Cyber Attack Path Analysis for Communication System Security Risk Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security risk analysis techniques for communication systems do not account for information security inspections of constituent apparatuses, leading to inadequate threat estimation and unclear risk evaluation.
Innovation Solution
A data processing device and method that sets a path or procedure for cyber attacks, collects safety information regarding information security inspections of constituent apparatuses, and evaluates security risks based on this information, with lower risks when inspections are performed compared to when they are not.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security risk analysis is performed without considering information security inspections of constituent apparatuses, then the analysis process is simpler and faster, but the threat estimation accuracy and validity of security risk evaluation deteriorate
Solution Approach 1:
The patent performs information security inspections on constituent apparatuses before conducting security risk analysis. By conducting inspections in advance and collecting the results, the system ensures that accurate threat estimation can be performed later without needing to perform inspections during the risk analysis process, thus improving evaluation validity while managing complexity through preliminary actions.
Solution Approach 2:
The patent introduces safety information as an intermediary element that links the inspection results to the security risk evaluation. This intermediary collects and stores inspection data, making it available for use in risk analysis without directly integrating the inspection process into the risk evaluation process, thereby improving measurement precision while maintaining process separability.
2Measurement precision
If information security inspections are performed on all constituent apparatuses, then the security risk evaluation becomes more accurate, but the time and resources required for inspection increase
Solution Approach 1:
The patent applies information security inspections selectively to constituent apparatuses that are relevant to the security risk analysis, rather than uniformly inspecting all apparatuses. By identifying and inspecting only the necessary apparatuses based on the risk analysis scope and criticality, the system improves threat estimation accuracy for the targeted area while reducing overall inspection time and resource consumption.
Solution Approach 2:
The patent performs information security inspections on a partial set of constituent apparatuses rather than all of them. By conducting inspections only on apparatuses that are identified as potential security risks or critical components, the system achieves sufficient accuracy for threat estimation without the time cost of inspecting every single apparatus in the communication system.
Data Source
AI summary
A setting unit (11) sets a path or a procedure for a cyber attack that is obtained through analysis of a risk to a communication system. A collection unit (12) collects safety information that is associated with safety in terms of information security regarding the constituent apparatuses of a communication system. An evaluation unit (13) evaluates the magnitude of a security risk present in the communication system, in accordance with the path or procedure for the cyber attack, on the basis of the security information, the security risk to a constituent apparatus related to the path or procedure for the cyber attack being evaluated to be lower when inspection for information security has been carried out on the constituent apparatus related to the path or procedure for the cyber attack than when inspection for information security is not carried out.


