Attack detection rule generation apparatus and attack detection rule generation method
By generating attack detection rules based on risk values, identifying and prioritizing high-risk attack scenarios, the problem of high-risk events being buried in existing SIEM technology is solved, and more accurate and efficient detection of security attacks is achieved.
Patent Information
- Application Number
- JP2023187793
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-01
- Publication Date
- 2025-05-15
AI Technical Summary
When detecting security attacks, it is difficult to effectively distinguish the risk levels of different attack scenarios, resulting in high-risk events being buried in low-risk events and being difficult to quickly identify and process.
High-risk attack scenarios are identified and prioritized by generating attack detection rules based on risk values. The system includes device configuration model, exceptional event model and attack scenario identification unit, generating attack detection rules with high priority to detect and respond to high-risk security attacks.
It realizes more accurate and efficient detection of security attacks, ensures that high-risk events are identified and processed in a timely manner, reduces interference with low-risk events, and improves the efficiency and accuracy of security monitoring.
Smart Images

Figure 2025076088000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a technique for supporting a response to a security abnormality in an information processing system caused by a security attack including unauthorized access. [Background technology]
[0002] Information technology (IT) systems and operational technology (OT) systems for social infrastructure and industry (hereafter referred to as systems) are playing an important role in our daily lives. However, there are concerns that security attacks on these systems (so-called cyber attacks) could affect not only the convenience of our lives, but also human lives and the environment, and there is a need to prevent such attacks before they occur. To achieve this, it is necessary to quickly detect abnormalities caused by attacks on systems and respond appropriately to them.
[0003] For this reason, a technology called Security Information and Event Management (SIEM) has been proposed. SIEM collects operation logs generated by the devices that make up the system and the contents of communications between devices, and monitors them according to pre-set rules to see if they deviate from expected operating states.
[0004] However, depending on the rules you set, SIEM may detect not only important characteristics and signs of security attacks, but also logs from normal operation and low-importance anomalies, and output warnings. Warnings from the latter can sometimes be generated in large numbers, and warnings from the former can get lost in them and go unnoticed. For this reason, SIEM operation requires personnel who are familiar with the systems to be monitored and the means of attacks, and examining the detection results also requires a lot of man-hours.
[0005] As a prior art related to this problem, Patent Document 1 has been proposed. In Patent Document 1, attack scenarios that may occur in a monitored system and the attacks that compose them are specified in advance, and when an event corresponding to the specified attack is detected in a log acquired from the monitored system, the stage at which the attack may have progressed in the attack scenario and the importance of the detected event in the attack scenario are evaluated and notified to the user. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] JP 2023-060483 A Summary of the Invention [Problem to be solved by the invention]
[0007] Here, multiple attack scenarios for security attacks against a system are assumed. In addition, the risk of resulting events caused when each attack scenario reaches its final target may differ. Here, the resulting events may be, for example, a malfunction of the controlled plant causing an explosion, or a production line stopping and products no longer being produced, and the risks may be defined by the likelihood of the occurrence of the event and the magnitude of its impact, as exemplified by the international standard IEC 62443.
[0008] In such a case, it is desirable to be more vigilant against attack scenarios with a high risk of resulting events. For this reason, it is necessary to present the events constituting such attack scenarios to the user with a higher priority so that they are not buried under events of other attack scenarios. However, in Patent Document 1, when multiple attack scenarios with different risks are assumed, the means for reflecting the difference in risk between attack scenarios in the importance of detected events is not necessarily clear. Therefore, the present invention aims to detect security attacks more appropriately according to their importance and necessity. [Means for solving the problem]
[0009] The present invention has been made in consideration of the above problems, and detects security attacks based on risk values, particularly in accordance with monitoring priorities that correspond to the risk values.
[0010] One example of a specific configuration is an attack detection rule generation device that generates attack detection rules for detecting security attacks against a monitored system, the attack detection rule generation device having a memory unit that stores an equipment configuration model of the monitored system and an abnormal event model that indicates result events that may occur and their effects when each component device of the monitored system is subjected to an abnormal event, an attack scenario identification unit that identifies an attack scenario against the monitored system and a risk value of the attack scenario based on the equipment configuration model and the abnormal event model, and an attack detection rule generation unit that generates attack detection rules that detect security attacks that fall under the attack scenario in order of priority based on the risk values.
