Attack Tree Generation via System Segmentation and Nesting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Attack tree automatic generation tools of a logical inference type face a significant challenge with increasing computational complexity, leading to longer development times and higher costs due to polynomial-scale calculations for large systems.
Innovation Solution
The approach involves dividing the target system into sub-systems, selecting root and descendant systems based on threat and intrusion data, generating attack trees for each sub-system, and integrating these to form the overall attack tree, thereby reducing the computational load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a logical inference type attack tree automatic generation tool is used to analyze a large-scale system, then comprehensive attack scenario analysis is achieved, but the calculation amount increases on the order of polynomials leading to longer development time and higher costs
Solution Approach 1:
The patent divides a large-scale target system into multiple sub-systems and generates attack trees for each sub-system separately. This segmentation reduces the calculation complexity from polynomial order for the entire system to manageable levels for individual sub-systems, while still achieving comprehensive attack scenario analysis by integrating results from all sub-systems.
2Reliability
If a logical inference type attack tree automatic generation tool is used to analyze a large-scale system, then comprehensive attack scenario analysis is achieved, but the calculation amount increases on the order of polynomials leading to higher costs
Solution Approach 1:
The patent segments the system analysis into independent sub-system analyses, each with its own attack tree generation. This approach reduces the overall computational cost by avoiding polynomial-scale calculations on the entire system, making large-scale security analysis more economically feasible.
3Productivity
If the target system is divided into sub-systems and attack trees are generated for each sub-system separately, then the calculation amount is reduced, but the integration of sub-attack trees into a comprehensive attack tree requires additional processing
Solution Approach 1:
The patent integrates sub-attack trees into a comprehensive attack tree by nesting them in a hierarchical structure where sub-attack trees become nodes in the parent attack tree. This nesting approach manages integration complexity by organizing sub-system results in a structured manner that maintains comprehensive analysis while controlling processing complexity.
Data Source
AI summary
A system dividing unit (110) divides a target system into a plurality of sub-systems. A root system selection unit (122) selects a sub-system in which a threat on security occurs, as a root system from among the plurality of sub-systems. A root tree generation unit (131) generates an attack tree of the root system, as a root tree. A descendant system selection unit (132) selects one sub-system or more located on an intrusion course to the root system, as one descendent system or more from among the plurality of sub-systems. A descendant tree generation unit (133) generates one attack tree or more corresponding to the one descendent system or more, as one descendent tree or more. A sub-attack tree integration unit (140) integrates the root tree and the one descendent tree or more, to thereby generate an attack tree of the target system.


