Attack surface information-based deception information generation system and method

The deception information generation system for ICT-based ships addresses cyber threats by disguising as internal systems, analyzing packets, and triggering alarms to prevent damage, enhancing cyber defense and reducing costs.

WO2025143909A1PCT designated stage expired Publication Date: 2025-07-03HANWHA OCEAN CO LTD (KR) +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021344
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-27
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

The construction of ICT-based ships such as smart ships and autonomous ships increases cyber threats, and existing deception technologies face challenges in limited ship systems and excessive satellite communication costs, requiring efficient cyber threat detection and early attack sign identification.

Method used

A deception information generation system using a deception terminal that disguises as an actual internal system, analyzing packets, determining risk levels, and triggering alarms or blocks when malicious activity is detected, employing protocols like 802.1x and generating decoy information with ship-specific data.

Benefits of technology

Secures cyber threat detection and defense in new environments, enabling early identification of attacks and preventing system damage by deceiving attackers, with reduced resource and communication costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021344_03072025_PF_FP_ABST
    Figure KR2024021344_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to an attack surface information-based deception information generation system and method, and provides an attack surface information-based deception information generation system and method for protecting a ship by deceiving a cyber attacker attacking the ship, posing as an actual internal system of the ship, identifying a sign of attack during an early stage of attack, and responding early to the sign of attack.
Need to check novelty before this filing date? Find Prior Art

Description

System and method for generating deception information based on attack surface information

[0001] The present invention relates to a system and method for generating deception information based on attack surface information, and relates to a technology for protecting a ship by deceiving a cyber attacker attacking a ship, disguising the attacker as an actual ship internal system, identifying attack signs in the early stage of the attack, and taking an initial response.

[0002] In the past, in response to cyber threats, we developed a framework and module for deceiving cyber attackers by luring them into attacks based on deception technology, and blocked the spread of damage by detecting anomalies in the cyber attack preparation stage, and improved the detection rate by linking logs detected by deception technology with other security equipment.

[0003] In addition, with the rapid increase in the construction of ICT-based autonomous ships, smart ships, and unmanned ships, and the increased connectivity between land and sea vessels, cyber threats to ships are increasing. However, the construction and operation of various security systems, such as those on land, are limited, and there is a problem of excessive satellite communication costs when transmitting all security logs inside the ship to land.

[0004] In addition, as illustrated in Fig. 1, the deception-related technology places a decoy system disguised as a monitoring device or a normal device in front of the network, and transmits the packet received from the device to a decoy agent if it is a normal IP used in the past, and to a decoy agent if it is an unused IP. However, since the communication path inside the ship is limited to the IEEE6112-450 / 460 environment, analyzing the lured attacker by operating a large number of vulnerable systems based on virtualization requires an excessive amount of resources (systems, VMs, IPs, etc.) that must be installed on the ship, and there were difficulties in the limited ship system, network, and human resource environment.

[0005] As a related prior art document, Republic of Korea Patent Publication No. 10-2020-0055403 (May 21, 2020) is published.

[0006] The purpose of the present invention is to provide a system and method for generating deception information based on attack surface information that can secure cyber threat detection and defense technology in a new environment as the construction of ICT-based ships such as smart ships and autonomous ships increases.

[0007] Another object of the present invention is to provide a system and method for generating deception information based on attack surface information, which can identify attack signs in the early stage of an attack by deceiving an attacker and disguising it as an actual ship internal system, so as to respond before system damage occurs.

[0008] In order to achieve the above object, a system for generating deception information based on attack surface information according to one aspect of the present invention comprises a deception terminal for deceiving an attacker attacking a ship, and a decoy terminal for luring a cyber attack by disguising itself as an actual ship internal system and analyzing information, wherein the deception terminal comprises a decoy information generation unit for generating decoy information, a decoy information determination unit for determining whether a user, system, or device accessing the decoy terminal is a normal user or a malicious user, and a decoy information action unit for transmitting a blocking or alarm event if the lured user, system, or device is a malicious user; and the decoy terminal comprises a decoy information collection unit for collecting packets initially accessing the decoy terminal, a decoy information analysis unit for analyzing packets entering the decoy terminal, and a decoy unit for causing a decoy agent generated through decoy information generated by the decoy information generation unit of the terminal to operate; Based on the received information such as packet information received from the above-mentioned deceptive terminal and input information of the lured user, the risk level of the lure is determined, and if it exceeds the set value, it is determined to be an attacker and action can be taken through a notification.

