Asset model generating device, security evaluation system, and asset model generation method

The asset model generation device and method automatically generate accurate models by simulating cyberattacks and comparing candidate models with past evaluations, addressing manual errors and ensuring timely, valid security measures for OT systems.

WO2025182420A1PCT designated stage Publication Date: 2025-09-04HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/002909
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-01
Filing Date
2025-01-30
Publication Date
2025-09-04

AI Technical Summary

Technical Problem

Existing asset model generation methods are prone to errors and inaccuracies, especially when manually created, and struggle to automatically handle diverse input data formats, structures, and abstraction levels, leading to potential system vulnerabilities and delayed security measures.

Method used

An asset model generation device and method that automatically collects input data, generates multiple candidate models, evaluates their security, and compares them with past evaluations to select a highly accurate model, using a security evaluation system that includes a digital twin to simulate cyberattacks and assess business continuity.

Benefits of technology

Enables the generation of highly accurate asset models that reduce manual errors, ensure model validity, and facilitate timely security measures by automatically selecting models that align with past evaluations and business goals, thereby enhancing system security and response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025002909_04092025_PF_FP_ABST
    Figure JP2025002909_04092025_PF_FP_ABST
Patent Text Reader

Abstract

An asset model generating device 100 comprises: an input data collecting unit 110 that collects input data including information relating to equipment constituting a system and information relating to connectivity between the equipment; a candidate asset model generating unit 120 that generates a plurality of candidate asset models as candidates for an asset model, which is a model of the equipment, on the basis of the collected input data; a security evaluating unit 150 that evaluates security for the plurality of candidate asset models; and a security evaluation comparing unit 160 that compares the evaluations for the plurality of candidate asset models with past evaluations and selects an asset model from among the plurality of candidate asset models. One objective of the present invention is to provide an asset model generating device and an asset model generation method capable of automatically generating a highly accurate asset model. Another objective of the present invention is to provide a security evaluation system capable of improving the accuracy of security evaluation of a system.
Need to check novelty before this filing date? Find Prior Art

Description

Asset model generation device, security evaluation system, and asset model generation method

[0001] The present invention relates to an asset model generation device, a security evaluation system, and an asset model generation method, and more particularly to an asset model generation device and the like that can generate an asset model suitable for evaluating the security of an OT (Operational Technology) system.

[0002] The threat of cyberattacks against OT systems has been rapidly increasing. Even when vulnerabilities are discovered in OT systems, patch and firmware updates must undergo extensive testing before their applicability can be determined. This slows down the development of security countermeasures. Meanwhile, efforts are underway to develop security digital twins (SDTs) as a technology for replicating cyberattacks and countermeasure applications on digital twins. SDTs recreate attacks on SDTs and predict their impact, as well as the effectiveness and side effects of countermeasures when applied. This enables the planning and application of countermeasures that ensure business continuity (business continuity) while meeting predefined standards for critical system operations. SDTs generate digital twins using three-layer models (actors, assets, and processes). By interconnecting these three-layer models, it becomes possible to represent the time-series state transitions of the entire OT system from multiple business perspectives. The asset model is generated using information about the information and control devices operating on the system and their connectivity.

[0003] Patent Literature 1 describes that a network asset information management system may include an asset determination and event prioritization module for generating real-time asset information based on network activity involving assets. A rule module may include a set of rules for monitoring network activity involving assets. An information analysis module may evaluate the real-time asset information and the rules to generate notifications regarding the assets. The rules may include rules for determining vulnerabilities and risks associated with the assets based on a comparison between a level of traffic identified between IP addresses associated with the assets and a predetermined threshold. The notification may include a level of risk associated with the asset.

[0004] Patent Literature 2 describes a system for providing network services, in which the system receives an inventory of network assets and a range of available network services. For at least a subset of assets, an importance-related ranking attribute and a scannability-related ranking attribute are selected from the available service characteristics of the assets. The importance of the assets is determined based on the importance-related ranking attribute. The system determines the scannability of the assets based on the ranking attribute related to scannability or the range of available network services. The priority of the assets is determined based on the importance and scannability of the assets. A prioritized asset inventory is determined based on the priority of the assets.

[0005] US Patent Application Publication No. 2014 / 0075564 US Patent Application Publication No. 2022 / 0158944

[0006] In conventional asset model generation, experts typically manually generate asset models using information such as system design documents and system configuration diagrams. While asset model generation by experts is highly accurate, it requires a lot of work and does not automatically detect errors in manual model generation. On the other hand, when asset models are automatically generated, the input data used for asset model generation includes various formats, structures, and levels of abstraction, making it difficult to determine which of multiple records refer to the same thing. As a result, there is a risk that the asset model generated may contain matching errors, making it difficult to confirm and ensure the validity of the model. The present invention aims to provide an asset model generation device and asset model generation method that can automatically generate highly accurate asset models. Another aim of the present invention is to provide a security evaluation system that can improve the accuracy of system security evaluations.

[0007] In order to solve the above problems, the present invention provides an asset model generation device that includes an input data collection unit that collects input data including information about devices that make up a system and information about connectivity between the devices, a candidate asset model generation unit that generates a plurality of candidate asset models as candidates for asset models that are models of devices based on the collected input data, a security evaluation unit that evaluates the security of the plurality of candidate asset models, and a security evaluation comparison unit that compares the evaluation of the plurality of candidate asset models with past evaluations and selects an asset model from the plurality of candidate asset models.In this case, it is possible to provide an asset model generation device that can automatically generate highly accurate asset models.

