Abnormal communication determination device, abnormal communication determination method, and abnormal communication handling system

The anomalous communication detection device employs event and statistical analysis to distinguish between cyber attacks and device malfunctions, enhancing the ability to address abnormal communications effectively.

JP7756066B2Active Publication Date: 2025-10-17HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2022205896
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-12-22
Publication Date
2025-10-17
Estimated Expiration
2042-12-22

AI Technical Summary

Technical Problem

Existing technologies struggle to differentiate between cyber attacks and device malfunctions causing abnormal communications in control systems, particularly during complex operations like DoS or DDoS attacks, as they primarily focus on anomaly detection rather than cause determination.

Method used

An anomalous communication detection device that utilizes a phenomenon feature table and statistical feature table to evaluate abnormal communications based on event and statistical analysis, determining whether the cause is a cyber attack or a device malfunction.

Benefits of technology

Enables accurate and rational differentiation between cyber attacks and device malfunctions in business-related communications, facilitating effective countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007756066000001
    Figure 0007756066000001
  • Figure 0007756066000002
    Figure 0007756066000002
  • Figure 0007756066000003
    Figure 0007756066000003
Patent Text Reader

Abstract

To easily and rationally determines that an abnormality when generated in a communication in regard to a business is caused by a cyber attack or a failure of a device.SOLUTION: An abnormal communication determination device is configured to: hold an event characteristic table evaluated by an event character for each abnormal communication detection event, and a statistic evaluation character table that performs an evaluation from a statistic character for each establishment condition of a statistic amount of the abnormal communication; calculate an event evaluation value from the number of matching of a record of the abnormal communication detection event in the event character table; calculate a statistic evaluation value from the number of matching of the record that is matched to the condition of the statistic amount of the abnormal communication; calculate a determination result evaluation value by a weight liner sum of the event evaluation value and the statistic evaluation value; and determine whether the abnormal communication is caused by a cyber attack or a failure of a device of a monitoring object system by the determination result evaluation value.SELECTED DRAWING: Figure 17
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an anomalous communication detection device, an anomalous communication detection method, and an anomalous communication handling system, and in particular to an anomalous communication detection device, an anomalous communication detection method, and an anomalous communication handling system that are suitable for determining whether an abnormality in business-related communications is caused by a cyber attack or a device malfunction. [Background technology]

[0002] With the explosive growth of the Internet and the rapid evolution of hardware such as PCs and smartphones, communications have become an indispensable part of the social lives of businesses and individuals.

[0003] In this situation, cyber attacks have become a major risk in our information society. Cyber ​​attacks are acts that involve tampering with, destroying, or stealing data stored on computers such as servers, PCs, and smartphones via networks such as the Internet. be. In particular, cyber attacks in recent years have become increasingly complex and sophisticated, posing a threat that could potentially affect any company. Therefore, countermeasures against such cyber attacks (cybersecurity) are not something that can be limited to the information systems department, but have become a management issue, an important matter that needs to be addressed by the entire company.

[0004] A technology relating to countermeasures against cyber attacks is disclosed, for example, in Patent Document 1. The anomaly cause determination device described in Patent Document 1 is provided in a control system including a control device, saves control state data (Fig. 2, paragraph

[0021] ) including a control state indicating the operating state of the control device, and determines whether the cause of an anomaly that has occurred in the control system is an attack via a network or a malfunction of equipment based on the control state data (Fig. 3, paragraphs

[0024] and

[0025] ). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Publication No. 2019-205125 Summary of the Invention [Problem to be solved by the invention]

[0006] The technology described in Patent Document 1 discloses a method for determining whether the cause of an abnormality that has occurred in a control system is an attack via a network or a malfunction of the equipment, based on the control state that indicates the operating status of the control device.

[0007] However, in the judgment of communication anomalies described in Patent Document 1, anomaly detection and cause judgment are performed taking into consideration the control state of the control device (paragraph

[0024] ). For example, even if the control device is "stopped," if the control device is the origin of communication, the cause of the attack is "spoofing," and if the control device is "starting" and communication requesting program rewriting is detected, it is judged to be an unauthorized operation (paragraph

[0025] ).

[0008] Therefore, in the case of an attack that exploits control communications or communications such as sensor output that occur during business operations, such as a DoS attack / DDoS attack against a specific target, the determination of communication anomalies described in Patent Document 1 cannot determine whether the abnormal communications are due to a cyber attack or equipment failure.

[0009] Furthermore, in Patent Document 1, paragraph

[0026] states that "the analysis unit 142 detects anomalies by matching the network data with abnormal patterns and analyzing the degree of deviation from normal times, and when an anomaly is detected, it may determine whether the cause is an attack or a malfunction," but this is an analysis of whether communication is normal or abnormal, and does not determine whether the abnormal communication is the result of a cyber attack or a malfunction of the equipment.

[0010] The object of the present invention is to provide an anomalous communication detection device, an anomalous communication detection method, and an anomalous communication response system that can easily and rationally determine whether an abnormality in business-related communications is caused by a cyber attack or a device malfunction. [Means for solving the problem]

[0011] The anomalous communication detection device of the present invention is preferably configured as an anomalous communication detection device that determines the cause of anomalous communication detected in a monitored system in which the device operates, and holds a phenomenon feature table that stores records storing a determination event class indicating whether the anomalous communication is due to a cyber-attack or a malfunction of a device in the monitored system for each anomalous communication detection event, and a statistical feature table that stores records storing a determination event class indicating whether the anomalous communication is due to a cyber-attack or a malfunction of a device in the monitored system for each condition under which statistics of anomalous communication are established, and receives anomalous communication detection information in the monitored system, and based on the received anomalous communication detection information, the value of the determination event class of the record corresponding to the anomalous communication detection information in the phenomenon feature table is An event evaluation value is calculated from the number of abnormal communications that are caused by a cyber-attack or a malfunction of a device in the monitored system, a statistical quantity of abnormal communications is calculated from the received abnormal communication detection information, and based on the calculated statistical quantity of abnormal communications, a statistical evaluation value is calculated from the number of abnormal communications that are caused by a cyber-attack or a malfunction of a device in the monitored system for records in which the condition for the statistical quantity of abnormal communications in the statistical feature table is met, and a discrimination result evaluation value indicating whether the abnormal communication is caused by a cyber-attack or a malfunction of a device in the monitored system is calculated based on the event evaluation value and the statistical evaluation value, and a discrimination result evaluation value is used to determine whether the abnormal communication is caused by a cyber-attack or a malfunction of a device in the monitored system. [Effects of the Invention]

