Security Design Support Device for Threat Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As the number of assets, system components, and communication paths increases, the complexity of threat scenarios in threat analysis grows exponentially, leading to a huge volume of analysis. This complexity often results in insufficient risk reduction when assessments of threats involving takeover are omitted.
Innovation Solution
A security design support device is configured to input system information, generate threat scenarios, assess risk levels, estimate takeover possibilities, and output secondary threat scenarios. This device reduces the amount of analysis by focusing on significant threat scenarios, including multi-hop threats, by filtering out scenarios with low feasibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive threat analysis is performed on all system components and communication paths, then risk reduction is improved, but analysis complexity and time consumption increase exponentially
Solution Approach 1:
The patent segments the threat analysis process into two distinct phases: first analyzing threats to individual subsystems, then analyzing threats that span across multiple subsystems (multi-hop threats). This segmentation allows the complex overall analysis to be broken down into manageable parts, reducing the exponential complexity while maintaining comprehensive risk coverage.
Solution Approach 2:
The patent performs preliminary analysis by first identifying and assessing threats to individual subsystems before proceeding to analyze multi-hop threats. By establishing a foundation of subsystem-level threat understanding first, the subsequent multi-hop analysis can focus specifically on cross-subsystem attack paths, thereby reducing overall analysis complexity while maintaining thoroughness.
2Reliability
If multi-hop threat scenarios are included in the analysis, then risk reduction is improved, but analysis volume increases significantly
Solution Approach 1:
The patent segments multi-hop threat analysis into structured steps: identifying subsystem threats first, then systematically analyzing attack paths that traverse multiple subsystems. This segmentation enables focused analysis on relevant multi-hop scenarios rather than exhaustive enumeration of all possible threat combinations, thereby reducing analysis time while maintaining comprehensive risk coverage.
Solution Approach 2:
The patent performs preliminary identification of subsystem threats and their characteristics before proceeding to multi-hop analysis. By having this foundational information ready, the multi-hop analysis can efficiently build upon it without repeating basic assessments, significantly reducing the time required for comprehensive threat analysis.
3Productivity
If low-feasibility threat scenarios are filtered out, then analysis efficiency is improved, but risk coverage may be reduced
Solution Approach 1:
The patent applies feasibility criteria as filtering parameters to eliminate low-feasibility threat scenarios from further analysis. By establishing and applying these feasibility parameters systematically, the patent maintains analysis efficiency while preserving coverage of significant threats that meet the feasibility threshold, thus balancing efficiency and comprehensiveness.
Data Source
AI summary
A security design support device is configured to input system information indicating a component of a system and including information indicating a subsystem; generate a first threat scenario indicating a security threat; obtain a risk level of the first threat scenario; estimate a takeover possibility that is a possibility that the subsystem is taken over using a second feasibility that is a feasibility of the first threat scenario when a necessary countermeasure is implemented against the first threat scenario of which the risk level is equal to or higher than a predetermined level; generate a second threat scenario indicating a security threat that occurs with the subsystem that is taken over as a starting point when the takeover possibility is equal to or higher than a predetermined level; and output the second threat scenario.


