Attack path presentation device, attack path presentation method, and recording medium having attack path presentation program stored thereon
The attack path presentation device addresses the inefficiency in prioritizing cyberattack security measures by extracting and presenting attack paths based on their risk and impact, enhancing the efficiency of risk assessments and security measures.
Patent Information
- Application Number
- PCT/JP2023/045586
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-20
- Publication Date
- 2025-06-26
AI Technical Summary
Existing technologies are insufficient in efficiently identifying and prioritizing security measures for individual attack paths of cyberattacks, and in presenting these attack paths according to their priority.
An attack path presentation device that extracts multiple attack paths from an information processing system, acquires risk information for each attack path, sets a higher priority for presentation based on the number of attack targets and risk, and presents the attack paths to users accordingly.
The device effectively identifies and prioritizes security measures for each attack path, enabling efficient risk assessment and targeted security measures for cyberattack prevention.
Smart Images

Figure JP2023045586_26062025_PF_FP_ABST
Abstract
Description
Attack path presentation device, attack path presentation method, and recording medium storing attack path presentation program
[0001] The present invention relates to an attack path presentation device, an attack path presentation method, and a recording medium storing an attack path presentation program.
[0002] In recent years, cyber attacks, including unauthorized access to computer systems and malware infections, have been rampant, causing great damage to our highly information-oriented society. Therefore, there is a need for technology that can help system administrators to efficiently conduct system risk assessments in preparation for such cyber attacks.
[0003] In relation to the above-mentioned technology, Patent Literature 1 discloses an analysis system that can display attack paths so that a security administrator can easily determine which attack paths require priority countermeasures. This system identifies the network topology of devices included in a system to be diagnosed. This system detects attack paths that indicate the flow of feasible attacks in the system to be diagnosed based on security information related to the devices. This system then superimposes the attack paths on the network topology and displays the attack paths on a display device. In this case, this system displays the attack paths on the display device in a manner that corresponds to the impact on the system to be diagnosed.
[0004] International Publication No. 2020 / 195228
[0005] In recent years, the number of attack vectors for cyberattacks against large-scale computer systems has become enormous, making it necessary to appropriately and efficiently assess the risk of such systems. To achieve this, it is important to identify, from among the numerous attack vectors, attack vectors for which security measures should be prioritized, taking into account factors such as the likelihood of a cyberattack being received and the likelihood of the cyberattack being successful, and to present the identified attack vectors to the system administrator. In other words, the challenge is to appropriately and efficiently identify the priority of security measures for each cyberattack vector and present the attack vectors in accordance with that priority. The technology disclosed in Patent Document 1 cannot be said to be sufficient to solve this problem.
[0006] A primary object of the present invention is to appropriately and efficiently identify the priority of security measures for each attack path of a cyber attack, and to present the attack paths in accordance with the priority.
[0007] An attack path presentation device according to one aspect of the present invention comprises an extraction means for extracting, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system; an acquisition means for acquiring, for each of the attack paths, information representing the risk of a cyber attack being successful against an attack target included in the attack path; a setting means for setting a higher priority for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk; and a presentation means for presenting the attack paths to a user in accordance with the priority.
[0008] In another aspect of achieving the above-mentioned object, an attack path presentation method according to one embodiment of the present invention uses an information processing device to extract, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system, obtain information for each of the attack paths that indicates the risk of the cyber attack being successful against the attack targets included in the attack path, set a higher priority for presenting the attack path the fewer the number of attack targets included in the attack path and the higher the risk of the attack targets, and present the attack paths to a user in accordance with the priority.
[0009] Furthermore, in a further aspect of achieving the above-mentioned object, an attack path presentation program according to one embodiment of the present invention causes a computer to execute an extraction process that extracts, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system; an acquisition process that acquires, for each of the attack paths, information indicating the risk of a cyber attack being successful against an attack target included in the attack path; a setting process that sets a higher priority for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk of the attack targets; and a presentation process that presents the attack paths to a user in accordance with the priority.
[0010] Furthermore, the present invention can also be realized by a computer-readable, non-volatile recording medium on which such an attack path presentation program (computer program) is stored.
[0011] The present invention can appropriately and efficiently identify the priority of security measures for each attack path of a cyber attack and present the attack paths in accordance with the priority.
[0012] FIG. 1 is a block diagram showing the configuration of an attack path presentation device 10 according to the present disclosure. FIG. 2 is a diagram showing a schematic example of attack paths extracted by an extraction unit 11 in the attack path presentation device 10 according to the present disclosure. FIG. 3 is a diagram showing an example of data of attack path information 152 in the attack path presentation device 10 according to the present disclosure. FIG. 4 is a diagram showing an example of data of risk information 153 in the attack path presentation device 10 according to the present disclosure. FIG. 5 is a flowchart (1 / 2) showing the operation of the attack path presentation device 10 according to the present disclosure. FIG. 6 is a flowchart (2 / 2) showing the operation of the attack path presentation device 10 according to the present disclosure. FIG. 7 is a block diagram showing the configuration of an attack path presentation device 30 according to the present disclosure. FIG. 8 is a flowchart showing the operation of the attack path presentation device 30 according to the present disclosure. FIG. 9 is a block diagram showing the configuration of an information processing device 900 that can realize the attack path presentation device according to the present disclosure.
[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0014] 1 is a block diagram showing the configuration of an attack path presentation device 10 according to the present disclosure. The attack path presentation device 10 is a device that sets priorities to be presented to a user regarding attack paths from an entry point of a cyber-attack to an attack target against an information processing system (not shown) that is the target of security diagnosis, and presents the attack paths to the user in accordance with the priorities.
[0015] The attack path presentation device 10 is communicably connected to a terminal device 20. The terminal device 20 is an information processing device such as a personal computer, a smartphone, or a tablet terminal. The terminal device 20 inputs information entered by a user through input operations to the attack path presentation device 10, and displays the information output from the attack path presentation device 10 on a display screen 21 provided therein.
[0016] The attack path presentation device 10 is an information processing device such as a server, and includes an extraction unit 11, an acquisition unit 12, a setting unit 13, a presentation unit 14, and a storage unit 15. The extraction unit 11, the acquisition unit 12, the setting unit 13, and the presentation unit 14 are examples of an extraction means, an acquisition means, a setting means, and a presentation means, respectively.