[0012] According to the present invention, it is possible to provide an anomalous communication detection device, an anomalous communication detection method, and an anomalous communication response system that can easily and rationally determine whether an abnormality in business-related communications is caused by a cyber attack or a device malfunction. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a configuration diagram of an abnormal communication handling system. [Figure 2] FIG. 2 is a functional configuration diagram of the communication monitoring device. [Figure 3] FIG. 2 is a functional configuration diagram of an abnormal communication determination device. [Figure 4] FIG. 2 is a functional configuration diagram of an administrator terminal. [Figure 5] FIG. 2 is a functional configuration diagram of an abnormal communication handling device. [Figure 6A] FIG. 2 is a diagram illustrating the hardware and software configuration of the communication monitoring device. [Figure 6B] FIG. 2 is a diagram illustrating the hardware and software configuration of the abnormal communication handling device. [Figure 6C] FIG. 1 is a diagram illustrating the hardware and software configuration of an administrator terminal. [Figure 6D] FIG. 1 is a diagram illustrating the hardware and software configuration of an abnormal communication detection device. [Figure 7] FIG. 10 is a diagram illustrating an example of a device information table. [Figure 8] FIG. 10 is a diagram illustrating an example of a white communication table. [Figure 9] FIG. 10 is a diagram illustrating an example of a business information table. [Figure 10] FIG. 10 is a diagram illustrating an example of a control information table. [Figure 11] FIG. 10 is a diagram illustrating an example of a control command. [Figure 12] FIG. 10 is a diagram illustrating an example of a phenomenon characteristic information table. [Figure 13] FIG. 10 is a diagram illustrating an example of a statistical feature information table. [Figure 14] FIG. 10 is a diagram showing an example of discrimination result information data. [Figure 15]FIG. 10 is a diagram illustrating an example of an abnormal communication handling information table. [Figure 16] FIG. 10 is a sequence diagram showing the processing of the abnormal communication handling system. [Figure 17] 10 is a flowchart showing details of an event category determination process for abnormal communication. [Figure 18] FIG. 10 is a diagram illustrating an example of an abnormal communication handling screen displayed on the administrator terminal. DETAILED DESCRIPTION OF THE INVENTION

[0014] This invention relates to the second phase of the Cross-ministerial Strategic Innovation Promotion Program (SIP) of the Council for Science, Technology and Innovation, promoted by NEDO, titled "Cyber-Physical Security for an IoT Society."

[0015] An embodiment of the present invention will be described below with reference to FIGS. First, the configuration of an abnormal communication handling system according to one embodiment will be described with reference to FIGS. 1 to 6D.

[0016] The abnormal communication handling system of this embodiment is a system that determines whether an abnormal communication detected in a cyber-physical system is an abnormality caused by a cyber attack or an abnormality caused by a malfunction.

[0017] Here, a cyber-physical system is a system that collects and analyzes information from the real physical world on a computer system in the cyber world, and then feeds back the analysis results to the physical world for utilization. In this embodiment, a factory IoT system that analyzes information collected from sensors and controls production will be used as an example of a cyber-physical system. Note that IoT (Internet of Things) refers to a mechanism in which various "things" are connected to the Internet and mutually control each other by exchanging information.

[0018] As shown in FIG. 1, the anomalous communication handling system 1 includes a monitored system 5, a communication monitoring device 20, an anomalous communication handling device 30, a network switch 40, an administrator terminal 60, and an anomalous communication determination device 100.

[0019] The anomalous communication handling system 1 has a function of evaluating anomalous communication detected by the communication monitoring device 20 in the monitored system 5, and determining, based on the evaluation result, whether the anomalous communication is due to a cyber attack or a malfunction of a device constituting the monitored system 5. The logic for evaluating anomalous communication will be described in detail later.

[0020] The monitored system 5 is an IoT system, and includes one or more controllers 61, one or more actuators 71, one or more sensors 72, and a control server 50.

[0021] The devices included in the monitored system 5 function as information processing devices capable of two-way communication via a communication network.

[0022] The control server 50 and each controller 61 are connected via a first network N1, allowing them to communicate with each other. Furthermore, each controller 61 is connected via a second network N2, allowing them to communicate with each other, with each actuator 71 and each sensor 72. When the monitored system 5 is an industrial IoT system, the first network N1 is a control network using a communication protocol such as Modbus, and the second network N2 is a field network using a communication protocol such as MQTT (Message Queuing Telemetry Transport). In the factory automation (FA) industry, a field network refers to a network that connects a host computer / server that aggregates operational status data to controllers such as programmable logic controllers (PLCs) that control devices, sensors and measuring instruments that monitor status, and driving devices such as servo motors used for positioning.

[0023] The control server 50 is a server device having a function of monitoring the operation of the entire monitored system 5 via the first network N1. The control server 50 may also have a function of changing and updating the logic of the control program running on the server or the controller 61.

[0024] The controller 61 controls the operation of each actuator 71 and each sensor 72 connected via the second network N2 in accordance with a command received via the first network N1 from the control server 50. The controller 61 is, for example, a PLC that sets operation setting values ​​such as the number of rotations of a motor for the actuators 71 in accordance with commands from the control server, and collects information output by the sensors 72.

[0025] The actuator 71 is a mechanical element that actively performs physical movement based on a command from the controller 61. The actuator 71 is, for example, a device that actually moves a valve, a motor, an electric motor, or the like in accordance with a set value that is set based on a command from the controller 61.

[0026] The sensor 72 is a device that measures temperature, flow rate, pressure, or the like, and outputs the measured value.

[0027] As shown in Figure 1, the communication monitoring device 20, the abnormal communication handling device 30, the administrator terminal 60, and the abnormal communication discrimination device 100 are all connected via the management network N3 in a state where they can communicate bidirectionally with each actuator 71 and each sensor 72.

[0028] First network N1 and second network N2are connected to monitor port 41a and monitor port 42a of the network switch 40, and the communication monitoring device 20 is connected to mirror port 41b and mirror port 42b of the network switch 40. The network switch 40 copies (mirrores) packets of the first network N1 received at monitor port 41a and transmits them to the communication monitoring device 20 from mirror port 41b, and copies communication packets of the second network N2 received at monitor port 42a and transmits them to the communication monitoring device 20 from mirror port 42b.

[0029] The communication monitoring device 20 is connected to the mirror port 41. b , 42 b The network analyzer 100 detects abnormal communications in the first network N1 and the second network N2 by collecting and analyzing communication packets in the first network N1 and the second network N2 of the monitored system 5 via the above.

