Incident monitoring support server, integrated control system, incident monitoring support method, and incident monitoring support program

The incident monitoring support server provides centralized monitoring and response to industrial control systems by updating and transmitting evaluation indices, addressing the challenges of delayed response and overlooked incidents in existing systems.

JP2026011114APending Publication Date: 2026-01-23MITSUBISHI HEAVY IND LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024111444
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-11
Publication Date
2026-01-23

AI Technical Summary

Technical Problem

Existing incident monitoring systems in industrial control systems, such as SIEM, require specialized knowledge to understand the status of detected incidents, leading to delayed responses, and lack continuous monitoring, risking overlook of high-severity incidents amidst numerous minor ones.

Method used

An incident monitoring support server that includes an incident detection unit, a table information storage unit, and a transmission unit to provide centralized monitoring by updating and transmitting evaluation indices to a management unit, enabling accurate and timely incident recognition and response.

Benefits of technology

Enables centralized and accurate monitoring of incidents in industrial control systems, allowing for rapid response and reducing the risk of overlooking high-severity incidents by providing comprehensive and standardized incident information to operators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026011114000001_ABST
    Figure 2026011114000001_ABST
Patent Text Reader

Abstract

To monitor an incident occurring in a control system in a management unit of the control system together with conventional management processing in an integrated manner with high accuracy.SOLUTION: An incident monitoring support server includes an incident detection signal acquisition part, a table information storage part, a table information update part, and a table information transmission part. The incident detection signal acquisition unit acquires an incident detection signal corresponding to an incident detected based on a log collected by the control system. The table information storage unit stores table information that defines an evaluation index for each piece of identification information for identifying an incident. The table information updating unit updates the table information based on the incident detection signal. The table information transmission unit transmits the table information stored in the table information storage unit to the management unit as incident information that can be handled by the management unit for managing the control system.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an incident monitoring support server, an integrated control system, an incident monitoring support method, and an incident monitoring support program. [Background technology]

[0002] For systems connected to communication networks, such as business systems such as business PCs used by companies, security measures against cyber attacks are becoming increasingly important. SIEM (Security Information and Event Management) is known as a technology for monitoring such cyber attacks as incidents. SIEM comprehensively monitors incidents in systems by collecting logs from the various components of the systems being monitored and combining the collected data for correlation analysis.

[0003] In recent years, industrial control systems (ICS) that support infrastructures such as oil, gas, electricity, and manufacturing have also become connected to external networks, increasing the importance of security measures against cyberattacks. Distributed control systems (DCSs) are known as a type of industrial control system that controls plants, such as power plants and manufacturing plants, through mutual communication between multiple control devices. A DCS connects to multiple field devices installed in the plant via a control network and controls and monitors them (see, for example, Patent Documents 1 and 2). Each control device in the distributed control system is connected to a human-machine interface (HMI) or other device for operating and monitoring the plant via a control information network built using Ethernet (registered trademark) or other technology. The control devices control each field device based on commands sent from an external computer, such as an HMI. Cyberattacks against industrial control systems equipped with such DCSs can include, for example, denial-of-service (DoS) attacks, as well as attacks commonly used in information systems, such as spoofing, eavesdropping, and falsification.

[0004] Incident monitoring technologies such as the aforementioned SIEM have traditionally been widely adopted for the aforementioned business systems, but given this technological background, they are also being introduced into industrial control systems. For example, Patent Document 3 discloses a control device and control system that can monitor abnormalities by notifying a predetermined notification destination when an abnormality is detected. Furthermore, Patent Document 4 discloses a system that, when a malicious program incident is detected in a device that is not constantly monitored by a user, issues a warning message or a buzzer to a device that is constantly monitored by an operator, thereby preventing humans from noticing the incident. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2011-221846 [Patent Document 2] Japanese Patent Application Laid-Open No. 2012-226680 [Patent Document 3] Patent No. 6977507 [Patent Document 4] Patent No. 6163793 Summary of the Invention [Problem to be solved by the invention]

[0006] With incident monitoring technologies such as the aforementioned SIEM, when an incident is detected, a warning based on analysis functions is displayed on the screen of a dedicated monitoring monitor terminal. While this warning display makes it easy to recognize that some kind of incident has been detected, understanding the status of the control system in which the incident was detected requires specialized knowledge, such as analyzing the monitoring results. As a result, it takes time to understand the status of the control system, which can delay response to the incident.

[0007] Furthermore, because incident monitoring monitor terminals are generally not equipped with a continuous monitoring system, even if a warning is displayed, there is a risk that the situation of the incident may not be grasped promptly, for example, during times when the operator is not present. Some SIEMs are known to have a function for notifying pre-registered notification destinations, for example, by email, when an incident such as an abnormality is detected, as in Patent Document 1 above, but the content of the notification is brief, so it may take time for the person in charge who receives the notification to grasp the situation of the incident.

[0008] On the other hand, industrial control systems such as those for plant facilities are equipped with a management unit (for example, a central control room in a power plant) for managing the components of the control system, and such management units often manage the control system 24 hours a day. For this reason, it is desirable to centrally monitor incidents in the management unit so that the situation can be grasped and a response can be made quickly when an incident occurs.

