IP Library › Granted Patent US 12,730,886
Granted Patent B2
US 12,730,886 · App. 18/569,289 · Granted Sep 8, 2026

Information visualization apparatus, information visualization method, and computerreadable recording medium

Inventor: Itaru Hosomi (Tokyo, JP)
Assignee: NEC CORPORATION
G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,886
App. No.
18/569,289
Granted
Sep 8, 2026
Kind
B2
Abstract

An information visualization apparatus includes: an inference unit that infers, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack; a location specification unit that specifies locations at which the events have been observed in the computer system, from the observation data; a graph generation unit that generates a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details; and a graph display unit that displays the directed graph.

Claims (29)

1 . An information visualization method comprising:

inferring, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;

identifying locations at which the events have been observed in the computer system, from the observation data;

inferring a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;

identifying locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;

generating a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;

displaying a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;

based on selection of a node of the directed graph, additionally displaying information based on the observation data related to the selected node; and

constructing a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.

2 . A non-transitory computer-readable recording medium that includes a program including instructions recorded thereon, the instructions causing a computer to carry out:

inferring, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;

identifying locations at which the events have been observed in the computer system, from the observation data;

inferring a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;

identifying locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;

generating a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;

displaying a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;

based on selection of a node of the directed graph, additionally displaying information based on the observation data related to the selected node; and

constructing a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.

3 . An information visualization apparatus comprising:

at least one memory storing instructions; and

at least one processor configured to execute the instructions to:

infer, using observation data representing events observed at a time of a cyber attack to a computer system and inferential knowledge, details of the cyber attack, wherein the observation data comprises first-order predicate logic formulas representing operation logs collected from a plurality of terminal devices;

identify locations at which the events have been observed in the computer system, from the observation data;

infer a tactic, a technique, and a procedure in the cyber attack as details of the cyber attack;

identify locations at which the events have been observed using the observation data that is evidence of the tactic or the observation data that is evidence of the technique;

generate a directed graph in which the specified locations are nodes, and edges are set between the nodes based on the observation data or the inferred details, wherein the edges are set based on the observation data including information representing two or more of the locations, or the inferred procedure;

display a time axis and the directed graph on a screen, wherein the nodes of the directed graph are arranged on the time axis based on time information included in the observation data used to specify the nodes;

based on selection of a node of the directed graph, additionally display information based on the observation data related to the selected node; and

construct a hierarchical structure of events by setting a lowest layer by literals representing observed events and setting higher layers using consequences included in rules representing relationships between events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2023
From: HOSOMI, ITARU
To: NEC CORPORATION
Reel/Frame 065840/0241 →
Continuity (1)
Related Publication 20240273197A1 · Aug 15, 2024
References Cited (25)
US 8881288B1 · Levy et al. · 2014 [cited by applicant]
US 11363057B1 · Talbot · 2022 [cited by examiner]
US 20070192474A1 · Decasper · 2007 [cited by examiner]
US 20110277034A1 · Hanson · 2011 [cited by examiner]
US 20140181968A1 · Ge · 2014 [cited by examiner]
US 20210058428A1 · Arlitt · 2021 [cited by examiner]
US 20210112090A1 · Rivera · 2021 [cited by examiner]
US 20210211438A1 · Trim · 2021 [cited by examiner]
US 20210350248A1 · Rogers · 2021 [cited by examiner]
US 20220247759A1 · Wang · 2022 [cited by examiner]
CN 104539626A · 2015 [cited by applicant]
JP H11259331A · 1999 [cited by applicant]
WO 2014112185A1 · 2014 [cited by applicant]
WO 2015140842A1 · 2015 [cited by applicant]
WO 2015140843A1 · 2015 [cited by applicant]
WO 2016072310A1 · 2016 [cited by applicant]
WO 2017175283A1 · 2017 [cited by applicant]
WO 2018079439A1 · 2018 [cited by applicant]
WO 2019011060A1 · 2019 [cited by applicant]
WO 2019186777A1 · 2019 [cited by applicant]
Written opinion for PCT Application No. PCT/JP2021/022890, mailed on Sep. 14, 2021 with English translation. [cited by applicant]
JP Official Communication for JP Application No. 2023-528844, mailed on Apr. 8, 2025 with English Translation. [cited by applicant]
International Search Report for PCT Application No. PCT/JP2021/022890, mailed on Sep. 14, 2021. [cited by applicant]
Capobianco, F et al., “Employing Attack Graphs for Intrusion Detection”, Proceedings of the New Security Paradigms Workshop, Sep. 2019, pp. 16-30, <DOI:10.1145/3368860.3368862>, p. 16, Abstract, p. 22, 5 Research Proble… [cited by applicant]
Wu, S., Zhang, Y. and Cao, W., “Network security assessment using a semantic reasoning and graph based approach”, Computers and Electrical Engineering., Feb. 21, 2017, vol. 64, pp. 96-109, <DOI:10.1016/j.compeleceng.201… [cited by applicant]