[0030] The anomalous communication handling device 30 is connected to the monitored system 5 and the anomalous communication discrimination device 100 via the management network N3 and communicates with both. The anomalous communication handling device 30 has processing authority over each device in the monitored system 5, receives handling instructions from the administrator terminal 60, converts the received handling instructions into control commands or control logic programs that can be executed or processed by the device to be handled, and transmits the converted control commands or control logic programs to the devices (controllers 61, actuators 71, sensors 72) of the monitored system 5, causing the devices to execute processing to handle the anomalous communication.

[0031] The anomalous communication discrimination device 100 evaluates the anomalous communication detection information received from the communication monitoring device 20 from two perspectives: an event perspective and a statistical perspective, and based on the evaluation results, determines whether the anomalous communication is due to a cyber attack or a device malfunction, generates discrimination result information including the discrimination result, and transmits it to the administrator terminal 60.

[0032] The administrator terminal 60 is connected to the anomalous communication discrimination device 100 and the anomalous communication handling device 30 via the management network N3 and communicates with both. The administrator terminal 60 is a terminal that displays and presents to the administrator 2 countermeasures appropriate for the cause of the anomalous communication and the discrimination results based on the discrimination results of the anomalous communication received from the anomalous communication discrimination device 100. Furthermore, in accordance with the operator's selection of a countermeasure for the presented content, the administrator terminal 60 transmits information on how to handle the anomalous communication to the anomalous communication handling device 30.

[0033] The above-mentioned first network N1, second network N2, and management network N3 can be configured as, for example, a LAN (Local Area Network), a WAN (Wide Area Network) such as the Internet, or a wired or wireless communication network such as a dedicated line.

[0034] Next, the functional configuration of each device in the abnormal communication handling system will be described with reference to FIGS.

[0035] The communication monitoring device 20 is a device that collects and analyzes communication packets from the monitoring target system 5 to detect anomalous communication, and transmits anomalous communication detection information to the anomalous communication determination device 100.

[0036] As shown in FIG. 2, the communication monitoring device 20 is functionally configured to include an abnormal communication detection unit 21, a system information management unit 22, an abnormal communication detection information transmission unit 23, and a storage unit 24.

[0037] The anomalous communication detection unit 21 collects communication packets flowing from the mirror ports 41b and 42b of the network switch 40 to the first network N1 and the second network N2 of the monitored system 5. The anomalous communication detection unit 21 then analyzes the collected communication packets and obtains (1) header information (such as the IP addresses of the data source device and the data destination device, the communication protocol, and the port number) and (2) control commands and (3) parameters contained in the payload. The anomalous communication detection unit 21 also generates (4) statistical information, such as changes in the number of communications, related to the control commands.

[0038] The abnormal communication detection unit 21 then compares the specifications of the monitored system 5 indicated in the system information tables 220 accessed via the system information management unit 22 described later with the analysis information (1) to (4) above to determine whether the communication in the monitored system 5 is abnormal communication, and if it determines that the communication is abnormal communication, it transmits abnormal communication information including information about the abnormal communication to the abnormal communication detection information transmission unit 23.

[0039] Abnormal communication is determined by, for example, an abnormally large number of communication packets being sent from a particular line or device, or an operating parameter of a device being outside a normal range.

[0040] The information regarding abnormal communication includes general information about the communication, information that abnormal communication has been detected, and information about the event detected by the system.

[0041] The abnormal communication detection information transmitter 23 transmits the received abnormal communication information to the abnormal communication determination device 100 via the management network N3.

[0042] The storage unit 24 is a functional unit that stores system information tables 220. The system information tables 220 include a device information table 221, a white communication table 222, a business information table 223, and a control information table 224. Details of each of the system information tables 220 will be explained later.

[0043] The system information management unit 22 is a functional unit that accesses the system information tables 220 stored in the storage unit 24 .

[0044] Based on the abnormal communication information received from the communication monitoring device 20, the abnormal communication discrimination device 100 evaluates the abnormal communication detected by the system from two perspectives: an event perspective and a statistical perspective, and based on the evaluation results, determines whether the abnormal communication is due to a cyber attack or a malfunction of a system device, generates discrimination result information including the discrimination result, and transmits it to the administrator terminal 60.

[0045] As shown in Figure 3, the anomalous communication detection device 100 has a functional configuration consisting of an anomalous communication detection information receiving unit 120, an event evaluation unit 130, a statistical evaluation unit 140, an anomalous communication category discrimination unit 150, a communication unit for administrator terminal 160, a characteristic information management unit 110, and a memory unit 170.

[0046] The abnormal communication detection information receiving unit 120 receives the abnormal communication detection information detected by the communication monitoring device 20 via the management network N3.

[0047] The event evaluation unit 130 refers to the event feature information table 111 using the function of the feature information management unit 110, and determines the abnormal communication from the event features in the cyber attack linked to the detected event and the number of matches with the event features in the failure. but Evaluate whether the problem is due to a cyber attack or a malfunction of the system's equipment (detailed logic will be described later).

[0048] The statistical evaluation unit 140 uses the function of the feature information management unit 110 to refer to the statistical feature information table 112, and evaluates whether the detected event is due to abnormal communication, a cyber attack, or a failure of a system device based on the number of matches between the statistical features of the cyber attack linked to the detected event and the statistical features of the failure (detailed logic will be described later).

[0049] The abnormal communication category discriminator 150 discriminates the cause of the abnormal communication based on the evaluation results of the event evaluation unit 130 and the statistical evaluation unit 140. but It determines whether the problem is due to a cyber attack or a malfunction of the system's equipment (detailed logic is described below).

[0050] The manager terminal communication unit 160 generates discrimination result information including the discrimination result of the anomalous communication category discrimination unit 150 and anomalous communication detection event information, and transmits the information to the manager terminal 60.

[0051] The storage unit 170 is a functional unit that stores the event characteristic information table 111 and the statistical characteristic information table 112 .

[0052] The feature information management unit 110 is a functional unit for accessing the phenomenon feature information table 111 and the statistical feature information table 112 held in the storage unit 170 .

[0053] The administrator terminal 60 is a terminal that receives information about abnormal communication, presents it to the administrator 2, and allows the administrator 2 to select a countermeasure for dealing with the information. As shown in FIG. 4, the administrator terminal 60 has, as its functional parts, a determination result receiving part, 68 , an abnormal communication handling processing unit 62 , an abnormal communication handling information presentation unit 63 , an abnormal communication handling command generation unit 64 , an abnormal communication handling command transmission unit 65 , an abnormal communication handling information management unit 66 , and a storage unit 67 .

