Cyber Attack Scenario Analysis System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack the ability to effectively present attack scenarios in a way that is easily understandable for security administrators, making it difficult to comprehend the order and complexity of cyber attacks.
Innovation Solution
An analysis system that generates facts representing security situations of devices within the system to be diagnosed, and uses these facts along with analysis rules to derive attack scenarios, which are then presented in a clear and understandable format.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If detailed attack analysis is performed to accurately represent security situations, then analysis precision is improved, but the complexity of presenting results increases making it difficult for administrators to understand
Solution Approach 1:
The attack scenario is segmented into discrete facts representing specific security states of devices. Each fact captures a particular aspect of the attack situation (e.g., compromised device, attack vector, privilege level), allowing complex attack scenarios to be broken down into manageable, understandable units that can be independently analyzed and presented
Solution Approach 2:
The patent introduces an intermediary representation layer between the complex security analysis and the administrator. Attack scenarios are transformed into standardized fact-based representations that serve as intermediaries, converting detailed technical attack data into a format that is both analytically precise and administratively comprehensible
2Reliability
If comprehensive security analysis of all devices is conducted, then security coverage is improved, but the time required for analysis increases
Solution Approach 1:
The system performs preliminary actions by pre-defining attack scenarios as facts representing potential security states. These facts are prepared in advance and can be quickly matched against actual system states, enabling rapid comprehensive analysis without requiring full re-evaluation of all attack vectors for each analysis run
Solution Approach 2:
The patent changes the parameter representation from detailed continuous security states to discrete fact-based parameters. By representing security situations as discrete facts with specific attributes (device, attack type, privilege level), the system enables efficient processing and comparison that reduces analysis time while maintaining comprehensive coverage
Data Source
AI summary
An analysis unit 6 generates one or more pairs of a start point fact which is a fact representing possibility of the attack in a device that is a start point and an end point fact which is a fact representing possibility of the attack in the device that is an end point, analyzes, for each pair, whether or not it is possible to derive the end point fact from the start point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack, and generates an attack scenario in a case where it is possible to derive the end point fact from the start point fact.


