Training environment design device, cyber training system, training environment design method and program

The exercise environment design device and system address the need for safe and rapid restoration of user environments post-cyber exercises by setting protected and recoverable storage areas, creating backup and restore programs, ensuring minimal business impact and effective cyber training.

JP2026084940APending Publication Date: 2026-05-22CHIEF OF DEFENSE EQUIP DEPT +1
View PDF 9 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CHIEF OF DEFENSE EQUIP DEPT
Filing Date
2024-11-12
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Existing cyber exercises conducted on user's normal environment require a safe and rapid way to restore the environment to its original state after the exercise without significant impact on business operations.

Method used

An exercise environment design device and system that sets storage areas for modification prevention and recovery, creates backup and restore programs for critical data, and executes these programs to ensure quick and safe restoration.

Benefits of technology

Enables safe and rapid restoration of the user's environment to its pre-exercise state, minimizing business disruption and allowing practical cyber exercises on user terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026084940000001_ABST
    Figure 2026084940000001_ABST
Patent Text Reader

Abstract

This document provides a method for configuring a training environment that can be safely and quickly restored to its original state after the completion of a cyber exercise. [Solution] The exercise environment design device includes means for setting a storage area that is prevented from being altered by cyber exercises, means for setting an area that requires recovery after cyber exercises among the storage areas that are allowed to be altered by cyber exercises, means for creating a backup program to back up the data in the area requiring recovery, and means for creating a restore program to restore the backed-up data to the area requiring recovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an exercise environment design device, a cyber exercise system, an exercise environment design method, and a program.

Background Art

[0002] With the expansion of the use of communication networks, security measures such as cyberattacks have become increasingly important. In contrast, private companies are training personnel through cyber exercises. In general cyber exercises, an exercise environment equipped with a high-quality network or the like is prepared, and a management server that manages the content of the cyber exercise often proceeds with the exercise while sequentially controlling the execution of simulated cyberattacks on the exercise terminals.

[0003] In order to conduct effective and practical exercises, it is preferable to conduct cyber exercises using the environment that the user normally uses as it is, rather than a pseudo environment prepared for the exercise. If cyber exercises are conducted using the environment that the user normally uses, it is preferable that the original environment can be quickly restored without much effort after the exercise. For example, Patent Document 1 discloses a simulator for training against cyberterrorism in nuclear power plants. Patent Document 1 describes that backup data is acquired by a backup data acquisition module before training with the simulator, and the exercise environment is restored by restoring the backup data after the training is completed. In the case of a dedicated training environment such as a simulator, performing a backup and restore of the entire system does not affect the business. However, performing a backup and restore of the entire system for the terminal that the user normally uses is not desirable because it has a great impact on the business in terms of processing time and the like.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

[0005] After a cyber exercise concludes, there is a need for a safe and rapid way to restore the environment to its original state.

[0006] Therefore, the purpose of this invention is to provide an exercise environment design device, a cyber exercise system, an exercise environment design method, and a program that solve the above-mentioned problems. [Means for solving the problem]

[0007] According to one aspect of the present invention, the exercise environment design device includes means for setting a storage area that is prevented from being modified by a cyber exercise, means for setting a storage area that is permitted to be modified by the cyber exercise and requires recovery after the cyber exercise, means for creating a backup program for backing up the data in the storage area that requires recovery, and means for creating a restore program for restoring the backed-up data to the area that requires recovery.

[0008] According to one aspect of the present invention, a cyber exercise system comprises the exercise environment design device described above and an exercise terminal for performing the cyber exercise, wherein the exercise environment design device further comprises means for transmitting the backup program and the restore program, and the exercise terminal comprises means for receiving the backup program and the restore program, means for executing the backup program, and means for executing the restore program.

[0009] According to one aspect of the present invention, the exercise environment design method includes the steps of: setting a storage area that is prevented from being modified by the cyber exercise; setting a storage area that is permitted to be modified by the cyber exercise and requires recovery after the cyber exercise; creating a backup program that backs up the data in the storage area that requires recovery; and creating a restore program that restores the backed-up data to the area that requires recovery.

