Attack visualization device, attack visualization method, and attack visualization program
The attack visualization device addresses redundant determinations in scenario-based threat analysis by generating attack success and element graphs, improving the efficiency and clarity of attack scenario visualization.
Patent Information
- Application Number
- PCT/JP2024/027576
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-07
- Filing Date
- 2024-08-01
- Publication Date
- 2025-11-13
AI Technical Summary
Existing methods for visualizing attacks in scenario-based threat analysis using graph representations result in a large number of redundant attack success determinations due to overlapping arrow endpoints, leading to inefficiencies.
An attack visualization device that generates an attack success determination graph and an element graph to identify successful attack techniques, reducing redundant determinations by analyzing transitions between elements and using logical formulas to determine attack success conditions.
The device effectively reduces the number of redundant attack success determinations and enhances the efficiency of scenario-based threat analysis by providing a clear visualization of attack scenarios.
Smart Images

Figure JP2024027576_13112025_PF_FP_ABST
Abstract
Description
Attack visualization device, attack visualization method, and attack visualization program
[0001] The present disclosure relates to an attack visualization device, an attack visualization method, and an attack visualization program.
[0002] In scenario-based threat analysis related to cybersecurity, there is a demand for visualization of attacks. Patent Literature 1 discloses a technology for visualizing attacks.
[0003] International Publication No. 2020-195228
[0004] In scenario-based threat analysis related to cybersecurity, the feasibility of an attack is determined based on the attacker's capabilities and vulnerability information held by each device. Therefore, the conditions for an attack to succeed are complex. Therefore, a method for visualizing attacks using a graph representation can be considered. Patent Document 1 does not disclose a method for visualizing attacks using a graph representation. When a method for visualizing attacks using a graph representation is adopted, there is a problem in that the number of attack success determinations is large because the number of attack success determinations is equal to the number of arrows. Another problem is that there is redundant attack success determinations because the determinations are made repeatedly at the points where the arrow endpoints overlap.
[0005] The present disclosure aims to relatively reduce the number of attack success determinations and to prevent redundant attack success determinations when adopting a method for visualizing attacks using graph representations in scenario-based threat analysis related to cybersecurity.
[0006] an attack visualization device according to the present disclosure, comprising: an attack identification unit that generates an attack success determination graph, which is a graph indicating attack success conditions for the target attack method based on each logical formula and each single condition associated with each logical formula, and which identifies each attack method that can be used on the target element by determining whether the target attack method is successful using the attack success determination graph; and an attack scenario generation unit that generates an element graph, which is a graph indicating each attack method that can be used on the target element in order of tactics, the graph indicating the environmental information and the attack success conditions corresponding to each attack method that can be used on the target element; and an attack scenario generation unit that generates an attack scenario for the analysis target by analyzing whether transitions between elements are possible based on each generated element graph, the configuration of the analysis target, a start element that is one of the plurality of elements, and an end element that is one of the plurality of elements.
[0007] According to the present disclosure, an attack identification unit generates an element graph by determining whether an attack technique is successful for each element constituting an analysis target using an attack success determination graph. Furthermore, an attack scenario generation unit generates an attack scenario by analyzing whether transitions between elements are possible based on each generated element graph. Here, the attack success determination graph is a graph indicating the attack success conditions of a target attack technique based on each logical expression and each single condition associated with each logical expression, and is a graph indicating the relationship between environmental information indicating the configuration of the target element and each single condition. Therefore, by using the attack success determination graph, the number of attack success determinations can be relatively reduced and redundant attack success determinations can be avoided. Therefore, according to the present disclosure, when a method for visualizing attacks using graph representations is adopted in scenario-based threat analysis related to cybersecurity, the number of attack success determinations can be relatively reduced and redundant attack success determinations can be avoided.
[0008] 1 is a diagram for explaining an attack scenario. A diagram showing an example of the configuration of an attack visualization system 99 according to the first embodiment. A diagram for explaining the processing of an attack identification unit 20 according to the first embodiment. A diagram for explaining the processing of the attack identification unit 20 according to the first embodiment. A diagram for explaining the processing of the attack identification unit 20 according to the first embodiment. A diagram for explaining the processing of the attack identification unit 20 according to the first embodiment. A diagram for explaining an element graph 41 according to the first embodiment. A diagram for explaining the processing of an attack scenario generation unit 50 according to the first embodiment. A diagram for explaining the processing of a visualization unit 70 according to the first embodiment. A diagram for explaining the processing of the visualization unit 70 according to the first embodiment. A diagram for explaining the processing of the visualization unit 70 according to the first embodiment. A diagram for explaining the processing of the visualization unit 70 according to the first embodiment. A diagram showing an example of the hardware configuration of an attack visualization device 1 according to the first embodiment. A flowchart showing the operation of the attack visualization system 99 according to the first embodiment. A flowchart showing the operation of the attack visualization system 99 according to the first embodiment. A flowchart showing the operation of the attack identification unit 20 according to the first embodiment. A flowchart showing the operation of the attack identification unit 20 according to the first embodiment. A flowchart showing the operation of the attack identification unit 20 according to the first embodiment. 1 is a flowchart showing the operation of the attack identification unit 20 according to the first embodiment. 2 is a flowchart showing the operation of the attack identification unit 20 according to the first embodiment. 3 is a flowchart showing the operation of the attack scenario generation unit 50 according to the first embodiment. 4 is a flowchart showing the operation of the attack scenario generation unit 50 according to the first embodiment. 5 is a flowchart showing the operation of the visualization unit 70 according to the first embodiment. 6 is a diagram showing an example of the hardware configuration of an attack visualization device 1 according to a modification of the first embodiment. 7 is a diagram showing an example of the configuration of an attack visualization system 99 according to the second embodiment. 8 is a diagram explaining the processing of a result cache unit 100 according to the second embodiment. 9 is a flowchart showing the operation of the result cache unit 100 according to the second embodiment. 10 is a flowchart showing the operation of the attack identification unit 20 according to the second embodiment. 11 is a flowchart showing the operation of the attack identification unit 20 according to the second embodiment. 12 is a flowchart showing the operation of the attack identification unit 20 according to the second embodiment. 13 is a flowchart showing the operation of the attack identification unit 20 according to the second embodiment. 14 is a flowchart showing the operation of the attack identification unit 20 according to the second embodiment. 15 is a diagram showing an example of the configuration of an attack visualization system 99 according to the third embodiment.1 is a diagram for explaining the processing of the attack scenario generation unit 50 according to embodiment 3. A flowchart showing the operation of the result cache unit 110 according to embodiment 3. A flowchart showing the operation of the attack scenario generation unit 50 according to embodiment 3. A diagram for explaining effects according to embodiment 3. A diagram showing an example of the configuration of an attack visualization system 99 according to embodiment 4. A diagram for explaining the processing of the attack scenario generation unit 50 and the result cache unit 120 according to embodiment 4. A flowchart showing the operation of the result cache unit 120 according to embodiment 4. A flowchart showing the operation of the attack scenario generation unit 50 according to embodiment 4. A diagram for explaining an example of the configuration of an attack visualization system 99 according to embodiment 5. A diagram for explaining the processing of the transition possibility determination unit 130 according to embodiment 5. A flowchart showing the operation of the transition possibility determination unit 130 according to embodiment 5. A flowchart showing the operation of the attack scenario generation unit 50 according to embodiment 5.
[0009] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. The description of elements given the same reference numerals will be omitted or simplified as appropriate. Arrows in the drawings mainly indicate the flow of data or the flow of processing. Furthermore, "unit" may be read as "circuit," "step," "procedure," "process," or "circuitry" as appropriate.
[0010] First Embodiment Hereinafter, the present embodiment will be described in detail with reference to the drawings.
[0011] ***Description of Configuration*** Figure 1 is a diagram illustrating an overview of an attack scenario, which is the target of visualization in this embodiment. An attack scenario comprehensively shows attacks that can occur on a system. Attacks are also called cyber attacks. In an attack scenario, attacks may be shown element by element. An element is a component that is the target of attack, and is the smallest unit of analysis in scenario-based threat analysis. Specific examples of an element are a PC (Personal Computer), a virtual PC, or a software function. An element is also called a system configuration element. Figure 1 shows how an attacker breaks through a firewall to infiltrate a system, and then attacks PCs and servers, etc., through internal activities, etc., to reach the target database.
[0012] 2 shows an example configuration of an attack visualization system 99 according to this embodiment. The attack visualization system 99 includes an attack visualization device 1, an attack database 30, and an external website 80. As shown in FIG. 2, the attack visualization device 1 includes an attack identification unit 20, an element graph storage unit 40, an attack scenario generation unit 50, an attack scenario storage unit 60, a visualization unit 70, and a screen 90. The attack visualization device 1 is also called an attack scenario visualization device or an attack scenario visualization system.
[0013] The attack identification unit 20 generates an attack success determination graph for a target element, determines whether a target attack technique is successful using the attack success determination graph, and identifies each attack technique that can be used on the target element. The attack identification unit 20 then generates an element graph 41 based on each identified attack technique. The target element is each of multiple elements that constitute the analysis target in scenario-based threat analysis related to cybersecurity. The attack success determination graph is a graph that shows the attack success conditions of a target attack technique based on each logical formula and each single condition associated with each logical formula, and is a graph that shows the relationship between the environment information 11 that indicates the configuration of the target element and each single condition. The target attack technique is each of one or more attack techniques. The attack identification unit 20 may generate the attack success determination graph based on each element indicated by the attack database 30. The element graph 41 is a graph that shows each attack technique that can be used on the target element in order of tactics, and is a graph that shows the environment information 11 and the attack success conditions corresponding to each attack technique that can be used on the target element. The attack success conditions may also be referred to as "success conditions." As a specific example, the attack identification unit 20 acquires the environmental information 11 from the worker 10, acquires the attack information 31 from the attack database 30, and generates each element graph 41 using the environmental information 11 and the attack information 31.
