Security management system and security management method

The system automates security countermeasure implementation based on impact assessment, addressing the inefficiency of manual decision-making in existing systems by reducing administrative burden and enabling rapid response to security threats.

JP7701851B2Active Publication Date: 2025-07-02HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2021171490
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-20
Publication Date
2025-07-02
Estimated Expiration
2041-10-20

AI Technical Summary

Technical Problem

Existing security management systems require significant administrative burden to implement security countermeasures, as administrators must decide on the implementation of security measures considering business impact, which can be time-consuming and inefficient.

Method used

An information processing system that monitors communication paths, identifies unauthorized communication, assesses the scope of influence, generates countermeasure plans, and automatically implements them based on impact values, reducing administrative burden.

Benefits of technology

Quickly implements necessary security countermeasures while minimizing the administrative load on system managers, ensuring timely response to security violations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007701851000001
    Figure 0007701851000001
  • Figure 0007701851000002
    Figure 0007701851000002
  • Figure 0007701851000003
    Figure 0007701851000003
Patent Text Reader

Abstract

To provide a system and method capable of conducting necessary countermeasures against security violation quickly while reducing a burden on an administrator who manages the security.SOLUTION: A security management system stores a communication path utilized for communication between business devices that configure a monitoring target system and a business communication importance that is information on importance of each communication path, monitors communication in the monitoring target system, and when detecting unauthorized communication, identifies a communication path utilized for unauthorized communication. The security management system then identifies an influence range of the unauthorized communication on the monitoring target system on the basis of the identified communication path, and generates a countermeasure plan against the unauthorized communication on the basis of the identified influence range. The security management system further identifies the communication path that can be affected when the countermeasure plan is conducted, calculates an influence value that is an index indicating a degree of influences of the countermeasure plan on business on the basis of the business communication importance of the identified communication path, and determines whether or not to automatically conduct the countermeasure plan on the basis of the influence value.SELECTED DRAWING: Figure 10
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a security management system and a security management method.

Background Art

[0002] Patent Document 1 describes a security countermeasure plan design device configured to shorten the operation time from attack detection to attack countermeasure against attacks occurring in a network and to realize an early response to attacks. The security countermeasure plan design device stores a countermeasure template for creating a security countermeasure plan against an attack, receives attack detection information from an attack detection device that detects an attack, extracts a countermeasure template corresponding to the detection information, creates a security countermeasure plan based on the extracted countermeasure template and the detection information, refers to device information and topology information in the network, extracts an executable security countermeasure plan from the created security countermeasure plans, and outputs the extracted security countermeasure plan.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] As described above, the security countermeasure plan design device described in Patent Document 1 refers to device information and topology information in the network and presents an executable security countermeasure plan to the administrator from among the security countermeasure plans created based on the countermeasure template and the detection information.

[0005] However, whether to implement the proposed security measures needs to be ultimately decided by the administrator while considering the impact on the business, and the problem is that the burden on the administrator is significant. On the other hand, for security measures that can tolerate the impact on the business, it can be said that it is preferable from a security perspective to implement them promptly.

[0006] The present invention has been made in view of such a background, and an object thereof is to provide a security management system and a security management method capable of quickly implementing necessary countermeasures against security violations while reducing the burden on the administrator who performs security management.

Means for Solving the Problems

[0007] One aspect of the present invention for achieving the above object is an information processing system (security management system) that performs security management of a monitoring target system configured to include a plurality of business devices communicably connected, which is configured using an information processing device having a processor and a memory, stores information indicating a communication path used for communication between the business devices and business communication importance that is information indicating the importance of each of the communication paths, monitors communication performed in the monitoring target system, and when detecting unauthorized communication performed in the monitoring target system, identifies the communication path used for the unauthorized communication, identifies the scope of influence that the unauthorized communication has on the monitoring target system based on the identified communication path, generates a countermeasure plan for the unauthorized communication based on the identified scope of influence, identifies the communication paths that may be affected when the countermeasure plan is implemented, obtains an impact value that is an index indicating the degree of impact on the business based on the business communication importance of the identified communication paths, and determines whether to automatically implement the countermeasure plan based on the impact value. Performed by the system to be monitored Based on the impact value, it is determined whether to automatically implement the countermeasure plan.

[0008] In addition, the problems disclosed in the present application and the solutions thereto will be clarified by the embodiments for carrying out the invention and the drawings.

Effects of the Invention

[0009] According to the present invention, it is possible to quickly implement necessary countermeasures against security violations while reducing the burden on the administrator who performs security management.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments of the present invention will be described with appropriate reference to the drawings. The following description and drawings are examples for explaining the present invention, and for the sake of clarity of explanation, appropriate omissions and simplifications are made. The present invention can be implemented in various other forms. Unless otherwise particularly limited, each component may be singular or plural.

[0012] In the following description, the same or similar configurations may be denoted by the same reference numerals and redundant descriptions may be omitted. Also, in the following description, the letter "S" attached before a reference numeral means a processing step.

[0013] In the following description, various types of information may be described using expressions such as "table", but the various types of information may be represented by data structures other than these. Also, in order to indicate that it does not depend on the data structure, "XX table" or the like may be referred to as "XX information". Also, when describing identification information, expressions such as "identification information", "identifier", "name", "ID", "number", etc. are used, but these are mutually replaceable.

[0014] FIG. 1 shows a schematic configuration of an information processing system (hereinafter referred to as "security management system 1") described as one embodiment. As shown in the figure, the security management system 1 includes a monitoring target system 5, a communication monitoring device 20, a countermeasure execution device 30, a manager device 40, and a countermeasure support device 100. Note that the monitoring target system 5 does not necessarily have to be a component of the security management system 1. The communication monitoring device 20, the countermeasure execution device 30, the manager device 40, and the countermeasure support device 100 are all configured using information processing devices (computers).

