Security measures support device and security measures support method
The security countermeasure support device and method address the limitations of conventional systems by optimizing countermeasure selection based on system configuration and constraints, resulting in efficient and cost-effective security measures for the entire target system.
Patent Information
- Application Number
- JP2021167244
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-12
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-10-12
AI Technical Summary
Conventional security countermeasure systems are inadequate in optimizing countermeasure locations and contents based on system configuration and constraints, leading to insufficient and costly security measures that do not consider the entire system's effectiveness and cost.
A security countermeasure support device and method that utilize a storage device to hold profile information on a target system and candidate information on security countermeasures. The system compares attack occurrence points and patterns with candidate information to identify effective countermeasures, calculates their scope and implementation cost, and determines a priority order for the countermeasure candidates based on cost-effectiveness.
Enables efficient selection of cost-effective security measures with a reduced number of work steps for the entire target system, ensuring comprehensive coverage and optimized resource allocation.
Smart Images

Figure 0007682073000001 
Figure 0007682073000002 
Figure 0007682073000003
Abstract
Description
[Technical field]
[0001] The present invention relates to a security countermeasure support device and a security countermeasure support method. [Background technology]
[0002] It is important to analyze security threats that exploit system vulnerabilities and develop effective countermeasures. However, as these threats tend to become more diverse and sophisticated with each passing year, the costs and effort required to analyze the risks and develop countermeasures are also increasing. In view of this, as a conventional technique for analyzing and evaluating security risks, for example, a risk evaluation countermeasure planning system for determining countermeasures for reducing vulnerabilities and security tests (see Patent Document 1) has been proposed.
[0003] This system is a risk evaluation countermeasure planning system having a processing device and a storage device, and which plans countermeasures and security tests regarding attacks against a system, the storage device storing a vulnerability database that stores vulnerability information regarding vulnerabilities, and a product information database that stores product information, the processing device having an input / output processing unit to which design information is input, a vulnerability analysis unit that analyzes the vulnerabilities based on the design information, a threat analysis processing unit that analyzes threats to the system based on the analysis result of the vulnerability analysis unit and outputs a threat analysis result, a countermeasure planning unit that plans the countermeasures to reduce the influence of the vulnerability based on the threat analysis result output from the threat analysis processing unit and the vulnerability information stored in the vulnerability database, a security test planning unit that plans the security test based on the countermeasure plan planned by the countermeasure planning unit, an evaluation calculation unit that performs an evaluation based on the security test planned by the security test planning unit and outputs the evaluation result, and a result processing unit that processes the evaluation result evaluated by the evaluation calculation unit, generates security countermeasures as the product information, and stores the security countermeasures in the product information database. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2020-166650 A Summary of the Invention [Problem to be solved by the invention]
[0005] Conventional technology can output insufficient security measures based on the cost of the measures, but it does not cover optimization of the countermeasure locations and countermeasure contents based on the constraints and system configuration based on the system configuration. In other words, it only statically outputs countermeasures corresponding to one threat event, and does not consider the countermeasure effectiveness and cost for the entire system. Therefore, an object of the present invention is to provide a technique that can support efficient selection of cost-effective security measures with a small number of work steps for the entire target system. [Means for solving the problem]
[0006] The security countermeasure support device of the present invention, which solves the above-mentioned problems, comprises a storage device that holds profile information on a target system for security countermeasures and candidate information on security countermeasures determined according to the points and patterns of attacks, a process of comparing information on the occurrence points and patterns of each attack identified based on the profile information with the candidate information to identify candidate security countermeasures for each attack, and a process of calculating the scope of countermeasures for each attack and the implementation cost for each of the candidate security countermeasures. , and the application conditions of the proposed security measures, A process of calculating based on the candidate information, and a process of calculating the implementation cost when the scope of the solution is large and the implementation cost is large. and the number of said applicable conditions and a calculation device that executes a process of determining the priority order of the security countermeasure candidates based on which of the countermeasure candidates is small. Furthermore, a security countermeasure support method of the present invention includes a process in which an information processing device stores profile information on a target system for security countermeasures and candidate information on security countermeasures determined according to points and patterns of attacks in a storage device, and compares information on the occurrence points and patterns of each attack identified based on the profile information with the candidate information to identify candidate security countermeasures for each attack, and a process in which the scope of countermeasures against each attack and implementation costs for each of the candidate security countermeasures are calculated. , and the application conditions of the proposed security measures, A process of calculating based on the candidate information, and a process of calculating the implementation cost when the scope of the solution is large and the implementation cost is large. and the number of said applicable conditions and determining a priority order of the security countermeasure candidates based on which of the countermeasure candidates is small. Effect of the Invention
