Attack monitoring device and attack monitoring method
The attack monitoring device and method analyze logs to identify attack stages and display warnings based on progression, addressing the lack of correlation evaluation in existing systems and enhancing cyber-attack detection.
Patent Information
- Application Number
- JP2021170117
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-18
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2041-10-18
AI Technical Summary
Existing cyber-attack detection systems fail to evaluate the correlation between multiple attack events, making it difficult to determine the progression of an attack scenario and its impact on devices.
An attack monitoring device and method that analyze logs from connected devices to detect multiple attack events, identify the corresponding attack stages based on predefined scenarios, and display warnings based on the progression of these stages, using a warning display unit to indicate the severity of the attack.
Enables effective monitoring of cyber-attack progression by displaying warnings that reflect the stage and severity of the attack, allowing users to understand the threat level and take appropriate actions.
Smart Images

Figure 0007814884000001 
Figure 0007814884000002 
Figure 0007814884000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an attack monitoring device and an attack monitoring method. [Background technology]
[0002] With the recent advances in information and communication technology, operational technology (OT), a technology for controlling things, is increasingly being integrated with information technology (IT). For example, remote monitoring systems are known that monitor the control status of equipment used in plant facilities from remote locations via communication networks such as the Internet. Equipment connected to such communication networks can be subject to cyber attacks using malware from outside with the aim of leaking information to the outside or tampering with control parameters.
[0003] To prevent disruptions to equipment operations due to cyberattacks, monitoring is required to quickly detect cyberattacks, but cyberattacks are becoming increasingly sophisticated. For example, Patent Document 1 discloses a technology for detecting advanced cyberattacks such as APTs (Advanced Persistent Threats), which reduces missed attacks by analyzing computer system logs based on attack scenarios. Furthermore, Patent Document 2 discloses an attack analysis system that, when an attack is detected by analyzing the logs of a monitored device, can analyze the predicted occurrence of other attacks based on the attack scenarios. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Patent No. 6104149 Summary of the Invention [Problem to be solved by the invention]
[0005] Advanced cyber-attacks such as APTs progress in stages according to an attack scenario, and typically, the impact on devices increases as the attack progresses. Patent Documents 1 and 2 detect cyber-attacks by analyzing logs based on the attack scenario. However, even if multiple attack events are detected, these attack events are detected individually, and the correlation between the attack events is not evaluated. Therefore, it is not possible to determine how far the detected attack event has progressed in the attack scenario.
[0006] At least one embodiment of the present disclosure has been developed in consideration of the above-mentioned circumstances, and aims to provide an attack monitoring device and an attack monitoring method that are capable of displaying a warning corresponding to the progress of an attack scenario based on a detected attack event. [Means for solving the problem]
[0007] In order to solve the above problem, an attack monitoring device according to one embodiment includes: an attack event detection unit for detecting a plurality of attack events by analyzing a log collected from at least one device connected to a communication network; an attack stage identification unit for identifying an attack stage corresponding to each of the plurality of attack events based on an attack scenario in which at least one attack candidate is defined for each attack stage; a warning display unit for displaying a warning based on the number of detected attack events when it is determined that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events; Equipped with.
[0008] In order to solve the above problem, an attack monitoring method according to one embodiment includes: detecting a plurality of attack events by analyzing logs collected from at least one device connected to a communications network; identifying an attack stage corresponding to each of the plurality of attack events based on an attack scenario in which at least one attack candidate is defined for each attack stage; a step of displaying a warning based on the number of detected attack events when it is determined that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events; Equipped with. [Effects of the Invention]
[0009] According to at least one embodiment of the present disclosure, an attack monitoring device and an attack monitoring method can be provided that are capable of displaying a warning corresponding to the progress of an attack scenario based on a detected attack event. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a diagram illustrating an overall configuration of a device according to an embodiment. [Figure 2] FIG. 1 is a block diagram of an attack monitoring device according to an embodiment. [Figure 3] 3 is an example of an attack scenario stored in the storage unit of FIG. 2. [Figure 4] 1 is a flowchart illustrating an attack monitoring method according to one embodiment. [Figure 5] FIG. 4 is a schematic diagram showing how an attack progresses as attack events are repeatedly detected in the attack scenario of FIG. 3. [Figure 6] 3 is an example of a warning display by the warning display unit of FIG. 2. [Figure 7] FIG. 7 is a diagram showing the transition of attack states corresponding to FIG. 6. [Figure 8] 10 is a calculation example showing the correspondence between the comprehensive evaluation index and the warning display. [Figure 9] 3 is a display example of a resolution procedure by the resolution procedure display unit of FIG. 2. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, several embodiments of the present invention will be described with reference to the accompanying drawings. However, the dimensions, materials, shapes, relative arrangements, etc. of components described as embodiments or shown in the drawings are merely illustrative examples and are not intended to limit the scope of the present invention.
