Information visualization device, information visualization method, and program
The information visualization device addresses the challenge of visualizing cyber attack progression by inferring attack processes, identifying locations, and generating directed graphs, thereby enhancing the ability of system administrators to respond effectively to cyber threats.
Patent Information
- Application Number
- JP2023528844
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-06-16
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2041-06-16
AI Technical Summary
Existing information visualization devices for cyber attacks lack the ability to directly visualize the actual course of an attack, making it difficult for system administrators to quickly respond to cyber threats.
An information visualization device that infers the process of a cyber attack using observation data and inference knowledge, identifies locations within the system where the attack occurred, and generates a directed graph to visually represent the attack path.
Enables system administrators to visually understand the progression of a cyber attack, identify affected locations, and take timely measures to mitigate the threat.
Smart Images

Figure 0007679878000001 
Figure 0007679878000002 
Figure 0007679878000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an information visualization device and an information visualization method for enabling a response to a cyber attack, and further relates to a program for implementing the same. To Regarding. [Background technology]
[0002] In recent years, the role of computer systems has become increasingly important in companies and other organizations, as well as in society. As a result, the threat of cyber attacks against confidential information management by computer systems has become more serious. Furthermore, since such cyber attacks advance while expanding their scope within an organization, it is important to quickly recognize them, understand the history of the attack by the software (malware, virus, etc.) that has invaded the organization, and take the necessary measures as soon as possible.
[0003] For this reason, for example, Patent Document 1 discloses a device that extracts a chain of attack paths across a group of devices that constitute a system as the course of an attack, and analyzes the threats expected to the system. Specifically, the device disclosed in Patent Document 1 first graphs the relationships between devices from an input network configuration diagram, and traces the expected infection paths of computer viruses, etc. from the graph to identify the attack path. Next, the device disclosed in Patent Document 1 searches a database that stores attack uses and attack examples in cyber attacks using the conditions of each device (device type, status, etc.) as a query, and displays the search results in association with the identified attack path. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2019 / 011060 Summary of the Invention [Problem to be solved by the invention]
[0005] According to the device disclosed in the above-mentioned Patent Document 1, when a system is attacked, the route of the attack and related attack cases are displayed, so that the system administrator can respond based on past cases.
[0006] However, since the information displayed by the device disclosed in Patent Document 1 is not the result of analyzing a specific attack on the system, the system administrator cannot directly grasp the actual course of the attack. With the device disclosed in Patent Document 1, it is difficult for the administrator to quickly take necessary measures when the system is attacked.
[0007] An example of the object of the present invention is to provide an information visualization device, an information visualization method, and program The purpose of this invention is to provide [Means for solving the problem]
[0008] In order to achieve the above object, an information visualization device according to one aspect of the present invention comprises: an inference unit that infers a process of a cyber-attack by using observation data representing an event observed during a cyber-attack on a computer system and inference knowledge; a location identification unit that identifies a location in the computer system where the event was observed from the observation data; and a graph generation unit that generates a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display unit that displays the directed graph; Equipped with It is characterized by:
[0009] In order to achieve the above object, an information visualization method according to one aspect of the present invention comprises: an inference step of inferring a process of the cyber-attack by using observation data representing an event observed during the cyber-attack on the computer system and inference knowledge; a location identification step of identifying a location in the computer system where the event was observed from the observation data; a graph generation step of generating a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display step of displaying the directed graph; having It is characterized by:
[0010] Further, in order to achieve the above object, in one aspect of the present invention, program teeth, On the computer, an inference step of inferring a process of the cyber-attack by using observation data representing an event observed during the cyber-attack on the computer system and inference knowledge; a location identification step of identifying a location in the computer system where the event was observed from the observation data; a graph generation step of generating a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display step of displaying the directed graph; Run 、 It is characterized by: Effect of the Invention
[0011] As described above, according to the present invention, the progress of a cyber attack can be visualized. [Brief description of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of an information visualization device according to an embodiment. [Diagram 2]FIG. 2 is a configuration diagram specifically showing the configuration of the information visualization device according to the embodiment. [Diagram 3] FIG. 3 is a flow diagram showing the operation of the information visualization device in the embodiment. [Figure 4] FIG. 4 is a diagram showing an example of observed data used in the specific example. [Diagram 5] FIG. 5 is a diagram showing an example of inference knowledge used in a specific example. [Figure 6] FIG. 6 is a diagram showing an example of the result (hypothesis) of the inference executed in the specific example. [Figure 7] FIG. 7 is a diagram showing an example of a TTPs graph obtained from the inference result shown in FIG. [Figure 8] FIG. 8 is a diagram showing an example of a directed graph generated in the specific example. [Figure 9] FIG. 9 is a diagram showing an example of a display screen in the specific example. [Figure 10] FIG. 10 is a block diagram showing an example of a computer that realizes the information visualization device according to the embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0013] (Embodiment) An information visualization device, an information visualization method, and a program according to an embodiment will be described below with reference to FIGS.
