For example, the program may also be a program for causing a computer to execute. In addition, one aspect of the present disclosure may also be a computer-readable non-transitory recording medium on which such a program is recorded. For example, such a program may be recorded on a recording medium for distribution or circulation. For example, by installing the distributed program on another device having a processor and causing the processor to execute the program, the above-described various processes can be performed on the device.

[0177] Industrial Applicability

[0178] The present disclosure is useful for a prediction device for predicting an attack path of a network attack and the like.

[0179] Description of Reference Numerals

[0180] 1: Attack path prediction system

[0181] 10: Network attack path prediction device (attack path prediction device)

[0182] 20: Threat information collection server

[0183] 20: Threat information collection server

[0184] 30: Threat information sharing server

[0185] 40: Vehicle under surveillance

[0186] 50: Analyst (monitor)

[0187] 110: Event information input unit (first acquisition unit)

[0188] 120: Communication unit

[0189] 130: Input information analysis unit (second acquisition unit)

[0190] 140: Analysis result screen output unit

[0191] 150: Trend information analysis unit (third acquisition unit)

[0192] 160: Attack path prediction unit (prediction unit)

[0193] 1100: List screen of analysis results

[0194] 1200: Screening section

[0195] 1300: Selection section

[0196] 1400: Save section

[0197] 1500: Delete section

[0198] 1600: Checkbox section

[0199] 1700: Sorting section

[0200] 1800: Trend value display section

[0201] 1900: Page display section

[0202] 2100: Detailed screen of analysis result

[0203] 2200: Home page display section

[0204] 2300: Display section of analysis result

[0205] 2400: Display section of attack steps

[0206] 2500: Display section of vehicle architecture

[0207] 2600, 2700: Object display section

[0208] 2800: Display section of threat information

Claims

1. An attack path prediction method, which is a method for predicting the attack path of a network attacker, includes: Obtaining event information about a cyber-attack on a monitored vehicle from a monitor who monitors the monitored vehicle; Based on the obtained event information, obtaining one or more threat information related to past cyber-attacks on vehicles; Based on the obtained one or more threat information, predicting the attack path of a cyber-attack on the monitored vehicle, In the acquisition of the threat information, Generating a first search query for obtaining the one or more threat information based on the event information, When the number of obtained threat information is less than a predetermined number, further generating a second search query with looser search conditions than the first search query based on the event information, Using the generated second search query to obtain the one or more threat information.

2. The attack path prediction method according to claim 1, In the acquisition of the threat information, Extracting one or more named entities included in the event information, Generating the first search query based on the extracted one or more named entities.

3. The attack path prediction method according to claim 2, The event information includes two or more classification items and string information, In the acquisition of the threat information, Extracting the one or more named entities included in the string information of the event information, Based on the one or more named entities, weighting each of the two or more classification items, Generating the second search query based on the weighting values of the two or more classification items respectively.

4. The attack path prediction method according to claim 3, In the acquisition of the threat information, Extracting one or more classification items other than the classification item with the lowest weighting value among the two or more classification items, Generating the second search query based on the extracted one or more classification items.

5. The attack path prediction method according to claim 3 or 4, In the case where the string information does not include a named entity, generating the first search query based on a preset weighting value.

6. The attack path prediction method according to claim 3 or 4, The two or more classification items include at least two of the vehicle model of the monitored vehicle, the attack path at the current moment of the cyber-attack on the monitored vehicle, the interface that is the entry point of the cyber-attack, and the device that is the target of the cyber-attack.

7. The attack path prediction method according to any one of claims 1 to 4, For each of the obtained one or more threat information, obtaining trend information indicating the prevalence of a cyber-attack on the threat information, In the prediction of the attack path of the cyber-attack, further predicting the attack path of the cyber-attack on the monitored vehicle based on the trend information.

8. An attack path prediction device, which is a device for predicting the attack path of a network attacker, includes: The first acquisition unit acquires event information regarding a cyber-attack on the monitored vehicle from a monitor who monitors the monitored vehicle; The second acquisition unit acquires one or more threat information related to past cyber-attacks on vehicles based on the acquired event information; and The prediction unit predicts an attack path of a cyber-attack on the monitored vehicle based on the one or more threat information acquired. The second acquisition unit generates a first search query for acquiring the one or more threat information based on the event information, and when the number of acquired threat information is less than a predetermined number, further generates a second search query whose search conditions are looser than the first search query based on the event information, and acquires the one or more threat information using the generated second search query.

9. A program for causing a computer to execute the attack path prediction method according to any one of claims 1 to 4.

Citation Information

Cited By

  • Novel combat concept analysis method based on killing chain

    CN121581438A