Causal relationship graph generation device and causal relationship graph generation method

The causal relationship graph generation device addresses the challenge of incomplete causal graphing by specifying related elements and generating a comprehensive graph using system and data flow information, ensuring thorough analysis of incident causes.

WO2025150214A1PCT designated stage expired Publication Date: 2025-07-17HITACHI LTD

Patent Information

Application Number
PCT/JP2024/028172
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-12
Filing Date
2024-08-07
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

Existing methods for generating causal relationship graphs, such as fault or attack trees, are inadequate in ensuring comprehensive coverage of incident causes, leading to a high risk of overlooking critical factors.

Method used

A causal relationship graph generation device that specifies related elements affecting detection parameters and generates a graph based on system information and data flow, using a combination of data flow independent and dependent parts to create a comprehensive graph.

Benefits of technology

Enables the easy creation of a highly comprehensive causal relationship graph, accounting for diverse incident causes and reducing the risk of oversight.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024028172_17072025_PF_FP_ABST
    Figure JP2024028172_17072025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a causal relationship graph generation device with which it is possible to easily create a causal relationship graph with high coverage. On the basis of a detection parameter, which is data used in order to detect an incident occurring in a system, and a data flow indicating the flow of data used in the system, a related element extraction unit 13 identifies a related element, which is an element affecting the detection parameter, among elements on the data flow. A graph generation unit 14 identifies a related event, which is an event causing an incident, on the basis of system information and the related element identified by the related element extraction unit 13, and generates a causal relationship graph on the basis of the related event.
Need to check novelty before this filing date? Find Prior Art

Description

Causal relationship graph generating device and causal relationship graph generating method

[0001] The present disclosure relates to a causal relationship graph generation device and a causal relationship graph generation method.

[0002] A known method for describing the causes of incidents, such as failures and attacks, that occur in systems such as computer systems is to decompose events using a tree-structured graph called a fault tree or attack tree. This type of tree-structured causal graph is useful for analyzing the causes of incidents. However, because the causes of incidents that occur in systems are diverse, manually creating a causal graph requires a lot of effort.

[0003] In response to this, Patent Document 1 discloses a technology for generating an attack tree corresponding to a system by decomposing the system, selecting one or more subsystems that are located on the intrusion path of a threat to a root system, which is one of multiple subsystems, and combining sub-attack trees corresponding to each of the selected subsystems.

[0004] International Publication No. 2020 / 137847

[0005] It is desirable to comprehensively describe the causes of incidents in a causal relationship graph, but with the technology described in Patent Document 1, the comprehensiveness of causes in an attack tree depends on the method of constructing the sub-attack tree, and depending on the construction method, sufficient comprehensiveness cannot be ensured, which increases the risk of overlooking the causes of incidents.

[0006] An object of the present disclosure is to provide a causal relationship graph generation device and a causal relationship graph generation method that are capable of easily creating a highly comprehensive causal relationship graph.

[0007] A causal graph generation device according to one aspect of the present disclosure is a causal graph generation device that generates a causal graph describing related events, which are events that cause an incident that occurs in a system, and includes: an identification unit that identifies related elements, which are elements that affect the detection parameters among elements on the data flow based on detection parameters, which are data used to detect the occurrence of the incident, and a data flow that indicates the flow of data used in the system; and a graph generation unit that identifies the related events based on the related elements and system information that indicates the configuration of the system, and generates the causal graph based on the related events.

[0008] According to the present invention, it is possible to easily create a highly comprehensive causal relationship graph.

[0009] 1 is a diagram illustrating a functional configuration of a causal relationship graph generation device according to an embodiment of the present disclosure; FIG. 2 is a diagram illustrating an example of an incident list; FIG. 3 is a diagram illustrating an example of a data flow list; FIG. 4 is a diagram illustrating an example of system information; FIG. 5 is a diagram illustrating an example of a decomposition template DB; FIG. 6 is a diagram illustrating an example of a data flow related event template DB; FIG. 7 is a diagram illustrating an example of an input screen; FIG. 8 is a flowchart illustrating an example of an operation of the causal relationship graph generation device; FIG. 9 is a sequence chart illustrating an example of an operation of the causal relationship graph generation device; FIG. 10 is a diagram illustrating an example of a process for generating a data flow independent portion; FIG. 11 is a diagram illustrating an example of a process for acquiring a list of related elements; FIG. 12 is a diagram illustrating an example of a process for generating a node; FIG. 13 is a diagram illustrating an example of a process for adding a node to a data flow independent portion;

[0010] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings.

