Gateway device and communication system

The gateway device with integrated attack detection capabilities addresses the vulnerability of cloud controllers to fake control devices by calculating communication states and detecting deviations, effectively preventing unauthorized control and enhancing security.

JP2025097201APending Publication Date: 2025-06-30KK TOSHIBA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023213356
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-18
Publication Date
2025-06-30

AI Technical Summary

Technical Problem

Conventional cloud controllers lack an attack detection function, making them vulnerable to unauthorized control from fake control devices, which can lead to abnormal control, malfunction, and destruction of controlled devices.

Method used

A gateway device equipped with a transmission unit, reception unit, communication state calculation unit, and attack detection unit that calculates the communication state with external devices and detects attacks by identifying deviations from normal communication states, thereby distinguishing between legitimate and fake control devices.

Benefits of technology

The solution effectively detects attacks from fake control devices, preventing unauthorized control of controlled devices by transitioning them to an external stop state, thus enhancing the security of cloud-based industrial control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025097201000001_ABST
    Figure 2025097201000001_ABST
Patent Text Reader

Abstract

To provide a gateway device capable of detecting an attack on a device to be controlled.SOLUTION: A gateway device receives control signal data from an external device via a communication network and relays the control signal data to a control target device, and includes a transmitting unit for transmitting request data requesting a response to the external device, a receiving unit for receiving response data indicating a response to the request data, a communication state calculating unit for calculating a communication state with the external device based on the request data and the response data, and an attack detecting unit for detecting that the external device is a fake control device different from a control device for controlling the control target device and an attack is being made from the fake control device to the control target device via the control signal data when the calculated communication state is different from a normal communication state with the control device. The communication state includes at least one of an average communication time, a packet loss rate, a jitter, a bandwidth, and a hop count.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This embodiment relates to a gateway device and a communication system.

Background Art

[0002] An industrial controller is used to automatically control industrial processes, machines, manufacturing equipment, etc. in a factory. Generally, an industrial controller (hereinafter referred to as a controller) is installed at the manufacturing site of a factory. In recent years, a form of installing a controller in a cloud environment on a network has been considered. Installing a controller in a cloud environment has multiple advantages, such as enabling work from anywhere through remote connection, and enabling replacement of a backup device in a short time in case of a failure.

[0003] A controller installed in a cloud environment (hereinafter referred to as a cloud-type controller) communicates with controlled devices such as motors and valves installed at the manufacturing site via a control relay device installed at the manufacturing site. Since the cloud-type controller uses the Internet for communication with the control relay device, it is vulnerable to cyberattacks. An attacker installs a fake control device that mimics the control device (cloud-type controller) in the cloud environment, and illegally connects from the fake control device to the control relay device to perform attacks such as abnormal control, malfunction, and destruction of the controlled device. Generally, an attacker often constructs a fake control device in a cloud environment at a location far from the location where the cloud-type controller is installed in the cloud environment (such as overseas).

[0004] Since conventional cloud controllers do not have an attack detection function, they cannot defend against unauthorized control from a fake controller to a controlled device. As a general attack detection technique, there is a known method of detecting an attack by pattern-matching packets flowing through a network. However, in a cloud controller, since it uses its own communication protocol, an attack cannot be detected by pattern-matching. There is also a known technique for detecting a denial-of-service (DoS) attack based on the number of network packets. However, with a determination based on the number of packets, access from an unauthorized destination cannot be detected.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0006] The present embodiment provides a gateway device and a communication system capable of detecting an attack on a controlled device.

Means for Solving the Problems

[0007] The gateway device according to this embodiment is a gateway device that receives a control signal from an external device via a communication network and relays the control signal data to a device to be controlled. The gateway device includes: a transmission unit that transmits request data for requesting a response from the external device; a reception unit that receives response data indicating a response to the request data; a communication state calculation unit that calculates a communication state with the external device based on the request data and the response data; and an attack detection unit that detects that when the calculated communication state is different from a normal communication state with a control device that controls the device to be controlled, the external device is a fake control device different from the control device, and an attack is being performed on the device to be controlled via the control signal data from the fake control device. The communication state includes at least one of an average communication time, a packet loss rate, jitter, a bandwidth, and a hop count.

Brief Description of Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0010] (First Embodiment) FIG. 1 shows an example of a communication system according to the first embodiment. A control device 311 is provided in a cloud environment, and a control relay device 321, an I / O device 322, and a controlled device 323 are provided in a field environment. The controlled device 323 is a device to be controlled by the control device 311. The control device 311 and the control relay device 321 are connected via the Internet 331, and the control relay device 321 functions as a gateway device for accessing the controlled device 323 from the control device 311. The Internet 331 is an example of a communication network, and a communication network other than the Internet 331 may be used. This system enables detection of this unauthorized control as an attack when a fake control device attempts to unauthorizedly control the controlled device 323 via the Internet 331. The control device 311 and the fake control device are external devices of the control relay device 321.

