Attack Prediction via Event Stage Information
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional attack detection systems face challenges in determining attacks, particularly those involving spoofing, as they require predefined scenarios and logic trees, leading to high monitoring costs and false detections, and are not adaptable to new events or techniques.
Innovation Solution
An information processing apparatus that predicts events by storing event stage information and using observed event notices to extract predicted events without predefining scenarios or logic trees, allowing flexible adaptation to new monitoring targets and techniques.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If attack scenarios and logic trees are predefined in advance, then attack detection accuracy is improved, but system adaptability to new attacks deteriorates
Solution Approach 1:
The patent implements dynamic attack scenario generation by continuously analyzing attack patterns and automatically updating detection scenarios. The system transitions from static predefined scenarios to dynamic scenarios that adapt in real-time based on observed attack behaviors, resolving the contradiction between detection accuracy and adaptability to new attacks.
Solution Approach 2:
The system performs self-learning by automatically analyzing attack data and generating detection scenarios without requiring manual configuration. The automated scenario generation mechanism enables the system to serve itself in adapting to new attack types, maintaining both high detection accuracy and adaptability simultaneously.
2Reliability
If comprehensive monitoring is practiced to detect spoofing attacks, then detection capability is improved, but monitoring cost and false detections increase
Solution Approach 1:
The patent applies partial monitoring by selectively monitoring only those events and patterns that are most indicative of spoofing attacks. Rather than practicing comprehensive monitoring of all system events, the system focuses resources on high-value detection targets, reducing monitoring costs and false detections while maintaining effective detection capability.
Solution Approach 2:
The system dynamically adjusts monitoring parameters such as detection thresholds, monitoring intensity, and event filtering criteria based on the current threat landscape. This allows the system to optimize the balance between detection capability and monitoring cost by changing operational parameters rather than maintaining fixed comprehensive monitoring.
3Adaptability or versatility
If attack scenarios are modified to cover new events, then detection coverage is improved, but system complexity and maintenance burden increase
Solution Approach 1:
The system automatically generates and updates attack scenarios through self-service mechanisms that analyze new attack events and create appropriate detection scenarios without requiring manual intervention. This automated approach expands detection coverage while avoiding the complexity increase associated with manual scenario management and maintenance.
Solution Approach 2:
The patent replaces the manual mechanical process of scenario creation and modification with an automated computational system. The automated scenario generation mechanism substitutes human analysts who would manually update scenarios, thereby expanding detection coverage while reducing system complexity and maintenance burden.
Data Source
AI summary
An attack activity definition information database 111 stores, for a plurality of events, attack activity definition information describing an event, a precondition, and an achieved phenomenon. The event is observed by an information system when an attack against the information system is underway. The precondition is a prerequisite condition for the event to be observed. The achieved phenomenon is a phenomenon of the time after the event is observed. An event receiving part 108 receives observed event notice information notifying an observed event which is observed by the information system. An attack activity predicting part 105 acquires an achieved phenomenon from the attack activity definition information describing the observed event notified by the observed event notice information, and extracts an event that is predicted to be observed by the information system, based on the attack activity definition information describing a precondition corresponding to the acquired achieved phenomenon of the observed event.