[0008] Here, for example, the security evaluation unit evaluates security based on the results of an attack on a device using a predetermined attack path. In this case, by using already known attack paths, security evaluation can be performed under conditions that more closely match the risks that may actually occur. Furthermore, for example, the security evaluation unit evaluates the security of software running on each device when an attack is performed on the device for each attack path. In this case, highly accurate security evaluation can be performed for each device. Furthermore, for example, the security evaluation comparison unit obtains a security evaluation result for each attack path based on the security evaluation of the software. In this case, the security evaluation result can be obtained for each attack path. Furthermore, for example, the security evaluation comparison unit compiles the security evaluation results for each attack path and evaluates the security of each candidate asset model. In this case, the security evaluation result can be obtained for each candidate asset model. Then, for example, the security evaluation comparison unit compares the difference between the evaluation of each candidate asset model and a previous evaluation. In this case, the accuracy of the candidate asset model can be easily evaluated. Furthermore, for example, the security evaluation comparison unit selects an asset model with a small difference from among the candidate asset models. In this case, a candidate asset model with higher accuracy can be selected as the asset model. Furthermore, for example, the security evaluation comparison unit determines the accuracy of the generated candidate asset model by comparing evaluations of multiple candidate asset models with past evaluations. In this case, the validity of the generated candidate asset model can be determined. Furthermore, for example, the system is an OT (Operational Technology) system. In this case, security measures can be taken for the OT system.

[0009] The present invention also provides a security evaluation system that evaluates the impact of security measures on business continuity using a digital twin that uses an asset model generated by the above asset model generation device, an actor model that represents human behavior in a system, and a process model that represents critical operations of the system. In this case, a security evaluation system that can improve the accuracy of system security evaluation can be provided.

[0010] Furthermore, the present invention provides an asset model generation method in which a processor executes a program recorded in a memory to collect input data including information about devices that constitute a system and information about connectivity between the devices, generates a plurality of candidate asset models as candidates for asset models that are models of the devices based on the collected input data, evaluates the security of the plurality of candidate asset models, compares the evaluation of the plurality of candidate asset models with past evaluations, and selects an asset model from the plurality of candidate asset models.In this case, it is possible to provide an asset model generation method that can automatically generate highly accurate asset models.

[0011] An object of the present invention is to provide an asset model generation device and an asset model generation method that can automatically generate highly accurate asset models, and a security evaluation system that can improve the accuracy of system security evaluations.

[0012] 11 is a conceptual diagram showing the overall configuration and an example of operation of a security evaluation system according to the present embodiment. FIG. 12 is a block diagram showing the functional configuration of an asset model generation device that generates an asset model. FIG. 13 is a diagram showing a case where the configuration of a network (NW configuration) used in an OT system is used as input data 1. FIG. 14 is a diagram showing a case where communication information of a network (NW communication information) used in the OT system is used as input data 2. FIG. 15 is a diagram showing a case where asset management information of a device used in the OT system is used as input data 3. FIG. 16 is a diagram showing one of multiple candidate asset models generated by a candidate asset model generation unit. FIG. 17 is a diagram showing security evaluation results for software running on each device when attacked by the attack path shown in FIG. 8. FIG. 18 is a diagram showing an analysis result of an attack path for candidate asset model #1. FIG. 19 is a diagram showing a primary summary result of security evaluation results. FIG. 19 is a diagram showing a secondary summary result of security evaluation results. FIG. 19 is a diagram showing past security evaluation results used to compare security evaluation results. FIG. 20 is a diagram showing a comparison result between FIG. 25 and FIG. 26. FIG. 27 is a diagram showing another example of a candidate asset model generated by a candidate asset model generation unit. 19 is a diagram showing security evaluation results for software running on each device when attacked by the attack path shown in FIG. 15. FIG. 19 is a diagram showing the analysis results of the attack path for candidate asset model #2. FIG. 20 is a diagram showing the first summary result of the security evaluation results. FIG. 21 is a diagram showing the second summary result of the security evaluation results. FIG. 22 is a diagram showing the comparison results between the evaluation for candidate asset model #2 and past evaluations. FIG. 23 is a diagram showing thresholds. FIG. 24 is a diagram showing the comparison results between candidate asset model #1 and candidate asset model #2 and the thresholds listed in FIG. 19. FIG. 25 is a flowchart explaining the overall operation of the asset model generation device. FIG. 26 is a flowchart explaining the operation when the candidate asset model generation unit creates multiple candidate asset models. FIG. 27 is a flowchart explaining the operation when the security evaluation unit performs security evaluation using a selected candidate asset model.1 is a flowchart illustrating the operation of the security evaluation comparison unit when comparing security evaluation results. FIG. 1 is a flowchart illustrating the operation of the security evaluation comparison unit when obtaining a first summary result of the security evaluation results. FIG. 2 is a flowchart illustrating the operation of the security evaluation comparison unit when obtaining a second summary result of the security evaluation results. FIG. 3 is a flowchart illustrating the operation of the security evaluation comparison unit when obtaining a comparison table of the second summary result of the security evaluation results. FIG. 4 is a flowchart illustrating the operation of the security evaluation comparison unit when adding the comparison result of the security evaluation results to a selected candidate asset model list. FIG. 5 is a flowchart illustrating the operation of the security evaluation comparison unit when selecting an asset model from the candidate asset model list that has an appropriate comparison result of the security evaluation results. FIG. 6 is a flowchart illustrating the operation of the security evaluation comparison unit when verifying the accuracy of a candidate asset model created by the candidate asset model generation unit. FIG. 7 is a flowchart illustrating the processing of displaying error detection results. FIG. 8 is a diagram illustrating the display contents of error detection results. FIG. 9 is a diagram illustrating an example of the hardware configuration of the asset model generation device in this embodiment.