[0011] FIG. 2 shows an example in which a false control device 251 attempting to illegally control the controlled device 323 is provided in a cloud environment different from the control device 311 and is connected to the Internet 331. There are no restrictions on the physical installation locations of the control device 311 and the false control device 251. As an example, the control device 311 is provided in the country and the false control device 251 is provided overseas. The false control device 251 may attempt to illegally control the controlled device 323 via the control relay device 321 by transmitting transmission data including control signal data for the purpose of attacking the controlled device 323 to the control relay device 321. For this purpose, the false control device 251 may acquire in advance various types of information such as the IP address of the control device 311, the format of the above transmission data (see FIG. 9), and the format of the reception response data (see FIG. 10) described later.

[0012] The control device 311 is a device that generates control signal data for controlling the controlled device 323 and controls the controlled device 323 by transmitting it to the control relay device 321. Specifically, the control device 311 is realized by using cloud services such as virtual machines, virtual networks, and storage services. Since stable operation is required, the control device 311 is constructed in a specific region (area) in the country, for example. For this reason, the communication state between the control device 311 and the control relay device 321 is characterized by being stable.

[0013] The control device 311 and the control relay device 321 in FIG. 1 are synchronized in time in advance by using an NTP (Network Time Protocol) server or the like.

[0014] The control device 311 is configured as a computer device including a circuit such as a processor or a CPU, a storage device such as a memory or a hard disk, and a communication circuit. This device may be configured by a single computer device or may be configured as a system including a plurality of computer devices connected to each other. The functions of the control device 311 may be realized by causing a CPU to execute a program.

[0015] The control device 311 includes a periodic communication unit 3111, a cloud-side shared memory 3112, and a control execution unit 3113. The control execution unit 3113 executes a control program for controlling the controlled device 323. The control program is stored in a storage unit such as a memory (not shown), and the control execution unit 3113 reads and executes the control program from the storage unit.

[0016] The cloud-side shared memory 3112 is a memory having an area for storing control signal data generated by the control execution unit 3113 and an area for storing device state data indicating the state of the controlled device 323 received from the control relay device 321. Examples of the state of the controlled device 323 include information on whether it is operating or stopped, and information on the current state when the controlled device 323 can transition between a plurality of states during operation.

[0017] FIG. 3(A) shows an example of the data arrangement area in the cloud-side shared memory 3112. The storage area is divided into an area D11_2 for control signal data and an area D12_2 for device state data.

[0018] When the periodic communication unit 3111 receives transmission data including the device state data of the controlled device 323 from the control relay device 321, it writes the device state data to the area D12_2 of the cloud-side shared memory 3112. At this time, the periodic communication unit 3111 transmits reception response data to the control relay device 321 as a confirmation response to the transmission data including the device state data. The reception time field D33 (see FIG. 6) of the reception response data includes the reception time of the device state data (details will be described later).

[0019] The control execution unit 3113 reads the device state data from the cloud-side shared memory 3112, generates control signal data instructing the process to be executed by the controlled device 323 based on the device state data, and writes the control signal data to the area D11_2 of the cloud-side shared memory 3112.

[0020] The fixed-period communication unit 3111 periodically reads control signal data from the cloud-side shared memory 3112 and transmits it to the control relay device 321 via the Internet 331. The transmission period of the control signal data may vary depending on the controlled device 323 and can be various, for example, from about 1 millisecond to about 1 second.

[0021] The control relay device 321 (gateway device) receives control signal data from the fixed-period communication unit 3111 of the control device 311 and transmits it to the controlled device 323 via the I / O device 322. Thereby, it relays the control command from the control device 311 to the controlled device 323. Even when control signal data is received due to an attack from the fake control device 251, similar to the case of the control device 311, the control signal data is transmitted to the controlled device 323 via the I / O device 322. Thereby, the controlled device 323 may be illegally controlled, but this embodiment enables early detection of this illegal control.

[0022] The control relay device 321 is configured as a computer device including a circuit such as a processor or CPU, a storage device such as a memory or hard disk, a communication circuit, etc. This device may be composed of a single computer device or may be configured as a system composed of a plurality of interconnected computer devices. The functions of the control relay device 321 may be realized by causing the CPU to execute a program.

