Cyber ​​attack response support system, cyber attack response support method, and cyber attack response support program

The cyber attack response support system addresses the challenge of designing effective countermeasures for industrial control systems by simulating attacker and defender behaviors, enabling quicker and more effective response strategies through a system model and profile-based countermeasure design.

JP7808014B2Active Publication Date: 2026-01-28HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2022163555
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-11
Publication Date
2026-01-28
Estimated Expiration
2042-10-11

AI Technical Summary

Technical Problem

Industrial control systems face challenges in designing effective countermeasures against cyber attacks due to the lack of practical training and expertise, especially when high availability is prioritized, leading to delayed decision-making and potential expansion of damage.

Method used

A cyber attack response support system that includes a memory unit storing attacker and defender profiles, and a countermeasure design unit that uses a system model to reproduce the target system, predict attacker and defender behaviors, and design appropriate countermeasures based on these profiles.

Benefits of technology

Enables the design of appropriate countermeasures against cyber attacks by simulating joint exercises between attacker and defender groups, facilitating quicker and more effective response strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007808014000001
    Figure 0007808014000001
  • Figure 0007808014000002
    Figure 0007808014000002
  • Figure 0007808014000003
    Figure 0007808014000003
Patent Text Reader

Abstract

To provide a cyber attack countermeasure support system, method and program for designing an appropriate countermeasure against a cyber attack.SOLUTION: A cyber attack countermeasure support system 1000 designs countermeasures against a cyber attack on a predetermined target system. The cyber attack countermeasure support system comprises: a storage unit 120 that stores one or more attacker profiles 122 including an attack purpose and attack technique of an attacker performing the cyber attack, and one or more defender profiles 123 including a defense purpose and defense technique of a defender performing defense against the cyber attack; and a countermeasure design unit 111 that uses a system model 121 for reproducing a state of the target system and outputting index values of one or more indices indicating a performance of the target system corresponding to the state of the target system to design a countermeasure for each of combinations of the attacker profiles 122 and the defender profiles 123.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a technology for supporting countermeasures against cyber attacks in a system including information devices. [Background technology]

[0002] For example, computer systems in the industrial field (industrial control systems) are composed of highly reliable information devices specialized for specific control processes, including PLCs (Programmable Logic Controllers) and HMIs (Human Machine Interfaces). Industrial control systems play an important role in monitoring and controlling social infrastructure such as electricity, railways, water, and gas, as well as production facilities such as factories and plants. For this reason, it is important for industrial control systems to continue operating stably (availability) even when abnormal situations occur.

[0003] While industrial control systems traditionally operated in isolated environments, recent advances in IoT (Internet of Things) technology have led to an increasing number of systems being connected to external networks, such as the Internet. While connecting to external networks has improved productivity and convenience, it has also significantly increased the risk of cyberattacks. Because the impact on society would be significant if an industrial control system were to cease operation, it is vulnerable to APT (Advanced Persistent Threat) attacks, which specifically target and continuously launch sophisticated attacks. While implementing sufficient security measures to minimize damage is essential, APT attacks often involve zero-day exploits, making it difficult to completely eliminate the risk of an attack. Therefore, in order to reduce security risks, it is important to establish an organizational structure that can quickly implement countermeasures to minimize the impact on systems, even if an attack occurs.

[0004] In general, improving an organization's response capabilities in information systems involves deploying both an attacker group (comprised of experts who mimic attackers and launch attacks) and a defender group (comprised of experts (including the organization's security personnel) who thwart attacks) and conducting practical exercises that combine both groups to improve the defender group's decision-making and response capabilities. It is recommended that the attacker group repeat practical exercises, imitating attacker profiles consisting of multiple attack objectives and methods based on actual APT attack cases. The defender group may also change their defender profile (comprising defensive objectives and methods) depending on the situation and conduct repeated training under different conditions. In the cybersecurity field, the attacker group is called the red team and the defender group is called the blue team. Strengthening organizational capabilities to respond to cyberattacks through joint practical exercises involving both teams is sometimes referred to as purple teaming.

[0005] However, unlike general information systems, industrial control systems place a high priority on availability, so practical training that could affect availability is often not permitted on the actual system. Furthermore, industrial control systems require not only advanced security knowledge but also the development of countermeasures that take into account the special system operations where availability is crucial, resulting in a shortage of experts. For these reasons, defender training is lacking, which can delay decision-making and response implementation in the event of a cyberattack, potentially leading to the expansion of damage.

[0006] For example, Patent Document 1 discloses a technology that, when a cyber attack is detected, presents the most appropriate countermeasure from among multiple predefined countermeasure templates, taking into account the impact of the countermeasure on the system's business. [Prior art documents] [Patent documents]

[0007] [Patent Document 1] JP 2018-137500 A Summary of the Invention [Problem to be solved by the invention]

[0008] By using the technology disclosed in Patent Document 1, when a cyber-attack is detected, it is possible to automate decision-making and support for implementing countermeasures from the perspective of a defender group. However, since the countermeasures are from the perspective of the defender, they are not necessarily appropriate, and it is not possible to present countermeasures that anticipate the actions of the attacker.

