Security Measure Mapping by Kill Chain and Compliance Rules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to accurately identify and present appropriate security measures in compliance with various security laws and regulations, lacking a mechanism to ensure the adequacy of automatically identified measures.

Innovation Solution

A system that includes a computer with an arithmetic device and storage device, connected to input and display devices, to associate rule information with measure information, receive user input, and extract and transmit appropriate security measures based on user input, using databases to manage laws and regulations and cybersecurity knowledge.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing technologies are used to manage information assets, then basic importance degree information can be tracked, but accurate identification of appropriate security measures in compliance with security laws and regulations cannot be achieved

Engineering Contradiction:
Improveaccuracy of security measure identificationVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments security measure identification into distinct phases corresponding to kill chain phases (reconnaissance, weaponization, delivery, exploitation, installation, command and control, actions on objectives). Each phase is associated with specific attack techniques and countermeasures, allowing precise identification of appropriate security measures for each stage of a potential cyberattack while maintaining manageable system complexity through structured organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism that connects rule information (security laws and regulations) with measure information (security countermeasures) through required items. This intermediary structure enables accurate identification of compliance-appropriate security measures by mapping regulatory requirements to specific technical countermeasures without requiring direct complex integration of all regulatory texts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If automatic identification of security measures is implemented, then productivity increases, but accuracy regarding adequacy of identified measures deteriorates

Engineering Contradiction:
Improveefficiency of security measure identificationVSAvoidadequacy of security measures
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary organization of security measure information by kill chain phases, attack techniques, and required items before actual security assessment. This pre-structuring of data enables rapid automatic retrieval and identification of appropriate measures during compliance assessments, maintaining both high productivity and reliability through advance preparation of the knowledge base.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms that allow users to provide input operations regarding the identified security measures. The arithmetic device extracts and refines measures based on this feedback, continuously improving the adequacy and accuracy of identified security measures while maintaining efficient automatic identification through iterative refinement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20260067329A1System and method for presenting security measures
Publication Date: 2026.03.05 HITACHI LTD
  • US20260067329A1 patent drawing
  • US20260067329A1 patent drawing
  • US20260067329A1 patent drawing

AI summary

The security measures presenting system presents information indicating security measures by displaying the information on a display device. The security measures presenting system is configured of a computer which includes at least an arithmetic device and a storage device, and is mutually connected to an input device and the display device outside the computer in a manner capable of mutual data communication. The storage device stores rule information with respect to a rule concerning security, the rule information including at least a target system indicating a targeted system to which a security measure is to be applied, and required items for a component included in the target system; and measure information indicating a kill chain phase which represents an execution phase of an attack, an attack technique which represents an attack method to be used in the kill chain phase, and measures for defending and/or alleviating the attack technique.