[0017] The storage unit 15 is, for example, a storage device such as a RAM (Random Access Memory) 903 or a hard disk 904, which will be described later with reference to Fig. 8. The storage unit 15 stores information processing system information 151, attack path information 152, risk information 153, calculation formulas 154, weighting information 155, priorities 156, adjustment criteria 157, attribute information 158, and setting criteria 159. Details of the above-mentioned information stored in the storage unit 15 will be described later.
[0018] The extraction unit 11 extracts, from information processing system information 151 representing an information processing system whose security is to be diagnosed, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system. The information processing system information 151 may be provided by, for example, a user of the attack path presentation device 10, or may be obtained by the attack path presentation device 10 from an external device.
[0019] The information processing system information 151 includes the topology of a communication network that communicatively connects devices included in the information processing system to be diagnosed, information on the security specifications of the devices, etc. The extraction unit 11 can extract multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system from the topology of the communication network, etc., using existing technology.
[0020] FIG. 2 is a diagram illustrating a schematic example of a cyberattack path extracted by the extraction unit 11 in the attack path presentation device 10 according to the present disclosure. In recent large-scale information processing systems, there are generally many more cyberattack paths than the example shown in FIG. 2 . However, a simplified example as shown in FIG. 2 will be used for explanation. In FIG. 2 , the entry point, attack target, and attack subject refer to devices (equipment) such as servers, terminals, and switches included in the information processing system to be diagnosed, or firewalls running as applications on the devices. In the present disclosure, the term "attack target" refers to the final target of a cyberattack, and the term "attack subject" refers to all attack subjects along the attack path from the entry point to the attack subject. In other words, the term "attack target" refers to the last one included in the "attack subject."
[0021] 3 is a diagram illustrating data of attack path information 152 in the attack path presentation device 10 according to the present disclosure. The attack path information 152 is information generated by the extraction unit 11 and represents the attack paths extracted by the extraction unit 11 as illustrated in FIG. 2. The extraction unit 11 stores the generated attack path information 152 in the storage unit 15.
[0022] In the example shown in FIGS. 2 and 3, the extraction unit 11 extracts three attack paths: attack path X, attack path Y, and attack path Z.
[0023] 2 and 3, attack path X includes attack target A1 and attack target A2 between the entry point and the attack target. A cyber attack via attack path X includes three attack steps: attack step X1 from the entry point to attack target A1, attack step X2 from attack target A1 to attack target A2, and attack step X3 from attack target A2 to the attack target. In other words, the number of attack steps in a cyber attack via attack path X is three.
[0024] 2 and 3, attack path Y includes attack targets B1, B2, and B3 between the entry point and the attack target. A cyber attack via attack path Y includes four attack steps: attack step Y1 from the entry point to attack target B1, attack step Y2 from attack target B1 to attack target B2, attack step Y3 from attack target B2 to attack target B3, and attack step Y4 from attack target B3 to the attack target. In other words, the number of attack steps in a cyber attack via attack path Y is four.
[0025] As illustrated in Figures 2 and 3, attack path Z includes attack targets B1, C1, and C2 between the entry point and the attack target. A cyberattack via attack path Z includes five attack steps: attack step Y1 from the entry point to attack target B1, attack step Z2 from attack target B1 to attack target C1, attack step Z3 from attack target C1 to attack target C2, attack step Z4 from attack target C2 to attack target C2, and attack step Z5 from attack target C2 to the attack target. In other words, the number of attack steps in a cyberattack via attack path Z is five. Note that attack path Y and attack path Z share the same attack path from the entry point to attack target B1. Furthermore, attack step Z4 represents an attack from attack target C2 to the target itself (own device). This is because attack target C2 has two-stage countermeasures against cyberattacks, and two attack steps are carried out against attack target C2. For example, if the target of attack C2 has two countermeasures in place: a firewall to prevent unauthorized access to itself and encryption of information necessary to access the target of attack, attack step Z3 represents an attack to break through the firewall, and attack step Z4 represents an attack to break the encryption.
[0026] As mentioned above, the number of attack steps of a cyber-attack via the extracted attack path usually depends on the number of targets included in the attack path, but if multiple stages of countermeasures against cyber-attacks are implemented for one target, the number of attack steps can be calculated by considering the target as multiple targets for attack, equal to the number of countermeasures implemented.
[0027] 1 acquires risk information 153 indicating the risk of a successful cyber attack on an attack target included in each attack path extracted by the extraction unit 11. The acquisition unit 12 may acquire (extract) the risk information 153 from, for example, information on the security specifications of each attack target represented by the information processing system information 151. The acquisition unit 12 stores the acquired risk information 153 in the storage unit 15.
[0028] The risk of a successful cyberattack (individual attack steps) against a target of attack, as represented by the risk information 153, can be calculated using two indicators, for example, a threat level and a vulnerability level. The threat level is an indicator of the likelihood of a cyberattack occurring, and depends on the location of the target of attack, the type of operating system (OS) and software used, communication functions, and functions provided. The vulnerability level is an indicator of the likelihood of a successful attack method in the event of a cyberattack, and depends on the status of security measures such as antivirus software.
[0029] Fig. 4 is a diagram illustrating data of risk information 153 in the attack path presentation device 10 according to the present disclosure. The risk information 153 illustrated in Fig. 4 represents the risk value (a value representing the risk described above) for each attack step of a cyber attack carried out via attack path X, attack path Y, and attack path Z extracted by the extraction unit 11 illustrated in Fig. 2 and Fig. 3, and the sum of the risk values for each of attack path X, attack path Y, and attack path Z. In Fig. 4, the risk value for each attack step is an integer between "1" and "5," and the larger the risk value, the higher the risk.
[0030] 1 sets a higher priority 156 for presenting the attack path to the user the fewer the number of attack targets included in the attack path extracted by the extraction unit 11 and the higher the risk of a cyber attack on the attack targets being successful. The fewer the number of attack targets included in the attack path (i.e., the fewer the number of attack steps), the lower the difficulty for a cyber attack to reach the attack target, so the higher the priority 156 needs to be. The setting unit 13 stores the priority 156 for each of the set attack paths in the storage unit 15.
