Method and system for developing ship network attack scene
By combining attack graphs from network attack trees and diamond analysis models, and integrating them with the MITRE ATT&CK framework, the problem of insufficient development of ship network attack scenarios was solved, thereby enhancing the ability to identify and counterattack potential attack surfaces.
Patent Information
- Application Number
- CN202480036749.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-02
- Filing Date
- 2024-05-31
- Publication Date
- 2025-12-26
AI Technical Summary
Existing technologies fail to effectively consider the unique characteristics of ship systems, resulting in insufficient development of cyberattack scenarios. Furthermore, traditional methods have limitations in visualization and analysis, making it difficult to identify potential attack surfaces.
A combined attack graph using the Attack Tree in Network (CAT) and Diamond Analysis model, along with the MITRE ATT&CK framework, identifies and visualizes ship network attack paths, analyzes intrusion techniques and attack characteristics, and identifies potential attack surfaces through asset identification, threat data confirmation, attack target selection, scenario creation, and attack graph output.
It enables full-path visualization of ship network attack paths and identification of potential attack surfaces, provides countermeasures and strategies, and enhances the ability to counter network attacks and manage risks.
Smart Images

Figure CN121220008A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a method and system for developing a ship cyber-attack scenario, which creates a ship attack scenario model to visualize all paths of an attacker penetrating an attack target through an attack graph and captures the range of attack techniques and characteristics to identify potential attack surfaces. BACKGROUND
[0002] As cyber attack threats continue to grow, governments and international organizations are demanding countermeasures against cyber threats. In response to this demand, research on the development of cyber attack scenarios is being conducted in Korea. The Korea Electronics and Telecommunications Research Institute published “Cyber Attack Simulation Technology Trends” in 2020, emphasizing the importance of developing cyber attack simulations to identify the security status and attack surface of a system at an early stage. For the development of cyber attack scenarios, a Korean patent titled “Design and system for managing security vulnerability based on standard dataset for developing and validating cyber warfare scenarios” registered by the Korea Advanced Institute of Defense Science and Technology in 2018 provides a standardized data-based countermeasure for security vulnerabilities by selecting security vulnerabilities suitable for creating cyber warfare scenarios based on open standard data to manage security vulnerability data. As another scenario creation method, “Design and Implementation of Cyber Attack Simulator based on Attack Techniques Modeling” published in the Journal of the Korean Computer and Information Society derives various attack scenarios by modeling cyber attack techniques and discloses a simulator for cyber security training.In addition, Research on stage-based flow graph model for representation of cyberattack training scenarios published in the Journal of Information Security discloses a stage-based flow graph model that can represent various cyberattack training scenarios that are difficult to represent through an attack tree modeling technique. Although the shipbuilding industry and the marine industry have made such active research and investment into autonomous ships and smart ships (also referred to as marine mobility), specific regulations and scenarios for cyber security have not yet been established.
[0003] In addition, the conventional technology fails to take into account the unique characteristics of marine ships and is thus limited in terms of application. As one unique characteristic of a ship system, unlike a land-based communication protocol, a ship communication system uses a communication protocol optimized for marine use. In addition, a computer based system (CBS) for a ship has specific hardware and software designed for use on a ship. In view of the unique characteristics of a ship system, it is necessary to develop a ship cyberattack scenario system that reflects the specificity of a ship communication protocol and the specific hardware and software used in a ship system.
[0004] A cyberattack tree (CAT) that visualizes the attack flow of a typical cyberattack scenario has limitations in explaining the interconnections between cyberattacks because the attack flow is linear and hierarchical. A semantic graph has the following problem: as the amount of data increases, the graph becomes complex and difficult to explain.
[0005] Related art is disclosed in Korean Patent Registration No. 10-1697189 (January 17, 2017). SUMMARY
[0006] TECHNICAL PROBLEM
[0007] An aspect of the present disclosure is to provide a method and system for developing a ship cyberattack scenario that can create a ship attack scenario model to visualize all paths of an attacker penetrating an attack target through an attack graph and can establish a countermeasure strategy by identifying potential attack surfaces through analysis of various intrusion techniques, attack techniques, attributes, and impacts.