[0015] The security management system 1 has a function of generating a necessary security countermeasure plan (hereinafter referred to as "countermeasure plan") for unauthorized communication (hereinafter referred to as "unauthorized communication") detected in the monitoring target system 5, while considering the impact on the operations performed by the monitoring target system 5, and automatically implementing the plan when the impact on the operations is acceptable. According to the security management system 1 it is possible to reduce the burden on the person (hereinafter referred to as "manager 2") who monitors the monitoring target system 5 while maintaining the continuity of the operations.

[0016] The monitored system 5 is a so-called industrial network system. The type of the monitored system 5 is not necessarily limited. For example, it can be a factory IoT system (IoT: Internet of Things), a smart factory, a social infrastructure system (such as a railway transportation system, a power transmission and transformation system, a water supply and sewerage system, a road system, a communication and broadcasting system, etc.). And so on (such as a water supply and sewerage system, a road system, a communication and broadcasting system, etc.).

[0017] The exemplified monitored system 5 includes one or more controllers 61, one or more actuators 71, one or more sensors 72, and a control server 50. Hereinafter, these devices are collectively referred to as "business devices". The business devices function as information processing devices capable of two-way communication via a communication network.

[0018] The monitored system 5 includes an information network 51 and a control network 52, which are communication networks that communicably connect the components of the system. When the monitored system 5 is, for example, a factory IoT system, the information network 51 is, for example, a control network, and the control network 52 is, for example, a field network.

[0019] The information network 51 and the control network 52 are communication networks of wired or wireless methods, such as LAN (Local Area Network), WAN (Wide Area Network), the Internet, various public wireless communication networks, dedicated lines, etc. These communication networks are all appropriately subject to a certain level of security management, such as the use of encrypted communication, VPN (Virtual Private Network), the installation of firewalls and DMZ (DeMilitarized Zone).

[0020] ​As shown in the figure, one or more controllers 61 and a control server 50 are connected to the information network 51. Further, each of the above controllers 61, one or more actuators 71, and one or more sensors 72 are communicably connected to the control network 52.

[0021] The control server 50 and the controller 61 are connected via the information network 51 in a state where two-way communication is possible. The control server 50 monitors and controls the operating states of the controller 61, the actuator 71, and the sensor 72 via the information network 51. For example, the control server 50 transmits a control instruction to the controller 61 via the information network 51. For example, the control server 50 receives information (such as the measured value of the sensor) sent from the controller 61 via the information network 51, and monitors the state of each controller 61 based on the received information. The control server 50 functions as, for example, an EWS (Engineering WorkStation), and, for example, changes / updates (upgrades) the logic of the control program (firmware) executed in the controller 61.

[0022] The controller 61 is connected to the actuator 71 and the sensor 72 via the control network 52 in a state where two-way communication is possible. The controller 61 is, for example, a PLC (Programmable Logic Controller), and follows an instruction sent from the control server 50 via the information network 51, and performs, for example, control of the rotation speed of the motor constituting the actuator 71, operation setting, collection of information output by the sensor 72, etc. via the control network 52.

[0023] The actuator 71 functions a valve, a motor, an electric motor, etc. according to a set value set based on an instruction from the controller 61, for example. The sensor 72 measures physical quantities such as temperature, flow rate , pressure, etc., and transmits the measured value to the controller 61 via the control network 52.

[0024] The communication monitoring device 20 acquires communications (packets, communication messages) flowing through the information network 51 via the mirror port 41, and monitors (such as detecting unauthorized communications) the communications in the information network 51 by analyzing the acquired information. The communication monitoring device 20 acquires the content of communications (packets, communication messages) flowing through the control network 52 via the mirror port 42, and monitors (such as detecting unauthorized communications) the communications in the control network 52 by analyzing the acquired content.

[0025] As shown in the figure, the communication monitoring device 20, the countermeasure execution device 30, the administrator device 40, and the countermeasure support device 100 are all connected via the countermeasure network 43 in a state where they can communicate bidirectionally with each actuator 71 and each sensor 72.

[0026] The countermeasure execution device 30 is communicably connected to the monitored system 5 and the countermeasure support device 100 via the countermeasure network 43. The countermeasure network 43 is a wired or wireless communication network, such as a LAN, WAN, Internet, various public wireless communication networks, dedicated lines, etc.

[0027] The countermeasure execution device 30 has processing authority (control authority) over each business device of the monitored system 5. The countermeasure execution device 30 receives a countermeasure command sent from the countermeasure support device 100 via the countermeasure network 43. The countermeasure execution device 30 converts the received countermeasure command into, for example, a control command or a control logic program that the countermeasure execution device 30 can execute or process (hereinafter referred to as "control command"), and transmits the converted control command or control logic program (hereinafter referred to as "control command") to the business device to which the countermeasure plan is to be applied (hereinafter referred to as "countermeasure business device") to cause the countermeasure business device to execute the process corresponding to the countermeasure plan (implementation of security countermeasures).

[0028] The countermeasure support device 100 analyzes the operations affected by the unauthorized communication using the information on the unauthorized communication received from the communication monitoring device 20 (hereinafter referred to as "detection information"), and generates a countermeasure plan based on the analysis result. Further, the countermeasure support device 100 obtains the magnitude of the impact on the operations due to the countermeasure (hereinafter referred to as "operation impact value"), and determines whether the countermeasure plan can be automatically executed based on the obtained operation impact value. Then, when it is determined that the countermeasure plan can be automatically executed, the countermeasure support device 100 generates a countermeasure command based on the countermeasure plan, and transmits the generated countermeasure command to the countermeasure execution device 30.

[0029] The administrator device 40 presents the countermeasure plan received from the countermeasure support device 100 to the administrator 2, and accepts the input of the intention indication as to whether to execute the countermeasure plan. When the administrator device 40 accepts the input of the intention indication, it transmits the received content to the countermeasure support device 100.

