Cyber ​​exercise system, cyber exercise execution method, and program

The cyber exercise system dynamically adjusts exercise difficulty based on participant proficiency, addressing the challenge of uniform content in existing systems by evaluating and controlling scenarios to match individual skill levels, ensuring effective training across devices.

JP2026084963AActive Publication Date: 2026-05-22CHIEF OF DEFENSE EQUIP DEPT +1
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CHIEF OF DEFENSE EQUIP DEPT
Filing Date
2024-11-12
Publication Date
2026-05-22

Smart Images

  • Figure 2026084963000001_ABST
    Figure 2026084963000001_ABST
Patent Text Reader

Abstract

We provide training terminals that offer training content tailored to the skill level of the training participants. [Solution] The training terminal comprises a training scenario, which is a program configured to simulate cyberattacks according to the proficiency level of the training participants; means for controlling the execution of the training scenario; and means for evaluating the response to the simulated cyberattacks during the execution of the training scenario. The evaluation means determines the proficiency level based on the evaluation results, and the execution control means controls the training scenario to simulate cyberattacks according to the determined proficiency level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an exercise terminal, a cyber exercise system, a cyber exercise execution method, and a program.

Background Art

[0002] With the expansion of the use of communication networks, security measures such as cyberattacks have become increasingly important. In response, private companies are training personnel through cyber exercises. In general cyber exercises, an exercise environment equipped with a high-quality network or the like is prepared, and a management server that manages the content of the cyber exercise often advances the exercise while sequentially controlling the execution of simulated cyberattacks on the exercise terminal.

[0003] In such general cyber exercises, the proficiency (skill level) of exercise participants is uniformly managed, and a cyber exercise suitable for the proficiency set before the start of the exercise is often carried out. For example, Patent Document 1 discloses a training system in which a training target is set in an exercise scenario and the scenario is repeatedly executed until the proficiency of the exercise participants reaches the training target. However, skills related to cyber security vary among individuals, and in order to conduct an effective exercise, it is necessary to conduct an exercise tailored to an individual's skills. In the case of a general cyber exercise system, even if it is found that the level of the exercise content is too low or too high after actually starting the cyber exercise, in order to conduct an exercise suitable for the skills, it is necessary to reconfigure the exercise environment by re-setting the content of the cyber exercise or distributing additional data.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] There is a need for methods to conduct cyber exercises that are tailored to the skill levels of the exercise participants.

[0006] Therefore, the purpose of this invention is to provide an exercise terminal, a cyber exercise system, a method for executing a cyber exercise, and a program that solve the above-mentioned problems. [Means for solving the problem]

[0007] According to one aspect of the present invention, the training terminal comprises a training scenario configured to simulate a cyberattack corresponding to the proficiency level of the training participants, means for controlling the execution of the training scenario, and means for evaluating the response to the simulated cyberattack during the execution of the training scenario. The means for performing the evaluation determines the proficiency level based on the results of the evaluation, and the means for controlling the execution controls the training scenario to simulate a cyberattack corresponding to the proficiency level based on the determined proficiency level.

[0008] According to one aspect of the present invention, the cyber exercise system comprises a first exercise terminal and a second exercise terminal, wherein the first exercise terminal comprises an exercise scenario configured to simulate a cyber attack on the second exercise terminal according to the proficiency level and means for transmitting the proficiency level to the second exercise terminal before simulating the cyber attack on the second exercise terminal, and the second exercise terminal comprises means for receiving the proficiency level from the first exercise terminal and an exercise scenario configured to perform a preparatory process for receiving the cyber attack from the first exercise terminal according to the proficiency level received from the first exercise terminal.

[0009] According to one aspect of the present invention, a cyber exercise execution method includes the steps of: executing an exercise scenario configured to simulate a cyber attack corresponding to the proficiency level of the exercise participants; evaluating the response to the simulated cyber attack during the execution of the exercise scenario; determining the proficiency level based on the results of the evaluation; and controlling the exercise scenario to simulate the cyber attack corresponding to the proficiency level based on the determined proficiency level.

[0010] According to one aspect of the present invention, the program causes a computer to perform the following steps: execute an exercise scenario configured to simulate a cyberattack corresponding to the proficiency level of the exercise participants; evaluate the response to the simulated cyberattack during the execution of the exercise scenario; determine the proficiency level based on the results of the evaluation; and control the exercise scenario to simulate the cyberattack corresponding to the proficiency level based on the determined proficiency level. [Effects of the Invention]

[0011] According to the present invention, it is possible to provide exercise content tailored to the skill level of the exercise participants. [Brief explanation of the drawing]

