Network Segment Attack Resistance Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques face challenges in accurately evaluating resistance against cyber attacks in systems with multi-level network segments, as they struggle to reflect the unique characteristics of normal communication data and attack paths within these complex systems.
Innovation Solution
An information processing device that associates normal communication data models with each network segment, predicts communication data based on attack scenarios, and calculates an effectiveness degree by determining the similarity between predicted and normal communication data, thereby evaluating attack scenarios with high accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional techniques use a single normal-state model to evaluate cyber attacks, then the evaluation process is simple, but the accuracy of evaluating resistance against cyber attacks in multi-level network segments is insufficient
Solution Approach 1:
The patent divides the network into multiple network segments and creates a separate normal communication data model for each segment. This segmentation allows the system to accurately evaluate attack resistance in multi-level networks by comparing attack communication data against segment-specific normal models, resolving the contradiction between evaluation accuracy and system complexity.
2Measurement precision
If conventional techniques compare attack samples with normal-state models, then the evaluation method is straightforward, but it fails to identify effective attack scenarios hidden within normal communication patterns
Solution Approach 1:
The patent applies local quality by creating specialized normal communication data models tailored to each network segment's specific communication characteristics. This allows the system to detect hidden attack patterns by comparing against segment-specific baselines, improving attack scenario identification accuracy while accounting for the unique properties of different network areas.
Solution Approach 2:
The system uses feedback by continuously comparing actual communication data against normal-state models and using the results to refine attack detection. This feedback mechanism enables the system to identify effective attack scenarios by detecting deviations from normal patterns while adapting to changing communication behaviors.
Data Source
AI summary
An attack control device according to an embodiment is provided with a storage unit and one or more hardware processors configured to function as a selection unit, a determination unit, and a calculation unit. The storage unit associates and stores a normal communication data model representing a model of communication data of a normal system, with each network segment. The selection unit specifies the network segment based on the communication prediction data predicted upon execution of the attack scenario and selects the normal communication data model associated with the network segment. The determination unit determines the similarity degree between the normal communication data represented by the normal communication data model, and the communication prediction data. The calculation unit calculates an effectiveness degree of the attack scenario to be higher as the similarity degree is higher.


