Security management device and security management method

The security management device addresses the issue of false positives in conventional tools by automatically calculating an attack amount and initiating countermeasures, thereby enabling rapid and effective responses to cyber threats.

JP2025080797APending Publication Date: 2025-05-27FUJI ELECTRIC CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023194055
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-15
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Conventional security management tools often produce many false positives, leading to increased human workload and potential delays in responding to actual cyber threats.

Method used

A security management device that collects log information, detects attacks, stores detection history and pattern information, calculates an attack amount based on detected methods, and automatically initiates countermeasures when the attack amount exceeds a threshold.

Benefits of technology

Enables quick and automated response to cyberattacks, reducing the reliance on human analysts and minimizing the risk of delayed countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025080797000001_ABST
    Figure 2025080797000001_ABST
Patent Text Reader

Abstract

To provide a device and method that can immediately respond to cyber-attacks.SOLUTION: A security management device comprises: a log information collection unit, an attack detection unit, an attack detection history storage unit, an attack pattern information storage unit, an attack volume calculation unit, and an attack response unit. The log information collection unit collects log information of a monitored system. The attack detection unit detects attack methods against the monitored system based on the log information. The storage unit stores an attack detection history in which the attack methods detected by the attack detection unit are recorded, and attack pattern information representing an attack pattern composed of a plurality of the attack methods. The attack volume calculation unit extracts an attack method recorded in the attack detection history from among the plurality of attack methods that constitute the attack pattern represented by the attack pattern information, and calculates a volume of attacks based on the extracted attack method. The attack response unit implements response processing to attacks against the monitored system based on the volume of attacks calculated by the attack volume calculation unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus and method for managing security against cyberattacks.

Background Art

[0002] As one of the technologies for detecting cyberattacks on information processing systems or facilities, security management tools such as SIEM (Security Information and Event Management) are known. The SIEM tool detects security threats by analyzing log information managed centrally. When a threat is detected, the SIEM tool outputs information instructing a response process. Note that a method for determining whether to execute countermeasures against cyberattacks has been proposed (for example, Patent Document 1).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, the determination results by conventional security management tools may include many false positives (i.e., events that are not actually threats). For this reason, it is necessary for experts such as security analysts to analyze the determination results of security management tools and determine whether countermeasures are necessary. As a result, the human workload increases, and there is a risk that countermeasures against threats will be delayed.

[0005] An object related to one aspect of the present invention is to provide an apparatus and method that can quickly respond to cyberattacks.

Means for Solving the Problems

[0006] A security management device according to one aspect of the present invention includes a log collection unit that collects log information representing events occurring in a monitoring target system, an attack detection unit that detects an attack method against the monitoring target system based on the log information, an attack detection history storage unit that stores an attack detection history in which the attack method detected by the attack detection unit is recorded, an attack pattern information storage unit that stores attack pattern information representing an attack pattern composed of a plurality of attack methods created based on threat information provided by a threat information collection vendor, an attack amount calculation unit that extracts the attack method recorded in the attack detection history from among the plurality of attack methods constituting the attack pattern represented by the attack pattern information and calculates an attack amount based on the extracted attack method, and an attack countermeasure unit that performs a response process against an attack on the monitoring target system based on the attack amount calculated by the attack amount calculation unit.

Advantages of the Invention

[0007] According to the above aspect, it becomes possible to quickly respond to cyberattacks.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0009] FIG. 1 shows an example of the functional configuration of a security management device according to an embodiment of the present invention. The security management device 10 according to the embodiment of the present invention monitors attacks on the monitored system 20 and performs corresponding processing as necessary. The monitored system 20 is not particularly limited, but includes one or more computers. The monitored system 20 may be a cloud computer system. Further, the monitored system 20 may have one or more edge devices connected thereto.

[0010] The security management device 10 includes a log collection unit 11, an attack detection unit 12, an attack detection history storage unit 13, an attack pattern information creation unit 14, an attack pattern information storage unit 15, an attack amount calculation unit 16, and an attack countermeasure unit 17. Note that the security management device 10 may have other functions not shown in FIG. 1. Also, in FIG. 1, the communication function is omitted.

