Security control and cost control optimization system and method

The system optimizes security and cost control by calculating and simulating control costs and risks in ship cybersecurity architecture, addressing the challenge of inappropriate security level selection and enhancing security standards through standardized data analysis.

WO2025144026A1PCT designated stage expired Publication Date: 2025-07-03HANWHA OCEAN CO LTD (KR) +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/097196
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-12-27
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Current methods lack the ability to accurately calculate and simulate detailed control costs for security controls, leading to overspending or under-execution in selecting appropriate security levels, and there is a risk of control circumvention due to inappropriate security control selection.

Method used

A system and method for optimizing security and cost control by calculating control costs based on control policies, identifying acceptable risks, and automatically suggesting optimal security costs through a server-connected cybersecurity database and user terminal devices, utilizing a security control and cost control program to analyze ship cybersecurity architecture.

Benefits of technology

Enables improved security standards by accurately determining control costs and risks, allowing for standardized data-based security control component selection and simulation of mitigation measures, thereby optimizing security and cost management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024097196_03072025_PF_FP_ABST
    Figure KR2024097196_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a system for simulating, in the configuration of a ship cybersecurity architecture, the appropriateness of control costs for suitable security controls. Presented are a security control and cost control optimization system and method, which calculate control costs according to a control policy included in selected security control; and identifying an acceptable control risk according to the control costs so as to automatically present optimal security costs, thereby enabling the determination that security standards of newly constructed companies, organizations and ships can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

System and method for optimizing security control and cost control

[0001] The invention relates to a system for simulating the appropriateness of control costs for appropriate security controls in configuring a ship cybersecurity architecture, calculating control costs according to control policies included in selected security controls, and automatically suggesting optimal security costs by identifying acceptable control risks according to the control costs, thereby enabling the security and cost simulation method and system to be used for making judgments so as to improve the security standards of newly constructed companies, organizations, and ships.

[0002] Recently, as cybersecurity threats have become more diverse and sophisticated, various security technologies and products are being released to respond to these threats. Threat response requires appropriate security cost calculations through security controls.

[0003] Typically, the conditions affecting security cost calculations are structured around requirements, compliance, environmental analysis results, and mitigation measures.

[0004] For example, in order to fulfill the Protect requirements of the International Association of Classification Societies (IACS) UR E26, it consists of the ship owner requirements of the relevant vessel, the rules to be followed, the manufacturer and model of the CBS to be installed as a result of the environmental analysis, the speed / capacity (bandwidth) of the underlying network, the number of cores in the system, the type of application, and the network configuration.

[0005] Accordingly, mitigation measures are implemented through firewalls, intrusion detection systems, and logging.

[0006] However, security control requires both technical measures such as systems, networks, applications, mobile devices, and source code, as well as policy measures such as security organizations, policies, users, and administrators. However, the stronger the control, the higher the cost of security control.

[0007] Therefore, the security controls that must be implemented according to security requirements and the cost invested in security controls must be selected at an appropriate level.

[0008] However, there is currently no way to calculate and simulate the detailed control costs required for security control to select an appropriate level of security control, and there has been a problem of control circumvention due to overspending or under-enforcement by selecting an inappropriate level of security control.

[0009] As a related prior art document, Republic of Korea Patent Publication No. 10-2020-0029266 (March 18, 2020) is published.

[0010] The purpose of the present invention is to provide a security control and cost control optimization system and method that can be judged through security and cost simulation so that the security standards of newly built companies, organizations, and ships can be improved by calculating the control cost according to the control policy included in the selected security control when configuring a ship cybersecurity architecture, automatically suggesting the optimal security cost by identifying the acceptable control risk according to the control cost.

[0011] Another object of the present invention is to provide a security control and cost control optimization system and method capable of formalizing components for security control, calculating security control costs based on formalized data, and performing simulations for various mitigation measures.

