Attack scenario generating apparatus, attack scenario generating method, and computer readable recording medium
An attack scenario generating apparatus including: first attack step detection unit executes an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detects a first attack step that satisfies a damage condition with which damage occurs in the first virtual model; an input/output condition extraction unit extracts an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition; a second attack step detection unit executes an attack simulation on a second virtual model obtained from the storage device, and detects a second attack step in which output of the second virtual model satisfies the input condition; and a combination unit combines the first attack step and the second attack step to generate an attack scenario.
1 . An attack scenario generating apparatus comprising:
at least one memory storing instructions; and
at least one processor configured to execute the instructions to:
execute an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detect a first attack step that satisfies a damage condition with which damage occurs in the first virtual model;
extract an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition;
execute an attack simulation on a second virtual model obtained from the storage device, and detect a second attack step in which output of the second virtual model satisfies the input condition; and
combine the first attack step and the second attack step to generate an attack scenario.
2 . The attack scenario generating apparatus according to claim 1 , further comprising
the at least one processor is configured to execute the instructions to:
convert, in a case where the attack simulations are of different types, the input condition and the output condition into descriptions that correspond to the types of the attack simulations.
3 . The attack scenario generating apparatus according to claim 1 ,
wherein a plurality of the first and second attack steps are generated in parallel.
4 . An attack scenario generating method in which a computer is caused to carry out:
executing an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detecting a first attack step that satisfies a damage condition with which damage occurs in the first virtual model;
extracting an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition;
executing an attack simulation on a second virtual model obtained from the storage device, and detecting a second attack step in which output of the second virtual model satisfies the input condition; and
combining the first attack step and the second attack step to generate an attack scenario.
5 . An attack scenario generating method according to claim 4 ,
wherein, in a case where the attack simulations are of different types, the computer converts the input condition and the output condition into descriptions that correspond to the types of the attack simulations.
6 . The attack scenario generating method according to claim 4 ,
wherein a plurality of the first and second attack steps are generated in parallel.
7 . A non-transitory computer readable recording medium that includes a program recorded thereon, the program including instructions that cause a computer to carry out:
executing an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detecting a first attack step that satisfies a damage condition with which damage occurs in the first virtual model;
extracting an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition;
executing an attack simulation on a second virtual model obtained from the storage device, and detecting a second attack step in which output of the second virtual model satisfies the input condition; and
combining the first attack step and the second attack step to generate an attack scenario.
8 . The non-transitory computer readable recording medium according to claim 7 ,
wherein, in a case where the attack simulations are of different types, the program causes the computer to convert the input condition and the output condition into descriptions that correspond to the types of the attack simulations.
9 . The non-transitory computer readable recording medium according to claim 7 ,
wherein the program causes the computer to generate a plurality of the first and second attack steps in parallel.