IP Library › Granted Patent US 12,287,883
Granted Patent B2
US 12,287,883 · App. 17/775,941 · Granted Apr 29, 2025

Analysis system, method, and program

Inventors: Yoshinobu Ohta (Tokyo, JP); Hirofumi Ueda (Tokyo, JP); Shunichi Kinoshita (Tokyo, JP); Ryo Mizushima (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,287,883
App. No.
17/775,941
Granted
Apr 29, 2025
Kind
B2
Abstract

An analysis unit 6 generates one or more pairs of a start point fact which is a fact representing possibility of the attack in a device that is a start point and an end point fact which is a fact representing possibility of the attack in the device that is an end point, analyzes, for each pair, whether or not it is possible to derive the end point fact from the start point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack, and generates an attack scenario in a case where it is possible to derive the end point fact from the start point fact.

Claims (65)

1. An analysis method performed by one or more computers and comprising:

generating a fact which is data representing a security situation of a system to be diagnosed, based on information regarding each device included in the system to be diagnosed;

generating one or more pairs of a start point fact which is a fact representing an attack in the device that is a start point and an end point fact which is a fact representing an attack in the device that is an end point;

analyzing, for each pair, whether or not it is possible to trace from the start point fact to the end point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack; and

generating an attack scenario which is information that represents a transition relationship of a combination of the device, an attack state, and privileges that correspond to the attack state according to the start point fact and the end point fact, in a case where it is possible to trace from the start point fact to the end point fact.

2. An analysis method performed by one or more computers and comprising:

receiving an input of an attack graph regarding a system to be diagnosed;

searching for, in the attack graph, a pair of a combination node indicating a combination of a device, an attack state, and privileges, and a combination node next to the combination node; and

generating an attack scenario which is information that represents a transition relationship of a combination of the device, the attack state, and the privileges that correspond to the attack state, for each pair of the combination nodes;

displaying the generated attack scenario on a display device by

displaying a second icon representing the privileges in a first icon representing the device;

displaying a third icon representing the attack state in the second icon, for each of a start point combination node and an end point combination node in a pair of the combination nodes; and

displaying an edge extending from the third icon corresponding to the start point combination node to the third icon corresponding to the end point combination node; and

omitting displaying the second icon in a predetermined case.

3. An analysis system comprising:

a memory storing instructions; and

a processor configured to execute the instructions to:

generate a fact which is data representing a security situation of a system to be diagnosed, based on information regarding each device included in the system to be diagnosed; and

generate one or more pairs of a start point fact which is a fact representing an attack in the device that is a start point and an end point fact which is a fact representing an attack in the device that is an end point;

analyze, for each pair, whether or not it is possible to trace from the start point fact to the end point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack; and

generate an attack scenario which is information that represents a transition relationship of a combination of the device, an attack state, and privileges that correspond to the attack state according to the start point fact and the end point fact, in a case where it is possible to trace from the start point fact to the end point fact.

4. The analysis system according to claim 3 , wherein

the processor

generates a combination of one of the devices, one of multiple types of attack states defined in advance, and one of privileges that correspond to the attack state, as the start point fact, and

generates a combination of one of the devices, one of the multiple types of the attack states, and one of privileges that correspond to the attack state, as the end point fact.

5. The analysis system according to claim 3 , wherein

the processor displays the generated attack scenario on a display device.

6. The analysis system according to claim 5 , wherein

the processor displays the attack scenario by displaying a second icon representing the privileges in a first icon representing the device, displaying a third icon representing the attack state in the second icon, for each of the start point fact and the end point fact, and displaying an edge extending from the third icon corresponding to the start point fact to the third icon corresponding to the end point fact, and

omits displaying the second icon in a predetermined case.

7. The analysis system according to claim 5 , wherein

when a first device and a second device are designated from outside, the processor displays the attack scenario from the first device to the second device.

8. The analysis system according to claim 5 , wherein

when one device is designated from outside, the processor displays the attack scenario from the one device to another device.

9. The analysis system according to claim 5 , wherein

the processor identifies a network topology of devices included in the system to be diagnosed,

wherein the processor displays the attack scenario superimposed on the network topology.

10. The analysis system according to claim 5 , wherein

in the case where it is possible to trace from the start point fact to the end point fact, the processor generates an attack pattern that includes at least an attack condition, an attack result, and an attack means, and

wherein the processor displays the attack pattern associated with the attack scenario along with the attack scenario.

