Security support device, security support method, and security support program

The security support device integrates cyber and physical information using AI to address abnormalities in CPS, providing comprehensive and effective countermeasures by analyzing past threat and vulnerability data.

JP2026058570APending Publication Date: 2026-04-06KDDI CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024166130
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-25
Publication Date
2026-04-06

AI Technical Summary

Technical Problem

Conventional security devices in Cyber-Physical Systems (CPS) lack the ability to effectively integrate and analyze information from both cyberspace and physical space using AI, making it difficult to determine appropriate countermeasures for abnormal situations.

Method used

A security support device that utilizes generating AI to integrate and analyze cyber and physical information, performing cyber-physical mapping and generating prompts for AI to derive optimal security measures, with a system that includes cyber information collection, physical information collection, cyber-physical mapping, generating AI input/output, CPS integrated security measure determination, recording, and cyber-physical countermeasure separation.

Benefits of technology

The system provides objective and optimal security measures by identifying the cause of abnormalities in CPS through integrated analysis, recommending countermeasures for both cyberspace and physical space, leveraging AI's learning from past threat and vulnerability information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026058570000001_ABST
    Figure 2026058570000001_ABST
Patent Text Reader

Abstract

We provide security measures that integrate and analyze information from cyberspace and physical space using generative AI. [Solution] A security support device 10 is provided, comprising: a cyber information collection means 150 for collecting anomaly information in cyberspace; a physical information collection means 160 for collecting anomaly information in physical space; a cyber-physical correspondence means 170 for associating anomaly information in cyberspace with anomaly information in physical space; a generation AI input / output means 110 for inputting the associated anomaly information in cyberspace and anomaly information in physical space as prompts to a generation AI 20 and obtaining security measures as a response from the generation AI 20; and a CPS integrated security measure determination means 120 for assigning priority and reliability to the security measures, which are the response from the generation AI 20, and transmitting them to a CPS (cyber-physical system) 30.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a security measure support device that supports security measures in a Cyber-Physical System (CPS).

Background Art

[0002] Conventionally, efforts related to security in CPS have mainly focused on information observable in a wide-area cyber space, such as searching for vulnerable IoT (Internet of Things) devices discoverable from the Internet and observing abnormal communications such as scans performed by IoT devices infected with malware. Therefore, when an IoT device itself is attacked in the physical space without being observed from a wide-area network, abnormalities and unauthorized operations in the physical space caused by the IoT device appear as phenomena that can only be observed in the nearby cyber space.

[0003] Therefore, even if these events are accidentally observed in a certain physical space, it has been difficult to accurately determine the presence or absence of an impact on the wide-area network and the necessity of countermeasures. Also, even if an attack is shared, its affected range may vary depending on the situation and usage scenario of each physical space, and effective countermeasures may also vary.

[0004] In Patent Document 1, for the purpose of applying security measures in consideration of the adverse effects on the user's business when each security measure is executed, malware is executed on a simulation terminal, an attack method is generated from the analysis results, and based on the rules described in a countermeasure candidate generation rule table showing the relationship between the attack method and the security measures, a security measure candidate for the attack method is determined by a countermeasure candidate generation program. However, in Patent Document 1, the generation rules for countermeasure candidates are stored in the internal storage device of the security measure device, and AI (Artificial Intelligence) generation is not used.

[0005] Patent Document 2 aims to provide a security measure selection system that can verify the cost-effectiveness of combinations of security measures. For any combination of security measures stored in a database, the total cost of the security measures and the expected damage amount if those measures are implemented are calculated and compared to verify the cost-effectiveness. However, Patent Document 2 stores the countermeasures table in a database, and does not utilize generation AI. [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] Patent No. 6712207 [Patent Document 2] Patent No. 6320965 [Overview of the project] [Problems that the invention aims to solve]

[0007] Conventional security devices do not use AI for generating responses, making it difficult to propose appropriate countermeasures for abnormal situations.