[0007] According to the present invention, it is possible to support efficient selection of cost-effective security measures with few work steps for the entire target system. [Brief description of the drawings]
[0008] [Figure 1] 1 is an overall configuration diagram including a security countermeasure support device according to an embodiment of the present invention; [Diagram 2] 1 is a diagram illustrating an example of a hardware configuration of a security countermeasure support device according to an embodiment of the present invention. [Figure 3A] 1 is a configuration diagram of a network system to which a security measure according to an embodiment of the present invention is applied. [Figure 3B] 1 is an explanatory diagram of a logical path on a target system of a security measure according to the present embodiment. [Figure 4] 1 is an explanatory diagram of a logical path on a target system of a security measure according to the present embodiment. [Figure 5A] 1 is a table showing an attack procedure performed along an attack path in this embodiment. [Figure 5B] 1 is a table showing an attack procedure performed along an attack path in this embodiment. [Figure 6A] 11 is a diagram showing an example of the configuration of a point list in a system profile of the present embodiment. FIG. [Figure 6B] 11 is a diagram showing an example of a configuration of a logical configuration profile in a system profile of the present embodiment. FIG. [Figure 6C] FIG. 11 is a diagram illustrating an example of a configuration of a physical configuration profile in a system profile of the present embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of the configuration of a countermeasure candidate DB according to the present embodiment. [Figure 8] FIG. 11 is a diagram illustrating an example of an attack path identification flow in this embodiment. [Figure 9] FIG. 2 is a diagram showing a specific example of a point requiring countermeasures in this embodiment. [Figure 10] FIG. 11 is a diagram showing a list of points requiring countermeasures in this embodiment. [Figure 11] FIG. 2 is a diagram showing an example of a flow of a security countermeasure support method according to the present embodiment. [Figure 12] FIG. 11 is a diagram illustrating an example of a list of countermeasure candidates in the present embodiment. [Figure 13] FIG. 11 is a diagram showing a specific example of cost determination in the present embodiment. [Figure 14] FIG. 11 is a diagram showing an example of output in this embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0009] <Overall composition> Hereinafter, an embodiment of the present invention will be described in detail with reference to the drawings. Fig. 1 is an overall configuration diagram including a security measures support device 100 of this embodiment. The security measures support device 100 shown in Fig. 1 is a computer that can support efficient selection of cost-effective security measures with few work steps for the entire target system 10.
[0010] As shown in FIG. 1, a security countermeasure support device 100 of this embodiment is communicably connected to a target system 10 and a user terminal 200 via an appropriate network 1 such as the Internet or a LAN (Local Area Network).
[0011] Alternatively, instead of this configuration, the security countermeasure support device 100 may be configured as a stand-alone machine, and may obtain information about the target system 10 for security countermeasures through its own user interface and execute predetermined processing.
[0012] On the other hand, the target system 10 for security measures is a system whose physical and logical configurations are described in a system profile (profile information).
[0013] This target system 10 has assets (e.g., personal information, technical information, trade secrets, etc.) that may be attacked by a malicious third party. Of course, there is no limitation on the types of such assets. In addition, assets targeted by attacks are not limited to those that are directly subject to theft, such as specific information or data.
[0014] The user terminal 200 is, for example, a terminal operated by a user of the security countermeasure support service provided by the security countermeasure support apparatus 100 or by an administrator of the service. Specifically, a personal computer, a smartphone, a tablet terminal, etc. can be envisioned. <Hardware configuration> The hardware configuration of the security measure support device 100 of this embodiment is as shown in FIG.
[0015] That is, the security countermeasure support device 100 includes a storage device 101 , a memory 103 , a calculation device 104 , an input device 105 , an output device 106 , and a communication device 107 .
[0016] Of these, the storage device 101 is configured with an appropriate non-volatile storage element such as an SSD (Solid State Drive) or a hard disk drive.
[0017] The memory 103 is composed of a volatile storage element such as a RAM.
[0018] The arithmetic unit 104 is a CPU that reads out the program 102 stored in the storage unit 101 into the memory 103 and executes the program, controls the device itself, and performs various types of judgment, calculation, and control processing.
[0019] The input device 105 is an input device such as a keyboard that accepts key input from the user and a microphone that accepts voice input.
[0020] The output device 106 is an output device such as a display that displays the results of processing by the arithmetic unit 104 .
[0021] The communication device 107 is assumed to be a network interface card or the like that is connected to the network 1 and handles communication processing with the target system 10 and the user terminal 200 .
[0022] When the security measure support device 100 does not function as a stand-alone machine and input and output are performed via the user terminal 200, the input device 105 and the output device 106 may be omitted.
[0023] In addition to the program 102 for implementing the functions required for the security countermeasures support device of this embodiment, at least a system profile 125 and a countermeasure candidate DB 126 are stored in the storage device 101. However, details of these databases will be described later. <Systems subject to security measures> Here, a configuration example of the target system 10 to which the security measures are applied in this embodiment will be described with reference to FIGS. 3A to 4. FIG.