[0009] In addition, in the deception information generation system based on attack surface information according to one aspect of the present invention, the decoy information generation unit of the deception terminal is characterized by generating a web page and configuration file of a ship marine satellite communication system, dynamic navigation information, and hardware information (MAC) of the system.

[0010] In addition, in the deception information generation system based on attack surface information according to one aspect of the present invention, the decoy information determination unit of the deception terminal is characterized in that it determines whether the decoy is an attacker based on a risk score based on received information such as an incoming packet and input information of the decoyed user.

[0011] In addition, in a deception information generation system based on attack surface information according to one aspect of the present invention, the decoy information action unit of the deception terminal is characterized in that, if the risk level is calculated to be above a certain level, the deception system determines the user as an attacker and displays an alarm such as an emergency bell or message to the user, displays it on a ship terminal device, or displays a message on an HMI of a ship alarm monitoring system.

[0012] In addition, in a deception information generation system based on attack surface information according to one aspect of the present invention, the decoy information analysis unit of the decoy terminal can classify a signal of a packet introduced into the decoy terminal, define and extract a message value from the classified signal, and extract decoy information from the extracted message value.

[0013] In addition, in a deception information generation system based on attack surface information according to one aspect of the present invention, the deception unit of the deception terminal causes a deception agent generated with a program, an operating system, and system information having the characteristics of a shipboard equipment system generated from the deception information generation unit of the deception terminal to operate.

[0014] According to another aspect of the present invention, a method for generating deception information based on attack surface information comprises: a deception terminal for deceiving a cyber attacker attacking a ship, and a decoy terminal for disguising itself as an actual ship internal system to lure a cyber attack and analyze information; a decoy information generation step for generating decoy information in a decoy information generation unit of the deception terminal; a decoy information collection step for receiving the decoy information generated in the decoy information generation step and collecting packets that initially access the decoy terminal in a decoy information collection unit; a decoy information analysis step for analyzing the decoy information and packets collected in the decoy information collection step; a decoy step for causing a decoy agent generated through the decoy information generated in the decoy information generation unit of the terminal to operate in the decoy unit; a decoy information determination step for determining whether a user, system, or device accessing the decoy terminal in the decoy step is a normal user or a malicious user; The above-mentioned lure information judgment step may include an action step of transmitting a blocking or alarm event from the lure information action unit if the lured user, system, or device is a malicious user.

[0015] In addition, in a method for generating deception information based on attack surface information according to another aspect of the present invention, the decoy information generation step is characterized by generating a web page and configuration file of a ship marine satellite communication system, dynamic navigation information, and hardware information (MAC) of the system.

[0016] In addition, in a method for generating deception information based on attack surface information according to another aspect of the present invention, the lure information determination step is characterized in that it determines whether the lure is an attacker based on a risk score based on received information such as an incoming packet and input information of the lured user.

[0017] In addition, in a method for generating deception information based on attack surface information according to another aspect of the present invention, the action step is characterized in that, if the risk level is calculated to be above a certain level, the attacker is judged, and the deception system displays an alarm to the user with an emergency bell, message, etc., or displays it on a ship terminal device, or displays a message on an HMI of a ship alarm monitoring system.

[0018] In addition, in a method for generating deception information based on attack surface information according to another aspect of the present invention, the decoy information analysis step may classify a signal of a packet introduced into a decoy terminal, define and extract a message value from the classified signal, and extract decoy information from the extracted message value.

[0019] In addition, in a method for generating deception information based on attack surface information according to another aspect of the present invention, the lure step causes a lure agent generated with a program, an operating system, and system information having the characteristics of a shipboard equipment system generated from a lure information generation unit of a deception terminal to operate.

[0020] According to the present invention, as the construction of ICT-based ships such as smart ships and autonomous ships increases, it has the effect of securing cyber threat detection and defense technology in a new environment.

[0021] In addition, according to the present invention, it has the effect of being able to identify attack signs in the early stage of an attack by deceiving an attacker and disguising it as an actual ship internal system, thereby enabling response before system damage occurs.

[0022] Figure 1 is a diagram showing a deception technique for conventional cyber threats.

[0023] FIG. 2 is a diagram showing the configuration of a deception information generation system based on attack surface information according to the present invention.

[0024] FIG. 3 is a diagram showing a process performed in a deception information analysis unit in a deception information generation system based on attack surface information according to the present invention.

[0025] FIG. 4 is a diagram showing detailed data of a decoy information analysis unit in a deception information generation system based on attack surface information according to the present invention.