[0030] FIG. 2 is a block diagram showing a hardware configuration example of an information processing apparatus used for realizing the components of the security management system 1 (communication monitoring device 20, countermeasure execution device 30, administrator device 40, control server 50, countermeasure support device 100). The illustrated information processing apparatus 10 includes a processor 11, a main storage device 12 (memory), an auxiliary storage device 13, an input device 14, an output device 15, and a communication device 16. Examples of the information processing apparatus 10 include a personal computer, an office computer, a server device, a smartphone, a tablet, a general-purpose machine (mainframe), and the like. Note that two or more of the components of the security management system 1 (communication monitoring device 20, countermeasure execution device 30, administrator device 40, control server 50, countermeasure support device 100) may be realized by a common information processing apparatus 10.

[0031] The information processing apparatus 10 may be realized using virtual information processing resources provided using virtualization technology, process space separation technology, etc., such as a virtual server provided by, for example, a cloud system. Also, all or part of the functions provided by the information processing apparatus 10 may be realized by, for example, services provided by a cloud system via an API (Application Programming Interface) or the like. Also all or part of the functions provided by the information processing apparatus 10 may be realized using, for example, SaaS (Software as a Service), PaaS (Platform as a Service), IaaS (Infrastructure as a Service), etc.

[0032] The processor 11 is configured using, for example, a CPU (Central Processing Unit), MPU (Micro Processing Unit), GPU (Graphics Processing Unit), FPGA (Field Programmable Gate Array), ASIC (Application Specific Integrated Circuit), AI (Artificial Intelligence) chip, or the like.

[0033] The main memory device 12 is a device that stores programs and data, and is, for example, a ROM (Read Only Memory), RAM (Random Access Memory), non-volatile memory (NVRAM (Non Volatile RAM)), or the like. The functions realized in each component of the security management system 1 are realized by the processor 11 reading and executing a program stored (stored) in the main memory device 12.

[0034] The auxiliary storage device 13 is, for example, an SSD (Solid State Drive), a hard disk drive They include auxiliary storage devices such as hard disk drives, optical storage devices (such as CDs (Compact Discs), DVDs (Digital Versatile Discs), etc.), storage systems, IC cards, read / write devices for non-volatile recording media such as SD cards and optical recording media, and non-volatile storage areas of cloud servers, etc. The auxiliary storage device 13 can read programs and data from non-volatile recording media and other information processing devices equipped with non-volatile storage devices via a recording medium reader or a communication device 16. Programs and data stored (stored) in the auxiliary storage device 13 are read into the main storage device 12 at any time.

[0035] The input device 14 is an interface for receiving input of external information, and examples thereof include a keyboard, a mouse, a touch panel, a card reader, a pen-input type tablet, a voice input device, and the like.

[0036] The output device 15 is an interface for outputting various information such as the progress of processing and the processing results to the outside. The output device 15 is, for example, a display device (such as a liquid crystal monitor, an LCD (Liquid Crystal Display), a graphics card, etc.) for visualizing the above various information, a device (such as a voice output device (such as a speaker)) for vocalizing the above various information, and a device (such as a printing device) for characterizing the above various information. Incidentally, for example, the information processing device 10 may be configured to input and output information to and from other devices via the communication device 16.

[0037] The input device 14 and the output device 15 constitute a user interface for realizing interactive processing (such as receiving information and providing information) with the user.

[0038] The communication device 16 is a device that realizes communication with other devices. The communication device 16 is a wired or wireless communication interface that realizes communication with other devices compliant with a predetermined communication protocol via various communication networks (information network 51, control network 52, response network 53), and is, for example, a NIC (Network Interface Card), a wireless communication module, a USB module, etc.

[0039] In the information processing device 10, for example, an operating system, a file system, a DB MS (DataBase Management System) (relational database, NoSQL, etc.), a KVS (Key-Value Store), etc. may be introduced.

[0040] FIG. 3 is a block diagram showing the main functions of the communication monitoring device 20. When the communication monitoring device 20 detects unauthorized communication by monitoring the communication in the monitoring target system 5, it generates detection information of the detected unauthorized communication and transmits the generated detection information to the countermeasure support device 100.

[0041] As shown in the figure, the communication monitoring device 20 has functions of a storage unit 210, a system information management unit 220, an unauthorized communication detection unit 230, and a detection information transmission unit 240.

[0042] Among the above functions, the storage unit 210 stores a business device information table 211, a white communication table 212, a business information table 213, and a control information table 214.

[0043] Among these, information about business devices (hereinafter referred to as "business device information") is managed in the business device information table 211. The content of the business device information table 211 is set by, for example, the administrator 2.

[0044] FIG. 6 shows an example of the business device information table 211. As shown in this figure, the business device information table 211 is composed of one or more records having items of a business device ID 611, a device name 612, an IP address 613, an alternative device ID 614, whether autonomous control is possible 615, and a business ID 616. One record of the business device information table 211 corresponds to one business device.

[0045] Among the above items, the business device ID 611 stores the business device ID which is an identifier of the business device. The device name 612 stores the name (device name) of the business device.

[0046] The IP address 613 stores the network address (in this example, the IP address) in the control network 52 of the business device. Note that in the illustrated business device information table 211, only the IP address in the control network 52 is shown, but the IP addresses of the communication networks to which each business device is connected are managed in the business device information table 211.

[0047] The alternative device ID 614 stores the business device ID (hereinafter referred to as the "alternative device ID") of another device (hereinafter referred to as the "alternative device") that can substitute (act on behalf of) the business of the business device. Note that when the business of the business device cannot be substituted by another device or when the substitute device is not prepared, "none" is stored in the alternative device ID 614.

[0048] The information indicating whether the business device is capable of autonomous operation (capable of autonomous control) is stored in whether autonomous control is possible 615. In this example, "yes" is stored in whether autonomous control is possible 615 when autonomous operation is possible, and "no" is stored when autonomous operation is not possible. Note that the case where the business can be continued safely although there is an influence such as a decrease in business efficiency is also included in the case of "capable of autonomous control".

