Asset model generating apparatus, security evaluation system, and asset model generation method

The asset model generation device and method address accuracy issues in OT systems by automatically generating models through data collection, evaluation, and comparison, enhancing security evaluations and ensuring business continuity.

JP2025133595APending Publication Date: 2025-09-11HITACHI LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024031633
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-01
Publication Date
2025-09-11

AI Technical Summary

Technical Problem

Existing asset model generation methods, whether manual or automatic, face challenges in accuracy due to varied data formats, structures, and levels of abstraction, leading to potential errors and difficulties in validating the generated models, which affects the reliability of security evaluations in OT systems.

Method used

An asset model generation device and method that includes an input data collection unit, candidate asset model generation, security evaluation, and comparison units to automatically generate highly accurate asset models by evaluating and selecting models based on predetermined attack paths and past evaluations, ensuring higher accuracy and validity.

Benefits of technology

The solution enables the automatic generation of highly accurate asset models, improving the accuracy of security evaluations in OT systems by identifying high-risk vulnerabilities and planning effective security measures that ensure business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025133595000001_ABST
    Figure 2025133595000001_ABST
Patent Text Reader

Abstract

To provide: an asset model generating apparatus and an asset model generation method that are capable of automatically generating a highly accurate asset model; and a security evaluation system capable of improving the accuracy of security evaluation of a system.SOLUTION: An asset model generating apparatus 100 comprises: an input data collecting unit 110 that collects input data including information relating to devices constituting a system and information relating to connectivity between the devices; a candidate asset model generating unit 120 that generates a plurality of candidate asset models as candidates for an asset model, which is a model of the devices, on the basis of the collected input data; a security evaluating unit 150 that evaluates security for the plurality of candidate asset models; and a security evaluation comparing unit 160 that compares the evaluations for the plurality of candidate asset models with past evaluations and selects an asset model from among the plurality of candidate asset models.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an asset model generation device, a security evaluation system, and an asset model generation method, and more particularly to an asset model generation device and the like that can generate an asset model suitable for evaluating the security of an OT (Operational Technology) system. [Background technology]

[0002] The threat of cyber attacks against OT systems has been growing rapidly in recent years. Even when vulnerabilities are discovered in OT systems, security measures are slow to be implemented, as patches and firmware updates are often only approved after undergoing a wide range of tests. Meanwhile, efforts are underway to develop security digital twins (SDTs) as a technology for reproducing cyberattacks on systems and the application of countermeasures on them in a digital twin. SDTs reproduce attacks on SDTs and predict the impact of the attack and the effectiveness and side effects of countermeasures on the system when they are applied. This makes it possible to plan and apply countermeasures that ensure the ability to continue important system operations (business continuity) while meeting predetermined standards. In this case, SDT generates digital twins using three-layer models (actors, assets, and processes). By interconnecting these three-layer models, it becomes possible to represent the time-series state transitions of the entire OT system from multiple business perspectives. Of these, the asset model is generated using information about the information devices and control devices operating on the system and their connectivity.

[0003] Patent Document 1 describes that a network asset information management system may include an asset determination and event prioritization module for generating real-time asset information based on network activity involving assets. A rule module may include a set of rules for monitoring network activity involving assets. An information analysis module may evaluate the real-time asset information and the rules to generate notifications regarding the assets. The rules may include rules for determining vulnerabilities and risks associated with the assets based on a comparison between the level of traffic identified between IP addresses associated with the assets and predetermined thresholds. The notifications may include the level of risk associated with the assets.

[0004] Patent Document 2 describes a system for providing network services, in which the system receives an inventory of network assets and a range of available network services. For at least a subset of assets, an importance-related ranking attribute and a scannability-related ranking attribute are selected from the available service characteristics of the assets. The importance of the asset is determined based on the importance-related ranking attribute. The system determines the scannability of the asset based on the ranking attribute related to scannability or the range of available network services. The priority of the assets is determined based on the importance and scannability of the assets. A prioritized asset inventory is determined based on the priority of the assets. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] US Patent Application Publication No. 2014 / 0075564 [Patent Document 2] US Patent Application Publication No. 2022 / 0158944 Summary of the Invention [Problem to be solved by the invention]

[0006] Traditionally, asset models have been generated manually by experts using information such as system design documents and system configuration diagrams. While asset model generation by experts is highly accurate, it requires a lot of work and manual effort, and manual model generation errors cannot be automatically detected. On the other hand, when asset models are generated automatically, the input data used to generate the asset model contains a variety of formats, structures, and levels of abstraction, making it difficult to determine which of multiple records refer to the same thing. As a result, there is a risk that the asset model generated may contain errors in matching, making it difficult to confirm and ensure the validity of the model. The present invention aims to provide an asset model generation device and an asset model generation method that can automatically generate highly accurate asset models, and a security evaluation system that can improve the accuracy of system security evaluations. [Means for solving the problem]

[0007] In order to solve the above problems, the present invention provides an asset model generation device that includes an input data collection unit that collects input data including information about devices that make up a system and information about connectivity between the devices, a candidate asset model generation unit that generates a plurality of candidate asset models as candidates for asset models that are models of devices based on the collected input data, a security evaluation unit that evaluates the security of the plurality of candidate asset models, and a security evaluation comparison unit that compares the evaluation of the plurality of candidate asset models with past evaluations and selects an asset model from the plurality of candidate asset models.In this case, it is possible to provide an asset model generation device that can automatically generate highly accurate asset models.

