Security risk assessment support method and security risk assessment support system

The security risk assessment support system addresses the challenge of comprehensive threat identification in complex systems by generating and presenting attack scenarios based on functional models, ensuring thorough risk assessment without specialized knowledge.

JP7829450B2Active Publication Date: 2026-03-13HITACHI LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-02
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Conventional security risk assessment methods struggle to comprehensively identify threats to complex systems, especially when they consist of multiple domains, and require specialized knowledge of attack methods to ensure comprehensiveness, making it difficult for non-experts to validate threat coverage.

Method used

A security risk assessment support system that searches for attack paths, generates attack scenarios based on functional models of component devices, and presents these scenarios to users, enabling comprehensive threat identification without requiring detailed knowledge of attack methods.

Benefits of technology

The system allows for thorough identification and presentation of threats to complex systems, facilitating comprehensive risk assessment even for non-security experts, and highlighting key areas requiring countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007829450000001
    Figure 0007829450000001
  • Figure 0007829450000002
    Figure 0007829450000002
  • Figure 0007829450000003
    Figure 0007829450000003
Patent Text Reader

Abstract

To grasp all threats to a target system, in security risk assessment.SOLUTION: A security risk assessment assistance method includes: a configuration information input step that receives an input of configuration information regarding a target system configured to include component devices; and an attack route search step that searches for attack routes of attacks to the target system through the component devices. The security risk assessment assistance method includes an attack scenario generation step which generates an attack scenario composed of attack routes arranged in the order in which the attacks pass through the component devices, estimates attack types corresponding to interference modes of the attacks that interfere with operations of the component devices constituting the attack routes, based on a functional model which represents configuration of the component devices in terms of functions, and reflects the estimated attack types to the attack scenario. The security risk assessment assistance method includes an attack scenario presentation step which presents the attack scenario.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a security risk assessment support method and a security risk assessment support system.

Background Art

[0002] Regardless of whether it is an information system (IT system) or a control system (OT system) such as social infrastructure and industry, a security risk assessment is performed in order to implement appropriate security measures for the system. It is important to accurately identify security threats in the target system and a series of impacts caused by these threats through security risk assessment.

[0003] Since the result of security risk assessment greatly affects the subsequent security measure planning and implementation process, attempts have been made to perform it based on objective criteria. For example, Patent Document 1 discloses that "attack route information (21) includes information on attack routes including one or more attack steps including an attack source, an attack destination, and an attack method. Vulnerability identification means (11) refers to the attack route information (21) and identifies vulnerabilities used in the attack on the attack destination in the attack step. The vulnerability information DB (22) stores in association a vulnerability and the presence or absence of an attack verification code for the vulnerability. The diagnostic evaluation generation means (12) refers to the vulnerability information DB (22), checks whether there is an attack verification code for the identified vulnerability, and generates a risk diagnostic evaluation including the number of identified vulnerabilities and the presence or absence of an attack verification code for the attack step."

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] When a vendor sells a system, or when an operator obtains third-party certification for the system's security, proof is required that threats have been accurately identified and mitigated through a security risk assessment. In particular, it is crucial that all threats to the target system are identified without exception (comprehensiveness). If any threats remain unidentified, it cannot be claimed that appropriate measures have been taken, no matter how rigorously other threats are addressed.

[0006] However, conventional security risk assessment methods use specific attack methods such as "unauthorized manipulation" and "data tampering" as components of attack scenarios (corresponding to a series of attack steps occurring along the attack path in Patent Document 1). Therefore, knowledge of specific attack methods is necessary to understand the attack scenarios obtained through security risk assessment. Furthermore, the attack methods referenced in conventional methods are merely a collection of known attack methods, and it is difficult for non-security experts to determine whether they cover all possible attack methods. In other words, it is difficult to claim comprehensiveness of threats to the target system when attack scenarios are described using specific attack methods.

[0007] Furthermore, when the target system consists of multiple domains (for example, wide-area infrastructure such as railways or roads with multiple operating entities, or structures such as such infrastructure and service businesses that utilize it), the preconditions such as threat sources and conditions for damage caused by attacks may differ for each domain, making it more difficult to comprehensively cover threats to the entire system.

[0008] This invention has been made in consideration of the above points, and aims to provide a security risk assessment support method and a security risk assessment support system that can comprehensively grasp threats to a target system. [Means for solving the problem]

[0009] To solve the above-mentioned problems, one aspect of the present invention provides a security risk assessment support method executed by a security risk assessment support system, comprising: a configuration information input step of receiving configuration information relating to a target system comprising component devices; an attack path search step of searching for attack paths in which an attack against the target system passes through the component devices based on the configuration information; an attack scenario generation step of arranging the attack paths in the order in which the attack passes through the component devices to generate an attack scenario, estimating which type of attack corresponds to the form in which the operation of the component devices constituting the attack path is inhibited by the attack, based on a functional model that represents the configuration of the component devices in terms of function, and reflecting the estimated attack type in the attack scenario; and an attack scenario presentation step of presenting the attack scenario generated by the attack scenario generation step. [Effects of the Invention]

[0010] According to the present invention, threats to the target system can be fully identified in a security risk assessment. [Brief explanation of the drawing]