[0014] The worker 10 is a user of the attack visualization device 1 and is the entity that performs scenario-based threat analysis.
[0015] The attack database 30 is a database showing attack information 31, a specific example of which is MITRE ATT&CK (registered trademark). The attack information 31 is information about cyber attacks. The attack information 31 is data showing, for example, cyber attack techniques and tactics, campaigns, attacker groups, software, mitigation measures, and detection measures.
[0016] The element graph 41 is a graph defined for each element based on the attack database 30 and the element, and is a graph used to determine the conditions for establishing an attack. The element graph 41 is a graph showing cyber attacks and countermeasures for each element.
[0017] FIG. 3 is a diagram illustrating an overview of the element graph 41. In the example shown in FIG. 3, the element graph 41 appropriately connects attack classes, attack conditions, and environmental information. In this example, the attack database 30 is MITRE ATT&CK (registered trademark). Attack classes are defined based on the tactics and techniques indicated in the attack database 30. Classes are also defined for each of the mitigation measures, attacker groups, campaigns, software, and detection measures indicated in the attack database 30. The attack conditions are a set of AND conditions, OR conditions, and NOT conditions. The attack conditions may not include one or two of the AND conditions, OR conditions, and NOT conditions. The attack conditions may also be expressed as a composite condition that combines these conditions. Each of the AND conditions and OR conditions is made up of a set of single-condition classes. The composite condition includes classes similar to the AND condition but other than the single-condition classes. The attack condition for the NOT condition is that no instance corresponding to the NOT condition exists in the environmental information. The environment information 11 is an instance that indicates the attacker's capabilities regarding an element and the countermeasures applied to the element. The attacker's capabilities correspond to attacks expected on the element, and are determined according to, for example, a campaign, an attacker group, and software. The countermeasures consist of, for example, mitigation measures and detection measures.
[0018] FIG. 4 is a diagram illustrating an inference process performed by the attack identification unit 20 using an element graph 41. The diagram illustrates a process for determining whether an attack technique is usable based on whether a single condition of an attack establishment condition exists in the environmental information 11. FIG. 4 shows an example of a process for determining whether a single condition exists. This process will be described below. First, as shown in (1) in FIG. 4 , the attack identification unit 20 determines whether the attack establishment condition exists. In this example, the presence of APT19 is identified as a condition for an attack to be established. Note that, depending on the presence or absence of countermeasures, either True or False can be a condition for an attack to be established. When False is associated with the condition for an attack to be established, the absence of a corresponding instance in the environmental information 11 is a condition for an attack to be established. Next, as shown in (2) in FIG. 4 , the attack identification unit 20 determines whether the environmental information 11 has a single condition. In this example, by following the arrows in the graph, it is possible to reach the APT19 instance included in the environmental information 11 via the APT19 class. Therefore, it is determined that APT 19 is true. The attack identification unit 20 executes the above-described determination process as necessary for all conditions linked to the composite condition.
[0019] 5 is a diagram illustrating the process in which the attack identification unit 20 executes attack success determination so as to reduce the number of times the attack success determination is performed. The attack identification unit 20 determines that an OR condition is true when a single condition under the OR condition is true. The attack identification unit 20 determines that an AND condition is false when a single condition under the AND condition is false.
[0020] The element graph storage unit 40 stores each element graph 41 generated by the attack identification unit 20 .
[0021] The attack scenario generation unit 50 generates an attack scenario for the analysis target by analyzing whether transitions between elements are possible based on each generated element graph 41, the configuration of the analysis target, a start element which is one of the multiple elements, and an end element which is one of the multiple elements. As a specific example, the attack scenario generation unit 50 generates an attack scenario graph 61 based on the analysis target information 12 and each element graph 41. The analysis target information 12 is information indicating the analysis target in scenario-based threat analysis. As a specific example, the analysis target information 12 is information indicating the system configuration, the start point of an attack, and the end point of an attack. The attack scenario graph 61 is a graph indicating an attack scenario in scenario-based threat analysis.
[0022] FIG. 6 is a diagram illustrating an example of an element graph 41. In this example, attack techniques are listed in tactical order, along with the conditions for each attack technique and the relationship between each condition and the environment information 11. FIG. 6 is explained below. Attack technique A is established when condition 1 is established. When attack technique A is established, transitions to attack technique B and attack technique C occur. Attack technique B is established when condition 2 is established. When attack technique B is established, the worker 10 can transition to an element with which element 1 can communicate. Attack technique C is established when condition 3 is established. When attack technique C is not established, the attack on element 1 ends. As a specific example, attack techniques are defined by a combination of tactics and techniques as specified by MITRE ATT&CK (registered trademark). Note that tactics do not loop, so loop detection is not required when analyzing transitions between attack techniques.
[0023] FIG. 7 is a diagram illustrating the process performed by the attack scenario generation unit 50 to analyze the transition of an attack between elements. When analyzing a path from the start point to the end point of an attack, the attack scenario generation unit 50 efficiently searches for a path by searching for the path in reverse order, i.e., by tracing the transitions while determining whether a transition is possible from the end point to the start point. By searching for a path in reverse order, the attack scenario generation unit 50 can terminate the search midway if a path from the start point to the end point does not exist. When searching in reverse order, the attack scenario generation unit 50 determines whether a transition to each element is possible based on whether an attack method that enables a transition to the source element is available at the destination element. The attack scenario generation unit 50 extracts all paths from the start point to the end point. Each extracted path does not include a loop. In the example shown in FIG. 7, all possible paths include "1 → 2 → 3 → 5," "1 → 2 → 4 → 5," "1 → 6 → 2 → 3 → 5," and "1 → 6 → 2 → 4 → 5." Here, each number represents an element. Evaluating "1 → 2 → 3 → 5" in reverse order results in "5 (OK) → 3 (OK) → 2 (OK) → 1." Here, "OK" immediately after a certain number means that an attack method that enables a transition to the element corresponding to the number following that certain number is successful in the element corresponding to the number following that certain number. Evaluating "1 → 2 → 4 → 5" in reverse order results in "5 (OK) → 4 (NOT OK) → NO." Here, "NOT OK" immediately after a certain number means that an attack method that enables a transition to the element corresponding to the number following that certain number is not successful in the element corresponding to the number following that certain number. Evaluating "1 → 6 → 2 → 3 → 5" in reverse order results in "5 (OK) → 3 (OK) → 2 (OK) → 6 (NOT OK) → NO." Evaluating "1 → 6 → 2 → 4 → 5" in reverse order results in "5 (OK) → 4 (NOT OK) → NO."
[0024] The attack scenario storage unit 60 stores the attack scenario graph 61 generated by the attack scenario generation unit 50 .
[0025] The visualization unit 70 generates a visualization graph 71 for visualizing a portion of each generated element graph 41 and an attack scenario graph 61 corresponding to the attack scenario, according to the visualization conditions. The visualization unit 70 may generate, as the visualization graph 71, a graph that displays an attack technique and an analysis target element related to the attack technique. The visualization unit 70 may link graph elements that are elements of the visualization graph 71 to external attack information. The external attack information is information that corresponds to the graph elements, and is information that corresponds to elements indicated in the attack database 30. As a specific example, the visualization unit 70 generates the visualization graph 71 based on the attack scenario graph 61 and the visualization conditions 13.
[0026] The screen 90 accepts input of the visualization conditions 13, instructs the visualization unit 70 to generate a visualization graph 71 in accordance with the accepted visualization conditions 13, and displays the visualization graph 71 generated by the visualization unit 70. The visualization conditions 13 are conditions related to the visualization of attack scenarios. Specific examples of the visualization conditions 13 include filter conditions related to attack techniques or elements, or search words.
[0027] FIG. 8 shows an example of a visualization graph 71. In this example, the visualization tool is linked to an explanation page (external website 80) of MITRE ATT&CK (registered trademark). Specifically, a hyperlink is appropriately set for each attack method shown in the visualization graph 71. When an attack method shown in the visualization graph 71 displayed on the screen 90 is selected, an explanation page corresponding to the attack method is displayed on the screen 90. The visualization graph 71 also shows the attacker's intrusion route and the attack method used by the attacker to infiltrate. Note that in practice, the visualization graph 71 often consists of a huge number of nodes. However, for ease of explanation, a greatly simplified visualization graph 71 is shown in each example of the visualization graph 71.
[0028] FIG. 9 shows an example of the visualization graph 71. In this example, when an element shown in the visualization graph 71 is selected on the screen 90, details of the selected element are displayed on the screen 90. In the display of the element details, the hierarchical relationship of the attack techniques available for the element is displayed, that is, the attack techniques available for the element are displayed in tactical order. In addition, each attack technique is appropriately associated with CVE (Common Vulnerabilities and Exposures) information corresponding to each attack technique. When CVE information is selected on the screen 90, the page (external website 80) of the selected CVE information is displayed on the screen 90.
[0029] 10 shows an example of a visualization graph 71. In this example, it is possible to switch between displaying and hiding each type of attack. This function is utilized when it is desired to display only the intrusion point, only the transition between elements, or only the attack techniques necessary for the occurrence of a threat. As a specific example, by selecting a pentagonal icon displayed on the screen 90, it is possible to switch the display so that attack techniques A, B, C, D, and E are hidden and only attack techniques 1, 2, 3, 4, and 5 are displayed.
