Cyber Attack Scenario Generation via Adaptive Strategy Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for generating cyber attack scenarios are limited in considering the characteristics of attackers and target systems, resulting in ineffective scenario generation.

Innovation Solution

A method and device that evaluate and combine attack strategies and techniques based on system configuration information, using a scenario generation device to identify effective combinations of attack strategies and techniques, thereby generating a dynamic cyber attack scenario.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed combination of attack strategy and technique is used, then the generation process is simple, but the scenario cannot be tailored to attacker characteristics and target system

Engineering Contradiction:
Improveadaptability to attacker characteristics and target systemVSAvoidcomplexity of scenario generation process
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by making the attack scenario generation process adaptive rather than static. The system dynamically evaluates multiple attack strategies and techniques based on attacker characteristics and target system properties, selecting and combining them according to evaluation results. This allows the generation process to adapt to different scenarios while maintaining a structured approach through automated evaluation and combination logic.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes parameters by introducing evaluation criteria that assess attack strategies and techniques based on attacker characteristics and target system properties. By varying the evaluation parameters and combination logic according to specific scenarios, the system generates tailored attack scenarios without requiring a completely different generation process for each case.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If detailed attack strategy and technique evaluation is performed, then the attack scenario becomes more effective, but the generation time and computational resources increase

Engineering Contradiction:
Improveeffectiveness of attack scenarioVSAvoidgeneration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-defining multiple attack strategies and techniques in a database before the actual scenario generation. These pre-prepared attack elements can be quickly evaluated and combined during scenario generation, reducing the time needed for detailed analysis while maintaining effectiveness through systematic evaluation of pre-categorized attack options.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the attack scenario generation into distinct evaluation stages: evaluating attack strategies based on attacker characteristics, evaluating attack techniques based on target system properties, and combining selected strategies and techniques. This segmentation allows each component to be evaluated independently and efficiently, reducing overall generation time while maintaining comprehensive assessment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230367884A1Cyber attack scenario generation method and device
Publication Date: 2023.11.16 HITACHI LTD
  • US20230367884A1 patent drawing
  • US20230367884A1 patent drawing
  • US20230367884A1 patent drawing

AI summary

A method of generating an attack scenario by evaluating an attack strategy and a technique based on a characteristic of an attacker, a target system, and the like, and combining an attack strategy and a technique based on the evaluation. In a method of generating a cyber attack scenario including a combination of attack strategy/technique information configured by a plurality of attack strategies and attack techniques for realizing a threat to a target system, an attack strategy/technique evaluation unit 106 calculates an evaluation point for attack strategy/technique information, and an attack strategy/technique combination determination unit 107 generates a cyber attack scenario by combining the attack strategy/technique evaluation unit 106 based on the evaluation point.