Attack scenario analysis device and attack scenario analysis method
The attack scenario analysis apparatus efficiently analyzes cyber risks in industrial control systems by generating scenarios from state transition models and calculating risk evaluation values, addressing the challenge of limited resources and device vulnerabilities.
Patent Information
- Application Number
- JP2021170652
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2041-10-19
AI Technical Summary
In industrial control systems, collecting vulnerability information for numerous control devices and IoT devices is time-consuming and labor-intensive, making it difficult to apply conventional risk analysis methods, especially when resources are limited.
An attack scenario analysis apparatus and method that generate multiple cyber attack scenarios by combining state transition models for each device type, allowing for the calculation of evaluation values for the risks to both the attacker and the victim based on cost and damage information.
Enables efficient risk analysis from both the attacker's and victim's perspectives without requiring detailed vulnerability information for each device, facilitating timely and effective countermeasures against cyber threats in industrial control systems.
Smart Images

Figure 0007685929000001 
Figure 0007685929000002 
Figure 0007685929000003
Abstract
Description
Technical Field
[0001] The present invention relates to an attack scenario analysis apparatus and an attack scenario analysis method.
Background Art
[0002] In recent years, the threat of cyberattacks has spread beyond conventional information systems and has also become apparent in computer systems (industrial control systems) in the industrial field.
[0003] Generally, the life cycle of computer equipment operating in industrial control systems is longer than that of information systems. Therefore, it is not uncommon for legacy operating systems (OS) and software for which vendor support has ended to still be in operation.
[0004] In addition, since it is difficult to easily apply security patches from the perspective of availability, industrial control systems often have many more vulnerabilities in terms of security compared to information systems.
[0005] On the other hand, as a result of the active introduction of IoT (Internet of Things) technology for the purpose of improving production efficiency and other factors, and an increase in cases where various systems are interconnected via the Internet, industrial control systems have become convenient targets for attackers.
[0006] Cyberattacks on industrial control systems, including critical infrastructure, have a significant social impact and may in some cases cause accidents related to health and safety.
[0007] The threat of APT (Advanced Persistent Threat) attacks, in which an attacker targets a target system and continuously conducts sophisticated attacks with the intention of causing such damage, is also increasing.
[0008] To counter such sophisticated attacks, it is effective to adopt an approach that involves predicting in advance, from the attacker's perspective, a series of routes and actions (hereinafter abbreviated as "attack scenario" or "scenario") from the time the attacker penetrates the target system until the goal is achieved, evaluating the risks, and then introducing necessary countermeasures.
[0009] Here, it is important to evaluate the "risk" from both perspectives of the risk to the attacker and the risk to the victim.
[0010] The former is related to the feasibility of the attack scenario, such as the "risk of incurring costs in implementing the attack" and the "risk of the attack failing".
[0011] The latter is related to the damage impact on the victim (the system targeted by the cyber attack), such as the "amount of damage caused by the attack" and the "impact on human life and the environment caused by the attack".
[0012] In Patent Document 1, a method and program are provided for identifying the route of a cyber attack and giving an evaluation value to the risk in an information processing system including a plurality of computers and the like. Specifically, by identifying the vulnerabilities of the devices existing on the attack route and comparing them with a database storing evaluation values for each predefined vulnerability, it becomes possible to perform a risk assessment for the entire analysis target system.
Prior Art Documents
Patent Documents
[0013]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0014] However, in an industrial control system, since a variety of control devices including IoT devices are operating, it takes a huge amount of time and labor to collect the vulnerability information of all the devices constituting the system.
[0015] Therefore, in a situation where resources of time and labor are limited, it is often difficult to apply the conventional risk analysis method based on vulnerability to an industrial control system. Thus, in risk analysis, it is also difficult to evaluate from both viewpoints of the risk for the attacker and the risk for the victim in the current situation.
[0016] Therefore, an object of the present invention is to enable efficient risk analysis from both viewpoints of an attacker and a victim for a cyber attack on an industrial control system.