[0030] 11 shows an example of the visualization graph 71. In this example, when the attack techniques are narrowed down by specifying the attack technique name as a search word, the narrowed down attack techniques and system components related to the narrowed down attack techniques are displayed. Specifically, by specifying "AAA" as a search word, attack techniques whose names include "AAA" and each element used in the attack techniques that include "AAA" are displayed on the screen 90.
[0031] 12 shows an example of the hardware configuration of the attack visualization device 1 according to this embodiment. The attack visualization device 1 is composed of a computer. The attack visualization device 1 may also be composed of multiple computers.
[0032] As shown in the figure, the attack visualization device 1 is a computer that includes hardware such as a processor 201, a memory 202, an auxiliary storage device 203, an input / output IF (Interface) 204, and a communication device 205. These pieces of hardware are connected as appropriate via signal lines 209.
[0033] The processor 201 is an integrated circuit (IC) that performs arithmetic processing and controls the hardware of a computer. Specific examples of the processor 201 include a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The attack visualization device 1 may include multiple processors that replace the processor 201. The multiple processors share the role of the processor 201.
[0034] The memory 202 is typically a volatile storage device, and a specific example is RAM (Random Access Memory). The memory 202 is also called a primary storage device or a main memory. Data stored in the memory 202 is saved in the secondary storage device 203 as needed.
[0035] The auxiliary storage device 203 is typically a non-volatile storage device, and specific examples thereof include a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the auxiliary storage device 203 is loaded into the memory 202 as needed. The memory 202 and the auxiliary storage device 203 may be configured integrally.
[0036] The input / output IF 204 is a port to which an input device and an output device are connected. Specific examples of the input / output IF 204 include a USB (Universal Serial Bus) terminal. Specific examples of the input device include a keyboard and a mouse. Specific examples of the output device include a display.
[0037] The communication device 205 is a receiver and a transmitter, and is specifically a communication chip or a NIC (Network Interface Card).
[0038] Each part of the attack visualization device 1 may use the input / output IF 204 and the communication device 205 as appropriate when communicating with other devices.
[0039] The auxiliary storage device 203 stores an attack visualization program. The attack visualization program is a program that causes a computer to realize the functions of each unit included in the attack visualization device 1. The attack visualization program is loaded into the memory 202 and executed by the processor 201. The functions of each unit included in the attack visualization device 1 are realized by software.
[0040] Data used when executing the attack visualization program and data obtained by executing the attack visualization program are stored in a storage device as appropriate. Each part of the attack visualization device 1 uses a storage device as appropriate. As a specific example, the storage device includes at least one of a memory 202, an auxiliary storage device 203, a register in the processor 201, and a cache memory in the processor 201. Note that the terms "data" and "information" may have the same meaning. The storage device may be independent of the computer. The functions of the memory 202 and the auxiliary storage device 203 may be realized by other storage devices.
[0041] The attack visualization program may be recorded on a computer-readable non-volatile recording medium. Specific examples of the non-volatile recording medium include an optical disk and a flash memory. The attack visualization program may be provided as a program product.
[0042] ***Explanation of Operation*** The operational procedure of the attack visualization device 1 corresponds to an attack visualization method. Also, the program that realizes the operation of the attack visualization device 1 corresponds to an attack visualization program.
[0043] 13 and 14 are flowcharts showing an example of the operation of the attack visualization system 99. The operation will be explained using the drawings.
[0044] (Step S101) Hereinafter, it is assumed that the attack visualization device 1 selects, as a selected element, an element that has not yet been selected in the iterative process consisting of steps S101 to S105. The attack identification unit 20 receives, from the operator 10, input of environment information 11 that indicates the attacker capabilities assumed by the selected element (campaign, attacker group, software, etc.), mitigation measures and detection measures that have been applied to the selected element, and the execution platform of the selected element, such as the OS (Operating System).
[0045] (Step S102 ) The attack identification unit 20 acquires the attack information 31 related to the selected element from the attack database 30 .
[0046] (Step S103) First, the attack identification unit 20 narrows down the tactics and attack methods based on the environmental information 11. Next, the attack identification unit 20 connects the attack methods in the order of the narrowed down tactics. Furthermore, the attack identification unit 20 generates a graph that links the campaign, attacker group, software, mitigation measures, and detection measures as attack success conditions for each attack method. After that, the attack identification unit 20 determines whether the attack methods are successful in the order of tactics based on the attack success conditions and the environmental information 11, and extracts only usable attack methods. Based on the extracted attack methods, the attack identification unit 20 generates an element graph 41 that connects the usable attack methods in the order of tactics.
[0047] (Step S104 ) The attack identification unit 20 stores the generated element graph 41 in the element graph storage unit 40 .
[0048] (Step S105) When the processing from step S101 onwards has been executed for all elements, the attack visualization device 1 proceeds to step S106. Otherwise, the attack visualization device 1 executes the processing from step S101 onwards again.
[0049] (Step S106) The attack scenario generation unit 50 receives input from the worker 10 as analysis target information 12, including an element class for identifying the element graph 41, a system configuration showing the connection relationships between the elements, the starting point of the attack, and the end point of the attack.
[0050] (Step S107 ) The attack scenario generation unit 50 acquires the element graph 41 from the element graph storage unit 40 based on the element class indicated by the analysis target information 12 .
[0051] (Step S108) The attack scenario generation unit 50 extracts all loop-free paths from the start point to the end point of the attack, and determines whether transition is possible for each extracted path by analyzing the path in reverse order (from the end point to the start point) using the element graph 41. At this time, if a path contains an element that cannot be transitioned, the attack scenario generation unit 50 excludes the path. The attack scenario generation unit 50 generates the attack scenario graph 61 by connecting available attack techniques to each element on each path that has not been excluded.
[0052] (Step S109 ) The attack scenario generation unit 50 stores the generated attack scenario graph 61 in the attack scenario storage unit 60 .
[0053] (Step S110 ) The visualization unit 70 acquires the attack scenario graph 61 from the attack scenario storage unit 60 .
[0054] (Step S111 ) The visualization unit 70 acquires, from the external website 80 , the URL 81 of the website related to the attack technique indicated by the attack scenario graph 61 .
[0055] (Step S112) The visualization unit 70 generates a hyperlink 91 to the website using the acquired URL 81.
[0056] (Step S113) If there is a CVE used in the attack technique indicated by the attack scenario graph 61, the visualization unit 70 acquires the URL 81 of the website related to the CVE.
[0057] (Step S114) The visualization unit 70 generates a hyperlink 91 to the website using the acquired URL 81.
[0058] (Step S115 ) The visualization unit 70 generates a visualization graph 71 by adding the generated hyperlink 91 to the attack scenario graph 61 .
[0059] (Step S116) The visualization unit 70 outputs the visualization graph 71 to the screen 90. This allows the worker 10 to check the visualization graph 71 on the screen 90. Furthermore, by clicking on the hyperlink 91, the worker 10 can access an external website 80 that describes details of the attack technique or CVE.
[0060] (Step S117) If the operator 10 clicks on the hyperlink 91, the attack visualization device 1 proceeds to step S118. Otherwise, the attack visualization device 1 proceeds to step S119.
[0061] (Step S118) The screen 90 loads, in a new tab, the web page of the external website 80 corresponding to the clicked hyperlink 91.
[0062] (Step S119) The worker 10 inputs the visualization conditions 13 as necessary. If the worker 10 inputs the visualization conditions 13, the attack visualization device 1 proceeds to step S120. Otherwise, the attack visualization device 1 proceeds to step S122.
[0063] (Step S120) The visualization unit 70 filters the attack techniques in the visualization graph 71 by tactic, or filters the elements of the visualization graph 71, the names of the attack techniques, etc., using search words based on the visualization conditions 13. Note that the visualization graph 71 on which the filtering process has been performed in this step is also the visualization graph 71.
[0064] (Step S121) The visualization unit 70 outputs the visualization graph 71 on which the filtering process has been performed to the screen 90.
[0065] (Step S122) If the operator 10 closes the screen 90, the attack visualization device 1 ends the processing of this flowchart. Otherwise, the attack visualization device 1 proceeds to step S117.
[0066] 15 to 21 are flowcharts showing an example of the operation of the attack identification unit 20 in step S103. This operation will be explained using FIGS.
[0067] (Step S201) The attack identification unit 20 narrows down the tactics and attack methods based on the environment information 11.
[0068] (Step S202) The attack identification unit 20 generates an attack technique graph by connecting the attack techniques in tactical order.
[0069] (Step S203) If the processes for all attack methods have been executed, the attack identifying unit 20 proceeds to step S232. Otherwise, the attack identifying unit 20 proceeds to step S204.
[0070] (Step S204) The attack identification unit 20 generates a composite condition instance. The composite condition instance is an instance of the composite condition class.
[0071] (Step S205) The attack identification unit 20 generates a campaign OR condition instance. The campaign OR condition instance is an instance of the campaign OR condition class.
[0072] (Step S206) The attack identification unit 20 identifies a campaign capable of executing the attack technique, and generates a class and an instance related to the identified campaign. A campaign corresponds to an example of an attack.
[0073] (Step S207) The attack identification unit 20 connects True to "is true?" in the campaign class.
[0074] (Step S208) The attack identification unit 20 connects the campaign instance to the campaign OR condition instance.
[0075] (Step S209) If there is an unprocessed campaign linked to the attack method, the attack identifying unit 20 proceeds to step S206. Otherwise, the attack identifying unit 20 proceeds to step S230.
[0076] (Step S210) The attack identification unit 20 generates an attacker group OR condition instance. The attacker group OR condition instance is an instance of the attacker group OR condition class.
[0077] (Step S211) The attack identification unit 20 identifies an attacker group capable of executing an attack technique, and creates a class and an instance related to the identified attacker group.
[0078] (Step S212) The attack identification unit 20 connects True to "Is true?" of the attacker group class.
