Security Analysis Assistance via Departmental Alert Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security analysis systems do not effectively reduce the administrative burden by visualizing traffic in units of departments, making it difficult to determine network risk, especially with the introduction of thin client services that obscure IP address departmental specifications.
Innovation Solution
A security analysis assistance apparatus and method that obtain alerts, organization address information specifying departments, compare alert occurrences by department, and visualize analysis results to facilitate departmental risk assessment in network systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If traffic is visualized in units of IP addresses on a network topology, then the administrator can quickly grasp unauthorized traffic, but it becomes difficult to specify a department by tracing the IP address of a terminal when thin client service is introduced
Solution Approach 1:
The patent introduces a thin client management server as an intermediary between the network traffic visualization system and the thin client terminals. This server maintains the mapping relationship between thin client terminal IDs and department information, allowing the visualization system to display departmental information without directly tracing IP addresses. The intermediary preserves departmental information that would otherwise be lost in thin client environments where IP addresses do not directly correspond to departments.
2Measurement precision
If manual analysis of alerts is performed using internal-organization information, then the administrator can determine the risk of the network system in units of departments, but the determination imposes a heavy burden on the administrator
Solution Approach 1:
The patent implements automatic visualization of alert occurrence tendencies by department using the thin client management server and the mapping information it maintains. Instead of requiring the administrator to manually analyze alerts and cross-reference them with department information, the system automatically performs this analysis and presents the results in a visual format. This self-service approach maintains precise departmental risk determination while eliminating the time burden on the administrator.
Data Source
AI summary
A security analysis assistance apparatus 10 is an apparatus for assisting security analysis in a network system of an organization. The security analysis assistance apparatus 10 includes: an analysis target obtaining unit 11 that obtains an alert generated in the network system; an information obtaining unit 12 that obtains organization address information specifying at least departments forming the organization and addresses used in the respective departments; an analysis unit 13 that compares the obtained alert with the organization address information, and analyzes the occurrence tendency of the alert for each department of the organization; and a visualization unit 14 that visualizes a result of the analysis performed by the analysis unit 13.