[0012] [Figure 1] This is a block diagram of the cyber exercise system according to the embodiment. [Figure 2A] This figure shows an example of an exercise scenario according to the embodiment. [Figure 2B] This is the first figure showing an example of executing an exercise scenario according to the embodiment. [Figure 2C] This is the second figure, which shows an example of executing an exercise scenario according to the embodiment. [Figure 3] This flowchart shows an example of proficiency calculation and log sharing processing during a cyber exercise according to the embodiment. [Figure 4] This figure shows an example of evaluation criteria in the proficiency assessment according to the embodiment. [Figure 5]This is a block diagram showing the configuration of a training terminal with a minimum setup. [Figure 6] This flowchart shows the processing of an exercise terminal with a minimal configuration. [Figure 7] This figure shows an example of the hardware configuration of the cyber exercise system according to the embodiment. [Modes for carrying out the invention]

[0013] <Embodiment> A cyber exercise system according to one embodiment of the present invention will be described below with reference to the drawings. In the drawings used in the following description, the configuration of parts not related to the present invention may be omitted from the description and not shown.

[0014] (System Configuration) Figure 1 is a block diagram of a cyber exercise system according to an embodiment. As shown in Figure 1, the cyber exercise system 1 comprises a management server 10 and user terminals 20a, 20b, and 20c. The management server 10 manages and controls the cyber exercises performed on user terminals 20a to 20c. For example, the management server 10 creates exercise scenarios for the cyber exercises performed on user terminals 20a to 20c, distributes the created exercise scenarios to user terminals 20a to 20c, and monitors the execution of the exercise scenarios. User terminals 20a to 20c are terminal devices that participants in the cyber exercise normally use for work or other purposes. For example, user terminals 20a to 20c are personal computers (PCs), tablet terminals, smartphones, and other mobile devices. The management server 10 and user terminals 20a to 20c are connected via a network NW. The network NW may use a line with narrow bandwidth that is prone to unstable communication conditions such as communication delays and interruptions.

[0015] The management server 10 comprises an input receiving unit 11, a control unit 12, a display unit 13, a storage unit 14, and a communication unit 15. The input reception unit 11 is configured to include an input device such as a touch panel, a hardware button, or a keyboard. It receives an operation performed by the user using the input device, generates information corresponding to the operation, and outputs the generated information to the control unit 12. Based on the operation received by the input reception unit 11, the control unit 12 creates and distributes an exercise scenario. For example, the exercise scenario is a plurality of program groups configured to simulate a cyber attack. The control unit 12 includes a cyber exercise evaluation unit 121 and a log collection unit 122. The log collection unit 122 receives the execution logs of the cyber exercise transmitted from the user terminals 20a to 20c and records them in the storage unit 14. The cyber exercise evaluation unit 121 reads out the execution logs recorded in the storage unit 14 and evaluates the cyber exercise performed on the user terminals 20a to 20c. Also, the control unit 12 performs display control of the display unit 13 and communication control using the communication unit 15. For example, the control unit 12 obtains the execution logs of the cyber exercise, the proficiency of the exercise participants, etc. from the user terminals 20a to 20c using the communication unit 15. The display unit 13 is configured to include a display device such as a liquid crystal display. The display unit 13 displays information such as the evaluation result of the cyber exercise based on the instruction of the control unit 12. The storage unit 14 is composed of storage media such as RAM (Random Access Memory), ROM (Read Only Memory), EEPROM (Electrically Erasable Programmable Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc., and stores various information such as exercise scenarios. The communication unit 15 is configured using a communication module and communicates with other devices such as the user terminals 20a to 20c.

[0016] The user terminal 20a includes an input reception unit 21a, a control unit 22a, a display unit 23a, a storage unit 24a, and a communication unit 25a. The input reception unit 21a is configured to include input devices such as a touch panel, hardware buttons, and a keyboard. It receives operations performed by the exercise participants using these input devices, generates information corresponding to the operations, and outputs the generated information to the control unit 22a.

[0017] The control unit 22a controls the operation of the user terminal 20a based on operations received by the input reception unit 21a and the like. For example, the control unit 22a executes various processes (such as stopping a dangerous process) based on the operations performed by the user to cope with simulated cyber attacks based on the exercise scenario. In addition, the control unit 22a performs display control of the display unit 23a and communication control using the communication unit 25a. For example, the control unit 22a uses the communication unit 25a to transmit the proficiency level of the exercise participants to the user terminals 20b and 20c, and shares the proficiency level among the participating terminals of the exercise participants. By sharing the proficiency level as described later, an exercise of a cyber attack involving multiple devices is realized. Also, the control unit 22a uses the communication unit 25a to transmit the proficiency level of the exercise participants and the execution log of the cyber exercise to the management server 10.