[0024] The target system 10 includes an untrusted OA-NW (Network) such as the Internet, an information NW, Each device is connected via a control network and a line network. The information network and the control network are wired LANs (Local Area Networks), and the line network is a serial peer connection.
[0025] The information network includes a monitoring terminal, a security gateway (GW), a monitoring control server, and an information network. The control NW is connected to a monitoring control server, a control NW switch, and a PLC. (Programmable Logic Controller). The line NW connects the PLC and a local HMI (Human Machine Interface).
[0026] The monitoring terminal can remotely control the monitoring control server and the PLC. The local HMI can operate the PLC. can.
[0027] As shown by the wavy arrow in Fig. 3A, the attack path AP11 indicates unauthorized access with the PLC as the attack target (asset point) by following the route of security gateway → monitoring terminal → monitoring control server → PLC. In this way, the attack path passes through each device (also called point, component) from the starting point (security gateway) to the ending point (PLC) in order.
[0028] Also, the number "6.44" attached to each device in the Security GW[6.44] in Figure 3A indicates the point importance of that device. Point importance is a parameter that indicates the importance of increasing security strength as the number increases, and is entered by the administrator for each device in advance.
[0029] Point importance is, for example, the importance of a point as an asset in business, and devices that store important confidential information such as customer personal information have a higher value. Alternatively, point importance is the degree to which an attacker can attack, which can be derived from the layout (connection configuration) of a network system, and the higher the value, the easier it is for an attacker to access the device.
[0030] From the perspective of the side defending against attacks from attackers, the attack path AP11 "Security GW → Monitoring Terminal → Monitoring Control Server → PLC" is a path that is attacked by the Security GW, the monitoring terminal, or the monitoring control server. You need to cut off (kill) the attack at at least one point on the bar.
[0031] In other words, by setting at least one kill point from a set of candidate points that make up an attack path, it is possible to block attacks that pass through that attack path (kill chain).
[0032] Here, if we focus on the attack path AP11, for example, if the attack is successfully blocked by using the security gateway at the starting point as the kill point, unauthorized access will not reach the monitoring terminal or monitoring control server at the subsequent stages, so there is no need to take excessive security measures. In other words, By selecting kill points, we can propose cost-effective security measures.
[0033] Furthermore, the classification of attack paths will be explained. Attackers' attacks are classified into logical attacks on computers, such as unauthorized access, and physical attacks, such as the attacker invading a premises and destroying equipment. Therefore, an attack path in which attacks from the start point to the end point are all logical, such as attack path AP11 in Figure 3A, is called a "logical path."
[0034] On the other hand, an attack path in which all attacks from the start point to the end point are physical attacks is called a "physical path," and an attack path that combines a physical path and a logical path is called a "logical path."
[0035] Fig. 3B is an explanatory diagram of logical paths on the target system 10 in Fig. 3A. Even in the same target system, important asset points may be distributed in multiple locations. Fig. 3B shows an attack path AP21 targeting a monitoring terminal, an attack path AP22 targeting a monitoring control server, and an attack path AP23 targeting a PLC.
[0036] Here, we define the number of stages that the attack path passes through. →Security GW →Information NW →Monitoring terminal, so the points after OA-NW are "Security The total number of stages in the attack path AP21 is three: the security gateway, the information network, and the monitoring terminal.
[0037] The attack path AP22 is OA-NW → Security GW → Information NW → Monitoring terminal → Monitoring control server in this order. However, since "monitoring terminal → monitoring control server" can be remotely controlled, it is counted as 0 steps. Therefore, the number of steps of the attack path AP22 is 3.
[0038] Attack path AP23 follows the order OA-NW → security GW → information NW → monitoring terminal → monitoring control server → control NW → PLC. Therefore, the number of stages in attack path AP23 is 5. As such, the more stages an attack path has, the more attack steps are required to reach the asset point, making it a more difficult attack path.
[0039] Fig. 4 is an explanatory diagram of a logical path on the target system 10 of Fig. 3A. The target system 10 of Fig. 3A is housed in a production building 320 as a physical configuration. The production building 320 is protected by a production building door 311 between it and the entrance 310 of the uncontrolled area.
[0040] A local HMI, a PLC, and a control NW switch are housed inside a machine room 330 in the production building 320 and is protected by a machine room door 331.
[0041] A security gateway, a monitoring terminal, and a server rack 342 are housed inside a monitoring room 340 in the production building 320, and the monitoring room 340 is protected by a monitoring room door 341. A monitoring control server and an information NW switch are housed inside the server rack 342, and the server rack door 343 protects the monitoring room 340.
[0042] The attacker goes to the entrance 310 → monitoring room 340 by himself and operates the monitoring terminal at hand (physical path AP31 indicated by a solid arrow).Then, the attacker performs unauthorized access to the monitoring control server → PLC via the monitoring terminal he operates at hand (logical path AP32 indicated by a wavy arrow).