[0023] The control relay device 321 includes a fixed-period communication unit 3211, a field-side shared memory 3212, an attack detection unit 3213, and a transmission / reception management table 3214. The fixed-period communication unit 3211 includes a transmission unit 32111, a reception unit 32112, and a communication state calculation unit 32113.

[0024] The field-side shared memory 3212 is a memory having a region for storing control signal data received from the control device 311 and a region for storing device state data received from the controlled device 323 via the I / O device 322.

[0025] FIG. 3(B) shows an example of the data arrangement area in the on-site shared memory 3212. The storage area is divided into an area D11_1 for control signal data and an area D12_1 for device status data.

[0026] In this embodiment, it is assumed that the on-site shared memory 3212 has the same storage area size as the cloud-side shared memory 3112 and has the same configuration. However, the configurations of the on-site shared memory 3212 and the cloud-side shared memory 3112 do not have to be the same, and it is sufficient if each has a size of an area capable of storing necessary data.

[0027] The I / O device 322 reads the control signal data from the on-site shared memory 3212 and transmits it to the controlled device 323. Also, the I / O device 322 writes the device status data received from the controlled device 323 into the on-site shared memory 3212.

[0028] The controlled device 323 operates according to the control signal data received from the I / O device 322. For example, when the controlled device 323 is a motor, it operates at the rotation speed specified by the control signal data. When the control signal data is received from the false control device 251, the controlled device 323 is thereby illegally controlled.

[0029] The fixed-period communication unit 3211 periodically reads device status data from area D12_1 of the on-site shared memory 3212. The transmission unit 32111 generates transmission data including the device status data and transmits the generated transmission data to the control device 311. The transmission data including the device status data is an example of request data that requests a response from the communication partner. The transmission unit 32111 may transmit the request data in a form different from the transmission data including the device status data. In this case, the transmission data including the device status data and the request data are transmitted separately. Also, the reception unit 32112 receives control signal data from the control device 311 and writes the control signal data to area D11_1 of the on-site shared memory 3212. Even when the control signal data is received from the fake control device 251, the reception unit 32112 similarly writes the control signal data to area D11_1 of the on-site shared memory 3212.

[0030] Figure 4 shows an example of the transmission data format. The data type field D21, data number field D22, transmission time field D23, data size field D24, and status data field D25 are shown. In the data type field D21, "1" indicating transmission is set. The data number field D22 is a field that stores a value for distinguishing the transmission data, and in this field D22, a sequence number that is incremented each time the transmission data is transmitted is set. In the transmission time field D23, the time (timestamp) when the transmission data is transmitted is set. In the data size field D24, the number of bytes of the device status data, which is the data to be transmitted, is set. In the status data field D25, the device status data is set.

[0031] When transmitting the transmission data including the device status data to the control device 311, the transmission unit 32111 registers the data number, transmission time, and data size in the transmission / reception management table 3214 based on the transmission data.

[0032] FIG. 5 shows an example of the transmission / reception management table 3214. In the data number column D41, the data number set for the transmission data is written. In the transmission time column D42, the transmission time (timestamp) set for the transmission data is written. In the data size column D45, the data size of the device state data set for the transmission data is written. The reception time column D43 and the communication time column D44 remain blank at this point. One line of data in the transmission / reception management table 3214 is called a record.

[0033] As described above, when the control device 311 receives transmission data from the control relay device 321, it generates reception response data as a confirmation response and transmits it to the control relay device 321. This reception response data is generated based on the transmission data. The reception response data is an example of response data indicating a response to the request data from the control relay device 321. When the control device 311 receives request data in a form different from the transmission data including the device state data, it may transmit response data for this request data. Note that in a state where the control signal data is received from the fake control device 251 and is being illegally controlled, the control relay device 321 recognizes the fake control device 251 as the communication partner, the transmission data is transmitted to the fake control device 251, and the reception response data may also be transmitted from the fake control device 251 to the control relay device 321. Thus, when the controlled device 323 is illegally controlled by the fake control device 251, there may be a situation where the control device 311 cannot communicate correctly or connect with the control relay device 321, or a situation where the fake control device 251 guides to a dummy device and the control device 311 connects to and communicates with that device.

[0034] FIG. 6 shows an example of the reception response data format. The data type field D31, the data number field D32, and the reception time field D33 are shown. In the data type field D31, “2” indicating reception is set. In the data number field D32, the same data number (sequence number) as the data number included in the transmission data is set. In the reception time field D33, the time (timestamp) when the transmission data was received is set.

