Attack channel data management device
The attack channel data management device integrates attack channel, threat information, and log file management to identify and implement effective log files, addressing the challenge of managing IoT device security threats by linking these elements, thus enhancing security measures.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-05
- Publication Date
- 2026-03-12
AI Technical Summary
Existing technologies fail to effectively identify and manage log files that are crucial for mitigating threats through IoT device attack channels, as they do not provide a comprehensive method to link attack channels, threat information, and log files, making it difficult to take effective measures against potential security breaches.
An attack channel data management device that integrates an attack channel management unit, threat information management unit, and log file management unit, enabling the linking and management of attack channels, threat information, and log files, allowing for the identification of effective log files to counter potential threats.
Enables users to proactively identify and implement effective log files in IoT devices, enhancing security measures by linking attack channels with threat information and log files, thereby improving the device's resilience against cyber threats.
Smart Images

Figure JP2024031860_12032026_PF_FP_ABST
Abstract
Description
Attack Channel Data Management Device
[0001] The present disclosure relates to security technology for IoT devices.
[0002] In general, IoT (Internet of Things) devices, which are devices that can be connected to a communication network, are often connected to other devices to form a network system. Such IoT devices have many intrusion routes (hereinafter referred to as "attack channels") that attackers can use to gain unauthorized access via the network.
[0003] There are various threats that exploit the characteristics of these attack channels, and it is necessary to take measures to address these threats. One of the known effective measures is to acquire logs related to the attack channels. Patent Document 1 discloses a method for efficiently acquiring these logs according to the status of the system, and Patent Document 2 discloses a technology for identifying the extent of contamination by a threat from the contents of the logs.
[0004] JP 2016-170568 A International Publication No. 2020 / 183615
[0005] Patent Documents 1 and 2 do not disclose any technology that indicates which log files are effective against an attack channel, and therefore it is not possible to take effective measures against threats.
[0006] The present disclosure has been made to solve the above-mentioned problems, and aims to provide an attack channel data management device that can take effective measures corresponding to attack channels.
[0007] The attack channel data management device of the present disclosure includes an attack channel management unit that manages attack channels, which are intrusion routes available to attackers attempting unauthorized intrusion into target devices that can be connected to a communication network; a threat information management unit that manages threat information, which is information that links threats and vulnerabilities, which are factors that cause risks in information security; a log file management unit that manages log files that can be acquired by the target devices; and a data integration management unit that manages linked information that links the information stored in the attack channel management unit, the threat information management unit, and the log file management unit.
[0008] According to the attack channel data management device of the present disclosure, when developing new IoT devices, etc., the attack channel data management device 1 can be used to obtain estimated results of valid log files corresponding to the intrusion routes of threats implemented in the IoT devices, and users of the attack channel data management device 1 can take measures against threats based on the obtained estimated results.
[0009] 1 is a functional block diagram showing a configuration of an attack channel data management device according to a first embodiment of the present disclosure; FIG. 2 is a diagram showing an example of an attack channel table; FIG. 3 is a diagram showing an example of a threat information table; FIG. 4 is a diagram showing an example of a log file table; FIG. 5 is a diagram showing an example of linking attack channels and threat information; FIG. 6 is a diagram showing an example of linking threat information and log files; FIG. 7 is a diagram showing a hardware configuration for realizing the attack channel data management device according to the first embodiment of the present disclosure; FIG. 8 is a diagram showing a hardware configuration for realizing the attack channel data management device according to the first embodiment of the present disclosure;
[0010] <First Embodiment> <Device Configuration> Figure 1 is a functional block diagram showing the configuration of an attack channel data management device 1 according to a first embodiment of the present disclosure. As shown in Figure 1, the attack channel data management device 1 includes an attack channel management unit 3 that manages attack channels, a threat information management unit 4 that manages threat information, a log file management unit 5 that manages log files that can be acquired by IoT devices that are devices under development, and a data integration management unit 2 that integrates and manages the data of the attack channel management unit 3, the threat information management unit 4, and the log file management unit 5.
[0011] The attack channel data management device 1 is connected to an input / output interface IF via a communication network NW such as the Internet. When a user of the attack channel data management device 1 inputs a keyword such as the name of an attack channel via the communication network NW, the attack channel data management device 1 transmits log file information valid for the attack channel to the user via the communication network NW. The user then implements the acquired log file information in the development target device IT, such as an IoT device. Note that, while the input / output interface IF in FIG. 1 is connected to the attack channel data management device 1 via the communication network NW, this is not limited thereto, and the input / output interface IF may be directly connected to the attack channel data management device 1.
