Cybersecurity evaluation method using testbed and electronic device for the same

KR102999842B1Active Publication Date: 2026-08-05AGENCY FOR DEFENSE DEV
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
KR1020230008875
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-01-20
Publication Date
2026-08-05
Estimated Expiration
2043-01-20

Smart Images

  • Figure 112023008202483-PAT00001_ABST
    Figure 112023008202483-PAT00001_ABST
Patent Text Reader

Abstract

According to the present disclosure, a cyber security evaluation method and an electronic device for the same are provided, comprising the steps of: establishing a testbed for a system to be tested; conducting a cyber attack simulation on the testbed; visualizing the process of the cyber attack simulation on the testbed; and evaluating the cyber attack simulation based on the information visualized on the testbed.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present disclosure relates to a method for evaluating cyber security using a testbed and an electronic device for the same. Background Technology

[0002] Recently, the risk of cyber attacks on critical national industrial facilities, such as nuclear power plants and power grids, has been rising, leading to the emergence of cybersecurity importance for Industrial Control Systems (ICS). Due to the nature of ICS operating for long periods once installed and established, there is a need to analyze and evaluate cybersecurity vulnerabilities. This need is particularly high for nuclear power plants, given that a single attack can pose a tremendous risk.

[0003] Meanwhile, there is a demand for alternative methods to evaluate cybersecurity, as testing cyberattack processes on actual industrial control systems involves many constraints and carries a risk of exposure to cyberattacks during the experiment. Prior art literature

[65535] (Patent Document 0001) KR 10-2401154 B1 The problem to be solved

[0004] The present disclosure aims to provide a cyber security evaluation method and an electronic device for the same, which can effectively evaluate whether a cyber attack software achieves its objectives and its performance using a testbed.

[0005] The technical problems to be solved by the present disclosure are not limited to the technical problems described above, and other technical problems can be inferred from the following embodiments. means of solving the problem

[0006] A cyber security evaluation method using a testbed according to a disclosed embodiment may include the steps of constructing a testbed for a system to be tested, conducting a cyber attack simulation on the testbed, visualizing the process of the cyber attack simulation on the testbed, and evaluating the cyber attack simulation based on the information visualized on the testbed.

[0007] The step of constructing the above testbed may include the step of obtaining identification information of a required testbed template, the step of obtaining first configuration information regarding a testbed template corresponding to the identification information from a testbed configuration database, and the step of replicating the testbed template into a virtual machine based on the first configuration information.

[0008] The step of constructing the above testbed may further include the step of obtaining second configuration information regarding network equipment from a network configuration database and the step of creating virtual network equipment based on the second configuration information.

[0009] The above testbed may include a data measurement unit including an industrial Internet of Things sensor, a data processing unit configured to process information detected by the data measurement unit, and a monitoring control unit that transmits and receives information to and from each of the data measurement unit and the data processing unit and controls the system to be tested.

[0010] The step of conducting the cyber attack simulation on the testbed may include receiving a request to proceed with the cyber attack simulation, obtaining characteristic information of the configuration required for the simulation from a test simulation database in response to the request to proceed, and configuring a virtual machine based on the characteristic information.

[0011] The step of conducting the cyber attack simulation on the above testbed may further include the step of creating a virtual network device based on the above characteristic information.

[0012] The step of conducting the cyber attack simulation on the testbed may include the step of performing a remote access attack on at least a part of the testbed, the step of stealing target information through the remote access attack, the step of setting an attack target on the testbed based on the target information, and the step of causing abnormal operation through the attack target.

[0013] The step of visualizing the process of the cyber attack simulation above on the testbed may include the step of obtaining identification information of a component requiring visualization, the step of obtaining performance data of a virtual machine based on data corresponding to the identification information, the step of configuring a visualization screen module based on the performance data of the virtual machine, and the step of displaying a screen visualized by the visualization screen module.

[0014] An electronic device according to one disclosed embodiment may include a memory for storing at least one instruction and a processor for constructing a testbed for a system to be tested based on the at least one instruction, conducting a cyber attack simulation on the testbed, visualizing the process of the cyber attack simulation on the testbed, and evaluating the cyber attack simulation based on the information visualized on the testbed.

[0015] Specific details of other embodiments are included in the detailed description and drawings. Effects of the invention

[0016] According to the present disclosure, the achievement of objectives and performance of cyber attack software can be effectively evaluated using a testbed without the risk of the industrial control system under test being exposed to cyber attacks, and the costs of simulation and evaluation can be reduced.

