Attack path display control device, attack path display control method, and recording medium
The attack path display control device simplifies the presentation of cyberattack paths by aggregating components with shared attack characteristics, enabling easier understanding and prioritization of critical routes in information processing systems.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- NEC CORP
- Filing Date
- 2024-10-15
- Publication Date
- 2026-04-23
AI Technical Summary
Existing systems struggle to present complex attack routes of cyberattacks on information processing systems in an easily understandable manner, making it difficult for administrators to grasp the security issues effectively.
An attack path display control device and method that identifies and aggregates components in cyberattack paths based on common attack sources, targets, and contents, displaying them in a simplified diagram format, considering aggregation conditions and priority levels.
Simplifies the presentation of cyberattack paths, allowing administrators to understand main attack routes more easily and prioritize critical paths, thereby enhancing security assessment efficiency.
Smart Images

Figure JP2024036583_23042026_PF_FP_ABST
Abstract
Description
Attack Route Display Control Device, Attack Route Display Control Method, and Recording Medium
[0001] The present disclosure relates to an attack route display control device, an attack route display control method, and a recording medium, and particularly to an attack route display control device, an attack route display control method, and a recording medium.
[0002] In recent years, cyberattacks including unauthorized access to computer systems such as factories (manufacturing) and hospitals (medical) or malware infections have been rampant, causing great damage to highly informationized societies. In preparation for such cyberattacks, there is a demand for technology to support administrators so that they can efficiently perform risk assessments of information processing systems.
[0003] For example, the security diagnosis system described in Patent Document 1 detects an intrusion route unique to a system to be diagnosed based on the vulnerabilities of the system to be diagnosed, and performs a security diagnosis based on the detected intrusion route.
[0004] Specifically, the security diagnosis system described in Patent Document 1 explores an intrusion route (attack route) for the system to be diagnosed by combining points determined to be vulnerable in the system to be diagnosed. Then, the security diagnosis system displays an image representing the discovered intrusion route (attack route) on the configuration diagram of the system to be diagnosed.
[0005] Japanese Unexamined Patent Application Publication No. 2008 - 257577
[0006] The number of attack routes of cyberattacks on large-scale information processing systems in recent years is enormous. Therefore, even if complex attack routes extracted by analyzing an information processing system are presented to users such as administrators as they are, there is a problem that it is difficult for users (such as administrators) to grasp the problems in cyber security.
[0007] The present disclosure has been made in view of the above problems, and its purpose is to present the analysis results regarding the attack routes of cyberattacks on an information processing system in an easy-to-understand manner.
[0008] An attack path display control device according to one aspect of the present disclosure includes, based on information representing the configuration of an information processing system, identification means for each of a plurality of components in the middle of a plurality of attack paths of a cyberattack on the information processing system, identification means for an attack source that targets a component in a cyberattack, a first attack content that the attack source executes against the component, a target that the component targets in a cyberattack, and a second attack content that the component executes against the target; determination means for determining whether an aggregation condition is met among the plurality of components, such that at least one of the attack source and the first attack content is the same, and at least one of the target and the second attack content is the same; and display control means for aggregating and displaying the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths.
[0009] An attack path display control method according to one aspect of the present disclosure involves a computer, based on information representing the configuration of an information processing system, identifying for each of a plurality of components in the middle of a plurality of attack paths of a cyberattack on the information processing system, the source of the cyberattack that targets the component, the first attack that the source of the cyberattack executes against the component, the target of the cyberattack that the component targets, and the second attack that the component executes against the target. The computer then determines whether the aggregation conditions are met among the plurality of components, such that at least one of the source of the cyberattack and the first attack, and at least one of the target and the second attack, and aggregates and displays the plurality of components that satisfy the aggregation conditions in a diagram representing the plurality of attack paths.
[0010] A recording medium according to one aspect of the present disclosure stores a program for causing a computer to execute the following based on information representing the configuration of an information processing system: a process to identify, for each of a plurality of components located in the middle of a plurality of attack paths of a cyberattack on the information processing system, a source of attack that targets the component, a first attack that the source of attack executes against the component, a target that the component targets for the cyberattack, and a second attack that the component executes against the target; a process to determine whether, among the plurality of components, the aggregation condition is met such that at least one of the source of attack and the first attack, and at least one of the target and the second attack, is the same; and a process to aggregate and display the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths.
[0011] According to one aspect of this disclosure, the results of an analysis of attack paths in cyberattacks against information processing systems can be presented in an easily understandable manner.
[0012] This figure shows an example of an information analysis system equipped with an attack path display control device according to one embodiment. This is an example of a diagram showing multiple attack paths against an information processing system. This is a table showing an example of aggregation conditions. This figure shows a case in which multiple attack paths are aggregated under the aggregation conditions of one example. This figure shows another case in which multiple attack paths are aggregated under the aggregation conditions of one example. This figure shows yet another case in which multiple attack paths are aggregated under the aggregation conditions of one example. This figure shows a case in which multiple attack paths are not aggregated under the aggregation conditions of one example. This figure shows yet another case in which multiple attack paths are not aggregated under the aggregation conditions of one example. This is a block diagram showing the configuration of the attack path display control device according to one embodiment. This is a flowchart showing the operation of the attack path display control device according to one embodiment. This is a block diagram showing the configuration of the attack path display control device according to one embodiment. This is a flowchart showing the operation of the attack path display control device according to one embodiment. This figure shows an example of the hardware configuration of the attack path display control device according to one embodiment.