Means for Solving the Problem
[0017] The attack scenario analysis apparatus of the present invention for solving the above problems is Information on the costs required by an attacker during a cyber-attack, information on the damage caused by the attacker's attack actions, and for each type of device in the system targeted by the attack a storage unit that holds a state transition model of a cyber attack, Corresponding to each type of device included in the system to be analyzed an attack scenario generation unit that generates a plurality of cyber attack scenarios by combining the state transition models, and the risk for the attacker that sequentially occurs when the attacker transitions attack actions along the scenarios Based on the information on the costs risk And the risk for the system Based on the information on the damage risk Each of calculate an evaluation value, and a risk evaluation unit that specifies an evaluation value of the risk related to the scenario based on the evaluation value, and is characterized by comprising the same. Each
[0018] Further, the attack scenario analysis method of the present invention is such that an information processing apparatus holds, in a storage unit, Information on the costs required by an attacker during a cyber-attack, information on the damage caused by the attacker's attack actions, and for each type of device in the system targeted by the attack a state transition model of a cyber attack, Corresponding to each type of device included in the system to be analyzed a process of generating a plurality of cyber attack scenarios by combining the state transition models, and the risk for the attacker that sequentially occurs when the attacker transitions attack actions along the scenarios Based on the information on the costs risk And the risk for the systemBased on the information on the damage Risk Each of calculate an evaluation value, and based on the Each evaluation value, identify an evaluation value of the risk related to the scenario. It is characterized by executing the process of
Effect of the Invention
[0019] According to the present invention, it is possible to generate an attack scenario from the perspective of an attacker from the configuration information of the analysis target system without individually discriminating a huge amount of vulnerability information, and perform risk analysis from both perspectives of the attacker and the analysis target system. That is, regarding cyberattacks on industrial control systems, it is possible to perform efficient risk analysis from both perspectives of the attacker and the victim.
Brief Description of the Drawings
[0020]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Mode for Carrying Out the Invention
[0021] [First Embodiment] <Flow of Attack Scenario Analysis Method>
[0022] Hereinafter, a first embodiment of the present invention will be described with reference to the drawings. FIG. 1 is a diagram showing the processing flow of the attack scenario analysis method by the attack scenario analysis device 10. It is a diagram showing the processing flow of the attack scenario analysis method by the attack scenario analysis device 10.
[0023] Hereinafter, an overview of each step in the flowchart of FIG. 1 will be described. First, the attack scenario analysis device 10 receives and acquires user input of the system configuration information 161 of the system to be analyzed via an appropriate input / output interface (step S1).
[0024] Subsequently, the attack scenario analysis device 10 automatically generates an attack scenario by combining the system configuration information 161 acquired in S1 with an attacker state transition model 162 (which may generally be called a "cyber kill chain") defined individually for each device type of the system (step S2).
[0025] In addition, the attack scenario analysis device 10 individually analyzes the risks for the attacker and the victim with respect to the attack scenario generated in S2, and assigns an evaluation value (step S3).
[0026] Here, the victim refers to the target system that is attacked by the attacker. Also, "the risk for the victim" and "the risk for the analysis target system" are synonymous.
[0027] Subsequently, the attack scenario analysis device 10 analyzes the risk of the entire attack scenario based on the evaluation values of the risks for the attacker and the victim respectively evaluated in S3 above, and calculates an evaluation value (step S4).
[0028] Finally, the attack scenario analysis device 10 associates the attack scenario with the evaluation value of the risk, outputs it to the user of the input / output device 17 (step S5), and ends the process.
[0029] <Configuration of the attack scenario analysis device> An example of a system configuration in which the functions of the above attack scenario analysis device 10 are realized by a computer is shown in FIG. 2.
[0030] In this case, the attack scenario analysis device 10 includes a CPU (Central Processing Unit) 11, a memory 12, an input / output interface 13, and a storage device 14, which are connected to each other by a bus or the like. and so on.
[0031] The CPU 11 is a central processing unit that overall controls the attack scenario analysis device 10. When the attack scenario analysis device 10 is executed, the CPU 11 expands the processing program group 15 stored in the storage device 14 into the memory 12 and executes it.
[0032] The memory 12 is, for example, a RAM (Random Access Memory) or the like, and is used as a work area when the CPU 11 executes a program.
[0033] In addition, the input / output interface 13 is an interface that outputs the processing result at the CPU 11 to an external input / output device 17.
[0034] The input / output device 17 is a device for the user to perform data input / output with respect to the attack scenario analysis device 10, and is mainly composed of a keyboard, a mouse, a display, and the like.
[0035] In addition, the storage device 14 is composed of, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The information stored in this storage device 14 is roughly classified into a processing program group 15 and a storage unit 16.
[0036] The processing program group 15 is a program that executes the processes S1 to S5 in FIG. 1. The information input unit 151 is a program that executes step S1, the attack scenario generation unit 152 is a program that executes step S2, the risk assessment unit 153 is a program that executes steps S3 and S4, and the analysis result output unit 154 is a program that executes step S5. The learning unit 155 included in the processing program group 15 is used only in the third embodiment.
[0037] In addition, the storage unit 16 becomes an area for storing a database that stores the input / output data processed by the processing program group 15. The storage unit 16 includes system configuration information 161, information transition model 162, attack scenario information 163, risk assessment information 164, and technical information 165. Note that the technical information 165 is mainly used in the second and third embodiments.
[0038] Hereinafter, each piece of information stored in the storage unit 16 will be described in association with the detailed functions of the processing program group 15.
[0039] The system configuration information 161 is information on devices constituting the analysis target system, and is input from the user by the information input unit 151.
[0040] Fig. 3 shows an example of the system configuration information 161 in this embodiment. The system configuration information 161 includes the ID (Identifier) 1611 of the device, the name 1612, the type 1613, the OS 1614, the connected network 1615, the security level 1616, and the importance level 1617.