[0012] In order to achieve the above-described object, a security control and cost control optimization method according to one aspect of the present invention may include a server connection step in which a server, which is linked to a cybersecurity database and is equipped with a security control and cost control program, is connected to and communicates with a plurality of user terminal devices via the Internet, wherein the server connects to the server using a user terminal device; an input window provision step in which the server provides cybersecurity requirements and a menu, and provides an input window in which a cybersecurity condition for a selected menu can be input; an information input step in which the server inputs basic ship information and CBS condition information into the input window provided from the server through the input window provision step using the user terminal device; an extraction step in which the server calculates a control cost according to a control policy through analysis of ship cybersecurity requirements by linking with the cybersecurity database through the security control and cost control program based on the data entered through the information input step, and extracts an acceptable control risk according to the control cost; and a result provision step in which the result extracted through the extraction step is provided to the user terminal device.

[0013] In addition, in the security control and cost control optimization method according to one aspect of the present invention, in the information input step, the CBS condition information may include at least one of ship CBS, network, document, and onboard test information.

[0014] In addition, in the security control and cost control optimization method according to one aspect of the present invention, the extraction step is characterized by analyzing ship cybersecurity requirements, calculating the cost required to apply the security control method and the control technology and control policy dependent thereon, and extracting an acceptable control risk according to the control cost by simulating data corresponding to the input value.

[0015] In addition, in the security control and cost control optimization method according to one aspect of the present invention, the providing step may be provided as an axis graph representing characteristics of multiple security control items in conjunction with a cybersecurity database; and characterized in that the items requiring security control and the level of security control can be confirmed by checking the filled state of the reference axis graph of each security control item.

[0016] In addition, a security control and cost control optimization system according to another aspect of the present invention includes: a user terminal device that is connected to a cybersecurity database and communicates with a server equipped with a security control and cost control program to input requirements necessary for cybersecurity, including security requirements and regulations; a server that can be accessed through the user terminal device, provides cybersecurity requirements and menus, and provides an input window for inputting cybersecurity conditions for a selected menu; and a cybersecurity database that is connected to the server and stores cybersecurity information necessary for a ship, such as security requirements and regulations; the server analyzes security control through a security control and cost control program based on input data including basic ship information and CBS condition information input through the user terminal device by connecting to the cybersecurity database, thereby calculating a control cost according to a control policy, and extracting an acceptable control risk according to the control cost; and the server is characterized in that it provides the extracted result to the user terminal device.

[0017] In addition, in a security control and cost control optimization system according to another aspect of the present invention, the user terminal device inputs ship basic information and CBS condition information through an input window of a server; the CBS condition information may include at least one of ship CBS, network, document, and onboard test information.

[0018] In addition, in a security control and cost control optimization system according to another aspect of the present invention, the server is characterized in that it analyzes ship cybersecurity requirements, calculates the cost required to apply a security control method and a control technology and control policy dependent thereon, and extracts an acceptable control risk according to the control cost by simulating data corresponding to the input value.

[0019] In addition, in a security control and cost control optimization system according to another aspect of the present invention, the server can provide extracted data in conjunction with a cybersecurity database to a user terminal device as an axis graph representing characteristics of multiple security control items; and is characterized in that by checking the filled state of the reference axis graph of each security control item, the items requiring security control and the level of security control can be checked.

[0020] According to the present invention, when configuring a ship cybersecurity architecture, the control cost is calculated according to the control policy included in the selected security control, the acceptable control risk is identified according to the control cost, and the optimal security cost is automatically suggested, thereby improving the security standards of newly constructed companies, organizations, and ships, thereby having the effect of being able to judge through a simulation of security and cost.

[0021] In addition, according to the present invention, it is possible to standardize components for security control, calculate security control costs based on standardized data, and perform simulations for various mitigation measures.

[0022] Figure 1 is a drawing showing the configuration of a security control and cost control optimization system according to the present invention.

[0023] Figure 2 is a flowchart showing a security control and cost control optimization method according to the present invention.

[0024] FIG. 3 is a diagram showing a control cost calculation process in the extraction step of the security control and cost control optimization method according to the present invention.

[0025] FIG. 4 is a diagram showing an information input step and an extraction step in a security control and cost control optimization method according to the present invention.

[0026] FIG. 5 is a diagram showing the configuration of a ship cybersecurity database in a security control and cost control optimization system according to the present invention.

[0027] FIG. 6 is a drawing showing an input window provision step in a security control and cost control optimization method according to the present invention.

[0028] FIG. 7 is a diagram showing information input in the information input step in the security control and cost control optimization method according to the present invention.