[0079] (Step S213) The attack identification unit 20 connects the attacker group instance to the attacker group OR condition instance.
[0080] (Step S214) If there is an unprocessed attacker group linked to the attack method, the attack identifying unit 20 proceeds to step S211. Otherwise, the attack identifying unit 20 proceeds to step S230.
[0081] (Step S215) The attack identification unit 20 generates a software OR condition instance. The software OR condition instance is an instance of the software OR condition class.
[0082] (Step S216) The attack identification unit 20 identifies software capable of executing the attack technique, and creates a class and an instance related to the identified software.
[0083] (Step S217) The attack identification unit 20 connects True to "Is true?" of the software class.
[0084] (Step S218) The attack identification unit 20 connects the software instance to the software OR condition instance.
[0085] (Step S219) If there is unprocessed software linked to the attack method, the attack identifying unit 20 proceeds to step S216. Otherwise, the attack identifying unit 20 proceeds to step S230.
[0086] (Step S220) The attack identification unit 20 generates a mitigation AND condition instance. The mitigation AND condition instance is an instance of the mitigation AND condition class.
[0087] (Step S221) The attack identification unit 20 identifies mitigation measures that can be implemented to mitigate the attack method, and creates a class and an instance related to the identified mitigation measures.
[0088] (Step S222) The attack identification unit 20 connects False to "Is true?" of the mitigation class.
[0089] (Step S223) The attack identification unit 20 connects the mitigation measure instance to the mitigation measure AND condition instance.
[0090] (Step S224) If there are any unprocessed mitigation measures associated with the attack method, the attack identifying unit 20 proceeds to step S221. Otherwise, the attack identifying unit 20 proceeds to step S230.
[0091] (Step S225) The attack identification unit 20 generates a detection strategy AND condition instance. The detection strategy AND condition instance is an instance of the detection strategy AND condition class.
[0092] (Step S226) The attack identification unit 20 identifies a detection measure that can be used to detect the attack technique, and creates a class and an instance related to the identified detection measure.
[0093] (Step S227) The attack identification unit 20 connects False to "Is true?" of the detection measure class.
[0094] (Step S228) The attack identification unit 20 connects the detection measure instance to the detection measure AND condition instance.
[0095] (Step S229) If there are unprocessed detection measures associated with the attack method, the attack identifying unit 20 proceeds to step S226. Otherwise, the attack identifying unit 20 proceeds to step S230.
[0096] (Step S230) The attack identification unit 20 connects a campaign OR condition instance, an attacker group OR condition instance, a software OR condition instance, a mitigation measure AND condition instance, and a detection measure AND condition instance to the composite condition instance.
[0097] (Step S231) The attack identification unit 20 connects a composite condition instance to the attack establishment condition of the attack method.
[0098] (Step S232) The attack identification unit 20 sets an empty graph as the element graph 41.
[0099] (Step S233) The attack identification unit 20 selects one attack method that has not yet been selected from the attack methods that include the connection relationships indicated by the attack establishment condition graph, and assigns the selected attack method to the variable “attack method”.
[0100] (Step S234) The attack identification unit 20 assigns the composite condition instance associated with the "attack method" to the variable "composite condition instance."
[0101] (Step S235) The attack identification unit 20 assigns False to the variable "campaign RESULT".
[0102] (Step S236) The attack identification unit 20 selects one campaign instance from the campaign OR condition instances.
[0103] (Step S237) The attack identification unit 20 assigns the value of "is true?" of the campaign class to the variable "BOOL".
[0104] (Step S238) If the selected campaign instance exists in the environment information 11, the attack identifying unit 20 proceeds to step S239. Otherwise, the attack identifying unit 20 proceeds to step S240.
[0105] (Step S239) The attack identification unit 20 assigns True to the variable “campaign RESULT”.
[0106] (Step S240) If there is an unprocessed campaign instance in the campaign OR condition instance, the attack identifying unit 20 proceeds to step S236. Otherwise, the attack identifying unit 20 proceeds to step S265.
[0107] (Step S241) The attack identification unit 20 assigns False to the variable “attacker group RESULT”.
[0108] (Step S242) The attack identification unit 20 selects one attacker group instance from the attacker group OR condition instances.
[0109] (Step S243) The attack identification unit 20 assigns the value of "is true?" of the attacker group class to the variable "BOOL".
[0110] (Step S244) If the selected attacker group instance exists in the environment information 11, the attack identification unit 20 proceeds to step S245. Otherwise, the attack identification unit 20 proceeds to step S246.
[0111] (Step S245) The attack identification unit 20 assigns True to the variable “attacker group RESULT”.
[0112] (Step S246) If there is an unprocessed attacker group instance in the attacker group OR condition instance, the attack identification unit 20 proceeds to step S242. Otherwise, the attack identification unit 20 proceeds to step S265.
[0113] (Step S247) The attack identification unit 20 assigns False to the variable "software RESULT".
[0114] (Step S248) The attack identification unit 20 selects one software instance from the software OR condition instances.
[0115] (Step S249) The attack identification unit 20 assigns the value of "is true?" of the software class to the variable "BOOL".
[0116] (Step S250) If the selected software instance exists in the environment information 11, the attack identifying unit 20 proceeds to step S251. Otherwise, the attack identifying unit 20 proceeds to step S252.
[0117] (Step S251) The attack identification unit 20 assigns True to the variable "software RESULT".
[0118] (Step S252) If there is an unprocessed software instance in the software OR condition instance, the attack identification unit 20 proceeds to step S248. Otherwise, the attack identification unit 20 proceeds to step S265.
[0119] (Step S253) The attack identification unit 20 assigns True to the variable “mitigation measure RESULT”.
[0120] (Step S254) The attack identification unit 20 selects one mitigation measure instance from the mitigation measure AND condition instances.
[0121] (Step S255) The attack identification unit 20 assigns the value of "is true?" of the mitigation class to the variable "BOOL".
[0122] (Step S256) If the selected mitigation measure instance exists in the environment information 11, the attack identifying unit 20 proceeds to step S258. Otherwise, the attack identifying unit 20 proceeds to step S257.
[0123] (Step S257) The attack identification unit 20 assigns False to the variable “mitigation measure RESULT”.
[0124] (Step S258) If there is an unprocessed mitigation measure instance in the mitigation measure AND condition instance, the attack identifying unit 20 proceeds to step S254. Otherwise, the attack identifying unit 20 proceeds to step S265.
[0125] (Step S259) The attack identification unit 20 assigns True to the variable “detection measure RESULT”.
[0126] (Step S260) The attack identification unit 20 selects one detection measure instance from the detection measure AND condition instances.
[0127] (Step S261) The attack identification unit 20 assigns the value of "is true?" of the detection measure class to the variable "BOOL".
[0128] (Step S262) If the selected detection measure instance exists in the environment information 11, the attack identifying unit 20 proceeds to step S264. Otherwise, the attack identifying unit 20 proceeds to step S263.
[0129] (Step S263) The attack identification unit 20 assigns False to the variable “detection measure RESULT”.
[0130] (Step S264) If there is an unprocessed detection measure instance in the detection measure AND condition instance, the attack identification unit 20 proceeds to step S260. Otherwise, the attack identification unit 20 proceeds to step S265.
[0131] (Step S265) The attack identification unit 20 assigns the logical product of the variables “campaign RESULT”, “attacker group RESULT”, “software RESULT”, “mitigation measure RESULT”, and “detection measure RESULT” to the variable “composite condition RESULT”.
[0132] (Step S266) If the value of the variable "composite condition RESULT" is True, the attack identification unit 20 proceeds to step S267. Otherwise, the attack identification unit 20 proceeds to step S268.
[0133] (Step S267 ) The attack identification unit 20 adds “attack method” to the element graph 41 .
[0134] (Step S268) If the processing has been executed for all the composite condition instances indicated by the attack establishment condition graph, the attack identification unit 20 proceeds to step S269. Otherwise, the attack identification unit 20 proceeds to step S233.
[0135] (Step S269) The attack identification unit 20 outputs the element graph 41.
[0136] 22 and 23 show an example of the operation of the attack scenario generation unit 50 in step S108. This operation will be explained using FIGS.
[0137] (Step S501) The attack scenario generation unit 50 extracts all paths from the start element to the end element and includes each extracted path in a path group. Note that the attack scenario generation unit 50 does not extract paths with loops.
[0138] (Step S502) The attack scenario generation unit 50 sets an empty graph as the attack scenario graph 61.
[0139] (Step S503) The attack scenario generation unit 50 assigns True to the variable "transition possible or not."
[0140] (Step S504) The attack scenario generation unit 50 selects one route that has not yet been selected from the group of routes, and assigns the selected route to the variable "route".
[0141] (Step S505) The attack scenario generation unit 50 sorts the "route" elements in reverse order.
[0142] (Step S506) The attack scenario generation unit 50 selects the first element of the "route" and assigns the selected element to the variable "element".
[0143] (Step S507) The attack scenario generation unit 50 selects an element graph 41 of the same class as the class of the “element”.
[0144] (Step S508) If there is no path to the attack technique required for the transition in the selected element graph 41, the attack scenario generation unit 50 transitions to step S509. Otherwise, the attack scenario generation unit 50 transitions to step S510.
[0145] (Step S509) The attack scenario generation unit 50 assigns False to the variable "transition possible or not."
[0146] (Step S510) The attack scenario generation unit 50 removes the "element" from the "route".
[0147] (Step S511) If the "route" is empty, the attack scenario generation unit 50 proceeds to step S512. Otherwise, the attack scenario generation unit 50 proceeds to step S506.