[0008] The present invention aims to provide a security support device for CPS that can derive security measures by integrating and analyzing information from cyberspace and physical space using generating AI, in accordance with the conditions of individual cyberspace and physical space, and the usage scenarios. [Means for solving the problem]

[0009] (1) The security support device according to the present invention includes: cyber information collection means for collecting cyber information relating to abnormal conditions detected in the cyber space of a CPS in a predetermined area; physical information collection means for collecting physical information relating to abnormal conditions detected in the physical space of the CPS in the predetermined area; cyber-physical mapping means for performing mapping between the collected cyber information and physical information by referring to mapping information; and generating a prompt for a predetermined generating AI from the cyber information and physical information collected and mapped in the CPS, as well as input / output auxiliary information, and sending the generated prompt to the generating AI. The system includes: a generating AI input / output means for inputting data and receiving a response from the generating AI; a CPS integrated security measure determination means for determining CPS integrated security measure support information for a predetermined area based on the response from the generating AI and countermeasure support information; a recording means for recording threat information, vulnerability information, and CPS integrated security measure support information for cyberspace and physical space previously detected in one or more areas in a recording device; and a cyber-physical countermeasure separation means for separating the CPS integrated security measure support information determined by the CPS integrated security measure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifying the CPS.

[0010] (2) The generating AI input / output means may input prompts to the generating AI for integrating and analyzing the cyber information and physical information collected from the CPS.

[0011] (3) The generating AI input / output means may analyze the physical information and / or cyber information collected from the CPS, detect abnormal patterns, and feed back the analysis results to the generating AI, thereby inputting a prompt to the generating AI to propose security measures for the detected abnormal patterns.

[0012] (4) The CPS integrated security measures determination means may assign priority and reliability to each of the multiple security measures output from the generating AI and notify the CPS.

[0013] (5) The CPS integrated security measures determination means may notify the recording means of the CPS integrated security measures support information and store it.

[0014] (6) The security support method according to the present invention includes: a cyber information collection step of collecting cyber information relating to abnormal conditions detected in the cyber space of a CPS in a predetermined area; a physical information collection step of collecting physical information relating to abnormal conditions detected in the physical space of the CPS in the predetermined area; a cyber-physical mapping step of performing mapping between the collected cyber information and physical information by referring to mapping information; and generating a prompt for a predetermined generating AI from the cyber information and physical information collected and mapped in the CPS, as well as input / output auxiliary information, and inputting the generated prompt to the generating AI. The computer performs the following steps: a generation AI input / output step of receiving a response from a generation AI; a CPS integrated security measure determination step of determining CPS integrated security measure support information for a predetermined area based on the response from the generation AI and the countermeasure support information; a recording step of recording threat information, vulnerability information, and CPS integrated security measure support information for cyberspace and physical space previously detected in one or more areas in a recording device; and a cyber-physical countermeasure separation step of separating the CPS integrated security measure support information determined by the CPS integrated security measure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifying the CPS.

[0015] (7) The security support program according to the present invention includes: a cyber information collection step of collecting cyber information relating to abnormal conditions detected in the cyber space of a CPS in a predetermined area; a physical information collection step of collecting physical information relating to abnormal conditions detected in the physical space of the CPS in the predetermined area; a cyber-physical mapping step of performing mapping between the collected cyber information and physical information by referring to mapping information; and generating a prompt for a predetermined generating AI from the cyber information and physical information collected and mapped in the CPS, as well as input / output auxiliary information, and inputting the generated prompt to the generating AI. The computer is made to execute the following steps: a generation AI input / output step of receiving a response from the generation AI; a CPS integrated security measure determination step of determining CPS integrated security measure support information for a predetermined area based on the response from the generation AI and the countermeasure support information; a recording step of recording threat information, vulnerability information, and CPS integrated security measure support information for cyberspace and physical space previously detected in one or more areas in a recording device; and a cyber-physical countermeasure separation step of separating the CPS integrated security measure support information determined by the CPS integrated security measure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifying the CPS. [Effects of the Invention]

[0016] According to the present invention, based on the output of a generating AI that has learned from a wide range of past CPS threat information, vulnerability information, and CPS integrated security support information, CPS integrated security support information is provided to CPS in an abnormal state, and it is expected that optimal security measures will be recommended. The output of the generating AI is information mechanically generated from a wide range of information sources, and it is expected that objective CPS integrated security support information will be proposed. According to the present invention, by integrally analyzing the information in both the cyber space and the physical space in CPS, or the information of one of them, with the generated AI, the cause of an abnormality is identified, and in the security countermeasures, countermeasures for both the cyber space and the physical space, or one of them, can be derived.