[0009] To address this issue, Patent Document 4 discloses a system in which an incident occurs and is notified to a device that is constantly monitored by an operator. In this document, a notification is sent to the device that is constantly monitored each time an incident is detected, regardless of the severity of the incident. Therefore, for example, if a large number of incidents are detected and many of the detected incidents are relatively minor, there is a risk that incidents of high severity will be buried and overlooked by the operator.

[0010] At least one embodiment of the present disclosure has been made in consideration of the above-mentioned circumstances, and aims to provide an incident monitoring support server, an integrated control system, an incident monitoring support method, and an incident monitoring support program that can monitor incidents that occur in a control system in a centralized and accurate manner in a management unit of the control system, together with conventional management processing. [Means for solving the problem]

[0011] In order to solve the above problem, an incident monitoring support server according to at least one embodiment of the present disclosure includes: an incident detection signal acquisition unit for acquiring an incident detection signal corresponding to an incident detected based on a log collected by the control system; a table information storage unit that stores table information that defines an evaluation index for each piece of identification information for identifying the incident; a table information update unit that updates the table information based on the incident detection signal; a table information transmitting unit for transmitting the table information stored in the table information storage unit to a management unit for managing the control system as incident information that can be handled by the management unit; Equipped with.

[0012] In order to solve the above problem, an integrated control system according to at least one embodiment of the present disclosure includes: An incident monitoring support server according to at least one embodiment of the present disclosure; the control system; Equipped with The management unit has a display unit that displays the operating status of multiple constituent devices of the control system in a manner that allows the incident to be distinguished, based on the table information received from the table information transmission unit.

[0013] In order to solve the above problem, an incident monitoring support method according to at least one embodiment of the present disclosure includes: obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information that defines an evaluation index for each piece of identification information for identifying the incident stored in a table information storage unit based on the incident detection signal; transmitting the table information to a management unit for managing the control system as incident information that can be handled by the management unit; Equipped with.

[0014] In order to solve the above problem, an incident monitoring support program according to at least one embodiment of the present disclosure includes: Using a computer, obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information that defines an evaluation index for each piece of identification information for identifying the incident stored in a table information storage unit based on the incident detection signal; transmitting the table information to a management unit for managing the control system as incident information that can be handled by the management unit; is possible. [Effects of the Invention]

[0015] According to at least one embodiment of the present disclosure, it is possible to provide an incident monitoring support server, an integrated control system, an incident monitoring support method, and an incident monitoring support program that can centrally and accurately monitor incidents that occur in a control system in a management unit of the control system, together with conventional management processing. [Brief explanation of the drawings]

[0016] [Figure 1] 1 is an overall configuration diagram illustrating an integrated control system according to an embodiment. [Figure 2] 2 is a block diagram showing the internal configuration of the incident monitoring support server of FIG. 1. FIG. [Figure 3] 3 is a diagram showing table information stored in a table information storage unit of FIG. 2. FIG. [Figure 4] 1 is a flowchart illustrating an incident monitoring support method according to an embodiment. [Figure 5] FIG. 10 is a diagram showing an example of a display on a display unit of an OPS. [Figure 6] 10 is a flowchart showing a procedure for isolating a component device. [Figure 7] FIG. 2 is a schematic diagram illustrating a communication state between an OPS and a management terminal and a client terminal. DETAILED DESCRIPTION OF THE INVENTION

[0017] Hereinafter, several embodiments of the present invention will be described with reference to the accompanying drawings. However, the configurations described as the embodiments or shown in the drawings are merely illustrative examples and are not intended to limit the scope of the present invention.

[0018] 1 is a diagram illustrating the overall configuration of an integrated control system 1 according to one embodiment. The integrated control system 1 is an industrial control system that supports infrastructure for, for example, oil, gas, electricity, manufacturing, etc. The integrated control system 1 mainly includes a control system 2 for controlling a control target, and an incident monitoring support server 4 for monitoring incidents in the control system 2.

[0019] The control system 2 is a system for controlling plant equipment constituting an infrastructure as a control target. It includes a distributed control device 8 composed of multiple control devices 6 that automatically control the plant equipment and perform input / output processing with the site while communicating with each other. For example, the components of the control system 2 include a central processing unit (CPU), random access memory (RAM), read-only memory (ROM), and computer-readable storage media. The processes for implementing various functions are stored in storage media, for example, in the form of programs. The CPU reads these programs into RAM and executes information processing and arithmetic operations to realize various functions. The programs may be pre-installed in a ROM or other storage media, provided in a computer-readable storage medium, or distributed via wired or wireless communication. Examples of computer-readable storage media include magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, and semiconductor memories. In the following, an example will be described in which the control system 2 is configured to include a distributed control device 8, but the present invention is not limited to this.

[0020] Each control device 6 constituting the distributed control device 8 is connected via a control network N1 to an input / output module (IOM 12) connected to field devices 10 installed in the plant facility. Instead of the IOM 12, each control device 6 may be connected to a programmable logic controller (PLC) that controls the field devices 10. The field devices 10 include various sensors that measure temperature, flow rate, pressure, etc., and control elements such as valves (control valves, etc.). The control network N1 is a communication network that connects such field devices 10 and the control device 6. Each control device 6 collects plant data such as measurement data and event data obtained from the field devices 10, performs various calculations using the collected plant data, and transmits the calculation results to the IOM 12, etc., thereby automatically controlling the plant facility.