[0014] [Device configuration] First, a schematic configuration of an information visualization device in an embodiment will be described with reference to Fig. 1. Fig. 1 is a configuration diagram showing a schematic configuration of an information visualization device in an embodiment.
[0015] 1, an information visualization device 10 is a device for visualizing the history of a cyber-attack on a computer system to facilitate a response to the cyber-attack. As shown in FIG. 1, the information visualization device 10 includes an inference unit 11, a location identification unit 12, a graph generation unit 13, and a graph display unit 14.
[0016] The inference unit 11 infers the course of a cyber-attack by using observation data representing an event observed during a cyber-attack on a computer system and inference knowledge. The location identification unit 12 identifies the location in the computer system where the event was observed from the observation data.
[0017] The graph generation unit 13 generates a directed graph in which the identified locations are nodes and edges based on the observed data or the inferred circumstances are set between the nodes. The graph display unit 14 displays the generated directed graph.
[0018] In this way, when a cyber-attack is observed, the information visualization device 10 can infer the course of the cyber-attack and identify the location where the attack was observed, and further generate and display a directed graph using the inference result and the identified location. Therefore, when a computer system is subjected to a cyber-attack, the information visualization device 10 can visualize the course of the attack.
[0019] Next, the configuration and functions of the information visualization device in the embodiment will be specifically described with reference to Fig. 2. Fig. 2 is a configuration diagram specifically showing the configuration of the information visualization device in the embodiment.
[0020] 2, in the embodiment, the information visualization device 10 is connected to a computer system 30. The computer system 30 is constructed by a large number of terminal devices connected via a network. When the computer system 30 is subjected to a cyber-attack, the information visualization device 10 visualizes the course of the cyber-attack.
[0021] As shown in FIG. 2, the information visualization device 10 includes an observation data acquisition unit 15 in addition to the inference unit 11, the place identification unit 12, the graph generation unit 13, and the graph display unit 14 described above.
[0022] The observation data acquisition unit 15 acquires observation data at the time of a cyber attack from the computer system 30. Specifically, the observation data acquisition unit 15 acquires the operation logs of each terminal constituting the computer system 30, and can collect the acquired operation logs, information on the terminal from which the operation logs were acquired, and time information, etc., into data in a setting format, which can be acquired as the observation data. For example, assume that an event occurs in which the terminal "alice" receives an email identified by the identification information "hoge" at 10:21:35, and the observation data acquisition unit 15 acquires an operation log representing this event. In this case, the observation data acquisition unit 15 creates data in the format of "emailReceived("10:21:35", "alice", "hoge")" and acquires this data as the observation data. A first-order predicate logical formula is adopted as the data setting format, and the observation data is composed of a predicate name and a term in parentheses. In addition, the combination of this predicate and parentheses is also referred to as a "literal" hereinafter.
[0023] In the embodiment, the inference unit 11 acquires inference knowledge stored in the inference knowledge database 20. In the example of Fig. 2, the inference knowledge database 20 is a database located outside the information visualization device 10, but it may be a database provided in the information visualization device 10 instead.
[0024] In the embodiment, the inference knowledge is expressed, for example, in the form of "pre-state (presupposition) ∧ action (achievement state) ⇒ post-state (conclusion)". This form indicates that if the pre-state, which is the premise, and the action (achievement state) are both true, the post-state, which is the necessary conclusion, is derived. In this form, the pre-state and the action are each necessary conditions for the post-state to be true. "Pre-state ∧ action" is a sufficient condition for the post-state to be true. An action can also be expressed as a conjunction of multiple propositions. For example, the knowledge data may be expressed as "pre-state ∧ action 1 ∧ action 2 ⇒ post-state".
