Ship cyber attack early warning system and method

The ship cyber attack early warning system addresses the lack of cyber attack detection in conventional AMS by integrating a learning and detection system with the AMS to classify normal and abnormal responses, effectively generating early warnings and enhancing ship IT/OT security.

WO2025135789A1PCT designated stage expired Publication Date: 2025-06-26HANWHA OCEAN CO LTD (KR) +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/020624
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-19
Filing Date
2024-12-18
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Conventional ship Alarm Monitoring & Control Systems (AMS) lack detection and monitoring capabilities for cyber attacks, making it difficult to implement effective threat detection systems for all onboard Operational Technology (OT) systems.

Method used

A ship cyber attack early warning system and method that links the ship control system with an AMS, utilizing a learning unit to analyze crew responses to abnormal cyber behavior, a detection unit to identify abnormalities, a storage unit to record actions, a simulation unit to analyze responses, a classification unit to determine normal or abnormal actions, and an alarm unit to generate warnings through the AMS and visual/auditory systems.

Benefits of technology

The system effectively detects abnormal behavior and generates early warnings of cyber attacks by integrating with the AMS, enhancing ship IT/OT security detection and providing a new layer of cybersecurity by classifying normal and abnormal response measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024020624_26062025_PF_FP_ABST
    Figure KR2024020624_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention presents a ship cyberattack early warning system and method, which can detect abnormal behavior through interworking with an alarm, monitoring and control system (AMS) in consideration of the environment of a ship control system, and provide early warning of a cyberattack on a ship. According to the present invention, abnormal behavior conditions of a system on a ship are generated in a crew training environment implemented on land, the behaviors and input data, of the crew, corresponding thereto are learned so that normal response actions and abnormal response actions are classified, and, on the basis of the behavior and input learning data of the crew when a cyber accident occurs at real sea, early warning can be provided if the abnormal response actions are input or abnormal behavior occurs.
Need to check novelty before this filing date? Find Prior Art

Description

Ship cyber attack early warning system and method

[0001] The present invention relates to a ship cyber attack early warning system and method capable of detecting abnormal behavior and providing early warning of ship cyber attacks by linking a ship control system with an AMS (Alarm. Monitoring & Control System) system while taking the environment into consideration.

[0002] Typically, when a dangerous situation occurs on a ship, such as fire, flooding, or mechanical failure, alarm lamps, speakers, etc. are used as the ship's warning system.

[0003] The ship is building a surveillance monitoring system by collecting input / output values ​​for field stations through the AMS (Alarm. Monitoring & Control System).

[0004] Additionally, conventional AMS systems lacked detection / monitoring capabilities for cyberattacks.

[0005] Therefore, the cybersecurity equipment of the existing control system (OT) had the problem of making it difficult to implement a system for threat detection for all OT systems on board the ship.

[0006] As a related prior art document, Republic of Korea Patent Publication No. 10-2017-0110932 (October 12, 2017) is published.

[0007] The purpose of the present invention is to provide a ship cyber attack early warning system and method capable of detecting abnormal behavior and issuing an alarm through linkage with an AMS (Alarm. Monitoring & Control System) system while taking into account the ship control system environment.

[0008] Another object of the present invention is to provide a ship cyber attack early warning system and method, which generates abnormal behavior conditions of a ship system in a seafarer training environment implemented on land, learns the actions and input data of seafarers in response to the abnormal behavior conditions, classifies normal and abnormal response measures, and provides an early warning when abnormal response measures or actions occur based on the actions and input learning data of seafarers when a cyber accident actually occurs at sea.

[0009] In order to achieve the above object, according to one aspect of the present invention, a method for early warning of a cyber attack on a ship may include: a learning step for learning the actions and input data of crew members regarding abnormal cyber activity on the ship through a learning unit; a detection step for detecting whether an abnormal activity has occurred on the ship's equipment through a detection unit linked with an AMS (Alarm. Monitoring & Control System); a storage step for storing the actions and input data of crew members taking actions in response to the abnormal activity detected through the detection step in a storage unit; a simulation step for simulating the details of the actions taken through a simulation unit based on the data stored in the storage unit; a classification step for comparing the actions and input data of crew members regarding the abnormal activity as a result of the simulation through the simulation step with the learned data and classifying them as normal or abnormal actions through a classification unit; and an alarm step for generating an early warning through an alarm unit that generates an alarm by linking the AMS (Alarm. Monitoring & Control System) and a visual and auditory alarm system within the ship in case the action is confirmed as abnormal through the classification step.