[0011] The log collection unit 11 may collect, for example, the system logs of the monitored system 20. The system logs may include computer startup / termination / restart, administrator login / logoff, hardware failures, kernel errors, startup / termination of server software / daemons / resident programs, and messages such as notifications / warnings / errors sent from servers / daemons / services. Further, the log collection unit 11 may collect log information on events occurring in the monitored system 20. In this case, the event log information includes, for example, information related to abnormal logins, access failures to protected files, and forgery of security logs. These log information may include information representing the source address, port number, protocol, and date / time. Note that the collection of log information is realized by a known technique.

[0012] The attack detection unit 12 detects an attack on the monitored system 20 from the log information collected by the log collection unit 11 by using a pre-prepared detection rule. The detection rule represents the correspondence between events and / or abnormal events that can occur on a computer and the types of attacks. In this embodiment, the types of attacks are classified based on the "tactics" related to attacks defined by the non-profit organization MITRE in the United States.

[0013] Here, MITRE provides the "Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK)" shown in FIG. 2. ATT&CK is a knowledge base that classifies attacks exploiting vulnerabilities based on tactics and techniques, and systematically represents the flow and methods of cyber attacks.

[0014] In addition, one or more attack methods are associated with each tactic of ATT&CK. For example, for the tactic "Initial Access", the attack methods such as "Drive-by Compromise", "Exploit Public Applications", "External Remote Services", "Hardware Addition", "Phishing", "Replication via Removable Media", "Supply Chain Compromise", "Trust Relationship", and "Valid Accounts" may be associated. Similarly, one or more attack methods are associated with other tactics. The association between each strategy and one or more attack methods may be created by the user of the security management device 10 or by external experts.

[0015] Therefore, the attack detection unit 12 can detect the type of attack on the monitored system 20 (for example, the attack methods associated with each tactic of ATT&CK) by searching for the events and / or abnormal events recorded in the log information with reference to the detection rule. Note that the procedure for detecting the type of attack on the monitored target based on the log information can be realized by known techniques.

[0016] The attack detection history storage unit 13 stores, in chronological order, the attack detection history representing the attack on the monitoring target system 20 detected by the attack detection unit 12. As shown in FIG. 3, the attack detection history includes, for each attack, information representing the detection date and time, the attack method, the source address, the source user, and the destination address. Note that the attack detection history is not limited to these pieces of information, and for example, the port number and protocol may be recorded.

[0017] The detection date and time represents the date and time when an attack on the monitoring target system 20 was detected. The attack method represents the type of the detected attack. In this embodiment, the type of the attack corresponds to the attack method associated with each tactic of ATT&CK. The source address represents the source IP address of the packet related to the detected attack. The source user represents the user related to the detected attack. The destination address represents the IP address of the communication interface that received the packet related to the detected attack or the destination IP address of the packet.

[0018] In the example shown in FIG. 3, an attack related to "valid account" was detected at 13:00 on the ddth day of November 2023. For example, cases where access with an unknown login name or a suspicious login name is detected, cases where a password that is not generally set is input, cases where password authentication failures are repeated, etc. are applicable. Also, an attack related to "abuse for privilege escalation" was detected at 14:00 on the ddth day of November 2023. For example, cases where processing in privileged mode or supervisor mode is requested from an improper account are applicable.

[0019] The attack pattern information creation unit 14 creates attack pattern information based on the threat information provided by the threat information collection vendor 30. The threat information collection vendor 30 constantly collects information related to various cyberattacks occurring around the world. The information collected by the threat information collection vendor 30 represents the type of cyberattack occurring, the type of virus, the region, and the scale, etc. For example, information related to events such as the stoppage of equipment due to ransomware attacks, the leakage of subscriber information, unauthorized access to confidential information, and the unviewability due to the encryption of electronic medical records is collected.

[0020] The user of the security management device 10 can receive threat information from the threat information collection vendor 30 regularly according to a contract or the like. For example, every time the threat information collection vendor 30 detects a new threat, it notifies the contractor of the threat information related to that threat. At this time, the threat information collection vendor 30 may notify the threat information for each campaign. Note that generally, an attacker has know-how including characteristic attack procedures for each attacker and tends to carry out attacks all at once according to events such as events of the system to be attacked, and this may be called a "campaign".

[0021] In this way, the security management device 10 acquires threat information related to newly occurred threats. Then, the attack pattern information creation unit 14 creates attack pattern information based on the threat information acquired from the threat information collection vendor 30. The attack pattern information represents the attack pattern for each campaign, and in this embodiment, it is composed of a plurality of attack methods arranged in a predetermined order.