[0009] The present invention has been made in consideration of the above circumstances, and its purpose is to provide a technology that enables the design of appropriate countermeasures against cyber attacks. [Means for solving the problem]

[0010] In order to achieve the above-mentioned object, one aspect of the cyber attack response support system is a cyber attack response support system that designs countermeasures against cyber attacks on a specified target system, and includes a memory unit that stores one or more attacker profiles including the attack objectives and attack methods of the attacker who carries out the cyber attack, and one or more defender profiles including the defense objectives and defense methods of the defender who defends against the cyber attack, and a countermeasure design unit that reproduces the state of the target system and designs countermeasures for each combination of the attacker profile and the defender profile using a system model that reproduces the state of the target system and outputs index values ​​of one or more indicators that indicate the performance of the target system corresponding to the state of the target system. [Effects of the Invention]

[0011] According to the present invention, it is possible to design appropriate countermeasures against cyber attacks. [Brief explanation of the drawings]

[0012] [Figure 1] FIG. 1 is a functional block diagram of a cyber-attack response support system according to the first embodiment. [Figure 2] FIG. 2 is a diagram illustrating a system model according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating a time series transition of production volume according to the first embodiment. [Figure 4] FIG. 4 is a diagram showing the configuration of an attacker profile according to the first embodiment. [Figure 5] FIG. 5 is a diagram showing the configuration of a defender profile according to the first embodiment. [Figure 6] FIG. 6 is a flowchart of the countermeasure design process according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing the system configuration of a system model that reflects abnormality detection information according to the first embodiment. [Figure 8] FIG. 8 is a diagram illustrating prediction of the behavior of an attacker with respect to the system model according to the first embodiment. [Figure 9] FIG. 9 is a diagram illustrating the prediction of the defender's behavior with respect to the system model according to the first embodiment. [Figure 10] FIG. 10 is a diagram showing the configuration of a list of countermeasures according to the first embodiment. [Figure 11] FIG. 11 is a configuration diagram of statistical information of countermeasures according to the first embodiment. [Figure 12] FIG. 12 is a diagram showing the structure of information indicating the relationship between the observed behavior of an attacker and a match with an attacker profile according to the first embodiment. [Figure 13] FIG. 13 is a functional block diagram of a cyber-attack response support system according to the second embodiment. [Figure 14] FIG. 14 is a diagram showing the configuration of an output table of countermeasures according to the second embodiment. [Figure 15] FIG. 15 is a functional block diagram of a cyber-attack response support system according to the third embodiment. [Figure 16] FIG. 16 is a diagram illustrating a defender model according to the third embodiment. [Figure 17] FIG. 17 is a flowchart of the defender model generation process according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] The following description of the embodiments will be given with reference to the drawings. Note that the embodiments described below do not limit the scope of the invention as claimed, and not all of the elements and combinations thereof described in the embodiments are necessarily essential to the solution of the invention.

[0014] (First embodiment) FIG. 1 is a functional block diagram of a cyber-attack response support system according to the first embodiment.

[0015] The cyber-attack response support system 1000 includes a cyber-attack response support device 10, an anomaly detection system 11, an input / output device 12, and an industrial control system 13.

[0016] The cyber-attack response support device 10 is configured by a computer including, for example, a processor, a memory, a storage device, and the like, and has a processing unit 110 and a storage unit 120.

[0017] The processing unit 110 is a functional unit realized by the processor executing a program (cyber-attack response support program) loaded in memory. The processing unit 110 includes a countermeasure design unit 111, a countermeasure selection unit 112 as an example of a reception unit and a display unit, and a countermeasure execution unit 113.

[0018] The storage unit 120 is configured with a storage device that stores data. The storage device is, for example, a memory such as a RAM (Random Access Memory), a HDD (Hard Disk Drive), or an SSD (Solid State Drive). The storage unit 120 may be configured with an external storage medium such as an HDD or SSD that is independent of the cyber-attack response support device 10. The storage unit 120 stores a system model 121, one or more attacker profiles 122, and one or more defender profiles 123.

[0019] The anomaly detection system 11 is a system that detects anomalies in the industrial control system 13 (target system), and is composed of a NIDS (Network-based Intrusion Detection System) that detects signs of attack by monitoring network communications in real time, a HIDS (Host-based Intrusion Detection System) that detects signs of attack using software running on a computer, etc. When the anomaly detection system 11 detects an anomaly in the target system, it notifies the countermeasure design unit 111 of the cyber-attack response support device 10 of anomaly detection information including the location of the anomaly, the content of the anomaly, etc.

[0020] The input / output device 12 is a device that allows a user to interactively input and output data to and from the cyber-attack response support device 10, and is composed of a keyboard, a mouse, a display, and the like.

[0021] The industrial control system 13 includes a plurality of information devices 130, robots (not shown) controlled by the information devices 130, etc. The plurality of information devices 130 includes computer devices such as PLCs and HMIs, and network devices such as switches and firewalls that connect and disconnect networks between computer devices.

[0022] Next, the processing unit 110 and the storage unit 120 will be described in detail.

[0023] When the countermeasure design unit 111 receives anomaly detection information of the target system transmitted from the anomaly detection system 11, it starts operation, reads the system model 121, the attacker profile 122, and the defender profile 123 from the storage unit 120, and executes processing to design countermeasures for the industrial control system 13. The countermeasure selection unit 112 displays information about the designed countermeasures (countermeasure information) on the input / output device 12, and accepts designation of the countermeasure to be applied from the user via the input / output device 12. The countermeasure execution unit 113 executes processing to apply the countermeasure accepted by the countermeasure selection unit 112 to the industrial control system 13 and execute it.

[0024] The system model 121 is a model that includes configuration information of information devices in the target system and can reproduce the target system when executed by the processing unit 110. The system model 121 also has a calculation function that quantifies the performance of the target system using one or more indices depending on the state of the information devices. Here, the configuration information includes, for example, information on the hardware, software, vulnerability information, logical configuration, physical configuration of the information devices, and dependency information between information devices for the information devices to operate normally. The configuration information also has attributes that represent the state of the information devices, and it is possible to reflect anomaly detection information detected by the anomaly detection system 11 in the information devices.