[0012] The attack channel management unit 3, threat information management unit 4, and log file management unit 5 each have an attack channel table 31, a threat information table 41, and a log file table 51. The data integration management unit 2 manages all information stored in each management unit and linked to each other.
[0013] As a specific example, a case will be shown in which a denial-of-service attack carried out via a Wi-Fi network leaves traces in an access log file. The Wi-Fi recorded in the attack channel table 31 of the attack channel management unit 3, the denial-of-service attack recorded in the threat information table 41 of the threat information management unit 4, and the access log file recorded in the log file table 51 of the log file management unit 5 are linked to each other and managed by the data integration management unit 2.
[0014] The information in each management unit is assigned a unique number, linked to each other, and stored in the data integration management unit 2. For example, if the number "1" is assigned to Wi-Fi, which is an attack channel, "5" to a denial-of-service attack, which is threat information, and "3" to an access log file, which is a log file, the data integration management unit 2 manages only linking information such as "1-5, 5-3." Therefore, the data integration management unit 2 can be realized with a simple configuration that includes a database that stores linking information and a system that reads the linking information from the database.
[0015] For example, when a specific name of an attack channel such as "Wi-Fi" is input as a keyword from the input / output interface IF via the communication network NW, the data integration management unit 2 queries the attack channel management unit 3 and the threat information management unit 4, which manage the keyword text, obtains a unique number associated with the input keyword, and extracts it from the associated information it manages based on the obtained number.
[0016] For example, if "Wi-Fi" is entered as a keyword, the data integration management unit 2 queries the attack channel management unit 3 to obtain the number "1" linked to "Wi-Fi," and extracts "1-5, 5-3" from the linking information it manages.
[0017] The attack channel data management device 1 can be constructed with a single or multiple databases. When a single database is used, the data integration management unit 2, attack channel management unit 3, threat information management unit 4, and log file management unit 5 all construct their respective tables in a common database, and the data integration management unit 2 is used as a parent table to form relationships with each table in the attack channel management unit 3, threat information management unit 4, and log file management unit 5.
[0018] When multiple databases are used, the data integration management unit 2, attack channel management unit 3, threat information management unit 4, and log file management unit 5 each build their own tables in separate databases. In this case, the database selected is a relational database that allows for relationships. This allows for the creation of an environment similar to that achieved with a single database. In other words, relationships can be established by building the database of the data integration management unit 2 as a parent database and building the databases of the attack channel management unit 3, threat information management unit 4, and log file management unit 5 as child databases.
[0019] <Method for Confirming Threat Information> Hereinafter, a method for confirming threat information from attack channel information using the attack channel data management device 1 will be described in more detail.
[0020] First, each management unit constituting the attack channel data management device 1 and a method for using the attack channel data management device 1 will be described.
[0021] We will now explain each management unit that constitutes the attack channel data management device 1. The attack channel table 31 of the attack channel management unit 3 is a table that lists all attack channels.
[0022] An attack channel is a route for a threat to penetrate the device, and includes both physical and logical channels, as well as side channels. Physical channels are channels physically implemented in devices, including USB ports, LAN cable ports, and SD card slots. Logical channels are channels that distinguish transmission information by purpose, including TCP (Transmission Control Protocol), HTTP (Hyper Text Transfer Protocol), and FTP (File Transfer Protocol). Side channels are a general term for channels that can be observed from outside the device, and include thermal information and electromagnetic wave information emitted by the device.
[0023] FIG. 2 shows an example of the attack channel table 31, which includes information such as an entry number, attack channel, formal name, and description. The entry number is a unique number assigned to each attack channel. In the example of FIG. 2, "1" is assigned to "VLAN." The formal name is "Virtual Local Area Network," and it is described as "technology for creating virtual LAN segments."
[0024] The item numbered "2" is "VoIP," whose official name is "Voice over Internet Protocol," and which is described as "a technology that allows voice communication using data lines such as the Internet."
[0025] The item numbered "3" is "MQTT," whose official name is "Message Queuing Telemetry Transport," and which is described as a "data delivery protocol."
