Information processing device, information processing method, and program

The information processing device tailors cybersecurity training by generating customized scenarios and content based on learner history, enhancing training effectiveness by aligning with individual learning progress.

JP7910631B2Active Publication Date: 2026-08-25NEC CORP
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024574088
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-01-30
Publication Date
2026-08-25
Estimated Expiration
2043-01-30

AI Technical Summary

Technical Problem

Existing cybersecurity training systems are limited by pre-prepared scenarios that may not align with the learner's learning situation, reducing the effectiveness of skill improvement.

Method used

An information processing device that extracts learning history data to identify content characteristics, generates customized attack scenarios, and creates new exercise content tailored to the learner's progress, using attribute information from databases to enhance training relevance.

Benefits of technology

Enables the generation of security exercise content that aligns with the learner's progress, improving the effectiveness of cybersecurity training by addressing specific areas of difficulty or strength.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007910631000001
    Figure 0007910631000001
  • Figure 0007910631000002
    Figure 0007910631000002
  • Figure 0007910631000003
    Figure 0007910631000003
Patent Text Reader

Abstract

An information processing device 10 comprises a training history extraction unit 11 that extracts a group of content matching a condition from training history data identifying exercise content and training results in cybersecurity exercises taken by trainees, a content feature identification unit 12 that identifies features of the group of content by using attribute information in the extracted group of content, and an exercise content generation unit 13 that generates an attack scenario for cyberattacks by using the identified features, and generates new exercise content for cybersecurity exercises by using the attack scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus and an information processing method for assisting training against cyberattacks, and further to a program for realizing these. Mu Related thereto.

Background Art

[0002] In recent years, damages such as information leakage and business suspension have increased due to cyberattacks targeting organizations, and strengthening countermeasures against cyberattacks has been demanded. And in order to strengthen countermeasures against cyberattacks, it is essential to improve the skills of system security personnel.

[0003] For this reason, conventionally, cyber security drills have been conducted to improve the skills of security personnel. Patent Document 1 discloses a system for executing a cyber security drill. Patent Document 1 proposes a system for conducting a cyber security drill according to the skills of the trainees.

[0004] The system disclosed in Patent Document 1 first deploys an attack execution program to each machine in a group of machines to be attacked. Then, the system disclosed in Patent Document 1 controls each attack execution program along a pre-prepared scenario and executes a simulated cyberattack on the group of machines to be attacked according to the skills of the trainees. When a cyberattack is executed, the trainee executes an operation to block the execution of the cyberattack.

[0005] After that, the system disclosed in Patent Document 1 collects, from each machine, an attack result log indicating the result (success / failure) of the cyberattack and an operation log indicating the response operations performed by the trainee during the cyberattack, and displays the collected logs on a screen. Then, the trainee determines whether the operations he / she performed were appropriate from the displayed screen.

Prior Art Documents

Patent Documents

[0006] [Patent Document 1] Japanese Patent Publication No. 2019-191670 [Overview of the Initiative] [Problems that the invention aims to solve]

[0007] Incidentally, in the system disclosed in Patent Document 1 mentioned above, the scenarios used for simulated cyberattacks are prepared in advance by the examiner. In other words, it is impossible for participants to perform cybersecurity exercises using scenarios other than those prepared by the examiner.

[0008] Therefore, if the prepared scenario is not appropriate to the learner's learning situation, for example, if it is not a scenario that the learner should focus on, the effectiveness of skill improvement will decrease. In other words, the system disclosed in Patent Document 1 has the problem that it cannot generate content for exercises according to the learner's learning situation.

[0009] One example of the purpose of this disclosure is to generate content for security exercises according to the learning progress of the participants. [Means for solving the problem]

[0010] To achieve the above objective, the information processing device in one aspect of this disclosure is: A learning history extraction unit extracts content sets that match certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by participants. A content feature identification unit identifies the characteristics of the content group using attribute information in the extracted content group, An exercise content generation unit generates attack scenarios for cyberattacks using the identified characteristics, and further generates new exercise content for cybersecurity exercises using the generated attack scenarios. It is characterized by having the following features.

