Response support device and response support method

The countermeasure support device addresses the challenge of rapid incident response in OT and IoT systems by evaluating incident impact and urgency, facilitating quick and effective decision-making to maintain business continuity.

JP7791776B2Active Publication Date: 2025-12-24HITACHI LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022089309
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-05-31
Publication Date
2025-12-24
Estimated Expiration
2042-05-31

AI Technical Summary

Technical Problem

Existing systems struggle to provide rapid and effective responses to cyber incidents in OT and IoT systems, failing to consider the dynamic business and system status, which can lead to significant impact on operations and disrupt business continuity.

Method used

A countermeasure support device and method that evaluates the impact and urgency of incidents, determines priority of responses based on system and business status, and provides a display for quick decision-making.

Benefits of technology

Enables prompt and minimally disruptive responses to cyber incidents, ensuring business continuity by prioritizing countermeasures based on real-time system status and impact analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007791776000001
    Figure 0007791776000001
  • Figure 0007791776000002
    Figure 0007791776000002
  • Figure 0007791776000003
    Figure 0007791776000003
Patent Text Reader

Abstract

To provide a response support technique for minimizing an impact on a job as much as possible and enabling the continuation of the job and prompt response.SOLUTION: A response support device for supporting a response executed according to a situation of an incident that has occurred in a monitoring target, includes: an incident evaluation unit 103 that evaluates an impact of the incident on the monitoring target and an urgency level of the response to the incident; a response evaluation unit 104 that evaluates an impact level on a job and an effectiveness level to the incident, for the response to the incident; a priority order determination unit 105 that determines a priority order of responses based on evaluation by the incident evaluation unit and evaluation by the response evaluation unit; and a display unit 106 that displays a screen including the priority order of responses determined by the priority order determination unit.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a countermeasure support device and a countermeasure support method, and more particularly to support for making countermeasure decisions that are suitable for quickly dealing with incidents such as security intrusions. [Background technology]

[0002] There have been reported cases where cyberattacks have affected business continuity. For example, a cyberattack on an automobile manufacturing company affected its production management system, causing production to be halted at global bases, and it took four days for full production to resume. Furthermore, according to a survey by SANS, approximately 60% of cases reported that it took six hours or more to implement a first response. These reports show that shortening the first response time is important in order to limit the spread of damage caused by cyberattacks and maintain business continuity.

[0003] Various techniques have been proposed for monitoring incidents in target devices or systems and dealing with them appropriately. For example, Patent Document 1 discloses a technique for calculating the occurrence frequency of each word included in event information for each classified category, and, upon receiving a new event, estimating the category to which the new event belongs based on the words included in the event information of the new event and the calculated occurrence frequency of each word. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Publication No. 2017-97781 Summary of the Invention [Problem to be solved by the invention]

[0005] In OT and IoT systems, the social impact of any damage caused by the system is significant, so a rapid response is necessary. Furthermore, it is important to consider business continuity and availability when responding. For example, in the past, abnormal events and the corresponding responses were predetermined. Depending on the system's operating status, such as the strain on CPU resources of the device where the abnormality was detected or the device that was responsible for the response, it could take a long time to actually implement the response, despite the significant impact on business operations.

[0006] The technology of Patent Document 1 estimates the category to which a new event belongs based on the words contained in the event information of the new event and the calculated frequency of occurrence of each word in response to the reception of the new event, so it is difficult to take measures that reflect the status of the business and the system at the time of the incident, which change depending on the situation, such as the impact on business, the risk situation due to the incident, and the system status.

[0007] Therefore, an object of the present invention is to realize a response support technology that minimizes the impact on business operations, allows business continuity, and enables prompt response. [Means for solving the problem]

[0008] A preferred example of a countermeasure support device according to the present invention is a countermeasure support device that supports countermeasures to be executed in accordance with the status of an incident that has occurred in a monitored object, and has an incident evaluation unit that evaluates the impact of the incident on the monitored object and the urgency of dealing with the incident, a countermeasure evaluation unit that evaluates the impact of the incident on business operations and the effectiveness of dealing with the incident, a priority determination unit that determines the priority of the countermeasures based on the evaluation by the incident evaluation unit and the evaluation by the countermeasure evaluation unit, and a display unit that displays a screen including the priority of the countermeasures determined by the priority determination unit.

[0009] The present invention can also be understood as a countermeasure support method performed by the countermeasure support device. The present invention can also be understood as a countermeasure support program that, when executed by a computer, realizes the functions of the countermeasure support device, and a medium for storing the program. [Effects of the Invention]

[0010] According to the present invention, it is possible to realize a response support technique that minimizes the impact on business operations, allows business continuity, and enables prompt response. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 illustrates an example of a response support device according to an embodiment. [Figure 2] FIG. 2 illustrates an example of hardware of a countermeasure support device. [Figure 3] FIG. 10 is a diagram illustrating an example of a device information table. [Figure 4] FIG. 10 is a diagram illustrating an example of a business information table. [Figure 5] FIG. 10 is a diagram illustrating an example of a threat information table. [Figure 6] FIG. 10 is a diagram illustrating an example of a handling information table. [Figure 7] FIG. 10 is a diagram showing an example of a response display screen. [Figure 8] FIG. 2 is a diagram showing an overall processing flow of the countermeasure support device. [Figure 9] FIG. 10 is a diagram showing the sequence of the overall processing of the countermeasure support device. [Figure 10] FIG. 10 is a diagram showing a detailed processing flow of incident evaluation (step 805). [Figure 11] FIG. 10 is a diagram showing a detailed processing flow of the countermeasure evaluation (step 806). [Figure 12] FIG. 10 is a diagram showing a detailed processing flow of determining the priority order of the measures (step 807). DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, preferred embodiments of the present invention will be described with reference to the drawings.