[0025] A specific example of inference knowledge is "Malware intrusion (Event1, Mal) ∧ Unauthorized logon (Event2, Host, Host1) ⇒ Spread of infection (Plan, Mal, Host1)." In this case, Event1, Mal, Host, etc. are variables called "terms" of each predicate. A logical expression in which a "term" has a specific value is called an "observation." An example is "Unauthorized logon ("e1", "10.23.123.1")."
[0026] In the embodiment, the inference unit 11 obtains a hypothesis by applying the inference knowledge acquired from the inference knowledge database to the observation data acquired by the observation data acquisition unit 15. The obtained hypothesis corresponds to the course of a cyber-attack, specifically, the tactics, techniques, and procedures of a cyber-attack. Hereinafter, the tactics, techniques, and procedures are collectively referred to as "TTPs." Furthermore, the inference unit 11 graphs the TTPs obtained by inference. Hereinafter, the graphed TTPs are referred to as a "TTPs graph."
[0027] In the embodiment, the location identification unit 12 identifies the location where the event was observed using the observation data on which the tactic was based or the observation data on which the technique was based. Furthermore, when the location identification unit 12 identifies the location where the event was observed using the observation data on which the technique was based, the location identification unit 12 associates the identified location with the technique on which the observation data is based. Furthermore, in this case, the location identification unit 12 also associates the tactic corresponding to the technique associated with the observation data with the identified location.
[0028] The graph generating unit 13 generates a directed graph with the identified locations as nodes while referring to the above-mentioned TTPs graph. Furthermore, in the embodiment, the graph generating unit 13 sets edges between the nodes based on observation data including information representing two or more locations or on an inferred procedure. Specifically, the graph generating unit 13 generates a directed graph expressing the relationship between two or more locations using, for example, one piece of observation data related to two or more locations, that is, observation data that is the basis of a method for achieving a tactic while moving between terminal devices.
[0029] In the embodiment, the graph display unit 14 displays the directed graph on the screen of the display device 40 in a state in which a tactic or technique based on the observation data used to identify the location of each node is added to each node. The graph display unit 14 can also display the directed graph on the screen of a terminal device connected to the information visualization device 10 via a network.
[0030] The graph display unit 14 can also display the corresponding observation data for each node or each tactic in the directed graph. Furthermore, when displaying the directed graph, the graph display unit 14 can also display a time axis on the screen and display the nodes on this time axis based on time information included in the observation data that identifies the nodes.
[0031] [Device operation] Next, the operation of the information visualization device 10 in the embodiment will be described with reference to Fig. 3. Fig. 3 is a flow diagram showing the operation of the information visualization device in the embodiment. In the following description, Figs. 1 and 2 will be referred to as appropriate. Also, in the embodiment, an information visualization method is implemented by operating the information visualization device 10. Therefore, the description of the information visualization method in the embodiment will be replaced with the following description of the operation of the information visualization device 10.
[0032] 3, first, the observation data acquisition unit 15 acquires observation data during a cyber-attack from the computer system 30 (step A1). Specifically, the observation data acquisition unit 15 acquires an operation log indicating each operation performed by software on a terminal constituting the computer system 30, and creates data in a setting format from the acquired operation log, terminal device information, time information, etc. Then, the observation data acquisition unit 15 acquires the created data as observation data.
[0033] Next, the inference unit 11 acquires inference knowledge from the inference knowledge database 20 and applies the acquired inference knowledge to the observation data acquired in step A1 to infer the tactics, methods, and procedures that constitute the course of the cyber attack (step A2).
[0034] Next, the location identification unit 12 identifies the location where the event was observed by using the observation data on which the tactic obtained by the inference was based or the observation data on which the method obtained by the inference was based (step A3). Specifically, the location identification unit 12 identifies the terminal device on which the event was observed by using the observation data.