[0013] Embodiments of this disclosure will be described with reference to the drawings.
[0014] This disclosure aims to display, in a diagram representing multiple attack paths of a cyberattack on an information processing system, the components (nodes) that pass through between the entry point and the target when a cyberattack is carried out against the information processing system, by merging them as stepping stones, under aggregation conditions relating to the following items: • Attack source • Attack target • Attack content from the attack source to the intermediary nodes (first attack content) • Attack content from the intermediary nodes to the attack target (second attack content) • Presence or absence of countermeasures against cyberattacks • Attributes of the component (node) • Special attack content For example, if the content of the predetermined items is the same among multiple components, those components may be aggregated and displayed.
[0015] In the following explanation, "component" refers to a component (node) of an information processing system, such as a computer, server, VM (Virtual Machine), or NAS (Network Attached Storage). "Attack source" refers to the entity that carries out a cyberattack against a component of an information processing system, such as another component of the information processing system or an external information processing device. "Component type" refers to the name or category of the component determined according to its functions and performance.
[0016] "Target of attack" refers to the object that is subjected to a cyberattack from a component of an information processing system, such as another component of the information processing system or an external information processing device. "Attack content" refers to any attack method against an information processing system, such as unauthorized operation, unauthorized access, data tampering, data theft, malware infection, malfunction, or unauthorized operation using vulnerable protocols, by exploiting vulnerabilities in the components of the information processing system.
[0017] (Information Analysis System 1) Figure 1 shows an example of an information analysis system 1 equipped with attack path display control devices 10 and 20 (Figures 9 and 11) according to embodiments 1 and 2 described later.
[0018] As shown in Figure 1, the information analysis system 1 includes an attack path display control device 10 (20), a display device 100, and a recording device 200. In Figure 1, "attack path display control device 10 (20)" means "either the attack path display control device 10 or the attack path display control device 20."
[0019] The attack path display control device 10 (20), the display device 100, and the recording device 200 are connected to each other via wired or wireless means so that they can communicate with each other.
[0020] The display device 100 is equipped with a display. The display device 100 is, for example, a personal computer, a smartphone, or a tablet device. The screen of the display device 100 displays a diagram (Figure 2) that shows multiple attack paths, which will be described later.
[0021] As shown in Figure 1, the recording device 200 stores information processing system configuration information, aggregation conditions, and attribute information. The recording device 200 may also store limiting conditions (described in other embodiments) that restrict the aggregation conditions.
[0022] Information processing system configuration information is information that indicates the components of the information processing system (not shown) that is the subject of analysis.
[0023] The aggregation conditions indicate the conditions under which multiple components constituting the information processing system are aggregated and displayed as a single component in the diagram (Figure 2) representing multiple attack paths, which will be described later.
[0024] Attribute information represents the attributes of each component of an information processing system. The attributes of a component refer to its type and role.
[0025] The attack path display control device 10 (20) refers to the information processing system configuration information, aggregation conditions, and attribute information stored in the recording device 200 when creating a diagram representing multiple attack paths based on the information processing system configuration information. Note that attribute information is not mandatory. The recording device 200 may store only the information processing system configuration information and aggregation conditions.
[0026] (An example of a diagram representing multiple attack paths against an information processing system) Figure 2 shows an example of a diagram representing multiple attack paths in a cyberattack against an information processing system (hereinafter referred to as "a diagram representing multiple attack paths"). As shown in Figure 2, in a diagram representing multiple attack paths, the components that serve as entry points into the information processing system are connected by arrows via one or more components (nodes A to Y, firewall FW) to the components that are targeted by the cyberattack. The arrows represent the attack path and the destination of the attack. Different types of arrows correspond to different types of attacks.
[0027] Generally, several components are involved between the entry point and the target of a server attack on an information processing system. These components are sometimes referred to as "stepping stones." It should be noted that the components of an information processing system are not limited to servers and firewalls, but may also include various computers, IoT devices, electronic devices, and communication equipment.
[0028] (Example of aggregation conditions) Figure 3 shows an example of aggregation conditions for a diagram (Figure 2) representing multiple attack paths, where different components are aggregated and displayed as a single component.
[0029] One example of aggregation conditions is that, among multiple components constituting an information processing system, at least one of the attack source and the content of the first attack (the content of the cyberattack from the attack source to a specific component) are the same, and at least one of the attack target and the content of the second attack (the content of the cyberattack from the specific component to the attack target) are the same. However, the aggregation conditions are not limited to this example.
[0030] For example, if the source of a cyberattack on a first component of an information processing system is the same as the source of a cyberattack on a second component of the information processing system, and the target of the cyberattack on the first component is the same as the target of the cyberattack on the second component, then the aggregation condition in this example is satisfied between the first component and the second component.
[0031] In the following, we will explain whether the aggregation condition is met by giving several examples, specifically when the aggregation condition is "at least one of the attack source and the content of the first attack is the same between the first and second components (which constitute the information processing system), and at least one of the attack target and the content of the second attack is the same."
[0032] (Cases where the aggregation conditions are met and cases where they are not) Figure 3 is a table showing an example of the aggregation conditions. Here, we will explain the cases enclosed in boxes among the 16 cases shown in Figure 3. In Figure 3, solid lines indicate cases where the aggregation conditions of this example are met, and dashed lines indicate cases where the aggregation conditions of this example are not met.
