Security Risk Analysis Using Vulnerability Database
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security risk analysis methods lack an objective index for evaluating threat levels, making it difficult for analysts to determine the appropriate threat level for each threat item.
Innovation Solution
A security risk analysis support apparatus that includes vulnerability specification means, diagnosis evaluation generation means, and output means. The apparatus refers to attack path information and a vulnerability information database to specify vulnerabilities and generate risk diagnosis evaluations, providing an objective index for evaluating risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual risk analysis is performed without objective indexes, then analysts can perform qualitative assessment, but the determination of threat level evaluation values becomes subjective and inconsistent
Solution Approach 1:
The patent introduces an intermediary system comprising a vulnerability information database and automated analysis apparatus that mediates between raw system data and threat level determination. This intermediary provides objective indexes (vulnerability counts, exploit code presence) that guide analysts in making consistent threat level assessments without requiring complex manual evaluation of each security parameter.
2Measurement precision
If comprehensive vulnerability analysis is performed for each attack step, then accurate risk evaluation is achieved, but the analysis time and computational resources increase
Solution Approach 1:
The patent implements preliminary action by pre-populating a vulnerability information database with known vulnerabilities and their associated exploit codes before actual risk analysis is needed. During analysis, the system automatically queries this pre-prepared database rather than performing comprehensive vulnerability scans from scratch, significantly reducing analysis time while maintaining evaluation accuracy.
Solution Approach 2:
The system creates copies of vulnerability data from authoritative sources and stores them in the vulnerability information database. These copied vulnerability profiles can be quickly referenced and applied to multiple attack steps without repeating the original vulnerability discovery process, enabling efficient batch analysis of multiple attack paths.
3Reliability
If detailed attack path information is analyzed, then comprehensive vulnerability identification is achieved, but the complexity of processing and presenting results increases
Solution Approach 1:
The patent segments the complex attack path analysis into discrete attack steps, each evaluated independently for vulnerability presence. The system processes each attack step separately, identifying vulnerabilities and exploit codes specific to that step, then aggregates results. This segmentation reduces processing complexity by breaking down the overall analysis into manageable units while maintaining comprehensive vulnerability identification.
Solution Approach 2:
The system applies local quality assessment by providing specific vulnerability information tailored to each attack step rather than a generic overall assessment. Each attack step receives customized analysis results including the number of vulnerabilities specific to that step and the presence of exploit codes relevant to that particular attack method, enabling targeted security improvements.
Data Source
AI summary
Attack path information includes information about an attack path including at least one attack step including an attack source, an attack destination, and an attack method. Vulnerability specification means refers to the attack path information and thereby specifies vulnerabilities exploitable by an attack on the attack destination in the attack step. In the vulnerability information DB, vulnerabilities and presence/absence of exploit codes for the vulnerabilities are stored and associated with each other. Diagnosis evaluation generation means refers to the vulnerability information DB, and thereby examines whether or not there is an exploit code for the specified vulnerability and generates, for the attack step, a risk diagnosis evaluation including the number of specified vulnerabilities and the presence/absence of the exploit codes therefor. Output means outputs the attack step and the risk diagnosis evaluation while associating them with each other.