[0035] Next, the graph generation unit 13 generates a directed graph in which the places identified in step A3 are nodes (step A4). In step A4, the graph generation unit 13 also sets edges between the nodes based on the observed data including information representing two or more places or on the inferred procedure.
[0036] Next, in this embodiment, the graph display unit 14 displays the directed graph with a tactic or technique based on the observation data used to identify the location of each node added to each node (step A5).
[0037] In step A5, the graph display unit 14 can also display the corresponding observation data for each node or each tactic in the directed graph. Furthermore, when displaying the directed graph, the graph display unit 14 can also display a time axis on the screen and display the nodes on this time axis based on time information included in the observation data that identifies the nodes.
[0038] [Specific example] Here, a specific example of the operation of the information visualization device 10 in the embodiment will be described with reference to Fig. 4 to Fig. 9. The specific example will be described along the steps shown in Fig. 3 above.
[0039] [Step A1] The observation data acquisition unit 15 acquires operation logs from each terminal constituting the computer system 30, and creates data in a setting format from the acquired operation logs, terminal information, time information, etc. Then, the observation data acquisition unit 15 acquires the created data as observation data. A specific example of the observation data is as shown in FIG. 4. The source of the observation data may be a router, a switching hub, etc. other than a terminal device. FIG. 4 is a diagram showing an example of the observation data used in the specific example.
[0040] [Step A2] The inference unit 11 applies the inference knowledge shown in Fig. 5 to the operation log acquired in step A1 to execute inference, and obtains the hypothesis shown in Fig. 6. Fig. 5 is a diagram showing an example of the inference knowledge used in the specific example. Fig. 6 is a diagram showing an example of the result (hypothesis) of the inference executed in the specific example.
[0041] Next, the inference unit 11 sets the lowest layer by the part of the hypothesis that represents the observed event, and sets the layer of events above the lowest layer using the consequences included in the rules that indicate the relationship between events, thereby constructing a hierarchical structure of events. The constructed hierarchical structure becomes a TTPs graph. Figure 7 is a diagram showing an example of a TTPs graph obtained from the inference result shown in Figure 6.
[0042] Specifically, in the example of FIG. 7, the inference unit 11 sets the lowest layer of the hierarchical structure of events by the following parts representing the events in the hypothesis shown in FIG. "hasAttachedFile" "isUnknownSender" "emailReceived" "openFile" “vulnerableProgramExecuted” "exeFileCreated" "isAbnormalWorkTime" "remoteLogon" "exeFileCreated" "queryRegistry"
[0043] Furthermore, the inference unit 11 sets a layer above the lowest layer in the hierarchical structure of events by using the following consequences included in the inference knowledge shown in FIG. "suspiciousFileReceived" "malwareInjected" "suspiciousExeCreated" "Lateral Movement" "suspiciousLogon" "resourceDiscovery"
[0044] [Step A3]
[0045] The location identification unit 12 identifies the observation data that is the basis of the tactics or the method from among the observation data shown in Fig. 4, and identifies the location where the event was observed based on the name of the terminal (hereinafter referred to as "host name") or IP address included in the identified observation data. For example, if the observation data is the above-mentioned "emailReceived("10:21:35", "alice", "hoge")", the host name "alice" receives the email identified by the identification information "hoge", so the host name "alice" is identified as the location. In Fig. 7, the dashed lines indicate the observed events for each terminal device.
[0046] [Step A4] The graph generation unit 13 first extracts events and edges (arrows) between events that have the host name specified as the location as an attribute and are in the top layer from the TTPs graph shown in Fig. 7. Then, the graph generation unit 13 sets the host name specified as the location as a node, and further determines edges between the nodes based on the edges between the events to generate a directed graph shown in Fig. 8. Specifically, the edges between the nodes are determined based on information (movement source, movement destination, etc.) that the event "lateralMovement" has. Fig. 8 is a diagram showing an example of a directed graph generated in the specific example.
[0047] [Step A5] The graph display unit 14 displays the directed graph shown in Fig. 8 on the screen. At this time, the graph display unit 14 extracts a time from the literal of the observed event for each node (terminal device) in the directed graph, and identifies the earliest time among the extracted times. Then, the graph display unit 14 displays a time axis on the screen as shown in Fig. 9, and further arranges each node on the time axis according to the identified time. Fig. 9 is a diagram showing an example of a display screen in a specific example.
