Security monitoring apparatus, security monitoring method, and program

The security monitoring device addresses the challenge of identifying cyber attacks in plant control systems by assessing control command risk and incident signs, enabling early detection and prevention of incidents.

JP2025163549APending Publication Date: 2025-10-29FUJI ELECTRIC CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024066929
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-17
Publication Date
2025-10-29

AI Technical Summary

Technical Problem

Conventional methods fail to determine whether an incident in a plant control system is caused by a cyber attack before it occurs.

Method used

A security monitoring device that includes a first verification unit to assess control command risk, a second unit to verify signs of an incident, and a judgment unit to determine the cause of the incident based on the number of control commands exceeding a predetermined risk threshold.

Benefits of technology

Enables the identification of cyber attacks before they occur, allowing for timely intervention and prevention of incidents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025163549000001_ABST
    Figure 2025163549000001_ABST
Patent Text Reader

Abstract

To determine whether an incident is to be caused by a cyberattack, before the incident occurs.SOLUTION: A security monitoring apparatus includes: a first verification unit which verifies a risk level of a control command on the basis of definition information on the control command for a control target; a second verification unit which verifies a sign of an incident on the control target, on the basis of data collected from the control target; and a determination unit which determines, when the presence of the sign of the incident is verified on the control target, whether the incident is to be caused by an external attack on the basis of the number of control commands issued, the control commands having a predetermined risk level or higher.SELECTED DRAWING: Figure 13
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to a security monitoring device, a security monitoring method, and a program. [Background technology]

[0002] In a control system for a plant or the like, when an incident occurs, it is necessary to identify the cause of the incident. For this reason, there is known a technique for determining whether the cause of the incident is a cyber attack (for example, Patent Document 1). [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-111003 Summary of the Invention [Problem to be solved by the invention]

[0004] However, with conventional technology, it was not possible to determine whether an incident was caused by a cyber attack based on the symptoms of the incident before it actually occurred.

[0005] The present disclosure has been made in consideration of the above points, and aims to determine whether an incident is caused by a cyber attack before the incident occurs. [Means for solving the problem]

[0006] A security monitoring device according to one embodiment of the present disclosure includes a first verification unit that verifies the risk of a control command based on definition information of the control command for a controlled object, a second verification unit that verifies signs of an incident for the controlled object based on data collected from the controlled object, and a judgment unit that, when it is verified that there are signs of an incident for the controlled object, determines whether the cause of the incident is due to an external attack based on the number of control commands issued that are greater than or equal to a predetermined risk. [Effects of the Invention]

[0007] Before an incident occurs, it is possible to determine whether the cause of the incident is a cyber attack. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a diagram illustrating an example of the overall configuration of a security monitoring system according to an embodiment of the present invention. [Figure 2] 1 is a diagram illustrating an example of a hardware configuration of a security monitoring device according to an embodiment of the present invention. [Figure 3] FIG. 2 is a diagram illustrating an example of the functional configuration of the security monitoring device according to the present embodiment. [Figure 4] FIG. 10 is a diagram illustrating an example of control command information. [Figure 5] FIG. 10 is a diagram illustrating an example of control command definition information. [Figure 6] 10A and 10B are diagrams illustrating examples of control command verification result information and control command executability determination count information. [Figure 7] FIG. 10 is a diagram illustrating an example of unauthorized operation criteria information. [Figure 8] FIG. 10 is a diagram illustrating an example of plant operation status verification result information. [Figure 9] FIG. 10 is a diagram illustrating an example of failure definition information. [Figure 10] 10 is a flowchart illustrating an example of a control command verification process. [Figure 11]10 is a flowchart illustrating an example of a plant operation status verification process. [Figure 12] 10 is a flowchart illustrating an example of an incident determination process. [Figure 13] FIG. 10 is a diagram illustrating an example of a security monitoring screen. DETAILED DESCRIPTION OF THE INVENTION

[0009] An embodiment of the present invention will be described in detail below with reference to the drawings. The following describes a security monitoring system 1 that targets a plant control system and can determine whether an incident is caused by a cyber-attack before the incident occurs. An incident is any abnormality that occurs in a plant (including a malfunction, an abnormality caused by a cyber-attack, etc.). A cyber-attack is an unauthorized operation from outside (i.e., an operation using an unauthorized control command), etc.

[0010] <Overall configuration example of security monitoring system 1> An example of the overall configuration of a security monitoring system 1 according to this embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing an example of the overall configuration of a security monitoring system 1 according to this embodiment.

[0011] As shown in Fig. 1, the security monitoring system 1 according to this embodiment includes a security monitoring device 10, a control system 20, a plant main machine 30, and an operator terminal 40. The security monitoring device 10 and the control system 20 are communicatively connected via a network such as a LAN (Local Area Network). Similarly, the security monitoring device 10 and the operator terminal 40 are communicatively connected via a network such as a LAN. Furthermore, the control system 20 and the plant main machine 30 are communicatively connected via a control network or the like.

