Ship Cyberattack Scenario Modeling for Maritime Attack Path Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyberattack scenario development techniques fail to account for the unique characteristics of maritime vessels, particularly ship communication protocols and hardware/software, and lack comprehensive visualization of attack paths and potential attack surfaces.

Innovation Solution

A method and system that combines a cyberattack tree (CAT) model with a diamond analysis model to create a ship attack scenario model, visualizing all attack paths and identifying potential attack surfaces through analysis of intrusion techniques, attack techniques, attributes, and impacts, using the MITRE ATT&CK Framework and maritime threat intelligence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional cyberattack scenario development techniques are used, then general cybersecurity scenarios can be created, but they fail to account for unique characteristics of maritime vessels such as ship communication protocols and hardware/software

Engineering Contradiction:
Improveadaptability to maritime vessel characteristicsVSAvoidaccuracy of attack scenario representation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by customizing the attack scenario model to specifically represent maritime vessel characteristics such as ship communication protocols (e.g., NAVTEX, Inmarsat), onboard computer systems, and marine equipment. Instead of using generic cyberattack scenarios, the model locally adapts attack paths and techniques to match the unique infrastructure and communication architecture of ships, thereby improving both adaptability and representation accuracy.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent achieves universality by creating a standardized attack scenario model that can be applied across different types of maritime vessels while maintaining specificity for each vessel type. The model serves multiple functions: it represents attack paths for various ship systems, provides a basis for security assessments, and enables comparative analysis across different vessel types, thus achieving both specificity and broad applicability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If cyberattack trees (CATs) are used to visualize attack processes, then attack paths can be represented, but the attack process appears linear and hierarchical limiting the explanation of interconnected relationships

Engineering Contradiction:
Improvevisualizability of attack pathsVSAvoidcomplexity of attack relationship representation
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the cyberattack tree (CAT) model with additional relational modeling techniques to combine linear attack path visualization with interconnected relationship representation. This hybrid approach integrates the structured hierarchy of CATs with network-like relationship mappings, allowing simultaneous representation of sequential attack steps and parallel/interconnected attack vectors, thereby reducing the limitation of purely linear hierarchical structures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces another dimension to attack path representation by transitioning from purely linear sequential attacks to multi-dimensional attack scenarios that include parallel attack vectors, interconnected attack paths, and simultaneous attack phases. This dimensional expansion allows the model to represent complex interrelationships among attacks while maintaining visualizability through structured graphical representations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Quantity of substance

If semantic graphs are used to represent attack data, then comprehensive attack relationships can be captured, but the graph becomes complex and difficult to interpret upon increase in amount of data

Engineering Contradiction:
Improveamount of attack data capturedVSAvoidinterpretability of attack graph
Core Design Contradiction:
Quantity of substanceVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the attack graph into manageable components such as attack paths, attack trees, and relationship maps that can be processed and interpreted separately. By dividing the comprehensive attack data into structured segments (e.g., initial access phase, execution phase, persistence phase), the model maintains comprehensive data capture while improving interpretability through organized presentation and hierarchical decomposition of complex relationships.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4723549A1Method and system for developing cyber attack scenario for ship
Publication Date: 2026.04.08 HANWHA OCEAN CO LTD (KR)
  • EP4723549A1 patent drawingFigure 1
  • EP4723549A1 patent drawingFigure 2
  • EP4723549A1 patent drawingFigure 3

AI summary

The present invention provides a method and system for developing a cyberattack scenario for a ship, which are capable of: creating a ship attack scenario model to visualize all paths for an attacker to penetrate an attack target through an attack graph; and capturing the range of attack technology and characteristics to identify a potential attack surface.