Security violation analyzer, security violation analysis method, and security analysis system
The security intrusion analysis device addresses the limitation of conventional systems by comparing real and simulated system statuses to infer and detect real-time cyber attacks, enhancing the speed and accuracy of cyber threat detection.
Patent Information
- Application Number
- JP2024056499
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2025-10-10
AI Technical Summary
Conventional security systems fail to provide real-time reporting of cyber attacks on actual systems, as they are limited to rules generated from simulated systems and do not reflect real-time cyber attacks.
A security intrusion analysis device that calculates the actual operating status from a real system, compares it with a simulated system, estimates mismatches to infer undetected or falsely detected cyber attacks, and generates analysis rules to detect these attacks in real time.
Enables the appropriate detection of cyber attacks in real time on real systems, allowing for quick response and minimization of attack damage.
Smart Images

Figure 2025153840000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a security intrusion analysis device, a security intrusion analysis method, and a security analysis system. [Background technology]
[0002] As a security measure against the threat of cyber attacks, it is effective to collect environmental information, history information, and attack information from the actual system on which the attack was carried out, and analyze the attack based on this collected information. By automatically generating the rules used for this analysis (security work), the burden of analysis on administrators can be reduced.
[0003] For example, Patent Document 1 states: The rule generation device includes a collection unit that collects, from a simulated system that simulates a system that is the target of an attack, environmental information that indicates the environment constructed in the simulated system, history information recorded in the simulated system, and attack information that indicates whether an attack has been performed on the simulated system and whether the attack has succeeded or failed; an attack success condition generation unit that uses the attack information to extract environmental information at the time of a successful attack and environmental information at the time of an unsuccessful attack from the environmental information, calculates a difference between the environmental information at the time of an unsuccessful attack, which includes all of the environmental information at the time of a successful attack, and the environmental information at the time of the successful attack, attaches exclusion information indicating that the attack has failed to the difference, and adds the difference with the attachment of the exclusion information to the environmental information at the time of a successful attack to generate an attack success condition; an attack history generation unit that calculates, for each of the same environmental information at the time of successful attack, a difference between historical information at the time of no attack and historical information at the time of successful attack, extracts common historical information at the time of successful attack that is common to the calculated differences at the time of successful attack, and calculates, for each of the same environmental information at the time of unsuccessful attack, a difference between historical information at the time of no attack and historical information at the time of unsuccessful attack, extracts common historical information at the time of unsuccessful attack that is common to the calculated differences at the time of unsuccessful attack, and generates attack history information using the common historical information at the time of successful attack and the common historical information at the time of unsuccessful attack; and a rule generation unit that generates rules using the attack success conditions and the history information." [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 7207536 specification Summary of the Invention [Problem to be solved by the invention]
[0005] Since cyber attacks can occur at any time, it is necessary to respond quickly to attacks that occur in real time. To achieve this, a security system with high speed reporting is needed, which can notify administrators and others in real time of cyber attacks that are actually occurring on actual systems.
[0006] However, while conventional technologies such as those in Patent Document 1 automate the generation of rules used in analysis, they are limited to rules that are generated in advance using only a simulated system. As a result, they do not reflect cyber attacks that actually occur on real systems, and a security system that can report information quickly has not been realized.
[0007] In view of the above problems, the present invention aims to appropriately detect cyber attacks occurring in real time on a real system. [Means for solving the problem]
[0008] In order to solve the above problems, the security intrusion analysis device of the present invention has the following features. The present invention provides a computing unit that calculates the actual operating status from an actual business log recorded in a real system to be analyzed, and calculates a simulated operating status when a cyber-attack detected in the real system is executed as a simulated attack on a simulated system that simulates the real system; a comparison unit that compares the actual operating status with the simulated operating status; an estimation unit that estimates a predetermined cyber-attack that is a mismatch between a cyber-attack that occurred in the real system and a cyber-attack that was detected in the real system based on the comparison result of the comparison unit; It is characterized by having an output unit that outputs at least one of the information on the comparison results of the comparison unit and the information on the specified cyber attack inferred by the inference unit. Other means will be described later. [Effects of the Invention]
[0009] According to the present invention, it is possible to appropriately detect cyber attacks occurring in real time on a real system. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a configuration diagram showing an overview of a security analysis system according to an embodiment of the present invention. [Figure 2] FIG. 10 is an explanatory diagram showing an example of the operation of the security infringement analysis device according to the present embodiment. [Figure 3] 1 is a configuration diagram of a security analysis system that is a first example related to this embodiment. [Figure 4] FIG. 10 is a configuration diagram of a security analysis system that is a second example related to the present embodiment. [Figure 5] FIG. 10 is a configuration diagram of a security analysis system that is a third example related to the present embodiment. [Figure 6] 10 is a flowchart showing a main process of the security analysis system according to the present embodiment. [Figure 7] FIG. 10 is a screen diagram showing a first example of an individual comparison screen of operational statuses presented to a user according to the present embodiment. [Figure 8] FIG. 10 is a screen diagram showing a second example of an individual comparison screen of operational statuses presented to a user according to the present embodiment. [Figure 9] 10 is a graph showing an example of calculation of a matching rate by a comparison unit according to the present embodiment. [Figure 10] FIG. 10 is a diagram illustrating a screen of statistical information on the operational status presented to the user according to the present embodiment. [Figure 11] 10 is a flowchart showing details of a process for inferring the details of an attack by an inferring unit according to the present embodiment. [Figure 12] FIG. 10 is a screen diagram showing a list of analysis results by an analysis unit according to the present embodiment. [Figure 13] FIG. 10 is a screen diagram showing a setting screen for analysis by an analysis unit according to the present embodiment. [Figure 14] 10 is a table showing an example of an actual operation log according to the present embodiment. [Figure 15] 10 is a table illustrating an example of an attack detection log according to the present embodiment. [Figure 16] 10 is a table illustrating an example of an attack method DB according to the present embodiment. [Figure 17] 10 is a table showing an example of an actual operation status according to the present embodiment. [Figure 18] 10 is a table showing an example of history information related to the present embodiment. [Figure 19] 19 is a table showing an example of history information related to this embodiment, and is a diagram continuing from FIG. 18. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0011] An embodiment of the present invention will be described below.
