Virtual Host Grouping for Risk Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing risk analysis systems face high computational costs when analyzing large systems, as they do not efficiently infer attack procedures and paths, especially in complex systems with numerous hosts, such as control systems and IoT networks.

Innovation Solution

The proposed solution involves grouping hosts into virtual analysis elements, analyzing potential attacks between these elements, and determining risk targets within the system, thereby reducing computational load by focusing on specific attack paths and eliminating unnecessary analyses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of hosts in the system is large, then the system complexity increases, but the computational cost for attack graph generation becomes enormous

Engineering Contradiction:
Improvesystem size capabilityVSAvoidcomputational cost
Core Design Contradiction:
Adaptability or versatilityVSPower

Solution Approach 1:

The patent segments the system into multiple domains (e.g., network domains, cloud domains, IoT domains) and further divides hosts into groups based on their characteristics and relationships. This segmentation allows the attack graph generation to be performed on smaller, manageable subsets rather than the entire large system at once, significantly reducing computational cost while maintaining the ability to analyze complex systems.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and focuses the analysis on specific attack paths and critical hosts rather than performing a comprehensive analysis of all possible attack scenarios across the entire system. By identifying and extracting only the relevant attack paths from attacker to victim through intermediate hosts, the system reduces computational burden while maintaining security analysis effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If comprehensive attack procedure inference is performed, then analysis precision improves, but computational cost increases enormously

Engineering Contradiction:
Improveattack procedure inference accuracyVSAvoidcomputational cost
Core Design Contradiction:
Measurement precisionVSPower

Solution Approach 1:

The patent applies local quality by performing detailed attack procedure inference only for specific attack paths and critical segments rather than uniformly across the entire system. The analysis focuses on identifying attack procedures along the specific path from attacker to victim, using localized inference techniques that maintain precision for relevant attack scenarios while avoiding the computational overhead of analyzing all possible paths.

Inventive Principle:
Principle #3Local quality

3Reliability

If all hosts are analyzed individually, then analysis completeness improves, but device complexity increases

Engineering Contradiction:
Improveanalysis completenessVSAvoidanalysis process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple hosts into groups based on their characteristics, network relationships, and security properties. By analyzing groups of hosts together rather than individually, the system maintains analysis completeness for all critical hosts while significantly reducing the complexity of the analysis process. The grouped approach allows for more efficient processing and interpretation of attack paths.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20240022589A1Risk analysis device, analysis target element determination device, and method
Publication Date: 2024.01.18 NEC CORP
  • US20240022589A1 patent drawing
  • US20240022589A1 patent drawing
  • US20240022589A1 patent drawing

AI summary

A risk analysis is conducted without increasing the computational cost. A grouping means groups a plurality of hosts included in a system to be analyzed into a plurality of groups. A virtual analysis element generation means generates at least one virtual analysis element for each of the plurality of groups. An analysis means analyzes whether an attack against the virtual analysis element being an end point of an attack is possible by using the virtual analysis element. An analysis target element determination means determines, as a target of a risk analysis, a host corresponding to the virtual analysis element included in a path where the attack occurs among hosts included in the system to be analyzed. An analysis means analyzes whether an attack against the host being the end point of the attack is possible for the host determined as a target of the risk analysis.