[0011] Furthermore, in order to achieve the above objectives, the information processing method in one aspect of this disclosure is: A learning history extraction step extracts a set of content that matches certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by the participants. A content feature identification step involves using attribute information in the extracted content group to identify the characteristics of the content group, An exercise content generation step, which involves generating attack scenarios for cyberattacks using the identified characteristics, and further generating new exercise content for cybersecurity exercises using the generated attack scenarios, It is characterized by having the following:

[0012] Furthermore, in order to achieve the above objectives, one aspect of this disclosure program teeth, On the computer, A learning history extraction step extracts a set of content that matches certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by the participants. A content feature identification step involves using attribute information in the extracted content group to identify the characteristics of the content group, An exercise content generation step, which involves generating attack scenarios for cyberattacks using the identified characteristics, and further generating new exercise content for cybersecurity exercises using the generated attack scenarios, Let's execute it ru, It is characterized by the following: [Effects of the Invention]

[0013] As described above, this disclosure allows for the generation of security exercise content according to the learner's progress. [Brief explanation of the drawing]

[0014] [Figure 1] FIG. 1 is a configuration diagram showing a schematic configuration of an information processing apparatus in an embodiment. [Figure 2] FIG. 2 is a diagram showing the configuration of the information processing apparatus in the embodiment more specifically. [Figure 3] FIG. 3 is a diagram showing an example of lecture history data stored in a lecture history database in the embodiment. [Figure 4] FIG. 4 is a diagram showing an example of information stored in an exercise content database in the embodiment. [Figure 5] FIG. 5 is a diagram showing an example of information stored in a simulated attack scenario database in the embodiment. [Figure 6] FIG. 6 is a diagram showing an example of information stored in an attack command database in the embodiment. [Figure 7] FIG. 7 is a diagram showing an example of characteristic identification processing of a content group, respectively. [Figure 8] FIG. 8 is a diagram showing an example of characteristic identification processing of a content group, respectively. [Figure 9] FIG. 9 is a diagram showing an example of characteristics of a content group specified in the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of a simulated attack scenario generated in the embodiment. [Figure 11] FIG. 11 is a diagram showing an example of a log group collected from a computer system in the embodiment. [Figure 12] FIG. 12 is a diagram showing an example of generation processing of exercise content in the embodiment. [Figure 13] FIG. 13 is a diagram showing an example of exercise content generated in the embodiment. [Figure 14] FIG. 14 is a flowchart showing the operation of the information processing apparatus in the embodiment. [Figure 15] FIG. 15 is a configuration diagram showing a configuration example of a modified information processing apparatus in the embodiment. [Figure 16]Figure 16 is a block diagram showing an example of a computer that implements the information processing device in the embodiment. [Modes for carrying out the invention]

[0015] (Embodiment) The information processing device, information processing method, and program in the embodiment will be described below with reference to Figures 1 to 16.

[0016] [Device configuration] First, the schematic configuration of the information processing device in the embodiment will be described using Figure 1. Figure 1 is a configuration diagram showing the schematic configuration of the information processing device in the embodiment.

[0017] The information processing device 10 in the embodiment shown in Figure 1 is a cyberattack training support device that assists in training against cyberattacks. As shown in Figure 1, the information processing device 10 includes a training history extraction unit 11, a content feature identification unit 12, and an exercise content generation unit 13.

[0018] Of these, the training history extraction unit 11 extracts a group of content that matches the specified criteria from the training history data, which identifies the training content and training results of the cybersecurity training exercises that the trainees have taken.

[0019] The content feature identification unit 12 identifies the characteristics of the content group using the attribute information of the content group extracted by the course history extraction unit 11.

[0020] The exercise content generation unit 13 first uses the characteristics identified by the content feature identification unit 12, and then uses the generated attack scenario to generate new exercise content for cybersecurity exercises.

[0021] In this way, the information processing device 10 can identify, for example, the characteristics of content groups that the learner finds difficult (or easy) from the learner's learning history, and use the identified characteristics to generate new exercise content. In other words, the information processing device 10 can generate security exercise content according to the learner's learning status.