[0021] As shown in FIG. 1 , each control device 6 is connected to a control information network N2 constructed using, for example, Ethernet. The control information network N2 is a communication network, such as an IP network, that connects the control devices 6 to computers for controlling, monitoring, and managing the plant equipment, and is connected to an external network (not shown), such as an in-house LAN or the Internet. For example, the control information network N2 is connected to an operator station (OPS 16) that serves as a human-machine interface (HMI) for operating and monitoring the plant equipment, an EMS 17 that manages the control logic in the control system 2, and an Accessory Station (ACS) 18 that stores and manages large volumes of plant data. When the control device 6 receives commands for the plant equipment transmitted from the OPS 16 or a remote OPS (not shown) connected to the Internet via the control information network N2, the control device 6 executes the commands and returns responses.

[0022] The OPS 16 of the control system 2 is located, for example, in a central control room of the plant facility where an operator is stationed. The OPS 16 has a display unit 16a that can monitor the control status of the control target by the control system 2, and functions as a management unit that allows the operator to manage the control system 2. The display unit 16a displays various control parameters of the control system 2 and various data collected from the field devices 10, allowing the operator to constantly monitor the control status by the control system 2. In this embodiment, in addition to these typical control parameters and various data on the control system 2 side, the display unit 16a displays a warning in accordance with the occurrence status of an incident based on table information received from the incident monitoring support server 4, which will be described later, thereby enabling centralized incident monitoring on the control system 2 side.

[0023] The incident monitoring support server 4 is configured to support the monitoring of incidents in the control system 2. The incident monitoring support server 4 is connected to the control system 2 via a network N3. The network N3 is a network through which, for example, various computer devices (OPS 16, EMS 17, ACS 18, etc.) provided in the control system 2 are connected to peripheral devices such as printers, and is a network with a lower security priority than the control network N1 and the control information network N2 described above.

[0024] The incident monitoring support server 4 is typically installed in a server room independent of the control system 2, and its processing details can be checked on a monitoring terminal 5 connected via network N3. The incident monitoring support server 4 constantly monitors cyberattacks against the control system 2, but since the operator of the monitoring terminal 5 is not always on duty, even if an incident is detected by the incident monitoring support server 4, for example, outside of the operator's working hours, it may take some time for the operator to recognize the incident. Furthermore, specialized knowledge and experience are required to understand the various data related to incidents displayed on the monitoring terminal 5, and it may also take some time to respond based on the display on the monitoring terminal 5.

[0025] On the other hand, in the control system 2, as described above, a system of constant monitoring by operators is in place in the OPS 16 installed in the central control room, etc. In this embodiment, by transmitting table information corresponding to detected incidents from the incident monitoring support server 4, incident monitoring can be performed centrally on the control system 2 side, which has a system of constant monitoring in place.

[0026] Fig. 2 is a block diagram showing the internal configuration of the incident monitoring support server 4 of Fig. 1. The incident monitoring support server 4 includes an incident detection unit 20, an incident detection signal acquisition unit 22, a table information storage unit 24, a table information update unit 26, and a table information transmission unit 28.

[0027] The incident detection unit 20 is configured to monitor incidents related to cyber attacks such as DoS (Denial of Service) attacks, spoofing, eavesdropping, and tampering, with the control system 2 as the monitoring target. In this embodiment, the incident detection unit 20 employs SIEM (Security Information and Event Management) as the incident detection method. Specifically, the incident detection unit 20 collects logs from various locations in the control system 2 as the monitoring target, and performs correlation analysis by combining the collected data to comprehensively detect incidents therein.

[0028] In this embodiment, the incident detection unit 20 is configured as part of the incident monitoring support server 4, but it may also be configured as an external component of the incident monitoring support server 4.

[0029] The incident detection signal acquisition unit 22 is configured to acquire the incident detection signal output from the incident detection unit 20. The incident detection unit 20 detects an incident as described above and outputs an incident detection signal corresponding to the detection result. By acquiring such an incident detection signal, the incident detection signal acquisition unit 22 can acquire information related to the detected incident.

[0030] The table information storage unit 24 is configured to store table information TI that indicates the occurrence status of incidents in the control system 2 that is the target of incident monitoring. Here, Fig. 3 is a diagram showing the table information TI stored in the table information storage unit of Fig. 2. The table information TI is prepared as a data set that defines an evaluation index for each piece of identification information for identifying an incident, and is readably stored in the table information storage unit 24, which is a memory or the like. Fig. 3 shows an example of table information TI, which includes multiple data sets each consisting of a combination of identification information PID, incident name OID, and evaluation index Value.

[0031] The identification information PID is a management parameter for identifying incidents. In this embodiment, the incident names are assigned in the order of "1," "2," ..., to the incident name OID. The incident name OID is registered in advance for each incident. In this embodiment, the incident name is registered as a name that reflects whether the corresponding evaluation index Value is an analog value or a digital value, but this can be set as appropriate. The evaluation index Value is an index for evaluating the state of the monitoring target. For example, the evaluation index Value may be an index that is counted each time the incident detection signal acquisition unit 22 acquires a corresponding incident detection signal, such as the incident name OID "OID-Analog1" indicated by the identification information PID "1" in FIG. 3, or a binary index indicated by "1" or "0" that corresponds to whether the incident detection signal acquisition unit 22 acquires a corresponding incident detection signal, such as the incident name OID "OID-Digital2" indicated by the identification information PID "2." The table information TI in FIG. 3 also includes a quality item indicating the communication quality for each identification index.