[0012] An attack monitoring device according to at least one embodiment monitors at least one device 1 connected to a communication network 2. FIG. 1 is a diagram showing the overall configuration of the device 1 according to one embodiment. In the following embodiment, an integrated testing system will be described as an example of the device 1, which includes a plant facility 6 installed on-site and a remote monitoring center 8 installed geographically away from the plant facility 6 and capable of communicating with the plant facility 6 via the communication network 2.
[0013] The plant facility 6 includes control target devices 10 such as pumps, valves, and sensors, a PLC 12 (programmable logic controller) for controlling the control target devices 10, an HMI 14 (human machine interface) capable of communicating with the PLC 12, an operation management system 16 for managing the operation of the plant facility 6, and a server 18 associated with the operation management system 16. The remote monitoring center 8 includes a remote monitoring system 19 and a server 20 associated with the remote monitoring system 19. These components in the plant facility 6 and the remote monitoring center 8 are connected to each other so as to be able to communicate with each other via a cloud server 21 provided on the communication network 2. It should be noted that a firewall (FW) is provided between each of the components connected by the communication network 2 as appropriate.
[0014] The device 1 having the above configuration is broadly divided into an IT security system 22 close to the communication network 2 and an OT security system 24 capable of communicating with the IT security system 22. Each configuration of the device 1 includes multiple segments, each with a level set according to the hierarchical depth relative to the communication network 2, across the IT security system 22 and the OT security system. Specifically, the segment SG0 including the controlled device 10 belonging to the OT security system 24 is set to "Level 0: Field Equipment / Devices," the segment SG1 including the PLC 12 is set to "Level 1: Control Equipment / Devices," and the segment SG2 including the HMI 14 is set to "Level 2: Operation Monitoring and Operating System." Furthermore, the segment SG3 including the operation management system 16, server 18, remote monitoring system 19, and server 20 belonging to the IT security system 22 is set to "Level 3: Operation Management System," and the segment SG4 including the cloud server 21 is set to "Level 4: Information System."
[0015] It should be noted that, among the above levels 0 to 4, the larger the numerical value, the closer the layer is to the communication network 2. Such level settings and allocations to the devices 1 are merely examples, and the user can set them appropriately depending on the configuration of the devices 1.
[0016] Next, an attack monitoring device 100 that monitors the device 1 configured as described above will be described. FIG. 2 is a block diagram of the attack monitoring device 100 according to one embodiment. The attack monitoring device 100 is configured, for example, with a central processing unit (CPU), random access memory (RAM), read-only memory (ROM), and a computer-readable storage medium. A series of processes for implementing various functions is stored in a storage medium, for example, in the form of a program. The CPU reads the program into RAM and executes information processing and arithmetic operations to implement various functions. The program may be pre-installed in a ROM or other storage medium, provided in a state stored in a computer-readable storage medium, or distributed via wired or wireless communication. Examples of computer-readable storage media include magnetic disks, magneto-optical disks, CD-ROMs, DVD-ROMs, and semiconductor memories.
[0017] As shown in FIG. 2, the attack monitoring device 100 includes a log acquisition unit 102, a log analysis unit 104, an attack event detection unit 106, a memory unit 108, an attack stage identification unit 110, a warning display unit 112, a reset unit 114, and a resolution procedure display unit 116. The log acquisition unit 102 is configured to acquire logs collected from the device 1 to be monitored. The log analysis unit 104 is configured to analyze the logs acquired by the log acquisition unit 102. The attack event detection unit 106 is configured to detect an attack event based on the analysis results of the log analysis unit 104. The memory unit 108 is configured to store various information (attack scenario AS, described below) required for the attack monitoring method performed by the attack monitoring device 100. The attack stage identification unit 110 is configured to identify the attack stage corresponding to the attack event detected by the attack event detection unit 106. The warning display unit 112 is configured to display a warning corresponding to the attack stage identified by the attack stage identification unit 110. The reset unit 114 is configured to reset the number of times an attack event has been detected by the attack event detection unit 106. The resolution procedure display unit 116 is configured to display a procedure for resolving an attack event.