[0011] [Figure 1] A diagram showing the configuration of the system being analyzed. [Figure 2] A diagram showing the configuration of the components of the system being analyzed. [Figure 3] A diagram illustrating the functional model of the constituent components. [Figure 4] A diagram illustrating, using a functional model, the forms in which the expected and intended operation of the constituent components is hindered. [Figure 5] A diagram showing a correspondence table between combinations of operating elements and inhibition modes, and attack methods. [Figure 6] A diagram showing the correspondence between attack methods and the events that may occur as a result of the attack. [Figure 7] A diagram showing the configuration of a security risk assessment support system. [Figure 8] Flowchart showing a risk assessment process. [Figure 9] Diagram showing the configuration of the analysis target system, the functional models of each component device constituting the analysis target system, and the device configuration information. [Figure 10] Diagram showing the menu display and configuration diagram display of the device configuration information input GUI. [Figure 11] Diagram showing an example of information input to the device configuration information input GUI. [Figure 12] Diagram showing the scenario information display GUI 16D2 for displaying attack scenario information. [Figure 13] Diagram for explaining the attack stage. [Figure 14] Diagram for explaining the inhibition form and attack means estimation. [Figure 15] Diagram showing the detailed processing confirmation screen of attack scenario information. [Figure 16] Diagram for explaining the detailed information input process. [Figure 17] Diagram showing the detailed information of the attack means and the generated events. [Figure 18] Diagram showing the detailed attack scenario information.

Embodiments for Carrying Out the Invention

[0012] Hereinafter, embodiments of the technology disclosed in the present application will be described with reference to the drawings. The embodiments are examples for explaining the present application including the drawings. In the embodiments, for the sake of clarity of explanation, appropriate omissions and simplifications are made. Unless otherwise particularly limited, each component of the embodiments may be singular or plural.

[0013] The same or similar components are given the same reference numerals, and the description in later embodiments for those already described may be omitted or may be made focusing on the differences.

[0014] When there are multiple identical or similar components, they may be distinguished and explained by assigning different subscripts to the same symbol. Furthermore, when there is no need to distinguish between these multiple components, the subscripts may be omitted in the explanation.

[0015] In the following embodiments, various types of information are described in table format, but these types of information may be in data formats other than table format. Also, various names such as "XX information," "XX table," "XX list," and "XX queue" are interchangeable. For example, "XX information" may be called "XX table." Furthermore, when describing identification information, expressions such as "identification information," "identifier," "name," "ID," and "number" are interchangeable.

[0016] [Embodiment] (System Configuration) First, we will explain the system under consideration (hereinafter referred to as SuC) which is the target of the risk assessment. Figure 1 shows the configuration of SuC10. Figure 2 shows the configuration of the components 100 of SuC10. SuC10 is, for example, a control system, but is not limited to this, and may be an information processing system or other system.

[0017] SuC10 includes component devices 100a, 100b, 100c, and 100d. The component devices 100 are interconnected within SuC10. Each component device 100 also has input interfaces 101a, 101b, ... and output interfaces (not shown), as shown in Figure 2. Input interfaces 101 are used for interconnecting the component devices 100 and for connecting SuC10 to the outside. The number of component devices 100 and input interfaces 101 in this embodiment is merely illustrative. The number of component devices 100 and input interfaces 101 will differ for each SuC10.

[0018] (Definition of attack types) In this embodiment, attack methods that may occur in an attack scenario are identified by an "attack type" defined by the function of the component device 100 that is disrupted by the attack and the form of disruption of that function. The concept is explained below.

[0019] Figure 3 is a diagram illustrating the functional model M100 of the component equipment 100. Functional model M100 includes control devices such as PLCs (Programmable Logic Controllers) and processing devices (computers). Functional model M100 omits specific elements such as the actual hardware. Functional model M100 represents the configuration of component equipment 100 from a functional perspective.

[0020] The functional model M100 is given appropriate "operating elements" to achieve the expected operation. In this embodiment, the operating elements include "logic" M101 such as programs and control rules, "input" M102 provided by sensors and the user, and "output" M103 output by the functional model M100. Depending on the type of component represented by the functional model M100, there may be operating elements other than "logic," "sensors," "input," and "output." Furthermore, "logic," "sensors," "input," and "output" may be further subdivided and defined.

[0021] An attack on a component can be understood as an attack that disrupts the expected operation of the component by applying something "unintended" to its operating elements, such as logic or inputs. "Unintended" means that various attributes of the operating elements, such as data format, processing timing, and various values, contradict or deviate from those defined in the operating specifications of the component.

[0022] Figure 4 is a diagram illustrating, using a functional model, the forms in which the expected and intended operation of the component device 100 is inhibited. The forms in which the intended operation of the component device 100 is inhibited by the introduction of "unintended" operating elements as described above can be classified into three forms of inhibition, as shown in Figure 4, for example: (a) invalid input of an invalid operating element, (b) modification of the input operating element (falsified), and (c) input of an operating element from an untrusted source (untrusted).

[0023] (a) is a form of disruption in which an unintended operational element ae1 is generated for some reason in the attacking device (device model M100A-a) and is applied to the victim's device (device model M100V-a).

[0024] (b) is a form of disruption in which the operational element ae2, which is transmitted from the attacking device (device model M100A-b) to the victim's device (device model M100V-b), is modified unintended for some reason.

[0025] (c) is a form of interference in which an unintended operating element ae3 is generated in a component (component model M100A-c) that is not specified to be connected to the affected component (component model M100V-c), and is applied to the affected component.

[0026] Furthermore, in the attack types described above, the way in which the operation of the constituent devices is disrupted differs depending on which layer the unintended malicious input of an operating element corresponds to. For this reason, in conventional attack classifications, even if the malicious input of an operating element is the same, different layers were considered to be different attacks. However, in this embodiment, if the malicious input of an operating element is the same, it can be represented in a way that encompasses different layers.

