Vehicle Cyberattack Path Prediction Using Threat Trends

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The operation of a Security Operation Center (SOC) requires advanced knowledge and significant resources, and variations in analysis results occur due to the manual creation of search queries for cyberattacks, which often do not match predefined data, making it difficult to predict the attack path and next actions of cyberattacks.

Innovation Solution

An attack path prediction method and device that automatically obtain and analyze incident information, create search queries, and predict the attack path using threat information and trend analysis, even when limited initial data is available, by relaxing search conditions and utilizing named entities and trend information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If manual creation of search queries is used to obtain cyberattack information, then information can be obtained from CTI databases, but it requires advanced security knowledge and significant person-hours

Engineering Contradiction:
Improvecyberattack informationVSAvoidperson-hours
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The system enables self-service by automatically generating search queries and obtaining cyberattack information without requiring manual intervention from SOC operators. The attack path prediction device autonomously performs information retrieval from CTI databases, eliminating the need for operators to manually create queries and reducing dependency on their security knowledge expertise.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual analysis is performed by SOC operators, then cyberattacks can be detected and analyzed, but variations in analysis results occur due to different operators' knowledge and judgment

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis result consistency
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system replaces the mechanical system of manual human analysis with an automated computational system. The attack path prediction device uses algorithms and automated processes to analyze cyberattacks, substituting human operators' variable judgment with consistent machine-based analysis that produces uniform results regardless of which operator would have performed the analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If predefined data is used for cyberattack analysis, then information can be retrieved efficiently, but cyberattacks often do not match the predefined data

Engineering Contradiction:
Improveinformation retrieval efficiencyVSAvoidmatch rate with actual cyberattacks
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamics by adaptively adjusting search conditions based on the specific characteristics of each cyberattack incident. Rather than using fixed predefined data matching, the attack path prediction device dynamically modifies search parameters and query conditions to accommodate varying attack types and patterns, enabling efficient retrieval while maintaining high adaptability to novel and diverse cyber threats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250301006A1Attack path prediction method, attack path prediction device, and recording medium
Publication Date: 2025.09.25 PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
  • US20250301006A1 patent drawing
  • US20250301006A1 patent drawing
  • US20250301006A1 patent drawing

AI summary

An attack path prediction method, which is an attack path prediction method of predicting an attack path of a cyberattacker, includes: obtaining incident information related to a cyberattack on a monitoring target vehicle from a monitor who is monitoring the monitoring target vehicle; obtaining one or more items of threat information related to a past cyberattack on a vehicle, based on the incident information obtained; obtaining, for each of the one or more items of threat information obtained, trend information indicating a degree of trend of the cyberattack; and predicting the attack path of the cyberattack on the monitoring target vehicle, based on the one or more items of threat information and the trend information for each of the one or more items of threat information.