[0012] FIG. 1 is a diagram showing an overview of a security analysis system 100. As shown in FIG. The security analysis system 100 is configured by connecting a real system 10 and a security infringement analysis device 20 via a network. The actual system 10 is a system that is configured with computer devices such as manufacturing equipment in a factory, operates in an actual business environment, and further includes an information collection device 11 and an analysis execution device 12. The information collection device 11 collects, as log information, an actual business log 11A, an attack detection log 11B, and an analysis target log 11C.
[0013] The task log is log information relating to tasks, such as packing being performed by manufacturing equipment in a factory at 10:14. The actual task log 11A is log information relating to tasks performed in the actual system 10. The attack detection log 11B is log information showing the results of a cyber-attack detection device (not shown) of the real system 10 detecting a cyber-attack that the real system 10 has received. However, since the cyber-attack detection device cannot detect all attacks, some cyber-attacks against the real system 10 may not be detected and may end up being omitted from the attack detection log 11B. The analysis target log 11C is log information related to the actual system 10 that is the target of analysis by the analysis execution device 12. The analysis target log 11C is, for example, login data of a management device in a factory. Note that for ease of explanation, the actual business log 11A, the attack detection log 11B, and the analysis target log 11C are described separately, but the analysis target log 11C may include the attack detection log 11B, and there may be logs that correspond to multiple logs.
[0014] The analysis execution device 12 analyzes the analysis target log 11C to discover indicators of compromise (IoC) or provides information useful for discovering IoCs. IoCs are data left behind when a system or network is compromised or attacked. Information useful for discovering IoCs is, for example, part of the data extracted from the analysis target log 11C that is likely to contain IoCs. The administrator can refer to the analysis results output by the analysis execution device 12 and discover traces of infringement from the analysis target log 11C, thereby planning measures to minimize damage from cyber attacks against those traces of infringement.
[0015] The security violation analysis device 20 includes a calculation unit 21, a comparison unit 22, an estimation unit 23, a generation unit 24, and an analysis unit 25. The security violation analysis device 20 also stores a simulated system 31, an actual operation status 32, a simulated operation status 33, an attack technique DB 34, history information 35, and analysis rules 36.
[0016] First, we define the following terms regarding cyber attacks. A "real cyber attack" is a cyber attack that actually occurs on a real system10 and whose impact is visible in the actual operating conditions32. A "detected cyber attack" is a cyber attack that is detected by the cyber attack detection device of the actual system 10 and recorded in the attack detection log 11B. For example, a new type of actual cyber attack that has not yet been registered as a detection pattern of the cyber attack detection device does not fall under the category of a detected cyber attack.
[0017] "Simulated attack details" is information indicating the details of a simulated cyber-attack that occurs when the simulated system 31 is operated, and is composed of the date, time, device, and attack method, and is included in the history information 35 in Fig. 18. The simulated attack details may be the same as the detected cyber-attack, for example, or may be updated based on the cyber-attack estimated by the estimation unit 23. A "predetermined cyber attack" is a cyber attack that is deduced by the estimation unit 23 when there is a mismatch between the actual cyber attack and the simulated attack content (such as a detected cyber attack). For example, there are cases where the detected cyber attack is matched with an actual cyber attack by supplementing a missing (undetected) predetermined cyber attack, or where the detected cyber attack is matched with an actual cyber attack by deleting a predetermined cyber attack that is excessive (i.e., a false positive) from the detected cyber attack.
[0018] The simulated system 31 is a virtual reproduction of the real system 10, and is capable of reproducing the same log information as the real system 10. The simulated system 31 is a system that simulates the real system 10 and is virtually generated on a computer as an electronic twin (digital twin) or a CPS (Cyber Physical Systems). Then, in the same way that the actual business log 11A is measured from the operating real system 10, the calculation unit 21 acquires a simulated business log as a result of running (simulating) the simulated attack content in the simulated system 31. This simulated business log is expressed in the same format as the actual business log 11A.
[0019] Furthermore, the simulated system 31 is generated by, for example, computer simulation (such as reproducing the entire simulated system 31 using a graph model) or mathematical modeling, which can reproduce data equivalent to the log information generated in the real system 10. In this way, by generating the simulated system 31 by computer simulation or mathematical modeling, it is possible to execute the cyber-attack verification process faster than real time. Alternatively, the simulated system 31 may use VMware (registered trademark) or VirtualBox (registered trademark) to replicate the real system 10 at the device OS level, but each simulated attack takes a time equivalent to real time.