[0010] In addition, in the early warning method for a ship cyber attack according to one aspect of the present invention, the detection step can detect whether an abnormality has occurred in any one of the major equipment in the ship, including an AMS (Alarm. Monitoring & Control System) abnormal signal generator, an AIS (Automatic Identification System) abnormal signal generator, an M / E (Main Engine) abnormal signal generator, a sensor abnormal signal generator, a ship electronic chart system, and a loading computer.

[0011] In addition, in the early warning method for a ship cyber attack according to one aspect of the present invention, the detection step is characterized in that it can detect abnormal behavior at the early stage of the response measure by comparing various actual abnormal behaviors and response details, and confirming the result value through simulation of the initial response measure, thereby generating an early warning.

[0012] In addition, in the early warning method for a ship cyber attack according to one aspect of the present invention, the classification step is characterized by checking the equipment input values, time, location, route, and communication records for actions taken in response to the occurrence of an abnormal signal, comparing the actions and input data of the crew members, and classifying the actions as normal or abnormal.

[0013] In addition, a ship cyber attack early warning system according to another aspect of the present invention is characterized by including: a learning unit that learns the behavior and input data of crew members regarding abnormal cyber activity of a ship; a detection unit that detects whether an abnormal activity has occurred on the ship's equipment in conjunction with an AMS (Alarm. Monitoring & Control System); a storage unit that stores the behavior and input data of crew members taken as measures for the abnormal activity detected by the detection unit; a simulation unit that simulates the details of the measures taken based on the data stored in the storage unit; a classification unit that compares the behavior and input data of crew members regarding the abnormal activity as a result of simulation through the simulation unit with the data learned through the learning unit and classifies the measures as normal or abnormal; and an alarm unit that generates an early warning in conjunction with an AMS (Alarm. Monitoring & Control System) and a visual and auditory alarm system within the ship when the action is confirmed as abnormal through the classification unit.

[0014] In addition, in a ship cyber attack early warning system according to another aspect of the present invention, the detection unit is characterized in that it detects whether an abnormality has occurred in any one of the main equipment in the ship, including an AMS (Alarm. Monitoring & Control System) abnormal signal generator, an AIS (Automatic Identification System) abnormal signal generator, an M / E (Main Engine) abnormal signal generator, a sensor abnormal signal generator, a ship electronic chart system, and a loading computer.

[0015] In addition, in a ship cyber attack early warning system according to another aspect of the present invention, the detection unit compares various actual abnormal behaviors with response details and verifies the results through simulations of initial response measures, thereby detecting abnormal behaviors at an early stage of response measures and generating an early warning.

[0016] In addition, the early warning system for a ship cyber attack according to another aspect of the present invention is characterized in that the classification unit checks the equipment input values, time, location, route, and communication records for actions taken in response to the occurrence of an abnormal signal, compares the actions and input data of the crew members, and classifies the actions as normal or abnormal.

[0017] According to the present invention, it has the effect of detecting abnormal behavior and performing an alarm through linkage with the AMS (Alarm. Monitoring & Control System) system while taking into account the ship control system environment.

[0018] In addition, according to the present invention, in a seafarer training environment implemented on land, abnormal behavior conditions of a ship's system are generated, and the actions and input data of the seafarers in response to the abnormal behavior conditions are learned, thereby classifying normal and abnormal response measures, and when a cyber accident occurs at sea in an actual sea, an early warning can be issued in the event of abnormal response measures input or actions based on the actions and input learning data of the seafarers.

[0019] In addition, according to the present invention, it has the effect of being able to perform new ship IT / OT security detection by overcoming security application limitations for IT / OT systems within ships.