[0013] Hereinafter, an embodiment of the present invention will be described in detail with reference to the accompanying drawings. <Overall Description of Security Evaluation System 1> FIG. 1 is a conceptual diagram showing the overall configuration and an example of operation of a security evaluation system 1 according to this embodiment. The security evaluation system 1 of this embodiment evaluates the security of an OT system. More specifically, when implementing security measures for an OT system, it identifies high-risk vulnerabilities using a digital twin. Then, it formulates multiple effective security measures and evaluates the impact of each measure on business continuity. As a result, it is possible to appropriately design security measures based on the evaluation results so as to be consistent with business goals.

[0014] To perform such processing, the security assessment system 1 reproduces the OT system as a digital twin using a three-layer model of actors, assets, and processes. Of these, the actor model is a model that represents the behavior of people with respect to the OT system. Specifically, the actor model represents the behavior of workers who perform their daily tasks. The actor model also represents the behavior of attackers who launch cyberattacks against the OT system. Furthermore, the actor model represents the behavior of security personnel who implement countermeasures against cyberattacks.

[0015] An asset model is a model of the devices that make up an OT system. Specifically, the asset model is a model of the computer devices that run on the OT system, and represents software vulnerabilities, network dependencies, etc. The asset model used here is generated by the asset model generation device 100, which will be described later.

[0016] The process model is a model that represents a critical operation of an OT system. Specifically, the process model represents the impact on computer devices running on the OT system when the OT model is subjected to a cyber-attack from an attacker.

[0017] A state transition program linking these three-layer models reproduces the behavior of each model in chronological order. As an example of how this program works, an attacker is made to attack the asset model in cyberspace, and high-risk vulnerabilities are identified. Then, the program has the countermeasure provider apply security measures to mitigate the risk of the attack. Meanwhile, the degree to which business performance declines as a result of implementing the measures is analyzed.

[0018] 2 is a block diagram showing the functional configuration of the asset model generation device 100 that generates asset models. The illustrated asset model generation device 100 includes an input data collection unit 110, a candidate asset model generation unit 120, a candidate asset model DB (database) 130, a candidate asset model selection unit 140, a security evaluation unit 150, a security evaluation comparison unit 160, and a past security evaluation DB 170.

[0019] The input data collection unit 110 collects input data including information about devices that constitute the OT system and information about connectivity between devices. The candidate asset model generation unit 120 generates multiple candidate asset models as candidates for asset models, which are device models, based on the input data collected by the input data collection unit 110. The candidate asset model DB 130 stores the multiple candidate asset models generated by the candidate asset model generation unit 120. The candidate asset model selection unit 140 selects one of the multiple candidate asset models generated by the candidate asset model generation unit 120. The security evaluation unit 150 evaluates the security of the multiple candidate asset models generated by the candidate asset model generation unit 120. The security evaluation comparison unit 160 compares the evaluation of the multiple candidate asset models generated by the candidate asset model generation unit 120 with past evaluations, and selects an asset model from the multiple candidate asset models. The past security evaluation DB 170 stores past security evaluations used by the security evaluation comparison unit 160.

[0020] Each of these functional units will be described in detail below. <Explanation of Input Data> Figures 3 to 5 are diagrams showing the input data collected by the input data collection unit 110. Of these, Figure 3 is a diagram showing the case where the configuration of the network (NW configuration) used in the OT system is input data 1. Note that the NW configuration here also includes FW (Firewall) settings. In Figure 3, the name, IP address, and NW segment of each device connected to the network used in the OT system are associated and described.

[0021] 4 is a diagram showing a case where communication information (NW communication information) of a network used in an OT system is used as input data 2. This information is obtained, for example, as statistical information on the traffic volume of a router. In FIG. 4, the communication percentage, the IP address of the source host, the IP address of the destination host, and the protocol used are associated and described.

[0022] Fig. 5 is a diagram showing a case where asset management information of devices used in an OT system is input data 3. In Fig. 5, the asset model name of each device connected to a network used in the OT system, the name of the software running on each device, and the version of the software are associated and described.

[0023] The input data in Figures 3 to 5 can also be said to be data viewed from different perspectives of the same OT system. For example, Figure 3 is data viewed from the perspective of the devices that make up the OT system. Figure 4 can also be said to be data viewed from the perspective of information on connectivity between the devices that make up the OT system. Furthermore, Figure 5 can also be said to be data viewed from the perspective of software running on the devices that make up the OT system.

[0024] <Explanation of Candidate Asset Model> FIG. 6 is a diagram showing one of the multiple candidate asset models generated by the candidate asset model generation unit 120. Here, this candidate asset model will be referred to as candidate asset model #1. Candidate asset model #1 is generated based on the input data shown in FIGS. 3 to 5. In other words, it can be said that the candidate asset model is a single asset model in which a wide variety of input data is merged. The upper section of FIG. 6 lists the asset names shown in FIG. 5 as a software bill of materials (SBOM). Meanwhile, the lower section of FIG. 6 lists the names of the devices shown in FIG. 4 and their associated IP addresses. The correspondence between these is indicated by solid and dotted lines. The solid lines indicate that the devices are connected on a network. The dotted lines indicate that the devices are related to each other.

