Information processing device, information processing method, and program

The information processing device tailors cybersecurity exercises to individual participant schedules by generating and executing cyber-attack scenarios within specified time frames, improving engagement and skill development.

JP7810250B2Active Publication Date: 2026-02-03NEC CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024504090
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-03-02
Publication Date
2026-02-03
Estimated Expiration
2042-03-02

AI Technical Summary

Technical Problem

Conventional cybersecurity exercises lack flexibility in accommodating individual participant schedules and preferences, leading to low participation and ineffective skill development.

Method used

An information processing device and method that allows participants to specify exercise duration and type, generating tailored cyber-attack scenarios within the specified time frame, and executing a series of attack actions accordingly.

Benefits of technology

Enables personalized cybersecurity exercises that enhance participant engagement and skill improvement by aligning training with individual participant availability and preferences.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007810250000001
    Figure 0007810250000001
  • Figure 0007810250000002
    Figure 0007810250000002
  • Figure 0007810250000003
    Figure 0007810250000003
Patent Text Reader

Abstract

This information processing device 10 comprises: an exercise condition acquisition unit 11 that acquires, as an exercise condition, an exercise execution time indicated by a participant in a cybersecurity exercise; and an attack operation generation unit 12 that generates cyberattack scenarios to be used in the cybersecurity exercise and extracts a portion of the generated scenarios that fits within the indicated execution time, thereby creating a string of attack operations to be carried out in the cybersecurity exercise.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device and an information processing method for supporting training against cyber attacks, and further relates to a program for realizing these. Mu Regarding. [Background technology]

[0002] In recent years, cyberattacks targeting organizations have caused an increase in damage, such as information leaks and business interruptions, necessitating stronger countermeasures against cyberattacks. To strengthen countermeasures against cyberattacks, it is essential to improve the investigative skills of system security personnel. For this reason, cybersecurity exercises (or cyber exercises) are being conducted in which participants are tasked with finding logs that serve as traces of incidents (hereinafter referred to as "attack logs").

[0003] In cybersecurity exercises, it is important to prepare logs, including attack logs, for various cyberattacks as exercise materials. However, it is difficult for a specific organization to collect a large number of logs for various cyberattacks, and it is difficult for multiple organizations to share logs. For this reason, Patent Document 1 discloses a device that generates attack scenarios for virtual cyberattacks. The device disclosed in Patent Document 1 generates attack scenarios by appropriately arranging program components using information indicating the relationships between the program components.

[0004] Furthermore, by using the device disclosed in Patent Document 1, during a cybersecurity exercise, attack logs can be collected from the exercise computer system by executing virtual cyber attacks in accordance with the generated attack scenario on the exercise computer system. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent Publication No. 2021-120780 Summary of the Invention [Problem to be solved by the invention]

[0006] To maximize the effectiveness of cybersecurity exercises, many people need to participate in them multiple times. However, traditional cybersecurity exercises do not take into consideration the convenience of each individual participant, and the duration of the exercise is the same regardless of who participates.

[0007] For this reason, conventional cybersecurity exercises have the problem that it is difficult to get many people to take part in the cybersecurity exercises. Furthermore, even the device disclosed in Patent Document 1 does not have a means for adjusting the time of the cybersecurity exercises to suit the convenience of the participants, making it difficult to solve the above problem.

[0008] An example of the object of the present disclosure is to provide an information processing device, an information processing method, and program The purpose is to provide [Means for solving the problem]

[0009] In order to achieve the above object, an information processing device according to one aspect of the present disclosure includes: an exercise condition acquisition unit that acquires an exercise duration designated by a participant of a cybersecurity exercise as an exercise condition; an attack action generation unit that generates a cyber-attack scenario to be used in the cybersecurity exercise and extracts a portion of the generated scenario that fits within the specified implementation time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; It is equipped with:

[0010] In order to achieve the above object, an information processing method according to one aspect of the present disclosure includes: an exercise condition acquisition step of acquiring an exercise duration designated by a participant of the cybersecurity exercise as an exercise condition; an attack action generation step of generating a cyber-attack scenario to be used in the cybersecurity exercise and extracting a part of the generated scenario that fits within the specified execution time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; It has.

[0011] Furthermore, in order to achieve the above object, in one aspect of the present disclosure, program teeth, On the computer, an exercise condition acquisition step of acquiring an exercise duration designated by a participant of the cybersecurity exercise as an exercise condition; an attack action generation step of generating a cyber-attack scenario to be used in the cybersecurity exercise and extracting a part of the generated scenario that fits within the specified execution time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; Run It is characterized by is doing. [Effects of the Invention]

[0012] As described above, according to the present disclosure, it is possible to provide cybersecurity exercises tailored to the needs of individual participants. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing a schematic configuration of an information processing device according to the first embodiment. [Figure 2] FIG. 2 is a diagram specifically illustrating the configuration of the information processing device according to the first embodiment. [Figure 3] FIG. 3 is a diagram showing an example of attack type information used in the first embodiment. [Figure 4] FIG. 4 is a diagram showing an example of software information used in the first embodiment. [Figure 5]FIG. 5 is a diagram for explaining the processing executed by the attack scenario generation unit in the first embodiment, and FIG. 5(a) and FIG. 5(b) show the progress of a series of processing. [Figure 6] FIG. 6 is a diagram illustrating an example of an attack scenario generated in the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of extraction conditions used in the first embodiment. [Figure 8] FIG. 8 is a flowchart showing the operation of the information processing device according to the first embodiment. [Figure 9] FIG. 9 is a diagram showing an example of a screen for specifying exercise conditions. [Figure 10] FIG. 10 is a diagram illustrating an example of a log output by a computer system. [Figure 11] FIG. 11 is a diagram showing another example of a log output by a computer system. [Figure 12] FIG. 12 is a configuration diagram showing the configuration of an information processing device according to the second embodiment. [Figure 13] FIG. 13 is a diagram illustrating an example of non-aggressive action information used in the second embodiment. [Figure 14] FIG. 14 is a flowchart showing the operation of the information processing device according to the second embodiment. [Figure 15] FIG. 15 is a block diagram showing an example of a computer that realizes the information processing device according to the first and second embodiments. DETAILED DESCRIPTION OF THE INVENTION

[0014] (Embodiment 1) An information processing device, an information processing method, and a program according to the first embodiment will be described below with reference to FIGS.

