IP Library › Granted Patent US 12,748,856
Granted Patent B2
US 12,748,856 · App. 18/408,699 · Granted Sep 29, 2026

Attack scenario generation apparatus, attack scenario generation method, and computer readable medium

Inventors: Takeshi Asai (Tokyo, JP); Ryosuke Shimabe (Tokyo, JP)
Assignee: MITSUBISHI ELECTRIC CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,748,856
App. No.
18/408,699
Granted
Sep 29, 2026
Kind
B2
Abstract

A diversion determination unit ( 110 ) compares a configurational element included in a system threat ( 21 ) with a configurational element included in a scenario threat ( 311 ) which is a threat corresponded to an analysis scenario ( 31 ), where one attack scenario among a plurality of attack scenarios is used as the analysis scenario ( 31 ). The diversion determination unit ( 110 ) determines based on a comparison result, whether or not the analysis scenario ( 31 ) can be diverted to the attack scenario indicating a process up to occurrence of the system threat ( 21 ). When it is determined that the analysis scenario ( 31 ) can be diverted, a scenario diversion unit ( 120 ) generates a new attack scenario ( 32 ) indicating the process up to the occurrence of the system threat ( 21 ), by diverting the analysis scenario ( 31 ).

Claims (24)

1 . An attack scenario generation apparatus that generates an attack scenario indicating a process up to occurrence of a security threat in a subject system, the attack scenario generation apparatus comprising:

an analysis memorandum database to store a plurality of attack scenarios which is calculated in advance, and each of which consists of attack activities listed in chronological order and each of which is corresponded to a threat; and

processing circuitry:

to specify a configurational element of a system threat which is a threat that occurs in the subject system and which is a threat for which a new attack scenario is to be generated, and a subject element that includes a system element string which is an element string indicating an order of system configurational elements in the subject system up to the system threat, and to obtain one attack scenario among the plurality of attack scenarios stored in the analysis memorandum database, as an analysis scenario;

to obtain the system element string and a scenario element string of a calculated element, the calculated element being generated from one of the stored plurality of attack scenarios and including the scenario element string which is an element string corresponding to attack activities that consist of the analysis scenario and configurational elements of a scenario threat which is a threat corresponded to the analysis scenario;

when all configurational elements are equal, and the system element string and the scenario element string are different, between the system threat and the scenario threat, to determine whether or not configurational elements of each of the different system element string and scenario element string are equal, and when it is determined that all configurational elements of the different system element string and scenario element string are equal, to determine that the analysis scenario can be diverted; and

when it is determined that the analysis scenario can be diverted, to generate the new attack scenario corresponding to the system threat, by replacing the element name of the scenario element string, with the element name of the system element string.

2 . The attack scenario generation apparatus according to claim 1 , wherein

the processing circuitry compares identity of system configurational elements included in the subject system, and stores a result of the comparison as a comparison result.

3 . The attack scenario generation apparatus according to claim 2 , wherein

the comparison result is tabular information, and

when the system configurational elements are equal, the processing circuitry sets in the comparison result, a setting column of setting the result of the comparison between the equal system configurational elements, as equal information indicating that the system configurational elements are equal.

4 . An attack scenario generation method used for an attack scenario generation apparatus that generates an attack scenario indicating a process up to occurrence of a security threat in a subject system, wherein

the attack scenario generation apparatus includes an analysis memorandum database to store a plurality of attack scenarios which is calculated in advance, and each of which consists of attack activities listed in chronological order and each of which is corresponded to a threat, and

the attack scenario generation method comprising:

specifying a configurational element of a system threat which is a threat that occurs in the subject system and which is a threat for which a new attack scenario is to be generated, and a subject element that includes a system element string which is an element string indicating an order of system configurational elements in the subject system up to the system threat, and obtaining one attack scenario among the plurality of attack scenarios stored in the analysis memorandum database, as an analysis scenario,

obtaining the system element string and a scenario element string of a calculated element, the calculated element being generated from one of the stored plurality of attack scenarios and including the scenario element string which is an element string corresponding to attack activities that consist of the analysis scenario and configurational elements of a scenario threat which is a threat corresponded to the analysis scenario, and

when all configurational elements are equal, and the system element string and the scenario element string are different, between the system threat and the scenario threat, determining whether or not configurational elements of each of the different system element string and scenario element string are equal, and when it is determined that all configurational elements of the different system element string and scenario element string are equal, determining that the analysis scenario can be diverted, and

when it is determined that the analysis scenario can be diverted, generating the new attack scenario corresponding to the system threat, by replacing the element name of the scenario element string, with the element name of the system element string.