[0031] The setting unit 13 calculates the priority by using a calculation formula 154 for determining the priority from the number of attack targets (number of attack steps) included in each attack path and a risk value indicating danger. Note that the calculation formula 154 is provided by, for example, a user of the attack path presentation device 10.
[0032] The calculation formula 154 is expressed, for example, as the following formula 1: Priority of presenting an attack path to a user = Wh / Number of attack steps + Sum of WrX risk values (Formula 1) where Wh is a coefficient representing the weighting (first weighting) for the first term (term related to the number of attack steps) in formula 1, and Wr is a coefficient representing the weighting (second weighting) for the second term (term related to the sum of risk values) in formula 1, and the values of Wh and Wr are represented by the weighting information 155. Note that the weighting information 155 is provided, for example, by the user of the attack path presentation device 10. In formula 1, " / ", "+", and "X" are operators representing division, addition, and multiplication, respectively.
[0033] In the example shown in FIG. 3 , the number of attack steps for each attack path ranges from 3 to 5, so the reciprocal of the number of attack steps included in the first term of Equation 1 is approximately 0.2 to 0.3. On the other hand, in the example shown in FIG. 4 , the risk value for each attack step is expressed as an integer ranging from 1 to 5, so the sum of the risk values included in the second term of Equation 1 is approximately 10. Therefore, in this case, if Wh and Wr are set to 1 in Equation 1 (i.e., if the first and second terms in Equation 1 are weighted equally), the value of the second term in Equation 1 will be approximately 40 times the value of the first term, and the number of attack steps will hardly be reflected in the calculation of the priority for presenting attack paths to users. Therefore, in this case, in order to equally reflect the number of attack steps and the sum of risk values in the calculation of the priority for presenting attack paths to users, it is desirable to set Wh to 40 and Wr to 1, for example. In this way, when formula 154 is used to calculate the priority of presenting an attack path to a user, values of Wh and Wr need only be given so that the proportion of the attack step count element and the risk value total element that influence the priority calculation is the desired value.
[0034] The setting unit 13 may also have a function of setting the values of Wh and Wr so as to be consistent with the success of cyberattacks, based on the relationship between the number of attack targets (number of attack steps) included in past attack paths, the total risk value of the attack paths, and the success of cyberattacks. In other words, in this case, the setting unit 13 can appropriately set the values of Wh and Wr using, for example, a learning model that has learned the relationship between the number of attack targets included in past attack paths, the total risk value of the attack paths, and the success of cyberattacks.
[0035] Furthermore, the setting unit 13 may use, for example, the maximum value of the risk values for the attack steps in the attack path as the second term of the above-described formula 1, rather than the sum of the risk values for the attack steps in the attack path. In this case, the difference in the influence of the element of the number of attack steps and the element of the risk value on the calculation of the priority of presenting the attack path to the user can be made smaller than when the sum of the risk values for the attack steps is used as the second term of formula 1.
[0036] The setting unit 13 may also use the product of the probabilities of success of the attack in each attack step as the calculation formula 154, instead of formula 1. In this case, since the value of the probability is less than 1, the priority 156 is set higher as the number of attack targets included in the attack path decreases and as the risk of a cyber attack on the attack targets being successful increases, just like when formula 1 is used.
[0037] Furthermore, when the priorities 156 calculated by the calculation formula 154 for two attack paths are equal, the setting unit 13 may adjust the priorities 156 of the two attack paths based on an adjustment criterion 157 for adjusting the priorities 156 of the two attack paths. The adjustment criterion 157 may, for example, represent changing the priority 156 of the attack path that includes fewer attack targets to a value higher than the priority 156 of the other attack path. Alternatively, the adjustment criterion 157 may represent changing the priority 156 of the attack path that includes a higher risk value of attack targets to a value higher than the priority 156 of the other attack path. Note that the adjustment criterion 157 is provided, for example, by a user of the attack path presentation device 10.
[0038] The setting unit 13 may also determine whether the attack path includes an attack target whose risk value is lower than a predetermined first threshold. In this case, the setting unit 13 controls the presentation unit 14 (described later) to exclude attack paths including attack targets whose risk value is lower than the first threshold from the targets to be presented. Note that the first threshold is provided, for example, by a user of the attack path presentation device 10.
[0039] Furthermore, the acquisition unit 12 may acquire (extract) attribute information 158 representing attributes related to risk values for the attack target from, for example, the information processing system information 151. The acquisition unit 12 stores the acquired attribute information 158 in the storage unit 15. In this case, the setting unit 13 sets the priority 156 based on setting criteria 159 for setting the priority 156 according to the attributes indicated by the attribute information 158 and the attributes. Note that the setting criteria 159 are provided by, for example, a user of the attack path presentation device 10.
[0040] The attribute indicated by the attribute information 158 indicates the type of attack target (asset type), for example, a device (equipment) such as a server, terminal, or switch, or a firewall running as an application on a device. The setting criteria 159 are criteria that associate the attributes of the attack target with the priority 156 based on the commonly known vulnerability of each asset type to cyber attacks, etc.
[0041] The setting unit 13 may also determine whether the number of attack targets included in the attack path is less than a predetermined second threshold, and set the priority 156 of the attack path in which the number of attack targets is less than the second threshold to the highest, regardless of the priority 156 calculated by the calculation formula 154. Note that the second threshold is provided by, for example, a user of the attack path presentation device 10.
[0042] The setting unit 13 may also determine whether the number of attack targets included in the attack path is less than a predetermined second threshold, and set the priority 156 of a first attack path in which the number of attack targets is less than the second threshold to be higher than a second attack path excluding the first attack path, and set the priority 156 between the first attack paths and between the second attack paths using the calculation formula 154, respectively.
[0043] The presentation unit 14 presents the attack paths indicated by the attack path information 152 to the user by displaying them on the display screen 21 of the terminal device 20 in accordance with the priority 156 set by the setting unit 13. For example, the presentation unit 14 may display the attack paths on the display screen 21 in a manner that makes the attack paths with higher priority 156 more noticeable (by using a display color, thickness, etc.), or may display the attack paths on the display screen 21 in descending order of priority 156. In this case, the presentation unit 14 may display each attack path on the display screen 21 by superimposing it on a diagram showing the topology of the communication network from the entry point to the attack target, as shown in FIG. 2, for example.