[0032] The table information update unit 26 is configured to update the table information TI stored in the table information storage unit 24. The table information is updated based on an incident detection signal acquired by the incident detection signal acquisition unit 22. For example, when an incident is detected by the incident detection unit 20 and the incident detection signal acquisition unit 22 acquires the incident detection signal, the table information update unit 26 updates the table information TI as a trigger.

[0033] Further, the table information TI is updated by identifying the identification information PID included in the incident detection signal acquired by the incident detection signal acquisition unit 22, and updating the evaluation index Value corresponding to the identification information PID in the table information TI stored in the table information storage unit 24. For example, in the example shown in FIG. 3, when an incident detection signal corresponding to the incident name OID "OID-Analog1" corresponding to the identification information PID of "1" is acquired, the table information update unit 26 updates the value of the evaluation index Value corresponding to the incident information in the table information TI by counting up (incrementing by "+1"). When an incident detection signal corresponding to the incident name OID "OID-Digital2" corresponding to the identification information PID of "2" is acquired, the table information update unit 26 updates the value of the evaluation index Value corresponding to the incident information in the table information TI by switching it from "0" to "1." By updating the table information TI stored in the table information storage unit 24 by the table information update unit 26 in this way, the state corresponding to the incident detected by the incident detection unit 20 is reflected in the table information TI.

[0034] The table information transmission unit 28 is configured to transmit the table information TI stored in the table information storage unit 24 (the table information TI after being updated by the table information update unit 26) to the control system 2. The table information TI is in a form that can be handled by the control system 2. The control system 2 receives the table information TI transmitted from the table information transmission unit 28 and displays a warning based on the table information TI on the OPS 16. In the example shown in FIG. 3 , when the evaluation index Value corresponding to the incident detection signal corresponding to the incident name OID “OID-Analog1” corresponding to the identification information PID “1” is counted up and exceeds a threshold set as a predetermined standard, a warning is displayed indicating that an incident corresponding to the incident detection signal has occurred and various related information is displayed. Furthermore, when the evaluation index Value corresponding to the incident detection signal corresponding to the incident name OID “OID-Digital2” corresponding to the identification information PID “2” is switched from “0” to “1,” a warning is displayed indicating that an incident corresponding to the incident detection signal has occurred and various related information is displayed. As a result, the control system 2 can monitor incidents based on the incident information contained in the received table information TI. That is, OPS 16 enables centralized monitoring of incidents based on table information TI in addition to the conventional function of managing the control system 2.

[0035] The warning displayed by OPS 16 may be displayed according to the importance of the incident identified based on the evaluation index. For example, for an incident corresponding to the incident name OID "OID-Analog1" whose identification information PID is "1" in Fig. 3, as described above, the warning display is triggered when the evaluation index Value, which is counted up each time an incident detection signal corresponding to the incident is acquired, exceeds a predetermined reference value. However, the importance of the incident can be identified by setting multiple reference values ​​according to the importance.

[0036] The table information transmitting unit 28 also includes a request signal transmitting unit 30 for transmitting a request signal together with the table information TI to the control system 2, and a reply signal receiving unit 32 for receiving a reply signal when the table information TI is received by the control system 2. As a result, when the table information transmitting unit 28 transmits the table information TI, a request signal is transmitted together with the table information TI. When the control system 2 receives the table information TI and the request signal, it transmits a reply signal in response to the request signal. By receiving such a reply signal, the incident monitoring support server 4 can confirm that the table information TI has been reliably received by the control system 2, thereby improving the reliability of incident monitoring on the control system 2 side.

[0037] Next, a description will be given of an incident monitoring support method executed by the incident monitoring support server 4. Fig. 4 is a flowchart showing an incident monitoring support method according to an embodiment.

[0038] First, when an incident is detected by the incident detection unit 20, the incident detection signal acquisition unit 22 acquires an incident detection signal from the incident detection unit 20 (step S100). Subsequently, the table information update unit 26 accesses the table information storage unit 24 (step S101) and updates the table information TI stored in the table information storage unit 24 based on the incident detection signal acquired in step S100 (step S102). As described above, the table information storage unit 24 stores table information TI in advance, and acquisition of the incident detection signal from the incident detection unit 20 is used as a trigger to update the table information TI, so that the incident detected in step S100 is reflected in the table information TI stored in the table information storage unit 24.

[0039] Next, the table information transmitting unit 28 reads the interval information (step S103) and also reads the history of past transmissions of the table information TI to the control system 2 (step S104). The interval information and the history of past transmissions are stored in advance in a storage device (not shown), such as a memory. The interval information is information for defining the interval at which the table information TI is transmitted to the control system 2. Based on the transmission history read in step S104, the table information transmitting unit 28 determines whether the interval defined in the interval information read in step S103 has elapsed since the previous transmission time (step S105).