[0017] The effects of the invention are not limited to those mentioned above, and other unmentioned effects will be clearly understood by a person skilled in the art from the description in the claims. Brief explanation of the drawing

[0018] FIG. 1 is a flowchart illustrating a cyber security evaluation method according to embodiments of the present disclosure. FIG. 2 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure. FIG. 3 is a conceptual diagram for explaining the structure of a testbed constructed according to a cyber security evaluation method according to embodiments of the present disclosure. FIG. 4 is a conceptual diagram illustrating the configuration of a virtual machine for implementing a testbed according to the cyber security evaluation method according to the embodiments of the present disclosure. FIG. 5 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure. FIGS. 6 and 7 are conceptual diagrams for explaining a cyber attack simulation conducted according to a cyber security evaluation method according to embodiments of the present disclosure. FIGS. 8 and 9 are flowcharts illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure. FIG. 10 is a schematic block diagram illustrating an electronic device for a cyber security evaluation method according to embodiments of the present disclosure. Specific details for implementing the invention

[0019] The terms used in the embodiments have been selected to be as widely used as possible, taking into account their functions in the present disclosure; however, these terms may vary depending on the intent of those skilled in the art, case law, the emergence of new technologies, etc. Additionally, in specific cases, terms have been selected at the applicant's discretion, and in such cases, their meanings will be described in detail in the relevant explanatory section. Therefore, terms used in the present disclosure should be defined not merely by their names, but based on their meanings and the overall content of the present disclosure.

[0020] When a part of a specification is described as "including" a certain component, this means that, unless specifically stated otherwise, it does not exclude other components but may include additional components.

[0021] The expression "at least one of a, b, and c" described throughout the specification may include 'a alone', 'b alone', 'c alone', 'a and b', 'a and c', 'b and c', or 'a, b, and c all'.

[0022] In describing the embodiments, technical details that are well known in the technical field to which this disclosure belongs and are not directly related to this disclosure are omitted. This is intended to convey the essence of this disclosure more clearly without obscuring it by omitting unnecessary explanations.

[0023] For the same reason, some components in the attached drawings have been exaggerated, omitted, or schematically depicted. Additionally, the size of each component does not entirely reflect its actual dimensions. Identical or corresponding components in each drawing have been assigned the same reference numbers.

[0024] The advantages and features of the present disclosure and the methods for achieving them will become clear by referring to the embodiments described below in detail together with the accompanying drawings. However, the present disclosure is not limited to the embodiments below but may be implemented in various different forms. The embodiments provided are merely to make the present disclosure complete and to fully inform those skilled in the art of the scope of the invention, and the present disclosure is defined only by the scope of the claims.

[0025] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0027] FIG. 1 is a flowchart illustrating a cyber security evaluation method according to embodiments of the present disclosure.

[0028] Referring to FIG. 1, a cyber security evaluation method using a testbed according to the present disclosure may include the steps of constructing a testbed for a system to be tested (S210), conducting a cyber attack simulation on the testbed (S220), visualizing the process of the cyber attack simulation on the testbed (S230), and evaluating the cyber attack simulation based on the information visualized on the testbed (S240). In this case, the system to be tested refers to an industrial control system (ICS) such as a nuclear power plant or a power grid. Hereinafter, the system to be tested is described based on a nuclear power plant, but this is merely illustrative and the present disclosure is not limited thereto.

[0029] According to the embodiments, the testbed can be constructed based on the components of an actual nuclear power plant. Each component of the actual nuclear power plant can be linked to each virtual component of the testbed through a network connection and can be implemented on the testbed by a virtual machine (VM).

[0030] Hereinafter, each step of the cyber security evaluation method using a testbed according to the present disclosure will be described in detail.

[0032] FIG. 2 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure.

[0033] Referring to FIG. 2, the step of building a testbed for a system to be tested (S210) may include, for example, a step of obtaining identification information of a required testbed template (S211), a step of obtaining first configuration information regarding a testbed template corresponding to the identification information from a testbed configuration database (S212), a step of replicating the testbed template into a virtual machine based on the first configuration information (S213), a step of obtaining second configuration information regarding a network equipment from a network configuration database if there is network equipment (S214), and a step of creating a virtual network equipment based on the second configuration information (S215).

[0034] In step S211, the electronic device can obtain identification information of the required testbed template. The testbed template may include, for example, at least one of a general-purpose OS network template, a SCADA (supervisory control and data acquisition) network template, and an IoT / network connection network template.