[0011] FIG. 1 is a diagram illustrating the functional configuration of a causal graph generation device according to an embodiment of the present disclosure. The causal graph generation device 1 illustrated in FIG. 1 is a device for generating a causal graph that describes related events, which are events that cause incidents such as failures and attacks that occur in a system such as a computer system. The causal graph generation device 1 is realized, for example, by an information processing device including a processor (computer) and memory (neither of which is shown). In this case, the components and functions of the causal graph generation device 1 described below are realized, for example, by the processor reading a computer program and executing the read computer program.

[0012] The causal relationship graph generation device 1 has, as functional components, an input / output unit 10, a storage unit 11, a data flow independent part generation unit 12, a related element extraction unit 13, and a graph generation unit 14.

[0013] The input / output unit 10 accepts various information for generating a causal relationship graph from a user who uses the causal relationship graph generation device 1 or an external device such as a terminal device used by the user, and also outputs (e.g., displays) the causal relationship graph and various information for generating the causal relationship graph.

[0014] In this embodiment, the input / output unit 10 receives, as input data, an incident list that indicates, for each incident, detection parameters that the system uses to detect incidents that are the subject of the causal relationship graph, a data flow list that is a list of data flows that indicate the flow of data used in the system, and system information that indicates the system configuration. The input / output unit 10 also displays an input screen for the user to enter input data and a causal relationship graph.

[0015] The storage unit 11 stores various information for generating a causal relationship graph. In this embodiment, the storage unit 11 stores a decomposition template database (DB) 111 and a data flow-related event template DB 112. The decomposition template DB 111 indicates decomposition templates that are templates for data flow-independent portions of the causal relationship graph that are not dependent on the data flow of the detection parameters. The data flow-related event template DB 112 indicates event templates that are templates for data flow-dependent portions of the causal relationship graph that are dependent on the data flow of the detection parameters.

[0016] The data flow independent part generation unit 12 is an independent part generation unit that generates a data flow independent part, which is an independent part that does not depend on data flow in the causal relationship graph, based on the incident list received by the input / output unit 10 and the decomposition template DB 111 stored in the memory unit 11.

[0017] The related element extraction unit 13 is an identification unit that identifies related elements, which are elements that affect the detection parameters, among the elements on the data flow, based on the detection parameters included in the incident list received by the input / output unit 10 and the data flow list received by the input / output unit 10. In this embodiment, the elements on the data flow include system functions and data used in the system.

[0018] The graph generation unit 14 generates a dependent portion that depends on a data flow in the causal relationship graph, based on the related elements identified by the related element extraction unit 13, the system information received by the input / output unit 10, and the data flow related event template DB 112 stored in the storage unit 11. The graph generation unit 14 then generates a causal relationship graph based on the dependent portion of the generated causal graph and the data flow independent portion of the causal relationship graph generated by the data flow independent portion generation unit 12.

[0019] 2 to 4 are diagrams showing examples of input data received by the input / output unit 10. FIG.

[0020] Specifically, an example of an incident list is shown in Fig. 2. The incident list 200 shown in Fig. 2 includes fields 201 to 203.

[0021] Field 201 stores an incident name, which is the name of the incident, as identification information for identifying the incident. Field 202 stores an incident type, which indicates the type of incident. The incident type may further indicate whether a single or multiple detection parameters are used to detect the incident. For example, the incident type indicates "single type (functional safety, etc.)" when there is a single detection parameter, and indicates "comparison type" when there are multiple detection parameters. Note that when there are multiple detection parameters, for example, an incident is detected by comparing these detection parameters. Furthermore, field 203 is provided for each detection parameter used to detect the incident.