[0044] Next, the operation (processing) of the attack path presentation device 10 according to the present disclosure will be described in detail with reference to the flowcharts of FIGS. 5A and 5B.
[0045] The extraction unit 11 extracts attack paths in cyber attacks from the information processing system information 151 and stores attack path information 152 representing the extraction result in the storage unit 15 (step S101). The acquisition unit 12 acquires risk information 153 and attribute information 158 of attack targets included in the extracted attack paths indicated by the attack path information 152 from the information processing system information 151 (step S102). The setting unit 13 determines whether the extracted attack paths include (exist) an attack step whose risk value is lower than a first threshold (step S103).
[0046] If there is no attack path including an attack step whose risk value is lower than the first threshold (No in step S104), the process proceeds to step S106. If there is an attack path including an attack step whose risk value is lower than the first threshold (Yes in step S104), the presentation unit 14 excludes the attack path including the attack step whose risk value is lower than the first threshold from the targets to be presented to the user (step S105).
[0047] The setting unit 13 determines whether the number of attack steps is less than the second threshold for each of the extracted attack paths (step S106). If there is no attack path with a number of attack steps less than the second threshold (No in step S107), the process proceeds to step S110. If there is an attack path with a number of attack steps less than the second threshold (Yes in step S107), the setting unit 13 sets the priority 156 of the attack path with a number of attack steps less than the second threshold higher than the priority 156 of the other attack paths (step S108). The setting unit 13 sets the priority 156 between attack paths with a number of attack steps less than the second threshold based on the calculation formula 154 (step S109). The setting unit 13 sets the priority 156 between attack paths with a number of attack steps equal to or greater than the second threshold based on the calculation formula 154 (step S110).
[0048] If there are no attack paths with the same priority 156 according to the calculation formula 154 (No in step S111), the processing proceeds to step S113. If there are attack paths with the same priority 156 according to the calculation formula 154 (Yes in step S111), the setting unit 13 sets the priority 156 between the attack paths with the same priority 156 according to the calculation formula 154 based on the adjustment criteria 157, attribute information 158, and setting criteria 159 (step S111). The presentation unit 14 displays the attack paths on the display screen 21 of the terminal device 20 in accordance with the priority 156 set by the setting unit 13 (step S113), and the entire processing ends.
[0049] The attack path presentation device 10 according to the present disclosure can appropriately and efficiently identify the priority of security measures for each attack path of a cyber attack and present the attack path according to the priority. This is because the attack path presentation device 10 sets a higher priority for presenting the attack path the fewer the number of attack targets included in the attack path of the cyber attack and the higher the risk of the cyber attack being successful, and presents the attack path to the user according to the priority.
[0050] The effects achieved by the attack path presentation device 10 according to the present disclosure will be described in detail below.
[0051] In recent years, the number of attack vectors for cyberattacks against large-scale computer systems has become enormous, making it necessary to appropriately and efficiently assess the risk of such systems. To achieve this, it is important to identify attack vectors with high security priority from among the numerous attack vectors, taking into account the likelihood of a cyberattack being received and the likelihood of the cyberattack being successful, and to present these attack vectors to system administrators. In other words, the challenge is to appropriately and efficiently identify the priority of security measures for each cyberattack vector and present the attack vectors according to that priority.
[0052] To address this issue, the attack path presentation device 10 according to the present disclosure extracts, from information processing system information 151 representing an information processing system, multiple attack paths from an entry point to an attack target in a cyberattack against the information processing system. For each attack path, the attack path presentation device 10 acquires risk information 153 indicating the risk of a cyberattack succeeding against an attack target included in the attack path. The attack path presentation device 10 sets a higher priority 156 for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk of the attack targets. The attack path presentation device 10 then presents the attack paths to the user according to the priority 156. In other words, the attack path presentation device 10 sets the priority for presenting the attack paths from the perspectives of both the number of attack targets included in the attack path and the risk of the attack targets, thereby making it possible to appropriately and efficiently identify the priority of security measures for each attack path of a cyberattack and present the attack paths according to the priority.
[0053] Furthermore, the attack path presentation device 10 according to the present disclosure calculates the priority 156 using a calculation formula 154 for determining the priority 156 from the number of attack targets included in the attack path and a value representing the risk, and the calculation formula 154 includes a first weighting for the number of attack targets included in the attack path and a second weighting for the value representing the risk. This allows the attack path presentation device 10 to more appropriately identify the priority of security measures for each attack path of a cyber attack.
[0054] Furthermore, when the values indicating the priority 156 calculated by the calculation formula 154 for two attack paths are equal, the attack path presentation device 10 according to the present disclosure adjusts the priorities of the two attack paths based on an adjustment criterion 157 for adjusting the priorities 156 of the two attack paths. In this case, the adjustment criterion 157 may represent changing the priority 156 of the attack path that includes fewer attack targets to a value higher than the priority 156 of the other attack path, or may represent changing the priority 156 of the attack path that includes a higher risk of attack targets to a value higher than the priority 156 of the other attack path. This allows the attack path presentation device 10 to more appropriately identify the priority of security measures for each cyber attack path in accordance with the user's desired policy.
[0055] Furthermore, the attack path presentation device 10 according to the present disclosure determines whether an attack path includes an attack target whose value representing risk is lower than a first threshold, and excludes from the targets to be presented attack paths that include an attack target whose value representing risk is lower than the first threshold. Since attack paths that include an attack target whose value representing risk is lower than the first threshold can be considered safe from a security perspective, the attack path presentation device 10 can present to the user information that is narrowed down to attack paths that highly require security measures by excluding such attack paths from the targets to be presented to the user.
[0056] Furthermore, the attack path presentation device 10 according to the present disclosure acquires attribute information 158 representing attributes related to risk regarding the target of attack, and sets the priority 156 based on setting criteria 159 for setting the priority 156 according to the attributes and the attribute information 158. This allows the attack path presentation device 10 to more appropriately identify the priority of security measures for each attack path of a cyber attack.
