Cyber Attack Path Analysis for Communication System Security Risk Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security risk analysis techniques for communication systems do not account for information security inspections of constituent apparatuses, leading to inadequate threat estimation and unclear risk evaluation.

Innovation Solution

A data processing device and method that sets a path or procedure for cyber attacks, collects safety information regarding information security inspections of constituent apparatuses, and evaluates security risks based on this information, with lower risks when inspections are performed compared to when they are not.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security risk analysis is performed without considering information security inspections of constituent apparatuses, then the analysis process is simpler and faster, but the threat estimation accuracy and validity of security risk evaluation deteriorate

Engineering Contradiction:
Improvesecurity risk evaluation validityVSAvoidrisk analysis process complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent performs information security inspections on constituent apparatuses before conducting security risk analysis. By conducting inspections in advance and collecting the results, the system ensures that accurate threat estimation can be performed later without needing to perform inspections during the risk analysis process, thus improving evaluation validity while managing complexity through preliminary actions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces safety information as an intermediary element that links the inspection results to the security risk evaluation. This intermediary collects and stores inspection data, making it available for use in risk analysis without directly integrating the inspection process into the risk evaluation process, thereby improving measurement precision while maintaining process separability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If information security inspections are performed on all constituent apparatuses, then the security risk evaluation becomes more accurate, but the time and resources required for inspection increase

Engineering Contradiction:
Improvethreat estimation accuracyVSAvoidinspection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies information security inspections selectively to constituent apparatuses that are relevant to the security risk analysis, rather than uniformly inspecting all apparatuses. By identifying and inspecting only the necessary apparatuses based on the risk analysis scope and criticality, the system improves threat estimation accuracy for the targeted area while reducing overall inspection time and resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent performs information security inspections on a partial set of constituent apparatuses rather than all of them. By conducting inspections only on apparatuses that are identified as potential security risks or critical components, the system achieves sufficient accuracy for threat estimation without the time cost of inspecting every single apparatus in the communication system.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240396925A1Data processing device, data processing method, and recording medium
Publication Date: 2024.11.28 NEC CORP
  • US20240396925A1 patent drawing
  • US20240396925A1 patent drawing
  • US20240396925A1 patent drawing

AI summary

A setting unit (11) sets a path or a procedure for a cyber attack that is obtained through analysis of a risk to a communication system. A collection unit (12) collects safety information that is associated with safety in terms of information security regarding the constituent apparatuses of a communication system. An evaluation unit (13) evaluates the magnitude of a security risk present in the communication system, in accordance with the path or procedure for the cyber attack, on the basis of the security information, the security risk to a constituent apparatus related to the path or procedure for the cyber attack being evaluated to be lower when inspection for information security has been carried out on the constituent apparatus related to the path or procedure for the cyber attack than when inspection for information security is not carried out.