[0041] Among these, the ID 1611 is an identifier that uniquely represents the device. Also, the name 1612 is the name of the device, and in the example shown in Fig. 3, it is "Notebook PC1", "Data Server 1", "Monitoring PC1", "PLC1", and "PLC2".
[0042] Also, the type 1613 is the type of the device, and in the example shown in Fig. 3, it is "General IT business terminal", "Control and monitoring terminal", and "Control controller".
[0043] The OS 1614 is information on the OS installed in each device, and in the example shown in Fig. 3, it is either "General-purpose OS" or "Proprietary OS".
[0044] Also, the connected network 1615 is information on the network to which each device is connected. In the example of Fig. 3, there are three networks: "Information NW (NetWork)", "Control NW", and "Internet" ".
[0045] The security level 1616 indicates the security level (level of security measures) of each device. The security level 1616 in this embodiment has three levels from 1 to 3. The higher the numerical value of the security level, the more fully the security measures are implemented.
[0046] Also, the value of the security level 1616 may be set based on whether it meets the pre-set security policy, such as "Is regular patch application being performed?" and "Is the latest antivirus software always installed?".
[0047] The importance level 1617 shows the results of evaluating the importance of each device in the system to be analyzed from three perspectives: the confidentiality 1617A, integrity 1618B, and availability 1619C of security.
[0048] In this embodiment, the confidentiality 1617A, integrity 1618B, and availability 1619C are evaluated with three items: High, Low, and None.
[0049] For example, when the evaluation of the confidentiality 1617A is "High", it indicates that if the corresponding device is attacked by a cyber-attack and its confidentiality is compromised, it will lead to serious information leakage.
[0050] Also, if the confidentiality 1617A is "Low", it means minor information leakage, and if it is "None", it means that the information leakage will not develop.
[0051] Similarly, regarding the integrity 1617B, it is evaluated by those with appropriate knowledge on the degree to which a cyber-attack on the corresponding device will lead to serious information tampering, and regarding the availability 1617C, it is evaluated on the degree to which a cyber-attack on the corresponding device will lead to serious service interruption, and the results are stored.
[0052] Also, instead of the qualitative evaluation using High, Low, and None shown in Figure 3, a method of giving quantitative evaluation values may be adopted for the confidentiality 1617A, integrity 1618B, and availability 1619C.
[0053] Subsequently, the state transition model will be described based on Figure 4. The state transition model 162 shows the state transition at the tactical level when an attacker performs a cyber-attack.
[0054] That is, the state transition model represents the transition of a series of actions (attack actions) when an attacker attacks each device. The state transition model 162 is different for each type of device and is defined individually.
[0055] FIG. 4 shows an example of the state transition model 162. The state transition model 162 is defined for each type 1613 of device defined in FIG. 3. That is, the state transition model 162 means that it can only be selected from the types of devices predefined by the device type 1613 in FIG. 3.
[0056] For example, the state transition model shown in FIG. 4 includes a state transition model 1621 applicable to the "general IT business terminal" defined by the device type 1613 in FIG. 3, and similarly, a state transition model 1622 applicable to the "control and monitoring terminal".
[0057] In addition, in the state transition model 162, when an attacker reaches each state through a predetermined attack action, it is predefined which elements of confidentiality, integrity, and availability in the target system are damaged.
[0058] For example, in FIG. 4, when the attacker reaches the "removal" state, the "confidentiality" of the general IT business terminal is damaged, when reaching the "response control" state, the "integrity" of the control and monitoring terminal is damaged, and when reaching the "control inhibition" state, the "availability" of the control and monitoring terminal is damaged.
[0059] Note that the attack scenario information 163 is information on the attack scenario generated by the attack scenario generation unit 152. As described above, the attack scenario in the present invention refers to a series of routes and attack actions from when an attacker intrudes into a target system until the goal is achieved.
[0060] The device that the attacker first accesses may be specified by the user at the information input unit 151, or may be automatically selected from the information input into the connection network 1615 of the system configuration information 161. For example, it is conceivable to set a device connected to the Internet as an attack entry point.
[0061] Similarly, the device targeted by the attacker may be specified by the user at the information input unit 151, or may be automatically selected from the information input into the importance level 1617 of the system configuration information 161. For example, it is conceivable to set as the target of the attack a device for which all of the availability 1617A, confidentiality 1617B, and availability 1617C are set to "High".
[0062] Once the device that the attacker first accesses and the device that is the final target are determined, the attack scenario analysis device 10 automatically searches for the attack path based on the information of the connection network 1615 of the system configuration information 161.
[0063] FIG. 5 is a diagram showing the system configuration information 161 shown in FIG. 3 as a network configuration diagram. In the present embodiment, assuming that the attacker first accesses a notebook PC1 connected to the Internet and the monitoring PC1 as the target device of the attack, a method for generating an attack scenario will be described.