[0057] Furthermore, the attack path presentation device 10 according to the present disclosure determines whether the number of attack targets included in an attack path is less than a second threshold, and sets the priority 156 of an attack path whose number of attack targets is less than the second threshold to the highest, regardless of the priority 156 calculated by the calculation formula 154. Alternatively, the attack path presentation device 10 sets the priority 156 of a first attack path whose number of attack targets is less than the second threshold to a higher priority than a second attack path excluding the first attack path, and sets the priority 156 between the first attack paths and between the second attack paths using the calculation formula 154, respectively. In this way, the attack path presentation device 10 sets the priority 156 by combining multi-stage criteria (rules) for setting the priority 156, thereby making it possible to more appropriately identify the priority of security measures for each attack path of a cyber attack.
[0058] 6 is a block diagram showing the configuration of an attack path presentation device 30 according to the present disclosure. The attack path presentation device 30 includes an extraction unit 31, an acquisition unit 32, a setting unit 33, and a presentation unit 34. The extraction unit 31, the acquisition unit 32, the setting unit 33, and the presentation unit 34 are examples of an extraction means, an acquisition means, a setting means, and a presentation means, respectively.
[0059] The extraction unit 31 extracts, from information 300 representing an information processing system, a plurality of attack paths 310 from an entry point to an attack target in a cyber attack against the information processing system. The information 300 representing the information processing system is, for example, information similar to the information processing system information 151 related to the attack path presentation device 10. The attack paths 310 are, for example, paths similar to the attack paths represented by the attack path information 152 related to the attack path presentation device 10. The extraction unit 31 operates in the same manner as the extraction unit 11 related to the attack path presentation device 10, for example.
[0060] The acquisition unit 32 acquires, for each attack path 310, information indicating a risk 320 that a cyber attack will be successful against an attack target included in the attack path 310. The information indicating the risk 320 is, for example, information similar to the risk information 153 related to the attack path presentation device 10. The acquisition unit 32 operates in the same manner as, for example, the acquisition unit 12 related to the attack path presentation device 10.
[0061] The fewer the number of attack targets included in the attack path 310 and the higher the risk 320, the higher the setting unit 33 sets the priority 330 for presenting the attack path 310. The priority 330 is, for example, information similar to the priority 156 related to the attack path presentation device 10. The setting unit 33 operates in the same manner as the setting unit 13 related to the attack path presentation device 10, for example.
[0062] The presentation unit 34 presents the attack paths 310 to the user according to the priority 330. The presentation unit 34 operates in the same manner as the presentation unit 14 of the attack path presentation device 10, for example.
[0063] Next, the operation (processing) of the attack path presentation device 30 according to the present disclosure will be described in detail with reference to the flowchart of FIG.
[0064] The extraction unit 31 extracts multiple attack paths 310 from an entry point to an attack target in a cyber attack against an information processing system from information 300 representing the information processing system (step S201). The acquisition unit 32 acquires information representing a risk 320 that a cyber attack against an attack target included in the attack path 310 will succeed for each of the attack paths 310 (step S202).
[0065] The setting unit 33 sets a higher priority 330 for presenting the attack path 310 as the number of attack targets included in the attack path 310 decreases and the risk 320 increases (step S203). The presentation unit 34 presents the attack path 310 to the user according to the priority 330 (step S204), and the entire process ends.
[0066] The attack path presentation device 30 according to the present disclosure can appropriately and efficiently identify the priority of security measures for each attack path of a cyber attack and present the attack path according to the priority. This is because the attack path presentation device 30 sets a higher priority for presenting the attack path the fewer the number of attack targets included in the attack path of the cyber attack and the higher the risk of the cyber attack being successful, and presents the attack path to the user according to the priority.
[0067] <Hardware Configuration Example> In each of the above-described embodiments, each unit in the attack path presentation device shown in Figures 1 and 6 can be realized by dedicated HW (Hardware) (electronic circuitry). Furthermore, in Figures 1 and 6, at least the following components can be considered as functional (processing) units (software modules) of a software program that includes instructions executed by a processor: Extraction units 11 and 31, Acquisition units 12 and 32, Setting units 13 and 33, Presentation units 14 and 34, and Storage control function in the storage unit 15.
[0068] However, the division of the various components shown in these drawings is for the sake of convenience of explanation, and various configurations may be assumed for implementation. An example of the hardware environment in this case will be described with reference to FIG. 8.
[0069] 8 is a diagram illustrating an example of the configuration of an information processing device 900 (computer) capable of realizing the attack path presentation device according to the present disclosure. That is, FIG. 8 shows the configuration of a computer (information processing device) capable of realizing the attack path presentation device shown in FIGS. 1 and 6, and represents a hardware environment capable of realizing each function in the above-described embodiment. However, each unit in the above-described attack path presentation device may be distributed among multiple information processing devices 900, or at least some of the functions may be provided in a server or the like that constitutes a cloud computing environment.
[0070] The information processing device 900 shown in Fig. 8 includes the following components: a CPU (Central Processing Unit) 901, a ROM (Read Only Memory) 902, a RAM (Random Access Memory) 903, a hard disk (storage device) 904, a communication interface 905, a bus 906 (communication line), a reader / writer 908 capable of reading and writing data stored in a recording medium 907 such as a CD-ROM (Compact Disc Read Only Memory), and an input / output interface 909 such as a monitor, speaker, keyboard, etc.
[0071] That is, the information processing device 900 having the above-described components is a general computer in which these components are connected via a bus 906. The information processing device 900 may have multiple CPUs 901, or may have a CPU 901 configured with multiple cores. The information processing device 900 may also not have some of the above-described components.
[0072] The present invention, explained using the above-mentioned embodiment as an example, supplies a computer program capable of realizing the following functions to the information processing device 900 shown in FIG. 8. The functions are the above-mentioned configurations in the block diagrams (FIGS. 1 and 6) or the functions of the flowcharts (FIGS. 5A, 5B, and 7) referred to in the description of the embodiment. The present invention is then achieved by reading the computer program into the CPU 901 of the hardware, interpreting it, and executing it. The computer program supplied to the device may be stored in a readable / writable volatile memory (RAM 903) or a non-volatile storage device such as a ROM 902 or a hard disk 904.
[0073] In the above case, the method of supplying the computer program to the hardware can be a currently common procedure, such as installing the program in the device via a recording medium 907 such as a CD-ROM, or downloading the program from an external source via a communication line such as the Internet. In such a case, the present invention can be considered to be constituted by the code constituting the computer program or the recording medium 907 on which the code is stored.