[0022] 3 is a diagram showing an example of a data flow list. The data flow list 300 shown in FIG.

[0023] Field 301 stores a flow source type, which is the type of element at the source of the data flow. Element types include system functions and data used in the system. Field 302 stores a flow source element name, which is the name of the element at the source of the data flow, as identification information for identifying the element at the source of the data. Field 303 stores a flow source component name, which is the name of the component at the system corresponding to the element at the source of the data, as identification information for identifying the component at the system. A component is specifically a device that makes up the system. If the element type is a function, the component corresponding to the element is the component that has that function, and if the element type is data, the component that generates that data.

[0024] Field 304 stores a destination type, which is the type of the destination element of the data flow. Field 305 stores a destination element name, which is the name of the destination element as identification information for identifying the destination element. Field 306 stores a destination component name, which is the name of the component corresponding to the destination element.

[0025] In the example of FIG. 3, the data flow list 300 omits data other than data that may be detection parameters in the data flow, but this data does not have to be omitted.

[0026] 4 is a diagram showing an example of system information. System information 400 shown in FIG.

[0027] Field 401 stores the component name, which is the name of the component. Field 402 stores the layer name as identification information that identifies a layer on a system realized by the component. Note that one component may realize multiple layers. Layers indicate, for example, hardware (HW), operating system (OS), functions, and data. Field 403 stores the element name of a data flow element (function or data) in the layer. Fields 404 to 406 store properties that indicate the characteristics of the layer. Examples of properties include command acceptance possibility, which indicates whether commands can be accepted, GUI operability, which indicates whether operations can be performed from a GUI (Graphical User Interface), and update possibility, which indicates whether updates are possible. In the example of FIG. 4 , field 404 stores command acceptance possibility, field 405 stores GUI operability, and field 406 stores update possibility. These properties indicate "1" if acceptance is possible and "0" if not. Note that the properties shown in FIG. 4 are merely examples and are not limited to these.

[0028] 5 and 6 are diagrams showing an example of the registration data stored in the storage unit 11. FIG.

[0029] 5 is a diagram showing an example of the decomposition template DB 111. The decomposition template DB 111 shown in FIG.

[0030] Field 501 stores the incident type of the incident. As will be described later, the incident type in field 501 is used to link the incident to the incident that is the target of the causal relationship graph shown in the incident list. Field 502 stores the graph type, which is the type of causal relationship graph for the incident of the incident type in field 501. In this embodiment, the graph type indicates a fault (fault tree) or an attack (attack tree), but is not limited to this example. For example, the graph type may indicate an operation error or the like.

[0031] Fields 503 to 505 store decomposition templates, which are templates for the data flow independent portion of the causality graph. Fields 503 to 505 are provided for each node in the data flow independent portion of the causality graph, and are arranged from the left of the same record in order from the highest node to the lowest node.

[0032] Field 503 stores logic gate information indicating the logic gate that defines the connection relationship between the target node and its next higher node. When there are multiple lower nodes connected to the next higher node, the logic gate information indicates OR (logical sum) or AND (logical multiplication) as the logic gate connecting those nodes. When there is only one lower node, the logic gate information indicates "none" (-). Field 504 stores a node template, which is a template for the target node. The node template includes an event corresponding to the node and an insertion section for inserting detection parameters used to detect the event corresponding to the node. The event corresponding to the node indicates, for example, "parameter abnormality caused by attack" or "attempt to circumvent functional safety." In addition, in the example of FIG. 5 , the insertion section is indicated by [detection parameter 1] and [detection parameter 2]. Field 505 stores deployment necessity information indicating whether the target node is to be deployed based on the data flow. In the example shown in the figure, the deployment necessity information indicates "Yes" if the target node is to be deployed based on the data flow, and indicates "No" if the target node is not to be deployed based on the data flow. In this embodiment, the node to be expanded based on the data flow is the lowest node in the data flow independent part, and if a node in the data flow independent part exists below the target node, the expansion necessity information indicates "-".