[0020] Figure 1 is a drawing showing a conventional AMS (Alarm. Monitoring & Control System).

[0021] Figure 2 is a diagram showing the configuration of a ship cyber attack early warning system according to the present invention.

[0022] Figure 3 is a diagram showing a learning step in a ship cyber attack early warning method according to the present invention.

[0023] Figure 4 is a drawing showing the sequence of a ship cyber attack early warning method according to the present invention.

[0024] Figures 5 and 6 are diagrams showing a learning step for enhancing a detection unit in a ship cyber attack early warning method according to the present invention.

[0025] The purpose and technical configuration of the present invention and the resulting operation and effects will be more clearly understood through a detailed description based on the drawings attached to the specification of the present invention.

[0026] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. For example, terms such as "consist of" or "include" used herein should not necessarily be construed to include all of the various components or various steps described in the invention, but should be construed to mean that some of the components or some steps may not be included, or that additional components or steps may be included. Furthermore, the singular expression "a" or "an" as used herein includes the plural expression unless the context clearly dictates otherwise.

[0027] Hereinafter, the present invention will be described in detail by describing preferred embodiments thereof with reference to the attached drawings. The embodiments described below are provided to facilitate the technical concept of the present invention for those skilled in the art to understand, and should not be construed as limiting the present invention. It should be understood that the embodiments of the present invention will have various applications to those skilled in the art.

[0028] The ship is building a surveillance monitoring system by collecting input / output values ​​for field stations through the AMS (Alarm. Monitoring & Control System).

[0029] Referring to FIGS. 2 to 6, the present invention relates to a ship cyber attack early warning system and method capable of detecting abnormal behavior through linkage with an AMS (Alarm. Monitoring & Control System) system while taking into account a ship control system (OT) environment.

[0030] More specifically, the ship cyber attack early warning system (100) according to the present invention may include a learning unit (110), a detection unit (120), a storage unit (130), a simulation unit (140), a classification unit (150), and an alarm unit (160), as shown in FIG. 2.

[0031] When cyber abnormal behavior is generated (50) outside the ship, such as in a crew training environment implemented on land, and transmitted to the ship, the learning unit (110) of the ship cyber attack early warning system (100) learns the behavior and input data of the crew in response to the cyber abnormal behavior of the ship.

[0032] In addition, the detection unit (120) can detect whether an abnormal behavior has occurred in the ship's equipment by linking with the AMS (Alarm. Monitoring & Control System).

[0033] That is, it is possible to detect through the detection unit whether an abnormality has occurred in any of the major equipment on board the ship, including the AMS (Alarm. Monitoring & Control System) abnormal signal generator, AIS (Automatic Identification System) abnormal signal generator, M / E (Main Engine) abnormal signal generator, sensor abnormal signal generator, ship electronic chart system, and loading computer.

[0034] Additionally, the storage unit (130) can store the actions and input data of the crew members taken as measures for abnormal behavior detected by the detection unit (120).

[0035] The simulation unit (140) can simulate the action details based on the data stored in the storage unit (130).

[0036] The classification unit (150) can classify the sailors' behavior and input data regarding abnormal behavior as a result of simulation through the simulation unit (140) into normal or abnormal actions by comparing them with data learned through the learning unit (110).

[0037] If an abnormal action is confirmed through the classification unit (150), the alarm unit (160) can generate an alarm by linking with the visual and auditory alarm system on the ship, such as the AMS (Alarm. Monitoring & Control System).

[0038] At this time, the detection unit (120) is characterized in that it can detect abnormal behavior at the initial stage of response measures and generate an early warning by comparing various actual abnormal behaviors and response details and confirming the result values ​​through simulation of initial response measures.

[0039] In addition, in the early warning system for ship cyber attacks according to the present invention, the classification unit (150) can check the equipment input values, time, location, route, and communication records for actions taken in response to the occurrence of an abnormal signal, and compare the actions and input data of the crew members to classify the actions as normal or abnormal.