[0010] According to one aspect of the present invention, the program causes a computer to perform the following steps: setting up a storage area that is prevented from being modified by a cyber exercise; setting up a storage area among the storage areas that is permitted to be modified by the cyber exercise that requires recovery after the cyber exercise; creating a backup program that backs up the data in the storage area that requires recovery; and creating a restore program that restores the backed-up data to the area that requires recovery. [Effects of the Invention]

[0011] According to the present invention, after the completion of a cyber exercise, the environment can be safely and quickly restored to its original state. [Brief explanation of the drawing]

[0012] [Figure 1] This is a block diagram of the cyber exercise system according to the embodiment. [Figure 2A] This is the first figure illustrating the region setting according to the embodiment. [Figure 2B] This is a second figure illustrating the region setting according to the embodiment. [Figure 3] This flowchart shows an example of the operation of the management server according to the embodiment. [Figure 4] This figure shows an example of the operation of a user terminal according to the embodiment. [Figure 5]This is a block diagram showing the configuration of a training environment design device with a minimum configuration. [Figure 6] This is a flowchart showing the processing of a training environment design device with a minimal configuration. [Figure 7] This figure shows an example of the hardware configuration of the cyber exercise system according to the embodiment. [Modes for carrying out the invention]

[0013] <Embodiment> A cyber exercise system according to one embodiment of the present invention will be described below with reference to the drawings. In the drawings used in the following description, the configuration of parts not related to the present invention may be omitted from the description and not shown.

[0014] (System Configuration) Figure 1 is a block diagram of a cyber exercise system according to an embodiment. As shown in Figure 1, the cyber exercise system 1 comprises a management server 10 and user terminals 20a, 20b, and 20c. The management server 10 distributes data to the user terminals 20a to 20c and the network device 30 for use in cyber exercises executed on the user terminals 20a to 20c. The user terminals 20a to 20c and the network device 30 conduct cyber exercises using the distributed data. The distributed data includes exercise scenarios, attack modules, backup scripts, restore scripts, deterrence setting scripts, deterrence setting removal scripts, environment setting scripts, and environment recovery scripts. The exercise scenario is a program configured to execute a simulated cyber attack based on a predetermined execution schedule and execution conditions. The attack module includes programs necessary for simulating cyber attacks such as malware. The exercise scenario simulates a cyber attack by calling the attack module. The backup script is a program for obtaining a backup of the data on user terminals 20a to 20c before the cyber exercise, and the restore script is a program for restoring the backup data obtained by the backup script. The deterrence setting script is a program that configures the environment to protect data, such as data that cannot be modified or important data, from access during cyber exercises. The deterrence setting deactivation script is a program that reverts the environment settings configured by the deterrence setting script. The environment configuration script is a script that configures the network and other environment settings to build a cyber exercise environment on user terminals 20a to 20c and network device 30. The environment recovery script is a program that reverts the network and other environment settings configured by the environment configuration script. In addition, the environment configuration script and environment recovery script may be configuration files defined for each product such as network device 30.In other words, network and other environment settings can be configured by replacing the default (current) configuration file with an environment configuration file, and the network and other environment settings can be restored by replacing the environment configuration file that was replaced during environment configuration with an environment recovery configuration file (returning to the original configuration file). Hereafter, these may simply be referred to as environment configuration scripts and environment recovery scripts, but these may also refer to environment configuration files and environment recovery configuration files, or environment configuration scripts and environment configuration files, and environment recovery scripts and environment recovery configuration files. User terminals 20a to 20c are terminal devices that participants in the cyber exercise normally use for work, etc. For example, user terminals 20a to 20c are personal computers (PCs), tablet terminals, smartphones, and other mobile terminals. Network device 30 is equipment such as routers and switches related to communication of user terminals 20a to 20c. The management server 10, user terminals 20a to 20c, and network device 30 are connected to each other via the network NW so that they can communicate with each other. The network (NW) may use a line with narrow bandwidth, which is prone to unstable communication conditions such as delays and interruptions.

[0015] The management server 10 comprises an input receiving unit 11, a control unit 12, a display unit 13, a storage unit 14, and a communication unit 15. The input receiving unit 11 includes input devices such as a touch panel and a keyboard, and receives operations performed by a user (for example, the administrator of a cyber exercise) using the input device, generates information corresponding to the operation, and outputs the generated information to the control unit 12.

[0016] The control unit 12 controls the operation of the management server 10 based on the operations received by the input reception unit 11. For example, the control unit 12 performs display control of the display unit 13 and communication control using the communication unit 15. The control unit 12 uses the communication unit 15 to distribute data used in the cyber exercise, transmit an execution instruction for the cyber exercise, receive logs related to the cyber exercise, etc. The control unit 12 includes an exercise scenario creation unit 121, an operation suppression area setting unit 122, a recovery target area setting unit 123, and a script creation unit 124.