[0022] Next, the configuration and functions of the information processing device 10 in the embodiment will be specifically described using Figures 2 to 13. Figure 2 is a device that more specifically shows the configuration of the information processing device in the embodiment.

[0023] As shown in Figure 2, in this embodiment, the information processing device 10 is data-communicatively connected to the course history database 20, the exercise content database 21, the simulated attack scenario database 22, and the attack command database 23. The information stored in these databases will be described later. These databases may also be provided by the information processing device 10.

[0024] The computer system 100 shown in Figure 2 is the system that will be subjected to a simulated attack for the purpose of generating training content. The computer system 100 consists of multiple terminal devices and a server device, which are connected via a network. A simulated attack is a simulated cyberattack carried out for the purpose of generating training content.

[0025] In this embodiment, the course history extraction unit 11 extracts a group of content that matches the specified conditions from the course history database 20. The course history database 20 stores course history data. Figure 3 shows an example of course history data stored in the course history database in this embodiment.

[0026] As shown in Figure 3, the course history database 20 stores course history data that identifies the course history of the exercise content that each student has previously taken. In the example in Figure 3, the course history data consists of the student's user ID (Identifier), content ID that identifies the exercise content the student took, the number of answers the student entered before obtaining the correct answer (number of answer entries), and the course duration. Of these, the number of answer entries and the course duration correspond to the course results described above.

[0027] When extracting content sets, conditions for identifying areas of difficulty for the learner include, for example, the number of times an answer was entered exceeding a threshold, or the study time exceeding a threshold. Furthermore, if the study history data includes the number of times a hint was displayed during the answering process, the condition that the number of times a hint was displayed exceeds a threshold can also be added. When such conditions are adopted, the study history extraction unit 11 extracts the exercise content that the learner found difficult.

[0028] Furthermore, the conditions for extracting content sets may also be conditions for identifying the learner's strengths. In this case, possible conditions include the number of answer inputs being below a threshold, the study time being below a threshold, and the number of times hints were displayed being zero. In this case, the study history extraction unit 11 extracts the exercise content that the learner excelled at.

[0029] In this embodiment, the content feature identification unit 12 first uses the exercise content database 21, the simulated attack scenario database 22, and the attack command database 23 to obtain attribute information for each exercise content extracted by the training history extraction unit 11.

[0030] Figure 4 shows an example of the information stored in the exercise content database in the embodiment. As shown in Figure 4, the exercise content database 21 stores information for each exercise content. Specifically, the exercise content database 21 stores information such as the content ID of the exercise content, the ID of the simulated attack scenario used to generate the exercise content (simulated attack scenario ID), a situation description, exercise tasks, hints, the correct answer (log), the path of the log to be investigated, and the type of log to be investigated.

[0031] Figure 5 shows an example of the information stored in the simulated attack scenario database in the embodiment. As shown in Figure 5, the simulated attack scenario database 22 stores information for each simulated attack scenario. Specifically, the simulated attack scenario database 22 stores information such as the simulated attack scenario ID, the attack method used in the simulated attack, and the attack command used in the simulated attack.

[0032] Figure 6 shows an example of the information stored in the attack command database in the embodiment. As shown in Figure 6, the attack command database 23 stores information for each command used in the simulated attack. Specifically, the attack command database 23 stores information such as the ID of the attack command used in the simulated attack (attack command ID), the corresponding attack method, the attack command, and the type of log trace left by the corresponding attack command.

[0033] In Figures 5 and 6, the attack methods and commands are expressed in accordance with the vocabulary used in MITRE ATT&CK ID (see https: / / atack.mitre.org). Specifically, numbers such as "T1003" and "T1041" are identification numbers that identify the techniques used in the attack, as defined in MITRE ATT&CK ID.

[0034] Specifically, the content feature identification unit 12 acquires attribute information for each exercise content, such as information about the exercise content and information about the attack used in the exercise content. Information about the exercise content includes the theme of the exercise content and the type of log being investigated, and these are acquired from the exercise content database 21 (see Figure 4). Information about the attack used in the exercise content includes the attack method and attack commands used in the exercise content, and these are acquired from the simulated attack scenario database 23 (see Figure 5).