[0033] Figures 4 to 6 show cases where the aggregation conditions described above are met. On the other hand, Figures 7 and 8 show cases where the aggregation conditions described above are not met.
[0034] For example, in Case 1 of the aggregation conditions shown in Figure 3, the "attack source" that carries out the cyberattack on the first component (bbb) and the "attack source" that carries out the cyberattack on the second component (ccc) are the same, and the "attack content" from that "attack source" to the first component (bbb) and the second component (ccc) are also the same.
[0035] Furthermore, in Case 1 of Figure 3, the "target" to which the first component (bbb) carries out a cyberattack is the same as the "target" to which the second component (ccc) carries out a cyberattack, and the "attack content" from the first component (bbb) and the second component (ccc) to that "target" is also the same (Figure 4).
[0036] Therefore, in Case 1 of Figure 3, the aggregation condition for this example is satisfied because "both the source of the attack and the content of the first attack are the same, and both the target of the attack and the content of the second attack are the same between the first component (bbb) and the second component (ccc)."
[0037] In another example, in Case 6 of Figure 3, the "attack source" that carries out the cyberattack on the first component (bbb) and the "attack source" that carries out the cyberattack on the second component (ccc) are the same, and the "target" that the first component (bbb) attacks and the "target" that the second component (ccc) attacks are the same.
[0038] On the other hand, the "first attack content" from the "source of the attack" to the first component (bbb) and the second component (ccc) is different, and the "second attack content" from the first component (bbb) and the second component (ccc) to their "target" is also different (Figure 5).
[0039] Therefore, in Case 6 of Figure 3, the aggregation condition for this example is met because "the source of the attack and the target of the attack are the same between the first component (bbb) and the second component (ccc)."
[0040] In yet another example, in Case 11 of Figure 3, the "attack source" that carries out the cyberattack on the first component (bbb) and the "attack source" that carries out the cyberattack on the second component (ccc) are different, but the "first attack content" from these "attack sources" to the first component (bbb) and the second component (ccc) is the same.
[0041] Furthermore, the "target" to which the first component (bbb) carries out a cyberattack is the same as the "target" to which the second component (ccc) carries out a cyberattack, and the "second attack content" from the first component (bbb) and the second component (ccc) to their respective "targets" is also the same (Figure 6).
[0042] Therefore, in Case 11 of Figure 3, the aggregation condition for this example is satisfied because "the content of the first attack is identical between the first component (bbb) and the second component (ccc), and both the target and the content of the second attack are identical."
[0043] In the above three cases, the aggregation condition of this example, namely, "at least one of the attacker and the first attack content is the same among a plurality of components (constituting the information processing system), and at least one of the attack target and the second attack content is the same", is satisfied. Therefore, as shown in FIGS. 4 to 6, in the diagram (FIG. 2) representing a plurality of attack paths, the first component (bbb) and the second component (ccc) are aggregated and displayed as a single component.
[0044] On the other hand, in Case 4 of FIG. 3, the "attack target" for executing a cyber-attack from the first component (bbb) is different from the "attack target" for executing a cyber-attack from the second component (ccc). Moreover, the "second attack content" from the first component (bbb) to the "attack target" is also different from the "second attack content" from the second component (ccc) to the "attack target" (FIG. 7).
[0045] Also, in Cases 13 to 16 of FIG. 3, the "attacker" for executing a cyber-attack on the first component (bbb) is different from the "attacker" for executing a cyber-attack on the second component (ccc). Moreover, the "first attack content" from those "attackers" to the first component (bbb) is also different from the "first attack content" to the second component (ccc) (FIG. 8).
[0046] In the above two cases, the aggregation condition, namely, "at least one of the attacker and the first attack content is the same among a plurality of components (constituting the information processing system), and at least one of the attack target and the second attack content is the same", is not satisfied. Therefore, in the diagram (FIG. 2) representing a plurality of attack paths, the first component and the second component are not aggregated and are displayed as separate components.
[0047] Regarding the other cases shown in FIG. 3, similar to the above examples, the meaning can be read from the table, so the description here is omitted.
[0048] In Embodiments 1 to 2 described later, the configurations and operations of the attack path display control devices 10 and 20 will be described respectively.
[0049] [Embodiment 1] An attack path display control device 10 according to Embodiment 1 of the present disclosure will be described with reference to Figures 9 to 10.
[0050] (Configuration of the attack path display control device 10) Figure 9 is a block diagram showing the configuration of the attack path display control device 10 according to this first embodiment. As shown in Figure 9, the attack path display control device 10 includes a specification unit 11, a determination unit 12, and a display control unit 13.
[0051] Based on information representing the configuration of the information processing system, the identification unit 11 identifies (1) to (4) below for each of the multiple components (hereinafter referred to as "the component") that are in the middle of multiple attack paths of a cyberattack against the information processing system.
[0052] (1) The source of the attack that targets the said component in a cyberattack
[0053] (2) The first attack that the attacker executes against the component
[0054] (3) The target of the cyberattack that the said component is intended for
[0055] (4) The second attack content identification unit 11 that the component performs against the target of the attack is an example of identification means.
[0056] For example, the identification unit 11 first identifies the attributes of the attack source and target of each of the multiple components that make up the information processing system. Here, attributes refer to the type and role of the component. The identification unit 11 also identifies the attack method for each of the multiple components that make up the information processing system as the content of the attack. Examples of "attack methods" here include unauthorized operation, unauthorized access, data falsification, data theft, malware infection, malfunction, and unauthorized operation using vulnerable protocols.