[0035] In step S212, the electronic device may obtain first configuration information regarding a testbed template corresponding to the identification information obtained in step S211 from a testbed configuration database. The first configuration information may include, for example, information regarding at least one of the OS, number of CPU cores, and memory capacity of the testbed template.

[0036] In step S213, the electronic device can replicate the testbed template into a new virtual machine based on the first configuration information obtained in step S212. Step S213 can be performed, for example, by a virtual machine API (application programming interface). In other words, the electronic device can configure a new virtual machine by replicating the testbed template.

[0037] In step S214, if network equipment exists, the electronic device may obtain second configuration information regarding network equipment from a network configuration database. The second configuration information may include, for example, at least one of information on the type of network equipment and information regarding the network connected to said network equipment. The network equipment may be, for example, a network adapter.

[0038] In step S215, the electronic device may create virtual network equipment based on the second configuration information obtained in step S214. Step S215 may include the step of connecting the virtual network equipment to a virtual machine. According to embodiments, the electronic device may link the components of an actual nuclear power plant with each of the virtual components of a testbed through the virtual network equipment (e.g., a virtual network adapter), and thereby the testbed may be constructed.

[0040] FIG. 3 is a conceptual diagram for explaining the structure of a testbed constructed according to a cyber security evaluation method according to embodiments of the present disclosure.

[0041] Referring to FIG. 3, the testbed constructed according to the steps described with reference to FIG. 1 and FIG. 2 may include, for example, a data measurement unit (310), a data processing unit (320), a monitoring control unit (330), and a remote monitoring unit (340).

[0042] The data measurement unit (310) may include, for example, an industrial internet of things (IIoT) sensor. The industrial internet of things sensor may include, for example, an IoT gateway device attached to analog machine equipment or manufacturing equipment. The industrial internet of things sensor can detect environmental conditions related to the machine equipment or manufacturing equipment (e.g., temperature, pressure, humidity, gas concentration, motion characteristics, fluid level, tilt angle, whether other objects are approaching, etc.) and can process and transmit information regarding environmental conditions in real time.

[0043] For example, when conducting an earthquake simulation on a testbed for a nuclear power plant, the industrial IoT sensor of the data measurement unit (310) can detect the tilted angle of one component of the testbed, and if the tilted angle is greater than a threshold value, it can recognize the occurrence of an earthquake and transmit information regarding a warning action to the data processing unit (320) or monitoring control unit (330) described later. At this time, the industrial IoT sensor may include, for example, an inertial measurement unit (IMU).

[0044] Additionally, for example, when conducting a tsunami simulation in a testbed for a nuclear power plant, the industrial IoT sensor of the data measurement unit (310) can detect the fluid level of one component of the testbed (e.g., a water tank), and if the fluid level is above a threshold value, it can recognize the occurrence of a tsunami and transmit information regarding a warning action to the data processing unit (320) or the monitoring control unit (330) described later.

[0045] The data processing unit (320) may include, for example, a PLC (programmable logic controller). The PLC can receive information regarding environmental conditions detected by an industrial IoT sensor and output the result of logically processing it by a program.

[0046] The monitoring control unit (330) may include, for example, a SCADA / HMI (supervisory control and data acquisition / human machine interface) program. The SCADA / HMI program can remotely monitor, control, and analyze systems such as industrial control systems. The monitoring control unit (330) can monitor, control, and analyze a system under test using the SCADA / HMI program. The monitoring control unit (330) can be linked with the data measurement unit (310) and the data processing unit (320), respectively, and can transmit and receive information with each of them.

[0047] The remote monitoring unit (340) may be configured to monitor the status of the entire testbed through the monitoring control unit (330). The remote monitoring unit (340) may be provided to an electronic device that builds the testbed, or it may be provided to a separate server. The remote monitoring unit (340) may be, for example, a web system created as a virtual machine.

[0048] According to embodiments, the testbed may be constructed in the form of a diorama that visualizes the components of an actual nuclear power plant. According to embodiments, the virtual machine implementing the testbed may be configured by at least one of a data processing unit (320) and a monitoring control unit (330).

[0050] FIG. 4 is a conceptual diagram illustrating the configuration of a virtual machine for implementing a testbed according to the cyber security evaluation method according to the embodiments of the present disclosure.