[0020] "Operation status" is a representation of the business log of a system such as a product production system, using one or more features that change over time (such as the time series production volume of product A). The calculation unit 21 calculates an actual operation status 32 and a simulated operation status 33 as one or more feature quantities that indicate the operation status of the system and are defined in a time series. Specifically, the calculation unit 21 creates (shapes as features) the actual operation status 32 from the actual operation log 11A recorded in the actual system 10. The calculation unit 21 also creates simulated attack details from the detected cyber-attacks. Then, the calculation unit 21 calculates a simulated operating situation 33 when the simulated attack content is executed on a simulated system 31 that simulates the real system 10. To this end, the calculation unit 21 operates a CPS or simulator, generates simulated attack content on the simulated system 31, and creates a simulated business log, and then creates a simulated operating situation 33 from the simulated business log.
[0021] The comparison unit 22 compares the actual operation status 32 with the simulated operation status 33 and generates a comparison result. For example, the comparison unit 22 calculates a match rate, which increases as the degree of match between the actual operation status 32 and the simulated operation status 33 increases. Alternatively, the comparison unit 22 may generate a comparison result including the location and time of the cyber-attack by comparing the feature amounts of the actual operation status 32 with the feature amounts of the simulated operation status 33 in chronological order.
[0022] The estimation unit 23 estimates a predetermined cyber attack based on the comparison result of the comparison unit 22, as exemplified below. Undetected cyber attacks are cyber attacks that occurred as actual cyber attacks but were not included in the detected cyber attacks, resulting in false negatives. A false positive is a cyber attack that has not actually occurred but has been included in the detected cyber attacks, resulting in a false positive.
[0023] In addition, the estimation unit 23 may update the simulated attack content and cause the calculation unit 21 to recalculate the simulated operation status 33 so that the degree of agreement between the actual operation status 32 and the simulated operation status 33 increases as a comparison result of the comparison unit 22. The output unit 26 (FIGS. 3 to 5) outputs at least one of the information on the comparison result of the comparison unit 22 and the information on the predetermined cyber attack inferred by the inferring unit 23.
[0024] The generation unit 24 generates an analysis rule 36 for discovering the intrusion traces of the predetermined cyber-attack inferred by the inference unit 23 from the analysis target log 11C of the real system 10. The generation unit 24 generates the analysis rules 36 by referring to the attack records (the attack method DB 34 in FIG. 16) that indicate the characteristics of the intrusion traces caused by each cyber attack in the past.
[0025] The analysis unit 25 uses the analysis rules 36 generated by the generation unit 24 to analyze whether or not an IoC exists in the real system 10. For example, the analysis unit 25 uses the analysis rules 36 generated by the generation unit 24 to extract the range in which traces of intrusion of a predetermined cyber-attack inferred by the inference unit 23 exist from the analysis target log 11C of the real system 10. Therefore, the analysis unit 25 inputs the analysis rule 36 to the analysis execution device 12, thereby extracting IoCs from the analysis target log 11C. The analysis execution device 12 extracts log information that conforms to the analysis rule 36 from the analysis target log 11C, and returns the extraction result to the analysis unit 25 as IoC analysis information. This allows administrators to refer to IoC analysis information to determine which hosts / networks have been compromised and how (the extent of the attack's impact), allowing them to take appropriate measures to contain the threat, such as installing security devices that can respond to undetected cyber attacks.
[0026] The analysis execution device 12 is implemented using a security information and event management (SIEM) that accumulates the analysis target log 11C. The analysis rules 36 correspond to search commands for logs input to the SIEM. Since search commands differ depending on the SIEM vendor, the generation unit 24 absorbs these differences.
[0027] Furthermore, if the matching rate between the actual operation status 32 and the simulated operation status 33 is low, the analysis unit 25 changes the simulated attack content used in the calculation of the simulated operation status 33 (for example, adds a constraint), thereby causing the calculation unit 21 to recalculate the simulated operation status 33. In this way, the analysis unit 25 improves the matching rate between the recalculated simulated operation status 33 and the actual operation status 32. Therefore, the analysis unit 25 reads a set of executable attack patterns from the attack method DB 34 as candidates for cyber attacks to be included in the simulated attack content.
[0028] As described above with reference to FIG. 1, the security analysis system 100 includes the real system 10 and the security intrusion analysis device 20. The real system 10 includes an information collection device 11 and an analysis execution device 12 . The information collection device 11 collects an actual business log 11A and an analysis target log 11C recorded in a real system 10 to be analyzed, as well as information on cyber attacks detected in the real system 10. The analysis execution device 12 executes an analysis process using the analysis rule 36 to extract the range in which traces of infringement of a predetermined cyber attack exist from the analysis target log 11C.
[0029] The security violation analysis device 20 includes a calculation unit 21, a comparison unit 22, an estimation unit 23, a generation unit 24, an analysis unit 25, and an output unit 26. The calculation unit 21 calculates the actual operation status 32 from the actual business log 11A provided by the information collection device 11, and also calculates a simulated operation status 33 when executed as a simulated attack content indicating the cyber attack information provided by the information collection device 11 on a simulated system 31 that simulates the actual system 10. The comparison unit 22 compares the actual operation status 32 with the simulated operation status 33 . Based on the comparison result of the comparison unit 22, the estimation unit 23 estimates a predetermined cyber attack that results in a mismatch between the cyber attack that occurred in the real system 10 and the cyber attack that was detected in the real system 10. The generation unit 24 generates an analysis rule 36 to be used in the analysis process of the predetermined cyber attack inferred by the inference unit 23. The analysis unit 25 provides the analysis rule 36 generated by the generation unit 24 to the analysis execution unit 12, thereby causing the analysis execution unit 12 to execute the analysis process. The output unit 26 (Figures 3 to 5) outputs at least one of the following information: information on the comparison results of the comparison unit 22, information on a specified cyber attack inferred by the inference unit 23, and information on the results of the analysis process performed by the analysis unit 25 in the analysis execution device 12.
