Countermeasure plan creation support device
The countermeasure plan creation support device addresses the challenge of unaddressed vulnerabilities in production facilities by using historical process configurations to create alternative plans, calculate vulnerabilities, and generate effective countermeasures, thereby maintaining productivity.
Patent Information
- Application Number
- JP2023204839
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-16
AI Technical Summary
Existing technologies do not effectively create threat scenarios based on past device configurations or determine the vulnerability of production facilities, leading to potential decreases in productivity due to unaddressed vulnerabilities.
A countermeasure plan creation support device that utilizes process configuration history information to create alternative process configurations, calculates vulnerability levels for production facilities, and generates countermeasure plans to minimize the impact of vulnerabilities on production activities.
The device effectively suppresses decreases in productivity by creating countermeasure plans that address vulnerabilities in production facilities, ensuring continuity and availability of production processes.
Smart Images

Figure 2025089888000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a device for supporting the creation of countermeasure plans.
Background Art
[0002] In recent years, the risk of cyber security has been increasing even in production sites such as manufacturing factories. For example, when the vulnerability of a control system that controls production equipment such as a production line or a management system that manages information such as a production plan is targeted by a cyber attack, events such as production stoppage may occur, causing serious damage to the manufacturing site.
[0003] In order to avoid such damage, it is necessary to take appropriate measures against the vulnerability information of production equipment that is publicly available every day. However, factory system administrators, including control systems and management systems, often cannot immediately take measures against the disclosed vulnerabilities. One of the reasons is that in the manufacturing industry, the continuity and availability of business and production are particularly emphasized from the perspective of production evaluation indicators such as meeting delivery deadlines and reducing costs.
[0004] Under such circumstances, there is an expectation for a device or software that supports the creation of a countermeasure plan for the vulnerability of production equipment while suppressing the impact on production activities in a planned manner.
[0005] Patent Document 1 describes a control system that creates a countermeasure scenario in which countermeasures for each protected asset of a controller system are stored according to a threat scenario created from importance and threat level and countermeasures in a countermeasure database according to device configuration and protected assets.
[0006] Patent Document 2 describes a production management device that creates a recovery plan according to a predetermined production evaluation index based on the repair time determined based on the failure information of equipment for producing products and the production information of the line of the failed equipment, other equipment, and the line.
Prior Art Documents
Patent Document
[0007]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0008] Although the control system of Patent Document 1 creates a threat scenario based on the current device configuration, it does not disclose a means for creating a threat scenario based on a device configuration with a proven track record in the past. Furthermore, the production management device of Patent Document 2 does not disclose a means for determining the vulnerability of production facilities.
[0009] Therefore, the present invention has been made in view of the above problems, and an object thereof is to provide a technique for suppressing a decrease in productivity due to the vulnerability of production facilities.
Means for Solving the Problems
[0010] In order to solve the above object, the present invention is a countermeasure plan creation support device that supports the creation of a countermeasure plan for the vulnerability of production facilities included in a process configuration for executing a production plan, and based on process configuration history information for each of a plurality of past production plans, an alternative process configuration plan creation unit that creates an alternative process configuration plan to replace the process configuration of the current production plan, a vulnerability calculation unit that calculates the vulnerability level for each of the production facilities based on the vulnerability information of the production facilities, a risk level calculation unit that calculates the risk level of the current production plan based on the vulnerability level, and a countermeasure plan creation unit that creates a countermeasure plan to replace the current production plan based on the alternative process configuration plan, and an output unit that outputs the alternative process configuration plan, the countermeasure plan, and an evaluation index including the risk level.
Effects of the Invention
[0011] According to the present invention, a decrease in productivity due to the vulnerability of production equipment is suppressed.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Modes for Carrying Out the Invention
[0013] Hereinafter, a specific example of the countermeasure plan creation support device according to an embodiment of the present invention will be described with reference to the drawings. Note that the present invention is not limited by the examples, but is indicated by the scope of the claims.
Examples
[0014] FIG. 1 is a functional block diagram of the countermeasure plan creation support device according to Embodiment 1.