[0008] Here, for example, the security evaluation unit evaluates security based on the results of attacks on the device using predetermined attack paths. In this case, by using attack paths that have already been identified, security evaluation can be performed under conditions that are closer to the risks that may actually occur. Furthermore, for example, the security evaluation unit evaluates the security of software running on each device when an attack is made on the device for each attack path, which allows for highly accurate security evaluation for each device. Furthermore, for example, the security evaluation comparison unit obtains the security evaluation result for each attack path based on the security evaluation of the software. In this case, the security evaluation result can be obtained for each attack path. Furthermore, for example, the security evaluation comparison unit compiles the security evaluation results for each attack path and evaluates the security of each candidate asset model. In this case, the security evaluation result can be obtained for each candidate asset model. Then, for example, the security evaluation comparison unit compares the difference between the evaluation of each candidate asset model and past evaluations. In this case, the accuracy of the candidate asset models can be easily evaluated. Furthermore, for example, the security evaluation comparison unit selects, as the asset model, one of the candidate asset models with a small difference. In this case, it is possible to select, as the asset model, a candidate asset model with higher accuracy. Furthermore, for example, the security evaluation comparison unit determines the accuracy of the generated candidate asset model by comparing the evaluation of multiple candidate asset models with past evaluations. In this case, the validity of the generated candidate asset model can be determined. Furthermore, for example, the system may be an OT (Operational Technology) system. In this case, security measures can be taken for the OT system.

[0009] The present invention also provides a security evaluation system that evaluates the impact of security measures on business continuity using a digital twin that uses an asset model generated by the above asset model generation device, an actor model that represents human behavior in a system, and a process model that represents critical operations of the system. In this case, a security evaluation system that can improve the accuracy of system security evaluation can be provided.

[0010] Furthermore, the present invention provides an asset model generation method in which a processor executes a program recorded in a memory to collect input data including information about devices that constitute a system and information about connectivity between the devices, generates a plurality of candidate asset models as candidates for asset models that are models of the devices based on the collected input data, evaluates the security of the plurality of candidate asset models, compares the evaluation of the plurality of candidate asset models with past evaluations, and selects an asset model from the plurality of candidate asset models.In this case, it is possible to provide an asset model generation method that can automatically generate highly accurate asset models. [Effects of the Invention]

[0011] An object of the present invention is to provide an asset model generation device and an asset model generation method that can automatically generate highly accurate asset models, and a security evaluation system that can improve the accuracy of system security evaluations. [Brief explanation of the drawings]

[0012] [Figure 1] 1 is a conceptual diagram showing an overall configuration and an example of operation of a security evaluation system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing the functional configuration of an asset model generation device that generates an asset model. [Figure 3]FIG. 1 is a diagram showing a case where the configuration of a network (NW configuration) used in an OT system is input data 1. [Figure 4] FIG. 10 is a diagram illustrating a case where communication information (NW communication information) of a network used in an OT system is used as input data 2. [Figure 5] FIG. 10 is a diagram illustrating a case where asset management information of devices used in an OT system is input data 3. [Figure 6] FIG. 2 is a diagram showing one of a plurality of candidate asset models generated by a candidate asset model generation unit. [Figure 7] FIG. 9 shows the results of security evaluation of software running on each device when attacked using the attack paths shown in FIG. 8. [Figure 8] FIG. 10 is a diagram showing the analysis results of attack paths for candidate asset model #1. [Figure 9] FIG. 10 is a diagram showing the first summary of the security evaluation results. [Figure 10] FIG. 10 is a diagram showing the secondary summary of the security evaluation results. [Figure 11] FIG. 10 is a diagram showing past security evaluation results used for comparison of security evaluation results. [Figure 12] FIG. 12 is a diagram showing the results of a comparison between FIG. 10 and FIG. [Figure 13] FIG. 10 is a diagram showing another example of a candidate asset model generated by the candidate asset model generation unit. [Figure 14] FIG. 16 shows the results of security evaluation of software running on each device when attacked using the attack paths shown in FIG. [Figure 15] FIG. 10 is a diagram showing the analysis results of attack paths for candidate asset model #2. [Figure 16] FIG. 10 is a diagram showing the first summary of the security evaluation results. [Figure 17] FIG. 10 is a diagram showing the secondary summary of the security evaluation results. [Figure 18] FIG. 10 is a diagram showing the results of comparing the evaluation of candidate asset model #2 with past evaluations. [Figure 19] FIG. 10 is a diagram illustrating a threshold value. [Figure 20] FIG. 20 is a diagram showing the results of comparison of candidate asset model #1 and candidate asset model #2 with the thresholds listed in FIG. 19. [Figure 21] 10 is a flowchart illustrating the overall operation of the asset model generation device. [Figure 22] 10 is a flowchart illustrating an operation of a candidate asset model generation unit when creating multiple candidate asset models. [Figure 23] 10 is a flowchart illustrating an operation of a security evaluation unit when performing a security evaluation using a selected candidate asset model. [Figure 24] 10 is a flowchart illustrating an operation of a security evaluation comparison unit when comparing security evaluation results. [Figure 25] 10 is a flowchart illustrating an operation of the security evaluation comparison unit when obtaining a primary summary result of the security evaluation results. [Figure 26] 10 is a flowchart illustrating an operation of the security evaluation comparison unit when obtaining a secondary summary result of the security evaluation results. [Figure 27] 10 is a flowchart illustrating an operation of the security evaluation comparison unit when obtaining a comparison table of secondary summary results of security evaluation results. [Figure 28] 10 is a flowchart illustrating an operation of the security evaluation comparison unit when adding a comparison result of security evaluation results to a list of selected candidate asset models. [Figure 29] 10 is a flowchart illustrating the operation of the security evaluation comparison unit when selecting an asset model from the candidate asset model list that has an appropriate security evaluation result as a result of comparison. [Figure 30]10 is a flowchart illustrating an operation performed by a security evaluation comparison unit when verifying the accuracy of a candidate asset model created by a candidate asset model generation unit. [Figure 31] 10 is a flowchart illustrating a process for displaying an error detection result. [Figure 32] FIG. 10 is a diagram showing the display contents of the error detection result. [Figure 33] FIG. 2 is a diagram illustrating an example of a hardware configuration of an asset model generation device according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. <Overall explanation of Security Assessment System 1> FIG. 1 is a conceptual diagram showing the overall configuration and an example of operation of a security evaluation system 1 according to this embodiment. The security evaluation system 1 of this embodiment evaluates the security of an OT system. More specifically, when implementing security measures for an OT system, it uses a digital twin to identify high-risk vulnerabilities. It then plans multiple effective security measures and evaluates the impact of each measure on business continuity. This allows the system to appropriately design security measures based on the evaluation results so that they are consistent with business goals.