[0012] In response to a control command verification request, the security monitoring device 10 verifies a risk level indicating the risk that a control command for controlling the plant main machine 30 is an unauthorized control command. The security monitoring device 10 also verifies signs of an incident in the plant based on process data. Furthermore, when the security monitoring device 10 verifies that there are signs of an incident, it determines whether the incident is caused by a cyber-attack using the verification results for the control command, etc. Additionally, the security monitoring device 10 transmits notification information including the determination results to the operator terminal 40, receives instruction information related to various information from the operator terminal 40, and transmits control command verification results indicating the verification results for the control command to the control system 20. The security monitoring device 10 is realized, for example, by a PC (personal computer), a workstation, a general-purpose server, etc.

[0013] The control command is instruction information for operating (e.g., starting, operating, stopping, etc.) the plant's main machinery 30. Process data is data that indicates various states (e.g., temperature, pressure, flow rate, etc.) of the process executed by the plant. The process data is composed of, for example, measurement values ​​obtained by measuring various states of the process using measuring devices such as sensors. The variables in which these measurement values ​​are stored are called process variables, and generally, process data is composed of multiple process variable values.

[0014] The control system 20 is a system that controls a plant. The control system 20 includes, for example, a control server 50, a plant control device 60, and an on-site plant control device 70. The control server 50 issues control commands and transmits them to the plant control device 60. The plant control device 60 transmits the control commands received from the control server 50 to the subordinate on-site plant control device 70. The on-site plant control device 70 transmits control command verification requests for the control commands received from the plant control device 60 to the security monitoring device 10, controls the main plant machine 30 in accordance with the control commands, and receives process data from the main plant machine 30.

[0015] For example, the control server 50 is realized by a supervisory control and data acquisition (SCADA) system or a distributed control system (DCS). The plant control device 60 is realized by a DCS. The on-site plant control device 70 is realized by a programmable logic controller (PLC) or an inverter. Generally, a plurality of on-site plant control devices 70 exist for one plant control device 60.

[0016] The plant main machinery 30 is various equipment that constitutes the plant. If the plant is a power plant, a specific example of the plant main machinery 30 is a steam turbine or the like.

[0017] The operator terminal 40 is a terminal used by an operator of the plant. The operator terminal 40 is realized by, for example, a PC, a smartphone, a tablet terminal, a wearable device, or the like.

[0018] 1 is merely an example, and the overall configuration of the security monitoring system 1 is not limited to this. For example, the plant control device 60 may not exist, and the control server 50 may send a control command to the on-site plant control device 70.

[0019] <Example of hardware configuration of security monitoring device 10> An example of the hardware configuration of the security monitoring device 10 according to this embodiment will be described with reference to Fig. 2. Fig. 2 is a diagram showing an example of the hardware configuration of the security monitoring device according to this embodiment.

[0020] 2, the security monitoring device 10 according to this embodiment includes an input device 11, a display device 12, an external I / F 13, a communication I / F 14, a RAM (Random Access Memory) 15, a ROM (Read Only Memory) 16, an auxiliary storage device 17, and a processor 18. Each of these pieces of hardware is connected to each other via a bus 19 so as to be able to communicate with each other.

[0021] The input device 11 is, for example, a keyboard, a mouse, a touch panel, a physical button, etc. The display device 12 is, for example, a display, a display panel, etc. Note that the security monitoring device 10 does not necessarily have to have at least one of the input device 11 and the display device 12, for example.

[0022] The external I / F 13 is an interface with an external device such as a recording medium 13a. Examples of the recording medium 13a include a CD (Compact Disc), a DVD (Digital Versatile Disk), an SD memory card (Secure Digital memory card), and a USB (Universal Serial Bus) memory card.

[0023] The communication I / F 14 is an interface for communicating with the on-site plant control device 70, the operator terminal 40, etc. The RAM 15 is a volatile semiconductor memory (storage device) that temporarily stores programs and data. The ROM 16 is a non-volatile semiconductor memory (storage device) that can store programs and data even when the power is turned off. The auxiliary storage device 17 is a non-volatile storage device (storage device) such as an HDD (Hard Disk Drive), an SSD (Solid State Drive), or a flash memory. The processor 18 is one of various arithmetic devices such as a CPU (Central Processing Unit) or a GPU (Graphics Processing Unit).

[0024] 2 is an example, and the hardware configuration of the security monitoring device 10 is not limited to this. For example, the security monitoring device 10 may have multiple auxiliary storage devices 17 or multiple processors 18, may not have some of the hardware shown in the figure, or may have various hardware other than the hardware shown in the figure.

[0025] <Example of functional configuration of security monitoring device 10> An example of the functional configuration of the security monitoring device 10 according to this embodiment will be described with reference to Fig. 3. Fig. 3 is a diagram showing an example of the functional configuration of the security monitoring device 10 according to this embodiment.

