Cyber Attack Analysis Support System Using STIX Visual Graphs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in recognizing and understanding the similarities between cyber attacks based on the information obtained from existing technologies.
Innovation Solution
A cyber attack analysis support system that includes a client terminal and a server device, where the server registers and searches for similar cyber attack event information, generating display information to present similarities in an easy-to-understand manner using a structured threat information expression (STIX) format, with graphic diagrams showing related nodes and coupling lines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If existing malware similarity inspection methods are used to obtain cyber attack information, then the information can be obtained through behavior comparison, but the user has difficulty recognizing and understanding the similarities between cyber attacks
Solution Approach 1:
The patent creates visual copies of cyber attack information in the form of graphic diagrams that replicate the structural relationships between attack elements. These visual representations copy the essential similarity patterns while presenting them in an easily comprehensible format, allowing users to recognize attack similarities without dealing with complex raw data
Solution Approach 2:
The patent transforms one-dimensional text-based or data-based cyber attack information into two-dimensional visual graphic diagrams. This dimensional transformation adds visual spatial relationships that make similarity patterns immediately apparent to users, converting abstract similarity metrics into concrete visual representations
2Measurement precision
If detailed cyber attack event information is stored and analyzed, then similarity detection accuracy is improved, but the time and computational resources required for analysis increase
Solution Approach 1:
The patent performs preliminary actions by pre-processing cyber attack event information into structured formats with defined nodes and relationships before actual similarity analysis is needed. This preparation work includes organizing attack data into standardized graphic diagram formats, so that when similarity detection is required, the system can quickly compare pre-structured information without extensive real-time processing
Solution Approach 2:
The patent segments cyber attack information into discrete nodes representing specific attack elements and relationships between them. This segmentation allows the system to compare individual nodes and their relationships independently, improving detection accuracy while enabling efficient processing by breaking down complex attack patterns into manageable comparison units
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A non-transitory computer readable recording medium storing a computer executable program that, when executed, causes a computer to perform a cyber attack analysis support process, the cyber attack analysis support process includes: when information of a first cyber attack event including information of malware is registered as a result of a detection of the malware within an information processing system to be monitored, searching for a second cyber attack event having a similarity relationship with the first cyber attack event by referring to a storage storing information on past cyber attack events; and displaying information of the searched second cyber attack event and the registered information of the first cyber attack event on a display circuit.