[0035] The receiving unit 32112 provides the received response data received from the control device 311 to the communication state calculation unit 32113, and writes data to the transmission / reception management table 3214 based on the received response data. More specifically, it identifies the row identical to the data number included in the received response data, and in the identified row, writes the reception time included in the received response data to the reception time column D43. Also, it calculates the communication time from the difference between the reception time and the transmission time included in the row, and writes the communication time to the communication time column D44 of the row. Note that even when the received response data is received from the fake control device 251, in the same manner, the row identical to the data number included in the received response data is identified, and the reception time and the communication time are written to the identified row.

[0036] The communication state calculation unit 32113 calculates the communication state with the communication partner based on the transmission / reception management table 3214 at a fixed cycle, and generates data indicating the communication state (communication state data). Examples of the communication state include average communication time, packet loss rate, jitter, and bandwidth. The communication partner is the control device 311 when the controlled device 323 is correctly controlled by the control device 311, and is the fake control device 251 when it is illegally controlled by the fake control device 251.

[0037] The average communication time is an index indicating the communication speed, and is the average value of the time (transmission time) required for transmitting the device state data from the control relay device 321 to the communication partner.

[0038] The packet loss rate is an index indicating the communication stability, and is the ratio per unit time that the device state data transmitted from the control relay device 321 could not be received by the communication partner.

[0039] Jitter is an index indicating the variation in the communication time, and is the difference between the maximum value and the minimum value of the time (transmission time) required for transmitting the device state data from the control relay device 321 to the communication partner. Jitter may also be represented by the standard deviation of the transmission time.

[0040] The bandwidth is an index indicating the communicable amount, and is the total data size per unit time of the transmission of the device state data from the control relay device 321 to the communication partner.

[0041] The attack detection unit 3213 compares the value of the communication state data generated by the communication state calculation unit 32113 with a threshold value to detect the presence or absence of an attack. When an attack is detected, the transmission source device of the reception response data is the false control device 251, and when no attack is detected, the transmission source device of the reception response data is the control device 311. When the attack detection unit 3213 detects an attack, in order to prevent unauthorized control of the controlled device 323 by the attacker, the attack detection unit 3213 causes the controlled device 323 to transition to an external stop state (operation stop). Specifically, the attack detection unit 3213 writes an operation mode signal instructing an emergency stop to the area D11_1 of the on-site shared memory 3212, thereby causing the controlled device 323 to transition to the stop state.

[0042] When using the average communication time as an indicator, measure the communication time during a period (training period) when it can be assumed in advance that there is no attack, and determine the upper threshold value and the lower threshold value of the communication time. If the false control device 251 (see FIG. 2) is installed at a location physically farther from the normal control device 211 than the control device 311 (such as overseas), the physical distance from the control relay device 321 becomes larger than the physical distance between the control relay device 321 and the control device 211. Therefore, the communication time with the control relay device 321 also becomes larger than the communication time between the control relay device 321 and the control device 211. Conversely, if the false control device 251 (see FIG. 2) is installed at a location physically closer to the normal control device 211 than the control device 311, the physical distance from the control relay device 321 becomes smaller than the physical distance between the control relay device 321 and the control device 211. Therefore, the communication time with the control relay device 321 also becomes smaller than the communication time between the control relay device 321 and the control device 211. Thus, when the average communication time is greater than the upper threshold value of the communication time or less than the lower threshold value, that is, when it is outside the threshold range of the communication time, it can be detected that an attack is being carried out from the false control device 251. The communication time being within the threshold range corresponds to the case where the communication state with the communication partner is the same as the normal communication state with the control device 311 (that is, the communication partner is the control device 311). The communication time being outside the threshold range corresponds to the case where the communication state with the communication partner is different from the normal communication state with the control device 311 (that is, the communication partner is the false control device 251).

[0043] When using the packet loss rate as an indicator, communication is carried out in a training period in advance to measure the packet loss rate multiple times, and an upper threshold value of the packet loss rate and a lower threshold value of the packet loss rate are determined. If the false control device 251 is installed in a developing country, since the communication infrastructure is unstable, the packet loss rate may be worse (higher) than that of the control device 311. Conversely, if the false control device 251 is installed in a communication environment of higher quality than the control device 311, the packet loss rate may be better (lower) than that of the control device 311. Therefore, when the packet loss rate is greater than the upper threshold value of the packet loss rate or smaller than the lower threshold value, that is, when it is outside the threshold range of the packet loss rate, it is detected that an attack is being carried out from the false control device 251. The fact that the packet loss rate is within the threshold range corresponds to the case where the communication state with the communication partner is the same as the normal communication state with the control device 311 (that is, the communication partner is the control device 311). The fact that the packet loss rate is outside the threshold range corresponds to the case where the communication state with the communication partner is different from the normal communication state with the control device 311 (that is, the communication partner is the false control device 251).