[0015] [Device configuration] First, a schematic configuration of the information processing device according to the first embodiment will be described with reference to Fig. 1. Fig. 1 is a diagram showing a schematic configuration of the information processing device according to the first embodiment.

[0016] 1, an information processing device 10 according to a first embodiment is a device for supporting training against cyber attacks, for example, cybersecurity training. As shown in FIG. 1, the information processing device 10 includes a training condition acquisition unit 11 and an attack action generation unit 12.

[0017] The exercise condition acquisition unit 11 acquires the duration of the exercise specified by the participant of the cybersecurity exercise as an exercise condition. The attack action generation unit 12 generates a cyberattack scenario by a virtual attacker to be used in the cybersecurity exercise. The attack action generation unit 12 then creates a series of attack actions to be executed in the cybersecurity exercise by extracting parts of the generated scenario that fit within the specified duration.

[0018] In this way, in the first embodiment, the information processing device 10 creates a series of attack actions to be executed in a cybersecurity exercise according to the duration of the exercise specified by the participant of the cybersecurity exercise. Therefore, the information processing device 10 can provide a cybersecurity exercise tailored to the wishes of each participant.

[0019] Next, the configuration and functions of the information processing device 10 according to the first embodiment will be specifically described with reference to Figures 2 to 9. Figure 2 is a configuration diagram specifically showing the configuration of the information processing device according to the first embodiment.

[0020] 2, in the first embodiment, the information processing device 10 is connected to a trainee's terminal device 30 and a computer system 40 for executing a cybersecurity exercise via a network so as to be able to communicate data with each other. Also, as shown in FIG. 2, the information processing device 10 includes an attack action execution unit 13 and a memory unit 14 in addition to the exercise condition acquisition unit 11 and attack action generation unit 12 described above.

[0021] In the first embodiment, the student specifies the duration of the exercise on the terminal device 30. Specifically, the student can specify the start date and time of the exercise and the end date and time of the exercise. The exercise condition acquisition unit 11 calculates the duration of the exercise from the start date and time of the exercise and the end date and time of the exercise, and acquires the start date and time of the exercise and the duration of the exercise as the exercise conditions. The student can also specify the start date and time of the exercise and the duration of the exercise. In this case as well, the exercise condition acquisition unit 11 acquires the start date and time of the exercise and the duration of the exercise as the exercise conditions.

[0022] Furthermore, in the first embodiment, the student can also specify the type of cyber-attack (hereinafter referred to as "attack type") in addition to the duration of the exercise. Specifically, the student specifies the type of cyber-attack by inputting, for example, a past case, an attack group (or attack tool), or the purpose of the attack, as shown below. In this case, the exercise condition acquisition unit 11 acquires the type of cyber-attack as an exercise condition from the terminal device 30 in addition to the specified duration.

[0023] Past cases: Case A, Case B, etc. Attack groups (or attack tools): APT29, REvil, Emotet, Cobalt Strike, etc. · Purpose of the attack: Obtaining personal information, obtaining trade secrets, obtaining ransom, coin mining, denial of service, information theft, data encryption, resource hijacking, service denial, etc.

[0024] In the first embodiment, the attack action generation unit 12 creates a series of attack actions to be executed in a cybersecurity exercise using attack type information 141, software information 142, attack action condition information 143, scenario information 144, and environment information 145 stored in the memory unit 14. As shown in FIG. 2 , the attack action generation unit 12 includes an attack scenario generation unit 121, a partial scenario extraction unit 122, a partial scenario verification unit 123, and an execution sequence generation unit 124.

[0025] The attack scenario generation unit 121 generates a scenario of a cyber attack by a virtual attacker (hereinafter referred to as an "attack scenario") according to the attack type specified by the student. The attack scenario is information that specifies the target of attack, tactics, and attack method for each stage (step) of the attack. In the first embodiment, the attack scenario generation unit 121 generates an attack scenario by comparing the attack type acquired as the training condition with the attack type information 141.

[0026] The operation of the attack scenario generation unit 121 will be specifically described with reference to Figs. 3 to 6. Fig. 3 is a diagram showing an example of attack type information used in the first embodiment. Fig. 4 is a diagram showing an example of software information used in the first embodiment. Fig. 5 is a diagram explaining the processing executed by the attack scenario generation unit in the first embodiment, and Figs. 5(a) and 5(b) show the progress of a series of processing. Fig. 6 is a diagram showing an example of an attack scenario generated in the first embodiment.

[0027] 3, the attack type information 141 is information that indicates the relationship between attack types, tactics, and attack techniques. The attack type information 141 is composed of attack types and their corresponding "type types," "relevant main tactics (Tactic(s))," and "attack techniques (Technique(s))."

[0028] In Figure 3, for example, "Exfiltration" indicates a tactic of taking discovered important information to the outside. "Collection" indicates a tactic of collecting data related to the attack target. "Impact" indicates a tactic of manipulating, shutting down, or destroying systems and data.