[0013] FIG. 1 shows an overall diagram of a system including a response support device according to an embodiment. A countermeasure support device 100 is connected to a monitored system 191, a monitoring device 192, and a countermeasure execution device 193 via a network to form a system. In this system, the monitoring device 192 monitors events that occur in the monitored system 191, and the countermeasure execution device 193 takes action depending on the status of the monitored event. The countermeasure support device 100 supports the action taken by the countermeasure execution device 193.

[0014] First, a brief description of these devices 191 to 193 will be provided. The monitored system 191 is a system configured from, for example, IT devices such as computers, printers, proxies, and routers, and IoT devices such as temperature sensors and acceleration sensors, and availability is particularly important. The monitoring device 192 is a resource monitoring device or antivirus device for each device in the monitored system 191, and monitors the CPU usage rate, power on / off status, network response status, and malware infection (incident) status of each device. The countermeasure execution device 193 is, for example, an IDS / IPS, and when the monitoring device 192 detects an abnormality in the monitored system 191, it automatically or according to instructions from an operator performs processing such as isolating the device where the abnormality was detected and peripheral devices from the network, deleting malware-infected files, etc.

[0015] The response support device 100 is configured to include a receiving unit 101, a system status acquisition unit 102, an incident evaluation unit 103, a response evaluation unit 104, a response priority determination unit 105, a display unit 106, a response instruction unit 107, a device information table 110, a business information table 111, a threat table 112, and a response information table 113 (the tables are illustrated as "TB").

[0016] The receiving unit 101 receives various information. In particular, in this embodiment, the receiving unit 101 receives system status information of the monitored system 191 and alert information transmitted by the monitoring device 192. The alert information is issued when the monitoring device 192 detects that an incident, such as a malware infection or a malfunction, has occurred in the monitored system 191. The system status acquisition unit 102 acquires system status information of the monitored system 191. The system status information includes, for example, the resource devices constituting the monitored system 191, their addresses, and the status of business processing in the devices. This status information is used by the response support device 100 to determine the priority of responses. The incident evaluation unit 103 determines the impact of the incident on the monitored system 191 and the urgency of the incident response based on the alert information received by the receiving unit 101. The response evaluation unit 104 determines the time required for each response to the incident, the impact on business operations, and the effectiveness of the response to the incident. The priority determination unit 105 calculates the priority of each countermeasure based on the evaluation results by the incident evaluation unit 103 and the evaluation results by the countermeasure evaluation unit 104. The display unit 106 processes display information for the display unit 205 (FIG. 2) and displays the screen. In this embodiment, in order to support the operator in making quick countermeasure decisions, the display unit 106 processes and controls the display of a screen that includes the countermeasure content and priority of each countermeasure, selection items for prioritization perspectives, a button to update the countermeasure prioritization information, a countermeasure instruction button, etc. The countermeasure instruction unit 107 transmits the countermeasure content determined by the operator on the screen displayed on the display unit 106 to the countermeasure execution device 193.

[0017] The functions of the above-described units 101 to 107 are respectively realized by executing a program in CPU 201 of Fig. 2. Furthermore, each of tables 110 to 113 is stored in memory 202 or storage unit 203 of Fig. 2. The configuration of each table will be described later with reference to Figs. 3 to 6.

[0018] FIG. 2 shows an example of the hardware configuration of a computer that is applied to the response support device 100. As shown in FIG. The computer is configured by connecting a processing unit 201, a memory 202, a storage unit 203, an input unit 204, a display unit 205, and a communication control unit 206 via a bus 207. The processing unit 201 executes a program to realize each of the functional units shown in FIG. 1. The memory 202 and the storage unit 203 store data acquired by the receiving unit 101, various data used by the processing unit 201, and various programs including programs that realize each of the functional units. The input unit 204 is an information input device such as a keyboard or a mouse. The display unit 205 is a display device such as a liquid crystal display. The communication control unit 206 is communication control means that communicates with, for example, a wireless network interface, a network interface card, etc.

[0019] Next, examples of the configuration of each table will be described with reference to FIGS.

