Log generation device, log generation method, and log generation program
The log generation device addresses the lack of security event logging in industrial control systems by analyzing and converting target event data into log format, thereby improving security monitoring and analysis.
Patent Information
- Application Number
- PCT/JP2023/045903
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-26
AI Technical Summary
Existing industrial control systems, particularly those with embedded devices like PLCs, often lack the capability to record or output security event logs, making it difficult to perform effective security monitoring.
A log generation device that analyzes data from target events in embedded control devices and converts this data into event log format, enabling the creation of logs indicating security events even where the device itself does not have this functionality.
This solution allows for the generation of security event logs in industrial control systems, even from devices that do not have the capability to record or output such logs, thereby enhancing security monitoring and analysis capabilities.
Smart Images

Figure JP2023045903_26062025_PF_FP_ABST
Abstract
Description
Log generation device, log generation method, and log generation program
[0001] The present disclosure relates to a log generation device, a log generation method, and a log generation program.
[0002] Security monitoring of industrial control systems requires the collection of security event logs from each device. In particular, it is necessary to collect login histories and event logs, such as setting changes, for embedded control devices such as programmable logic controllers (PLCs). However, many existing embedded control devices do not record such logs, or even if they do, they do not have the functionality to output them. Specific examples of existing technologies for monitoring the security of industrial control systems include log collection agents installed on personal computers (PCs) and intrusion detection systems (IDSs) that monitor networks. However, log collection agents cannot be installed on PLCs, which are embedded devices. Furthermore, while IDSs can monitor for signs of cyberattacks on networks, they are not suitable for acquiring event logs generated by devices such as PLCs. Patent document 1 discloses an unauthorized communication device that connects to a control system network, observes communication data between a monitoring device and a control device, analyzes the communication header of the observed communication data, and determines whether the communication is unauthorized.
[0003] Patent No. 6860161
[0004] The technology disclosed in Patent Document 1 analyzes only the communication header and does not analyze the payload portion that contains security events. Therefore, this technology has a problem in that it cannot perform analysis based on security events such as logins and setting changes.
[0005] The present disclosure aims to provide a log generating device in an industrial control system that generates logs indicating security events in place of existing equipment such as PLCs that do not have the function to record logs or that record logs but do not have the function to output them.
[0006] The log generating device according to the present disclosure includes a packet analyzing unit that acquires target event data indicating a target event, which is a security event in a target device provided in a control system, by analyzing data indicating the target event; and a log generating unit that generates a target log indicating the target event by converting the target event data into an event log format.
[0007] According to the present disclosure, a packet analysis unit acquires data indicating a target event, which is a security event in a target device included in a control system, by analyzing data indicating the target event. Furthermore, a log generation unit generates a log indicating the target event. Here, the target device may not have a function for recording a log, or may record a log but not have a function for outputting it. Here, the control system may be an industrial control system. Therefore, according to the present disclosure, it is possible to provide a log generation device in an industrial control system that generates a log indicating a security event on behalf of an existing device, such as a PLC, that does not have a function for recording a log or that records a log but does not have a function for outputting it. Furthermore, the present disclosure is not limited to industrial control systems, but can also be applied to any system in which multiple embedded devices are connected via a communication network.
[0008] FIG. 1 is a diagram showing an example of the configuration of a log generation system 90 according to the first embodiment. FIG. 2 is a diagram showing an example of the hardware configuration of a log generation device 101 according to the first embodiment. FIG. 3 is a flowchart showing the operation of a packet analysis unit 205 according to the first embodiment. FIG. 4 is a diagram showing a specific example of a security event 209 according to the first embodiment. FIG. 5 is a flowchart showing the operation of a log generation unit 206 according to the first embodiment. FIG. 6 is a diagram showing a specific example of a log generation rule 207 according to the first embodiment. FIG. 7 is a diagram showing an example of the hardware configuration of a log generation device 101 according to a modification of the first embodiment. FIG. 8 is a diagram showing an example of the configuration of a log generation system 90 according to the second embodiment. FIG. 9 is a flowchart showing the operation of a command communication generation unit 305 according to the second embodiment. FIG. 10 is a diagram showing a specific example of an event acquisition method definition 308 according to the second embodiment. FIG. 11 is a flowchart showing the operation of a packet analysis unit 306 according to the second embodiment. FIG. 12 is a diagram showing a specific example of a log generation rule 309 according to the second embodiment.