11. An analysis system comprising:

a memory storing instructions; and

a processor configured to execute the instructions to:

receive an attack graph regarding a system to be diagnosed, and

search for, in the attack graph, a pair of a combination node indicating a combination of a device, an attack state, and privileges, and a combination node next to the combination node;

generate an attack scenario which is information that represents a transition relationship of a combination of the device, the attack state, and the privileges that correspond to the attack state, for each pair of the combination nodes;

display the generated attack scenario on a display device by

displaying a second icon representing the privileges in a first icon representing the device;

displaying a third icon representing the attack state in the second icon, for each of a start point combination node and an end point combination node in a pair of the combination nodes; and

displaying an edge extending from the third icon corresponding to the start point combination node to the third icon corresponding to the end point combination node; and

omit displaying the second icon in a predetermined case.

12. The analysis system according to claim 11 , wherein

when a first device and a second device are designated from outside, the processor displays the attack scenario from the first device to the second device.

13. The analysis system according to claim 11 , wherein

when one device is designated from outside, the processor displays the attack scenario from the one device to another device.

14. The analysis system according to claim 11 , wherein

the processor identifies a network topology of the devices included in the system to be diagnosed,

wherein the processor displays the attack scenario superimposed on the network topology.

15. The analysis system according to claim 11 , wherein

the processor generates an attack pattern that includes at least an attack condition, an attack result, and an attack means, for each pair of the combination nodes, and

wherein the processor displays the attack pattern associated with the attack scenario along with the attack scenario.

16. A non-transitory computer-readable recording medium storing an analysis program executable by a computer to perform processing comprising:

generating a fact which is data representing a security situation of a system to be diagnosed, based on information regarding each device included in the system to be diagnosed; and

generating one or more pairs of a start point fact which is a fact representing an attack in the device that is a start point and an end point fact which is a fact representing an attack in the device that is an end point, analyzing, for each pair, whether or not it is possible to trace from the start point fact to the end point fact, based on facts representing states of the devices generated based on information regarding the device that is the start point and information regarding the device that is the end point, the start point fact, and one or more analysis rules for analyzing the attack; and

generating an attack scenario which is information that represents a transition relationship of a combination of the device, an attack state, and privileges that can correspond to the attack state according to the start point fact and the end point fact, in a case where it is possible to trace from the start point fact to the end point fact.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2022
From: OHTA, YOSHINOBU; UEDA, HIROFUMI; KINOSHITA, SHUNICHI; MIZUSHIMA, RYO
To: NEC CORPORATION
Reel/Frame 059889/0163 →
Continuity (1)
Related Publication 20220414229A1 · Dec 29, 2022
References Cited (26)
US 8881288B1 · Levy · 2014 [cited by examiner]
US 9292695B1 · Bassett · 2016 [cited by examiner]
US 11720844B2 · Ladnai · 2023 [cited by examiner]
US 12052272B2 · Ladnai · 2024 [cited by examiner]
US 20010013094A1 · Etoh et al. · 2001 [cited by applicant]
US 20050138413A1 · Lippmann · 2005 [cited by examiner]
US 20100058456A1 · Jajodia et al. · 2010 [cited by applicant]
US 20150326600A1 · Karabatis · 2015 [cited by examiner]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20190081970A1 · Teramoto · 2019 [cited by examiner]
US 20190342307A1 · Gamble · 2019 [cited by examiner]
US 20200065483A1 · Mu · 2020 [cited by examiner]
US 20200134076A1 · Ogrinz · 2020 [cited by examiner]
US 20200175071A1 · Ogrinz · 2020 [cited by examiner]
US 20200177615A1 · Grabois · 2020 [cited by examiner]
US 20200410109A1 · Yamada · 2020 [cited by examiner]
US 20210006582A1 · Yamada · 2021 [cited by examiner]
US 20210099490A1 · Crabtree · 2021 [cited by examiner]
US 20210117536A1 · Takeuchi · 2021 [cited by applicant]
US 20220124108A1 · Gamble · 2022 [cited by examiner]
US 20220124115A1 · Grabois · 2022 [cited by examiner]
JP 2001216161A · 2001 [cited by applicant]
JP 2017224053A · 2017 [cited by applicant]
WO 2019193958A1 · 2019 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2019/044620, malled on Jan. 7, 2020. [cited by applicant]
English translation of Written opinion for PCT Application No. PCT/JP2019/044620, mailed on Jan. 7, 2020. [cited by applicant]