[0051] Referring to FIG. 4, a virtual machine (410) for implementing a testbed built according to the steps described with reference to FIG. 1 and FIG. 2 may include various modules. Hereinafter, the virtual machine (410) is described as including various modules, but the virtual machine (410) may be connected to various modules through a network.

[0052] The virtual machine (410) may include, for example, at least one of a SCADA module, a Wi-Fi / RFID module, an infrastructure visualization module, an HMI drawing module, a wired / wireless communication module, an IoT module, a multilayered module, and a wired / wireless hybrid equipment module. According to embodiments, each of the above-described modules may be referenced by a function call of the virtual machine (410). In other words, each of the above-described modules may process commands by a function call of the virtual machine (410).

[0053] The virtual machine (410) may further include, for example, a system OS module and a performance diagnostic visualization module. According to embodiments, the virtual machine (410) may be referenced in relation to the system OS and performance diagnostic visualization.

[0054] According to embodiments, the virtual machine (410) may further include at least one of a connection procedure authentication module, a password and account management module, an access control management module, a network configuration module, a user-defined mock information transmission module, a system monitoring module, a fault recovery and incident response module, and a remote access and communication line management module.

[0055] According to embodiments, the virtual machine (410) can be connected to various databases and APIs.

[0057] FIG. 5 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure.

[0058] Referring to FIG. 5, the step of conducting a cyber attack simulation on a testbed (S220) may include, for example, a step of receiving a request to proceed with the simulation (S221), a step of obtaining characteristic information of a configuration required for the simulation from a test simulation database in response to the request to proceed with the simulation (S222), a step of configuring a virtual machine based on the characteristic information (S223), and, if there is network equipment, a step of creating a virtual network equipment based on the characteristic information (S224).

[0059] In step S221, the electronic device may receive a simulation progress request from another server (e.g., a web server) or another terminal (e.g., a terminal of a cybersecurity manager or a cybersecurity-related worker). The simulation progress request may include, for example, at least one of a system simulation request and a network simulation request.

[0060] In step S222, the electronic device may obtain characteristic information of the configuration required for the simulation from a test simulation database in response to the simulation progress request received in step S221. The characteristic information of the configuration required for the simulation may include, for example, at least one of characteristic information regarding system components and characteristic information regarding networks.

[0061] In step S223, the electronic device may configure a virtual machine based on the characteristic information obtained in step S222. Step S223 may include the step of replicating a component of the system or a network based on the characteristic information. The virtual machine configured in step S223 may be provided in multiple numbers.

[0062] In step S224, if network equipment exists, the electronic device may create virtual network equipment based on the characteristic information obtained in step S222. The characteristic information may further include, for example, at least one of type information of the network equipment and information regarding the network connected to the network equipment. The virtual network equipment created in step S224 may be provided in multiple numbers.

[0063] According to the embodiments, in step S220, the electronic device may use at least one of the system OS module, wired / wireless communication module, wifi / RFID module and IoT module of the virtual machine (410) described with reference to FIG. 4.

[0065] FIG. 6 is a conceptual diagram illustrating a cyber attack simulation performed according to a cyber security evaluation method according to embodiments of the present disclosure.

[0066] Referring to FIGS. 5 and 6, the electronic device can perform a cyber attack simulation on the testbed using at least one of the virtual machine configured in step S223 and the virtual network equipment created in step S224. The cyber attack simulation can be performed according to various scenarios.

[0067] According to embodiments, step S220 may include a step of performing a remote access attack (S610), a step of stealing target information (S620), a step of setting an attack target based on the stolen target information (S630), and a step of causing an abnormal operation through the set attack target (S640). Steps S610 to S640 may be performed after step S224. Steps S610 to S640 may be implemented on a testbed by an electronic device.

[0068] In step S610, for example, a remote access attack on the system of an attack server may be performed in response to an input in which a user of the first component (601) of the system (e.g., 'business PC') executes a specific file. In the description of FIG. 6, the system refers to a system implemented on a testbed.

[0069] In step S620, for example, target information may be stolen from the first component (601) that has been targeted by a remote access attack through keylogging. However, the method of stealing target information is merely exemplary and the present disclosure is not limited thereto.

[0070] In step S630, for example, a third component (603) of the system (e.g., 'SCADA') may be set as an attack target in response to a second component (602) of the system (e.g., 'SCADA administrator PC') accessed based on stolen target information. At this time, the third component (603) shown in FIG. 6 may be the monitoring control unit (330) described with reference to FIG. 3, but this is merely exemplary and the present disclosure is not limited thereto.