[0027] For example, in a PLC, the data referred to as "input" may include not only the pure input values ​​to the control logic (corresponding to the application layer in the OSI model), but also the data format (corresponding to the presentation layer), protocol headers (corresponding to the session layer, network layer, etc.), and so on. If any of these are of an unintended nature, it can manifest as different attacks such as unintended control outputs, buffer overflows, or replay attacks.

[0028] Furthermore, the range of attack methods can be expanded by adding attributes to operational elements, such as allowing eavesdropping to be selected as an attack method when the "input" is "unencrypted."

[0029] Figure 5 is a diagram showing the Attack Means Correspondence Information 201, which indicates the correspondence between combinations of operating elements ("logic" and "input") and inhibition forms ((a) to (c) in Figure 4) and attack means. Attack Means Correspondence Information 201 shows "Attack Means 1" to "Attack Means 6" corresponding to each combination of operating elements and inhibition forms in Figure 4. Attack Means Correspondence Information 201 shows the type or overview of attacks that may occur with combinations of operating elements handled by the input I / F 101 of the configuration device 100 and inhibition forms (the above-mentioned (a) to (c)) of the connection between this input I / F and the preceding configuration device 100, as well as the type or overview of events that may occur as a result of the attack. Attack Means Correspondence Information 201 is stored in the storage device 13 (Figure 7) of the security risk assessment support system 1.

[0030] Figure 6 shows the event response information 202, which indicates the correspondence between attack methods and events that may occur as a result of the attack. The event response information 202 shows the type or overview of the "events that may occur as a result of the attack" corresponding to each of the attack methods 1 to 6 in Figure 5. The "events that may occur as a result of the attack" include a score for each event, which expresses the degree of security risk to the target system caused by the attack on a scale of 1 to 5, for example. In Figure 6, the numbers in parentheses next to each event correspond to this score. The event response information 202 is stored in the storage device 13 (Figure 7) of the security risk assessment support system 1.

[0031] (Configuration of the security risk assessment support system) Figure 7 shows the configuration of Security Risk Assessment Support System 1. Security Risk Assessment Support System 1 is implemented by a computer executing a risk assessment support program. Security Risk Assessment Support System 1 is an on-premise or cloud-based system.

[0032] The security risk assessment support system 1 comprises a processor 11, memory 12, storage device 13, communication device 14, input device 15, and output device 16. The processor 11, memory 12, storage device 13, communication device 14, input device 15, and output device 16 are interconnected via internal communication lines such as a bus.

[0033] The processor 11 controls the overall operation of the security risk assessment support system 1 as a computer. The memory 12 is composed of, for example, volatile semiconductor memory and is used as the work memory of the processor 11.

[0034] The storage device 13 is an example of a computer-readable non-temporary storage medium and consists of a large-capacity non-volatile storage device such as a hard disk drive, SSD (Solid State Drive), or flash memory. The storage device 13 stores device configuration information 200 (Figure 9), attack means response information 201 (Figure 5), incident response information 202 (Figure 6), detailed information 203 (Figure 16), detailed information 204 (Figure 17), and attack scenario information 205 (Figures 12 and 18). Note that the device configuration information 200, attack means response information 201, incident response information 202, detailed information 203, detailed information 204, and attack scenario information 205 may be stored in memory 12.

[0035] Furthermore, the storage device 13 stores various programs and data. Programs stored in the storage device 13 are loaded into the memory 12 when the security risk assessment support system 1 is started or when necessary, and executed by the processor 11. As a result, the processor 11 implements the following functions: the device configuration information input unit 111, the attack path search unit 112, the attack scenario generation unit 113, and the attack scenario presentation unit 114. The processing functions of the device configuration information input unit 111, the attack path search unit 112, the attack scenario generation unit 113, and the attack scenario presentation unit 114 will be described later with reference to the flowchart in Figure 8.

[0036] The program executed by the processor 11 may be recorded on a non-temporary recording medium, read from the non-temporary recording medium by a media reader, and loaded into memory 12. Alternatively, the executable program may be obtained from an external computer via a network and loaded into memory 12.

[0037] The communication device 14 is an interface device for the security risk assessment support system 1, which functions as a computer, to communicate with other computers. The communication device 14 is composed of, for example, a NIC (Network Interface Card) such as a wired LAN (Local Area Network) or a wireless LAN.

[0038] The input device 15 consists of a keyboard, a pointing device such as a mouse, a touch device, etc., and is used by the user to input various instructions and information into the security risk assessment support system 1. The output device 16 consists of a display device such as a liquid crystal display or an organic EL (Electro Luminescence) display, or an audio output device such as a speaker, and is used to present necessary information to the user when needed.

[0039] Figure 7 shows an example where the security risk assessment support system 1 is implemented on a single computer. However, the security risk assessment support system 1 is not limited to this, and may be implemented by distributing each processing function across multiple computers that are connected to each other in a communicative manner.

[0040] (Risk assessment process) Figure 8 is a flowchart of the risk assessment process. The security risk assessment support system 1 executes the risk assessment process in response to user instructions.

[0041] First, in step S1, the device configuration information input unit 111 (Figure 7) receives input of the device configuration of SuC10 from the user and executes a device configuration information input process to create device configuration information 200.