[0025] <Explanation of Security Evaluation> FIGS. 7 and 8 show the security evaluation performed by the security evaluation unit 150. Of these, FIG. 8 shows the analysis results of the attack path for candidate asset model #1. This attack path is prepared in advance as a known path. FIG. 8 shows that the attack path with path ID 1 is a route from the attacker (start) to IP address 10.200.0.34 (end), passing through four devices with IP addresses 10.12.0.15, 10.0.0.180, 10.200.0.17, and 10.200.0.31. FIG. 8 also lists the probability and confidence of this attack path along with the path ID. The probability is the probability of success when an attack is made using this attack path. The confidence indicates the degree of possibility of an actual attack.

[0026] FIG. 7 shows the security evaluation results for software running on each device when attacked using the attack paths shown in FIG. 8. In this case, the results of security evaluation are shown for the device indicated by Asset name, using the number of vulnerabilities and the Risk Score for the software indicated by Name and Version. In this case, it can be said that the security evaluation unit 150 evaluates security based on the results of attacks on the device using predetermined attack paths. It can also be said that the security evaluation unit 150 evaluates the security of the software running on each device when an attack is made on the device for each attack path.

[0027] <Explanation of Comparison of Security Evaluation Results> Figures 9 to 12 show the comparison of security evaluations performed by the security evaluation comparison unit 160. Of these, Figure 9 shows the first summary of security evaluation results. The first summary of security evaluation results is a summary of the security evaluation results for each attack path for candidate asset model #1, and can be statistically determined from the values ​​in Figure 7. Here, the first summary of security evaluation results is determined for each path ID of the attack path using the path length (Length), average probability (Avg. Probability), average confidence (Avg. Confidence), median number of vulnerabilities (Median Number of Vulnerabilities), and median risk score (Median Risk Score). The path length (Length) is the number of steps on the path from the attacker (start) to the end point. For a path with four devices in between, as shown in Figure 8, the path length (Length) is 5. The smaller the average probability (Avg. Probability), average confidence (Avg. Confidence), median number of vulnerabilities (Median Number of Vulnerabilities), and median risk score (Median Risk Score), the higher the security level. In this case, it can be said that the security evaluation comparison unit 160 obtains the security evaluation result for each attack path based on the security evaluation of the software.

[0028] FIG. 10 shows the secondary summary of security evaluation results. The secondary summary of security evaluation results is a summary of the overall security evaluation results for candidate asset model #1 and can be statistically determined from the values ​​in FIG. 9. Here, the secondary summary of security evaluation results is determined using the number of assets, average path length, average probability, average confidence, average number of vulnerabilities, and average risk score. The smaller the average number of vulnerabilities and average risk score, the higher the security. In this case, the security evaluation comparison unit 160 can be said to summarize the security evaluation results for each attack path and evaluate the security of each candidate asset model.

[0029] The methods used to calculate the primary and secondary summary results of the security evaluation results include, for example, the arithmetic mean, median, mode, interquartile mean, number, variance (e.g., standard deviation, interquartile range, etc.), etc. This method also includes shape / skewness (e.g., skewness, kurtosis, etc.), etc.

[0030] 11 is a diagram showing past security evaluation results used for comparing security evaluation results. As described above, past security evaluation results are stored in the past security evaluation DB 170. The past security evaluation results shown in the figure are in the same format as in FIG. 10. That is, they are composed of the number of assets (Number of assets), average path length (Avg. path length), average probability (Avg. probability), average confidence (Average Confidence), average number of vulnerabilities (Avg. number of vulnerabilities), and average risk score (Avg. Risk Score).

[0031] The security evaluation comparison unit 160 then compares the evaluation of candidate asset model #1 with past evaluations. That is, a comparison is made between FIG. 10 and FIG. 11. In this embodiment, the security evaluation comparison unit 160 compares the items of the average probability (Avg. Probability) and the average reliability (Average Confidence). These are compared because they are more important parameters for comparing security evaluation results, but other items may also be added for comparison. Specifically, the comparison result is the square of the difference between the numerical values ​​in FIG. 10 and FIG. 11 for each of the items of the average probability (Avg. Probability) and the average reliability (Average Confidence).

[0032] Fig. 12 shows the results of a comparison between Fig. 10 and Fig. 11. The bold-framed areas show the comparison results of the average probability (Avg. Probability) and the average confidence (Average Confidence). In this case, it can be said that the security evaluation comparison unit 160 compares the difference between the evaluation of each candidate asset model and past evaluations.

[0033] <Description of Other Candidate Asset Models> As described above, the candidate asset model generation unit 120 generates multiple candidate asset models, which are models of equipment, based on the input data collected by the input data collection unit 110. Other examples of candidate asset models and their evaluations will be described below.

[0034] 13 is a diagram showing another example of a candidate asset model generated by the candidate asset model generation unit 120. Here, this candidate asset model will be referred to as candidate asset model #2. Compared to candidate asset model #1 described in FIG. 6, the correspondence relationships between devices indicated by solid and dotted lines are different.