[0029] FIG. 8 is a diagram illustrating a result provision step that provides results extracted from a security control and cost control optimization method according to the present invention.

[0030] The purpose and technical configuration of the present invention and the resulting operation and effects will be more clearly understood through a detailed description based on the drawings attached to the specification of the present invention.

[0031] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. For example, terms such as "consist of" or "include" used herein should not necessarily be construed to include all of the various components or various steps described in the invention, but should be construed to mean that some of the components or some steps may not be included, or that additional components or steps may be included. Furthermore, the singular expression "a" or "an" as used herein includes the plural expression unless the context clearly dictates otherwise.

[0032] Hereinafter, the present invention will be described in detail by describing preferred embodiments thereof with reference to the attached drawings. The embodiments described below are provided to facilitate the technical concept of the present invention for those skilled in the art to understand, and should not be construed as limiting the present invention. It should be understood that the embodiments of the present invention will have various applications to those skilled in the art.

[0033] The present invention relates to a system for simulating the appropriateness of control costs for appropriate security controls in configuring a ship cybersecurity architecture, calculating control costs according to control policies included in selected security controls, and automatically suggesting optimal security costs by identifying acceptable control risks according to the control costs, thereby enabling the security standards of newly constructed companies, organizations, and ships to be improved. The present invention relates to a method and system for simulating security and costs.

[0034] Referring to FIG. 1, the security control and cost control optimization system according to the present invention may include a user terminal device (10) that is connected to a server equipped with a security control and cost control program and is linked to a cybersecurity database (150) to input requirements necessary for cybersecurity, including security requirements and regulations, a server (100) that can be accessed through the user terminal device (10), provides cybersecurity requirements (Requirements) and a menu, and provides an input window for inputting cybersecurity conditions for a selected menu; and a cybersecurity database (DB, 150) that is linked to the server (100) and stores cybersecurity information necessary for a ship, such as security requirements and regulations.

[0035] The server (100) analyzes security control through a security control and cost control program by linking with a cybersecurity database (150) based on input data including basic ship information and ship (CBS: Computer Based System) condition information input through a user terminal device (10), calculates control costs according to a control policy, and extracts acceptable control risks according to the control costs.

[0036] In addition, the server (100) can provide the extracted results to the user terminal device, and can provide the extracted data to the user terminal device (10) in the form of an axis graph representing the characteristics of multiple items of security control by linking with the cybersecurity database (150), and is characterized in that it is possible to check the filled state of the standard axis graph of each security control item to confirm the items requiring security control and the level of security control.

[0037] At this time, a user terminal device (10) can communicate with a server through the Internet by connecting multiple user terminal devices (11, 12).

[0038] In addition, the user terminal device (10) inputs ship basic information and CBS condition information through the input window (110) of the server (100), and the CBS condition information may include at least one of ship CBS, network, documents, and onboard test information.

[0039] In addition, the server (100) can analyze ship cybersecurity requirements, calculate the cost required to apply security control methods and control technologies and control policies dependent thereon, and extract acceptable control risks according to control costs by simulating data corresponding to input values.

[0040] That is, the security control and cost control optimization system is linked to a cybersecurity database (DB) required for a ship, such as security requirements and regulations, and a server (100) equipped with a security control and cost control program is connected to multiple terminal devices (11, 12) via the Internet to communicate and provide a security control method through analysis of ship cybersecurity requirements, control technology and control policy dependent thereon, and the cost required to apply the same.

[0041] Referring to FIG. 2, a security control and cost control optimization method according to one aspect of the present invention is described. The method includes a server connection step (S100) in which a server, which is linked to a cybersecurity database and is equipped with a security control and cost control program, is connected to and communicates with a plurality of user terminal devices via the Internet, a server connection step (S100) in which the server connects to the server using a user terminal device, an input window provision step (S120) in which the server provides cybersecurity requirements and a menu (S110) and provides an input window in which cybersecurity conditions for a selected menu can be input, an information input step (S130) in which the ship basic information and CBS condition information are input into the input window provided from the server through the input window provision step (S120) using the user terminal device, and the server (100) calculates a control cost according to a control policy through analysis of ship cybersecurity requirements by linking with a cybersecurity database (150) through a security control and cost control program based on the data entered through the information input step (S130), and an extraction step (S140) in which acceptable control risks are extracted according to the control costs, and the extracted control costs through the extraction step (S140) It may include a provision step (S150) of providing the result to a user terminal device.