[0042] The device configuration information input process in step S1 will be explained with reference to Figures 9 to 11. Figure 9 is a diagram showing the configuration of SuC10, the functional model M100 of each component device 100 that constitutes SuC10, and the device configuration information 200. As shown in Figure 9, in step S1, based on the functional model M100 of each component device 100 that constitutes SuC10, device configuration information 200 is created for each component device 100, which has the items "device ID", "device name", "number of inputs", "input I / F1", "input I / F2", ... "output destination". "Input I / F1", "input I / F2", ... include the "ID" and "name" of each input I / F and the "operational elements" handled by the corresponding input I / F. In the device configuration information input process, the configuration information of the component devices 100 is input according to the functional model M100. By inputting the configuration information of the component device 100 according to the functional model M100, attack scenarios can be evaluated even without detailed knowledge of the specifications and security vulnerabilities of SuC10 and the component device 100.

[0043] Figure 10 shows the menu display 300 and configuration diagram display 310 of the device configuration information input GUI (Graphical User Interface) 16D1. In step S1, the device configuration information input unit 111 displays the device configuration information input GUI 16D1 on the display screen of the output device 16. The device configuration information input GUI 16D1 includes a menu display 300 and a configuration diagram display 310. The menu display 300 includes a device configuration creation button 301, an input I / F creation button 302, an input / output relationship creation button 303, an erase button 304, and a setting button 305.

[0044] The component creation button 301 is used to create SuC10 and component 100 on the configuration diagram display 310. When the component creation button 301 is turned on, SuC10 or component 100 will be created at the clicked location. Also, when the component creation button 301 is turned on, component 100 will be created inside SuC10 when clicked.

[0045] The input interface creation button 302 is used to create the input interface 101 for the device 100 on the configuration diagram display 310. When the input interface creation button 302 is turned ON, the input interface 101 is created at the clicked position.

[0046] The input / output relationship creation button 303 is used to create an input / output relationship 102 between the constituent devices 100. When the input / output relationship creation button 303 is turned on, the input / output relationship 102 between the constituent devices 100 is created at the location where it is dragged (or swiped).

[0047] The erase button 304 is used to erase the component 100, input I / F 101, and input / output relationship 102 from the configuration diagram display 310. When the erase button 304 is turned ON, the component 100, input I / F 101, and input / output relationship 102 at the clicked position will be erased.

[0048] The setting button 305 is a button that transitions to an input screen that accepts input of various setting information for the device configuration information input GUI 16D1.

[0049] The user operates the buttons on the menu display 300 to create a configuration diagram display 310 of a SuC10 having, for example, the components 100, input I / F 101, and input / output relationships 102, as shown in Figure 10, in the equipment configuration information input GUI 16D1. The information of the components 100, input I / F 101, and input / output relationships 102 of the ScU10 for which the configuration diagram display 310 has been created in the equipment configuration information input GUI 16D1 is automatically reflected in the equipment configuration information 200 for each ScU10.

[0050] Figure 11 shows an example of information input to the device configuration information input GUI 16D1. When a new ScU10 is created on the configuration diagram display 310 of the device configuration information input GUI 16D1, a template for device configuration information 200 corresponding to the newly created ScU10 is created.

[0051] On the configuration diagram display 310 of the device configuration information input GUI 16D1, when a device 100 is created inside ScU10, a row for device configuration information 200 corresponding to the newly created device 100 is created. On the configuration diagram display 310 of the device configuration information input GUI 16D1, when an input I / F 101 is created inside device 100, the "ID," "Name," and "Operating Element" fields of the device configuration information 200 corresponding to the newly created input I / F 101 are created. The values ​​for each of the "ID," "Name," and "Operating Element" fields in the device configuration information 200 are entered by the user.

[0052] Furthermore, when an input / output relationship 102 for a component device 100 is newly created on the configuration diagram display 310 of the equipment configuration information input GUI 16D1, a row for the equipment configuration information 200 related to the newly created input / output relationship 102 is created. For example, as shown in Figure 10, double-clicking on a component device 100c on the configuration diagram display 310 displays the equipment configuration information 200 in a pop-up window. It becomes possible to input information into the row corresponding to component device 100c in the equipment configuration information 200 that is displayed in the pop-up window. The information is entered into the row corresponding to component device 100c in the equipment configuration information 200 according to the equipment model (not shown) of component device 100c.

[0053] Specifically, since the input I / F 101c-1 of component 100c is an "input" operating element, "101c-1", "input1", and "input" are input to the "ID", "Name", and "Operating Element" of "Input I / F1" corresponding to input I / F 101c-1. Similarly, since the input I / F 101c-2 of component 100c is an "input" operating element, "101c-2", "input2", and "input" are input to the "ID", "Name", and "Operating Element" of "Input I / F2" corresponding to input I / F 101c-2. In addition, the output of component 100c is input to the input I / F 101d-1 of component 100d. Therefore, "101d-1" is input to the "Output Destination" of component 100c.

[0054] Furthermore, the operating element of the input I / F 101d-2 of component 100d is "logic (maintenance)". Therefore, in the row for "Device ID" "100d" in the device configuration information 200 in Figure 11, "101c-2", "maintenance", and "logic" are entered for "ID", "Name", and "Operating Element" of "Input I / F2". Also, the output of component 100d is an output to the outside of SuC10. Therefore, "SYSOUT" is entered for the "Output Destination" of component 100d.