Brief Description of the Drawings

[0017] [Figure 1] FIG. 8 is a diagram showing a configuration example of a security countermeasure support system to which the security countermeasure support device according to an embodiment of the present invention is applied. [Figure 2] FIG. 11 is a diagram showing a hardware configuration of the security countermeasure support device according to an embodiment of the present invention. [Figure 3] FIG. 14 is a flowchart showing the processing of the security countermeasure support device according to an embodiment of the present invention.

Embodiments for Carrying Out the Invention

[0018] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIG. 24 is a diagram showing a configuration example of a security countermeasure support system 100 to which a security countermeasure support device 10 according to an embodiment of the present invention is applied.

[0019] The security countermeasure support device 10 in FIG. 1 collects information from the CPS 30 and applies countermeasures to the CPS 30. The CPS 30 provides services using IoT devices such as mobility, robots, and sensors in a predetermined area. The CPS 30 is composed of a cyber space 310 and a physical space 320.

[0020] The CPS30 processes information in the real world (physical space 320) collected from IoT devices in the digital space (cyber space 310) and feeds back the results to the real world. The CPS30 may constitute a DT (Digital Twin). DT refers to a mechanism that constructs a twin corresponding to the real world (physical space 320) in the digital space (cyber space 310) to enable monitoring and simulation.

[0021] By constructing a DT in the cyber space 310, when the CPS30 receives security countermeasure information from the security countermeasure support device 10, it becomes easy to identify problem locations using the virtual model of the DT and derive the scope of influence caused by those problem locations.

[0022] The security countermeasure support device 10 in FIG. 1 can also communicate via the Internet 40 and communicate with the generation AI 20. [[ID=X]]The security countermeasure support device 10 includes a generation AI input / output means 110, a CPS integrated security countermeasure decision means 120, a recording means 130, a cyber-physical countermeasure separation means 140, a cyber information collection means 150, a physical information collection means 160, and a cyber-physical association means 170. Also, the security countermeasure support device 1 uses information including input / output auxiliary information 210, association information 220, and countermeasure auxiliary information 230.

[0023] The recording means 130 records threat information (260, 270) and vulnerability information (240, 250) of the cyber space and physical space detected in one or more other areas existing on the Internet, as well as information on the implemented CPS security countermeasures. It also records the CPS integrated security countermeasure support information 280 determined by the CPS integrated security countermeasure decision means 120.

[0024] It should be noted that there seems to be a mistake in the original text where "the security countermeasure support device 1 uses information" in [[ID=X]] should probably be "the security countermeasure support device 10 uses information". This has been corrected in the translation.Furthermore, the recording means 130 may include, for example, vulnerability information regarding servers in cyberspace 310, cyberattack observation information observed over a wide area such as the internet, physical device threat information such as the insertion of physically malicious circuits into devices in physical space 320, and OSINT (Open-Source Intelligence) information such as social media. OSINT is information obtained by diagnosticians (so-called white hat hackers) investigating legally available external resources such as domains, IP addresses, and public services, and analyzing them from the attacker's perspective to see if they can be used to attack devices.

[0025] The cyber information gathering means 150 and the physical information gathering means 160 collect information regarding abnormal conditions detected in the CPS 30 in a predetermined area, for both the cyberspace 310 and the physical space 320, respectively. Hereinafter, information regarding abnormal conditions detected by the cyber information gathering means 150 will be referred to as "cyber information," and information regarding abnormal conditions detected by the physical information gathering means 160 will be referred to as "physical information." An abnormal condition is a state in which the operation of an object managed by CPS30 exceeds the normal operating range, such as a mobility device deviating from its course, a service robot stopping during service hours, or sensor detection values ​​exceeding a predetermined range. Abnormal conditions can occur in both cyberspace 310 and physical space 320.