[0030] FIG. 2 is an explanatory diagram showing an example of the operation of the security intrusion analysis device 20. As shown in FIG. The security intrusion analysis device 20 performs the following steps. (First Step) The security intrusion analysis device 20 calculates a feature quantity related to the actual operation status 32 of the actual system 10 from the actual business log 11A. In Fig. 2, the security intrusion analysis device 20 calculates the actual operation status 32 including a decrease in the feature quantity T1 due to the cyber-attack SA and a decrease in the feature quantity T2 due to the cyber-attack SB.
[0031] (Second Step) The security breach analysis device 20 calculates features related to a simulated operating situation 33 calculated from the simulated attack content using the simulated system 31. In Fig. 2, the security breach analysis device 20 calculates the simulated operating situation 33 including a decrease in feature T1 due to the cyber-attack SA and a decrease in feature T3 due to the cyber-attack SC.
[0032] (Third Step) Based on the results of comparing the actual operation status 32 in (first step) with the simulated operation status 33 in (second step), the security breach analysis device 20 uses reinforcement learning or the like to infer the attack content (predetermined cyber attack) that fills in the difference in the features that differ between the two, based on the simulated system 31, as follows: · Cyber-attack SA (decrease in feature T1) is observed consistently in both real and detected cyber-attacks, so it is a normal detection and does not correspond to the specified cyber-attack. A cyber attack SB (decrease in feature T2) is a case where an abnormal value of the feature due to a cyber attack is observed in the actual operation status 32, but a normal value of the feature is observed in the simulated operation status 33. In this case, the estimation unit 23 estimates that a cyber attack that actually occurred in the actual system 10 but was not detected is a predetermined cyber attack. A cyber attack SC (decrease in feature T3) occurs when a normal value of the feature is observed in the actual operating condition 32, but an abnormal value of the feature due to a cyber attack is observed in the simulated operating condition 33. In this case, the estimation unit 23 estimates that a cyber attack that did not actually occur in the real system 10 but was falsely detected is a specified cyber attack.
[0033] (Fourth Step) The security intrusion analysis device 20 analyzes whether or not an IoC that determines the occurrence of the specified cyber-attack inferred in (Third Step) exists in the analysis target log 11C of the real system 10. If an undetected cyber-attack SB does not exist in the analysis target log 11C, or if a false positive cyber-attack SC exists in the analysis target log 11C, it means that the accuracy of the inference of the specified cyber-attack was not good. In this case, security intrusion analysis device 20 updates the simulated attack content, recalculates simulated operating status 33 in accordance with the update, and returns to (second procedure).
[0034] Three examples of hardware configurations for implementing the security analysis system 100 of FIG. 1 will be illustrated below with reference to the drawings (FIGS. 3, 4, and 5). FIG. 3 is a configuration diagram of a security analysis system 100A as a first example. In security analysis system 100A, a security violation analysis program 20P for configuring each processing unit described in security analysis system 100 of Fig. 1 and output unit 26 is stored in storage device 20H. Output unit 26 outputs the processing results of each processing unit in the form of a screen display, file output, or the like. Storage device 20H also stores each data described in security analysis system 100 of Fig. 1.
[0035] Furthermore, the security violation analysis device 20 of the security analysis system 100A has a hardware configuration for running the security violation analysis program 20P, including a CPU 41, a memory 42, an input / output interface 43, an input device 44, a display device 45, and an external communication interface 46. The external communication interface 46 is connected to an external device such as the real system 10. The input / output interface 43 is connected to an input device 44 and a display device 45. Furthermore, CPU 41 controls each processing unit by executing security infringement analysis program 20P loaded into memory 42. This security infringement analysis program 20P can be distributed via a communication line or recorded on a recording medium such as a CD-ROM and distributed.
[0036] FIG. 4 is a configuration diagram of a security analysis system 100B according to the second example. In the security analysis system 100A of the first example, the information collection device 11 holds various logs collected by the information collection device 11 (actual business log 11A, attack detection log 11B, analysis target log 11C). In the second example security analysis system 100B, the collection unit 27 of the security violation analysis device 20 collects various logs collected by the information collection device 11 from the information collection device 11 and stores them in the storage device 20H.
[0037] FIG. 5 is a configuration diagram of a security analysis system 100C according to the third example. In the security analysis system 100A of the first example, one analysis execution device 12 analyzes the analysis target log 11C. The security analysis system 100A of the third example has a plurality of analysis execution devices 12. The generator 24 then references the analysis rule notation 37 to generate an analysis rule 36 corresponding to each analysis execution device 12.
[0038] FIG. 6 is a flowchart showing the main processing of the security analysis system 100. The calculation unit 21 calculates the actual operation status 32 from the actual business log 11A (S101), and also calculates the simulated operation status 33 using the attack detection log 11B and the simulated system 31 (S102). The comparison unit 22 compares the actual operation status 32 of S101 with the simulated operation status 33 of S102, and presents the comparison result to the user via the output unit 26 (S103). The comparison unit 22 then determines whether or not there is a significant difference in the comparison result of S103 (S104). If the answer is No in S104, the comparison unit 22 ends the process, and if the answer is Yes, the process proceeds to S105.