[0029] In Figure 3, the "attack techniques used" are expressed in accordance with the vocabulary used in the MITRE ATT&CK ID (see https: / / atack.mitre.org). In other words, numbers such as "T1041" and "T1566.001" are identification numbers that identify the techniques used in the attacks, and are specified in the MITRE ATT&CK ID. The "attack techniques used" column lists all the techniques used in the attacks.

[0030] As shown in Fig. 4, software information 142 is information that indicates the relationship between the techniques used in attacks and software. The software information 142 is composed of "compatible techniques," "software name," "compatible environments," "execution type," "required time," "input format," and "output format." The numbers attached to the "compatible techniques" are the corresponding MITRE ATT&CK IDs.

[0031] The attack scenario generation unit 121 first identifies the attack type specified by the student from the practice conditions acquired by the practice condition acquisition unit 11. Next, the attack scenario generation unit 121 compares the identified attack type with the attack type information 141 (see FIG. 3) to identify the corresponding "type type," "related main tactics," and "attack techniques used." Then, the attack scenario generation unit 121 uses the software information 142 to identify software corresponding to each technique included in the "attack techniques used."

[0032] The attack scenario generation unit 121 then completes the attack scenario using the identified tactics, techniques, and software, as shown in Figure 5. In Figure 5, "TA1, TA2, TA3, ..." indicate tactics included in the identified "related main tactics." "TE1, TE2, TE3, ..." indicate techniques included in the identified "attack techniques used." "S1, S2, S3, ..." indicate software corresponding to each technique.

[0033] Furthermore, when the attack type is specified by the attack objective, the attack scenario generation unit 121 can also generate an attack scenario so that the specified attack objective becomes the terminal (last tactic).

[0034] One specific example of an attack scenario generated by the attack scenario generation unit 121 is shown in Fig. 6. In the example of Fig. 6, the attack scenario generation unit 121 selects a terminal device to be attacked from among the terminal devices constituting the computer system 40, depending on the system environment of the terminal device.

[0035] In Figure 6, the "execution time" is obtained by adding the "required time" in the software information (see Figure 4) to the execution time of the previous attack. The "execution time" may also be obtained by adding a random amount of time to the time obtained by adding the required time.

[0036] 6, the "execution command" corresponds to the "input format" shown in FIG. 4. The execution sequence generation unit 124, which will be described later, inputs the file path and IP address of the attack destination into the variable portion of the execution command by referring to the environment information 145 stored in the storage unit 14. The environment information 145 is information that specifies, for example, values ​​of the file path and IP address corresponding to each parameter ($source, $target, $ipaddress, etc.) for each attack destination (client A, client B, etc.).

[0037] The partial scenario extraction unit 122 extracts, from the generated attack scenario, a portion that fits within the execution time of the exercise acquired as the exercise condition as a partial scenario. Specifically, for example, if the execution time, which is the exercise condition, is one hour, the partial scenario extraction unit 122 extracts a partial scenario that can be executed within one hour.

[0038] Furthermore, in the first embodiment, the partial scenario extraction unit 122 determines whether each attack action of the extracted partial scenario satisfies the extraction conditions included in the attack action condition information 143. If the extracted partial scenario does not satisfy the extraction conditions, the partial scenario extraction unit 122 causes the attack scenario generation unit 121 to generate an attack scenario again. Figure 7 is a diagram showing an example of extraction conditions used in the first embodiment. In the example of Figure 7, the extraction conditions are set for each attribute by an attribute value and a reference value condition.

[0039] After extracting the partial scenario, the partial scenario extraction unit 122 associates the ID (identifier) ​​of the student who specified the practice conditions with the extracted partial scenario, and stores both as scenario information 144. The scenario information 144 is information that identifies partial scenarios extracted in the past for each student ID.

[0040] The partial scenario verification unit 123 determines whether the partial scenario extracted by the partial scenario extraction unit 122 is appropriate. Specifically, the partial scenario verification unit 123 compares the ID of the student who specified the exercise conditions and the extracted partial scenario with the scenario information 144. The partial scenario verification unit 123 then compares the extracted part with a part previously extracted for the same student, and determines whether the overlapping ratio between the two is equal to or greater than a threshold value.

[0041] If the result of the determination is that the overlapping ratio between the two is equal to or greater than a threshold, the partial scenario verification unit 123 causes the partial scenario extraction unit 122 to extract another partial scenario from the attack scenario. On the other hand, if the result of the determination is that the overlapping ratio between the two is not equal to or greater than the threshold, the partial scenario verification unit 123 instructs the execution sequence generation unit 124 to perform processing. Note that the threshold in this case is set appropriately.

[0042] The execution sequence generation unit 124 uses the partial scenario to generate a series of attack actions to be executed in the cybersecurity training, i.e., an attack execution sequence. In the execution sequence, execution commands are arranged in the order of execution. As described above, the execution sequence generation unit 124 refers to the environment information 145 stored in the memory unit 14 and inputs the file path and IP address of the attack target, etc., into the variable portion of the "execution command" of the attack scenario (see Figure 6).

[0043] The attack operation execution unit 13 transmits the created series of attack operations, i.e., an execution sequence, to a computer system 40 for executing a cybersecurity exercise, and causes the computer system 40 to execute the series of attack operations.

[0044] Furthermore, in the first embodiment, the student specifies the start date and time of the exercise, so the attacking action execution unit 13 executes a series of attacking actions in accordance with the specified start date and time in the computer system 40. The execution timing of the series of attacking actions may be the specified start date and time, or may be a random time within a predetermined range centered on the specified start date and time.

