Abnormality detection method, monitoring device, and program
The abnormal detection method addresses the inadequacy of existing countermeasures by prioritizing analysis and response to cyber attacks in power facilities based on the power shortage degree, ensuring effective handling of security events during high demand situations.
Patent Information
- Application Number
- PCT/JP2024/042185
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-30
- Filing Date
- 2024-11-28
- Publication Date
- 2025-06-26
AI Technical Summary
Existing countermeasures for cyber attacks on power facilities do not adequately consider the degree of power shortage, which can exacerbate damage during high demand and tight power supply situations.
An abnormal detection method that utilizes a monitoring device to analyze transmission/reception information between power facilities, determining an analysis priority for detected security events based on an abnormality score and the degree of power shortage.
Enables appropriate handling of abnormalities in power facilities even during power shortages by prioritizing analysis and response to security events based on the power demand situation.
Smart Images

Figure JP2024042185_26062025_PF_FP_ABST
Abstract
Description
Anomaly detection method, monitoring device, and program
[0001] The present disclosure relates to an anomaly detection method, a monitoring device, and a program.
[0002] In the case of power plants, electric vehicle charging stations, and other electric power facilities, if they are subjected to a cyber attack, there is a risk that excessive loads may occur, causing damage or fraud. For this reason, as a countermeasure against cyber attacks targeting power facilities, the installation of intrusion detection devices (IDS) that detect cyber attacks and the introduction of security monitoring systems are being considered, or are being considered.
[0003] For example, Patent Document 1 discloses a technology that aims to determine the priority of cyber-attacks in real time, taking into account the situation of cyber-attacks that evolves in real time, and to make it easier to determine the optimal measures to minimize the damage caused by cyber-attacks.
[0004] Japanese Patent Application Laid-Open No. 2022-191649
[0005] In this situation, if a cyber attack were to occur on power facilities during a power shortage situation where power demand is high and power supply is tight, there is a risk that the damage could be exacerbated.However, measures against security events (attack events) such as cyber attacks on power facilities have not taken into consideration the degree of power shortage, which indicates the power shortage situation, and there is room for improvement in how to deal with abnormalities in power facilities.
[0006] An object of the present disclosure is to make it possible to appropriately deal with abnormalities in power equipment even in a power shortage situation.
[0007] An anomaly detection method according to the present disclosure is executed by a monitoring device that monitors communication between a first power facility configured to be capable of at least one of power supply and power reception with a connected charging / discharging device and a second power facility that controls the first power facility. The anomaly detection method includes performing anomaly detection based on transmission / reception information transmitted and received between the first power facility and the second power facility. The anomaly detection method includes determining an analysis priority for analyzing a detected event, which is a security event detected by the anomaly detection, based on an anomaly score of the detected event and information on a power pressure level that indicates the degree of pressure on power demand at the time of the detection.
[0008] FIG. 1 is a diagram illustrating an example of the configuration of a charging system according to a first embodiment. FIG. 2 is a diagram illustrating an example of the configuration of a security monitoring server according to the first embodiment. FIG. 3 is a diagram illustrating an example of the configuration of a charging station management server according to the first embodiment. FIG. 4 is a diagram illustrating an example of the configuration of a charging device according to the first embodiment. FIG. 5 is a diagram illustrating an example of the hardware configuration of an information processing device that realizes each device of the charging system according to the first embodiment. FIG. 6 is a diagram illustrating an example of the configuration of a charging history table according to the first embodiment. FIG. 7 is a diagram illustrating an example of the configuration of an abnormality detection result table according to the first embodiment. FIG. 8 is a sequence diagram illustrating an example of the flow of an abnormality detection process executed in the charging system according to the first embodiment. FIG. 9 is a flowchart illustrating an example of the flow of a correction score calculation process based on a power tightness level executed in the security monitoring server according to the first embodiment. FIG. 10 is a diagram for explaining calculation of a correction score according to a power tightness level according to the first embodiment. FIG. 11 is a diagram illustrating an example of the configuration of a charging system according to a fourth embodiment. FIG. 12 is a diagram illustrating an example of the configuration of a security monitoring server according to a fifth embodiment. FIG. 13 is a diagram illustrating an example of the configuration of an abnormality detection result table according to the fifth embodiment. Fig. 14 is a sequence diagram showing an example of the flow of an abnormality detection process executed in a charging system according to the fifth embodiment. Fig. 15 is a flowchart showing an example of the flow of an analysis priority determination process based on a power tightness level executed in a security monitoring server according to the fifth embodiment. Fig. 16 is a diagram showing an example of an event management screen displayed in a security monitoring server according to the sixth embodiment.
[0009] Hereinafter, with reference to the drawings, embodiments of a charge control method (anomaly detection method), a charge control device (monitoring device), a charge system (monitoring system), a program, and a recording medium according to the present disclosure will be described.
[0010] In the description of the present disclosure, components having the same or substantially the same functions as those described above with respect to the previously-mentioned drawings may be given the same reference numerals, and descriptions thereof may be omitted as appropriate. Furthermore, even when the same or substantially the same parts are shown, the dimensions and proportions may be different depending on the drawing. Furthermore, for example, in order to ensure the visibility of the drawings, reference numerals may be given to only the main components in the description of each drawing, and reference numerals may not be given to components having the same or substantially the same functions as those described above with respect to the previously-mentioned drawings.
[0011] In the description of the present disclosure, components having the same or substantially the same functions may be distinguished by adding an alphanumeric character to the end of the reference symbol. Alternatively, when multiple components having the same or substantially the same functions are not distinguished, they may be collectively described by omitting the alphanumeric character at the end of the reference symbol.
[0012] The present disclosure provides an example of a charging system that provides charging and discharging services to mobile objects such as electric vehicles that are configured to be powered by power from an onboard battery, using power equipment installed in a charging station (power infrastructure).
[0013] Here, the charging service is a service that supplies power from a charging station to a mobile object to charge a battery mounted on the mobile object, for example, by selling the power to the user of the mobile object. The discharging service is a service that purchases power from the user of the mobile object, for example, by discharging the battery mounted on the mobile object and using the power from the mobile object to charge a battery at the charging station, or by supplying power from the mobile object to an upstream power grid (system).
[0014] Here, a mobile object is an example of a charging / discharging device equipped with a battery (storage battery) and configured to charge the battery using power supplied from an external source and discharge the battery by receiving power from the battery to an external source. The battery of this charging / discharging device can be any battery, such as a lithium-ion battery, a nickel-metal hydride battery, or an all-solid-state battery. The mobile object may be any type of electric vehicle, such as an electric vehicle (EV) driven by a motor, or a hybrid vehicle driven by both an internal combustion engine and a motor. The mobile object may be, for example, a passenger car, truck, or motorcycle, but may also be an electric bicycle, an electric kick scooter, an electric wheelchair, construction machinery, agricultural machinery, a ship, a train, an airplane, or the like. The mobile object is not limited to passenger vehicles, but may also be a cargo vehicle such as a luggage transport vehicle. The mobile object may be configured to be autonomous or to be driven by a driver's direct or remote control.
[0015] The technology disclosed herein is not limited to mobile objects such as electric vehicles, but can also be applied to various types of power devices and power facilities in which the output or input of power is controlled by communication, such as power storage devices, power generation devices, and charging devices at charging stations.
[0016] First Embodiment Fig. 1 is a diagram showing an example of the configuration of a charging system 1 according to a first embodiment. As shown in Fig. 1, the charging system 1 includes a security monitoring server 3, a charging station 5, and an analyst terminal 7. The charging station 5 is a facility (electric power infrastructure) for providing a charging service or a discharging service to a visiting vehicle 9 (mobile object), and includes a charging station management server 51 and a charging device 52 as shown in Fig. 1.
[0017] 1 , the security monitoring server 3, the charging station management server 51, and the charging device 52 are communicatively connected via a network N, which is a telecommunications line such as the Internet. The security monitoring server 3 and the analyst terminal 7 are also communicatively connected via the network N. The charging device 52 is connected to an upstream power grid (not shown) via a power transmission grid such as an electric wire, for example, so as to be able to exchange power with the upstream power grid.
[0018] As an example, in the charging system 1, the charging device 52 is controlled by communicating with the charging station management server 51. The security monitoring server 3 monitors the bidirectional communication between the charging station management server 51 and the charging device 52. The security monitoring server 3 detects security events indicating anomalies or the possibility of anomalies due to cyberattacks based on control messages transmitted and received through this communication, and calculates, as the detection results, an anomaly score indicating, for example, normality or anomaly. The security monitoring server 3 also executes a correction score calculation process to calculate a corrected score by correcting the anomaly score indicating whether or not a detected security event (detected event) is abnormal, based on the degree of power pressure. The analyst terminal 7 analyzes the detected detected events by presenting the detected events to an analyst in a priority order based on the correction score, for example, in descending order of the correction score, and by acquiring the analyst's analysis results of the detected detected events. The detected events presented to the analyst may be all detected security events, or may be only security events determined to be abnormal, i.e., attack events with an anomaly score or a corrected score greater than "0." An attack event may be a collection of multiple attack messages that aggregate various attack messages and alerts.
[0019] The charging system 1 may include two or more charging stations 5. Furthermore, each of at least one charging station 5 in the charging system 1 may include two or more charging devices 52. Furthermore, the charging system 1 may include two or more analyst terminals 7. Furthermore, at least one analyst terminal 7 may not be included in the charging system 1 but may be an external information processing device. Each of at least one charging device 52 is connected to a vehicle 2 visiting the charging station 5 so as to be able to exchange power via, for example, a detachable charging cable (not shown) mounted on the vehicle 9 or the charging device 52. The number of vehicles 9 connected to or connectable to one charging device 52 may be two or more. The vehicle 9 connected to the charging device 52 is a mobile object configured to be powered by power from an onboard battery (not shown) and can receive charging and discharging services at the charging station 5. Furthermore, each of at least one vehicle 9 may be included in the charging system 1.