[0074] The present invention has been described above using the above-described embodiments as exemplary examples. However, the present invention is not limited to the above-described embodiments. In other words, the present invention can be applied in various aspects that can be understood by a person skilled in the art within the scope of the present invention.
[0075] Note that part or all of the above-described embodiments can also be described as follows: However, the present invention, which has been exemplarily described using the above-described embodiments, is not limited to the following.
[0076] (Supplementary Note 1) An attack path presentation device comprising: an extraction means for extracting, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system; an acquisition means for acquiring, for each of the attack paths, information representing the risk of a cyber attack being successful against an attack target included in the attack path; a setting means for setting a higher priority for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk; and a presentation means for presenting the attack paths to a user in accordance with the priority.
[0077] (Supplementary Note 2) The attack path presentation device according to Supplementary Note 1, wherein the setting means calculates the priority using a calculation formula for determining the priority from the number of attack targets included in the attack path and a value representing the risk.
[0078] (Supplementary Note 3) The attack path presentation device according to Supplementary Note 2, wherein the calculation formula includes a first weighting for the number of attack targets included in the attack path and a second weighting for the value representing the risk.
[0079] (Supplementary Note 4) The attack path presentation device according to Supplementary Note 3, wherein the calculation formula indicates that the first weighting is greater than the second weighting.
[0080] (Supplementary Note 5) The attack path presentation device according to Supplementary Note 3, wherein the setting means sets the first weighting and the second weighting based on the relationship between the number of attack targets included in the attack path in the past, the value representing the risk, and the success of cyber attacks.
[0081] (Supplementary Note 6) The attack path presentation device according to Supplementary Note 2 or Supplementary Note 3, wherein the calculation formula includes an inverse of the number of attack targets included in the attack path and a sum of values representing the risk of one or more of the attack targets.
[0082] (Supplementary Note 7) The attack path presentation device according to Supplementary Note 2 or Supplementary Note 3, wherein the calculation formula includes an inverse of the number of attack targets included in the attack path and a maximum value among values representing the risk of one or more of the attack targets.
[0083] (Supplementary Note 8) The attack path presentation device according to Supplementary Note 2, wherein the calculation formula includes a product of probabilities that a cyber-attack representing the risk will succeed for one or more of the attack targets included in the attack path.
[0084] (Supplementary Note 9) The attack path presentation device according to Supplementary Note 2, wherein the setting means adjusts the priorities of the two attack paths based on an adjustment criterion for adjusting the priorities of the two attack paths when the values indicating the priorities calculated by the calculation formula for the two attack paths are equal.
[0085] (Supplementary Note 10) The attack path presentation device according to Supplementary Note 9, wherein the adjustment criterion indicates changing the priority of one of the attack paths including a smaller number of attack targets to a value higher than the priority of the other of the attack paths.
[0086] (Supplementary Note 11) The attack path presentation device according to Supplementary Note 9, wherein the adjustment criterion represents changing the priority of one of the attack paths that is included in the attack path and that presents a higher risk to the attack target to a value higher than the priority of the other of the attack paths.
[0087] (Supplementary Note 12) The attack path presentation device according to any one of Supplementary Notes 1 to 11, wherein the setting means determines whether the attack path includes an attack target whose value representing the risk is lower than a first threshold, and the presentation means excludes the attack path including the attack target whose value representing the risk is lower than the first threshold from the targets to be presented.
[0088] (Supplementary Note 13) The attack path presentation device described in any one of Supplementary Notes 1 to 12, wherein the acquisition means acquires information representing attributes related to the risk regarding the target of attack, and the setting means sets the priority based on setting criteria for setting the priority according to the attribute and the attribute.
[0089] (Supplementary Note 14) The attack path presentation device according to Supplementary Note 13, wherein the attribute represents one of a server, a terminal, a switch, and a firewall.
[0090] (Supplementary Note 15) The attack path presentation device according to Supplementary Note 2, wherein the setting means determines whether the number of attack targets included in the attack path is less than a second threshold, and sets the priority of the attack path in which the number of attack targets is less than the second threshold to the highest regardless of the priority determined by the calculation formula.
[0091] (Supplementary Note 16) The attack path presentation device described in Supplementary Note 2, wherein the setting means determines whether the number of attack targets included in the attack path is less than a second threshold, and sets the priority of a first attack path in which the number of attack targets is less than the second threshold higher than a second attack path excluding the first attack path, and sets the priority between the first attack paths and between the second attack paths using the calculation formula, respectively.
[0092] (Supplementary Note 17) An attack path presentation method, comprising: an information processing device extracting, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system; obtaining, for each of the attack paths, information representing the risk of the cyber attack being successful against the attack targets included in the attack path; setting a higher priority for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk of the attack targets; and presenting the attack paths to a user in accordance with the priority.
[0093] (Supplementary Note 18) The attack path presentation method according to Supplementary Note 17, wherein the priority is calculated using a calculation formula for determining the priority from the number of attack targets included in the attack path and a value representing a risk of the attack targets.
[0094] (Supplementary Note 19) The attack path presentation method according to Supplementary Note 18, wherein the calculation formula includes a first weighting for the number of attack targets included in the attack path and a second weighting for the value representing the risk.
[0095] (Supplementary Note 20) The attack path presentation method according to Supplementary Note 19, wherein the calculation formula indicates that the first weighting is greater than the second weighting.
[0096] (Supplementary Note 21) The attack path presentation method according to Supplementary Note 19, wherein the first weighting and the second weighting are set based on the relationship between the number of attack targets included in the attack path in the past, the value representing the risk, and the success of cyber attacks.
[0097] (Supplementary Note 22) The attack path presentation method according to Supplementary Note 18 or Supplementary Note 19, wherein the calculation formula includes the reciprocal of the number of attack targets included in the attack path and the sum of values representing the risk of one or more of the attack targets.
[0098] (Supplementary Note 23) The attack path presentation method according to Supplementary Note 18 or Supplementary Note 19, wherein the calculation formula includes the reciprocal of the number of attack targets included in the attack path and the maximum value among values representing the risk of one or more of the attack targets.
[0099] (Supplementary Note 24) The attack path presentation method according to Supplementary Note 18, wherein the calculation formula includes a product of probabilities that a cyber attack representing the risk will succeed for one or more of the attack targets included in the attack path.