[0018] FIG. 3 is an example of an attack scenario AS stored in the storage unit 108 of FIG. 2. The attack scenario AS is a model in which at least one candidate attack is defined for each attack stage. The attack scenario AS shown in FIG. 3 shows eight attack stages S1 to S8 that progress in chronological order, and each of the attack stages S1 to S8 defines a candidate attack that an attacker may select. Specifically, the attack stage S1 defines candidate attack AT1 to AT12, the attack stage S2 defines candidate attack AT1 to AT11, the attack stage S3 defines candidate attack AT1 to AT9, the attack stage S4 defines candidate attack AT1 to AT12, the attack stage S5 defines candidate attack AT1 to AT5, the attack stage S6 defines candidate attack AT1 to AT12, the attack stage S7 defines candidate attack AT1 to AT11, and the attack stage S8 defines candidate attack AT1 to AT11.
[0019] Next, a description will be given of an attack monitoring method that can be implemented by the attack monitoring device 100 having the above configuration. Fig. 4 is a flowchart showing an attack monitoring method according to an embodiment.
[0020] First, in the attack monitoring device 100, the log acquisition unit 102 collects and acquires logs from the device 1 to be monitored (step S100). The logs acquired in step S100 are analyzed by the log analysis unit 104 (step S101). In step S101, the logs acquired in step S100 are analyzed to obtain information about each major event that occurred in the device 1. These events are identified by the event name, source address, destination address, and time (or sequence number) if they are detected by monitoring the communication network 2 (i.e., communication monitoring), and are identified by the event name, occurrence node address, and time (or sequence number) if they are detected within each node that constitutes the device 1.
[0021] 2, the present embodiment describes a case where one device 1 is connected to the communication network 2, but if multiple devices 1 are connected to the communication network 2, attacks can be monitored for the multiple devices 1 by acquiring logs from each device 1 in step S100. In this case, the log acquisition unit 102 may acquire log information from each of the multiple devices 1 and sort this log information in chronological order to acquire logs for all devices 1 to be monitored. This makes it possible to appropriately monitor attacks on each device 1 even when multiple devices are connected to the communication network 2.
[0022] Next, the attack event detection unit 106 detects an attack event AE based on the analysis result of the log analysis unit 104 (step S102), and identifies the attack stage corresponding to the attack event AE (step S103). The attack stage identification in step S103 is performed based on the attack scenario AS stored in the storage unit 108. As described above with reference to FIG. 3, the attack scenario AS defines at least one attack candidate for each attack stage. The attack stage identification unit 110 determines which attack candidate included in the attack scenario AS the attack event AE detected in step S102 corresponds to, and identifies the attack stage to which the attack candidate corresponding to the attack event AE belongs.
[0023] The attack stage identification in step S103 is performed by previously associating the attack candidates in each attack stage defined in the attack scenario AS stored in the memory unit 108 with the attack event AE detected in step S102. This makes it possible to identify the attack stage corresponding to the attack event AE by determining which attack candidate defined for each attack stage in the attack scenario AS the attack event AE detected in step S102 corresponds to.
[0024] Next, the warning display unit 112 displays a warning corresponding to the attack stage identified by the attack stage identification unit 110 (step S104). The warning display in step S104 is performed based on the number of times the attack event AE is detected when it is determined that the attack scenario AS is progressing based on the attack event AE detected in step S102.
[0025] The warning display unit 112 varies the display mode of the warning depending on the number of times an attack event AE is detected. For example, the warning display unit 112 may display the warning so that the importance of the warning increases as the number of times an attack event AE is detected increases. For example, if the number of times an attack event AE is detected is once, a "significance" with an importance level of 1 is displayed; if the number of times an attack event AE is detected is twice, a "warning" with an importance level of 2 is displayed; and if the number of times an attack event AE is detected is three, a "warning" with an importance level of 3 is displayed. In this way, by gradually increasing the importance of the displayed warning depending on the number of times it is detected, the user can easily understand how advanced the cyber-attack that is the basis of the displayed warning is.
