Information Processing Security With Log-Based Function Restriction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures, such as endpoint detection and response (EDR), are ineffective against zero-day attacks using unknown vulnerabilities, and resource-constrained IoT devices lack the capability to implement such measures effectively.
Innovation Solution
An information processing apparatus with a log collecting unit, unauthorized-access detecting unit, function-to-be-restricted specifying unit, and function restricting unit to identify and restrict functions used in unauthorized access, minimizing damage by unknown vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint detection and response (EDR) is used to detect and isolate terminals, then security against known attacks is improved, but resource consumption increases and complexity increases
Solution Approach 1:
The patent segments the security response by identifying specific functions associated with attack scenarios and restricting only those functions rather than isolating the entire terminal. The attack scenario database is divided into multiple scenarios, each with associated functions that can be independently restricted. This segmentation allows targeted response that reduces overall system complexity while maintaining security effectiveness.
Solution Approach 2:
The patent applies local quality by restricting specific functions or services related to detected attack scenarios rather than applying blanket isolation to the entire terminal. Each function has different security restrictions applied based on its association with specific attack scenarios, allowing fine-grained control that reduces resource consumption while maintaining security where needed.
2Reliability
If all functions are isolated when unauthorized access is detected, then security is improved, but system functionality deteriorates
Solution Approach 1:
The patent segments functions into multiple categories associated with different attack scenarios. When unauthorized access is detected, only the functions related to the specific attack scenario are restricted, while other functions continue to operate normally. This segmentation preserves system functionality while maintaining security response effectiveness.
Solution Approach 2:
The patent applies partial action by restricting only the necessary functions related to detected attack scenarios rather than isolating all functions. This partial restriction approach maintains security against the detected attack while preserving other system functionalities, avoiding excessive action that would unnecessarily degrade system capability.
3Reliability
If functional degradation is applied without specifying which function to stop, then security coverage is improved, but precision of response deteriorates
Solution Approach 1:
The patent segments attack scenarios into multiple distinct categories, each with associated functions. When unauthorized access is detected, the system identifies which specific attack scenario occurred and restricts only the functions associated with that scenario. This segmentation provides precise response tailored to the specific attack type while maintaining comprehensive security coverage across multiple scenario types.
Solution Approach 2:
The patent replaces generic functional degradation with a more precise mechanism that maps attack scenarios to specific functions. Instead of mechanically degrading all functions, the system substitutes this with targeted function restriction based on attack scenario identification, achieving both precision and comprehensive security coverage.
Data Source
AI summary
An information processing apparatus collects a log of operations of a system or a program, and detects unauthorized access on the basis of the operation log and an attack scenario defined with a combination of functions which are not performed typically. When unauthorized access is detected, a function to be restricted is specified on the basis of the attack scenario used in the detection, and the specified function is restricted.


