Network Topology Vulnerability Visualization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security administrators face challenges in understanding the impact of known vulnerabilities on systems to be diagnosed, as existing systems lack effective visualization and analysis tools to assess and communicate vulnerability risks within network topologies.

Innovation Solution

An analysis system comprising a topology identification unit, an analysis unit, and a display control unit that generates and displays attack patterns on a network topology, highlighting segments where attacks can occur, with display modes changing based on vulnerability types, enabling administrators to visualize and understand vulnerability impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If attack patterns are displayed on network topology, then security administrators can understand vulnerability impact, but display complexity increases

Engineering Contradiction:
Improvevulnerability impact understandingVSAvoiddisplay system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The attack pattern information is segmented into distinct components: attack conditions, attack results, attack means (vulnerabilities), and segments where attacks can occur. Each segment is independently identified and displayed on the network topology, allowing administrators to understand vulnerability impacts without overwhelming display complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different display modes are applied to different segments based on the type of vulnerability that corresponds to the attack means. This local differentiation allows the system to highlight specific vulnerability impacts (e.g., using different colors or symbols for different vulnerability types) while maintaining overall display manageability.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If multiple vulnerability types are displayed with different modes, then vulnerability assessment precision improves, but information processing complexity increases

Engineering Contradiction:
Improvevulnerability assessment precisionVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies different display modes to different segments based on vulnerability types. Each vulnerability type (e.g., authentication vulnerabilities, buffer overflows, SQL injection) is assigned a specific display mode, enabling precise vulnerability assessment while managing information processing complexity through systematic categorization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The display control unit changes display modes of segments according to vulnerability types, which may include using different colors, symbols, or visual indicators to represent different vulnerability categories. This visual differentiation improves assessment precision while keeping the system manageable through consistent visual coding.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS12149554B2Analysis system, method, and program
Publication Date: 2024.11.19 NEC CORP
  • US12149554B2 patent drawing
  • US12149554B2 patent drawing
  • US12149554B2 patent drawing

AI summary

Provided is an analysis system that allows a security administrator to understand the impact of known vulnerabilities on the system to be diagnosed. The topology identification unit 14 identifies network topology of devices included in a system to be diagnosed. The analysis unit 6 generates an attack pattern that includes an attack condition, an attack result, an attack means that is vulnerability that is used by an attack, and a segment where the attack can occur in the system to be diagnosed. The display control unit 8 displays segments included in attack patterns superimposed on the network topology, on a display device. At this time, the display control unit 8 changes a display mode of the segment according to a type of the vulnerability that corresponds to the attack means included in the attack pattern including the segment.