[0045] As described above, the computer system 40 is composed of multiple terminal devices and a server device, and commands are executed on the terminal device that is the target of the attack. The computer system 40 then outputs logs collected during the execution of the series of attack operations. The output logs are used as teaching materials in cybersecurity exercises conducted by participants.

[0046] [Device operation] Next, the operation of the information processing device 10 in the first embodiment will be described with reference to Figs. 8 to 11. Fig. 8 is a flow diagram showing the operation of the information processing device in the first embodiment. In the following description, Figs. 1 to 7 will be referred to as appropriate. Furthermore, in the first embodiment, an information processing method is implemented by operating the information processing device 10. Therefore, the description of the information processing method in the first embodiment will be replaced by the following description of the operation of the information processing device 10.

[0047] 8, first, the exercise condition acquisition unit 11 acquires the exercise duration and attack type specified by the student as exercise conditions (step A1). The exercise condition acquisition unit 11 also inputs the acquired exercise conditions to the attack action generation unit 12.

[0048] Specifically, as a premise, a student specifies the start date and time of the exercise, the duration of the exercise, and the attack type on his / her own terminal device 30, as shown in Fig. 9. As a result, the terminal device 30 transmits information including the start date and time of the exercise, the duration of the exercise, and the attack type to the information processing device 10. Fig. 9 is a diagram showing an example of a screen for specifying exercise conditions.

[0049] Next, in the attack action generation unit 12, the attack scenario generation unit 121 generates an attack scenario by a virtual attacker according to the attack type designated by the student (step A2).

[0050] Next, in the attacking action generating unit 12, the partial scenario extracting unit 122 extracts, from the generated attack scenario, a part that fits within the execution time of the exercise acquired as the exercise condition, as a partial scenario (step A3).

[0051] Next, the partial scenario extraction unit 122 determines whether each attack action of the extracted partial scenario satisfies the extraction condition included in the attack action condition information 143 (step A4).

[0052] If the result of the judgment in step A4 is that each attack action of the extracted partial scenario does not satisfy the extraction conditions contained in the attack action condition information 143 (step A4: No), the partial scenario extraction unit 122 causes the attack scenario generation unit 121 to execute step A2 again.

[0053] On the other hand, if the result of the determination in step A4 is that each attack action of the extracted partial scenario satisfies the extraction conditions included in the attack action condition information 143 (step A4: Yes), processing by the partial scenario verification unit 123 is performed.

[0054] The partial scenario verification unit 123 determines whether the partial scenario extracted in step A3 is appropriate (step A5).

[0055] Specifically, the partial scenario verification unit 123 compares the ID of the student who specified the practice conditions and the extracted partial scenario with the scenario information 144. Then, the partial scenario verification unit 123 compares the extracted part with parts previously extracted for the same student, and determines whether the overlapping ratio between the two is equal to or greater than a threshold. If the result of the determination shows that the overlapping ratio between the two is equal to or greater than the threshold, the partial scenario verification unit 123 determines that the partial scenario is inappropriate. On the other hand, if the overlapping ratio between the two is not equal to or greater than the threshold, the partial scenario verification unit 123 determines that the partial scenario is appropriate.

[0056] If the result of the judgment in step A5 is that the partial scenario extracted in step A3 is not appropriate (step A5: No), the partial scenario verification unit 123 causes the partial scenario extraction unit 122 to execute step A3 again to extract another partial scenario from the attack scenario.

[0057] If the result of the judgment in step A5 is that the partial scenario extracted in step A3 is appropriate (step A5: Yes), the execution sequence generation unit 124 uses the partial scenario to generate a series of attack actions to be executed in the cybersecurity exercise (step A6).

[0058] Next, the attack operation execution unit 13 transmits the series of attack operations (execution sequence) created in step A6 to a computer system 40 for executing cybersecurity exercises, and causes the computer system 40 to execute the series of attack operations (step A7).

[0059] Execution of step A7 ends the processing in the information processing device 10. After that, in the computer system 40, a command is executed on the terminal device that is the target of the attack. Then, the computer system 40 outputs a log collected during the execution of the series of attack operations, as shown in Figures 10 and 11. The output log is used as a teaching material in cybersecurity training by participants.

[0060] Fig. 10 is a diagram showing an example of a log output by a computer system. The log shown in Fig. 10 is an event log acquired from a terminal device. Fig. 11 is a diagram showing another example of a log output by a computer system. The log shown in Fig. 11 is a USN journal (Update Sequence Number Journal) log acquired from a terminal device.

[0061] [Effects of the First Embodiment] As described above, in the embodiment, the information processing device 10 creates a series of attack actions to be executed in a cybersecurity exercise according to the start date and time of the exercise, the duration of the exercise, and the attack type specified by the student of the cybersecurity exercise. This allows the student to conduct the cybersecurity exercise under conditions specified by the student. Furthermore, since the series of attack actions will be different from those used in previous cybersecurity exercises taken by the student, the student can efficiently improve their skills.

[0062] [program] The program in the first embodiment may be any program that causes a computer to execute steps A1 to A7 shown in Fig. 8. By installing and executing this program on a computer, the information processing device 10 and information processing method of the present embodiment can be realized. In this case, the processor of the computer functions and performs processing as an exercise condition acquisition unit 11, an attacking action generation unit 12, and an attacking action execution unit 13. Examples of the computer include a general-purpose PC, a smartphone, and a tablet terminal device.

[0063] In addition, in the embodiment, the memory unit 14 may be realized by storing the data files that constitute these in a memory device such as a hard disk provided in the computer, or may be realized by a memory device of another computer.