[0026] Here, the warning display process in step S104 will be specifically described. Figure 5 is a schematic diagram showing how an attack progresses as attack events AE are repeatedly detected in the attack scenario AS of Figure 3.
[0027] In this example, the attack event detection unit 106 repeatedly detects attack events AE three times in chronological order. The first attack event AE1 detected first is identified by the attack stage identification unit 110 as a candidate attack AT4 in attack stage S2 of the attack scenario AS. The second attack event AE2 detected next is identified by the attack stage identification unit 110 as a candidate attack AT7 in attack stage S4 of the attack scenario AS. The third attack event AE3 detected next is identified by the attack stage identification unit 110 as a candidate attack AT1 in attack stage S7 of the attack scenario AS.
[0028] In this case, the attack stages identified by the attack stage identification unit 110 transition in order from "attack stage S2" to "attack stage S4" to "attack stage S7" in accordance with the attack scenario AS. This means that the attack stages progress in accordance with the attack scenario AS over time. When the warning display unit 112 determines that the attack is progressing in accordance with the attack scenario AS in this way, it counts the number of detections each time an attack event AE is detected and displays a warning according to the number of detections. Specifically, when the first attack event AE1 is detected, the number of detections of the attack event AE is "1," so a "sign" corresponding to severity 1 is displayed as a warning. Next, when the second attack event AE2 is detected, the number of detections of the attack event AE is "2," so a "caution" corresponding to severity 2 is displayed as a warning. Next, when the third attack event AE3 is detected, the number of detections of the attack event AE is "3," so a "warning" corresponding to severity 3 is displayed as a warning.
[0029] In this way, when the progress of an attack is determined in the attack scenario AS based on multiple attack events AE detected by analyzing the log from the device 1, a warning display is performed based on the number of detected attack events AE. This makes it possible to effectively make the user aware of the imminent threat of a cyber-attack by emphasizing the importance of the warning display as the number of detected events increases.
[0030] Furthermore, the count of the number of detections that serves as the basis for displaying a warning may be performed based on the transition of the attack state of the attack event AE detected by the attack event detection unit 106. The attack state is identified based on the attack stage in the attack scenario AS and the level of the hierarchy in which the attack event AE was detected. In this case, the attack display can be performed based on the level of the hierarchy in which the attack event AE was detected in addition to the attack stage as described above, so that the user can be informed, via the warning display, of how deep the attack on the device 1 has progressed in the hierarchy of the device 1.
[0031] FIG. 6 is an example of a warning displayed by the warning display unit 112, and FIG. 7 is a diagram illustrating the transition of attack states corresponding to FIG. 6. This example illustrates a case in which four attack events AE are detected in chronological order by the attack event detection unit 106. The first attack event AE1, which is detected first, is identified by the attack stage identification unit 110 as corresponding to attack stage S2 of the attack scenario AS and occurs in segment SG2 to which the IP address "192.19.21.x" is assigned at level 2. The second attack event AE2, which is detected next, is identified by the attack stage identification unit 110 as corresponding to attack stage S4 of the attack scenario AS and occurs in segment SG2 to which the IP address "192.19.21.x" is assigned at level 2. The third attack event AE3, which is detected next, is identified by the attack stage identification unit 110 as corresponding to attack stage S4 of the attack scenario AS and occurs in segment SG1 to which the IP address "192.19.32.x" is assigned at level 1. The subsequently detected fourth attack event AE4 is identified by the attack stage identification unit 110 as corresponding to attack stage S5 of the attack scenario AS, and occurred in segment SG1 at level 1 to which the IP address "192.19.32.x" is assigned.
[0032] Furthermore, in segment SG0, which is assigned the IP address "192.20.1.x" at level 0, segment SG1, which is assigned the IP address "192.19.31.x" at level 1, segment SG2, which is assigned the IP address "192.19.22.x" at level 2, and segment SG2, which is assigned the IP address "192.10.1.x" at level 3, no attack events were detected, indicating that the status is normal.