[0035] Next, the content feature identification unit 12 uses the attribute information of each exercise content acquired to identify the characteristics of the content group extracted by the course history extraction unit 11. For example, suppose information about the exercise content has been acquired from the content group. In this case, the content feature identification unit 12 can identify the information that accounts for a proportion of the acquired information that is equal to or greater than a threshold as a characteristic of the content group.

[0036] Furthermore, it is assumed that information regarding the content of the attacks used in the exercise content has been obtained from the content group. In this case, the content feature identification unit 12 can identify the content group features that are set at a threshold or higher rate in the simulated attack scenario from the obtained information.

[0037] Here, we will explain the process of identifying the characteristics of a content group using specific examples, with reference to Figures 7 and 8. Figures 7 and 8 are diagrams illustrating examples of the process of identifying the characteristics of a content group, respectively.

[0038] Figure 7 shows an example where the content feature identification unit 12 identifies the theme of the exercise content and the type of log to be investigated as attribute information of the exercise content. In this case, the content feature identification unit 12 calculates the proportion of each component for both the theme and the type of log to be investigated.

[0039] In terms of themes, the proportion of "attack persistence" is 60% (=(3 / 5)×100), and the proportion of "lateral movement" is 40% (=(2 / 5)×100). In terms of the types of logs investigated, "event logs" account for 40%, while "proxy logs," "registry," and "USN journals" each account for 20%. In the example in Figure 7, the threshold is set to 60%, so the content feature identification unit 12 identifies "attack persistence," which exceeds the threshold, as a feature of the content group.

[0040] Figure 8 shows an example where the content feature identification unit 12 identifies the attack methods used in the exercise content as attribute information of the exercise content. In this case, the content feature identification unit 12 extracts the acquired attack methods that are set at a threshold or higher rate in the simulated attack scenario.

[0041] In the example shown in Figure 8, since the threshold is set to 100%, the content feature identification unit 12 extracts the attack methods set in all simulated attack scenarios, namely T1018, T1041, T1053, T1074, and T1083, and identifies them as features of the content group.

[0042] The content feature identification unit 12 may acquire both information about the exercise content and information about the attack used in the exercise content as attribute information for each exercise content, or it may acquire only one of them. In the former case, the features of the content group are identified from both.

[0043] Figure 9 shows an example of the characteristics of the content group identified in the embodiment. In the example in Figure 9, the content feature identification unit 12 identifies "attack persistence" identified from information about the exercise content, attack methods "T1018, T1041, T1053, T1074, and T1083" identified from information about the content of the attack used in the exercise content, and attack commands "A10, A20, A30, A40, ..." as characteristics of the content group.

[0044] In this embodiment, the exercise content generation unit 13 includes a simulated attack generation unit 131, a simulated attack execution unit 132, a log acquisition unit 133, and a task generation unit 134, as shown in Figure 2.

[0045] The simulated attack generation unit 131 generates an attack scenario (also referred to as a "simulated attack scenario") for a cyberattack (simulated attack) using features identified by the content feature identification unit 12, such as the theme of the exercise content, attack methods, and attack commands. For example, the technology disclosed in International Publication No. 2020 / 255359 may be used to generate the simulated attack scenario.

[0046] Specifically, the simulated attack generation unit 131 sets attack methods and attack commands for each process in accordance with the theme of the exercise content identified by the content feature identification unit 12. In this embodiment, rules are set in advance for each theme that define the number of processes and the candidate attack methods to be set for each process. Therefore, the simulated attack generation unit 131 applies the attack methods identified by the content feature identification unit 12 to each process based on these rules. Furthermore, the simulated attack generation unit 131 selects an attack command corresponding to the applied attack method from among the attack commands identified by the content feature identification unit 12 and sets the attack command for each process.

[0047] Figure 10 shows an example of a simulated attack scenario generated in the embodiment. In the example in Figure 10, the simulated attack scenario consists of a sequence, attack method, and attack command for each process. In the example in Figure 9, the simulated attack scenario consists of three layers for each process, but the embodiment is not limited to this example. The simulated attack scenario may also include, for example, software for executing attack commands, a corresponding environment, etc.