[0020] FIG. 3 shows an example of the device information table 110. The device information table 110 manages information about each device that constitutes the monitored system 191. Specifically, it holds a device ID 301 that uniquely distinguishes each device, a device IP address 302, a device name 303, an associated task ID 304 that the device is associated with in a task, and a device importance 305. For example, a device with device ID 301 of "00001" has IP address 302 of "192.168.0.5", device name 303 of "machine-A", associated task IDs 304 of "0002" and "0003", and the importance 305 of the device is "5" when importance is managed in ascending order from 1 to 10, for example.

[0021] Here, the importance level 305 of a device refers to the degree of importance of the device in executing related tasks. The importance level may also include calculation of information held by the device. For example, in a certain factory assembly process, machine A issues instructions to machines B to D, and machines B to D install parts in their designated positions according to the instructions from machine A. If machine C and machine A operate abnormally, machine C can be compensated for by the other machines B and D. However, if machine A operates abnormally, machines B and D cannot compensate for machine A's processing. Furthermore, machine A contains instruction and command information that can instruct machines B to D to perform malicious operations, so machine A can be considered to be more important than machines B to D.

[0022] FIG. 4 shows an example of the business information table 111. The task information table 111 manages information about tasks executed in the monitored system 191. Specifically, it holds a task ID 401 that uniquely distinguishes each task, a task name 402, a task sequence 403 that indicates inter-device communications and in-device processing content for a series of task processes, a unit task time 404 required to process the task sequence 403, a task time 405 that is a time period during which the task can be executed, a task importance 406, and the like.

[0023] For example, the task ID 401 is "00001", the task name 402 is "gyoumu-A", and the task sequence 403 is "192.168.0.5:3000→192.168.0.7:3010, Since the IP and port are "192.168.0.8:3005 → 192.168.0.6:3012," the communication from IP and Port 192.168.0.5:3000 to 192.168.0.7:3010 and the communication from 192.168.0.8:3005 to 192.168.0.6:3012 are a task sequence that form a series of unit tasks, the unit task time 404 is "5" minutes, the task time 405 during which the task may occur is the time period from "10:00 to 17:00," and the importance 406 of the task is "5," for example, when the importance is managed in ascending order from 1 to 10.

[0024] Here, the importance of a task can be considered, for example, in a chemical factory, where task 1 involves mixing chemical A and chemical B to create a chemical reaction and produce chemical X, and task 2 involves diluting chemical C to produce chemical C'. In this case, the mixing ratio of chemical A and chemical B must be precise, and this mixing operation results in the production of expensive chemical X being wasted, resulting in a process with high damage costs. Furthermore, even if there is a slight error in the ratio of the dilution process of chemical C, it does not have much of an impact on the production of chemical C' itself (it can be recovered), and even if a certain number of chemicals C' are not produced successfully, the damage cost is not as great as that of chemical X. In this case, the chemical X production process task is considered to be "higher" in importance.

[0025] The device information table 110 and the business information table 111 register, update, and delete information in each table when, for example, a system administrator installs or disposes of a device, or adds or deletes new business information accordingly.

[0026] FIG. 5 shows an example of the threat information table 112. The threat information table 112 manages threat information of incidents detected by the monitoring device 192. Specifically, it holds a threat ID 501 that uniquely distinguishes each piece of threat information, a threat classification 502 that classifies the type of threat, a threat name 503, a threat level 504 that indicates the degree of impact of the threat on business or the system, a threat propagation speed (min) 505 that indicates the speed at which the threat propagates to other devices, etc., and an urgency 506 that is defined in advance based on the impact of the threat, the threat propagation speed, etc.

[0027] For example, a threat with threat ID 501 of "00001" has threat classification 502 of "malware" and "worm," threat name 503 of "warm-1," threat level 504 of "5" when importance is managed in ascending order from 1 to 10, threat spread speed 505 of "5" minutes, and urgency of "5" when importance is managed in ascending order from 1 to 10, for example.

[0028] In this embodiment, the threat ID 501 is transmitted by the monitoring device 192 including a predetermined ID in the alert information, which is received by the receiving unit 101 and stored in the threat information table. However, when linking with monitoring devices 192 provided by multiple operators, the correspondence between the alert information and the threat ID may differ depending on the multiple operators, so a unit for associating the alert information output by the monitoring device 192 with each element of the threat information table including the threat ID may be provided between the monitoring device 192 and the receiving unit 101.

[0029] FIG. 6 shows an example of the handling information table 113. The countermeasure information table 113 manages the details of countermeasures against incidents. Specifically, it holds a countermeasure ID 601 that uniquely distinguishes each countermeasure, a countermeasure target threat ID 602 ​​that identifies the threat that is the target of the countermeasure, a countermeasure classification 603 that classifies the type of countermeasure, a countermeasure name 604, a required time 605 that indicates an estimate of the time required to execute the countermeasure and to expect the effect on the incident, and an effectiveness 606 that indicates the degree of effectiveness of the countermeasure against the incident.

[0030] For example, for a countermeasure with a countermeasure ID 601 of "00001", the threat IDs 602 targeted by that countermeasure are "00001" and "00003", the countermeasure classification is "stop", the countermeasure name is "stop-1", the estimated time required for the countermeasure to be implemented and be effective against the incident is "5" minutes, and the effectiveness of the countermeasure is "5" when the importance is managed in ascending order from 1 to 10, for example.