[0043] In this way, the logical / physical path is configured by combining the physical path AP31 and the logical path AP32.
[0044] 5A and 5B are tables showing attack procedures along the attack paths. Table 511 shows the detailed attack procedures of the attack path AP11 in FIG. 3A. Table 512 shows the detailed attack procedures of the attack path AP11 in FIG. 4. This shows the detailed attack procedure for the logical path (physical path AP31 + logical path AP32).
[0045] Here, the "ID" columns in tables 511 and 512 are added for the purpose of explanation to distinguish between the different attack procedures. Comparing tables 511 and 512, the attack procedures are different up to the takeover of the monitoring terminal [6.44] (ID=A06), but the attack procedures from ID=A06 onwards are the same. Therefore, by setting the monitoring terminal [6.44] as the kill point, both attack paths can be blocked at one location at the same time, improving cost-effectiveness.
[0046] In this way, in order to propose cost-effective security measures, it is effective to narrow down the kill points in the target system where measures should be focused.
[0047] The "path priority" is a path-by-path priority that indicates the order in which countermeasures should be taken against various attack paths anticipated in the target system.
[0048] "Point priority" refers to a priority order on a point-by-point basis that indicates the order in which candidate points that should be targeted as kill points among the various candidate points that make up an attack path.
[0049] In addition, for both the pass priority and the point priority, the smaller the number, the earlier it will be addressed, so it is preferentially selected in order: 1st, 2nd, ...
[0050] The method for calculating the path priority will be explained below. The path priority is determined, for example, in the following order: (Guideline 1), (Guideline 2), (Guideline 3).
[0051] (Guideline 1) Prioritize the "logical path" over the "logical-physical path." This is because a logical attack has a lower attack cost than a physical attack.
[0052] (Guideline 2) When the path priority is the same in (Guideline 1) above, the lower the protection level of the physical security measures on the route through which the physical path passes, the higher the priority. The protection level of physical security measures is, for example, Level 1 to 3, and the higher the level number, the more secure it is at the present time. Therefore, measures may be postponed.
[0053] This protection level may be set higher the longer the distance from the starting point of intrusion (production building door 311 in Figure 3), or it may be set according to the degree of barrier provided by the machine room door 331, monitoring room door 341, etc. (the strength of the metal used to make the door, the strength of the biometric authentication required to pass through the door, etc.).
[0054] (Guideline 3) When the path priority is the same in (Guideline 1) and (Guideline 2) above, the shorter the distance from the start point to the end point (the number of steps), the higher the priority. This is because the smaller the number of steps, the lower the attack cost for an attacker.
[0055] According to these guidelines 1 to 3, for example, the path priorities for various attack paths assumed in the target system of Figs. 3A to 4 are ranked from 1st to 8th as follows. The notation "to logic" indicates an attack in which the path before this notation is the physical path and the path after this notation is the logical path. The switching points are shown below. First, the first place tied is that both are logical paths and have the same number of steps.
[0056] 1st place: [0th level (physical) + 3th level (logical) = 3 levels in total] = OA-NW → Security GW (6.44) → Information NW (Information NW switch) → Monitoring and control server (9.54) 1st place: [0th stage (physical) + 3rd stage (logical) = 3 stages in total] = OA-NW → Security GW (6.44) → Information NW (Information NW switch) → Monitoring terminal (6.44) = Monitoring control server (9.54) Next, the third to sixth places are all logical and physical passes with protection level LV2. It will be ranked very high.
[0057] 3rd place: [LV2: 4 levels (physical) + 1 level (logical) = 5 levels in total] = (uncontrolled area) → entrance → production building → monitoring room door → monitoring room → [to logic] → monitoring terminal (6.44) = monitoring control server (9.54) 4th place: [LV2: 4 steps (physical) + 3 steps (logical) = total 7 steps] = (uncontrolled area) → entrance → production building → monitoring room door → monitoring room → [to logic] → security GW (6.44) → information NW → monitoring control server (9.54) 4th place: [LV2: 6 steps (physical) + 1 step (logical) = total 7 steps] = (uncontrolled area) → entrance → production building → monitoring room door → monitoring room → rack door → server rack → [to logic] → monitoring control server (9.54) 6th place: [LV2: 6 steps (physical) + 2 steps (logical) = total 8 steps] = (uncontrolled area) → entrance → production building → monitoring room door → monitoring room → rack door → server rack → [to logic] → information network switch (6.44) → monitoring control server (9.54) Furthermore, the 7th and 8th places are both logical and physical passes with protection level LV3, and the fewer the number of steps, the higher the chance of success. It will be ranked very high.