[0049] The business ID 616 stores an identifier of the business performed by the business device (hereinafter referred to as the "business ID"). Note that although "none" is stored in the business ID 616 of the business device with the business device ID 611 being "D03" in the exemplified business device information table 211, this indicates that the business device is prepared as a replacement device and is currently in a standby state (not performing a business). Note that when the replacement device subsequently starts operating as a replacement destination, the business ID of the business performed by the original business device of the replacement device is stored in the business ID 616 of the record. is stored.

[0050] Returning to FIG. 3, the white communication table 212 manages information indicating the correspondence (hereinafter referred to as the "communication path") between the node that is the source of information and the node that is the destination (recipient) of information in the regular communication (communication performed between business devices when a business is executed) performed in the business of the monitoring target system 5. The above communication path is identified (specified) by a combination of the protocol, IP address, and port used for communication. The white communication table 212 manages information indicating the importance level of each of the above communication paths (hereinafter referred to as the "business communication importance level"). The content of the white communication table 212 is set by, for example, the administrator 2.

[0051] FIG. 7 shows an example of the white communication table 212. As shown in the figure, the exemplified white communication table 212 is composed of one or more records having items of communication path ID 711, communication protocol 712, source address 713, destination address 714, source port 715, destination port 716, and business communication importance level 717. One record of the white communication table 212 corresponds to one of the communication paths performed via the information network 51 or the control network 52.

[0052] The communication path ID 711 stores an identifier of the communication path (hereinafter referred to as the "communication path ID"). The communication protocol 712 stores information indicating the communication protocol used in the communication path.

[0053] The source address 713 stores the network address (in this example, the IP address) of the source node of the communication path. The destination address 714 stores the network address (in this example, the IP address) of the destination node of the communication path.

[0054] The source port 715 stores the port number of the source node of the communication path. The destination port 716 stores the port number of the destination node of the communication path. For communication paths where the source port or destination port is not specified (communication paths with an arbitrary port number), "*" is stored in the source port 715 or the destination port 716.

[0055] The business communication importance 717 stores information indicating the business communication importance. In this embodiment, the business communication importance takes a value in the range of "0" to "1" (where "1" has the highest importance and "0" has the lowest importance). For example, when the business that uses the communication path stops if the communication path is interrupted, "1" is stored in the business communication importance 717. Also, for example, when the communication path is for maintenance or is a communication path used by one of the redundantly configured sensors 72, "0" is stored in the business communication importance 717. The business communication importance 717 is preset by the administrator 2.

[0056] Returning to FIG. 3, the business information table 213 manages information related to the business performed in the monitoring target system 5 (hereinafter referred to as "business information"). For example, the business information table 213 manages information such as the operation period of each business, the priority of each business, the communication performed in each business, and the availability of degraded operation for each business.

[0057] FIG. 8 shows an example of the business information table 213. As shown in the figure, the business information table 213 is composed of one or more records having items such as a business ID 811, a business name 812, an operation period 813, a business priority 814, a usage path 815, and the availability of degraded operation 816. One record of the business information table 213 corresponds to one of the businesses performed by the monitoring target system 5.

[0058] The business ID 811 stores the business ID of the relevant business. The business name 812 stores the name of the relevant business (hereinafter referred to as the "business name"). is stored.

[0059] The operation period 813 stores information indicating the period during which the relevant business is conducted.

[0060] The business priority 814 stores information indicating the priority of the relevant business (hereinafter referred to as the "business priority"). In this example, the smaller the value of the business priority, the higher the priority.

[0061] The usage route 815 stores the communication route ID of the communication route used when executing the relevant business.

[0062] The degenerate operation availability 816 stores information indicating whether the relevant business can be degenerate-operated. If degenerate operation is possible, "Yes" is stored in the degenerate operation availability 816, and if degenerate operation is impossible, "No" is stored in the degenerate operation availability 816.

[0063] Returning to FIG. 3, the control information table 214 manages information related to control (control protocol, control command, control parameter, communication cycle, influence value, etc., hereinafter referred to as "control information") performed between business devices using a communication route.

[0064] FIG. 9 shows an example of the control information table 214. As shown in the figure, the control information table 214 is composed of one or more records having items of communication route ID 911, control protocol 912, control command 913, control parameter 914, communication cycle 915, and influence degree 916. One record of the control information table 214 corresponds to one communication route.

[0065] The communication route ID 911 stores the communication route ID of the relevant communication route.

[0066] The control protocol 912 stores information indicating the control protocol used when controlling the business device via the communication path.

[0067] The control command 913 stores information indicating the control command used when controlling the business device via the communication path.

[0068] The control parameter 914 stores information indicating the control parameter used when controlling the business device via the communication path.

[0069] The communication cycle 915 stores information indicating the communication cycle (which may be the average value of the communication cycles) of the communication when controlling the business device via the communication path. When the communication is not a periodic communication, "*" is stored in the communication cycle 915.

[0070] The impact degree 916 stores a value (hereinafter referred to as the "impact degree") indicating the magnitude of the impact on the continuity and safety of the business when an abnormality occurs in the communication path (such as when the control command cannot be sent or suddenly increases, or when an incorrect control parameter is set, etc.). The content of the impact degree 916 is used, for example, as the basis for setting the business communication importance 717. In this example, for example, any one of "high", "medium", and "low" is set in the impact degree 916. For example, when the impact on the business is large, such as when the business may stop for several days or human life is threatened, "high" is stored in the impact degree 916. Also, for example, when the impact is minor or limited, "low" is stored in the impact degree 916.

[0071] Returning to FIG. 3, among the functions shown in the figure, the system information management unit 220 manages the business device information table 211, the white communication table 212, the business information table 213, and the control information ta ble 214 (hereinafter, these information are collectively referred to as "system information").