[0064] First, regarding the attack path, consider, as an example, the shortest path "notebook PC1 → monitoring PC1". In this case, the attack scenario analysis device 10 can model the actions performed by the attacker on the notebook PC1 and the monitoring PC1 by referring to the state transition model 162 of FIG. 4 corresponding to the device.
[0065] According to the system configuration information 161 of FIG. 3, the type of the notebook PC1 is "general IT business terminal", and the type of the monitoring PC1 is "control monitoring device".
[0066] Therefore, the attack scenario analysis device 10 can model the actions of the attacker on the notebook PC1 using the state transition model 1621 of the general IT business terminal in FIG. 4.
[0067] Also, the attack scenario analysis device 10 can model the actions of the attacker on the monitoring PC1 using the state transition model 1622 of the control monitoring terminal in FIG. 4. Then, by combining these, an attack scenario can be generated.
[0068] Figure 6 shows a schematic diagram of an attack scenario generated from the above combination. An action ID, which is a unique identifier, is assigned to the attack actions in which the attacker transitions states. In the case of the attack scenario in Figure 6, action IDs from 1 to 11 are assigned.
[0069] Also in Figure 6, the action with action ID "1" assigned is displayed as "Action 1", and the same display format is adopted for each action with action IDs from 2 to 11.
[0070] The path in the attack scenario of Figure 6 is fixed as "Notebook PC1 → Monitoring PC1", but the actions of the attacker can be considered in the following 4 patterns.
[0071] [Attack Scenario ID: 1] Action 1 → Action 2 → Action 6 → Action 7 → Action 8 → Action 9 → Action 10
[0072] [Attack Scenario ID: 2] Action 1 → Action 2 → Action 6 → Action 7 → Action 8 → Action 9 → Action 11
[0073] [Attack Scenario ID: 3] Action 1 → Action 2 → Action 3 → Action 4 → Action 5 → Action 7 → Action 8 → Action 9 → Action 10
[0074] [Attack Scenario ID: 4] Action 1 → Action 2 → Action 3 → Action 4 → Action 5 → Action 7 → Action 8 → Action 9 → Action 11
[0075] A unique attack scenario ID is assigned to each attack scenario. In Figure 7, as an example, a schematic diagram of the attack scenario with attack scenario ID 1 is shown.
[0076] In the attack scenario analysis device 10, even when the attack paths are the same, if the state transitions of the attacker are different, they are recognized as separate attack scenarios. That is, for a single attack path of "Notebook PC 1 → Monitoring PC 1", since there are four patterns of state transitions, the attack scenario generation unit 152 identifies them as four individual attack scenarios. These attack scenarios are stored as attack scenario information 163 together with the assigned attack scenario IDs.
[0077] FIG. 8 is an example of the attack scenario information 163, and is an example of a table in which information on the attack scenario with the above attack scenario ID of "1" is stored. In the attack scenario information 163, an attack step 1631 representing the order of attacks, an action ID 1632, details 1633 of each action ID, an attack cost 1634, and a damage impact level 1635 are stored in association with each other. The attack cost 1634, the damage impact level 1635, the total value 1636, and the comprehensive risk assessment value 1637 will be described later.
[0078] In addition, the risk assessment information 164 stores information on the risk of the attack scenario analyzed by the risk assessment unit 153. The risk assessment in the present invention is performed on the actions of the attacker to transition the state from both the viewpoints of the attacker and the victim.
[0079] By focusing on the actions of the attacker to transition the state, it becomes possible to evaluate the risk considering the states of the attacker before and after the transition, and the accuracy is improved compared to the case of evaluating the risk for the state of the attacker alone.
[0080] In this embodiment, for example, "attack cost" is adopted as an index for evaluating the risk for the attacker. The attack cost means the effort spent by the attacker when implementing a cyber attack.
[0081] When the attack cost is high, the risk for the attacker increases, so it is considered that the attacker will select an attack scenario with a low attack cost as much as possible. Therefore, it is necessary to preferentially implement countermeasures against attack scenarios with a low attack cost. scenarios.
[0082] As described above, the attack cost is calculated for the actions in which the attacker changes the state. For calculating the attack cost, the device type 1613, OS 1614, connection network 1615, and security level 1616 in the system configuration information 161 of FIG. 3 may be utilized. For example, when taking an action that transitions to the "intruded" state, it is conceivable to calculate a higher attack cost when passing through an in-house network such as the information NW or control NW than when passing through the Internet. According to this evaluation method, in the case of FIG. 6, when comparing action 1 and action 7 that both transition to the same "intruded" state, the attack cost of action 7 is calculated to be higher than that of action 1.
[0083] As an index for evaluating the risk for the attacker, in addition to the "attack cost", any index related to the risk for the attacker may be used, such as the "attack difficulty" indicating the difficulty of the attack and the "attack detection rate" indicating the possibility of the attack being detected. These may be combined to calculate the evaluation value of the risk for the attacker.