[0026] The threat information table 41 in the threat information management unit 4 is a table that lists all types of threat information.
[0027] A threat is a factor that creates a risk in information security, such as theft or unauthorized use of information, and threat information is information that links that threat with a vulnerability. A vulnerability is a cybersecurity flaw that occurs in a computer's operating system (OS) or software due to a program malfunction or design error, and is assigned a unique score called a Common Weakness Enumeration (CWE), which is a common vulnerability identifier.
[0028] FIG. 3 is a diagram showing an example of a threat information table 41, which includes information such as item numbers, threat information, and CWE scores. The item numbers are unique numbers assigned to each piece of threat information. In the example of FIG. 3, "cross-site scripting" is assigned a "1," and the CWE score is "79." "Cross-site scripting" is an attack carried out by a malicious third party by planting scripts on websites and web apps with the aim of exploiting personal information and information assets.
[0029] The item numbered "2" is "Cross-site request forgery," and its CWE score is "352." "Cross-site request forgery" is an attack in which a malicious third party eavesdrops on the session of a user who has successfully logged in to a website, spoofs the user, and sends a fraudulent request.
[0030] The item numbered "3" is a "DDoS attack," with a CWE score of "119." A "DDoS (Distributed Denial of Service) attack" is an attack in which multiple devices send a large number of packets to the target server or site, placing a huge load on the target and causing difficulty in accessing the service or causing it to stop.
[0031] The log file table 51 of the log file management unit 5 is a table that lists all log files that can be implemented in the device under development.
[0032] A log file is a data file that stores information such as events that have occurred and operation history in a chronological order, and is stored on a storage device. Log files are output by operating systems and security software, and include system files, firewall access files, and network log files.
[0033] FIG. 4 shows an example of the log file table 51, which includes information on the item number and the name of the log file for which a trail is left. The item number is a unique number assigned to each log file. In the example of FIG. 4, the log file " / var / log / syslog" is assigned the number "1." The log file " / var / log / messages" is assigned the number "2," and the log file " / var / log / secure" is assigned the number "3."
[0034] <Linking of Each Data> The data integration management unit 2 manages linking information of data in each table of the attack channel management unit 3, the threat information management unit 4, and the log file management unit 5 described above.
[0035] The linking is based on the results of a preliminary investigation, which is explained below.
[0036] First, the attack channel is linked to the threat information. Threat information is collected based on the NVD (National Vulnerability Database) published by the National Institute of Standards and Technology. The attack channel is identified for each piece of collected threat information, and linking is performed based on that information. Using the NVD makes it possible to investigate more detailed and accurate threat information.
[0037] As a specific example, in the case of a threat of infiltrating malware via a USB memory, the intrusion route is USB, and therefore the attack channel is USB.
[0038] An example of linking attack channels and threat information will be explained using Fig. 5 based on the attack channel table 31 shown in Fig. 2 and the threat information table 41 shown in Fig. 3. In Fig. 5, the top column shows attack channel item numbers 1 to 3, the leftmost column shows threat information item numbers 1 to 3, and a circle indicates which threat information is linked to each attack channel.
[0039] For example, the attack channel with item number 1, i.e., "VLAN" in Figure 2, is linked to the threat information with items numbers 1 and 3 in Figure 3, "Cross-site scripting" and "DDoS attack." Furthermore, the attack channel with item number 2, i.e., "VoIP" in Figure 2, is not linked to any threat information. Furthermore, the attack channel with item number 3, i.e., "MQTT" in Figure 2, is linked to the threat information with item number 2, "Cross-site request forgery."
[0040] Next, the threat information is linked to the log files. The damage caused by the threat information and the target OS and software are identified, and the log files are identified and linked based on the impact of the damage. Linking threat information to log files is done by investigating examples of damage caused by the threats indicated in the threat information. This method, commonly known as forensics, involves investigating the inside of devices such as PCs that have been affected by threats and investigating traces left by the threat. This information is published by the manufacturers of the affected devices or security researchers, and linking is done based on this information. This allows for accurate linking. Linking can also be done using MiterATT&CK (Adversarial Tactics, Techniques, and Common Knowledge), a tool that documents attacker behavior and uses it for defense, and information from the security analysis guide published by the Information Technology Promotion Agency, Japan (IPA).