[0072] The unauthorized communication detection unit 230 acquires the content of the communication (packets, communication telegrams) flowing through the information network 51 and the control network 52 of the monitoring target system 5 via the mirror port 41 and the mirror port 42. The unauthorized communication detection unit 230 analyzes the acquired communication content, and for example, acquires the header information of the packet (IP addresses of the data source device and the data destination device, communication protocol, port number, etc.), and each piece of information on the control commands and parameters included in the payload of the packet (hereinafter referred to as "communication information"). Further, the unauthorized communication detection unit 230 generates information based on the acquired communication information (change in the number of communications per unit time, number of control commands per unit time, etc.; hereinafter referred to as "statistical information"). The unauthorized communication detection unit 230 determines whether unauthorized communication is being performed in the monitoring target system 5 by comparing, for example, the communication information and the statistical information (hereinafter referred to as "analysis information") with the information in each table stored in the storage unit 210.

[0073] When the unauthorized communication detection unit 230 determines that unauthorized communication is being performed in the monitoring target system 5, the detection information transmission unit 240 generates detection information and transmits the generated detection information to the countermeasure support device 100 via the countermeasure network 43.

[0074] FIG. 4 is a block diagram for explaining the main functions of the countermeasure support device 100. When the countermeasure support device 100 receives detection information from the communication monitoring device 20, it identifies the operations that may be affected by the unauthorized communication in the detection information and generates a countermeasure plan for the unauthorized communication. Further, the countermeasure support device 100 obtains a service impact value, which is an index indicating the impact on the service when the generated countermeasure plan is implemented, and determines whether the generated countermeasure plan can be automatically implemented based on the obtained service impact value.

[0075] As shown in the figure, the countermeasure support device 100 has functions of a storage unit 110, a system information management unit 120, a detection information reception unit 130, a countermeasure plan generation unit 140, an automatic implementation determination unit 150, a countermeasure command transmission unit 160, and a countermeasure information transmission unit 170.

[0076] Of the above functions, the storage unit 110 stores a business device information table 211, a white communication table 212, and a business information table 213. These pieces of information are similar to the system information (business device information table 211, white communication table 212, and business information table 213) shown in Fig. 3, so a description thereof will be omitted. The countermeasure support device 100 refers to these pieces of information when generating countermeasures and calculating a business impact value for the generated countermeasures.

[0077] The system information management unit 120 manages a business device information table 211, a white communication table 212, and a business information table 213. The communication monitoring device 20 and the response support device 100 may share and manage the system information.

[0078] The detection information receiving unit 130 receives the detection information sent from the communication monitoring device 20 .

[0079] Based on the detection information, the countermeasure plan generating unit 140 identifies business operations that may be affected by the unauthorized communication of the detection information, and generates one or more countermeasure plans for the unauthorized communication. Specifically, based on the detection information and the system information stored in the memory unit 110 (business device information table 211, white communication table 212, and business information table 213), the countermeasure plan generating unit 140 identifies business devices related to the unauthorized communication and business operations that may be affected by the unauthorized communication. In addition, the countermeasure plan generating unit 140 calculates a business impact value when the generated countermeasure plan is implemented. When some countermeasure is currently being implemented for a certain business, the countermeasure plan generating unit 140 multiplies the impact values ​​of all measures being implemented by the newly generated countermeasure. The business impact value is calculated by adding up the impact values ​​when the countermeasures are implemented. The method of calculating the business impact value will be described later in detail. The countermeasure generation unit 140 may assign a recommendation order to each generated countermeasure in consideration of the operating status of the business device and the implementation status of the business, present each countermeasure and its respective recommendation order to the manager 2, and have the manager 2 select the recommendation order he / she wishes to implement via a user interface.

[0080] The automatic execution determination unit 150 determines whether the countermeasure can be automatically executed by comparing the business impact value of the countermeasure with a preset threshold value. If it is determined that the countermeasure can be automatically executed, the automatic execution determination unit 150 transmits a countermeasure command to the countermeasure execution device 30. On the other hand, if it is determined that the countermeasure cannot be automatically executed, the automatic execution determination unit 150 generates countermeasure information including the content of the countermeasure, information indicating the business affected by implementing the countermeasure, the business impact value of the countermeasure, etc., transmits the generated countermeasure information to the administrator device 40, and receives a determination of whether to implement the countermeasure.

[0081] The countermeasure command transmission unit 160 transmits a countermeasure command to the countermeasure execution device 30 when implementing a countermeasure.

[0082] The countermeasure information transmission unit 170 transmits countermeasure information to the administrator device 40 when the countermeasure is not automatically executed.

[0083] FIG. 5 is a block diagram for explaining the main functions of the countermeasure execution device 30. The countermeasure execution device 30 receives a countermeasure command from the countermeasure support device 100, and based on the received countermeasure command, transmits a control command and control logic (the control sequence of the controller 61 realized by executing predetermined processing and calculations) to the countermeasure business device.

[0084] As shown in the figure, the countermeasure execution device 30 has functions of a storage unit 310, a countermeasure information receiving unit 320, a control logic configuration unit 330, and a control command transmission unit 340.

[0085] Among the above functions, the storage unit 310 stores a control logic table 311 that manages information regarding control commands and control logic corresponding to each business device of the monitoring target system 5.

[0086] The countermeasure information receiving unit 320 receives a countermeasure command sent from the countermeasure support device 100 via the communication device 16, and inputs the received countermeasure command to the control logic configuration unit 330.

[0087] The control logic configuration unit 330 acquires, from the control logic table 311, a control command or control logic to be transmitted to the countermeasure service device corresponding to the countermeasure command input from the countermeasure information reception unit 320, and inputs the acquired control command or control logic to the control command transmission unit 340 as a countermeasure command.

