Security breach analysis device, security breach analysis method, and security analysis system

The security breach analysis device addresses the limitation of conventional systems by calculating and comparing real-time cyber-attack data with simulated data to detect and analyze cyber threats effectively.

WO2025203855A1PCT designated stage Publication Date: 2025-10-02HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2024/041166
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-11-20
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Conventional security systems fail to detect cyber attacks in real-time on actual systems due to their reliance on pre-generated rules from simulated systems, lacking the ability to reflect real-time cyber attacks and provide quick reporting.

Method used

A security breach analysis device that calculates an actual operation status from a real system, compares it with a simulated operation status, estimates inconsistencies, and outputs information on detected and estimated cyber-attacks, using a configuration that includes a calculation unit, comparison unit, estimation unit, and output unit.

Benefits of technology

Enables real-time detection of cyber attacks on actual systems, allowing for quick identification and containment of threats by accurately matching actual and simulated operation statuses and generating analysis rules for intrusion trace detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2024041166_02102025_PF_FP_ABST
    Figure JP2024041166_02102025_PF_FP_ABST
Patent Text Reader

Abstract

A security breach analysis device (20) is provided with: a calculation unit (21) for calculating an actual operation status (32) from an actual system (10) under analysis and also calculating a simulated operation status (33) from a simulation system (31) simulating the actual system (10); a comparison unit (22) for comparing the actual operation status (32) and the simulated operation status (33); an inference unit (23) for inferring a predetermined cyberattack that will be mismatched between a cyberattack that occurred in the actual system (10) and a cyberattack that was detected in the actual system (10) on the basis of a comparison result of the comparison unit (22); and an output unit (26) for outputting information about the comparison result of the comparison unit (22) and / or information about the predetermined cyberattack inferred at the inference unit (23).
Need to check novelty before this filing date? Find Prior Art

Description

Security intrusion analysis device, security intrusion analysis method, and security analysis system

[0001] The present invention relates to a security intrusion analysis device, a security intrusion analysis method, and a security analysis system.

[0002] As a security measure against the threat of cyber attacks, it is effective to collect environmental information, history information, and attack information from the actual system where the attack was carried out, and analyze the attack based on this collected information. By automatically generating the rules used for this analysis (security work), the burden of analysis on administrators can be reduced.

[0003] For example, Patent Document 1 describes the rule generation device as follows: "A collection unit collects, from a simulated system that simulates a system that is the target of attack, environmental information that indicates the environment constructed in the simulated system, history information recorded in the simulated system, and attack information that indicates whether an attack has been executed against the simulated system and whether the attack has succeeded or failed; an attack success condition generation unit that uses the attack information to extract environmental information at the time of a successful attack and environmental information at the time of an unsuccessful attack from the environmental information, calculates a difference between the environmental information at the time of the unsuccessful attack that includes all of the environmental information at the time of the successful attack and the environmental information at the time of the successful attack, attaches exclusion information that indicates that the attack has failed to the difference, and adds the difference with the exclusion information attached to the environmental information at the time of the successful attack to generate an attack success condition." the attack history generation unit which calculates, for each of the same environmental information when the attack is successful, a difference between the historical information when there is no attack and the historical information when the attack is successful, extracts common historical information when the attack is successful that is common to the calculated differences when the attack is successful, and calculates, for each of the same environmental information when the attack is unsuccessful, a difference between the historical information when there is no attack and the historical information when the attack is unsuccessful, extracts common historical information when the attack is unsuccessful that is common to the calculated differences when the attack is unsuccessful, and generates attack history information using the common historical information when the attack is successful and the common historical information when the attack is unsuccessful; and a rule generation unit which generates rules using the attack success conditions and the historical information.

[0004] Patent No. 7207536 specification

[0005] Since cyber attacks can occur at any time, it is necessary to respond quickly to attacks that occur in real time. To achieve this, a security system with high speed reporting is needed, which can notify administrators and others in real time of cyber attacks that are actually occurring on actual systems.

[0006] However, while conventional techniques such as those in Patent Document 1 automate the generation of rules used in analysis, they are limited to rules that are generated in advance using only a simulated system. As a result, they do not reflect cyber attacks that actually occur on real systems, and a security system that can report information quickly has not been realized.

