Security Analysis Device Threat Likelihood Calculation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security risk assessment methods for IT systems and IoT devices rely heavily on individual skills, leading to variable results and a high degree of subjectivity in determining the likelihood of threat occurrence.
Innovation Solution
A security analysis device that calculates the likelihood of threat occurrence by comparing the similarity between an attack scenario and a past scenario, reducing dependence on individual skills and providing a more objective assessment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security analysis is performed using traditional methods with subjective judgment, then the analysis can be completed with simple tools, but the results vary depending on the analyst's individual skills and judgment
Solution Approach 1:
The patent replaces the mechanical system of human analyst judgment with an automated AI-based system. The AI model processes attack scenarios and historical data to calculate threat likelihood objectively, eliminating the variability introduced by different analysts' skills and experiences while maintaining systematic analysis procedures.
Solution Approach 2:
The patent creates a digital copy of historical attack scenarios and analyst judgments in the form of training data for the AI model. By training the AI on past attack patterns and established analysis criteria, the system replicates and extends human expertise without the variability inherent in individual analyst performance.
2Measurement precision
If detailed security analysis is performed with thorough evaluation of indicators, then the accuracy of threat assessment improves, but the time required for analysis increases
Solution Approach 1:
The patent performs preliminary action by pre-processing and storing historical attack scenarios, indicator data, and analysis criteria in a structured database that trains the AI model. This preparation allows the system to rapidly analyze new threats by retrieving and processing relevant historical patterns instantly, avoiding the time-consuming manual review process.
Solution Approach 2:
The AI system automatically performs the time-consuming tasks of evaluating multiple indicators, comparing attack scenarios against historical data, and synthesizing threat likelihood assessments. This automated processing achieves high measurement precision through comprehensive data analysis while dramatically reducing the time required compared to manual analyst evaluation.
3Adaptability or versatility
If qualitative criteria are used for setting indicator values, then the analysis remains flexible and adaptable, but the subjectivity and dependence on individual skills increases
Solution Approach 1:
The patent transforms qualitative criteria into quantitative parameters by training the AI model on structured data representing attack scenarios and their outcomes. The model learns to assign numerical weights and probabilities to different indicators based on historical patterns, converting subjective qualitative judgments into objective quantitative assessments that maintain analytical flexibility while eliminating individual skill dependence.
Solution Approach 2:
The system copies and digitizes the knowledge embedded in qualitative criteria and historical judgments into the AI model's training data. This allows the system to replicate the adaptability of human analysts in evaluating diverse security scenarios while producing consistent, objective results through automated pattern recognition and calculation.
Data Source
AI summary
A scenario analysis unit (22) identifies an attack scenario indicating a chronological sequence of attack methods up to occurrence of a threat that may occur in a constituent element of a system. A past case collection unit (231) collects information on attack cases that have occurred in the past. A past case analysis unit (232) identifies a past scenario indicating a chronological sequence of attack methods for each attack case. A likelihood calculation unit (233) calculates a similarity between the attack scenario and the past scenario. Then, the likelihood calculation unit (233) calculates a likelihood of occurrence of the threat based on the similarity.