[0017] The exercise scenario creation unit 121 is configured to include tools such as a development environment used for creating an exercise scenario and an attack module. For example, the exercise scenario creation unit 121 creates an exercise scenario for the cyber exercise, an attack module such as malware that simulates a cyber attack during the cyber exercise, and coping evaluation information on how to cope with a cyber attack. The exercise scenario includes, for example, information on the target of the cyber attack, such as the data and its location (path). The coping evaluation information includes, for example, the storage location (path) of the data that the exerciser should access in response to a cyber attack during the exercise, and a list of information on services that should be stopped or started.

[0018] The operation inhibition area setting unit 122 sets an operation inhibition area. Here, refer to FIG. 2A. FIG. 2A shows an overview of the operation inhibition area 100. The operation inhibition area 100 is a storage area where access is prohibited during cyber exercises. As shown in FIG. 2A, in the operation inhibition area 100, an area where files such as OS settings and existing services (software installed on the exercise terminal) and files related to the startup of the OS and recovery functions are arranged is set. For example, when the OS (operating system) of the exercise terminal for executing a cyber exercise is Linux (registered trademark), the operation inhibition area is " / bin", " / boot", " / dev", " / etc", " / lib", " / media", " / mnt", " / opt", " / sbin", " / srv", " / tmp", " / usr", " / var", etc. Also, the operation inhibition area 100 is set according to the content of the cyber exercise to be performed and the business systems installed on the user terminals 20a to 20c. For example, when the business system includes customer data, the area where the customer data is stored may be set as the operation inhibition area 100. For example, when the user designates a certain storage area (such as " / bin"), the operation inhibition area setting unit 122 records that area as the operation inhibition area 100 in the storage unit 24.

[0019] The recovery target area setting unit 123 sets the recovery target area. Figure 2A shows an overview of the recovery target area 101. The recovery target area 101 is an area where data related to the cyber exercise, such as OS settings, existing service files, and user data, is stored and needs to be restored to its original state after the exercise. Data related to the cyber exercise is data that is targeted by cyber attacks or data necessary for operations to deal with cyber attacks. Data related to the cyber exercise can be identified by analyzing the exercise scenario created by the exercise scenario creation unit 121 and attack modules such as malware. For example, a user with knowledge of the contents of the cyber exercise and the directory structure of the exercise terminals (user terminals 20a to 20c) may specify the storage area containing data that needs to be recovered from the storage area containing data related to the cyber exercise, and based on this specification, the recovery target area setting unit 123 may set the recovery target area 101 by recording the path information of the storage area containing the data that needs to be recovered in the storage unit 14. Alternatively, the recovery target area setting unit 123 may identify the storage locations of data related to the cyber exercise based on information such as the storage locations of attack target data included in the exercise scenario created by the exercise scenario creation unit 121, and the storage locations of data that the exerciser should access included in the countermeasure evaluation information, and then identify the storage locations of data that need to be recovered from among them. For example, the recovery target area setting unit 123 may identify the overlapping portion between the storage area to be recovered and the storage locations of data related to the cyber exercise as the recovery target area 101 based on definition information such as the storage locations of data that need to be recovered and the file names, directory names, and folder names of the data that need to be recovered, which have been predetermined by the user. Alternatively, it may have the user input this information interactively and identify the recovery target area 101 based on the input information.

[0020] Among the storage areas of the exercise terminal (such as user terminal 20a), the area excluding the operation suppression area 100 and the recovery target area 101 is set as the non-recovery target area 102. The outline of the non-recovery target area 102 is shown in FIG. 2A. The non-recovery target area 102 is an area where data that does not need to be recovered among files such as OS settings and existing services and user data is stored. For example, logs output by the OS or existing services, user data, and storage locations of data that are not targets of cyberattacks or countermeasure operations against cyberattacks are examples of the non-recovery target area 102. FIG. 2B shows an example of the allocation of the operation suppression area 100, the recovery target area 101, and the non-recovery target area 102 in the storage area of the user terminal 20.

[0021] The script creation unit 124 creates a suppression setting script executed before the cyber exercise, an environment setting script and / or an environment setting configuration file, a backup script, a suppression setting release script executed after the cyber exercise, an environment recovery script and / or an environment recovery configuration file, and a restore script. In the suppression setting script, a process for performing a setting to suppress (prohibit) access to the operation suppression area 100 is executed. In the backup script, a process for acquiring a backup of the data in the recovery target area 101 is executed. In the environment setting script, a process for setting the settings of the user terminal 20, the network of the network device 30, etc. for the exercise environment is executed. In the suppression setting release script, a process for releasing the access suppression (prohibition) to the operation suppression area 100 is executed. In the restore script, a process for restoring the data in the recovery target area 101 using the backed-up data is executed. In the environment recovery script, a process for restoring the settings changed by the environment setting script or resetting them to the default settings is executed.

