Security Determination Device Attack Path Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing automated secure system design techniques face inefficiencies in generating secure system configurations due to the need for extensive evaluation of multiple plans, leading to long processing times and high rejection rates of insecure configurations before arriving at a secure design.

Innovation Solution

A security determination device and method that comprehensively generates and evaluates attack paths within system configurations, determining their validity to assess the security of the system, allowing for the implementation of countermeasures and efficient identification of secure configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple system configuration plans are generated and evaluated sequentially, then security determination can be performed, but processing time increases significantly

Engineering Contradiction:
Improvesecurity determination accuracyVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by evaluating attack paths before finalizing system configuration plans. The security determination device proactively identifies potential attack paths and evaluates their validity during the configuration generation process, allowing insecure configurations to be rejected early without requiring extensive sequential evaluation of multiple plans, thus reducing overall processing time while maintaining security determination accuracy

Inventive Principle:
Principle #10Preliminary action

2Reliability

If concrete system configurations are evaluated after generation, then security can be assessed, but large numbers of insecure configurations are rejected leading to low productivity

Engineering Contradiction:
Improvesecurity evaluation completenessVSAvoidsecure configuration generation rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements feedback by continuously evaluating attack path validity during the system configuration generation process. The security determination device provides immediate feedback on whether generated configurations contain valid attack paths, allowing the generation process to adjust and produce secure configurations more efficiently, thereby increasing productivity while maintaining complete security evaluation

Inventive Principle:
Principle #23Feedback

3Reliability

If attack path evaluation is performed comprehensively, then security determination is accurate, but the complexity of the evaluation process increases

Engineering Contradiction:
Improvesecurity determination precisionVSAvoidevaluation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the attack path evaluation process into distinct manageable components: threat identification, attack path generation, validity evaluation, and security determination. This segmented approach maintains comprehensive security determination precision while reducing the perceived complexity by organizing the evaluation process into clear, sequential stages that can be implemented systematically

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240422188A1Security determination device, secure system design device, security determination method, and non-transitory storage medium
Publication Date: 2024.12.19 NEC CORP
  • US20240422188A1 patent drawing
  • US20240422188A1 patent drawing
  • US20240422188A1 patent drawing

AI summary

A security determination device comprehensively generates an attack path, which is a chained route of a threat showing execution steps of an attack to be prevented from being established; determines the validity of the attack path; and determines whether a system configuration is secure or insecure, depending on the validity of the attack path.