[0044] When using jitter as an indicator, communication is carried out in a training period in advance to measure the jitter multiple times, and an upper threshold value of the jitter and a lower threshold value of the jitter are determined. If the false control device 251 is installed in a developing country, since the communication infrastructure is unstable, if the false control device 251 is installed in a developing country, since the communication infrastructure is unstable, the jitter may be worse (higher) than that of the control device 311. Conversely, if the false control device 251 is installed in a communication environment of higher quality than the control device 311, the jitter may be better (lower) than that of the control device 311. Therefore, when the jitter is greater than the upper threshold value of the jitter or smaller than the lower threshold value, that is, when it is outside the threshold range of the jitter, it is detected that an attack is being carried out from the false control device 251. The fact that the jitter is within the threshold range corresponds to the case where the communication state with the communication partner is the same as the normal communication state with the control device 311 (that is, the communication partner is the control device 311). The fact that the jitter is outside the threshold range corresponds to the case where the communication state with the communication partner is different from the normal communication state with the control device 311 (that is, the communication partner is the false control device 251).

[0045] When using the bandwidth as an indicator, communication is performed during a training period in advance to measure the bandwidth multiple times, and a bandwidth threshold (upper limit) and a bandwidth threshold (lower limit) are determined. When the false control device 251 is installed in a developing country, since the communication infrastructure is unstable, if the false control device 251 is installed in a developing country, the bandwidth may become worse (smaller) compared to the control device 311 because the communication infrastructure is unstable. Conversely, if the false control device 251 is installed in a communication environment of higher quality than the control device 311, the bandwidth may become better (larger) compared to the control device 311. Therefore, when the bandwidth is smaller than the lower threshold value of the bandwidth or larger than the upper threshold value, that is, when it is outside the threshold range of the bandwidth, it is detected that an attack is being performed from the false control device 251. The fact that the bandwidth is within the threshold range corresponds to the case where the communication state with the communication partner is the same as the normal communication state with the control device 311 (that is, the communication partner is the control device 311). The fact that the bandwidth is outside the threshold range corresponds to the case where the communication state with the communication partner is different from the normal communication state with the control device 311 (that is, the communication partner is the false control device 251).

[0046] Hereinafter, an example of the processing flow of the transmission unit 32111, the reception unit 32112, the communication state calculation unit 32113, and the attack detection unit 3213 will be described with reference to FIGS. 7 to 10.

[0047] FIG. 7 shows an example of the processing flow of the transmission unit 32111. Step S10-1 is a step of determining whether the timing for periodic transmission has arrived, and waits until a predetermined transmission period (for example, a period of 50 milliseconds) elapses.

[0048] In step S10-2, when the predetermined transmission period elapses in step S10-1, transmission data having the transmission data format of FIG. 4 is created.

[0049] In step S10-3, the transmission data is transmitted to the communication partner.

[0050] In step S10-4, based on the transmission data, the data number, transmission time, and data size are registered in the data number column D41, transmission time column D42, and data size column D45 of the transmission / reception management table 3214 in FIG. 5. The reception time column D43 and communication time column D44 are left blank.

[0051] FIG. 8 shows an example of the processing flow of the reception unit 32112. In step S20-1, it is confirmed whether control signal data has been received from the communication partner.

[0052] In step S20-2, it is confirmed whether reception response data has been received from the communication partner.

[0053] In step S20-3, the received control signal data is written into the area D11_1 (see FIG. 3(B)) of the on-site shared memory 3212.

[0054] In step S20-4, based on the received reception response data, the reception time and communication time are registered in the reception time column D43 and communication time column D44 of the transmission / reception management table 3214. More specifically, a row (record) that matches the data number included in the reception response data is specified from the transmission / reception management table 3214, and the reception time included in the reception response data is written into the reception time column D43 in the specified record. Further, the difference between the reception time and the transmission time in the specified record is calculated, and the difference is written as the communication time into the communication time column D44 in the specified record.

[0055] FIG. 9 shows an example of the processing flow of the communication state calculation unit 32113. Step S30-1 is a step of determining the timing for periodic transmission, and waits until a predetermined calculation period (for example, 1 hour) has elapsed.

[0056] In step S30-2, the average communication time is calculated. More specifically, the average value of the communication time is calculated by dividing the sum of all the values (excluding blanks) registered in the communication time column D44 of the transmission / reception management table 3214 by the number of those records.

[0057] In step S30-3, the packet loss rate is calculated. More specifically, the records with blank reception times or communication times are counted from the transmission / reception management table 3214, and the packet loss rate is calculated by dividing the counted number of records by the total number of records in the transmission / reception management table 3214.