[0035] FIGS. 14 to 17 show the security evaluation performed by the security evaluation unit 150. These figures are similar to FIGS. 7 to 10, respectively. That is, FIG. 15 shows the analysis results of the attack path for candidate asset model #2. FIG. 15 shows that there are two attack paths. Of these, the attack path with path ID 1 indicates a route from the attacker (start) to IP address 10.200.0.34 (end), passing through five devices: 10.12.0.15, FW, 10.0.0.180, 10.200.0.17, and 10.200.0.31. Furthermore, the attack path with path ID 2 indicates a route from the attacker (start) to IP address 10.200.0.34 (end), passing through two devices: 10.12.0.15 and FW. FIG. 14 shows the results of security evaluation of software running on each device when attacked using the attack paths shown in FIG.

[0036] 16 is a diagram showing the first summary of the security evaluation results. The first summary of the security evaluation results is a summary of the security evaluation results for each attack path for candidate asset model #2, and can be statistically determined from the numerical values ​​in FIG.

[0037] 17 is a diagram showing the secondary summary of the security evaluation results. The secondary summary of the security evaluation results is a summary of the overall security evaluation results for the candidate asset model #2, and can be statistically determined from the numerical values ​​in FIG.

[0038] 18 is a diagram showing the results of comparing the evaluation of candidate asset model #2 with past evaluations. The bold framed areas show the comparison results of the average probability (Avg. Probability) and the average confidence (Average Confidence).

[0039] <Asset Model Selection> The security evaluation comparison unit 160 selects an asset model from the candidate asset models by comparing the evaluation of multiple candidate asset models generated by the candidate asset model generation unit 120 with past evaluations. Specifically, the security evaluation comparison unit 160 compares the average probability (Avg. Probability) and average reliability (Average Confidence) calculated for each candidate asset model with predetermined thresholds. Then, the security evaluation comparison unit 160 selects the candidate asset model with the smaller of these.

[0040] 19 is a diagram showing thresholds, which indicate that 0.1 is set as the threshold for each of the average probability (average probability) and the average confidence (average confidence).

[0041] FIG. 20 is a diagram showing the comparison results of candidate asset model #1 and candidate asset model #2 with the thresholds listed in FIG. 19 . As shown in the figure, candidate asset model #1 exceeds the thresholds for both the average probability (Avg. Probability) and the average reliability (Average Confidence), and therefore does not meet the requirements. In contrast, candidate asset model #2 falls within the threshold range for both the average probability (Avg. Probability) and the average reliability (Average Confidence), and therefore meets the requirements. In this case, the security evaluation comparison unit 160 adopts candidate asset model #2 as the asset model. This makes it possible to confirm and ensure the accuracy of the asset model. As a result, it is possible to automatically generate a highly accurate asset model. In this case, it can also be said that the security evaluation comparison unit 160 selects the candidate asset model with the smallest difference as the asset model from among the candidate asset models.

[0042] <Detailed Description of Operation of Asset Model Generation Device 100> Next, the operation of the asset model generation device 100 will be described in detail.

[0043] 21 is a flowchart illustrating the overall operation of the asset model generation device 100. First, the input data collection unit 110 collects input data such as that described in FIGS. 3 to 5 (S2101). Next, the candidate asset model generation unit 120 generates multiple candidate asset models and creates a candidate asset model list (S2102). The candidate asset models are as described in FIGS. 6 and 13 and are stored in the candidate asset model DB 130. Next, the candidate asset model selection unit 140 selects the first candidate asset model from the multiple candidate asset models (S2103). Then, the security evaluation unit 150 performs security evaluation using the selected candidate asset model (S2104).

[0044] Furthermore, the security evaluation comparison unit 160 compares the selected candidate asset model with past evaluations (S2105). The past evaluation is selected from the past security evaluation DB 170 to find one that is closest to the selected candidate asset model. The security evaluation comparison unit 160 then determines whether the comparison result is equal to or less than the threshold shown in FIG. 19 (S2106). If the result is equal to or less than the threshold (YES in S2106), the process proceeds to S2111. On the other hand, if the result exceeds the threshold (NO in S2106), the security evaluation comparison unit 160 adds the comparison result of the security evaluation results to the selected candidate asset model list (S2107).

[0045] Next, the candidate asset model selection unit 140 determines whether there are other candidate asset models (S2108). As a result, if there are other candidate asset models (YES in S2106), the candidate asset model selection unit 140 selects another candidate asset model (S2109) and returns to S2104. On the other hand, if there are no other candidate asset models (NO in S2106), the candidate asset model selection unit 140 selects an asset model from the candidate asset model list that has an appropriate security evaluation result comparison result (S2110). Then, the selected candidate asset model is extracted and set as the asset model to be adopted (S2111).

[0046] FIG. 22 is a flowchart illustrating the operation of the candidate asset model generation unit 120 when creating multiple candidate asset models. That is, FIG. 22 is a flowchart illustrating S2102 in FIG. 21 in more detail. The method in FIG. 22 is an existing method. First, the candidate asset model generation unit 120 initializes a change parameter P for a certain asset model generation method (S2201). The change parameter P is a parameter for generating different candidate asset models, and represents, for example, the similarity of input data or the connectivity of devices. Next, the candidate asset model generation unit 120 generates an initial asset model according to a certain asset model generation method, including the change parameter P, using the collected input data (S2202). Next, the candidate asset model generation unit 120 registers the generated asset model in a candidate asset model list (S2203). Then, the candidate asset model generation unit 120 determines whether or not there is a next setting for the change parameter P (S2204). As a result, if there is a next setting (YES in S2204), the change parameter P is changed to the next setting (S2205), and the process returns to S2202. On the other hand, if there is no next setting (NO in S2204), the candidate asset model generation unit 120 deletes asset models below a certain threshold from the candidate asset model list (S2206). Furthermore, the candidate asset model generation unit 120 rearranges the order of the items in the candidate asset model list according to a certain method (S2207). However, the execution of S2206 and S2207 is optional and does not have to be performed. Then, the candidate asset model generation unit 120 creates a candidate asset model list (S2208).