[0033] 6 is a diagram showing an example of the data flow related event template DB 112. The data flow related event template DB 112 shown in FIG.

[0034] Field 601 stores an ID as identification information for identifying an event template, which is a template related to a node corresponding to an event that occurs in relation to each element of a data flow. Field 602 stores the graph type of the causal graph corresponding to the event template. Field 603 stores the event template. The event template has an event that includes an insertion section for inserting components, functions, etc. related to the event. Field 604 stores the layer name of the layer in which the event of the event template occurs. Field 605 stores the occurrence condition for the event of the event template. In this embodiment, the occurrence condition indicates the property of the layer in which the event of the event template occurs.

[0035] Fig. 7 is a diagram showing an example of an input screen for a user to input input data. The input screen 700 shown in Fig. 7 includes input fields 701 to 703 for inputting an incident list, a data flow list, and system information, respectively, a confirm button 704, and a cancel button 705. The confirm button 704 is a button for confirming the data input in the input fields 701 to 703, and the cancel button 705 is a button for canceling the data input in the input fields 701 to 703.

[0036] 7 is merely an example, and is not limited to this example. For example, the input screen may have a UI (User Interface) that allows a data flow to be created in a graph format.

[0037] FIG. 8 is a flowchart illustrating an example of the operation of the causal relationship graph generation device 1, and FIG. 9 is a sequence chart illustrating an example of the operation of the causal relationship graph generation device 1.

[0038] 8 and 9, the input / output unit 10 of the causal relationship graph generation device 1 acquires input data, namely, an incident list, a data flow list, and system information, inputted by a user. The input / output unit 10 outputs the incident list to the data flow independent part generation unit 12, outputs the data flow list to the related element extraction unit 13, and outputs the system information to the graph generation unit 14 (step S101).

[0039] For each incident name included in the incident list from the input / output unit 10, the data flow independent part generation unit 12 obtains a decomposition template corresponding to the target incident, which is the incident with that incident name (step S102). Specifically, the data flow independent part generation unit 12 obtains a decomposition template corresponding to the incident type of the target incident from the decomposition template DB 111. In the following, it is assumed that there is only one target incident. Note that if there are multiple target incidents, the following processing is performed for each target incident.

[0040] The data flow independent part generation unit 12 generates a data flow independent part of the causal relationship graph of the target incident based on the acquired decomposition template, and outputs the data flow independent part to the related element extraction unit 13 (step S103).

[0041] 10 is a diagram illustrating an example of a process for generating a data flow independent portion. As shown in FIG. 10, the data flow independent portion generator 12 sets the node indicating the target incident as the top node, and generates each node 1001 by substituting the values ​​of the detection parameters in the incident list into the insertion section of each node template in field 504 according to the acquired decomposition template. The data flow independent portion generator 12 then generates a data flow independent portion 1000 of the causality graph by connecting each node 1001 with a logic gate indicated by the logic gate information in field 503. Note that in FIG. 10, among the nodes 1001, nodes to be expanded based on the data flow, that is, nodes to be expanded 1002, are shaded.

[0042] Returning to the explanation of the operation, the related element extraction unit 13 and the graph generation unit 14 start a loop process A in which they repeat the processes of steps S105 to S110 for each node to be expanded (step S104).

[0043] In loop processing A, first, the related element extraction unit 13 refers to the data flow list and acquires a list of related elements, which are elements in the data flow that affect the detection parameters included in the node to be expanded, among the elements in the data flow. The related element extraction unit 13 outputs the data flow independent part of the causal relationship graph and the list of related elements to the graph generation unit 14 (step S105).

[0044] FIG. 11 is a diagram illustrating an example of a process for acquiring a list of related elements. As shown in FIG. 11 , the related element extraction unit 13 identifies data that corresponds to the detection parameter "engine stop command issuance history" included in the node to be expanded from the data flow list. The related element extraction unit 13 then identifies all elements lower than the top-level element as related elements by tracing back from the top-level element to the flow source element, and acquires a list 1100 of these related elements. Note that in the example of FIG. 11 , "engine stop command issuance history" is used as the detection parameter, but the related element list 1100 can also be acquired in a similar manner for other detection parameters (e.g., "vehicle speed").