[0014] To perform this processing, the Security Assessment System 1 reproduces the OT system as a digital twin using a three-layer model of actors, assets, and processes. Of these, the actor model is a model that represents the behavior of people in relation to OT systems. Specifically, the actor model represents the behavior of workers who perform their daily work. The actor model also represents the behavior of attackers who launch cyber attacks against OT systems. Finally, the actor model represents the behavior of security personnel who implement countermeasures against cyber attacks.

[0015] An asset model is a model of the devices that make up an OT system. Specifically, an asset model is a model of computer devices that run on the OT system, and represents software vulnerabilities, network dependencies, etc. The asset model used here is generated by the asset model generation device 100, which will be described later.

[0016] A process model is a model that represents the critical operations of an OT system. Specifically, the process model represents the impact on the computer devices running on the OT system when the OT model is subjected to a cyber-attack by an attacker.

[0017] A state transition program linking these three-layer models reproduces the behavior of each model in chronological order. As an example of how this program works, an attacker is made to attack the asset model in cyberspace, identifying high-risk vulnerabilities. Then, the program has the countermeasure provider apply security measures to mitigate the risk of the attack. Meanwhile, the degree to which business performance declines as a result of implementing the measures is analyzed.

[0018] <Description of the Asset Model Generating Device 100> FIG. 2 is a block diagram showing the functional configuration of an asset model generation device 100 that generates an asset model. The illustrated asset model generation device 100 includes an input data collection unit 110, a candidate asset model generation unit 120, a candidate asset model DB (database) 130, a candidate asset model selection unit 140, a security evaluation unit 150, a security evaluation comparison unit 160, and a past security evaluation DB 170.

[0019] The input data collection unit 110 collects input data including information about the devices that configure the OT system and information about connectivity between the devices. The candidate asset model generating unit 120 generates a plurality of candidate asset models as candidates for the asset model, which is a model of the equipment, based on the input data collected by the input data collecting unit 110. The candidate asset model DB 130 stores a plurality of candidate asset models generated by the candidate asset model generating unit 120 . The candidate asset model selection unit 140 selects one of the multiple candidate asset models generated by the candidate asset model generation unit 120 . The security evaluation unit 150 evaluates the security of the multiple candidate asset models generated by the candidate asset model generation unit 120 . The security evaluation comparison unit 160 compares the evaluations of the multiple candidate asset models generated by the candidate asset model generation unit 120 with past evaluations, and selects an asset model from the multiple candidate asset models. The past security evaluation DB 170 stores past security evaluations used by the security evaluation comparison unit 160 .

[0020] Each of these functional units will be described in detail below. <Description of input data> 3 to 5 are diagrams showing input data collected by the input data collection unit 110. FIG. Of these, Figure 3 shows the case where the network configuration (NW configuration) used in the OT system is used as input data 1. Note that the NW configuration here also includes FW (FireWall) settings. In Figure 3, the name, IP address, and NW segment of each device connected to the network used in the OT system are associated and described.

[0021] FIG. 4 is a diagram showing a case where communication information (NW communication information) of a network used in an OT system is used as input data 2. This can be obtained, for example, as statistical information on the traffic volume of a router. In Figure 4, the traffic percentage, the IP address of the source host, the IP address of the destination host, and the protocol used are associated and described.

[0022] FIG. 5 is a diagram showing a case where asset management information of devices used in an OT system is used as input data 3. In Figure 5, the asset model name (Asset name) of each device connected to the network used in the OT system, the name (Name) of the software running on each device, and the software version (Version) are associated and described.

[0023] The input data in Figures 3 to 5 can also be said to be data viewed from different perspectives of the same OT system. For example, Figure 3 is data viewed from the perspective of the devices that make up the OT system. Figure 4 can also be said to be data viewed from the perspective of information on the connectivity between the devices that make up the OT system. Furthermore, Figure 5 can also be said to be data viewed from the perspective of the software that runs on the devices that make up the OT system.

[0024] <Description of the candidate asset model> FIG. 6 is a diagram showing one of the multiple candidate asset models generated by the candidate asset model generating unit 120. As shown in FIG. Here, this candidate asset model will be referred to as candidate asset model #1. Candidate asset model #1 is generated based on the input data shown in Figures 3 to 5. In other words, the candidate asset model can be said to be a single asset model in which a wide variety of input data is merged. The upper section of Fig. 6 lists the asset names shown in Fig. 5 as an SBOM (Software Bill of Materials). Meanwhile, the lower section of Fig. 6 lists the names of the devices shown in Fig. 4 and their associated IP addresses. The correspondence between these is indicated by solid and dotted lines. The solid lines indicate that the devices are connected on the network. The dotted lines indicate that the devices are related to each other.

