Primary-Secondary Attack Paths for Simultaneous Branched Network Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies struggle to effectively handle multiple simultaneous attack paths in a network system, making it difficult to manage cyberattacks that target multiple devices simultaneously.

Innovation Solution

An attack path generation method and device that generates primary and secondary attack paths based on logs from network-connected devices with attack detection functions, allowing for the identification of upstream and downstream devices involved in cyberattacks within a certain time frame, and outputs these paths for further analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If one attack scenario is specified based on logs, then the attack detection function works for single attack paths, but it becomes difficult to handle multiple simultaneous attack paths

Engineering Contradiction:
Improveattack path detection accuracyVSAvoidhandling capability for multiple attack paths
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The attack path detection is segmented into primary attack path detection and secondary attack path detection. The primary attack path detection handles the main attack scenario, while the secondary attack path detection handles branching and merging attack paths separately, allowing the system to manage multiple simultaneous attack paths effectively

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary component is introduced to manage the complexity of multiple attack paths. This intermediary coordinates between the primary attack path detection results and the secondary attack path detection, enabling the system to handle multiple simultaneous attack scenarios without losing track of any individual path

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system monitors all devices in the network, then complete attack path coverage is achieved, but the complexity of processing logs from multiple devices increases

Engineering Contradiction:
Improveattack path detection coverageVSAvoidlog processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts only the necessary log information related to attack paths from the multitude of device logs. By taking out only the relevant attack-related events and ignoring unrelated log entries, the system maintains comprehensive monitoring coverage while significantly reducing the complexity of log processing

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary filtering and organization of logs from multiple devices before detailed attack path analysis. Logs are pre-processed to identify potential attack indicators and organize them by device and time, reducing the complexity of subsequent attack path reconstruction and analysis

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12375511B2Attack path generation method and attack path generation device
Publication Date: 2025.07.29 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12375511B2 patent drawing
  • US12375511B2 patent drawing
  • US12375511B2 patent drawing

AI summary

An attack path generation method according to the present disclosure is an attack path generation method executed by acquiring logs in devices connected to a network including at least one of a branch and a merge where each device has an attack detection function. The method includes: generating a primary-attack path without the branch and merge based on the acquired logs; generating a secondary-attack path branching from the primary-attack path or merging with the primary-attack path based on the logs; and outputting the generated primary-attack path and secondary-attack path to a device that performs attack-determination. The secondary-attack path is an attack path including an upstream or downstream device in which an event assumed to be an attack occurs within a certain period of time from an event assumed to be an attack on a device included in the primary-attack path and connected to the network merging/branching point.