[0088] The control command transmission unit 340 transmits the countermeasure command input from the control logic configuration unit 330 to the countermeasure service device, causing the countermeasure service device to execute processing for countermeasures. Note that the control command transmission unit 340 may receive information indicating the result of the above processing from the countermeasure service device and transfer the received information to the countermeasure support device 100. Thereby, the countermeasure support device 100 can grasp the implementation status of the countermeasures in the countermeasure service device. Also in that case, the countermeasure support device 100 may transmit information indicating the grasped implementation status to the administrator device 40, and the administrator device 40 may receive the above information and present its content to the administrator 2. Thereby, the administrator 2 can efficiently grasp the implementation status of the countermeasure plan.

[0089] Subsequently, the processing performed in the security management system 1 will be described.

[0090] FIG. 10 is a sequence diagram for explaining the processing (hereinafter referred to as "illegal communication monitoring process S1000") performed by the security management system 1 when monitoring illegal communication in the monitoring target system 5. Hereinafter, the illegal communication monitoring process S1000 will be described together with the figure.

[0091] The communication monitoring device 20 acquires the packets flowing through the information network 51 via the mirror port 41 and the control network 52 via the mirror port 42, respectively, and monitors in real time whether illegal communication is being performed in the monitoring target system 5 (S1010: NO). When the communication monitoring device 20 detects illegal communication (S1010: YES), it transmits the detection information of the illegal communication to the countermeasure support device 100.

[0092] Furthermore, unauthorized communication refers to communication that does not conform to the content of the control information table 214 among the communications of the communication paths existing in the white communication table 212. Examples of the above non-conforming communication include the following communications.

[0093] (1) Communication using a control protocol other than the control protocol stored in the control protocol 912 of the control information table 214 (communication deviating from the available control protocol) (2) Communication using a control command other than the control command stored in the control command 913 of the control information table 214 (communication deviating from the available control command) (3) Communication using a control parameter other than the control parameter stored in the control parameter 914 of the control information table 214 (communication deviating from the available control parameter) (4) Communication whose communication cycle significantly deviates from the communication cycle stored in the communication cycle 915 of the control information table 214 (communication performed with a communication cycle exceeding the preset allowable range)

[0094] Furthermore, in this embodiment, it is assumed that communications performed on communication paths that do not exist in the white communication table 212 are blocked by other security countermeasure mechanisms such as routing settings, firewalls, and security countermeasure software.

[0095] The detection information includes, for example, the communication path ID of the communication path of unauthorized communication and information indicating the specific content of the unauthorized communication (the deviating control protocol, the deviating control command, the deviating control parameter, the deviating communication cycle).

[0096] When the countermeasure support device 100 receives the detection information from the communication monitoring device 20, it executes a process of calculating the business impact value (hereinafter referred to as "business impact value calculation process S1011"), and generates a countermeasure plan for unauthorized communication in the received detection information and calculates the business impact value when the countermeasure plan is implemented. The details of the business impact value calculation process S1011 will be described later.

[0097] Subsequently, the countermeasure support device 100 determines whether to automatically execute the generated countermeasure plan (S1012). Specifically, if the business impact value obtained in the business impact value calculation process S1011 is less than a preset threshold value (business impact value < threshold value), the countermeasure support device 100 determines to automatically execute it (S1012: YES). If the business impact value obtained in the business impact value calculation process S1011 is greater than or equal to the preset threshold value (business impact value ≥ threshold value), the countermeasure support device 100 determines not to automatically execute it (S1012: NO )

[0098] If it is determined to automatically execute (S1012: YES), the countermeasure support device 100 generates a countermeasure command corresponding to the countermeasure plan and transmits the generated countermeasure command to the countermeasure execution device 30 (S1017). When receiving the countermeasure command from the countermeasure support device 100, the countermeasure execution device 30 generates a control command and transmits the generated control command to the countermeasure business device (S1018). When receiving the control command, the countermeasure business device executes the control according to the control command (S1019).

[0099] On the other hand, if it is determined not to automatically execute (S1012: NO), the countermeasure support device 100 generates countermeasure information and transmits the generated countermeasure information to the administrator device 40. When receiving the countermeasure information, the administrator device 40 presents the content of the received countermeasure information to the administrator 2 and accepts an input of an intention indication on whether to implement the countermeasure plan (S1013). The administrator 2 checks the content of the presented countermeasure information and inputs a judgment result on whether to implement the countermeasure plan to the administrator device 40 (S1014). The administrator device 40 transmits the input content (hereinafter referred to as the "judgment result") to the countermeasure support device 100 (S1015).

[0100] Fig. 12 shows an example of a screen (hereinafter referred to as the "Countermeasure Implementation Decision Screen 1200") displayed by the countermeasure support device 100 when receiving a response from the administrator 2 on whether to implement the countermeasure in S1013. In the illustrated Countermeasure Implementation Decision Screen 1200, two countermeasures are presented, and by prompting the operation of buttons ( "Implement" and "Do not implement") indicated by reference numerals 1211 and 1212, the countermeasure support device 100 receives a response from the administrator 2 on whether to implement each countermeasure. Incidentally, on the Countermeasure Implementation Decision Screen 1200, together with the countermeasure, the name of the business affected by implementing the countermeasure and the magnitude of the impact on the business (business impact value) may be displayed. By displaying this information, it is possible to assist the administrator 2 in making a decision on the selection and implementation of the countermeasure.

[0101] Returning to Fig. 10, when the countermeasure support device 100 receives the judgment result from the administrator device 40, it determines whether to implement the countermeasure based on the content of the received judgment result (S1016). If it is determined to implement the countermeasure, the countermeasure support device 100 generates a countermeasure command corresponding to the countermeasure and transmits the generated countermeasure command to the countermeasure execution device 30 (S1017). Incidentally, as described above, when the countermeasure execution device 30 receives the countermeasure command, it generates a control command and transmits the generated control command to the business device (S1018). Further, when the business device receives the control command, it executes the control according to the control command (S1019).