[0007] In view of the above problems, the present invention aims to appropriately detect cyber attacks occurring in real time on a real system.

[0008] In order to solve the above problems, the security breach analysis device of the present invention has the following features. The present invention is characterized by comprising: a calculation unit that calculates an actual operation status from an actual business log recorded in a real system to be analyzed, and calculates a simulated operation status when a cyber-attack detected in the real system is executed as the simulated attack content on a simulated system that simulates the real system; a comparison unit that compares the actual operation status with the simulated operation status; an estimation unit that estimates a predetermined cyber-attack that is inconsistent between the cyber-attack that occurred in the real system and the cyber-attack detected in the real system based on the comparison result of the comparison unit; and an output unit that outputs at least one piece of information from the comparison result of the comparison unit and information about the predetermined cyber-attack estimated by the estimation unit. Other means will be described below.

[0009] According to the present invention, it is possible to appropriately detect cyber attacks occurring in real time on a real system.

[0010] 1 is a configuration diagram showing an overview of a security analysis system according to the present embodiment. FIG. 2 is an explanatory diagram showing an example of the operation of a security violation analysis device according to the present embodiment. FIG. 3 is a configuration diagram of a security analysis system that is a first example according to the present embodiment. FIG. 4 is a configuration diagram of a security analysis system that is a second example according to the present embodiment. FIG. 5 is a configuration diagram of a security analysis system that is a third example according to the present embodiment. FIG. 6 is a flowchart showing main processing of the security analysis system according to the present embodiment. FIG. 7 is a screen diagram showing a first example of an individual comparison screen of operational statuses presented to a user according to the present embodiment. FIG. 8 is a screen diagram showing a second example of an individual comparison screen of operational statuses presented to a user according to the present embodiment. FIG. 9 is a graph showing an example of calculation of a match rate by a comparison unit according to the present embodiment. FIG. 10 is a screen diagram of statistical information of operational statuses presented to a user according to the present embodiment. FIG. 11 is a flowchart showing details of processing for inferring attack content by an inference unit according to the present embodiment. FIG. 12 is a screen diagram showing a list of analysis results by an analysis unit according to the present embodiment. FIG. 13 is a screen diagram showing a setting screen for analysis by the analysis unit according to the present embodiment. FIG. 14 is a table showing an example of an actual business log according to the present embodiment. FIG. 15 is a table showing an example of an attack detection log according to the present embodiment. FIG. 16 is a table showing an example of an attack technique DB according to the present embodiment. FIG. 17 is a table showing an example of an actual operation status according to the present embodiment. FIG. 18 is a table showing an example of history information according to the present embodiment. FIG. 19 is a table showing an example of history information related to this embodiment, and is a diagram continuing from FIG. 18.

[0011] An embodiment of the present invention will be described below.

[0012] 1 is a configuration diagram showing an overview of a security analysis system 100. The security analysis system 100 is configured by connecting an actual system 10 and a security violation analysis device 20 via a network. The actual system 10 is configured with computer equipment such as manufacturing equipment in a factory, and is a system that operates in an actual business environment, and further includes an information collection device 11 and an analysis execution device 12. The information collection device 11 collects, as log information, an actual business log 11A, an attack detection log 11B, and an analysis target log 11C.

[0013] The business log is log information related to business operations, such as packing performed by a factory's manufacturing equipment at 10:14. The actual business log 11A is log information related to business operations performed in the actual system 10. The attack detection log 11B is log information indicating the results of a cyberattack detected by a cyberattack detection device (not shown) of the actual system 10, which detected a cyberattack on the actual system 10. However, because the cyberattack detection device cannot detect all attacks, some cyberattacks on the actual system 10 may not be detected and may be missed from the attack detection log 11B. The analysis target log 11C is log information related to the actual system 10 that is the target of analysis by the analysis execution device 12. The analysis target log 11C is, for example, login data for a factory management device. Note that for ease of explanation, the actual business log 11A, the attack detection log 11B, and the analysis target log 11C are described separately. However, the analysis target log 11C may include the attack detection log 11B, and there may be logs that correspond to multiple logs.