[0008] TECHNICAL SOLUTION
[0009] According to an aspect of the present application, a method for developing a cyber attack scenario of a ship includes: an asset identification step in which ship system and stakeholder assets are identified; a threat data confirmation step in which asset information identified in the asset identification step is analyzed to determine whether there is threat data; an attack target selection step in which an attack target is selected when at least one of the identified assets is confirmed to exist in the threat data in the threat data confirmation step; an attack scenario creation step in which an attack scenario for the attack target selected in the attack target selection step is created; and an attack graph output step in which an attack graph according to the attack scenario created in the attack scenario creation step is output.
[0010] The attack scenario creation step can further include: an attack target vulnerability assignment step in which a vulnerability is assigned to the selected attack target; an attack execution step in which an attack is executed based on the vulnerability assigned to the attack target in the attack target vulnerability assignment step; a subsequent attack execution step in which a subsequent attack is executed using a different technique or tactic after the attack execution step is executed; an attack target strike step in which the attack target is struck after the subsequent attack execution step; a postcondition derivation step in which a postcondition is derived after the attack target is struck in the attack target strike step; an additional attack surface identification step in which an additional attack surface is identified based on what is derived in the postcondition derivation step; and an attack graph formation step in which an attack graph is formed based on the executed attack scenario.
[0011] The attack scenario creation step can further include: if an additional attack surface is identified in the additional attack surface identification step, executing a subsequent attack; and executing an additional attack by striking n additional attack targets.
[0012] The attack graph output step can include visualizing and outputting the attack graph through a combination of a cyber attack tree (CAT) model and a diamond analysis model.
[0013] The attack graph output step can include: capturing a range of attack techniques and characteristics; and enabling identification of potential attack surfaces.
[0014] According to another aspect of the present application, a system for developing a ship cyber attack scenario includes an asset identification unit configured to identify ship system and stakeholder assets, a threat data confirmation unit configured to analyze asset information identified by the asset identification unit to determine whether there is threat data, an attack target selection unit configured to select an attack target when at least one of the identified assets is confirmed by the threat data confirmation unit to exist in the threat data, an attack scenario creation unit configured to create an attack scenario for the attack target selected by the attack target selection unit, and an attack graph output unit configured to output an attack graph according to the attack scenario created by the attack scenario creation unit.
[0015] The attack scenario creation unit can further include an attack target vulnerability assignment unit configured to assign a vulnerability to the selected attack target, an attack execution unit configured to execute an attack based on the vulnerability assigned to the attack target by the attack target vulnerability assignment unit, a subsequent attack execution unit configured to execute a subsequent attack using a different technique or tactic from the attack execution unit, an attack target strike unit configured to strike the attack target of the subsequent attack by the subsequent attack execution unit, a postcondition derivation unit configured to derive a postcondition after the attack target is struck by the attack target strike unit, an additional attack surface identification unit configured to identify an additional attack surface based on what is derived by the postcondition derivation unit, and an attack graph formation unit configured to form an attack graph based on the executed attack scenario if there is no additional attack target identified by the additional attack surface identification unit.
[0016] The attack scenario creation unit can further include a subsequent attack execution unit configured to execute a subsequent attack if an additional attack surface is identified by the additional attack surface identification unit, and an additional attack target strike unit configured to execute an additional attack by striking n additional attack targets.
[0017] The attack graph output unit can visualize and output an attack graph through a combination of a cyber attack tree (CAT) model and a diamond analysis model.
[0018] The attack graph output unit can capture a range of attack techniques and characteristics, and can identify a potential attack surface.
[0019] Advantageous Effects
[0020] According to the present application, the method and system for developing a ship cyber attack scenario can employ a ship attack scenario model to visualize all paths of an attacker penetrating an attack target through an attack graph, and can establish a countermeasure strategy by identifying a potential attack surface through analysis of analysis of various intrusion techniques, attack techniques, attributes, and impacts. BRIEF DESCRIPTION OF DRAWINGS
[0021] Figure 1 is a flow chart illustrating a method for creating a ship cyber attack scenario model according to the present application.
[0022] Figure 2 is a flow chart illustrating a method for developing a ship cyber attack scenario according to the present application.
[0023] Figure 3 is a flow chart illustrating a method for creating an attack scenario according to the present application.