[0100] (Supplementary Note 25) The attack path presentation method according to Supplementary Note 18, wherein when the values indicating the priorities calculated by the calculation formula for the two attack paths are equal, the priorities of the two attack paths are adjusted based on an adjustment criterion for adjusting the priorities of the two attack paths.
[0101] (Supplementary Note 26) The attack path presentation method according to Supplementary Note 25, wherein the adjustment criterion indicates changing the priority of the attack path that includes a smaller number of attack targets to a value higher than the priority of the other attack path.
[0102] (Supplementary Note 27) The attack path presentation method according to Supplementary Note 25, wherein the adjustment criterion represents changing the priority of one of the attack paths that includes a higher risk to the target of attack to a value higher than the priority of the other of the attack paths.
[0103] (Supplementary Note 28) The attack path presentation method according to any one of Supplementary Notes 17 to 27, comprising determining whether the attack path includes an attack target whose value representing the risk is lower than a first threshold, and excluding the attack path including the attack target whose value representing the risk is lower than the first threshold from the targets to be presented.
[0104] (Supplementary Note 29) The attack path presentation method according to any one of Supplementary Notes 17 to 28, further comprising: acquiring information representing attributes related to the risk of the target of attack; and setting the priority based on the attributes and setting criteria for setting the priority according to the attributes.
[0105] (Supplementary Note 30) The attack path presentation method according to Supplementary Note 29, wherein the attribute represents one of a server, a terminal, a switch, and a firewall.
[0106] (Supplementary Note 31) The attack path presentation method according to Supplementary Note 18, further comprising determining whether the number of attack targets included in the attack path is less than a second threshold, and setting the priority of the attack path in which the number of attack targets is less than the second threshold to the highest regardless of the priority determined by the calculation formula.
[0107] (Supplementary Note 32) The attack path presentation method according to Supplementary Note 18, comprising determining whether the number of attack targets included in the attack paths is less than a second threshold, setting the priority of a first attack path in which the number of attack targets is less than the second threshold higher than that of a second attack path excluding the first attack path, and setting the priority between the first attack paths and between the second attack paths using the calculation formula, respectively.
[0108] (Supplementary Note 33) A recording medium storing an attack path presentation program for causing a computer to execute the following steps: an extraction process for extracting, from information representing an information processing system, multiple attack paths from an entry point to an attack target in a cyber attack against the information processing system; an acquisition process for acquiring, for each of the attack paths, information representing the risk of a cyber attack being successful against an attack target included in the attack path; a setting process for setting a higher priority for presenting the attack paths the fewer the number of attack targets included in the attack path and the higher the risk of the attack targets; and a presentation process for presenting the attack paths to a user in accordance with the priority.
[0109] (Supplementary Note 34) A recording medium storing the attack path presentation program according to Supplementary Note 33, wherein the setting process calculates the priority using a calculation formula for determining the priority from the number of attack targets included in the attack path and a value representing the risk of the attack targets.
[0110] (Supplementary Note 35) A recording medium storing the attack path presentation program according to Supplementary Note 34, wherein the calculation formula includes a first weighting for the number of attack targets included in the attack path and a second weighting for the value representing the risk.
[0111] (Supplementary Note 36) A recording medium storing the attack path presentation program according to Supplementary Note 35, wherein the calculation formula indicates that the first weighting is greater than the second weighting.
[0112] (Supplementary Note 37) A recording medium storing the attack path presentation program described in Supplementary Note 35, wherein the setting process sets the first weighting and the second weighting based on the relationship between the number of attack targets included in the attack path in the past, the value representing the risk, and the success of cyber attacks.
[0113] (Supplementary Note 38) A recording medium storing the attack path presentation program according to Supplementary Note 34 or Supplementary Note 35, wherein the calculation formula includes the reciprocal of the number of attack targets included in the attack path and the sum of values representing the risk of one or more of the attack targets.
[0114] (Supplementary Note 39) A recording medium storing the attack path presentation program according to Supplementary Note 34 or Supplementary Note 35, wherein the calculation formula includes the reciprocal of the number of attack targets included in the attack path and the maximum value among values representing the risk of one or more of the attack targets.
[0115] (Supplementary Note 40) A recording medium storing the attack path presentation program according to Supplementary Note 34, wherein the calculation formula includes a product of probabilities that a cyber attack representing the risk will succeed for one or more of the attack targets included in the attack path.
[0116] (Supplementary Note 41) A recording medium storing the attack path presentation program described in Supplementary Note 34, wherein the setting process adjusts the priorities of the two attack paths based on an adjustment criterion for adjusting the priorities of the two attack paths when the values indicating the priorities according to the calculation formula for the two attack paths are equal.
[0117] (Supplementary Note 42) A recording medium storing the attack path presentation program according to Supplementary Note 41, wherein the adjustment criterion indicates changing the priority of the attack path that includes fewer attack targets to a value higher than the priority of the other attack path.
[0118] (Supplementary Note 43) A recording medium storing the attack path presentation program according to Supplementary Note 41, wherein the adjustment criterion indicates changing the priority of the attack path that is included in the attack path and that poses a higher risk to the attack target to a value higher than the priority of the other attack path.
[0119] (Supplementary Note 44) A recording medium storing an attack path presentation program according to any one of Supplementary Note 33 to Supplementary Note 43, wherein the setting process determines whether the attack path includes an attack target whose value representing the risk is lower than a first threshold, and the presentation process excludes the attack path including the attack target whose value representing the risk is lower than the first threshold from the targets to be presented.
[0120] (Supplementary Note 45) A recording medium storing an attack path presentation program according to any one of Supplementary Notes 33 to 44, wherein the acquisition process acquires information representing attributes related to the risk of the target of attack, and the setting process sets the priority based on setting criteria for setting the priority according to the attribute and the attribute.
[0121] (Supplementary Note 46) A recording medium storing the attack path presentation program according to Supplementary Note 45, wherein the attribute indicates one of a server, a terminal, a switch, and a firewall.
[0122] (Supplementary Note 47) A recording medium storing the attack path presentation program described in Supplementary Note 34, wherein the setting process determines whether the number of attack targets included in the attack path is less than a second threshold, and sets the priority of the attack path in which the number of attack targets is less than the second threshold to the highest regardless of the priority determined by the calculation formula.