[0026] As shown in FIG. 3 , the security monitoring device 10 according to this embodiment includes an external input / output unit 101, a control command verification unit 102, a plant operation status verification unit 103, an incident determination unit 104, and an output unit 105. These units are realized, for example, by a processor 18 or the like executing one or more programs installed in the security monitoring device 10. The security monitoring device 10 according to this embodiment also includes a control command definition information storage unit 106, a control command verification result DB 107, a plant operation status verification result DB 108, an unauthorized operation criteria information storage unit 109, and a fault definition information storage unit 110. Each of these storage units or DBs is realized, for example, by a storage area of ​​the auxiliary storage device 17 or the like. However, at least one of these storage units or DBs may also be realized, for example, by a storage area of ​​a storage device (e.g., a storage device provided in a database server) or the like connected to the security monitoring device 10 so as to be able to communicate with the security monitoring device 10.

[0027] The external input / output unit 101 receives control command verification requests and process data transmitted from the on-site plant control device 70, and transmits control command verification results to the on-site plant control device 70. Furthermore, the external input / output unit 101 transmits an email including the control command verification results to the operator terminal 40 in accordance with the control command verification results, and receives instruction information from the operator terminal 40. Hereinafter, it is assumed that the control command verification results include control command information that represents various information related to the control commands. Furthermore, the external input / output unit 101 stores control command definition information in the control command definition information storage unit 106, stores improper operation criteria information in the improper operation criteria information storage unit 109, and stores fault definition information in the fault definition information storage unit 110, in accordance with the instruction information received from the operator terminal 40. In addition, the external input / output unit 101, in accordance with instruction information received from the operator terminal 40, updates or deletes the control command definition information stored in the control command definition information storage unit 106, updates or deletes the improper operation criterion information stored in the improper operation criterion information storage unit 109, updates or deletes the fault definition information stored in the fault definition information storage unit 110, and resets counters (a normal determination count counter, a caution determination count counter, and a warning determination count counter, which will be described later) included in the control command execution feasibility determination count information stored in the control command verification result DB 107. Examples of instructions represented by the instruction information include an instruction to store, update, or delete the control command definition information, an instruction to store, update, or delete the improper operation criterion information, an instruction to store, update, or delete the fault definition information, and an instruction to reset the counters. Details of the control command information, the control command definition information, the improper operation criterion information, the fault definition information, and the control command execution feasibility determination count information will be described later.

[0028] The control command verification unit 102 verifies the risk level of the control command based on the control command information included in the control command verification request and the control command definition information stored in the control command definition information storage unit 106. The control command verification unit 102 also stores control command verification result information indicating the verification result in the control command verification result DB 107, and updates a counter included in the control command execution feasibility determination count information stored in the control command verification result DB 107 according to the risk level. Details of the control command verification result information will be described later.

[0029] The plant operational status verification unit 103 verifies, based on the process data, whether the plant is operating normally or whether there are any abnormal signs, as the operational status of the plant. The plant operational status verification unit 103 stores plant operational status verification result information representing the verification results in a plant operational status verification result DB 108. The plant operational status verification unit 103 may verify the operational status of the plant using a known anomaly diagnosis or anomaly detection technique capable of diagnosing or detecting anomaly signs. Examples of known anomaly diagnosis or anomaly detection techniques capable of diagnosing or detecting anomaly signs include an anomaly diagnosis or anomaly detection technique using multivariate statistical process control (MSPC) and an anomaly diagnosis or anomaly detection technique using machine learning. The plant operational status verification result information will be described in detail later.

[0030] The incident determination unit 104 determines the cause of the incident based on the control command verification result information and the control command execution feasibility determination count information stored in the control command verification result DB 107, the plant operation status verification result information stored in the plant operation status verification result DB 108, the improper operation criteria information stored in the improper operation criteria information storage unit 109, and the fault definition information stored in the fault definition information storage unit 110. In other words, the incident determination unit 104 determines whether the cause of the incident is a "failure" representing a malfunction of equipment or the like, or an "attack" representing a cyberattack.

[0031] The output unit 105 transmits notification information including the determination result by the incident determination unit 104 to the operator terminal 40. This enables the operator terminal 40 to display a screen (such as a security monitoring screen described later) including the determination result by the incident determination unit 104 on a display or the like.

[0032] The control command definition information storage unit 106 stores, for each control command type, control command definition information that indicates the definition of the control command.

[0033] The control command verification result DB 107 stores control command verification result information indicating the verification result for each control command. The control command verification result DB 107 also stores information on the number of control command execution feasibility determinations including a counter for each risk level of each control command type.

[0034] The plant operation status verification result DB 108 stores plant operation status verification result information that indicates the verification results of the plant operation status.

[0035] The unauthorized operation criteria information storage unit 109 stores unauthorized operation criteria information that indicates criteria for determining an unauthorized control command (in other words, criteria for determining that an operation using a certain control command is an unauthorized operation).