[0015] The countermeasure plan creation support device 10 supports the creation of a countermeasure plan for the vulnerability of production facilities included in the process configuration for executing a production plan. The process configuration may include workers, machines or jigs including production facilities, work procedures, and materials. Hereinafter, taking the initial letter M of these workers (Machine), machines (Man), work procedures (Method), and materials (Material), these may also be referred to as 4M. The countermeasure plan creation support device 10 is a computer equipped with a storage device, a calculation processing device, and a communication device. Note that the hardware configuration of the computer that realizes the countermeasure plan creation support device 10 and the like will be described later with reference to FIG. 2.
[0016] The countermeasure plan creation support device 10 includes a process configuration information acquisition unit 11, a process configuration history DB 12, an alternative process configuration plan creation unit 13, a process configuration storage unit 14, a vulnerability calculation unit 15, a countermeasure plan creation unit 16, and an output unit 17.
[0017] The process configuration information acquisition unit 11 acquires performance information 21 for each process configuration of a plurality of past production plans and production performance 22. The production performance 22 may include workers, working methods, and product types for each process configuration. The process configuration information acquisition unit 11 extracts process configuration history information 40 (described later in FIG. 4) for each of the plurality of past production plans based on the acquired performance information 21.
[0018] The process configuration history DB 12 stores the process configuration history information 40 for each of the plurality of past production plans extracted by the process configuration information acquisition unit 11.
[0019] The alternative process configuration plan creation unit 13 acquires the process configuration information 23 of the current production plan 26 and the process configuration history information 40 for each of the plurality of past production plans stored in the process configuration history DB 12. The process configuration information 23 includes the process configuration of the current production plan 26. The alternative process configuration plan creation unit 13 creates an alternative process configuration plan 24 to replace the process configuration of the current production plan 26 based on the acquired process configuration history information 40 for each of the plurality of past production plans.
[0020] The process configuration storage unit 14 stores the process configuration information 23 of the current production plan 26 and the alternative process configuration plan 24 created by the alternative process configuration plan creation unit 13.
[0021] The vulnerability calculation unit 15 acquires the vulnerability information 25 disclosed by the vendor etc. of the production equipment, and calculates the vulnerability for each production equipment based on the acquired vulnerability information 25.
[0022] The countermeasure plan creation unit 16 acquires the current production plan 26, the date and time statistical information 27 of the cyber attack, the process configuration information 23 of the current production plan 26 and the alternative process configuration plan 24 stored in the process configuration storage unit 14, and the vulnerability for each production equipment calculated by the vulnerability calculation unit 15. The current production plan 26 may include the operator, the working method, and the product type for each process configuration. The countermeasure plan creation unit 16 calculates the risk level of the current production plan 26 based on the vulnerability, and creates a countermeasure plan 28 to replace the current production plan 26 based on the alternative process configuration plan 24.
[0023] Furthermore, the countermeasure plan creation unit 16 may generate a prediction model (to be described later with reference to FIG. 8) that predicts the attack arrival probability to the production equipment over time based on the date and time statistical information 27, and determine the change deadline from the process configuration in the current production plan 26 to the alternative process configuration plan 24 based on the prediction model. Furthermore, the countermeasure plan creation unit 16 calculates the influence degree from the production equipment having vulnerability among the production equipment to other production equipment, and may calculate an evaluation index 29 including the risk level of the current production plan 26 based on the calculated influence degree and risk level.
[0024] The output unit 17 outputs an alternative process configuration plan 24, a countermeasure plan 28, and an evaluation index 29 including a risk level. The evaluation index 29 may include a productivity evaluation index indicating the productivity of the alternative process configuration plan 24 and a security risk evaluation index for production equipment. Further, the output unit 17 may preferentially output the alternative process configuration plan 24 and the countermeasure plan 28 having a high or low risk level among the evaluation indexes 29.
[0025] FIG. 2 is a block diagram showing the hardware configuration of the countermeasure plan creation support device according to Embodiment 1.
[0026] The countermeasure plan creation support device 10 is realized by, for example, a computer 100 as shown in FIG. 2. The computer 100 includes a storage device 101, a calculation processing device 102, a communication device 103, and an input / output interface 104.