[0025] Next, the calculation function of the system model 121 will be described.

[0026] FIG. 2 is a diagram illustrating a system model according to the first embodiment.

[0027] When status information 21 of information device 130 is input, system model 121 (strictly speaking, processing unit 110 using system model 121) outputs performance 23 of the target system quantified by one or more types of indexes. For example, the status information 21 indicates that information device identified as PLC1 is in a normal operating state, information device identified as PLC2 is in a DoS (Denial of Service) state, and information device identified as HMI is in a state where the device's operating mode has been changed. In this case, system model 121 outputs, for example, indexes representing the performance of the target system and their values, such as a production volume of 50%, a confidentiality protection rate of 20%, and a safety risk avoidance rate of 80%. Here, the safety risk avoidance rate indicates the rate at which states that pose a risk in terms of safety are avoided.

[0028] The system model 121 may calculate the percentage of information devices in a normal operating state as the production volume, for example. For example, if 100 information devices are operating in the target system and 50 of the information devices are in a normal operating state, the production volume may be calculated as 50%. In this example, the system model 121 calculates a unique production volume based only on the status information 21 of the information devices at a certain time, regardless of the time-series transition of the status of the information devices. However, the present invention is not limited to this, and the production volume may be calculated taking into account, for example, the history effect related to the time-series transition of the status of the information devices.

[0029] Next, an example of calculating the production volume taking into consideration the time series transition of the status information 21 of the information device will be shown.

[0030] FIG. 3 is a diagram illustrating the time series transition of production volume according to the first embodiment. In FIG. 3, the horizontal axis represents time, and the vertical axis represents production volume. In the example of FIG. 3, all information devices are in a normal operating state from time 0 to t1, half of the information devices are in a normal operating state from time t1 to t2, and all information devices are in a normal operating state from time t2 onwards. In this example, the production volume is 100% until time t1, and then decreases continuously from time t1 to t2, and then recovers continuously from time t2 onwards.

[0031] In addition, the system model 121 may calculate the confidentiality protection rate by, for example, setting a confidentiality protection score for each information device 130 in the industrial control system 13, and calculating the ratio of the total scores of information devices 130 for which confidentiality protection is ensured to the total scores of all information devices 130.

[0032] In addition, the system model 121 may calculate the safety risk avoidance rate, for example, by setting a score for safety risk for each information device 130 in the industrial control system 13, and calculating the ratio of the total scores of information devices 130 for which safety risks have been avoided to the total scores of all information devices 130.

[0033] The calculations performed by the calculation function of the system model 121 are not limited to the above examples, but may be any calculation that can input the status information 21 of the information device and output the performance 23 of the target system quantified using one or more types of indicators, and a different indicator may be used to calculate a certain indicator.

[0034] Next, the attacker profile 122 will be described.

[0035] FIG. 4 is a diagram showing the configuration of an attacker profile according to the first embodiment.

[0036] The attacker profile 122 is information that defines the type of attacker that is assumed. The attacker profile 122 is stored in the storage unit 120. In this embodiment, the storage unit 120 stores multiple (Ni) patterns of attacker profiles 122.

[0037] The attacker profile 122 includes an identifier, an identification name, an attack purpose, and an attack method. The attacker profile 122 may also include identification information of an APT group that has a similar attack purpose and attack method.

[0038] The identifier defines information that can uniquely identify the attacker profile 122. For example, an integer value from 1 to Ni is assigned as the identifier. The identification name defines a name that identifies the attacker profile 122. Note that in this embodiment, the identification name can also uniquely identify the attacker profile 122.

[0039] Attack methods are defined as specific attack methods that attackers can use, such as DoS and changing control parameters.

[0040] The attack objective defines the percentage (target value) of one or more indicators (attack objective indicators) that are important when conducting an attack. This means that the attacker's goal is to maximize the change in this indicator. For example, in attacker profile 122-1, whose identifier is production volume-specialized, the attack objective is defined as "production volume (100%)," which means that the attack objective is aimed only at affecting production volume. This means that the attacker of attacker profile 122-1 does not aim to affect other indicators such as confidentiality protection rate or safety risk avoidance rate.

[0041] In addition, in attacker profile 122-2, whose identification name is balanced, the attack objective is defined as "production volume (30%), confidentiality protection rate (40%), safety risk avoidance rate (30%)," which means that the objective is to affect production volume, confidentiality protection rate, and safety risk avoidance rate in a ratio of 3:4:3.

[0042] Regarding the method of calculating the impact on the target system, taking the impact of production volume as an example, when production volume changes as shown in Figure 3, the cumulative amount represented by the area of ​​the shaded area in the figure can be used as the impact on production volume, or the maximum instantaneous change can be used.

[0043] Hereinafter, the influences of production volume, confidentiality protection rate, and safety risk aversion rate will be represented as X, Y, and Z. In the case of the production volume-specialized attacker profile 122-1, the objective is to maximize 1X, and in the case of the balanced attacker profile 122-2, the objective is to maximize 0.3X + 0.4Y + 0.3Z.

[0044] Next, the defender profile 123 will be described.

[0045] FIG. 5 is a diagram showing the configuration of a defender profile according to the first embodiment.

[0046] The defender profile 123 is information that defines the type of defender that is assumed. The defender profile 123 is stored in the storage unit 120. In this embodiment, the storage unit 120 stores multiple (Nj) patterns of the defender profile 123.