5 . A non-transitory computer readable medium storing an attack scenario generation program used for an attack scenario generation apparatus that generates an attack scenario indicating a process up to occurrence of a security threat in a subject system, wherein

the attack scenario generation apparatus includes an analysis memorandum database to store a plurality of attack scenarios which is calculated in advance, and each of which consists of attack activities listed in chronological order and each of which is corresponded to a threat, and

the attack scenario generation program causing the attack scenario generation apparatus which is a computer to execute:

a diversion determination process to specify a configurational element of a system threat which is a threat that occurs in the subject system and which is a threat for which a new attack scenario is to be generated, and a subject element that includes a system element string which is an element string indicating an order of system configurational elements in the subject system up to the system threat, and to obtain one attack scenario among the plurality of attack scenarios stored in the analysis memorandum database, as an analysis scenario, to obtain the system element string and a scenario element string of a calculated element, the calculated element being generated from one of the stored plurality of attack scenarios and including the scenario element string which is an element string corresponding to attack activities that consist of the analysis scenario and configurational elements of a scenario threat which is a threat corresponded to the analysis scenario, and when all configurational elements are equal, and the system element string and the scenario element string are different, between the system threat and the scenario threat, to determine whether or not configurational elements of each of the different system element string and scenario element string are equal, and when it is determined that all configurational elements of the different system element string and scenario element string are equal, to determine that the analysis scenario can be diverted, and

when it is determined that the analysis scenario can be diverted, a scenario diversion process to generate the new attack scenario corresponding to the system threat, by replacing the element name of the scenario element string, with the element name of the system element string.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 10, 2024
From: ASAI, TAKESHI; SHIMABE, RYOSUKE
To: MITSUBISHI ELECTRIC CORPORATION
Reel/Frame 066082/0021 →
Continuity (2)
Continuation PCTJP2021032676 · Sep 6, 2021
Related Publication 20240202345A1 · Jun 20, 2024
References Cited (18)
US 12032687B2 · Stokes, III · 2024 [cited by examiner]
US 12407703B2 · Cho · 2025 [cited by examiner]
US 20070294766A1 · Mir · 2007 [cited by examiner]
US 20200311284A1 · Sato et al. · 2020 [cited by applicant]
US 20220164438A1 · Kito et al. · 2022 [cited by applicant]
US 20230379351A1 · Mizushima · 2023 [cited by examiner]
EP 4254866A1 · 2023 [cited by examiner]
JP 2008167099A · 2008 [cited by applicant]
JP 201849361A · 2018 [cited by applicant]
JP 2019219898A · 2019 [cited by applicant]
JP 2020129166A · 2020 [cited by applicant]
JP 2020160611A · 2020 [cited by applicant]
JP 20215165A · 2021 [cited by applicant]
Abe et al., “Eliciting Security Functional Requirements Using Security Targets”, Research Report Software Engineering (SE), (SE) [online], Mar. 5, 2015, vol. 2015-SE-187, No. 17, pp. 1-8, particularly, pp. 3-4. [cited by applicant]
Asai et al., “Security analysis for Automated Countermeasure Selection”, Research Report Multimedia Communication and Distributed Processing System (DPS), (DPS) [online], Feb. 25, 2019, vol. 2019-DPS-178, No. 4, pp. 1-7… [cited by applicant]
International Search Report (PCT/ISA/210) issued in PCT/JP2021/032676 mailed on Nov. 2, 2021. [cited by applicant]
Japanese Office Action for application No. 2022-515682 issued on Jun. 14, 2022. [cited by applicant]
Ou et al., “MulVAL: A Logic-based Network Security Analyzer”, 14th USENIX Security Symposium, USENIX Association, 2005, pp. 113-128. Total 22 pages. [cited by applicant]