Cyberattack Visualization via Partial Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in visualizing cyberattack situations effectively, especially when information about the attack source and target is incomplete or unclear, making it difficult to accurately display the attack scenario.

Innovation Solution

An attack situation visualization device and method that analyze logs to specify either the source or destination of a cyberattack and generate display information showing a map with source and destination images, along with an attack situation image visualizing traffic volume and communication frequency between the two, even when only one is specified.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If log analysis is performed to specify attack source and destination, then measurement precision of attack situation is improved, but device complexity increases due to need for sophisticated log analysis means

Engineering Contradiction:
Improveattack situation specification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the log analysis process into distinct functional modules: log collection means, log analysis means, and display information generation means. Each module handles specific tasks independently, reducing overall system complexity while maintaining measurement precision through specialized processing at each stage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary display information generation means that bridges the gap between raw log analysis results and visual presentation. This intermediary layer processes and structures the analyzed data before display, reducing the complexity burden on both the log analysis means and the final visualization system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If complete source and destination information is required for attack visualization, then measurement precision is improved, but loss of information increases when such complete information is not available in logs

Engineering Contradiction:
Improveattack scenario accuracyVSAvoidmissing attack information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system applies partial action by visualizing attack situations even when complete source and destination information is not available. The log analysis means processes available log entries to extract whatever source or destination information exists, and the display information generation means creates visual representations based on this partial information, rather than requiring complete data sets.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent applies local quality by allowing different regions of the visualization to represent different levels of information completeness. The display can show attack sources, destinations, or both depending on what information is available in the logs, creating a visualization that adapts to the local quality of available data rather than requiring uniform completeness across all attack records.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If detailed attack information is visualized, then measurement precision is improved, but ease of operation decreases due to information overload

Engineering Contradiction:
Improveattack situation detailVSAvoiduser comprehension
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent transforms detailed attack information from a potentially overwhelming one-dimensional data list into a two-dimensional visual map representation. The display information generation means plots attack sources, destinations, and communication patterns on a geographical or network map, allowing users to comprehend detailed attack situations through spatial relationships rather than text-heavy presentations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The system uses color changes to encode different aspects of attack information in the visualization. The display information generation means can use different colors to represent attack sources, destinations, communication directions, and severity levels, allowing detailed information to be conveyed through visual cues that are easier to process than raw data, thus maintaining measurement precision while improving ease of operation.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS12126641B2Attack situation visualization device, attack situation visualization method and recording medium
Publication Date: 2024.10.22 NEC CORP
  • US12126641B2 patent drawing
  • US12126641B2 patent drawing
  • US12126641B2 patent drawing

AI summary

An attack situation visualization device includes: a memory that stores instructions; and at least one processer configured to process the instructions to: analyze a log in which information about a cyberattack is recorded and specify at least either of a source of a communication related to the cyberattack and a destination of a communication related to the cyberattack; and generate display information allowing display of an image in which an image representing a map, a source image representing the source, and a destination image representing the destination are arranged on the map, wherein, the at least one processer configured to process the instructions to generate the display information including an attack situation image visualizing at least either of a traffic volume and a communication frequency of a communication related to the cyberattack between the source and the destination.