[0024] Figure 4 is an algorithm of a ship cyber attack scenario according to one embodiment of the present application.
[0025] Figure 5 is an attack graph generated by the algorithm of the embodiment of the present application shown in Figure 4 is an attack graph generated by the algorithm of the embodiment of the present application shown in
[0026] Figure 6 is an algorithm of a ship cyber attack scenario according to another embodiment of the present application.
[0027] Figure 7 is an attack graph generated by the algorithm of the embodiment of the present application shown in Figure 6 is an attack graph generated by the algorithm of the embodiment of the present application shown in DETAILED DESCRIPTION
[0028] The above and other aspects, features and advantages of the present application will become apparent from the following detailed description of the embodiments taken in conjunction with the accompanying drawings.
[0029] The terms used in the present specification are for the purpose of describing particular embodiments only and are not intended to be limiting. The use of the terms "comprises / comprising" and / or "includes / including" when used in this specification, specifies the presence of stated features, integers, steps, operations, elements, components and / or groups thereof, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. In addition, as used in this specification, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0030] Hereinafter, exemplary embodiments of the present application will be described in detail with reference to the accompanying drawings. It should be understood that the embodiments are devised to fully disclose the present application and to make a clear understanding of the present application to those skilled in the art, and the present application is not limited to the following embodiments but can be embodied differently by those skilled in the art.
[0031] In the method and system for developing a ship cyber attack scenario according to the present application, a ship attack scenario model visualizes all paths in which an attacker penetrates an attack target through an attack graph in which a cyber attack tree (CAT) is combined with a diamond model, thereby providing comprehensive insight into dependency relationships between cyber attacks.
[0032] Further, the method and system for developing a ship cyber attack scenario according to the present application can identify a potential attack surface by analyzing various intrusion techniques, attack techniques, attributes, and impacts using a MITRE attack tactics, technique (ATT) and common knowledge (CK) framework (MITRE ATT&CK Framework) and capturing the range of attack techniques and attributes by analyzing an attack scenario model.
[0033] Figure 1 FIG. 1 is a flowchart illustrating a method for creating a ship cyber attack scenario model according to the present application.
[0034] The method can include an asset identification step (S100) in which ship system and stakeholder assets are identified, a threat determination step (S200) in which it is determined whether the identified asset information exists in a set of threat databases (DB), and an attack scenario modeling step (S500) in which a cyber attack scenario is created by performing modeling of an attack scenario when it is determined in the threat determination step (S200) that the identified asset information exists in the set of threat databases.
[0035] The method can further include a threat data collection step (S300) in which additional threat data is collected when the identified asset information does not exist in the set of threat databases in the threat determination step (S200), and a confirmation step (S400) in which it is confirmed whether the identified asset information in the threat data collection step (S300) exists in a set of additionally collected threat databases. Accordingly, when the identified asset information exists in the set of additionally collected threat databases, attack scenario modeling can be performed to create a cyber attack scenario.
[0036] More specifically, with reference to Figure 2 and Figure 3The method for developing a cyber attack scenario of a ship according to the present disclosure and the attack scenario creation method can include an asset identification step (S510) in which ship systems and stakeholder assets are identified, an attack target selection step (S520), an attack scenario creation step (S530), and an attack graph output step (S540).
[0037] The asset identification step (S510) can include a step (S530-1) of determining whether the identified asset information exists in the set of threat databases, and a step (S530-1-2) of analyzing the asset information to collect assets having vulnerabilities.
[0038] Further, the attack target selection step (S520) can include selecting at least one of the assets collected in the asset identification step as an attack target.
[0039] The attack scenario creation step (S530) can include assigning a vulnerability to the attack target (S531), performing a vulnerability-based attack (S532), performing a follow-up attack after the vulnerability-based attack (S533), striking the attack target (S534), deriving a post-condition (S535), identifying an additional attack surface after the derivation of the post-condition (S536), and forming an attack graph if there is no additional attack surface (S539).
[0040] Further, if it is identified that there is an additional attack surface in the additional attack surface identification step (S536), a follow-up attack can be performed (S537), n additional attack targets can be struck (S538), and an attack graph can be formed (S539).