[0047] The defender profile 123 includes an identifier, an identification name, a defense purpose, and a defense technique.

[0048] The identifier defines information that can uniquely identify the defender profile 123. For example, an integer value from 1 to Nj is assigned as the identifier. The identification name defines a name that identifies the defender profile 123. Note that in this embodiment, the identification name can also uniquely identify the defender profile 123.

[0049] The defensive techniques define specific defensive techniques that can be used by the defender, such as changing the operation mode of the device or shutting down the device.

[0050] The defense objective defines the percentage (target value) of one or more indicators (defense objective indicators) that are important when implementing defense. This means that the defender aims to minimize the change in this indicator. For example, in the defender profile 123-1, whose identifier is safety risk avoidance rate specialization, the defense objective is defined as "safety risk avoidance rate (100%)", and therefore the defender of the defender profile 123-1 aims to minimize 1Z.

[0051] In addition, in the defender profile 123-2, whose identification name is confidentiality protection rate emphasis type, the defense objectives are defined as "production volume (10%), confidentiality protection rate (70%), safety risk avoidance rate (20%)", and the objective is to minimize 0.1X + 0.7Y + 0.2Z.

[0052] Here, if the attack objective of the attacker profile 122 and the defense objective of the defender profile 123 are the same, it means that they are trying to achieve completely opposite objectives. Note that the attack objective of the attacker profile 122 and the defense objective of the defender profile 123 do not necessarily have to be the same.

[0053] Next, the processing operation of the cyber-attack response support device 10 will be described.

[0054] FIG. 6 is a flowchart of the countermeasure design process according to the first embodiment.

[0055] The countermeasure design process is executed when the countermeasure design unit 111 of the cyber-attack response support device 10 receives anomaly detection information about the target system (industrial control system 13) from the anomaly detection system 11.

[0056] The countermeasure design unit 111 reads the system model 121 from the storage unit 120, and reflects the state corresponding to the received abnormality detection information in the system model 121 (S61).

[0057] 7 is a diagram showing the system configuration of a system model that reflects anomaly detection information according to the first embodiment. In FIG. 7, the industrial control system 13 includes, as information devices 130, a monitoring terminal, control server 1, control server 2, PLC1, PLC2, and an HMI, all connected via a network, and the anomaly detection information includes information that an abnormal intrusion has been detected in the monitoring terminal.

[0058] In step S61, as shown in FIG. 7, in the system model 121, the attribute representing the state of the monitoring terminal is set to "unauthorized intrusion."

[0059] Returning to the explanation of FIG. 6, the countermeasure design unit 111 defines integer variables i and j and sets the values ​​to 1 (S62).

[0060] Next, the countermeasure design unit 111 reads the attacker profile 122 of the identifier i and the defender profile 123 of the identifier j from the storage unit 120 (S63).

[0061] Next, the countermeasure design unit 111 uses the system model 121 to predict the attacker's behavior based on the loaded attacker profile 122. Note that the attacker's purpose and attack method differ depending on the loaded attacker profile 122, and therefore the attacker's behavior changes.

[0062] FIG. 8 is a diagram illustrating prediction of the behavior of an attacker with respect to the system model according to the first embodiment.

[0063] For example, the attacker's behavior predicted from the production volume-specialized attacker profile 122-1 is that an attacker who has illegally infiltrated a monitoring terminal will then attack control server 1 using the "control parameter change" attack method, and finally attack PLC1 using the "DoS" attack method. The attack method is selected from the attack methods defined in attacker profile 122-1. Furthermore, the attacker's behavior is derived so as to maximize the impact on the target system, represented by 1X, which corresponds to the purpose of the attack.

[0064] Furthermore, the attacker's behavior predicted from the balanced attacker profile 122-2 is, for example, that an attacker who has illegally infiltrated a monitoring terminal will next attack the control server 2 using the attack method "collect control tag information," and finally attack the HMI using the attack method "change alarm settings." This attacker's behavior is derived so as to maximize the impact on the target system, which is expressed as 0.3X + 0.4Y + 0.3Z, which corresponds to the attack purpose.

[0065] Returning to the explanation of FIG. 6, the countermeasure design unit 111 uses the system model 121 to derive optimal countermeasures based on the attacker's behavior and the defender profile 123 (S63).

[0066] FIG. 9 is a diagram illustrating the prediction of the defender's behavior with respect to the system model according to the first embodiment.

[0067] For example, the defender's behavior predicted from the safety risk aversion rate specialized defender profile 123-1 is derived as the optimal countermeasure to defend against PLC1 using the defense method "stop equipment." The defense method is selected from the defense methods of the defender profile 123-1. In addition, this defender's behavior is derived so as to minimize the impact on the target system represented by 1Z corresponding to the defense objective.

[0068] Furthermore, the defender's behavior predicted from the confidentiality protection rate-focused defender profile 123-2 is derived as the optimal countermeasure, for example, to defend against the control server 1 using the defensive technique of "changing access control settings." This defender's behavior is derived so as to minimize the impact on the target system, which is expressed as 0.1X + 0.7Y + 0.2Z, corresponding to the defensive objective.

[0069] 6, the countermeasure design unit 111 compares the variable i with Ni and determines whether the variable i is less than Ni (S66). As a result, if the variable i is less than Ni (S66: Y), this means that countermeasures have not been derived for one defender profile 123 with all attacker profiles 122 as targets, so the countermeasure design unit 111 adds 1 to the variable i (S67) and proceeds to step S63.

