Device and method for information security measures in emergencies

JP2024103306A5Pending Publication Date: 2025-08-01谷川康夫
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2023007572
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-01-20
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

Existing technologies lack effective and rapid measures to enhance information security during emergencies, such as state-sponsored cyberattacks, due to the complexity and speed requirements exceeding conventional peacetime standards, and there is a lack of automatic detection and immediate adaptation of security settings in response to emergency signals.

Method used

The system automatically processes emergency signals from the National Instant Alert System and NISC to instantly adjust security settings of gateways, using programmable logic controllers (PLCs) to enhance security measures across information devices.

Benefits of technology

This solution enables rapid and automatic adaptation of security settings, preventing the 'worst-case scenario' even during simultaneous vulnerabilities, thereby minimizing operational disruption and security breaches.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To prevent the "worst-case scenario" even when suffering state-sponsored cyber attacks simultaneously targeting at multiple vulnerabilities during an emergency, although a slight decline in operational efficiency may be experienced.SOLUTION: An emergency level is determined on the basis of signals from one or more information sources, and a setting modification for performing security level setting according to the determined level is transmitted to an information device. Thus, setting modification for policies and protection of a security product is done automatically and instantaneously upon receipt of an emergency signal.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to information security measures against malware intrusion and cyber attacks in emergency situations such as armed attack situations, emergency response situations, and large-scale disaster situations. [Background technology]

[0002] The Organization for Economic Cooperation and Development (OECD) released a report stating that if a cyberattack on a computer system were to occur simultaneously with other disasters or calamities, it could cause a "catastrophe" worldwide. In order to prepare for large-scale cyberattacks, public organizations such as JPCERT share information on cyberattack damage, which allows other organizations to take effective early action to a certain extent. However, since information on attack techniques is only released after an investigation is completed, it can be said that this information lacks immediacy.

[0003] In the relatively recent past, before a certain country was invaded militarily, the existence of state-sponsored cyber attacks (cyber attacks aimed at strengthening a country's cyber warfare capabilities, such as stealing information and destroying critical infrastructure in order to achieve political and military objectives) was revealed, and multiple vulnerabilities were targeted, critical infrastructure was attacked using multiple attack methods, and many companies were infected with attack software one after another. One company reportedly suffered damage in which thousands of servers and tens of thousands of PCs were shut down in about seven minutes. In this way, if a state-sponsored cyber attack is targeted at an emergency situation and targets human and equipment vulnerabilities, it will be too late to wait for the investigation of attack technology information, which takes days.

[0004] The rapidly changing characteristics and complexity of malware intrusions and cyber threats make it difficult for a single organization to analyze and respond to attack technology information on its own. Furthermore, analyzing malware intrusions and cyberattack damage requires a great deal of man-hours and time, which is contrary to the speed and accuracy of information sharing. As mentioned above, if cyber attackers are waiting for the right timing in times of national emergency, there are concerns that the malware intrusion and cyberattack countermeasures based on peacetime standards, and the technologies and mechanisms for sharing information on the damage caused by them, will not be able to prevent the above-mentioned "worst case scenario."

[0005] The Cabinet Secretariat's National Incident Readiness and Strategy for Cybersecurity has prepared a draft guide for sharing and publishing information related to cyber-attack damage, and the Information-Technology Promotion Agency, Japan (IPA) also provides and operates the technology for information sharing. However, because this is based on the premise of peacetime, it has not been possible to provide technology to prevent malware intrusions and reduce the damage caused by cyber-attacks in emergencies. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] JP 2019-046122 A [Patent Document 2] JP 2009-111603 A [Non-patent literature]

[0007] [Non-Patent Document 1] Peter Sommer / Ian Brown “Reducing Systemic Cybersecurity Risk” OECD project 2014 Summary of the Invention [Problem to be solved by the invention]

[0008] The problem to be solved is that there are few effective and rapid means to strengthen information security throughout society, especially in times of emergency. In Patent Document 1, "when the occurrence of an emergency is detected by the detection unit, access restrictions are lifted by permitting access by users other than authorized users. In the event of an emergency such as a natural disaster, a technology is proposed to enable the earliest possible rescue of human lives, for example, by disclosing the user's location information to other users previously authorized by the user." This technology is not aimed at strengthening security, but rather at mitigating security, and its purpose is clearly different from that of the present invention. Furthermore, in Patent Document 2, "in multi-system access of mobile phones, acceptance from other network terminals is restricted according to the time of the disaster occurrence, and congestion in an emergency is alleviated," and its purpose is different from that of strengthening information security in the event of a disaster. Furthermore, since there are not always experts on staff who can change the policies and protection settings of security measures such as firewalls, IDS / IPS, and WAF, most security measures products continue to operate without changing them once they are set. As a result, there was no technology that could automatically detect an emergency and automatically and instantly incorporate an emergency signal into a security product. Furthermore, it was difficult to automatically and instantly change the security product's policies and protection settings after receiving an emergency signal. [Means for solving the problem]

[0009] The main feature of this invention is that it automatically inputs cyber-attack technology information from the nationwide instantaneous warning system (J-Alert) and sources such as the NISC, and automatically processes these input signals to quickly strengthen and change the security countermeasure settings of each gateway, so that each organization can quickly implement countermeasures against malware intrusions and cyber-attacks in emergencies. Effect of the Invention

[0010] The technology of the present invention, which automatically detects emergencies and instantly incorporates emergency signals into security products, can prevent the "worst case scenario" even if a nation-sponsored cyber attack occurs in an emergency and multiple vulnerabilities are targeted at the same time, even if it reduces business efficiency slightly. [Brief description of the drawings]