[0022] For example, the script creation unit 124 reads the path information of the operation inhibition area 100 set by the operation inhibition area setting unit 122 from the storage unit 14, and creates a script for inhibition setting that executes a command (for example, the chmod command in the case of Linux (registered trademark)) that restricts (prohibits) reading and writing to the files and directories of the read path (access right setting). Also, for example, the script creation unit 124 makes settings such that the execution right of a command that the user is to be restricted from executing is not granted to the user (command execution right setting), or makes settings such that the change right of a system setting that the user is to be restricted from changing is not granted to the user (system setting change right setting) for a system setting for which the user's setting change is to be restricted, and creates a script. Also, in addition to these direct change prohibition operation settings, the script creation unit 124 may create a script that performs an indirect change prohibition operation setting such as hiding the setting screen or hiding the drive / folder. For example, the script creation unit 124 creates a script that executes a command (for example, the attrib command in the case of Windows (registered trademark)) that makes the operation inhibition area 100 invisible to the user authority (hiding). Further, the script creation unit 124 may create a script that presents a prohibited operation to the user and issues a warning, for example, by displaying an operation that is to be prohibited during the cyber exercise and the reason therefor on the console screen or window screen. The inhibition setting script performs data protection of the operation inhibition area 100 by performing these various settings (it is not necessary to perform all of them, and any one or a plurality of them may be sufficient). Also, the script creation unit 124 creates a script for inhibition setting release that executes a command opposite to the command described to be executed by the inhibition setting script (a command to restore the right to read and write to a file, etc., a command to解除 the hiding of a folder, etc.).

[0023] Furthermore, for example, the script creation unit 124 reads the path information of the recovery target area 101 set by the recovery target area setting unit 123 from the storage unit 14 and creates a backup script that executes a command (for example, the tar command in the case of Linux®) to back up files, etc., that exist under the read path. The script creation unit 124 also creates a restore script that extracts the archive of backup data obtained by the backup script and restores the data of the recovery target area 101 to its state before the exercise. Note that in addition to commands provided by the OS, commands provided by commercial backup software can be used for backup and restore processes.

[0024] Furthermore, the script creation unit 124 creates an environment setting script to change the settings of user terminals 20a to 20c and network devices 30 installed in the cyber exercise execution environment, and an environment recovery script to restore the settings to those before the cyber exercise. Alternatively, the script creation unit 124 may also create environment setting files and environment recovery setting files instead of / in addition to the environment setting script and environment recovery script. Network devices 30 are, for example, routers or switches installed at the location where user terminals 20a, etc., are installed. When executing a cyber exercise, a closed network including the user terminals 20 performing the cyber exercise is constructed, and the cyber exercise is carried out. For this reason, the script creation unit 124 creates an environment setting script to switch the network settings of user terminals 20a and network devices 30 to settings for the cyber exercise, and an environment recovery script to restore the settings to those before the cyber exercise. For example, the script creation unit 124 has a function to automatically create a script that changes the value of an item to a specified value when the target item and its value related to network settings are specified, and this function may be used to create the environment setting script and the environment recovery script. Similarly, the script creation unit 124 may create configuration files for environment setup and configuration files for environment recovery.

[0025] The display unit 13 includes a display device such as a liquid crystal display. Based on instructions from the control unit 12, the display unit 13 displays various information, such as logs received from user terminals 20a to 20c. The memory unit 14 is composed of storage media such as RAM (Random Access Memory), ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), HDD (Hard Disk Drive), and SSD (Solid State Drive), and stores various types of information. The communication unit 15 is configured using a communication module and communicates with other devices such as user terminals 20a to 20c. For example, the communication unit 15 transmits exercise scenarios created by the exercise scenario creation unit 121 and various scripts created by the script creation unit 124 to user terminals 20a to 20c and the network device 30. In addition to being distributed to user terminals 20a to 20c and the network device 30 by transmission from the communication unit 15, the various scripts may also be distributed via portable storage media PM such as USB. For example, before the environment setup script is executed on user terminals 20a to 20c and the network device 30 to build the network environment for the exercise, each device may not be able to communicate with the management server 10. In such cases, the management server 10 distributes various scripts to user terminals 20a to 20c and the network device 30 using portable storage media PM.