[0055] Furthermore, information about the input I / F 101 for which an input / output relationship 102 has been created on the configuration diagram display 310 of the device configuration information input GUI 16D1 is automatically reflected in the device configuration information 200. For example, if the output destination of device 100c is connected to the input I / F 101d-1 of device 100d on the configuration diagram display 310 of the device configuration information input GUI 16D1, then the input I / F 101d-1 will also be stored in the "Output Destination" column of the device configuration information 200 row in the pop-up display corresponding to device 100c. Conversely, if the connection destination of the input I / F 101 is stored in the table of device configuration information 200, it will be reflected on the configuration diagram display 310 of the device configuration information input GUI 16D1.

[0056] Next, in step S2, the attack path search unit 112 performs an attack path search process based on the device configuration information 200 created in step S1. Based on the device configuration information 200 created in step S1, the attack path search unit 112 searches for candidate attack paths in the SuC10 by tracing the connections between the configuration devices 100 that exist between the input I / F 101 connected to the outside of the SuC10 and the output I / F (SYSOUT) connected to the outside of the SuC10.

[0057] In the example of SuC10 and device configuration information 200 shown in Figure 9, three attack paths are identified. Specifically, attack path 1: external → component 100a → component 100c → component 100d → external, attack path 2: external → component 100b → component 100c → component 100d → external, and attack path 3: external → attack path 3: component 100d → external.

[0058] Next, in step S3, the attack scenario generation unit 113 executes an attack scenario generation process that includes estimating "attack means" and "events that may occur as a result of the attack" based on the results of the attack path search process in step S3. For example, suppose that three attack paths, attack paths 1 to 3, are identified based on the equipment configuration information 200 shown in Figure 9. The attack scenario generation unit 113 generates attack scenario information 205 that includes attack scenarios AS1, AS1, and AS3 corresponding to each attack path.

[0059] Figure 12 shows the scenario information display GUI 16D2 which displays attack scenario information 205. As shown in Figure 12, the attack scenario information 205 has the following items: "Attack Scenario ID", "Attack Stage ID", "Attack Source Device ID", "Attack Target Device ID", "Attack Target Input I / F_ID", "Detailed Device Connection Configuration", "Predicted Attack Configuration", "Attack Method", and "Events that may occur as a result of the attack".

[0060] The "attack scenario ID" is the identification information for an attack scenario, and an ID is assigned to each attack path identified based on the device configuration information 200. In the example in Figure 12, the "attack scenario IDs" of the attack scenarios created for each of the three attack paths identified based on the device configuration information 200 (Figure 9) are attack scenarios AS1, AS2, and AS3. An attack scenario is a list of attack paths arranged in the order in which the attack passes through the configured device 100.

[0061] The "Attack Stage ID" is the identification information for each attack stage that makes up each attack scenario. Figure 13 is a diagram illustrating the attack stages. Attack scenario AS1, illustrated in Figure 12, corresponds to attack path 1: External → Component 100a → Component 100c → Component 100d → External. Therefore, attack scenario AS1 consists of three attack stages, as shown in Figure 13: Attack Stage AS1-1: External → Component 100a, Attack Stage AS1-2: Component 100a → Component 100c, and Attack Stage AS1-3: Component 100c → Component 100d. In attack scenario AS2 and beyond, which is the second stage, component 100 that was attacked in the previous stage becomes a stepping stone to trigger an attack on component 100 in the next stage due to malfunction caused by the attack or malicious operation by the attacker.

[0062] The attack scenario is generated by listing the predicted attack patterns for each component device 100, in the order in which the data passes through each component device 100.

[0063] The "Source Device ID" and "Target Device ID" indicate the source and target devices 100 in the attack path of the relevant attack stage. As can be seen from Figure 13, in attack stage AS1-1, an external attacker is the direct source of the attack and device 100a is the target, so the "Source Device ID" is "attacker (external)" and the "Target Device ID" is device 100a. Similarly, in attack stage AS1-2, device 100a is the source of the attack and device 100c is the target, so the "Source Device ID" is device 100a and the "Target Device ID" is device 100c. Similarly, in attack stage AS1-3, device 100c is the source of the attack and device 100d is the target, so the "Source Device ID" is device 100c and the "Target Device ID" is device 100d.

[0064] The "Target Input I / F_ID" indicates the input I / F 101 of the target device 100 in the attack path of the relevant attack stage. As can be seen from Figure 13, in attack stage AS1-1, the source and target of the attack is the input I / F 101a-1 of device 100a, so the "Target Input I / F_ID" is input I / F 101a-1. Similarly, in attack stage AS1-2, the source and target of the attack is the input I / F 101c-1 of device 100c, so the "Target Input I / F_ID" is input I / F 101c-1. Similarly, in attack stage AS1-3, the source and target of the attack is the input I / F 101d-1 of device 100d, so the "Target Input I / F_ID" is input I / F 101d-1.

[0065] The "Configuration Device Connection Configuration Details" is information stored based on the detailed information 203 that is entered through the detailed information addition input process described later (step S6 in Figure 8). Immediately after step S3 is executed, the "Configuration Device Connection Configuration Details" contains "(Not Entered)" because the detailed information 203 has not been entered.

[0066] The "predicted attack mode" includes the items "target operating element" and "inhibition mode". The "target operating element" indicates the operating element targeted by the attack stage in question. Figure 14 is a diagram illustrating the estimation of the inhibition mode and attack means. In the example in Figure 14, in attack stage AS1-2 from component 100a to component 100c, the operating mode of input I / F 101c-1 is "input". Which "inhibition mode" applies to an attack stage depends on the connection configuration of the input I / F 101 of the target component 100 in that attack stage. However, if the "configuration device connection configuration details" are not entered, all anticipated inhibition modes for the "corresponding operating element" are stored. Therefore, from the attack means correspondence information 201 (Figure 5), all inhibition modes (a), (b), and (c) are reflected in the "inhibition mode" corresponding to the "operating element" "input" in attack stage AS1-2 in Figure 12.