[0026] The collected information is transmitted to the generating AI input / output means 110 to derive security measures for the CPS30 and used as input to the generating AI 20. For this reason, the cyber information collection means 150 and the physical information collection means 160 handle the information in text format. The security support device 10 may collect information from the CPS30, or the CPS30 may actively provide information to the security support device 10.

[0027] Abnormal conditions can be classified as follows, for example, but the types are not limited to these. Examples of information items to be collected include IoT devices in physical space 320, operational logs regarding the types of devices and their abnormal states in the vicinity of those IoT devices, and information regarding services provided by other IoT devices in the same area in cyberspace 310, which is paired with physical space 320.

[0028] The information collected may also include information about signs of anomalies, in order to detect CPS30 abnormalities early and minimize damage. For example, information such as a large amount of logs being recorded on the server managing the IoT device in cyberspace 310, unauthorized access being detected on a server managing other IoT devices in the same area, or a large amount of traffic occurring in the area. This makes it possible to detect anomalies at the early stages.

[0029] (1) Abnormal conditions in cyberspace 310 (a) Network related (A) Communication interruption (B) Reduced throughput (C) Delay (i) Security related (A) Unauthorized access (B) Malware infection (C) Data leak (c) Application related (A) Service suspension (B) Performance decline

[0030] (2) Abnormal state of physical space 320 (a) Sensor related (A) Sensor failure (B) Data inconsistency (i) Actuator-related (A) Actuator failure (B) Abnormal operation (c) Device related (A) Device failure (B)Physical damage

[0031] Based on the above classification, the collected information can be handled in the following format, for example. In the following example, "details" refers to specific information that supplements the details of the anomaly, such as the circumstances of its occurrence, the scope of its impact, and the time of its occurrence.

[0032] [Examples of collected information] {Space: Cyberspace} Category: Security-related Device ID: 020 Abnormality: Unauthorized access Details: Unauthorized login attempt from IP address 192.168.1.10

[0033] The cyber-physical mapping means 170 maps cyber information to physical information by referring to cyber information received from the cyber information collection means 150, physical information received from the physical information collection means 160, and mapping information 220. The mapping between cyber information and physical information includes, for example, the correspondence between the hardware ID of a sensor device in physical space 320 and the network address information of the same device in cyber space 310, the correspondence between the self-position estimated by a mobility device in physical space 320 and the coordinate position of that mobility device in cyber space 310, and the correspondence between the operation record of equipment in physical space 320 and the entry for that equipment in the event log in cyber space 310. The mapping information 220 records these correspondences, and the cyber-physical mapping means 170 performs the mapping between cyber information and physical information based on this mapping information.

[0034] The generation AI input / output means 110 refers to the cyber information and physical information received from the cyber-physical mapping means 170 and the input / output auxiliary information 210 to create a prompt for the generation AI 20 to output security support information, and inputs it to a predetermined generation AI 20.

[0035] The input / output support information 210 includes contextual information such as the usage scenario of CPS30, the output format from generation AI20, the output items from generation AI20, and whether or not feedback is provided.

[0036] The output format from the generating AI20 may be natural language, or a format such as Linux® commands may be specified to facilitate processing in the CPS30. The output items from the generating AI20 may include risks caused by the anomaly and Common Vulnerabilities and Exposures (CVEs) that are expected to be associated with the anomaly.

[0037] Alternatively, log data such as operational log data from the CPS30 in a designated area and network traffic data for that area may be input to the generating AI20 first to analyze the anomaly, and the detected anomaly may be reflected in the next input to the generating AI20, and a prompt instructing it to propose security measures may be entered. In this case, if the input to the generating AI20 is log data, it is predicted that the first response from the generating AI20 will only detect the anomaly, and it will be difficult for it to propose countermeasures for the anomaly. In this case, by setting the feedback of the input / output auxiliary information 210 to "Yes", if the first response from the generating AI20 is insufficient, the first response from the generating AI20 will be recorded in the input / output auxiliary information 210 and referred to when creating the next input prompt to the generating AI20.