[0026] The user terminal 20a comprises an input receiving unit 21a, a control unit 22a, a display unit 23a, a storage unit 24a, and a communication unit 25a. The input receiving unit 21a is configured to include input devices and input interfaces such as a touch panel and a keyboard, and receives operations performed by exercise participants using these input devices, generates information corresponding to the operations, and outputs the generated information to the control unit 22a. For example, if a suppression setting script, an environment setting script and / or an environment setting configuration file, a backup script, a suppression setting release script, a restore script, an environment recovery script and / or an environment recovery configuration file are distributed using a portable storage medium PM, the input receiving unit 21a receives an operation by the user to copy the various scripts from the portable storage medium PM, and copies the various scripts stored on the portable storage medium PM from the portable storage medium PM to the storage unit 24a.

[0027] The control unit 22a controls the operation of the user terminal 20a based on the operation received by the input reception unit 21a. For example, the control unit 22a controls the display of the display unit 23a and controls communication using the communication unit 25a. The control unit 22a also executes exercise scenarios, suppression setting scripts, backup scripts, suppression setting release scripts, restore scripts, environment setting scripts, and environment recovery scripts distributed from the management server 10. Alternatively, the control unit 22a replaces the original configuration file with an environment setting file or reverts it to an environment recovery configuration file.

[0028] The display unit 23a includes a display device such as a liquid crystal display. The display unit 23a displays information based on instructions from the control unit 22a. The memory unit 24a is composed of storage media such as RAM, ROM, EEPROM, HDD, and SSD, and stores various information such as exercise scenarios. The communication unit 25a is configured using a communication module and communicates with other devices such as the management server 10 and user terminals 20b to 20c. For example, the communication unit 25a receives exercise scenarios, suppression setting scripts, environment setting scripts and / or configuration files for environment settings, backup scripts, suppression setting release scripts, environment recovery scripts and / or configuration files for environment recovery, restore scripts, etc., from the management server 10.

[0029] The configurations of user terminals 20b and 20c are the same as those of user terminal 20a, so their illustrations and descriptions are omitted. When it is not necessary to distinguish between user terminals 20a to 20c, they are referred to as user terminal 20, and each functional unit may be described as input reception unit 21, control unit 22, display unit 23, storage unit 24, communication unit 25, etc. Also, user terminal 20 may be referred to as the exercise terminal. In the cyber exercise system 1 shown in Figure 1, there are three user terminals, but there may be two or fewer user terminals 20, or four or more. Furthermore, the cyber exercise system 1 may have multiple management servers 10.

[0030] (operation) Next, with reference to Figure 3, the preparation process for the cyber exercise in the management server 10 will be described. Figure 3 is a flowchart showing an example of the operation of the management server according to the embodiment.

[0031] First, the input reception unit 11 acquires information about the OS and business system of the exercise terminal (step S1). The cyber exercise administrator inputs information about the OS and business system of the user terminal 20, such as the storage location of data related to the OS and business system in the storage area of ​​the user terminal 20, the characteristics of the business system, processing content, and vulnerabilities, into the management server 10. The input reception unit 11 acquires the input information and records it in the storage unit 14. For example, the administrator may input path information for the operation suppression area 100 and the recovery target area 101. Next, the administrator designs the content of the cyber exercise (step S2). The attack content of the cyber exercise is designed by collecting information on the characteristics and vulnerabilities of the OS, existing services, and business systems. Next, the administrator creates exercise scenarios and cyber exercise attack modules based on the designed exercise content (step S3). For example, the exercise scenario creation unit 121 is a tool that supports the creation of programs such as exercise scenarios and attack modules, and the administrator uses the exercise scenario creation unit 121 to create exercise scenarios and attack modules.

[0032] In parallel with this, the administrator considers the settings for the training terminals, network devices, etc. (Step S4), and inputs the network configuration information for the training and the network configuration information before the training into the management server 10. The script creation unit 124 creates environment setup scripts and environment recovery scripts for the user terminals 20 and network devices 30 (Step S5). The script creation unit 124 records the created environment setup scripts and environment recovery scripts in the storage unit 14.

[0033] Next, the operation suppression area setting unit 122 sets the operation suppression area 100 (step S6). For example, the operation suppression area setting unit 122 sets the operation suppression area 100 in the storage unit 14 based on the path information of the operation suppression area 100 entered in step S1. Next, the script creation unit 124 creates a script for setting suppression and a script for releasing suppression (step S7). The script creation unit 124 records the created script for setting suppression and script for releasing suppression in the storage unit 14.

[0034] Next, the recovery target area setting unit 123 sets the recovery target area 101 (step S8). For example, the recovery target area setting unit 123 sets the recovery target area 101 in the storage unit 14 based on the path information of the recovery target area 101 entered in step S1. Then, the script creation unit 124 creates a backup script and a restore script for the recovery target area 101 (step S9). The script creation unit 124 records the created backup script and restore script in the storage unit 14.