[0011] The present invention also includes an attack detection rule generating method using this attack detection rule generating device, a program that causes this attack detection rule generating device to function as a computer, and a storage medium that stores the program.Furthermore, a device or system that detects security attacks using attack detection rules generated by the attack detection rule generating device, and a detection method using these are also aspects of the present invention. Effect of the Invention
[0012] According to the present invention, it is possible to detect security attacks more appropriately according to importance and necessity. [Brief description of the drawings]
[0013] [Figure 1] FIG. 1 is a diagram showing the overall configuration of an attack detection system according to a first embodiment. [Diagram 2] FIG. 1 is a diagram showing the configuration of a control system 100 according to a first embodiment. [Diagram 3] 2 is a diagram showing a configuration of an attack detection rule generating device 200 and a procedure for generating attack detection rules in the first embodiment. [Figure 4] FIG. 2 is a diagram showing an example of a device configuration model 201 according to the first embodiment. [Diagram 5] FIG. 2 is a diagram showing an example of an abnormal event model 202 in the first embodiment. [Figure 6] 4 is a flowchart showing a procedure for identifying an attack scenario 211 and a risk value 212 in the first embodiment. [Figure 7] FIG. 4 is a diagram showing an example of a configuration of a detection rule in the first embodiment. [Figure 8] 11 is a diagram showing a configuration of an attack detection rule generating device 200a and a procedure for generating and modifying attack detection rules in a second embodiment. [Figure 9] FIG. 11 is a hardware configuration diagram showing an implementation example of the attack detection rule generation device 200, 200a according to the third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0014] An embodiment of the present invention is an attack detection rule generation device that generates attack detection rules for detecting security attacks against a monitored system, the attack detection rule generation device having a storage unit that stores an equipment configuration model of the monitored system and an abnormal event model that indicates result events that may occur when each component of the monitored system is subjected to an abnormal event and their effects, an attack scenario identification unit that identifies an attack scenario against the monitored system based on the equipment configuration model and the abnormal event model and identifies a risk value of the attack scenario, and an attack detection rule generation unit that generates attack detection rules that detect security attacks corresponding to the attack scenario in order of priority based on the risk value. Each example showing a specific example of this embodiment will be described below with reference to the drawings. EXAMPLES
[0015] <Overall composition> In this embodiment and in Example 2 described later, a security attack detection system for an information processing system will be described. That is, a control system 100, which is an example of an information processing system, is set as a detection target system, and security attacks against the control system are detected using the security attack detection system.
[0016] Fig. 1 is a diagram showing the overall configuration of a security attack detection system in this embodiment. In Fig. 1, the security attack detection system is composed of a control system 100, which is a monitored system, and an attack detection rule generation device 200, a security monitoring device 300, and a user terminal 410, which are connected via a network 420. The configuration of each of these devices will be described below.
[0017] First, the control system 100 is an example of a detection target system, which is an information processing system in which a security attack is expected. The attack detection rule generating device 200 is a device that realizes the main part of this embodiment, and generates attack detection rules to be set in the security monitoring device 300. The attack detection rule generating device 200 also receives a detection result of a security attack from the security monitoring device 300 and adjusts the priority of the attack detection rules. In this way, the attack detection rule generating device 200 supports the detection of security anomalies.
[0018] Furthermore, the security monitoring device 300 acquires the operating status of the devices constituting the control system 100 and communication data between the devices, and detects security attacks against these. For this purpose, the security monitoring device 300 checks against the attack detection rules generated by the attack detection rule generation device 200, and if a security attack or a symptom thereof occurs, outputs an alert indicating the detection result. The security monitoring device 300 can be realized by a computer having a function known as SIEM (Security Information and Event Management).
[0019] The security monitoring device 300 may be realized as a device integrated with the attack detection rule generating device 200. Alternatively, the security monitoring device 300 may be provided with a portion of the functions of the attack detection rule generating device 200.
[0020] Furthermore, the security monitoring device 300 may output an alarm according to the monitoring priority level described later. For example, the security monitoring device 300 outputs events such as security attacks or their signs whose monitoring priority level is equal to or higher than a predetermined value or a predetermined rank, distinguishing them from other events. In this case, events whose monitoring priority level is equal to or higher than a predetermined value or a predetermined rank may be output in a limited manner, or may be output by distinguishing their shapes such as size or color. As a result, the user terminal 410 can display events whose monitoring priority level is equal to or higher than a predetermined value or a predetermined rank, distinguishing them from other events. Furthermore, the creation of such distinguished alarms may be executed by either the security monitoring device 300 or the user terminal 410. Furthermore, the output of these alarms may be executed according to a risk value described later.
[0021] Furthermore, the user terminal 410 displays information according to the generated attack detection rule including at least one of the operation state of the security monitoring device 300, the contents of the outputted alert, the attack detection rule, and the detected event. As a result, the attack detection rule generating device 200 presents information according to the generation of the attack detection rule to the user. Furthermore, the user terminal 410 performs various operations on the attack detection rule generating device 200 and the security monitoring device 300 according to input from the user. For this reason, the user terminal 410 can be realized by a computer having a display device and an input device such as a PC or a tablet. Furthermore, the user terminal 410 is not limited to the one illustrated, and these functions may be provided in the attack detection rule generating device 200 and the security monitoring device 300.