[0033] Comparing the first attack event AE1 and the second attack event AE2, it is found that they belong to the same level of segment, and that the attack stage S4 corresponding to the second attack event AE2 is later than the attack stage S2 corresponding to the first attack event AE1, and therefore it is determined that an attack is progressing in accordance with the attack scenario AS. In such a case, as shown in Figure 7, when the third attack event AE3 is detected after the second attack event AE2, the attack state transitions by one stage, and the number of attack event detections is counted as one. As a result, when the first attack event AE1 is detected, the warning display unit 112 displays "Indication" corresponding to severity 1 as a warning, and then when the second attack event AE2 is detected, it displays "Caution" corresponding to severity 2 as a warning.
[0034] Next, comparing the second attack event AE2 and the second attack event AE3, both the second attack event AE2 and the third attack event AE3 correspond to attack stage S4, and the segment SG1 corresponding to the third attack event AE3 is at a level adjacent to the segment SG2 corresponding to the second attack event AE2. In this case, the second attack event AE2 and the third attack event AE3 represent substantially the same attack event, and it is determined that the attack is not progressing. In this case, as shown in FIG. 7, the attack state is passed from one attack scenario AS corresponding to the segment SG2 to which the second attack event AE2 belongs to the other attack scenario AS corresponding to the segment SG1 to which the third attack event AE3 belongs, but this state is maintained and is not counted as the number of attack event AE detections (i.e., the attack state is inherited as is). As a result, when the third attack event AE3 is detected, a warning "Caution" corresponding to severity level 2 is displayed, just as when the second attack event AE2 is detected.
[0035] Next, comparing the third attack event AE3 and the fourth attack event AE4, it is determined that the attack is progressing in accordance with the attack scenario AS because the attack stage S5 corresponding to the fourth attack event AE4 is later than the attack stage S4 corresponding to the third attack event AE3. In such a case, as shown in Figure 7, when the fourth attack event AE4 is detected after the third attack event AE3, the attack state transitions by one stage, and the number of detections of the attack event AE is counted as one. As a result, when the fourth attack event AE4 is detected, a warning "Warning" corresponding to severity level 3 is displayed.
[0036] Furthermore, if the attack stage corresponding to a previously detected attack event AE is earlier in the attack scenario AS than the attack stage corresponding to a later detected attack event AE, the two are not related and do not indicate the progress of the attack scenario AS, so they are not counted as the number of times the attack event AE is detected.
[0037] Furthermore, if the attack stage identification unit 110 identifies multiple attack stages for one attack event AE (for example, if the same attack candidate exists in different attack stages of the attack scenario AS), the attack stage identification unit 110 may identify the smallest attack stage that is larger than the current attack stage.
[0038] In this way, when multiple attack events AE are detected by analyzing the logs collected from device 1, the attack status can be identified based on the attack stage and segment level of each attack event AE, making it possible to evaluate the severity of the cyber-attack on device 1 and display a warning according to the evaluation result. Based on such a warning, when a cyber-attack occurs, the user can conveniently understand to what level device 1 has been attacked, in addition to the progress of the cyber-attack in the attack scenario AS.
[0039] The warning display unit 112 may also display a warning based on a comprehensive evaluation index Y calculated using weighting coefficients from multiple evaluation indexes including at least the number of transitions in the attack state and the importance of the attack stage in the attack scenario AS. In this case, a numerical range that the comprehensive evaluation index Y should take is set according to each importance level of the warning, and a warning is displayed according to the importance level depending on which numerical range the calculated value of the comprehensive evaluation index Y falls within.
[0040] The overall evaluation index Y is calculated as the weighted average using weighting coefficients w1, w2, . . . , wi, where x1, x2, . . . , xi, using the following formula: Y=(w1×x1+w2×x2+···+wi×xi) / (w1+w2+···+wi) For example, when i=3, the evaluation indices x1, x2, and x3 can be set as follows: First evaluation index x1: Number of transitions in the attack state (actual number of detections) Second evaluation index x2: Importance of attack event AE in attack scenario AS 3rd evaluation index x3: Other evaluation items
[0041] The weighting coefficients w1, w2, ..., wi can be set appropriately based on the importance of each evaluation index. Any known method can be used to set the specific weighting coefficients. For example, when the number of evaluation indexes i is large, weighting coefficients can be appropriately set for many evaluation indexes by using, for example, a paired comparison method. Furthermore, as described above, in the embodiment in which a warning is displayed based only on the number of attack event detections, the weighting coefficients w2, ..., wi corresponding to the evaluation indexes x2, ..., xi other than the first evaluation index x1 are essentially the same as when they are set to zero.