[0025] <Security Assessment Description> 7 and 8 are diagrams showing the security evaluation performed by the security evaluation unit 150. FIG. Of these, FIG. 8 is a diagram showing the analysis results of the attack path for candidate asset model #1. This attack path is known and prepared in advance. Figure 8 shows that the attack path with path ID 1 is a route from the attacker (start) to IP address 10.200.0.34 (end), passing through four devices with IP addresses 10.12.0.15, 10.0.0.180, 10.200.0.17, and 10.200.0.31. Figure 8 also lists the probability and confidence of this attack path along with the path ID. The probability is the probability of success when an attack is carried out using this attack path. The confidence indicates the degree of possibility of an attack actually being carried out.

[0026] FIG. 7 shows the results of security evaluation of software running on each device when attacked using the attack paths shown in FIG. In this case, the result of security assessment is shown for the device indicated by the Asset name, with the number of vulnerabilities and the Risk Score for the software indicated by the Name and Version. In this case, it can be said that the security evaluation unit 150 evaluates the security based on the results of attacks on devices using predetermined attack paths. It can also be said that the security evaluation unit 150 evaluates the security of software running on each device when attacks on the device are made using each attack path.

[0027] <Explanation of the comparison of security evaluation results> 9 to 12 are diagrams showing the comparison of security evaluations performed by the security evaluation comparison unit 160. FIG. Of these, FIG. 9 shows the first summary of the security evaluation results. The first summary of the security assessment results is a summary of the security assessment results for each attack path for candidate asset model #1, and can be statistically determined from the values ​​in Figure 7. Here, the first summary of the security assessment results is determined for each path ID of the attack path using the path length (Length), average probability (Avg. Probability), average confidence (Avg. Confidence), median number of vulnerabilities (Median Number of Vulnerabilities), and median risk score (Median Risk Score). The path length (Length) is the number of steps in the path from the attacker (start) to the end point; for a path that has four devices in between, as shown in Figure 8, the path length (Length) is 5. The smaller the average probability (Avg. Probability), average confidence (Avg. Confidence), median number of vulnerabilities (Median Number of Vulnerabilities), and median Risk Score (Median Risk Score), the higher the security. In this case, it can also be said that the security evaluation comparison unit 160 obtains the security evaluation result for each attack path based on the security evaluation of the software.

[0028] FIG. 10 shows the secondary summary of the security evaluation results. The secondary summary of security evaluation results is a summary of the overall security evaluation results for candidate asset model #1, and can be statistically determined from the values ​​in Figure 9. Here, the secondary summary of security evaluation results is determined using the number of assets (Number of assets), average path length (Avg. Path Length), average probability (Avg. Probability), average confidence (Average Confidence), average number of vulnerabilities (Avg. Number of Vulnerabilities), and average risk score (Avg. Risk Score). For the average number of vulnerabilities (Avg. Number of Vulnerabilities) and average risk score (Avg. Risk Score), the smaller the values, the higher the security level. In this case, it can be said that the security evaluation comparison unit 160 compiles the security evaluation results for each attack path and evaluates the security of each candidate asset model.

[0029] The methods used to calculate the primary and secondary summary results of the security evaluation results include, for example, the arithmetic mean, median, mode, interquartile mean, number, variance (e.g., standard deviation, interquartile range, etc.), etc. This method also includes shape / skewness (e.g., skewness, kurtosis, etc.), etc.

[0030] FIG. 11 shows past security evaluation results used for comparison of security evaluation results. As mentioned above, past security evaluation results are stored in the past security evaluation DB 170. The illustrated past security evaluation results are in the same format as in Fig. 10. That is, they are composed of the number of assets (Number of assets), average path length (Avg. path length), average probability (Avg. probability), average confidence (Average Confidence), average number of vulnerabilities (Avg. number of vulnerabilities), and average risk score (Avg. risk score).

[0031] Then, the security evaluation comparison unit 160 compares the evaluation of the candidate asset model #1 with past evaluations. That is, a comparison is made between FIG. 10 and FIG. 11. In this embodiment, the security evaluation comparison unit 160 compares the items of the average probability (Avg. Probability) and the average reliability (Average Confidence) among these. These are compared because they are more important parameters for comparing security evaluation results, but other items may also be added for comparison. Specifically, for each item of the average probability (Avg. Probability) and the average confidence (Average Confidence), the square of the difference between the numerical values ​​in FIG. 10 and FIG. 11 is used as the comparison result.

[0032] FIG. 12 is a diagram showing the results of comparing FIG. 10 and FIG. The bold framed areas show the comparison results of the average probability (Avg. Probability) and the average confidence (Average Confidence). In this case, it can also be said that the security evaluation comparison unit 160 compares the difference between the evaluation of each candidate asset model and the past evaluation.

[0033] <Description of other candidate asset models> As described above, the candidate asset model generation unit 120 generates a plurality of candidate asset models, which are models of equipment, based on the input data collected by the input data collection unit 110. Other examples of candidate asset models and their evaluation are described below.

[0034] FIG. 13 is a diagram showing another example of a candidate asset model generated by the candidate asset model generating unit 120. In FIG. Here, this candidate asset model will be referred to as candidate asset model #2. Compared to candidate asset model #1 described in Fig. 6, the correspondence relationships between devices indicated by solid lines and dotted lines are different.