[0022] Furthermore, the network 420 interconnects the above-mentioned devices and provides a communication path for data required for their operation. For this reason, the network 420 may be wired or wireless. Furthermore, both wired and wireless networks may be used. Furthermore, the network 420 may be a wide area network such as the Internet, or a local network such as an intranet. Furthermore, the network 420 may be composed of multiple networks.
[0023] Next, the control system 100 will be described in detail. FIG. 2 is a diagram showing the configuration of the control system 100 in this embodiment. As shown in FIG. 2, the control system 100 includes a plurality of constituent devices, which are connected to each other. The constituent devices include an information device 101, a control device 102, and a control target 103, which are connected to each other via networks 104 and 105. The control system 100 also has a network device 106 that connects the network 104 and the network 105. This network device 106 can also be treated as a constituent device. Below, the constituent devices of the control system 100, including the networks 104 and 105, will be described.
[0024] First, the information device 101 monitors the states of the control device 102 and the controlled object 103 and performs various settings. For this reason, the information device 101 can be realized by a system monitoring / operation terminal or server such as a Supervisory Control and Data Acquisition (SCADA). Furthermore, the control device 102 is a device that controls the controlled object 103, and can be realized by a Programmable Logic Controller (PLC) or a Distributed Control System (DCS). Furthermore, the controlled object 103 is a facility or device that is controlled and driven by the control device 102 and performs a predetermined operation in the real world. For this reason, the control device 102 corresponds to, for example, a chemical plant or a production line.
[0025] Furthermore, the control device 102 acquires the state of the controlled object 103 from a sensor or the like (not shown), outputs a control command corresponding to the state, and transmits the control command to the controlled object 103 via an actuator (not shown). As a result, the controlled object 103 operates according to the control command. Furthermore, the control device 102 calculates and generates a control command from an input from a sensor according to a preset control logic (program, rule, model, etc.).
[0026] Furthermore, the network 104 connects the information device 101 and the control device 102 to each other. As a result, the information device 101 and the control device 102 can monitor the states of the control device 102 and the controlled object 103 described above, and set control target values and control modes for them, via the network 104. Furthermore, the control devices 102 can share, via the network 104, state values, control command values, and other related data relating to the controlled object 103 that they each control.
[0027] Furthermore, the network device 106 can also provide a security function in addition to relaying and managing communications in the network 104. For this reason, the network device 106 can be realized as a router or a firewall, or a combination of these.
[0028] In this embodiment, it is assumed that each of the above-mentioned components is given an identification name. For example, as shown in Fig. 2, the identification name of each device is a name that matches its role, such as "SCADA1" or "PLC1". This is for the sake of making the following description of the embodiment easier to understand, and in reality, numbers or other numbers that can uniquely identify the devices may be used.
[0029] <Procedure for generating attack detection rules> Next, the generation of attack detection rules for detecting various events such as security attacks and their symptoms in this embodiment will be described. Note that here, the configuration of the attack detection rule generation device 200 that generates the attack detection rules will also be described. The attack detection rules will be used in the security monitoring device 300.
[0030] Fig. 3 is a diagram showing the configuration of the attack detection rule generating device 200 and the procedure for generating attack detection rules in this embodiment. In Fig. 3, squares indicate each component of the attack detection rule generating device 200, and arrows connecting these components indicate the flow of information created by the generation procedure (steps). First, the configuration of the attack detection rule generating device 200 will be described. The attack detection rule generating device 200 has an attack scenario identifying unit 210, a monitoring priority determining unit 220, and an attack detection rule generating unit 230. A device configuration model 201, an abnormal event model 202, and an attack characteristic database 203 are stored in the storage unit of the attack detection rule generating device 200. Below, the procedure for generating attack detection rules will be described using this.
[0031] First, the attack scenario identification unit 210 performs an attack scenario analysis and a risk analysis of the control system 100, which is a monitored system, based on the device configuration model 201 and the abnormal event model 202, identifies an attack scenario 211, and calculates a risk value 212 of the identified attack scenario 211. Here, the attack scenario 211 indicates the content of an attack on the control system 100, which is a monitored system. Also, the risk value 212 indicates the degree of risk due to an attack indicated by the corresponding attack scenario. Here, the device configuration model 201 is information that expresses the device configuration of the control system 100. Here, an example of the device configuration model 201 is shown in FIG. 4.
