Security Management System Automating Countermeasures by Influence Value

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems burden administrators with the decision to implement countermeasures against security intrusions, requiring them to consider business influences, which can be time-consuming and inefficient.

Innovation Solution

A security management system that monitors communication paths in a network, detects unauthorized communication, assesses the influence range, and automatically implements countermeasures based on a calculated influence value, reducing administrative burden by automating decisions when the impact is minimal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If security countermeasures are automatically implemented without administrator approval, then response speed is improved, but reliability deteriorates due to potential incorrect decisions affecting business operations

Engineering Contradiction:
Improveresponse speedVSAvoiddecision reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs self-evaluation by automatically assessing the influence of detected unauthorized communication on business operations and making autonomous decisions about countermeasure implementation. The influence evaluation unit calculates an influence value based on communication path importance, and the automatic implementation unit executes countermeasures when the influence value is below a threshold, enabling the system to serve itself without administrator intervention for low-impact incidents

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the parameter of administrator involvement from constant (always required) to variable (conditional). By introducing an influence value threshold parameter, the system dynamically adjusts whether administrator approval is needed based on the assessed impact of the security incident. When influence value < threshold, automatic implementation occurs; otherwise, administrator approval is sought

Inventive Principle:
Principle #35Parameter changes

2Reliability

If administrator approval is required for all countermeasures, then reliability is improved, but productivity deteriorates due to delayed response

Engineering Contradiction:
Improvedecision reliabilityVSAvoidcountermeasure implementation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The decision-making process is segmented into two distinct paths: automatic implementation for low-impact incidents and administrator approval for high-impact incidents. The influence evaluation unit segments countermeasures based on calculated influence values, routing them to appropriate handling procedures. This segmentation allows routine, low-risk countermeasures to be implemented quickly while reserving administrator review for critical decisions

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If the system automatically implements countermeasures, then ease of operation is improved, but device complexity increases due to additional evaluation and decision-making components

Engineering Contradiction:
Improveoperational simplicityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The influence evaluation unit and automatic implementation unit are merged into the existing security management system architecture. The influence evaluation functionality is integrated with the communication monitoring and countermeasure generation components, creating a unified system that automatically assesses impact and executes decisions without requiring separate external evaluation tools or complex external approval workflows

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12153672B2Security management system and security management method
Publication Date: 2024.11.26 HITACHI LTD
  • US12153672B2 patent drawing
  • US12153672B2 patent drawing
  • US12153672B2 patent drawing

AI summary

In a security management system, communication paths used for communication between business devices constituting a monitoring target system and a business communication importance which is information indicating an importance of each of the communication paths are stored, communication performed in the monitoring target system is monitored, when unauthorized communication performed in the monitoring target system is detected, a communication path used for the unauthorized communication is specified, and an influence range of the unauthorized communication on the monitoring target system is specified based on the specified communication path, the communication path having a possibility of being influenced when the countermeasure is implemented is specified, an influence value which is an index indicating a degree of influence of the countermeasure on the business is obtained, and whether or not to automatically implement the countermeasure is determined based on the influence value.