[0067] "Attack means" refers to the attack means corresponding to the combination of "target operating element" and "inhibition form" in the attack means correspondence information 201 (Figure 5). In the example in Figure 14, the combination of "target operating element" "input" and "inhibition form" "(a)" in attack stage AS1-2 from component device 100a to component device 100c stores the corresponding "attack means" "attack means 4" in the attack means correspondence information 201. Similarly, the combination of "target operating element" "input" and "inhibition form" "(b)" stores the corresponding "attack means" "attack means 5" in the attack means correspondence information 201. Similarly, the combination of "target operating element" "input" and "inhibition form" "(c)" stores the corresponding "attack means" "attack means 6" in the attack means correspondence information 201.

[0068] "Events that may occur as a result of the attack" refers to the events and effects that are expected to occur as a result of each "attack method," corresponding to each "attack method" in Event Response Information 202 (Figure 6). In "Events that may occur as a result of the attack," corresponding to "attack method" "attack method 4," "event 4(5)" in Event Response Information 202 is reflected. Similarly, corresponding to "attack method" "attack method 5," "event 5(4)" in Event Response Information 202 is reflected. Similarly, corresponding to "attack method" "attack method 6," "event 6(5)" in Event Response Information 202 is reflected.

[0069] The numbers in parentheses next to "Potential Events Caused by the Attack" represent a score for each event, indicating the degree of security risk posed to the target system by the attack, on a scale of 1 to 5. This score allows for an intuitive understanding of the degree of security risk for each attack path. Furthermore, by summing the scores for each attack scenario, the degree of security risk for each scenario can be intuitively understood. In addition, based on the results of the security risk assessment, key areas requiring countermeasures can be selected based on the scores.

[0070] Next, in step S4, the attack scenario presentation unit 114 presents the attack scenario generated in step S3 to the user. The attack scenario presentation unit 114 outputs attack scenario information 205 to the user via the scenario information display GUI 16D2 (Figure 12) on the output device 16, for example, as illustrated in Figure 12.

[0071] Up to this stage, the attack methods included in the generated attack scenario are represented by the operating models and inhibition methods of the constituent devices. Therefore, a user with knowledge of SuC can roughly grasp the risks posed by the attack scenario, even without specialized knowledge of the attack methods. However, in order to move from the attack scenario to countermeasure planning, information on the specific attack mechanism is required. Therefore, a process of detailing the attack scenario is necessary at the user's request. The details are explained below.

[0072] Next, in step S5, the attack scenario presentation unit 114 determines whether the user has made an input requesting further details of the attack scenario. If the user has made an input requesting further details of the attack scenario (step S5YES), the attack scenario presentation unit 114 proceeds to step S6, and if the user has not made an input requesting further details of the attack scenario (step S5NO), the risk assessment process ends. In step S5, the attack scenario presentation unit 114 may also determine whether predetermined conditions (for example, whether all the detailed information that can be entered in step S6 described later has been entered) have been met, rather than only determining whether the user has made an input requesting further details of the attack scenario.

[0073] In step S5, the attack scenario presentation unit 114 prompts the user to input whether or not to perform detailed processing of the attack scenario information 205 via the detailed processing requirement confirmation GUI 16D3 on the output device 16, as illustrated in Figure 15. When the row of the component device 100 to be detailed in the attack scenario information 205 is double-clicked, the detailed processing requirement confirmation GUI 16D3 is displayed as shown in Figure 15. When "Yes (Y)" is clicked on the detailed processing requirement confirmation GUI 16D3, the detailed information input window 16D4 is displayed on the device configuration information input GUI 16D1, as shown in Figure 16. Steps S5 to S7 are repeated as long as the user wishes.

[0074] In step S6, the device configuration information input unit 111 performs the detailed information addition input process. The device configuration information input unit 111 accepts detailed information 203 to elaborate on the attack scenario information 205 from the user via the detailed information input window 16D4 displayed on the device configuration information input GUI 16D1 on the output device 16, for example, as illustrated in Figure 16.

[0075] Detailed information 203 contains information for each of the 100 constituent devices. As shown in Figure 16, detailed information 203 includes the "Name" and "Version" of the "Installed OS," the "Name" and "Version" of the "Installed Software," and the "Connection Type" and "Additional Attributes" of the "Input I / F_ID." Whether or not values ​​corresponding to each of these items are actually stored is at the user's discretion.

[0076] The "Connection Type" of the "Input I / F_ID" indicates the connection standard of the corresponding Input I / F101, such as "Ethernet" (registered trademark, same applies hereinafter), "RS-232C", or "Signal Line". The "Additional Attributes" of the "Input I / F_ID" are information that includes one or more attributes other than the connection standard of the corresponding Input I / F101, such as "Inside Enclosure" or "Outside Enclosure" indicating the connection location.

[0077] The device configuration information input unit 111 stores the detailed information 203 entered by the user in the storage device 13 and reflects it in the attack scenario information 205.

[0078] Next, in step S7, the attack scenario generation unit 113 performs an attack scenario refining process, which includes estimating detailed attack means and events that may occur as a result of the attack, based on the detailed information 203 input in step S6.