[0057] The identification unit 11 outputs to the determination unit 12 information indicating the source of the attack and the content of the first attack on each of the multiple components constituting the information processing system, and information indicating the target of the attack from that component and the content of the second attack.
[0058] The determination unit 12 determines whether the aggregation condition is met between any two components constituting the information processing system, such that at least one of the attack source and the first attack content is the same, and at least one of the attack target and the second attack content is the same. The determination unit 12 is an example of a determination means. Furthermore, the determination unit 12 may perform the above determination while considering constraint conditions that restrict the aggregation condition. The limiting conditions may be arbitrarily set by the user. Specific examples of limiting conditions will be described in the other embodiments described later.
[0059] For example, the determination unit 12 receives from the identification unit 11 information indicating the source of the attack and the content of the first attack on each of the multiple components constituting the information processing system, and information indicating the target of the attack from that component and the content of the second attack.
[0060] Furthermore, if, between any two components constituting the information processing system, either the attack source and the first attack content, or both, are identical, and either the attack target and the second attack content, or both, the determination unit 12 determines that the aggregation condition is met between these components. Examples of cases corresponding to this are cases 1 to 3 and cases 5 to 12 in Figure 3 described above.
[0061] On the other hand, if both the source of the attack and the content of the first attack differ between any two components, and / or both the target of the attack and the content of the second attack differ, the determination unit 12 determines that the aggregation condition is not met between these components. Examples of cases corresponding to this are Case 4 and Cases 13 to 16 in Figure 3 described above.
[0062] The determination unit 12 outputs a determination result to the display control unit 13 indicating whether or not the aggregation condition is met between any two components that constitute the information processing system.
[0063] The display control unit 13 aggregates and displays multiple components that satisfy the aggregation conditions in a diagram (Figure 2) representing multiple attack paths. The display control unit 13 is an example of a display control means.
[0064] For example, the display control unit 13 receives a determination result from the determination unit 12 indicating whether or not an aggregation condition is met between any two components that constitute the information processing system.
[0065] If the aggregation condition is not met between any two components constituting the information processing system, the display control unit 13 displays those components separately in a diagram (Figure 2) representing multiple attack paths.
[0066] In addition, the display control unit 13 may display security measures implemented for each of the multiple components constituting the information processing system in a diagram (Figure 2) representing multiple attack paths (not shown).
[0067] On the other hand, the display control unit 13 displays multiple components that satisfy the aggregation conditions as a single component in a diagram representing multiple attack paths (Figure 2) (Figures 4 to 6).
[0068] Thus, in a diagram representing multiple attack paths (Figure 2), the diagram is simplified by consolidating and displaying multiple components that satisfy the aggregation conditions from among the multiple components constituting the information processing system into a single diagram (Figure 2). Therefore, there is an advantage in that users can easily understand the main attack paths of server attacks against the information processing system from the diagram representing multiple attack paths (Figure 2).
[0069] (Operation of the attack path display control device 10) Figure 10 is a flowchart showing the operation of the attack path display control device 10 according to this first embodiment.
[0070] As shown in Figure 10, the identification unit 11 acquires information processing system configuration information representing the configuration of the information processing system from the recording device 200 (Figure 1) (S101). The identification unit 11 may also acquire information processing system configuration information from data in a system configuration diagram showing the connection relationships of the equipment and devices that constitute the system.
[0071] Then, based on the acquired information processing system configuration information, the identification unit 11 identifies the source of the attack, the first attack, the target, and the second attack for each of the multiple components located along the multiple attack paths of a cyberattack on the information processing system (S102).
[0072] The meanings of "attack source (node)," "first attack," "attack target (node)," and "second attack" are as described above.
[0073] Next, the determination unit 12 determines whether, between any two components constituting the information processing system, at least one of the attack source and the first attack content is the same, and whether at least one of the attack target and the second attack content is the same (S103).
[0074] Then, if, among the two components subject to the determination, at least one of the attack source and the first attack content is the same, and at least one of the attack target and the second attack content is the same (Yes in S103), the display control unit 13 aggregates those components into one in the diagram representing multiple attack paths (Figure 2) and displays it as a single component (S104A).
[0075] On the other hand, if both the source of the attack and the content of the first attack are different between the two components that were judged, or if both the target of the attack and the content of the second attack are different (No in S103), the display control unit 13 displays those components separately in the diagram representing multiple attack paths (Figure 2) (S104B).
[0076] Subsequently, it is determined whether the determination has been completed for all combinations of two components among the multiple components of the information processing system (S105).
[0077] If the determination has not been completed for all combinations of two components (No in S105), the flow returns to step S103.
[0078] On the other hand, if the determination is completed for all combinations of two components (Yes in S105), the operation of the attack path display control device 10 according to this embodiment ends.
[0079] (Effects of this embodiment) According to the configuration of this embodiment, the identification unit 11 identifies, based on information representing the configuration of the information processing system, the attack source that targets the component in the middle of multiple attack paths of a cyberattack on the information processing system, the first attack content that the attack source executes against the component, the target that the component targets in the cyberattack, and the second attack content that the component executes against the target. The determination unit 12 determines whether the aggregation condition is met among the multiple components, such that at least one of the attack source and the first attack content is the same, and at least one of the target and the second attack content is the same. The display control unit 13 aggregates and displays the multiple components that satisfy the aggregation condition in a diagram representing the multiple attack paths.