[0031] Based on the above tables, the response support device 100 performs incident evaluation and response evaluation based on the alert information received from the monitoring device 192, and prioritizes the responses.

[0032] In addition, the threat information table 112 and the response information table 113 are registered, updated, and deleted by, for example, the manufacturer of the response support device in this embodiment or a security administrator who is the user of the response support device, when security threat information is updated.

[0033] Next, an example of a countermeasure display screen will be described with reference to FIG. The display unit 205 displays a countermeasure display screen 700 containing countermeasure details for prioritized incidents. Specifically, the countermeasure display screen 700 includes a countermeasure selection field 701 in which the operator can select a countermeasure, a countermeasure list 702 displaying a list of countermeasures for the incident, a priority field 707 indicating the priority of each countermeasure, an evaluation perspective 708 for selecting the perspective for prioritizing the countermeasures and their application, an update button 711 for reloading and displaying the countermeasure list contents when the prioritization changes in real time, and a countermeasure instruction button 712. According to this example, multiple countermeasures can be provided for a single incident, and the operator can select the countermeasure they deem most appropriate. That is, when the operator selects "Countermeasure" in the countermeasure selection field 701 and presses the countermeasure instruction button 712, the selected countermeasure is sent to the countermeasure execution device 193.

[0034] Furthermore, the countermeasure list 702 has a countermeasure ID 703, a countermeasure name 704, a countermeasure summary 705 that explains the countermeasure classification and summary to the operator, and a countermeasure target device 706 that indicates the countermeasure target device. Here, the countermeasure ID 703 and the countermeasure name 704 are the same as the countermeasure ID 601 and the countermeasure name 604 in the countermeasure table 113. Furthermore, the evaluation perspective 708 has a business impact 709 and a speed level 710. The business impact 709 further has a selection box for whether or not to include the business impact in the evaluation perspective items when calculating the countermeasure prioritization, and a display of the business impact level that indicates the degree of business impact. The speed level 710 further has a selection box for whether or not to include the speed level in the evaluation perspective items when calculating the countermeasure prioritization, and a display of the speed level that indicates the expected required time for the countermeasure to be effective against a threat. The countermeasure support device according to this embodiment uses the display screen to support the operator in making countermeasure decisions.

[0035] Next, the overall processing of the response support device 100 will be described with reference to FIGS. FIG. 8 shows the overall operation of the response support process, and FIG. 9 shows the sequence of the process when an incident occurs. 8, first, the monitoring device 192 determines whether or not an incident has occurred in the monitored system 191 (step 801). If the monitoring device 192 does not detect an incident in the monitored system 191, the contents of the countermeasure list are not displayed on the display unit 106 (i.e., the countermeasure list remains blank), and the process ends (step 802).

[0036] On the other hand, if the monitoring device 192 detects an incident in the monitored system 191, the monitoring device 192 transmits alert information, which is received by the response support device 100 (step 803). Thereafter, the processing continues from step 804 to step 810. This corresponds to the alert notification from the monitoring device 192 to the receiving unit 101 in the response support device 100 in the sequence of FIG. 9.

[0037] Next, the system status acquisition unit 102 of the countermeasure support device 100 queries the monitoring device 192 to acquire system status information of the monitored system 191 (step 804). The system status information includes the business communication status of the monitored system 191, the start / stop status of the device that detected the incident and peripheral devices, and resource status such as CPU load and memory load. The system status acquisition unit 102 continues to acquire system status information while the display unit 106 displays the countermeasure list screen and the process from countermeasure selection to countermeasure execution is carried out. This corresponds to the system status information query and transmission of system status information from the monitoring device 192 to the system status acquisition unit 102 in the sequence of FIG. 9.

[0038] Next, the priority of the response is determined based on the alert information acquired in step 803, the system status information acquired in step 804, and the information in each of the tables 110 to 113 (steps 805 to 807).

[0039] In step 805, the degree of impact of the incident on business operations and the urgency of the response are calculated based on information such as alert information, system status information, device storage table 110, business information table 111, and threat information table 112. This corresponds to the block in the sequence of Fig. 9 where the response priority determination unit queries various tables and evaluates the incident. Details of this process will be described later with reference to the incident evaluation processing flow in Fig. 10.

[0040] In step 806, the effectiveness, business impact, speed, etc. of the response are calculated based on information such as alert information, system status information, device storage table 110, business information table 111, threat information table 112, and response information table 113. This corresponds to the block in the sequence of Fig. 9 where the response priority determination unit queries various tables and evaluates the response. Details of this process will be described later with reference to the response evaluation processing flow in Fig. 11.

[0041] In step 807, the priority of the countermeasure is calculated based on the results of calculations in steps 805 and 806 and the information on the countermeasure evaluation viewpoint 708 selected by the operator on the countermeasure display screen 700 or set in advance by the countermeasure support device 100. This corresponds to the bottom block of the countermeasure priority determination section in the sequence of Fig. 9. Details of this process will be described later with reference to the process flow of countermeasure priority determination in Fig. 12.