[0048] The simulated attack execution unit 132 executes a simulated attack against the computer system 100 according to the simulated attack scenario generated by the simulated attack generation unit 131. Specifically, the simulated attack execution unit 132 sends software (e.g., malware) that executes attack commands for each step of the process to terminal devices that make up the computer system 100, and has them executed on the terminal devices. As a result, the computer system 100 is subjected to a simulated attack.

[0049] The log acquisition unit 133 collects log files from terminal devices and server devices that constitute the computer system 100 subjected to a simulated attack. Figure 11 shows an example of log files collected from the computer system in this embodiment. In the example in Figure 11, Prefetch logs and USN journal logs are shown.

[0050] The task generation unit 134 matches the features identified by the content feature identification unit 12 with the exercise content database 21 to generate exercise content that will serve as the task. Specifically, the task generation unit 134 identifies exercise content from the exercise content database 21 that matches the identified features, and if there are multiple exercise contents that match, it randomly selects one of them.

[0051] Furthermore, in this embodiment, if the task generation unit 134 is unable to identify exercise content from the exercise content database 21 that matches all of the identified features, it may identify exercise content that matches some of the features. Moreover, if the task generation unit 134 is unable to identify any exercise content from the exercise content database 21 that matches the identified features, the content feature identification unit 12 can change the threshold for identifying content features and execute the process again.

[0052] Figure 12 shows an example of the process for generating exercise content in an embodiment. In the example in Figure 12, the theme of the exercise content and the type of log to be investigated are identified by the content feature identification unit 12. In this case, the task generation unit 134 identifies content C51 and content C72, and selects content C72.

[0053] The task generation unit 134 then extracts the exercise tasks and hints (Figure 12) for the selected content and selects a template corresponding to the extracted exercise tasks. The templates are pre-created for each exercise task, and the input fields for hints and logs are blank. The task generation unit 134 then inputs the hints and the log data acquired by the log acquisition unit 133 into the blank sections of the selected template. Once the task generation unit 134 has entered the hints and log data into the blank sections of the selected template, a new exercise content for the cybersecurity exercise is completed.

[0054] Figure 13 shows an example of exercise content generated in the embodiment. In Figure 13, the situation description and the explanatory text for the exercise task are provided in advance using templates. Also, in the example in Figure 13, the exercise content is displayed on the screen of the participant's terminal device.

[0055] Furthermore, the task generation unit 134 can also generate the correct answer for the generated exercise content. Specifically, the task generation unit 134 first identifies traces of the simulated attack from the log collection unit 133 using the attack commands used in the simulated attack. Next, the task generation unit 134 compares the identified traces with the correct answer logs that have been prepared in advance for each attack method to identify the correct trace and sets it as the correct answer.

[0056] [Device operation] Next, the operation of the information processing device 10 in the embodiment will be explained using Figure 14. Figure 14 is a flowchart showing the operation of the information processing device in the embodiment. In the following explanation, Figures 1 to 13 will be referred to as appropriate. In the embodiment, the information processing method is carried out by operating the information processing device 10. Therefore, the explanation of the information processing method in the embodiment will be replaced by the following explanation of the operation of the information processing device 10.

[0057] As shown in Figure 14, first, in the information processing device 10, the course history extraction unit 11 accesses the course history database 20 and extracts a group of content that matches the conditions from the course history data of cybersecurity exercises taken by the student (Step A1).

[0058] Next, the content feature identification unit 12 uses the exercise content database 21, the simulated attack scenario database 22, and the attack command database 23 to obtain attribute information for each exercise content extracted in step A1 (step A2).

[0059] Next, the content feature identification unit 12 uses the attribute information of each exercise content obtained in step A2 to identify the features of the content group extracted in step A1 (step A3).

[0060] Next, in the exercise content generation unit 13, the simulated attack generation unit 131 generates an attack scenario for a simulated attack (simulated attack scenario) using the features identified in step A3 (step A4).

[0061] Next, in the exercise content generation unit 13, the simulated attack execution unit 132 executes a simulated attack against the computer system 100 according to the simulated attack scenario generated in step A4 (step A5).