[0040] If the interval has elapsed (step S105: YES), the table information transmission unit 28 reads out the table information TI from the table information storage unit 24 and transmits it to the control system 2 side together with a request signal (step S106). The table information TI transmitted in step S106 is the table information TI after being updated in step S102. As a result, the control system 2 side receives the table information TI transmitted in step S106, and the OPS 16 displays a warning based on the table information TI. As described above, this warning display may include a warning display indicating that the incident has occurred, as well as a display of various information related to the incident (such as the severity level).

[0041] Next, the incident monitoring support server 4 determines whether or not a reply signal has been received from the control system 2 (step S107). If a reply signal has not been received (step S107: NO), the process returns to step S106, and the table information TI and the request signal are retransmitted. On the other hand, if a reply signal has been received (step S107: YES), the process is completed (END).

[0042] Next, we will explain the contents displayed on the display unit 16a of the OPS 16 in the control system 2 that received the table information TI. FIG. 5 is a diagram showing an example of a display on the display unit 16a of the OPS 16. The display unit 16a displays various data and warnings based on the table information TI received from the incident monitoring support server 4. In FIG. 5, (a) shows the number of alarms, which is one of the evaluation indicators of incidents in each monitored component device (OPS 16, ACS 18, etc.). In this example, the horizontal axis shows time and the vertical axis shows the number of alarms issued for a specific incident, indicating that the number of alarms issued tends to increase over time. (b) shows a schematic representation of the incident status in each monitored component device of the control system 2, in which a component device in which a worrisome incident has been detected is highlighted compared to the other components (note that such highlighting may be done in any way, such as by color, as long as the operator can distinguish between them). (c) shows the time progression of the number of login errors, which is an example of an incident in each component device, and (d) shows the progression of traffic volume in each component device. By making a comprehensive assessment based on the displays (a) to (d), the operator can recognize which components are at risk from cyberattacks.

[0043] Furthermore, screen displays related to such incidents may be displayed on a large display terminal shared by multiple operators in a central control room under constant monitoring, or on small display terminals individually assigned to each operator.

[0044] The control system 2 may also include an isolation unit for isolating specific components from the control system 2. In this embodiment, the isolation unit is installed as a function of the OPS 16, and is configured so that an operator can refer to the display content on the display unit 16a of the OPS 16 and isolate specific components selected by the operator. For example, in the display example of FIG. 5(b), the terminal on which the incident occurred is highlighted, and upon recognizing this, the operator can isolate the terminal for which isolation measures are deemed necessary. Note that the selection of components on the display unit 16a can be performed using a human interface, such as a mouse, keyboard, or touch panel.

[0045] The isolation unit recognizes the component device selected by OPS 16 and performs an operation to isolate the component device from other component devices. Although the isolation operation performed by the isolation unit is not limited, in this embodiment, the isolation unit performs an isolation operation by performing at least one of the following for the specific component device selected as the isolation target: (i) shutdown, (ii) network disconnection, or (iii) exclusion from communication targets (e.g., address deletion by rewriting the ARP table). These multiple isolation operations may be performed in stages, as described below. This enables a rapid response to a cyber attack by isolating the component device in which an incident has occurred from other component devices.

[0046] Here, the procedure for isolating a component device selected by the OPS 16 will be described with reference to Fig. 6. Fig. 6 is a flowchart showing the procedure for isolating a component device.

[0047] First, OPS 16, functioning as the isolation unit, identifies the component devices selected as targets for isolation (step S200). As described above, the selection of the component devices to be isolated is performed, for example, based on the display results on display unit 16a of OPS 16, and the component devices determined to require isolation are identified. OPS 16 then performs a first isolation operation on the component devices identified in step S200 (step S201). The first isolation operation is, for example, (i) shutdown.

[0048] Next, OPS 16 determines whether the isolation of the component device identified in step S200 was successful as a result of the first isolation operation performed in step S201 (step S202). The determination in step S202 may be performed when a predetermined period of time has elapsed since the first isolation operation was performed in step S201. If the isolation was not successful through the first isolation operation (step S202: NO), OPS 16 performs a second isolation operation on the component device identified in step S200 (step S203). The second isolation operation is an isolation operation based on an approach different from that of the first isolation operation, such as (ii) network disconnection. If isolation is successful in the first isolation operation (step S202: YES), the series of isolation operations ends.

[0049] Next, OPS16 determines whether isolation of the component device identified in step S200 was successful as a result of the second isolation operation performed in step S203 (step S204). The determination in step S204 may be performed when a predetermined period of time has elapsed since the second isolation operation was performed in step S203. If isolation was not successful through the second isolation operation (step S204: NO), OPS16 performs a third isolation operation on the component device identified in step S200 (step S205). The third isolation operation is an isolation operation based on an approach different from the first and second isolation operations, and is, for example, (iii) exclusion from communication targets. If isolation is successful through the second isolation operation (step S204: YES), the series of isolation operations ends.

[0050] Next, OPS 16 determines whether isolation of the component device identified in step S200 was successful as a result of the third isolation operation performed in step S205 (step S206). The determination in step S206 may be made when a predetermined period of time has elapsed since the third isolation operation was performed in step S205. If isolation was not successful through the third isolation operation (step S206: NO), a warning message indicating that isolation was not successful is displayed (step S207). If isolation is successful in the third isolation operation (step S206: YES), the series of isolation operations ends.