[0054] Discrimination result receiving unit 68 receives the abnormal communication determination result from the abnormal communication determination device 100 via the management network N3.

[0055] The abnormal communication handling processing unit 62 extracts abnormal communication handling information from the abnormal communication handling information table 400 and sends it to the abnormal communication handling information presentation unit 63, and sends information regarding the measures for dealing with the abnormal communication selected by the administrator 2 to the abnormal communication handling command generation unit 64.

[0056] The abnormal communication handling information presentation unit 63 presents the abnormal communication handling information to the administrator 2, and transmits information regarding the measures for handling the abnormal communication selected by the administrator 2 to the handling command generation unit 64. Note that the user interface by which the administrator terminal presents the abnormal communication handling information to the administrator 2 and allows the administrator 2 to select the measures for handling the abnormal communication will be described later.

[0057] The abnormal communication handling command generation unit 64 generates an abnormal communication handling command based on the information on the measures for handling the abnormal communication sent from the abnormal communication handling processing unit 62, Abnormal communication response command transmission unit 65 Send to.

[0058] The abnormal communication handling command transmitting unit 65 transmits the abnormal communication handling command sent from the abnormal communication handling command generating unit 64 to the abnormal communication handling device 30 via the management network N3.

[0059] The storage unit 67 is a functional unit that stores the abnormal communication handling information table 400 .

[0060] The abnormal communication handling information management unit 66 is a functional unit that accesses the abnormal communication handling information table 400 held in the storage unit 67 .

[0061] The abnormal communication handling device 30 receives information relating to handling of abnormal communication from the administrator terminal 60 via the management network N3, and based on the received information relating to handling of abnormal communication, transmits control commands or control logic programs to devices (controllers 61, actuators 71, sensors 72) of the monitored system 5 for which the abnormal communication handling device 30 has processing authority. Note that the control logic program is, for example, control processing software for the sequence of the controller that is realized by executing predetermined processing or calculation.

[0062] As shown in FIG. 5, the abnormal communication handling device 30 has, as its functional configuration, an abnormal communication handling information receiving unit 31, a control logic configuration unit 32, a control information transmitting unit 33, a control logic management unit 34, and a storage unit 35.

[0063] The abnormal communication handling information receiving unit 31 receives information on how to handle abnormal communication from the administrator terminal 60 via the management network N3, and transmits the information to the control logic configuration unit 32.

[0064] The control logic configuration unit 32 is configured by the control logic management unit 34. Command Data 301 , Parameter Data 302 , Logic Data 303 The logic data 303 is data describing an algorithm for control, such as the order in which control commands are issued, to be transmitted to the device in the monitored system 5 corresponding to the information on how to deal with the abnormal communication, and transmits the generated control information to the control information transmission unit 33. The logic data 303 is data describing an algorithm for control, such as the order in which control commands are issued.

[0065] The control information transmitting unit 33 transmits control information such as a control command or a control logic program configured by the control logic configuration unit 32 to the devices of the monitored system 5, thereby causing them to execute control processing.

[0066] Thereafter, the control information transmitting unit 33 receives return information on the execution result of the control process from the device of the monitored system 5, and transmits the received return information to the abnormal communication handling information receiving unit 31.

[0067] The control logic management unit 34 is a functional unit that accesses the command data 301, the parameter data 302, and the logic data 303 stored in the storage unit 35.

[0068] The storage unit 35 holds command data 301, parameter data 302, and logic data 303 for configuring control logic programs and control commands that are compatible with each device in the monitored system 5.

[0069] Specific examples of control commands sent to devices in the monitored system 5 will be explained later.

[0070] Next, the hardware and software configuration of each component of the device that constitutes the abnormal communication handling system will be described with reference to FIGS. 6A to 6D.

[0071] As shown in FIG. 6A, the communication monitoring device 20 includes a processor 201, Main memory 202, network I / F 203, auxiliary memory I / F 204, auxiliary memory device 210 These are connected to each other by internal communication lines such as a bus.

[0072] The processor 201 is a semiconductor device called, for example, a CPU (Central Processing Unit) or MPU (Micro Processing Unit), and executes various programs loaded from the auxiliary storage device 210 to the main memory 202, realizing various functions of the device and controlling the entire device. The main memory 202 is a semiconductor device that stores programs and work data, and is, for example, a ROM, which is a non-volatile storage element, and a RAM, which is a volatile storage element. Here, the ROM stores immutable programs (e.g., BIOS, firmware), and the RAM is a high-speed, volatile storage element such as a DRAM (Dynamic Random Access Memory), and temporarily stores programs executed by the processor 201 and data used when the programs are executed.

[0073] The network I / F 203 is an interface circuit that connects to the network, and collects communication packets from devices in the monitored system 5 connected to the first network N1 and the second network N2 from the network switch 40 according to a predetermined protocol, and sends and receives communication packets to and from each device connected to the management network N3.

[0074] The auxiliary storage device 210 is a device that stores programs executed by the processor 201 and data used during execution, and is, for example, a non-volatile storage device such as a magnetic storage device (HDD: Hard Disk Drive) or flash memory (SSD: Solid State Drive).

[0075] An anomalous communication detection program 211, a system information management program 212, and an anomalous communication detection information transmission program 213 are installed in the auxiliary storage device 210.

[0076] The abnormal communication detection program 211, the system information management program 212, and the abnormal communication detection information transmission program 213 are programs that realize the functions of the abnormal communication detection unit 21, the system information management unit 22, and the abnormal communication detection information transmission unit 23, respectively.

[0077] The auxiliary storage device 210 also stores system information tables 220 .

[0078] In the above explanation, the communication monitoring device 20 is an example of a general-purpose information processing device that realizes each function using software, but it may also be a dedicated device realized using an FPGA (Field-Programmable Gate Array) or ASIC (Application Specific Integrated Circuit).

[0079] 6B, the hardware configuration of the anomalous communication handling device 30 is the same as that of the above-described communication monitoring device 20. The anomalous communication handling device 30 may also be configured such that each function is realized by software using a general-purpose information processing device, or may be realized by a dedicated device.

[0080] An abnormal communication handling information receiving program 311, a control logic configuration program 312, a control information transmission program 313, and a control logic management program 314 are installed in the auxiliary storage device 310 of the abnormal communication handling device 30.

[0081] The abnormal communication handling information receiving program 311, the control logic configuration program 312, the control information transmitting program 313, and the control logic management program 314 are programs that respectively realize the functions of the abnormal communication handling information receiving unit 31, the control logic configuration unit 32, the control information transmitting unit 33, and the control logic management unit 34.