[0062] Next, in the exercise content generation unit 13, the log acquisition unit 133 collects a set of logs from the terminal devices and server devices that constitute the computer system 100 that has been subjected to a simulated attack (step A6).

[0063] Next, in the exercise content generation unit 13, the task generation unit 134 matches the features identified in step A3 with the exercise content database 21 and selects one of the exercise contents. Then, the task generation unit 134 uses the selected exercise content and the log data collected in step A6 to generate new exercise content (step A7).

[0064] After step A7 is completed, the newly generated exercise content is displayed on the screen of the participant's terminal device. The task generation unit 134 can also generate the correct answers for the generated exercise content and display the correct answers on the screen upon request from the participant.

[0065] According to this embodiment, the information processing device 10 can identify, for example, the characteristics of content groups that are difficult (or easy) for the learner based on the learner's learning history, and generate new exercise content using the identified characteristics. By using the information processing device 10, learners can efficiently learn about cybersecurity.

[0066] [Differentiation] Next, a modified example of the information processing device in the embodiment will be described using Figure 15. Figure 15 is a configuration diagram showing the configuration of a modified example of the information processing device in the embodiment.

[0067] As shown in Figure 15, in the modified example, the information processing device 10 further includes an exercise content verification unit 14. Note that in the modified example, the information processing device 10 also has the configuration shown in Figure 2.

[0068] The exercise content verification unit 14 calculates the similarity between the new exercise content generated by the exercise content generation unit 13 and the group of content extracted from the course history data (past exercise content).

[0069] Specifically, rules are provided in advance to set similarity levels between elements for each item, such as attack methods and commands. Therefore, the exercise content verification unit 14 calculates the similarity level by comparing the items of the new exercise content with the items of past exercise content against these rules.

[0070] Then, the exercise content verification unit 14 determines that the calculated similarity is below a threshold, that is, that the new exercise content is not similar to past exercise content, and sets the new exercise content as content for the learner's review.

[0071] In this modified form, the situation where new exercise content that is too similar to past exercise content is generated is avoided.

[0072] [program] The program in this embodiment can be any program that causes a computer to execute steps A1 to A7 shown in Figure 14. By installing and running this program on a computer, the information processing device 10 and the information processing method in this embodiment can be realized. In this case, the computer's processor functions as the learning history extraction unit 11, the content feature identification unit 12, and the exercise content generation unit 13 of the information processing device 10, and performs processing. In the modified example, the computer's processor also functions as the exercise content verification unit 14. Examples of computers include general-purpose PCs, smartphones, and tablet devices.

[0073] Furthermore, the program in the embodiment may be executed by a computer system constructed by multiple computers. In this case, for example, each computer may function as one of the following: the course history extraction unit 11, the content feature identification unit 12, and the exercise content generation unit 13 (or even as the exercise content verification unit 14).

[0074] [Physical configuration] Here, a computer that implements the information processing device 10 by executing the program in the embodiment will be described with reference to Figure 16. Figure 16 is a block diagram showing an example of a computer that implements the information processing device in the embodiment.

[0075] As shown in Figure 16, the computer 110 comprises a CPU (Central Processing Unit) 111, main memory 112, storage device 113, input interface 114, display controller 115, data reader / writer 116, and communication interface 117. Each of these components is connected to the others via a bus 121, enabling data communication.

[0076] Furthermore, the computer 110 may include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array) in addition to, or instead of, the CPU 111. In this embodiment, the GPU or FPGA can execute the program in the embodiment.

[0077] The CPU 111 loads the program in the embodiment, which consists of a set of codes stored in the storage device 113, into the main memory 112, and performs various calculations by executing each code in a predetermined order. The main memory 112 is typically a volatile storage device such as DRAM (Dynamic Random Access Memory).

[0078] Furthermore, the program in this embodiment is provided stored on a computer-readable recording medium 120. The program in this embodiment may also be distributed over the internet via a communication interface 117.

[0079] Specific examples of the storage device 113 include hard disk drives and semiconductor storage devices such as flash memory. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and mouse. The display controller 115 is connected to the display device 119 and controls the display on the display device 119.