[0080] In this way, in diagrams representing multiple attack paths, multiple components that satisfy predetermined aggregation conditions are aggregated into a single display, thus simplifying the diagrams representing multiple attack paths. This makes it possible to present the analysis results regarding the attack paths of cyberattacks against information processing systems in an easy-to-understand manner.
[0081] [Embodiment 2] An attack path display control device 20 according to Embodiment 2 of the present disclosure will be described with reference to Figures 11 to 12. In the following description, "node" corresponds to an example of "component of an information processing system".
[0082] In this second embodiment, we will describe a configuration in which, in a diagram representing multiple attack paths, only a predetermined number or fewer attack paths are displayed from among multiple (more than a predetermined number) attack paths that constitute the information processing system. In this second embodiment, the same reference numerals are used for components that are common to the first embodiment, and their descriptions are omitted.
[0083] (Configuration of the attack path display control device 20) Figure 11 is a block diagram showing the configuration of the attack path display control device 20 according to this first embodiment. As shown in Figure 11, the attack path display control device 20 includes a specification unit 11, a determination unit 12, and a display control unit 23.
[0084] The display control unit 23 receives a determination result from the determination unit 12 indicating whether or not the aggregation condition is met between any two components that constitute the information processing system.
[0085] The display control unit 23 further determines the priority level for each of the multiple attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step.
[0086] For example, in the example shown in Figure 2, the number of attack steps for attack path X, which goes from the entry point through "Node D" and "Node E" to the target, is 3. Also, the number of attack steps for attack path Y, which goes from the entry point through "Node C" to the target, is 2. Attack path Y has fewer attack steps than attack path X. In this case, the display control unit 23 assigns a higher priority to attack path Y than to attack path X.
[0087] The display control unit 23 then displays only a predetermined number of attack paths, or fewer, in the diagram (Figure 2) representing multiple attack paths, in order of the determined priority. The predetermined number can be freely set by the user (administrator, etc.).
[0088] If the aggregation condition is not met between any two nodes constituting the information processing system, the display control unit 23 displays those nodes separately in a diagram (Figure 2) representing multiple attack paths.
[0089] (Operation of the display control unit 23) Figure 12 is a flowchart showing the flow of processing performed by the display control unit 23 according to this embodiment 2.
[0090] As shown in Figure 12, first, the display control unit 23 aggregates and displays multiple nodes that satisfy the determination conditions in a diagram representing multiple attack paths (Figure 2) into one (S201).
[0091] Next, the display control unit 23 measures the number of attack steps and the likelihood of success for each of the multiple attack paths (S202).
[0092] For example, in step S202, the display control unit 23 measures the number of connecting arrows (number of attack steps) for each of the multiple attack paths. The display control unit 23 also measures the likelihood of success for each attack step based on the types of nodes included in each attack path and a table (not shown) that shows the rank (risk level) of ease of attack for each type of node. At this time, the display control unit 23 may also consider whether or not countermeasures against cyberattacks are in place when measuring the likelihood of success for each attack step.
[0093] Next, the display control unit 23 estimates the priority level based on the number of attack steps and the likelihood of success for each attack step (S203).
[0094] Finally, the display control unit 23 displays only a predetermined number of attack paths from among the multiple attack paths, in order of estimated priority (S204).
[0095] This concludes the operation of the display control unit 23 according to this second embodiment.
[0096] In addition to the operations described above, the attack path display control device 20 according to this second embodiment performs the same operations (Figure 10) as the attack path display control device 10 according to the first embodiment. However, in this second embodiment, the explanation of operations that overlap with those in the first embodiment is omitted.
[0097] (Effects of this embodiment) According to the configuration of this embodiment, the identification unit 11 identifies, based on information representing the configuration of the information processing system, the attack source that targets the component in the middle of multiple attack paths of a cyberattack on the information processing system, the first attack content that the attack source executes against the component, the target that the component targets in the cyberattack, and the second attack content that the component executes against the target. The determination unit 12 determines whether the aggregation condition is met among the multiple components, such that at least one of the attack source and the first attack content is the same, and at least one of the target and the second attack content is the same. The display control unit 23 aggregates and displays the multiple components that satisfy the aggregation condition in a diagram representing the multiple attack paths.
[0098] In this way, in diagrams representing multiple attack paths, multiple components that satisfy predetermined aggregation conditions are aggregated into a single display, thus simplifying the diagrams representing multiple attack paths. This makes it possible to present the analysis results regarding the attack paths of cyberattacks against information processing systems in an easy-to-understand manner.
[0099] Furthermore, according to the configuration of this embodiment, the display control unit 23 further determines the priority level for each of the multiple attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step, and in the diagram representing the multiple attack paths, displays only a predetermined number of attack paths from the multiple attack paths in order of the determined priority level.
[0100] This allows only the primary attack path to be displayed in a diagram representing multiple attack paths, making it easier to understand the results of the analysis of attack paths in cyberattacks against information processing systems.
[0101] [Other Embodiments] In the embodiments 1 and 2 described above, the following configurations can also be applied.
[0102] A user (such as an administrator) may use a user terminal (not shown in the diagram) to add a limitation to the aggregation conditions, such as "the source or target of the attack is a server or computer."
