IP Library Granted Patent US 12,547,710
Granted Patent B2
US 12,547,710 · App. 18/088,453 · Granted Feb 10, 2026

Attack means evaluation apparatus, attack means evaluation method, and computer readable medium

Inventors: Keisuke Kito (Tokyo, JP); Kiyoto Kawauchi (Tokyo, JP)
Assignee: MITSUBISHI ELECTRIC CORPORATION
G06F21/554G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,710
App. No.
18/088,453
Granted
Feb 10, 2026
Kind
B2
Abstract

An attack means evaluation apparatus ( 100 ) evaluates an attack means used in a cyberattack. A score value calculation unit ( 110 ) obtains a plurality of attack means, and for each attack means of the plurality of attack means, calculates a score value that shows validity of an attack on an attack target system. A means selection unit ( 120 ) selects an attack means that is valid as an attack on the attack target system from the plurality of attack means using the score value of each attack means of the plurality of attack means and a threshold ( 173 ). A means execution unit ( 130 ) executes the attack means that is selected on the attack target system, and verifies whether or not an attack for achieving a final aim of the cyberattack is possible based an execution result of the attack means that is selected.

Claims (35)

1 . An attack means evaluation apparatus that evaluates an attack means used in a cyberattack, the attack means evaluation apparatus comprising:

processing circuitry configured to:

obtain a plurality of attack means, and for each attack means of the plurality of attack means, calculate a score value that shows validity of an attack on an attack target system, the attack target system being a target of the attack, each of the plurality of attack means configuring a different cyberattack on the attack target system, the plurality of attack means including a brute force attack and an exploitation of a vulnerable operating system,

select an attack means that executes the attack on the attack target system from the plurality of attack means based on the score value, and

execute the attack means that is selected on the attack target system, and verify whether or not an attack for achieving a final aim of the cyberattack is possible based on an execution result of the attack means that is selected; and

a memory to store a system configuration database in which a system configuration of the attack target system is set, wherein

the processing circuitry is further configured to

calculate the score value based on the system configuration of the attack target system included in the system configuration database, the system configuration including an operating system of the attack target system and a state of a port being open.

2 . The attack means evaluation apparatus according to claim 1 , wherein

the processing circuitry

when verifying that the attack for achieving the final aim is possible, executes the attack for achieving the final aim.

3 . The attack means evaluation apparatus according to claim 1 , wherein

the processing circuitry

calculates as the score value, an attack detection probability that shows a degree of how easily detected an attack is in the attack target system.

4 . The attack means evaluation apparatus according to claim 1 , wherein

the processing circuitry

when the attack for achieving the final aim is verified as not possible, analyzes the system configuration of the attack target system based on the execution result of the attack means that is selected, and provides feedback on an analysis result to the system configuration database, and

recalculates the score value based on the system configuration of the attack target system included in the system configuration database to where the feedback on the analysis result is provided.

5 . The attack means evaluation apparatus according to claim 1 , wherein

the processing circuitry

with regard to an attack scenario consisting of an attack means that configures the cyberattack, calculates a scenario score value that shows validity of an attack on the attack target system,

selects an attack scenario that is valid for the attack on the attack target system using the scenario score value, and

executes the cyberattack on the attack target system by executing on the attack target system, the attack scenario that is selected.

6 . An attack means evaluation method of an attack means evaluation apparatus that evaluates an attack means used in a cyberattack, the attack means evaluation method comprising:

obtaining a plurality of attack means, and for each attack means of the plurality of attack means, calculating a score value that shows validity of an attack on an attack target system, the attack target system being a target of the attack, each of the plurality of attack means configuring a different cyberattack on the attack target system, the plurality of attack means including a brute force attack and an exploitation of a vulnerable operating system;

selecting an attack means that executes the attack on the attack target system from the plurality of attack means based on the score value;

executing the attack means that is selected on the attack target system, and verifying whether or not an attack for achieving a final aim of the cyberattack is possible based on an execution result of the attack means that is selected; and

storing, in a memory, a system configuration database in which a system configuration of the attack target system is set, wherein

calculating the score value is further based on the system configuration of the attack target system included in the system configuration database, the system configuration including an operating system of the attack target system and a state of a port being open.

7 . A non-transitory computer readable medium storing an attack means evaluation program of an attack means evaluation apparatus that evaluates an attack means used in a cyberattack, the attack means evaluation program causing a computer to execute:

a score value calculation process to obtain a plurality of attack means, and for each attack means of the plurality of attack means, to calculate a score value that shows validity of an attack on an attack target system, the attack target system being a target of the attack, each of the plurality of attack means configuring a different cyberattack on the attack target system, the plurality of attack means including a brute force attack and an exploitation of a vulnerable operating system;

a means selection process to select an attack means that executes the attack on the attack target system from the plurality of attack means based on the score value; and

a means execution process to execute the attack means that is selected on the attack target system, and to verify whether or not an attack for achieving a final aim of the cyberattack is possible based on an execution result of the attack means that is selected; and

a memory storing a system configuration database in which a system configuration of the attack target system is set, wherein

calculating the score value is further based on the system configuration of the attack target system included in the system configuration database, the system configuration including an operating system of the attack target system and a state of a port being open.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 24, 2022
From: KITO, KEISUKE; KAWAUCHI, KIYOTO
To: MITSUBISHI ELECTRIC CORPORATION
Reel/Frame 062199/0512 →
Continuity (2)
Continuation PCTJP2020031149 · Aug 18, 2020
Related Publication 20230137325A1 · May 4, 2023
References Cited (23)
US 20050241000A1 · Kawauchi · 2005 [cited by applicant]
US 20080256638A1 · Russ · 2008 [cited by examiner]
US 20110035803A1 · Lucangeli Obes et al. · 2011 [cited by applicant]
US 20110061104A1 · Sarraute Yamada · 2011 [cited by examiner]
US 20190166164A1 · Yamada et al. · 2019 [cited by applicant]
US 20200065482A1 · Taniguchi et al. · 2020 [cited by applicant]
US 20200145446A1 · Deardorff · 2020 [cited by examiner]
US 20200145449A1 · Segal et al. · 2020 [cited by applicant]
US 20210029154A1 · Picard · 2021 [cited by examiner]
CN 110912945A · 2020 [cited by applicant]
CN 111475818A · 2020 [cited by examiner]
JP 2004145413A · 2004 [cited by applicant]
JP 2015114833A · 2015 [cited by applicant]
JP 2018195197A · 2018 [cited by applicant]
JP 2018196054A · 2018 [cited by applicant]
JP 2019101672A · 2019 [cited by applicant]
JP 2019125267A · 2019 [cited by applicant]
JP 2019191657A · 2019 [cited by applicant]
German Office Action dated Oct. 24, 2023 for Application No. 11 2020 007 314.9 with an English translation. [cited by applicant]
“CALDERATM”, mitre/caldera, Automated Adversary Emulation Platform, https://github.com/mitre/caldera, retrieved on Oct. 19, 2022, pp. 1-4. [cited by applicant]
Andy Applebaum, “Finding Dependencies Between Adversary Techniques”, FIRST Annual Conference 2019, Jun. 19, 2019, https://www.first.org/resources/papers/conf2019/1100-Applebaum.pdf, total of 85 pages. [cited by applicant]
International Search Report for PCT/JP2020/031149 (PCT/ISA/210) mailed on Nov. 24, 2020. [cited by applicant]
Chinese Office Action and Search Report for Chinese Application No. 202080104132.2, dated May 30, 2025, with English translation of the Office Action. [cited by applicant]