[0035] Next, the control unit 12 archives the exercise scenarios and attack modules created by the exercise scenario creation unit 121, as well as the deterrence setting scripts, deterrence setting deactivation scripts, environment setting scripts, environment recovery scripts, backup scripts, and restore scripts created by the script creation unit 124 (step S10). The control unit 12 archives and encrypts each of the above files. The control unit 12 also archives and encrypts the network setting scripts and network environment recovery scripts for the network device 30.

[0036] Next, the control unit 12 distributes the archive containing the encrypted exercise scenarios, etc., to the user terminal 20 and the network device 30 (step S11). For example, the control unit 12 uses the communication unit 15 to transmit the archive containing the encrypted exercise scenarios, etc., to the user terminal 20 and the network device 30. At the user terminal 20, the control unit 22 retrieves the transmitted archive via the communication unit 25 and records it in the storage unit 24. Alternatively, if the management server 10 and the user terminal 20 are not connected via the network NW, or if communication is unstable, the control unit 12 may copy the archive containing the exercise scenarios, etc., to a portable storage medium PM and distribute the archive to the user terminal 20, etc., using the portable storage medium PM. At the user terminal 20, the user's operation causes the control unit 22 to copy the archive stored in the portable storage medium PM to the storage unit 24. The control unit 22 decrypts and extracts the archive stored in the storage unit 24. In the memory unit 24, the exercise scenario, attack module, environment setup script, environment recovery script, deterrence setting script, deterrence setting removal script, backup script, and restore script are placed in designated locations. In the network device 30, the archive is received, decrypted, and extracted, and the environment setup script and environment recovery script are placed in designated locations in the memory unit (storage area) of the network device 30.

[0037] Next, with reference to Figure 4, the backup process before the cyber exercise and the restore process after the cyber exercise on the user terminal 20 will be described. Figure 4 is a diagram showing an example of the operation of the exercise terminal according to the embodiment. Figure 4 shows a flowchart 200 of the process executed before the start of the cyber exercise and a flowchart 300 of the process executed after the end of the cyber exercise.

[0038] Referring to the flowchart 200 in Figure 4, the processing before the start of the cyber exercise will be explained. First, the control unit 22 performs backup processing (step S21). Based on the user's instructions, the control unit 22 executes a backup script stored in the storage unit 24. This backs up the data in the recovery target area 101. The backup data is saved in a predetermined location in the storage unit 24 or on a portable storage medium PM such as a USB memory. Next, the control unit 22 performs operation suppression setting processing (step S22). Based on the user's instructions, the control unit 22 executes a suppression setting script stored in the storage unit 24. This restricts access to the operation suppression area 100 and protects the data in the operation suppression area 100.

[0039] When the process shown in flowchart 200 is executed, the control unit 22 executes the exercise scenario stored in the memory unit 24 based on the user's instructions. This executes the cyber exercise. When the cyber exercise is completed, the process shown in flowchart 300 is executed.

[0040] Referring to the flowchart 300 in Figure 4, the processing after the cyber exercise is completed will be explained. First, the control unit 22 executes the operation suppression setting release process (step S31). Based on the user's instructions, the control unit 22 executes the suppression setting release script stored in the memory unit 24. This releases the access restriction to the operation suppression area 100, returning it to the state before the exercise. Next, the control unit 22 executes the restore process (step S32). Based on the user's instructions, the control unit 22 executes the restore script stored in the memory unit 24. This restores the data in the recovery target area 101 to the state before the cyber exercise. Next, the user performs a check process (step S33). For example, the user checks the data in the recovery target area 101 to confirm that the data in the recovery target area 101 has returned to the state before the exercise and that there are no abnormalities in the data. Also, for example, the user executes a command to check the access rights to the operation suppression area 100 to confirm that access is possible. Next, the user restarts the OS and initializes the processes (step S34). This restores the user terminal 20 to the environment in which it normally performs its work. Although not shown in the diagram, a configuration script is executed on the network device 30 before the start of the cyber exercise. After the cyber exercise ends, a recovery script is executed. Additionally, if necessary, a configuration script is executed on the user terminal 20 before the start of the cyber exercise, and a recovery script is executed after the cyber exercise ends.