[0058] In step S30-4, jitter is calculated. More specifically, jitter is calculated by taking the difference between the maximum communication time and the minimum communication time in the communication time column D44 of all the records registered in the transmission / reception management table 3214.

[0059] In step S30-5, the bandwidth is calculated. More specifically, the records in the transmission / reception management table 3214 with non-blank reception times or communication times are identified, and the bandwidth is calculated by summing the values in the data size column D45 of the identified records.

[0060] In step S30-6, the attack detection process (see FIG. 10) of the attack detection unit 3213 is called. The values of each communication state calculated in steps S30-2 to S30-5 serve as the input to the attack detection process.

[0061] FIG. 10 shows an example of the processing flow of the attack detection unit 3213. Step S40-1 is a step of detecting an attack based on the average communication time, and it detects that an attack has been performed when the average communication time is outside the threshold range of the communication time.

[0062] Step S40-2 is a step of detecting an attack based on the packet loss rate, and it detects that an attack has been performed when the packet loss rate is outside the threshold range of the packet loss rate.

[0063] Step S40-3 is a step of detecting an attack based on jitter, and it detects that an attack has been performed when the jitter is outside the threshold range of the jitter.

[0064] Step S40-4 is a step of detecting an attack based on the bandwidth, and detects that an attack has been performed when the bandwidth is outside the threshold range of the bandwidth.

[0065] In step S40-5, when it is not detected that an attack has been performed in all of steps S40-1 to S40-4, it is determined that no attack has been performed, and this process ends.

[0066] Step S40-6 is a step of performing a measure (attack detection countermeasure process) when an attack is detected in any of steps S40-1 to S40-4. The attack detection unit 3213 transitions the controlled device 323 to the stopped state of operation. Specifically, as described above, the attack detection unit 3213 writes an operation mode signal instructing an emergency stop to the area D11_1 of the on-site side shared memory 3212, thereby transitioning the controlled device 323 to the stopped state.

[0067] In the process of FIG. 10, the average communication time, packet loss rate, jitter, and bandwidth, which are indicators of the communication state, are evaluated independently, but it is also possible to evaluate them comprehensively. For example, when it is determined that two or more of these multiple indicators are outside the threshold range, it may be determined that an attack has been detected.

[0068] As described above, according to the present embodiment, the communication state with the communication partner is measured, and when the communication state is different from the normal communication state with the control device 311, it is detected that an attack has been performed. Thereby, when a false control device installed in a cloud environment different from the control device 311 performs an operation of illegally controlling the controlled device 323, an attack from the false control device can be detected.

[0069] (Second Embodiment) FIG. 11 shows an example of a communication system according to the second embodiment. As a difference from the first embodiment, a hop count acquisition unit 32114 is added to the fixed-period communication unit 3211 of the control relay device 321. Elements having the same names as those in FIG. 1 are denoted by the same reference numerals, and description thereof is omitted except for the extended or changed processes.

[0070] The hop count acquisition unit 32114 acquires the hop count in the communication with the communication partner. The hop count represents the number of communication relay facilities (such as routers) passed through until connecting to the communication partner. When the physical installation locations of the control device 311 and the control relay device 321 do not change, the hop count with the control device 311 is often stable. The hop count acquisition unit 32114 uses a program such as ping during the training period to perform multiple measurements to acquire the hop count until connecting to the control device 311, and determines the upper limit threshold value and the lower limit threshold value of the hop count. The measurements for acquiring the hop count may be performed on the same day or divided over multiple days. The maximum value of the hop counts of the multiple measurements is determined as the upper limit threshold value, and the minimum value is determined as the lower limit threshold value. If all the measured values of the hop count are the same, the upper limit threshold value and the lower limit threshold value may be the same.

[0071] FIG. 12 shows an example of the processing flow of the communication state calculation unit 32113 according to the second embodiment. As a difference from the first embodiment, step S30-7 is added between steps S30-5 and S30-6. In step S30-7, the hop count acquisition unit 32114 uses a program (command) such as ping to acquire the hop count with the communication partner.

[0072] FIG. 13 shows an example of the processing flow of the attack detection unit 3213 according to the second embodiment. As a difference from the first embodiment, step S40-7 is added between steps S40-4 and S40-5.

[0073] In step S40-7, it is detected whether an attack has been performed based on the hop count acquired in step S30-7 of FIG. 12. When the hop count is greater than the upper limit threshold value of the hop count or less than the lower limit threshold value, that is, when it is outside the threshold range, it is detected that an attack has been performed. When the upper limit threshold value and the lower limit threshold value are the same, when the hop count does not match the upper limit threshold value or the lower limit threshold value, it is detected that an attack has been performed.