[0020] The security monitoring server 3 is an example of a monitoring device that monitors communication between the charging station management server 51 and the charging device 52. The security monitoring server 3 is configured to be able to execute an anomaly detection method according to an embodiment. For example, the security monitoring server 3 is configured to be able to execute a correction score calculation process based on a power tightness according to an embodiment. FIG. 2 is a diagram showing an example of the configuration of the security monitoring server 3 according to the first embodiment. As shown in FIG. 2, the security monitoring server 3 includes an anomaly detection unit 31, a score correction unit 32, a memory unit 33, a communication unit 34, and a display unit 35.
[0021] The anomaly detection unit 31 detects an anomaly related to charging or discharging at the charging station 5 based on transmission / reception information transmitted and received between the charging station management server 51 and the charging device 52. For example, the anomaly detection unit 31 determines whether a received message (transmission / reception information) from the charging device 52 is normal, and if it is not normal (abnormal), detects it as a security event. Furthermore, for the detected security event (detected event), the anomaly detection unit calculates an anomaly score indicating, for example, normality or abnormality based on the received message. Furthermore, when the anomaly detection unit 31 detects a security event, it outputs information indicating the detection result (for example, an anomaly score) to the storage unit 33 or to an external device. For example, the anomaly detection unit 31 determines that the control target determined by the received message to be abnormal is an attack target, and calculates the anomaly score by referring to, for example, score values, relational expressions, and parameters predetermined for each attack target and stored in the storage unit 33 or the like.
[0022] The anomaly detection unit 31 may perform anomaly detection based not only on received messages from the charging device 52 but also on transmitted messages (transmitted and received information) transmitted from the device itself to the charging device 52 or the like. The anomaly detection unit 31 may perform anomaly detection and calculate anomaly scores based on any transmitted and received information indicated in transmitted and received messages, such as control details, control values, observed values (actual measured values), and predicted values, rather than on control targets (attack targets). In this case, the transmitted and received information used for anomaly detection and the transmitted and received information used for calculating the anomaly score may be the same or different. The anomaly detection unit 31 may calculate an anomaly score based not only on attack targets but also on the type of cyber-attack, the number of attack targets, the extent of damage caused by the attack, and the like. The anomaly detection unit 31 may also be installed outside the security monitoring server 3, for example, in the charging station management server 51 or the charging device 52.
[0023] The score correction unit 32 is configured to determine an analysis priority for analyzing a detected event based on an anomaly score of the detected event detected by anomaly detection and information related to the power tightness at the time of detection. Specifically, the score correction unit 32 executes a corrected score calculation process that calculates a corrected score by correcting the anomaly score, which indicates whether the detected event is normal or abnormal, according to the power tightness. The score correction unit 32 determines an analysis priority based on the calculated corrected score. Details of the corrected score calculation process will be described later.
[0024] Here, the information relating to the degree of power tightness is information indicating the degree of tightness in power demand at the time of detection, and is, for example, information indicating the charge control mode (operation mode) of the charging device 52. The charge control mode of the charging device 52 includes at least a normal mode and a suppression mode in which the charging device 52 performs operations related to the charging service. The charge control mode of the charging device 52 may further include a discharge mode in which the charging device 52 performs operations related to the discharging service.
[0025] For example, the normal mode is an operation mode in which charging is performed without any restriction on the charging upper limit. Specifically, the normal mode is an operation mode in which power is supplied to the vehicle 9 without any restriction on the power supply due to a power shortage, such as when there is no tight power demand. Here, the restriction on the power supply due to a power shortage refers to setting upper limits (thresholds) for the power supply amount, power supply speed, number of power supplies, and power supply frequency, or reducing the set upper limits.
[0026] For example, the suppression mode is an operation mode in which charging is performed with a restriction imposed on the upper limit of charging. Specifically, the suppression mode is an operation mode in which, when the demand for power is tight, for example, power is supplied to the vehicle 9 in a state in which the power supply is limited due to the power tightness in response to a request from the charging station management server 51 or the power grid.
[0027] For example, the discharge mode is an operation mode in which power is supplied from the vehicle 9 to the charging device 52. Specifically, the discharge mode is an operation mode in which, when power demand is tight, for example, in response to a request from the charging station management server 51 or the power grid, the battery mounted on the vehicle 9 connected to the charging device 52 is discharged and the discharged power is supplied from the battery.
[0028] The storage unit 33 is a storage medium or storage device that stores control programs, parameters, data being processed, and data on processing results related to each process executed by the security monitoring server 3. As an example, the storage unit 33 stores an anomaly detection result table 331 that stores output results from the anomaly detection unit 31 and the score correction unit 32. Details of the anomaly detection result table 331 will be described later.
[0029] The communication unit 34 is a communication circuit that communicates with the outside of the security monitoring server 3. A communication circuit for wired or wireless communication can be used as appropriate for the communication unit 34. A communication circuit for wireless communication can be used as appropriate for communication circuits that comply with various standards such as 4G, 5G, 6G, Wi-Fi (registered trademark), Bluetooth (registered trademark), and infrared communication.
[0030] The display unit 35 is a display that displays various images. As this display, a display device such as a liquid crystal display (LCD), an organic electroluminescence (EL) display, or a projector can be used as appropriate. As an example, the display unit 35 displays the determination results stored in the storage unit 33. For example, the display unit 35 displays a display screen that displays a list of detected events based on the anomaly detection result table 331. Note that this display screen may also include an indication of the analyst (analyst) and the response status.
[0031] The charging station management server 51 is an example of a second power facility that controls the charging device 52. For example, the charging station management server 51 is configured to be able to control both power supply to the vehicle 9 by the charging device 52 and power discharge by the vehicle 9, i.e., power reception from the vehicle 9. FIG. 3 is a diagram showing an example of the configuration of the charging station management server 51 according to the first embodiment. As shown in FIG. 3, the charging station management server 51 includes a charging control instruction unit 511, a storage unit 512, and a communication unit 513.
[0032] The charge control instruction unit 511 controls the operation of the charging device 52 through communication with the charging device 52. For example, the charge control instruction unit 511 transmits a control message (transmitted / received information) for controlling the operation of the charging device 52 via the communication unit 513. Furthermore, for example, the charge control instruction unit 511 receives a message (transmitted / received information) from the charging device 52 via the communication unit 513. For example, the message transmitted to the charging device 52 includes a control message for controlling power supply to the connected vehicle 9. For example, the message transmitted to the charging device 52 includes a control message for controlling discharging from the connected vehicle 9. For example, the message received from the charging device 52 includes a message indicating that the transmitted control message has been received. For example, the message received from the charging device 52 includes a message indicating the status of the power supply or discharging, such as the amount of power supply or discharging, the start time, end time, duration, and remaining battery capacity. For example, the message received from the charging device 52 includes a message indicating the status of the charging device 52 during power supply or discharging, such as observed values such as temperature and communication bandwidth. These messages (transmitted and received information) may include a message to instruct the charging device 52 to select a charging control mode (operating mode), or a message to notify the charging device 52 of the charging control mode that is being executed or has been executed.
[0033] The storage unit 512 is a storage medium or storage device that stores control programs, parameters, data during processing, and data on processing results related to each process executed by the charging station management server 51. As an example, the storage unit 512 stores a charging history table 5121 that stores information indicating the history of charging and discharging performed by the charging devices 52 that are subject to management. The charging history table 5121 will be described in detail later.
[0034] The communication unit 513 is a communication circuit that communicates with the outside of the charging station management server 51. A communication circuit for wired or wireless communication can be used as appropriate as the communication unit 513. A communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi (registered trademark), Bluetooth (registered trademark), and infrared communication can be used as appropriate as the communication circuit for wireless communication.
[0035] The charging station management server 51 may be installed, for example, inside the charging station 5 together with the charging device 52, or may be installed outside the charging station 5. The charging station management server 51 may also control the charging device 52 of another charging station 5. In this case, the other charging station 5 may not be provided with the charging station management server 51.
[0036] The charging device 52 is configured to be operable in accordance with instructions (control messages) from the charging station management server 51. The charging device 52 is an example of a first power facility configured to be capable of performing at least one of power supply and power reception between the charging device 52 and the connected vehicle 9. For example, the charging device 52 is configured to be capable of performing an operation related to a charging service, in which the charging device 52 supplies (sells) power to the connected vehicle 9 and charges a battery mounted on the vehicle 9 in response to a request from the user of the vehicle 9. Furthermore, for example, the charging device 52 is configured to be capable of performing an operation related to a discharging service, in which the charging device 52 receives (purchases) power discharged from a battery mounted on the connected vehicle 9 and discharges the battery mounted on the vehicle 9 in response to a request from the charging station management server 51 or the power grid. Note that the discharging service may be performed in response to a request from the user of the vehicle 9. Note that the charging device 52 operable in the normal mode and the suppressed mode and the charging device 52 operable in the discharging mode may be configured as independent devices. FIG. 4 is a diagram illustrating an example of the configuration of the charging device 52 according to the first embodiment. As shown in FIG. 4 , the charging device 52 includes a charging control unit 521 and a communication unit 522 .