[0058] · 7th digit: [LV3: 4 segments (physical) + 2 segments (logical) = 6 segments in total] = (Outside management area) → entrance → production building → machine room door → machine room → [to logical] → control NW switch (9.21) → monitoring control server (9.54) · 8th digit: [LV3: 4 segments (physical) + 4 segments (logical) = 8 segments in total] = (Outside management area) → entrance → production building → machine room door → machine room → [to logical] → local HMI (4.94) → PLC (9.21) → control NW → monitoring control server (9.54) <Example of data structure> Next, various information used by the security countermeasure support device 100 of the present embodiment will be described. FIGS. 6A to 6C show an example of the system profile 125 in the present embodiment.
[0059] The system profile 125 of the present embodiment is information describing the logical and physical configurations of the target system 10 for security countermeasures.
[0060] This system profile 125 is composed of, for example, a point list 1251, a logical configuration profile 1252, and a physical configuration profile 1253.
[0061] Among these, the point list 1251 shown in FIG. 6A has a configuration in which a platform (HW: Hardware), a platform (SW: Software), attribute information (usage), and point importance are associated as attributes for each point name of the attack path (name of the device passing through).
[0062] Also, the logical configuration profile 1252 shown in FIG. 6B has a configuration in which a network type, an NW control device, and a connection point are associated for each logical network name.
[0063] Also, the physical configuration profile 1253 shown in FIG. 6C has a configuration in which attribute information, an adjacent physical area, and a point installed in the area are associated for each physical area name.
[0064] Therefore, by referring to the system profile 125, the security countermeasure support apparatus 100 can grasp the physical configuration and logical configuration of the target system 10 for security countermeasures.
[0065] 7 shows an example of the countermeasure candidate DB 126 in this embodiment. The countermeasure candidate DB 126 in this embodiment stores candidate information of security countermeasures determined according to points and patterns of attacks. It is a database that stores the following:
[0066] Such countermeasure candidate DB 126 is a collection of records that link, for each type of point, data such as an attack pattern against the point and countermeasure candidates in that case. <Pre-processing> The actual procedure of the security countermeasure support method in this embodiment will be described below with reference to the drawings. The various operations corresponding to the security countermeasure support method described below are realized by a program that the security countermeasure support device 100 reads into a memory or the like and executes. This program is composed of codes for performing the various operations described below.
[0067] First, the pre-processing of the security countermeasure support method in this embodiment will be described. In this pre-processing, the security countermeasure support device 100 identifies the point and pattern of an attack based on the system profile 125 of the storage device 101.
[0068] The outline of the flow is that the security measure support device 100, based on the system profile 125, sets the point to be protected (asset point) in the target system 10 as the end point (s1), identifies the attack path from the start point, which is the point of the attack, to the end point as an attack pattern (s2), and extracts points requiring countermeasures, or kill points, based on this attack pattern (s3).
[0069] More specifically, it is as follows. The security measure support device 100 grasps the security measure problems to be proposed this time based on the system profile 125 and a predetermined evaluation profile. The above-mentioned evaluation profile is, for example, the determination information of the above-mentioned points and the attacker ability information, and is to be held in advance by the storage device 101.
[0070] The point determination information is information for calculating the point importance. For example, in the following, "very large" is the highest value, and the point importance decreases in the order of "medium" and "minor".
[0071] · Very large: It causes an extremely large business impact when the attack is successful (human disaster, large-scale business loss).
[0072] · Medium: It causes a medium business impact when the attack is successful (small-scale business loss).
[0073] · Minor: It does not cause a large business impact even if the attack is successful.
[0074] Also, the attacker ability information indicates the ability of the attacker assumed for the above-mentioned points. Hereinafter, the higher the level, the higher the ability of the attacker.
[0075] · Level 3: An attacker with severe malice and high attack skills.
[0076] · Level 2: An attacker with mild malice and simple attack skills.
[0077] · Level 1: An attack at the level of accidental operation or prank.
[0078] For example, when protecting a storage device of map data that only describes general geography such as a river as the above-mentioned point, there is little merit in attacking that point, so it is unlikely that a level 3 attacker will take risks and attack. Therefore, the countermeasure cost can be reduced by implementing a mild security measure that only prevents level 1 attackers.
[0079] Furthermore, the security measure support device 100 designates which points among the points scattered throughout the target system 10 are to be protected as asset points in accordance with the above-mentioned evaluation profile (point importance, attacker capability).
[0080] For example, by setting only points with a point importance of "very high" as asset points, countermeasure costs can be significantly reduced. Alternatively, the administrator of the target system 10 may directly specify individual points as asset points from the target system 10. The administrator also specifies the degree of attacker capability that each specified asset point should be protected from. For example, when protecting a storage device containing bank account information as an asset point, it is necessary to implement robust security measures that can protect against not only level 1 and 2 attackers, but also level 2 attackers.
[0081] The security measure support device 100 refers to attack pattern information (not shown) stored in advance in the storage device 101, and generates an attack path (attack procedure) to each asset point specified in the above-mentioned process.