[0009] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. The description of elements given the same reference numerals will be omitted or simplified as appropriate. Arrows in the drawings mainly indicate the flow of data or the flow of processing. Furthermore, "unit" may be read as "circuit," "step," "procedure," "process," or "circuitry" as appropriate.
[0010] First Embodiment Hereinafter, the present embodiment will be described in detail with reference to the drawings.
[0011] ***Description of Configuration*** FIG. 1 shows an example of the configuration of a log generation system 90 according to this embodiment. The log generation system 90 is a system in which a log generation device 101 is connected to a control system. As shown in FIG. 1, the log generation system 90 includes the log generation device 101, one or more monitoring devices 103, one or more control devices 104, and an SOC (Security Operation Center) 105. The devices included in the log generation system 90 are communicatively connected via a network 102. The network 102 may be a wired network or a wireless network. The control system is a system in which multiple embedded devices are connected via a communication network, and a specific example is an industrial control system. The log generation device 101 is connected to a network to which target devices are connected. As a specific example, the log generation device 101 is connected to a mirror port of a switching hub (not shown) on the network 102. The SOC 105 is connected to the network 102 directly or indirectly via a router or the like. The target device is a device included in the control system and corresponds to an embedded device. A specific example of the target device is the control device 104. The target device may be an environmental sensor such as a river water level sensor or a temperature sensor, or may be a security device such as a surveillance camera or an intrusion detection sensor.
[0012] The log generating device 101 includes a communication unit 204, a packet analysis unit 205, and a log generating unit 206. The log generating device 101 passively acquires data indicating security events. Specific examples of security events include a source address, a destination address, a port number, a control command, and a result.
[0013] The communication unit 204 acquires communication data 208 flowing through the network 102 and sends the acquired communication data 208 to the packet analysis unit 205. The communication unit 204 also receives a security event log 210 from the log generation unit 206 and transmits the received security event log 210 to the SOC 105. The communication data 208 is data indicating a target event and is typically unencrypted data.
[0014] The packet analysis unit 205 analyzes data indicating a target event to obtain target event data indicating the target event. The target event is a security event in the target device. As a specific example, the packet analysis unit 205 receives communication data 208 from the communication unit 204, generates a security event 209 from the received communication data 208, and sends the generated security event 209 to the log generation unit 206.
[0015] The log generation unit 206 generates a target log indicating the target event by converting the target event data into an event log format. The log generation unit 206 may generate the target log if the target event indicated by the target event data matches a log generation rule indicating the conditions for the security event to be output. The event log format may be any format. As a specific example, the log generation unit 206 receives a security event 209 from the packet analysis unit 205 and determines whether the received security event 209 matches the conditions described in the log generation rule 207. If the security event 209 matches the conditions, the log generation unit 206 generates a security event log 210 by processing the security event 209 into a predetermined format such as Syslog. The log generation unit 206 may add additional information such as time to the security event log 210. The security event log 210 corresponds to the target log.
[0016] The monitoring device 103 is a device that monitors signals from devices and sensors included in the control system and outputs the monitoring results.
[0017] The control device 104 is a device that controls devices, sensors, etc. A specific example of the control device 104 is a PLC (Programmable Logic Controller).
[0018] 2 shows an example of the hardware configuration of the log generating device 101 according to this embodiment. The log generating device 101 is made up of a computer. The log generating device 101 may be made up of multiple computers.
[0019] 2, the log generating device 101 is a computer including hardware such as a processor 201, a storage device 202, and a communication device 203. These pieces of hardware are connected appropriately via signal lines.
[0020] The processor 201 is an integrated circuit (IC) that performs arithmetic processing and controls the hardware of a computer. Specific examples of the processor 201 include a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The log generating device 101 may include multiple processors that replace the processor 201. The multiple processors share the role of the processor 201.
[0021] The storage device 202 is typically a non-volatile storage device, and specific examples thereof include a ROM (Read Only Memory), a HDD (Hard Disk Drive), or a flash memory. The storage device 202 may be a combination of a non-volatile storage device and a volatile storage device. A specific example of a volatile storage device is a RAM (Random Access Memory).
[0022] The communication device 203 is a receiver and a transmitter, and is specifically a communication chip or a NIC (Network Interface Card).