[0084] On the other hand, as an index for evaluating the risk for the victim, for example, the "damage impact degree" is adopted. The damage impact degree is an index obtained by quantifying the damage impact suffered when the analysis target system is subjected to a cyber attack. It is considered that the attacker will execute an attack scenario with a higher damage impact degree as much as possible. Therefore, it is necessary to preferentially implement countermeasures against attack scenarios with a high damage impact degree.
[0085] Similar to the attack cost, the damage impact degree is also calculated for the actions in which the attacker changes the state. For calculating the damage impact degree, the confidentiality 1617A, integrity 1617B, and availability 1617C of the importance 1617 in the system configuration information 161 of FIG. 3 may be utilized.
[0086] For example, in the schematic diagram of the attack scenario in FIG. 6, when the attacker performs Action 4, the confidentiality of the notebook PC1 is compromised. Since "Low" is assigned to the confidentiality 1617A of the notebook PC1, when the attacker performs Action 4, it means that it will lead to a minor information leakage for the system.
[0087] Similarly, when the attacker performs Action 10, the integrity of the monitoring PC1 is inhibited. Since "High" is assigned to the integrity 1617C of the monitoring PC1, when the attacker performs Action 10, it means that it will lead to a serious information forgery for the system. When quantifying these damage impact degrees, the items for evaluating the impact of an attack in CVSS v3 (Common Vulnerability Scoring System v3) may be referred to.
[0088] As an index for evaluating the risk for the victim, in addition to the "damage impact degree", any index related to the risk for the victim, such as the "assumed damage amount" indicating the assumed damage amount, may be used, and these may be combined to calculate the evaluation value of the risk for the victim.
[0089] FIG. 9 shows an example of the risk assessment information 164. In this embodiment, the attack cost 1642, which is the evaluation value of the risk for the attacker, and the damage impact degree 1643, which is the evaluation value of the risk for the victim, are associated with the action ID 1641.
[0090] Such risk assessment information 1642 is also input to the attack cost 1634 and the damage impact degree 1635 in FIG. 8. In the total value 1636 in the attack scenario information 163 in FIG. 6, the value obtained by summing up the attack cost and the damage impact degree for the entire attack scenario is set.
[0091] Also, in the comprehensive risk assessment value 1637, the value obtained by dividing the total value of the damage impact degree by the total value of the attack cost is stored. That is, it can be interpreted that an attack scenario with a high comprehensive risk assessment value can cause a large damage impact degree with a small attack cost. It can be interpreted that it can cause a large damage impact degree with a small attack cost.
[0092] In this embodiment, a simple division as described above is adopted as the calculation method for the comprehensive risk evaluation value 1637. However, any calculation method can be used as long as the value is derived using both the risk evaluation values for the attacker and the victim.
[0093] FIG. 10 is a diagram showing an example in which the analysis result output unit 154 reads the attack scenario information 163 and displays it on the input / output device 17 as the attack scenario analysis result 1540. The attack scenario analysis result 1540 includes a table 1549, a sorting button 1546, a risk evaluation method change button 1547, and a batch file output button 1548.
[0094] Among these, the table 1549 associates the attack scenario ID 1541, the attack cost 1542, the damage impact degree 1543, and the comprehensive risk evaluation value 1544.
[0095] The combined value 1636 calculated in FIG. 8 is stored for the attack cost 1542 and the damage impact degree 1543, and the same value as the comprehensive risk evaluation value 1637 calculated in FIG. 8 is stored for the comprehensive risk evaluation value 1544, corresponding to the attack scenario ID 1541.
[0096] Also, upon receiving the pressing of the detailed display button 1545, the attack scenario analysis device 10 calls the detailed information of the corresponding attack scenario from the attack scenario information 163 and displays it to the user.
[0097] Also, upon receiving the pressing of the detailed display button 1545, the attack scenario analysis device 10 may display a schematic diagram of the corresponding attack scenario as shown in FIG. 7. Alternatively, a tabular attack scenario as shown in FIG. 8 may be displayed.
[0098] Also, upon receiving the pressing of the sorting button 1546, the attack scenario analysis device 10 sorts, that is, rearranges, the display contents of the table 1549 in ascending or descending order of the attack scenario ID 1541, the attack cost 1542, the damage impact degree 1543, and the comprehensive risk evaluation value 1544.
[0099] Depending on the user, instead of the comprehensive risk assessment value 1544, it is also conceivable to evaluate the risk of the attack scenario using either the attack cost 1542 or the damage impact level 1543.
[0100] Upon receiving the pressing of the risk assessment method change button 1547, the attack scenario analysis device 10 changes the risk assessment method for the attacker and the victim. For example, it is conceivable to switch the risk assessment method for the attacker from "attack cost" to "attack detection rate".