[0038] The prompt to the generating AI 20 instructs it to integrate and analyze information from cyberspace 310 and physical space 320, enabling the generating AI 20 to output security information regarding CPS 30, including the impact of cyberattacks on physical space 320, or vice versa. For example, if a server handling mobility is subjected to a cyberattack, the operation of the mobility may also be affected. The AI ​​can analyze the cause, such as whether the mobility anomaly is due to a simple physical failure or a cyberattack, and propose countermeasures based on the analysis results.

[0039] If CPS30 consists of sensors in physical space 320 and servers in cyber space 310, the integrated analysis will analyze the anomaly information detected by the sensors in physical space 320 and the anomaly information detected by the servers in cyber space 310 together and input prompts to propose security measures. For example, if a sensor malfunctions and accurate location information cannot be obtained, no anomaly will be detected in the server logs in cyber space 310, but an air conditioning malfunction will be detected in a specific area of ​​physical space 320. In this case, the generating AI20 will determine that the sensor is malfunctioning due to temperature changes and can derive countermeasures on the physical space 320 side.

[0040] Furthermore, in addition to analyzing the current situation, you may also enter prompts to predict potential future security anomalies based on CPS30's past log data and suggest recommended risk mitigation methods. An example of prompts for performing an integrated analysis is shown below. Here, we assume that the mapping information 220 is registered as follows: Device ID: 010 is a server and Device ID: 020 is a micromobility device.

[0041] [Prompt example] Integrate information regarding cyber-physical anomalies, analyze their causes, identify vulnerabilities, and propose security measures. #role: You are the security administrator for cyber-physical systems. #Usage scenarios: Micro-mobility devices are operating within the shopping mall to assist shoppers with their movement. #Abnormal state: The following abnormalities have occurred. {Space: Cyberspace Type: Network-related Device ID: 010 (Server) Error Description: Communication interruption Details: The device has been unable to connect to the network for the past minute.} {Space: Physical space Type: Device-related Device ID: 020 (Micromobility) Error description: Device failure Details: Motor is not working.} #Output format: JSON format #Output items: ·Cause ·risk ·Common vulnerability identifier • Cybersecurity measures Security measures for physical spaces

[0042] JSON format is an abbreviation for "JavaScript Object Notation," and refers to "a data definition method based on the way JavaScript objects are written." The CPS integrated security measure determination means 120 determines the CPS integrated security measure support information for the CPS 30 in a predetermined area based on the output result of the prompt input by the generation AI input / output means 110 to the generation AI 20 and the countermeasure support information 230. Furthermore, if similar events occur in the area or other areas, the CPS integrated security measure support information is notified to and stored in the recording means 130 so that the information can be used to support security measures.

[0043] The supplementary information 230 for countermeasures includes, for example, information obtained by conducting a risk assessment in advance regarding CPS30, evaluating the impact and frequency of occurrence of each risk, CPS30-dependent information such as the device manufacturer and model, and the usage status of available resources such as budget and personnel. Note that the "impact of each risk" mentioned above means "the degree to which each risk has an impact on CPS30."

[0044] In the prompt example described above, the generating AI input / output means 110 sets a risk in the output item as a result of referring to the input / output auxiliary information 210. If the risk output by the generating AI 20 corresponds to a risk registered in the countermeasure auxiliary information 230, the CPS integrated security countermeasure determination means 120 can estimate the degree of impact and frequency of occurrence by referring to the prior risk assessment results stored in the countermeasure auxiliary information 230. In order to prioritize responses to significant risks, if the CPS integrated security measures support information consists of multiple measures, the CPS integrated security measures determination means 120 may assign a priority and reliability to each measure and notify the CPS 30 accordingly.

[0045] Furthermore, in the prompt example mentioned above, since the output item is set to a Common Vulnerability Identifier, if a device with the vulnerability identified by the output of the generated AI20 exists within the CPS30, it can notify that countermeasures against that vulnerability are necessary. The notification information may be in text format for presentation to the operator. Alternatively, when directly inputting to a server or device, the output format of the generating AI20 may be specified as the command of the server constituting the CPS30.