[0035] 14 to 17 are diagrams showing the security evaluation performed by the security evaluation unit 150. FIG. These figures are similar to Figures 7 to 10, respectively. That is, Figure 15 shows the analysis results of the attack paths for candidate asset model #2. Figure 15 shows that there are two attack paths. Of these, the attack path with path ID 1 indicates that it is a route from the attacker (start) to IP address 10.200.0.34 (end) that passes through five devices: 10.12.0.15, FW, 10.0.0.180, 10.200.0.17, and 10.200.0.31. Also, the attack path with path ID 2 indicates that it is a route from the attacker (start) to IP address 10.200.0.34 (end) that passes through two devices: 10.12.0.15 and FW. FIG. 14 shows the results of security evaluation of software running on each device when attacked using the attack paths shown in FIG.

[0036] FIG. 16 shows the first summary of the security evaluation results. The first summary of the security evaluation results is a summary of the security evaluation results for each attack path for the candidate asset model #2, and can be statistically determined from the values ​​in FIG.

[0037] FIG. 17 shows the secondary summary of the security evaluation results. The secondary summary of the security evaluation results is a summary of the overall security evaluation results for the candidate asset model #2, and can be statistically determined from the values ​​in FIG.

[0038] FIG. 18 is a diagram showing the results of comparing the evaluation of the candidate asset model #2 with past evaluations. The bold framed areas show the comparison results of the average probability (Avg. Probability) and the average confidence (Average Confidence).

[0039] <Asset model selection> The security evaluation comparison unit 160 compares the evaluations of the multiple candidate asset models generated by the candidate asset model generation unit 120 with past evaluations, thereby selecting an asset model from among the candidate asset models. Specifically, the security evaluation comparison unit 160 compares the average probability (Avg. Probability) and the average confidence (Average Confidence) calculated for each candidate asset model with predetermined thresholds, and then selects the candidate asset model with the smaller average probability and confidence.

[0040] FIG. 19 is a diagram showing the threshold value. Here, it is shown that 0.1 is set as the threshold for the average probability (Avg. Probability) and the average confidence (Average Confidence).

[0041] FIG. 20 is a diagram showing the results of comparison of candidate asset model #1 and candidate asset model #2 with the thresholds listed in FIG. As shown in the figure, candidate asset model #1 does not meet the requirements because both the average probability (Avg. Probability) and the average confidence (Average Confidence) exceed the thresholds. In contrast, candidate asset model #2 meets the requirements because both the average probability (Avg. Probability) and the average confidence (Average Confidence) fall within the threshold ranges. In this case, the security evaluation comparison unit 160 adopts candidate asset model #2 as the asset model. This allows us to check and guarantee the accuracy of the asset model, which in turn allows us to automatically generate highly accurate asset models. In this case, it can also be said that the security evaluation comparison unit 160 selects the candidate asset model with the smallest difference as the asset model.

[0042] <Detailed Description of the Operation of the Asset Model Generation Device 100> Next, the operation of the asset model generation device 100 will be described in detail.

[0043] FIG. 21 is a flowchart illustrating the overall operation of the asset model generation device 100. First, the input data collection unit 110 collects input data such as those described with reference to FIGS. 3 to 5 (S2101). Next, the candidate asset model generation unit 120 generates a plurality of candidate asset models and creates a candidate asset model list (S2102). The candidate asset models are as described in FIGS. 6 and 13 and are stored in the candidate asset model DB 130. Next, the candidate asset model selection unit 140 selects a first candidate asset model from among the plurality of candidate asset models (S2103). Then, the security evaluation unit 150 executes a security evaluation using the selected candidate asset model (S2104).

[0044] Furthermore, the security evaluation comparison unit 160 compares the selected candidate asset model with past evaluations (S2105). The past evaluations are selected from the past security evaluation DB 170 so as to be closest to the selected candidate asset model. Then, the security evaluation comparison unit 160 judges whether the comparison result is equal to or less than the threshold value shown in FIG. 19 (S2106). As a result, if it is equal to or less than the threshold value (YES in S2106), the process proceeds to S2111. On the other hand, if the threshold value is exceeded (NO in S2106), the security evaluation comparison unit 160 adds the comparison result of the security evaluation results to the selected candidate asset model list (S2107).

[0045] Next, the candidate asset model selection unit 140 determines whether there are other candidate asset models (S2108). As a result, if there is another candidate asset model (YES in S2106), the candidate asset model selection unit 140 selects another candidate asset model (S2109), and the process returns to S2104. On the other hand, if there are no other candidate asset models (NO in S2106), an asset model that is appropriate as a result of the comparison of the security evaluation results is selected from the candidate asset model list (S2110). Then, the selected candidate asset model is extracted and set as the asset model to be adopted (S2111).