[0026] FIG. 5 is a diagram showing a process performed in a deception information judgment unit in a deception information generation system based on attack surface information according to the present invention.

[0027] FIG. 6 is a diagram showing an example of an alarm display performed in a decoy information action unit in a deception information generation system based on other attack surface information according to the present invention.

[0028] The purpose and technical configuration of the present invention and the resulting operation and effects will be more clearly understood through a detailed description based on the drawings attached to the specification of the present invention.

[0029] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. For example, terms such as "consist of" or "include" used herein should not necessarily be construed to include all of the various components or various steps described in the invention, but should be construed to mean that some of the components or some steps may not be included, or that additional components or steps may be included. Furthermore, the singular expression "a" or "an" as used herein includes the plural expression unless the context clearly dictates otherwise.

[0030] Hereinafter, the present invention will be described in detail by describing preferred embodiments thereof with reference to the attached drawings. The embodiments described below are provided to facilitate the technical concept of the present invention for those skilled in the art to understand, and should not be construed as limiting the present invention. It should be understood that the embodiments of the present invention will have various applications to those skilled in the art.

[0031] Referring to FIGS. 2 to 6, a deception information generation system (100) based on attack surface information according to the present invention may include a deception terminal (110) including a decoy information generation unit (111) that generates decoy information, a decoy information determination unit (112) that determines whether a user, system, or device accessing a decoy terminal is a normal user or a malicious user, and a decoy information action unit (113) that transmits a blocking or alarm event if the decoyed user, system, or device is a malicious user, a decoy information collection unit (121) that collects packets that initially approach the decoy terminal, a decoy information analysis unit (122) that analyzes packets that enter the decoy terminal, and a decoy unit (113) that causes a decoy agent generated through information generated by the decoy information generation unit of the terminal to operate.

[0032] At this time, the deception information generation system (100) based on attack surface information was designed to take into account the isolation means that took into account the 802.1x environment of the ship, and applied the 802.1x protocol mandatory as a cybersecurity technology installed in a new ship.

[0033] It can also be applied as an alternative to protocols or equipment authentication methods used in wireless environments, and can be blocked through deauthentication / disassociation through prove linkage with the system.

[0034] The decoy information generation unit (111) of the deception terminal (110) of the deception information generation system (100) based on attack surface information according to the present invention generates information on the main system within the ship that induces a cyber attacker to mistake it for an internal system within the ship.

[0035] Additionally, the main information of the system can be configured to have the characteristics of the operating system, program, and network of the ship's navigation, communication, control, propulsion, and power systems.

[0036] Additionally, it may include navigation information (Heading, Speed, GPS, throttle, temperature, pressure, etc.) and the manufacturer, product name, and hardware information (MAC) of each system.

[0037] Additionally, information generated in the attraction information generation unit (111) can be injected into the attraction terminal.

[0038] That is, the attractor information collection unit (121) of the attractor terminal (120) can collect packets that first access the attractor terminal (120), and the interface can be configured as an industrial standard RS-232, RS-422, or Modbus TCP Master / Slave.

[0039] In addition, the attractor information analysis unit (122) analyzes packets entered into the attractor terminal (120). Protocols such as HTTP, FTP, and SSH, which are generally known in TCP packets, and MODBUS, NMEA, PLC, and CAN included in TCP packets are classified.

[0040] As illustrated in FIGS. 3 and 4, the attractor information analysis unit (122) includes a signal classification step (S220) for classifying a signal from an incoming packet (S210), a packet definition step (S230) for extracting a message value from a signal classified through the signal classification step (S220), and a packet extraction step (S240) for extracting packet information through the message value extracted in the packet definition step (S230) to confirm attractor information.

[0041] More specifically, the attractor information analysis unit (122) classifies (S220) a signal from a packet (S210) introduced into the attractor terminal (120).

[0042] At this time, the signal classification step (S220) that classifies the signal classifies whether the incoming packet is a normal TCP packet or a packet transmitted as a TCP packet from a control terminal device.

[0043] Next, in the packet definition step (S230), the message value is extracted from the classified signal.

[0044] For example, in the case of MODBUS-TCP, the values ​​of the messages are defined from the industry standard RS-485 / Modbus-RTU.

[0045] In the packet extraction step (S240), the IP address, Port, Unit ID, Protocol, Slave Address, Baud Rate, etc. are checked.

[0046] In the manned unit (123) of the manned terminal (120), a manned agent generated with a program, operating system, and system information having the characteristics of the ship's equipment system generated from the manned information generation unit (111) of the deception terminal (110) operates.