[0101] Also, upon receiving the pressing of the batch file output button, the attack scenario analysis device 10 outputs both the display content of Table 1549 and the display content obtained by pressing the detailed display button 1545 in a batch as a file.
[0102] [Second Embodiment] Hereinafter, a second embodiment of the present invention will be described with reference to the drawings. In the first embodiment, when generating an attack scenario as shown in FIG. 6, a single action ID is assigned to the action of transitioning from one state to the next state.
[0103] However, the technologies for realizing each action are diverse. Taking the action of transitioning from a certain state to the "intruded" state as an example, various technologies such as "malware infection via targeted emails" and "exploitation of remote login services" are used to realize this action.
[0104] In this embodiment, an attack scenario analysis device 10 that enables generating and evaluating attack scenarios separately according to the technologies adopted as in the above example will be described.
[0105] The attack scenario analysis device 10 according to the second embodiment has a configuration in which technical information 165 is added to the storage unit 16 of the attack scenario analysis device according to the first embodiment.
[0106] FIG. 11 is a diagram showing an example of a flow of an attack scenario analysis method by the attack scenario analysis device 10 according to the second embodiment.
[0107] In the flow of FIG. 11, steps S11, S13, S14, and S15 are the same as steps S1, S3, S4, and S5 in the flow of FIG. 1, respectively.
[0108] On the other hand, in step S12, different from step S2, the attack scenario analysis device 10 automatically generates an attack scenario by comprehensively combining the input system configuration information 121 with the attacker's state transition model 162 and technical information 165 defined individually for each type of device.
[0109] FIG. 12 shows an example of the technical information 165. The technical information 165 stores a list of states 1652 that an attacker transitions to in a series of attack scenarios and technologies 1653 for realizing the state transitions.
[0110] Each realization technology 1653 is defined with a technology ID 1651 for uniquely identifying the technology, a technology difficulty 1654 representing the difficulty of using the technology, an implementation effort 1655 indicating the effort required for an attack using the technology, an attack detection rate 1656 representing the possibility of the attack being detected, a damage impact degree 1657 indicating the degree of damage caused by the attack using the technology, and an assumed damage amount 1658 indicating the amount of damage caused by the attack using the technology.
[0111] In FIG. 12, each of the technology difficulty 1654, implementation effort 1655, attack detection rate 1656, damage impact degree 1657, and assumed damage amount 1658 is evaluated as "High", "Mid", "Low", but a quantitative score may also be given.
[0112] FIG. 13 shows an example of attack scenario information 163A storing the attack scenarios generated in the second embodiment. In the attack scenario generation unit 152 of the second embodiment, attack scenarios are generated for all combinations of action IDs and technology IDs and stored in the attack scenario information 163A.
[0113] In FIG. 13, an example of an attack scenario with an attack scenario ID of "1" is displayed, and a combination of an action ID 1632A and a technology ID 1638A corresponding to each attack step 1631A, and its details 1633A are associated with each other.
[0114] Also, similar to FIG. 8, the attack scenario analysis device 10 calculates an attack cost 1634A and a damage impact level 1635A for each attack step, and calculates a comprehensive risk evaluation value 1637A based on their total value 1636A.
[0115] In the second embodiment, when calculating the attack cost 1634A, in addition to the device type 1613, OS 1614, connection network 1615, and security level 1616 in the system configuration information 161 of FIG. 3, the evaluation of the technical difficulty 1654 in FIG. 12 may also be taken into consideration.
[0116] For example, when taking an action to move to an "intruded" state, assume an operation where the attack cost is calculated higher when using a technology with an evaluation of "High" for technical difficulty than when using a technology with an evaluation of "Low".
[0117] Finally, the analysis result output unit 154 reads the attack scenario information 163A and outputs it to the analysis result output unit 154, thereby completing the cyber attack scenario evaluation of this embodiment.
[0118] [Third Embodiment] Hereinafter, a third embodiment of the present invention will be described with reference to the drawings. In the attack scenario analysis measures in the first and second embodiments, a method of calculating risk evaluation values for all attack scenarios and outputting them to the user was adopted. On the other hand, in this embodiment, an attack scenario analysis measure will be described in which, through analysis using reinforcement learning, an optimal attack scenario for the attacker is extracted and output to the user.
[0119] The attack scenario analysis device 10 according to the third embodiment has a configuration in which a learning unit 155 is added to the processing program group 15 of the attack scenario analysis device according to the first embodiment, and technical information 165 is added to the storage unit 16.
[0120] FIG. 14 is a diagram showing an example of a flow of an attack scenario analysis method by the attack scenario analysis device 10 according to the third embodiment. Steps S111, S112, and S113 in the flow of FIG. 14 perform the same processing as steps S11, S12, and S13 in FIG. 11, respectively.
[0121] Here, in step S114, the learning unit 155 defines the reward for each action based on the evaluation values of the risks for the attacker and the victim for each action calculated in step 113, and repeats the learning.