[0042] That is, a user terminal device (10) is used to connect to a server (100), and the server (100) provides a menu of requirements necessary for cybersecurity to the user terminal device (10), and when the user terminal device (10) selects a menu, the server (100) can provide a corresponding cybersecurity condition input window.

[0043] Next, when the basic information of the ship and the CBS conditions constituting the ship are input into the input window through the user terminal device (10), the server (100) can extract data from the ship cybersecurity database (150) according to the input conditions by the operation of the security control and cost control program and provide information corresponding to the input values ​​to the user terminal device.

[0044] In addition, referring to Figure 3, the process of calculating control costs in the extraction stage can be examined by analyzing cybersecurity requirements to determine whether the risk is acceptable, and if it is acceptable, the process is terminated, and if it is not acceptable, security control can be performed, and the cost of performing security control can be calculated accordingly.

[0045] FIG. 4 is a diagram showing an information input step and an extraction step in a security control and cost control optimization method according to the present invention. In the information input step (S120), requirements necessary for cybersecurity can be input and input information can be confirmed.

[0046] Additionally, you can input CBS condition information including ship CBS, network, document information and onboard test, as well as ship basic information, and check the input information.

[0047] Next, the server (100) analyzes the input information, links it with a cybersecurity database, calculates control costs according to the control policy, extracts acceptable control risks according to the control costs, and provides the extracted results to the user terminal.

[0048] The results may be provided by sending a message or email, and may be provided as an axis graph showing the characteristics of multiple items of security control when provided, and the standard axis graph of each security control item is filled in, so that the items requiring security control and the level of security control can be easily checked at once.

[0049] FIG. 5 is a diagram showing the configuration of a ship cybersecurity database in a security control and cost control optimization system according to the present invention, in which a type table, a notation table, and a cybersecurity requirements table for classification and reference organizations are stored and can be linked.

[0050] Additionally, ship CBS inventory, application system list, and information storage table can be stored and linked.

[0051] Therefore, it can be linked to a server to analyze cybersecurity requirements including the data.

[0052] FIG. 6 is a drawing showing an input window provision step in a security control and cost control optimization method according to the present invention. In FIG. 6(a), an input window may be provided for inputting customer information, in FIG. 6(b), a ship cybersecurity quotation request content may be input, and in FIG. 6(c) to FIG. 6(e), an application system and document may be input.

[0053] FIG. 7 is a diagram showing information input in the information input step in the security control and cost control optimization method according to the present invention, in which basic ship information and requester information are provided, and ship cybersecurity requests and documents, networks, and onboard test data can be input in detail.

[0054] That is, in the information input step (S130), the CBS condition information may include at least one of ship CBS, network, document, and onboard test information.

[0055] In addition, the extraction step (S140) is characterized by analyzing ship cybersecurity requirements, calculating the cost required to apply security control methods, control technologies and control policies dependent thereon, and simulating data corresponding to input values ​​to extract acceptable control risks based on control costs.

[0056] In addition, FIG. 8 is a diagram illustrating a result providing step that provides results extracted from a security control and cost control optimization method according to the present invention.

[0057] That is, it can be provided as an axis graph representing the characteristics of multiple items of security control, and in Fig. 8, the state in which the standard axis graph of each security control item is filled with five characteristics of IDENTIFY, PROTECT, DETECT, RECOVERY, and RESPOND (in the form of the axis graph being filled from the center to the outside) is confirmed, so that the items requiring security control and the level of security control can be easily checked at once.

[0058] Additionally, in the provision step (S150), recommended items for necessary cybersecurity may be provided in various cases.

[0059] By changing the security control level from the aforementioned IDENTIFY, PROTECT, DETECT, RECOVERY and RESPOND, recommended products for each item can be suggested and provided depending on which feature is focused on security control.

[0060] Accordingly, according to the present invention, when configuring a ship cybersecurity architecture, the control cost is calculated according to the control policy included in the selected security control, the acceptable control risk is identified according to the control cost, and the optimal security cost is automatically suggested, thereby improving the security standards of newly constructed companies, organizations, and ships, thereby having the effect of being able to judge through a simulation of security and cost.