[0041] (effect) As described above, according to the cyber exercise system 1 of this embodiment, an operation suppression process is performed by executing a suppression setting script on the operation suppression area 100 before the cyber exercise. This prevents the cyber exercise from adversely affecting the OS or business systems used for normal operations. Furthermore, by executing a suppression setting release script after the cyber exercise, access rights to the operation suppression area 100 can be quickly restored to the state before the exercise. In addition, according to this embodiment, a recovery target area 101 is set, the data in the recovery target area 101 is backed up before the cyber exercise, and restored after the exercise. This ensures that even if a cyber exercise is performed using a user terminal 20 used for normal operations, the environment of the user terminal 20 can be reliably restored to the state before the cyber exercise after the exercise. In particular, areas that do not need to be accessed during the cyber exercise are set as the operation suppression area 100, and backup and restore are limited to areas that need to be accessed for the cyber exercise and need to be restored to the state before the exercise (recovery target area 101) based on the content of the cyber exercise. This reduces the amount of data to be backed up and restored, and suppresses the processing time required for backup and restore. Therefore, after the cyber exercise is completed, the environment of the user terminal 20 can be quickly recovered to its state before the exercise. Consequently, even if the cyber exercise is conducted using the user terminal 20 that is normally used for work, the user can quickly return to their normal work. In other words, according to this embodiment, the environment can be restored safely and quickly, so those involved in the cyber exercise can rest assured that the user (exercise participant) can conduct the cyber exercise using the terminal that they normally use for work. This makes it possible to conduct practical and effective cyber exercises that cannot be performed in a simulated exercise environment. Furthermore, with the method of this embodiment, if the exercise scenario and various scripts can be distributed to the user terminal 20, even if communication with the management server 10 is interrupted, backup and operation suppression settings, cyber exercise, restore and release of operation suppression settings can be performed independently on the user terminal 20 side, so the cyber exercise can be conducted regardless of the user's communication environment.

[0042] (Minimum configuration) Figure 5 is a block diagram showing the configuration of a training environment design device with a minimum setup. The exercise environment design device 40 includes an operation suppression area setting means 41, a recovery target area setting means 42, a backup program creation means 43, and a restore program creation means 44. The operation suppression area setting means 41 sets a storage area that is suppressed from being modified by the execution of a cyber exercise. The recovery target area setting means 42 sets a storage area that is allowed to be modified by the execution of a cyber exercise and that requires recovery after the exercise. The backup program creation means 43 creates a backup program (backup script) that backs up the data in the area that requires recovery. The restore program creation means 44 creates a restore program (restore script) that restores the backed-up data to the area that requires recovery.

[0043] Figure 6 is a flowchart showing the processing of a training environment design device with a minimal configuration. The operation suppression area setting means 41 sets the operation suppression area 100 (step S41). Next, the recovery target area setting means 42 sets the recovery target area 101 (step S42). Next, the backup program creation means 43 creates a backup program (step S43). The restore program creation means 44 creates a restore program (step S44).

[0044] Figure 7 shows an example of the hardware configuration of the cyber exercise system according to the embodiment. Computer 900 is, for example, a PC (Personal Computer) or server terminal device equipped with a CPU 901, main memory 902, auxiliary memory 903, input / output interface 904, and communication interface 905. The management server 10, user terminal 20, and network device 30 mentioned above are implemented in computer 900. The processes described above are stored in auxiliary memory 903 in the form of programs. The CPU 901 reads the program from auxiliary memory 903, expands it into main memory 902, and executes the above processes according to the program. The CPU 901 also allocates memory space in main memory 902 according to the program. The CPU 901 also allocates memory space in auxiliary memory 903 to store data being processed according to the program.

[0045] In at least one embodiment, the auxiliary storage device 903 is an example of a non-temporary tangible medium. Other examples of non-temporary tangible media include magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, semiconductor memory, etc., connected via the input / output interface 904. Furthermore, if this program is distributed to the computer 900 via a communication line, the computer 900 that receives the program may expand it into the main memory 902 and execute the above processing. The program may also be for the purpose of realizing some of the functions described above. Moreover, the program may be a so-called differential file (differential program) that realizes the above-mentioned functions in combination with other programs already stored in the auxiliary storage device 903.

[0046] Although one embodiment of this invention has been described in detail above with reference to the drawings, the specific configuration is not limited to that described above, and various design changes can be made without departing from the spirit of this invention. Furthermore, one aspect of the present invention can be modified in various ways within the scope of the claims, and embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. In addition, configurations in which elements described in the above embodiments and modifications are replaced with elements that produce similar effects are also included.

[0047] Some or all of the above embodiments may be described as follows, but are not limited to the following:

[0048] (Note 1) An exercise environment design device comprising: means for setting a storage area that is prevented from being altered by a cyber exercise; means for setting an area of ​​the storage area that is permitted to be altered by the cyber exercise and requires recovery after the cyber exercise; means for creating a backup program for backing up the data in the area requiring recovery; and means for creating a restore program for restoring the backed-up data to the area requiring recovery.