[0022] FIG. 4 shows an example of a method for creating attack pattern information. In this embodiment, threat information indicating that the threat of "encrypting server data" is spreading is provided from the threat information collection vendor 30. This threat information may include a report describing the characteristics of the procedure from the initial access to the encryption of the data. Also, this threat information may include a proposal regarding the countermeasure method when under attack.

[0023] The attack pattern information creation unit 14 analyzes the attack pattern of "encrypting server data" based on the threat information received from the threat information collection vendor 30. At this time, "encrypting server data" is decomposed into a plurality of procedures from initial access to data encryption. And each procedure is mapped to the tactics of ATT&CK. Furthermore, for each procedure, the attack methods related to "encrypting server data" are extracted from one or more attack methods associated with the tactics.

[0024] For example, in the embodiment shown in FIG. 4(a), "encrypting server data" is decomposed into procedures 1 to 6. Also, procedures 1 to 6 are respectively mapped to "initial access", "execution", "privilege escalation", "lateral movement", "exfiltration", and "impact". Furthermore, "phishing" and "valid account" are extracted from the attack methods associated with "initial access", "user execution" is extracted from the attack methods associated with "execution", "exploitation for privilege escalation" is extracted from the attack methods associated with "privilege escalation", "exploitation of remote service" and "lateral movement of tools" are extracted from the attack methods associated with "lateral movement", "leakage via network media" is extracted from the attack methods associated with "exfiltration", and "data encryption" is extracted from the attack methods associated with "impact".

[0025] Subsequently, the attack pattern information creation unit 14 creates attack pattern information by assigning "weight" and "countermeasure" to each attack method obtained by the above-described mapping process and extraction process. The weight represents the magnitude or severity of the impact of the attack. In this example, the larger the value of the weight, the greater the impact of the attack or the more severe the impact of the attack. The countermeasure represents a method for preventing the spread of the impact of the attack.

[0026] For example, in the embodiment shown in FIG. 4(b), since the impact of phishing on the encryption of server data is not significant, its weight is small and is "1". Also, as a countermeasure when phishing is detected, it is determined to execute a logout. On the other hand, if a leakage occurs via the network medium, it can have a significant impact on the encryption of server data, so its weight is large and is "11". Also, as a countermeasure when a leakage is detected, it is determined to isolate the server.

[0027] In this way, the attack pattern information creation unit 14 creates attack pattern information based on the threat information provided by the threat information collection vendor 30. At this time, the attack pattern information creation unit 14 may create attack pattern information based on the threat information by executing a software program prepared in advance. Also, an expert such as a security analyst may create attack pattern information based on the threat information. In this case, the function of the attack pattern information creation unit 14 is realized by a person (for example, an expert such as a security analyst) operating a computer. Alternatively, the threat information collection vendor 30 may create attack pattern information and provide it to the security management device 10. In this case, the security management device 10 does not need to include the attack pattern information creation unit 14.

[0028] The attack pattern information storage unit 15 stores the attack pattern information created by the attack pattern information creation unit 14. Here, the attack pattern information is created for each campaign (or for each threat). Therefore, a plurality of sets of attack pattern information may be stored in the attack pattern information storage unit 15.

[0029] The attack amount calculation unit 16 periodically searches the attack pattern information storage unit 15 using the attack detection history stored in the attack detection history storage unit 13 within the latest predetermined period. At this time, the attack amount calculation unit 16 extracts the attack methods recorded in the attack detection history from among the plurality of attack methods that constitute the attack pattern represented by the attack pattern information stored in the attack pattern information storage unit 15. Then, the attack amount calculation unit 16 calculates the attack amount on the monitoring target system 20 based on the weights assigned to the extracted attack methods. Note that the attack amount is an example of an index for determining whether to perform corresponding processing for an attack on the monitoring target system 20, and the larger the value, the stronger the degree of corresponding processing should be.

[0030] For example, the attack amount calculation unit 16 searches the attack pattern information storage unit 15 using the attack detection history shown in FIG. 3. At this time, assume that the attack pattern information shown in FIG. 4(b) is stored in the attack pattern information storage unit 15. In this case, the attack amount calculation unit 16 extracts "valid account" detected at 13:00, "abuse for privilege escalation" detected at 14:00, and "leakage via network medium" detected at 15:00 from among the eight attack methods that constitute the attack pattern information shown in FIG. 4(b). Then, the attack amount calculation unit 16 adds up the weights assigned to each of the extracted attack methods in order. As a result, the attack amount history shown in FIG. 5 is obtained.