[0041] Further, as cyber attack tactics exploiting vulnerabilities in specific systems are becoming more and more complex, it is necessary to identify vulnerabilities and detect intrusions as early as possible in order to minimize damage caused by cyber attacks. Among various mechanisms for detecting intrusions, a cyber attack tree (CAT) representing an attack flow in the form of a tree can provide a systematic and structured solution for establishing security countermeasures against various attacks on a cyber system.
[0042] Further, the system for developing a ship cyber attack scenario according to the present application includes an asset identification unit (100) configured to identify ship system and stakeholder assets, a threat data confirmation unit (200) configured to analyze asset information identified by the asset identification unit to determine whether there is threat data, an attack target selection unit (300) configured to select an attack target when it is confirmed by the threat data confirmation unit that at least one of the identified assets exists in the threat data, an attack scenario creation unit (400) configured to create an attack scenario for the attack target selected by the attack target selection unit, and an attack graph output unit (500) configured to output an attack graph according to the attack scenario created by the attack scenario creation unit.
[0043] The attack graph output unit (500) can visualize and output the attack graph through a combination of a cyber attack tree (CAT) model and a diamond analysis model.
[0044] The attack graph output unit (500) can capture the range of attack techniques and characteristics, and can identify potential attack surfaces.
[0045] Figure 4 is an algorithm of a ship cyber attack scenario according to an embodiment of the present application. Figure 5 is a diagram illustrating an attack graph generated by an algorithm of an embodiment of the present application according to Figure 4 is an attack graph generated by an algorithm of an embodiment of the present application according to
[0046] In the attack graph using the cyber attack tree (CAT) model and the diamond analysis model, a plurality of root nodes of the cyber attack tree can represent various attack methods against an attack target (victim) as a final destination.
[0047] In the diamond analysis model, a node represents an attack technique and a state, a vector represents an activity thread, and a graph represents an attack graph.
[0048] The cyber attack is performed in an attack direction from top to bottom, and the attack graph can be formed by creating an attack scenario against an attack target (victim) at at least one node.
[0049] In the algorithm, a node belonging to predecessor data representing a potential attack vector is selected, and an attack target (victim) is selected from targets representing a ship or a computer-based system (CBS).
[0050] Next, each node in the attack vector is repeated to confirm whether the corresponding node belongs to a subset of the previous node, and when it is confirmed that the corresponding node belongs to the subset of the previous node, the attack flow proceeds to the next node.
[0051] If the node belongs to the subset of attack targets, the attack flow proceeds to the next node in the attack vector.
[0052] Then, if the node is a subset of attack targets, the network attack is considered successful.
[0053] The data collection criteria can collect a threat database (DB) based on marine threat intelligence information (Indicators of Compromise (IoC), Common Vulnerabilities and Exposures (CVE), Common Platform Enumeration (CPE), Common Weakness Enumeration (CWE), Common Vulnerability Scoring System (CVSS), Dark Web, Attack Case).
[0054] In identifying ship system and stakeholder assets, assets can be identified based on ship system information, stakeholder accounts including crew, and network information (Internet Protocol (IP), Domain, Domain Name System (DNS), etc.) of related companies.
[0055] In the present disclosure, the cyber attack tree (CAT) model and the diamond analysis model are selected because the combination of these models can provide a comprehensive and flexible approach to understanding cyber attack scenarios, and the top-down and vertical attack direction can provide a deeper understanding of the dependency between cyber attacks.
[0056] In addition, the compatibility of the MITRE ATT&CK framework combined with the diamond analysis model is advantageous in analyzing intrusion techniques, attack techniques, attack strategies, etc.
[0057] By combining the models, different types of cyber attack scenarios can be effectively analyzed.
[0058] Therefore, in analyzing the cyber attack model, the MITRE ATT&CK framework is used to systematically understand each phase and component of the attack.
[0059] The techniques in the MITRE ATT&CK framework can be used to classify the attack phases in the cyber attack model, and the attack status and techniques of each node can be analyzed by sub-techniques or tactics.
[0060] This approach provides an in-depth understanding of the tactics and strategies used by attackers and helps to understand the motivation of the attacker. In addition, reference can be made to the International Association of Classification Societies (IACS) guideline No. 171 to determine the impact of a cyber attack on the availability, confidentiality, integrity, and traceability of systems and equipment.