[0049] (Note 2) The exercise environment design apparatus described in Appendix 1 further comprises: means for creating a program that configures to suppress access to the storage area that is prevented from being modified; and means for creating a program that removes the restriction on access to the storage area that is prevented from being modified.

[0050] (Note 3) The exercise environment design apparatus according to Appendix 1 or Appendix 2 further comprises means for creating a program that configures the storage area to be prevented from being modified, and means for creating a program that removes the concealment of the storage area to be prevented from being modified.

[0051] (Note 4) An exercise environment design device according to any one of Appendix 1 to Appendix 3, further comprising means for setting the content of the cyber exercise, wherein means for setting the area requiring recovery sets the area requiring recovery from the storage area based on the content of the exercise.

[0052] (Note 5) A cyber exercise system comprising: an exercise environment design device described in any one of Appendix 1 to Appendix 4; and an exercise terminal for performing the cyber exercise, wherein the exercise environment design device further comprises means for distributing the backup program and the restore program; and the exercise terminal comprises means for acquiring the backup program and the restore program, means for executing the backup program, and means for executing the restore program.

[0053] (Note 6) A method for designing an exercise environment, comprising the steps of: setting up a storage area that is prevented from being modified by the cyber exercise; setting up an area among the storage areas that is allowed to be modified by the cyber exercise that requires recovery after the cyber exercise; creating a backup program to back up the data in the area that requires recovery; and creating a restore program to restore the backed-up data to the area that requires recovery.

[0054] (Note 7) A program that causes a computer to perform the following steps: setting up a storage area that is prevented from being modified by a cyber exercise; setting up an area within the storage area that is allowed to be modified by the cyber exercise and that requires recovery after the cyber exercise; creating a backup program to back up the data in the area that requires recovery; and creating a restore program to restore the backed-up data to the area that requires recovery. [Explanation of symbols]

[0055] 1. Cyber ​​Exercise System 10. Management Server 11. Input Reception Section 12. Control Unit 121... Exercise Scenario Creation Department 122...Operation suppression area setting section 123...Setting the area to be recovered 124...Script Creation Department 13...Display section 14...Storage section 15. Communications Department 20, 20a, 20b, 20c... User terminals 21,21a...Input reception section 22,22a...nursing care 23,23a...Display section 24,24a...Storage section 25,25a...Communication Department 30. Network devices 900... Computer 901···CPU 902...Main memory 903...Auxiliary storage device 904... Input / Output Interface 905...Communication Interface

Claims

1. A means of setting up a storage area that is prevented from being altered by cyber exercises, A means for setting out a storage area that is permitted to be modified by the cyber exercise and which requires recovery after the cyber exercise, Means for creating a backup program that backs up the data in the area requiring recovery, Means for creating a restore program to restore the backed-up data to the area requiring recovery, A training environment design device equipped with the following features.

2. A means for creating a program that configures settings to suppress access to the storage area that is prevented from being modified, Means for creating a program that removes the access restriction to the storage area that prevents the aforementioned modification, The exercise environment design apparatus according to claim 1, further comprising:

3. A means for creating a program that configures the storage area to conceal the aforementioned modification, Means for creating a program that removes the concealment of the storage area that prevents the aforementioned modification, The exercise environment design apparatus according to claim 1 or claim 2, further comprising:

4. The system further comprises means for setting the content of the cyber exercise, The means for setting the area requiring recovery sets the area requiring recovery from the storage area based on the exercise content. The exercise environment design apparatus according to claim 1 or claim 2.

5. The training environment design device according to claim 1 or claim 2, The training terminal for executing the aforementioned cyber exercise, Equipped with, The aforementioned training environment design device, means for distributing the backup program and the restore program, Furthermore, The aforementioned training terminal is Means for obtaining the backup program and the restore program, Means for executing the aforementioned backup program, Means for executing the restore program, A cyber exercise system equipped with the following features.

6. Steps include setting up a storage area that will be prevented from being altered by cyber exercises, The steps include: setting a storage area that is permitted to be modified by the cyber exercise and which requires recovery after the cyber exercise; The steps include creating a backup program to back up the data in the area requiring recovery, The steps include creating a restore program to restore the backed-up data to the area requiring recovery, A method for designing an exercise environment that includes the following.

7. On the computer, Steps include setting up a storage area that will be prevented from being altered by cyber exercises, The steps include: setting a storage area that is permitted to be modified by the cyber exercise and which requires recovery after the cyber exercise; The steps include creating a backup program to back up the data in the area requiring recovery, The steps include creating a restore program to restore the backed-up data to the area requiring recovery, A program that executes the command.