[0103] Users may also be able to arbitrarily set which components or types of components are excluded from aggregation.
[0104] The user may also arbitrarily set constraints that restrict the aggregation conditions, such as "the source and target of the attack must be the same" or "the content of the attack on the target must be the same." The constraints set by the user are stored in the recording device 200 (Figure 1).
[0105] The user may set an upper limit on the number of components displayed in a diagram representing multiple attack paths (Figure 2). In addition, the user may add the above-mentioned constraints until the number of components displayed in the diagram representing multiple attack paths is less than or equal to the set upper limit.
[0106] (Modification) Even if the "attack content (from the attacker / attack target) is the same," the attack may be either ineffective or effective depending on whether or not countermeasures against cyberattacks are in place. Therefore, in one modification of Embodiments 1 to 2, one of the aggregation conditions may be that the "attack content is the same" and the "presence or absence of countermeasures is the same" between any two components constituting the information processing system. As a result, in the diagram representing multiple attack paths (Figure 2), components with and without countermeasures are not aggregated, allowing the user to understand that the attack risk is reduced by the countermeasures. Consequently, the possibility of user confusion can be suppressed.
[0107] (Hardware configuration of attack path display control devices 10 and 20) Each component of the attack path display control devices 10 and 20 described in Embodiments 1 and 2 represents a functional unit block. Some or all of these components are realized by an information processing device, for example, as shown in Figure 13. Figure 13 is a block diagram showing an example of the hardware configuration of the information processing device.
[0108] As shown in Figure 13, the computer 110 comprises a CPU (Central Processing Unit) 111, main memory 112, storage device 113, input interface 114, display controller 115, data reader / writer 116, and communication interface 117. Each of these components is connected to each other via a bus 121 to enable data communication. In addition to the CPU 111, or in place of the CPU 111, the computer 110 may also include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array).
[0109] The CPU 111 loads the program (code) in this embodiment, stored in the storage device 113, into the main memory 112 and performs various calculations by executing them in a predetermined order. The main memory 112 is typically a volatile storage device such as DRAM (Dynamic Random Access Memory). The program in this embodiment is provided stored in a computer-readable recording medium 120. The program in this embodiment may also be distributed over the internet connected via the communication interface 117.
[0110] Specific examples of the storage device 113 include hard disk drives and semiconductor storage devices such as flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and mouse. The display controller 115 is connected to the display device 119 and controls the display on the display device 119.
[0111] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.
[0112] Furthermore, specific examples of the recording medium 120 include general-purpose semiconductor memory devices such as CF (Compact Flash®) and SD (Secure Digital), magnetic recording media such as Flexible Disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).
[0113] (Note) Some or all of the above embodiments may also be described as follows, but are not limited to the following.
[0114] (Note 1) An attack path display control device comprising: identification means that, based on information representing the configuration of the information processing system, for each of a plurality of components in the middle of a plurality of attack paths of a cyberattack on the information processing system, identifies the source of the cyberattack that targets the component, the first attack content that the source of the cyberattack will execute against the component, the target of the cyberattack that the component will target, and the second attack content that the component will execute against the target; determination means that determines whether an aggregation condition is met among the plurality of components, such that at least one of the source of the cyberattack and the first attack content is the same, and at least one of the target of the cyberattack and the second attack content is the same; and display control means that aggregates and displays the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths.
[0115] (Note 2) The attack path display control device according to Note 1, characterized in that the identifying means identifies the type of cyberattack against the plurality of components as the first attack content or the second attack content.
[0116] (Note 3) The attack path display control device according to Note 1 or 2, characterized in that the determination means determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the attack source and the first attack content are different, or both the attack target and the second attack content are different.
[0117] (Note 4) The attack path display control device according to any one of Notes 1 to 3, characterized in that, if the aggregation condition is not met among the plurality of components, the display control means displays the plurality of components separately in the figure representing the plurality of attack paths.
[0118] (Note 5) The attack path display control device according to any one of Notes 1 to 4, characterized in that the display control means displays security measures implemented for each of the multiple components in the figure representing the multiple attack paths.
[0119] (Note 6) The attack path display control device according to any one of Notes 1 to 5, characterized in that the display control means displays the plurality of components that satisfy the aggregation condition as a single component in the figure representing the plurality of attack paths.
[0120] (Note 7) The attack path display control device according to any one of Notes 1 to 6, characterized in that the display control means further determines the priority level for each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step, and in the figure representing the plurality of attack paths, displays only a predetermined number or less of the attack paths among the plurality of attack paths in order of the determined higher priority.
[0121] (Note 8) The attack path display control device according to any one of the notes 7, characterized in that the display control means determines the priority level for each of the plurality of attack paths based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the plurality of components located along the plurality of attack paths.
[0122] (Note 9) An attack path display control method comprising: a computer, based on information representing the configuration of an information processing system, identifies, for each of a plurality of components in the middle of a plurality of attack paths of a cyberattack on the information processing system, the source of the attack that targets the component, the first attack that the source of the attack performs against the component, the target of the cyberattack that the component targets, and the second attack that the component performs against the target; determining whether the aggregation condition is met among the plurality of components, such that at least one of the source of the attack and the first attack, and at least one of the target and the second attack, is the same; and in a diagram representing the plurality of attack paths, the plurality of components that satisfy the aggregation condition are aggregated into one and displayed.