[0039] The estimation unit 23 estimates attack details that have not been detected or have been falsely detected in the real system 10 using the simulated system 31, the attack method DB 34, and the history information 35 (S105). The generation unit 24 creates analysis rules 36 for checking whether or not an IoC exists for the attack details estimated in S105 (S106). The analysis unit 25 inputs the analysis rule 36 generated in S106 to the analysis execution device 12, and executes an IoC analysis from the analysis target log 11C in the real system 10 (S107). The analysis unit 25 determines whether or not an IoC exists in the real system 10 (analysis target log 11C) as a result of the analysis in S107 (S108). If the answer is Yes in S108, the analysis unit 25 ends the process, and if the answer is No, the analysis unit 25 updates the history information 35 (S109) and then returns the process to S105.
[0040] FIG. 7 is a diagram showing a first example of an individual comparison screen of operational statuses presented to the user in S103. The comparison unit 22 displays the time series graph (solid line graph) of the actual operation status 32 and the time series graph (dashed line graph) of the simulated operation status 33 for the "production rate of product A" individually selected from the list of features, aligning the time series so that they can be compared. From this graph display, the administrator can confirm that the operation status of both products matches with regard to the production rate of product A, and therefore that cyber attacks on devices related to product A have been detected without omission. In addition, the administrator can click the statistics button to move to the "Operation Status Statistics" screen shown in Figure 10.
[0041] FIG. 8 is a screen diagram showing a second example of the individual comparison screen of the operational status presented to the user in S103. The comparison unit 22 confirms that for the "production rate of product B" individually selected from the list of features, the solid line graph of the actual operation status 32 and the dashed line graph of the simulated operation status 33 do not match after 17:00. Note that in the actual operation status 32, a drop in the production rate occurred after 17:00, but in the simulated operation status 33, the production rate did not drop after 17:00. 8 suggests that the simulated operation status 33 (the simulated attack content used to generate the simulated operation status 33) has not detected the cyber-attack that actually occurred in the actual operation status 32. In this case, for example, the analysis unit 25 predicts the cyber-attack that actually occurred in the actual operation status 32, and updates the history information 35 (the simulated attack content) so as to newly include the cyber-attack in the simulated attack content (S109).
[0042] FIG. 9 is a graph showing an example of calculation of the matching rate by the comparison unit 22. The graph in Figure 9 is the same as the graph in Figure 8, but with the following calculation parameters added: ·X(t)=Actual operating status 32 Y(t) = Simulated operating condition 33 D = Maximum error between X(t) and Y(t) T = the time interval during which X(t) and Y(t) disagree τ = simulation time Here, (Equation 1) is an equation that expresses the matching rate as a numerical value between 0% and 100%, and the matching rate can be defined as a function proportional to D×T.
[0043]
number
[0044] The comparison unit 22 calculates the match rate for each feature based on (Equation 1) and calculates the average value as the match score. Alternatively, if the comparison unit 22 wants to emphasize a specific feature, it may calculate the match score by multiplying it by a coefficient that increases the weight of the match rate associated with that feature (weighting the feature that is to be emphasized).
[0045] FIG. 10 is a diagram showing the screen of the statistical information on the operational status presented to the user in S103. The statistical information screen diagram displays all the information displayed on the individual comparison screens such as Figures 7 and 8 in one place, and includes the following elements: The summary table on the individual comparison screen displays the match rate (%) and the start date and time of the mismatch for each individual feature. As explained in Figure 9, the match score is a representative value summarizing the match rate for each feature. The higher the value, the higher the degree of match between the actual operating status 32 and the simulated operating status 33. The target score is a target value for the match score that can be edited via the text box, and if the match score is greater than or equal to the target score, the comparison unit 22 determines that there is no significant difference in the comparison result of S103 (No in S104). The Individual Comparison button is a button to return to the individual comparison screen such as Figure 7 and Figure 8. The "start inference of mismatch cause" button is a button for starting the process of inferring the attack details by the inference unit 23 (S105, details are shown in FIG. 11).
[0046] FIG. 11 is a flowchart showing the details of the process (S105) of estimating the attack content by the estimation unit 23. The estimation unit 23 estimates the details of the simulated attack using the history information 35 and the attack method DB 34, as shown in the following example (S201). Cyber attacks that cannot be detected (such as forced shutdown of control devices) that are not marked with a circle in the attack detection correspondence table shown in Figure 16 below are likely to be missed, so they should be selected as a priority. For example, if a brute force attack (attack ID = 1) and the destruction of attack evidence (attack ID = 3) are recorded as correlated cyber attacks among multiple detected cyber attacks, as shown in Figure 14, it can be inferred that an attack such as process termination (attack ID = 2) occurred during the time between them. Furthermore, the time of the attack can be inferred in more detail from the operational status 32. For example, a cyber-attack learned through reinforcement learning can be simulated to obtain a higher matching score. If an incorrect simulated attack affects an unrelated feature (such as the production volume of product C), a negative reward can be given and the system can move on to the next simulated attack. Do not select attacks that have already been recorded in the history information 35. This is because it is obvious that they will fail. Alternatively, the estimation unit 23 may use the cyber-attack detected as the attack detection log 11B as the simulated attack content in S201.