[0032] In this diagram, the device configuration model 201 has entries for at least the identification name, device type, input source, and output destination for each component device of the control system 100. First, the identification name identifies the component device of the control system 100. Furthermore, the device type indicates the role of the corresponding component device in the control system 100. Furthermore, the input source and output destination indicate the input source and output destination of data in the corresponding component device. In addition, in the device types in the diagram, "host" refers to the component device corresponding to the information device 101, "control" refers to the control device 102, and "target" refers to the control target 103.
[0033] Additionally, although not illustrated in this embodiment, the device configuration model 201 may include detailed configuration information such as the specifications and versions of the hardware and software (for example, the OS and applications) in each of the configuration devices. The device configuration model 201 is created by a user using the user terminal 410. Furthermore, the device configuration model 201 may be automatically generated by the attack detection rule generation device 200 from a design document of the control system 100, or may be generated by performing an operation analysis on the control system 100.
[0034] The abnormal event model 202 is information showing the results when each component device of the control system 100 receives an input or command (abnormal event) that is different from the design intent. The results include possible resulting events and their effects. An example of these results and effects is shown in FIG. 5.
[0035] 5 is a diagram showing an example of the abnormal event model 202 in this embodiment. In this example, a reaction tank in a chemical plant is assumed as the control system 100. In this case, a pair of a cause event, a result event, and the impact of the result event are described, such as when the heater output from the PLC1 becomes excessive, the inside of the reaction tank overheats and the contents ignite or explode. In this figure, the abnormal event is expressed abstractly for the purpose of explanation, but in reality, more specific attack means such as unauthorized input or spoofing that exploits the vulnerability of the device may be described.
[0036] The abnormal event model 202 can also be created by a user using the user terminal 410. The attack detection rule generation device 200 can also create the abnormal event model 202 by using a publicly known or unpublicized risk analysis technique, or by a simulation using a physical model or a logical model of each component device.
[0037] Next, the identification of an attack scenario 211 and a risk value 212 indicating the degree of risk in generating an attack detection rule will be described. In this identification, a device configuration model 201 and an abnormal event model 202 are used. First, an overview will be described. The attack scenario identification unit 210 identifies, in the component devices that are closest to the real world in the control system 100, a component device (causative device) that brings about a resultant event that may occur due to an event such as a security attack and an abnormal event that is the cause of the resultant event. Here, the component devices that are closest to the real world include the component devices that perform physical operations, and these are identified from the control target 103.
[0038] In addition, the attack scenario identification unit 210 identifies the component device that is the cause of the abnormal event in the component device by tracing back the input source and output destination of the device configuration model 201. In other words, the attack scenario identification unit 210 identifies the input source of the causative device from the device configuration model 201.
[0039] Next, the attack scenario identification unit 210 identifies the output destination corresponding to the identified input source. These processes are repeated until an external interface (I / F) such as a firewall is reached as a component device, and the component devices are identified in a chain reaction. Here, as the external I / F, it is possible to identify those in the device configuration model 201 where the input source or output destination is unspecified (-) or the device type indicates an external I / F (for example, host). As a result, it becomes possible to identify an attack scenario including each component device from the identified causal device to the external I / F and their order. Note that the order here indicates the progression path of the security attack.
[0040] For example, in FIG. 5, the attack scenario would be the series of abnormal events that ultimately lead to the excessive output of the HEATER (202a) that causes a reaction tank explosion, followed by the excessive target temperature of PLC1 (202b) that causes this, and even tracing back to the unauthorized command input to SCADA1 (external I / F) (202c) that caused this.
[0041] Here, the procedure for identifying the attack scenario 211 and the risk value 212 will be described with reference to Fig. 6. Fig. 6 is a flowchart showing the procedure for identifying the attack scenario 211 and the risk value 212 in this embodiment.
[0042] First, the attack scenario identification unit 210 searches the device configuration model 201 for the control target 103, which is the component device in the control system 100 that is closest to the real world as the component device that is the starting point of the attack scenario, and sets it as the target device (step S210-1). If there are multiple control targets 103, the attack scenario identification unit 210 performs the following steps for each of them to generate attack scenarios that start from each of the multiple control targets 103.
[0043] Furthermore, the attack scenario identification unit 210 searches the abnormal event model 202 for an entry corresponding to the target device identified in step S210-1, and acquires possible result events and their impacts (step S210-2). The attack scenario identification unit 210 identifies the impacts as the risk value 212 of the attack scenario to be determined. Note that, in step S210-2, similar to step S210-1, if there are multiple result events for the same target device, each is treated as a different attack scenario. Here, in FIG. 5, the impacts that are the risk values 212 are information that relatively indicate the degree of the impacts, such as "very severe" or "large", but numerical values such as absolute values or rankings for each abnormal event may be used as the impacts, that is, the risk values 212. Note that the attack scenario identification unit 210 may calculate the risk value 212 from the impacts. For example, when using a rank as the degree of influence, the rank of the identified abnormal event may be used as the risk value 212 instead of the rank itself, or the reciprocal of the rank may be used as the risk value 212 .