[0123] (Note 10) The attack path display control method according to Note 9, characterized in that the computer identifies the type of cyberattack against the plurality of components as the first attack content or the second attack content.
[0124] (Note 11) The attack path display control method according to Note 9 or 10, characterized in that the computer determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the source of the attack and the content of the first attack are different, or both the target of the attack and the content of the second attack are different.
[0125] (Note 12) The attack path display control method according to any one of Notes 9 to 11, characterized in that if the aggregation condition is not met among the plurality of components, the computer displays the plurality of components separately in the diagram representing the plurality of attack paths.
[0126] (Note 13) The attack path display control method according to any one of Notes 9 to 12, characterized in that the computer displays security measures implemented for each of the multiple components in the diagram representing the multiple attack paths.
[0127] (Note 14) The attack path display control method according to any one of Notes 9 to 13, characterized in that the computer displays the plurality of components that satisfy the aggregation condition as a single component in the diagram representing the plurality of attack paths.
[0128] (Note 15) The attack path display control method according to any one of Notes 9 to 14, characterized in that the computer further determines the priority level for each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step, and in the diagram representing the plurality of attack paths, only a predetermined number or less of the attack paths are displayed from among the plurality of attack paths in order of the determined highest priority.
[0129] (Note 16) The attack path display control method according to Note 15, characterized in that the computer determines the priority level for each of the plurality of attack paths based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the plurality of components located along the plurality of attack paths.
[0130] (Note 17) A non-temporary recording medium storing a program for causing a computer to execute: a process that identifies, based on information representing the configuration of an information processing system, for each of a plurality of components located in the middle of a plurality of attack paths of a cyberattack on the information processing system, the source of the attack that targets the component, the first attack that the source of the attack will execute against the component, the target of the cyberattack that the component will execute against the target; a process that determines whether, among the plurality of components, the aggregation condition is met such that at least one of the source of the attack and the first attack, and at least one of the target and the second attack, is the same; and a process that aggregates and displays the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths.
[0131] (Note 18) The recording medium according to Note 17, characterized in that the program causes the computer to execute a process to identify the type of cyberattack against the plurality of components as the first attack content or the second attack content.
[0132] (Note 19) The recording medium according to Note 17 or 18, characterized in that the program causes the computer to execute a process that determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the source of the attack and the content of the first attack are different, or both the target of the attack and the content of the second attack are different.
[0133] (Note 20) The recording medium according to any one of Notes 17 to 19, characterized in that, if the aggregation condition is not met among the plurality of components, the program causes the computer to perform a process of displaying the plurality of components separately in the diagram representing the plurality of attack paths.
[0134] (Note 21) The recording medium according to any one of Notes 17 to 20, characterized in that the program causes the computer to perform a process to display the security measures implemented for each of the multiple components in the diagram representing the multiple attack paths.
[0135] (Note 22) The recording medium according to any one of Notes 17 to 21, characterized in that the program causes the computer to perform a process of displaying the plurality of components that satisfy the aggregation condition as a single component in the diagram representing the plurality of attack paths.
[0136] (Note 23) The recording medium according to any one of Notes 17 to 22, characterized in that the program causes the computer to perform the following: a process of further determining the priority of each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step; and a process of displaying only a predetermined number or fewer attack paths from the plurality of attack paths in the diagram representing the plurality of attack paths, in order of the determined highest priority.
[0137] (Note 24) The recording medium according to Note 23, characterized in that the program causes the computer to perform a process to determine the priority level for each of the multiple attack paths, based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the multiple components located along the multiple attack paths.
[0138] (Supplement) Furthermore, some or all of the configurations described in Supplements 2 to 8, which are dependent on Supplement 1 (e.g., attack path display control device) mentioned above, may also be dependent on Supplement 9 (e.g., attack path display control method) and Supplement 17 (e.g., recording medium) in the same dependent relationship as Supplements 2 to 8. Moreover, within the scope that does not deviate from each of the embodiments described above, some or all of the configurations described as Supplements may also be dependent on various hardware, software, various recording means for recording software, or systems.
[0139] The present disclosure has been described above with reference to several embodiments. However, the present disclosure is not limited to the embodiments described above. Each embodiment can be combined with other embodiments as appropriate. Furthermore, various modifications to the configuration and details of the above embodiments can be made that will be understood by those skilled in the art within the scope of the present disclosure.
[0140] This disclosure can be used, for example, in a security diagnostic system that diagnoses vulnerabilities in information processing systems.
[0141] 10 Attack path display control device 11 Identification unit 12 Determination unit 13 Display control unit 20 Attack path display control device 23 Display control unit
Claims
1. An attack path display control device comprising:
1. Based on information representing the configuration of an information processing system, identification means for each of a plurality of components located along multiple attack paths of a cyberattack on the information processing system, identifying the source of the cyberattack that targets the component, the first attack content that the source of the cyberattack will execute against the component, the target of the cyberattack that the component will target, and the second attack content that the component will execute against the target; 2. Determination means for determining whether an aggregation condition is met among the plurality of components, such that at least one of the source of the cyberattack and the first attack content is the same, and at least one of the target of the cyberattack and the second attack content is the same; and 3. Display control means for aggregating and displaying the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths.
2. The attack path display control device according to claim 1, characterized in that the identifying means identifies the type of cyberattack against the plurality of components as the first attack content or the second attack content.
