Network Attack Risk Estimation for Early Cyber Incident Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods fail to detect cyber incidents at an early stage, particularly in small-scale companies, leading to extended damage due to the lack of advanced knowledge among executives regarding information systems and cyber attacks.

Innovation Solution

An estimation method and device that receive a device ID and observation event, acquire attribute information, and estimate the risk of a network attack, allowing for early detection of potential cyber incidents by outputting the estimated attack risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional evaluation methods are used to estimate risk of secondary infection, then the evaluation can be performed after a cyber incident occurs, but the detection of impending attacks is delayed until damage has already extended

Engineering Contradiction:
Improvedetection timing accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary analysis by evaluating device attribute information and observation events before a cyber incident fully manifests. The estimation unit calculates attack risk in advance by analyzing device attributes (OS type, device type, firmware version) and observed events (login failures, process execution, file access patterns), enabling early detection and response before damage extends across the network.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If detailed attribute information of devices is collected and analyzed, then the accuracy of attack risk estimation is improved, but the complexity of the estimation system increases

Engineering Contradiction:
Improverisk estimation accuracyVSAvoidestimation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the risk estimation process into distinct modules: an information acquisition unit that collects device attribute information (OS type, device type, firmware version) and observation events separately, and an estimation unit that processes these segmented inputs through structured evaluation rules. This modular segmentation improves estimation accuracy while managing system complexity through organized, independent processing stages.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11936675B2Estimation method, estimation device, and estimation program
Publication Date: 2024.03.19 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11936675B2 patent drawing
  • US11936675B2 patent drawing
  • US11936675B2 patent drawing

AI summary

An estimation device (10) receives a device ID for identifying a device in a network and an observation event that has occurred in the device from a user terminal (20) as an input. The estimation device (10) acquires attribute information of the device corresponding to the received device ID from a device information storage unit (13c), estimates a risk that the device in the network is subject to an attack on the basis of the acquired attribute information and the received observation event, and outputs the estimated attack risk to the user terminal (20).