[0044] Next, the attack scenario identification unit 210 acquires information on the abnormal event that is the cause of the aforementioned result event and its source from the entry corresponding to the identified target device (the same entry as in step S210-2) (step S210-3). The attack scenario identification unit 210 regards the acquired information on the abnormal event and its source as the identification result of the attack content that occurs on the attack path in the attack scenario.
[0045] Furthermore, in order to trace back the cause of the abnormal event, the attack scenario identification unit 210 sets the target device as the source device of the abnormal event (step S210-4). In other words, the attack scenario identification unit 210 uses the input destination and output destination to sequentially identify the target device, which is the source device.
[0046] Then, the attack scenario identification unit 210 judges whether the source device is an external I / F (step S210-5). As a result, if it is an external I / F (Y), that is, if the causative component device does not yet exist, the process proceeds to step S210-6. On the other hand, if it is not an external I / F (N), and if the causative component device still exists, the process proceeds to step S210-7.
[0047] Here, in step 210-6, there are no more causative components, and the last identified component becomes the starting point of the attack scenario. Therefore, the attack scenario identification unit 210 outputs the attack scenario 211 including the abnormal event identified as the component traced in steps S210-3 to 5 and its risk value 212 (step S210-6). Then, the procedure of this flowchart ends.
[0048] Furthermore, the attack scenario identification unit 210 acquires the entry of the abnormal event model 202 corresponding to the last identified component device, and acquires information on the result event that occurs there (step S210-7).Then, the process proceeds to step S210-3.
[0049] <Determining monitoring priority> In this embodiment, the monitoring priority determination unit 220 assigns a monitoring priority (hereinafter, also simply referred to as priority) to the attack detection rule for detecting the attack scenario specified by the above-mentioned method, which reflects the risk of the result of the establishment of the attack scenario. This makes it easier to detect an event related to an attack scenario with a high risk, that is, a high risk value 212.
[0050] Therefore, the monitoring priority determination unit 220 converts the risk value 212 of the attack scenario 211 identified in the attack scenario identification procedure, i.e., the impact level of “severe,” “large,” or “medium” obtained from the abnormal event model 202, into a priority of the attack detection rule.
[0051] Here, the range of priority to be converted follows the specifications of the security monitoring device 300 that sets the attack detection rules, if the device has this function. If priority values from 0 to 100 (the higher the number, the higher the priority) are available, the risk assessment class is converted to a numerical value, for example, risk value "severe" = 100, "large" = 80, and "medium" = 60. Note that there is no proportional relationship between the priority values 0 to 100 of the attack detection rules, and they are simply used to express the relative priority relationship.
[0052] Furthermore, if the security monitoring device 300 does not have a function for assigning priorities to attack detection rules, priorities are assigned to the attack detection rules by a method that will be described later. In this case, the range of priorities may be designed arbitrarily.
[0053] <Creating attack detection rules> Next, the generation of attack detection rules will be described. In the attack detection rule generation unit 230, an attack detection rule 231 to be set in the security monitoring device 300 is generated from the generated attack scenario 211 as follows. The attack scenario 211 includes the component devices on the progression path of the security attack and the attack means occurring in the devices. Here, the abnormal event identified in step S210-3 can be used as the attack means. The attack detection rule generation unit 230 searches the attack characteristics database 203 using the attack means as a key.
[0054] Here, the attack characteristic database 203 is a database of attack characteristic information, which is information about already known security attacks. Here, examples of the attack characteristic information include the type of component device (target device) targeted by the security attack, the details of the attack operation and communication performed on the target device, the behavior of the target device observed at the time of the attack, and the details of the damage. The attack characteristic database 203 can be constructed by the user himself, or can be constructed using a database prepared by a public institution or a private research group.
[0055] Furthermore, if the aforementioned attack means exists in the attack characteristics database 203, attack operations against the component devices on the progression path and the behavior of the relevant component devices can be obtained from there. For this reason, the attack detection rule generation unit 230 concretizes the attack operations and behavior by referring to the specifications of the relevant component devices described in the device configuration model 201. As a result, the attack detection rule generation unit 230 generates the concretized results as attack detection rules 231. For example, in the case of an attack via a network against a vulnerability, the destination address and port of the communication for the attack, the vulnerability attack pattern included in the attack packet, and the like are specifically determined, and these are set as the attack detection rules 231.
[0056] The attack detection rules 231 can be composed of one or more configuration rules. Each of these configuration rules is set with a priority corresponding to the risk of the attack scenario, as explained in the section on determining the monitoring priority. The priority is generated according to the specifications of the security monitoring device 300.
