Attack Prediction via Event Stage Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional attack detection systems face challenges in determining attacks, particularly those involving spoofing, as they require predefined scenarios and logic trees, leading to high monitoring costs and false detections, and are not adaptable to new events or techniques.

Innovation Solution

An information processing apparatus that predicts events by storing event stage information and using observed event notices to extract predicted events without predefining scenarios or logic trees, allowing flexible adaptation to new monitoring targets and techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If attack scenarios and logic trees are predefined in advance, then attack detection accuracy is improved, but system adaptability to new attacks deteriorates

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem adaptability to new attacks
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic attack scenario generation by continuously analyzing attack patterns and automatically updating detection scenarios. The system transitions from static predefined scenarios to dynamic scenarios that adapt in real-time based on observed attack behaviors, resolving the contradiction between detection accuracy and adaptability to new attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs self-learning by automatically analyzing attack data and generating detection scenarios without requiring manual configuration. The automated scenario generation mechanism enables the system to serve itself in adapting to new attack types, maintaining both high detection accuracy and adaptability simultaneously.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive monitoring is practiced to detect spoofing attacks, then detection capability is improved, but monitoring cost and false detections increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidmonitoring cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies partial monitoring by selectively monitoring only those events and patterns that are most indicative of spoofing attacks. Rather than practicing comprehensive monitoring of all system events, the system focuses resources on high-value detection targets, reducing monitoring costs and false detections while maintaining effective detection capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system dynamically adjusts monitoring parameters such as detection thresholds, monitoring intensity, and event filtering criteria based on the current threat landscape. This allows the system to optimize the balance between detection capability and monitoring cost by changing operational parameters rather than maintaining fixed comprehensive monitoring.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If attack scenarios are modified to cover new events, then detection coverage is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvedetection coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically generates and updates attack scenarios through self-service mechanisms that analyze new attack events and create appropriate detection scenarios without requiring manual intervention. This automated approach expands detection coverage while avoiding the complexity increase associated with manual scenario management and maintenance.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of scenario creation and modification with an automated computational system. The automated scenario generation mechanism substitutes human analysts who would manually update scenarios, thereby expanding detection coverage while reducing system complexity and maintenance burden.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10282542B2Information processing apparatus, information processing method, and computer readable medium
Publication Date: 2019.05.07 MITSUBISHI ELECTRIC CORP
  • US10282542B2 patent drawing
  • US10282542B2 patent drawing
  • US10282542B2 patent drawing

AI summary

An attack activity definition information database 111 stores, for a plurality of events, attack activity definition information describing an event, a precondition, and an achieved phenomenon. The event is observed by an information system when an attack against the information system is underway. The precondition is a prerequisite condition for the event to be observed. The achieved phenomenon is a phenomenon of the time after the event is observed. An event receiving part 108 receives observed event notice information notifying an observed event which is observed by the information system. An attack activity predicting part 105 acquires an achieved phenomenon from the attack activity definition information describing the observed event notified by the observed event notice information, and extracts an event that is predicted to be observed by the information system, based on the attack activity definition information describing a precondition corresponding to the acquired achieved phenomenon of the observed event.