[0148] (Step S512) If the value of the variable "transition possible" is True, the attack scenario generation unit 50 transitions to step S513. Otherwise, the attack scenario generation unit 50 transitions to step S514.
[0149] (Step S513) The attack scenario generation unit 50 adds a “route” to the attack scenario graph 61.
[0150] (Step S514) If there are any unprocessed routes in the route group, the attack scenario generation unit 50 transitions to step S503. Otherwise, the attack scenario generation unit 50 transitions to step S515.
[0151] (Step S515) The attack scenario generation unit 50 selects one element from the attack scenario graph 61 and assigns the selected element to the variable “element”.
[0152] (Step S516) The attack scenario generation unit 50 selects an element graph 41 of the same class as the class of the “element”.
[0153] (Step S517 ) The attack scenario generation unit 50 extracts all attack methods indicated by the selected element graph 41 .
[0154] (Step S518) The attack scenario generation unit 50 connects each of the extracted attack techniques to the “elements” of the attack scenario graph 61.
[0155] (Step S519) If there are unprocessed elements in the attack scenario graph 61, the attack scenario generation unit 50 proceeds to step S515. Otherwise, the attack scenario generation unit 50 proceeds to step S520.
[0156] (Step S520) The attack scenario generation unit 50 outputs the attack scenario graph 61.
[0157] 24 shows an example of the operation of the visualization unit 70 in step S120. This operation will be described with reference to FIG.
[0158] (Step S701) The visualization unit 70 sets the attack scenario graph 61 in the visualization graph 71.
[0159] (Step S702 ) The visualization unit 70 connects a hyperlink 91 to the “attack method” indicated in the visualization graph 71 .
[0160] (Step S703) If an attack technique to be visualized is specified through the visualization condition 13, the visualization unit 70 proceeds to step S704. Otherwise, the visualization unit 70 proceeds to step S705.
[0161] (Step S704) The visualization unit 70 visualizes the attack techniques specified by the visualization conditions 13 in the visualization graph 71.
[0162] (Step S705) If an attack technique to be made invisible is specified through the visualization condition 13, the visualization unit 70 proceeds to step S706. Otherwise, the visualization unit 70 proceeds to step S707.
[0163] (Step S706 ) The visualization unit 70 makes the attack methods specified by the visualization conditions 13 invisible in the visualization graph 71 .
[0164] (Step S707) If a search word for an attack technique is specified through the visualization condition 13, the visualization unit 70 proceeds to step S708. Otherwise, the visualization unit 70 proceeds to step S709.
[0165] (Step S708) The visualization unit 70 visualizes attack techniques indicated by the visualization graph 71 that include the search word specified by the visualization condition 13, and does not visualize other attack techniques.
[0166] (Step S709) The visualization unit 70 outputs the visualization graph 71.
[0167] ***Explanation of the Effects of First Embodiment*** As described above, in this embodiment, complex attack conditions are expressed consistently and without redundancy using a graph that shows at least one of AND conditions, OR conditions, and NOT conditions. Therefore, this embodiment can speed up the attack success determination process for deriving an attack scenario compared to conventional methods that use predicate logic or decision tables. Furthermore, this embodiment can omit condition determination by utilizing the characteristics of the success conditions for both AND conditions and OR conditions.
[0168] Furthermore, while there is a demand for visualizing attack scenarios in various formats by setting various conditions, conventional techniques have the problem that visibility decreases as the number of attack scenarios increases. On the other hand, this embodiment allows for drill-down display of attack scenarios, allows switching between visualization and non-visibility of each element depending on the type of attack, and also allows attack techniques to be searched for by specifying the attack name. Therefore, according to this embodiment, visibility is unlikely to decrease even if the attack scenarios become more complex or the number of attack scenarios increases.
[0169] ***Other Configurations*** <Variation 1> Fig. 25 shows an example hardware configuration of the attack visualization device 1 according to this variation. The attack visualization device 1 includes a processing circuit 208 instead of the processor 201, the processor 201 and memory 202, the processor 201 and auxiliary storage device 203, or the processor 201, memory 202, and auxiliary storage device 203. The processing circuit 208 is hardware that realizes at least a portion of the components included in the attack visualization device 1. The processing circuit 208 may be dedicated hardware, or may be a processor that executes a program stored in the memory 202.
[0170] When the processing circuit 208 is dedicated hardware, the processing circuit 208 is, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The attack visualization device 1 may include multiple processing circuits that replace the processing circuit 208. The multiple processing circuits share the role of the processing circuit 208.
[0171] In the attack visualization device 1, some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.
[0172] The processing circuit 208 is realized by, for example, hardware, software, firmware, or a combination of these. The processor 201, memory 202, auxiliary storage device 203, and processing circuit 208 are collectively referred to as "processing circuitry." In other words, the functions of each functional component of the attack visualization device 1 are realized by the processing circuitry. Attack visualization devices 1 according to other embodiments may also have a configuration similar to this modification.
[0173] Second Embodiment The following mainly describes the differences from the above-described embodiment with reference to the drawings.
[0174] 26 shows an example of the configuration of an attack visualization system 99 according to this embodiment. Compared to the first embodiment, the attack visualization device 1 according to this embodiment further includes a result cache unit 100.
[0175] The result cache unit 100 receives the attack success condition 21 and outputs a result 22 corresponding to the received attack success condition 21. The result cache unit 100 is also called a first result cache unit. The first result cache unit stores data indicating a determination result regarding whether or not a target attack method is successful. The attack success condition 21 is used to query the result cache unit 100 for a determination result corresponding to the attack success condition 21. If the attack success condition 21 has been determined in the past, the result 22 is information indicating the determination result corresponding to the attack success condition 21. In other cases, the result 22 is information indicating that the attack success condition 21 has not been determined in the past.
[0176] FIG. 27 is a diagram illustrating the processing of the result cache unit 100. Here, the environment information 11 does not change within the same element. Therefore, the judgment result for the same single condition does not change. Therefore, the result cache unit 100 immediately returns the judgment result for a single condition that has been previously judged among the single conditions indicated by the attack success conditions. In the example shown in FIG. 27, in the judgment of the "execution_Python_OR condition" and the "initial-access_Drive-by-Compromise_OR condition," a judgment is made for the single condition "Does it have APT19?" for both. Therefore, if the single condition for the "execution_Python_OR condition" has already been judged to be True, the result cache unit 100 immediately judges the "initial-access_Drive-by-Compromise_OR condition" to be True.
[0177] The attack identification unit 20 according to this embodiment utilizes the data stored in the result cache unit 100 when determining whether a target attack technique is successful. In other words, the attack identification unit 20 utilizes the result cache unit 100 when determining whether a single condition is met.
[0178] ***Explanation of Operation*** The following mainly explains the differences from the first embodiment regarding the operation of the attack visualization system 99.
[0179] (Step S103) The attack identification unit 20 executes the same process as step S103 according to the first embodiment. However, the attack identification unit 20 stores the results of the determination of the success of the attack method in the result cache unit 100. Furthermore, before determining the success of each attack method, the attack identification unit 20 queries the result cache unit 100 as to whether the attack success condition 21 has been determined in the past. If a certain attack method has been determined in the past, the attack identification unit 20 receives a result 22 corresponding to the certain attack method from the result cache unit 100.
[0180] 28 is a flowchart showing an example of the operation of the result cache unit 100. This operation will be described with reference to FIG.
[0181] (Step S291) Attack establishment condition 21 c i and c i Judgment result r regarding i If the result cache unit 100 receives the message, the process proceeds to step S292. Otherwise, the process proceeds to step S293. i corresponds to each instance.
[0182] (Step S292) The result cache unit 100 calculates H(c i ) = r i Save as.
[0183] (Step S293) Attack establishment condition 21 c j If the result cache unit 100 receives the request, the process proceeds to step S294. Otherwise, the process proceeds to step S297.
[0184] (Step S294) H(c j If the value of ( ) exists in the result cache unit 100, the result cache unit 100 proceeds to step S295. Otherwise, the result cache unit 100 proceeds to step S296.
[0185] (Step S295) The result cache unit 100 adds H(c j ) is substituted.
[0186] (Step S296) The result cache unit 100 empties the result 22.
[0187] (Step S297) The result cache unit 100 outputs the result 22.
[0188] 29 to 33 show an example of the operation of the attack identifying unit 20 according to this embodiment. Differences between the operation of the attack identifying unit 20 and the first embodiment will be mainly described with reference to FIGS.
[0189] (Step S271) The attack identification unit 20 acquires the result 22 by inquiring of the result cache unit 100 whether or not there is a determination result of the campaign instance.
[0190] (Step S272) If the result 22 is empty, the attack identifying unit 20 proceeds to step S237. Otherwise, the attack identifying unit 20 proceeds to step S273.
[0191] (Step S273) The attack identification unit 20 assigns the result 22 to the variable "campaign RESULT".
[0192] (Step S274) The attack identification unit 20 stores the determination result of the campaign instance, that is, the value of campaign RESULT, in the result cache unit 100.
[0193] (Step S275) If the value of the campaign RESULT is True, the attack identifying unit 20 proceeds to step S265. Otherwise, the attack identifying unit 20 proceeds to step S240.
[0194] (Step S276) The attack identification unit 20 acquires the result 22 by inquiring of the result cache unit 100 whether or not there is a determination result for the attacker group instance.
[0195] (Step S277) If the result 22 is empty, the attack identifying unit 20 proceeds to step S243. Otherwise, the attack identifying unit 20 proceeds to step S278.
[0196] (Step S278) The attack identification unit 20 assigns the result 22 to the variable “attacker group RESULT”.
[0197] (Step S279) The attack identification unit 20 stores the determination result of the attacker group instance, that is, the value of the attacker group RESULT, in the result cache unit 100.