[0023] The storage device 202 stores a log generation program. The log generation program is a program that causes a computer to realize the functions of each unit included in the log generation device 101. The log generation program is loaded into memory and executed by the processor 201. The functions of each unit included in the log generation device 101 are realized by software.
[0024] Data used when executing the log generating program and data obtained by executing the log generating program are stored in a storage device as appropriate. Each unit of the log generating device 101 uses a storage device as appropriate. Note that the terms "data" and "information" may have the same meaning. The storage device may be independent of the computer.
[0025] The log generation program may be recorded on a computer-readable non-volatile recording medium. Specific examples of the non-volatile recording medium include an optical disk and a flash memory. The log generation program may be provided as a program product.
[0026] ***Explanation of Operation*** The operation procedure of the log generating device 101 corresponds to a log generating method. Also, the program that realizes the operation of the log generating device 101 corresponds to a log generating program.
[0027] 3 is a flowchart showing an example of the operation of the packet analysis unit 205. The operation of the packet analysis unit 205 will be described with reference to FIG.
[0028] (Step S101) The packet analysis unit 205 acquires communication data 208 from the network 102 via the communication unit 204 as target communication data, and analyzes the header of the target communication data to acquire information indicating the source IP (Internet Protocol) address, source IP port, destination IP address, destination IP port, protocol type, communication direction, etc. from the target communication data.
[0029] (Step S102) The packet analysis unit 205 determines whether the target communication data is a target for generating a security event based on the acquired information. Specifically, the packet analysis unit 205 makes this determination based on the port number and protocol type indicated by the acquired information. If the target communication data is a target for generating a security event, the packet analysis unit 205 proceeds to step S103. Otherwise, the packet analysis unit 205 ends the processing of this flowchart.
[0030] (Step S103) The packet analysis unit 205 analyzes the payload of the target communication data to obtain information indicating a command, an error code, parameters, etc. from the target communication data.
[0031] (Step S104) The packet analysis unit 205 generates a security event 209 from the target communication data. The security event 209 may include a reception time, a source address, a destination address, a port number, a communication direction, a control command, a command execution result, parameters, etc. Fig. 4 shows a specific example of the security event 209.
[0032] 5 is a flowchart showing an example of the operation of the log generating unit 206. The operation of the log generating unit 206 will be described with reference to FIG.
[0033] (Step S121 ) The log generating unit 206 reads the log generation rule 207 .
[0034] (Step S122) If the log generation rule 207 has been successfully read, the log generation unit 206 proceeds to step S123, otherwise the log generation unit 206 ends the processing of this flowchart.
[0035] (Step S123) The log generation unit 206 determines whether the acquired security event 209 matches the generation condition indicated by the log generation rule 207. If there are multiple log generation rules 207, the log generation unit 206 performs the determination for all of the log generation rules 207. Fig. 6 shows a specific example of the log generation rule 207. In this example, when the "Protocol" is "SLMP / UDP" and the "Command" is "Device Read," the log generation unit 206 generates a security event log 210.
[0036] (Step S124) For security events 209 that match the generation conditions, the log generation unit 206 extracts from the security events 209 the content described in the content. In the example shown in FIG. 6 , the log generation unit 206 extracts all (ALL) of the "SrcMAC," "SrcIP_Port," "DstMAC," "DstIP_Port," "Protocol," "Direction," "Command," and "DeviceCode" of the "Parameter." The log generation unit 206 processes the extracted security events 209 according to the format (Syslog in the example shown in FIG. 6 ) described in the "Format" column of the log generation rule 207, thereby generating a security event log 210. Thereafter, the log generation unit 206 transmits the generated security event log 210 to the SOC 105 via the communication unit 204.
[0037] ***Description of Effects of First Embodiment*** As described above, according to this embodiment, in a control system, it is possible to acquire security logs from devices that do not record security events.
[0038] ***Other Configurations*** <Modification 1> Fig. 7 shows an example of the hardware configuration of the log generating device 101 according to this modification. The log generating device 101 includes a processing circuitry 18 instead of the processor 201 or the processor 201 and the storage device 202. The processing circuitry 18 is hardware that realizes at least a portion of the components included in the log generating device 101. The processing circuitry 18 may be dedicated hardware, or may be a processor that executes a program stored in the storage device 202.
[0039] When the processing circuitry 18 is dedicated hardware, the processing circuitry 18 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The log generating device 101 may include multiple processing circuits that replace the processing circuitry 18. The multiple processing circuits share the role of the processing circuitry 18.