[0042] Next, the display unit 106 displays a list of countermeasures with the priorities calculated by the priority determination unit 105 (step 808). If the operator takes time to consider which countermeasure to take and a certain period of time has passed, the status of the impact of the incident on the business, the resource status of the countermeasure target device, and the business that may be affected by the countermeasure will also change, so for example, the processing of steps 804 to 808 is executed again after a certain period of time has passed (step 809).

[0043] Next, when the operator selects the countermeasure to be actually executed from the countermeasure list screen displayed on the display unit 106 (701) and presses countermeasure instruction 712, the countermeasure instruction unit 107 transmits countermeasure instruction information to the countermeasure execution device 193 (step 810). The countermeasure execution device 193 executes the countermeasure in accordance with the received countermeasure content, and the series of countermeasure processing ends.

[0044] FIG. 10 shows an example of a detailed processing flow of incident evaluation (step 805). The purpose of this process is to first calculate the impact of the incident, i.e., the business impact and urgency of the response, in order to extract responses that correspond to the impact and urgency of the response and then proceed with the process when prioritizing responses.

[0045] The incident evaluation unit 103 first acquires the importance of the device in which an abnormality has been detected (step 1001), which are components of the incident evaluation calculation, acquires the importance of the related business of the device in which an abnormality has been detected (step 1002), acquires threat characteristic information (step 1003), and acquires system status information (step 1004).

[0046] Specifically, if the anomaly detection device ID received from the alert information is "00001", by referring to the device information table 110, it is found that the importance 305 of the device corresponding to the anomaly detection device ID 301 "00001" is "5". Furthermore, because the related tasks 304 of the device are "0001, 0002", by referring to the task information table 111, it is found that the importance 406 of the task corresponding to the related task ID 401 of the anomaly detection device "0001" and "0002" is "5" and "3". Furthermore, if the threat ID received from the alert information is "00001", by referring to the threat information table 112, it is found that the threat level 504 and urgency 506 corresponding to the threat ID 501 "00001" are "5". Furthermore, from the time the abnormality was detected contained in the alert information, the operating status of the abnormality detection device received from the system status information, the business communication information, and so forth, it can be seen that the time the abnormality was detected was "11:00", which was within the business hours 405 of either "00001" or "00002" of business ID 401, the abnormality detection device was in an operating state without system downtime, and the business communication status was that communications had occurred between "192.168.0.5:3000 → 192.168.0.7:3010" and "192.168.0.5 (shori.sh)", which means that within the business sequence 403 of each row of the corresponding business ID 401, the communication status is that immediately after the start of each business sequence.

[0047] Next, the degree of impact of the incident on business operations is calculated based on the information acquired in steps 1001 to 1004 (step 1005). The degree of impact on business operations is, for example, the sum of the importance of the anomaly detection device, the importance of the business operations that are related to the anomaly detection device and are in operation, and the threat level of the detected threat. Note that there is also a method of adding up the values ​​of the importance of the device, the importance of the business operations, and the threat level after assigning weights to them, but in this embodiment, for simplicity of explanation, all weights are added as "1." Specifically, when the abnormality detection device ID is "00001", the importance 305 of the device is "5", and the time the abnormality was detected is "11:00", which falls within the business hours 405 of the related business IDs "0001" and "0002". The "5" and "3" in the importance 406 of each business are added together to get "8", and the threat information obtained from the alarm information shows that the threat ID 501 is "0001", so the threat level 504 is "5" and the urgency 506 is "5", and the importance of the above assets "5", the business importance "8", and the threat level "5" are added together to get the result "18".

[0048] Next, the urgency of dealing with the incident is calculated based on the information acquired in steps 1001 to 1004 (step 1006). The urgency of dealing with the incident is, for example, the sum of the importance of the anomaly detection device, the importance of the business that is related to the anomaly detection device and is in operation, and the urgency of the detected threat. Specifically, if the anomaly detection device ID is "00001", the time the anomaly was detected is "11:00", and the threat ID is "0001", then, as in step 1005, the asset importance of "5", the business importance of "8", and the urgency 506 of the detected threat of "5" are added together to obtain the result "18".

[0049] Finally, the tolerance for the incident is calculated (step 1007). The tolerance for the incident is a value used to determine whether the impact on business operations and the urgency of dealing with the incident calculated in steps 1005 and 1006 are equal to or lower than a preset tolerance threshold. If the impact on business operations and the urgency of dealing with the incident calculated in steps 1005 and 1006 exceed the preset tolerance threshold, immediate action is required, and therefore the weighting of the impact on business operations is calculated as "0" in the subsequent prioritization of actions. Specifically, if the impact on business operations is "18," the urgency of dealing with the incident is "18," and the preset tolerance thresholds are "20" for the impact on business operations and "15" for the urgency of dealing with the incident, both the impact on business operations and the urgency of the incident are below the tolerance thresholds for the impact level and the urgency of dealing with the incident, and therefore these values ​​are used in the subsequent prioritization of actions. Furthermore, if an incident with threat ID 501 "00001" is detected with device ID 301 "00003" at time "11:30", the threat level 504 for that threat ID 501 "00001" is "5", the importance of the device ID 301 "00003" that detected it is "10", and the importance 406 of the related ongoing task ID 401 "0003" is "6", so the sum of these amounts is "21". Because this exceeds the allowable business impact level of "20", the weighting of business impact is set to "0" in the subsequent prioritization of responses, and the response candidate with a faster speed is calculated as having a higher priority, regardless of the level of business impact. This completes the processing of the incident evaluation unit 103.