[0040] In addition, the early warning method for a ship cyber attack according to the present invention may include a learning step (S10), a detection step (S110), a storage step (S120), a simulation step (S130), a classification step (S140), and an alert step (S150), as illustrated in FIGS. 3 to 6.

[0041] The learning stage (S10) can learn the crew's actions and input data regarding cyber anomalies on the ship through the learning unit.

[0042] More specifically, the learning step (S10) can generate ship cyber abnormality conditions and transmit them to the ship (S11) by generating them on land or outside the ship.

[0043] In case of abnormal cyber activity on ships, the occurrence of abnormal activity on ship equipment is detected (S12) through linkage with AMS (Alarm. Monitoring & Control System), actions are taken by passengers or shore personnel (S13), the actions taken and input data are saved (S14), and the action data is simulated (S15), and the impact on ship equipment and the details of the actions taken are analyzed (S16).

[0044] Therefore, it is possible to determine whether measures taken against cyber anomalies on ships were carried out normally or abnormally based on the impact on ship equipment.

[0045] The detection step (S110) can detect whether an abnormality has occurred in the ship's equipment through a detection unit linked to the AMS (Alarm. Monitoring & Control System).

[0046] In addition, the detection step (S110) compares and updates (S70) the data learned through the learning step with various actual abnormal behaviors and response details, and confirms the result value through simulation (S80) for initial response measures, thereby detecting abnormal behaviors in the initial stage of response measures and generating an early alert (S90).

[0047] The storage step (S120) can store the actions and input data of the crew members taken as measures for abnormal behavior detected through the detection step (S110) in the storage unit.

[0048] Simulation step (S130) Action details can be simulated through the simulation section based on data stored in the storage section.

[0049] The classification step (S140) can classify the abnormal behavior of the sailors and input data through the simulation result of the simulation step (S130) by comparing it with the learned data and judging it as normal or abnormal through the classification unit.

[0050] The alert stage (S150) can generate an early warning through the alert unit if an abnormal action is confirmed through the classification stage (S140).

[0051] In addition, the detection step (S110) can detect whether an abnormal behavior has occurred in any one of the AMS (Alarm. Monitoring & Control System) abnormal signal generator, the AIS (Automatic Identification System) abnormal signal generator, the M / E (Main Engine) abnormal signal generator, and the sensor abnormal signal generator, and is characterized by being able to detect an abnormal behavior in the early stage of the response measure by comparing various actual abnormal behaviors and response details and confirming the result value through simulation of the initial response measure, and generating an alarm early.

[0052] In addition, the classification step (S140) can classify the action as normal or abnormal by comparing the actions and input data of the crew members by checking the equipment input values, time, location, route, and communication records for the actions taken in response to the occurrence of an abnormal signal.

[0053] This allows for early warning of abnormal response actions and behaviors based on the sailors' behavior and input learning data in the event of a cyber incident at sea.

[0054] Therefore, according to the present invention, it has the effect of detecting abnormal behavior and performing an alarm through linkage with the AMS (Alarm. Monitoring & Control System) system while taking into consideration the ship control system environment.

[0055] In addition, according to the present invention, in a seafarer training environment implemented on land, abnormal behavior conditions of a ship's system are generated, and the actions and input data of the seafarers in response to the abnormal behavior conditions are learned, thereby classifying normal and abnormal response measures, and when a cyber accident occurs at sea in an actual sea, an early warning can be issued in the event of abnormal response measures input or actions based on the actions and input learning data of the seafarers.

[0056] In addition, according to the present invention, it has the effect of overcoming the limitations of security application to the IT (Information Technology) / OT (Operational Technology) system in a ship, thereby performing new ship IT / OT security detection.

[0057] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0058] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be construed as limiting the present invention thereby. It will be apparent to those skilled in the art that the embodiments of the present invention can be variously modified and altered without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be considered to fall within the scope of the claims of the present invention.