[0064] The program in the first embodiment may be executed by a computer system constructed by multiple computers. In this case, for example, each computer may function as one of the exercise condition acquisition unit 11, the attacking action generation unit 12, and the attacking action execution unit 13.

[0065] (Embodiment 2) Next, an information processing device, an information processing method, and a program according to the second embodiment will be described with reference to FIGS.

[0066] [Device configuration] First, the configuration of the information processing device in the second embodiment will be described with reference to Fig. 12. Fig. 12 is a configuration diagram showing the configuration of the information processing device in the second embodiment.

[0067] The information processing device according to the second embodiment shown in FIG. 2 Similarly to the information processing device 10 described in the first embodiment, the information processing device 10 is also a device for supporting training against cyber attacks, for example, cybersecurity training.

[0068] 12, in the second embodiment, the information processing device 20 differs from the information processing device 10 in the first embodiment in that it includes a non-attacking action generating unit 21 and a non-attacking action executing unit 22 in addition to the practice condition acquiring unit 11, the attacking action generating unit 12, and the attacking action executing unit 13. Also, the storage unit 14 stores non-attacking action information 146 in addition to attack type information 141, software information 142, attacking action condition information 143, and scenario information 144. The following mainly describes the differences from the first embodiment.

[0069] The non-attacking action generation unit 21 generates non-attacking actions that do not constitute cyber-attacks using execution commands included in the series of attacking actions generated by the attacking action generation unit 12. In the second embodiment, the non-attacking action generation unit 21 compares the execution commands (e.g., OS standard commands, application programs, etc.) used in the series of attacking actions with the non-attacking action information 146, and selects non-attacking actions that include one or more actions that use the same execution commands.

[0070] Here, the operation of the non-attack action generation unit 21 will be specifically described with reference to Fig. 13. Fig. 13 is a diagram showing an example of non-attack action information used in the second embodiment. As shown in Fig. 13, the non-attack action information 146 is information that specifies, for each application used in an attack type, a command sequence that uses that application. The non-attack action information 146 is made up of a "command sequence," an "application," a "difficulty level," and an "attack type." The difficulty level will be described later.

[0071] Specifically, for example, if the attack type designated by the student is "APT29," the non-attacking action generation unit 21 selects a command sequence corresponding to "APT29" and sets the selected command sequence as a non-attacking action. Also, if the student designates the difficulty level in advance, the non-attacking action generation unit 21 can also select a corresponding command sequence according to the designated difficulty level.

[0072] Furthermore, the non-aggressive action generation unit 21 can also create an action log showing user operations using the techniques disclosed in the following reference documents 1 and 2, and set this as a non-aggressive action. (Reference document 1) Yasuda et al., "Automatic Terminal Driving System in an Active Attack Observation Environment," IEICE Technical Report 119(140), 299-304, 2019-07-23, [https: / / ci.nii.ac.jp / naid / 40021970984] (Reference document 2) IEICE Technical Committee, "Automatic Terminal Driving System in an Active Attack Observation Environment," [https: / / www.ieice.org / publications / ken / summary.php?contribution_id=103289]

[0073] The non-attacking action execution unit 22 transmits the non-attacking action generated by the non-attacking action generation unit 21 to the computer system 40, causing the computer system 40 to execute the non-attacking action. Specifically, the non-attacking action execution unit 22 transmits a command sequence selected as a non-attacking action to the computer system 40. As a result, the computer system 40 causes each command sequence to be executed in the terminal devices that constitute the computer system 40.

[0074] The computer system 40 can also randomly select a command sequence to be executed from the transmitted command sequence. Furthermore, the execution interval of the non-attack action can be set to a predetermined value (for example, 1 minute, 1 minute 3 0 seconds The execution interval may be randomly selected from the following intervals: 1 minute, 2 minutes, 5 minutes, 10 minutes, etc., or may be increased or decreased by a few seconds from the set execution interval to enhance naturalness.

[0075] The computer system 40 can also generate variations of pseudo operation logs from existing user operation logs using the technology disclosed in Reference 3 below. (Reference document 3) International Publication No. 2021 / 171383

[0076] [Device operation] Next, the information processing device according to the second embodiment 2 The operation of the information processing device 20 will be described with reference to FIG. 14. FIG. 14 is a flow diagram showing the operation of the information processing device in the second embodiment. In the following description, FIGS. 12 and 13 will be referred to as appropriate. In the second embodiment, the information processing method is implemented by operating the information processing device 20. Therefore, the description of the information processing method in the second embodiment will be replaced by the following description of the operation of the information processing device 20.

[0077] 14, first, the exercise condition acquisition unit 11 acquires the exercise duration and attack type specified by the student as exercise conditions (step B1). Step B1 is the same as step A1 shown in FIG.

[0078] Next, in the attack action generation unit 12, the attack scenario generation unit 121 generates an attack scenario by a virtual attacker according to the attack type specified by the student (step B2). Step B2 is the same as step A2 shown in FIG.

[0079] Next, in the attack action generation unit 12, the partial scenario extraction unit 122 extracts, from the generated attack scenario, a part that fits within the execution time of the exercise acquired as the exercise condition as a partial scenario (step B3). Step B3 is a step similar to step A3 shown in FIG.

[0080] Next, the partial scenario extraction unit 122 determines whether each attack action of the extracted partial scenario satisfies the extraction conditions included in the attack action condition information 143 (step B4). Step B4 is the same as step A4 shown in FIG.

[0081] If the result of the judgment in step B4 is that each attack action of the extracted partial scenario does not satisfy the extraction conditions contained in the attack action condition information 143 (step B4: No), the partial scenario extraction unit 122 causes the attack scenario generation unit 121 to execute step B2 again.