[0123] (Supplementary Note 48) A recording medium storing the attack path presentation program described in Supplementary Note 34, wherein the setting process determines whether the number of attack targets included in the attack path is less than a second threshold, sets the priority of a first attack path in which the number of attack targets is less than the second threshold higher than a second attack path excluding the first attack path, and sets the priority between the first attack paths and between the second attack paths using the calculation formula, respectively.
[0124] 10 Attack path presentation device 11 Extraction unit 12 Acquisition unit 13 Setting unit 14 Presentation unit 15 Storage unit 151 Information processing system information 152 Attack path information 153 Risk information 154 Calculation formula 155 Weighting information 156 Priority 157 Adjustment standard 158 Attribute information 159 Setting standard 20 Terminal device 21 Display screen 30 Attack path presentation device 31 Extraction unit 310 Attack path 32 Acquisition unit 320 Risk 33 Setting unit 330 Priority 34 Presentation unit 900 Information processing device 901 CPU 902 ROM 903 RAM 904 Hard disk (storage device) 905 Communication interface 906 Bus 907 Recording medium 908 Reader / writer 909 Input / output interface
Claims
1. An extraction means for extracting a plurality of attack paths from the information representing the information processing system, from the intrusion point to the attack target in a cyber attack on the information processing system; an acquisition means for acquiring information representing the risk of a cyber attack on an attack target included in the attack path for each of the attack paths; a setting means for setting a higher priority for presenting the attack path as the number of the attack targets included in the attack path is smaller and the risk is higher; and a presentation means for presenting the attack path to a user according to the priority. An attack path presentation device comprising the above.
2. The setting means calculates the priority using a calculation formula for obtaining the priority from the number of the attack targets included in the attack path and the value representing the risk. The attack path presentation device according to claim 1.
3. The calculation formula includes a first weighting for the number of the attack targets included in the attack path and a second weighting for the value representing the risk. The attack path presentation device according to claim 2.
4. The calculation formula indicates that the first weighting is larger than the second weighting. The attack path presentation device according to claim 3.
5. The setting means sets the first weighting and the second weighting based on the relationship between the number of the attack targets included in the attack path in the past and the value representing the risk, and the success record of the cyber attack. The attack path presentation device according to claim 3.
6. The calculation formula includes the reciprocal of the number of the attack targets included in the attack path and the total value of the values representing the risk of one or more of the attack targets. The attack path presentation device according to claim 2 or claim 3.
7. The calculation formula includes the reciprocal of the number of the attack targets included in the attack path and the maximum value among the values representing the risk of one or more of the attack targets. The attack path presentation device according to claim 2 or claim 3.
8. The calculation formula includes the product of the probabilities of success of the cyber attacks representing the risk for one or more of the attack targets included in the attack path. The attack path presentation device according to claim 2.
9. The setting means adjusts the priorities of the two attack paths based on an adjustment criterion for adjusting the priorities of the two attack paths when the values indicating the priorities by the calculation formula are equal for the two attack paths. The attack path presentation device according to claim 2.
10. The adjustment criterion represents changing the priority of the attack path with fewer attack targets included in the attack path to a value higher than the priority of the other attack path. The attack path presentation device according to claim 9.
11. The adjustment criterion represents changing the priority of the attack path with a higher risk of the attack targets included in the attack path to a value higher than the priority of the other attack path. The attack path presentation device according to claim 9.
12. The setting means determines whether the attack path includes an attack target whose value representing the risk is lower than a first threshold value. The presentation means excludes from the presentation targets the attack path that includes an attack target whose value representing the risk is lower than the first threshold value. The attack path presentation device according to claim 1 or claim 2.
13. The acquisition means acquires information representing an attribute related to the risk for the attack target. The setting means sets the priority based on a setting criterion for setting the priority according to the attribute and the attribute. The attack path presentation device according to claim 1 or claim 2.
14. The attribute represents any one of a server, a terminal, a switch, and a firewall. The attack path presentation device according to claim 13.
15. The setting means determines whether the number of attack targets included in the attack path is less than a second threshold value, and sets the priority of the attack path with the number of attack targets less than the second threshold value to the highest regardless of the priority by the calculation formula. The attack path presentation device according to claim 2.
16. The setting means determines whether the number of the attack targets included in the attack path is less than a second threshold value, sets the priority of the first attack path in which the number of the attack targets is less than the second threshold value to be higher than that of the second attack path excluding the first attack path, and sets the priority using the calculation formula among the first attack paths and among the second attack paths, respectively. The attack path presentation device according to claim 2.
17. An information processing apparatus extracts a plurality of attack paths from an entrance to an attack target in a cyber attack on the information processing system from information representing the information processing system, obtains information representing the risk of a cyber attack on the attack targets included in the attack path for each of the attack paths, sets the priority of presenting the attack path to be higher as the number of the attack targets included in the attack path is smaller and as the risk of the attack targets is higher, and presents the attack path to a user according to the priority. An attack path presentation method.
18. The priority is calculated using a calculation formula for obtaining the priority from the number of the attack targets included in the attack path and a value representing the risk of the attack targets. The attack path presentation method according to claim 17.
19. A recording medium storing an attack path presentation program for causing a computer to execute an extraction process of extracting a plurality of attack paths from an entrance to an attack target in a cyber attack on the information processing system from information representing the information processing system, an acquisition process of obtaining information representing the risk of a cyber attack on the attack targets included in the attack path for each of the attack paths, a setting process of setting the priority of presenting the attack path to be higher as the number of the attack targets included in the attack path is smaller and as the risk of the attack targets is higher, and a presentation process of presenting the attack path to a user according to the priority.
20. The setting process calculates the priority using a calculation formula for obtaining the priority from the number of the attack targets included in the attack path and a value representing the risk of the attack targets. The recording medium storing the attack path presentation program according to claim 19.
Citation Information
Patent Citations
Security diagnostic system, method and program
JP2008257577A
Security measure planning support system and method
JP2018077597A
Security measure planning support device and security measure planning support method
JP2022165207A
Analysis device, analysis method, and non-transitory computer-readable medium in which analysis program is stored
WO2021130933A1