[0037] The charging control unit 521 controls charging and discharging of the connected vehicle 9 in accordance with the control of the charging station management server 51. The charging control unit 521 operates the charging device 52 in one of a plurality of charging control modes including at least a normal mode, a suppression mode, and a discharging mode. In this way, the charging control unit 521 realizes the charging and discharging functions of the charging device 52. As an example, the charging control unit 521 controls the charging control mode of the charging device 52 in accordance with an instruction (control message) from a charging control instruction unit 511 installed in the charging station management server 51.
[0038] The communication unit 522 is a communication circuit that communicates with the outside of the charging device 52. A communication circuit for wired or wireless communication can be used as appropriate as the communication unit 522. As a communication circuit for wireless communication, a communication circuit compatible with various standards such as 4G, 5G, 6G, Wi-Fi (registered trademark), Bluetooth (registered trademark), and infrared communication can be used as appropriate.
[0039] The analyst terminal 7 is an information processing device used by an analyst who performs the analysis. The analyst terminal 7 is configured to be able to execute an analysis process for the determination result of the anomaly detection process according to the embodiment, i.e., for a detected event. As an example, the analyst terminal 7 receives an analysis request from the security monitoring server 3. For example, this analysis request is transmitted to the analyst terminal 7 used by the analyst whose assignment has been determined by the security monitoring server 3. The analysis request may include various information related to the detected event to be analyzed. For example, the analysis request may include some or all of the items in the anomaly detection result table 331 or the charging history table 5121. Furthermore, for example, the analysis request may include information related to the device in which the detected event to be analyzed occurred and the devices connected to that device, such as the name and type of the charging station management server 51, the charging device 52, and the vehicle 9, the installed application programs, and the versions of each application program. As an example, the analyst terminal 7 displays various display screens, such as a notification screen that notifies the analyst of the detected event to be analyzed and an input screen that accepts the analyst's input of the analysis results, on a display equipped with the analyst terminal 7 or a connected display. As an example, the analyst terminal 7 transmits the analysis results input by the analyst to the security monitoring server 3 .
[0040] The analyst terminal 7 may be configured to perform the analysis itself, or may be configured to perform analysis assistance by generating information to assist the analyst in the analysis. In this case, the analyst terminal 7 may perform the analysis or analysis assistance using a machine learning model whose parameters are determined to output analysis results or assisting information in response to input information about the detection event to be analyzed. The parameters of this machine learning model may be determined by learning using, for example, accumulated information about past detection events and past analysis results by analysts for each detection event as training data. Any machine learning model, such as a convolutional neural network (CNN), can be used as this machine learning model. The analyst terminal 7 may also be provided outside the charging system 1.
[0041] Note that two or more devices included in the charging system 1 according to the above-described embodiment may be configured as an integrated unit. For example, the charging station management server 51 and the charging device 52 may be configured as an integrated unit. Alternatively, the charging station management server 51 may be realized by the cooperation of two or more charging devices 52. For example, the security monitoring server 3 and the analyst terminal 7 may be configured as an integrated unit. Alternatively, the security monitoring server 3 may be realized by the cooperation of two or more analyst terminals 7.
[0042] 5 is a diagram showing an example of the hardware configuration of an information processing device 8 that realizes each device (security monitoring server 3, charging station management server 51, charging device 52, and analyst terminal 7) of the charging system 1 according to the first embodiment. As shown in FIG. 5 , the information processing device 8 includes a processor 81, a main storage device 82, an auxiliary storage device 83, and an I / F (interface) circuit 84. The processor 81, the main storage device 82, the auxiliary storage device 83, and the I / F circuit 84 are communicatively connected to each other via, for example, a bus 89. Note that each component of the information processing device 8 may be realized by a combination of two or more components.
[0043] The information processing device 8 has at least one processor 81 and at least one main storage device 82 (memory), and has a hardware configuration using a normal computer. For example, the at least one processor 81 loads a program stored in the auxiliary storage device 83 into the main storage device 82 and executes the loaded program, thereby realizing each function of each device. Note that the at least one processor 81 of the information processing device 8 may be configured as a dedicated hardware circuit.
[0044] For example, in the security monitoring server 3, at least one processor 81 realizes each function of the security monitoring server 3, including the anomaly detection unit 31 and the score correction unit 32. Note that the anomaly detection unit 31 may execute some or all of the functions of the score correction unit 32, or the anomaly detection unit 31 and the score correction unit 32 may be realized as a single function. For example, in the charging station management server 51, at least one processor 81 realizes each function of the charging station management server 51, including the charging control instruction unit 511. For example, in the charging device 52, at least one processor 81 realizes each function of the charging device 52, including the charging control unit 521. For example, in the charging device 52, at least one processor 81 realizes each function of the analyst terminal 7.
[0045] As the at least one processor 81, various types of processors such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), an ASIC (Application Specific Integrated Circuit), or an FPGA (Field Programmable Gate Array) can be used as appropriate.
[0046] As the main storage device 82, various types of memory such as RAM (Random Access Memory) can be used as appropriate.
[0047] As the auxiliary storage device 83, various recording media and recording devices such as a ROM (Read Only Memory), an HDD (Hard Disk Drive), an SSD (Solid State Drive), and a flash memory can be used as appropriate.
[0048] For example, at least one of the main storage device 82 and the auxiliary storage device 83 in the security monitoring server 3 implements the storage unit 33. For example, at least one of the main storage device 82 and the auxiliary storage device 83 in the charging station management server 51 implements the storage unit 512. For example, at least one of the main storage device 82 and the auxiliary storage device 83 in each of the charging device 52 and the analyst terminal 7 implements the respective storage units (not shown).
[0049] The I / F circuit 84 is an interface for implementing input / output functions, connecting external devices, and / or communicating with the outside. The I / F circuit 84 may be an output interface for connecting or implementing an output device that outputs audio, images, or video, an input interface for connecting or implementing an input device that acquires user input, or an interface that functions as one of these devices. As output devices, various displays such as an LCD display, an organic EL display, or a projector, as well as speakers, can be used as appropriate. As input devices, a keyboard, a mouse, a touch panel, a microphone, etc. can be used as appropriate.
[0050] For example, in the security monitoring server 3, the I / F circuit 84 realizes an output interface (display unit 35) that connects or realizes an output device, an input interface (not shown) that connects or realizes an input device, and a communication interface (communication unit 34) for communicating with the outside. For example, in the charging station management server 51, the I / F circuit 84 realizes a communication interface (communication unit 513) for communicating with the outside. For example, in the charging device 52, the I / F circuit 84 realizes a power interface that connects to the power grid (system) and the vehicle 9, and a communication interface (communication unit 513) for communicating with the outside. For example, in the analyst terminal 7, the I / F circuit 84 realizes an output interface (not shown) that connects or realizes an output device, an input interface (not shown) that connects or realizes an input device, and a communication interface (not shown) for communicating with the outside.
[0051] Note that, with regard to each device included in the charging system 1 according to the above-described embodiment, only the configuration necessary to explain the main parts of this embodiment is illustrated, but the configurations possessed by each of these devices are not limited to these.
[0052] Management of the charge / discharge history of the managed charging device 52 by the charging station management server 51 according to this embodiment will now be described with reference to the drawings. FIG. 6 is a diagram showing an example of the configuration of a charging history table 5121 according to the first embodiment. As shown in FIG. 6, the charging history table 5121 includes at least the following fields: "Charging Start Time," "Charging End Time," "Charging Device ID," "Supplied Power (kW)," "Power Consumption (kW)," and "Charging Control Mode." The "Charging Start Time" and "Charging End Time" fields store information indicating the start and end times of charging and discharging, respectively. The "Charging Device ID" field stores identification information for uniquely identifying the charging device 52 that performed charging and discharging. The "Supplied Power (kW)" field stores the value of the amount of power from the power grid (grid) used during charging. Therefore, the "Supplied Power (kW)" field stores a value greater than or equal to 0 during charging, whereas the "Supplied Power (kW)" field stores a value of zero during discharging. The "power consumption (kW)" field stores the value of the amount of power supplied from the charging device 52 to the battery of the vehicle 9 during charging and discharging. Therefore, the "power consumption (kW)" field stores a positive value of 0 or greater during charging, and a negative value during discharging. Here, the power consumption of the vehicle 9 during charging may be all or a portion of the supplied power. In other words, not all of the power supplied from the power grid to the charging device 52 needs to be supplied directly to the vehicle 9, and the power consumption is a value of the amount of power with the supplied power as the upper limit. The "charge control mode" field stores information indicating which charge control mode the charging device 52 is in during charging and discharging. Here, the information indicating which charge control mode the charging device 52 is in is information indicating the degree of power demand pressure in the upstream power grid, including the charging station itself, and in other charging stations 5 in a common power grid, and is an example of information regarding power pressure pressure.
[0053] Note that when a portion of the power supplied to the vehicle 9 during charging is used as power consumption, the remaining power may be stored in a storage battery mounted on or attached to the charging device 52. Similarly, power expressed as a negative value of power consumption during discharge of the vehicle 9 is supplied, for example, to the power grid, but some or all of it may be stored in the storage battery of the charging device 52. Note that when power discharged from the vehicle 9 is stored in the storage battery of the charging device 52, a negative value other than "0" may be stored in the supply power field. Note that the power supplied to the battery of the vehicle 9 from the power grid or the power supplied from the vehicle 9 to the power grid may or may not pass through the storage battery of the charging device 52. Furthermore, the power supplied to the vehicle 9 as power consumption during charging of the vehicle 9 may be power from the storage battery of the charging device 52 in addition to or instead of power from the power grid. As the storage battery (battery) mounted on or attached to the charging device 52, any battery, such as a lithium-ion battery, a nickel-metal hydride battery, or an all-solid-state battery, may be used as appropriate.