[0047] The manned agent operates with HTTP, FTP, SSH, SFTP, TELNET, MODBUS, PLC, CAN, and NMEA protocols and their corresponding port and MAC information.

[0048] For example, when the manned information of a ship's marine satellite communication system is generated in the manned information generation unit (111), the web page and configuration file constituting it, dynamic navigation information, and hardware information (MAC) of the system are generated.

[0049] Dynamic navigation information can consist of detailed information such as the vessel's current location (GPS position), heading, and knot.

[0050] In addition, when the lure information is generated from the lure information generation unit (111) to the ship alarm monitoring system (AMS), it may be composed of hardware information (MAC), information on open ports, and information on services in operation.

[0051] The lure information judgment unit (112) determines whether the lure is an attacker based on the risk score based on the received information such as the incoming packet and the input information of the lured user.

[0052] That is, as shown in Fig. 5, it is checked whether the received information is a registered CBS IP (Computer Based System Internet Protocol), and if it is registered, a risk score of 0 is given, and if it is not registered, a risk score of 3 is given.

[0053] Next, check whether it is a port of a registered CBS IP, and if it is registered, give it a risk score of 0, and if it is not registered, give it a risk score of 3.

[0054] Next, check whether it is a registered CBS MAC, and if it is registered, give it a risk score of 0, and if it is not registered, give it a risk score of 3.

[0055] That is, if registered, the risk score will not increase, and if not registered, the risk score may accumulate and increase.

[0056] Next, we check who owns the registered origin IP, and if it is a device, we give it a risk score of 0, and if it is a crew, we give it a risk score of 3.

[0057] Next, the owner's authority is judged, and if it is LOCAL, a risk score of 1 point is given, and if it is REMOTE, a risk score of 3 points is given.

[0058] Next, the registered IP owner location hop information is checked and if it is the same, a risk score of 1 point is given, and if it is different, a risk score of 3 points is given.

[0059] Next, the number of requests is checked, and if it is 1 time, a risk score of 1 point is given, and if it is n or more times, a risk score of 3 points is given.

[0060] Next, the number of failures in the input information is checked, and if it is 1 time, a risk score of 1 point is given, and if it is n or more times, a risk score of 3 points is given.

[0061] Next, the risk level is determined based on the total score, and if it exceeds the set value, the person can be determined to be an attacker.

[0062] The decoy information action unit (113) determines that the attacker is an attacker when the risk level is calculated to be above a certain level, and the deception system can display an alarm to the user (sailor, shore worker) with an emergency bell, message, etc., display it on the ship terminal device, or display a message on the HMI of the ship alarm monitoring system (AMS).

[0063] The displayed message, as illustrated in Figure 6, compares the detected Source IP with registered CBS Inventory information and displays the deck, room, IP, MAC, and user / system information used by the IP. This allows ground / board personnel to take remote or on-site action.

[0064] Therefore, according to the present invention, as the construction of ICT-based ships such as smart ships and autonomous ships increases, it has the effect of securing cyber threat detection and defense technology in a new environment.

[0065] In addition, according to the present invention, it has the effect of being able to identify attack signs in the early stage of an attack by deceiving an attacker and disguising it as an actual ship internal system, thereby enabling response before system damage occurs.

[0066] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0067] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be construed as limiting the present invention thereby. It will be apparent to those skilled in the art that the embodiments of the present invention can be variously modified and altered without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be considered to fall within the scope of the claims of the present invention.

[0068] 100: Deception Information Generation System Based on Attack Surface Information

[0069] 110: Deception Terminal

[0070] 111: Information Generation Unit

[0071] 112: Manned Information Decision Department

[0072] 113: Manned Information Action Unit

[0073] 120: Manned terminal

[0074] 121: Information Collection Unit for the Attractor

[0075] 122: Attractor Information Analysis Department

[0076] 123: The Manned Unit

Claims

1. The deception information generation system based on attack surface information includes a deception terminal that deceives the attacker attacking the ship and a decoy terminal that disguises itself as an actual ship internal system to induce a cyber attack and analyze the information. The above-mentioned deceptive terminal includes a deception information generation unit that generates deceptive information, a deceptive information judgment unit that determines whether a user, system, or device accessing the deceptive terminal is a normal user or a malicious user, and a deceptive information action unit that blocks or transmits an alarm event if the deceptive user, system, or device is a malicious user. The above-mentioned manned terminal includes a manned information collection unit that collects packets initially accessing the manned terminal, a manned information analysis unit that analyzes packets entering the manned terminal, and a manned unit that causes a manned agent generated through manned information generated in the manned information generation unit of the terminal to operate; A deception information generation system based on attack surface information that determines the risk level of a decoy based on received information such as packet information received from the above-mentioned deception terminal and input information of a decoyed user, and if the risk level exceeds a set value, determines the user to be an attacker and enables measures to be taken through a notification.

