Trace Identification Unit for Cyberattack Log Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cyber security exercise systems require manual intervention for participants to identify correct attack logs from collected logs, which is burdensome and inefficient for improving skills.

Innovation Solution

An information processing apparatus and method that automatically identifies traces of cyberattacks from logs using history data, including a trace identification unit that acquires and analyzes logs to determine attack traces without manual intervention, and a correct solution determination unit that verifies the accuracy of identified traces against preset conditions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the system presents only collected logs to participants, then the system complexity remains low, but the participant burden increases significantly as they must manually investigate and determine whether extracted logs are correct attack logs

Engineering Contradiction:
Improveparticipant burdenVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an automatic attack log extraction mechanism as an intermediary between the log collection system and the participant. This intermediary component automatically identifies and extracts attack logs from collected logs using analysis rules, thereby reducing the participant's burden of manual investigation while adding a moderate level of system complexity through the extraction mechanism

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically extracting attack logs without requiring participant intervention. The extraction mechanism autonomously analyzes collected logs, identifies attack-related entries, and presents only relevant attack logs to participants, eliminating the need for manual log verification while maintaining manageable system complexity through rule-based automation

Inventive Principle:
Principle #25Self-service

2Productivity

If manual log investigation is required, then the system requires less computational resources, but the time required for skill improvement increases due to the burdensome manual process

Engineering Contradiction:
Improveskill improvement efficiencyVSAvoidtime for log investigation
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs preliminary action by automatically extracting attack logs before participants begin their analysis. The extraction mechanism pre-processes collected logs, identifies attack-related entries using analysis rules, and prepares the filtered attack logs in advance, thereby eliminating the time participants would otherwise spend on manual log investigation and significantly improving skill improvement efficiency

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical manual log investigation process with an automated computational system. The extraction mechanism uses analysis rules and algorithms to automatically identify and extract attack logs, substituting human manual effort with computational processing that is both faster and more efficient, thereby reducing time loss and improving productivity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20240211606A1Information processing apparatus, information processing method, and computer-readable recording medium
Publication Date: 2024.06.27 NEC CORP
  • US20240211606A1 patent drawing
  • US20240211606A1 patent drawing
  • US20240211606A1 patent drawing

AI summary

An information processing apparatus includes: a trace identification unit that acquires a set of logs from a computing system that has been subjected to a cyberattack, and identifies, from the acquired set of logs, a trace indicating a result of the cyberattack by using history data indicating execution history of the cyberattack.