[0122] The above learning method is arbitrary, and for example, Q-learning, which is one method of reinforcement learning, may be used. In this Q-learning, a reward is given to all actions that can be selected in each state, and the action value function Q is learned. In step S113, the evaluation values of the risks for the attacker and the victim are calculated for each combination of action and technology.
[0123] To fit this example into the framework of Q-learning, the combination of each action and technology may be redefined as an individual action. For example, the combination of action ID XX and technology ID YY, and the combination of action ID XX and technology ID ZZ may be treated as different actions, and their respective action IDs may be redefined as XX-YY and XX-ZZ. FIG. 15 shows an example of redefining FIG. 13 according to the action IDs described above.
[0124] Regarding the reward given to an action, a higher reward may be set for an action with a higher evaluation value of the risk for the victim, and a lower reward may be set for an action with a higher evaluation value of the risk for the attacker.
[0125] In step S115, in the learning unit 155, the attack scenario in which the combination of actions and techniques with the maximum action value function Q learned in the above step S114 is selected is regarded as the optimal attack scenario for the attacker and output to the analysis result output unit 154. Thus, the cyber attack scenario evaluation of this embodiment is completed.
[0126] As described above, the best mode for carrying out the present invention has been specifically described. However, the present invention is not limited to this, and various modifications can be made without departing from the gist thereof.
[0127] According to such an embodiment, it becomes possible to perform an efficient risk analysis from the viewpoints of both the attacker and the victim regarding a cyber attack on an industrial control system.
[0128] From the description of this specification, at least the following is clarified. That is, in the attack scenario analysis device of this embodiment, the storage unit holds the state transition model for each type of device constituting the system, and the attack scenario generation unit combines the state transition models corresponding to the types of each device included in the system to generate a plurality of the scenarios.
[0129] According to this, in response to the case where information regarding the devices constituting the system is obtained, it becomes possible to generate scenarios with higher accuracy. As a result, it becomes possible to perform a more efficient risk analysis from the viewpoints of both the attacker and the victim regarding a cyber attack on an industrial control system.
[0130] Further, in the attack scenario analysis device of this embodiment, the storage unit further holds information on the cost required for the attack action, and the risk evaluation unit aggregates, based on the cost information, the cost of each attack action included in the scenario from at least one of the viewpoints of the labor required for the attack, the difficulty of the attack, and the attack detection rate representing the possibility of the attack being detected, and sets the aggregated cost as the risk evaluation value for the attacker.
[0131] According to this, it becomes possible to perform risk assessment by more accurately considering the cost from the perspective of the attacker. As a result, it becomes possible to perform more efficient risk analysis from both the perspectives of the attacker and the victim regarding cyberattacks on industrial control systems.
[0132] Further, in the attack scenario analysis device of the present embodiment, the storage unit may further hold information on the damage caused by the attack actions, and the risk assessment unit may, regarding the scenario, aggregate the costs from at least either the perspective of the damage impact degree representing the impact of the damage caused by each of the attack actions included in the scenario and the assumed damage amount representing the damage amount assumed to be caused by the attack, based on the information on the damage, and use the aggregated cost as the risk assessment value for the system.
[0133] According to this, it becomes possible to perform risk assessment by more accurately considering the cost of the analysis target system, which is the attacked side. As a result, it becomes possible to perform more efficient risk analysis from both the perspectives of the attacker and the victim regarding cyberattacks on industrial control systems.
[0134] Further, the attack scenario analysis device of the present embodiment may further include an information input unit that receives input of information on the devices constituting the system.
[0135] According to this, it becomes possible to efficiently acquire information on devices that can improve the accuracy of scenario generation. As a result, it becomes possible to perform more efficient risk analysis from both the perspectives of the attacker and the victim regarding cyberattacks on industrial control systems.
[0136] Further, in the attack scenario analysis device of the present embodiment, the attack scenario generation unit may select, based on the information on the importance of the devices of the system input by the information input unit, the device that the attacker first accesses and the device that is the final target in the system in the scenario.
[0137] According to this, it becomes possible to accurately identify the start / end in the scenario. As a result, regarding cyberattacks on industrial control systems, more efficient risk analysis can be performed from the perspectives of both the attacker and the victim. This enables more efficient risk analysis.
[0138] Further, the attack scenario analysis apparatus according to the present embodiment may further include an analysis result output unit that displays a scenario list in which each scenario generated by the attack scenario generation unit is associated with the evaluation value obtained for each scenario by the risk evaluation unit.
[0139] According to this, it becomes possible to accurately present to the user what the characteristics of each scenario are. As a result, regarding cyberattacks on industrial control systems, more efficient risk analysis can be performed from the perspectives of both the attacker and the victim.