[0042] Figure 8 is a calculation example showing the correspondence between the overall evaluation index Y and the warning display when i = 2. In Figure 8, the case where the weighting coefficients are set to w1:w2 = 2:1 is shown on the left as Table 1, and the case where the weighting coefficients are set to w1:w2 = 1:1 is shown on the right as Table 2. In addition, the "Sign" display corresponding to severity level 1 is set to the numerical range 0≦Y<2, the "Caution" display corresponding to severity level 2 is set to the numerical range 2≦Y<3, and the "Warning" display corresponding to severity level 3 is set to the numerical range 3≦Y. Comparing the two shows that the likelihood of displaying a warning of high importance can be adjusted by changing the way the weighting coefficients are set, even if the evaluation index value is the same.
[0043] In this embodiment, since the warning display is performed based on the value of the overall evaluation index Y, for example, even if the number of times an attack event is detected is one, depending on the value of the overall evaluation index Y, a "Caution" corresponding to importance level 2 or a "Warning" corresponding to importance level 3 may be displayed. This makes it possible to display a warning of high importance depending on the content of the attack, even if the number of times an attack event is detected is small.
[0044] The overall evaluation index Y is calculated each time an attack event is detected, and when a new overall evaluation index Y is calculated, the larger of the previous values is used. This is to avoid situations where, for example, the warning display changes from "Sign" to "Caution" to increase its importance, and then returns to "Sign" to decrease its importance, which would be unnatural to the user.
[0045] Furthermore, the reset unit 114 can be operated by the user to reset the number of detections made by the attack event detection unit 106. For example, when a response to a cyber attack monitored by the attack monitoring device 100 described above has been completed, the reset unit 114 can reset the warning display to its initial state, allowing resetting at any time.
[0046] Furthermore, when a warning display is issued by the warning display unit 112, the resolution procedure display unit 116 may, as necessary, display to the user a procedure for resolving the attack event related to the warning display. FIG. 9 is an example of a display of the resolution procedure by the resolution procedure display unit 116 of FIG. 2. In this example, the resolution procedure is displayed in a flowchart format as a link to the warning display by the warning display unit 112. Specifically, in the display example of FIG. 9, as the resolution procedure, first, fact-checking is performed to confirm the details of the attack (step S200), and initial responses such as situation assessment, temporary measures, communication shutdown, and operation suspension are performed (step S201). Next, as incident management, information is shared (step S202), and whether or not an analysis of the entire attack is necessary is determined (step S203). Then, the entire attack is analyzed as needed (step S204), and countermeasures are planned (step S205). Then, countermeasures are implemented and recovery is performed (step S206), and a report is shared as incident management (step S207), and convergence processing is performed (step S208). These steps are displayed for each main party (incident response organization, specialized analysis organization, security officer, etc.), allowing users to easily understand the steps to resolve an attack event by referring to the display.
[0047] As described above, according to the above embodiment, multiple attack events AE are detected by analyzing logs collected from the device 1. Each attack event AE is compared with attack candidates defined for each attack stage of the attack scenario AS, thereby identifying which attack stage of the attack scenario AS it corresponds to. As a result, if it is determined that the attack scenario AS is progressing, a warning based on the number of attack events AE detected is displayed. This allows the user to recognize the attack and understand not only that an attack event AE has been detected, but also whether the attack event AE corresponds to the progress of the attack scenario AS.
[0048] In addition, within the scope of the present disclosure, the components in the above-described embodiments may be replaced with well-known components as appropriate, and the above-described embodiments may be combined as appropriate.
[0049] The contents described in each of the above embodiments can be understood, for example, as follows.
[0050] (1) An attack monitoring device (100) according to one aspect includes: an attack event detection unit (106) for detecting a plurality of attack events (AEs) by analyzing logs collected from at least one device connected to the communication network (2); an attack stage identification unit (110) for identifying an attack stage corresponding to each of the plurality of attack events based on an attack scenario (AS) in which at least one attack candidate is defined for each attack stage; a warning display unit (112) for displaying a warning based on the number of times the attack events are detected when it is determined that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events; Equipped with.
