Security Risk Analysis Apparatus for Data Flow Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security risk analysis techniques, such as vulnerability assessment and penetration testing, face challenges in comprehensively understanding undefined vulnerabilities and incurring high costs and time when analyzing entire systems, particularly in determining the validity of data handling due to security issues not caused by attacks or failures, and in validating data transport routes generated based on operational specifications rather than actual program behavior.

Innovation Solution

An analysis apparatus and method that collect historical information on program operations, add external information, and perform risk determining processing to assess security risks based on preset conditions, enabling the evaluation of actual data flows and security validity within systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability assessment is performed to comprehensively verify the entire system, then security coverage is improved, but time and cost increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts and focuses analysis on critical data transport routes rather than performing comprehensive system-wide vulnerability assessment. By identifying and isolating the most important data flow paths, the system achieves effective security verification without the time and resource costs of complete system analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the system into distinct data transport routes and analyzes each route separately based on operational specifications. This segmentation allows for targeted security analysis of critical paths while avoiding unnecessary analysis of non-critical system components, thereby reducing overall analysis time while maintaining security coverage.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If penetration test is performed to verify specific invasion manner, then attack scenario verification is improved, but cost and time increase when comprehensively analyzing the system

Engineering Contradiction:
Improveattack scenario verificationVSAvoidcomprehensive analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent extracts specific attack scenarios relevant to identified data transport routes and performs penetration testing only on those extracted scenarios. This approach maintains high measurement precision for verifying attack scenarios while avoiding the time consumption of comprehensive system-wide penetration testing.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If data transport route is generated based on operational specification information, then security policy validation is improved, but actual data flow validation deteriorates

Engineering Contradiction:
Improvesecurity policy validationVSAvoidactual data flow validation
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent merges theoretical data transport routes (based on operational specifications) with actual observed data flows. By combining both specification-based validation and actual behavior monitoring, the system achieves both security policy validation and accurate actual data flow validation simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If operational specification is described in detail to reduce defeat for data transport route, then validation accuracy is improved, but cost and time required for analyzing security risk increase

Engineering Contradiction:
Improvevalidation accuracyVSAvoidsecurity risk analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by describing operational specifications only for critical data transport routes rather than detailing all system operations. This selective approach maintains validation accuracy for the most important security paths while avoiding the time and resource expenditure of comprehensive detailed specification description.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240146757A1Analysis apparatus, analysis system, analysis method and analysis program
Publication Date: 2024.05.02 NEC CORP
  • US20240146757A1 patent drawing
  • US20240146757A1 patent drawing
  • US20240146757A1 patent drawing

AI summary

It is determined whether to involve the security risk based on the data flow in the system to be analyzed. An analysis apparatus 1A a historical information collecting unit 220A configured to collect historical information on an operational history for a program executed in a system to be analyzed, an information adding unit 230 configured to add to the historical information, external information obtained from an information resource other than an information processing apparatus that executes the program, and a risk determining unit 180A configured to perform a risk determining processing for determining based on preset determining condition, whether to involve security risk in the historical information to which the external information is added.