[0040] In the log generating device 101, some of the functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.
[0041] The processing circuitry 18 is realized by, for example, hardware, software, firmware, or a combination of these. The processor 201, the storage device 202, and the processing circuitry 18 are collectively referred to as "processing circuitry." In other words, the functions of the functional components of the log generating device 101 are realized by the processing circuitry. The log generating device 101 according to other embodiments may also have a configuration similar to that of this modified example.
[0042] Second Embodiment The following mainly describes the differences from the above-described embodiment with reference to the drawings.
[0043] *** Description of Configuration *** Fig. 8 shows an example configuration of a log generation system 90 according to embodiment 2. The log generation device 101 according to embodiment 2 includes a communication unit 304, a packet analysis unit 306, a log generation unit 307, a command communication generation unit 305, and a monitoring unit 314. The log generation device 101 actively acquires data indicating security events.
[0044] The monitoring unit 314 monitors the load of each device included in the control system. Each device may include the network 102. The monitoring unit 314 measures the load of the network 102 and the CPU utilization rate of the control device 104, and sends data indicating the measurement results to the command communication generation unit 305.
[0045] The command communication generation unit 305 generates a command communication 310 indicating a transmission instruction. The transmission instruction is an instruction to transmit data indicating a security event in the target device, and is an instruction to the target device. The command communication generation unit 305 may generate the command communication 310 in accordance with an event acquisition method definition 308. The event acquisition method definition 308 defines a method for acquiring a security event in the target device from the target device. As a specific example, the command communication generation unit 305 receives data indicating the measurement results from the monitoring unit 314, reads the event acquisition method definition 308, generates a command communication 310 from the received data in accordance with the read event acquisition method definition 308, and sends the generated command communication 310 to the communication unit 304.
[0046] The communication unit 304 transmits a command communication 310 to the target device. The communication unit 304 acquires a response communication 311 transmitted by the target device in accordance with the command communication 310 as data indicating the target event. The communication unit 304 may transmit the command communication 310 in accordance with the load monitored by the monitoring unit 314. As a specific example, the communication unit 304 receives the command communication 310 from the command communication generation unit 305 and transmits the received command communication 310 to the control device 104 via the network 102. At this time, the communication unit 304 may adjust the transmission frequency of the command communication 310 in consideration of the network load, the CPU utilization rate of the control device 104, and the like. The communication unit 304 also receives a security event log 313 from the log generation unit 307 and transmits the received security event log 313 to the SOC 105. The communication unit 304 receives the response communication 311 from the control device 104 via the network 102 and sends the received response communication 311 to the packet analysis unit 306.
[0047] The packet analysis unit 306 is similar to the packet analysis unit 205. The packet analysis unit 306 receives a response communication 311 from the communication unit 304, generates a security event 312 from the received response communication 311, and sends the generated security event 312 to the log generation unit 307.
[0048] The log generation unit 307 is similar to the log generation unit 206. The log generation unit 307 receives a security event 312 from the packet analysis unit 306 and determines whether the received security event 312 matches the conditions described in the log generation rule 309. If the security event 312 matches the conditions, the log generation unit 307 generates a security event log 313 from the security event 312.
[0049] The hardware configuration of the log generating device 101 is the same as the hardware configuration of the log generating device 101 according to embodiment 1. The functions of the monitoring unit 314 and the command communication generating unit 305 are realized by the processor 201. The storage device 202 stores an event acquisition method definition 308.
[0050] ***Explanation of Operation*** Fig. 9 is a flowchart showing an example of the operation of the command communication generation unit 305. The operation of the command communication generation unit 305 will be described with reference to Fig. 9 .
[0051] (Step S201) The command communication generation unit 305 reads the event acquisition method definition 308 and obtains information indicating the destination IP port, the port number, the protocol to be used, the control command, etc. from the read event acquisition method definition 308. Fig. 10 shows a specific example of the event acquisition method definition 308.
[0052] (Step S202) The command communication generating unit 305 generates a command communication 310 from the information acquired in step S201.
[0053] (Step S203) The command communication generation unit 305 determines whether the communication conditions are satisfied. Specific examples of the communication conditions include a condition indicating at least one of the following: a certain time interval has elapsed; a separately defined schedule has been reached; the network load status acquired by the monitoring unit 314 is below a certain level; and the CPU utilization rate of the control device acquired by the monitoring unit 314 is below a certain level. If the communication conditions are satisfied, the command communication generation unit 305 proceeds to step S204. Otherwise, the command communication generation unit 305 executes the processing of this step again.