[0014] The analysis execution device 12 analyzes the analysis target log 11C to discover indicators of compromise (IoCs) or provides information useful for discovering IoCs. IoCs are data left behind when a system or network is compromised or attacked. Information useful for discovering IoCs is, for example, a portion of data extracted from the analysis target log 11C that is likely to contain IoCs. By referring to the analysis results output by the analysis execution device 12 and discovering indicators of compromise from the analysis target log 11C, an administrator can plan measures to minimize damage from cyberattacks against those indicators of compromise.

[0015] The security violation analysis device 20 includes a calculation unit 21, a comparison unit 22, an estimation unit 23, a generation unit 24, and an analysis unit 25. The security violation analysis device 20 also stores a simulated system 31, an actual operation status 32, a simulated operation status 33, an attack technique DB 34, history information 35, and analysis rules 36.

[0016] First, the following terms regarding cyber attacks are defined. An "actual cyber attack" is a cyber attack that actually occurs on the actual system 10 and whose impact is apparent in the actual operation status 32. A "detected cyber attack" is a cyber attack that is detected by the cyber attack detection device of the actual system 10 and recorded in the attack detection log 11B. For example, a new type of actual cyber attack that has not yet been registered as a detection pattern for the cyber attack detection device does not fall under the category of a detected cyber attack.

[0017] "Simulated attack content" is information indicating the content of a simulated cyber-attack that occurs when the simulated system 31 is operated, and is composed of the date, time, device, and attack method, and is included in the history information 35 of FIG. 18. The simulated attack content may be, for example, the same content as the detected cyber-attack, or may be updated based on the cyber-attack estimated by the estimation unit 23. "Specified cyber-attack" is a cyber-attack estimated by the estimation unit 23 when there is a mismatch between the actual cyber-attack and the simulated attack content (such as a detected cyber-attack). For example, the detected cyber-attack may be matched with the actual cyber-attack by supplementing the detected cyber-attack with a missing (undetected) specified cyber-attack, or the detected cyber-attack may be matched with the actual cyber-attack by deleting a specified cyber-attack that is excessive (i.e., a false positive) from the detected cyber-attack.

[0018] The simulated system 31 is a virtual reproduction of the real system 10, and is capable of reproducing the same log information as the real system 10. This simulated system 31 is a system that simulates the real system 10 and is virtually generated on a computer as an electronic twin (digital twin) or CPS (Cyber ​​Physical Systems). Just as the actual business log 11A is measured from the operating real system 10, the calculation unit 21 acquires a simulated business log that is the result of operating (simulating) the contents of a simulated attack on the simulated system 31. This simulated business log is expressed in the same format as the actual business log 11A.

[0019] The simulated system 31 may be generated, for example, by computer simulation (such as by reproducing the entire simulated system 31 using a graph model) or mathematical modeling, which can reproduce data equivalent to the log information generated in the real system 10. By generating the simulated system 31 using computer simulation or mathematical modeling in this way, the cyber-attack verification process can be executed faster than real time. Alternatively, the simulated system 31 may be generated using VMware (registered trademark) or VirtualBox (registered trademark) to reproduce the real system 10 at the device OS level, but each execution of a simulated attack requires a time equivalent to real time.

[0020] The "operation status" is a representation of a business log of a system, such as a product production system, using one or more feature quantities (e.g., the time-series production volume of product A) that change over time. The calculation unit 21 calculates an actual operation status 32 and a simulated operation status 33 as one or more feature quantities that indicate the system's operation status and are defined over time. Specifically, the calculation unit 21 creates the actual operation status 32 (shaping it into feature quantities) from the actual operation log 11A recorded in the real system 10. The calculation unit 21 also creates simulated attack details from the detected cyber-attack. The calculation unit 21 then calculates a simulated operation status 33 when the simulated attack details are executed on a simulated system 31 that simulates the real system 10. To this end, the calculation unit 21 runs a CPS or simulator to generate simulated attack details in the simulated system 31, thereby creating a simulated business log, and then creates a simulated operation status 33 from the simulated business log.

