IP Library › Granted Patent US 12,321,461
Granted Patent B2
US 12,321,461 · App. 17/617,619 · Granted Jun 3, 2025

Attack graph processing device, method, and program

Inventors: Masaki Inokuchi (Tokyo, JP); Yoshinobu Ohta (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,461
App. No.
17/617,619
Granted
Jun 3, 2025
Kind
B2
Abstract

An attack graph processing device includes a node extraction unit which extracts a node relating to a rule classified into a predetermined group from an attack graph that is configured from one or more nodes indicating the state of a system to be diagnosed, or the state of the primary agent of an attack on the system to be diagnosed, and one or more edges indicating the relationship among a plurality of nodes, the attack graph being generated using rules indicating a condition in which the attack can be executed, and a graph configuration unit which simplifies the attack graph on the basis of the extracted node.

Claims (54)

1. An attack graph processing device comprising:

a memory storing software instructions; and

one or more processors configured to execute the software instructions to:

extract a node relating to a rule classified into a predetermined group from an attack graph that is configured from one or more nodes indicating a state of a system to be diagnosed, or a state of a primary agent of an attack, which is a state of being able to log in or communicate with a certain host, on the system to be diagnosed, and one or more edges indicating a relationship among a plurality of nodes, the attack graph being generated using rules indicating a condition in which the attack can be executed; and

simplify the attack graph by deleting the one or more nodes that were not extracted.

2. The attack graph processing device according to claim 1 , wherein

the one or more processors are configured to execute the software instructions to simplify the attack graph by deleting nodes other than the extracted node from the attack graph.

3. The attack graph processing device according to claim 2 , wherein

the one or more processors are configured to execute the software instructions to extract the node using classification information that indicates the rule classified into the predetermined group.

4. The attack graph processing device according to claim 3 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

5. The attack graph processing device according to claim 3 , wherein

the classification information indicates the rule related to a behavior of the primary agent of the attack.

6. The attack graph processing device according to claim 5 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

7. The attack graph processing device according to claim 5 , wherein

the rule related to the behavior of the primary agent of the attack is the rule that contains information indicating an identifier of the vulnerability.

8. The attack graph processing device according to claim 7 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

9. The attack graph processing device according to claim 1 , wherein

the one or more processors are configured to execute the software instructions to extract the node using classification information that indicates the rule classified into the predetermined group.

10. The attack graph processing device according to claim 9 , wherein

the classification information indicates the rule related to a behavior of the primary agent of the attack.

11. The attack graph processing device according to claim 10 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

12. The attack graph processing device according to claim 10 , wherein

the one or more processors are further configured to execute the software instructions to generate an attack graph attached with the classification information on the basis of the rule attached with the classification information, and

the one or more processors are configured to execute the software instructions to extract the node using the classification information from the generated attack graph.

13. The attack graph processing device according to claim 10 , wherein

the rule related to the behavior of the primary agent of the attack is the rule that contains information indicating an identifier of the vulnerability.

14. The attack graph processing device according to claim 13 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

15. The attack graph processing device according to claim 13 ,

the one or more processors are further configured to execute the software instructions to generate an attack graph attached with the classification information on the basis of the rule attached with the classification information, and

the one or more processors are configured to execute the software instructions to extract the node using the classification information from the generated attack graph.

16. The attack graph processing device according to claim 9 , wherein

the one or more processors are further configured to execute the software instructions to classify one or more rules into groups, and

the one or more processors are configured to execute the software instructions to generate the classification information indicating the rule classified into the predetermined group.

17. The attack graph processing device according to claim 9 , wherein

the one or more processors are further configured to execute the software instructions to generate an attack graph attached with the classification information on the basis of the rule attached with the classification information, and

the one or more processors are configured to execute the software instructions to extract the node using the classification information from the generated attack graph.

18. The attack graph processing device according to claim 1 , further comprising:

an attack graph display which displays a simplified attack graph.

19. An attack graph processing method performed by a computer and comprising:

extracting a node relating to a rule classified into a predetermined group from an attack graph that is configured from one or more nodes indicating a state of a system to be diagnosed, or a state of a primary agent of an attack, which is a state of being able to log in or communicate with a certain host, on the system to be diagnosed, and one or more edges indicating a relationship among a plurality of nodes, the attack graph being generated using rules indicating a condition in which the attack can be executed; and

simplifying the attack graph by deleting the one or more nodes that were not extracted.

20. A non-transitory computer-readable recording medium storing an attack graph processing program causing executable by a computer to perform processing comprising:

extracting a node relating to a rule classified into a predetermined group from an attack graph that is configured from one or more nodes indicating a state of a system to be diagnosed, or a state of a primary agent of an attack, which is a state of being able to log in or communicate with a certain host, on the system to be diagnosed, and one or more edges indicating a relationship among a plurality of nodes, the attack graph being generated using rules indicating a condition in which the attack can be executed; and

simplifying the attack graph by deleting the one or more nodes that were not extracted.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: INOKUCHI, MASAKI; OHTA, YOSHINOBU
To: NEC CORPORATION
Reel/Frame 058342/0917 →
Continuity (1)
Related Publication 20220237303A1 · Jul 28, 2022
References Cited (18)
US 20050138413A1 · Lippmann · 2005 [cited by examiner]
US 20070226796A1 · Gilbert · 2007 [cited by examiner]
US 20150074806A1 · Roundy et al. · 2015 [cited by applicant]
US 20150128211A1 · Kirner et al. · 2015 [cited by applicant]
US 20160205122A1 · Bassett · 2016 [cited by examiner]
US 20170286690A1 · Chari · 2017 [cited by examiner]
US 20200053116A1 · Soroush · 2020 [cited by examiner]
US 20200134076A1 · Ogrinz · 2020 [cited by examiner]
US 20200175071A1 · Ogrinz · 2020 [cited by examiner]
US 20200177617A1 · Hadar · 2020 [cited by examiner]
JP 2008250680A · 2008 [cited by applicant]
JP 2015130153A · 2015 [cited by applicant]
JP 2016528656A · 2016 [cited by applicant]
JP 2016206943A · 2016 [cited by applicant]
JP 2016540463A · 2016 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2019/023832, mailed on Sep. 10, 2019. [cited by applicant]
English translation of Written opinion for PCT Application No. PCT/JP2019/023832, mailed on Sep. 10, 2019. [cited by applicant]
X Ou et al., “MulVAL: A logic-based network security analyzer,” USENIX Association, 14th USENIX Security Symposium, pp. 113-128, 2005. [cited by applicant]