[0046] Fig. 22 is a flowchart illustrating the operation of the candidate asset model generation unit 120 when creating multiple candidate asset models. That is, Fig. 22 is a flowchart that provides a more detailed explanation of S2102 in Fig. 21. Note that the method in Fig. 22 is an existing method. First, the candidate asset model generation unit 120 initializes a change parameter P for a certain asset model generation method (S2201). The change parameter P is a parameter for generating a different candidate asset model, and represents, for example, the similarity of input data or the connectivity of devices. Next, the candidate asset model generation unit 120 generates an initial asset model using the collected input data and including the change parameter P in accordance with a certain asset model generation method (S2202). Next, the candidate asset model generating unit 120 registers the generated asset model in a candidate asset model list (S2203). Then, the candidate asset model generation unit 120 determines whether or not there is a next setting for the change parameter P (S2204). As a result, if there is a next setting (YES in S2204), the change parameter P is changed to the next setting (S2205), and the process returns to S2202. On the other hand, if there is no next setting (NO in S2204), the candidate asset model generation unit 120 deletes asset models below a certain threshold from the candidate asset model list (S2206). Also, the candidate asset model generation unit 120 rearranges the order of the items in the candidate asset model list according to a certain method (S2207). However, the execution of S2206 and S2207 is optional and does not have to be performed. Then, the candidate asset model generating unit 120 creates a candidate asset model list (S2208).

[0047] Fig. 23 is a flowchart illustrating the operation of the security evaluation unit 150 when performing a security evaluation using a selected candidate asset model. That is, Fig. 23 is a flowchart illustrating S2104 in Fig. 21 in more detail. First, the security evaluation unit 150 uses the selected candidate asset model to obtain the security evaluation result (FIG. 7) based on the analysis result of the attack path (FIG. 8) (S2301). Then, the security evaluation unit 150 creates a security evaluation result (S2302).

[0048] Fig. 24 is a flowchart illustrating the operation when security evaluation comparison section 160 compares security evaluation results. That is, Fig. 24 is a flowchart illustrating S2105 in Fig. 21 in more detail. First, the security evaluation comparison unit 160 obtains a primary summary of the security evaluation results (S2401), which will be as explained in FIG. Next, the security evaluation comparison unit 160 obtains a secondary summary result of the security evaluation results (S2402), which will be as explained in FIG. Then, the security evaluation comparison unit 160 obtains a comparison table of the secondary summary of the security evaluation results (S2403), which will be as shown in FIG. Furthermore, the security evaluation comparison unit 160 creates a comparison result of the security evaluation results (S2404).

[0049] Fig. 25 is a flowchart illustrating the operation when the security evaluation comparison unit 160 obtains a primary summary of the security evaluation results. That is, Fig. 25 is a flowchart illustrating S2401 in Fig. 24 in more detail. First, the security evaluation comparison unit 160 selects the first path ID according to the attack path analysis result (FIG. 8) (S2501). Next, the security evaluation comparison unit 160 statistically derives a summary result while referring to the selected path ID (S2502). As a result, the security evaluation comparison unit 160 obtains the path length (Length), average probability (Avg. Probability), and average confidence (Avg. Confidence) shown in FIG. Furthermore, the security evaluation comparison unit 160 extracts the relevant assets while referring to the selected path IDs, and obtains statistically summarized results while referring to the risk evaluation results of the assets (FIG. 14) (S2503). As a result, the security evaluation comparison unit 160 obtains the median number of vulnerabilities and the median risk score (Median Risk Score) shown in FIG. Next, the security evaluation comparison unit 160 determines whether there are other path IDs (S2504). As a result, if there is another path ID (YES in S2504), another path ID is selected (S2505), and the process returns to S2502. On the other hand, if there is no other path ID (NO in S2504), the series of processes ends.

[0050] Fig. 26 is a flowchart illustrating the operation when the security evaluation comparison unit 160 obtains a secondary summary result of the security evaluation results. That is, Fig. 26 is a flowchart illustrating S2402 in Fig. 24 in more detail. First, the security evaluation comparison unit 160 selects the first path ID according to the first summary of the security evaluation results (FIG. 9) (S2601). Next, the security evaluation comparison unit 160 statistically compiles the results (FIG. 10) (S2602) while referring to the asset information of the asset model such as that shown in FIG. 6. As a result, the security evaluation comparison unit 160 obtains the number of assets in FIG. 10. Furthermore, the security evaluation comparison unit 160 statistically summarizes the results by referring to the selected path IDs, thereby obtaining the average path length (Avg. Path Length), average probability (Avg. Probability), average confidence (Average Confidence), average number of vulnerabilities (Avg. Number of Vulnerabilities), and average risk score (Avg. Risk Score) shown in FIG. Next, the security evaluation comparison unit 160 determines whether there are other path IDs (S2604). As a result, if there is another path ID (YES in S2604), another path ID is selected (S2605), and the process returns to S2602. On the other hand, if there is no other path ID (NO in S2604), the series of processes ends.

[0051] Fig. 27 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when obtaining a comparison table of the secondary summary results of the security evaluation results. That is, Fig. 27 is a flowchart illustrating S2403 in Fig. 24 in more detail. First, the security evaluation comparison unit 160 selects the first attribute (S2701) by referring to the secondary summary result of the security evaluation results (FIG. 10) and the past security evaluation results (FIG. 11). In the case of FIG. 12, the attributes correspond to the average probability (Avg. Probability) and the average confidence (Average Confidence). Next, the security evaluation comparison unit 160 uses a predetermined comparison method (e.g., mean square error) to write the comparison values ​​of the selected attributes of the secondary summary result of the security evaluation results (Figure 10) and the past security evaluation results (Figure 11) into a comparison table of the summary result of the security results (Figure 12) (S2602). Next, the security evaluation comparison unit 160 determines whether there are other attributes (S2703). As a result, if there are other attributes (YES in S2703), the next attribute is selected (S2704) and the process returns to S2702. On the other hand, if there is no other path ID (NO in S2703), the series of processes ends.