[0051] In this embodiment, the OPS 16, which functions as the isolation unit, performs multiple isolation operations in stages, thereby accurately isolating a specific component device in which an incident has been detected from other normal component devices. Furthermore, if isolation is not possible even after multiple isolation operations, the operator can be quickly notified by displaying a warning to that effect.

[0052] Furthermore, the plurality of components of the control system 2 that are to be isolated by the OPS 16 functioning as the isolation unit may include the management terminal 6m and the client terminal 6c. Fig. 7 is a schematic diagram showing the communication state between the OPS 16 and the management terminal 6m and the client terminal 6c.

[0053] The management terminal 6m is a terminal that can communicate directly with OPS 16 and can be isolated based on an isolation command received from OPS 16. The client terminal 6c is a terminal that can communicate with OPS 16 via the management terminal 6m and can be isolated based on an isolation command received from OPS 16 via the management terminal 6m. As a result, the management terminal 6m is the only terminal that directly receives an isolation command from OPS 16, so that traffic on the communication path between OPS 16 and the multiple component devices can be reduced while isolation control of a specific component device selected from the multiple component devices can be appropriately performed.

[0054] As described above, according to each of the above embodiments, when an incident is detected based on a log collected in the control system 2 to be monitored, the incident monitoring support server 4 acquires an incident detection signal corresponding to the incident. In this server, an evaluation index Value is stored as table information TI for each incident identification information PID, thereby enabling the system status to be evaluated for each incident based on the table information TI. The table information TI is updated as an incident detection signal is acquired, thereby appropriately reflecting the occurrence state of an incident in the control system 2. Such table information TI is transmitted as incident information to the OPS 16, which is the management unit of the control system 2, thereby enabling the OPS 16 to monitor incidents based on the incident information contained in the received table information TI. In other words, the OPS 16 can centrally monitor incidents based on the table information TI in addition to the conventional function of managing the control system. As a result, it is possible to provide an incident monitoring support server 4, an integrated control system 1, an incident monitoring support method, and an incident monitoring support program that enable the OPS 16 of the control system 2 to centrally perform monitoring of incidents occurring in the control system 2 together with conventional management processing.

[0055] In addition, within the scope of the present disclosure, the components in the above-described embodiments may be replaced with well-known components as appropriate, and the above-described embodiments may be combined as appropriate.

[0056] The contents described in each of the above embodiments can be understood, for example, as follows.

[0057] (1) An incident monitoring support server according to one aspect includes: an incident detection signal acquisition unit (22) for acquiring an incident detection signal corresponding to an incident detected based on a log collected by the control system; a table information storage unit (24) that stores table (TI) information that defines an evaluation index (Value) for each identification information (PID) for identifying the incident; a table information update unit (26) that updates the table information based on the incident detection signal; a table information transmitting unit (28) for transmitting the table information stored in the table information storage unit to a management unit (OPS16) for managing the control system as incident information that can be handled by the management unit; Equipped with.

[0058] According to the above aspect (1), when an incident is detected based on logs collected in a monitored control system, the incident monitoring support server acquires an incident detection signal corresponding to the incident. In this server, evaluation indices are stored as table information for each incident's identification information, enabling the system status to be evaluated for each incident based on the table information. The table information updates the corresponding evaluation indices when an incident detection signal is acquired, appropriately reflecting the state of the incident occurring in the control system. This table information is transmitted as incident information to a management unit of the control system, enabling the management unit to monitor incidents, such as by notifying an operator of incidents whose evaluation indices meet a predetermined standard based on the incident information contained in the received table information. In other words, the management unit can centrally monitor incidents based on the table information in addition to its conventional function of managing the control system. Furthermore, even when various incidents are detected based on logs collected in the control system, it is possible to identify and notify an operator of incidents that should be notified if the corresponding evaluation indices contained in the table information meet a predetermined standard. This makes it possible to appropriately notify operators of incidents that are useful to them, even when various incident detection signals are obtained from the control system, effectively reducing the risk of important incidents being overlooked and enabling accurate system monitoring.

[0059] (2) In another embodiment, in the above embodiment (1), the table information update unit updates the evaluation index corresponding to the identification information of the incident based on the incident detection signal; The table information transmitting unit transmits the incident information to the management unit when the evaluation index satisfies a predetermined standard.

[0060] According to the above aspect (2), when an incident detection signal is acquired, the evaluation index corresponding to the identification information of the incident detected as the incident detection signal is updated in the table information. If the updated evaluation index satisfies a predetermined standard, incident information indicating that an incident corresponding to the evaluation index has been detected is transmitted to the management unit.

[0061] (3) In another embodiment, in the above embodiment (2), the table information update unit counts up the evaluation index corresponding to the identification information of the incident based on the incident detection signal; The table information transmitting unit transmits the incident information to the management unit when the evaluation index exceeds a threshold value set as the criterion.

[0062] According to the above aspect (3), when an incident detection signal is acquired, the evaluation index corresponding to the identification information of the incident detected as the incident detection signal is updated so as to be counted up in the table information. When the counted-up evaluation index exceeds a threshold, incident information indicating that an incident corresponding to the evaluation index has been detected is transmitted to the management unit.