[0051] According to the above aspect (1), multiple attack events are detected by analyzing logs collected from devices. Each attack event is compared with attack candidates defined for each attack stage of an attack scenario, thereby identifying which attack stage among the attack events it corresponds to. As a result, if it is determined that an attack scenario is progressing based on the attack stages corresponding to multiple attack scenarios, a warning based on the number of attack events detected is displayed. This allows the user to recognize an attack and understand not only that an attack event has been detected, but also whether the attack event corresponds to the progress of the attack scenario.
[0052] (2) In another embodiment, in the above embodiment (1), the device includes a plurality of segments, each of which has a level corresponding to a hierarchical depth in the communication network; The warning display unit displays the warning based on the attack state specified based on the attack stage and the level.
[0053] According to the above aspect (2), a warning is displayed based on the attack stage defined in the attack scenario and the level of the segment that constitutes the device. Based on this warning, the user can understand the importance of the detected attack event based on not only the progress in the attack scenario but also the hierarchical depth of the segment in which the attack event was detected.
[0054] (3) In another embodiment, in the above embodiment (2), The attack state is defined in stages according to the progress of the attack, and transitions based on the number of detections.
[0055] According to the above aspect (3), the warning display is performed in stages based on the attack state transition according to the number of attack events detected, so that the user can easily grasp the importance of the detected attack event by recognizing the warning.
[0056] (4) In another embodiment, in the above embodiment (3), the plurality of attack events include a first attack event and a second attack event detected after the first attack event; In the attack scenario, if the attack stage corresponding to the second attack event is the same as the attack stage corresponding to the first attack event, and the segment corresponding to the first attack event and the segment corresponding to the second attack event are adjacent, the attack state is maintained.
[0057] According to the above aspect (4), when a first attack event and a second attack event corresponding to the same attack stage in an attack scenario are detected as attack events, if the two events correspond to adjacent segments, they essentially represent the same attack event, and therefore the attack state is maintained regardless of the number of times the attack events are detected.
[0058] (5) In another embodiment, in any one of the above (2) to (4), The warning display unit displays the warning based on a comprehensive evaluation index calculated using a weighting coefficient from evaluation indexes including at least the number of transitions of the attack state and the importance of the attack stage in the attack scenario.
[0059] According to the above aspect (5), a warning is displayed based on the overall evaluation index calculated using a weighting coefficient from other evaluation indexes in addition to the number of transitions in the attack state. The evaluation index includes at least the importance of the attack stage in the attack scenario, so that a warning display can be made that reflects the importance of the attack stage as perceived by the user.
[0060] (6) In another embodiment, in any one of the above (1) to (5), The log is configured by sorting log information collected from the plurality of devices in chronological order.
[0061] According to the above aspect (6), attack events are detected based on a log in which log information collected from multiple devices is sorted in chronological order, thereby making it possible to appropriately monitor attacks on multiple devices connected to a communication network.
[0062] (7) In another embodiment, in any one of the above (1) to (6), The device further includes a reset unit (114) for resetting the number of times of detection.
[0063] According to the above aspect (7), by resetting the number of times an attack event has been detected, it is possible to restart attack monitoring once again, for example, when a detected attack event has been dealt with.
[0064] (8) In another embodiment, in any one of the above (1) to (7), The system further comprises a resolution procedure display unit (116) for displaying a procedure for resolving the attack event.
[0065] According to the above aspect (8), the procedure for resolving the attack event corresponding to the warning is displayed, and the user can easily understand the procedure for resolving the attack event by referring to the display.
[0066] (9) In another embodiment, in any one of the above (1) to (8), The at least one device comprises: a communication device for accessing the communication network; a facility capable of transmitting and receiving data to and from the communication network via the communication device; Includes:
[0067] According to the above aspect (9), it is possible to suitably monitor advanced cyber attacks in so-called OT and IT fusion equipment that is equipped with facilities capable of sending and receiving data to and from a communication network via communication equipment.