[0045] Returning to the explanation of the operation, the graph generating unit 14 starts a loop process B in which the processes of steps S107 to S109 are repeated for each related element included in the list of related elements (step S106).

[0046] In loop process B, first, the graph generator 14 references the data flow related event template and the system information to obtain an event template related to an event that affects the related element of interest (step S107). The graph generator 14 adds information related to the related element (components, functions, etc.) to the insertion section of the obtained event template according to the insertion section, and generates a node corresponding to the related element in the data flow dependency part of the causal relationship graph (step S108).

[0047] 12 is a diagram illustrating an example of a process for generating a node. As shown in FIG. 12, the graph generation unit 14 first uses system information to identify layers related to the target related element "communication relay function." The layers related to the target related element are layers realized by the components corresponding to the related element. If the related element is a "function," the layers will be "function," "OS," and "HW," and if the related element is "data," the layers will be "data," "OS," and "HW."

[0048] Next, the graph generation unit 14 acquires an event template whose layer properties (command acceptance possibility, GUI operability, and update possibility) match the occurrence condition from among the layers related to the target related element "communication relay function" from the data flow related event template DB 112. The graph generation unit 14 adds information related to the related element (components, functions, etc.) to the insertion part of the acquired event template in accordance with the insertion part, and generates a node 1201 corresponding to the related element in the data flow dependency part of the causal relationship graph.

[0049] Returning to the explanation of the operation, the graph generation unit 14 adds the generated node to the data flow independent part of the causal relationship graph (step S109).

[0050] 13 is a diagram illustrating an example of a process for adding a node to a dataflow-independent portion. As shown in FIG. 13 , the graph generation unit 14 generates a causal relationship graph 1300 by connecting a node 1201 in a dataflow-dependent portion generated from detection parameters included in a node 1002 to be expanded in a dataflow-independent portion 1000 of the causal relationship graph. In the example of FIG. 13 , the logic gate connecting the nodes is an OR (logical sum), but this is not limiting. For example, the logic gate connecting the nodes may be an AND (logical product), or a combination of OR (logical sum) and AND (logical product).

[0051] Then, when the graph generation unit 14 has executed the processes of steps S107 to S109 for all related elements, it ends loop process B (step S110). Then, when the processes of steps S105 to S110 have been executed for all target nodes, it ends loop process A. In this way, a causal relationship graph is generated.

[0052] Then, the input / output unit 10 outputs the generated causal relationship graph (step S112), and the process ends.

[0053] In the process described above, a node of a dependent part of a data flow is added below a node of an independent part of a data flow in the causal relationship graph, but the causal relationship graph is not limited to this example and may be a graph in which dependent and independent parts of a data flow are mixed. For example, a node of an independent part of a data flow may be connected below a node of a dependent part of a data flow.

[0054] As described above, according to this embodiment, the related element extraction unit 13 identifies related elements in the data flow that affect the detection parameters, based on detection parameters, which are data used to detect incidents occurring in the system, and a data flow that indicates the flow of data used in the system. The graph generation unit 14 identifies related events, which are events that cause the incident, based on the related elements identified by the related element extraction unit 13 and system information, and generates a causal relationship graph based on the related events. Therefore, it is possible to generate a causal relationship graph based on the detection parameters and the data flow, making it possible to easily create a highly comprehensive causal relationship graph.

[0055] In this embodiment, the graph generator 14 further identifies, as related events, events that occur in related elements and that match the occurrence conditions based on event template information that indicates event templates for events that occur in relation to each element for each occurrence condition under which the event occurs. This makes it easier to create a causal relationship graph.

[0056] In this embodiment, the graph generator 14 identifies related events by inserting information related to the related elements into an event template that matches the occurrence condition, which makes it easier to create a causal relationship graph.

