Security Risk Analysis Using Vulnerability Database

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security risk analysis methods lack an objective index for evaluating threat levels, making it difficult for analysts to determine the appropriate threat level for each threat item.

Innovation Solution

A security risk analysis support apparatus that includes vulnerability specification means, diagnosis evaluation generation means, and output means. The apparatus refers to attack path information and a vulnerability information database to specify vulnerabilities and generate risk diagnosis evaluations, providing an objective index for evaluating risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual risk analysis is performed without objective indexes, then analysts can perform qualitative assessment, but the determination of threat level evaluation values becomes subjective and inconsistent

Engineering Contradiction:
Improvethreat level evaluation precisionVSAvoidrisk analysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system comprising a vulnerability information database and automated analysis apparatus that mediates between raw system data and threat level determination. This intermediary provides objective indexes (vulnerability counts, exploit code presence) that guide analysts in making consistent threat level assessments without requiring complex manual evaluation of each security parameter.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive vulnerability analysis is performed for each attack step, then accurate risk evaluation is achieved, but the analysis time and computational resources increase

Engineering Contradiction:
Improverisk evaluation accuracyVSAvoidanalysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-populating a vulnerability information database with known vulnerabilities and their associated exploit codes before actual risk analysis is needed. During analysis, the system automatically queries this pre-prepared database rather than performing comprehensive vulnerability scans from scratch, significantly reducing analysis time while maintaining evaluation accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates copies of vulnerability data from authoritative sources and stores them in the vulnerability information database. These copied vulnerability profiles can be quickly referenced and applied to multiple attack steps without repeating the original vulnerability discovery process, enabling efficient batch analysis of multiple attack paths.

Inventive Principle:
Principle #26Copying

3Reliability

If detailed attack path information is analyzed, then comprehensive vulnerability identification is achieved, but the complexity of processing and presenting results increases

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidresult processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex attack path analysis into discrete attack steps, each evaluated independently for vulnerability presence. The system processes each attack step separately, identifying vulnerabilities and exploit codes specific to that step, then aggregates results. This segmentation reduces processing complexity by breaking down the overall analysis into manageable units while maintaining comprehensive vulnerability identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality assessment by providing specific vulnerability information tailored to each attack step rather than a generic overall assessment. Each attack step receives customized analysis results including the number of vulnerabilities specific to that step and the presence of exploit codes relevant to that particular attack method, enabling targeted security improvements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12314399B2Security risk analysis assistance device, method, and computer-readable medium
Publication Date: 2025.05.27 NEC CORP
  • US12314399B2 patent drawing
  • US12314399B2 patent drawing
  • US12314399B2 patent drawing

AI summary

Attack path information includes information about an attack path including at least one attack step including an attack source, an attack destination, and an attack method. Vulnerability specification means refers to the attack path information and thereby specifies vulnerabilities exploitable by an attack on the attack destination in the attack step. In the vulnerability information DB, vulnerabilities and presence/absence of exploit codes for the vulnerabilities are stored and associated with each other. Diagnosis evaluation generation means refers to the vulnerability information DB, and thereby examines whether or not there is an exploit code for the specified vulnerability and generates, for the attack step, a risk diagnosis evaluation including the number of specified vulnerabilities and the presence/absence of the exploit codes therefor. Output means outputs the attack step and the risk diagnosis evaluation while associating them with each other.