[0050] FIG. 11 shows an example of a detailed processing flow of the countermeasure evaluation (step 806). The purpose of this process is to calculate the effectiveness and speed of the countermeasures, which are the evaluation criteria for prioritizing the countermeasures, when prioritizing the countermeasures.

[0051] The countermeasure evaluation unit 104 first extracts a list of countermeasures corresponding to the threat ID 602 ​​of the incident (step 1101). By referencing the threat ID information included in the alert information and the countermeasure information table 113, the unit extracts items corresponding to the countermeasure target threat ID 602. Specifically, it extracts rows containing the threat ID "00001" in the countermeasure target threat ID 602 ​​column, and extracts countermeasures with countermeasure ID 601 values ​​of "00001" and "00002".

[0052] Next, for each of the extracted countermeasure candidates, the degree of impact on business operations when the countermeasure is executed is calculated (step 1102). The degree of impact on business operations when the countermeasure is executed is calculated by, for example, referring to the device information table 110, the business information table 111, and the countermeasure information table 113, adding the degree of business impact previously assigned to each countermeasure classification of the countermeasure candidate and the importance of the business operations that are currently running and related to the abnormality detection device and the countermeasure instruction destination device. Note that each element of this addition may be weighted before addition. In this embodiment, for ease of explanation, all weights are added as "1". Specifically, for the action with action ID 601 "00001" and action name 604 "stop-1," which is one of the action candidates, the action classification 603 is "stop," so the pre-assigned business impact degree is "5," and the anomaly detected device and the action instruction destination device also have device ID 301 "00001," the importance 305 of that device is "5," the related task ID 304 is "0001, 0002," and the time the anomaly was detected is "11:00," so it is within the business hours 405 of the related task IDs "0001" and "0002," and the importance 406 of each task is "5" and "3," respectively, and the business impact degree "5" pre-assigned to the action classification 603 "stop" is added to the importance 406 of each task, which is "5" and "3," respectively, to obtain the result "18." Similarly, calculations are made for the action with action ID 601 "00002" and action name 604 "syukutai-1," which is one of the action candidates. For the action with action ID 601 "00002" and action name 604 "syukutai-1", the action classification 603 is "degeneration", so the pre-assigned degree of business impact is "3", and the result is "14".

[0053] Next, for each of the extracted candidate measures, the effectiveness of the response to the incident when the measure is executed is calculated (step 1103). The effectiveness of the response is determined, for example, by referencing each row corresponding to the extracted candidate measure from the response information table 113 and obtaining the value of the effectiveness 606. Specifically, for one of the candidate measures, the measure with the measure ID 601 "00001" and the measure name 604 "stop-1", the effectiveness 606 is referenced and the result is "5". Similarly, for another candidate measure, the measure with the measure ID 601 "00002" and the measure name 604 "syukutai-1", the effectiveness 606 is referenced and the result is "2".

[0054] Next, for each of the extracted countermeasure candidates, the promptness of the incident response when the countermeasure is executed is calculated (step 1104). The promptness of the response is calculated, for example, by referencing each row corresponding to the extracted countermeasure candidate from the countermeasure information table 113, adding the value of the required time 605 and the countermeasure execution waiting time calculated from the progress status of the task sequence of the task that is related to the countermeasure instruction destination device and is in operation and the unit task time, and sorting the result in descending order from "10" on a 10-point scale every 10 minutes. Specifically, for the action with action ID 601 "00001" and action name 604 "stop-1", which is one of the action candidates, it is determined whether task IDs 401 "0001" and "0002", which are related to device ID "00001" that is the device to which the action is instructed and which are in operation, are in operation. If they are in operation, if there is an operation with an importance equal to or greater than the pre-assigned threshold "4", which is the threshold for determining whether to wait for the action to be executed, then after the task sequence of that operation is completed, that is, after the maximum time equivalent to the unit task time is added to the required time (minutes) 605 for action ID 601 "00001" and action name 604 "stop-1", which is "5", a value of "10" is obtained, and this results in the value "10" being calculated in descending order from the value "10" on a 10-point scale every 10 minutes.

