IP Library › Granted Patent US 12,596,812
Granted Patent B2
US 12,596,812 · App. 18/697,775 · Granted Apr 7, 2026

Attack route extraction system, attack route extraction method, and program

Inventor: Masaki Inokuchi (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,812
App. No.
18/697,775
Granted
Apr 7, 2026
Kind
B2
Abstract

An attack route extraction system includes a functional part which extracts one or more attack steps that can be performed by a system to be diagnosed according to configuration information of the system to be diagnosed; a cost setting part which sets a cost to the attack step based on at least one piece of information of threat information, attack content information, countermeasure possibility information based on countermeasure information corresponding to an attack method; and an attack route extraction part which determines a priority of each attack route acquired by concatenating the one or more attack steps from an intrusion point to an attack target of the system to be diagnosed based on the cost of the attack step set by the cost setting part and extracts the one or more attack route in a descending order of the priority.

Claims (33)

1 . An attack route extraction system, comprising:

at least one processor; and

a memory in circuit communication with the processor, wherein the at least one processor is configured to execute program instructions stored in the memory to perform:

extracting one or more attack steps that can be performed by a system to be diagnosed according to configuration information of the system to be diagnosed;

setting a cost to an attack step based on countermeasure possibility information based on countermeasure information corresponding to an attack method; and

determining a priority of each attack route acquired by concatenating the one or more attack steps from an intrusion point to an attack target of the system to be diagnosed based on the cost of the attack step set by the cost setting and extracting the one or more attack route in a descending order of the priority, wherein the countermeasure possibility information includes at least one of a number of applicable countermeasures calculated based on the countermeasure information corresponding to the attack method, a number of appearances in an attack graph from which the one or more attack steps of the same attack method are extracted, a number of appearances of attack methods to which the same countermeasure is usable in the attack graph, a number of appearances of a combination of an attack destination host and an attack method in the attack graph, an indegree to an attack destination node in the attack graph.

2 . The attack route extraction system according to claim 1 ,

wherein the setting the cost comprises extracting attack content information based on the attack graph from which the one or more attack steps are extracted; and

wherein the determining the priority comprises determining a priority of each attack route based on a value acquired by adding a cost of each edge on each attack route from the intrusion point to the attack target.

3 . The attack route extraction system according to claim 1 ,

wherein the extracting the one or more attack steps comprises further extracting, to each attack step of all attack steps in the attack graph from which the attack step is extracted, an attack route with minimum cost which includes each of the attack steps but does not include overlapping attack steps.

4 . The attack route extraction system according to claim 3 ,

wherein a cost of each edge is changed to lower a priority of each edge included in the extracted attack route with the minimum cost.

5 . An attack route extraction method performed by a computer including a processor and a memory, comprising:

extracting one or more attack steps that can be performed by a system to be diagnosed according to configuration information of the system to be diagnosed;

setting a cost to an attack step based countermeasure possibility information based on countermeasure information corresponding to an attack method; and

determining a priority of each attack route acquired by concatenating the one or more attack steps from an intrusion point to an attack target of the system to be diagnosed based on the cost of the attack step set by the cost setting and extracting the one or more attack route in a descending order of the priority,

wherein the countermeasure possibility information includes at least one of a number of applicable countermeasures calculated based on the countermeasure information corresponding to the attack method, a number of appearances in an attack graph from which the one or more attack steps of the same attack method are extracted, a number of appearances of attack methods to which the same countermeasure is usable in the attack graph, a number of appearances of a combination of an attack destination host and an attack method in the attack graph, an indegree to an attack destination node in the attack graph.

6 . The attack route extraction method according to claim 5 ,

wherein the setting the cost includes extracting attack content information based on the attack graph from which the one or more attack steps are extracted; and

wherein the determining the priority includes determining a priority of each attack route based on a value acquired by adding a cost of each edge on each attack route from the intrusion point to the attack target.

7 . The method according to claim 5 ,

wherein the extracting the one or more attack steps comprises further extracting, to each attack step of all attack steps in the attack graph from which the attack step is extracted, an attack route with minimum cost which includes each of the attack steps but does not include overlapping attack steps.

8 . The method according to claim 7 ,

wherein a cost of each edge is changed to lower a priority of each edge included in the extracted attack route with the minimum cost.

9 . A computer-readable non-transitory recording medium recording a program, the program which causes a computer to perform processings of:

extracting one or more attack steps that can be performed by a system to be diagnosed according to configuration information of the system to be diagnosed;

setting a cost to an attack step based on countermeasure possibility information based on countermeasure information corresponding to an attack method; and

determining a priority of each attack route acquired by concatenating the one or more attack steps from an intrusion point to an attack target of the system to be diagnosed based on the cost of the attack step set by the processing of setting the cost and extracting the one or more attack route in a descending order of the priority,

wherein the countermeasure possibility information includes at least one of a number of applicable countermeasures calculated based on the countermeasure information corresponding to the attack method, a number of appearances in an attack graph from which the one or more attack steps of the same attack method are extracted, a number of appearances of attack methods to which the same countermeasure is usable in the attack graph, a number of appearances of a combination of an attack destination host and an attack method in the attack graph, an indegree to an attack destination node in the attack graph.

10 . The computer-readable non-transitory recording medium according to claim 9 ,

wherein the processing of setting the cost comprises extracting attack content information based on the attack graph from which the one or more attack steps are extracted; and

wherein the processing of determining the priority comprises determining a priority of each attack route based on a value acquired by adding a cost of each edge on each attack route from the intrusion point to the attack target.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2024
From: INOKUCHI, MASAKI
To: NEC CORPORATION
Reel/Frame 066975/0161 →
Continuity (1)
Related Publication 20250238523A1 · Jul 24, 2025
References Cited (19)
US 9100431B2 · Oliphant · 2015 [cited by examiner]
US 9239926B2 · Tripp · 2016 [cited by examiner]
US 9507944B2 · Lotem · 2016 [cited by examiner]
US 11108790B1 · Deardorff · 2021 [cited by examiner]
US 11403427B2 · Potteiger · 2022 [cited by examiner]
US 11847227B2 · Tsirkin · 2023 [cited by examiner]
US 12299120B2 · Strogov · 2025 [cited by examiner]
US 20200320191A1 · Asai et al. · 2020 [cited by applicant]
US 20210397702A1 · Amano et al. · 2021 [cited by applicant]
US 20210400079A1 · Amano et al. · 2021 [cited by applicant]
US 20220191220A1 · Nagatani · 2022 [cited by applicant]
US 20230017839A1 · Mizushima et al. · 2023 [cited by applicant]
JP 2019050477A · 2019 [cited by applicant]
WO 2018134909A1 · 2018 [cited by applicant]
WO 2020189668A1 · 2020 [cited by applicant]
WO 2020189669A1 · 2020 [cited by applicant]
WO 2020195228A1 · 2020 [cited by applicant]
WO 2021130943A1 · 2021 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2021/042120, mailed on Feb. 8, 2022. [cited by applicant]