Vehicle Cyberattack Path Prediction Using Threat Trends
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The operation of a Security Operation Center (SOC) requires advanced knowledge and significant resources, and variations in analysis results occur due to the manual creation of search queries for cyberattacks, which often do not match predefined data, making it difficult to predict the attack path and next actions of cyberattacks.
Innovation Solution
An attack path prediction method and device that automatically obtain and analyze incident information, create search queries, and predict the attack path using threat information and trend analysis, even when limited initial data is available, by relaxing search conditions and utilizing named entities and trend information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If manual creation of search queries is used to obtain cyberattack information, then information can be obtained from CTI databases, but it requires advanced security knowledge and significant person-hours
Solution Approach 1:
The system enables self-service by automatically generating search queries and obtaining cyberattack information without requiring manual intervention from SOC operators. The attack path prediction device autonomously performs information retrieval from CTI databases, eliminating the need for operators to manually create queries and reducing dependency on their security knowledge expertise.
2Reliability
If manual analysis is performed by SOC operators, then cyberattacks can be detected and analyzed, but variations in analysis results occur due to different operators' knowledge and judgment
Solution Approach 1:
The system replaces the mechanical system of manual human analysis with an automated computational system. The attack path prediction device uses algorithms and automated processes to analyze cyberattacks, substituting human operators' variable judgment with consistent machine-based analysis that produces uniform results regardless of which operator would have performed the analysis.
3Productivity
If predefined data is used for cyberattack analysis, then information can be retrieved efficiently, but cyberattacks often do not match the predefined data
Solution Approach 1:
The system implements dynamics by adaptively adjusting search conditions based on the specific characteristics of each cyberattack incident. Rather than using fixed predefined data matching, the attack path prediction device dynamically modifies search parameters and query conditions to accommodate varying attack types and patterns, enabling efficient retrieval while maintaining high adaptability to novel and diverse cyber threats.
Data Source
AI summary
An attack path prediction method, which is an attack path prediction method of predicting an attack path of a cyberattacker, includes: obtaining incident information related to a cyberattack on a monitoring target vehicle from a monitor who is monitoring the monitoring target vehicle; obtaining one or more items of threat information related to a past cyberattack on a vehicle, based on the incident information obtained; obtaining, for each of the one or more items of threat information obtained, trend information indicating a degree of trend of the cyberattack; and predicting the attack path of the cyberattack on the monitoring target vehicle, based on the one or more items of threat information and the trend information for each of the one or more items of threat information.