[0068] (10) An attack monitoring method according to one aspect includes: Detecting a plurality of attack events (AEs) by analyzing logs collected from at least one device connected to a communication network; identifying an attack stage corresponding to each of the plurality of attack events based on an attack scenario (AS) in which at least one attack candidate is defined for each attack stage; a step of displaying a warning based on the number of detected attack events when it is determined that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events; Equipped with.
[0069] According to the above aspect (10), multiple attack events are detected by analyzing logs collected from devices. Each attack event is compared with attack candidates defined for each attack stage of an attack scenario, thereby identifying which attack stage among the attack events it corresponds to. As a result, if it is determined that an attack scenario is progressing based on the attack stages corresponding to multiple attack scenarios, a warning based on the number of attack events detected is displayed. This allows the user to recognize an attack and understand not only that an attack event has been detected, but also whether the attack event corresponds to the progress of the attack scenario. [Explanation of symbols]
[0070] 1 equipment 2. Communication Network 6 Plant Facilities 8 Remote Monitoring Center 10 Controlled Equipment 16 Operational Management System 18,20 Server 19 Remote Monitoring System 21 Cloud Server 22 IT Security Systems 24 OT Security System 100 Attack Monitoring Device 102 Log acquisition unit 104 Log Analysis Department 106 Attack Event Detection Unit 108 Storage section 110 Attack Stage Identification Unit 112 Warning display section 114 Reset section 116 Resolution procedure display section
Claims
1. an attack event detection unit for detecting a plurality of attack events by analyzing a log collected from at least one device connected to a communication network; an attack stage identification unit for identifying an attack stage corresponding to each of the plurality of attack events based on an attack scenario in which at least one attack candidate is defined for each attack stage; a warning display unit for displaying a warning based on the number of detected attack events when it is determined that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events; Equipped with the device includes a plurality of segments, each of which has a level corresponding to a hierarchical depth in the communication network; The warning display unit displays the warning based on the attack status identified based on the attack stage and the level.
2. The attack monitoring device according to claim 1 , wherein the attack state is defined in stages corresponding to the progress of the attack, and transitions based on the number of detections.
3. the plurality of attack events include a first attack event and a second attack event detected after the first attack event; 3. The attack monitoring device of claim 2, wherein the attack state is maintained when, in the attack scenario, the attack stage corresponding to the second attack event is the same as the attack stage corresponding to the first attack event, and the segment corresponding to the first attack event and the segment corresponding to the second attack event are adjacent.
4. An attack monitoring device as described in any one of claims 1 to 3, wherein the warning display unit displays the warning based on a comprehensive evaluation index calculated using a weighting coefficient from an evaluation index that includes at least the number of transitions in the attack state and the importance of the attack stage in the attack scenario.
5. 5. The attack monitoring device according to claim 1, wherein the log is configured by sorting log information collected from a plurality of the devices in chronological order.
6. The attack monitoring device according to claim 1 , further comprising a reset unit for resetting the number of detections.
7. The attack monitoring device according to claim 1 , further comprising a resolution procedure display unit for displaying a procedure for resolving the attack event.
8. The at least one device a communication device for accessing the communication network; a facility capable of transmitting and receiving data to and from the communication network via the communication device; 8. An attack monitoring device according to claim 1, comprising:
9. An attack monitoring method implemented using the attack monitoring device according to any one of claims 1 to 8, detecting a plurality of attack events by analyzing a log collected from at least one device connected to a communication network by the attack event detection unit; a step of identifying, by the attack stage identification unit, the attack stage corresponding to each of the plurality of attack events detected by the attack event detection unit based on an attack scenario in which at least one attack candidate is defined for each attack stage; a step of displaying a warning based on the number of times the attack events are detected when the warning display unit determines that the attack scenario is progressing based on the transition of the attack stages corresponding to the plurality of attack events identified by the attack stage identification unit; The attack monitoring method comprises:
Citation Information
Patent Citations
High pressure sodium discharge lamp
JP1986004149A
Illegitimate access detecting apparatus, illegitimate access detecting method, and illegitimate access detecting program
JP2005136526A
Attack countermeasure device, attack countermeasure method, and attack countermeasure program
JP2013121008A
Attack detection system, attack detection apparatus, attack detection method, and attack detection program
JP2015179979A
Unauthorized access detection apparatus, unauthorized access detection program, and unauthorized access detection method
WO2003100619A1