[0048] The graph display unit 14 also arranges the events extracted in step A4 for each node on the screen. Furthermore, when the user performs an operation to select a node on the screen, the graph display unit 14 can display a literal related to the selected node and a value of a term (attribute) included in the literal (for example, the value of IoC shown in FIG. 9).
[0049] [Effects of the embodiment] As described above, according to the embodiment, a directed graph showing the TTPs and the locations of attacks is displayed. Therefore, a user such as a computer system administrator can simultaneously grasp the "flow of the cyber attack," "locations where malware is active and where the effects of the attack are being felt," and "how the attack spreads." In addition, in the embodiment, the user can instantly understand the correspondence in the cyber attack, for example, what happened on which terminal device, etc.
[0050] Furthermore, as shown in Fig. 9, the user can grasp the IoC of the terminal device under cyber attack and the literals that constitute the observation data, so that the user can easily analyze and take measures against the cyber attack. According to the embodiment, it is possible to more directly provide the user with comprehensive information that is useful when responding to an incident.
[0051] [program] The program in the embodiment may be any program that causes a computer to execute steps A1 to A5 shown in Fig. 3. By installing and executing this program in a computer, the information visualization device 10 and the information visualization method in the embodiment can be realized. In this case, the processor of the computer functions as an inference unit 11, a location identification unit 12, a graph generation unit 13, a graph display unit 14, and an observation data acquisition unit 15, and performs processing. Examples of the computer include a general-purpose PC, a smartphone, and a tablet terminal device.
[0052] The program in the embodiment may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as any one of the inference unit 11, the location identification unit 12, the graph generation unit 13, the graph display unit 14, and the observation data acquisition unit 15.
[0053] [Physical configuration] Here, a computer that realizes the information visualization device 10 by executing the program in the embodiment will be described with reference to Fig. 10. Fig. 10 is a block diagram showing an example of a computer that realizes the information visualization device in the embodiment.
[0054] 10, a computer 110 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These components are connected to each other via a bus 121 so as to be able to communicate data with each other.
[0055] Furthermore, the computer 110 may include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array) in addition to or instead of the CPU 111. In this embodiment, the GPU or FPGA can execute the programs in the embodiments.
[0056] The CPU 111 loads a program in the embodiment, which is composed of a group of codes and is stored in the storage device 113, into the main memory 112, and executes each code in a predetermined order to perform various calculations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).
[0057] Moreover, the program in the embodiment is provided in a state stored in a computer-readable recording medium 120. The program in the embodiment may be distributed on the Internet connected via the communication interface 117.
[0058] Specific examples of the storage device 113 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to a display device 119 and controls the display on the display device 119.
[0059] Data reader / writer 116 mediates data transmission between CPU 111 and recording medium 120, reads programs from recording medium 120, and writes processing results in computer 110 to recording medium 120. Communication interface 117 mediates data transmission between CPU 111 and other computers.
[0060] Specific examples of the recording medium 120 include general-purpose semiconductor storage devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as a flexible disk, or optical recording media such as a CD-ROM (Compact Disk Read Only Memory).
[0061] The information visualization device 10 in the embodiment can be realized not by a computer with a program installed, but by hardware corresponding to each part, such as an electronic circuit. Furthermore, the information visualization device 10 may be partially realized by a program and the remaining part by hardware.
[0062] A part or all of the above-described embodiment can be expressed by (Additional Notes 1) to (Additional Notes 15) described below, but is not limited to the following descriptions.