[0046] The following is an example of CPS integrated security support information, with the countermeasures presented to operators prioritized and expressed as Linux® commands. The following example includes four countermeasures: "#1. Emergency incident response," "#2. Restarting physical devices," "#3. Checking server and device logs," and "#4. Inspecting hardware." [Example of CPS integrated security support information] #! / bin / bash # Prioritized Integrated Security Measures Support Script for Cyber-Physical Systems echo “Initiating integrated security measures for cyber-physical systems” #Priority: High #1. Emergency Incident Response echo “Emergency Incident Response: Attempting to restore network communication.” sudo ifconfig eth0 down sudo ifconfig eth0 up echo “Network interface restarted.” echo “Checking network settings” cat / etc / network / interfaces #2. Restarting physical devices echo “Emergency Incident Response: Attempting to reset micromobility devices” sudo systemctl restart mobility-device-id-020.service echo “Service for micromobility device ID:020 has been restarted.” #Priority: Medium #3. Check server and device logs. echo “Medium priority task: Checking server and device logs” cat / var / log / syslog|grep“Device ID :010”|tail -n50 cat / var / log / device.log|grep“Device ID :020”|tail -n50 #Priority:Low #4. Hardware Inspection echo “Low-priority task: Hardware check of mobility devices” cat / var / log / device_status.log|grep“Device ID :020”|tail -n50

[0047] The cyber-physical countermeasure separation means 140 divides the CPS integrated security countermeasure support information determined by the CPS integrated security countermeasure determination means 120 into countermeasures in cyberspace 310 and countermeasures in physical space 320, and notifies the CPS 30 in a predetermined area. For example, in the above command, devices with device ID 010 will be subject to countermeasures in cyberspace 310, and devices with device ID 020 will be subject to countermeasures in physical space 320.

[0048] The generating AI 20 generates an answer based on previously learned information in response to an input prompt received from the generating AI input / output means 110, and outputs the answer to the generating AI input / output means 110. The generating AI 20 is assumed to use a general-purpose large-scale language model, but pre-training may be performed by adding past threat information, vulnerability information, and CPS integrated security support information to the dataset used for pre-training of the generating AI 20. Furthermore, in order to improve the accuracy of the answer, fine-tuning may be performed, for example, by tuning the pre-trained generating AI using the most recent threat information, vulnerability information, and CPS integrated security support information.

[0049] To reflect the latest information not included in the dataset for which the generating AI 20 learns, RAG (Retrieval-Augmented Generation) may be used, which searches for data related to a given prompt from the recording means 130 or the internet 40 and adds the search results to the prompt, which is the input to the generating AI 20.

[0050] Figure 2 shows the hardware configuration of the security support device 10. The security support device 10 is installed on the computer 900. The computer 900 is equipped with a CPU 901, RAM 902, ROM 903, HDD (Hard Disk Drive) 904, communication I / F 905, input / output I / F 906, media I / F 907, and bus 908.

[0051] The application program is stored in the ROM 903, and the CPU 901 executes this application program to configure various means such as the CPS integrated security measure determination means 120 in Figure 1. The RAM 902 is used to temporarily store information. Various types of information, such as the input / output auxiliary information 210 in Figure 1 and the information in the recording means 130, are formed in the HDD 904.

[0052] The communication interface 905 is connected to an external communication device 915. Communication with the Internet 40 and the generating AI 20 is performed via the communication device 915. The input / output interface 906 is connected to the input / output device 916. The media interface 907 is connected to the recording medium 917. Information such as the input / output auxiliary information 210 in Figure 1 and the information in the recording means 130 may be input from the input / output device 916 or loaded from the recording medium 917.

[0053] Figure 3 is a flowchart showing the processing of the security support device 10. Step S100 is a step in which various types of information are accumulated. Step S100 may be performed by the user. In step S102, the recording means 130 stores cyber vulnerability information 240, physical vulnerability information 250, cyber threat information 260, physical threat information 270, and CPS integrated security countermeasure support information 280.