[0055] Finally, for each of the extracted candidate actions, it is calculated whether the impact and urgency of the action on the incident fall within the tolerances (step 1105). For example, for each of the extracted candidate actions, if the impact on business or the speed of the action calculated in steps 1102 and 1104 when the action is taken exceeds the pre-assigned impact on each business, a negative point is given for the difference. If the speed is lower than the urgency, a negative point is given for the difference. In all other cases, it is determined that the impact and urgency of the action on the incident fall within the tolerances, and the values ​​of the impact on business and the speed of the action calculated in steps 1102 and 1104 when the action is taken are used as is for prioritizing the actions, as described below. Specifically, for the action with action ID 601 "00001" and action name 604 "stop-1," which is one of the candidate actions, the impact on business of "18" calculated in step 1102 is lower than the pre-assigned business impact threshold of "20," so the value "18" is given as is. Next, since the promptness of response to the incident calculated in step 1104, "10", exceeds the maximum value of "5" among the urgency levels of each threat, the result remains the same, "10". Similarly, when calculations are made for one of the candidate responses, with response ID 601 "00002" and response name 604 "syukutai-1", the degree of impact on business remains "14" calculated in step 1102, and since the promptness of response to the incident, "4" calculated in step 1104, exceeds the maximum value of "5" among the urgency levels of each threat, the result is "3", which is one point less than "4" calculated in step 1104.

[0056] FIG. 12 shows an example of a detailed processing flow for determining the priority order of the measures (step 807). The priority determination unit 105 first refers to information on the response evaluation criteria 708 selected by the operator on the response display screen 700 or set in advance by the response support device 100 (step 1201). For example, if there are items selected as evaluation criteria such as business impact and response speed, or other criteria, these are referenced as items that will serve as the basis for the evaluation criteria for prioritizing responses. Note that the effectiveness of the response is not included in the options for the evaluation criteria item, since the effectiveness of all the responses extracted for the threat is guaranteed. Specifically, since the checkboxes for business impact 709 and speed 710 are checked in the evaluation criteria 708 on the response display screen 700 (example in FIG. 7), these two criteria are referenced as items that will serve as the basis for the evaluation criteria for prioritizing responses.

[0057] Next, the priority of the response is calculated and the process ends (step 1202). That is, the priority of the response is calculated based on the information of the response evaluation viewpoint 708 (step 1201). For example, assuming that the impact on business and the speed of response are selected as evaluation viewpoints, the priority of the response is assigned based on the evaluation values ​​calculated in the incident evaluation (step 805) and response evaluation (step 806) processes. Specifically, for the response with response ID 601 "00001" and response name 604 "stop-1", which is one of the response candidates, referring to the evaluation values ​​calculated in the incident evaluation (step 805) and response evaluation (step 806) processes based on the impact on business and the speed of response, which are the selected evaluation viewpoint items, the degree of impact on business is "18" and the speed of response to the incident is "10". Similarly, when the evaluation values ​​are referenced for one of the candidate actions, action ID 601 "00002" and action name 604 "syukutai-1," the degree of business impact is "14" and the speed of response to the incident is "3." As described in the explanation of the action evaluation process (step 806) (FIG. 11), both action names 604 "stop-1" and "syukutai-1" are below the pre-assigned business impact threshold of "20," which means they are within the acceptable range of business impact. Furthermore, action "stop-1" has a higher evaluation value for the speed of response to the incident, and its effectiveness is also higher than "syukutai-1." Therefore, the priority of the actions is "stop-1," followed by "syukutai-1." Similarly, calculations are performed for the other candidate actions, and a prioritized list of the candidate actions can be displayed, as shown in the action display screen 700 of FIG. 7.

[0058] As described above, according to this embodiment, the degree of impact on business, the degree of speed, the degree of effectiveness, and the required resources can be calculated in an integrated manner based on the system status information and the analysis results of detected events, and the priority of responses can be prioritized and presented to the operator. This makes it possible to minimize the impact on business, achieve a speedy response, and ensure business continuity. It also reduces the time required for the operator to determine how to respond to system abnormalities.

[0059] Furthermore, according to this embodiment, by taking into consideration system status information such as the system's operating status, which changes in real time, it is possible to provide support for countermeasures that provide an opportunity to select countermeasure candidates that have a shorter actual countermeasure execution time and a lower impact on business operations.

[0060] The present invention is not limited to the above-described embodiment, but can be practiced with various modifications and alternatives. For example, in the above embodiment, the functional units 101 to 107 of the response support device 100 are realized by executing a program on a computer as shown in FIG. 2. According to another example, one or more functions of some of the functional units 101 to 107 may be realized by executing a program on one or more computers. Also, it is not necessary to realize all of the above functional units by executing a single program. Each of the above functional units may be realized by a separate program, or several functional units may be realized together as a single program. For example, the incident evaluation unit 103, the response evaluation unit 104, and the priority determination unit 105, which are characteristic of this embodiment, may be realized together as a single program.

[0061] Furthermore, the various functional units of the countermeasure support device of this embodiment may be integrated into the countermeasure execution device, and the two devices may be configured as an integrated unit. In this case, the integrated unit may be called the countermeasure execution device.

[0062] Furthermore, instead of calling the information tables 110 to 113 tables as in this embodiment, they may be called databases (DBs), or simply their information or information structure, or their storage units.