[0047] The estimation unit 23 calls the calculation unit 21, and calculates the simulated operation status 33 using the simulated attack content estimated in S201 and the simulated system 31 (S202). The estimation unit 23 calls the comparison unit 22, and has it calculate a match score based on the actual operation status 32 and the simulated operation status 33 (S203). The estimation unit 23 updates the simulated attack details in the history information 35 to those estimated in S201 (S204), and determines whether the match score of the updated simulated attack details exceeds the target match score (S205). If the answer is Yes in S205, the estimation unit 23 ends the process, and if the answer is No, the process returns to S201.
[0048] FIG. 12 is a diagram showing a screen showing a list of analysis results by the analysis unit 25. 12 shows a table listing the analysis results, which associates the simulated attack details (attack ID, date and time, device, attack method) inferred by the inference unit 23 with the analysis information (analysis status, correction details) resulting from the analysis performed by the analysis unit 25 using the analysis rules 36. The attack IDs in FIG. 12 correspond to the same numbers as the history IDs in the history information 35 in FIGS. 18 and 19. The administrator selects the attack ID to be analyzed from the pull-down menu ("2" is selected in the figure) and clicks the "Run Analysis" button. In this case, the analysis unit 25 transitions to the setting screen in Fig. 13 for analyzing whether the attack with the selected attack ID = 2 actually occurred.
[0049] FIG. 13 is a screen diagram showing a setting screen for analysis by the analysis unit 25. The analysis unit 25 displays the range where traces of infringement from a cyber attack exist on a screen as shown in Figure 13, and accepts input to confirm whether or not there are traces of infringement.If there are no traces of infringement, the analysis unit 25 causes the estimation unit 23 to update the details of the simulated attack. The setting screen of FIG. 13 has, from the top, an attack information column 301, an analysis rule 36 editing column 302, and an analysis result column 303. Similar to FIG. 12, the attack information column 301 is a table that associates simulated attack details (attack ID, date and time, device, attack method) with analysis information (analysis status, correction details), and the record for the selected attack ID = 2 is extracted. Note that although the attack detection log 11B is recorded in the analysis status column, there is also a possibility that the corresponding IoC was not found and it was actually a false positive. In this example, since an IoC was found, the status is changed to IoC confirmation. The input content of this change is also reflected in the history information 35. Additionally, if there is a discrepancy between the simulated attack details and the IoCs that were actually discovered, the administrator is asked to enter that information in the correction details field. In this example, the event occurred at 14:17, not 14:00, so the administrator is asked to enter that correction information.
[0050] The analysis rule 36 editing field 302 has a text box for writing the analysis rule 36, an edit button, and an execute button. The analysis rule 36 output from the generation unit 24 is substituted for the initial value of the text box. The administrator can click the edit button to enter a mode for changing the contents of the text box, and manually edit the analysis rule 36 to fine-tune it. When the administrator clicks the execute button, the analysis unit 25 sends the analysis rule 36 written in the text box to the analysis execution device 12. The analysis execution device 12 extracts log information that matches the analysis rule 36 from the analysis target log 11C of the real system 10, and returns the extracted log information to the analysis unit 25.
[0051] The format for describing analysis rule 36, which extracts logs corresponding to recording time "zzz" from logs "xxx" on device "yyy", is as follows: "search log_xxx from device_yyy time zzz" Furthermore, the analysis rule 36 for finding the attack record "log recorded when a process on a monitoring server is forcibly terminated" (see FIG. 16) is as follows: "search log -device_name "Monitoring Server A" --event_type_id 12345 --time_from 20XX-01-14 13:00 --time_to 20XX-01-14 15:00" Here, since the format of the analysis rules 36 may differ depending on the vendor, the analysis unit 25 may utilize the generation AI to absorb (convert the format) the differences in how the analysis rules 36 (log search statements) are written, which differ depending on the vendor.
[0052] The analysis result column 303 is a column that displays the log information (corresponding data between the log recording time and the log content) returned from the analysis execution device 12. In the example of FIG. 13, an IoC of an attack corresponding to attack ID=2 of the simulated attack content was discovered in the line with "CRITICAL" written at the beginning of the log content. After confirming this IoC, the administrator switches the radio button in the analysis status column of the attack information column 301 from "analysis not performed" to "IoC confirmed." The updated results of the attack information column 301 (analysis information) are reflected on the analysis result list screen of FIG. 12 from the setting screen of FIG.
[0053] FIG. 14 is a table showing an example of the actual operation log 11A. The actual work log 11A recorded in the actual system 10 associates the product type with the manufacturing record (dates and times of assembly completion, inspection completion, packaging completion, and shipping preparation completion) for each product ID. The simulated work log recorded in the simulated system 31 has the same format as the actual work log 11A.
[0054] FIG. 15 is a table showing an example of the attack detection log 11B. The attack detection log 11B associates the circumstances (date and time, device) in which the attack occurred, the attack method, and the detection source. The detection source may be, for example, a host-based intrusion detection system (HIDS) or a network-based intrusion detection system (NIDS), which is the cyber attack detection device (not shown) described in FIG.
[0055] FIG. 16 is a table showing an example of the attack method DB 34. The attack method DB 34 associates an attack detection correspondence table with an attack record for each attack method. The attack detection correspondence table is a table that shows the attack detection correspondence status of the cyber attack detection device, and is either fully compatible (marked with a circle), partially compatible (marked with a triangle), or not compatible (blank). The attack record shows an example of what kind of log is recorded as an IoC when an attack is carried out using the corresponding attack method.
