Cyber Attack Information Masking and Sharing Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in controlling the range of information categories provided about cyber attacks, leading to potential leakage of personal information when sharing security information across networks.
Innovation Solution
A method and system that utilize a server device and client terminals to register and manage cyber attack event information, allowing users to set policies on the range of information provided, including mask processing for sensitive data, ensuring secure transmission and control over information categories.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cyber attack information is shared across networks to improve security collaboration, then security information sharing is improved, but personal information leakage risk increases
Solution Approach 1:
The patent segments cyber attack information into different categories (attack patterns, indicators, tactics) and applies different masking rules to different information types. Sensitive personal information is separated and masked while security-relevant information is shared, resolving the contradiction between sharing effectiveness and privacy protection.
Solution Approach 2:
The patent applies different quality treatments to different parts of the information data. Masking processing is applied locally to personal information fields while leaving security-critical fields unchanged, allowing selective protection rather than uniform treatment of all information.
2Object-affected harmful factors
If mask processing is applied to sensitive information categories, then personal information protection is improved, but information sharing completeness deteriorates
Solution Approach 1:
The masking policy is dynamically configurable based on information category and sharing context. The system can adjust the degree of masking applied to different information types, allowing optimization between protection and completeness based on specific sharing scenarios rather than using fixed masking rules.
Solution Approach 2:
The patent changes the parameter of information presentation by applying configurable masking levels. Different masking parameters (complete masking, partial masking, anonymization) can be applied to different information categories, allowing the system to optimize the balance between protection and information utility.
3Reliability
If configurable masking policies are implemented for different information categories, then information security control is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal masking policy framework that handles multiple information categories (attack patterns, indicators, tactics, personal information) through a single configurable system. This multi-functional approach reduces overall system complexity by providing unified control rather than separate mechanisms for each information type.
Solution Approach 2:
The system provides self-service capabilities through automated masking policy application. Once policies are configured, the system automatically applies appropriate masking to different information categories without requiring manual intervention for each data element, reducing operational complexity while maintaining security control.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A non-transitory computer-readable recording medium storing a control program causing a computer to execute processing, the processing includes: displaying a first node of a first type and a second node of a second type; receiving registration of a third node representing an access destination in association with the first node; receiving registration of a fourth node representing mask processing on information in association with the second node; receiving registration of a fifth node representing an information category in association with the second node; allowing transmission of information about a cyber attack event to the third node; and providing the information about the cyber attack event after executing the mask processing associated with the fourth node on information belonging to the information category associated with the fifth node, when the information about the cyber attack event is transmitted to the third node.