[0018] Furthermore, the control unit 22a includes an exercise scenario control unit 221a, a log collection and distribution unit 222a, and a proficiency determination unit 223a. The exercise scenario control unit 221a controls the execution of exercise scenarios distributed from the management server 10. The exercise scenario is configured to simulate a cyberattack according to a predetermined scenario that defines when, to which target, and what kind of cyberattack to execute. The exercise scenario control unit 221a executes the exercise scenario while providing the information necessary for the scenario's execution. For example, as the exercise scenario progresses, the exercise scenario control unit 221a provides the exercise scenario with the proficiency level of the exercise participants estimated from previous exercises, and controls the execution of the exercise scenario to simulate a cyberattack appropriate to the proficiency level of the exercise participants. The proficiency determination unit 223a evaluates how the exercise participants dealt with cyberattacks during the execution of the exercise scenario and determines the proficiency level of the exercise participants. The exercise scenario control unit 221a switches the exercise level according to the proficiency level of the exercise participants and controls the exercise scenario to execute a cyber exercise appropriate to the proficiency level of the exercise participants. The log collection and distribution unit 222a records the execution status of the exercise scenario, the results of the proficiency assessment by the proficiency assessment unit 223a, and other information as logs in the storage unit 24a.

[0019] The display unit 23a includes a display device such as a liquid crystal display. The display unit 23a displays information based on instructions from the control unit 22a. The memory unit 24a is composed of storage media such as RAM, ROM, EEPROM, HDD, and SSD, and stores various information such as exercise scenarios. The communication unit 25a is configured using a communication module and communicates with other devices such as the management server 10 and user terminals 20b to 20c.

[0020] The configurations of user terminals 20b and 20c are the same as those of user terminal 20a, so their illustrations and descriptions are omitted. For example, user terminal 20b scores the cyber exercises performed on user terminal 20b and sends the scoring results to user terminals 20a, 20c, and the management server 10. The same applies to user terminal 20c. Hereafter, when it is not necessary to distinguish between user terminals 20a to 20c, they will be referred to as user terminal 20, and each functional unit will be referred to as input reception unit 21, control unit 22, exercise scenario control unit 221, log collection / distribution unit 222, proficiency determination unit 223, display unit 23, storage unit 24, communication unit 25, etc. In the cyber exercise system 1 shown in Figure 1, there are three user terminals, but there may be two or fewer user terminals 20, or four or more. Also, the cyber exercise system 1 may have multiple management servers 10.

[0021] (operation) Next, referring to Figures 2A to 2C, we will explain the control system that determines the user's proficiency level during the exercise and dynamically changes the exercise content according to that level. Figure 2A shows an example of the control flow of an exercise scenario. The exercise scenario illustrated in Figure 2A first simulates a cyberattack of "intrusion" into the exercise terminal (S01), and based on the evaluation results of the response to the "intrusion," it is configured to simulate one of the following cyberattacks as the next attack: "information gathering," "information exfiltration," or "lateral deployment to other terminals." Specifically, if the evaluation results show that the proficiency of the exercise participants is "low," "information gathering" is executed (S02); if it is "medium," "information exfiltration" is executed (S03); and if it is "high," "lateral deployment to other terminals" is executed (S04). In other words, the exercise scenario is designed this way because dealing with "information exfiltration" is more difficult than dealing with "information gathering," and dealing with "lateral deployment to other terminals" requires more proficiency than dealing with "information exfiltration." Other examples of cyberattacks tailored to skill levels include, for instance, in attacks that spread laterally over a network, increasing the number of target terminals as skill level increases. For example, a low-skill level might target one terminal, while a high-skill level might target 100. Alternatively, as skill level increases from low to medium to high, attacking other training terminals could become more sophisticated (less noticeable). Furthermore, in the case of attacks that tamper with local data, such as manipulating the user terminal's location information, a low-skill level might change the location information of user terminal 20 (if it's in Tokyo) to Osaka, while a high-skill level might shift the location information by a few meters from its current location. Finally, in software manipulation attacks, a low-skill level might install custom-named software on the target terminal and manipulate it, while a high-skill level might target standard OS services.

[0022] Figure 2B shows the control of the cyber exercise system 1 when the exercise scenario executed on user terminal 20a performs an "intrusion." In Figure 2B and Figure 2C described later, user terminal 20c is not shown, but user terminal 20c may be the same as user terminal 20b. First, the management server 10 distributes information such as the exercise scenario exemplified in Figure 2A and the evaluation criteria for the simulated cyber attack executed in the exercise scenario to user terminals 20a and 20b (S1). The control units 22a and 22b acquire the distributed exercise scenario and other information through the communication units 25a and 25b and register them in the storage units 24a and 24b, respectively.

