Network Security Analysis System with Attack Route Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to provide an analysis system, method, and program that help security administrators select appropriate security measures for a system to be diagnosed, given limited budgets and the need to prioritize countermeasures based on risk and cost.

Innovation Solution

The proposed system includes a topology identification unit to map network devices, a detection unit to identify potential attack routes, and a countermeasure identification unit to suggest prevention plans and their associated costs, enabling administrators to make informed decisions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all security measures are implemented, then system security is improved, but implementation cost increases

Engineering Contradiction:
Improvesystem securityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system implements feedback by continuously monitoring security events, analyzing attack patterns, and dynamically adjusting security measures. The security information collection unit gathers data on actual security incidents and system responses, feeding this information back to improve future security decisions and optimize resource allocation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes parameters by dynamically adjusting security measure intensity and priority based on detected attack patterns and risk assessments. Instead of static implementation, security measures are adapted in real-time based on system state, threat level, and cost considerations.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If security analysis is performed manually, then implementation flexibility is maintained, but analysis time increases

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidanalysis time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system introduces an intermediary security information collection and analysis unit that acts as a mediator between raw security events and decision-makers. This intermediary automatically processes, analyzes, and prioritizes security information, reducing manual analysis time while maintaining operational flexibility through configurable analysis parameters.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces manual mechanical analysis processes with automated information processing. Security events are automatically collected, analyzed, and synthesized by computational algorithms rather than human analysts, dramatically reducing analysis time while preserving flexibility through programmable analysis rules.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If detailed security monitoring is implemented, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments security monitoring into distinct functional units: collection, analysis, and response. Each unit handles specific aspects of security monitoring independently, reducing overall system complexity while maintaining high detection accuracy through specialized processing in each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security information collection unit performs multiple functions simultaneously: collecting security events, analyzing attack patterns, identifying threats, and generating responses. This multi-functionality reduces the need for separate specialized systems, lowering overall complexity while maintaining comprehensive monitoring accuracy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12244614B2Analysis system, method, and program
Publication Date: 2025.03.04 NEC CORP
  • US12244614B2 patent drawing
  • US12244614B2 patent drawing
  • US12244614B2 patent drawing

AI summary

A topology identification unit identifies a network topology of devices included in the system to be diagnosed. A detection unit detects attack routes that indicate flows of attacks that can be executed in the system to be diagnosed, based on security information about each device. A countermeasure identification unit identifies countermeasure plans to prevent the attacks and a cost required to implement the countermeasure plans.