[0031] In this embodiment, when an attack related to an "effective account" is detected at 13:00, "1" is calculated as the amount of the attack. This value corresponds to the weight assigned to the "effective account". Subsequently, when an attack related to "abuse for privilege escalation" is detected at 14:00, "5" is calculated as the amount of the attack. Here, by 14:00, attacks related to the "effective account" and attacks related to "abuse for privilege escalation" have been detected. Therefore, as the amount of the attack, the sum of the weights respectively assigned to the "effective account" and "abuse for privilege escalation" is calculated. Furthermore, when an attack related to "leakage via a network medium" is detected at 15:00, "16" is calculated as the amount of the attack. Here, by 15:00, attacks related to the "effective account", attacks related to "abuse for privilege escalation", and attacks related to "leakage via a network medium" have been detected. Therefore, as the amount of the attack, the sum of the weights respectively assigned to the "effective account", "abuse for privilege escalation", and "leakage via a network medium" is calculated.

[0032] Based on the amount of the attack calculated by the attack amount calculation unit 16, the attack countermeasure unit 17 performs response processing for an attack on the monitoring target system 20. Specifically, first, an attack amount threshold is set by a user of the security management device 10 or an expert such as a security analyst. The attack amount threshold is an index for determining whether to perform response processing for an attack on the monitoring target system 20. Then, when the amount of the attack calculated by the attack amount calculation unit 16 exceeds the attack amount threshold, the attack countermeasure unit 17 performs response processing for an attack on the monitoring target system 20 based on the response processing information in the attack pattern information.

[0033] For example, in the embodiments shown in FIGS. 4 to 5, assume that the attack amount threshold is "15". In this case, due to the detection of an attack related to "leakage via the network medium" at 15:00, the attack amount exceeds the attack amount threshold. Then, the attack countermeasure unit 17 implements "server isolation", which is the corresponding process set for "leakage via the network medium" in the attack pattern information. At this time, the attack countermeasure unit 17 blocks the communication related to the IP address of the server in which information leakage has been detected within the monitored system 20. This avoids further information leakage.

[0034] As another example, assume that the attack amount threshold is "4". In this case, due to the detection of an attack related to "abuse for privilege escalation" at 14:00, the attack amount exceeds the attack amount threshold. Then, the attack countermeasure unit 17 implements "access block", which is the corresponding process set for "abuse for privilege escalation" in the attack pattern information. At this time, the attack countermeasure unit 17 blocks the communication between the source IP address detected at 14:00 and the monitored system 20. After that, when an attack related to "leakage via the network medium" is detected at 15:00, server isolation is implemented in the same manner as in the above case.

[0035] In this way, when the cumulative value of the weight of the attack on the monitored system 20 (i.e., the attack amount) exceeds a predetermined threshold, the security management device 10 immediately and automatically implements corresponding processing on the monitored system 20. Therefore, it is possible to avoid the spread of damage caused by attacks without relying on experts such as security analysts or while reducing the labor of experts such as security analysts. In addition, since the security management device 10 monitors attacks using the latest threat information provided by the threat information collection vendor 30, accurate security measures can be taken.

[0036] FIG. 6 is a flowchart showing an example of the operation of the security management apparatus 10. In this embodiment, it is assumed that attack pattern information created based on threat information provided from the threat information collection vendor 30 is stored in the attack pattern information storage unit 15.

[0037] In S1 to S2, the log collection unit 11 constantly collects log information of the monitoring target system 20. Then, the attack detection unit 12 monitors an attack on the monitoring target system 20 based on the log information. As a result, when an attack on the monitoring target system 20 is detected, in S3, the attack detection unit 12 records an attack detection history representing the detected attack in the attack detection history storage unit 13.

[0038] When a new attack detection history is recorded in the attack detection history storage unit 13, in S4, the attack amount calculation unit 16 calculates the attack amount. At this time, the attack amount calculation unit 16 calculates the attack amount by cumulatively adding the weights of the attacks detected from a predetermined trigger time to the current time.

