IP Library › Granted Patent US 12,034,757
Granted Patent B2
US 12,034,757 · App. 17/440,302 · Granted Jul 9, 2024

Analysis system, method, and program

Inventor: Noboru Nagatani (Tokyo, JP)
Assignee: NEC CORPORATION
H04L63/1433H04L63/205H04L2463/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,034,757
App. No.
17/440,302
Granted
Jul 9, 2024
Kind
B2
Abstract

The topology identification unit 4 identifies a network topology of devices included in the system to be diagnosed. The detection unit 5 detects first attack routes that indicate flows of attacks that can be executed in the system to be diagnosed, based on security information about each device. The damage identification unit 8 identifies damage information that indicates content of damage of devices on the first attack routes when the devices are attacked. The detection unit 5 detects, based on the security information and the identified damage information, second attack routes that indicate flows of attacks that can be executed resulting from the content of damage.

Claims (52)

1. An analysis system comprising:

at least one memory configured to store instructions; and

at least one processor connected to the at least one memory and configured to execute the instructions to:

identify a network topology of devices included in a system to be diagnosed;

detect first attack routes that indicate first flows of attacks that can be executed in the system to be diagnosed, based on security information about each of the devices,

identify first damage information that indicates content of first damage of first devices on the first attack routes when the devices are attacked; and

detect, based on the security information and the first damage information, second attack routes that indicate second flows of the attacks that can be executed resulting from the content of the first damage.

2. The analysis system according to claim 1 , wherein the at least one processor is further configured to execute the instructions to:

display the first attack routes and the second attack routes on a display device by superimposing the first attack routes and the second attack routes on the network topology.

3. The analysis system according to claim 2 , wherein the at least one processor is further configured to execute the instructions to:

display the first attack routes and the second attack routes together on a single screen displayed by the display device.

4. The analysis system according to claim 2 , wherein the at least one processor is further configured to execute the instructions to:

display the first attack routes and the second attack routes separately on each of two screens displayed by the display device.

5. The analysis system according to claim 2 , wherein the at least one processor is further configured to execute the instructions to:

display the first damage information near the first devices.

6. The analysis system according to claim 2 , wherein the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices when the second devices are attacked, the second devices being the devices on the second attack routes.

7. The analysis system according to claim 6 , wherein the at least one processor is further configured to execute the instructions to:

display the second damage information near the second devices.

8. The analysis system according to claim 1 , wherein the at least one processor is further configured to execute the instructions to:

obtain specified devices that are specified from outside from among the first devices; and

detect the second attack routes from the content of the first damage of the specified devices.

9. An analysis method, implemented by a computer, comprising:

identifying a network topology of devices included in a system to be diagnosed;

detecting first attack routes that indicate first flows of attacks that can be executed in the system to be diagnosed, based on security information about each of the devices;

identifying first damage information that indicates content of first damage of first devices on the first attack routes when the devices are attacked; and

detecting, based on the security information and the first damage information, second attack routes that indicate second flows of the attacks that can be executed resulting from the content of the first damage.

10. A computer-readable recording medium in which an analysis program is recorded, the analysis program causing a computer to execute:

a topology identification process of identifying a network topology of devices included in a system to be diagnosed;

a first detection process of detecting first attack routes that indicate first flows of attacks that can be executed in the system to be diagnosed, based on security information about each of the devices;

a damage identification process of identifying first damage information that indicates content of first damage of first devices on the first attack routes when the devices are attacked; and

a second detection process of detecting, based on the security information and the first damage information, second attack routes that indicate second flows of the attacks that can be executed resulting from the content of the first damage.

11. The analysis system according to claim 3 , wherein the at least one processor is further configured to execute the instructions to:

display the first damage information near the first devices.

12. The analysis system according to claim 4 , wherein the at least one processor is further configured to execute the instructions to:

display the first damage information near the first devices.

13. The analysis system according to claim 3 , wherein the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices on the second attack routes when the devices are attacked.

14. The analysis system according to claim 4 , wherein the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices on the second attack routes when the devices are attacked.

15. The analysis system according to claim 5 , the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices on the second attack routes when the devices are attacked.

16. The analysis system according to claim 11 , wherein the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices on the second attack routes when the devices are attacked.

17. The analysis system according to claim 12 , wherein the at least one processor is further configured to execute the instructions to:

identify second damage information that indicates content of second damage of second devices on the second attack routes when the devices are attacked.

18. The analysis system according to claim 13 , wherein the at least one processor is further configured to execute the instructions to:

display the second damage information near the second devices.

19. The analysis system according to claim 14 , wherein the at least one processor is further configured to execute the instructions to:

display the second damage information near the second devices.

20. The analysis system according to claim 15 , wherein the at least one processor is further configured to execute the instructions to:

display the second damage information near the second devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2021
From: NAGATANI, NOBORU
To: NEC CORPORATION
Reel/Frame 057512/0682 →
Priority Claims (1)
JP 2019-063599 · Mar 28, 2019 · national
Continuity (1)
Related Publication 20220159031A1 · May 19, 2022
Cited By (1)
US 12,235,953