[0036] The fault definition information storage unit 110 stores fault definition information that defines a plant fault for each fault cause.

[0037] <<Control command information>> An example of the control command information will be described with reference to Fig. 4. Fig. 4 is a diagram showing an example of the control command information.

[0038] As shown in FIG. 4, the control command information includes a control command type, a source IP address, and parameter information. The control command type is information indicating the type of the control command. The source IP address is the IP address of the source of the control command. The parameter information is information related to the parameters of the control command. The parameter information includes, for example, a parameter number indicating the number of the parameter, and a parameter setting value indicating the setting value of the parameter for that parameter number. The parameter setting value may be a numerical value, a character string, or other information.

[0039] <<Control command definition information>> An example of the control command definition information will be described with reference to Fig. 5. Fig. 5 is a diagram showing an example of the control command definition information.

[0040] As shown in Fig. 5, the control command definition information includes a control command type, whether the control command is executable, and a control command executable condition. The control command type is information that indicates the type of control command. The control command executable condition is information that indicates whether the control command is executable ("executable" or "not executable"). The control command executable condition is information that indicates the executable condition of the control command. However, the control command executable condition is optional information, and the control command executable condition does not have to be included in the control command definition information.

[0041] The control command executable conditions include, for example, one or more of an execution timing condition, an execution source condition, a frequency condition, a process data condition, a parameter condition, etc. The execution timing condition is a condition related to the time, time period (e.g., AM, PM, all day, etc.), day of the week, and day type (e.g., weekday, weekend, public holiday, holiday, etc.) when the control command can be executed. The execution source condition is a condition related to the IP address of the sender that can execute the control command. The frequency condition is a condition related to the cycle (e.g., regular cycle, irregular cycle) when the control command can be executed, the elapsed time since the control command was last executed, the number of times the control command can be executed consecutively, etc. The process data condition is a condition related to the process variable value that can execute the control command (e.g., a condition that represents a range of a certain process variable value, a condition that represents a trend of a certain process variable value, etc.). The parameter condition is a condition related to the parameter number and parameter setting value that can execute the control command (e.g., a condition that represents a parameter number and a range of parameter setting values ​​for that parameter number, etc.). The control command executable conditions may include, instead of or in addition to the executable conditions, an executable condition that indicates a condition under which the control command cannot be executed.

[0042] <<Control command verification result information and control command execution determination count information>> An example of the control command verification result information and the information on the number of times of control command executability determination will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the control command verification result information and the information on the number of times of control command executability determination.

[0043] As shown in FIG. 6(A), the control command verification result information includes control command information, verification time, and danger level. The control command information is the control command information of the control command that was the subject of verification by the control command verification unit 102. The verification time is the time when the verification was performed. The danger level is information that indicates the risk that represents the result of the verification. As an example, the danger level is expressed in three levels: "normal," "caution," and "warning." When the danger level is "normal" or "caution," the control command can be executed, but when the danger level is "warning," the control command cannot be executed.

[0044] As shown in FIG. 6(B), the control command execution determination count information includes a control command type, a normal determination count counter, a caution determination count counter, and a warning determination count counter. The control command type is information that indicates the type of control command. The normal determination count counter is the number of times the danger level for a control command of that type has been determined to be "normal." The caution determination count counter is the number of times the danger level for a control command of that type has been determined to be "caution." The warning determination count counter is the number of times the danger level for a control command of that type has been determined to be "warning." The normal determination count counter, caution determination count counter, and warning determination count counter for each control command type are reset by the external input / output unit 101 in accordance with instruction information received from the operator terminal 40.

[0045] <Information on the standards for unauthorized operations> An example of the improper operation criteria information will be described with reference to Fig. 7. Fig. 7 is a diagram showing an example of the improper operation criteria information.

[0046] As shown in FIG. 7, the unauthorized operation criteria information includes a threshold for each control command type, a threshold for the sum of the caution determination counters, and a threshold for the sum of the warning determination counters. The threshold for each control command type is a threshold for the counter for each control command type. The threshold for each control command type includes, for example, a threshold for the caution determination count counter for that control command type and a threshold for the warning determination count counter for that control command type. On the other hand, the threshold for the sum of the caution determination counters is a threshold for the sum of the caution determination count counters for all control command types. Similarly, the threshold for the sum of the warning determination counters is a threshold for the sum of the warning determination count counters for all control command types. Note that if the caution determination count counter or its sum, or the warning determination counter or its sum, exceeds the threshold included in the unauthorized operation criteria information, the type of incident is determined to be "attack."

[0047] For simplicity, the threshold for the warning determination count counter will be referred to as the "warning threshold," the threshold for the warning determination count counter will be referred to as the "warning threshold," the threshold for the total of the warning determination counter will be referred to as the "warning total threshold," and the threshold for the total of the warning determination count counter will be referred to as the "warning total threshold."

[0048] <<Information on plant operation status verification results>> An example of the plant operational status verification result information will be described with reference to Fig. 8. Fig. 8 is a diagram showing an example of the plant operational status verification result information.