[0082] The auxiliary storage device 310 of the abnormal communication handling device 30 stores command data 301, parameter data 302, and logic data 303.

[0083] 6C, the hardware configuration of the anomalous communication determination device 100 is similar to that of the above-described communication monitoring device 20. The anomalous communication determination device 100 may also be configured such that each function is realized by software on a general-purpose information processing device, or may be realized by a dedicated device.

[0084] The auxiliary storage device 1010 of the anomalous communication discrimination device 100 is installed with a characteristic information management program 1011, an anomalous communication information receiving program 1012, an event evaluation program 1013, a statistical evaluation program 1014, an anomalous communication category discrimination program 1015, and an administrator terminal communication program 1016.

[0085] The characteristic information management program 1011, the abnormal communication information receiving program 1012, the event evaluation program 1013, the statistical evaluation program 1014, the abnormal communication category discrimination program 1015, and the administrator terminal communication program 1016 are programs that respectively realize the functions of the characteristic information management unit 110, the abnormal communication detection information receiving unit 120, the event evaluation unit 130, the statistical evaluation unit 140, the abnormal communication category discrimination unit 150, and the administrator terminal communication unit 160.

[0086] In addition, the abnormal communication determination device 100 The auxiliary storage device 1010 includes: A phenomenon feature information table 111 and a statistical feature information table 112 are stored.

[0087] The hardware configuration of the administrator terminal 60 can be realized by the same configuration as the communication monitoring device 20 described above, such as a general PC, workstation, or tablet, as shown in FIG. 6D.

[0088] The auxiliary storage device 610 of the administrator terminal 60 is installed with a discrimination result receiving program 611, an abnormal communication handling processing program 612, an abnormal communication handling information presentation program 613, an abnormal communication handling command generation program 614, an abnormal communication handling command transmission program 615, and an abnormal communication handling information management program 616.

[0089] The discrimination result receiving program 611, the abnormal communication handling processing program 612, the abnormal communication handling information presentation program 613, the abnormal communication handling command generating program 614, the abnormal communication handling command transmitting program 615, and the abnormal communication handling information management program 616 are each a discrimination result receiving unit. 68 , an abnormal communication handling processing unit 62, an abnormal communication handling information presentation unit 63, an abnormal communication handling command generation unit 64, an abnormal communication handling command transmission unit 65, and an abnormal communication handling information management unit 66.

[0090] The auxiliary storage device 610 of the administrator terminal 60 also stores an abnormal communication handling information table 400.

[0091] The administrator terminal 60 also has a display I / F 606 and an input / output I / F 607 .

[0092] The display I / F 606 is an interface for connecting a display device 620 such as an LCD (Liquid Crystal Display).

[0093] The input / output I / F 607 is an interface for connecting input / output devices, and is connected to, for example, a keyboard 630 and a mouse 632, which is a pointing device.

[0094] Next, we will use Figures 7 to 15 to analyze abnormal communication. handle The data structures used in the system are explained.

[0095] The system information tables 220 are a group of tables held by the communication monitoring device 20 and are used to determine whether or not there is an abnormality in communication. The system information tables 220 include a device information table 221, a white communication table 222, a business information table 223, and a control information table 224.

[0096] The device information table 221 is a table that holds information about devices within the monitored system 5, and as shown in Figure 7, has the following fields: device ID 221a, device name 221b, IP address 221c, alternative device ID 221d, model information 221e, device specification information 221f, execution environment requirement information 221g, and business ID 221h.

[0097] The device ID 221a stores an identifier for uniquely identifying the device. The device name 221b stores the device name. The IP address 221c stores the IP address assigned to the device. The alternative device ID 221d stores the identifier of an alternative device that will replace the device and continue operations in the event of a malfunction in the device. The model information 221e stores the model number of the device assigned by the manufacturer. The device specification information 221f stores information related to the specifications of the device (e.g., memory capacity and operating clock for the controller 61, operating speed for the actuator 71, measurement range and measurement capability for the sensor 72, etc.). The execution environment requirement information 221g stores information related to the environment in which the device is used (e.g., operating voltage, temperature required for normal operation, etc.). The task ID 221h stores the task identifier of the task performed by the device.

[0098] The white communication table 222 is a table for storing communication information for performing whitelist communication regarding communications within the monitored system 5, and has fields for a white communication ID 222a, a communication protocol 222b, a source IP address 222c, a destination IP address 222d, a source port number 222e, and a destination port number 222f, as shown in Fig. 8. Here, whitelist communication refers to a communication method in which only permitted communications are permitted to be performed, or in which abnormality determination regarding communications is relaxed.

[0099] The white communication ID 222a stores an ID that uniquely identifies the white communication. The communication protocol 222b stores an identifier or name (such as "TCP / IP") that identifies the communication protocol. The source IP address 222c and destination IP address 222d store the IP addresses of the source and destination of the communication packet, respectively. The source port number 222e and The destination port number 222f stores the port numbers of the source and destination of the communication packet.

[0100] The business information table 223 is a table that stores information about the business performed within the monitored system 5, and as shown in Figure 9, has the following fields: business ID 223a, business name 223b, operating time 223c, priority 223d, and communication ID list 223e.

[0101] The task ID 223a stores an identifier that uniquely identifies the task. The task name 223b stores the name of the task. The operating time 223c stores information about the operating time that indicates the time period during which the task is executed. The priority 223d stores information indicating the priority of the task, such as a number. The communication ID list 223e stores a list of communication IDs that handle the task.

[0102] The control information table 224 is a table that stores control information of devices used in a business, and as shown in FIG. 10, has fields for a communication ID 224a, a control protocol 224b, a control command 224c, a control parameter 224d, and a communication cycle 224e.

[0103] The communication ID 224a stores an ID that uniquely represents communication with a device. The control protocol 224b stores an identifier or name that represents a protocol related to communication for control. The control command 224c stores information (command name, command identifier, etc.) related to a control command to be given to a device in the monitored system 5. The control parameter 224d stores information on the parameters of the control command. The communication cycle 224e stores the cycle at which control communication packets are sent and received.

[0104] The control command 80 is a command for controlling a device in the monitored system 5, and in this embodiment, is information that is given from the abnormal communication handling device 30 to the device in the monitored system 5 in order to handle abnormal communication, and is stored in the payload of a communication packet.

[0105] As shown in FIG. 11, the control command 80 includes, for example, a control protocol 80a, a control command 80b, control It consists of the fields of parameter 80c.