[0047] Fig. 23 is a flowchart illustrating the operation of the security evaluation unit 150 when performing a security evaluation using a selected candidate asset model. Specifically, Fig. 23 is a flowchart illustrating S2104 in Fig. 21 in more detail. First, the security evaluation unit 150 uses the selected candidate asset model to obtain a security evaluation result (Fig. 7) based on the attack path analysis result (Fig. 8) (S2301). Then, the security evaluation unit 150 creates a security evaluation result (S2302).

[0048] FIG. 24 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when comparing security evaluation results. That is, FIG. 24 is a flowchart illustrating S2105 in FIG. 21 in more detail. First, the security evaluation comparison unit 160 obtains a primary summary of the security evaluation results (S2401). This is as described in FIG. 9. Next, the security evaluation comparison unit 160 obtains a secondary summary of the security evaluation results (S2402). This is as described in FIG. 10. Then, the security evaluation comparison unit 160 obtains a comparison table of the secondary summary of the security evaluation results (S2403). This is as described in FIG. 12. Furthermore, the security evaluation comparison unit 160 creates a comparison result of the security evaluation results (S2404).

[0049] FIG. 25 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when determining a first summary of security evaluation results. That is, FIG. 25 is a flowchart that provides more detailed information about S2401 in FIG. 24. First, the security evaluation comparison unit 160 selects an initial path ID according to the attack path analysis results (FIG. 8) (S2501). Next, the security evaluation comparison unit 160 statistically determines a summary result while referring to the selected path ID (S2502). As a result, the security evaluation comparison unit 160 determines the path length (Length), average probability (Avg. Probability), and average reliability (Avg. Confidence) shown in FIG. 9. Furthermore, the security evaluation comparison unit 160 extracts the relevant asset while referring to the selected path ID, and statistically determines a summary result while referring to the asset's risk evaluation results (FIG. 14) (S2503). As a result, the security evaluation comparison unit 160 calculates the median number of vulnerabilities and the median risk score (Median Risk Score) shown in Fig. 9. Next, the security evaluation comparison unit 160 determines whether or not there are other path IDs (S2504). As a result, if there are other path IDs (YES in S2504), the security evaluation comparison unit 160 selects another path ID (S2505) and returns to S2502. On the other hand, if there are no other path IDs (NO in S2504), the series of processes ends.

[0050] FIG. 26 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when determining a secondary summary of security evaluation results. That is, FIG. 26 is a flowchart that provides more detailed information about S2402 in FIG. 24. First, the security evaluation comparison unit 160 selects an initial path ID in accordance with the primary summary of security evaluation results (FIG. 9) (S2601). Next, the security evaluation comparison unit 160 statistically determines a summary (FIG. 10) while referring to the asset information in the asset model such as FIG. 6 (S2602). As a result, the security evaluation comparison unit 160 determines the number of assets in FIG. 10. Furthermore, the security evaluation comparison unit 160 statistically determines a summary while referring to the selected path ID (S2603). As a result, the security evaluation comparison unit 160 calculates the average path length (Avg. Path Length), average probability (Avg. Probability), average reliability (Average Confidence), average number of vulnerabilities (Avg. Number of Vulnerabilities), and average risk score (Avg. Risk Score) shown in FIG. 10. Next, the security evaluation comparison unit 160 determines whether or not there are other path IDs (S2604). As a result, if there are other path IDs (YES in S2604), the security evaluation comparison unit 160 selects another path ID (S2605) and returns to S2602. On the other hand, if there are no other path IDs (NO in S2604), the process ends.

[0051] FIG. 27 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when generating a comparison table of the secondary summary of security evaluation results. That is, FIG. 27 is a flowchart illustrating S2403 in FIG. 24 in more detail. First, the security evaluation comparison unit 160 selects an initial attribute by referencing the secondary summary of security evaluation results (FIG. 10) and the past security evaluation results (FIG. 11) (S2701). In the case of FIG. 12, the attribute corresponds to the average probability (Avg. Probability) and the average confidence (Average Confidence). Next, the security evaluation comparison unit 160 uses a predetermined comparison method (e.g., mean square error) to write the comparison values ​​of the selected attribute between the secondary summary of security evaluation results (FIG. 10) and the past security evaluation results (FIG. 11) into the comparison table of the security result summary (FIG. 12) (S2702). Next, the security evaluation comparison unit 160 determines whether there are any other attributes (S2703). As a result, if there are other attributes (YES in S2703), the next attribute is selected (S2704) and the process returns to S2702. On the other hand, if there are no other path IDs (NO in S2703), the series of processes ends.

[0052] Fig. 28 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when adding the comparison result of the security evaluation results to the selected candidate asset model list. That is, Fig. 28 is a flowchart illustrating S2107 in Fig. 21 in more detail. First, the security evaluation comparison unit 160 selects an item (row) of the selected candidate asset model from the candidate asset model list (Fig. 20) (S2801). Then, the security evaluation comparison unit 160 adds the comparison result of the security evaluation results to the selected candidate asset model item (S2802).