[0198] (Step S280) If the value of the attacker group RESULT is True, the attack identifying unit 20 proceeds to step S265. Otherwise, the attack identifying unit 20 proceeds to step S246.
[0199] (Step S281) The attack identification unit 20 acquires the result 22 by inquiring of the result cache unit 100 whether or not there is a judgment result for the software instance.
[0200] (Step S282) If the result 22 is empty, the attack identifying unit 20 proceeds to step S249. Otherwise, the attack identifying unit 20 proceeds to step S283.
[0201] (Step S283) The attack identification unit 20 assigns the result 22 to the variable "software RESULT".
[0202] (Step S284) The attack identification unit 20 stores the determination result of the software instance, that is, the value of the software RESULT, in the result cache unit 100.
[0203] (Step S285) If the value of the software RESULT is True, the attack identifying unit 20 proceeds to step S265. Otherwise, the attack identifying unit 20 proceeds to step S252.
[0204] (Step S286) The attack identification unit 20 acquires the result 22 by inquiring of the result cache unit 100 whether or not there is a judgment result of the mitigation measure instance.
[0205] (Step S287) If the result 22 is empty, the attack identifying unit 20 proceeds to step S255. Otherwise, the attack identifying unit 20 proceeds to step S288.
[0206] (Step S288) The attack identification unit 20 assigns the result 22 to the variable “mitigation measure RESULT”.
[0207] (Step S289) The attack identification unit 20 stores the determination result of the mitigation measure instance, that is, the value of the mitigation measure RESULT, in the result cache unit 100.
[0208] (Step S290) If the value of the mitigation measure RESULT is False, the attack identifying unit 20 proceeds to step S265. Otherwise, the attack identifying unit 20 proceeds to step S258.
[0209] (Step S291) The attack identification unit 20 obtains the result 22 by inquiring of the result cache unit 100 whether or not there is a judgment result for the detection measure instance.
[0210] (Step S292) If the result 22 is empty, the attack identifying unit 20 proceeds to step S261. Otherwise, the attack identifying unit 20 proceeds to step S293.
[0211] (Step S293) The attack identification unit 20 assigns the result 22 to the variable “detection measure RESULT”.
[0212] (Step S294) The attack identification unit 20 stores the detection measure instance determination result, that is, the value of the detection measure RESULT, in the result cache unit 100.
[0213] (Step S295) If the value of the detection measure RESULT is False, the attack identifying unit 20 proceeds to step S265. Otherwise, the attack identifying unit 20 proceeds to step S264.
[0214] ***Explanation of the Effects of Second Embodiment*** As described above, according to this embodiment, by utilizing the determination result for a single condition that has already been determined in the past, the determination of the conditions for establishing an attack can be performed more quickly.
[0215] Third Embodiment Hereinafter, differences from the above-described embodiments will be mainly described with reference to the drawings.
[0216] *** Description of Configuration *** Fig. 34 shows an example configuration of an attack visualization system 99 according to this embodiment. Compared to embodiment 1, the attack visualization device 1 according to this embodiment further includes a result cache unit 110.
[0217] The result cache unit 110 stores the results of past judgments regarding a series of attack techniques that have been used to determine whether an attack is successful. The result cache unit 110 is also called a second result cache unit. The second result cache unit stores data indicating the analysis results regarding whether a transition between attack techniques is possible for each element.
[0218] The attack scenario generation unit 50 according to this embodiment utilizes the result cache unit 110 when identifying reachable attack techniques, thereby omitting the determination of a series of attack techniques for which the conditions for attack success have been determined in the past. Specifically, the attack scenario generation unit 50 analyzes whether transitions between attack techniques are possible for each element, and analyzes whether transitions between elements are possible based on the results of the analysis of whether transitions between attack techniques are possible for each element. Furthermore, the attack scenario generation unit 50 utilizes the data stored in the result cache unit 110 when analyzing whether transitions between attack techniques are possible.
[0219] FIG. 35 is a diagram illustrating an example of the processing of the attack scenario generation unit 50. In this example, the attack scenario generation unit 50 identifies attack methods reachable from each starting point in the order of "starting point 1" and "starting point 2." Assume that "A, B, C, D, E, F" are identified, in this order, as attack methods reachable from starting point 1. Assume that "G, H, C, D, E, F" are identified, in this order, as attack methods reachable from starting point 2. Each alphabet represents an attack method. Here, "C, D, E, F" are determined to be reachable from starting point 1. Therefore, the result cache unit 110 stores data indicating "C, D, E, F" as a series of reachable attack methods. Therefore, when identifying attack methods reachable from starting point 2, if the attack scenario generation unit 50 determines that C is reachable from H, it determines that "C, D, E, F" are reachable by utilizing the result cache unit 110.
[0220] ***Explanation of Operation*** The following mainly explains the differences from the first embodiment regarding the operation of the attack visualization system 99.
[0221] (Step S108) The attack scenario generation unit 50 executes the same process as step S108 according to embodiment 1. However, in determining whether a transition is possible, the attack scenario generation unit 50 queries the result cache unit 110 using the element graph 41 as input in order to omit the determination for a series of attack techniques for which the conditions for attack success have been determined in the past. The attack scenario generation unit 50 regards the result 52, which is the result of the query, as the result of determining whether a transition is possible for the series of attack techniques.
[0222] 36 shows an example of the operation of the result cache unit 110. This operation will be explained using FIG.
[0223] (Step S301) The result cache unit 110 receives an input of the element graph 41.
[0224] (Step S302) The result cache unit 110 calculates a set of attack methods required for transitions between elements as T(={a t1 , ..., a tn}).
[0225] (Step S303) The result cache unit 110 selects an element that serves as a starting point from the element graph 41, and assigns the selected element to the variable a.
[0226] (Step S304) The result cache unit 110 sets the variable A indicating the search history to an empty set.
[0227] (Step S305) The result cache unit 110 assigns False to the result 52.
[0228] (Step S306) The result cache unit 110 sets A to the union of A and a.
[0229] (Step S307) If the value of H(a) exists, the result cache unit 110 proceeds to step S308. Otherwise, the result cache unit 110 proceeds to step S309.
[0230] (Step S308) The result cache unit 110 substitutes H(a) into the result 52 and outputs the result 52.
[0231] (Step S309) If a is an element of T, the result cache unit 110 proceeds to step S310. Otherwise, the result cache unit 110 proceeds to step S311.
[0232] (Step S310) The result cache unit 110 assigns True to the result 52.
[0233] (Step S311) The result cache unit 110 selects an element that will be the next tactic after a from the element graph 41, and assigns the selected element to the variable a. Here, multiple elements may be selected.
[0234] (Step S312) If a exists, the result cache unit 110 proceeds to step S306. Otherwise, the result cache unit 110 proceeds to step S313.
[0235] (Step S313) The result cache unit 110 assigns the result 52 to H(a) for any a included in A.
[0236] (Step S314) The result cache unit 110 outputs the result 52.
[0237] 37 is a flowchart showing an example of the operation of the attack scenario generator 50 according to this embodiment. The following mainly explains the differences between the operation of the attack scenario generator 50 and embodiment 1.
[0238] (Step S531) The attack scenario generation unit 50 obtains the result 52 by making an inquiry to the result cache unit 110 using the element graph 41 as an input.
[0239] (Step S532) If the value of the result 52 is True, the attack scenario generation unit 50 transitions to step S510. Otherwise, the attack scenario generation unit 50 transitions to step S509.
[0240] ***Explanation of Effect of Third Embodiment*** As described above, according to this embodiment, by utilizing past judgment results regarding reachable attack techniques, usable attack techniques can be identified more quickly. Furthermore, according to this embodiment, when there is a bottleneck structure such as that shown in Fig. 38, the speed-up effect of omitting judgment is further enhanced.
[0241] Fourth Embodiment Hereinafter, differences from the above-described embodiments will be mainly described with reference to the drawings.
[0242] *** Description of Configuration *** Fig. 39 shows an example configuration of an attack visualization system 99 according to this embodiment. Compared to embodiment 1, the attack visualization device 1 according to this embodiment further includes a result cache unit 120.
[0243] The attack scenario generation unit 50 according to this embodiment appropriately omits the determination of whether a transition between elements is possible by utilizing the result cache unit 120. Specifically, the attack scenario generation unit 50 utilizes the data stored in the result cache unit 120 when analyzing whether a transition between elements is possible.
[0244] The result cache unit 120 caches the determination results regarding the transition possibilities between each element that were previously determined in the attack scenario generation process. In addition, when the result cache unit 120 caches the determination results regarding the transition possibilities between each element, it immediately returns the determination results regarding the transition possibilities between each element. The result cache unit 120 is also called a third result cache unit. The third result cache unit stores data indicating a series of transition possibilities identified when analyzing the transition possibilities between elements.