[0080] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, reads programs from the recording medium 120, and writes processing results from the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.

[0081] Furthermore, specific examples of the recording medium 120 include general-purpose semiconductor memory devices such as CF (Compact Flash®) and SD (Secure Digital), magnetic recording media such as Flexible Disks, or optical recording media such as CD-ROMs (Compact Disk Read Only Memory).

[0082] Furthermore, the information processing device 10 in this embodiment can be implemented not by a computer on which a program is installed, but by using hardware corresponding to each part, such as electronic circuits. Moreover, the information processing device 10 may be partially implemented by a program and the remaining part by hardware. In this embodiment, the computer is not limited to the computer shown in Figure 16.

[0083] Some or all of the embodiments described above can be expressed by (Appendix 1) to (Appendix 15) described below, but are not limited to the following descriptions.

[0084] (Note 1) A learning history extraction unit extracts content sets that match certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by participants. A content feature identification unit identifies the characteristics of the content group using attribute information in the extracted content group, An exercise content generation unit generates attack scenarios for cyberattacks using the identified characteristics, and further generates new exercise content for cybersecurity exercises using the generated attack scenarios. An information processing device characterized by having the following features.

[0085] (Note 2) The content feature identification unit identifies exercise tasks and attack content that satisfy the set conditions from the exercise tasks and attack content included in the attribute information, and defines the identified exercise tasks and attack content as features of the content group. The information processing device described in Appendix 1.

[0086] (Note 3) The content feature identification unit identifies exercise tasks and attack content that exist in a predetermined proportion or more of the exercise tasks included in the attribute information, and defines the identified exercise tasks and attack content as features of the content group. The information processing device described in Appendix 2.

[0087] (Note 4) The exercise content generation unit executes a cyberattack on a computer system in accordance with the attack scenario, collects a set of logs from the computer system, and uses the collected log set to generate the new exercise content. The information processing device described in Appendix 1.

[0088] (Note 5) The system further includes an exercise content verification unit that calculates the similarity between the newly generated exercise content and the group of content extracted from the course history data, and if the calculated similarity is below a threshold, uses the new exercise content as content for the student's review. The information processing device described in Appendix 1.

[0089] (Note 6) A learning history extraction step extracts a set of content that matches certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by the participants. A content feature identification step involves using attribute information in the extracted content group to identify the characteristics of the content group, An exercise content generation step, which involves generating attack scenarios for cyberattacks using the identified characteristics, and further generating new exercise content for cybersecurity exercises using the generated attack scenarios, An information processing method characterized by having the following:

[0090] (Note 7) In the content feature identification step, exercise tasks and attack content that satisfy the set conditions are identified from the exercise tasks and attack content included in the attribute information, and the identified exercise tasks and attack content are defined as features of the content group. The information processing method described in Appendix 6.

[0091] (Note 8) In the content feature identification step, among the exercises included in the attribute information, exercises and attack content that constitute a predetermined proportion or more are identified, and the identified exercises and attack content are defined as features of the content group. The information processing method described in Appendix 7.

[0092] (Note 9) In the exercise content generation step, a cyberattack in accordance with the attack scenario is executed on a computer system, logs are collected from the computer system, and the collected logs are used to generate the new exercise content. The information processing method described in Appendix 6.

[0093] (Note 10) The system further includes an exercise content verification step, which involves calculating the similarity between the newly generated exercise content and the group of content extracted from the course history data, and, if the calculated similarity is below a threshold, using the new exercise content as review content for the student. The information processing method described in Appendix 6.

[0094] (Note 11) On the computer, A learning history extraction step extracts a set of content that matches certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by the participants. A content feature identification step involves using attribute information in the extracted content group to identify the characteristics of the content group, An exercise content generation step, which involves generating attack scenarios for cyberattacks using the identified characteristics, and further generating new exercise content for cybersecurity exercises using the generated attack scenarios, Let's execute it ru, Professional Hmm.

[0095] (Note 12) In the content feature identification step, exercise tasks and attack content that satisfy the set conditions are identified from the exercise tasks and attack content included in the attribute information, and the identified exercise tasks and attack content are defined as features of the content group. As described in Appendix 11 program .

