Security Determination Device Attack Path Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automated secure system design techniques face inefficiencies in generating secure system configurations due to the need for extensive evaluation of multiple plans, leading to long processing times and high rejection rates of insecure configurations before arriving at a secure design.
Innovation Solution
A security determination device and method that comprehensively generates and evaluates attack paths within system configurations, determining their validity to assess the security of the system, allowing for the implementation of countermeasures and efficient identification of secure configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple system configuration plans are generated and evaluated sequentially, then security determination can be performed, but processing time increases significantly
Solution Approach 1:
The patent applies preliminary action by evaluating attack paths before finalizing system configuration plans. The security determination device proactively identifies potential attack paths and evaluates their validity during the configuration generation process, allowing insecure configurations to be rejected early without requiring extensive sequential evaluation of multiple plans, thus reducing overall processing time while maintaining security determination accuracy
2Reliability
If concrete system configurations are evaluated after generation, then security can be assessed, but large numbers of insecure configurations are rejected leading to low productivity
Solution Approach 1:
The patent implements feedback by continuously evaluating attack path validity during the system configuration generation process. The security determination device provides immediate feedback on whether generated configurations contain valid attack paths, allowing the generation process to adjust and produce secure configurations more efficiently, thereby increasing productivity while maintaining complete security evaluation
3Reliability
If attack path evaluation is performed comprehensively, then security determination is accurate, but the complexity of the evaluation process increases
Solution Approach 1:
The patent applies segmentation by dividing the attack path evaluation process into distinct manageable components: threat identification, attack path generation, validity evaluation, and security determination. This segmented approach maintains comprehensive security determination precision while reducing the perceived complexity by organizing the evaluation process into clear, sequential stages that can be implemented systematically
Data Source
AI summary
A security determination device comprehensively generates an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established; determines the validity of the attack path; and determines whether a system configuration is secure or insecure, depending on the validity of the attack path.