[0057] Here, a configuration example of the generated attack detection rule 231 is shown in Fig. 7. In Fig. 7, the first example, an attack detection rule 231a, is a configuration example in the case where the security monitoring device 300 has a priority setting function for the attack detection rule.
[0058] In the attack detection rule 231a in FIG. 7, the configuration rule on the first line (No. 1) is a configuration rule that detects attack communications that exploit a vulnerability named "vuln1" to TCP port 80 for any configuration device. Because it is an attack via communication, this means that the network packets acquired by the network device 106 ("Firewall" in the rule) are matched against this rule for detection. The configuration rule on the second line (No. 2) indicates that the condition for detection is five consecutive failed login attempts for the information device 101 with the identification name "SCADA1". This is intended to detect events that attempt to guess passwords as a precursor to unauthorized login.
[0059] 7 is a configuration example in the case where the security monitoring device 300 does not have a priority setting function for the attack detection rules. Like the attack detection rules 231, the attack detection rules 231b include configured rules for detecting three types of attacks, but each is surrounded by "if", "else if", and "else". These are arranged in order of the set priority, and the configured rules surrounded by "if" are compared with the generated event.
[0060] Next, rules enclosed in "else if" are matched in the order they are written, and finally configuration rules enclosed in "else" are matched. If there is an event that meets multiple conditions, only the rule that meets the first rule will be matched, and configuration rules written after that will not be matched, so the priority between configuration rules is reflected in the event detection results.
[0061] According to the present embodiment described above, attack scenarios that may occur against the control system 100, which is the detection target, are identified along with their respective risk values. That is, in this embodiment, the attack scenario identification unit 210 creates attack detection rules 231 for detecting events, particularly security attacks, in order of priority based on the risk values 212. As an example, security attacks corresponding to attack scenarios with higher risk values 212 are detected with higher priority. Furthermore, attack detection rules 231 are generated for detecting events with priority according to the monitoring priority identified based on the risk values 212. As an example, security attacks corresponding to attack scenarios with higher monitoring priority are detected with higher priority.
[0062] The attack detection rules 231 generated as described above are notified from the attack detection rule generation device 200 to the security monitoring device 300. This notification may be performed each time they are generated, or may be performed as a batch process on a periodic basis. This batch process is assumed to be performed, for example, every few seconds, but this period is not limited. Furthermore, attack detection rules 231 corresponding to the attack means identified in each attack scenario are generated. These attack detection rules 231 include priorities (or a collation order based on priorities) that reflect the risk values 212 in the attack scenarios 211.
[0063] As a result, when the security monitoring device 300 detects events based on this attack detection rule, events related to attack scenarios with higher priorities can be detected with higher priority. This reduces the risk that events of attack scenarios with relatively high risks will be buried under events of other attack scenarios. This is expected to enable users to quickly recognize the occurrence of the attack scenario and take action. EXAMPLES
[0064] Next, a second embodiment of the present invention will be described. As most of the configuration and operation are common to the first embodiment, the differences will be mainly described. In this embodiment, the attack detection rules 231 generated in the same manner as in the first embodiment and their priorities are registered in the security monitoring device 300, and events occurring in the control system 100 are monitored. In this embodiment, information on the events detected as a result is fed back to the attack detection rule generation device 200. Then, by updating the monitoring priority of the attack scenario to which the detected event belongs, such as by raising it from the time of setting, it becomes possible to more intensively monitor attack scenarios that have actually occurred or whose signs have been observed.
[0065] The specific contents of this embodiment will be described with reference to Fig. 8. Fig. 8 is a diagram showing the configuration of an attack detection rule generating device 200a in this embodiment, and the procedures for generating and modifying attack detection rules. The attack detection rule generating device 200a in this embodiment includes an attack scenario determining unit 240 in addition to the configuration of the attack detection rule generating device 200 in the first embodiment, and also includes a monitoring priority determining unit 220a that further has a priority modification function that will be described later.
[0066] In this embodiment, the security monitoring device 300 uses the event detection notification 301 to notify the attack scenario determination unit 240 of the attack detection rule generation device 200a of information on an event including a security attack detected by the attack detection rule 231. The attack scenario determination unit 240 also compares the contents of the notified event with the attack detection rule 231 to determine which attack scenario the detected event relates to. The attack scenario determination unit 240 then notifies the monitoring priority determination unit 220a of the determined attack scenario as a scenario 241 to be subjected to priority modification.
[0067] The monitoring priority determination unit 220a also identifies the current monitoring priority applied to the notified priority correction target scenario 241 and updates it, preferably correcting it upward. For example, it applies a priority higher than the attack scenario to which the highest priority is currently applied. If there is already a scenario to which the highest priority is applied, the monitoring priorities of scenarios other than those specified in the priority correction target scenario 241 may be lowered.
