Attack Scenario Generation by Segmenting Large Virtual Models

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies require excessive processing time and memory to generate attack scenarios on large-scale systems due to the large number of devices, leading to inefficiencies in attack simulation.

Innovation Solution

The approach involves dividing virtual models of a target system into smaller components, executing attack simulations on each component, and combining the results to generate attack scenarios, thereby reducing processing time and memory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If attack simulation is executed on a virtual model representing a large-scale system with many devices, then comprehensive attack scenario coverage is achieved, but processing time and memory requirements increase significantly

Engineering Contradiction:
Improveattack scenario coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides a large-scale target system into multiple subsystems, creating separate virtual models for each subsystem. Attack simulations are executed independently on each subsystem model rather than on the entire system at once. This segmentation reduces the computational complexity and memory requirements while maintaining comprehensive attack scenario coverage by combining results from all subsystems.

Inventive Principle:
Principle #1Segmentation

2Reliability

If attack simulation is executed on a virtual model representing a large-scale system with many devices, then comprehensive attack scenario coverage is achieved, but memory capacity requirements increase

Engineering Contradiction:
Improveattack scenario coverageVSAvoidmemory capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the target system into multiple subsystems, each represented by a separate virtual model. This division reduces the memory capacity required for each individual simulation by limiting the scope to only the devices within that subsystem. The overall attack scenario coverage is maintained by aggregating results from all subsystem simulations.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If the target system includes many devices, then system comprehensiveness is improved, but processing time for attack simulation increases

Engineering Contradiction:
Improvesystem comprehensivenessVSAvoidprocessing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent divides the comprehensive target system into multiple smaller subsystems, allowing attack simulations to be executed in parallel or sequentially on each subsystem. This segmentation maintains system comprehensiveness by covering all devices across all subsystems while reducing the processing time required for each individual simulation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by dividing the system into subsystems and creating virtual models for each before executing attack simulations. This preparatory segmentation enables more efficient processing by organizing the simulation work into manageable units that can be processed independently.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12634335B2Attack scenario generating apparatus, attack scenario generating method, and computer readable recording medium
Publication Date: 2026.05.19 NEC CORP
  • US12634335B2 patent drawing
  • US12634335B2 patent drawing
  • US12634335B2 patent drawing

AI summary

An attack scenario generating apparatus including: first attack step detection unit executes an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detects a first attack step that satisfies a damage condition with which damage occurs in the first virtual model; an input/output condition extraction unit extracts an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition; a second attack step detection unit executes an attack simulation on a second virtual model obtained from the storage device, and detects a second attack step in which output of the second virtual model satisfies the input condition; and a combination unit combines the first attack step and the second attack step to generate an attack scenario.