[0054] In step S104, the input / output auxiliary information 210 is set to contain information, output items, output format, and whether or not feedback is provided. In step S106, the correspondence between cyber information and physical information is registered in the correspondence information 220. In step S108, supplementary information regarding CPS30 is registered in the countermeasure support information 230.

[0055] In step S110, the cyber information gathering means 150 and the physical information gathering means 160 collect anomaly information from cyberspace 310 and physical space 320, respectively. In step S120, the cyber-physical mapping means 170 refers to the mapping information 220 and maps the cyber information to the physical information. In step S130, the generation AI input / output means 110 creates a prompt for the generation AI 20 from the associated cyber information and physical information, and input / output auxiliary information 210.

[0056] In step S140, the generation AI input / output means 110 inputs a prompt to the generation AI 20 and receives a response from the generation AI 20. In step S150, the generation AI input / output means 110 transmits the response from the generation AI 20 to the CPS integrated security measures determination means 120. In step S160, the CPS integrated security measure determination means 120 determines CPS integrated security measure support information from the response from the generating AI 20 and the countermeasure support information 230.

[0057] In step S170, if "Feedback Available" is set in the input / output auxiliary information 210, the CPS integrated security measures determination means 120 determines whether or not CPS integrated security measures support information can be assembled. If CPS integrated security measures support information cannot be assembled, the process proceeds to step S180. If CPS integrated security measures support information can be assembled, the process proceeds to step S190. If "Feedback Available" is not set in the input / output auxiliary information, the process proceeds directly to step S190.

[0058] In step S180, the generation AI input / output means 110 sets the response from the generation AI 20 in the input / output auxiliary information 210 and proceeds to step S130. In step S130, the generation AI input / output means 110 creates a prompt, taking into consideration the response from the generation AI 20 set in the input / output auxiliary information 210.

[0059] An example of a case where "Feedback Available" is set for input / output auxiliary information 210 is when cyber information and / or physical information consists of log data such as operational log data or network traffic data, and it is easy to predict that the generating AI's initial response will end with "An abnormal pattern has been detected in such-and-such a place," and no countermeasures for the abnormal condition will be proposed.

[0060] In step S190, the CPS integrated security measures determination means 120 transmits the CPS integrated security measures support information to the cyber-physical measures separation means 140 and registers it in the recording means 130. In step S200, the cyber-physical countermeasure separation means 140 separates the CPS integrated security countermeasure support information into cyber countermeasure information and physical countermeasure information and transmits them to the CPS 30.

[0061] According to the embodiments of the present invention described above, by having a generating AI perform an integrated analysis using information from both cyberspace and physical space, or information from either one of them, in a CPS, the cause of an anomaly can be identified, and security measures can be derived that address both cyberspace and physical space, or either one of them.

[0062] Furthermore, this allows us to provide CPS integrated security support information to CPS systems in abnormal states based on the output of a generating AI that has learned from a wide range of past CPS threat and vulnerability information, as well as CPS integrated security support information. This will contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), "Build resilient infrastructure, promote sustainable industrialization and foster innovation." [Explanation of symbols]

[0063] 10. Security support device 20 Generation AI 30 CPS 40 Internet 100 Security Measures Support System 110 Generation AI input / output means 120 CPS Integrated Security Measures Decision-Making Method 130 Recording means 140 Cyber-physical countermeasures and isolation methods 150 Cyber ​​Information Gathering Methods 160 Physical Information Collection Methods 170 Cyber-physical mapping means 210 Input / Output Auxiliary Information 220 Correspondence Information 230 Support Information for Countermeasures 240 Cyber ​​Vulnerability Information 250 Physical Vulnerability Information 260 Cyber ​​Threat Intelligence 270 Physical Threat Information 280 CPS Integrated Security Measures Support Information 310 Cyberspace 320 Physical Space 900 Computers 901 CPU 902 RAM 903 ROM 904 HDD 905 Communication I / F 906 Input / Output Interface 907 Media I / F 908 Bus 915 Communication equipment 916 Input / Output Device 917 Recording media