[0082] The above-mentioned attack pattern information is information that indicates the attack procedures that are performed along the attack path. This information indicates the detailed attack procedures of the attack path and the detailed attack procedures of the logical-physical path (physical path + logical path). The information on such attack paths has already been described.
[0083] The attack path generation process is performed for each asset point (eg, according to the priority order between the attack paths) until attack paths are generated with all asset points already specified as described above as end points.
[0084] For each attack path generated as described above, the security measure support device 100 determines a critical candidate point (one that can effectively kill the attack path) as a kill point, that is, a point requiring countermeasures.
[0085] Below, four examples of algorithms for determining points requiring countermeasures are given as (Algorithm 1) to (Algorithm 4).
[0086] As (algorithm 1), the security measure support device 100 sets the point (start point) closest to the attack origin of each attack path as the countermeasure-required point. This allows unauthorized access to be appropriately blocked at the entrance to the in-house system by border control, making it possible to secure a wide range of the in-house system.
[0087] For example, the logical path "OA-NW → Security GW (6.44) → Information NW (Information NW switch) → Monitoring system For "control server (9.54)", the security measure support device 100 sets the point priority order in the following order from the start point: security GW at first, information NW (information NW switch) at second, and monitoring control server at third. Then, the security measure support device 100 sets the security GW with the first point priority order as the point requiring countermeasures.
[0088] In addition, for a logical path that connects a physical path to a logical path, the higher the protection level of the physical path included in the logical path, the more secure the subsequent logical path is. Therefore, in FIG. 4, the logical path from the monitoring terminal outside the server rack 342 to the PLC is not opened. The first logical / physical path that starts a logical path to the PLC is given a higher path priority than the second logical / physical path that starts a logical path to the PLC after opening the server rack 342 and physically attacking the monitoring control server.
[0089] As a result, the security measure support apparatus 100 detects the start point of the first logical-physical path (monitoring The point priority order of the first logical path is set to a higher level than that of the starting point of the second logical path (the monitoring and control server), making it more likely to be selected as a point requiring countermeasures.
[0090] In (algorithm 2), the security measure support device 100 sets a point where multiple attack paths converge (in FIG. 4, this corresponds to the monitoring terminal [6.44]) as a countermeasure point. When there are multiple consolidation points, the point with the greater number of attack paths is prioritized as a countermeasure point. This makes it possible to block multiple attack paths at one point and secure the system, improving cost-effectiveness.
[0091] For example, Figure 3B shows three attack paths:
[0092] Attack path AP21 "OA-NW → Security GW → Information NW → Monitoring terminal" Attack path AP22 "OA-NW → Security GW → Information NW → Monitoring terminal → Monitoring control server" Attack path AP23 "OA-NW → Security GW → Information NW → Monitoring terminal → Monitoring control server → Control NW → PLC" In this case, the points priority is as follows:
[0093] [1st place] Security GW, monitoring terminal (used by attack paths AP21, AP22, and AP23) [Second place] Monitoring and control server (used by attack paths AP22 and AP23)
[0094] [3rd place] PLC (attack pass used by AP23) As (algorithm 3), for a set of candidate points constituting one attack path, if the same type of countermeasure is possible for multiple candidate points, the security measure support device 100 determines the multiple candidate points as points requiring countermeasures.
[0095] An example of the same type of countermeasure is installing the same security software on multiple routers running the same type of network OS.
[0096] This allows multiple countermeasure points to be set for one attack path, making it possible to focus on securing one attack path. In addition, even if the same type of countermeasure is applied to multiple locations, the cost required for applying it to one location does not increase significantly, making it possible to implement cost-effective countermeasures over a wide area.
[0097] As (algorithm 4), the security countermeasure support device 100 selects points requiring countermeasures, taking into consideration the current countermeasure status that has been checked on the countermeasures presence / absence checklist. This countermeasures presence / absence checklist associates, for each point in the target system 10, an attack pattern that is an attack procedure for that point with a countermeasure item for that attack pattern, and is stored in the storage device 101 by the security countermeasure support device 100. In addition, the countermeasures presence / absence checklist is provided with a check box for each countermeasure item, which allows the administrator to input whether or not a countermeasure is currently in place.
[0098] The security countermeasure support device 100 presents the pre-check countermeasure presence / absence confirmation slip to the manager on the output device 106 (screen output), and accepts input by having the manager click a check box.
[0099] For example, the security measure support device 100 determines the protection level for each attack path from the countermeasure status of the countermeasure-requiring points that have been checked on the countermeasure presence / absence confirmation sheet described above, and selects candidate points for attack paths that require countermeasures in order of lowest protection level.
[0100] This improves cost-effectiveness by providing comprehensive countermeasures against multiple attack paths. To make.