[0096] (Note 13) In the content feature identification step, among the exercises included in the attribute information, exercises and attack content that constitute a predetermined proportion or more are identified, and the identified exercises and attack content are defined as features of the content group. As described in Appendix 12 program .

[0097] (Note 14) In the exercise content generation step, a cyberattack in accordance with the attack scenario is executed on a computer system, logs are collected from the computer system, and the collected logs are used to generate the new exercise content. As described in Appendix 11 program .

[0098] (Note 15) before On the computer, The exercise content verification step involves calculating the similarity between the newly generated exercise content and the group of content extracted from the course history data, and if the calculated similarity is below a threshold, using the new exercise content as review content for the student. Furthermore, Let it be executed ru, As described in Appendix 11 program . [Industrial applicability]

[0099] As described above, this disclosure allows for the generation of security exercise content according to the learner's progress. This disclosure is useful for systems that conduct training against cyberattacks. [Explanation of Symbols]

[0100] 10 Information Processing Devices 11. Course History Extraction Section 12. Content Feature Identification Section 13. Exercise Content Generation Section 131 Simulated Attack Generation Unit 132 Simulated Attack Execution Unit 133 Log acquisition section 134 Assignment generation section 14. Exercise Content Verification Department 20 Course History Database 21 Exercise Content Database 22 Simulated Attack Scenario Database 23 Attack Command Database 100 Computer Systems 110 Computer 111 CPU 112 Main Memory 113 Storage device 114 Input Interface 115 Display Controller 116 Data Readers / Writers 117 Communication Interface 118 Input devices 119 Display device 120 recording media 121 Bus

Claims

1. A learning history extraction unit extracts content sets that match certain criteria from learning history data that identifies the exercise content and learning results of cybersecurity exercises taken by participants. A content feature identification unit identifies the characteristics of the content group using attribute information in the extracted content group, An exercise content generation unit generates attack scenarios for cyberattacks using the identified characteristics, and further generates new exercise content for cybersecurity exercises using the generated attack scenarios. An information processing device characterized by having the following features.

2. The content feature identification unit identifies exercise tasks and attack content that satisfy the set conditions from the exercise tasks and attack content included in the attribute information, and defines the identified exercise tasks and attack content as features of the content group. The information processing apparatus according to claim 1.

3. The content feature identification unit identifies exercise tasks and attack content that exist in a predetermined proportion or more of the exercise tasks included in the attribute information, and defines the identified exercise tasks and attack content as features of the content group. The information processing apparatus according to claim 2.

4. The exercise content generation unit executes a cyberattack on a computer system in accordance with the attack scenario, collects a set of logs from the computer system, and uses the collected log set to generate the new exercise content. The information processing apparatus according to claim 1.

5. The system further includes an exercise content verification unit that calculates the similarity between the newly generated exercise content and the group of content extracted from the course history data, and if the calculated similarity is below a threshold, uses the new exercise content as content for the student's review. The information processing apparatus according to claim 1.

6. From the course history data, which identifies the course content and results of the cybersecurity exercises taken by the participants, we extract a group of content that matches the specified criteria. Using the attribute information of the extracted content group, the characteristics of the content group are identified. Using the identified characteristics, attack scenarios for cyberattacks are generated, and further, new exercise content for cybersecurity exercises is generated using the generated attack scenarios. An information processing method characterized by the following:

7. On the computer, From the course history data, which identifies the course content and results of the cybersecurity exercises taken by the participants, we extract a group of content that matches the specified criteria. Using the attribute information in the extracted content group, the characteristics of the content group are identified. A program that generates attack scenarios for cyberattacks using the identified characteristics, and further generates new exercise content for cybersecurity exercises using the generated attack scenarios.

Citation Information

Patent Citations

  • Education service system and education service providing method using communication line

    JP2003006348A

  • Cyber terrorism security simulator of nuclear power plant

    JP2017198836A

  • Exercise control program for cyber-attack

    JP2019191670A

  • Exercise display program for cyber-attack

    JP2019191671A

  • Program, information processing device and cyber exercise control method

    JP2021120780A