[0041] An example of linking threat information and log files will be described with reference to Fig. 6, based on the threat information table 41 shown in Fig. 3 and the log file table 51 shown in Fig. 4. In Fig. 6, threat information item numbers 1 to 3 are shown in the top column, and log file item numbers 1 to 3 are shown in the leftmost column, with a circle indicating which log file is linked to each piece of threat information.
[0042] For example, the log file " / var / log / messages" of item 2 in Figure 4 is linked to the threat information of item 1, i.e., "cross-site scripting" in Figure 3. Also, the log file " / var / log / messages" of item 2 in Figure 4 is linked to the threat information of item 2, i.e., "cross-site request forgery" in Figure 3. Also, the log files " / var / log / syslog" and " / var / log / secure" of items 1 and 3 in Figure 4 are linked to the threat information of item 3, i.e., "DDoS attack" in Figure 3.
[0043] The data integration management unit 2 manages the above-mentioned linking information as a table in a database, thereby centrally managing the information of each management unit.
[0044] <How to Use the Attack Channel Data Management Device> Next, we will explain how to use the attack channel data management device 1. The assumed users are new developers of IoT devices and new software developers. The user first extracts attack channels for the device being developed during development. Next, the user inputs the extracted attack channels from the input / output interface IF (Figure 1) via the communication network NW into the attack channel data management device 1. The data integration management unit 2 of the attack channel data management device 1 uses the input attack channels as keywords and outputs all threat information associated with them.
[0045] When the user selects the threat information for which they wish to take measures from the output threat information, the data integration management unit 2 of the attack channel data management device 1 outputs all log files linked to the selected threat information. Based on the results, the user can identify the log files that require measures and incorporate them into the design of the IoT device to be developed so that the log files can be acquired as measures against the threat information.
[0046] In the case of software development, the software to be developed should be designed to output logs equivalent to the required log files. This will enable the acquisition of a log file that is effective against an attack when the software is attacked by the same threat as the selected threat information.
[0047] The input / output interface IF (FIG. 1) is equipped with a display device, a keyboard, etc. (not shown). The display device displays a management application image, etc., which displays a field for inputting attack channels, a threat information display field for displaying and selecting threat information, and a log file display field for displaying log files. These fields are display areas on the screen where a user of the attack channel data management device 1 inputs attack channels, selects threat information, and obtains log files.
[0048] <Inputting an attack channel> When an attack channel is entered in the attack channel input field of this management application image, the attack channel data management device 1 inputs the entered attack channel to the data integration management unit 2. The data integration management unit 2 instructs the attack channel management unit 3 to compare the entered attack channel with the data held by the attack channel management unit 3. If the result of the comparison shows that the entered attack channel exists in the attack channel table 31 held by the attack channel management unit 3, the threat information linked to that data is extracted from the threat information management unit 4 and displayed in the threat information display field. On the other hand, if the result of the comparison shows that the entered attack channel does not exist in the attack channel table 31 held by the attack channel management unit 3, a message indicating that the attack channel does not exist is displayed in the threat information display field.
[0049] Two specific examples are given below. The first is a case where "USB" is input as an attack channel to the attack channel data management device 1. When "USB" is input as an attack channel, the data integration management unit 2 instructs the attack channel management unit 3 to compare "USB" with the data held by the attack channel management unit 3.
[0050] If the result of the comparison is that the input "USB" exists in the attack channel table 31 held by the attack channel management unit 3, the threat information linked to that data is extracted from the threat information management unit 4.
[0051] If "malware attack" and "privilege escalation attack by hacking" exist in the threat information table 41 held by the threat information management unit 4 as threat information linked to "USB," then "malware attack" and "privilege escalation attack by hacking" will be displayed in the threat information display field as a result. A "privilege escalation attack" is an attack in which a malicious third party illegally obtains authority and performs an operation that cannot be performed without that authority.
[0052] The second example is when "LAN" is input as an attack channel to the attack channel data management device 1. When "LAN" is input as an attack channel, the data integration management unit 2 instructs the attack channel management unit 3 to compare "LAN" with the data held by the attack channel management unit 3.
[0053] If the result of the comparison is that the input "LAN" exists in the attack channel table 31 held by the attack channel management unit 3, the threat information linked to that data is extracted from the threat information management unit 4.
[0054] If "cross-site scripting" and "cross-site request forgery" exist in the threat information table 41 held by the threat information management unit 4 as threat information linked to "LAN," then "cross-site scripting" and "cross-site request forgery" will be displayed in the threat information display field as a result.