[0054] In the charging station management server 51, the charge control instruction unit 511 stores and manages the charge and discharge history of the managed charging devices 52 in a charge history table 5121 stored in the storage unit 512. As an example, the charge control instruction unit 511 stores information about each charge and discharge in the charge history table 5121 every time a charge or discharge is performed in the managed charging devices 52. As an example, the charge control instruction unit 511 stores information about each charge and discharge in the charge history table 5121 every time the charge control mode of the managed charging devices 52 is switched. Note that it is also possible to record other items of the "charge control mode" every time a charge or discharge is performed in the managed charging devices 52, and record the "charge control mode" item every time the charge control mode is switched.
[0055] Here, the determination results output in the anomaly detection process by the security monitoring server 3 according to this embodiment will be described with reference to the drawings. FIG. 7 is a diagram showing an example of the configuration of the anomaly detection result table 331 according to the first embodiment. As shown in FIG. 7, the anomaly detection result table 331 includes at least the following fields: "Message ID," "Timestamp," "Charging Device ID," and "Corrected Score." The "Message ID" field stores identification information for uniquely identifying a message in which an anomaly (security event) has been detected. The "Timestamp" field stores information indicating the time when the anomaly was detected. The "Charging Device ID" field stores identification information for uniquely identifying the charging device 52 that transmitted or received the message in which the anomaly was detected. Note that instead of or in addition to the "Charging Device ID" field, a "Charging Station Management Server ID" field may be provided in which identification information for uniquely identifying the charging station management server 51 that is the target of the transmission / reception may be stored. The "Corrected Score" field stores information indicating the corrected score calculated in the corrected score calculation process.
[0056] In the security monitoring server 3, the anomaly detection unit 31 and / or the score correction unit 32 stores and manages the determination results of the anomaly detection process in an anomaly detection result table 331 stored in the storage unit 33. As an example, in the anomaly detection process, the anomaly detection unit 31 stores information about the detected event in the anomaly detection result table 331 each time it calculates an anomaly score for a detected event, that is, each time a determination result of normal or abnormal is output. As an example, the score correction unit 32 stores information about the detected event in the anomaly detection result table 331 each time it calculates a corrected score for a detected event. Note that an embodiment may also be such that other items of the "corrected score" are recorded each time an anomaly score is calculated, and the "corrected score" item is recorded each time a corrected score is calculated.
[0057] An example of the operation of the charging system 1 according to the embodiment will be described below with reference to the drawings. Note that the processing described below is an example, and it is possible to change the processing order, delete some processing, or add other processing.
[0058] FIG. 8 is a sequence diagram showing an example of the flow of an abnormality detection process executed in the charging system 1 according to the first embodiment.
[0059] When a message is transmitted and received between the charging station management server 51 and the charging device 52 (S101), the anomaly detection unit 31 of the security monitoring server 3 observes the transmitted and received message (S102). The anomaly detection unit 31 may observe the transmitted and received message based on a notification from at least one of the charging station management server 51 and the charging device 52, or may observe the transmitted and received message by monitoring the transmission and reception itself, for example, by referring to a communication log. The anomaly detection unit 31 performs an anomaly detection process based on the observed message and outputs an anomaly score calculated in the anomaly detection process to the score correction unit 32 (S103). The anomaly detection unit 31 also stores a record of the detected event in the anomaly detection result table 331 of the storage unit 33. In this way, the anomaly detection unit 31 performs anomaly detection based on the communication data and communication volume of the transmitted and received message, and outputs a determination result (detection result).
[0060] The score correction unit 32 of the security monitoring server 3 inquires of the charging station management server 51 about the charge control mode of the target charging device 52 in relation to the detected event (S104). In response to the inquiry from the security monitoring server 3, the charging station management server 51 references the charging history table 5121 and outputs information indicating the charge control mode of the target charging device 52 to the security monitoring server 3 (S105). Thereafter, the score correction unit 32 executes a corrected score calculation process based on the power pressure and calculates a corrected score by correcting the anomaly score in accordance with the notified information indicating the charge control mode (S106). Furthermore, the score correction unit 32 stores information indicating the corrected score in the record of the detected event in the anomaly detection result table 331. In this way, if the determination result of the anomaly detection based on the communication data and communication volume for the transmitted and received message indicates an anomaly, the score correction unit 32 inquires of the charging station management server 51 about the charge control mode of the target charging device 52.
[0061] The anomaly detection unit 31 of the security monitoring server 3 outputs the determination result, for example, on the display unit 35, based on the anomaly detection result table 331 in which records of each detection event are stored (S107). The determination result may be output in any manner. For example, the detection events may be displayed in a list with higher corrected scores at the top. The analyst terminal 7 then performs analysis processing in response to an analysis request from the security monitoring server 3 (S108). For example, in the analysis processing, the analyst terminal 7 presents the detection events to the analyst in charge of analysis (analyst) in descending order of corrected scores, obtains the results of the analyst's analysis of the detection events, and outputs the obtained analysis results to the security monitoring server 3. For example, upon receiving the output of the determination result, the user of the security monitoring server 3 assigns each detection event to an analyst, for example, in descending order of corrected scores. The security monitoring server 3 then transmits an analysis request for the corresponding detection event to the analyst terminal 7 of the assigned analyst. Note that an analyst may be determined in advance, for example, when an anomaly score is calculated, or allocation rules may be established, and an analysis request may be notified to the analyst terminal 7 at any timing, for example, when a corrected score is calculated. The analyst terminal 7 presents the detected event for which the analyst has been requested to analyze to the analyst, acquires the analysis results by the analyst, and outputs the acquired analysis results to the security monitoring server 3.
[0062] Here, the corrected score calculation process executed in the anomaly detection process of Fig. 8 will be described. Fig. 9 is a flowchart showing an example of the flow of the corrected score calculation process based on the power tightness, executed in the security monitoring server 3 according to the first embodiment. Fig. 9 illustrates a case where the corrected score is calculated by replacing the anomaly score with a correction value corresponding to information related to the power tightness. Note that the corrected score values corresponding to the charge control modes illustrated in Fig. 9 are merely examples, and can be set appropriately within a range in which the magnitude relationship between the corrected scores is maintained.
[0063] In the security monitoring server 3, the score correction unit 32 acquires the abnormality score indicating normal "0" or abnormal "1" that is the determination result by the abnormality detection unit 31, and information indicating the charge control mode from the charging station management server 51 (S201). In addition, the score correction unit 32 determines whether the determination result by the abnormality detection unit 31 is normal or not (S202).
[0064] If the determination result by the anomaly detection unit 31 is normal (S202: Yes), the score correction unit 32 outputs a normal determination, i.e., a corrected score of "0", as the determination result based on the power tightness (S203). After that, the flow in Fig. 9 ends, and the process proceeds to S107 in Fig. 8. In other words, the score correction unit 32 outputs a corrected score of "0" indicating a normal determination based on the power tightness, regardless of the power tightness state, in response to an anomaly score of "0" indicating a normal determination based on the message.
[0065] If the determination result by the abnormality detection unit 31 is abnormal (S202: No), the score correction unit 32 determines whether the charge control mode is the discharge mode (S204). If the charge control mode is the discharge mode (S204: Yes), the score correction unit 32 outputs a corrected score of "100" indicating an abnormal determination based on the power tightness, in response to an abnormality score of "1 (>0)" indicating a normal determination based on the message (S205). The flow of FIG. 9 then ends, and the process proceeds to S107 of FIG. 8. The charge control mode being the discharge mode refers to a particularly high power tightness state (high power tightness state), for example, when the power tightness is so great that it is necessary to request the vehicle 9 to discharge in order to meet the power demand. In other words, in the case of the discharge mode indicating a high power tightness state, the score correction unit 32 outputs the highest corrected score of "100" taking into account the power tightness, in response to an abnormality score of "1 > 0" indicating an abnormal determination based on the message. Therefore, in a configuration in which the higher the correction score, the higher the analysis priority is determined, the higher the analysis priority is determined in the discharge mode than in the suppression mode and normal mode.
[0066] If the charge control mode is other than the discharge mode (S204: No), the score correction unit 32 determines whether the charge control mode is the suppression mode (S206). If the charge control mode is the suppression mode (S206: Yes), the score correction unit 32 outputs a corrected score of "80" indicating an abnormality determination based on the power tightness, in contrast to an abnormality score of "1 (>0)" indicating a normal determination based on the message (S207). After that, the flow in FIG. 9 ends, and the process proceeds to S107 in FIG. 8. Note that the charge control mode being in the suppression mode refers to a state of power tightness (medium tightness) with the next highest level of power tightness, for example, where the vehicle 9 is not required to discharge due to the power tightness, but the power supply needs to be restricted. That is, in the case of the suppression mode, which indicates a medium-pressure state next to the high-pressure state, the score correction unit 32 takes into account the power pressure level and outputs a corrected score of "80", which is the second highest after the discharge mode, for the abnormality score "1>0" indicating an abnormality determination based on the message. Therefore, in a configuration in which the higher the corrected score, the higher the analysis priority is determined, the lower the analysis priority is determined in the suppression mode than in the discharge mode and higher than in the normal mode.