[0057] In this embodiment, the related element extraction unit 13 identifies related elements for each type of causal relationship graph. The graph generation unit 14 generates a causal relationship graph for each type of causal relationship graph. This makes it possible to easily create various types of causal relationship graphs.

[0058] In this embodiment, the data flow independent portion generator 12 generates an independent portion of the causality graph that is independent of the data flow used in the system, based on the detection parameters and the type of incident. The graph generator 14 generates the causality graph based on the related elements and the independent portion. This makes it possible to easily generate a causality graph that takes into account events that are independent of data flow.

[0059] In this embodiment, the data flow independent portion generator 12 generates the data flow independent portion by inserting detection parameters into a decomposition template corresponding to the type of incident for which a causal relationship graph is to be generated, based on decomposition template information that indicates, for each type of incident, a decomposition template related to related events included in the independent portion. In this case, it is possible to easily create the data flow independent portion of the causal relationship graph.

[0060] In this embodiment, the elements of the data flow include the functions of the system and the data used in the system, which makes it possible to generate a more comprehensive causal relationship graph.

[0061] The above-described embodiments of the present disclosure are merely illustrative examples of the present disclosure, and are not intended to limit the scope of the present disclosure to these embodiments alone. Those skilled in the art may implement the present disclosure in various other forms without departing from the scope of the present disclosure.

[0062] 1: Causal graph generation device 10: Input / output unit 11: Storage unit 12: Data flow independent part generation unit 13: Related element extraction unit 14: Related event extraction unit

Claims

1. A causal relationship graph generation device that generates a causal relationship graph describing related events that are the causes of incidents occurring in a system, the device comprising: a detection parameter that is data used to detect the occurrence of the incident; and a specific part that specifies, based on a data flow showing the flow of data used in the system, related elements among the elements on the data flow that affect the detection parameter; and a graph generation part that specifies the related events based on the related elements and system information indicating the configuration of the system, and generates the causal relationship graph based on the related events.

2. The causal relationship graph generation device according to claim 1, wherein the graph generation part specifies, as the related events, events that match the occurrence conditions among the events occurring in relation to the related elements, further based on event template information showing event templates regarding events occurring in relation to each element for each occurrence condition in which the event occurs.

3. The causal relationship graph generation device according to claim 2, wherein the graph generation part inserts information related to the related element into the event template that matches the occurrence condition to specify the related events.

4. The causal relationship graph generation device according to claim 1, wherein the specific part specifies the related elements for each type of the causal relationship graph, and the graph generation part generates the causal relationship graph for each type.

5. The causal relationship graph generation device according to claim 1, further comprising a non-dependent part generation part that generates a non-dependent part that is a part independent of the data flow used in the system in the causal relationship graph, based on the detection parameter and the type of the incident, and the graph generation part generates the causal relationship graph based on the related elements and the non-dependent part.

6. The causal relationship graph generation device according to claim 5, wherein the non-dependent part generation part inserts the detection parameter into the decomposition template corresponding to the type of the incident that is the generation target of the causal relationship graph, based on decomposition template information showing decomposition templates regarding the related events included in the non-dependent part for each type of the incident, to generate the non-dependent part.

7. The causal relationship graph generation device according to claim 1, wherein the element includes a function of the system and data used in the system.

8. A causal relationship graph generation method by a causal relationship graph generation device that generates a causal relationship graph describing related events that are events causing an incident occurring in a system, the method comprising: identifying, based on a detection parameter that is data used for detecting the occurrence of the incident and a data flow indicating a data flow of data used in the system, a related element that is an element affecting the detection parameter among elements on the data flow; identifying the related event based on the related element and system information indicating a configuration of the system; and generating the causal relationship graph based on the related event.

Citation Information

Patent Citations

  • Rail transit vehicle equipment universal detection and fault diagnosis method and system

    CN102879680A

  • Reliability evaluation system, reliability evaluation method and reliability evaluation program of information system

    JP2007122639A

  • Software development support system

    JP2009026143A

Cited By

  • Abnormal event detection method and electronic device

    CN122674038A

  • Cause isolation system and cause isolation method

    WO2026126569A1