[0053] FIG. 29 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when selecting an asset model whose security evaluation results are deemed appropriate from the candidate asset model list. That is, FIG. 29 is a flowchart illustrating S2110 in FIG. 21 in more detail. First, the security evaluation comparison unit 160 selects a first candidate asset model from the selected candidate asset model list (FIG. 20) (S2901). Next, the security evaluation comparison unit 160 calculates the appropriateness (value) using a certain comparison method using one or more parameters (values) of the selected candidate asset model (S2902). Next, the security evaluation comparison unit 160 determines whether the comparison result is equal to or less than the threshold (FIG. 19) (S2903). As a result, if the comparison result is equal to or less than the threshold (YES in S2903), the process proceeds to S2907. On the other hand, if the comparison result exceeds the threshold (NO in S2903), the security evaluation comparison unit 160 determines whether there are other candidate asset models (S2904). If there are other candidate asset models (YES in S2904), the next candidate asset model is selected (S2905), and the process returns to S2902.

[0054] On the other hand, if there are no other candidate asset models (NO in S2904), the security evaluation comparison unit 160 determines whether there are any candidate asset models whose comparison results are equal to or less than the threshold value (FIG. 19) (S2906). As a result, if there are any candidate asset models whose comparison results are equal to or less than the threshold value (YES in S2906), the selected candidate asset model is extracted as the asset model (S2907). On the other hand, if there are no candidate asset models whose comparison results are equal to or less than the threshold value (NO in S2906), an error is generated (S2908). In other words, a message is sent to the effect that an appropriate candidate asset model could not be created.

[0055] <Modification> In this modification, the security evaluation comparison unit 160 verifies the accuracy of the candidate asset model created by the candidate asset model generation unit 120 using the comparison results shown in FIG. 12. FIG. 30 is a flowchart illustrating the operation of the security evaluation comparison unit 160 when verifying the accuracy of the candidate asset model created by the candidate asset model generation unit 120. First, the security evaluation comparison unit 160 selects the first threshold parameter while referring to the threshold table (FIG. 19) (S3001). Next, the security evaluation comparison unit 160 refers to the parameter value selected from the security result summary comparison table (FIG. 12) and determines whether the selected parameter value is greater than the threshold (S3002). In other words, the security evaluation comparison unit 160 determines whether the parameter value is greater than the threshold (S3003). As a result, if the parameter value is not greater than the threshold (parameter value≦threshold) (NO in S3003), the security evaluation comparison unit 160 determines whether there is a parameter for the next threshold (S3004). If there is a parameter for the next threshold (YES in S3004), the parameter for the next threshold is selected (S3005) and the process returns to S3002. On the other hand, if there is no parameter for the next threshold (NO in S3004), the process proceeds to S3007.

[0056] On the other hand, if the parameter value is greater than the threshold value in S3003 (YES in S3003), the security evaluation comparison unit 160 performs model error detection (S3006). That is, the security evaluation comparison unit 160 determines that the candidate asset model that exceeds the threshold value has a large error. The security evaluation comparison unit 160 then transmits the error detection result to the visualization unit (S3007). In this case, the visualization unit is a display device, such as a liquid crystal display. In this case, it can also be said that the security evaluation comparison unit 160 determines the accuracy of the generated candidate asset model by comparing the evaluations of multiple candidate asset models with past evaluations.

[0057] 31 is a flowchart illustrating the process of displaying the error detection results. First, the security evaluation comparison unit 160 references the error detection results (S3101). Next, it determines whether the detection results indicate a model error (S3102). If a model error is present (YES in S3102), the security evaluation comparison unit 160 prepares display content according to the error detection results (S3103). Furthermore, the security evaluation comparison unit 160 displays the display content of the error detection results (S3104). Note that if there is no model error (NO in S3102), the error detection results are not displayed.

[0058] 32 is a diagram showing the display content of the error detection result. Here, a warning screen is shown displaying the message "When the security evaluation result was compared with past statistical data, a mismatch was detected."

[0059] <Explanation of Effects> According to the asset model generation device 100 described above in detail, it is possible to automatically generate highly accurate asset models. That is, the asset model generation device 100 generates multiple candidate asset models and performs security evaluations on each of them. Then, by comparing the results with past security evaluation results, it is possible to select a more appropriate asset model from among the multiple candidate asset models. As a result, the selected asset model will have higher accuracy.

[0060] In the past, when experts manually generated asset models using information such as system design documents and system configuration diagrams, manual work could result in system configuration judgment errors and input errors. In this case, the accuracy of the generated model deteriorates, as does the accuracy of the security simulation and evaluation. In addition, since system updates (such as the addition of new functions) are not reflected in an asset model once created, SDT cannot be used without model updates. Furthermore, since manual model generation takes time, it is not possible to respond immediately even if new vulnerabilities or attack methods are made public. In the present embodiment, this is less likely to occur. Therefore, compared to conventional manual generation of asset models, not only can asset models be generated automatically, but asset models with higher accuracy can also be generated.