[0067] If the charge control mode is other than the suppression mode, i.e., the normal mode (S206: No), the score correction unit 32 outputs a corrected score of "50" indicating an abnormality determination based on the power tightness, for an abnormality score of "1 (>0)" indicating a normal determination based on the message (S208). The flow of FIG. 9 then ends, and the process proceeds to S107 of FIG. 8 . The normal mode of the charge control mode refers to a state of lowest power tightness (low power tightness), for example, where the power tightness is not severe enough to restrict the power supply or where there is no power tightness. In other words, in the normal mode indicating a low power tightness state, the score correction unit 32 outputs a corrected score of "50" that takes into account the power tightness, which is lower than the case of the suppression mode, for an abnormality score of "1 > 0" indicating an abnormality determination based on the message. Therefore, in a configuration in which a higher correction score determines a higher analysis priority, a lower analysis priority is determined in the normal mode than in the discharge mode and the suppression mode.
[0068] (Application Example) Here, an application example of the charging system 1 according to the embodiment will be described with reference to the drawings. FIG. 10 is a diagram illustrating calculation of a corrected score according to a power tightness level according to the first embodiment. FIG. 10 illustrates an example of corrected scores calculated by taking into account the power tightness level for each of message-based detection events A to D. The vertical and horizontal axes of the graph in FIG. 10 represent the power tightness level [%] and the time, respectively. In the example of FIG. 10 , time periods T1 and T5 are assumed to be in a low power tightness state where the power tightness level is the lowest, such as early morning or late night, and the charging device 52 is operating in normal mode. Furthermore, time periods T2 and T4 are assumed to be in a moderate power tightness state where the power tightness level is somewhat high, such as early morning or late evening, and the charging device 52 is operating in suppression mode. Furthermore, time period T3 is assumed to be in a particularly high power tightness state, such as daytime, and the charging device 52 is operating in discharge mode. In addition, the messages sent and received between the charging station management server 51 and the charging device 52 include information indicating the device temperature of the charging device 52 and information indicating the operating status of the air-cooling device installed in the charging device 52.
[0069] For example, the security monitoring server 3 determines that detection event B, in which the equipment temperature is normal (30 degrees) and the air-cooling device is on, is normal and outputs an abnormality score of "0." Similarly, for example, the security monitoring server 3 determines that detection event D, in which the equipment temperature is high (70 degrees) and the air-cooling device is on, is normal and outputs an abnormality score of "0." Although not illustrated in FIG. 10 , the security monitoring server 3 also determines that detection events in which the equipment temperature is normal (30 degrees) and the air-cooling device is off are normal and outputs an abnormality score of "0." For security events determined to be normal in anomaly detection based on messages from detection events B, D, etc., the security monitoring server 3 outputs a corrected score of "0," indicating a normal determination based on the power pressure level, regardless of the power pressure level.
[0070] On the other hand, for example, the security monitoring server 3 determines that detection events A and C, in which the equipment temperature is high (70 degrees) and the air-cooling device is off, are abnormal and outputs an abnormality score of "1." For detection event A, which is determined to be abnormal in the message-based anomaly detection, the security monitoring server 3 outputs a corrected score based on the power tightness of "50" in accordance with the fact that the power tightness is the lowest, low tightness state. Furthermore, for detection event C, which is determined to be abnormal in the message-based anomaly detection, the security monitoring server 3 outputs a corrected score based on the power tightness of "100" in accordance with the fact that the power tightness is the highest, high tightness state.
[0071] In this way, in the charging system 1 according to the present embodiment, when the security monitoring server 3 observes a message transmitted and received between the charging station management server 51 and the charging device 52, an anomaly score (corrected score) corrected according to the power tightness level is calculated for a detected event based on the message. That is, in the anomaly detection process according to the present embodiment, a corrected score according to the power tightness level is output as the detection result (determination result), so that an anomaly in the power equipment, such as a security event associated with a cyber-attack, can be detected taking the power tightness level into consideration.
[0072] Furthermore, by outputting a corrected score according to the power tightness as the detection result (determination result), the risk and analysis priority of the detected event can be highly evaluated when power is tight. Therefore, attacks and events that will cause greater damage can be notified to analysts preferentially. Furthermore, because the risk and analysis priority are highly evaluated when power is tight, analysis of attacks and events that will cause greater damage can be prioritized. Therefore, the above configuration, which calculates a corrected score that takes into account the power tightness of the anomaly detection result, can reduce the extent of damage and reduce human resources related to anomalies (attack events) in power equipment caused by cyberattacks. In other words, the anomaly detection process according to this embodiment makes it possible to appropriately deal with anomalies in power equipment even when power is tight.
[0073] Furthermore, in the charging system 1 according to this embodiment, information indicating the charge control mode of the charging device 52 is used as information indicating the power tightness. Generally, the power tightness depends on the region and the time of day. Therefore, a determination using the power tightness, which is a simple numerical representation of the degree of power tightness, may result in the same detection result (determination result) across multiple charging devices 52 in one charging station 5. On the other hand, in the charging system 1 according to this embodiment, a corrected score that takes into account the power tightness is calculated using a charge control mode that is expected to differ for each charging device 52, depending on user consent, settings, etc. This allows for anomaly detection that is more in line with the actual power tightness state.
[0074] Other embodiments of the charging system 1 according to the present disclosure will be described below with reference to the drawings. In the following description of each embodiment, differences will be mainly described, and descriptions of content that overlaps with the above-described content will be omitted as appropriate.
[0075] (Second embodiment) In the charging system 1 according to the above-described embodiment, the anomaly detection unit 31 of the security monitoring server 3 may calculate an anomaly score indicating the level of the detected event, for example, from 0 to 100, instead of being limited to a binary anomaly score such as normal "0" or abnormal "1".
[0076] Furthermore, the process of calculating the corrected score based on the power tightness by the score corrector 32 according to this embodiment may be any process as long as it corrects the anomaly score by increasing or decreasing it according to the power tightness, and is not limited to the case where the anomaly score is corrected by replacing it with a correction value according to the power tightness. The process may multiply the anomaly score by a correction coefficient having a magnitude according to the power tightness, or may add a correction value of a correction amount according to the power tightness to the anomaly score. The correction coefficient and correction amount are, for example, predetermined and stored in the storage unit 33 or the like.
[0077] As an example, in the case of a discharge mode indicating a high power pressure state, the score correction unit 32 multiplies the abnormality score "1>0" by the largest correction coefficient "1.2" taking into account the power pressure level and outputs the result. Similarly, in the case of a suppression mode indicating a medium power pressure state, the score correction unit 32 multiplies the abnormality score "1>0" by the correction coefficient "1.0", which is the next largest after the discharge mode, taking into account the power pressure level and outputs the result. Similarly, in the case of a normal mode indicating a low power pressure state, the score correction unit 32 multiplies the abnormality score "1>0" by a correction coefficient "0.8", which is smaller than the suppression mode, taking into account the power pressure level and outputs the result. Note that the magnitudes of the correction coefficients corresponding to each charge control mode are merely examples and can be set as appropriate within a range in which the magnitude relationship is maintained.
[0078] As an example, in the case of a discharge mode indicating a high power pressure state, the score correction unit 32 takes into account the power pressure level and adds the largest correction value "100" to the abnormality score "1>0", and outputs the result. Similarly, in the case of a suppression mode indicating a medium power pressure state, the score correction unit 32 takes into account the power pressure level and adds the second largest correction value "80" after the discharge mode to the abnormality score "1>0", and outputs the result. Similarly, in the case of a normal mode indicating a low power pressure state, the score correction unit 32 takes into account the power pressure level and adds the correction value "50" that is smaller than the correction value in the suppression mode to the abnormality score "1>0", and outputs the result. Note that the magnitudes (correction amounts) of the correction values corresponding to each charge control mode are merely examples and can be set as appropriate within a range in which the magnitude relationship is maintained.
[0079] In this way, the configuration in which an anomaly score indicating the level of a detected event is calculated enables anomaly detection that is more in line with the actual power shortage state. Therefore, the charging system 1 according to this embodiment can appropriately deal with an anomaly in the power equipment even in a power shortage state.
[0080] Third Embodiment In the charging system 1 according to each of the above-described embodiments, the security monitoring server 3 can use an indicator of the charge control mode as information indicating the power tightness. Meanwhile, the security monitoring server 3 according to this embodiment may, for example, query the charging station management server 51 to obtain information indicating the amount of requested power and the amount of supplied power for charging and discharging, instead of or in addition to the information indicating the charge control mode. The security monitoring server 3 may then determine the power tightness based on the power amount ratio (requested power amount / supplied power amount) indicating the magnitude of the amount of power requested by the vehicle 9 relative to the amount of supplied power supplied to the charging device 52 from the power grid. Alternatively, the security monitoring server 3 may determine the power tightness based on a combination of the charge control mode and the power amount ratio.
[0081] As an example, the security monitoring server 3 determines that the state is in a high pressure state when the power energy ratio is, for example, 90% or higher. Similarly, the security monitoring server 3 determines that the state is in a medium pressure state when the power energy ratio is, for example, 70% or higher. Similarly, the security monitoring server 3 determines that the state is in a low pressure state when the power energy ratio is, for example, less than 70%. The range of values of the power energy ratio that defines each state is, for example, predetermined and stored in the storage unit 33. Note that the range of values of the power energy ratio that defines each state is just an example, and can be set as appropriate within a range that maintains the magnitude relationship.
[0082] In this way, even if the power amount ratio indicating the magnitude of the required power amount relative to the supplied power amount is used as information indicating the power tightness, and a higher analysis priority is determined as the power amount ratio increases, the same effect as in the above-described embodiment can be obtained. Note that the technology according to this embodiment can be appropriately applied to the charging system 1 according to each of the above-described embodiments.