[0021] The comparison unit 22 compares the actual operation status 32 with the simulated operation status 33 and generates a comparison result. For example, the comparison unit 22 calculates a match rate, which increases as the degree of match between the actual operation status 32 and the simulated operation status 33 increases. Alternatively, the comparison unit 22 may generate a comparison result including the location and time of a cyber-attack by comparing the feature amounts of the actual operation status 32 with the feature amounts of the simulated operation status 33 in chronological order.

[0022] The estimation unit 23 estimates a predetermined cyber attack based on the comparison result of the comparison unit 22, as shown in the following examples: An undetected cyber attack is a cyber attack that occurred as an actual cyber attack but was not included in the detected cyber attacks, and is a false negative. A false positive cyber attack is a cyber attack that did not occur as an actual cyber attack but was included in the detected cyber attacks, and is a false positive.

[0023] Furthermore, the estimation unit 23 may update the simulated attack content and cause the calculation unit 21 to recalculate the simulated operation status 33 so that the actual operation status 32 and the simulated operation status 33 match more closely as a comparison result of the comparison unit 22. The output unit 26 (FIGS. 3 to 5) outputs at least one of information on the comparison result of the comparison unit 22 and information on the predetermined cyber attack estimated by the estimation unit 23.

[0024] The generation unit 24 generates an analysis rule 36 for discovering intrusion traces of a predetermined cyber-attack inferred by the inference unit 23 from the analysis target log 11C of the actual system 10. The generation unit 24 generates the analysis rule 36 by referring to the attack record (attack technique DB 34 in FIG. 16 ) indicating the characteristics of intrusion traces caused by each cyber-attack in the past.

[0025] The analysis unit 25 uses the analysis rule 36 generated by the generation unit 24 to analyze whether or not an IoC exists in the real system 10. For example, the analysis unit 25 uses the analysis rule 36 generated by the generation unit 24 to extract the range of traces of intrusion of a predetermined cyber-attack inferred by the inference unit 23 from the analysis target log 11C of the real system 10. To this end, the analysis unit 25 inputs the analysis rule 36 to the analysis execution device 12 to extract IoCs from the analysis target log 11C. The analysis execution device 12 extracts log information that conforms to the analysis rule 36 from the analysis target log 11C and returns the extraction results to the analysis unit 25 as IoC analysis information. This allows the administrator to refer to the IoC analysis information to determine which hosts / networks are being infringed and how (the scope of the attack's impact). Therefore, the administrator can take appropriate measures to contain the threat, such as introducing security equipment that can respond to undetected cyber-attacks.

[0026] The analysis execution unit 12 is implemented using SIEM (Security Information and Event Management) or the like, which accumulates the analysis target log 11C. The analysis rules 36 correspond to search commands for logs input to SIEM. Since search commands differ depending on the SIEM vendor, the generation unit 24 absorbs these differences.

[0027] Furthermore, if the matching rate between the actual operation status 32 and the simulated operation status 33 is low, the analysis unit 25 changes the simulated attack content used in calculating the simulated operation status 33 (for example, by adding a constraint), thereby causing the calculation unit 21 to recalculate the simulated operation status 33. In this way, the analysis unit 25 improves the matching rate between the recalculated simulated operation status 33 and the actual operation status 32. For this reason, the analysis unit 25 reads a set of feasible attack patterns from the attack method DB 34 as candidates for cyber-attacks to be included in the simulated attack content.

[0028] 1 , the security analysis system 100 includes a real system 10 and a security intrusion analysis device 20. The real system 10 includes an information collection device 11 and an analysis execution device 12. The information collection device 11 collects a real business log 11A and an analysis target log 11C recorded in the real system 10 to be analyzed, as well as information on cyberattacks detected in the real system 10. The analysis execution device 12 uses an analysis rule 36 to execute an analysis process to extract, from the analysis target log 11C, a range in which traces of intrusion from a specified cyberattack exist.