[0027] The storage device 101 may include, for example, a so-called main storage device composed of a semiconductor memory and a so-called auxiliary storage device composed of a large-capacity storage device such as a hard disk drive or a solid state drive. Programs and data executed by the calculation processing device 102 are stored in the storage device 101.
[0028] The calculation processing device 102 executes various processes according to the programs stored in the storage device 101. By operating the calculation processing device 102 according to the programs, various functional units are realized. For example, each function of the countermeasure plan creation support device 10 is realized by the calculation processing device 102 operating according to the programs stored in the storage device 101 in the computer 100 corresponding to the countermeasure plan creation support device 10.
[0029] The communication device 103 is an interface for connection to other communication networks. The input / output interface 104 may include an input device such as at least one of a keyboard, a mouse, and a touch panel, and an output device such as an image display device.
[0030] Figure 3 is a flowchart showing the process configuration information acquisition process according to Embodiment 1.
[0031] The process configuration information acquisition unit 11 reads the performance information 21 for each process configuration of a plurality of past production plans and the production performance 22 (S31).
[0032] The process configuration information acquisition unit 11 analyzes the process configuration (business type and 4M configuration) based on the performance information 21 for each process configuration of a plurality of past production plans (S32). Specifically, the process configuration information acquisition unit 11 extracts information on the production capacity of the production equipment (whether it can be used in a certain process) and the support capacity of the jig (whether it can be used in a certain process or work procedure).
[0033] The process configuration information acquisition unit 11 analyzes the operator's information based on the production performance 22 for each process configuration of a plurality of past production plans (S33). Specifically, the process configuration information acquisition unit 11 extracts information on the operator's skills (whether a certain machine can be used, whether support by a jig is required).
[0034] The process configuration information acquisition unit 11 stores the extracted information (production capacity of the production equipment, support capacity of the jig, and operator's skills) in the process configuration history DB 12 (S34).
[0035] Figure 4 is a diagram showing an example of the data structure of the process configuration history information according to Embodiment 1.
[0036] The process configuration history information 40 includes a process (past) information table 41, a process-related (past) information table 42, and a process configuration (past) information table 43.
[0037] The Process (Past) Information Table 41 is a table that stores, as item values (column values), the business ID, business type, process ID, material ID (input), and product ID (output). The business ID is a number that uniquely identifies a business. The business type is the type of business. The process ID is a number that uniquely identifies the process including this business. The material ID (input) is a number that uniquely identifies the material used in this business. The product ID (output) is a number that uniquely identifies the product manufactured in this business.
[0038] As an example, the first row of the Process (Past) Information Table 41 will be described. The first row pertains to the business ID "A0001". In this first row, it means that the business type is "Line Inflow", the process ID is "P0001", the material ID (input) is "M001,M002", and the product ID (output) is "M010".
[0039] The Process-Related (Past) Information Table 42 is a table that stores, as item values (column values), the business ID, previous process, next process, and component. The business ID is a number that uniquely identifies a business. The previous process is a number that uniquely identifies the previous process of the process including this business. The next process is a number that uniquely identifies the next process of the process including this business. The component is a number that uniquely identifies the element of the process configuration related to this business.
[0040] As an example, the first row of the Process-Related (Past) Information Table 42 will be described. The first row pertains to the business ID "A0001". In this first row, it means that the previous process is "null", the next process is "A0003", and the component is "N0001,N0003,…".
[0041] The Process Configuration (Past) Information Table 43 is a table that stores, as item values (column values), the configuration ID, name, configuration type, and ID. The configuration ID is a number that uniquely identifies a process configuration. The name is the name of the process configuration. The configuration type is the type of the process configuration. The ID is a number that uniquely identifies the name of the process configuration.
[0042] As an example, the first row of the process configuration (past) information table 43 will be described. The first row means that the configuration ID is "N0001", the name is "Robot Arm A", the configuration type is "Machine", and the ID is "as0001".
[0043] FIG. 5 is a flowchart showing the alternative process configuration plan creation process according to Embodiment 1.
[0044] The alternative process configuration plan creation unit 13 reads the process configuration information 23 of the current production plan 26 (S51).