[0063] (Appendix 1) an inference unit that infers a process of a cyber-attack by using observation data representing an event observed during a cyber-attack on a computer system and inference knowledge; a location identification unit that identifies a location in the computer system where the event was observed from the observation data; a graph generation unit that generates a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display unit that displays the directed graph; Equipped with An information visualization device comprising:
[0064] (Appendix 2) 2. The information visualization device according to claim 1, The inference unit infers tactics, techniques, and procedures in the cyber attack as a history of the cyber attack, the location identification unit identifies a location where the event was observed by using the observation data on which the tactic is based or the observation data on which the method is based; The graph generation unit sets the edges based on the observation data including information representing two or more of the locations or the inferred procedure. An information visualization device comprising:
[0065] (Appendix 3) 3. The information visualization device according to claim 2, the graph display unit displays the directed graph in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to each of the nodes. An information visualization device comprising:
[0066] (Appendix 4) 4. The information visualization device according to claim 3, the graph display unit displays the corresponding observation data for each of the nodes or each of the tactics in the directed graph. An information visualization device comprising:
[0067] (Appendix 5) An information visualization device according to any one of Supplementary Note 1 to 4, the graph display unit displays a time axis on a screen, and when displaying the directed graph, displays the nodes on the time axis based on time information included in the observation data that identifies the nodes. An information visualization device comprising:
[0068] (Appendix 6) an inference step of inferring a process of the cyber-attack by using observation data representing an event observed during the cyber-attack on the computer system and inference knowledge; a location identification step of identifying a location in the computer system where the event was observed from the observation data; a graph generation step of generating a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display step of displaying the directed graph; having 13. An information visualization method comprising:
[0069] (Appendix 7) 7. The information visualization method according to claim 6, In the inference step, tactics, techniques, and procedures in the cyber attack are inferred as the history of the cyber attack; In the location identification step, a location where the event was observed is identified using the observation data on which the tactic is based or the observation data on which the method is based; In the graph generation step, the edges are set based on the observation data including information representing two or more of the locations or the inferred procedure. 13. An information visualization method comprising:
[0070] (Appendix 8) 8. The information visualization method according to claim 7, In the graph display step, the directed graph is displayed in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to the node. 13. An information visualization method comprising:
[0071] (Appendix 9) 9. The information visualization method according to claim 8, In the graph display step, the observation data corresponding to each of the nodes or each of the tactics in the directed graph are displayed. 13. An information visualization method comprising:
[0072] (Appendix 10) An information visualization method according to any one of Supplementary Notes 6 to 9, a time axis is displayed on a screen in the graph display step, and when displaying the directed graph, the nodes are displayed on the time axis based on time information included in the observation data that identifies the nodes. 13. An information visualization method comprising:
[0073] (Appendix 11) On the computer, an inference step of inferring a process of the cyber-attack by using observation data representing an event observed during the cyber-attack on the computer system and inference knowledge; a location identification step of identifying a location in the computer system where the event was observed from the observation data; a graph generation step of generating a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display step of displaying the directed graph; Run R, Program Hmm.
[0074] (Appendix 12) As described in Appendix 11 program And, In the inference step, tactics, techniques, and procedures in the cyber attack are inferred as the history of the cyber attack; In the location identification step, a location where the event was observed is identified using the observation data on which the tactic is based or the observation data on which the method is based; In the graph generation step, the edges are set based on the observation data including information representing two or more of the locations or the inferred procedure. Characterized by program .
[0075] (Appendix 13) As described in Appendix 12 program And, In the graph display step, the directed graph is displayed in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to the node. Characterized by program .
[0076] (Appendix 14) As described in Appendix 13 program And, In the graph display step, the observation data corresponding to each of the nodes or each of the tactics in the directed graph are displayed. Characterized by program .
[0077] (Appendix 15) Any of Supplementary Notes 11 to 14 program And, a time axis is displayed on a screen in the graph display step, and when displaying the directed graph, the nodes are displayed on the time axis based on time information included in the observation data that identifies the nodes. Characterized by program .