[0054] (Step S204) The command communication generation unit 305 transmits the command communication 310 through the communication unit 304.
[0055] 11 is a flowchart showing an example of the operation of the packet analysis unit 306. The operation of the packet analysis unit 306 will be described with reference to FIG.
[0056] (Step S221) The packet analysis unit 306 acquires the response communication 311 from the network 102, and by analyzing the header of the acquired response communication 311, acquires information indicating the source IP address, source IP port, destination IP address, destination IP port, protocol type, communication direction, etc. from the response communication 311.
[0057] (Step S222) This step is the same as step S103 except that the packet analysis unit 306 analyzes the payload of the response message 311.
[0058] The operation of the log generation unit 307 is similar to the operation of the log generation unit 206. Fig. 12 shows a specific example of the log generation rule 309. In this example, when the "Title" is "Ethernet Communication Load (Up)", the log generation unit 307 generates a security event log 313.
[0059] ***Explanation of Effects of Embodiment 2*** As described above, according to this embodiment, in a control system, it is possible to acquire a security event log from a device that records a security event but does not output it. Furthermore, according to this embodiment, when acquiring a security event log, it is possible to relatively reduce the load on the network, the target control device, etc.
[0060] ***Other Embodiments*** The above-described embodiments can be freely combined, or any of the components of each embodiment can be modified, or any of the components can be omitted from each embodiment. Furthermore, the embodiments are not limited to those shown in embodiments 1 and 2, and various modifications are possible as needed. The procedures described using flowcharts, etc., can be modified as appropriate.
[0061] 18 Processing circuit, 90 Log generation system, 101 Log generation device, 102 Network, 103 Monitoring device, 104 Control device, 105 SOC, 201 Processor, 202 Storage device, 203 Communication device, 204, 304 Communication unit, 205, 306 Packet analysis unit, 206, 307 Log generation unit, 207, 309 Log generation rule, 208 Communication data, 209, 312 Security event, 210, 313 Security event log, 305 Command communication generation unit, 308 Event acquisition method definition, 310 Command communication, 311 Response communication, 314 Monitoring unit.
Claims
1. A packet analysis unit that acquires target event data indicating a target event, which is a security event in a target device included in a control system, by analyzing data indicating the target event; and a log generation unit that generates a target log indicating the target event by converting the target event data into an event log format. A log generation device comprising the above.
2. The log generation device according to claim 1, wherein the log generation unit generates the target log when the target event indicated by the target event data matches a log generation rule indicating a condition for a security event to be output.
3. The log generation device according to claim 1 or 2, wherein the log generation device is connected to a network to which the target device is connected, and the log generation device further comprises a communication unit that acquires data indicating the target event from the network.
4. The log generation device according to claim 1 or 2, wherein the log generation device is connected to a network to which the target device is connected, and the log generation device further comprises a command communication generation unit that generates command communication indicating a transmission instruction, which is an instruction to transmit data indicating a security event in the target device and is an instruction for the target device; and a communication unit that transmits the command communication to the target device and acquires, as data indicating the target event, response communication transmitted by the target device according to the command communication.
5. The log generation device according to claim 4, wherein the command communication generation unit generates the command communication according to an event acquisition method definition indicating a method for acquiring a security event in the target device from the target device.
6. The log generation device according to claim 4 or 5, wherein the log generation device further comprises a monitoring unit that monitors the load of each device included in the control system, and the communication unit transmits the command communication according to the monitored load.
7. A log generation method in which a computer acquires target event data indicating a target event, which is a security event in a target device included in a control system, by analyzing data indicating the target event, and the computer generates a target log indicating the target event by converting the target event data into an event log format. A log generation program that causes a log generation device, which is a computer, to execute: a packet analysis process for acquiring target event data indicating a target event, which is a security event in a target device included in a control system, by analyzing data indicating the target event; and a log generation process for generating a target log indicating the target event by converting the target event data into an event log format.
Citation Information
Patent Citations
Control device, control system, control method, and program
JP2015035648A
Overlay cyber security networked system and method
US10250619B1
Security event logging in process control
US20130055389A1
Industrial Network Security Translator
US20170126745A1