[0106] In the example of FIG. 11, the protocol 80a is "Modbus / TCP", which is a command for controlling the controller 61 such as a PLC. 80a However, the example of "MQTT" is intended for commands to control actuators 71 and sensors 72 such as PLCs.

[0107] The event characteristic information table 111 is a table that stores information used when the anomalous communication discrimination device 100 evaluates anomalous communication from event characteristics (details will be described later), and as shown in Figure 12, it consists of fields for anomalous communication detection event ID 111a, anomalous communication detection event 111b, discrimination event 111c, and discrimination event category 111d.

[0108] The abnormal communication detection event ID 111a stores an identifier for uniquely identifying the abnormal communication detection event. The abnormal communication detection event 111b stores text explaining the abnormal communication detection event. The discrimination event 111c stores Monitored Systems The discrimination event category 111d stores a text that explains an event such as an attack or a malfunction that is likely to occur in the equipment. The discrimination event category 111d stores a flag that indicates whether the abnormal communication is due to a cyber attack or a malfunction of the equipment.

[0109] The text of the abnormal communication detection event 111b and the determination event 111c can be used to display as the content of an abnormal communication handling screen (details of which will be described later) of the administrator terminal 60 shown to the administrator 2.

[0110] The statistical feature information table 112 is a table that stores information used when the anomalous communication discrimination device 100 evaluates anomalous communication from the characteristics of statistics (details will be described later), and as shown in Figure 13, it consists of fields for statistical feature ID 112a, statistical feature 112b, discrimination condition 112c, conditional expression 112d, and discrimination event classification 112e.

[0111] The statistical feature 112a stores an identifier for uniquely identifying the statistical feature. The statistical feature 112b stores text explaining the statistical feature. The discrimination condition 112c stores a discrimination condition for statistically analyzing received detection information and determining which statistical feature the anomalous communication matches based on the statistics indicated by the anomalous communication. The conditional expression 112d stores a discriminant constructed based on the conditions indicated in the discrimination condition 112c. The discrimination event classification 112e stores a flag indicating whether the anomalous communication is due to a cyber attack or a device failure.

[0112] Here, in the record with statistical feature ID 112a "SP1", the number of sources of similar anomalous communication per unit time is within the range of a predetermined threshold, and the number of similar anomalous communication occurrences per unit time is smaller than the predetermined threshold, so it is determined that the anomalous communication is due to equipment failure, not a cyber attack.

[0113] The discrimination result information data 500 is data transmitted from the anomalous communication discrimination device 100 to the administrator terminal 60, and as shown in FIG. 14, is made up of anomalous communication detection event information 500a and discrimination information 500b.

[0114] The anomalous communication detection event information 500a includes information on the anomalous communication detection event, anomalous communication information, and device information as shown in Figure 14, and the discrimination information 500b includes event feature evaluation results, statistical feature evaluation results, and discrimination result information.

[0115] The abnormal communication handling information table 400 is a table that stores information on abnormal communication detection events and countermeasures based on the event classification of the abnormal communication determined by the abnormal communication discrimination device, and as shown in Figure 15, it consists of fields for handling information ID 400a, abnormal communication detection event 400b, event classification 400c, and countermeasure 400d.

[0116] The handling information ID 400a stores an identifier for uniquely identifying the anomalous communication handling information. The anomalous communication detection event 400b stores text explaining the anomalous communication detection event. The event category 400c stores a flag indicating whether the anomalous communication determined by the anomalous communication determination device is due to a cyber attack or a device malfunction. The handling measure 400d stores text indicating the handling measure that should be taken by the management system corresponding to the anomalous communication detection event 400b and the event category 400c.

[0117] Next, the processing of the abnormal communication handling system will be described with reference to the already mentioned FIGS. 12, 13, 16 and 17. FIG.

[0118] First, the communication monitoring device 20 receives communication packets of the first network N1 and the second network N2 from the network switch 40 and monitors for abnormal communication ( A01 , S101). Then, when abnormal communication is detected (S102), the abnormal communication detection information data is transmitted to the abnormal communication determination device 100 (A02).

[0119] Next, the anomalous communication discrimination device 100 performs an event classification discrimination process for the anomalous communication based on the received anomalous communication detection information data (S111), and transmits discrimination result information data (details will be described later) including the anomalous communication detection information and the event classification discrimination result information to the administrator terminal 60 (A03).

[0120] The details of the process for determining the event category of abnormal communication will be explained later.

[0121] Next, the administrator terminal 60 edits the data of the anomalous communication detection information and the event classification discrimination result information based on the discrimination result information data received from the anomalous communication discrimination device 100 and the anomalous communication handling information table 400, and displays an anomalous communication handling screen (a specific example will be described later) on the display device 620 (S121) and presents it to the administrator 2.

[0122] When the administrator 2 selects a countermeasure for abnormal communication displayed on the abnormal communication countermeasure screen (A04), the administrator terminal 60 acquires information on the countermeasure for abnormal communication (S122), generates abnormal communication countermeasure information data accordingly (S123), and transmits the abnormal communication countermeasure information data including the abnormal communication detection information and the countermeasure to the abnormal communication countermeasure device 30 (A05).

[0123] Based on the transmitted abnormal communication handling information data, the abnormal communication handling device 30 identifies the corresponding device in the monitored system 5 (S131), generates a control command to be sent (S132), and sends it to the corresponding device in the monitored system 5 (A06).

[0124] Next, the details of the event classification determination process for abnormal communication will be described with reference to FIG.

[0125] First, the event evaluation unit 130 of the anomalous communication discrimination device 100 refers to the event characteristic information table 111, extracts a record from the event characteristic information table 111 of the anomalous communication detection event 111b that matches the content of the received anomalous information detection information, obtains the value of the discrimination event category 111d of that record, and counts the number of times that the value is either a "cyber attack" or a "failure" (S201).

[0126] Then, the event evaluation value EventEval of the abnormal communication is calculated by the following (Equation 1) (S202). EventEval=e c ×EC+e f ×EF…(Formula 1) Here, EC is the number of records in which the value of the discrimination event category 111d of the acquired records is "cyber attack", EF is the number of records in which the value of the discrimination event category 111d of the acquired records is "failure", and ec , e f is the optimization factor for evaluation.