[0045] Based on the process configuration history information 40 for each of the plurality of past production plans acquired, the alternative process configuration plan creation unit 13 creates a process configuration plan (alternative process configuration plan) 24 that can be used as an alternative to the process configuration of the current production plan 26 (S52).
[0046] For example, for the jig of the process configuration, a plan to use a jig different from the inoperable jig may be created for the alternative process configuration plan 24, or for the worker of the process configuration, a plan may be created in which a skilled worker works instead of an apprentice who requires a support jig. Further, for the machine of the process configuration, a plan to use a machine of a different vendor from the machine having vulnerability may be created for the alternative process configuration plan 24, or for the material (parts) of the process configuration, a plan to use parts different from the inoperable parts may be created.
[0047] Conditions may be set for the alternative process configuration plan 24. For example, the alternative process configuration plan 24 may have the same process configuration type (such as welding, painting, etc.), or may be the same including the previous and subsequent processes. Further, the alternative process configuration plan 24 may be for products of the same type or product types with compatibility manufactured by the production equipment. Thereby, the higher the similarity between the process configuration of the current production plan 26 and the alternative process configuration plan 24, the higher the applicability of the alternative process configuration plan 24 can be enhanced.
[0048] Furthermore, in the case where the process configuration is an operator, the alternative process configuration plan 24 may set, as a condition, the information on the operator's skills (whether a certain machine can be used or assistance by jigs is required) extracted in S23 of the process configuration information acquisition process.
[0049] The alternative process configuration plan creation unit 13 stores the process configuration information 23 of the current production plan 26 and the alternative process configuration plan 24 (S53).
[0050] FIG. 6 is a flowchart showing the countermeasure plan creation process according to Embodiment 1.
[0051] The countermeasure plan creation unit 16 reads the current production plan 26 (S61). The countermeasure plan creation unit 16 reads out the process configuration information 23 of the current production plan 26 and the alternative process configuration plan 24 from the process configuration storage unit 14, and also reads out the vulnerability for each production facility calculated by the vulnerability calculation unit 15 (S62).
[0052] The countermeasure plan creation unit 16 calculates the risk level of the current production plan 26 based on the vulnerability (S63). The risk level may be an index considering the decrease in the production evaluation index (such as the delivery compliance rate of the products manufactured by the production facility) when the production facility having the vulnerability stops, and the susceptibility of the cyber attack on each production facility.
[0053] The countermeasure plan creation unit 16 calculates the influence degree from the production facility having the vulnerability among the production facilities to other production facilities, and calculates an evaluation index 29 including the risk level of the alternative process configuration plan 24 based on the calculated influence degree and risk level (S64). The influence degree may include a secondary influence (secondary infection).
[0054] The countermeasure plan creation unit 16 acquires the date and time statistical information 27 of the cyber attack, and generates a prediction model (described later with reference to FIG. 8) that predicts the probability of an attack reaching the production facility over time based on the acquired date and time statistical information 27. The countermeasure plan creation unit 16 determines the deadline for changing from the process configuration in the current production plan 26 to the alternative process configuration plan 24 based on the generated prediction model (S65).
[0055] The countermeasure plan creation unit 16 creates, as the countermeasure plan 28 by the deadline, a production plan in which the process configuration in the current production plan 26 is changed to the alternative process configuration plan 24 (S66).
[0056] FIG. 7 is a diagram for explaining the evaluation index according to Embodiment 1.
[0057] The evaluation index 29 is managed by the risk analysis table 70. The risk analysis table 70 stores, as item values (column values), assets, threats (attack methods), and evaluation indexes. The asset is the name of the production facility (machine). The threat (attack method) is the name of the attack method against the production facility. The evaluation index has a threat level, a vulnerability level, an importance level, and a risk value.
[0058] As an example, the first row of the risk analysis table 70 will be described. The first row relates to the asset "Arm PLC". In this first row, it means that the threat (attack method) is "illegal access", the threat level is "2", the vulnerability level is "2", the importance level is "2", and the risk value is "B".
