Cyberattack Analysis Prioritization for High-Impact Target Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Honeypots receive a large volume of cyberattack communications, and existing analysis methods do not prioritize analysis based on the impact of cyberattacks on products or adapt priorities according to the content of observed attacks, leading to inefficient analysis of high-priority devices.

Innovation Solution

An attack analysis device that adjusts analysis priorities based on the impact of cyberattacks on devices and the content of observed attacks, using an analysis priority change unit to prioritize analysis of high-priority devices and anticipate future attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all cyberattacks are analyzed in chronological order, then analysis completeness is improved, but analysis time increases significantly

Engineering Contradiction:
Improveanalysis completenessVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary classification of cyberattacks into multiple stages (information collection, further attack, etc.) and pre-establishes priority levels for different devices based on their importance. This preliminary organization enables rapid retrieval and analysis of high-priority attacks without needing to process all attacks chronologically, thus reducing analysis time while maintaining completeness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The analysis process is segmented into distinct stages corresponding to different phases of cyberattacks. Each stage can be independently processed and prioritized, allowing the system to focus computational resources on critical stages and devices rather than treating all attacks uniformly, thereby improving both efficiency and completeness.

Inventive Principle:
Principle #1Segmentation

2Productivity

If fixed analysis priorities are assigned to devices, then analysis efficiency for critical devices is improved, but adaptability to changing attack patterns deteriorates

Engineering Contradiction:
Improveanalysis efficiencyVSAvoidadaptability to attack patterns
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic priority adjustment where device analysis priorities are not fixed but continuously updated based on observed attack patterns, device vulnerability assessments, and security incident history. This dynamic mechanism allows the system to adapt to emerging threats and changing attack landscapes while maintaining high efficiency for currently critical devices.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where analysis results, new attack observations, and security outcomes are fed back into the priority assignment mechanism. This feedback enables continuous refinement of device priorities, ensuring that the system adapts to new attack patterns while preserving efficient analysis of consistently high-risk devices.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260067303A1Attack analysis device, attack analysis method, and non-transitory computer readable medium
Publication Date: 2026.03.05 MITSUBISHI ELECTRIC CORP
  • US20260067303A1 patent drawing
  • US20260067303A1 patent drawing
  • US20260067303A1 patent drawing

AI summary

An attack analysis device (100) includes an analysis priority change unit (130) to change an analysis priority corresponding to a target device in accordance with a content of a target attack when the target device is subjected to the target attack being a cyberattack, the target device being a device provided to an attack target system including a plurality of devices each being set with an analysis priority. Assuming that the plurality of devices provided to the attack target system form an attack target device group, when the devices included in the attack target device group are subjected to cyberattacks, the cyberattacks against the devices included in the attack target device group are analyzed in order according to analysis priorities corresponding to the devices included in the attack target device group.