[0074] As described above, according to the present embodiment, by obtaining the number of hops to the communication partner and detecting an attack based on the number of hops, an attack can be detected with higher accuracy.

[0075] (Third Embodiment) FIG. 14 shows an example of a communication system according to the third embodiment. As a difference from the first embodiment, an engineering tool 341 is provided in a cloud environment, and the attack detection unit 3213 of the control relay device 321 includes a control device state acquisition unit 324. Elements having the same names as those in FIG. 1 are denoted by the same reference numerals, and description thereof is omitted except for extended or modified processes.

[0076] The engineering tool 341 is a device that develops a control program to be executed by the control execution unit 3113, writes (registers) the control program to the control device 311, and operates and controls the control device 311. The engineering tool 341 is constructed on a cloud environment different from the control device 311, and the engineering tool 341 is connected to the control device 311 and the Internet 331. The engineering tool 341 always monitors the operating state of the control device 311 and can acquire information representing the operating state. The engineering tool 341 has a function as a state management device that manages the operating state of the control device 311. The engineering tool 341 may be connected to the control device 311 via the Internet 331, or may be connected to the control device 311 via a communication network different from the Internet 331.

[0077] The control device state acquisition unit 324 of the attack detection unit 3213 acquires information indicating the operating state of the control device 311 by querying the engineering tool 341. Examples of the operating state include in operation, stopped, and halted. Halt corresponds to a state in which the operation related to the control of the controlled device 323 is stopped, but communication with the control relay device 321 is possible. As other operating states, there may be a state in which the control device 311 cannot communicate with the control relay device (for example, a state in which, although an attempt is made to communicate with the control relay device, connection fails and an error continues to be returned).

[0078] The attack detection unit 3213 detects the presence or absence of an attack, taking into account the operating state of the control device 311 identified by the information acquired by the control device state acquisition unit 324. Since the Internet 331 is used as the communication path between the control device 311 and the control relay device 321, the communication state between the control device 311 and the control relay device 321 may temporarily become unstable depending on the state of the Internet 331. In this case, if the presence or absence of an attack is detected based only on the communication state calculated by the communication state calculation unit 32113, there is a possibility of false detection due to the temporary instability of the state of the Internet 331. In the present embodiment, by performing detection taking into account the operating state of the control device 311, the possibility of false detection is reduced.

[0079] FIG. 15 shows an example of the processing flow of the attack detection unit 3213 according to the third embodiment. As a difference from the first embodiment, steps S40-8 and S40-9 are added between steps S40-4 and S40-6.

[0080] In step S40-8, the control device state acquisition unit 324 of the attack detection unit 3213 acquires information indicating the operating state of the control device 311.

[0081] In step S40-9, the attack detection unit 3213 determines whether the state of the control device 311 is normal based on the acquired information, for example, whether the control device 311 is in normal operation. If the operating state of the communication partner previously grasped on the control relay device 321 side matches the operating state of the control device 311, it is determined that the state of the control device 311 is normal, and if they do not match, it is determined that it is not normal. For example, assume that although the control relay device 321 has received control signal data from the communication partner until just before and has relayed the control signal data to the controlled device 323, the information indicating the operating state of the control device 311 indicates that the control device 311 is stopped. In this case, since the operating state of the communication partner previously grasped on the control relay device 321 side does not match the operating state of the control device 311, it is determined that the state of the control device 311 is not normal (for example, the control device 311 is not in normal operation).

[0082] When the state of the control device 311 is not normal, it is determined that an attack is being carried out from the fake control device 251. When the state of the control device 311 is normal, it is determined that no attack is being carried out from the fake control device 251. That is, when the control device 311 is normal, even if the value of the communication state is outside the threshold range, it is determined that no attack is being carried out. This can prevent false detection of an attack.

[0083] As described above, according to the present embodiment, by detecting an attack based on the information indicating the operating state of the control device 311 together with the communication state data, the possibility of false detection can be reduced.

[0084] (Fourth Embodiment) FIG. 16 shows an example of a communication system according to the fourth embodiment. As a difference from the first embodiment, an output device 325 is installed in the on-site environment, and the output device 325 is connected to the control relay device 321. Elements with the same names as those in FIG. 1 are denoted by the same reference numerals, and descriptions thereof are omitted except for the extended or modified processes.

[0085] When the attack detection unit 3213 detects an attack, it generates an alert signal and sends the alert signal to the output device 325.

