Attack Means Scoring for Automated Cyberattack Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional vulnerability testing technologies lack the ability to execute sophisticated cyberattacks without the intervention of skilled penetration testers, as they require manual parameter setting and selection of attack means, and there is no guarantee that the selected attack means will evade detection systems.

Innovation Solution

An attack means evaluation apparatus that calculates score values for various attack means, selects the most valid ones based on these scores, and executes them to verify if the final cyberattack goal is achievable, automating the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If automated attack execution is implemented without skilled penetration testers, then productivity and automation extent are improved, but the ability to select effective attack means that evade detection systems deteriorates

Engineering Contradiction:
Improveautomation of cyberattack executionVSAvoideffectiveness of attack means selection
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system implements feedback mechanisms where attack results are analyzed and fed back into the scoring model. The score value calculation unit continuously updates attack mean scores based on execution outcomes, detection events, and system responses, enabling the automated system to learn and improve its attack means selection over time without human intervention

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically changes parameters by calculating and adjusting score values for different attack means based on multiple factors including detection probabilities, system vulnerability states, and attack progression stages. This parameter-based selection mechanism allows automated identification of optimal attack means that balance effectiveness with evasion of detection systems

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If multiple attack means are evaluated and scored, then measurement precision of attack effectiveness is improved, but device complexity and calculation requirements increase

Engineering Contradiction:
Improvescoring accuracy of attack meansVSAvoidcomplexity of score calculation system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The score value calculation is segmented into distinct components: detection probability scores, effectiveness scores, and contextual adjustment factors. Each component is calculated independently based on specific criteria, then combined to produce the overall attack means score. This segmentation simplifies the complex evaluation process into manageable, modular calculations

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameter-based scoring where each attack means is evaluated against a standardized set of parameters (detection probability, effectiveness, resource requirements). By changing and adjusting these parameters dynamically based on system state and attack context, the system achieves precise measurement without requiring overly complex evaluation logic

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12547710B2Attack means evaluation apparatus, attack means evaluation method, and computer readable medium
Publication Date: 2026.02.10 MITSUBISHI ELECTRIC CORP
  • US12547710B2 patent drawing
  • US12547710B2 patent drawing
  • US12547710B2 patent drawing

AI summary

An attack means evaluation apparatus (100) evaluates an attack means used in a cyberattack. A score value calculation unit (110) obtains a plurality of attack means, and for each attack means of the plurality of attack means, calculates a score value that shows validity of an attack on an attack target system. A means selection unit (120) selects an attack means that is valid as an attack on the attack target system from the plurality of attack means using the score value of each attack means of the plurality of attack means and a threshold (173). A means execution unit (130) executes the attack means that is selected on the attack target system, and verifies whether or not an attack for achieving a final aim of the cyberattack is possible based an execution result of the attack means that is selected.