Threat Analysis System with Adoption-Based Recommendation Degrees

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat analysis methods for cyberattacks on mobile entities, such as in-vehicle systems, lack the ability to effectively output appropriate countermeasures and their recommendations, leading to inefficiencies and inconsistencies in security risk management.

Innovation Solution

A threat analysis method and system that obtain threat analysis results, determine multiple countermeasures based on these results, and calculate degrees of recommendation using an adoption database containing past adoption results of countermeasures, thereby presenting the countermeasures with associated recommendation degrees to users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional threat analysis methods are used to analyze cyberattack threats on mobile entities, then threat analysis can be performed, but the ability to output appropriate countermeasures with recommendations is insufficient

Engineering Contradiction:
Improvecountermeasure determination reliabilityVSAvoidcountermeasure output capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system establishes a feedback mechanism by collecting adoption results of countermeasures from multiple users and feeding them back into the recommendation degree calculation. The recommendation degree is dynamically adjusted based on how many users have adopted each countermeasure, creating a self-improving system that becomes more reliable over time as more adoption data is accumulated.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables automatic generation of recommended countermeasures with recommendation degrees without requiring manual expert evaluation for each case. The adoption database automatically serves as the evaluation basis, allowing the system to self-evaluate and self-improve its countermeasure recommendations based on accumulated user adoption patterns.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If multiple countermeasures are determined based on threat analysis results, then comprehensive security coverage is achieved, but determining the most appropriate countermeasure becomes difficult

Engineering Contradiction:
Improvecountermeasure coverageVSAvoidcountermeasure selection
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system applies a visual metaphor by assigning different recommendation degrees (effectively different 'colors' or levels) to multiple countermeasures. This allows users to quickly distinguish and select the most appropriate countermeasure based on the recommendation degree indicator, transforming a complex selection problem into an intuitive visual comparison.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

Instead of requiring users to evaluate all aspects of multiple countermeasures equally, the system provides a simplified indicator (recommendation degree) that captures the essential selection criterion. This partial information approach allows users to make quick decisions without being overwhelmed by the complexity of evaluating multiple comprehensive countermeasures.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If countermeasures are determined without reference to past adoption results, then analysis speed is maintained, but the appropriateness of countermeasures decreases

Engineering Contradiction:
Improveanalysis speedVSAvoidcountermeasure appropriateness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary analysis by pre-calculating recommendation degrees based on past adoption results stored in the database. When a new threat analysis is performed, the system can quickly retrieve and apply pre-computed recommendation information, maintaining fast analysis speed while incorporating the wisdom of past adoption decisions without performing time-consuming real-time evaluations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250080555A1Threat analysis method, threat analysis system and recording medium
Publication Date: 2025.03.06 PANASONIC AUTOMOTIVE SYST CO LTD
  • US20250080555A1 patent drawing
  • US20250080555A1 patent drawing
  • US20250080555A1 patent drawing

AI summary

A threat analysis method is a threat analysis method to be executed in a threat analysis system that presents a countermeasure against a threat of a cyberattack on a monitored object based on an analysis result of the cyberattack. The threat analysis method includes: obtaining a threat analysis result after analysis of a threat of a cyberattack on the monitored object; determining a plurality of countermeasures against the threat based on the threat analysis result; determining degrees of recommendation of the plurality of countermeasures determined, based on an adoption database containing adoption results of the plurality of countermeasures from the past; and outputting the plurality of countermeasures determined in association with the degrees of recommendation, and presenting the plurality of countermeasures to a user.