[0071] In step S640, for example, a fourth component (604) of the system (e.g., 'PLC') may be controlled through a set attack target, and an abnormal operation of the system may occur due to the fourth component (604). At this time, the fourth component (604) illustrated in FIG. 6 may be the data processing unit (320) described with reference to FIG. 3, but this is merely exemplary and the present disclosure is not limited thereto.

[0072] According to embodiments, step S220 may further include a step of bypassing a firewall through SSH (secure shell) tunneling (i.e., SSH port forwarding) while performing any one of steps S610 to S640. Additionally, according to embodiments, step S220 may further include a step of creating a backdoor account as an administrator account while performing any one of steps S610 to S640.

[0073] For example, when implementing steps S610 to S640 on a testbed for a nuclear power plant, a simulation of a situation in which the nuclear power plant is neutralized due to reasons such as the occurrence of an earthquake or tsunami, destruction of a cooling tower, or a reactor malfunction may be performed.

[0074] FIG. 7 is a conceptual diagram illustrating a cyber attack simulation conducted according to a cyber security evaluation method according to embodiments of the present disclosure. More specifically, FIG. 7 is a conceptual diagram illustrating a scenario of a cyber attack simulation conducted on a testbed for a nuclear power plant.

[0075] Referring to FIG. 7, the first scenario (710) is a situation in which the nuclear power plant is operating normally, and the second scenario (720) is a situation in which an earthquake or tsunami occurs at the nuclear power plant. In each of the first scenario (710) and the second scenario (720), the data measurement unit (310), data processing unit (320), monitoring control unit (330), and remote monitoring unit (340) of the testbed described with reference to FIG. 3 can each transmit and receive information regarding the status of the nuclear power plant to and from one another.

[0077] FIG. 8 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure.

[0078] Referring to FIG. 8, the step of visualizing the process of a cyber attack simulation on a testbed (S230) may include, for example, a step of obtaining identification information of a component requiring visualization (S231), a step of requesting data corresponding to the identification information from a performance diagnosis data API (S232), a step of obtaining performance data of a virtual machine based on data transmitted from the performance diagnosis data API (S233), a step of storing the performance data of a virtual machine in a performance diagnosis database (S234), a step of configuring a visualization screen module based on information obtained from the performance diagnosis database and the testbed equipment configuration diagram database (S235), and a step of displaying a screen visualized by the visualization screen module (S236).

[0079] In step S231, the electronic device can obtain identification information of the component requiring visualization. For example, if visualization of a component that has experienced abnormal operation is required in a testbed for a nuclear power plant, the electronic device can obtain identification information of the component that has experienced abnormal operation in step S231.

[0080] In step S232, the electronic device may request the identification information and corresponding data obtained in step S231 from the performance diagnostic data API. Step S232 may further include the step of transmitting the identification information and corresponding data from the performance diagnostic data API to the virtual machine.

[0081] In step S233, the electronic device can obtain performance data of the virtual machine based on data transmitted from the performance diagnostic data API according to step S232. The performance data of the virtual machine can be obtained from the server corresponding to the virtual machine. In step S234, the electronic device can store the performance data of the virtual machine in the performance diagnostic database.

[0082] In step S235, the electronic device may configure a visualization screen module based on information obtained from the performance diagnosis database and the testbed equipment configuration diagram database. The performance diagnosis database may include, for example, information regarding at least one of CPU usage, memory usage, and network usage per virtual machine. The testbed equipment configuration diagram database may include, for example, information regarding node groups of parts of the testbed and information regarding the connection method of parts of the testbed.

[0083] In step S236, the electronic device may display a screen visualized by a visualization screen module configured according to step S235. According to embodiments, step S236 may include the step of providing the screen visualized by the visualization screen module configured according to step S235 to another server (e.g., a web server) or another terminal (e.g., a terminal of a cyber security manager or a cyber security-related worker).

[0084] According to the embodiments, in step S230, the electronic device may use at least one of the infrastructure visualization module, multilayered module, HMI drawing module, SCADA module, performance diagnosis visualization module and wired / wireless hybrid equipment module of the virtual machine (410) described with reference to FIG. 4.

[0085] According to the present disclosure, by visualizing the process of a cyber attack simulation on a testbed, costs can be significantly reduced compared to testing the cyber attack process on an actual industrial control system.

[0087] FIG. 9 is a flowchart illustrating one step of a cyber security evaluation method according to embodiments of the present disclosure.