[0078] Although the present invention has been described above with reference to the embodiment, the present invention is not limited to the above embodiment. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Industrial Applicability]
[0079] INDUSTRIAL APPLICABILITY As described above, according to the present invention, the progress of a cyber-attack can be visualized. The present invention is useful for various computer systems. [Explanation of symbols]
[0080] 10 Information visualization device 11 Reasoning part 12 Location Identification Section 13 Graph Generation Unit 14 Graph display section 15 Observation data acquisition section 20 Inference Knowledge Database 30 Computer Systems 40 Display device 110 Computer 111 CPU 112 Main memory 113 Storage device 114 Input Interface 115 Display Controller 116 Data Reader / Writer 117 Communication Interface 118 Input Devices 119 Display device 120 Recording media 121 Bus
Claims
1. an inference unit that infers a process of a cyber-attack by using observation data representing an event observed during a cyber-attack on a computer system and inference knowledge; a location identification unit that identifies a location in the computer system where the event was observed from the observation data; a graph generation unit that generates a directed graph in which the identified locations are set as nodes and edges based on the observation data or the inferred history are set between the nodes; a graph display unit that displays the directed graph; Equipped with An information visualization device comprising:
2. The information visualization device according to claim 1 , The inference unit infers tactics, techniques, and procedures in the cyber attack as a history of the cyber attack, the location identification unit identifies a location where the event was observed by using the observation data on which the tactic is based or the observation data on which the method is based; the graph generation unit sets the edges based on the observation data including information representing two or more of the locations or based on the inferred procedure; An information visualization device comprising:
3. The information visualization device according to claim 2, the graph display unit displays the directed graph in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to each of the nodes. An information visualization device comprising:
4. The information visualization device according to claim 3, the graph display unit displays the corresponding observation data for each of the nodes or each of the tactics in the directed graph. An information visualization device comprising:
5. The information visualization device according to claim 1 , the graph display unit displays a time axis on a screen, and when displaying the directed graph, displays the nodes on the time axis based on time information included in the observation data that identifies the nodes. An information visualization device comprising:
6. Inferring a course of a cyber-attack using observation data representing events observed during a cyber-attack on a computer system and inference knowledge; identifying, from the observation data, a location in the computer system where the event was observed; A directed graph is generated in which the identified locations are nodes and edges based on the observation data or the inferred history are set between the nodes; Displaying the directed graph; 13. An information visualization method comprising:
7. The information visualization method according to claim 6, In the inference, the tactics, methods, and procedures in the cyber attack are inferred as the history of the cyber attack; In the identification of the location, a location where the event was observed is identified using the observation data on which the tactic is based or the observation data on which the method is based; In generating the directed graph, the edges are set based on the observation data including information representing two or more of the locations or based on the inferred procedure.
13. An information visualization method comprising:
8. The information visualization method according to claim 7, In displaying the directed graph, the directed graph is displayed in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to the directed graph.
13. An information visualization method comprising:
9. The information visualization method according to claim 8, In displaying the directed graph, the observation data corresponding to each of the nodes or each of the tactics in the directed graph is displayed.
13. An information visualization method comprising:
10. The information visualization method according to claim 6, a time axis is displayed on a screen in displaying the directed graph, and when displaying the directed graph, the nodes are displayed on the time axis based on time information included in the observation data that identifies the nodes.
13. An information visualization method comprising:
11. On the computer, inferring a process of a cyber-attack using observation data representing events observed during a cyber-attack on a computer system and inference knowledge; determining, from the observation data, a location in the computer system where the event was observed; generating a directed graph in which the identified locations are nodes and edges based on the observation data or the inferred history are set between the nodes; Displaying the directed graph; program.
12. The program according to claim 11, In the inference, the tactics, methods, and procedures in the cyber attack are inferred as the history of the cyber attack; In the identification of the location, a location where the event was observed is identified using the observation data on which the tactic is based or the observation data on which the method is based; In generating the directed graph, the edges are set based on the observation data including information representing two or more of the locations or based on the inferred procedure. A program characterized by:
13. The program according to claim 12, In displaying the directed graph, the directed graph is displayed in a state in which the tactic or the method based on the observation data used to identify the location of each of the nodes is added to the directed graph. A program characterized by:
14. The program according to claim 13, In displaying the directed graph, the observation data corresponding to each of the nodes or each of the tactics in the directed graph is displayed. A program characterized by:
15. The program according to claim 11, a time axis is displayed on a screen in displaying the directed graph, and when displaying the directed graph, the nodes are displayed on the time axis based on time information included in the observation data that identifies the nodes. A program characterized by:
Citation Information
Patent Citations
Network attack scene generating method based on multi-source alarm logs
CN104539626A
Method and device for detecting fault position on network and storage medium for storing network fault position detecting program
JP1999259331A
Graphical models for cyber security analysis in enterprise networks
US8881288B1
Attack analysis system, coordination device, attack analysis coordination method, and program
WO2014112185A1
System-monitoring information processing device and monitoring method
WO2015140842A1