[0079] In the attack scenario detailing process, the attack scenario generation unit 113 first reflects the detailed information 203 input in step S6 into the attack scenario information 205. Figure 18 shows the detailed attack scenario information 205. In the example shown in Figure 18, the "connection type" and "additional attributes" of the detailed information 203 are stored in the "configuration device connection type details" of the corresponding input I / F 101 in the attack scenario information 205. In addition, although not shown in the figure, the values ​​of the items in the detailed information 203 may be stored as the values ​​of the corresponding items in the attack scenario information 205.

[0080] Next, the attack scenario generation unit 113 performs a re-estimation of the "inhibition form," "attack means," and "events that may occur as a result of the attack" in the attack scenario information 205, which reflects the detailed information 203. In the "inhibition form," any inhibition form that can no longer occur is excluded through the re-estimation. For example, if the component devices 100 are housed inside a casing, the attacker cannot directly access the inside of the casing, so the inhibition form described in (b) above, which involves modification of the connections between the component devices 100, and the inhibition form described in (c) above, which is based on input from an untrusted party, cannot occur. For this reason, in the example shown in Figure 18, the "inhibition form" corresponding to attack stages AS1-2 and AS1-3 of attack scenario AS1, attack stages AS2-2 and AS2-3 of attack scenario AS2, and attack stage AS3-1 of attack scenario AS3 is reduced from "(a), (b), and (c)" to "(a)" only, with "(b)" and "(c)" being excluded.

[0081] Furthermore, the "attack method" is refined through re-estimation based on the added "configuration device connection configuration details." For example, in the example shown in Figure 18, the "attack method" of attack scenario AS1 is refined based on the refinement information 204. Figure 17 shows the refinement information 204 for the attack method and the resulting events. The refinement information 204 shows the "detailed attack method" and the "detailed events that may occur as a result of the attack" that correspond to the combination patterns of values ​​of the items in "attack method" and detailed information 203.

[0082] The "attack method" in detail information 204 is the attack method before it is refined based on detail information 204. The "detailed information" shows a pattern that includes the value of one item or a combination of values ​​of multiple items stored in detail information 204 (Figure 17). In this pattern, items in "detailed information" that do not have a value stored are excluded. The "detailed attack method" is information that specifically and in detail shows the attack method corresponding to the combination of "attack method" and "detailed information".

[0083] "Detailed events that may occur as a result of the attack" are events that may occur as a result of an attack corresponding to a "detailed attack method," and are information that specifically and in detail describes each event. Note that the same "detailed attack method" and "detailed events that may occur as a result of the attack" may correspond to different combinations of "detailed information."

[0084] Specifically, for example, the "attack methods" corresponding to attack stage AS1-1 of attack scenario AS1 and attack stage AS2-1 of attack scenario AS2 are further detailed based on detailed information 204 (Figure 17), with "attack method 4," "attack method 5," and "attack method 6" being further detailed as "attack method 4-1," "attack method 5-3," and "attack method 6-2" respectively for each of the "inhibition forms" (a), (b), and (c). In addition, the "events that may occur as a result of the attack" are further detailed as "event 4-1(3)," "event 5-3(2)," and "event 6-2(2)." The numbers in parentheses next to the "events that may occur as a result of the attack" are scores for each event, representing the degree of security risk to the target system caused by the attack on a scale of 1 to 5.

[0085] Similarly, the "attack means" corresponding to attack stages AS1-2 and AS1-3 of attack scenario AS1, and attack stages AS2-2 and AS2-3 of attack scenario AS2, are detailed as "attack means 4-2" for "inhibition form" (a) based on detailed information 204. In addition, "events that may occur as a result of the attack" are detailed as "event 4-2(4)".

[0086] Similarly, the "attack means" corresponding to attack stage AS3-1 of attack scenario AS3 are further detailed based on detail information 204, with "attack means 4" and "attack means 5" being further detailed as "attack means 4-3" and "attack means 5-1" respectively for "inhibition forms" (a) and (b). In addition, "events that may occur as a result of the attack" are further detailed as "event 4-3(3)" and "event 5-1(1)" respectively.

[0087] Once step S7 is completed, the attack scenario generation unit 113 returns to step S5.

[0088] As explained above, users are initially presented with attack scenarios represented by attack methods roughly categorized in step S3. This rough attack classification is a so-called classification without omissions or overlaps, and for non-security experts, it is easier to verify its comprehensiveness than attack scenarios represented by specific attack methods. Subsequently, for attack scenarios that require countermeasures, users are asked to input additional equipment information, and the attack scenarios are repeatedly refined and subdivided according to the user's requests. This allows for a smooth transition to identifying the specific technical content of the attacks to be addressed and selecting the necessary countermeasures.

[0089] According to this embodiment, attacks predicted based on the device configuration entered by the user are represented as attack types defined by the operating elements in the device's operating model and their inhibition methods, and presented to the user as attack scenarios. Since the entire set of possible attack methods is defined by the operating elements and inhibition methods, it is guaranteed that the attack types obtained by classifying them are exhaustive. Furthermore, unlike known attack methods, such classifications are based on the operation of the device, which has the advantage that even non-security experts can easily grasp the outline of the attack scenarios if they are familiar with the system targeted for security risk assessment.

[0090] It should be noted that, in the above description, functions and means of configuration that are not specifically mentioned may be implemented not only by electrical circuits, electronic circuits, logic circuits, and integrated circuits containing them, but also by programs executed by a combination of a microcomputer, processor, and similar arithmetic unit, ROM (Read Only Memory), RAM (Random Access Memory), flash memory, hard disk, SSD, memory card, optical disc, and similar storage devices, bus, network, and similar communication devices, and peripheral devices, and the present invention can be established in any of these implementation modes.