[0140] Further, in the attack scenario analysis apparatus according to the present embodiment, the storage unit further holds information on the technology for realizing the attack action as the cost information, and the attack scenario generation unit combines the state transition model and the information on the technology for realizing the attack action in the state transition model based on the technology information to generate the scenario in the system.
[0141] According to this, various processes can be performed taking into account the technical characteristics of each attack action constituting the scenario and the costs (both for the attacker side and the victim side) based thereon. As a result, regarding cyberattacks on industrial control systems, more efficient risk analysis can be performed from the perspectives of both the attacker and the victim.
[0142] Further, the attack scenario analysis apparatus according to the present embodiment may further include a learning unit that defines a reward for a combination of an attack action for the attacker to transition the state and the technology based on the evaluation value of the risk, and performs reinforcement learning on the scenario.
[0143] According to this, it becomes possible to apply a scenario obtained for a certain system to a system of other systems having similar configurations and features. As a result, for cyberattacks on industrial control systems, more efficient risk analysis from both the perspectives of the attacker and the victim becomes possible.
Explanation of Signs
[0144] 10 Attack scenario analysis device 11 CPU 12 Memory 13 Input / output interface 14 Storage device 15 Group of processing programs 151 Information input section 152 Attack scenario generation section 153 Risk evaluation section 154 Analysis result output section 155 Learning section 16 Storage section 161 System configuration information 162 State transition model 163 Attack scenario information 164 Risk evaluation information 165 Technical information
Claims
Claim 1. A storage unit that holds information on the cost required for an attacker in a cyber attack, information on the damage caused by the attack actions of the attacker, and a state transition model of cyber attacks for each type of device in the system to be attacked; An attack scenario generation unit that generates a plurality of cyber attack scenarios by combining the state transition models corresponding to each type of device included in the system to be analyzed; A risk evaluation unit that calculates respective evaluation values of the risk based on the information on the cost for the attacker and the risk based on the information on the damage for the system, which are sequentially generated when the attacker transitions attack actions along the scenario, and specifies an evaluation value of the risk regarding the scenario based on the respective evaluation values; An attack scenario analysis device, characterized by comprising the above. Claim 2. The risk evaluation unit: Regarding the scenario, aggregates the costs from at least one of the viewpoints of the labor required for the attack, the difficulty of the attack, and the attack detection rate representing the possibility of the attack being detected, for each of the attack actions included in the scenario, based on the information on the cost, and uses the aggregated cost as the evaluation value of the risk for the attacker. The attack scenario analysis device according to Claim 1, characterized by the above. Claim 3. The risk evaluation unit: Regarding the scenario, aggregates the costs from at least one of the viewpoints of the damage impact degree representing the impact of the damage caused by the attack and the assumed damage amount representing the damage amount assumed to be caused by the attack, for each of the attack actions included in the scenario, based on the information on the damage, and uses the aggregated cost as the evaluation value of the risk for the system. The attack scenario analysis device according to Claim 1, characterized by the above. Claim 4. The attack scenario analysis device according to Claim 1, further comprising an information input unit that receives input of information on the devices constituting the system. Claim 5. The attack scenario generation unit: Based on the information on the importance of the devices of the system input by the information input unit, selects the device that the attacker first accesses and the device that is the final target in the system in the scenario. The attack scenario analysis device according to Claim 4, characterized by the above. Claim 6. An analysis result output unit that displays a scenario list associating each scenario generated by the attack scenario generation unit with the evaluation value obtained for each scenario by the risk evaluation unit. The attack scenario analysis device according to claim 5, characterized in that.
7. The storage unit Further holds information on the technology for realizing the attack action as the information on the cost, The attack scenario generation unit Based on the information on the technology, combines the state transition model and the information on the technology for realizing the attack action in the state transition model to generate the scenario in the system. The attack scenario analysis device according to claim 2, characterized in that.
8. Further includes a learning unit that defines a reward for a combination of an attack action for the attacker to transition the state and the technology based on the evaluation value of the risk, and performs reinforcement learning on the scenario. The attack scenario analysis device according to claim 7, characterized in that.
9. An information processing device In the storage unit, holds information on the cost required for the attacker in a cyber attack, information on the damage caused by the attack action of the attacker, and a state transition model of cyber attacks for each type of device of the system to be attacked. A process of generating a plurality of cyber attack scenarios by combining the state transition models corresponding to each type of device included in the system to be analyzed. A process of calculating each evaluation value of the risk based on the information on the cost for the attacker and the risk based on the information on the damage for the system that occur successively when the attacker transitions the attack action along the scenario, and specifying the evaluation value of the risk regarding the scenario based on each evaluation value. An attack scenario analysis method characterized by executing.
Citation Information
Patent Citations
Unit and method for supporting information security measure decision, and computer program
JP2009110177A
Security measure planning support system and method
JP2018077597A
Threat Scoring System and Method
JP2019533856A
Control system and setting method
JP2020166520A
Incident scenario generation device and incident scenario generation system
JP2021005165A