Threat Analysis System with Adoption-Based Recommendation Degrees
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat analysis methods for cyberattacks on mobile entities, such as in-vehicle systems, lack the ability to effectively output appropriate countermeasures and their recommendations, leading to inefficiencies and inconsistencies in security risk management.
Innovation Solution
A threat analysis method and system that obtain threat analysis results, determine multiple countermeasures based on these results, and calculate degrees of recommendation using an adoption database containing past adoption results of countermeasures, thereby presenting the countermeasures with associated recommendation degrees to users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional threat analysis methods are used to analyze cyberattack threats on mobile entities, then threat analysis can be performed, but the ability to output appropriate countermeasures with recommendations is insufficient
Solution Approach 1:
The system establishes a feedback mechanism by collecting adoption results of countermeasures from multiple users and feeding them back into the recommendation degree calculation. The recommendation degree is dynamically adjusted based on how many users have adopted each countermeasure, creating a self-improving system that becomes more reliable over time as more adoption data is accumulated.
Solution Approach 2:
The system enables automatic generation of recommended countermeasures with recommendation degrees without requiring manual expert evaluation for each case. The adoption database automatically serves as the evaluation basis, allowing the system to self-evaluate and self-improve its countermeasure recommendations based on accumulated user adoption patterns.
2Adaptability or versatility
If multiple countermeasures are determined based on threat analysis results, then comprehensive security coverage is achieved, but determining the most appropriate countermeasure becomes difficult
Solution Approach 1:
The system applies a visual metaphor by assigning different recommendation degrees (effectively different 'colors' or levels) to multiple countermeasures. This allows users to quickly distinguish and select the most appropriate countermeasure based on the recommendation degree indicator, transforming a complex selection problem into an intuitive visual comparison.
Solution Approach 2:
Instead of requiring users to evaluate all aspects of multiple countermeasures equally, the system provides a simplified indicator (recommendation degree) that captures the essential selection criterion. This partial information approach allows users to make quick decisions without being overwhelmed by the complexity of evaluating multiple comprehensive countermeasures.
3Productivity
If countermeasures are determined without reference to past adoption results, then analysis speed is maintained, but the appropriateness of countermeasures decreases
Solution Approach 1:
The system performs preliminary analysis by pre-calculating recommendation degrees based on past adoption results stored in the database. When a new threat analysis is performed, the system can quickly retrieve and apply pre-computed recommendation information, maintaining fast analysis speed while incorporating the wisdom of past adoption decisions without performing time-consuming real-time evaluations.
Data Source
AI summary
A threat analysis method is a threat analysis method to be executed in a threat analysis system that presents a countermeasure against a threat of a cyberattack on a monitored object based on an analysis result of the cyberattack. The threat analysis method includes: obtaining a threat analysis result after analysis of a threat of a cyberattack on the monitored object; determining a plurality of countermeasures against the threat based on the threat analysis result; determining degrees of recommendation of the plurality of countermeasures determined, based on an adoption database containing adoption results of the plurality of countermeasures from the past; and outputting the plurality of countermeasures determined in association with the degrees of recommendation, and presenting the plurality of countermeasures to a user.