[0070] On the other hand, if the variable i is not less than Ni (S66:N), this means that countermeasures have been derived for all attacker profiles 122 for one defender profile 123, so the countermeasure design unit 111 proceeds to step S68.

[0071] In step S68, the countermeasure design unit 111 compares the variable j with Nj and determines whether the variable j is less than Nj. As a result, if the variable j is less than Nj (S68: Y), this means that countermeasures have not been derived for all the attacker profiles 122 for all the defender profiles 123, so the countermeasure design unit 111 sets the variable i to 1, adds 1 to the variable j (S69), and proceeds to step S63.

[0072] On the other hand, if the variable j is not less than Nj (S68:N), it means that countermeasures have been derived for all attacker profiles 122 for all defender profiles 123, that is, countermeasures of the Ni×Nj pattern have been derived, so the countermeasure design unit 111 outputs the derived countermeasures of the Ni×Nj pattern to the countermeasure selection unit 112 and terminates the processing.

[0073] According to this countermeasure design process, a joint practical exercise between an attacker group and a defender group, which is difficult to carry out in an actual industrial control system 13, can be virtually carried out using the system model 121 in an Ni×Nj pattern, and countermeasures for each group can be derived.

[0074] Next, the processing operation of the countermeasure selection unit 112 will be described.

[0075] The countermeasure selection unit 112 displays on the input / output device 12 a list 100 (see FIG. 10) of countermeasures for the Ni×Nj pattern designed and output by the countermeasure design unit 111, and receives from the user a selection of a countermeasure to be actually applied to the industrial control system 13. The user can compare the countermeasures by referring to the list displayed on the input / output device 12 connected to the countermeasure selection unit 112, and select the optimum countermeasure.

[0076] FIG. 10 is a diagram showing the configuration of a list of countermeasures according to the first embodiment.

[0077] The list 100 is a table that displays countermeasures for Ni×Nj patterns and includes entries corresponding to the countermeasures for each Ni×Nj pattern. Each entry in the list 100 includes fields for countermeasure 101, defender profile 102, attacker profile 103, and performance 104.

[0078] Countermeasures corresponding to the entries are displayed in countermeasures 101. In countermeasures 101, the content of the countermeasure is written before the symbol @, and the identification name of the information device 130 to which the countermeasure is to be applied is written after the symbol @.

[0079] The defender profile 102 displays information (e.g., an identification name) that can identify the defender profile 123 from which the countermeasure corresponding to the entry has been derived. In this embodiment, when the defender profile 123 is pressed (clicked), details of the defender profile 123 are displayed as shown in FIG. 5.

[0080] The attacker profile 103 displays information (e.g., an identification name) that can identify the attacker profile 122 from which the countermeasure corresponding to the entry has been derived. In this embodiment, when the attacker profile 122 is pressed (clicked), details of the attacker profile 122 are displayed as shown in FIG.

[0081] The performance 104 displays index values ​​for one or more indexes that indicate performance. The performance 104 includes fields such as production volume 104A, security protection rate 104B, and safety risk avoidance rate 104C.

[0082] The production volume 104A displays the production volume when the countermeasure corresponding to the entry is implemented. The security protection rate 104B displays the security protection rate when the countermeasure corresponding to the entry is implemented. The safety risk avoidance rate 104C displays the security risk avoidance rate when the countermeasure corresponding to the entry is implemented.

[0083] The user can select countermeasures to actually apply to the industrial control system 13 from the list 100 via the input / output device 12, taking into consideration the type of attacker expected, management priority, impact on the target system, etc.

[0084] In addition, the correspondence between countermeasures and the cost and speed required to apply the countermeasures may be stored in the memory unit 120, and the countermeasure selection unit 112 may display the cost and speed required to apply the countermeasures in correspondence with the countermeasures in the list 100.

[0085] Furthermore, since there is a possibility that the countermeasures in the list 100 may include overlapping countermeasures, in this embodiment, the countermeasure selection unit 112 displays statistical information regarding the derived countermeasures.

[0086] FIG. 11 is a configuration diagram of statistical information of countermeasures according to the first embodiment.

[0087] The statistical information is, for example, information about the overlap rate of each countermeasure among all countermeasures. In Fig. 11, the overlap rate of each countermeasure is expressed in a pie chart. This statistical information makes it easy to understand countermeasures with a high overlap rate, i.e., countermeasures that are considered to be recommended.

[0088] When the user completes the selection of a countermeasure by the countermeasure selection unit 112, the countermeasure execution unit 113 performs control to apply the countermeasure selected by the user to the information device 130. Specifically, the countermeasure execution unit 113 transmits a communication command to the information device 130 to cause the information device 130 to execute the countermeasure.

[0089] After a countermeasure is selected, the countermeasure selection unit 112 may continuously observe the anomaly detection information received from the anomaly detection system 11 and display information on the degree of match between the actually observed behavior of the attacker and the attacker profile.

[0090] FIG. 12 is a diagram showing the structure of information indicating the relationship between the observed behavior of an attacker and a match with an attacker profile according to the first embodiment.

[0091] Figure 12 shows statistical information in the form of a bar graph showing the degree of agreement between the actual attacker behavior (e.g., attack route, method, etc.) and the behavior estimated by each attacker profile. This statistical information makes it possible to understand which attacker profile is most effective for estimating each behavior.

[0092] (Second embodiment) Next, a cyber-attack response support system according to a second embodiment will be described.

[0093] 13 is a functional block diagram of a cyber-attack response support system according to the second embodiment. In the cyber-attack response support system 1100 according to the second embodiment, the same components as those in the cyber-attack response support system 1000 according to the first embodiment will be denoted by the same reference numerals.