Claims

1. A cyber information collection means for collecting cyber information concerning abnormal conditions detected in the cyberspace of a CPS in a predetermined area, A physical information collection means for collecting physical information relating to abnormal conditions detected in the physical space of the CPS in the predetermined area, A cyber-physical mapping means that performs mapping between the collected cyber information and physical information by referring to mapping information, A generating AI input / output means generates a prompt for a predetermined generating AI from cyber information and physical information collected and associated by the CPS, as well as input / output auxiliary information, inputs the generated prompt to the generating AI, and receives a response from the generating AI. A CPS integrated security measure determination means that determines CPS integrated security measure support information for a predetermined area based on the response from the generated AI and the countermeasure support information, A recording means for recording threat information, vulnerability information, and CPS integrated security support information in cyberspace and physical space that have been detected in the past in one or more areas, into a recording device, A cyber-physical countermeasure separation means that separates the CPS integrated security countermeasure support information determined by the CPS integrated security countermeasure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifies the CPS, A security support device characterized by being equipped with the following features.

2. The security support device according to claim 1, characterized in that the generating AI input / output means inputs a prompt to the generating AI for integrating and analyzing the cyber information and physical information collected from the CPS.

3. The security support device according to claim 1, characterized in that the generating AI input / output means analyzes the physical information and / or cyber information collected from the CPS to detect abnormal patterns, feeds back the analysis results to the generating AI, and inputs a prompt to the generating AI to propose security measures for the detected abnormal patterns.

4. The security support device according to claim 1, characterized in that the CPS integrated security measure determination means assigns priority and reliability to each of the multiple security measures output from the generating AI and notifies the CPS.

5. The security support device according to claim 1, characterized in that the CPS integrated security measure determination means notifies the recording means of and stores the CPS integrated security measure support information.

6. A cyber information collection step involves collecting cyber information regarding abnormal conditions detected in the cyberspace of a CPS in a designated area, and A physical information collection step involves collecting physical information relating to an abnormal state detected in the physical space of the CPS in the predetermined area, A cyber-physical mapping step is performed by referencing mapping information to establish a correspondence between the collected cyber information and physical information. A generation AI input / output step involves generating a prompt for a predetermined generation AI from cyber information and physical information collected and associated by the CPS, as well as input / output auxiliary information, inputting the generated prompt into the generation AI, and receiving a response from the generation AI. A CPS integrated security measure determination step in which CPS integrated security measure support information for a predetermined area is determined based on the response from the generated AI and the countermeasure support information, A recording step in which threat information, vulnerability information, and CPS integrated security support information previously detected in cyberspace and physical space in one or more areas are recorded in a recording device, A cyber-physical countermeasure separation step involves separating the CPS integrated security countermeasure support information determined by the CPS integrated security countermeasure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifying the CPS, A method for assisting computers in implementing security measures.

7. A cyber information collection step involves collecting cyber information regarding abnormal conditions detected in the cyberspace of a CPS in a designated area, and A physical information collection step involves collecting physical information relating to an abnormal state detected in the physical space of the CPS in the predetermined area, A cyber-physical mapping step is performed by referencing mapping information to establish a correspondence between the collected cyber information and physical information. A generation AI input / output step involves generating a prompt for a predetermined generation AI from cyber information and physical information collected and associated by the CPS, as well as input / output auxiliary information, inputting the generated prompt into the generation AI, and receiving a response from the generation AI. A CPS integrated security measure determination step in which CPS integrated security measure support information for a predetermined area is determined based on the response from the generated AI and the countermeasure support information, A recording step in which threat information, vulnerability information, and CPS integrated security support information previously detected in cyberspace and physical space in one or more areas are recorded in a recording device, A cyber-physical countermeasure separation step involves separating the CPS integrated security countermeasure support information determined by the CPS integrated security countermeasure determination means into cyber countermeasure information and physical countermeasure information by referring to the correspondence information and notifying the CPS, A security support program that instructs a computer to execute security measures.

Citation Information

Patent Citations

  • Electronic blackboard

    JP1988020965A

  • Security Devices

    JP6712207B2