[0127] The optimization coefficient for evaluation is e c >e f (For example, e c =1, e f (=-1). The optimization coefficient for this evaluation can be weighted based on the know-how of the system engineer and the status of the system equipment. For example, if there are many cyber attacks on a specific date, e c When the equipment's service life exceeds the specified period, e f For example, increasing the

[0128] e c =1, e f If we take e = -1, a positive value of the event evaluation value EventEval indicates a high possibility of a cyber attack, and the larger the value, the higher the possibility of a cyber attack. c =1, e f If the event evaluation value EventEval is taken as -1, a negative value indicates a high possibility of failure, and the smaller the value, the higher the possibility of failure. c =1, e f = -1, a negative value for the event evaluation value EventEval means that it is difficult to determine whether the abnormal communication is due to a cyber attack or a device failure.

[0129] Next, the statistical evaluation unit 140 of the anomalous communication detection device 100 acquires statistical information about communication from the received anomalous communication detection information (S203). Specifically, the statistical information about communication is the statistical amount of various anomalous communications, i.e., the increase in anomalous communications per unit time, the increase in anomalous communications of a specific communication per unit time, the number of sources of the same type of anomalous communications per unit time, the number of occurrences of the same type of anomalous communications per unit time, etc.

[0130] Next, the statistical evaluation unit 140 of the anomalous communication discrimination device 100 acquires records whose statistical information calculated in S203 satisfies the discrimination condition 112c and the conditional expression 112d stored in the statistical feature information table 112, acquires the value of the discrimination event classification 112e of the record, and counts the number of times that the value is either "cyber attack" or "failure" (S204).

[0131] Then, a statistical evaluation value StatEval of the abnormal communication is calculated by the following (Equation 2) (S205). StatEval=s c ×SC+s f ×SF…(Formula 2) Here, SC is the number of records in which the value of the discrimination event category 112e of the acquired records is "cyber attack", SF is the number of records in which the value of the discrimination event category 112e of the acquired records is "failure", and s c , s f is the optimization factor for evaluation.

[0132] The optimization coefficient for evaluation is s c >s f (For example, s c =1, s f =-1). Similarly, with regard to the optimization coefficient for this evaluation, it is possible to consider weighting measures based on the know-how of the system engineer and the status of the system equipment.

[0133] Optimization coefficients for assessing the likelihood of cyber attacks, of failure The probability is the same as that explained for the eventual rating value.

[0134] Next, the abnormal communication category discrimination unit 150 of the abnormal communication discrimination device 100 calculates the discrimination result evaluation value Eval based on the event evaluation value EventEval calculated in S202 and the statistical evaluation value StatEval calculated in S205 using the following (Equation 3) (S206). Eval=k E ×EventEval+k S ×StatEval …(Formula 3) where k E , k S are the weighting factors for the event-based and statistical evaluations, respectively.

[0135] Weighting factor k for evaluation E , k S The value of is a coefficient that indicates whether to give weight to event-based evaluation or statistical evaluation. E =1, k S = 1. In addition, it can be determined by whether the administrator 2 places importance on event-based evaluation or statistical evaluation.

[0136] Also, the optimization coefficient e for event-based evaluation c , e f , optimization coefficients for statistical evaluation s c , s f , the weighting coefficient k of the final classification result E , k S may be determined by learning using training data.

[0137] Next, the anomalous communication category determination unit 150 of the anomalous communication determination device 100 calculates the determination result evaluation Result using Equation 4 as described below, based on the determination result evaluation value Eval calculated in S206. The determination result evaluation is a textual representation of the evaluation of the anomalous communication based on the determination result evaluation value Eval.

[0138] The evaluation value Eval of the discrimination result is the optimal coefficient e in the event evaluation value EventEval. c , e f , the optimization coefficient s in the statistical evaluation value StatEval c , s f , the weighting coefficient k of the discrimination result evaluation value Eval E , k S Depending on how , is taken, the larger the value of the discrimination result evaluation value Eval, the more likely it is that the abnormal communication is due to a cyber attack and not due to a device malfunction.

[0139] Therefore, when evaluating on a five-point scale, the four thresholds (Th1, Th2, Th3, Th4) are set so that Th1>Th2>Th3>Th4, If Eval≧Th1, Result="cyber attack" If Th2≧Eval>Th1, Result="Possibility of cyber attack" If Th3≧Eval>Th2, Result="Cyber ​​attack / failure" When Th4≧Eval>Th3, Result="Possible failure" When Eval>Th4, Result="Failure" …(Formula 4)

[0140] Next, the abnormal communication handling screen displayed on the administrator terminal will be described with reference to FIG. FIG. 18 is a diagram showing an example of an abnormal communication handling screen displayed on the administrator terminal.

[0141] The abnormal communication handling screen 900 is a screen displayed by the administrator terminal 60 to allow the administrator to select how to handle abnormal communication based on the abnormal communication detection information detected by the communication monitoring device 20 and the results of the abnormal communication discrimination device 100 determining whether the abnormal communication is due to a cyber attack or a device malfunction.

[0142] 18, the abnormal communication handling screen 900 has a detected abnormal communication information display field 910 and a countermeasure selection field 920 in which the contents of the countermeasure 400d in the abnormal communication handling information table 400 are edited, and one or more countermeasures are displayed, such as "[Countermeasure 1] Switch Controller 1 to alternative device Controller 2." The countermeasure selection field 920 has an Implement button 921 and a Do Not Implement button 922 for selecting each countermeasure. The Implement button 921 and the Do Not Implement button 922 are exclusive toggle buttons.

[0143] When the administrator 2 selects the measure, he / she clicks the "Implement" button 921 to select it, and when he / she does not select the measure, he / she clicks the "Do not implement" button 922 to select it, and finally clicks the OK button 930. When he / she wants to cancel the input contents, he / she clicks the cancel button 931.

[0144] As described above, the anomalous communication handling system according to this embodiment evaluates the cause of anomalous communication detected on a device in the system based on an evaluation based on event characteristics and statistical characteristics, based on the number of matches between cyber-attack characteristics and fault characteristics. Furthermore, a discrimination result value for discriminating between cyber-attacks and faults is calculated based on these two evaluation values. This makes it possible to provide an anomalous communication discrimination device that can discriminate between cyber-attacks and faults regarding anomalous communication detected in a monitored system.