[0245] FIG. 40 is a diagram illustrating an example of the processing of the attack scenario generation unit 50 and the result cache unit 120. In this example, element 1 is the starting point and element 5 is the end point. Furthermore, the lines connecting the elements indicate that there is a connection relationship between the elements. Therefore, there are three total paths: path 1 that follows the order of "1 → 2 → 3 → 5", path 2 that follows the order of "1 → 2 → 4 → 5", path 3 that follows the order of "1 → 6 → 2 → 3 → 5", and path 4 that follows the order of "1 → 6 → 2 → 4 → 5". Here, each number indicates each element. Below, we will explain the processing of determining whether or not a transition is possible for each path in order. First, the result cache unit 120 calculates the undetermined element set of path n as Y n (⊂ / D), and the set of judged elements is D (the initial value of D is φ). Here, "⊂ / " means that there is no inclusion relationship. The attack scenario generation unit 50 calculates Y n Next, the attack scenario generation unit 50 determines whether or not each element of the path 1 can be transitioned. 1 = {1, 2, 3, 5}. Since D is an empty set, Y 1 There is no cache hit for any element of D. The result cache unit 120 converts D into D∪Y 1 (={1, 2, 3, 5}). Next, the attack scenario generation unit 50 determines whether or not a transition is possible for each element of the path 2. Here, since {1, 2, 5} is a cache hit, Y 2 = {4} (⊂ / {1, 2, 3, 5} (= D)). The result cache unit 120 converts D into D∪Y 2 (={1, 2, 3, 4, 5}). Next, the attack scenario generation unit 50 determines whether or not a transition is possible for each element of the path 3. Here, since {1, 2, 3, 5} is a cache hit, Y 3 = {6} (⊂ / {1, 2, 3, 4, 5}). The result cache unit 120 converts D into D∪Y 3 (={1, 2, 3, 4, 5, 6}). Next, the attack scenario generation unit 50 determines whether or not a transition is possible for each element of the path 4. Here, since {1, 2, 4, 5, 6} is a cache hit, Y 4 =φ.
[0246] ***Explanation of Operation*** The following mainly explains the differences from the first embodiment regarding the operation of the attack visualization system 99.
[0247] (Step S108) The attack scenario generation unit 50 executes the same processing as step S108 in embodiment 1. However, in determining whether a transition is possible, the attack scenario generation unit 50 queries the result cache unit 120 using the path 53 and the element graph 41 as input to omit determining whether a transition between elements has been previously determined to be possible. The attack scenario generation unit 50 regards the result 54, which is the result of the query, as the result of determining whether a transition is possible.
[0248] 41 shows an example of the operation of the result cache unit 120. This operation will be explained using FIG.
[0249] (Step S401) The result cache unit 120 receives an input of the path 53.
[0250] (Step S402) The result cache unit 120 receives an input of the element graph 41.
[0251] (Step S403) The result cache unit 120 assigns the set of elements for which transition possibility has been determined to a variable D. Here, the initial value of the set is an empty set.
[0252] (Step S404) The result cache unit 120 assigns a set of elements of the path 53 for which transition possibility has not yet been determined to a variable Y. Here, Y is not a subset of D.
[0253] (Step S405) The result cache unit 120 assigns the set of elements of path 53 for which transition possibility has been determined to Y-. Here, Y- is a subset of D. Note that due to restrictions on the characters that can be written, different notations may be used between the drawings and the main text of the specification. "Y-" is the same as the character Y with a "-" added above it.
[0254] (Step S406) The result cache unit 120 caches whether or not a transition is possible (True / False) for the element e as H(e).
[0255] (Step S407) The result cache unit 120 assigns True to the result 54.
[0256] (Step S408) If H(y-) is False for any element y- of Y-, the result cache unit 120 proceeds to step S409. Otherwise, the result cache unit 120 proceeds to step S410.
[0257] (Step S409) The result cache unit 120 assigns False to the result 54.
[0258] (Step S410) The result cache unit 120 selects an arbitrary element y of Y.
[0259] (Step S411) The result cache unit 120 selects an element graph 41 corresponding to the element y, and assigns the selected element graph 41 to the variable "element graph".
[0260] (Step S412) The result cache unit 120 sets D to the union of D and y.
[0261] (Step S413) If the "element graph" does not contain a path to the attack technique required for the transition, the result cache unit 120 transitions to step S414. Otherwise, the result cache unit 120 transitions to step S416.
[0262] (Step S414) The result cache unit 120 assigns False to the result 54.
[0263] (Step S415) The result cache unit 120 assigns False to H(y).
[0264] (Step S416) The result cache unit 120 assigns True to H(y).
[0265] (Step S417) If all elements of Y have been processed, the result cache unit 120 proceeds to step S418. Otherwise, the result cache unit 120 proceeds to step S410.
[0266] (Step S418) The result cache unit 120 outputs the result 54.
[0267] 42 is a flowchart showing an example of the operation of the attack scenario generator 50 according to this embodiment. The following mainly explains the differences between the operation of the attack scenario generator 50 and embodiment 1.
[0268] (Step S541) The attack scenario generation unit 50 obtains the result 54 by querying the result cache unit 120 using the path 53 and the element graph 41 as input.
[0269] (Step S542) If the result 54 is True, the attack scenario generation unit 50 proceeds to step S513. Otherwise, the attack scenario generation unit 50 proceeds to step S514.
[0270] ***Explanation of the Effects of the Fourth Embodiment*** As described above, according to this embodiment, since each element between which a transition possibility has been determined in the past is recorded, attack scenarios can be generated more quickly. Also, according to this embodiment, the more overlapping elements there are between multiple routes, the higher the possibility of a cache hit, and therefore attack scenarios can be generated more quickly.
[0271] Fifth Embodiment Hereinafter, differences from the above-described embodiments will be mainly described with reference to the drawings.
[0272] *** Description of Configuration *** Fig. 43 shows an example configuration of an attack visualization system 99 according to this embodiment. Compared to embodiment 1, the attack visualization device 1 according to this embodiment further includes a transition possibility determination unit 130.
[0273] The transition feasibility determination unit 130 treats elements of the system configuration elements that have the same conditions as elements of the same class. In other words, in this embodiment, multiple element classes are effectively aggregated as appropriate. That is, multiple elements are divided into multiple groups without overlap based on at least one of the environmental information 11, the attack method, and the attack success conditions, and each group corresponds to one class. The transition feasibility determination unit 130 also stores data indicating the analysis results regarding the feasibility of transitions between classes. FIG. 44 is a diagram illustrating an example of the processing performed by the transition feasibility determination unit 130. In this example, the transition feasibility determination unit 130 classifies each element into one of three classes: a firewall (FW) class, a server class, and a PC class. The transition feasibility determination unit 130 uses the determination results regarding the feasibility of transitions between classes when determining whether a transition between elements is possible.
[0274] The attack scenario generation unit 50 according to this embodiment utilizes the judgment result of the transition possibility determination unit 130 when determining whether a transition between elements is possible. Specifically, the attack scenario generation unit 50 analyzes whether a transition between classes is possible when analyzing whether a transition between elements is possible. Furthermore, the attack scenario generation unit 50 utilizes the data stored in the transition possibility determination unit 130 when analyzing whether a transition between classes is possible.
[0275] ***Explanation of Operation*** The following mainly explains the differences from the first embodiment regarding the operation of the attack visualization system 99.
[0276] (Step S108) The attack scenario generation unit 50 executes the same processing as step S108 in the first embodiment. However, the attack scenario generation unit 50 receives the path 53 and the element graph 41 as input and queries the transition feasibility determination unit 130 as to whether a transition between elements is possible. The attack scenario generation unit 50 regards the query result 55 as the transition feasibility determination result. Here, in determining whether a transition is possible by the transition feasibility determination unit 130, the same element graph 41 is used to determine whether a transition is possible for multiple elements in the path that can be treated as elements of the same class. At this time, if the transition feasibility determination unit 130 has already determined whether a transition is possible for a certain element graph 41, it uses the cached transition feasibility determination result in determining whether a transition is possible for that certain element graph 41.
[0277] 45 is a flowchart showing an example of the operation of the transition possibility determination unit 130. This operation will be described using FIG.
[0278] (Step S551) The transition possibility determination unit 130 receives the path 53 as an input.
[0279] (Step S552) The transition possibility determining unit 130 receives the element graph 41 as input.
[0280] (Step S553) The transition possibility determining unit 130 sets the class of the element e to Class(e).
[0281] (Step S554) The transition possibility determining unit 130 sets the cache of transition possibility (True / False) for Class(e) to H(Class(e)).
[0282] (Step S555) The transition possibility determining unit 130 sets the transition possibility determined element class set as C. Here, the initial value of the set is an empty set, and for a certain H(Class(e)), Class(e) is an element of C.
[0283] (Step S556) The transition possibility determination unit 130 determines that a set consisting of elements of the path 53 is E. Here, e is an element of E.
[0284] (Step S557) The transition possibility determining unit 130 assigns True to the result 55.
[0285] (Step S558) The transition possibility determining unit 130 selects an element e from among the elements of E that has not yet been selected.
[0286] (Step S559) If the transition possibility determination unit 130 has already determined whether the transition is possible for any element Class(e) of C, the transition possibility determination unit 130 proceeds to step S560. Otherwise, the transition possibility determination unit 130 proceeds to step S562.
[0287] (Step S560) If H(Class(e)) is False, the transition permission determination unit 130 transitions to step S561. Otherwise, the transition permission determination unit 130 transitions to step S567.
[0288] (Step S561) The transition possibility determination unit 130 assigns False to the result 55.
[0289] (Step S562) The transition possibility determining unit 130 selects an element graph 41 corresponding to Class(e) and assigns the selected element graph 41 to the variable "element graph".
[0290] (Step S563) If a path to an attack technique required for the transition exists in the "element graph", the transition possibility determination unit 130 transitions to step S565. Otherwise, the transition possibility determination unit 130 transitions to step S564.
[0291] (Step S564) The transition possibility determination unit 130 assigns False to the result 55.
[0292] (Step S565) The transition possibility determining unit 130 assigns the result 55 to H(Class(e)).
[0293] (Step S566) If the result 55 is False, the transition possibility determination unit 130 proceeds to step S568. Otherwise, the transition possibility determination unit 130 proceeds to step S567.
[0294] (Step S567) If the process has been executed for all elements of E, the transition possibility determination unit 130 proceeds to step S568. Otherwise, the transition possibility determination unit 130 proceeds to step S558.
[0295] (Step S568 ) The transition possibility determination unit 130 outputs the result 55 .
