Pseudo Trace Generator for Cyber Attack Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures for evaluating cyber attack detection and prevention in systems require actual system attacks, which can be detrimental and unnecessary, posing risks to the system's integrity.
Innovation Solution
An information processing device that generates and transmits pseudo trace information based on attack scenarios and trace data to simulate attacks, allowing evaluation of detection capabilities without actual system compromise, using a pseudo trace generator and transmitter to feed evaluation target devices with simulated communication data or logs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If actual attacks are executed on the system to evaluate security measures, then detection capability can be assessed, but system integrity and safety are compromised
Solution Approach 1:
The patent creates a virtualized attack simulation environment that copies attack behaviors and trace information without executing actual attacks on the target system. The virtual machine generates pseudo trace information that mimics real attack patterns, allowing security measures to be evaluated while preserving system integrity.
Solution Approach 2:
The patent introduces a virtual machine as an intermediary between the attack simulator and the target system. This intermediary generates and transmits pseudo trace information that represents attack behaviors without directly attacking the target system, thus enabling safe evaluation of security measures.
2Reliability
If actual attacks are performed to evaluate security settings, then real detection performance is measured, but unnecessary system interference occurs
Solution Approach 1:
The virtual machine copies attack trace information and generates pseudo trace information that replicates attack patterns without actually executing attacks. This allows reliable evaluation of security settings while avoiding unauthorized system interference.
Solution Approach 2:
The system performs preliminary actions by pre-generating attack scenarios and trace information in the virtual machine before evaluating security measures. This preliminary preparation allows the actual evaluation to use simulated data, avoiding the need for real attacks.
3Measurement precision
If real attack data is collected for evaluation, then accurate detection testing is possible, but system security is compromised
Solution Approach 1:
The patent copies attack trace information from real attacks into a virtual machine environment, where pseudo trace information is generated for evaluation purposes. This maintains measurement precision for detection testing while preserving system security by preventing actual attacks.
Solution Approach 2:
The system extracts attack trace information from real attack scenarios and separates it into a virtualized environment. This extraction allows the trace information to be used for evaluation without compromising the original system security.
Data Source
AI summary
According to one embodiment, an information processing device includes: a pseudo trace generator configured to employ trace information of a first attack acquired when the first attack is executed on a first apparatus in a communication network and attack method information related to an attack method of a second attack on a second apparatus to generate pseudo trace information of the second attack; and a pseudo trace transmitter configured to transmit the pseudo trace information of the second attack to an evaluation target device which detects an attack based on trace information of the attack.