[0039] In S5, the attack countermeasure unit 17 compares the attack amount calculated in S4 with a predetermined attack amount threshold. As a result, if the attack amount is equal to or less than the attack amount threshold, the process of the security management apparatus 10 returns to S1. That is, the processes of S1 to S5 are repeatedly executed until the attack amount exceeds the attack amount threshold. At this time, each time an attack is detected, the value of the attack amount increases. Then, when the attack amount exceeds the attack amount threshold, in S6, the attack countermeasure unit 17 specifies and executes a response process for the attack on the monitoring target system 20 based on the response process information in the attack pattern information.

[0040] As described above, in the security management method according to the embodiment of the present invention, each time an attack on the monitoring target system 20 is detected, the attack amount representing the severity of the impact of the attack on the monitoring target system 20 increases. Then, when this attack amount exceeds the threshold, a response process is immediately and automatically performed on the monitoring target system 20.

[0041] In the above procedure, the attack amount increases each time an attack is detected. Therefore, for example, in a case where small attacks (here, attack methods with small weights) are repeated, the attack amount may reach the attack amount threshold without receiving a significant attack (here, an attack method with a large weight). Thus, it is preferable that the attack amount be reset periodically as needed. For example, the attack amount calculation unit 16 may reset the value of the attack amount every few hours.

[0042] <Variation> The security management device 10 preferably has attack pattern information for each campaign in order to cope with various patterns of cyberattacks. In the example shown in FIG. 7, attack pattern information is created for each of the three attack patterns. Attack pattern A represents the encryption of server data by an attacker, attack pattern B represents the destruction of server data by an attacker, and attack pattern C represents the manipulation of server data by an attacker. Each attack pattern information is created, for example, by an expert such as a security analyst. At this time, an expert such as a security analyst may create the attack pattern information in cooperation with the threat information collection vendor 30. Alternatively, when the threat information collection vendor 30 creates the attack pattern information, the security management device 10 may acquire the attack pattern information from the threat information collection vendor 30.

[0043] The security management device 10 recognizes attack patterns to be monitored according to the threat information provided by the threat information collection vendor 30. The threat information represents, for example, warning information related to a cyber-attack campaign in which damage is spreading. Subsequently, the security management device 10 selects attack pattern information corresponding to the provided threat information from among a plurality of pieces of attack pattern information stored in the attack pattern information storage unit 15. For example, when there are frequent occurrences of damage caused by ransomware that encrypts server data and demands a ransom in exchange for the decryption key, the attack pattern information representing attack pattern A is selected. Then, the security management device 10 executes the procedure of the flowchart shown in FIG. 6 using the selected attack pattern information. As a result, it is possible to quickly respond to a cyber-attack in which damage is spreading.

[0044] Also, in the above case, attack pattern information corresponding to the threat information is selected and used from among a plurality of pieces of attack pattern information stored in the attack pattern information storage unit 15, but the variations of the present invention are not limited to this procedure. That is, the security management device 10 may calculate the amount of attack for each of a plurality or all of the attack pattern information stored in the attack pattern information storage unit 15.

[0045] For example, as shown in FIG. 7, it is assumed that attack pattern information has been created for attack patterns A to C respectively. Also, it is assumed that the attack amount threshold is 10. And it is assumed that the attack detection unit 12 sequentially detects "phishing", "account operation", "forced authentication", and "interception of multi-factor authentication" in this order. In this case, the attack amount calculated for attack pattern A is 1, the attack amount calculated for attack pattern B is 3, and the attack amount calculated for attack pattern C is 12. That is, the attack amount calculated for attack pattern C exceeds the attack amount threshold. Then, the security management device 10 determines that the monitored system 20 has been attacked with attack pattern C. Here, the attack method that triggered the attack amount exceeding the attack amount threshold is "interception of multi-factor authentication". Therefore, in this case, the security management device 10 performs the corresponding process (that is, access blocking) set for "interception of multi-factor authentication".

[0046] <Hardware Configuration> FIG. 8 shows an example of the hardware configuration of the security management device 10. The security management device 10 is realized by a computer 200 including a processor 201, a memory 202, a storage device 203, an input / output device 204, a recording medium reader 205, and a communication interface 206.

[0047] The processor 201 controls the operation of the security management device 10 by executing the security management program stored in the storage device 203. The security management program includes program codes describing the procedures of the flowchart shown in FIG. 6. Therefore, by the processor 201 executing this program, the functions of the log collection unit 11, the attack detection unit 12, the attack pattern information creation unit 14, the attack amount calculation unit 16, and the attack countermeasure unit 17 shown in FIG. 1 are provided. The memory 202 is used as a working area for the processor 201. The storage device 203 stores the security management program and other programs. Note that the attack detection history storage unit 13 and the attack pattern information storage unit 15 are realized by using the storage device 203.