[0011] [Figure 1] FIG. 1 is a system overview diagram for strengthening malware intrusion and cyber attack defense policy settings in an emergency (Example 1). [Diagram 2] FIG. 2 is a flow diagram showing the setting conditions for strengthening the malware intrusion and cyber attack defense policy setting in an emergency (Example 2). [Diagram 3] FIG. 3 is a flow diagram showing the process of determining the timing of sharing information related to cyber-attack damage. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0012] The objectives of detecting emergencies and preventing nation-state-level malware intrusions and cyber attacks were achieved using relatively simple devices and methods. EXAMPLES

[0013] FIG. 1 is a system outline diagram of an embodiment of the device of the present invention, in which 1 to 10 are information devices and a network in a general office. Here, the security level setting device 8 is composed of a programmable logic controller (PLC) and is an interface for receiving a signal from the receiving device 13 and outputting a setting signal required for the above-mentioned information devices. It is desirable that the dedicated network 15 and the setting level change signal 16 are separated from the general network 10 and made dedicated in order to ensure security. However, for simplification, it is also possible to make them all the same network. Also, it is desirable that the setting level change signal output from the security level setting device 8 is not a one-shot output signal, but a status output signal in order to ensure resistance to jamming signals due to external attacks. It goes without saying that the information security system can be configured in a similar manner even if a unified threat management (UTM) is installed instead of the firewall, IDS / IPS and WAF.

[0014] Examples of armed attack situations include landing invasions, ballistic missile attacks, attacks by guerrillas and special forces, and air attacks. Examples of emergency response situations include the destruction of nuclear facilities, the bombing of terminal stations and trains, the mass dispersal of sarin, and suicide bombings by aircraft. In these situations, the Cabinet Secretariat will set up an emergency disaster countermeasure headquarters, grasp the damage situation, and issue an alert (such as J-Alert) based on the Civil Protection Act to inform the public, and the alert will be transmitted via a disaster prevention network 14 such as satellite communications using a communications satellite 12. In addition, technical information on cyber attacks may be quickly shared via the Internet at the J-CSP or the JPCERT Coordination Center, a general incorporated association. These signals are received by a receiver 13 and sent to a security level setting device 8 through a dedicated network 15 with enhanced security. Here, unnecessary information such as training broadcasts and test broadcasts is removed, and the emergency level is determined based on signals from a single or multiple information sources, and setting changes are sent to information devices to set the security level according to the level. This makes it possible for security product policies and protection settings to be automatically and instantly changed after an emergency signal is received. EXAMPLES

[0015] Strict security risk measures and business efficiency are contradictory, and the stricter the information security measures are, the greater the burden on organizational members and the more difficult the working environment becomes. On the other hand, if business efficiency is given too much priority, the risk of cyber attacks and internal fraud increases, and security damage increases, such as information leaks due to external attacks and the shutdown of internal systems due to virus infections. System personnel will face an increased workload due to security measures. Figure 2 is a flowchart for setting the strictness of security measures according to the situation. If there are no emergency alerts and it is not the New Year holidays, the standard mode is set to level 0, and when there are few personnel, such as during the New Year holidays, level 1, which is a slightly stricter security measure, is selected. If an emergency alarm is issued but serious malware intrusions and cyber attacks have not yet been reported, the strict mode is set to level 2, and if serious malware intrusions and cyber attacks are reported during this period, the most strict mode is selected to level 3.

[0016] Table 1 shows the security countermeasure settings for firewalls, IPS / IDS, WAF, and endpoints according to each level. In this way, by setting the strictness of security countermeasures for each device according to levels 0 to 3, it is possible to minimize security damage in emergencies without impeding business efficiency in normal times. For example, in the "attacked victim organization shares information related to the damage with cybersecurity-related organizations" advocated by the National Center of Incident Readiness and Strategy for Cybersecurity (NISC), it is assumed that the report will be made after the cause is identified and other unclear points are cleared in the investigation. In normal times, it is possible to share information extremely quickly in emergencies, even if the technical information is not well organized. Figure 3 shows that the present invention can automatically or semi-automatically determine the timing of rapid information sharing in emergencies. In normal times, at levels 0 and 1, CSIRT work is performed in the normal steps after an incident occurs, but in emergency times, at levels 2 and 3, it is possible to select the process of sharing information to spread the damage before completing the analysis of the information, which is a secondary effect of the present invention.

[0017] [Table 1] [Industrial Applicability]

[0018] Even if a nation-sponsored cyber attack were to occur in an emergency and multiple vulnerabilities were to be targeted simultaneously, this invention can prevent the "worst case scenario" even if it would result in a slight reduction in business efficiency, and therefore can be widely applied to a wide range of industries, including infrastructure industries such as energy, communications, and railways, the cloud industry, banks, securities companies, trading companies, and mail-order companies. [Explanation of symbols]

[0019] 1. Internet 2. Firewall (FW) 3. Intrusion Detection System / Intrusion Prevention System (IDS / IPS) 4. Web Application Firewall (WAF) 5. Server or information terminal 6. Sandbox in the DMZ 7 DMZ Server 8. Security level setting device 9 DMZ Network 10 Network 11 Lighting lamp 12 Communication satellites, etc. 13 Receiving equipment from the nationwide instantaneous warning system and JPCERT / CC, etc. 14. Disaster prevention networks such as satellite communications 15 Dedicated Network 16 Setting level change signal

Claims

【Claim 1】 An information security countermeasure device and method, which are mainly characterized in that, in order to quickly implement countermeasures against malware intrusion and cyber attacks in an emergency, national instant warning system (J-Alert) information and cyber attack technical information transmitted from public institutions, etc. are automatically input, the input signals are automatically processed, and security countermeasure settings for each gateway are made. The emergency level is automatically determined based on the combination of the input signals, and the policies and protection countermeasure settings of the security products for each gateway are automatically changed according to the emergency level.