[0145] In this way, when abnormal communication occurs, it is possible to distinguish between a cyber attack and a malfunction, and propose appropriate countermeasures for the event.The administrator can select the appropriate response, and the system can quickly implement countermeasures that correspond to the abnormal communication, which is expected to have the effect of minimizing damage caused by cyber attacks and malfunctions. [Explanation of symbols]

[0146] 1...Abnormal communication handling system, 5...Monitored system, 20...Communication monitoring device, 30...Abnormal communication handling device, 40...Network switch, 60...Administrator terminal, 100...Abnormal communication determination device, 220...System information tables, 221...Device information table, 222...White communication table, 223...Business information table, 224...Control information table, 80......Control command, 111...Event characteristic information table, 112...Statistical characteristic information table, 500...Discrimination result information data, 400...Abnormal communication handling information table

Claims

1. An anomalous communication detection device that determines the cause of anomalous communication detected in a monitored system in which the device operates, an event feature table that stores, for each anomalous communication detection event, a record that stores a discrimination event classification that indicates whether the anomalous communication is due to a cyber attack or a malfunction of a device in the monitored system; a statistical feature table that stores records that store discriminative event classifications that indicate whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system, for each condition that establishes the statistical quantity of the abnormal communication; receiving abnormal communication detection information in the monitored system; Based on the received anomalous communication detection information, a case evaluation value is calculated from the number of cases where the value of the discrimination event category of the record corresponding to the anomalous communication detection information in the case characteristic table is either the anomalous communication caused by a cyber attack or the anomalous communication caused by a device failure in the monitored system; Calculates the statistics of abnormal communication from the received abnormal communication detection information, Based on the calculated statistics of anomalous communication, a statistical evaluation value is calculated from the number of anomalous communications caused by cyber attacks or malfunctions of devices in the monitored system for records that satisfy the conditions for the statistics of anomalous communication in the statistical feature table; An abnormal communication discrimination device characterized by calculating a discrimination result evaluation value indicating whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system based on the event evaluation value and the statistical evaluation value, and using the discrimination result evaluation value to discriminate whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system.

2. The abnormal communication discrimination device described in claim 1, characterized in that the event evaluation value is calculated by a weighted linear sum of the number of records indicating whether the abnormal communication is due to a cyber attack or a failure of equipment in the monitored system.

3. The abnormal communication discrimination device described in claim 1, characterized in that the statistical evaluation value is calculated by a weighted linear sum of the number of records indicating whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system.

4. 2. The abnormal communication detection device according to claim 1, wherein the detection result evaluation value is calculated as a weighted linear sum of the event evaluation value and the statistical evaluation value.

5. An anomalous communication detection method using an anomalous communication detection device that determines the cause of anomalous communication detected in a monitored system in which the device operates, comprising: The anomalous communication determination device includes an event feature table that stores records for each anomalous communication detection event, the record storing a determination event classification that indicates whether the anomalous communication is due to a cyber attack or a malfunction of a device in the monitored system; a statistical feature table that stores records that store discriminative event classifications that indicate whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system, for each condition that establishes the statistical quantity of the abnormal communication; a step in which the anomalous communication determination device receives anomalous communication detection information in the monitored system; a step in which the anomalous communication determination device calculates an event evaluation value based on the received anomalous communication detection information from the number of determination event categories of the record corresponding to the anomalous communication detection information in the event feature table, where the anomalous communication is caused by either a cyber attack or a malfunction of a device in the monitored system; a step of the anomalous communication determination device calculating statistics of anomalous communication from the received anomalous communication detection information; a step in which the anomalous communication determination device calculates a statistical evaluation value based on the calculated anomalous communication statistics from the number of anomalous communications of records in the statistical feature table that satisfy the conditions for the anomalous communication statistics being caused by either a cyber attack or a malfunction of a device in the monitored system; The abnormal communication discrimination method is characterized by comprising a step in which the abnormal communication discrimination device calculates a discrimination result evaluation value indicating whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system based on the event evaluation value and the statistical evaluation value, and determines whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system based on the discrimination result evaluation value.

6. An abnormal communication handling system that determines a cause of abnormal communication detected in a monitored system in which a device operates, a communication monitoring device that monitors abnormal communications in the monitored system; an abnormal communication handling device that transmits control information to a device in the monitored system; an administrator terminal that displays network information of the monitored system and receives instructions from an administrator; an abnormal communication determination device that evaluates the abnormal communication detection information and determines whether the abnormal communication is due to a cyber attack or a device malfunction based on the evaluation result; the communication monitoring device transmits abnormal communication detection information to the abnormal communication determination device; The abnormal communication determination device The system maintains a phenomenon feature table that stores, for each abnormal communication detection event, a record that stores a discriminative event classification that indicates whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system, and a statistical feature table that stores, for each condition under which the statistics of the abnormal communication are established, a record that stores a discriminative event classification that indicates whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system, The anomalous communication determination device calculates an event evaluation value based on the received anomalous communication detection information from the number of determination event classification values ​​of the record corresponding to the anomalous communication detection information in the event feature table, where the anomalous communication is caused by a cyber attack or a malfunction of a device in the monitored system; the anomalous communication determination device calculates statistics of anomalous communication from the received anomalous communication detection information; The anomalous communication determination device calculates a statistical evaluation value based on the calculated anomalous communication statistics from the number of anomalous communications caused by cyber attacks or malfunctions of devices in the monitored system for records that satisfy the conditions for the anomalous communication statistics in the statistical feature table; The anomalous communication discrimination device calculates a discrimination result evaluation value indicating whether the anomalous communication is due to a cyber-attack or a malfunction of a device in the monitored system based on the event evaluation value and the statistical evaluation value, and generates a discrimination result evaluation of text that evaluates whether the anomalous communication is due to a cyber-attack or a malfunction of a device in the monitored system based on the discrimination result evaluation value; the anomalous communication determination device transmits determination result information including anomalous communication detection information and the determination result evaluation to the administrator terminal; The administrator terminal holds an abnormal communication handling information table that stores the abnormal communication detection information and records that store countermeasures for the abnormal communication, for each of whether the abnormal communication is due to a cyber attack or a malfunction of a device in the monitored system. The administrator terminal displays an abnormal communication handling screen that displays the abnormal communication detection information, the evaluation of the determination result, and a countermeasure plan for the abnormal communication based on the received determination result information, and the administrator terminal receives a selection of a countermeasure plan for the abnormal communication from the administrator, generates abnormal communication handling information based on the selection of the countermeasure plan, and transmits the abnormal communication handling information to the abnormal communication handling device; The abnormal communication handling system is characterized in that the abnormal communication handling device transmits control information to devices of the monitored system based on the received abnormal communication handling information.

Citation Information

Patent Citations

  • Security management plan design device, security management plan evaluation device, security management plan design method and security management plan evaluation method

    JP2018137500A

  • Abnormal factor determination device, control system, and abnormal factor determination method

    JP2019205125A

  • Monitoring device, monitoring method, and monitoring program

    JP2021027505A

  • Log analysis device, information processing method and program

    WO2014119669A1

  • Electronic control device, electronic control system and program

    WO2020137743A1