[0083] Fourth Embodiment In the above-described embodiments, the security monitoring server 3 is connected to the charging station management server 51 and the charging device 52 via the network N so as to be able to communicate with each other, and acquires, from at least one of the charging station management server 51 and the charging device 52, the transmitted and received information transmitted and received between the charging station management server 51 and the charging device 52 via the network N. However, this is not limited to this. The charging system 1 according to this embodiment is similar to the charging system 1 according to the above-described embodiments, except that the mode of communication between the charging station management server 51 and the charging device 52 and the mode of communication between the security monitoring server 3 and the analyst terminal 7 are different. FIG. 11 is a diagram illustrating an example of the configuration of the charging system 1 according to the fourth embodiment. As shown in FIG. 11 , in the charging system 1 according to this embodiment, the charging device 52 may be connected directly to the charging station management server 51 without using the network N. That is, the security monitoring server 3 may be connected to the charging station management server 51, to which the charging device 52 is connected so as to be able to communicate with each other, via the network N. In this case, the security monitoring server 3 may acquire the transmission and reception information transmitted and received between the charging station management server 51 and the charging device 52 from the charging station management server 51 via the network N. Furthermore, in the charging system 1 according to this embodiment, the analyst terminal 7 may be connected directly to the security monitoring server 3 without using the network N. Note that either the communication mode between the charging station management server 51 and the charging device 52 or the communication mode between the security monitoring server 3 and the analyst terminal 7 may be performed via the network N, as in the above-described embodiments.
[0084] In this way, even if some components of the charging system 1 are connected without going through the network N, the same effects as those of the above-described embodiment can be obtained. Furthermore, with this configuration, for example, it is possible to speed up and stabilize communication on each path, and to improve safety related to charging control by restricting intrusion paths into the charging device 52 via the network N. Note that the technology according to this embodiment can be appropriately applied to the charging system 1 according to each of the above-described embodiments.
[0085] Fifth Embodiment In the above-described embodiments, the anomaly score is corrected according to the power tightness to calculate the corrected score, i.e., the anomaly detection result (determination result) is output taking the power tightness into account. However, this is not limiting. The charging system 1 according to this embodiment may be configured to determine the analysis priority based on the anomaly score taking the power tightness into account.
[0086] The security monitoring server 3 according to the fifth embodiment is configured to determine the analysis priority by determining the analysis priority between two or more detection events having the same anomaly score based on information regarding the power tightness. Specifically, the security monitoring server 3 is configured to be able to execute the analysis priority determination process based on the power tightness according to the fifth embodiment. FIG. 12 is a diagram illustrating an example of the configuration of the security monitoring server 3 according to the fifth embodiment. As shown in FIG. 12, the security monitoring server 3 according to the fifth embodiment is similar to the security monitoring server 3 according to the above-described embodiments (see FIG. 2), except that it includes an analysis priority determination unit 36 instead of the score correction unit 32 and stores an anomaly detection result table 332 in its memory unit 33 instead of the anomaly detection result table 331.
[0087] For example, in the security monitoring server 3 according to this embodiment, at least one processor 81 (see FIG. 5 ) realizes each function of the security monitoring server 3, including the anomaly detection unit 31 and the analysis priority determination unit 36. The anomaly detection unit 31 may execute some or all of the functions of the analysis priority determination unit 36, or the anomaly detection unit 31 and the analysis priority determination unit 36 may be realized as a single function. The analysis priority determination unit 36 performs a power-tightness-based analysis priority determination process that determines priority based on the power tightness for messages that have been assigned the same anomaly score based on the results of the anomaly detection process. In other words, the analysis priority determination unit 36 determines the analysis priority of a detected event through the analysis priority determination process. Details of the analysis priority determination process will be described later.
[0088] The storage unit 33 stores an anomaly detection result table 332 that stores output results from the anomaly detection unit 31 and the analysis priority determination unit 36. That is, the anomaly detection result table 332 stores determination results output in the anomaly detection process by the security monitoring server 3 according to this embodiment. FIG. 13 is a diagram showing an example of the configuration of the anomaly detection result table 332 according to the fifth embodiment. As shown in FIG. 13, the anomaly detection result table 332 has a configuration similar to that of the anomaly detection result table 331 according to the first embodiment (see FIG. 7 ), except that the "corrected score" field is changed to an "anomaly score" field and an "analysis priority" field is added. The "anomaly score" field stores information indicating the anomaly score calculated in the anomaly detection by the anomaly detection unit 31. The "analysis priority" field stores information indicating the analysis priority set in the analysis priority determination process by the analysis priority determination unit 36.
[0089] In the security monitoring server 3, the anomaly detection unit 31 and / or the analysis priority determination unit 36 stores and manages the determination results of the anomaly detection process in an anomaly detection result table 332 stored in the storage unit 33. As an example, in the anomaly detection process, the anomaly detection unit 31 stores information about the detected event in the anomaly detection result table 332 each time it calculates an anomaly score for a detected event, i.e., each time a determination result of normal or abnormal is output. As an example, each time the analysis priority determination unit 36 sets an analysis priority for a security event (attack event) determined to be abnormal among the detected events, it stores information about the attack event, such as information indicating the analysis priority, in the record of the corresponding detected event in the anomaly detection result table 332.
[0090] 14 is a sequence diagram showing an example of the flow of an abnormality detection process executed in the charging system according to the fifth embodiment. Here, differences from the flow of the abnormality detection process according to the first embodiment (see FIG. 8) will be mainly described.
[0091] In the security monitoring server 3, the anomaly detection unit 31 performs an anomaly detection process based on the observed message, similar to the flow shown in FIG. 8 , and outputs the anomaly score calculated in the anomaly detection process (S103). The anomaly detection unit 31 may calculate a binary anomaly score, such as "normal" or "abnormal," a ternary anomaly score, such as "high," "medium," or "low," or a four- or more-value anomaly score, such as 0 to 100. The analysis priority determination unit 36 then acquires attack events from past detection events that have the same anomaly score as the current attack event (S301). These attack events are security events that were determined to be abnormal in anomaly detection among the detection events, i.e., have an anomaly score greater than "0." The "identical anomaly score" does not necessarily have to be the same; it may be an anomaly score that satisfies a predetermined condition (threshold range) stored in the storage unit 33. The acquisition of attack events with the same anomaly score may be performed in the analysis priority determination process (see FIG. 15 ), described below.
[0092] Furthermore, the analysis priority determination unit 36 inquires of the charging station management server 51 about the power pressure level of the target charging device 52 for the detected event (S302). In response to the inquiry from the security monitoring server 3, the charging station management server 51 references the charging history table 5121 and outputs information indicating the power pressure level of the target charging device 52 to the security monitoring server 3 (S303). In this manner, the analysis priority determination unit 36 acquires the power pressure levels for multiple attack events that have the same anomaly score, including the currently detected attack event. Note that information indicating the power pressure levels of previously detected attack events may be stored in the storage unit 33 or the like at the stage of acquisition in the past. Therefore, the anomaly detection result table 332 in FIG. 13 may be provided with an item for storing information indicating the acquired power pressure levels. Alternatively, the storage unit 33 may store information indicating the acquired power pressure levels for each attack event separately from the anomaly detection result table 332. The power pressure level may be acquired in the analysis priority determination process (see FIG. 15) described later.
[0093] The analysis priority determination unit 36 then executes an analysis priority determination process (see FIG. 15 ) based on the power pressure level and sets the analysis priority according to the information indicating the power pressure level (S304). Specifically, the analysis priority determination unit 36 determines the analysis priority according to the anomaly score. For example, the analysis priority according to the anomaly score is the lowest priority, such as "low," for a detection event determined to be normal in anomaly detection with an anomaly score of "0." Furthermore, for an attack event determined to be abnormal in anomaly detection with an anomaly score greater than "0," the analysis priority according to the anomaly score is higher, and the analysis priority is set to any level, such as "medium," "high," or "highest," depending on the anomaly score. The analysis priority determination unit 36 then determines the analysis priority of an attack event among the detection events, relative to two or more attack events having the same anomaly score, such as "high-1" or "high-2," based on information regarding the power pressure level. The analysis priority determination unit 36 then stores information indicating the set priority in the record of the corresponding detection event in the anomaly detection result table 332. 8 , the anomaly detection unit 31 of the security monitoring server 3 outputs the determination result, for example, on the display unit 35, based on the anomaly detection result table 332 in which the records of each detection event are stored (S107). Regarding the analysis process (S108), an analyst may be designated in advance or assignment rules may be established when the anomaly score is calculated or the analysis priority is set or updated. Alternatively, an analysis request may be notified to the analyst terminal 7 at any timing, such as when the analysis priority is set or updated. In this way, the analysis priority determination unit 36 determines the analysis priority based on the power pressure and sets a priority for the attack event.
[0094] Here, the analysis priority determination process executed in the anomaly detection process of Fig. 14 will be described. Fig. 15 is a flowchart showing an example of the flow of the analysis priority determination process based on the power pressure level, executed in the security monitoring server 3 according to the fifth embodiment. Fig. 15 illustrates the flow when the process of S301 in the flow of Fig. 14 is not performed.
[0095] The analysis priority determination unit 36 extracts attack events that have been assigned the same anomaly score as the current attack event from among the previously detected events (S301). Note that this step is the same as the step S301 in the flow of FIG. 14 , which is executed before querying the charging station management server 51 about the power tightness. This step may be executed in either this step or S301 in FIG. 14 . The analysis priority determination unit 36 also acquires attack events that have not yet been analyzed from among the previously detected attack events (S402). For subsequent processing, the analysis priority of the acquired attack events that have not yet been analyzed may be reset at this point, and the attack events may be treated as attack events for which no analysis priority has been assigned, for example, in the same category as the currently detected attack event. In other words, the determination of the analysis priority in the flow of FIG. 15 includes re-determining the analysis priority of previously detected events that have not yet been analyzed.