[0082] On the other hand, if the result of the determination in step B4 is that each attack action of the extracted partial scenario satisfies the extraction conditions included in the attack action condition information 143 (step B4: Yes), processing by the partial scenario verification unit 123 is performed.

[0083] The partial scenario verification unit 123 determines whether the partial scenario extracted in step B3 is appropriate (step B5). Step B5 is the same as step A5 shown in FIG.

[0084] As a result of the determination in step B5, B If the partial scenario extracted in 3 is not appropriate (step B5: No), the partial scenario verification unit 123 causes the partial scenario extraction unit 122 to execute step B3 again to extract another partial scenario from the attack scenario.

[0085] If the result of the judgment in step B5 is that the partial scenario extracted in step B3 is appropriate (step B5: Yes), the execution sequence generation unit 124 uses the partial scenario to generate a series of attack actions to be executed in the cybersecurity exercise (step B6).

[0086] Next, the non-attacking action generating unit 21 generates a non-attacking action that does not constitute a cyber-attack, using the execution commands included in the series of attacking actions generated in step B6 (step B7).

[0087] Next, the attack operation execution unit 13 transmits the series of attack operations (execution sequence) created in step B6 to the computer system 40 for executing the cybersecurity training, and causes the computer system 40 to execute the series of attack operations (step B8). Step B8 is a step similar to step A7 shown in FIG. 8.

[0088] Next, the non-attacking action execution unit 22 transmits the non-attacking action generated in step B7 to the computer system 40, causing the computer system 40 to also execute the non-attacking action (step B9). Note that step B9 may be executed simultaneously with step B8.

[0089] By executing step B9, the information processing device 2The processing at step 0 ends. After that, in the computer system 40, a command is executed on the terminal device that is the target of the attack. After that, the computer system 40 outputs logs collected during the execution of a series of attack operations and logs collected during the execution of non-attack operations. The output logs are used as teaching materials in cybersecurity exercises by students.

[0090] [Effects of the second embodiment] As described above, the second embodiment also achieves the effects described in the first embodiment. Furthermore, according to the second embodiment, the computer system 40 outputs logs collected when a series of attack actions are executed, as well as logs collected when a non-attack action is executed. Therefore, the computer system 40 can include logs obtained as a result of executing a non-attack action in the logs obtained as a result of executing a series of attack actions. As a result, according to the second embodiment, it is possible to realize a cybersecurity exercise in which it is difficult to determine whether an action is an attack or not.

[0091] [program] The program in the second embodiment may be a program that causes a computer to execute steps B1 to B9 shown in Fig. 14. By installing and executing this program on a computer, ,fruit Form of implementation 2 Information processing equipment in 2 0 and an information processing method can be realized. In this case, the processor of the computer functions and performs processing as an exercise condition acquisition unit 11, an attacking action generation unit 12, an attacking action execution unit 13, a non-attacking action generation unit 21, and a non-attacking action execution unit 22. Examples of the computer include a general-purpose PC, a smartphone, and a tablet terminal device.

[0092] In addition, in the embodiment, the memory unit 14 may be realized by storing the data files that constitute these in a memory device such as a hard disk provided in the computer, or may be realized by a memory device of another computer.

[0093] The program in the first embodiment may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as one of the exercise condition acquisition unit 11, the attack action generation unit 12, the attack action execution unit 13, the non-attack action generation unit 21, and the non-attack action execution unit 22, respectively.

[0094] [Physical configuration] A computer that realizes the information processing device by executing the programs in the first and second embodiments will now be described with reference to Fig. 15. Fig. 15 is a block diagram showing an example of a computer that realizes the information processing device in the first and second embodiments.

[0095] 15, a computer 150 includes a CPU (Central Processing Unit) 151, a main memory 152, a storage device 153, an input interface 154, a display controller 155, a data reader / writer 156, and a communication interface 157. These components are connected to each other via a bus 161 so as to be able to communicate data with each other.

[0096] Furthermore, the computer 150 may include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array) in addition to or instead of the CPU 151. In this aspect, the GPU or FPGA can execute the programs in the embodiments.

[0097] The CPU 151 loads a program in the embodiment, which is composed of a group of codes and stored in the storage device 153, into the main memory 152 and executes each code in a predetermined order to perform various calculations. The main memory 152 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).

[0098] The program in the embodiment is provided in a state stored in a computer-readable recording medium 160. The program in the embodiment may be distributed over the Internet connected via the communication interface 157.

[0099] Specific examples of the storage device 153 include a hard disk drive and a semiconductor storage device such as a flash memory. The input interface 154 mediates data transmission between the CPU 151 and input devices 158 such as a keyboard and a mouse. The display controller 155 is connected to a display device 159 and controls the display on the display device 159.

[0100] Data reader / writer 156 mediates data transmission between CPU 151 and recording medium 170, reads programs from recording medium 160, and writes processing results from computer 150 to recording medium 160. Communication interface 157 mediates data transmission between CPU 151 and other computers.

[0101] Specific examples of the recording medium 160 include general-purpose semiconductor storage devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as flexible disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).

[0102] The information processing device in the first and second embodiments can be realized by using hardware corresponding to each unit, instead of a computer on which a program is installed. Furthermore, the information processing device may be partially realized by a program and the remaining unit by hardware.

[0103] Some or all of the above-described embodiments can be expressed by (Supplementary Note 1) to (Supplementary Note 18) described below, but are not limited to the following descriptions.