[0061] In addition, reference is made to the impact of potential accidents in the Unified Requirement (UR) E22 guideline to determine the damage and potential impact on the onboard CBS of a ship.
[0062] In order to develop countermeasures to mitigate the damage caused by a cyber attack by providing insights into the tactics and strategies used by cyber attackers, the cyber attack scenario model employs mitigation measures of the MITRE ATT&CK framework. In the framework, the attack behavior of cyber attackers can be analyzed and mitigation measures that can counter cyber attacks by cyber attackers can be suggested to develop countermeasures against attack surfaces.
[0063] In addition, in the event of a cyber attack, potential damage to a ship can be assessed, mitigation measures can be developed, and cyber attacks can be mitigated by strengthening the cyber security posture and proactive planning.
[0064] Figure 6 is an algorithm of a cyber attack scenario of a ship according to another embodiment of the present application, and Figure 7 is a diagram showing an attack graph generated by the algorithm of the embodiment of the present application shown in Figure 6 is a diagram showing an attack graph generated by the algorithm of the embodiment of the present application shown in
[0065] In the attack scenario against an attack target at each node, attack techniques and tactics can be represented by three stages.
[0066] In a cyber attack scenario against a Very Small Aperture Terminal (VSAT) communication, a list of vulnerabilities is used to collect threat information about a VSAT asset. The list is Common Vulnerabilities and Exposures (CVE), which is a collection of software and firmware vulnerabilities identified and categorized by MITRE (a non-profit research and development organization funded by the US federal government), and can be used as precursor threat data for a VSAT asset.
[0067] Here, a node belonging to CVE data is selected, and a VSAT is selected as an attack target.
[0068] If the node n1 belongs to the node n0, information collection is performed through active scanning, and if the node n2 belongs to the node n1, cross site scripting is performed.
[0069] If the node n5 belongs to the node n2, web session hijacking is performed.
[0070] If the node n3 belongs to the node n1, arbitrary content is written, and if the node n4 belongs to the node n1, code spoofing is performed.
[0071] If any one of the nodes n3, n4, and n5 belongs to the attack target (t0), credential theft is performed.
[0072] If the node n6 belongs to the attack target (t0), scanning of a ship network is performed, and if the node n6 belongs to the node n7, extension and propagation are performed.
[0073] If the new attack target (t1) belongs to the node n7, it is determined that a method for a cyber attack against a ship system is successful.
[0074] Accordingly, according to the present application, it is possible to construct a system capable of representing an attack graph through a combination of a cyber attack tree (CAT) model and a diamond analysis model, and capable of identifying a potential attack surface of a ship system and securing a cyber attack countermeasure capability by developing a cyber attack scenario of a ship.
[0075] Further, the present application has an effect capable of detecting inherent vulnerabilities and potential vulnerabilities of a ship system through a cyber attack scenario.
[0076] Further, the present application has an effect of providing a preventive countermeasure by creating a potential cyber threat scenario from a cyber attack scenario, and helping to enhance overall cyber resilience by identifying a potential attack surface, and establishing an effective strategy for counterattacking a cyber attack by identifying and analyzing the entire range of a cyber attack through an attack graph.
[0077] Further, by evaluating a scenario-based graph through a threat analysis method, the present application has an effect of enhancing a manager's cyber attack countermeasure capability and cyber risk management in practice.
[0078] The above-described embodiments of the present application can be implemented in the form of program instructions executable by various computer components and recorded in a computer-readable recording medium. The computer-readable recording medium can include program instructions, data files, data structures, etc. individually or in combination. The program instructions recorded on the computer-readable recording medium can be specifically designed and constructed for the present application, or can be known and available to those skilled in the computer software field. Examples of the computer-readable medium include hardware devices specifically configured to store and execute program instructions, including magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as compact disc read-only memories (CD-ROMs) and digital versatile discs (DVDs); magneto-optical media such as floptical disks; read-only memories (ROMs); random access memories (RAMs); and flash memories. Examples of the program instructions include not only machine language codes produced by a compiler but also high-level language codes executable by a computer using an interpreter, etc. The hardware devices can be configured to operate as one or more software modules to perform operations according to the present application, or vice versa.