[0029] The security breach analysis device 20 includes a calculation unit 21, a comparison unit 22, an estimation unit 23, a generation unit 24, an analysis unit 25, and an output unit 26. The calculation unit 21 calculates an actual operation status 32 from the actual work log 11A provided by the information collection device 11, and calculates a simulated operation status 33 when a simulated attack indicating information about a cyberattack provided by the information collection device 11 is executed on a simulated system 31 that simulates the actual system 10. The comparison unit 22 compares the actual operation status 32 with the simulated operation status 33. The estimation unit 23 estimates a predetermined cyberattack that results in a mismatch between a cyberattack that occurred in the actual system 10 and a cyberattack that was detected in the actual system 10, based on the comparison result of the comparison unit 22. The generation unit 24 generates an analysis rule 36 to be used in the analysis process of the predetermined cyberattack estimated by the estimation unit 23. The analysis unit 25 provides the analysis rule 36 generated by the generation unit 24 to the analysis execution device 12, thereby causing the analysis execution device 12 to execute the analysis process. The output unit 26 (FIGS. 3 to 5) outputs at least one piece of information from the comparison result information of the comparison unit 22, the predetermined cyber attack information inferred by the estimation unit 23, and the result information obtained when the analysis unit 25 causes the analysis execution device 12 to execute the analysis process.

[0030] 2 is an explanatory diagram showing an example of the operation of the security violation analysis device 20. The security violation analysis device 20 executes the following steps: (Step 1) The security violation analysis device 20 calculates a feature quantity related to the actual operation status 32 of the actual system 10 from the actual business log 11A. In Fig. 2, the security violation analysis device 20 calculates the actual operation status 32 including a decrease in feature quantity T1 due to the cyber-attack SA and a decrease in feature quantity T2 due to the cyber-attack SB.

[0031] (Second Step) The security breach analysis device 20 calculates a feature quantity related to a simulated operating situation 33 calculated from the simulated attack details using the simulated system 31. In Fig. 2, the security breach analysis device 20 calculates the simulated operating situation 33 including a decrease in feature quantity T1 due to the cyber-attack SA and a decrease in feature quantity T3 due to the cyber-attack SC.

[0032] (Third Procedure) Based on the results of comparing the actual operation status 32 (first procedure) with the simulated operation status 33 (second procedure), the security breach analysis device 20 uses reinforcement learning or the like to infer, based on the simulated system 31, the attack content (predetermined cyberattack) that compensates for the differences in the feature values ​​between the two, as follows: Cyberattack SA (decrease in feature value T1) is observed consistently in both the actual cyberattack and the detected cyberattack, and is therefore a normal detection and does not constitute a predetermined cyberattack. Cyberattack SB (decrease in feature value T2) occurs when an abnormal value of the feature value due to a cyberattack is observed in the actual operation status 32, but a normal value of the feature value is observed in the simulated operation status 33. In this case, the inference unit 23 infers that a cyberattack that actually occurred but was undetected in the actual system 10 is a predetermined cyberattack. Cyberattack SC (decrease in feature value T3) occurs when a normal value of the feature value is observed in the actual operation status 32, but an abnormal value of the feature value due to a cyberattack is observed in the simulated operation status 33. In this case, the estimation unit 23 estimates a cyber-attack that did not actually occur in the real system 10 but was falsely detected as a specified cyber-attack.

[0033] (Fourth Step) The security breach analysis device 20 analyzes whether an IoC that determines the occurrence of the specified cyber-attack predicted in (third step) exists in the analysis target log 11C of the actual system 10. If an undetected cyber-attack SB does not exist in the analysis target log 11C, or if a false positive cyber-attack SC exists in the analysis target log 11C, the accuracy of the prediction of the specified cyber-attack is poor. In this case, the security breach analysis device 20 updates the simulated attack content, recalculates the simulated operation status 33 based on the update, and returns to (second step).

[0034] Three examples of hardware configurations for implementing the security analysis system 100 of FIG. 1 are illustrated below in the drawings (FIGS. 3, 4, and 5). FIG. 3 is a configuration diagram of a security analysis system 100A, which is a first example. In the security analysis system 100A, a security violation analysis program 20P for configuring each processing unit described in the security analysis system 100 of FIG. 1 and an output unit 26 is stored in a storage device 20H. The output unit 26 outputs the processing results of each processing unit in the form of a screen display, file output, or the like. The storage device 20H also stores each data described in the security analysis system 100 of FIG. 1.