[0059] For example, the importance level is calculated as follows. First, the countermeasure plan creation unit 16 acquires the performance data 71 for each process configuration of a plurality of production plans. The performance information 21 may be a file in json format.
[0060] The countermeasure plan creation unit 16 generates an influence model 72 between devices (production facilities) and a process model 73 based on the performance data 71. The countermeasure plan creation unit 16 generates an evaluation scenario 74 based on the performance data 71 and the influence model 72.
[0061] Based on the process model 73 and the evaluation scenario 74, the countermeasure plan creation unit 16 evaluates the impact on the business and calculates a key performance indicator (KPI) 75 of importance as an example of "importance". The impact may be evaluated using a prepared trial calculation tool or the like. The importance KPI may include lost profit, business downtime, and the like.
[0062] FIG. 8 is a diagram for explaining the prediction model according to Embodiment 1.
[0063] A prediction model for predicting the probability of an attack reaching production equipment will be described. For example, in the prediction model, when the horizontal axis represents the passage of time and the vertical axis represents the number of port scans, the graph shows that the number of port scans increases with the passage of time. Based on the prediction model, the probability of an attack reaching (expected) will be "medium" X days from now and "high" Y days from now.
[0064] According to this configuration, the countermeasure plan creation support device 10 supports the creation of a countermeasure plan for the vulnerability of production equipment included in the process configuration for executing the production plan 26. The countermeasure plan creation support device 10 includes an alternative process configuration plan creation unit 13, a vulnerability calculation unit 15, a countermeasure plan creation unit 16, and an output unit 17. The alternative process configuration plan creation unit 13 creates an alternative process configuration plan 24 that replaces the process configuration of the current production plan 26 based on the process configuration history information 40 for each of a plurality of past production plans. The vulnerability calculation unit 15 calculates the vulnerability for each production equipment based on the vulnerability information 25 of the production equipment. The countermeasure plan creation unit 16 calculates the risk level of the current production plan 26 based on the vulnerability and creates a countermeasure plan 28 that replaces the current production plan 26 based on the alternative process configuration plan 24. The output unit 17 outputs the alternative process configuration plan 24, the countermeasure plan 28, and an evaluation index 29 including the risk level.
[0065] Accordingly, based on the process configuration history information 40 for each of a plurality of past production plans, an alternative process configuration plan 24 can be created, suppressing a decrease in productivity due to the vulnerability of production facilities.
[0066] Furthermore, performance information 21 on workers for each process configuration of a plurality of past production plans, machines or jigs included in the production facilities, work procedures, and materials is acquired, and based on the acquired performance information 21, a process configuration information acquisition unit 11 that extracts process configuration history information 40 is provided. Accordingly, based on the 4M performance information for each process configuration of a plurality of past production plans, the process configuration history information 40 can be extracted.
[0067] Furthermore, the alternative process configuration plan creation unit 13 creates an alternative process configuration plan 24 in which the types of process configurations are the same, or an alternative process configuration plan 24 in which the types of products manufactured by the production facilities are the same or mutually compatible. Accordingly, the alternative process configuration plan 24 can be easily created.
[0068] Furthermore, the risk level includes a production evaluation index indicating the productivity of the alternative process configuration plan 24 and a security risk evaluation index for the production facilities, and the countermeasure plan creation unit 16 calculates the production evaluation index and the security risk evaluation index. Accordingly, the risk level can be evaluated from the viewpoints of productivity and security risk.
[0069] The output unit 17 outputs the alternative process configuration plan 24, the countermeasure plan 28, the production evaluation index, and the security risk evaluation index. Accordingly, it becomes easier for the user to select an appropriate countermeasure plan.
[0070] Furthermore, the countermeasure plan creation unit 16 calculates the degree of influence from the production facilities having vulnerability among the production facilities to other production facilities, and based on the calculated degree of influence and risk level, calculates an evaluation index 29 of the current production plan 26. Accordingly, the evaluation index 29 considering the secondary influence between production facilities can be calculated.
[0071] Furthermore, based on the risk level, the output unit 17 preferentially outputs an alternative process configuration plan and a countermeasure plan with a high or low risk level. This makes it easier for the user to recognize an alternative process configuration plan and a countermeasure plan with a high or low risk.