[0104] (Appendix 1) an exercise condition acquisition unit that acquires an exercise duration designated by a participant of a cybersecurity exercise as an exercise condition; an attack action generation unit that generates a cyber-attack scenario to be used in the cybersecurity exercise and extracts a portion of the generated scenario that fits within the specified implementation time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; An information processing device comprising:

[0105] (Appendix 2) 10. The information processing device according to claim 1, the attack action generation unit determines whether the part satisfies an attack action condition that specifies whether a series of attack actions can be executed before extracting the part, and extracts the part if the attack action condition is satisfied. Information processing device.

[0106] (Appendix 3) 3. The information processing device according to claim 1, The attack action generation unit further identifies the student who specified the execution time used to extract the portion, compares the created series of attack actions with a series of attack actions previously created for the identified student, and if the comparison shows that the ratio of overlapping portions is equal to or greater than a threshold, re-extracts a portion of the generated scenario that falls within the execution time and is different from the extracted portion.

[0107] (Appendix 4) An information processing device according to any one of Supplementary Notes 1 to 3, the exercise condition acquisition unit acquires a type of cyber-attack designated by the student as the exercise condition; the attack action generation unit generates a scenario of the cyber-attack according to the type of the cyber-attack specified by the student; Information processing device.

[0108] (Appendix 5) An information processing device according to any one of Supplementary Notes 1 to 4, The computer system for executing the cybersecurity exercise further includes an attack action execution unit that executes the created series of attack actions. Information processing device.

[0109] (Appendix 6) 6. The information processing device according to claim 5, a non-attack action generation unit that generates a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; a non-aggressive action execution unit that executes the generated non-aggressive action in the computer system; Further comprising: Information processing device.

[0110] (Appendix 7) an exercise condition acquisition step of acquiring an exercise duration designated by a participant of the cybersecurity exercise as an exercise condition; an attack action generation step of generating a cyber-attack scenario to be used in the cybersecurity exercise and extracting a part of the generated scenario that fits within the specified execution time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; An information processing method comprising:

[0111] (Appendix 8) 8. The information processing method according to claim 7, further comprising: In the attack action generation step, before extracting the part, it is determined whether the part satisfies an attack action condition that specifies whether a series of attack actions can be executed, and if the part satisfies the attack action condition, the part is extracted. Information processing methods.

[0112] (Appendix 9) 9. The information processing method according to claim 7 or 8, In the attack action generation step, the student who specified the execution time used to extract the portion is further identified, and the created series of attack actions is compared with a series of attack actions previously created for the identified student, and if the result of the comparison shows that the ratio of overlapping portions is equal to or greater than a threshold, a portion of the generated scenario that falls within the execution time and is different from the extracted portion is re-extracted. Information processing methods.

[0113] (Appendix 10) An information processing method according to any one of Supplementary Notes 7 to 9, In the exercise condition acquisition step, a type of cyber-attack designated by the student is acquired as the exercise condition; In the attack action generation step, a scenario of the cyber attack is generated according to the type of the cyber attack specified by the student. Information processing methods.

[0114] (Appendix 11) An information processing method according to any one of Supplementary Notes 7 to 10, The computer system for executing the cybersecurity exercise further includes an attack action execution step of executing the created series of attack actions. Information processing methods.

[0115] (Appendix 12) 12. The information processing method according to claim 11, a non-attack action generation step of generating a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; a non-attacking action execution step of executing the generated non-attacking action in the computer system; Further comprising: Information processing methods.

[0116] (Appendix 13) On the computer, an exercise condition acquisition step of acquiring an exercise duration designated by a participant of the cybersecurity exercise as an exercise condition; an attack action generation step of generating a cyber-attack scenario to be used in the cybersecurity exercise and extracting a part of the generated scenario that fits within the specified execution time, thereby creating a series of attack actions to be executed in the cybersecurity exercise; Run Ru, Program Hmm.

[0117] (Appendix 14) As described in Appendix 13 program And, In the attack action generation step, before extracting the part, it is determined whether the part satisfies an attack action condition that specifies whether a series of attack actions can be executed, and if the part satisfies the attack action condition, the part is extracted. program .

[0118] (Appendix 15) Supplementary Note 13 or 14 program And, In the attack action generation step, the student who specified the execution time used to extract the portion is further identified, and the created series of attack actions is compared with a series of attack actions previously created for the identified student, and if the result of the comparison shows that the ratio of overlapping portions is equal to or greater than a threshold, a portion of the generated scenario that falls within the execution time and is different from the extracted portion is re-extracted. program .

[0119] (Appendix 16) Any of Supplementary Notes 13 to 15 program And, In the exercise condition acquisition step, a type of cyber-attack designated by the student is acquired as the exercise condition; In the attack action generation step, a scenario of the cyber attack is generated according to the type of the cyber attack specified by the student. program .

[0120] (Appendix 17) Any of Supplementary Notes 13 to 16 program And, before The computer Furthermore, In the computer system for executing the cybersecurity exercise, an attack action execution step is executed, which executes the created series of attack actions. Ru, program .

[0121] (Appendix 18) As stated in Appendix 17 program And, before The computer Furthermore, a non-attack action generation step of generating a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; a non-attacking action execution step of executing the generated non-attacking action in the computer system; Run Ru, program .