[0096] The analysis priority determination unit 36 acquires attack events with high anomaly scores from among attack events for which analysis priorities have not been assigned, including the currently detected attack event (S403). The analysis priority determination unit 36 also acquires the power pressure level at the time of the attack event occurrence from the storage unit 33 or the charging station management server 51 (S404) and sets analysis priorities in descending order of power pressure level (S405). That is, the analysis priority determination unit 36 assigns analysis priorities to multiple attack events with a "high" anomaly score in descending order of power pressure level, such as "High-1," "High-2," and so on, and ranks the attack events with the same anomaly score. The analysis priority determination unit 36 then determines whether analysis priorities have been assigned to all attack events (S406). If analysis priorities have not been assigned to all attack events (S406: No), the analysis priority determination unit 36 executes the processes of S403 to S406 for the attack event with the next highest anomaly score from among attack events for which analysis priorities have not been assigned. On the other hand, if analysis priorities have been set for all attack events (S406: Yes), the flow in FIG. 15 ends and the process proceeds to S107 in FIG.
[0097] 14, the anomaly detection unit 31 of the security monitoring server 3 outputs the determination result on, for example, the display unit 35 based on the anomaly detection result table 332 in which the records of each detection event are stored (S107). The form in which this determination result is output is arbitrary, and as one example, the detection events may be displayed in a list with the higher the analysis priority, the higher the ranking.
[0098] In this way, in the charging system 1 according to the present embodiment, the security monitoring server 3 is configured to determine the analysis priority of an unanalyzed event that has occurred, taking into account the power shortage state. With this configuration, a high analysis priority can be set for an attack event occurring under a power shortage state, and therefore, even under a power shortage state, an abnormality in the power equipment can be appropriately dealt with, for example, by prioritizing the analysis of an attack event occurring under a power shortage state.
[0099] Specifically, the analysis priority determination unit 36 sets analysis priorities for unanalyzed attack events within the same anomaly score in descending order of the power pressure at the time of their occurrence until analysis priorities have been assigned to all attack events. For example, even if the analysis priorities based on the anomaly score are determined to be the same "High," the analysis priority is ranked as "High-1," "High-2," and so on, based on the idea that the higher the power pressure, the greater the urgency. This makes it possible to identify attack events with the same anomaly score that need to be analyzed first in terms of power pressure, and reflect this in the analysis priorities.
[0100] Furthermore, the analysis priority determination unit 36 acquires unanalyzed attack events, including attack events received in the past, and sets an analysis priority for each of them. This configuration for acquiring a list of unanalyzed past events allows priorities to be set in subsequent processing, including attack events detected in the past, so it is also possible to handle cases where it is desired to prioritize the current attack event over attack events detected in the past, taking into account the degree of power pressure.
[0101] The technology according to this embodiment can be appropriately applied to the charging system 1 according to each of the above-described embodiments. For example, the charging system 1 according to the first embodiment, which performs an absolute evaluation based on the power tightness, may be combined with the charging system 1 according to this embodiment, which uses the power tightness to evaluate a relative evaluation with respect to past attack events in the form of an analysis priority. For example, the corrected score calculation process according to the first embodiment may calculate a corrected score using a correction coefficient based on the power tightness, and the analysis priority determination process according to this embodiment may set an analysis priority based on the power tightness. With this combination, even if the corrected score is the same, if the breakdown of the anomaly score portion and the correction portion is different, it is possible to set an analysis priority that is more in line with the actual power tightness.
[0102] Sixth Embodiment In the charging system 1 according to each of the above-described embodiments, the cases where the records of the detected events are sequentially stored in one anomaly detection result table 331, 332 have been exemplified, but the present invention is not limited thereto. Also, the cases where the display unit 35 displays (outputs) a display screen in which the detected events are listed in order based on the correction score, the analysis priority, or the like, based on the anomaly detection result tables 331, 332 have been exemplified, but the present invention is not limited thereto.
[0103] For example, detected events related to power equipment, including the charging station management server 51 and the charging device 52, may include power system security events and non-power system security events. Here, a power system security event is a detected event related to power control, such as when a power control protocol is included in the target of attack. A non-power system security event is a detected event that can be analyzed by a typical IT engineer, such as a DoS (Denial of Service) attack. For example, power system security events pose a high risk of spreading damage or causing equipment destruction if not appropriately addressed. Therefore, it is preferable to assign an analyst with knowledge of power equipment. Furthermore, from the perspectives of understanding the occurrence and response status of security events, assigning appropriate analysts, and understanding the progress of analysis and response, it is preferable to manage detected events related to power equipment separately as power system events and non-power system events.
[0104] For example, in the charging system 1 according to the present embodiment, the security monitoring server 3 may generate separate anomaly detection result tables 331, 332 for power system detection events and non-power system detection events. Alternatively, the anomaly detection result tables 331, 332 may further include an item for storing information indicating whether the event is a power system detection event or a non-power system detection event.
[0105] 16 is a diagram showing an example of an event management screen (display screen 410) displayed on the security monitoring server 3 according to the sixth embodiment. For example, as shown in FIG. 16, the security monitoring server 3 may divide a list of detected events into power-related and non-power-related events, and display the display screen 410 on the display unit 35 or output it to an external device. The display screen 410 may be displayed on an external display connected to the security monitoring server 3 or on the analyst terminal 7.
[0106] 16 , the display of each detected event for the power system and non-power system includes at least the items "Event ID," "Analysis Priority," and "Response Status." The display of each detected event for the power system and non-power system may further include the items "Occurrence Time" and "Analysis Person."
[0107] The "Event ID" field displays identification information for uniquely identifying a detected event. A "Message ID" may be used as the "Event ID." The "Analysis Priority" field displays, for example, the analysis priority set in the analysis priority determination process of FIG. 15 . The "Analysis Priority" field may be dynamically updated according to the results of the analysis priority determination performed on a new security event. In conjunction with this update, the display order of the detected event records may also be dynamically changed or updated. The "Analysis Priority" field may display, for example, the corrected score calculated in the corrected score calculation process of FIG. 9 or the analysis priority according to the corrected score. The "Analyst" field displays information indicating the analyst assigned to analyze each detected event, such as the name of the analyst. The "Analyst" field may function as an input field for accepting input from the analyst. The "Response Status" field displays, for example, information such as "Waiting for Analysis," "Analysis in Progress," or "Analysis Completed," indicating that the event analysis has not yet begun. In addition, when the analysis of the detected event has been completed, instead of displaying "Analysis Completed" in the "Response Status" field, the detected event may be deleted from the list on the display screen 410.
[0108] In this way, in the charging system 1 according to this embodiment, detected events are managed separately for the power system and the non-power system. This configuration allows for easy identification of power system security events, for which it is preferable to assign an analyst with knowledge of the power equipment, and allows for analysis by an appropriate analyst. Furthermore, any analyst can easily identify non-power system security events that can be assigned, improving allocation efficiency and enabling rapid response to detected events. Therefore, the charging system 1 according to this embodiment can appropriately respond to abnormalities in the power equipment even in a state of power shortage. Note that the technology according to this embodiment can be appropriately applied to the charging system 1 according to each of the above-mentioned embodiments.
[0109] In each of the above-mentioned embodiments, "whether it is A or not" refers to at least one of "it is A" and "it is not A." In other words, in each of the above-mentioned embodiments, the determination of "whether it is A or not" may be realized by determining only "it is A," or by determining only "it is not A," or by determining both of these.
[0110] The programs executed by each device of the charging system 1 in each of the above-described embodiments may be provided by being recorded in an installable or executable file format on a computer-readable recording medium (Computer Program Product) such as a CD-ROM, FD, CD-R, or DVD.
[0111] The programs executed by the devices in the charging system 1 of each of the above-described embodiments may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. The programs executed by the devices in the charging system 1 of each of the above-described embodiments may be provided or distributed via a network such as the Internet.
[0112] Furthermore, the programs executed by the devices of the charging system 1 of each of the above-described embodiments may be provided by being pre-installed in a ROM or the like.
[0113] According to at least one of the embodiments described above, it is possible to appropriately deal with abnormalities in power facilities even in a power shortage state.
[0114] Although several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be implemented in various other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their modifications are included within the scope and spirit of the invention, as well as within the scope of the invention described in the claims and their equivalents.