[0101] Specific examples of points requiring countermeasures extracted as described above are shown in Figures 9 and 10. The points requiring countermeasures shown in Figure 9 are highlighted in gray, extracted according to their importance, etc., in Scenario 1 to Scenario 3, which define the attack patterns at each point in the extracted attack path.
[0102] Moreover, a list of such countermeasure-requiring points is shown in Figure 10. Each record in this list, i.e., the information of the countermeasure-requiring points, specifies the name of the countermeasure-requiring point (e.g., user terminal, information LAN), the name of the attack pattern, and the severity. <Flow example> The actual procedure of the security countermeasure support method in this embodiment will be described below with reference to the drawings. The various operations corresponding to the security countermeasure support method described below are realized by a program that the security countermeasure support device 100 reads into a memory or the like and executes. This program is composed of codes for performing the various operations described below.
[0103] 10 is a diagram showing an example of a flow of the security countermeasure support method in this embodiment. In this case, the security countermeasure support device 100 collates the list of countermeasure-requiring points (information on points determined to be assets that require countermeasures and attack patterns thereon) with each record of the countermeasure candidate DB 126, and identifies countermeasure candidates that match the point type and attack pattern for each countermeasure-requiring point (s10).
[0104] A list of candidate measures identified in this way is shown in Figure 12. This list shows a specific example in which candidate security measures are linked to each combination of points and attack patterns.
[0105] Next, the security measure support device 100 calculates the scope of measures to be taken against each attack and the implementation costs for each of the security measure candidates identified in s10 based on candidate information on the security measure candidates (s11).
[0106] The calculation of the above-mentioned scope of measures is a process of counting the number of points requiring measures for which the candidate security measures are effective. For example, in the case of candidate measure (1) "education and training of users of user terminals," there is only one effective point requiring measures, #1, so the scope of measures is also "1." On the other hand, in the case of candidate measure (2) "introduction and activation of malware prevention functions on user terminals," there are three effective points requiring measures, #1, #2, and #5, so the scope of measures is also "3."
[0107] The calculation of the implementation cost is a process of extracting cost information of the candidate security measures from the corresponding records in the candidate measure DB 126. For example, in the case of candidate measure (1) “education and training of users of user terminals”, the implementation cost is “¥50k” according to the corresponding records in the candidate measure DB 126. On the other hand, in the case of candidate measure (2) “introduction and activation of anti-malware functions in user terminals”, the implementation cost is “¥500k”.
[0108] The implementation costs obtained in this way can be managed and used either as actual values or as level values (large, medium, small) in comparison with a certain reference amount.
[0109] Furthermore, the security measure support device 100 calculates application conditions for each of the candidate security measures based on the candidate information (s12).
[0110] The calculation of the application conditions described above is a process of extracting the application conditions of the security countermeasure candidate from the corresponding records in the countermeasure candidate DB 126.
[0111] For example, for candidate measure (1) “education and training of users of user terminals”, the applicable condition is “none”. On the other hand, for candidate measure (2) “introduction and activation of anti-malware functions on user terminals”, the applicable condition is “point = “user terminal, OS = “Enterprise OS”, HW = “Host Device”.
[0112] Furthermore, the security measure support device 100 determines the priority order among the candidate security measures based on the results of the calculations in s11 and s12, that is, the widest scope of the measures and the smallest implementation cost and number of application conditions (s13). Of course, in this case, the severity of the countermeasure points may also be taken into account.
[0113] However, which of the factors of the wide range of coverage, the low implementation cost, and the small number of applicable conditions is given more importance is determined by a predetermined setting made by the user.
[0114] For example, it is possible to sort security countermeasure candidates primarily based on the lowest implementation cost, and then prioritize the next highest priority element, which is the element with a larger scope of action than a certain standard, followed by the next highest priority element, which is the element with the smallest number of applicable conditions, and finally the highest priority element, which is the element with the highest severity. Of course, this is merely an example, and there is no limit to which elements should be prioritized, or to how to operate according to the degree of priority.
[0115] In the example of determining security measure costs shown in Figure 13, for example, if the candidate security measures are sorted primarily by the lowest implementation cost and then the highest priority is given to those with a scope that exceeds a certain threshold, then (1), (3), (6), and (7), which have "low" implementation costs, are identified. From these, the measures are selected based on the number of "effective countermeasure points" that have a high severity and a small number of applicable conditions. The final priority order among the candidate security measures, from highest to lowest, is (3), (1), (6), and (7).
[0116] Furthermore, the security measure support device 100 outputs information relating to the priority order of the security measure candidates determined in s13 (see FIG. 14) to the output device 106 or the user terminal 200 (s14), and ends the process.
[0117] Although the best mode for carrying out the present invention has been specifically described above, the present invention is not limited to this, and various modifications are possible without departing from the spirit and scope of the present invention.
[0118] According to this embodiment, it is possible to support efficient selection of cost-effective security measures for the entire target system with a small number of work steps.