[0056] FIG. 17 is a table showing an example of the actual operation status 32. The actual operation status 32 corresponds, as features for each date and time, numerical features (production rate of product A, production rate of product B, and production rate of product C) with features evaluated as a binary value of True or False (quality assurance and remote monitoring). The simulated operating status 33 has the same format as the actual operating status 32.
[0057] FIG. 18 is a table showing an example of the history information 35. The history information 35 is information that associates simulated attack details (date and time, device, attack method), analysis information (analysis status, correction details), and match scores for each history ID, and can also be called past failure information. The simulated attack details for history ID=1 were calculated by the calculation unit 21 from the attack detection log 11B, and three types of cyber attacks were detected with a time difference. However, the matching score was low at "65" (less than the threshold "98"), suggesting the existence of real cyber attacks that were either not detected or were falsely detected.
[0058] FIG. 19 is a table showing an example of the history information 35, and is a diagram continuing from FIG. In the record with history ID=10, the estimation unit 23 added two new attack methods (process forced termination and control device forced termination) to the simulated attack content of history ID=1 (updating process of simulated attack content in S204).The administrator was then able to confirm each attack except for "control device forced termination on PLC B" from the analysis result column 303 in FIG.
[0059] In the record with history ID=15, the estimation unit 23 updated the simulated attack content of history ID=10 from "forced termination of control device to PLC B" to "forced termination of process to control server B" (S204). Then, the administrator was able to confirm "forced termination of process to control server B" from the analysis result column 303 in Fig. 13. As a result, the match score became 100 (full marks), and the actual cyber attack and the simulated attack content were a perfect match. When this matching score is 100 (or when the matching score is higher than a predetermined score, such as > 98), the estimation unit 23 may compare the simulated attack content with the detected cyber attack, and based on the excess or deficiency, extract a predetermined cyber attack (an actual cyber attack that was not detected or was falsely detected).
[0060] Furthermore, the estimation unit 23 may perform a performance evaluation of the device that detects cyber-attacks in the real system 10 based on the comparison result of the comparison unit 22. For example, the estimation unit 23 intentionally generates a real cyber-attack in the real system 10 by a penetration test or the like, and performs a performance evaluation of the cyber-attack detection device installed in the real system 10 based on the comparison result between the real cyber-attack (actual operation status 32) and the detected cyber-attack (simulated operation status 33). The estimation unit 23 calculates one of the following values as a performance evaluation value and causes the output unit 26 to output the calculation result. - Match score between actual operating conditions 32 and simulated operating conditions 33. The higher this match score, the higher the performance of the cyber attack detection device. The false negative rate increases as the number of undetected cyber attacks increases. The lower this false negative rate, the higher the performance of the cyber attack detection device. The false positive rate increases as the number of false positive cyberattacks increases. The lower this false positive rate, the higher the performance of the cyberattack detection device.
[0061] The security breach analysis device 20 of this embodiment described above compares the actual operation status 32 calculated from the actual business log 11A of the actual system 10 that has been subjected to an actual cyber-attack with the simulated operation status 33 calculated from the simulated business log of the simulated system 31 and the simulated attack content, and infers the attack content (a specified cyber-attack) that will fill the gap. Here, the security intrusion analysis device 20 can create analysis rules 36 that take into account the location and time of an event by comparing the actual operation status 32 and the simulated operation status 33 in chronological order (aligning the time axes as shown in Figures 7 and 8). When a cyber-attack occurs, the scope of the attack's impact can be identified by intrusion analysis using the analysis rules 36, and the threat can be quickly contained and damage minimized.
[0062] Furthermore, the present invention is not limited to the above-described embodiments, and various other applications and modifications are possible without departing from the spirit of the present invention as set forth in the claims. For example, the above-described embodiments provide detailed and specific descriptions of the configuration of the security intrusion analysis device 20 in order to clearly explain the present invention, and are not necessarily limited to devices that include all of the components described. Furthermore, it is possible to replace part of the configuration of one embodiment with components of another embodiment. It is also possible to add components of another embodiment to the configuration of one embodiment. It is also possible to add, replace, or delete other components from part of the configuration of each embodiment.
[0063] Furthermore, the above-described configurations, functions, processing units, etc. may be partially or entirely realized in hardware, for example, by designing them as integrated circuits, etc. As the hardware, a broad processor device such as an FPGA (Field Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) may be used. Furthermore, each component of the security breach analysis device 20 according to the above-described embodiment may be implemented in any hardware as long as the respective hardware can transmit and receive information to and from each other via a network. Furthermore, the processing executed by a certain processing unit may be realized by a single piece of hardware, or may be realized by distributed processing using multiple pieces of hardware. [Explanation of symbols]
[0064] 10 Actual system 11 Information gathering device 11A Actual business log 11B Attack detection log 11C Analysis target log 12 Analysis execution device 20 Security Intrusion Analysis Equipment 21 Calculation section 22 Comparison section 23 Guessing part 24 Generation part 25 Analysis Department 26 Output section 27 Collection Department 31 Simulation System 32 Operational Status 33 Simulated operating conditions 34 Attack Method DB 35 Historical Information 36 Analysis Rules 37 Analysis Rule Notation 100 Security Analysis Systems
Claims
1. a calculation unit that calculates an actual operation status from an actual business log recorded in a real system to be analyzed, and calculates a simulated operation status when a cyber-attack detected in the real system is executed as a simulated attack content on a simulated system that simulates the real system; a comparison unit that compares the actual operating status with the simulated operating status; an estimation unit that estimates a predetermined cyber-attack that is a mismatch between a cyber-attack that occurred in the real system and a cyber-attack that was detected in the real system based on the comparison result of the comparison unit; and an output unit that outputs at least one of information on the comparison result of the comparison unit and information on the predetermined cyber attack inferred by the inference unit. Security breach analysis equipment.