[0023] On the user terminal 20a, the exercise scenario control unit 221a executes the exercise scenario based on the actions of the exercise participant. Based on the exercise scenario, the exercise scenario control unit 221a simulates a cyberattack "intrusion" at a predetermined timing after the start of the exercise scenario (S2). The log collection and distribution unit 222a records the time the "intrusion" was executed and its execution result (e.g., success or failure) as an execution log in the storage unit 24a (S3). The exercise participant takes action against this attack (S4). For example, the exercise participant may disconnect the communication cable from the user terminal 20A or stop network services. What constitutes a correct response to the "intrusion" is predetermined in the evaluation criteria distributed from the management server 10. When the exercise participant takes the correct action, the exercise scenario control unit 221a records the result of that action (e.g., the action performed and the time it was performed) in the execution log (S5). The proficiency determination unit 223a of the control unit 22a determines the proficiency level of the exercise participant based on the result of their response to the "intrusion". Specifically, the proficiency determination unit 223a measures the time it takes for the exercise participant to take the correct action after the "intrusion" is executed, and determines the proficiency level based on the measured time (the shorter the time taken to take action, the higher the proficiency level). The proficiency determination unit 223a notifies the exercise scenario control unit 221a and the user terminal 20b of the proficiency determination result (S6a, S6b). In addition, the log collection and distribution unit 222a sends the execution log related to the "intrusion" (for example, the execution of the "intrusion" and its execution time, the content of the action taken and the execution time of the action) and the proficiency determination result to the management server 10 (S7). On the management server 10, the cyber exercise evaluation unit 121 displays the contents of the execution log on the display unit 13, and the cyber exercise administrator monitors the progress of the cyber exercise, the success or failure of the cyber attack, and whether the exercise participants are taking appropriate action.

[0024] Furthermore, the exercise scenario control unit 221a, having acquired the proficiency assessment result, determines the next cyberattack to be executed based on the proficiency assessment result and the control flow in Figure 2A, and simulates the determined cyberattack at the timing specified in the exercise scenario. Meanwhile, on the user terminal 20b, the exercise scenario control unit 221b within the control unit 22b prepares for the next cyberattack to be simulated on the user terminal 20a (if necessary) based on the proficiency level transmitted from the user terminal 20a. For example, the exercise scenario distributed to the user terminal 20b includes a scenario for a cyberattack to be executed on the user terminal 20b, as well as a scenario in which, if the proficiency level of the exercise participant on the user terminal 20a is "high," the user terminal 20b becomes the target of an attack from the user terminal 20a, regardless of the proficiency level of the exercise participant on the user terminal 20b. In addition, this exercise scenario is configured to perform necessary preparatory processing in advance when attacked from another terminal. Based on such an exercise scenario, the exercise scenario control unit 221b performs simulation or preparatory processing for the next cyberattack to be executed on the user terminal 20b. Specifically, if the user terminal 20a's proficiency level is assessed as "low" or "medium," the next cyberattack simulated on user terminal 20a ("information gathering" and "information exfiltration," respectively) will target user terminal 20a. Therefore, the exercise scenario control unit 221b controls the execution of the exercise scenario to simulate a cyberattack targeting its own terminal (user terminal 20b). However, if the user terminal 20a's proficiency level is assessed as "high," the next cyberattack simulated on user terminal 20a will be "lateral deployment to other terminals," and user terminal 20b will be the terminal targeted by the attack. Therefore, the exercise scenario control unit 221b prepares for the next attack by creating vulnerabilities in user terminal 20b based on the exercise scenario (for example, by opening network ports used in the attack) so that a simulated cyberattack can be executed from user terminal 20a (so that the cyber exercise can be conducted smoothly).

[0025] In the exercise scenario shown in Figure 2A, when the proficiency level of user terminal 20a reaches "high," the scenario is structured so that an attack is launched against another terminal (user terminal 20b) rather than against the user terminal 20a itself. This is because the purpose of this scenario is to train the participant on user terminal 20a to consider not only the impact of a cyberattack on their own terminal, but also the impact on other user terminals 20b (for example, within the same team). This exercise scenario is just one example; the scenario may be structured to simulate a more difficult cyberattack on the user's own terminal when the proficiency level reaches "high," or to simulate a cyberattack on another terminal even when the proficiency level is "low."

[0026] If the proficiency level assessment result is "low" or "medium," the exercise scenario control unit 221a provides the proficiency level assessment result to the exercise scenario and executes the exercise scenario to simulate "information gathering" or "information extraction." In this case, only the content of S2 in Figure 2B changes from "intrusion" to "information gathering" or "information extraction," and the same control as described above with reference to Figure 2B is executed again.

[0027] If the proficiency level calculation result is "high," the exercise scenario control unit 221a assigns the "high" proficiency level to the exercise scenario, executes the exercise scenario, and simulates "lateral deployment to other terminals (for example, intrusion into user terminal 20b)." In this case, the control shown in Figure 2C is executed. First, on user terminal 20b, the exercise scenario control unit 221b performs preparation processing based on the "high" proficiency level of user terminal 20a and the exercise scenario (S8). For example, the exercise scenario control unit 221b creates a vulnerability on user terminal 20b. The log collection and distribution unit 222b records the time the preparation processing (vulnerability creation) was executed and its execution result as an execution log in the storage unit 24b (S9). If the preparation processing is successful, the exercise scenario control unit 221b may notify user terminal 20a of the success of the preparation processing. On user terminal 20a, the exercise scenario control unit 221a executes and controls the exercise scenario to simulate a cyberattack that "spreads laterally to other terminals" (for example, intrusion into user terminal 20b) (S10). The log collection and distribution unit 222a of the control unit 22a records the time when the "spreads laterally to other terminals" was executed and the result of its execution as an execution log in the storage unit 24a (S11).