[0072] Furthermore, the countermeasure plan creation unit 16 acquires the date and time statistical information 27 of the cyber-attack on the production facility, generates a prediction model for predicting the attack arrival probability on the production facility over time based on the acquired date and time statistical information 27, and determines the deadline for changing from the process configuration in the current production plan 26 to the alternative process configuration plan 24 based on the generated prediction model. This enables the user to appropriately grasp the timing of changing from the process configuration in the current production plan 26 to the alternative process configuration plan 24.
Example
[0073] Hereinafter, an example in which the countermeasure plan creation support device shown in Example 1 is partially modified will be described with reference to FIG. 9. Example 2 shows an example in which the countermeasure plan creation support device 30 has a comprehensive evaluation value calculation unit 31. In the following description, the same components as those in Example 1 are denoted by the same reference numerals, and the description thereof is simplified.
[0074] The comprehensive evaluation value calculation unit 31 calculates a countermeasure date (lead time) as an example of a "deadline" at which both the production evaluation index and the security risk evaluation index are optimal. When the comprehensive evaluation value calculation unit 31 divides the evaluation index into two types, a main evaluation index (KPI) and other evaluation indexes (PI), the main evaluation index (KPI) is set as the most important index value, and the other evaluation indexes (PI) are set as index values other than the main evaluation index (KPI).
[0075] The comprehensive evaluation value calculation unit 31 acquires various parameters from the parameter influence storage unit 32. For example, the key performance indicators (KPIs) may include, as parameters, production evaluation indicators, such as the on-time delivery rate of production products manufactured by production equipment, and security risk evaluation indicators, such as the probability of an attack reaching the production equipment. For example, the on-time delivery rate, the probability of an attack reaching, and the countermeasure date (grace period) are related such that as the countermeasure date (grace period) elapses, the on-time delivery rate decreases and the probability of an attack reaching increases. Other evaluation indicators (PIs) may include, as parameters, the inventory level and the equipment operation rate.
[0076] Based on the production evaluation indicators, such as the on-time delivery rate, and the security risk evaluation indicators, such as the probability of an attack reaching, the comprehensive evaluation value calculation unit 31 calculates the countermeasure date (grace period) as the comprehensive evaluation value. Let the weight coefficient of the on-time delivery rate be α and the weight coefficient of the probability of an attack reaching be β. Then, the comprehensive evaluation value is represented by the following formula 1. Comprehensive evaluation value = α × (on-time delivery rate) - β × (probability of an attack reaching) ··· (Formula 1) At this time, the comprehensive evaluation value is calculated only based on the KPIs. The weight coefficients of α and β may be set by a manager in the production technology department or the information system department, etc. The comprehensive evaluation value calculation unit 31 may calculate, as the comprehensive evaluation value, the countermeasure date with the highest comprehensive evaluation value based on the countermeasure date and the combination of various parameters.
[0077] Furthermore, the comprehensive evaluation value calculation unit 31 may determine which parameter among the adjustable parameters has a positive impact on the key performance indicators (KPIs) and perform a parameter adjustment process to adjust that parameter.
[0078] In the parameter adjustment process, the comprehensive evaluation value calculation unit 31 determines, based on the production results 22 or the production simulation results, the parameter that contributes to the change in the value of the KPIs and the direction of its change (+ / -).
[0079] Next, when calculating the comprehensive evaluation value for each countermeasure date, the comprehensive evaluation value calculation unit 31 varies the parameter (referred to as the parameter to be adjusted) in the direction in which the KPI changes positively. Other processes are the same as those for calculating the comprehensive evaluation value. Incidentally, when creating the countermeasure plan 28, the comprehensive evaluation value calculation unit 31 ignores the PI and evaluates considering only the KPI. As a result, there is room for optimization in the parameter to be adjusted.
[0080] According to this configuration, the countermeasure plan creation unit 16 determines the deadline for changing from the process configuration in the current production plan 26 to the alternative process configuration plan 24 based on the delivery compliance rate of the products manufactured by the production equipment and the attack arrival probability. Thereby, considering both the delivery compliance rate and the attack arrival probability, the deadline for changing from the process configuration in the current production plan 26 to the alternative process configuration plan 24 can be determined.