[0088] Referring to FIG. 9, the step (S240) of evaluating a cyber attack simulation based on information visualized on a testbed may include, for example, a step of authenticating a connection procedure (S241), a step of checking whether direct control of a virtual machine is required if the connection procedure is successfully authenticated (S242), a step of displaying a first screen if direct control of a virtual machine is required (S243), and a step of obtaining user-defined mock information through the first screen (S244).

[0089] At this time, the first screen may include a virtual monitoring screen of a virtual machine. The virtual monitoring screen may be a screen configured to monitor, for example, whether each component of the testbed is implementing the situation in a simulation situation of a specific scenario. For example, when conducting an earthquake situation simulation in a testbed for a nuclear power plant, the virtual monitoring screen may verify whether the earthquake alarm, reactor alarm, and tsunami alarm operate normally in response to the occurrence of an earthquake, and whether the earthquake is properly detected based on whether the fluid level in the water tank and water pump is above a threshold value; and a cyber attack simulation may be evaluated based on the information verified through the virtual monitoring screen.

[0090] According to the embodiments, step S240 may further include the step of reflecting user-defined mock information in a virtual machine after step S244.

[0091] According to embodiments, step S240 may further include, when direct control of the virtual machine is not required, a step of displaying a second screen (S245), a step of requesting data related to the second screen from a virtual machine API (S246), and a step of transmitting the data to a virtualization server (S247). In this case, the second screen may include a screen displayed on another server or another terminal by a visualization screen module in step S236 described with reference to FIG. 8.

[0092] According to embodiments, step S240 may include a step of obtaining at least one of information on whether the simulation was successful, first success rate information defined as the ratio of the stages successfully performed among the stages of the simulation, and second success rate information defined as the ratio of the number of times the simulation was successfully performed out of the total number of times the simulation was performed multiple times. In other words, the evaluation of the cyber attack simulation may be performed based on information on whether the simulation was successful or on quantified information.

[0093] According to the present disclosure, the process of a cyber attack simulation is visualized on a testbed, and by evaluating the cyber attack simulation based on information displayed on at least one of the first screen and the second screen described above, the achievement of objectives and performance of the cyber attack software can be effectively and easily evaluated and verified.

[0095] FIG. 10 is a schematic block diagram illustrating an electronic device for a cyber security evaluation method according to embodiments of the present disclosure.

[0096] Referring to FIG. 10, the electronic device (1100) may include a communication unit (1110), a memory (1120), and a processor (1130).

[0097] According to embodiments, the electronic device (1100) may further include an input section and an output section. Each of the input section and the output section may be various interfaces or connection ports that receive user input or output information to the user.

[0098] The input unit may include an input module, and the input module receives user input from a user. User input may take various forms, including key input, touch input, and voice input. Examples of input modules capable of receiving such user input include traditional keypads, keyboards, and mice, as well as touch sensors that detect user touch, microphones that receive voice signals, cameras that recognize gestures through image recognition, proximity sensors that include at least one of an illuminance sensor or an infrared sensor that detects user approach, motion sensors that recognize user movements through accelerometers or gyroscopes, and various other types of input means that detect or receive various forms of user input. The input module according to the embodiment of the present disclosure may include at least one of the devices listed above. Here, the touch sensor may be implemented as a piezoelectric or capacitive touch sensor that detects touch through a touch panel or touch film attached to a display panel, or an optical touch sensor that detects touch by an optical method. In addition, the input module may be implemented in the form of an input interface (USB port, PS / 2 port, etc.) that connects an external input device to receive user input, instead of a device that detects user input itself.

[0099] Meanwhile, the output unit may include an output module, and the output module may output various types of information. The output module may include at least one of a display that outputs images, a speaker that outputs sound, a haptic device that generates vibrations, and various other forms of output means. In addition, the output module may be implemented in the form of a port-type output interface that connects the individual output means described above. For example, an output module in the form of a display may display text, still images, and videos. The display may include at least one of a liquid crystal display (LCD), a light-emitting diode (LED) display, an organic light-emitting diode (OLED) display, a flat panel display (FPD), a transparent display, a curved display, a flexible display, a 3D display, a holographic display, a projector, and various other forms of devices capable of performing image output functions. Such a display may be in the form of a touch display integrated with the touch sensor of the input module.