[0061] In addition, according to the present invention, it is possible to standardize components for security control, calculate security control costs based on standardized data, and perform simulations for various mitigation measures.

[0062] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0063] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be construed as limiting the present invention thereby. It will be apparent to those skilled in the art that the embodiments of the present invention can be variously modified and altered without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be considered to fall within the scope of the claims of the present invention.

[0064] 10: User terminal device

[0065] 50: Internet

[0066] 100: Server

[0067] 110: Request Input Program

[0068] 120: Security Control Analysis Program

[0069] 150: Cybersecurity Database

Claims

1. A server that is linked to a cybersecurity database and equipped with security control and cost control programs is connected to multiple user terminal devices via the Internet and communicates. Server connection step for connecting to a server using a user terminal device; An input window provision step in which the server provides cybersecurity requirements and menus, and provides an input window in which cybersecurity conditions for the selected menu can be entered; An information input step for entering basic ship information and CBS condition information into an input window provided from a server using a user terminal device through the input window provision step; The server calculates the control cost according to the control policy through analysis of ship cybersecurity requirements by linking with the cybersecurity database through security control and cost control programs based on the data entered through the above information input step, and extracts the acceptable control risk according to the control cost; and A method for optimizing security control and cost control, comprising a result providing step of providing the results extracted through the above extraction step to a user terminal device.

2. In claim 1, A method for optimizing security control and cost control, wherein in the above information input step, the CBS condition information includes at least one of ship CBS, network, document and onboard test information.

3. In claim 1, The above extraction step is, A security control and cost control optimization method characterized by analyzing ship cybersecurity requirements, calculating the cost required to apply security control methods, control technologies and control policies dependent thereon, and simulating data corresponding to input values ​​to extract acceptable control risks according to control costs.

4. In claim 1, The above provision steps are: In conjunction with a cybersecurity database, it can be provided as an axis graph representing the characteristics of multiple items of security controls; A method for optimizing security control and cost control, characterized in that the items requiring security control and the level of security control can be identified by checking the filled state of the reference axis graph of each security control item.

5. A user terminal device that connects to a server that is linked to a cybersecurity database and has security control and cost control programs installed, and inputs requirements necessary for cybersecurity, including security requirements and regulations; A server that can be accessed through the above user terminal device, provides cybersecurity requirements and menus, and provides an input window for entering cybersecurity conditions for a selected menu; and It is linked to the above server and includes a cybersecurity database that stores cybersecurity information required for the ship, such as security requirements and regulations; The above server analyzes security control through a security control and cost control program by linking with a cybersecurity database based on input data including ship basic information and CBS condition information input through the user terminal device, calculates control costs according to the control policy, and extracts acceptable control risks according to the control costs; A security control and cost control optimization system, characterized in that the above server provides the extracted results to a user terminal device.

6. In claim 5, The above user terminal device inputs basic ship information and CBS condition information through the server's input window; The above CBS condition information includes at least one of ship CBS, network, document and onboard test information, a security control and cost control optimization system.

7. In claim 5, The above server, A security control and cost control optimization system characterized by analyzing ship cybersecurity requirements, calculating the cost required to apply security control methods, control technologies and control policies dependent thereon, and simulating data corresponding to input values ​​to extract acceptable control risks according to control costs.

8. In claim 5, The above server, The extracted data can be provided to the user terminal device as an axis graph representing the characteristics of multiple items of security control by linking with the cybersecurity database; A security control and cost control optimization system characterized in that the items requiring security control and the level of security control can be identified by checking the filled-in status of the reference axis graph of each security control item.

Citation Information

Patent Citations

  • Methods for communicating using non-terrestrial network and apparatuses thereof

    KR1020200110619A

  • Information technology risk management system and method the same

    KR100752677B1

  • Cyber security analysis method and apparatus of digital control systems in nuclear power plant

    KR101210027B1

  • Device for analyzing cyber security requirements of digital measurement control system in nuclear power plant and method thereof

    KR101378057B1

  • Method for operating cyber security evaluation managemental system

    KR101740666B1