2. The calculation unit calculates the actual operating status and the simulated operating status as one or more feature quantities that indicate the operating status of the system and are defined in a time series. The security breach analysis device of claim 1 .
3. The comparison unit generates a comparison result including the location and time of the cyber-attack by comparing the feature amount of the actual operation status with the feature amount of the simulated operation status in chronological order. The security breach analysis device according to claim 2 .
4. The estimation unit is characterized in that, when an abnormal value of a feature amount due to a cyber-attack is observed in the actual operation state and a normal value of the feature amount is observed in the simulated operation state, the estimation unit estimates that a cyber-attack that actually occurred in the actual system but was not detected is the predetermined cyber-attack. The security breach analysis device according to claim 2 .
5. The estimation unit is characterized in that, when a normal value of the feature quantity is observed in the actual operation state and an abnormal value of the feature quantity due to a cyber-attack is observed in the simulated operation state, the estimation unit estimates a cyber-attack that has not actually occurred in the actual system but has been falsely detected as the predetermined cyber-attack. The security breach analysis device according to claim 2 .
6. The estimation unit updates the simulated attack content and causes the calculation unit to recalculate the simulated operation status so that the actual operation status and the simulated operation status match to a higher degree as a comparison result of the comparison unit. The security breach analysis device of claim 1 .
7. The estimation unit is characterized in that it selects at least one cyber-attack from among a cyber-attack that cannot be detected by the real system, a cyber-attack that correlates with the detected cyber-attacks in a context, and a cyber-attack that has been learned by reinforcement learning, as the content of the simulated attack to be updated.
7. The security breach analysis device of claim 6.
8. the security intrusion analysis device further includes a generation unit that generates an analysis rule for discovering the intrusion traces of the predetermined cyber-attack inferred by the inference unit from the analysis target log of the real system; The generation unit generates the analysis rules by referring to attack records that indicate characteristics of intrusion traces caused by each cyber attack in the past.
7. The security breach analysis device of claim 6.
9. The security intrusion analysis device further includes an analysis unit that uses the analysis rule generated by the generation unit to extract a range in which traces of intrusion of the predetermined cyber-attack inferred by the inference unit exist from the analysis target log of the real system.
9. The security breach analysis device of claim 8.
10. The analysis unit displays on a screen the extent to which traces of infringement of a cyber attack exist, and receives an input to confirm the presence or absence of traces of infringement. If no traces of infringement exist, the analysis unit updates the details of the simulated attack to the estimation unit.
10. The security breach analysis device of claim 9.
11. The estimation unit evaluates the performance of a device for detecting cyber-attacks in the real system based on the comparison result of the comparison unit. The security breach analysis device of claim 1 .
12. The security breach analysis device includes a calculation unit, a comparison unit, an estimation unit, and an output unit; The calculation unit calculates an actual operation status from an actual business log recorded in the actual system to be analyzed, and calculates a simulated operation status in a simulated system that simulates the actual system when a cyber-attack detected in the actual system is executed as a simulated attack content, the comparison unit compares the actual operation status with the simulated operation status, the estimation unit estimates a predetermined cyber-attack that is a mismatch between the cyber-attack that occurred in the real system and the cyber-attack that was detected in the real system based on the comparison result of the comparison unit; The output unit outputs at least one of information on the comparison result of the comparison unit and information on the predetermined cyber attack inferred by the inferring unit. Security breach analysis methods.
13. A real system and a security intrusion analysis device are provided, The real system is an information collection device that collects actual business logs and analysis target logs recorded in the real system to be analyzed, and information on cyber attacks detected in the real system; an analysis execution device that executes an analysis process to extract, from the analysis target log, a range in which there exists a trace of infringement of a predetermined cyber-attack that is inconsistent between the cyber-attack that occurred in the real system and the information of the cyber-attack that was detected in the real system, using an analysis rule; The security breach analysis device a calculation unit that calculates an actual operation status from the actual operation log provided by the information collection device, and calculates a simulated operation status when executed as a simulated attack content indicating the cyber-attack information provided by the information collection device on a simulated system that simulates the actual system; a comparison unit that compares the actual operating status with the simulated operating status; an inference unit that infers the predetermined cyber-attack based on the comparison result of the comparison unit; a generation unit that generates the analysis rule to be used in the analysis process of the predetermined cyber-attack inferred by the inference unit; an analysis unit that provides the analysis rule generated by the generation unit to the analysis execution device, thereby causing the analysis execution device to execute the analysis process; an output unit that outputs at least one of information on the comparison result of the comparison unit, information on the predetermined cyber-attack inferred by the inference unit, and information on the result of the analysis unit causing the analysis execution device to execute the analysis process. Security analysis system.
Citation Information
Patent Citations
Rule generation device, rule generation method, and program
JP7207536B2