[0028] The exercise participants on user terminal 20a and user terminal 20b will deal with this attack. The memory units 24a and 24b have registered the correct way to deal with "lateral deployment to other terminals". When the exercise participant on user terminal 20b takes the correct action (for example, following the instructions of the exercise participant on user terminal 20a), the control unit 22b records the result of the action (for example, the operation content and the time the action was taken) in the execution log (S12). The proficiency determination unit 223b of the control unit 22b determines the proficiency of the exercise participants based on the result of dealing with "lateral deployment to other terminals". For example, the proficiency determination unit 223b measures the time it took from the execution of "lateral deployment to other terminals" until the exercise participant on user terminal 20b took the correct action, and determines the proficiency of the exercise participant on user terminal 20b based on the measured time (this proficiency may also be treated as the proficiency of the exercise participant on user terminal 20a). If cyberattacks continue, the proficiency determination unit 223b of the control unit 22b notifies the exercise scenario control unit 221b within the control unit 22b and the user terminal 20a of the calculation result of the proficiency level (not shown). For example, at the user terminal 20a, the exercise scenario control unit 221a determines the next attack based on the proficiency level transmitted from the user terminal 20b, and at the user terminal 20b, the exercise scenario control means prepares for further attacks based on the calculated proficiency level.

[0029] The log collection and distribution unit 222a sends logs related to "lateral deployment to other terminals" (for example, the execution of "lateral deployment to other terminals" and the time of execution) to the management server 10 (S13). The log collection and distribution means of the control unit 22b also sends logs related to "lateral deployment to other terminals" (for example, the execution of "lateral deployment to other terminals" and the time of execution, the content of the action taken, and the time of execution of the action taken) and the proficiency level determination result to the management server 10 (S14). In the management server 10, the log collection unit 122 acquires the logs and proficiency levels sent from user terminals 20a and 20b and records them in the storage unit 14. For example, the proficiency level sent last becomes the proficiency level of the latest exercise participant on user terminal 20a. When the same exercise participant participates in the cyber exercise again, the management server 10 may read the proficiency level of user terminal 20a from the storage unit 14, send this exercise participant's proficiency level along with the exercise scenario to the exercise terminal, and start the exercise from this proficiency level. In this way, by sharing execution logs and proficiency levels, the management server 10 can manage the exercise status of each exercise terminal and the proficiency levels of the exercise participants. Furthermore, in general cyber exercise systems, the information that can be obtained from the target exercise terminal (user terminal 20b) is often limited, but according to this embodiment, by notifying the management server 10 of logs from user terminal 20b, the detailed exercise status of not only user terminal 20a, which is the main subject of the exercise, but also user terminal 20b can be grasped. Since logs from the target as well as logs from the source of the attack can be used for exercise evaluation, more effective cyber exercises become possible. In addition, the cyber exercise evaluation unit 121 reads the execution logs recorded in the storage unit 14, evaluates the cyber exercises performed on user terminals 20a and 20b, and displays the evaluation results on the display unit 13. For example, the cyber exercise evaluation unit 121 generates a screen that displays the success or failure of each attack (e.g., "intrusion" and "information gathering"), the success or failure of the countermeasures against each attack, the time taken to counter them, and the proficiency level, and displays it on the display unit 13.

[0030] Next, with reference to Figure 3, the execution process of the cyber exercise on the user terminal 20a will be explained in more detail. First, the proficiency determination unit 223a executes the exercise preparation start process (step S21). For example, the proficiency determination unit 223a reads from the storage unit 24a a simulated cyber attack assumed in the exercise scenario, the correct response to that attack, the time limit for performing the response, and evaluation criteria (Figure 4). This information is distributed in advance from the management server 10. Next, the exercise scenario control unit 221a executes the exercise scenario (step S22). The log collection and distribution unit 222a performs log acquisition processing (step S23). For example, the log collection and distribution unit 222a records the simulated cyber attack and its execution time in the storage unit 24a when the exercise scenario control unit 221a executes the exercise scenario. Furthermore, when an exercise participant takes action against a cyberattack, the exercise scenario control unit 221a determines whether the action is correct. If the action is correct, the log collection and distribution unit 222a records the action taken (e.g., termination of an abnormal process) and the time the action was taken in the storage unit 24a. Next, the proficiency determination unit 223a determines the proficiency level (step S24). Refer to Figure 4 here.

