Security Evaluation System Dual Graph Visualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security evaluation systems face difficulties in effectively assessing the risk of resource infections, such as those caused by the Stuxnet worm, as they struggle to grasp the impact of physical separation measures and implement countermeasures using traditional attack models.
Innovation Solution
A security evaluation system that generates and displays two types of graphs: a first evaluation graph representing resource connections and a second evaluation graph showing user relationships, allowing for a comprehensive assessment of potential attack paths and vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional attack models are used for security evaluation, then the evaluation process is simple, but the ability to grasp the impact of physical separation measures and assess resource infection risk is insufficient
Solution Approach 1:
The patent divides the security evaluation into two separate graph models: a first graph representing resource connections and a second graph representing user relationships. This segmentation allows each graph to focus on specific aspects of security evaluation, improving measurement precision while managing complexity through modular design
Solution Approach 2:
The patent adds a new dimension to security evaluation by introducing the second graph (user relationships) that complements the traditional first graph (resource connections). This multi-dimensional approach enables comprehensive assessment of both physical separation measures and personal relationship-based attack vectors
2Adaptability or versatility
If only resource connections are evaluated, then the evaluation scope is narrow, but the system complexity is low
Solution Approach 1:
The patent merges two different evaluation perspectives (resource connections and user relationships) into a unified security evaluation system. By combining the first graph and second graph, the system achieves comprehensive coverage of both technical and human factors in security risks
3Reliability
If physical separation measures are not considered, then the evaluation is easier, but the ability to assess actual security posture is insufficient
Solution Approach 1:
The patent creates a graphical representation (copy) of the physical separation measures through the first graph structure. By modeling resource connections and separation measures in graph form, the system makes invisible physical arrangements visible and measurable, improving evaluation reliability
Data Source
AI summary
This security evaluation system includes a first graph generation part that generates a first evaluation graph representing a connection relationship between resources as a target for security evaluation; a second graph generation part that generates a second evaluation graph representing a personal relationship between areas where the resources are located; and display part that displays the first evaluation graph and the second evaluation graph in association with each other.