[0061] Furthermore, even if the input data contains various formats, structures, and abstraction levels, the method described above selects the candidate asset model that best matches which ones refer to the same thing. If an asset model with an incorrect match is used, the inherent risks may not be realized, resulting in increased risks to the system and insufficient countermeasures. However, in this embodiment, a more valid asset model is selected, making it possible to confirm and guarantee the accuracy of the asset model. Therefore, it is possible to generate an asset model with higher accuracy than when conventional asset models are automatically generated.

[0062] <Hardware Configuration> Fig. 33 is a diagram showing an example of the hardware configuration of the asset model generation device 100 in this embodiment. In this embodiment, the asset model generation device 100 is a computer device, such as a personal computer (PC), a workstation, or a server device. However, the device is not limited to these, and may also be a smartphone, a tablet, a mobile phone terminal, a PDA (Personal Digital Assistant), or the like.

[0063] The asset model generation device 100 includes a CPU (Central Processing Unit) 3301, which is a computing means, and a memory 3302, which is a storage means. The CPU 3301 executes various software such as an OS (operating system) and applications (application software). The memory 3302 is a storage area that stores various software and data used for executing the software. The asset model generation device 100 also includes storage as an auxiliary storage device. The storage is, for example, an HDD (Hard Disk Drive) or an SSD (Solid State Drive). The asset model generation device 100 also includes a network interface 3304 for communicating with the outside, and a peripheral device controller 3305 that controls peripheral devices such as output devices such as a display and input devices such as a keyboard and a mouse.

[0064] <Explanation of Asset Model Generation Method> As described above, the processing performed by the asset model generation device 100 is realized by the cooperation of software and hardware resources. Therefore, the processing performed by the above-described asset model generation device 100 can be considered to be an asset model generation method in which a processor such as the CPU 3301 executes a program recorded in the memory 3302 to collect input data including information about the devices constituting the system and information about the connectivity between the devices, generate multiple candidate asset models as candidates for asset models that are models of the devices based on the collected input data, evaluate the security of the multiple candidate asset models, compare the evaluation of the multiple candidate asset models with past evaluations, and select an asset model from the multiple candidate asset models. Furthermore, the program running on the asset model generation device 100 can be considered to be a program that causes a computer to implement the following functions: collect input data including information about the devices constituting the system and information about the connectivity between the devices, generate multiple candidate asset models as candidates for asset models that are models of the devices based on the collected input data, evaluate the security of the multiple candidate asset models, and compare the evaluation of the multiple candidate asset models with past evaluations and select an asset model from the multiple candidate asset models.

[0065] The program for realizing this embodiment can be provided not only by communication means but also by being stored on a recording medium such as a CD-ROM.

[0066] Although the present embodiment has been described above, the technical scope of the present invention is not limited to the scope described in the above embodiment. It is clear from the claims that various modifications and improvements to the above embodiment are also included in the technical scope of the present invention.

[0067] 1...security evaluation system, 100...asset model generation device, 110...input data collection unit, 120...candidate asset model generation unit, 130...candidate asset model DB, 140...candidate asset model selection unit, 150...security evaluation unit, 160...security evaluation comparison unit, 170...past security evaluation DB, 3301...CPU, 3302...memory

Claims

1. An asset model generation device comprising: an input data collection unit that collects input data including information about devices that constitute a system and information about connectivity between the devices; a candidate asset model generation unit that generates a plurality of candidate asset models as candidates for asset models that are models of the devices based on the collected input data; a security evaluation unit that evaluates the security of the plurality of candidate asset models; and a security evaluation comparison unit that compares evaluations of the plurality of candidate asset models with past evaluations and selects an asset model from the plurality of candidate asset models.

2. The asset model generation device according to claim 1, wherein the security evaluation unit evaluates security based on the results of an attack on the device using a predetermined attack path.

3. The asset model generation device according to claim 2, wherein the security evaluation unit evaluates the security of software running on each of the devices when an attack is made on the device for each of the attack paths.

4. The asset model generation device according to claim 3, wherein the security evaluation comparison unit obtains the security evaluation result for each attack path based on the security evaluation of the software.

5. The asset model generation device according to claim 4, wherein the security evaluation comparison unit compiles the security evaluation results for each of the attack paths and evaluates the security of each of the candidate asset models.

6. The asset model generation device according to claim 1, wherein the security evaluation comparison unit compares the difference between the evaluation of each of the candidate asset models and past evaluations.

7. The asset model generation device according to claim 6, wherein the security evaluation comparison unit selects, as the asset model, one of the candidate asset models for which the difference is small.

8. The asset model generation device according to claim 1, wherein the security evaluation comparison unit determines the accuracy of the generated candidate asset model by comparing the evaluations of the plurality of candidate asset models with past evaluations.

9. The asset model generation device according to claim 1, wherein the system is an OT (Operational Technology) system.

10. A security evaluation system that evaluates the impact of security measures on business continuity using a digital twin that uses an asset model generated using the asset model generation device described in any one of claims 1 to 9, an actor model that represents human behavior toward the system, and a process model that represents critical operations of the system.

11. An asset model generation method in which a processor executes a program recorded in memory to collect input data including information about devices that constitute a system and information about connectivity between said devices, generate a plurality of candidate asset models as candidates for asset models that are models of said devices based on the collected input data, evaluate the security of said plurality of candidate asset models, compare the evaluation of said plurality of candidate asset models with past evaluations, and select an asset model from among said plurality of candidate asset models.

Citation Information

Patent Citations

  • Secure system automatic design device, secure system automatic design method, and computer-readable medium

    WO2023042257A1