[0094] The cyber-attack response support system 1100 is newly provided with an impact re-evaluation unit 114 in the processing unit 110 .

[0095] The impact re-evaluation unit 114 starts operation based on a request from the countermeasure selection unit 112, reads the system model 121 and the attacker profile 122 and defender profile 123 corresponding to the selected countermeasure from the memory unit 120, and performs a process of evaluating the performance of the industrial control system 13.

[0096] The countermeasure selection unit 112 can accept multiple countermeasures from the user. When multiple countermeasures are accepted, the countermeasure selection unit 112 requests the impact re-evaluation unit 114 to instruct it to evaluate the impact on the target system when the multiple countermeasures are executed simultaneously, and displays the evaluation results from the impact re-evaluation unit 114 as an output table 1400 (see FIG. 14).

[0097] Next, the processing operation of the cyber-attack response support system 1100 will be described.

[0098] The processing operations up to outputting the list 100 of countermeasures for Ni×Nj patterns in the cyber-attack response support system 1100 are the same as those in the cyber-attack response support system 1000 of the first embodiment.

[0099] If multiple countermeasures are selected for the list 100, the countermeasure selection unit 112 requests the impact re-evaluation unit 114 to evaluate the impact on the target system if the selected multiple countermeasures are executed simultaneously.

[0100] When the impact re-evaluation unit 114 receives a request from the countermeasure selection unit 112, it reads the system model 121 and the attacker profile 122 and defender profile 123 corresponding to the selected multiple countermeasures from the storage unit 120, and updates the state of the information device 130 in the system model 121 to a state corresponding to the selected multiple countermeasures. Next, the impact re-evaluation unit 114 uses the calculation function of the system model 121 to quantify the performance of the target system using one or more indicators, and returns the result to the countermeasure selection unit 112.

[0101] The countermeasure selection unit 112 creates an output table 1400 based on the results from the impact re-evaluation unit 114, and displays the output table 1400 on the input / output device 12. The user can refer to this output table 1400 to determine whether or not it is okay to apply multiple countermeasures simultaneously.

[0102] FIG. 14 is a diagram showing the configuration of an output table of countermeasures according to the second embodiment.

[0103] The output table 1400 displays information about the impact of simultaneously executing multiple selected countermeasures. The output table 1400 includes fields for countermeasure 1401, defender profile 1402, attacker profile 1403, and performance 1404.

[0104] A plurality of selected countermeasures are displayed in countermeasure 1401. In the example of Fig. 14, the countermeasures are "Stop device @PLC1" and "Change device operation mode @HMI".

[0105] The defender profile 1402 displays information (for example, an identification name) that can identify the defender profile 123 from which each countermeasure was derived.

[0106] The attacker profile 1403 displays information (for example, an identification name) that can identify the attacker profile 122 from which each countermeasure has been derived.

[0107] Performance 1404 displays index values ​​for one or more indexes that indicate the performance of the target system when multiple countermeasures are implemented simultaneously. Performance 1404 includes fields such as production volume 1404A, security protection rate 1404B, and safety risk avoidance rate 1404C.

[0108] Production volume 1404A displays the production volume when multiple countermeasures are implemented. Confidentiality protection rate 1404B displays the confidentiality protection rate when multiple countermeasures are implemented. Safety risk avoidance rate 1404C displays the safety risk avoidance rate when multiple countermeasures are implemented.

[0109] The user can determine whether to execute multiple countermeasures simultaneously by referring to the output table 1400. When the countermeasure selection unit 112 receives an instruction from the user to execute multiple countermeasures, it notifies the countermeasure execution unit 113 to that effect, and the countermeasure execution unit 113 controls the application of the notified multiple countermeasures to the information device 130.

[0110] (Third embodiment) Next, a cyber-attack response support system according to a third embodiment will be described.

[0111] 15 is a functional block diagram of a cyber-attack response support system according to the third embodiment. In the cyber-attack response support system 1200 according to the third embodiment, the same components as those in the cyber-attack response support system 1000 according to the first embodiment will be denoted by the same reference numerals.

[0112] The cyber-attack response support system 1200 is a system that, compared to the cyber-attack response support system 1000, newly includes a defender model generation unit 115 in the processing unit 110, changes some of the processing operations of the countermeasure design unit 116, and stores a new defender model 124 in the memory unit 120.

[0113] In the cyber-attack response support system 1000 according to the first embodiment, when the anomaly detection system 11 detects an anomaly, it predicts the attacker's behavior based on the attacker profile, and then derives the defender's behavior, including the optimal countermeasure, based on the defender profile. However, in the cyber-attack response support system 1200 according to the third embodiment, when the anomaly detection system 11 detects an anomaly in the target system, it derives the optimal countermeasure without taking the step of predicting the attacker's behavior.

[0114] The defender model generation unit 115 reads the system model 121, the attacker profile 122, and the defender profile 123, and generates a defender model 124 that can input a system model that reflects the anomaly detection information of the anomaly detection system 11 and output a countermeasure. The process of generating the defender model 124 by the defender model generation unit 115 (defender model generation process: see FIG. 17 ) is executed at a stage before the anomaly detection system 11 detects an anomaly. One possible method of generating the defender model 124 is to utilize multi-agent reinforcement learning. When utilizing multi-agent reinforcement learning, the defender model generation unit 115 learns the defender model 124, and the countermeasure design unit 111 executes the defender model.

[0115] FIG. 16 is a diagram illustrating a defender model according to the third embodiment.