[0068] In this way, after the priority of the attack scenario in which an event was detected is revised upward, an attack detection rule is generated in the same manner as in the first embodiment. Then, the priority of the revised attack scenario is applied to each associated attack detection rule, and registered in the security monitoring device 300 as the attack detection rule 231.
[0069] By the above-described operation, the monitoring priority of an attack scenario in which an event has actually been detected is updated in accordance with the situation, particularly revised upward, making it easier to detect. This makes it possible to further draw the user's attention to events such as security attacks and to encourage a quick response. The monitoring priority may be updated by updating the risk value 212. In this case, as in the first embodiment, the information, numerical value, or ranking relatively indicated as the degree of influence that becomes the risk value 212 may be updated. At this time, it is desirable to increase the numerical value or raise the ranking. Similarly, the monitoring priority itself may be updated by increasing the numerical value or raising the ranking. EXAMPLES
[0070] Next, an implementation example of the attack detection rule generating devices 200, 200a will be described as a third embodiment. Fig. 9 is a hardware configuration diagram showing an implementation example of the attack detection rule generating devices 200, 200a in this embodiment. The hardware configuration will be described below using the attack detection rule generating device 200a as an example. The attack detection rule generating device 200a can be realized by a computer such as a server as shown in Fig. 9. In Fig. 9, the attack detection rule generating device 200a has a processing device 21, a communication device 22, a memory 23, and a secondary storage device 24, which are connected to each other via a communication path.
[0071] First, the processing device 21 can be realized by a processor such as a CPU, and executes calculations according to an attack detection rule generation program 25 stored in a secondary storage device 24 described later. Also, the communication device 22 connects to a network 420 and communicates with other devices such as a user terminal 410. Therefore, the communication device 22 can notify the security monitoring device 300 of the generated attack detection rule 231 and the updated monitoring priority.
[0072] The memory 23 and the secondary storage device 24 also store various information (data) such as the attack detection rule generation program 25, the device configuration model 201, the abnormal event model 202, and the attack characteristic database 203. That is, the memory 23 deploys the attack detection rule generation program 25 and various information stored in the secondary storage device 24. The secondary storage device 24 can be realized by a so-called storage. The secondary storage device 24 may be realized as a storage device connected via a network 420, and at least a part of the information of the secondary storage device 24 may be stored in this storage device. The secondary storage device 24 can also be realized by various storage media such as an external hard disk drive (HDD), solid state drive (SSD), or memory card.
[0073] Here, the attack detection rule generating program 25 has, for each function, an attack scenario identifying module 251, a monitoring priority determining module 252, an attack detection rule generating module 253, and an attack scenario determining module 254. Each of these modules may be realized as an individual program or a partial combination. Furthermore, in the case of the first embodiment, the attack scenario determining module 254 can be omitted.
[0074] Here, the configurations shown in FIG. 3 and FIG. 8 which perform the same functions as the modules are as follows. Attack scenario identification module 251: Attack scenario identification unit 210 Monitoring priority determination module 252: monitoring priority determination units 220, 220a Attack detection rule generation module 253: Attack detection rule generation unit 230 Attack scenario determination module 254: Attack scenario determination unit 240 Therefore, the processing device 21 executes the processes of the attack scenario identification unit 210, the monitoring priority determination unit 220, 220a, the attack detection rule generation unit 230, and the attack scenario discrimination unit 240 in accordance with the attack detection rule generation program 25. This completes the description of the hardware configuration of the attack detection rule generation device 200a.
[0075] According to each of the above embodiments, when there are multiple attack scenarios of security attacks assumed in the target system, the following processing is performed: Attack detection rules for events constituting each attack scenario are configured and registered in the security monitoring device 300 so that the resulting events ultimately caused in each attack scenario are detected with a priority according to the risk of the resulting events.
[0076] When an event that matches a registered attack detection rule is detected by the security monitoring device 300, it is identified which attack scenario the event belongs to. Also, for each event (including the detected event) that belongs to the same attack scenario, the attack detection rule is reconfigured so that the events are detected with a higher priority than the priority used to configure the attack detection rule, and are registered again in the security monitoring device 300.
[0077] Through the above operations, events that constitute an attack scenario with a high risk when it occurs are detected with priority and presented to the user. This reduces the risk that the events of the attack scenario are buried under events of other attack scenarios, and is expected to enable the user to quickly recognize the occurrence of the attack scenario and take action.
[0078] In addition, in each of the above embodiments, functions and means (units) that are not specifically mentioned in relation to the configuration can be realized as follows. Electric circuits, electronic circuits, logic circuits, and integrated circuits incorporating them, as well as microcomputers, processors, and similar arithmetic devices (processing devices) ROM, RAM, flash memory, hard disk, SSD, memory card, optical disk and similar storage devices Buses, networks and similar communication devices Peripheral equipment -Programs executed by any combination of the above.