[0102] Fig. 11 is a flowchart for explaining the details of the business impact value calculation process S1011 in Fig. 10. Hereinafter, the business impact value calculation process S1011 will be described with reference to the same figure.

[0103] First, the countermeasure support device 100 receives detection information from the communication monitoring device 20 (S1111).

[0104] Subsequently, the countermeasure support device 100 identifies the scope of influence that the unauthorized communication described in the received detection information has on the monitored system 5 (business devices that may be affected by the unauthorized communication) (S1112). Specifically, first, the countermeasure support device 100 identifies the communication path of the unauthorized communication by comparing the information on the communication path of the unauthorized communication included in the detection information (source address, destination address, source port, destination port) with the white communication table 212. Subsequently, the countermeasure support device 100 identifies the business that uses the identified communication path from the business information table 213. Subsequently, the countermeasure support device 100 identifies the business device that executes the identified business by comparing the identified business with the business device information table 211.

[0105] Subsequently, the countermeasure support device 100 generates one or more countermeasure plans that can be implemented for the business device identified in S1112 (S1113). For example, the countermeasure support device 100 refers to the business device information table 211 and determines whether the identified business device has an alternative device. Then, if the identified business device has an alternative device, the countermeasure support device 100 generates a countermeasure plan of "having the business performed by the identified business device replaced by the alternative device". Also, for example, the countermeasure support device 100 refers to the business device information table 211 and determines whether the identified business device can be autonomously controlled. Then, if the identified business device can be autonomously controlled, the countermeasure support device 100 generates a countermeasure plan of "switching the identified business device to autonomous control and disconnecting it from the communication path in use by the business device". Incidentally, for example, the countermeasure support device 1 00 may generate a countermeasure plan according to the content of the unauthorized communication. Also, for example, the countermeasure support device 100 may accumulate and manage information including the history of past unauthorized communications and the history of countermeasures taken for the unauthorized communication, and generate a countermeasure plan based on the information (for example, using a machine learning model that has learned the history).

[0106] Subsequently, the countermeasure support device 100 obtains a business impact value for the generated countermeasure plan (S1114). First, the countermeasure support device 100 obtains an impact value based on the following formula. [Number 1] Impact value = Impact criterion × Importance of business communication × Business operation status (Formula 1)

[0107] The impact criterion in the above formula is the base value of the impact that the countermeasure has on the business, and it is a value set by Administrator 2 for each business performed in the monitoring target system 5 in advance. In this example, the impact criterion takes a value from "0" to "1" (the larger the value, the greater the impact on the business). For example, when necessary communication in the business becomes impossible, such as the interruption of control communication or the stop of a device, "1" is set for the impact criterion. Also, for example, when the countermeasure is degraded operation or autonomous control, the impact on the business is limited, so an intermediate value such as "0.5" is set for the impact criterion. Also, when the alternative is a switch to an alternative device, the business can be continued, so "0" is set for the impact criterion. Incidentally, the value of the impact criterion may be adjusted according to the value of the business priority 814 in the business information table 213 (see FIG. 8) (for example, the higher the priority of the business, the larger the value of the impact criterion).

[0108] The importance of business communication in the above formula is the value of the business communication importance 717 in the white communication table 212 of the communication path specified by S1112, which may be affected by implementing the countermeasure. As described above, a value from "0" to "1" is set ("1" has the highest importance and "0" has the lowest importance).

[0109] Either the value "1" or "0" is set for the business operation status in the above formula. If the business (the business using the communication path that may be affected when the countermeasure is implemented) is currently in operation, "1" is set for the business operation status, and if the business is not currently in operation, "0" is set for the business operation status. In this way, when the business is currently in operation, there is a possibility of affecting the business, so the impact value obtained from Formula 1 becomes a value other than "0". Incidentally, the countermeasure support device 100 acquires the business operation status of the business by, for example, comparing the operation period 312 of the business information table 213 with the current time.

[0110] Subsequently, for the operations affected by unauthorized communication identified in S1112, the response support device 100 obtains the business impact value of the current response plan in progress. n Note that if there is no current response plan for the operation, the business impact value n is "0", and in this case, the impact value remains as the business impact value n+1 .

[0111] Subsequently, as shown in the following formula, the response support device 100 calculates the business impact value n , which is the sum of the impact values of the current response plan (currently applied) for the operation, and adds the impact value of the response plan generated in S1113 to obtain the business impact value n+1 . [Equation 2] Business impact value n+1 = Business impact value n + Impact value (Equation 2)

[0112] The business impact value calculation process S1011 ends here, and the business impact value n+1 obtained from the above formula is returned as the return value (business impact value), and the process returns to Figure 10 and proceeds to the process of S1012.

[0113] Note that if the response support device 100 generates a response command in S1017 of Figure 10 (i.e., when a new response is performed), the stored business impact value n is updated with the newly obtained business impact value n+1 .

[0114] As described in detail above, the security management system 1 of the present embodiment evaluates the impact of countermeasures on operations, and if it is determined that the impact is small, the countermeasures are automatically implemented. Therefore, countermeasures with a small impact on operations can be quickly implemented, and the security performance can be improved. In addition, since the administrator 2 does not need to give a will indication, the burden on the administrator 2 can be reduced in that case. Also, when it is determined that the impact on operations is large, whether to implement the countermeasures is determined based on the content (judgment) of the will indication of the administrator 2. Therefore, appropriate measures can be taken against unauthorized communication while considering the impact on operations.

[0115] As described above with respect to the embodiments, the present invention is not limited to the above-described embodiments, includes various modifications, and is not necessarily limited to those having all the configurations described. Also, it is possible to replace a part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Further, it is possible to add, delete, or replace other configurations for a part of the configuration of each embodiment.