[0055] <Method for checking valid log files> Next, a method for checking valid log files from attack channel information will be described. The attack channel data management device 1 displays threat information in the threat information display field and waits for the user to input threat information selected from the displayed threat information.
[0056] The system then acquires the selected threat information entered by the user. By selecting one piece of threat information that requires countermeasures, the user can acquire log file information that is effective for countermeasures, which will be described later.
[0057] When threat information is selected, the data integration management unit 2 of the attack channel data management device 1 uses the linking information it manages to extract the log file information linked to the threat information from the log file table 51 of the log file management unit 5 and displays it in the log file display field.
[0058] By selecting and entering one piece of threat information that requires countermeasures, the user can obtain log file information that is effective for countermeasures. This allows the user to check the displayed log file information and apply it to the design content of the IoT device so that a log file can be obtained as a countermeasure for the selected threat information. Note that if there are multiple pieces of threat information that require countermeasures, the user can select the threat information again to check the log file required for countermeasures for that threat.
[0059] Two specific examples are given below. The first example is when "USB" is input as the attack channel into the attack channel data management device 1, and "malware attack" and "privilege escalation attack by hacking" are displayed in the threat information display field.
[0060] The user selects "malware attack" as an attack that poses a threat to the device under development. The data integration management unit 2 of the attack channel data management device 1 uses the linking information it manages to extract "system files" and "network log files," which are log files that contain evidence of the "malware attack," from the log file table 51 of the log file management unit 5 as log file information linked to the "malware attack," and displays it in the log file display field.
[0061] The user applies it to the design content of the IoT device so that the "System file" and "Network log file" can be acquired.
[0062] The second case is when "LAN" is input as the attack channel into the attack channel data management device 1, and "Cross-site scripting" and "Cross-site request forgery" are displayed in the threat information display field.
[0063] The user selects "cross-site scripting" as an attack that poses a threat to the device under development. The data integration management unit 2 of the attack channel data management device 1 uses the linking information it manages to extract the "browsing application log file" and "firewall access log file," which are log files that contain evidence of "cross-site scripting," from the log file table 51 of the log file management unit 5 as log file information linked to "cross-site scripting," and displays them in the log file display field.
[0064] The user applies this to the design of the IoT device so that the "browsing application log file" and "firewall access log file" can be obtained.
[0065] A "browsing application log file" is a log file in which the application itself records the operation status of an application that uses a browser to view a homepage. A "firewall access log file" is a log file that records the operation of a server when accessing a firewall.
[0066] <Database Update> The attack channels, threat information, and log files contained in the attack channel data management device 1 are expected to be updated daily due to advances in technology and hacking skills. Each management unit constituting the attack channel data management device 1 includes a database, making it easy to add information. Information linking attack channels, threat information, and log files is also managed in the database of the data integration management unit 2, making it easy to add information linking each piece of information. Therefore, when new information about attack channels, threat information, and log files is released, the administrator of the attack channel data management device 1 can easily update the attack channel data management device 1, ensuring that users can always receive the latest information.
[0067] A specific example will be given below. When a new attack channel appears that is not stored in the attack channel table 31 of the attack channel management unit 3, the data updater registers the new attack channel in the attack channel management unit 3 using the functions of the attack channel table 31. Next, the updater investigates and acquires threat information linked to the attack channel, for example, based on the NVD, and registers information linking the attack channel with the acquired threat information in the data integration management unit 2. Because information linking threat information with log files is managed in advance in the data integration management unit 2, the new attack channel can be linked with the threat information and log files.
[0068] <Effects> When developing new IoT devices, etc., the attack channel data management device 1 can be used to obtain the estimation results of valid log files corresponding to the intrusion routes of threats implemented in the IoT devices, and the user of the attack channel data management device 1 can take measures against threats based on the obtained estimation results. This is extremely effective for designing IoT devices that have limited available memory and require pinpoint log file acquisition.
[0069] Furthermore, since the attack channel data management device 1 is configured as a database, it is easy to add and update information, and it is possible to respond quickly when new threat information emerges.
