Attack path presentation device, attack path presentation method, and attack path presentation program
Patent Information
- Application Number
- JP2025564683
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Filing Date
- 2023-12-20
- Publication Date
- 2025-06-26
Claims
1. An extraction means for extracting multiple attack paths from an entry point to an attack target in a cyberattack on an information processing system, from information representing the information processing system, Regarding each of the aforementioned attack paths, an acquisition means for acquiring information representing the risk of success of a cyberattack against a target included in the aforementioned attack path, A setting means that sets a higher priority for presenting the attack path the fewer the number of targets included in the attack path and the higher the risk, A presentation means for presenting the attack paths to the user in accordance with the aforementioned priority, An attack path presentation device equipped with the following features.
2. The setting means calculates the priority using a calculation formula for determining the priority from the number of targets included in the attack path and a value representing the risk. The attack path presentation device according to claim 1.
3. The calculation formula includes a first weighting for the number of targets included in the attack path and a second weighting for the value representing the risk. The attack path presentation device according to claim 2.
4. The calculation formula indicates that the first weighting is greater than the second weighting. The attack path presentation device according to claim 3.
5. The setting means sets the first weight and the second weight based on the relationship between the number of targets included in past attack paths and the value representing the risk, and the track record of successful cyberattacks. The attack path presentation device according to claim 3.
6. The setting means, with respect to the two attack paths, adjusts the priority of the two attack paths based on an adjustment criterion for adjusting the priority of the two attack paths if the values indicating the priority according to the calculation formula are equal. The attack path presentation device according to claim 2.
7. The setting means determines whether the number of targets included in the attack path is less than a second threshold, and sets the priority of the attack path in which the number of targets is less than the second threshold to the highest priority, regardless of the priority calculated by the formula. The attack path presentation device according to claim 2.
8. The setting means determines whether the number of targets included in the attack path is less than a second threshold, sets the priority of the first attack path in which the number of targets is less than the second threshold higher than the second attack path excluding the first attack path, and sets the priority between the first attack path and between the second attack path using the calculation formula, respectively. The attack path presentation device according to claim 2.
9. By an information processing device, From information representing the information processing system, multiple attack paths from the entry point to the attack target in a cyberattack against the said information processing system are extracted. For each of the aforementioned attack paths, information is obtained that represents the risk of success of a cyberattack against the target included in the aforementioned attack path. The fewer the number of targets included in the attack path, and the higher the risk to the targets, the higher the priority for presenting the attack path. The attack paths are presented to the user according to the aforementioned priority. Method for presenting attack paths.
10. An extraction process that extracts multiple attack paths from the entry point to the attack target in a cyberattack on the information processing system from information representing the information processing system, Regarding each of the aforementioned attack paths, an acquisition process is performed to acquire information representing the risk of success of a cyberattack against a target included in the aforementioned attack path. A setting process that sets a higher priority for presenting the attack path the fewer the number of targets included in the attack path and the higher the risk of the targets, A presentation process that presents the attack paths to the user in accordance with the aforementioned priority, A program that presents attack vectors to cause a computer to execute a specific command.