[0052] Fig. 28 is a flowchart illustrating the operation when the security evaluation comparison unit 160 adds the comparison result of the security evaluation results to the selected candidate asset model list. That is, Fig. 28 is a flowchart illustrating S2107 in Fig. 21 in more detail. First, the security evaluation comparison unit 160 selects the item (row) of the selected candidate asset model from the candidate asset model list (FIG. 20) (S2801). Then, the security evaluation comparison unit 160 adds the comparison result of the security evaluation results to the selected candidate asset model item (S2802).

[0053] Fig. 29 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when selecting an asset model from the candidate asset model list that has an appropriate security evaluation result as a result of comparison. That is, Fig. 29 is a flowchart that provides a more detailed explanation of S2110 in Fig. 21. First, the security evaluation comparison unit 160 selects the first candidate asset model from the selected candidate asset model list (FIG. 20) (S2901). Next, the security evaluation comparison unit 160 uses one or more parameters (values) of the selected candidate asset model to calculate the appropriateness (value) through a certain comparison method (S2902). Next, the security evaluation comparison unit 160 judges whether the comparison result is equal to or less than the threshold value (FIG. 19) (S2903). As a result, if the comparison result is equal to or less than the threshold value (YES in S2903), the process proceeds to S2907. On the other hand, if the comparison result exceeds the threshold value (NO in S2903), the security evaluation comparison unit 160 determines whether or not there are other candidate asset models (S2904). If there are other candidate asset models (YES in S2904), the next candidate asset model is selected (S2905), and the process returns to S2902.

[0054] On the other hand, if there are no other candidate asset models (NO in S2904), the security evaluation comparison unit 160 determines whether there is a candidate asset model whose comparison result is equal to or less than the threshold value (FIG. 19) (S2906). As a result, if there is a candidate asset model whose comparison result is equal to or less than the threshold (YES in S2906), the selected candidate asset model is extracted as the asset model (S2907). On the other hand, if there is no candidate asset model whose comparison result is equal to or less than the threshold (NO in S2906), an error occurs (S2908), that is, a notice is issued that an appropriate candidate asset model could not be created.

[0055] <Modification> In this modification, the security evaluation comparison unit 160 verifies the accuracy of the candidate asset model created by the candidate asset model generation unit 120 using the comparison results shown in FIG. FIG. 30 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when verifying the accuracy of the candidate asset model created by the candidate asset model generation unit 120. First, the security evaluation comparison unit 160 selects the first threshold parameter by referring to the threshold table (FIG. 19) (S3001). Next, the security evaluation comparison unit 160 refers to the parameter value selected from the comparison table of the security result summary (FIG. 12) and determines whether it is greater than the threshold value (S3002). In other words, the security evaluation comparison unit 160 determines whether the parameter value is greater than the threshold value (S3003). As a result, if the parameter value is not greater than the threshold value (parameter value≦threshold value) (NO in S3003), the security evaluation comparison unit 160 determines whether or not there is a parameter with the next threshold value (S3004). If there is a parameter for the next threshold value (YES in S3004), the parameter for the next threshold value is selected (S3005), and the process returns to S3002. On the other hand, if there is no parameter for the next threshold (NO in S3004), the process proceeds to S3007.

[0056] On the other hand, if the parameter value is greater than the threshold value in S3003 (YES in S3003), the security evaluation comparison unit 160 performs model error detection (S3006). That is, the security evaluation comparison unit 160 determines that the candidate asset model that exceeds the threshold value has a large error. Then, the security evaluation comparison unit 160 transmits the error detection result to the visualization unit (S3007). In this case, the visualization unit is a display device, such as a liquid crystal display. In this case, it can also be said that the security evaluation comparison unit 160 determines the accuracy of the generated candidate asset model by comparing the evaluations of the multiple candidate asset models with past evaluations.

[0057] FIG. 31 is a flowchart illustrating the process of displaying the error detection result. First, the security evaluation comparison unit 160 refers to the error detection result (S3101). Next, it is determined whether the detection result indicates that there is a model error (S3102). If there is a model error (YES in S3102), the security evaluation comparison unit 160 prepares the display content in accordance with the error detection result (S3103). Furthermore, the security evaluation comparison unit 160 displays the display contents of the error detection result (S3104). If there is no model error (NO in S3102), the error detection result is not displayed.

[0058] FIG. 32 is a diagram showing the display contents of the error detection result. Here, a warning screen is shown that displays the message "When security evaluation results are compared with past statistical data, a mismatch has been detected."

[0059] <Explanation of effect> According to the asset model generation device 100 described above in detail, it is possible to automatically generate a highly accurate asset model. That is, the asset model generation device 100 generates multiple candidate asset models and performs a security evaluation for each. Then, by comparing the results with past security evaluation results, it is possible to select a more appropriate asset model from among the multiple candidate asset models. As a result, the selected asset model will have a higher degree of accuracy.

[0060] In the past, when experts manually generated asset models using information such as system design documents and system configuration diagrams, the manual process could result in errors in system configuration judgment and input errors. In such cases, the accuracy of the generated model deteriorates, as does the accuracy of the security simulation and evaluation. In addition, since system updates (such as the addition of new functions) are not reflected in an asset model once it has been created, SDT becomes unusable without model updates. Furthermore, since the manual process of model generation is time-consuming, it is not possible to respond immediately even if new vulnerabilities or attack methods are made public. In the present embodiment, such problems are less likely to occur. Therefore, compared to conventional manual generation of asset models, not only can asset models be generated automatically, but asset models with higher accuracy can also be generated.