[0049] As shown in FIG. 8, the plant operational status verification result information includes measurement results, analysis results, and diagnosis results.

[0050] The measurement results include information about the process data used to verify the plant operation status, such as the collection date and time of the process data, the names of each process variable included in the process data, and the process variable values ​​of the process variables.

[0051] The analysis results include the results of analyzing process data using anomaly diagnosis or anomaly detection technology and information used in the analysis (e.g., thresholds, etc.). For example, when the operating status of a plant is verified using anomaly diagnosis or anomaly detection technology that uses multivariate statistical process control, the analysis results include the analysis date and time indicating the date and time when the anomaly diagnosis or anomaly detection was performed, the Q value, the T2 value, the Q value contribution of each process variable, the T2 value contribution of each process variable, the Q threshold indicating the threshold for the Q value, and the T2 threshold indicating the threshold for the T2 value.

[0052] The diagnosis result includes information indicating the diagnosis or detection result by the anomaly diagnosis or anomaly detection technology. For example, when the operating status of a plant is verified by an anomaly diagnosis or anomaly detection technology using multivariate statistical process management, the diagnosis result includes identification information of the main plant machinery 30 that was diagnosed, a diagnosis period that indicates the collection period of the process data analyzed by the anomaly diagnosis or anomaly detection technology, and a quality that indicates either "normal" or "signs of anomaly present." Note that the identification information of the main plant machinery 30 is included, for example, in the process data analyzed by the anomaly diagnosis or anomaly detection technology.

[0053] ≪Fault definition information≫ An example of the failure definition information will be described with reference to Fig. 9. Fig. 9 is a diagram showing an example of the failure definition information.

[0054] As shown in FIG. 9, the fault definition information includes the fault cause, the process state, and the number of past fault occurrences. The process state also includes the process variable name and its state. In the example shown in FIG. 9, the fault cause is "air leak due to damage to pipe A," the process variable names are "motor A rotation speed" and "pipe A pressure," the state corresponding to the process variable name "motor A rotation speed" is set to "high," the state corresponding to the process variable name is set to "decreased," and the number of past fault occurrences is set to "2." This indicates that when the motor A rotation speed increases and the pressure in pipe A is high, a sign of a fault caused by air leak due to damage to pipe A is estimated, and such a fault has occurred twice in the past.

[0055] This makes it possible to determine whether the incident cause is a "failure" and whether the failure is a defined failure that has occurred in the past, or an undefined failure. The failure definition information represents the relationship between the failure cause of a failure that has occurred in the past and the process variables at that time, and is created and stored, for example, by an experienced operator or a person who is familiar with the relationship between the process state and failures.

[0056] <Control command verification process> An example of the control command verification process will be described with reference to Fig. 10. Fig. 10 is a flowchart showing an example of the control command verification process. The control command verification process shown in Fig. 10 is executed every time a control command verification request is transmitted from the on-site plant control device 70.

[0057] The external input / output unit 101 receives a control command verification request transmitted from the on-site plant control device 70 (step S101).

[0058] The control command verification unit 102 identifies, from the control command definition information stored in the control command definition information storage unit 106, control command definition information that includes the same control command type as the control command type of the control command information included in the control command verification request received in the above step S101 (step S102).

[0059] The control command verification unit 102 determines whether the control command executable information of the control command definition information identified in the above step S102 is information indicating "executable" (step S103).

[0060] If it is determined in step S103 above that the information indicates "executable," the control command verification unit 102 refers to the control command executable conditions of the control command definition information identified in step S102 above, and determines whether the execution timing condition, the execution source condition, and the parameter condition are satisfied (step S104). That is, the control command verification unit 102 determines whether the reception date and time of the control command verification request satisfies the execution timing condition, whether the source IP address of the control command information included in the control command verification request satisfies the execution source condition, and whether the parameter information of the control command information satisfies the parameter condition.

[0061] If it is not determined in the above step S103 that the information represents "executable" (that is, if the information represents "unexecutable"), or if it is not determined in the above step S104 that the execution timing condition, the execution source condition, and the parameter condition are satisfied, the control command verification unit 102 stores control command verification result information including the control command information, the verification time, and the danger level "warning" in the control command verification result DB 107 (step S105). That is, the control command verification unit 102 stores in the control command verification result DB 107 the control command information included in the control command verification request received in the above step S101, the verification time representing the current date and time, and the danger level "warning".

[0062] On the other hand, if it is determined in step S104 that the execution timing condition, the execution source condition, and the parameter condition are satisfied, the control command verifier 102 determines whether the process data condition and the frequency condition are satisfied (step S106). That is, the control command verifier 102 determines whether the latest process data received from the on-site plant control device 70 satisfies the process data condition and whether the control command represented by the control command information satisfies the frequency condition.

