Air Gap Path Detection for Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security assessment systems cannot consider the possibility of air gap paths being used for attacks, as they only assess communication links within a network and do not account for data movement through unconnected hosts, such as via portable storage media.

Innovation Solution

An information processing apparatus and method that detects air gap paths between hosts with no direct communication link but where data movement is possible, calculates a score for the likelihood of these paths being used for attacks, and integrates this information into security assessments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security assessment is performed only based on communication links within a network, then the assessment system remains simple and focused on network connectivity, but it fails to detect air gap paths where data movement can occur between hosts with no direct communication link

Engineering Contradiction:
Improvedetection accuracy of attack pathsVSAvoidcomplexity of security assessment system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security assessment process into distinct functional modules: a system configuration detector that identifies hosts and communication links, an air gap path detector that specifically identifies paths between hosts without direct communication links, and a security assessment unit that evaluates risks. This segmentation allows the system to add sophisticated air gap detection capability without overwhelming complexity, as each module performs a specific function independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary air gap path detector module that bridges the gap between traditional network communication link detection and security risk assessment. This intermediary component analyzes system configuration data to identify indirect data movement paths between hosts that lack direct communication links, enabling comprehensive security assessment without requiring direct network connectivity between all hosts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system detects and assesses air gap paths between hosts, then comprehensive security coverage is achieved, but the computational complexity and data processing requirements increase

Engineering Contradiction:
Improvecompleteness of security assessmentVSAvoidcomplexity of detection and calculation processes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary detection of system configuration, including all hosts and communication links, before conducting air gap path analysis. The system first establishes a complete inventory of network elements and their direct connections, then uses this pre-processed information as a foundation for identifying indirect data movement paths. This preliminary action reduces computational complexity by avoiding redundant analysis during the main assessment phase.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent focuses detection efforts on identifying air gap paths specifically between hosts with no direct communication links, rather than analyzing all possible host pairs. By targeting only the partial case of indirect paths and excluding already-known direct communication links from air gap analysis, the system achieves comprehensive security coverage for the critical blind spot without excessive computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11503060B2Information processing apparatus, information processing system, security assessment method, and security assessment program
Publication Date: 2022.11.15 NEC CORP
  • US11503060B2 patent drawing
  • US11503060B2 patent drawing
  • US11503060B2 patent drawing

AI summary

To implement a security assessment system capable of assessing an attack path including an air gap path, there is provided an information processing apparatus including a system configuration detector that detects at least two hosts included in a system and a communication link between the at least two hosts, an air gap path detector that detects, among the at least two hosts, a pair of hosts between which there is no communication link but data movement can occur, a calculator that calculates a score concerning a possibility that the pair of hosts detected by the air gap path detector is used for an attack, and a security assessment unit that performs security assessment using the hosts, the communication link between the hosts, information of the pair of hosts, and the score.