Cyber Attack Analysis Support System Using STIX Visual Graphs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in recognizing and understanding the similarities between cyber attacks based on the information obtained from existing technologies.

Innovation Solution

A cyber attack analysis support system that includes a client terminal and a server device, where the server registers and searches for similar cyber attack event information, generating display information to present similarities in an easy-to-understand manner using a structured threat information expression (STIX) format, with graphic diagrams showing related nodes and coupling lines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If existing malware similarity inspection methods are used to obtain cyber attack information, then the information can be obtained through behavior comparison, but the user has difficulty recognizing and understanding the similarities between cyber attacks

Engineering Contradiction:
Improveunderstandability of cyber attack similarityVSAvoidcomplexity of information presentation
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent creates visual copies of cyber attack information in the form of graphic diagrams that replicate the structural relationships between attack elements. These visual representations copy the essential similarity patterns while presenting them in an easily comprehensible format, allowing users to recognize attack similarities without dealing with complex raw data

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent transforms one-dimensional text-based or data-based cyber attack information into two-dimensional visual graphic diagrams. This dimensional transformation adds visual spatial relationships that make similarity patterns immediately apparent to users, converting abstract similarity metrics into concrete visual representations

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If detailed cyber attack event information is stored and analyzed, then similarity detection accuracy is improved, but the time and computational resources required for analysis increase

Engineering Contradiction:
Improvesimilarity detection accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-processing cyber attack event information into structured formats with defined nodes and relationships before actual similarity analysis is needed. This preparation work includes organizing attack data into standardized graphic diagram formats, so that when similarity detection is required, the system can quickly compare pre-structured information without extensive real-time processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments cyber attack information into discrete nodes representing specific attack elements and relationships between them. This segmentation allows the system to compare individual nodes and their relationships independently, improving detection accuracy while enabling efficient processing by breaking down complex attack patterns into manageable comparison units

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3287927B1Non-transitory computer-readable recording medium storing cyber attack analysis support program, cyber attack analysis support method, and cyber attack analysis support device
Publication Date: 2019.11.20 FUJITSU LTD
  • EP3287927B1 patent drawingFigure 1
  • EP3287927B1 patent drawingFigure 2
  • EP3287927B1 patent drawingFigure 3

AI summary

A non-transitory computer readable recording medium storing a computer executable program that, when executed, causes a computer to perform a cyber attack analysis support process, the cyber attack analysis support process includes: when information of a first cyber attack event including information of malware is registered as a result of a detection of the malware within an information processing system to be monitored, searching for a second cyber attack event having a similarity relationship with the first cyber attack event by referring to a storage storing information on past cyber attack events; and displaying information of the searched second cyber attack event and the registered information of the first cyber attack event on a display circuit.