[0063] If it is determined in the above step S106 that the process data condition and the frequency condition are not satisfied, the control command verification unit 102 stores the control command verification result information including the control command information, the verification time, and the danger level "Caution" in the control command verification result DB 107 (step S107).

[0064] Following step S105 or step S107 above, the external input / output unit 101 sends an email indicating that a control command with a danger level of "warning" or "caution" has been issued to the operator terminal 40 (step S108). This notifies the operator that a control command with a danger level of "warning" or "caution" has been issued.

[0065] If it is determined in step S106 above that the process data conditions and frequency conditions are met, the control command verification unit 102 stores the control command verification result information, which includes the control command information, the verification time, and the risk level "normal," in the control command verification result DB 107 (step S109).

[0066] The control command verification unit 102 updates the counter of the control command execution possibility determination count information stored in the control command verification result DB 107 according to the risk level of the control command (step S110). That is, when the control command verification result information including the risk level "normal" is stored in the above step S109, the control command verification unit 102 increments by 1 the normal determination count counter of the same control command type as the control command type included in the control command execution possibility determination count information, among the normal determination count counters included in the control command execution possibility determination count information. Similarly, when the control command verification result information including the risk level "caution" is stored in the above step S107, the control command verification unit 102 increments by 1 the caution determination count counter of the same control command type as the control command type included in the control command execution possibility determination count information. Similarly, when control command verification result information containing a danger level of "warning" is stored in step S105 above, the control command verification unit 102 adds 1 to the warning determination count counter of the same control command type as the control command type contained in the control command execution feasibility determination count information.

[0067] The external input / output unit 101 transmits the control command verification result represented by the control command verification result information stored in the above step S105, step S107, or step S109 to the on-site plant control device 70 (step S111). This allows the on-site plant control device 70 to execute a control command whose danger level is determined to be "normal" or "caution" and to stop the execution of a control command whose danger level is determined to be "warning," for example.

[0068] <Plant operation status verification process> An example of the plant operation status verification process will be described with reference to Fig. 11. Fig. 11 is a flowchart showing an example of the plant operation status verification process. The plant operation status verification process shown in Fig. 11 is executed every time process data is transmitted from the on-site plant control device 70. Note that the process data is transmitted from the on-site plant control device 70 to the security monitoring device 10, for example, at each measurement period (sampling period) of the process variable values. In the following, as an example, it is assumed that the plant operation status is verified by an anomaly diagnosis or anomaly detection technique using multivariate statistical process management.

[0069] The external input / output unit 101 receives the process data transmitted from the on-site plant control device 70 (step S201).

[0070] The plant operational status verification unit 103 verifies the operational status of the plant using an anomaly diagnosis or anomaly detection technique that utilizes multivariate statistical process management based on the process data received in step S201 (step S202). In the anomaly diagnosis or anomaly detection technique that utilizes multivariate statistical process management, the Q-value contribution of each process variable and its integrated value (Q-value), and the T2-value contribution of each process variable and its integrated value (T2-value) are calculated, and the Q-value and the T2-value are compared with the Q-threshold and the T2-threshold, respectively. Note that, for example, if the Q-value exceeds the Q-threshold or the T2-value exceeds the T2-threshold, or both, the quality is diagnosed as "signs of anomaly"; otherwise, the quality is diagnosed as "normal."

[0071] The plant operational status verification unit 103 stores the plant operational status verification result information in the plant operational status verification result DB 108 (step S203). That is, the plant operational status verification unit 103 stores the plant operational status verification result information, which includes the measurement results related to the process data received in the above step S201, the analysis results based on the anomaly diagnosis or anomaly detection technology in the above step S202, and the diagnosis results using the analysis results, in the plant operational status verification result DB 108.

[0072] <Incident determination process> An example of the incident determination process will be described with reference to Fig. 12. Fig. 12 is a flowchart showing an example of the incident determination process. The incident determination process shown in Fig. 12 is executed, for example, every time step S203 in Fig. 11 is executed.

[0073] The incident determination unit 104 acquires quality from the diagnosis result included in the plant operational status verification result information stored in step S203 of FIG. 11 (step S301).

[0074] The incident determination unit 104 determines whether the quality acquired in the above step S301 is "signs of abnormality present" (step S302).

[0075] If the quality is not determined to be "signs of abnormality present" in step S302 (that is, if the quality is "normal"), the incident determination unit 104 ends the incident determination process because it is considered that no incident will occur in this case.

[0076] On the other hand, if the quality is determined to be "signs of abnormality present" in the above step S302 (that is, if an incident occurs), the incident determination unit 104 compares the counter included in the control command execution possibility determination count information stored in the control command verification result DB 107 with the threshold value included in the improper operation criteria information stored in the improper operation criteria information storage unit 109 (step S303). Specifically, the incident determination unit 104 performs the comparisons shown in the following (a) to (d).