[0086] Upon receiving the alert signal from the attack detection unit 3213, the output device 325 outputs information indicating that an attack has been detected. For example, the output device 325 is a display device (monitor device), and displays information (e.g., a warning message) indicating that an attack has been detected on the screen. At this time, detailed information serving as the basis for detecting the attack may be displayed as a factor for attack detection. For example, when an attack is detected because the packet loss rate exceeds the upper threshold value, information indicating that the packet loss rate has exceeded the upper threshold value may be displayed on the screen of the display device. The output device 325 may also be a light-emitting device such as an LED. When the attack detection unit 3213 detects an attack, it may cause the light-emitting device to emit light.

[0087] According to the above-described embodiment, when an attack is detected, by outputting information indicating the detection of the attack from the output device 325, it is possible to notify the on-site workers or supervisors, etc. of the detection of the attack at an early stage.

[0088] Note that the present invention is not limited to the above-described embodiment and each embodiment as it is, and at the implementation stage, the components can be modified and embodied without departing from the gist thereof. Also, various inventions can be formed by appropriately combining a plurality of components disclosed in the above-described embodiment. Further, for example, a configuration in which some components are deleted from all the components shown in the embodiment is also conceivable. Furthermore, components described in different embodiments may be appropriately combined.

Explanation of Reference Numerals

[0089] 211 Control device 251 False control device 311 Control device 321 Control relay device 322 I / O device 323 Controlled device 324 Control device state acquisition unit 325 Output device 331 Internet 341 Engineering tool 511 Control device 3111 Fixed-period communication unit 3112 Cloud-side shared memory 3113 Control execution unit 3211 Fixed-period communication unit 3212 Site-side shared memory 3213 Attack detection unit 3214 Transmission / reception management table 5213 Attack detection unit 32111 Transmission unit 32112 Reception unit 32113 Communication state calculation unit 32114 Hop count acquisition unit D11_1 Area D11_2 Area D12_1 Area D12_2 Area D21 Data Type Field D22 Data Number Field D23 Transmission Time Field D24 Data Size Field D25 Status Data Field D31 Data Type Field D32 Data Number Field D33 Reception Time Field D41 Data Number Sequence D42 Transmission Time Sequence D43 Reception Time Sequence D44 Communication Time Sequence D45 Data Size Sequence

Claims

1. A gateway device that receives control signal data from an external device via a communication network and relays the control signal data to a controlled device, a transmission unit that transmits request data for requesting a response to the external device, a reception unit that receives response data indicating a response to the request data, a communication state calculation unit that calculates a communication state with the external device based on the request data and the response data, when the calculated communication state is different from a normal communication state with a control device that controls the controlled device, the external device is a false control device different from the control device, and it is detected that an attack is being performed on the controlled device via the control signal data from the false control device, an attack detection unit, comprising: the communication state includes at least one of an average communication time, a packet loss rate, jitter, a bandwidth, and a hop count gateway device.

2. The attack detection unit acquires information indicating an operation state of the control device from a state management device that manages the operation state of the control device, determines whether the control device is normal based on the acquired information indicating the operation state, and when it is determined that the control device is not normal, even if the calculated communication state is the same as the normal communication state, it is detected that an attack on the controlled device is being performed by the false control device, The gateway device according to claim 1.

3. The attack detection unit determines that no attack on the controlled device is being performed by the false control device even if the calculated communication state is different from the normal communication state when it is determined that the control device is normal, The gateway device according to claim 2.

4. An output unit that outputs an alert when an attack on the controlled device is detected by the attack detection unit The gateway device according to claim 1, comprising.

5. When the attack detection unit detects an attack on the controlled device, it stops the operation of the controlled device The gateway device according to claim 1.

6. The request data includes a sequence number and a transmission time of the request data, The response data includes the sequence number and a reception time of the request data The gateway device according to claim 1.

7. A control device that transmits control signal data for controlling a controlled device, A gateway device that receives the control signal data via a communication network and relays the control signal data to the controlled device. The gateway device A transmission unit that transmits request data for requesting a response to the transmission source device of the control signal data. A reception unit that receives response data indicating a response to the request data. A communication state calculation unit that calculates a communication state with the transmission source device based on the request data and the response data. An attack detection unit that detects that when the calculated communication state is different from the normal communication state with the control device, the transmission source device is a fake control device different from the control device, and an attack is being performed on the controlled device via the control signal data from the fake control device. Comprises The communication state includes at least one of average communication time, packet loss rate, jitter, bandwidth, and number of hops. Communication system.

Citation Information

Patent Citations

  • printer

    JP1984059452A

  • Intrusion detector

    JP2005210601A

  • Device and method for intrusion detection in network

    JP2006121679A