[0048] The input / output device 204 includes input devices such as a keyboard, a mouse, a touch panel, and a microphone. The input / output device 204 also includes output devices such as a display device and a speaker. The recording medium reader 205 can acquire data and information recorded on the recording medium 210. The recording medium 210 is a removable recording medium detachable from the computer 200. Further, the recording medium 210 is realized by, for example, a semiconductor memory, a medium that records signals by optical action, or a medium that records signals by magnetic action. Note that the security management program may be provided from the recording medium 210 to the computer 200. The communication interface 206 provides a function of connecting to a network. When the security management program is stored in the program server 220, the computer 200 may acquire the security management program from the program server 220.

Explanation of Signs

[0049] 10 Security management device 11 Log collection unit 12 Attack detection unit 13 Attack detection history storage unit 14 Attack pattern information creation unit 15 Attack pattern information storage unit 16 Attack amount calculation unit 17 Attack countermeasure unit 20 System to be monitored 30 Threat information collection vendor 200 Computer 201 Processor

Claims

1. A log collection unit that collects log information representing events occurring in a system to be monitored, An attack detection unit that detects an attack method against the system to be monitored based on the log information, An attack detection history storage unit that stores an attack detection history in which the attack method detected by the attack detection unit is recorded, An attack pattern information storage unit that stores attack pattern information representing an attack pattern composed of a plurality of attack methods, the attack pattern information being created based on threat information provided by a threat information collection vendor, An attack amount calculation unit that extracts the attack method recorded in the attack detection history from among a plurality of attack methods constituting the attack pattern represented by the attack pattern information, and calculates an attack amount based on the extracted attack method, An attack countermeasure unit that performs a countermeasure process against an attack on the system to be monitored based on the attack amount calculated by the attack amount calculation unit, A security management device comprising:

2. The attack pattern information includes weight information representing a weight for each of a plurality of attack methods constituting the attack pattern, The attack amount calculation unit calculates the attack amount by adding up the weights corresponding to the attack methods extracted from the attack pattern information in the order detected by the attack detection unit. The security management device according to claim 1, characterized in that.

3. The attack pattern information includes response process information representing a response process set for each of a plurality of attack methods constituting the attack pattern, When the attack amount exceeds a predetermined threshold due to the first attack method being detected by the attack detection unit, the attack countermeasure unit performs the response process set for the first attack method on the system to be monitored. The security management device according to claim 2, characterized in that.

4. The attack countermeasure unit performs, on the system to be monitored, the response process set for the first attack method and the response process set for the attack methods detected after the first attack method based on the response process information. The security management device according to claim 3, characterized in that.

5. The attack pattern information storage unit stores a plurality of attack pattern information corresponding to a plurality of attack patterns. The attack amount calculation unit calculates the attack amount by using attack pattern information selected from among a plurality of pieces of attack pattern information based on the threat information provided by the threat information collection vendor. The security management apparatus according to claim 2, characterized in that.

6. In the attack pattern information storage unit, a plurality of pieces of attack pattern information corresponding to a plurality of attack patterns are stored. The attack amount calculation unit calculates an attack amount for each of the plurality of attack patterns. The attack countermeasure unit performs a response process on the monitored system based on the attack pattern in which the attack amount calculated by the attack amount calculation unit first exceeds a predetermined threshold value, or based on the attack pattern in which the attack amount calculated by the attack amount calculation unit is the largest. The security management apparatus according to claim 2, characterized in that.

7. Collect log information representing events occurring in the monitored system. Detect an attack method against the monitored system based on the log information. Save an attack detection history recording the detected attack method. Save attack pattern information representing an attack pattern composed of a plurality of attack methods created based on the threat information provided by the threat information collection vendor. Extract the attack method recorded in the attack detection history from among the plurality of attack methods constituting the attack pattern represented by the attack pattern information, and calculate an attack amount based on the extracted attack method. Perform a response process against the attack on the monitored system based on the calculated attack amount. A security management method, characterized in that.

Citation Information

Patent Citations

  • Security management apparatus

    JP2021140460A