2. In claim 1, The above deceptive terminal's decoy information generation unit is: A deception information generation system based on attack surface information, characterized by generating web pages and configuration files of a ship's marine satellite communication system, dynamic navigation information, and hardware information (MAC) of the system.

3. In claim 1, The above deceptive terminal's decoy information judgment unit is, A deception information generation system based on attack surface information, characterized in that it determines whether the lured user is an attacker based on a risk score based on received information such as incoming packets and input information of the lured user.

4. In claim 1, The above-mentioned deception terminal's decoy information action unit is: A deception information generation system based on attack surface information, characterized in that when the risk level is calculated to be above a certain level, the system determines that the attacker is an attacker, and the deception system displays an alarm to the user in the form of an emergency bell, message, etc., or displays a message on the ship terminal device, or displays a message on the HMI of the ship alarm monitoring system.

5. In claim 1, The manned information analysis unit of the above manned terminal is: A deception information generation system based on attack surface information that classifies the signal of a packet introduced into a decoy terminal, defines and extracts the value of a message from the classified signal, and extracts decoy information from the extracted message value.

6. In claim 1, The manned part of the above manned terminal is, A deception information generation system based on attack surface information that causes a decoy agent generated with a program, operating system, and system information having the characteristics of a shipboard equipment system generated from a decoy information generation unit of a deception terminal to operate.

7. The deception information generation system based on attack surface information includes a deception terminal that deceives the attacker attacking the ship, and a decoy terminal that disguises itself as an actual ship internal system to induce a cyber attack and analyze the information. A decoy information generation step for generating decoy information in the decoy information generation unit of the above-mentioned deception terminal; A lure information collection step in which the lure information generated in the above lure information generation step is received and the packet that initially accesses the lure terminal is collected by the lure information collection unit; A attractor information analysis step for analyzing the attractor information and packets collected in the above attractor information collection step; An attraction step in which an attraction agent generated through attraction information generated in the attraction information generation unit of the terminal terminal is operated in the attraction unit; A lure information judgment step for determining whether a user, system, or device accessing the lure terminal in the above lure step is a normal user or a malicious user; A method for generating deception information based on attack surface information, including an action step of transmitting a blocking or alarm event from a deception information action unit if the user, system, or device deceived through the above-mentioned deception information judgment step is a malicious user.

8. In claim 7, The above-mentioned attraction information generation step is: A method for generating deception information based on attack surface information, characterized by generating a web page and configuration file of a ship marine satellite communication system, dynamic navigation information, and hardware information (MAC) of the system.

9. In claim 7, The above-mentioned step of judging the attractive information is: A method for generating deception information based on attack surface information, characterized in that it determines whether the lured user is an attacker based on a risk score based on received information such as incoming packets and input information of the lured user.

10. In claim 7, The above action steps are: A method for generating deception information based on attack surface information, characterized in that when the risk level is calculated to be above a certain level, the attacker is judged to be an attacker, and the deception system displays an alarm to the user in the form of an emergency bell, message, etc., or displays a message on the ship terminal device, or displays a message on the HMI of the ship alarm monitoring system.

11. In claim 7, The above attractor information analysis step is: A method for generating deception information based on attack surface information, which classifies the signal of a packet introduced into a decoy terminal, defines and extracts the value of a message from the classified signal, and extracts decoy information from the extracted message value.

12. In claim 7, The above induction step is, A method for generating deception information based on attack surface information, which causes a decoy agent generated with a program, operating system, and system information having the characteristics of a shipboard equipment system generated from a decoy information generation unit of a deception terminal to operate.

Citation Information

Patent Citations

  • Apparatus and method for intrusion detection using client terminal, system and method for network security of the same

    KR1020090106197A

  • Method of location-based contents sharing

    KR1020210136728A

  • Interfloor noise mats that allow robot cleaners to enter

    KR1020250022350A

  • System And Method For Generating Deception Information Based On Attack Surface Information

    KR102729651B1

  • Software defined networking moving target defense honeypot

    US20210051175A1