Attack Path Extraction for Comprehensive Threat Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current analysis techniques can only identify fragmented threats and require specialized knowledge to recognize sequential attack paths and extract devices involved in chain attacks within a system, failing to provide comprehensive analysis of attack paths and necessary countermeasures.

Innovation Solution

An information processing device and method that reads device groups and connection relations, extracts attack paths using graph theory, stores past attack cases, determines attack phases and node conditions, and outputs comprehensive attack cases, including details and countermeasures, without needing specialized expertise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If analysis techniques are applied to individual devices, then threat analysis for each device can be performed, but comprehensive attack path identification across the system cannot be achieved

Engineering Contradiction:
Improvethreat analysis accuracyVSAvoidattack path coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system segments the overall attack path analysis into individual device threat analyses. Each device is analyzed separately to identify specific threats, and these segmented analyses are then integrated through the attack path generation unit to form comprehensive attack paths across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges individual device threat analyses into comprehensive attack paths. The attack path generation unit combines threat information from multiple devices, connection relationships, and attack patterns to generate unified attack paths that span across the entire system, transforming fragmented device-level data into system-level security insights.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If specialized knowledge is used to identify sequential attack paths, then accurate attack path recognition can be achieved, but automated analysis without expert intervention cannot be realized

Engineering Contradiction:
Improveattack path recognition accuracyVSAvoidanalysis automation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs self-service by automatically generating attack paths without requiring specialized security knowledge from operators. The attack path generation unit autonomously processes device information, connection relationships, and attack patterns to produce comprehensive attack paths, eliminating the need for expert intervention while maintaining high accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where attack patterns and historical data are continuously refined based on generated attack paths. The attack pattern information storage and retrieval units provide feedback loops that improve the accuracy of attack path recognition over time, allowing the system to learn and adapt without external expert input.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If comprehensive attack path analysis is performed across the system, then complete security assessment can be achieved, but analysis complexity increases significantly

Engineering Contradiction:
Improveattack path coverageVSAvoidanalysis system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The complex task of comprehensive attack path analysis is segmented into manageable components: device information management units, attack pattern storage and retrieval units, and an attack path generation unit. Each segment handles specific aspects of the analysis, reducing overall system complexity while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The attack path generation unit serves as an intermediary that bridges device information and security assessment results. It mediates between the complex device network data and the final attack path outputs, simplifying the analysis process by providing a structured intermediate representation that connects raw device data to comprehensive security insights.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Loss of information

If detailed attack cases are derived for each device, then comprehensive security information can be obtained, but information processing volume increases

Engineering Contradiction:
Improvesecurity information completenessVSAvoiddata processing volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The system extracts only the essential security information needed for attack path analysis from device data. Rather than processing all device information, the device information management units extract relevant attributes and relationships, and the attack path generation unit extracts specific threat patterns, reducing data processing volume while maintaining security information completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of processing all device data to generate security information, the system inverts the approach by starting with known attack patterns and retrieving only the specific device information relevant to those patterns. This inversion reduces data processing volume by filtering device data through the lens of attack patterns rather than analyzing all device data comprehensively.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11475127B2Information processing device and information processing method
Publication Date: 2022.10.18 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11475127B2 patent drawing
  • US11475127B2 patent drawing
  • US11475127B2 patent drawing

AI summary

Attack cases (for example, including attack details, countermeasures, and the like) of each device forming each attack path are derived by comprehensively extracting attack paths assumed for a target system. An information processing device D includes: an input unit (1) configured to read a list of a device group included in a system and a list of connection relations between devices; an attack path extracting unit (2) configured to extract an attack path on the basis of the list of the device group and the list of the connection relations read by the input unit (1); an attack case DB unit (3) configured to store a past attack case in association with an attack phase and a node condition at a time when the attack case occurred; an attack case search unit (4) configured to determine an attack phase and a node condition of each device serving as each node configuring the attack path extracted by the attack path extracting unit (2) and acquire an attack case corresponding to each device by searching the attack case DB unit (3) using the determined attack phase and the determined node condition; and an output unit (5) configured to output a result of the search.