Information visualization apparatus, information visualization method, and computerreadable recording medium
An information visualization apparatus includes: an inference unit that infers, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack; a location specification unit that specifies locations at which the events have been observed in the computer system, from the observation data; a graph generation unit that generates a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details; and a graph display unit that displays the directed graph.
1 . An information visualization method comprising:
inferring, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;
identifying locations at which the events have been observed in the computer system, from the observation data;
inferring a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;
identifying locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;
generating a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;
displaying a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;
based on selection of a node of the directed graph, additionally displaying information based on the observation data related to the selected node; and
constructing a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.
2 . A non-transitory computer-readable recording medium that includes a program including instructions recorded thereon, the instructions causing a computer to carry out:
inferring, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;
identifying locations at which the events have been observed in the computer system, from the observation data;
inferring a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;
identifying locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;
generating a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;
displaying a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;
based on selection of a node of the directed graph, additionally displaying information based on the observation data related to the selected node; and
constructing a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.
3 . An information visualization apparatus comprising:
at least one memory storing instructions; and
at least one processor configured to execute the instructions to:
infer, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;
identify locations at which the events have been observed in the computer system, from the observation data;
infer a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;
identify locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;
generate a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;
display a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;
based on selection of a node of the directed graph, additionally display information based on the observation data related to the selected node; and
construct a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.