[0296] 46 is a flowchart showing an example of the operation of the attack scenario generator 50. The following mainly explains the differences between the operation of the attack scenario generator 50 and the first embodiment.
[0297] (Step S571) The attack scenario generation unit 50 receives the path 53 and the element graph 41 as input and queries the transition possibility determination unit 130 to obtain the result 55.
[0298] (Step S572) If the result 55 is True, the attack scenario generation unit 50 transitions to step S513. Otherwise, the attack scenario generation unit 50 transitions to step S514.
[0299] ***Explanation of the Effects of the Fifth Embodiment*** As described above, according to this embodiment, the generation of attack scenarios is sped up because the determination result regarding whether or not a transition between classes is used in determining whether or not a transition between elements is possible. Furthermore, according to this embodiment, the more elements that can be treated as being in the same class, the more the condition determination process can be omitted.
[0300] ***Other Embodiments*** The above-described embodiments can be freely combined, or any of the components of each embodiment can be modified, or any of the components can be omitted from each embodiment. Furthermore, the embodiments are not limited to those shown in embodiments 1 to 5, and various modifications are possible as needed. The procedures described using flowcharts, etc., can be modified as appropriate.
[0301] Various aspects of the present disclosure are summarized below as appendices.
[0302] an attack visualization device comprising: an attack identification unit that generates an attack success determination graph, which is a graph showing attack success conditions for the target attack method based on each logical formula and each single condition associated with each logical formula, and determines whether the target attack method is successful using the attack success determination graph, and generates an element graph, which is a graph showing the attack methods available for the target element in order of tactics, the graph showing the environmental information and the attack success conditions corresponding to each attack method available for the target element; and an attack scenario generation unit that generates an attack scenario for the analysis target by analyzing whether transitions between elements are possible based on each of the generated element graphs, the configuration of the analysis target, a start element that is one of the plurality of elements, and an end element that is one of the plurality of elements.
[0303] (Supplementary Note 2) The attack visualization device according to Supplementary Note 1 further includes a visualization unit that generates a visualization graph for visualizing each generated element graph and a portion of the attack scenario graph corresponding to the attack scenario according to visualization conditions.
[0304] (Supplementary Note 3) The attack visualization device according to Supplementary Note 2, wherein the visualization unit generates, as the visualization graph, a graph that displays the attack techniques and the elements of the analysis target that are related to the attack techniques.
[0305] (Supplementary Note 4) The attack visualization device described in Supplementary Note 2 or 3, wherein the attack identification unit generates the attack success determination graph based on each element indicated in the attack database, and the visualization unit links graph elements that are elements of the visualization graph to external attack information that is information corresponding to the graph elements and corresponds to elements indicated in the attack database.
[0306] (Supplementary Note 5) The attack visualization device according to any one of Supplementary Notes 1 to 4, further comprising: a first result cache unit that stores data indicating a determination result regarding whether the target attack method is successful; and the attack identification unit utilizes the stored data when determining whether the target attack method is successful.
[0307] (Supplementary Note 6) The attack visualization device described in any one of Supplementary Notes 1 to 5, wherein the attack scenario generation unit analyzes whether or not a transition between attack methods is possible for each element, and analyzes whether or not a transition between elements is possible based on the results of the analysis of whether or not a transition between attack methods is possible for each element, and the attack visualization device further includes: a second result cache unit that stores data indicating the analysis results regarding whether or not a transition between attack methods is possible for each element, and the attack scenario generation unit utilizes the stored data when analyzing whether or not a transition between attack methods is possible.
[0308] (Supplementary Note 7) The attack visualization device further includes a third result cache unit that stores data indicating a series of elements that can be transitioned, which are identified when analyzing whether a transition between elements is possible; and the attack scenario generation unit utilizes the stored data when analyzing whether a transition between elements is possible. The attack visualization device described in any one of Supplementary Notes 1 to 6.
[0309] (Supplementary Note 8) When the multiple elements are divided into multiple groups without overlap based on at least one of the environmental information, the attack method, and the attack success conditions, and each group corresponds to one class, the attack scenario generation unit analyzes whether transitions between classes are possible when analyzing whether transitions between elements are possible, and the attack visualization device further includes a transition feasibility determination unit that stores data indicating the analysis results regarding whether transitions between classes are possible, and the attack scenario generation unit utilizes the stored data when analyzing whether transitions between classes are possible. An attack visualization device described in any one of Supplementary Notes 1 to 7.
[0310] 1 Attack visualization device, 10 Worker, 11 Environmental information, 12 Analysis target information, 13 Visualization conditions, 20 Attack identification unit, 21 Attack establishment conditions, 22 Results, 30 Attack database, 31 Attack information, 40 Element graph storage unit, 41 Element graph, 50 Attack scenario generation unit, 52 Results, 53 Paths, 54, 55 Results, 60 Attack scenario storage unit, 61 Attack scenario graph, 70 Visualization unit, 71 Visualization graph, 80 External website, 81 URL, 90 Screen, 91 Hyperlink, 99 Attack visualization system, 100, 110, 120 Result cache unit, 130 Transition possibility determination unit, 201 Processor, 202 Memory, 203 Auxiliary storage device, 204 Input / output IF, 205 Communication device, 208 Processing circuit, 209 Signal line.
Claims
1. An attack visualization device comprising: an attack identification unit that generates an element graph, which is a graph showing the environmental information and the attack conditions corresponding to each attack method that can be used on the target element, by determining whether the target attack method is viable using the attack success determination graph; and an attack scenario generation unit that generates an attack scenario for the analysis target by analyzing whether transitions between elements can be made based on each of the generated element graphs, the configuration of the analysis target, a start element that is one of the plurality of elements, and an end element that is one of the plurality of elements.
2. The attack visualization device according to claim 1, further comprising: a visualization unit that generates a visualization graph for visualizing each generated element graph and a portion of the attack scenario graph corresponding to the attack scenario in accordance with visualization conditions.
3. The attack visualization device according to claim 2, wherein the visualization unit generates a graph as the visualization graph, which displays the attack technique and the elements of the analysis target related to the attack technique.
4. The attack visualization device described in claim 2 or 3, wherein the attack identification unit generates the attack success determination graph based on each element indicated in the attack database, and the visualization unit links graph elements that are elements of the visualization graph to external attack information that is information corresponding to the graph elements and corresponds to elements indicated in the attack database.
5. The attack visualization device according to any one of claims 1 to 4, further comprising: a first result cache unit that stores data indicating the determination result regarding whether the target attack method is successful; and the attack identification unit utilizes the stored data when determining whether the target attack method is successful.
6. The attack visualization device described in any one of claims 1 to 5, wherein the attack scenario generation unit analyzes whether or not a transition between attack methods is possible for each element, and analyzes whether or not a transition between elements is possible based on the results of the analysis of whether or not a transition between attack methods is possible for each element, and the attack visualization device further comprises a second result cache unit that stores data indicating the analysis results regarding whether or not a transition between attack methods is possible for each element, and the attack scenario generation unit utilizes the stored data when analyzing whether or not a transition between attack methods is possible.
7. The attack visualization device according to any one of claims 1 to 6, further comprising: a third result cache unit that stores data indicating a series of elements that can be transitioned identified when analyzing whether a transition between elements is possible; and the attack scenario generation unit utilizes the stored data when analyzing whether a transition between elements is possible.
8. An attack visualization device according to any one of claims 1 to 7, wherein when the elements are divided into multiple groups without overlap based on at least one of the environmental information, the attack method, and the attack conditions, and each group corresponds to one class, the attack scenario generation unit analyzes whether transitions between classes are possible when analyzing whether transitions between elements are possible, and the attack visualization device further comprises a transition feasibility determination unit that stores data indicating the analysis results regarding whether transitions between classes are possible, and the attack scenario generation unit utilizes the stored data when analyzing whether transitions between classes are possible.
9. A method of attack visualization in which a computer sets each element of multiple elements that constitute an analysis target in scenario-based threat analysis related to cybersecurity as a target element, sets each of one or more attack methods for the target element as a target attack method, generates an attack success determination graph that is a graph showing the attack success conditions of the target attack method based on each logical formula and each single condition linked to each logical formula, the graph showing the relationship between environmental information that indicates the configuration of the target element and each single condition, identifies each attack method that can be used on the target element by determining whether the target attack method is successful using the attack success determination graph, and generates an element graph that is a graph showing each attack method that can be used on the target element in order of tactics, the graph showing the environmental information and the attack success conditions corresponding to each attack method that can be used on the target element, and generates an attack scenario for the analysis target by analyzing whether transitions between elements are possible based on each generated element graph, the configuration of the analysis target, a start element that is one of the multiple elements, and an end element that is one of the multiple elements.
10. An attack visualization program that causes a computer attack visualization device to execute the following steps: an attack identification process that generates an attack success determination graph, which is a graph showing the attack success conditions of the target attack method based on each logical formula and each single condition linked to each logical formula, and determines whether the target attack method is successful using the attack success determination graph, and generates an element graph, which is a graph showing the attack methods that can be used on the target element in order of tactics, and which is a graph showing the environmental information and the attack success conditions corresponding to each attack method that can be used on the target element; and an attack scenario generation process that generates an attack scenario for the analysis target by analyzing whether transitions between elements are possible based on each generated element graph, the configuration of the analysis target, a start element that is one of the multiple elements, and an end element that is one of the multiple elements.
Citation Information
Patent Citations
Risk assessment measure planning system and risk assessment measure planning method
JP2020166650A
Attack scenario risk evaluation device and method thereof
JP2021179777A
Cybersecurity management device, cybersecurity management method and cybersecurity management system
JP2022191649A
Inference device, inference method, and computer-readable recording medium
WO2021255859A1