[0116] The defender model 124 has a calculation function that takes as input a system model 1601 that reflects the anomaly detection information of the anomaly detection system 11, for example, a system model 1601 that is represented by the state of the information devices 130 that make up the target system, and outputs an optimal countermeasure 1603 for the state of the information devices that make up the target system.

[0117] Next, a defender model generation process for generating a defender model will be described.

[0118] Fig. 17 is a flowchart of the defender model generation process according to the third embodiment. Fig. 17 shows the defender model generation process for generating a defender model using multi-agent reinforcement learning.

[0119] The defender model generation unit 115 sets variables i and j to 1 (S1701). Next, the defender model generation unit 115 reads the system model 121, the attacker profile 122 of the identifier i, and the defender profile 123 of the identifier j from the storage unit 120 (S1702).

[0120] Next, the defender model generation unit 115 learns optimal behavior by operating an agent simulating an attacker (attacker agent) and an agent simulating a defender (defender agent) in the system model 121 as an environment (S1703).

[0121] Here, the actions that the attacker agent can perform are defined by the attack techniques in the attacker profile 122, and the reward that the attacker agent receives is determined by the attack objective in the attacker profile 122. For example, the reward that the attacker agent receives is determined according to the amount of change in the indicator defined in the attack objective. For example, an attacker agent generated based on the attacker profile 122-2, whose identification name is balanced in FIG. 4, may receive a reward that increases with an increase in 0.3X + 0.4Y + 0.3Z.

[0122] Furthermore, the actions that a defender agent can perform are defined by the defense techniques of the defender profile 123, and the reward that the defender agent receives is determined by the defense objective of the defender profile 123. For example, the reward that the defender agent receives is determined according to the amount of change in the indicator defined in the defense objective. For example, a defender agent generated based on the defender profile 123-2, whose identifier name is confidentiality protection rate-oriented in Fig. 5, may receive a reward that increases as 0.1X + 0.7Y + 0.2Z decreases.

[0123] Next, the defender model generation unit 115 stores the defender agent that has completed the multi-agent reinforcement learning and can output optimal behavior depending on the state of the information device in the system model 121 in the storage unit 120 as the defender model 124 (S1704).

[0124] Next, the defender model generation unit 115 compares the variable i with Ni and determines whether the variable i is greater than Ni (S1705). As a result, if the variable i is not greater than Ni (S1705: N), this means that a defender model has not been created by performing multi-agent reinforcement learning on all attacker profiles 122 for one defender profile 123, so the defender model generation unit 115 adds 1 to the variable i (S1706) and proceeds to step S1702.

[0125] On the other hand, if the variable i is greater than Ni (S1705: Y), this means that a defender model has been created by performing multi-agent reinforcement learning on all attacker profiles 122 for one defender profile 123, and the defender model generation unit 115 proceeds to step S1707.

[0126] In step S1707, the defender model generation unit 115 compares the variable j with Nj and determines whether the variable j is greater than Nj. If the result shows that the variable j is not greater than Nj (S1707: N), this means that a defender model has not been created by performing multi-agent reinforcement learning on all the attacker profiles 122 for all the defender profiles 123, so the defender model generation unit 115 sets the variable i to 1 and adds 1 to the variable j (S1708), and proceeds to step S1702.

[0127] On the other hand, if the variable j is greater than Nj (S1707: Y), this means that a defender model has been created by performing multi-agent reinforcement learning on all attacker profiles 122 for all defender profiles 123, i.e., a defender model 124 of the Ni×Nj pattern has been derived, so the defender model generation unit 115 stores the derived defender model 124 of the Ni×Nj pattern in the memory unit 120 and terminates the processing.

[0128] Next, the countermeasure design process performed by the cyber-attack response support system 1200 will be described.

[0129] The countermeasure design process is executed by activating the countermeasure design unit 116 when the cyber-attack response support device 10 receives anomaly detection information about the target system (industrial control system 13) from the anomaly detection system 11.

[0130] The countermeasure design unit 116 reads the system model 121 and the defender model 124 from the storage unit 120, reflects the state corresponding to the received anomaly detection information in the system model 121, inputs the state of the information devices in the system model 121 reflecting the anomaly detection information into each of the defender models 124 of the Ni×Nj pattern, calculates countermeasures for the Ni×Nj pattern using each defender model 124, and outputs the calculated countermeasures for the Ni×Nj pattern to the countermeasure selection unit 112. This countermeasure design process allows a joint practical training between an attacker group and a defender group, which is difficult to implement in an actual industrial control system 13, to be virtually conducted using the system model 121 in the Ni×Nj pattern, and derives respective countermeasures. Note that the subsequent processing by the countermeasure selection unit 112 and the countermeasure execution unit 113 is similar to that of the cyber-attack response support system 1000 according to the first embodiment.

[0131] According to the cyber-attack response support system 1200 of this embodiment, after the anomaly detection system 11 detects an anomaly, there is no need to take the step of predicting the attacker's behavior, and countermeasures can be derived using the Ni×Nj pattern defender model 124 that has been generated in advance for each combination of the attacker profile and the defender profile. Therefore, when a cyber-attack occurs, countermeasures can be quickly presented to the user.

[0132] The present invention is not limited to the above-described embodiment, and can be appropriately modified and implemented without departing from the spirit of the present invention.

[0133] For example, in the above embodiment, an example is shown in which the industrial control system 13 is the target, but the present invention is not limited to this and can be applied to general information systems.