[0061] Furthermore, even if the input data contains various formats, structures, and abstraction levels, the method described above allows the candidate asset model that best matches which data refers to the same thing to be selected as the asset model. If an asset model with an incorrect match is used, the inherent risks may not be realized, resulting in increased risks to the system and insufficient countermeasures. However, in this embodiment, a more valid asset model is selected, making it possible to confirm and ensure the accuracy of the asset model. Therefore, it is possible to generate an asset model with higher accuracy than when conventional asset models are automatically generated.

[0062] <Hardware configuration> FIG. 33 is a diagram showing an example of the hardware configuration of the asset model generation device 100 in this embodiment. In this embodiment, the asset model generation device 100 is a computer device, such as a personal computer (PC), a workstation, a server device, etc. However, the device is not limited to these, and may also be a smartphone, a tablet, a mobile phone terminal, a PDA (Personal Digital Assistant), etc.

[0063] The asset model generation device 100 includes a CPU (Central Processing Unit) 3301, which is a calculation means, and a memory 3302, which is a storage means. The CPU 3301 executes various software such as an OS (operating system) and applications (application software). The memory 3302 is a storage area that stores various software and data used for executing the software. The asset model generation device 100 also includes a storage device as an auxiliary storage device. The storage is, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The asset model generation device 100 also includes a network interface 3304 for communicating with the outside, and a peripheral device controller 3305 that controls peripheral devices such as output devices such as a display and input devices such as a keyboard and a mouse.

[0064] <Explanation of how to generate asset models> In this way, the processing performed by the asset model generation device 100 is realized by the cooperation of software and hardware resources. Therefore, the processing performed by the above-mentioned asset model generation device 100 can be considered to be an asset model generation method in which a processor such as the CPU 3301 executes a program recorded in the memory 3302 to collect input data including information about the devices that make up the system and information about the connectivity between the devices, generates multiple candidate asset models as candidates for asset models, which are models of the devices, based on the collected input data, evaluates the security of the multiple candidate asset models, compares the evaluation of the multiple candidate asset models with past evaluations, and selects an asset model from the multiple candidate asset models. Furthermore, the program running on the asset model generation device 100 can be considered to be a program that enables a computer to perform the following functions: collect input data including information about the equipment that constitutes the system and information about the connectivity between the equipment; generate multiple candidate asset models as candidates for asset models, which are models of the equipment, based on the collected input data; evaluate the security of the multiple candidate asset models; and compare the evaluation of the multiple candidate asset models with past evaluations and select an asset model from the multiple candidate asset models.

[0065] The program for realizing this embodiment can be provided not only by communication means but also by being stored on a recording medium such as a CD-ROM.

[0066] Although the present embodiment has been described above, the technical scope of the present invention is not limited to the scope of the above embodiment. It is clear from the claims that various modifications and improvements to the above embodiment are also included in the technical scope of the present invention. [Explanation of symbols]

[0067] 1...security evaluation system, 100...asset model generation device, 110...input data collection unit, 120...candidate asset model generation unit, 130...candidate asset model DB, 140...candidate asset model selection unit, 150...security evaluation unit, 160...security evaluation comparison unit, 170...past security evaluation DB, 3301...CPU, 3302...memory

Claims

1. an input data collection unit that collects input data including information about devices that configure the system and information about connectivity between the devices; a candidate asset model generation unit that generates a plurality of candidate asset models as candidates for an asset model that is a model of the device, based on the collected input data; a security evaluation unit that evaluates the security of the plurality of candidate asset models; a security evaluation comparison unit that compares evaluations of the plurality of candidate asset models with past evaluations and selects an asset model from the plurality of candidate asset models; An asset model generation device comprising:

2. 2. The asset model generation device according to claim 1, wherein the security evaluation unit evaluates security based on the results of an attack on the device using a predetermined attack path.

3. 3. The asset model generation device according to claim 2, wherein the security evaluation unit evaluates the security of software running on each of the devices when an attack is made on the device for each of the attack paths.

4. 4. The asset model generation device according to claim 3, wherein the security evaluation comparison unit obtains a security evaluation result for each attack path based on a security evaluation of software.

5. 5. The asset model generation device according to claim 4, wherein the security evaluation comparison unit compiles the security evaluation results for each of the attack paths and performs a security evaluation for each of the candidate asset models.

6. The asset model generation device according to claim 1 , wherein the security evaluation comparison unit compares the difference between the evaluation of each of the candidate asset models and a past evaluation.

7. The asset model generation device according to claim 6 , wherein the security evaluation comparison unit selects, as the asset model, one of the candidate asset models with the smallest difference.

8. The asset model generation device according to claim 1 , wherein the security evaluation comparison unit determines the accuracy of the generated candidate asset model by comparing evaluations of the plurality of candidate asset models with past evaluations.

9. The asset model generation device according to claim 1 , wherein the system is an OT (Operational Technology) system.

10. A security evaluation system that evaluates the impact of security measures on business continuity using a digital twin that uses an asset model generated using the asset model generation device described in any one of claims 1 to 9, an actor model that represents human behavior toward the system, and a process model that represents critical operations of the system.

11. The processor executes the program stored in the memory. collecting input data including information about devices that make up the system and information about connectivity between said devices; generating a plurality of candidate asset models as candidates for an asset model that is a model of the equipment based on the collected input data; performing a security assessment on the plurality of candidate asset models; comparing the assessments of the plurality of candidate asset models with past assessments and selecting an asset model from the plurality of candidate asset models; Asset model generation method.

Citation Information

Patent Citations

  • Network asset information management

    US20140075564A1

  • Asset ranking and classification systems and methods

    US20220158944A1