[0063] (4) In another embodiment, in the above embodiment (2), the table information update unit switches the evaluation index corresponding to the identification information of the incident from 0 to 1 based on the incident detection signal; When the evaluation index is equal to 1, the table information transmission unit transmits the incident information to the management unit.

[0064] According to the above aspect (4), when an incident detection signal is acquired, the evaluation index in the table information corresponding to the identification information of the incident detected as the incident detection signal is updated so as to be switched from "0" to "1." If the evaluation index in the updated table information is "1," incident information indicating that an incident corresponding to the evaluation index has been detected is transmitted to the management unit.

[0065] (5) In another embodiment, in any one of the above (1) to (4), The table information transmission unit a request signal transmitting unit (30) for transmitting a request signal (RTD set Request) to the management unit together with the table information; a reply signal receiving unit (32) for receiving a reply signal (RTD set Reply) transmitted from the management unit when the management unit receives the table information; Equipped with.

[0066] According to the above aspect (5), a request signal is sent to the management unit together with the table information. When the management unit receives the table information and the request signal, it sends a reply signal to the request signal. By receiving such a reply signal, the server can confirm that the table information has been reliably received by the management unit, thereby improving the reliability of incident monitoring on the management unit side.

[0067] (6) In another embodiment, in any one of the above (1) to (5), The control system is connected to the management unit via a second communication network (network N3) that has a lower security priority than a first communication network (networks N1 and N2) that connects the control system and the management unit.

[0068] According to the above aspect (6), the server can be connected to the management unit via a communication network with a low security priority, which makes it possible to introduce incident monitoring support using the server while avoiding traffic degradation on a communication network with a high security priority.

[0069] (7) An integrated control system (1) according to one aspect includes: An incident monitoring support server (4) according to any one of (1) to (6) above; The control system (2); Equipped with The management unit has a display unit (16a) that displays the operating status of multiple constituent devices of the control system in a manner that makes it possible to distinguish the incidents, based on the table information received from the table information transmission unit.

[0070] According to the above aspect (7), the management unit displays the operating status of the components of the control system based on the table information received from the incident monitoring support server. This display aspect allows incidents to be distinguished for each component of the control system, so that the management unit that manages the control system can perform incident monitoring in a unified manner.

[0071] (8) In another embodiment, in the above embodiment (7), The management unit includes an isolation section (OPS16) for isolating the component device selected based on the display on the display section.

[0072] According to the above aspect (8), the management unit that manages the control system can monitor the incident and isolate a specific component device of the control system depending on the occurrence of the incident.

[0073] (9) In another embodiment, in the above embodiment (8), The isolation unit isolates the component device by (i) shutting it down, (ii) disconnecting it from the network in the control system, or (iii) excluding it from communication targets in the control system.

[0074] According to the above aspect (9), a specific component device can be isolated by any of the methods (i) to (iii). These methods may be implemented in stages, and for example, a specific component device in which an incident has been detected can be accurately isolated from other normal component devices.

[0075] (10) In another embodiment, in the above embodiment (8), The components include: a management terminal (6m) capable of isolating the device based on an isolation command received from the isolation unit; a client terminal (6c) that can be isolated based on the isolation command received from the isolation unit via the management terminal; Includes.

[0076] According to the above aspect (10), the plurality of constituent devices to be isolated include a management terminal capable of receiving an isolation command directly from the management unit, and a client terminal capable of indirectly receiving the isolation command via the management terminal. As a result, the management terminal is the only device that directly receives the isolation command from the management unit, and therefore, it is possible to appropriately perform isolation control of a specific constituent device selected from the plurality of constituent devices while reducing traffic on the communication path between the management unit and the plurality of constituent devices.

[0077] (11) An incident monitoring support method according to one aspect includes: obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information (TI) that defines an evaluation index (Value) for each identification information (PID) for identifying the incident stored in a table information storage unit (24) based on the incident detection signal; transmitting the table information to a management unit (OPS16) for managing the control system as incident information that can be handled by the management unit; Equipped with.

[0078] According to the above aspect (11), when an incident is detected based on logs collected in a monitored control system, the incident monitoring support server acquires an incident detection signal corresponding to the incident. In this server, evaluation indices are stored as table information for each incident's identification information, enabling the system status to be evaluated for each incident based on the table information. In the table information, the corresponding evaluation indices are updated when an incident detection signal is acquired, thereby appropriately reflecting the state of incident occurrence in the control system. This table information is transmitted as incident information to a management unit of the control system, enabling the management unit to monitor incidents, such as by notifying an operator of incidents whose evaluation indices meet a predetermined standard based on the incident information contained in the received table information. In other words, the management unit can centrally monitor incidents based on the table information in addition to its conventional function of managing the control system. Furthermore, even when various incidents are detected based on logs collected in the control system, it is possible to identify and notify an operator of incidents that should be notified if the corresponding evaluation indices contained in the table information meet a predetermined standard. This makes it possible to appropriately notify operators of incidents that are useful to them, even when various incident detection signals are obtained from the control system, effectively reducing the risk of important incidents being overlooked and enabling accurate system monitoring.