[0077] (a) For each control command type, a comparison between the attention determination count counter for that control command type and the attention threshold for that control command type. (b) For each control command type, a comparison between the warning determination count counter for that control command type and the warning threshold value for that control command type. (c) Comparing the total of the warning determination count counters for each control command type with the warning total threshold value (d) Comparing the total of the warning determination counters for each control command type with the total warning threshold The incident determination unit 104 determines whether any of the thresholds is exceeded using the comparison results shown in (a) to (d) above (step S304). That is, the incident determination unit 104 determines whether or not there is a caution determination number counter that exceeds the caution threshold for at least one control command type, whether or not there is a warning determination number counter that exceeds the warning threshold for at least one control command type, whether or not the total of the caution determination number counters exceeds the caution total threshold, and whether or not the total of the warning determination number counters exceeds the warning total threshold.

[0078] If it is determined in step S304 above that there is no value exceeding the threshold, the incident determination unit 104 determines that the cause of the incident is a "failure" (step S305).

[0079] Following step S305, the incident determination unit 104 acquires the names and values ​​of each process variable from the measurement results included in the plant operational status verification result information stored in step S203 of FIG. 11 (step S306).

[0080] The incident determination unit 104 uses each process variable name and its process variable value acquired in the above step S306 to determine whether or not fault definition information matching the process state is present in the fault definition information storage unit 110 (step S307). That is, the incident determination unit 104 determines whether or not there is a process variable name defined in the process state and a process variable value that satisfies that state among each process variable name and its process variable value acquired in the above step S306.

[0081] If it is determined in step S307 above that the fault definition information storage unit 110 does not contain fault definition information that matches the process state, the output unit 105 transmits notification information including information indicating that the fault is undefined and the incident cause "fault" to the operator terminal 40 (step S308). This makes it possible to notify the operator that there is a symptom of an undefined fault.

[0082] On the other hand, if it is determined in step S307 above that the fault definition information storage unit 110 contains fault definition information that matches the process state, the output unit 105 transmits notification information including the fault cause of that fault definition information, the incident cause "fault", and the failure rate to the operator terminal 40 (step S309). Here, the failure rate can be calculated, for example, by the number of past fault occurrences of that fault definition information + 1 / number of incident occurrences × 100. This makes it possible to notify the operator that there is a sign of a fault due to that fault cause.

[0083] If it is determined in step S304 above that any of the threshold values ​​is exceeded, the incident determination unit 104 determines that the cause of the incident is "attack" (step S310). In this case, many control commands with alert levels of "Caution" or "Warning" have been issued, and it is highly likely that unauthorized operations are being performed from outside.

[0084] Following step S310, the output unit 105 transmits notification information including the incident cause "attack" to the operator terminal 40 (step S311). This notifies the operator that there is a high possibility that a cyber-attack is being carried out.

[0085] The notification information may include information on the number of times control command execution is determined, information on the criteria for unauthorized operation, etc. Hereinafter, it is assumed that the notification information includes at least information on the number of times control command execution is determined.

[0086] <Security monitoring screen> An example of a security monitoring screen displayed on the display of the operator terminal 40 will be described below with reference to Fig. 13. Fig. 13 is a diagram showing an example of the security monitoring screen.

[0087] As shown in FIG. 13, the security monitoring screen 1000 includes a control command operation status display field 1100 and a plant operation status display field 1200.

[0088] The control command operation status display field 1100 includes a first counter display field 1110 that displays the normal judgment count counter for each control command type, a second counter display field 1120 that displays the caution judgment count counter for each control command type and its caution threshold, and a third counter display field 1130 that displays the warning judgment count counter for each control command type and its warning value. A broken line 1121 displayed in the second counter display field 1120 represents the caution threshold, and a broken line 1131 displayed in the third counter display field 1130 represents the warning threshold. Note that "Command A" to "Command C" represent the control command types.

[0089] The control command operation status display field 1100 also includes a tampering standard setting button 1140 for setting or changing the caution threshold and warning threshold as well as the total caution threshold and total warning threshold for each control command type, and a reset button 1150 for resetting the values ​​of the normal judgment number counter, the caution judgment number counter, and the warning judgment number counter for each control command type. This allows the operator to set or change the value of each threshold, or reset the value of each counter. When the tampering standard setting button 1140 or the reset button 1150 is pressed, instruction information is sent from the operator terminal 40 to the security monitoring device 10.

[0090] The plant operation status display field 1200 includes an abnormal sign presence / absence display field 1210 that displays the presence or absence of abnormal signs, an incident cause display field 1220 that displays the cause of the incident, a failure cause display field 1230 that displays the cause of the failure, and a failure rate display field 1240 that displays the failure rate. The abnormal sign presence / absence display field 1210 displays "Present" when notification information is received, and displays "Not Present" when, for example, notification information has not been received for a certain period of time. The incident cause display field 1220 also displays the cause of the incident included in the notification information. Furthermore, if the failure cause and failure rate are included in the notification information, the failure cause and failure rate are displayed in the failure cause display field 1230 and the failure rate display field 1240, respectively. The plant operation status display field 1200 may also include a history display / incident occurrence count registration button 1250 for displaying past incident history and registering the number of incident occurrences.