[0119] The description of this specification makes at least the following clear: That is, in the security measure support device of this embodiment, the arithmetic device may further calculate application conditions for each of the candidate security measures based on the candidate information, and when determining the priority order, determine the priority order of the candidate security measures based on the result of the calculation that the response scope is large and the implementation cost and the number of application conditions are small.
[0120] According to this, in addition to the wide coverage of security measures (i.e., the number of types of points that can be addressed) and low implementation costs, the ease of implementation is also taken into consideration. This in turn makes it possible to propose a priority order that reflects the needs of the entire target system. This in turn makes it possible to more efficiently support the selection of cost-effective security measures that require fewer man-hours and effort.
[0121] In the security countermeasure support device of this embodiment, the arithmetic device may further execute a process of outputting information regarding the determined priority order of the security countermeasure candidates to a predetermined device.
[0122] This makes it possible to appropriately output and display information on the priority order of security countermeasure candidates to external clients, etc. via a specified network, thereby enabling more efficient support for the selection of cost-effective security countermeasures with fewer man-hours for the entire target system.
[0123] In addition, in the security measure support device of this embodiment, the computing device may be configured to, based on the profile information, set the asset point to be protected in the target system as an end point, and identify the attack path from the start point, which is the point of the attack, to the end point as the attack pattern.
[0124] This makes it possible to efficiently identify the points and patterns of attacks based on the profile information, and to appropriately identify potential security measures based on the above. As a result, it becomes possible to more efficiently support the selection of cost-effective security measures with fewer man-hours for the entire target system.
[0125] In addition, in the security countermeasure support method of this embodiment, the information processing device may further calculate application conditions for each of the candidate security countermeasures based on the candidate information, and when determining the priority, determine the priority of the candidate security countermeasures based on the result of the calculation that the coverage scope is large and the implementation cost and the number of application conditions are small.
[0126] In the security countermeasure support method of the present embodiment, the information processing device may further execute a process of outputting information relating to the determined priority order of the security countermeasure candidates to a predetermined device.
[0127] In addition, in the security countermeasure support method of this embodiment, the information processing device may, based on the profile information, set the asset point to be protected in the target system as an end point, and identify the attack path from the start point, which is the point of the attack, to the end point as the attack pattern. [Explanation of symbols]
[0128] 1 Network 10 Target System 100 Security measures support device 101 Storage device 102 Programs 103 Memory 104 Arithmetic unit 105 Input Device 106 Output Device 107 Communication Equipment 125 System Profile 126 Countermeasure candidate DB 200 User terminals
Claims
1. a storage device that holds profile information on a target system for security measures and candidate information on security measures determined according to points and patterns of attacks; a computing device that executes a process of comparing information on an occurrence point and a pattern of each attack identified based on said profile information with said candidate information to identify candidate security measures for each of said attacks, a process of calculating, for each of said candidate security measures, a response range and an implementation cost for each of said candidate security measures and application conditions for said candidate security measures based on said candidate information, and a process of determining a priority order for said candidate security measures based on the result of said calculation that the response range is large and the implementation cost and the number of said application conditions are small; A security countermeasure support device comprising:
2. The computing device includes: and further executing a process of outputting information regarding the determined priority order of the security countermeasure candidates to a predetermined device.
2. The security countermeasure support device according to claim 1.
3. The computing device includes: Based on the profile information, an asset point to be protected in the target system is set as an end point, and an attack path from a start point, which is a point of the attack, to the end point is identified as a pattern of the attack.
2. The security countermeasure support device according to claim 1.
4. An information processing device, profile information on a target system for security measures and candidate information on security measures determined according to points and patterns of attacks are stored in a storage device; a process of comparing information on an occurrence point and a pattern of each attack identified based on said profile information with said candidate information to identify candidate security measures for each of said attacks; a process of calculating, for each of said candidate security measures, a response range and an implementation cost for each of said candidate security measures, and application conditions for said candidate security measures, based on said candidate information; and a process of determining a priority order for said candidate security measures based on the result of said calculation, that the response range is large and the implementation cost and the number of said application conditions are small. A security countermeasure support method comprising the steps of:
5. The information processing device, and further executing a process of outputting information regarding the determined priority order of the security countermeasure candidates to a predetermined device.
5. The security countermeasure support method according to claim 4.
6. The information processing device, Based on the profile information, an asset point to be protected in the target system is set as an end point, and an attack path from a start point, which is a point of the attack, to the end point is identified as a pattern of the attack.
5. The security countermeasure support method according to claim 4.
Citation Information
Patent Citations
Unit and method for supporting information security measure decision, and computer program
JP2009110177A
Security measure planning support system and method
JP2018077597A
Risk assessment measure planning system and risk assessment measure planning method
JP2020166650A
Specification program, device and method
JP2020198027A