Network Attack Risk Estimation for Early Cyber Incident Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods fail to detect cyber incidents at an early stage, particularly in small-scale companies, leading to extended damage due to the lack of advanced knowledge among executives regarding information systems and cyber attacks.
Innovation Solution
An estimation method and device that receive a device ID and observation event, acquire attribute information, and estimate the risk of a network attack, allowing for early detection of potential cyber incidents by outputting the estimated attack risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional evaluation methods are used to estimate risk of secondary infection, then the evaluation can be performed after a cyber incident occurs, but the detection of impending attacks is delayed until damage has already extended
Solution Approach 1:
The system performs preliminary analysis by evaluating device attribute information and observation events before a cyber incident fully manifests. The estimation unit calculates attack risk in advance by analyzing device attributes (OS type, device type, firmware version) and observed events (login failures, process execution, file access patterns), enabling early detection and response before damage extends across the network.
2Measurement precision
If detailed attribute information of devices is collected and analyzed, then the accuracy of attack risk estimation is improved, but the complexity of the estimation system increases
Solution Approach 1:
The system segments the risk estimation process into distinct modules: an information acquisition unit that collects device attribute information (OS type, device type, firmware version) and observation events separately, and an estimation unit that processes these segmented inputs through structured evaluation rules. This modular segmentation improves estimation accuracy while managing system complexity through organized, independent processing stages.
Data Source
AI summary
An estimation device (10) receives a device ID for identifying a device in a network and an observation event that has occurred in the device from a user terminal (20) as an input. The estimation device (10) acquires attribute information of the device corresponding to the received device ID from a device information storage unit (13c), estimates a risk that the device in the network is subject to an attack on the basis of the acquired attribute information and the received observation event, and outputs the estimated attack risk to the user terminal (20).


