Attack Graph Simplification via Node Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to present potential attacks on a system to be diagnosed in an easily understandable manner for security administrators, making it difficult to take effective countermeasures.

Innovation Solution

An attack graph processing device and method that extracts nodes related to specific rules from an attack graph and simplifies the graph based on these extracted nodes, improving visibility and analysis efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the attack graph includes all nodes and edges representing complete system state and attack relationships, then the analysis comprehensiveness is improved, but the graph complexity increases making it difficult to understand

Engineering Contradiction:
Improveanalysis comprehensivenessVSAvoidgraph complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The attack graph is segmented by classifying nodes into different groups based on their attributes and relationships. The node extraction unit identifies and extracts specific nodes belonging to predetermined groups, dividing the complex graph into manageable segments that can be analyzed separately while maintaining overall comprehensiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The node extraction unit extracts specific nodes from the attack graph based on classification criteria. By taking out only the relevant nodes belonging to predetermined groups, the system maintains comprehensive analysis capability while reducing the visual and analytical complexity of the complete graph.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the attack graph includes all nodes representing complete system state, then the security analysis coverage is improved, but the ease of understanding for security administrators deteriorates

Engineering Contradiction:
Improvesecurity analysis coverageVSAvoidease of understanding
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Nodes in the attack graph are segmented into different groups based on their security relevance and attributes. The graph configuration unit organizes these segmented nodes into a structured layout where related nodes are grouped together, making the comprehensive security analysis coverage accessible while improving ease of understanding through logical organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different regions or areas of the attack graph are given different local qualities through the graph configuration unit. Nodes representing different security aspects are positioned in specific areas with appropriate labeling and grouping, allowing security administrators to easily understand different parts of the system while maintaining complete coverage.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the attack graph maintains all detailed relationships among nodes, then the accuracy of attack analysis is improved, but the time required to analyze the graph increases

Engineering Contradiction:
Improveattack analysis accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The node extraction unit performs preliminary action by pre-classifying and extracting nodes into predetermined groups before the actual security analysis. This preliminary organization of nodes based on their attributes and relationships enables faster access to relevant information during analysis while maintaining the accuracy of attack relationships.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The graph configuration unit acts as an intermediary between the complete attack graph and the security administrator. It mediates the detailed relationships by organizing and presenting them in a structured manner, allowing accurate attack analysis to be conducted without requiring the administrator to process all raw relationships directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12321461B2Attack graph processing device, method, and program
Publication Date: 2025.06.03 NEC CORP
  • US12321461B2 patent drawing
  • US12321461B2 patent drawing
  • US12321461B2 patent drawing

AI summary

An attack graph processing device includes a node extraction unit which extracts a node relating to a rule classified into a predetermined group from an attack graph that is configured from one or more nodes indicating the state of a system to be diagnosed, or the state of the primary agent of an attack on the system to be diagnosed, and one or more edges indicating the relationship among a plurality of nodes, the attack graph being generated using rules indicating a condition in which the attack can be executed, and a graph configuration unit which simplifies the attack graph on the basis of the extracted node.