[0079] (12) An incident monitoring support program according to one aspect, Using a computer, obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information (TI) that defines an evaluation index (Value) for each identification information (PID) for identifying the incident stored in a table information storage unit (24) based on the incident detection signal; transmitting the table information to a management unit (OPS16) for managing the control system as incident information that can be handled by the management unit; is possible.

[0080] According to the above aspect (12), when an incident is detected based on logs collected in a monitored control system, the incident monitoring support server acquires an incident detection signal corresponding to the incident. In this server, evaluation indices are stored as table information for each incident's identification information, enabling the system status to be evaluated for each incident based on the table information. The table information updates the corresponding evaluation indices when an incident detection signal is acquired, appropriately reflecting the state of the incident occurring in the control system. This table information is transmitted to a management unit of the control system as incident information, enabling the management unit to monitor incidents, such as by notifying an operator of incidents whose evaluation indices meet a predetermined standard based on the incident information contained in the received table information. In other words, the management unit can centrally monitor incidents based on the table information in addition to its conventional function of managing the control system. Furthermore, even when various incidents are detected based on logs collected in the control system, it is possible to identify and notify an operator of incidents that should be notified if the corresponding evaluation indices contained in the table information meet a predetermined standard. This makes it possible to appropriately notify operators of incidents that are useful to them, even when various incident detection signals are obtained from the control system, effectively reducing the risk of important incidents being overlooked and enabling accurate system monitoring. [Explanation of symbols]

[0081] 1. Integrated control system 2. Control System 4. Incident monitoring support server 5 Monitoring terminal 6. Control device 6c Client terminal 6m management terminal 8 Distributed Control Device 10 Field Devices 16a Display section 20 Incident detection unit 22 Incident detection signal acquisition unit 24 Table information storage unit 26 Table information update section 28 Table information transmission unit 30 Request signal transmitter 32 Reply signal receiving unit N1~N3 communication network

Claims

1. an incident detection signal acquisition unit for acquiring an incident detection signal corresponding to an incident detected based on a log collected by the control system; a table information storage unit that stores table information that defines an evaluation index for each piece of identification information for identifying the incident; a table information update unit that updates the table information based on the incident detection signal; a table information transmitting unit for transmitting the table information stored in the table information storage unit to a management unit for managing the control system as incident information that can be handled by the management unit; An incident monitoring support server comprising:

2. the table information update unit updates the evaluation index corresponding to the identification information of the incident based on the incident detection signal; 2 . The incident monitoring support server according to claim 1 , wherein the table information transmitting unit transmits the incident information to the management unit when the evaluation index satisfies a predetermined standard.

3. the table information update unit counts up the evaluation index corresponding to the identification information of the incident based on the incident detection signal; The incident monitoring support server according to claim 2 , wherein the table information transmitting unit transmits the incident information to the management unit when the evaluation index exceeds a threshold value set as the criterion.

4. the table information update unit switches the evaluation index corresponding to the identification information of the incident from 0 to 1 based on the incident detection signal; The incident monitoring support server according to claim 2 , wherein the table information transmitting unit transmits the incident information to the management unit when the evaluation index is equal to one.

5. The table information transmission unit a request signal transmitting unit for transmitting a request signal together with the table information to the management unit; a reply signal receiving unit for receiving a reply signal transmitted from the management unit when the management unit receives the table information; The incident monitoring support server according to claim 1 or 2, comprising:

6. 3. The incident monitoring support server according to claim 1, which is connected to the management unit via a second communication network having a lower security priority than a first communication network connecting the control system and the management unit.

7. an incident monitoring support server according to claim 1 or 2; the control system; Equipped with The management unit is an integrated control system having a display unit that displays the operating status of multiple constituent devices of the control system in a manner that allows the incident to be distinguished based on the table information received from the table information transmission unit.

8. The integrated control system according to claim 7 , wherein the management unit includes an isolation unit for isolating the component device selected based on the display on the display unit.

9. The integrated control system of claim 8, wherein the isolation unit isolates the component device by (i) shutting it down, (ii) disconnecting it from the network in the control system, or (iii) excluding it from communication targets in the control system.

10. The components include: a management terminal capable of isolating itself based on an isolation command received from the isolation unit; a client terminal that can be isolated based on the isolation command received from the isolation unit via the management terminal; The integrated control system of claim 8 , comprising:

11. obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information that defines an evaluation index for each piece of identification information for identifying the incident stored in a table information storage unit based on the incident detection signal; transmitting the table information to a management unit for managing the control system as incident information that can be handled by the management unit; An incident monitoring support method comprising:

12. Using a computer, obtaining an incident detection signal corresponding to the detected incident based on the logs collected by the control system; updating table information that defines an evaluation index for each piece of identification information for identifying the incident stored in a table information storage unit based on the incident detection signal; transmitting the table information to a management unit for managing the control system as incident information that can be handled by the management unit; A feasible incident monitoring support program.

Citation Information

Patent Citations

  • Twin wire apparatus of papermaking machine

    JP1986063793A

  • Access monitoring device, access monitoring method and program thereof

    JP2011221846A

  • Management system, management method and management program for managing industrial control system

    JP2012226680A

  • Control device and control system

    JP6977507B2