[0070] <Hardware Configuration> Each component of the attack channel data management device 1 of the first embodiment described above can be configured using a computer and is realized by the computer executing a program. That is, the attack channel data management device 1 is realized, for example, by a processing circuit 500 shown in Figure 7. The processing circuit 500 is equipped with a processor such as a CPU (Central Processing Unit) or a DSP (Digital Signal Processor), and the functions of each part are realized by executing a program stored in a storage device.
[0071] Dedicated hardware may be applied to the processing circuit 500. When the processing circuit 500 is dedicated hardware, the processing circuit 500 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a combination thereof.
[0072] The attack channel data management device 1 may have the functions of each of its components realized by separate processing circuits, or may have those functions realized together by a single processing circuit.
[0073] FIG. 8 also shows a hardware configuration in the case where the processing circuit 500 is configured using a processor. In this case, the functions of each part of the attack channel data management device 1 are realized by a combination of software, etc. (software, firmware, or software and firmware). The software, etc. is written as a program and stored in the memory 520. The processor 510 functioning as the processing circuit 500 realizes the functions of each part by reading and executing the program stored in the memory 520 (storage device). In other words, this program can be said to cause a computer to execute the procedures and methods of operation of the components of the attack channel data management device 1.
[0074] Here, the memory 520 may be, for example, a non-volatile or volatile semiconductor memory such as RAM, ROM, flash memory, EPROM (Erasable Programmable Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), HDD (Hard Disk Drive), magnetic disk, flexible disk, optical disk, compact disk, mini disk, DVD (Digital Versatile Disc) and its drive device, or any storage medium to be used in the future. The attack channel table 31, threat information table 41, and log file table 51 possessed by the attack channel data management device 1 can be constructed using the memory 520, or can be constructed using a storage device different from the memory 520.
[0075] The above describes a configuration in which the functions of each component of the attack channel data management device 1 are realized by either hardware or software, etc. However, this is not limited to this, and the configuration may be such that some components of the attack channel data management device 1 are realized by dedicated hardware and other components are realized by software, etc. For example, the functions of some components can be realized by the processing circuit 500 as dedicated hardware, and the functions of other components can be realized by the processing circuit 500 as the processor 510 reading and executing a program stored in the memory 520.
[0076] As described above, the attack channel data management device 1 can realize each of the above-mentioned functions by hardware, software, etc., or a combination of these.
[0077] Although the present disclosure has been described in detail, the above description is illustrative in all respects and does not limit the disclosure thereto. It is understood that countless variations not illustrated can be envisioned without departing from the scope of the present disclosure.
[0078] It should be noted that, within the scope of the present disclosure, the embodiments can be freely combined, modified, or omitted as appropriate.
Claims
1. An attack channel data management device comprising: an attack channel management unit that manages attack channels, which are intrusion routes that attackers attempting to illegally intrude into target devices that can be connected to a communication network; a threat information management unit that manages threat information, which is information that links threats and vulnerabilities that are factors that cause risks in information security; a log file management unit that manages log files that can be acquired by the target devices; and a data integration management unit that manages linked information that links together the information stored in the attack channel management unit, the threat information management unit, and the log file management unit.
2. The attack channel data management device of claim 1, wherein the attack channel management unit, the threat information management unit, and the log file management unit respectively have an attack channel table, a threat information table, and a log file table, the attack channel table being a table that lists a plurality of attack channels, the threat information table being a table that lists a plurality of pieces of threat information, and the log file table being a table that lists a plurality of log files that can be implemented in the target device, the data integration management unit using the attack channel entered by a user as a keyword to output the threat information associated with it, and when the user selects the outputted threat information, the data integration management unit outputs the log file associated with the selected threat information.
3. An attack channel data management device as described in claim 2, wherein: the multiple attack channels included in the attack channel table are each assigned a unique number; the multiple threat information included in the threat information table are each assigned a unique number; the multiple log files included in the log file table are each assigned a unique number; and the data integration management unit manages the unique numbers assigned to the multiple attack channels, the unique numbers assigned to the multiple threat information, and the unique numbers assigned to the multiple log files as the linking information.
4. The attack channel data management device of claim 2, wherein the multiple pieces of threat information are collected based on the NVD (National Vulnerability Database), the attack channel is identified for each piece of collected threat information, and the attack channel and the threat information are linked based on that information, and the threat information and the log file are linked based on the results of an investigation of traces left by the threat by forensics that investigates cases of damage caused by threats.
Citation Information
Patent Citations
Detection rule output method and security system
WO2023021840A1