[0059] 50: Cyber ​​anomaly generation outside the ship

[0060] 100: Ship Cyber ​​Attack Early Warning System

[0061] 110: Learning Department

[0062] 120: Detection Unit

[0063] 130: Storage

[0064] 140: Simulation Department

[0065] 150: Classification Department

[0066] 160: Alert Department

Claims

1. A learning stage in which the crew's actions and input data regarding cyber anomalies on the ship are learned through the learning unit; A detection step that detects whether an abnormality has occurred in the ship's equipment through a detection unit linked to the AMS (Alarm, Monitoring & Control System); A storage step for storing the actions and input data of sailors taken as measures for abnormal behavior detected through the above detection step in a storage unit; A simulation step for simulating action details through a simulation unit based on data stored in the above storage unit; A classification step for comparing the sailors' behavior and input data regarding abnormal behavior through the simulation results through the above simulation step with the learned data and classifying them as normal or abnormal measures through the classification unit; and A method for early warning of a cyber attack on a ship, characterized in that it includes an alarm step for generating an early warning through an alarm unit that links with the AMS (Alarm, Monitoring & Control System) and the visual and auditory warning system on the ship when an abnormal measure is confirmed through the above classification step.

2. In claim 1, The above detection step is, A method for early warning of a ship cyber attack, characterized by detecting whether an abnormality has occurred in any one of the main equipment on board the ship, including an AMS (Alarm, Monitoring & Control System) abnormal signal generator, an AIS (Automatic Identification System) abnormal signal generator, an M / E (Main Engine) abnormal signal generator, a sensor abnormal signal generator, a ship electronic chart system, and a loading computer.

3. In claim 1, The above detection step is, An early warning method for ship cyber attacks, characterized in that it can detect abnormal behaviors at the early stage of response measures and generate early warnings by comparing various actual abnormal behaviors and response details, verifying the results through simulation of initial response measures, and so on.

4. In claim 1, The above classification steps are: An early warning method for ship cyber attacks, characterized by checking input values ​​of equipment, time, location, route, and communication records for actions taken in response to occurrence of an abnormal signal, comparing the actions and input data of crew members, and classifying them as normal or abnormal actions.

5. A learning unit that learns the behavior and input data of crew members regarding cyber anomalies on the ship; A detection unit that detects whether abnormal behavior has occurred on board a ship by linking with the AMS (Alarm, Monitoring & Control System); A storage unit that stores the actions and input data of sailors taken as measures for abnormal behavior detected through the above detection unit; A simulation unit that simulates action details based on data stored in the above storage unit; A classification unit that compares the sailors' behavior and input data regarding abnormal behavior through the simulation results through the above simulation unit with the data learned through the learning unit and classifies it as normal or abnormal action; and A ship cyber attack early warning system characterized by including an alarm unit that generates an early warning by linking with the AMS (Alarm, Monitoring & Control System) and the visual and auditory warning system within the ship when an abnormal measure is confirmed through the above classification unit.

6. In claim 5, The above detection unit, A ship cyber attack early warning system characterized by detecting whether an abnormality has occurred in any one of the major equipment on board the ship, including an AMS (Alarm, Monitoring & Control System) abnormal signal generator, an AIS (Automatic Identification System) abnormal signal generator, an M / E (Main Engine) abnormal signal generator, a sensor abnormal signal generator, a ship electronic chart system, and a loading computer.

7. In claim 5, The above detection unit, An early warning system for ship cyber attacks, characterized by being able to detect abnormal behaviors at the early stage of response measures and generate early warnings by comparing various actual abnormal behaviors and response details, verifying the results through simulation of initial response measures, and so on.

8. In claim 5, The above classification section is, An early warning system for ship cyber attacks, characterized by checking input values, time, location, route, and communication records for measures taken in response to occurrence of abnormal signals, comparing the actions and input data of crew members, and classifying them as normal or abnormal measures.

Citation Information

Patent Citations

  • Alarm system of ship and method using the same

    KR1020170110932A

  • Fire alarm system for ship and method for monitoring fire alarm using same

    KR1020140057443A

  • Security Equipment Control Policy Automatic Application System based on Infringement Accident Counterpart and Method Thereof

    KR102090757B1

  • System and method for predicting health of vessel

    KR102316773B1

  • Method and apparatus for detecting network intrusion of vessel

    KR102569600B1