[0134] In addition, in the above embodiment, an example is shown in which the anomaly detection system 11 is installed outside the industrial control system 13, but the present invention is not limited to this, and the anomaly detection system 11 may also be installed within the industrial control system 13.

[0135] In addition, in the above-described embodiments, some or all of the processing performed by the processor may be performed by a hardware circuit. Also, the programs in the above-described embodiments may be installed from a program source. The program source may be a program distribution server or a recording medium (e.g., a portable recording medium). [Explanation of symbols]

[0136] 10...Cyber ​​attack response support device, 11...Abnormality detection system, 12...Input / output device, 13...Industrial control system, 110...Processing unit, 111, 116...Countermeasure design unit, 112...Countermeasure selection unit, 113...Countermeasure execution unit, 114...Impact re-evaluation unit, 115...Defender model generation unit, 120...Memory unit, 121...System model, 122...Attacker profile, 123...Defender profile, 124...Defender model, 1000, 1100, 1200...Cyber ​​attack response support system

Claims

1. A cyber attack response support system that designs countermeasures against cyber attacks on a predetermined target system, a storage unit that stores one or more attacker profiles including attack objectives and attack methods of attackers who carry out cyber attacks, and one or more defender profiles including defense objectives and defense methods of defenders who defend against cyber attacks; a countermeasure design unit that designs countermeasures for each combination of the attacker profile and the defender profile using a system model that reproduces the state of the target system and outputs index values ​​of one or more indexes that indicate the performance of the target system corresponding to the state of the target system; A cyber attack response support system equipped with

2. When the countermeasure design unit receives detection information of a cyber attack against the target system, the countermeasure design unit reflects the detection information in the system model and designs the countermeasure. The cyber-attack response support system according to claim 1.

3. The attack purpose of the attacker profile includes an attack purpose index and its target value, which are one or more indexes among the index values ​​output by the system model, The countermeasure design unit predicts the attacker's behavior that will maximize the impact on the attack purpose indicator, and determines the countermeasure for the predicted behavior using the system model. The cyber-attack response support system according to claim 1.

4. The defense objective of the defender profile includes a defense objective index and its target value, which are one or more indicators among the indicator values ​​output by the system model, The countermeasure design unit predicts the defender's behavior that minimizes the impact on the defense objective index, and determines the countermeasure for the predicted behavior using the system model. The cyber-attack response support system according to claim 1.

5. a display unit that displays countermeasure information that is information about the designed countermeasure, The countermeasure information is The countermeasure information includes the content of the countermeasure, the corresponding attacker profile and the corresponding defender profile, and information about the performance of the target system when the countermeasure is executed. The cyber-attack response support system according to claim 1.

6. a reception unit that receives a selection of a countermeasure to be applied to the target system from the countermeasure information; a countermeasure execution unit that applies the received countermeasure to the target system; Equipped with The cyber-attack response support system according to claim 5.

7. The display unit Display statistics about the above measures The cyber-attack response support system according to claim 5.

8. The system model is configured based on the hardware, software, vulnerability information, logical configuration, physical configuration of the information devices that make up the target system, and dependency information between the information devices for normal operation of the information devices. The cyber-attack response support system according to claim 1.

9. The display unit Based on the detected information of the cyber attack on the target system, statistical information regarding the match between the actual attacker behavior and the attacker profile is displayed. The cyber-attack response support system according to claim 5.

10. The reception unit Accepting a selection of a plurality of countermeasures to be applied to the target system from among the countermeasures designed by Fukusu; The system further includes an impact re-evaluation unit that calculates information about the performance of the target system when the received countermeasures are executed. The cyber-attack response support system according to claim 6.

11. a defender model that receives detection information of a cyber-attack against the target system as an input and outputs a countermeasure for each combination of the attacker profile and the defender profile; The countermeasure design unit designs the countermeasures based on the defender model. The cyber-attack response support system according to claim 1.

12. a defender model generation unit that generates the defender model that outputs the countermeasure for each combination by learning optimal actions of attacker agents that act based on the respective attacker profiles and defender agents that act based on the respective defender profiles; The cyber-attack response support system according to claim 11.

13. A cyber-attack response support method by a cyber-attack response support system that designs countermeasures against cyber-attacks on a predetermined target system, storing one or more attacker profiles including the attack objectives and attack techniques of attackers who carry out cyber attacks, and one or more defender profiles including the defense objectives and defense techniques of defenders who defend against cyber attacks; A system model is used to reproduce the state of the target system and output index values ​​of one or more indexes that indicate the performance of the target system corresponding to the state of the target system, and a countermeasure is designed for each combination of the attacker profile and the defender profile. Support methods for dealing with cyber attacks.

14. A cyber-attack response support program that is executed by a computer to design countermeasures against cyber-attacks on a predetermined target system, The computer a storage unit that stores one or more attacker profiles including attack objectives and attack methods of attackers who carry out cyber attacks, and one or more defender profiles including defense objectives and defense methods of defenders who defend against cyber attacks; A system model that reproduces the state of the target system and outputs index values ​​of one or more indexes that indicate the performance of the target system corresponding to the state of the target system is used to function as a countermeasure design unit that designs countermeasures for each combination of the attacker profile and the defender profile. Cyber ​​attack response support program.

Citation Information

Patent Citations

  • System for support of creating security countermeasure standard, program, and security countermeasure standard creation support method

    JP2011192105A

  • Information processing device and program

    JP2015130152A

  • Security management plan design device, security management plan evaluation device, security management plan design method and security management plan evaluation method

    JP2018137500A

  • System and Method for Responding to a Cyber-Attack-Related Incident Against an Industrial Control System

    US20180096153A1