Pseudo Trace Generator for Cyber Attack Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for evaluating cyber attack detection and prevention in systems require actual system attacks, which can be detrimental and unnecessary, posing risks to the system's integrity.

Innovation Solution

An information processing device that generates and transmits pseudo trace information based on attack scenarios and trace data to simulate attacks, allowing evaluation of detection capabilities without actual system compromise, using a pseudo trace generator and transmitter to feed evaluation target devices with simulated communication data or logs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If actual attacks are executed on the system to evaluate security measures, then detection capability can be assessed, but system integrity and safety are compromised

Engineering Contradiction:
Improvedetection capability assessmentVSAvoidsystem integrity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent creates a virtualized attack simulation environment that copies attack behaviors and trace information without executing actual attacks on the target system. The virtual machine generates pseudo trace information that mimics real attack patterns, allowing security measures to be evaluated while preserving system integrity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a virtual machine as an intermediary between the attack simulator and the target system. This intermediary generates and transmits pseudo trace information that represents attack behaviors without directly attacking the target system, thus enabling safe evaluation of security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If actual attacks are performed to evaluate security settings, then real detection performance is measured, but unnecessary system interference occurs

Engineering Contradiction:
Improvesecurity measure evaluation accuracyVSAvoidunauthorized system interference
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The virtual machine copies attack trace information and generates pseudo trace information that replicates attack patterns without actually executing attacks. This allows reliable evaluation of security settings while avoiding unauthorized system interference.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary actions by pre-generating attack scenarios and trace information in the virtual machine before evaluating security measures. This preliminary preparation allows the actual evaluation to use simulated data, avoiding the need for real attacks.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If real attack data is collected for evaluation, then accurate detection testing is possible, but system security is compromised

Engineering Contradiction:
Improvedetection testing accuracyVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent copies attack trace information from real attacks into a virtual machine environment, where pseudo trace information is generated for evaluation purposes. This maintains measurement precision for detection testing while preserving system security by preventing actual attacks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system extracts attack trace information from real attack scenarios and separates it into a virtualized environment. This extraction allows the trace information to be used for evaluation without compromising the original system security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240422176A1Information processing device and information processing method
Publication Date: 2024.12.19 KK TOSHIBA
  • US20240422176A1 patent drawing
  • US20240422176A1 patent drawing
  • US20240422176A1 patent drawing

AI summary

According to one embodiment, an information processing device includes: a pseudo trace generator configured to employ trace information of a first attack acquired when the first attack is executed on a first apparatus in a communication network and attack method information related to an attack method of a second attack on a second apparatus to generate pseudo trace information of the second attack; and a pseudo trace transmitter configured to transmit the pseudo trace information of the second attack to an evaluation target device which detects an attack based on trace information of the attack.