Cyberattack Visualization via Partial Log Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in visualizing cyberattack situations effectively, especially when information about the attack source and target is incomplete or unclear, making it difficult to accurately display the attack scenario.
Innovation Solution
An attack situation visualization device and method that analyze logs to specify either the source or destination of a cyberattack and generate display information showing a map with source and destination images, along with an attack situation image visualizing traffic volume and communication frequency between the two, even when only one is specified.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If log analysis is performed to specify attack source and destination, then measurement precision of attack situation is improved, but device complexity increases due to need for sophisticated log analysis means
Solution Approach 1:
The system segments the log analysis process into distinct functional modules: log collection means, log analysis means, and display information generation means. Each module handles specific tasks independently, reducing overall system complexity while maintaining measurement precision through specialized processing at each stage.
Solution Approach 2:
The patent introduces an intermediary display information generation means that bridges the gap between raw log analysis results and visual presentation. This intermediary layer processes and structures the analyzed data before display, reducing the complexity burden on both the log analysis means and the final visualization system.
2Measurement precision
If complete source and destination information is required for attack visualization, then measurement precision is improved, but loss of information increases when such complete information is not available in logs
Solution Approach 1:
The system applies partial action by visualizing attack situations even when complete source and destination information is not available. The log analysis means processes available log entries to extract whatever source or destination information exists, and the display information generation means creates visual representations based on this partial information, rather than requiring complete data sets.
Solution Approach 2:
The patent applies local quality by allowing different regions of the visualization to represent different levels of information completeness. The display can show attack sources, destinations, or both depending on what information is available in the logs, creating a visualization that adapts to the local quality of available data rather than requiring uniform completeness across all attack records.
3Measurement precision
If detailed attack information is visualized, then measurement precision is improved, but ease of operation decreases due to information overload
Solution Approach 1:
The patent transforms detailed attack information from a potentially overwhelming one-dimensional data list into a two-dimensional visual map representation. The display information generation means plots attack sources, destinations, and communication patterns on a geographical or network map, allowing users to comprehend detailed attack situations through spatial relationships rather than text-heavy presentations.
Solution Approach 2:
The system uses color changes to encode different aspects of attack information in the visualization. The display information generation means can use different colors to represent attack sources, destinations, communication directions, and severity levels, allowing detailed information to be conveyed through visual cues that are easier to process than raw data, thus maintaining measurement precision while improving ease of operation.
Data Source
AI summary
An attack situation visualization device includes: a memory that stores instructions; and at least one processer configured to process the instructions to: analyze a log in which information about a cyberattack is recorded and specify at least either of a source of a communication related to the cyberattack and a destination of a communication related to the cyberattack; and generate display information allowing display of an image in which an image representing a map, a source image representing the source, and a destination image representing the destination are arranged on the map, wherein, the at least one processer configured to process the instructions to generate the display information including an attack situation image visualizing at least either of a traffic volume and a communication frequency of a communication related to the cyberattack between the source and the destination.


