Over the last few years, attacks leading to major infringement accidents
mainly use strategies to observe specific targets for a long time to obtain
information, and to penetrate internal networks using target-type attacks
such as spear phishing. In order to cope with target-type attacks, it is
necessary to analyse the work characteristics and assets of the target and
predict possible additional attacks. However, there is a problem that it is
ambiguous what kind of infringement accidents can occur for each
specific target. Therefore, in order to identify specific problems with its
exposure to threats and prepare management and technical
countermeasures, analysis of existing accident cases according to attack
targets and attack techniques must be accompanied. In order to solve
these problems and respond in advance, it is necessary to analyse the
infringement accident scenarios that may occur by attack target and