3. The attack path display control device according to claim 1 or 2, characterized in that the determination means determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the attack source and the first attack content are different, or both the attack target and the second attack content are different.
4. The attack path display control device according to any one of claims 1 to 3, characterized in that, if the aggregation condition is not met among the plurality of components, the display control means displays the plurality of components separately in the figure representing the plurality of attack paths.
5. The attack path display control device according to any one of claims 1 to 4, characterized in that the display control means displays security measures implemented for each of the plurality of components in the figure representing the plurality of attack paths.
6. The attack path display control device according to any one of claims 1 to 5, characterized in that the display control means displays the plurality of components that satisfy the aggregation condition as a single component in the figure representing the plurality of attack paths.
7. The attack path display control device according to any one of claims 1 to 6, wherein the display control means further determines the priority level for each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step, and in the figure representing the plurality of attack paths, displays only a predetermined number or less of the attack paths among the plurality of attack paths in order of the determined highest priority.
8. The attack path display control device according to any one of the seven claims, characterized in that the display control means determines the priority level for each of the plurality of attack paths based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the plurality of components located along the plurality of attack paths.
9. An attack path display control method comprising: a computer, based on information representing the configuration of an information processing system, identifies, for each of a plurality of components in the middle of a plurality of attack paths of a cyberattack on the information processing system, the source of the cyberattack that targets the component, the first attack that the source of the cyberattack performs on the component, the target of the cyberattack that the component targets, and the second attack that the component performs on the target; determining whether, among the plurality of components, the aggregation condition is met such that at least one of the source of the cyberattack and the first attack, and at least one of the target and the second attack, is the same; and in a diagram representing the plurality of attack paths, the plurality of components that satisfy the aggregation condition are aggregated into one and displayed.
10. The attack path display control method according to claim 9, characterized in that the computer identifies the type of cyberattack against the plurality of components as the first attack content or the second attack content.
11. The attack path display control method according to 9 or 10, characterized in that the computer determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the source of the attack and the content of the first attack are different, or both the target of the attack and the content of the second attack are different.
12. The attack path display control method according to any one of claims 9 to 11, characterized in that if the aggregation condition is not met among the plurality of components, the computer displays the plurality of components separately in the diagram representing the plurality of attack paths.
13. The attack path display control method according to any one of claims 9 to 12, characterized in that the computer displays security measures implemented for each of the multiple components in the diagram representing the multiple attack paths.
14. The attack path display control method according to any one of claims 9 to 13, characterized in that the computer displays the plurality of components that satisfy the aggregation condition as a single component in the diagram representing the plurality of attack paths.
15. The attack path display control method according to any one of claims 9 to 14, characterized in that the computer further determines the priority of each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step, and in the diagram representing the plurality of attack paths, only a predetermined number or less of the attack paths are displayed in order of the determined higher priority.
16. The attack path display control method according to 15, characterized in that the computer determines the priority level for each of the plurality of attack paths based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the plurality of components located along the plurality of attack paths.
17. A non-temporary recording medium storing a program for causing a computer to execute:
17. Based on information representing the configuration of an information processing system, for each of a plurality of components located in the middle of multiple attack paths of a cyberattack on the information processing system, the process of identifying the attack source that targets the component, the first attack content that the attack source executes against the component, the target of the cyberattack that the component targets, and the second attack content that the component executes against the target; the process of determining whether, among the plurality of components, the aggregation condition is met such that at least one of the attack source and the first attack content is the same, and at least one of the target and the second attack content is the same; and the process of aggregating and displaying the plurality of components that satisfy the aggregation condition in a diagram representing the plurality of attack paths into one; 18. The recording medium according to claim 17, characterized in that the program causes the computer to perform a process of identifying the type of cyberattack against the plurality of components as the first attack content or the second attack content.
19. The recording medium according to claim 17 or 18, characterized in that the program causes the computer to execute a process that determines that the aggregation condition is not met among the multiple components if, among the multiple components, both the source of the attack and the content of the first attack are different, or both the target of the attack and the content of the second attack are different.
20. The recording medium according to any one of claims 17 to 19, characterized in that the program causes the computer to perform a process of displaying the multiple components separately in the diagram representing the multiple attack paths if the aggregation condition is not met among the multiple components.
21. The recording medium according to any one of claims 17 to 20, characterized in that the program causes the computer to perform a process of displaying security measures implemented for each of the multiple components in the diagram representing the multiple attack paths.
22. The recording medium according to any one of claims 17 to 21, characterized in that the program causes the computer to perform a process of displaying the plurality of components that satisfy the aggregation condition as a single component in the diagram representing the plurality of attack paths.
23. The recording medium according to any one of claims 17 to 22, characterized in that the program causes the computer to perform the following: a process of further determining the priority of each of the plurality of attack paths based on at least one of the number of attack steps and the likelihood of success of each attack step; and a process of displaying only a predetermined number or fewer attack paths from the plurality of attack paths in the diagram representing the plurality of attack paths, in order of the determined highest priority.
24. The recording medium according to 23, characterized in that the program causes the computer to perform a process for determining the priority of each of the plurality of attack paths, based on the number of attack steps and the likelihood of success of each attack step, as well as the attributes of the plurality of components located along the plurality of attack paths.
Citation Information
Patent Citations
Network security planning architecture
US20050138413A1
Information processing device, control method, and program
WO2019186777A1
Attack graph processing device, method, and program
WO2020255185A1