[0100] The communication unit (1110) can communicate with other devices. Therefore, the electronic device (1100) can transmit and receive information with other devices through the communication unit (1110). Here, communication, that is, the transmission and reception of data, can be performed via wired or wireless means. To this end, the communication unit (1110) may be composed of a wired communication module that connects to the internet, etc., via a LAN (Local Area Network), a mobile communication module that connects to a mobile communication network via a mobile communication base station to transmit and receive data, a short-range communication module that uses a communication method of the WLAN (Wireless Local Area Network) family such as Wi-Fi or a communication method of the WPAN (Wireless Personal Area Network) family such as Bluetooth or Zigbee, a satellite communication module that uses a GNSS (Global Navigation Satellite System) such as GPS (Global Positioning System), or a combination thereof.

[0101] The memory (1120) can store various types of information. The memory (1120) can store data temporarily or semi-permanently. For example, the memory (1120) of the electronic device (1100) may store an operating program (OS; Operating System) for operating the electronic device (1100), data for hosting a website, or data regarding a program or application (e.g., a web application) for generating Braille. In addition, the memory (1120) may store modules in the form of computer code.

[0102] Examples of memory (1120) may include a hard disk drive (HDD), a solid state drive (SSD), flash memory, ROM (Read-Only Memory), and RAM (Random Access Memory). Such memory (1120) may be provided as an internal type or a removable type.

[0103] The processor (1130) controls the overall operation of the electronic device (1100). To this end, the processor (1130) performs computation and processing of various information and can control the operation of the components of the electronic device (1100). For example, the processor (1130) can execute a program or application for managing file information. The processor (1130) can be implemented as a computer or a similar device depending on hardware, software, or a combination thereof. In terms of hardware, the processor (1130) can be implemented in the form of an electronic circuit that processes electrical signals to perform control functions, and in terms of software, it can be implemented in the form of a program that drives the hardware processor (1130). Meanwhile, unless otherwise specifically mentioned in the following description, the operation of the electronic device (1100) may be interpreted as being performed by the control of the processor (1130). That is, when modules implemented in the file information management method according to the embodiments of the present disclosure are executed, the modules can be interpreted as the processor (1130) controlling the electronic device (1100) to perform the steps of the cyber security evaluation method.

[0104] In summary, various embodiments can be implemented through various means. For example, various embodiments can be implemented by hardware, firmware, software, or a combination thereof.

[0105] In the case of implementation by hardware, the method according to various embodiments may be implemented by one or more ASICs (application specific integrated circuits), DSPs (digital signal processors), DSPDs (digital signal processing devices), PLDs (programmable logic devices), FPGAs (field programmable gate arrays), processors, controllers, microcontrollers, microprocessors, etc.

[0106] In the case of implementation by firmware or software, the method according to various embodiments may be implemented in the form of modules, procedures, or functions that perform the functions or operations described below. For example, software code may be stored in memory and executed by a processor. The memory may be located inside or outside the processor and may exchange data with the processor by various means already known.

[0107] The present disclosure describes various embodiments on the premise that, for example, an electronic device (1100), i.e., a server evaluating cybersecurity, performs the steps of a cybersecurity evaluation method. According to various embodiments, the electronic device (1100) may transmit and receive information related to the steps of the cybersecurity evaluation method to and from the electronic device (1100).

[0109] The specific examples described in this embodiment are not intended to limit the technical scope in any way. For the sake of brevity of the specification, descriptions of other functional aspects of the antenna-related components may be omitted. Additionally, the connections of lines or connecting members between the components shown in the drawings are illustrative of functional connections and / or physical or circuit connections, and may be replaced or additionally represented as various functional connections, physical connections, or circuit connections in the actual device.

[0110] In this specification (particularly in the claims), the use of the term “the above” and similar descriptive terms may be in both singular and plural. Furthermore, where a range is described, it includes individual values ​​belonging to said range (unless otherwise stated), and is equivalent to describing each individual value constituting said range in the detailed description. Finally, regarding the steps constituting the method, unless explicitly stated or otherwise stated, said steps may be performed in a suitable order. They are not necessarily limited to the order in which said steps are described. The use of all examples or exemplary terms (e.g., etc.) is merely for the detailed description of the technical concept and does not limit the scope by such examples or exemplary terms unless limited by the claims. Furthermore, a person skilled in the art will understand that various modifications, combinations, and changes may be added to the scope of the claims or equivalents, depending on design conditions and factors.