[0031] Figure 4 shows an example of evaluation criteria in proficiency assessment according to the embodiment. Line L1 in Figure 4 shows the evaluation criteria for the proficiency of the exercise participants, and this information is distributed from the management server 10 to the user terminal 20a, etc., and recorded in the storage unit 24a. The evaluation criteria shown in Figure 4 are prepared for each type of cyberattack. Line L1 in Figure 4 shows the relationship between the time elapsed since a certain cyberattack was simulated and the evaluation (score) of the response. In Figure 4, the vertical axis represents the score, and the horizontal axis represents time. Specifically, in Figure 4, the score at the start of scoring (for example, when the cyberattack is executed) is set to 100 points, P1 is set for the score after time t1, P2 is set for the score after time t2, and P3 is set for the score after time t3. Furthermore, the score is set to 100 points from time 0 to t1, the score for time t1 to t2 is the value indicated by the line connecting coordinates (t1, P1) and coordinates (t2, P2), the score for time t2 to t3 is the value indicated by the line connecting coordinates (t2, P2) and coordinates (t3, P3), and the score for time t3 to the control time is set to P3. For example, if the exercise participant takes the correct action by t1, that action is evaluated as 100 points, and if the exercise participant takes the correct action at t4, the score for that action is evaluated as P4. The proficiency determination unit 223a calculates the time from the execution time of the cyber attack recorded in the log of the memory unit 24a (for example, the execution time of the first "intrusion") to the time when the exercise participant takes the correct action, and applies this time to the horizontal axis of the graph in Figure 4 to look up the score in reverse. Furthermore, the memory unit 24a has pre-associated evaluation results (scores) based on Figure 4 with proficiency levels, for example, scores of 0-30 are "low," scores of 31-70 are "medium," and scores of 71 or higher are "high." The proficiency determination unit 223a evaluates the score of the response based on Figure 4 and determines the proficiency level of the exercise participant based on the score. The proficiency determination unit 223a records the determined proficiency level in the memory unit 24a.

[0032] Next, the log collection and distribution unit 222a performs the process of distributing the logs and scoring results (step S25). The log collection and distribution unit 222a reads the execution log and proficiency level from the storage unit 24a and sends the read information to the management server 10 using the communication unit 25a. The log collection and distribution unit 222a also reads the proficiency level from the storage unit 24a and sends the read proficiency level to the user terminals 20b and 20c using the communication unit 25a.

[0033] Next, the exercise scenario control unit 221a determines whether to terminate the exercise (step S26). For example, if the exercise scenario has a planned cyberattack, the exercise scenario control unit 221a determines not to terminate the exercise, and if all cyberattacks have been executed, it determines to terminate the exercise. If the exercise is to be terminated (step S26; Yes), the exercise scenario control unit 221a terminates the execution of the exercise scenario. If the exercise is not to be terminated (step S26; No), the process from step S22 is repeated. In step S22, the exercise scenario control unit 221a provides the exercise scenario with the proficiency level calculated in step S24, and the exercise scenario simulates the next cyberattack based on the control flow illustrated in Figure 2A.

[0034] The above description explains the exercise scenario executed on user terminal 20a, but in parallel, the exercise scenario may also be executed on user terminals 20b and 20c, with each terminal performing a cyber exercise individually. Furthermore, if the proficiency level on user terminal 20a is determined to be "high," the exercise scenarios for user terminals 20a to 20c may be configured such that the three terminals work together to launch an attack from user terminal 20a to user terminals 20b and 20c. Alternatively, for example, if the proficiency levels of the exercise participants on user terminals 20a to 20c are in the combination of "high," "low," and "medium," user terminal 20a may execute "Attack 1" targeting the other two terminals; if the combination is "low," "high," and "medium," user terminal 20b may execute "Attack 2" targeting the other two terminals; and so on. Multiple attack patterns for cyber attacks using multiple terminals may be designed, and the exercise scenario may be configured to flexibly coordinate multiple terminals according to the proficiency level of the exercise participants. With the cyber exercise system 1 of this embodiment, the proficiency level of each exercise participant is shared across all user terminals 20 during the exercise. Therefore, even when simulating a cyber attack using multiple devices, it is possible to provide an exercise tailored to the skill level of the group of exercise participants.

[0035] (effect) As described above, according to the cyber exercise system 1 of this embodiment, an exercise scenario configured to perform a cyber exercise according to the user terminal 20 conducting the cyber exercise is distributed, and the exercise scenario is executed on the user terminal 20. During the execution of the exercise scenario, the proficiency level of the exercise participants is determined, and the content of the cyber exercise can be switched according to the determined proficiency level. This makes it possible to dynamically change the difficulty level of the cyber exercise to match the skill level of the exercise participants during the execution of the cyber exercise without changing the content of the cyber exercise or distributing additional data. Therefore, an effective cyber exercise can be realized without requiring much effort or time.

[0036] Furthermore, according to the cyber exercise system 1 of this embodiment, the proficiency level determined during the cyber exercise is shared among all user terminals 20. This allows for flexible control of the user terminals 20 involved in the cyber exercise, even when conducting a cyber exercise that links multiple user terminals 20 according to the proficiency levels of one or more exercise participants, enabling the simulation of a cyber attack using multiple devices. In cyber attacks, the process is often not limited to the attacked terminal; the terminal itself is used as a stepping stone to affect other terminals. However, according to this embodiment, exercises against such cyber attacks can also be realized through the cooperation of user terminals 20.

