Cyberattack Route Adjustment Using Asset and Vulnerability Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional penetration tests primarily utilize vulnerability information to search for attack routes, neglecting the potential of asset information in simulating cyberattacks.

Innovation Solution

An attack status evaluation apparatus that emulates a cyberattack, incorporating a degree of goal achievement calculation unit and an attack route change determination unit to adjust the attack route based on both vulnerability and asset information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If vulnerability information is utilized to search for attack routes, then the penetration test can be automated, but asset information is not utilized reducing the accuracy of attack route simulation

Engineering Contradiction:
Improveautomation of penetration testVSAvoidaccuracy of attack route simulation
Core Design Contradiction:
Extent of automationVSMeasurement precision

Solution Approach 1:

The patent merges vulnerability information and asset information into a unified attack route search framework. The vulnerability information identifies potential entry points and weaknesses, while asset information provides context about the value and importance of target systems. By combining these two information sources, the system achieves both automation capability and accurate simulation of real cyberattacks, resolving the contradiction between automation extent and measurement precision.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If manual penetration testing is performed by experts, then attack routes can be accurately identified, but the process is time-consuming and requires specialized personnel

Engineering Contradiction:
Improveaccuracy of attack route identificationVSAvoidtime required for penetration test
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements feedback mechanisms where the system continuously evaluates attack routes based on both vulnerability and asset information. The degree of goal achievement calculation provides feedback on how closely the simulated attack matches real-world attack patterns. This feedback loop enables automated systems to learn and improve their attack route identification accuracy over time, achieving expert-level precision without requiring specialized personnel or excessive time.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If asset information is incorporated into attack route search, then the simulation of actual cyberattacks is improved, but the system complexity increases

Engineering Contradiction:
Improverealism of cyberattack simulationVSAvoidcomplexity of attack route search system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional system that handles both vulnerability assessment and asset evaluation within a single attack route search framework. The system universally processes different types of information (vulnerability data, asset data, attack patterns) through integrated algorithms. This universal approach improves cyberattack simulation realism while avoiding the complexity increase that would result from separate specialized systems, as the same infrastructure serves multiple functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20230421599A1Attack status evaluation apparatus, attack status evaluation method, and computer readable medium
Publication Date: 2023.12.28 MITSUBISHI ELECTRIC CORP
  • US20230421599A1 patent drawing
  • US20230421599A1 patent drawing
  • US20230421599A1 patent drawing

AI summary

An attack status evaluation apparatus (100) that emulates a cyberattack that steals information includes a degree of goal achievement calculation unit (105) and an attack route change determination unit (106). The degree of goal achievement calculation unit (105) calculates a degree of goal achievement that indicates a degree to which a goal is achieved in the cyberattack based on information that the attack status evaluation apparatus stole. The attack route change determination unit (106) determines whether or not to change an attack route of the cyberattack according to the degree of goal achievement.