Attack Scenario Generation Using Risk Analysis Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing attack scenario generation systems rely on analyst expertise and learned data, which may not always generate scenarios suitable for the analyzed system, lacking consistency and accuracy.

Innovation Solution

An apparatus and method that utilize an attack scenario generation system to acquire risk analysis results, condition parameters from a database, and generate scenarios based on these conditions, independent of human expertise, enabling tailored scenarios for detailed risk analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If an attack scenario is created by analyzing the attack procedure of a cyber-attack, then the attack scenario can be generated, but the suitability of the created attack scenario depends on the technique and knowledge of an analyst

Engineering Contradiction:
Improveaccuracy of attack scenarioVSAvoiddependence on analyst expertise
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs automatic attack scenario generation using a computer that acquires risk analysis results and automatically creates attack scenarios based on stored conditions, eliminating the need for manual analyst intervention and reducing dependence on human expertise while maintaining scenario accuracy

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The manual process of analysts creating attack scenarios is replaced by an automated computer-based system that uses risk analysis results and pre-stored conditions to generate scenarios, substituting human cognitive processes with mechanical computation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Extent of automation

If an attack scenario is generated by a cyber-attack scenario generation AI, then automation is achieved, but the generated scenario depends on learned data and may not always be suitable for the system to be analyzed

Engineering Contradiction:
Improveautomation of scenario generationVSAvoidsuitability of generated scenario
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The system changes the input parameters for scenario generation by using actual risk analysis results from the target system rather than relying solely on learned data from training, ensuring the generated scenarios are specifically suited to the system being analyzed

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system uses risk analysis results as feedback to guide the attack scenario generation process, creating a closed-loop system where the generated scenarios are based on actual system characteristics rather than generic learned patterns

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12609954B2Attack scenario generation apparatus, risk analysis apparatus, method, and computer readable media
Publication Date: 2026.04.21 NEC CORP
  • US12609954B2 patent drawing
  • US12609954B2 patent drawing
  • US12609954B2 patent drawing

AI summary

Generation of an attack scenario to be used for risk analysis of a system to be analyzed is enabled without depending on the technique and the knowledge of a person who creates it. An analysis result acquisition means acquires a risk analysis result of a first risk analysis performed on a system to be analyzed. A condition acquisition means acquires conditions for an attack scenario to be used for a second risk analysis on the basis of an attack scenario table and the risk analysis result. An attack scenario generation means generates an attack scenario to be used for the second risk analysis on the basis of the conditions for the attack scenario acquired by the condition acquisition means.