[0037] Furthermore, in order to conduct effective cyber exercises, it is desirable to conduct them using the environment that the exercise participants normally use, rather than using a pre-prepared simulated exercise environment. However, in recent years, network environments that are not necessarily of high quality, such as wireless communication and mobile communication, have become more widespread. For example, even when trying to change the exercise content according to the proficiency level, it may not be possible to control the exercise content based on proficiency level due to communication problems between the management server and the user terminal. In contrast, with this embodiment, the proficiency level can be determined at the user terminal 20, and the level of the next attack can be changed based on the determination result, so that cyber exercises can be conducted according to the proficiency level regardless of the communication status with the management server. In other words, according to this embodiment, practical cyber exercises that are appropriate to the skill level can be realized using the environment that users normally use.

[0038] (Minimum configuration) Figure 5 is a block diagram showing the configuration of a training terminal with a minimum setup. The training terminal 30 comprises a training scenario 31, an execution control means 32, and an evaluation means 33. The training scenario 31 is a program configured to simulate cyberattacks according to the proficiency level of the training participants. The execution control means 32 controls the execution of the training scenario 31. The evaluation means 33 evaluates the response to the simulated cyberattack during the execution of the training scenario 31 and determines the proficiency level of the training participants based on the results of the evaluation.

[0039] Figure 6 is a flowchart showing the processing of an exercise terminal with a minimal configuration. The execution control means 32 executes the exercise scenario (step S31). Next, the evaluation means 33 evaluates the response to the simulated cyberattack during the execution of the exercise scenario 31 (step S32). Next, the evaluation means 33 determines the proficiency level of the exercise participants based on the evaluation results (step S33). Next, the execution control means 32 controls the exercise scenario 31 to simulate a cyberattack corresponding to the notified proficiency level based on the determined proficiency level (step S34). The exercise scenario 31 simulates a cyberattack corresponding to the proficiency level. This makes it possible to provide a cyber exercise that is appropriate to the proficiency level of the exercise participants.

[0040] Figure 7 shows an example of the hardware configuration of the cyber exercise system according to the embodiment. Computer 900 is, for example, a PC (Personal Computer) or server terminal device equipped with a CPU 901, main memory 902, auxiliary memory 903, input / output interface 904, and communication interface 905. The management server 10, user terminal 20, and exercise terminal 30 mentioned above are implemented in computer 900. The processes described above are stored in auxiliary memory 903 in the form of programs. The CPU 901 reads the program from auxiliary memory 903, expands it into main memory 902, and executes the above processes according to the program. The CPU 901 also allocates memory space in main memory 902 according to the program. The CPU 901 also allocates memory space in auxiliary memory 903 to store data being processed according to the program.

[0041] In at least one embodiment, the auxiliary storage device 903 is an example of a non-temporary tangible medium. Other examples of non-temporary tangible media include magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, semiconductor memory, etc., connected via the input / output interface 904. Furthermore, if this program is distributed to the computer 900 via a communication line, the computer 900 that receives the program may expand it into the main memory 902 and execute the above processing. The program may also be for the purpose of realizing some of the functions described above. Moreover, the program may be a so-called differential file (differential program) that realizes the above-mentioned functions in combination with other programs already stored in the auxiliary storage device 903.

[0042] Although one embodiment of this invention has been described in detail above with reference to the drawings, the specific configuration is not limited to that described above, and various design changes can be made without departing from the spirit of this invention. Furthermore, one aspect of the present invention can be modified in various ways within the scope of the claims, and embodiments obtained by appropriately combining the technical means disclosed in different embodiments are also included in the technical scope of the present invention. In addition, configurations in which elements described in the above embodiments and modifications are replaced with elements that produce similar effects are also included.

[0043] Some or all of the above embodiments may be described as follows, but are not limited to the following:

[0044] (Note 1) An exercise terminal comprising: an exercise scenario configured to simulate a cyberattack according to the proficiency level of the exercise participants; means for controlling the execution of the exercise scenario; and means for evaluating the response to the simulated cyberattack during the execution of the exercise scenario, wherein the means for evaluation determines the proficiency level based on the results of the evaluation, and the means for execution control controls the exercise scenario to simulate a cyberattack according to the determined proficiency level.

[0045] (Note 2) The exercise terminal described in Appendix 1 further comprises a storage unit that stores information on the correct response to the cyberattack and information on evaluation criteria that shows the relationship between the time until the correct response is carried out and the evaluation, wherein the means for performing the evaluation measures the time from the start of the simulation of the cyberattack until the correct response is carried out, and performs the evaluation based on the measured time and the information on evaluation criteria.