[0091] In addition to the control command operation status display field 1100 and the plant operation status display field 1200, the security monitoring screen 1000 may include buttons for manually controlling the execution of control commands that have not yet been executed. Specifically, the screen may include a control command execution stop button 1310 for stopping the execution of a control command that has not yet been executed, and a control command execution start button 1320 for starting the execution of a control command that has not yet been executed. This allows, for example, an operator to stop the execution of a control command that has been fraudulently issued due to a cyber-attack.

[0092] By referring to the security monitoring screen 1000 shown in Fig. 13, operators can know the operation status of control commands and the operating status of the plant. Furthermore, if there are signs of abnormality in the plant, they can know whether the signs of abnormality are due to a malfunction or a cyber-attack. This makes it possible to know whether the cause of an incident is a cyber-attack before an actual incident occurs. Furthermore, it is also possible to stop or start the execution of control commands that have not yet been executed.

[0093] <Summary> As described above, the security monitoring system 1 according to this embodiment can determine whether an incident is caused by a cyber-attack before the incident actually occurs. Therefore, it becomes possible to take appropriate measures against a cyber-attack before the incident actually occurs due to the cyber-attack.

[0094] The present invention is not limited to the above-described specifically disclosed embodiments, and various modifications, changes, and combinations with known technologies are possible without departing from the scope of the claims. [Explanation of symbols]

[0095] 1. Security monitoring system 10. Security monitoring equipment 11 Input Devices 12 Display device 13 External I / F 13a Recording media 14 Communication I / F 15 RAM 16 ROM 17 Auxiliary storage 18 processors 19 Bus 20 Control System 30 Plant main engine 40 Operator terminal 50 Control Server 60 Plant control device 70 On-site plant control device 101 External input / output section 102 Control command verification unit 103 Plant Operation Status Verification Department 104 Incident Determination Department 105 Output section 106 Control command definition information storage unit 107 Control command verification result DB 108 Plant operation status verification result DB 109 Improper Operation Standard Information Memory Department 110 Fault Definition Information Memory Department

Claims

1. a first verification unit that verifies the risk of a control command based on definition information of the control command for a control target; a second verification unit that verifies a symptom of an incident in the control target based on data collected from the control target; a determination unit that, when it is verified that there is a symptom of an incident in the control target, determines whether the cause of the incident is an external attack based on the number of control commands issued that is equal to or greater than a predetermined risk; A security monitoring device having:

2. The security monitoring device according to claim 1 , further comprising an output unit that transmits a notification including a result of the determination made by the determination unit to a terminal of an operator who operates the controlled object.

3. The risk of the control command is classified into warning, caution, and normal in order of increasing risk, The first verification unit Verifying whether the risk of the control command is classified as a warning, a caution, or a normal state; The determination unit 3. The security monitoring device according to claim 1, wherein the security monitoring device determines whether the incident is caused by an external attack based on the number of times that a control command with a risk of caution or higher is issued.

4. The determination unit A security monitoring device as described in claim 3, which determines that the cause of the incident is due to an external attack if the number of times a control command indicating a caution regarding the risk is issued exceeds a first threshold, or if the number of times a control command indicating a warning regarding the risk is issued exceeds a second threshold.

5. There are multiple types of the control command, The determination unit When the number of times that a control command indicating caution regarding risk has been issued for at least one or more types of control commands exceeds a first threshold value, If the number of times that a control command indicating a risk warning has been issued for at least one or more types of control commands exceeds a second threshold value, If the total number of times that a control command for caution has been issued for all types of risk exceeds a third threshold, If the total number of times that a control command for issuing a warning about the risk has been issued for all types of the risk exceeds a fourth threshold value, The security monitoring device according to claim 4 , wherein the cause of the incident is determined to be an external attack.

6. The determination unit If it is determined that the cause of the incident is not due to an external attack, it is determined that the cause of the incident is a malfunction; 2. The security monitoring device according to claim 1, wherein the cause of the failure is determined based on definition information that defines past failures and data collected from the control target.

7. a first verification step of verifying the risk of a control command based on definition information of the control command for a control target; a second verification step of verifying an indication of an incident of the control object based on data collected from the control object; a determination procedure for determining whether the cause of the incident is an external attack based on the number of control commands issued that are greater than or equal to a predetermined risk, when it is verified that the control target has a symptom of an incident; A security monitoring method that a computer performs.

8. a first verification step of verifying the risk of a control command based on definition information of the control command for a control target; a second verification step of verifying an indication of an incident of the control object based on data collected from the control object; a determination procedure for determining whether the cause of the incident is an external attack based on the number of control commands issued that are greater than or equal to a predetermined risk, when it is verified that the control target has a symptom of an incident; A program that causes a computer to execute the following.

Citation Information

Patent Citations

  • Security monitoring system and security monitoring method

    JP2021111003A