Claims

Claim 1 A method for evaluating the cybersecurity of an electronic device using a testbed comprises: a step of constructing components of a system to be tested on the testbed by means of a virtual machine (VM) - wherein the testbed includes a data measurement unit comprising an industrial Internet of Things sensor, a data processing unit configured to process information detected by the data measurement unit, and a monitoring and control unit configured to transmit and receive information to and from the data measurement unit and the data processing unit, respectively, and to control the system to be tested -; a step of conducting a cyber attack simulation on the testbed; a step of visualizing the process of the cyber attack simulation on the testbed; and a step of evaluating the cyber attack simulation based on the information visualized on the testbed, wherein the step of conducting the cyber attack simulation on the testbed comprises: a step of receiving a request to proceed with the cyber attack simulation; a step of obtaining characteristic information of a configuration required for the simulation from a test simulation database in response to the request to proceed; a step of configuring the virtual machine based on the characteristic information; a step of performing a remote access attack on at least a part of the testbed; a step of stealing target information through the remote access attack; and a step of setting the monitoring and control unit on the testbed as an attack target based on the target information. A cyber security evaluation method comprising the step of causing abnormal operation by controlling the data processing unit on the testbed through the attack target, and the step of visualizing the process of the cyber attack simulation on the testbed: the step of obtaining information regarding environmental conditions including temperature, pressure, humidity, gas concentration, motion characteristics, fluid level, tilt angle, and whether another object is approaching, simulated by the data measurement unit; and the step of visualizing whether an alarm operates normally due to the abnormal operation when the information regarding the environmental conditions is above a threshold value. Claim 2 A cybersecurity evaluation method according to claim 1, wherein the step of constructing the testbed comprises: a step of obtaining identification information of a required testbed template; a step of obtaining first configuration information regarding a testbed template corresponding to the identification information from a testbed configuration database; and a step of replicating the testbed template to the virtual machine based on the first configuration information. Claim 3 A cyber security evaluation method according to paragraph 2, wherein the step of establishing the testbed further comprises: a step of obtaining second configuration information regarding network equipment from a network configuration database; and a step of creating virtual network equipment based on the second configuration information. Claim 4 delete Claim 5 delete Claim 6 A cyber security evaluation method according to claim 1, wherein the step of conducting the cyber attack simulation on the testbed further includes the step of creating a virtual network device based on the characteristic information. Claim 7 delete Claim 8 A cyber security evaluation method according to claim 1, wherein the step of visualizing the process of the cyber attack simulation on the testbed comprises: a step of obtaining identification information of a component requiring visualization; a step of obtaining performance data of the virtual machine based on the identification information and corresponding data; a step of configuring a visualization screen module based on the performance data of the virtual machine; and a step of displaying a screen visualized by the visualization screen module. Claim 9 A computer-readable non-transient storage medium storing a program for executing the method of any one of paragraphs 1, 2, 3, 6 and 8 on a computer. Claim 10 An electronic device for cyber security evaluation using a testbed, comprising: a memory for storing at least one instruction; and based on at least one command, the processor comprises a component of a system under test built on the testbed by a virtual machine, a cyber attack simulation on the testbed, a process of the cyber attack simulation visualized on the testbed, and an evaluation of the cyber attack simulation based on the information visualized on the testbed. The testbed comprises a data measurement unit including an industrial IoT sensor, a data processing unit configured to process information detected by the data measurement unit, and a monitoring control unit configured to transmit and receive information with each of the data measurement unit and the data processing unit and to control the system under test. The processor receives a request to proceed with the cyber attack simulation, obtains characteristic information of a configuration required for the simulation from a test simulation database in response to the request to proceed, configures the virtual machine based on the characteristic information, performs a remote access attack on at least a part of the testbed, steals target information through the remote access attack, sets the monitoring control unit on the testbed as an attack target based on the target information, and controls the data processing unit on the testbed through the attack target, thereby causing abnormal operation, and the temperature, pressure, and humidity simulated by the data measurement unit, An electronic device that acquires information regarding environmental conditions including gas concentration, kinetic characteristics, fluid level, tilt angle, and whether other objects are approaching, and visualizes whether an alarm operates normally due to the abnormal operation when the information regarding the environmental conditions is above a threshold value.

Citation Information

Patent Citations

  • Virtual factory system for industrial steel and method for controlling thereof

    KR1020120071766A

  • System and method for respose training on virtual disaster based on scenario

    KR1020170117818A

  • Method And System for Providing Cyber Attack Simulation

    KR1020220032788A

  • Method for managing security data of cyber security management apparatus

    KR101732679B1

  • System and method for simulation of real time visualizable electronic warfare

    KR1020160036284A