[0081] Note that the present invention is not limited to the above-described embodiments and includes various modifications. For example, the above-described embodiments have been described in detail for easy understanding of the present invention and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Further, for a part of the configuration of each embodiment, addition, deletion, or replacement with other configurations is possible.
Explanation of Reference Numerals
[0082] 10... Countermeasure plan creation support device, 11... Process configuration information acquisition unit, 13... Alternative process configuration plan creation unit, 15... Vulnerability calculation unit, 16... Countermeasure plan creation unit, 17... Output unit, 21... Performance information, 23... Process configuration information, 24... Alternative process configuration plan, 25... Vulnerability information, 26... Production plan, 27... Date and time statistical information, 28... Countermeasure plan, 29... Evaluation index, 30... Countermeasure plan creation support device, 40... Process configuration history information
Claims
1. A countermeasure plan creation support device for supporting the creation of a countermeasure plan against the vulnerability of production equipment included in a process configuration for executing a production plan, an alternative process configuration plan creation unit that creates an alternative process configuration plan to replace the process configuration of the current production plan based on process configuration history information for each of a plurality of past production plans; a vulnerability calculation unit that calculates the vulnerability of each production equipment based on the vulnerability information of the production equipment; a countermeasure plan creation unit that calculates the risk level of the current production plan based on the vulnerability and creates a countermeasure plan to replace the current production plan based on the alternative process configuration plan; and an output unit that outputs the alternative process configuration plan, the countermeasure plan, and evaluation indicators including the risk level. A countermeasure plan creation support device.
2. A process configuration information acquisition unit that acquires performance information of workers for each process configuration of the plurality of past production plans, machines or jigs included in the production equipment, work procedures, and materials, and extracts the process configuration history information based on the acquired performance information. The countermeasure plan creation support device according to claim 1.
3. The alternative process configuration plan creation unit creates the alternative process configuration plan having the same type of process configuration, or the alternative process configuration plan having the same or mutually compatible types of products manufactured by the production equipment. The countermeasure plan creation support device according to claim 2.
4. The risk level includes a production evaluation index indicating the productivity of the alternative process configuration plan and a security risk evaluation index for the production equipment. The countermeasure plan creation unit calculates the production evaluation index and the security risk evaluation index. The countermeasure plan creation support device according to claim 1.
5. The output unit outputs the alternative process configuration plan, the countermeasure plan, the production evaluation index, and the security risk evaluation index. The countermeasure plan creation support device according to claim 4.
6. The countermeasure plan creation unit calculates the degree of influence from the production equipment having vulnerability among the production equipment to other production equipment, and calculates the evaluation index of the current production plan based on the calculated degree of influence and the risk degree. The countermeasure plan creation support device according to claim 1.
7. The output unit preferentially outputs the alternative process configuration plan and the countermeasure plan with a high or low risk degree based on the risk degree. The countermeasure plan creation support device according to claim 1.
8. The countermeasure plan creation unit acquires the date and time statistical information of cyber attacks on the production equipment, and generates a prediction model for predicting the attack arrival probability on the production equipment over time based on the acquired date and time statistical information. The countermeasure plan creation support device according to claim 1.
9. The countermeasure plan creation unit generates a prediction model for predicting the attack arrival probability on the production equipment, and determines the change deadline from the process configuration in the current production plan to the alternative process configuration plan based on the generated prediction model. The countermeasure plan creation support device according to claim 1.
10. The countermeasure plan creation unit determines the change deadline from the process configuration in the current production plan to the alternative process configuration plan based on the production evaluation index and the security risk evaluation index. The countermeasure plan creation support device according to claim 4.
11. As the production evaluation index, the delivery compliance rate of the product manufactured by the production equipment is used. The countermeasure plan creation support device according to claim 10.
12. Using the attack reach probability to the production equipment as the security risk assessment index, The countermeasure plan creation support device according to claim 10.
Citation Information
Patent Citations
Internal state display system
JP2018079778A
Control system and setting method
JP2020166520A