[0046] (Note 3) A cyber exercise system comprising: a first exercise terminal as described in Appendix 1 or Appendix 2; and a second exercise terminal as described in Appendix 1 or Appendix 2, wherein the first exercise terminal comprises: an exercise scenario configured to simulate the cyber attack against the second exercise terminal according to the proficiency level; and means for transmitting the proficiency level to the second exercise terminal before simulating the cyber attack against the second exercise terminal; and the second exercise terminal comprises: means for receiving the proficiency level from the first exercise terminal; and an exercise scenario configured to perform preparatory processing for receiving the cyber attack from the first exercise terminal according to the proficiency level received from the first exercise terminal.

[0047] (Note 4) The cyber exercise system according to Appendix 3, further comprising a management server for distributing the exercise scenario to the exercise terminals, wherein the first and second exercise terminals are each provided with means for recording an execution log of the exercise scenario and means for transmitting the execution log and the proficiency level to the management server.

[0048] (Note 5) A cyber exercise execution method comprising the steps of: executing an exercise scenario configured to simulate a cyber attack according to the proficiency level of the exercise participants; evaluating the response to the simulated cyber attack during the execution of the exercise scenario; determining the proficiency level based on the results of the evaluation; and controlling the exercise scenario to simulate the cyber attack according to the determined proficiency level.

[0049] (Note 6) A program that causes a computer to perform the following steps: execute an exercise scenario configured to simulate a cyberattack according to the proficiency level of the exercise participants; evaluate the response to the simulated cyberattack during the execution of the exercise scenario; determine the proficiency level based on the results of the evaluation; and control the exercise scenario to simulate the cyberattack according to the determined proficiency level. [Explanation of symbols]

[0050] 1. Cyber ​​Exercise System 10. Management Server 11. Input Reception Section 12. Control Unit 121...Cyber ​​Exercise Evaluation Department 122...Log Collection Department 13...Display section 14...Storage section 15. Communications Department 20, 20a, 20b, 20c... User terminals 21,21a...Input reception section 22,22a..., control unit 221,221a...Exercise Scenario Control Unit 222,222a...Log Collection and Distribution Department 223,223a...Proficiency assessment unit 23,23a...Display section 24,24a...Storage section 25,25a...Communication Department 900... Computer 901···CPU 902...Main memory 903...Auxiliary storage device 904... Input / Output Interface 905...Communication Interface

Claims

1. The exercise scenario is designed to simulate cyberattacks according to the skill level of the exercise participants, Means for controlling the execution of the aforementioned exercise scenario, A means for evaluating the response to the simulated cyberattack during the execution of the aforementioned exercise scenario, Equipped with, The means for performing the evaluation determines the level of proficiency based on the results of the evaluation, The means for performing the execution control controls the exercise scenario to simulate a cyberattack corresponding to the determined proficiency level, based on the proficiency level. Training terminal.

2. A storage unit that stores information on the correct response to the cyberattack, and information on evaluation criteria that shows the relationship between the time until the correct response is carried out and the evaluation. Furthermore, The means for performing the evaluation measures the time from the start of the simulation of the cyberattack until the correct countermeasure is taken, and performs the evaluation based on the measured time and the information of the evaluation criteria. The training terminal according to claim 1.

3. The first exercise terminal according to claim 1 or claim 2, The second exercise terminal according to claim 1 or claim 2, comprising The first training terminal is, Depending on the level of proficiency, the training scenario is configured to simulate the cyberattack on the second training terminal, Means for transmitting the aforementioned proficiency level to the second training terminal before simulating the cyber attack against the second training terminal, Equipped with, The second aforementioned training terminal is, A means for receiving the proficiency level from the first training terminal, The training scenario is configured to perform preparatory processing on its own terminal to receive the cyberattack from the first training terminal, in accordance with the level of proficiency received from the first training terminal, A cyber exercise system equipped with the following features.

4. The system further comprises a management server that distributes the aforementioned exercise scenario to the aforementioned exercise terminals, The first training terminal and the second training terminal are, A means for recording the execution log of the aforementioned exercise scenario, Means for sending the execution log and the proficiency level to the management server, The cyber exercise system according to claim 3, comprising:

5. The exercise involves executing an exercise scenario designed to simulate cyberattacks tailored to the skill level of the exercise participants, and The steps include: evaluating the response to the simulated cyberattack during the execution of the aforementioned exercise scenario; A step of determining the level of proficiency based on the results of the evaluation, The steps include controlling the exercise scenario to simulate the cyber attack corresponding to the determined proficiency level, A method for conducting cyber exercises.

6. On the computer, The exercise involves executing an exercise scenario designed to simulate cyberattacks tailored to the skill level of the exercise participants, and The steps include: evaluating the response to the simulated cyberattack during the execution of the aforementioned exercise scenario; A step of determining the level of proficiency based on the results of the evaluation, The steps include controlling the exercise scenario to simulate the cyber attack corresponding to the determined proficiency level, A program that executes the command.