[0091] Furthermore, the present invention is not limited to the embodiments described above, and various modifications are included. For example, the embodiments described above are described in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. Also, it is possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add configurations from other embodiments to the configuration of one embodiment. In addition, it is possible to add, delete, or replace parts of the configuration of each embodiment with other configurations. [Explanation of symbols]

[0092] 1: Security risk assessment support system, 11: Processor, 13: Storage device, 16: Output device, 111: Equipment configuration information input unit, 112: Attack path exploration unit, 113: Attack scenario generation unit, 114: Attack scenario presentation unit, 200: Equipment configuration information, 201: Attack method response information, 202: Occurrence event response information, 203: Detailed information, 204: Detailed information, 205: Attack scenario information.

Claims

1. A security risk assessment support method performed by a security risk assessment support system, A configuration information input step that accepts input of configuration information regarding the target system which includes the constituent devices, An attack path search step, based on the configuration information, searches for attack paths through which an attack on the target system passes via the configuration devices, An attack scenario generation step involves arranging the attack path in the order in which the attack passes through the constituent devices to generate an attack scenario, estimating which type of attack the form in which the operation of the constituent devices constituting the attack path is disrupted by the attack, based on a functional model that represents the configuration of the constituent devices in terms of function, and reflecting the estimated attack type in the attack scenario. An attack scenario presentation step presents the attack scenario generated by the attack scenario generation step, A security risk assessment support method characterized by having [a certain feature].

2. A security risk assessment support method according to claim 1, In the aforementioned configuration information input step, A security risk assessment support method characterized by having the configuration information input according to the functional model.

3. A security risk assessment support method according to claim 1, A security risk assessment support method characterized in that the functional model includes the types of operating elements of the constituent devices.

4. A security risk assessment support method according to claim 1, In the aforementioned attack scenario generation step, A security risk assessment support method characterized by estimating the types of events that may occur in the constituent devices based on the estimated attack type, and reflecting the estimated types of events in the attack scenario.

5. A security risk assessment support method according to claim 4, A security risk assessment support method characterized in that the type of event includes a score for each type of event indicating the degree of security risk that arises in the target system as a result of the attack.

6. A security risk assessment support method according to claim 1, A detailed information input step that accepts additional input of detailed information about the aforementioned configuration information, An attack scenario refinement step which estimates detailed attack means based on the detailed information received in the detailed information input step compared with the attack type, and updates the attack type of the attack scenario generated in the attack scenario generation step with the estimated detailed attack means, A security risk assessment support method characterized by having [a certain feature].

7. A security risk assessment support method according to claim 6, In the aforementioned attack scenario detailing step, A security risk assessment support method characterized by excluding attack types from the attack scenario in which the operation of the components constituting the attack path is not disrupted by the attack, based on the aforementioned detailed information.

8. A security risk assessment support method according to claim 6, In the aforementioned attack scenario detailing step, A security risk assessment support method characterized by estimating detailed events that may occur in the constituent devices by the detailed attack means, and reflecting the estimated detailed events in the attack scenario.

9. A security risk assessment support method according to claim 8, A security risk assessment support method characterized in that the detailed events include a score for each detailed event indicating the degree of security risk incurred in the target system as a result of the attack.

10. A security risk assessment support method according to claim 6, A security risk assessment support method characterized by repeatedly performing the step of adding detailed information and the step of refining the attack scenario until predetermined conditions are met.

11. A security risk assessment support system that performs a security risk assessment regarding a target system that includes its constituent devices, A configuration information input unit that receives configuration information related to the aforementioned target system, Based on the aforementioned configuration information, an attack path search unit searches for attack paths that pass through the aforementioned configuration devices in an attack on the target system, An attack scenario generation unit generates an attack scenario by arranging the attack path in the order in which the attack passes through the constituent devices, estimates which type of attack the form in which the operation of the constituent devices constituting the attack path is disrupted by the attack, based on a functional model that represents the configuration of the constituent devices in terms of function, and reflects the estimated attack type in the attack scenario. An attack scenario presentation unit presents the attack scenario generated by the attack scenario generation unit, A security risk assessment support system characterized by having [a certain feature].

12. A security risk assessment support system according to claim 11, The aforementioned attack scenario generation unit, A security risk assessment support system characterized by estimating the types of events that may occur in the constituent devices based on the estimated attack type, and reflecting the estimated types of events in the attack scenario.

13. A security risk assessment support system according to claim 11, The configuration information input unit accepts additional input of detailed information about the configuration information. The aforementioned attack scenario generation unit, A security risk assessment support system characterized by estimating detailed attack means based on the detailed information received by the configuration information input unit, comparing it with the attack type, and updating the attack type of the attack scenario generated by the attack scenario generation unit with the estimated detailed attack means.

14. A security risk assessment support system according to claim 13, The aforementioned attack scenario generation unit, A security risk assessment support system characterized by excluding attack types from the attack scenario in which the operation of the components constituting the attack path is not disrupted by the attack, based on the aforementioned detailed information.

15. A security risk assessment support system according to claim 13, The aforementioned attack scenario generation unit, A security risk assessment support system characterized by estimating detailed events that may occur in the constituent devices by the detailed attack means, and reflecting the estimated detailed events in the attack scenario.

Citation Information

Patent Citations

  • Cyber attack scenario generation method, and device

    JP2022076159A

  • Security risk analysis assistance device, method, and computer-readable medium

    WO2021059471A1