[0063] The object to be monitored is not limited to a monitored system including multiple devices, but may be the sensor itself. [Explanation of symbols]

[0064] 100: Coping support device 101: Receiving unit 102: System status acquisition unit 103: Incident Assessment Department 104: Response Evaluation Department 105:Priority determination section 106: Display section 700: Troubleshooting screen 107: Handling instructions section 110: Device information table 111: Business information table 112: Threat Information Table 113: Response information table 191: Monitored system 192: Monitoring device 193: Response execution device

Claims

1. A response support device that supports responses to be taken in accordance with the status of an incident that has occurred in a monitored system in which multiple devices are operating and performing business operations, an incident evaluation unit that evaluates the impact of an incident on a monitored system and the urgency of dealing with the incident; a response evaluation unit that evaluates the impact of a response to an incident on business operations and the effectiveness of the response to the incident; a priority determination unit that determines the priority of measures based on the evaluation by the incident evaluation unit and the evaluation by the measure evaluation unit; a display unit that displays a screen including the priority of the measures determined by the priority determination unit; an acquisition unit that acquires system status information of the monitored system, the acquisition unit continues to acquire the system status information while the incident assessment unit, the response assessment unit, and the priority determination unit are running, The incident evaluation unit and the response evaluation unit each perform evaluation in consideration of the ongoing operations included in the system status information acquired by the acquisition unit. Coping aids.

2. A storage unit for storing in advance information about each device constituting the monitored system, information about operations performed in the monitored system, threat information about incidents detected by the monitoring device, and information about the content of countermeasures; The incident evaluation unit, the response evaluation unit, and the priority determination unit perform evaluation and determination using the information stored in the storage unit. The countermeasure support device according to claim 1.

3. The storage unit a device information table for managing information about each device constituting the monitored system; a business information table for managing information on business operations executed in a monitored system; a threat information table for managing threat information of incidents detected by the monitoring device; a handling information table for managing the details of handling; The incident evaluation unit, the response evaluation unit, and the priority determination unit perform evaluation and determination by referring to the information tables. The countermeasure support device according to claim 2.

4. The display unit a screen including a response selection field in which an operator can select a response, a response list displaying a list of responses to the incident, a priority indicating the priority of the responses, and an evaluation point of view for selecting whether or not to include the above point of view in an evaluation point of view item to calculate the priority of the responses; The countermeasure support device according to claim 1.

5. the screen has a response instruction button operated by an operator, When an operator selects a measure in the measure selection field and operates the measure instruction button, a measure instruction unit transmits the selected measure to a measure execution device. The countermeasure support device according to claim 4.

6. The screen has an update button that reloads and displays the contents of the action list when the prioritization changes in real time, the display unit automatically displays the screen including the list of actions when an operator operates the update button or at regular intervals. The countermeasure support device according to claim 5.

7. A method for supporting a response executed by a computer in response to an incident that has occurred in a monitored system in which multiple devices are operating and performing business, comprising: an incident evaluation step of evaluating the impact of the incident on the monitored system and the urgency of dealing with the incident; a response evaluation step of evaluating the impact of the response to the incident on business and the effectiveness of the response to the incident; a priority determination step of determining a priority of the response based on the evaluation by the incident evaluation step and the evaluation by the response evaluation step; a display step of displaying a screen including the priority of the measures determined in the priority determination step on a display unit; an acquisition step of acquiring system status information of the monitored system; the acquiring step continues to acquire the system status information during a period in which the incident evaluation step, the response evaluation step, and the priority determination step are being executed, The incident evaluation step and the response evaluation step each perform evaluation in consideration of the ongoing business included in the system status information acquired in the acquisition step. Coping support methods.

8. A method for monitoring a system comprising the steps of: storing in advance in a storage unit information about each device constituting the monitored system, information about operations performed in the monitored system, threat information about incidents detected by the monitoring device, and information about the content of countermeasures; The incident evaluation step, the response evaluation step, and the priority determination step are performed using the information stored in the storage unit. The method for supporting a response according to claim 7.

9. the display unit displays a screen having a countermeasure selection field in which an operator can select a countermeasure, a countermeasure list displaying a list of countermeasures for the incident, a priority indicating the priority of the countermeasures, a viewpoint for prioritizing the countermeasures and an evaluation viewpoint for selecting whether or not to include the viewpoint in an evaluation viewpoint item in calculating the priority of the countermeasures, and a countermeasure instruction button operated by the operator; When an operator selects a measure in the measure selection field and operates the measure instruction button, a measure instruction unit transmits the selected measure to a measure execution device. The method for supporting a response according to claim 7.

10. After a certain period of time has elapsed, the incident evaluation step, the response evaluation step, and the priority determination step are repeatedly executed. The method for supporting a response according to claim 9.

Citation Information

Patent Citations

  • Service management device

    JP2008129973A

  • Operation management apparatus and operation management method for information processing system

    JP2008217285A

  • Trouble coping apparatus, troubleshooting method for information technology system, and program therefor

    JP2009238010A

  • Man-hour estimation program, man-hour estimation method and man-hour estimation device

    JP2017097781A

  • Analyzer, analytical method, and analytical program

    JP2020170362A