[0122] Although the present invention has been described above with reference to the embodiments, the present invention is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention. [Industrial Applicability]

[0123] As described above, the present disclosure makes it possible to provide cybersecurity training tailored to the needs of individual participants. The present disclosure is useful in fields where training against cyberattacks is required. [Explanation of symbols]

[0124] 10 Information processing device (first embodiment) 11 Exercise Condition Acquisition Section 12 Attack motion generation unit 13 Attack action execution unit 20 Information processing device (embodiment 2) 21 Non-aggressive action generation unit 22 Non-attack action execution unit 30 Terminal Equipment 40 Computer Systems 121 Attack scenario generation unit 122 Partial scenario extraction unit 123 Partial Scenario Verification Section 124 Execution sequence generation unit 141 Attack Type Information 142 Software Information 143 Attack Operation Condition Information 144 Scenario Information 145 Environmental information 146 Non-Aggression Action Information 150 Computers 151 CPU 152 main memory 153 Storage device 154 input interfaces 155 Display Controller 156 Data Reader / Writer 157 Communication Interface 158 Input Devices 159 Display Device 160 Recording Media 161 Bus

Claims

1. an exercise condition acquisition unit that acquires an exercise duration designated by a participant of a cybersecurity exercise as an exercise condition; an attack action generation unit that generates a cyber-attack scenario to be used in the cybersecurity exercise and extracts a portion of the generated scenario that fits within the specified implementation time, thereby generating a series of attack actions to be executed in the cybersecurity exercise; An information processing device comprising:

2. 2. The information processing device according to claim 1, the attack action generation unit determines whether the part satisfies an attack action condition that specifies whether a series of attack actions can be executed before extracting the part, and extracts the part if the attack action condition is satisfied. Information processing device.

3. 2. The information processing device according to claim 1, The attack action generation unit further identifies the student who specified the implementation time used to extract the portion, compares the extracted portion with a portion previously extracted for the identified student, and if the comparison shows that the overlapping ratio between the two is equal to or greater than a threshold, re-extracts a portion of the generated scenario that falls within the implementation time and is different from the extracted portion. Information processing device.

4. 2. The information processing device according to claim 1, the exercise condition acquisition unit acquires a type of cyber-attack designated by the student as the exercise condition; the attack action generation unit generates a scenario of the cyber-attack according to the type of the cyber-attack specified by the student; Information processing device.

5. 2. The information processing device according to claim 1, The computer system for executing the cybersecurity exercise further includes an attack action execution unit that executes the generated series of attack actions. Information processing device.

6. 6. The information processing device according to claim 5, a non-attack action generation unit that generates a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; a non-aggressive action execution unit that executes the generated non-aggressive action in the computer system; Further comprising: Information processing device.

7. A computer-implemented method comprising: The duration of the cybersecurity exercise specified by the participant is acquired as an exercise condition. generating a cyber-attack scenario to be used in the cybersecurity exercise, and extracting a portion of the generated scenario that fits within the specified execution time, thereby generating a series of attack actions to be executed in the cybersecurity exercise; Information processing methods.

8. 8. The information processing method according to claim 7, In generating the attacking motion, before extracting the part, it is determined whether the part satisfies an attacking motion condition that specifies whether a series of attacking motions can be executed, and if the part satisfies the attacking motion condition, the part is extracted. Information processing methods.

9. 8. The information processing method according to claim 7, In generating the attacking actions, the method further identifies the student who specified the execution time used to extract the portion, compares the extracted portion with a portion previously extracted for the identified student, and if the comparison shows that the overlapping ratio between the two is equal to or greater than a threshold, re-extracts a portion of the generated scenario that falls within the execution time and is different from the extracted portion. Information processing methods.

10. 8. The information processing method according to claim 7, In acquiring the exercise conditions, a type of cyber-attack designated by the student is acquired as the exercise condition; In generating the attack behavior, a scenario of the cyber attack is generated according to the type of the cyber attack specified by the student. Information processing methods.

11. 8. The information processing method according to claim 7, executing the generated series of attack actions in a computer system for executing the cybersecurity exercise; Information processing methods.

12. 12. The information processing method according to claim 11, generating a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; executing the generated non-attack action in the computer system; Information processing methods.

13. On the computer, The duration of the cybersecurity exercise specified by the participants will be acquired as an exercise condition. generating a cyber-attack scenario to be used in the cyber-security exercise, and extracting a part of the generated scenario that fits within the specified implementation time, thereby generating a series of attack actions to be executed in the cyber-security exercise; program.

14. 14. The program according to claim 13, The computer, In generating the attacking motion, before extracting the part, it is determined whether the part satisfies an attacking motion condition that specifies whether a series of attacking motions can be executed, and if the part satisfies the attacking motion condition, the part is extracted. program.

15. 14. The program according to claim 13, The computer, In generating the attacking actions, the method further identifies the student who specified the execution time used to extract the portion, compares the extracted portion with a portion previously extracted for the identified student, and if the comparison shows that the overlapping ratio between the two is equal to or greater than a threshold, re-extracts a portion of the generated scenario that falls within the execution time and is different from the extracted portion. program.

16. 14. The program according to claim 13, The computer, In acquiring the exercise conditions, a type of cyber-attack designated by the student is acquired as the exercise conditions; In generating the attacking behavior, a scenario of the cyber-attack is generated according to the type of the cyber-attack designated by the student. program.

17. 14. The program according to claim 13, The computer further comprises: executing the generated series of attack actions in a computer system for executing the cybersecurity exercise; program.

18. 18. The program of claim 17, The computer, generating a non-attack action that does not correspond to the cyber-attack using execution commands included in the generated series of attack actions; executing the generated non-attack action in the computer system; program.

Citation Information

Patent Citations

  • Incident scenario generation device and incident scenario generation system

    JP2021005165A

  • Program, information processing device and cyber exercise control method

    JP2021120780A

  • Context-aware cybersecurity training systems, apparatuses, and methods

    US11158207B1

  • Scenario generation device, scenario generation method, and scenario generation program

    WO2020105156A1