[0079] Moreover, the present invention is not limited to the above-mentioned embodiment, and various modified examples are included. For example, the above-mentioned embodiment has been described in detail to easily explain the present invention, and is not necessarily limited to those having all the configurations described. Also, it is possible to replace a part of the configuration of a certain embodiment with the configuration of another embodiment, and it is also possible to add the configuration of another embodiment to the configuration of a certain embodiment. Also, it is possible to add, delete, or replace a part of the configuration of each embodiment with another configuration. In particular, the monitored system is not limited to the control system 100, and can be applied to various information processing systems and mobile objects such as automobiles. Also, the present invention includes controlling (including stopping) at least a part of the constituent devices of the monitored system such as the control system 100 in response to detection of a predetermined event including a security attack. [Explanation of symbols]
[0080] 100 Control System 200 Attack detection rule generator 201 Equipment Configuration Model 202 Abnormal Event Model 203 Attack Characteristics Database 210 Attack Scenario Identification Section 211 Attack Scenarios 212 Risk Value 220 Monitoring priority determination unit 221 Monitoring priority 230 Attack detection rule generation unit 231 Attack Detection Rules 300 Security monitoring equipment 410 User terminal 420 Network
Claims
1. An attack detection rule generation device that generates an attack detection rule for detecting a security attack on a monitored system, A storage unit that stores a device configuration model of the monitored system and an abnormal event model that indicates a result event and its influence that may occur when each of the configuration devices of the monitored system is subjected to an abnormal event; an attack scenario identification unit that identifies an attack scenario against the monitored system based on the device configuration model and the abnormal event model, and identifies a risk value of the attack scenario; an attack detection rule generation unit that generates an attack detection rule for detecting a security attack corresponding to an attack scenario in a priority order based on the risk value; An attack detection rule generating device capable of presenting information corresponding to the attack detection rule to a user.
2. 2. The attack detection rule generation device according to claim 1, a monitoring priority determination unit that determines a monitoring priority of a security attack on the monitored system based on the risk value of the attack scenario; The attack detection rule generating unit is an attack detection rule generating device that generates an attack detection rule that gives priority to detecting security attacks corresponding to attack scenarios with higher monitoring priorities.
3. 3. The attack detection rule generation device according to claim 2, an attack scenario determination unit that determines an attack scenario corresponding to a security attack detected by using the attack detection rule and that is notified from a security monitoring device; The monitoring priority determination unit is an attack detection rule generation device that updates the monitoring priority of the determined attack scenario.
4. 2. The attack detection rule generation device according to claim 1, The monitored system is composed of a plurality of components, The attack scenario identification unit is an attack detection rule generation device that identifies the component devices that make up the path of the security attack by chain-like identification of external interfaces from the device causing the security attack using the input source and output destination of each of the component devices.
5. An attack detection rule generation method for generating an attack detection rule for detecting a security attack on a monitored system, the method being executed by an attack detection rule generation device, comprising: a storage unit stores a device configuration model of the monitored system and an abnormal event model indicating a result event and its influence that may occur when each of the configuration devices of the monitored system is subjected to an abnormal event; an attack scenario identification unit identifies an attack scenario against the monitored system and a risk value of the attack scenario based on the device configuration model and the abnormal event model; An attack detection rule generation unit generates an attack detection rule for detecting a security attack corresponding to an attack scenario in a priority order based on the risk value, An attack detection rule generating method capable of presenting information corresponding to the attack detection rule to a user.
6. The attack detection rule generation method according to claim 5, Furthermore, a monitoring priority determination unit determines a monitoring priority of a security attack against the monitored system based on the risk value of the attack scenario; The attack detection rule generating method, wherein the attack detection rule generating unit generates an attack detection rule that gives priority to detecting security attacks corresponding to attack scenarios with higher monitoring priorities.
7. The attack detection rule generation method according to claim 6, Furthermore, an attack scenario determination unit determines an attack scenario corresponding to the security attack detected using the attack detection rule, the attack scenario being notified from the security monitoring device; The attack detection rule generating method includes updating the monitoring priority of the attack scenario determined by the monitoring priority determination unit.
8. The attack detection rule generation method according to claim 5, The monitored system is composed of a plurality of components, An attack detection rule generation method in which the attack scenario identification unit uses the input source and output destination of each of the constituent devices to identify external interfaces in a chain reaction from the device causing the security attack, thereby identifying the constituent devices that make up the path of the security attack.
Citation Information
Patent Citations
Attack monitoring device and attack monitoring method
JP2023060483A