Description of Reference Numerals

[0116] 1 Security management system, 2 Administrator, 5 Monitoring target system, 10 Information processing device, 20 Communication monitoring device, 100 Countermeasure support device, 110 Storage unit, 120 System information management unit, 130 Detection information reception unit, 140 Countermeasure generation unit, 150 Automatic implementation determination unit, 160 Countermeasure command transmission unit, 170 Countermeasure information transmission unit, 210 Storage unit, 211 Business device information table, 212 White communication table, 213 Business information table, 214 Control Information Table, 220 System Information Management Unit, 230 Illegal Communication Detection Unit, 240 Detection Information Transmission Unit, 30 Countermeasure Execution Device, 310 Storage Unit, 311 Control Logic Table, 320 Countermeasure Information Reception Unit, 330 Control Logic Configuration Unit, 340 Control Command Transmission Unit, 40 Administrator Device, 43 Countermeasure Network, 50 Control Server, 51 Information Network, 52 Control Network, 61 Controller, 71 Actuator, 72 Sensor, S1000 Illegal Communication Monitoring Process, S1011 Business Impact Value Calculation Process, 1200 Countermeasure Plan Execution Feasibility Designation Screen

Claims

1. A security management system for performing security management of a monitoring target system configured to include a plurality of business devices connected communicably, which is configured by using an information processing device having a processor and a memory, stores information indicating a communication path used for communication between the business devices and business communication importance which is information indicating the importance of each of the communication paths, monitors communication performed in the monitoring target system, when detecting unauthorized communication performed in the monitoring target system, identifies a communication path used for the unauthorized communication, and based on the identified communication path, identifies a range of influence that the unauthorized communication has on the monitoring target system, generates a countermeasure plan for the unauthorized communication based on the identified range of influence, identifies a communication path that may be affected when the countermeasure plan is implemented, obtains an influence value which is an index indicating the degree of influence that the countermeasure plan has on the operations performed by the monitoring target system based on the business communication importance of the identified communication path, determines whether to automatically implement the countermeasure plan based on the influence value, A security management system.

2. The security management system according to claim 1, which automatically implements the countermeasure plan when it is determined to automatically implement the countermeasure plan. A security management system.

3. The security management system according to claim 1, wherein if the influence value is less than a preset threshold value, it is determined to automatically implement the countermeasure plan, and if the influence value is greater than or equal to the threshold value, it is determined not to automatically implement the countermeasure plan. A security management system.

4. The security management system according to claim 1, manages a business operation state which is information indicating whether a business using a communication path that may be affected when the countermeasure plan is implemented is currently in operation, and obtains the influence value based on the business communication importance and the business operation state. A security management system.

5. The security management system according to claim 1, when one or more countermeasure plans are currently being applied to the business, obtains the influence value by adding the influence value obtained for the countermeasure plan of the newly detected unauthorized communication to the total value of the influence values of the countermeasure plans currently being applied. A security management system.

6. The security management system according to claim 1, Adjusting the influence value based on an influence criterion which is a value preset for each of the operations. Security management system.

7. The security management system according to claim 1, wherein the unauthorized communication is at least any one of communication deviating from a control protocol available for communication between the service devices, communication using a control command other than the control commands available for communication between the service devices, communication using a control parameter other than the control parameters available for communication between the service devices, and communication performed at a communication cycle exceeding a preset allowable range for communication between the service devices. Security management system.

8. The security management system according to claim 1, when it is determined not to automatically execute the countermeasure, presenting the content of the countermeasure via a user interface, receiving an input of a will indication as to whether to execute the countermeasure, and executing the countermeasure when receiving a will indication to execute the countermeasure. Security management system.

9. The security management system according to claim 1, wherein the countermeasure is to cause another service device to substitute for the service being performed by the service device that communicates using the identified communication path. Security management system.

10. The security management system according to claim 1, wherein the countermeasure is to switch the identified service device to autonomous control and disconnect the service device from the communication path. Security management system.

11. An information processing apparatus having a processor and a memory stores information indicating a communication path used for communication between service devices of a monitoring target system configured to include a plurality of service devices communicably connected, and service communication importance which is information indicating the importance of each of the communication paths, a step of monitoring communication performed in the monitoring target system, when detecting unauthorized communication performed in the monitoring target system, identifying the communication path used for the unauthorized communication, and identifying the influence range that the unauthorized communication has on the monitoring target system based on the identified communication path, generating a countermeasure for the unauthorized communication based on the identified influence range, identifying the communication paths that may be affected when the countermeasure is executed, Based on the importance of business communication of the specified communication path, obtain an impact value, which is an index indicating the degree of influence of the countermeasure on the business performed by the monitored system. Determine whether to automatically execute the countermeasure based on the impact value, and When it is determined to automatically execute the countermeasure, automatically execute the countermeasure. A security management method for performing the above.

12. The security management method according to claim 11, wherein the information processing device determines to automatically execute the countermeasure if the impact value is less than a preset threshold, and determines not to automatically execute the countermeasure if the impact value is greater than or equal to the threshold. A security management method for further performing the above.

13. The security management method according to claim 11, wherein the information processing device manages the business operation state, which is information indicating whether the business using the communication path that may be affected when the countermeasure is implemented is currently in operation, and obtains the impact value based on the importance of business communication and the business operation state. A security management method for further performing the above.

14. The security management method according to claim 11, wherein when one or more countermeasures are currently being applied to the business, the information processing device obtains the impact value by adding the impact value obtained for the countermeasure of the newly detected unauthorized communication to the total value of the impact values of the countermeasures currently being applied. A security management method for further performing the above.

15. The security management method according to claim 11, wherein the information processing device adjusts the impact value based on an impact criterion, which is a value preset for each business. A security management method for further performing the above.

Citation Information

Patent Citations

  • JP137500A

  • Security measure system and security measure method

    JP2018037962A

  • Security management plan design device, security management plan evaluation device, security management plan design method and security management plan evaluation method

    JP2018137500A

  • Countermeasure planning system and monitoring device for control system

    JP2019080211A

  • Abnormal factor determination device, control system, and abnormal factor determination method

    JP2019205125A