[0115] (Additional Notes) The above embodiments disclose the following technologies. (1) An anomaly detection method executed in a monitoring device that monitors communication between first power equipment configured to be able to perform at least one of power supply and power reception with a connected charging / discharging device, and second power equipment that controls the first power equipment, the anomaly detection method including: performing anomaly detection based on transmission / reception information transmitted and received between the first power equipment and the second power equipment; and determining an analysis priority for analyzing the detected event based on an anomaly score of the detected event, which is a security event detected by the anomaly detection, and information on a power tightness that indicates the degree of tightness of power demand at the time of detection. (2) The anomaly detection method described in (1) above, in which determining the analysis priority includes: calculating a corrected score by correcting the anomaly score of the detected event based on the information on the power tightness; and setting the analysis priority according to the corrected score. (3) The anomaly detection method described in (2) above, in which calculating the corrected score includes correcting the anomaly score by replacing it with a correction value according to the information on the power tightness. (4) The anomaly detection method according to (2), wherein calculating the corrected score includes correcting the anomaly score by multiplying the anomaly score by a correction coefficient having a magnitude according to the information on the power tightness. (5) The anomaly detection method according to (2), wherein calculating the corrected score includes correcting the anomaly score by adding a correction value of a correction amount according to the information on the power tightness. (6) The anomaly detection method according to any one of (1) to (5), wherein determining the analysis priority includes determining the analysis priority between two or more of the detected events having the same anomaly score based on information on the power tightness.(7) The anomaly detection method according to (6), wherein determining the analysis priority includes determining the analysis priority between two or more attack events having the same anomaly score based on information on the power tightness for an attack event determined to be an anomaly by the anomaly detection among the detected events, and determining the analysis priority includes setting the analysis priority for the detected events other than the attack event according to the anomaly score. (8) The anomaly detection method according to (6) or (7), wherein determining the analysis priority includes re-determining the analysis priority for a past detected event that has not yet been analyzed. (9) The anomaly detection method according to any one of (1) to (8), wherein the information on the power tightness is information indicating an operation mode of the first power facility, the operation mode including at least a normal mode in which the first power facility supplies power to the charging / discharging device without limiting the power supply, and a suppression mode in which the first power facility supplies power to the charging / discharging device with limiting the power supply, and determining the analysis priority includes determining the analysis priority to be higher in the suppression mode than in the normal mode. (10) The anomaly detection method according to (9), wherein the operation mode further includes a discharge mode in which the first power facility receives power from the charging / discharging device, and determining the analysis priority includes determining the analysis priority to be higher in the discharge mode than in the suppression mode. (11) The anomaly detection method according to any one of (1) to (10), wherein the information relating to the power tightness is information indicating a power ratio, which is the magnitude of the amount of power requested by the charging / discharging device relative to the amount of power supplied from a power grid to the first power equipment, and determining the analysis priority includes determining a higher analysis priority as the power ratio is larger.(12) The anomaly detection method according to any one of (1) to (11), wherein the monitoring device is connected to each of the first electric power equipment and the second electric power equipment via a network so as to be able to communicate with each other, and performing the anomaly detection includes acquiring the transmitted and received information transmitted and received between the first electric power equipment and the second electric power equipment via the network from at least one of the first electric power equipment and the second electric power equipment via the network. (13) The anomaly detection method according to any one of (1) to (11), wherein the monitoring device is connected to the second electric power equipment to which the first electric power equipment is communicatively connected via a network so as to be able to communicate with each other, and performing the anomaly detection includes acquiring the transmitted and received information transmitted and received between the first electric power equipment and the second electric power equipment from the second electric power equipment via the network. (14) A monitoring device that monitors communications between a first power facility configured to be able to perform at least one of power supply and power reception with a connected charging / discharging device, and a second power facility that controls the first power facility, the monitoring device comprising: at least one processor configured to perform anomaly detection based on transmission / reception information transmitted and received between the first power facility and the second power facility, and to determine an analysis priority for analyzing the detected event based on an anomaly score of a detected event that is a security event detected by the anomaly detection, and information on a power tightness that indicates the degree of tightness of power demand at the time of detection. (15) A monitoring device comprising: at least one processor; and a memory that stores at least one program executed by the at least one processor, the at least one processor configured to implement the anomaly detection method according to any one of (1) to (13) above by executing the at least one program.(16) A program for causing a computer realizing a monitoring device that monitors communications between first power equipment configured to be able to perform at least one of power supply and power reception with connected charging / discharging devices, and second power equipment that controls the first power equipment, to execute the following: detecting an anomaly based on transmission / reception information transmitted and received between the first power equipment and the second power equipment, and determining an analysis priority for analyzing the detected event based on an anomaly score of a detected event that is a security event detected by the anomaly detection and information on a power tightness that indicates the degree of tightness of power demand at the time of detection. (17) A program for causing a computer realizing a monitoring device that monitors communications between first power equipment configured to be able to perform at least one of power supply and power reception with connected charging / discharging devices, and second power equipment that controls the first power equipment, to execute the anomaly detection method described in any one of (1) to (13) above. (18) A recording medium (Computer Program Product) on which the program executed by a computer, as set forth in (16) or (17) above, is recorded.
[0116] REFERENCE SIGNS LIST 1 Charging system 3 Security monitoring server (monitoring device) 31 Abnormality detection unit 32 Score correction unit 33 Memory unit 331 Abnormality detection result table 34 Communication unit 35 Display unit 36 Analysis priority determination unit 5 Charging station 51 Charging station management server (second power equipment) 511 Charging control instruction unit 512 Memory unit 5121 Charging history table 513 Communication unit 52 Charging device (first power equipment) 521 Charging control unit 522 Communication unit 7 Analyst terminal 8 Information processing device 81 Processor 82 Main memory device 83 Auxiliary memory device 84 I / F circuit 89 Bus 9 Vehicle (charging / discharging device) N Network
Claims
1. An anomaly detection method executed in a monitoring device that monitors communications between a first power equipment configured to be capable of at least one of power supply and power reception with a connected charging / discharging device, and a second power equipment that controls the first power equipment, the anomaly detection method including: performing anomaly detection based on transmission / reception information transmitted and received between the first power equipment and the second power equipment; and determining an analysis priority for analyzing the detected event based on an anomaly score of a detection event, which is a security event detected by the anomaly detection, and information regarding a power tightness that indicates the degree of tightness of power demand at the time of detection.
2. The anomaly detection method of claim 1, wherein determining the analysis priority includes: calculating a corrected score by correcting the anomaly score of the detected event based on information regarding the power tightness; and setting the analysis priority according to the corrected score.
3. The anomaly detection method according to claim 2, wherein calculating the corrected score includes correcting the anomaly score by replacing it with a correction value corresponding to information relating to the power tightness.
4. The anomaly detection method according to claim 2, wherein calculating the corrected score includes correcting the anomaly score by multiplying the anomaly score by a correction coefficient having a magnitude corresponding to the information relating to the power tightness.
5. The anomaly detection method according to claim 2, wherein calculating the corrected score includes correcting the anomaly score by adding a correction value of a correction amount corresponding to information relating to the power tightness.
6. The anomaly detection method of claim 1, wherein determining the analysis priority includes determining the analysis priority among two or more of the detection events having the same anomaly score based on information regarding the power tightness.
7. The anomaly detection method according to claim 6, wherein determining the analysis priority includes determining, for an attack event among the detection events determined to be anomalous by the anomaly detection, the analysis priority between two or more attack events having the same anomaly score based on information related to the power tightness, and determining the analysis priority includes setting, for the detection events other than the attack event, the analysis priority according to the anomaly score.
8. The anomaly detection method according to claim 6, wherein determining the analysis priority includes re-determining the analysis priority for a past detection event that has not yet been analyzed.
9. The anomaly detection method according to any one of claims 1 to 8, wherein the information relating to the power tightness is information indicating an operation mode of the first power equipment, the operation mode including at least a normal mode in which the first power equipment supplies power to the charging / discharging equipment in a state in which no restriction on the power supply is involved, and a suppressed mode in which the first power equipment supplies power to the charging / discharging equipment in a state in which the power supply is involved, and determining the analysis priority includes determining the analysis priority to be higher in the suppressed mode than in the normal mode.
10. The anomaly detection method described in claim 9, wherein the operating modes further include a discharge mode in which the first power equipment receives power from the charging / discharging device, and determining the analysis priority includes determining the analysis priority to be higher in the discharge mode than in the suppression mode.
11. An anomaly detection method as described in any one of claims 1 to 8, wherein the information relating to the degree of power tightness is information indicating an electric energy ratio, which is the magnitude of the amount of electric energy requested by the charging / discharging device relative to the amount of supplied electric energy supplied from a power grid to the first electric power equipment, and determining the analysis priority includes determining the analysis priority to be higher the greater the electric energy ratio.
12. The anomaly detection method described in any one of claims 1 to 8, wherein the monitoring device is connected to each of the first power equipment and the second power equipment so as to be able to communicate with each other via a network, and performing the anomaly detection includes acquiring the transmitted and received information transmitted and received between the first power equipment and the second power equipment via the network from at least one of the first power equipment and the second power equipment via the network.
13. The anomaly detection method described in any one of claims 1 to 8, wherein the monitoring device is connected to the second power equipment to which the first power equipment is communicatively connected via a network so that they can communicate with each other, and performing the anomaly detection includes obtaining the transmission and reception information transmitted and received between the first power equipment and the second power equipment from the second power equipment via the network.
14. A monitoring device that monitors communications between a first power equipment configured to be capable of at least one of power supply and power reception between a connected charging / discharging device, and a second power equipment that controls the first power equipment, comprising at least one processor configured to perform anomaly detection based on transmission / reception information transmitted and received between the first power equipment and the second power equipment, and to determine an analysis priority for analyzing the detected event based on an anomaly score of a detection event, which is a security event detected by the anomaly detection, and information regarding a power tightness indicating the degree of tightness of power demand at the time of detection.
15. A program for causing a computer realizing a monitoring device that monitors communications between a first power equipment configured to be capable of at least one of power supply and power reception with a connected charging / discharging device, and a second power equipment that controls the first power equipment, to perform anomaly detection based on transmission and reception information transmitted and received between the first power equipment and the second power equipment, and to determine an analysis priority for analyzing the detection event based on an anomaly score of a detection event, which is a security event detected by the anomaly detection, and information regarding a power tightness indicating the degree of tightness of power demand at the time of detection.
Citation Information
Patent Citations
Intrusion detection method and system for charging pile CAN network
CN116488936A
Cybersecurity management device, cybersecurity management method and cybersecurity management system
JP2022191649A
Risk Index Correction System Based on Attack Frequency, Asset Importance, and Severity
KR102088310B1
Methods for optimizing an automated determination in real-time of a risk rating of cyber-attack and devices thereof
US20160226893A1
Technologies for detecting abnormal activities in an electric vehicle charging station
US20200162487A1