[0079] Although some embodiments have been described herein, it should be understood that these embodiments are offered by way of illustration only, and should not be construed in any way limiting the present application, and that various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application. Accordingly, the appended claims and their equivalents are intended to cover such changes or modifications as would fall within the scope and spirit of the present application.
Claims
1. A method for developing ship cyberattack scenarios, comprising: The asset identification step identifies the ship system and stakeholder assets. The threat data verification step involves analyzing the asset information identified in the asset identification step to determine whether threat data exists. The attack target selection step involves selecting an attack target when at least one of the identified assets is confirmed to exist in the threat data during the threat data confirmation step. The attack scenario creation step involves creating an attack scenario targeting the attack target selected in the attack target selection step. as well as The attack graph output step outputs an attack graph based on the attack scenario created in the attack scenario creation step.
2. The method for developing ship network attack scenarios according to claim 1, wherein the attack scenario creation step includes: The attack target vulnerability allocation step involves allocating vulnerabilities to the selected attack target. The attack execution step involves performing an attack based on the vulnerability assigned to the target in the attack target vulnerability allocation step. Subsequent attack execution steps, in which different techniques or tactics are used to execute subsequent attacks after the execution of the attack execution steps; The attack target strike step, wherein the attack target is struck after the subsequent attack execution step; The postcondition derivation step is performed after the target is attacked in the target attack step. An additional attack surface identification step, wherein the additional attack surface is identified based on the content exported in the post-condition derivation step; and The attack graph formation step involves forming an attack graph based on the attack scenario being executed.
3. The method for developing ship network attack scenarios according to claim 2, wherein the attack scenario creation step further includes: If the additional attack surface is identified in the additional attack surface identification step, then the subsequent attack is executed; as well as Additional attacks are performed by striking n additional targets.
4. The method for developing ship network attack scenarios according to claim 1, wherein the attack graph output step includes visualizing the attack graph and outputting the attack graph by combining a network attack tree (CAT) model with a diamond analysis model.
5. The method for developing ship network attack scenarios according to claim 4, wherein the attack graph output step includes: The scope of capture attack techniques and characteristics; And enable the identification of potential attack surfaces.
6. A system for developing ship cyberattack scenarios, comprising: The asset identification unit is configured to identify ship systems and stakeholder assets. The threat data confirmation unit is configured to analyze asset information identified by the asset identification unit to determine whether threat data exists. The attack target selection unit is configured to select an attack target when the threat data confirmation unit confirms that at least one of the identified assets exists in the threat data; The attack scenario creation unit is configured to create an attack scenario for the attack target selected by the attack target selection unit. as well as The attack graph output unit is configured to output an attack graph based on the attack scenario created by the attack scenario creation unit.
7. The system for developing ship network attack scenarios according to claim 6, wherein the attack scenario creation unit further comprises: The attack target vulnerability allocation unit is configured to allocate vulnerabilities to the selected attack target; An attack execution unit is configured to execute an attack based on a vulnerability assigned to the target by the attack target vulnerability allocation unit. The subsequent attack execution unit is configured to use different techniques or tactics than the attack execution unit to execute the subsequent attack; The attack target strike unit is configured to strike the attack target subsequently attacked by the subsequent attack execution unit; The postcondition derivation unit is configured to derive postconditions after the target of attack is struck by the target of attack unit. The additional attack surface identification unit is configured to identify additional attack surfaces based on the content exported by the post-conditional derivation unit; and The attack graph forming unit is configured to form an attack graph based on the executed attack scenario if no additional attack target is identified by the additional attack surface identification unit.
8. The system for developing ship network attack scenarios according to claim 7, wherein the attack scenario creation unit further comprises: The subsequent attack execution unit is configured to execute a subsequent attack if the additional attack surface is identified by the additional attack surface identification unit. And additional attack target strike units, configured to perform additional attacks by striking n additional attack targets.
9. The system for developing ship network attack scenarios according to claim 6, wherein the attack graph output unit visualizes and outputs the attack graph by combining a network attack tree (CAT) model with a diamond analysis model.
10. The system for developing ship network attack scenarios according to claim 9, wherein the attack graph output unit captures the range of attack techniques and characteristics and identifies potential attack surfaces.
Citation Information
Patent Citations
System and Method for Cyber Attack History Tracking based on Scenario
KR101697189B1