[0035] Furthermore, the security violation analysis device 20 of the security analysis system 100A has a hardware configuration for running the security violation analysis program 20P, which includes a CPU 41, memory 42, an input / output interface 43, an input device 44, a display device 45, and an external communications interface 46. The external communications interface 46 is connected to an external device such as the real system 10. The input / output interface 43 is connected to the input device 44 and the display device 45. Furthermore, the CPU 41 controls each processing unit by executing the security violation analysis program 20P loaded into the memory 42. This security violation analysis program 20P can also be distributed via a communications line or recorded on a recording medium such as a CD-ROM and distributed.

[0036] 4 is a configuration diagram of a security analysis system 100B according to the second example. In the security analysis system 100A according to the first example, the various logs (actual business log 11A, attack detection log 11B, and analysis target log 11C) collected by the information collection device 11 were held by the information collection device 11. In the security analysis system 100B according to the second example, the collection unit 27 of the security violation analysis device 20 collects the various logs collected by the information collection device 11 from the information collection device 11 and holds them in the storage device 20H.

[0037] 5 is a configuration diagram of a security analysis system 100C of the third example. In the security analysis system 100A of the first example, one analysis execution device 12 analyzed the analysis target log 11C. In the security analysis system 100A of the third example, there are multiple analysis execution devices 12. The generation unit 24 then references the analysis rule notation 37 to generate an analysis rule 36 corresponding to each analysis execution device 12.

[0038] 6 is a flowchart showing the main processing of the security analysis system 100. The calculation unit 21 calculates the actual operation status 32 from the actual operation log 11A (S101), and calculates the simulated operation status 33 using the attack detection log 11B and the simulated system 31 (S102). The comparison unit 22 compares the actual operation status 32 of S101 with the simulated operation status 33 of S102 and presents the comparison result to the user via the output unit 26 (S103). The comparison unit 22 then determines whether or not there is a significant difference in the comparison result of S103 (S104). If the answer to S104 is No, the comparison unit 22 terminates the processing; if the answer is Yes, the processing proceeds to S105.

[0039] The estimation unit 23 uses the simulated system 31, the attack method DB 34, and the history information 35 to estimate the details of attacks that have not been detected or have been falsely detected in the real system 10 (S105). The generation unit 24 creates an analysis rule 36 for confirming the presence or absence of an IoC for the attack details estimated in S105 (S106). The analysis unit 25 inputs the analysis rule 36 generated in S106 to the analysis execution device 12 and executes an IoC analysis from the analysis target log 11C in the real system 10 (S107). As a result of the analysis in S107, the analysis unit 25 determines whether an IoC exists in the real system 10 (analysis target log 11C) (S108). If the answer is Yes in S108, the analysis unit 25 terminates the process; if the answer is No, the analysis unit 25 updates the history information 35 (S109) and returns the process to S105.

[0040] FIG. 7 is a screen diagram showing a first example of an individual comparison screen for operation status presented to the user in S103. The comparison unit 22 displays a time series graph (solid line graph) of the actual operation status 32 and a time series graph (dashed line graph) of the simulated operation status 33, aligned in time series, for the "production rate of product A" individually selected from the list of features, so that they can be compared. This graph display allows the administrator to confirm that the operation statuses for the production rate of product A match, and therefore that cyberattacks on devices related to product A have been detected without omission. The administrator can also click the statistical information button to transition to the "Operation Status Statistical Information" screen shown in FIG. 10.

[0041] FIG. 8 is a screen diagram illustrating a second example of the individual comparison screen for operation statuses presented to the user in S103. The comparison unit 22 confirms that the solid line graph of the actual operation status 32 and the dashed line graph of the simulated operation status 33 are inconsistent after 17:00 for the “production rate of product B” individually selected from the feature list. Note that while a decline in production rate occurred after 17:00 in the actual operation status 32, the decline in production rate did not occur after 17:00 in the simulated operation status 33. Here, if a production device is damaged by a cyberattack, causing a decline in production rate, the screen display in FIG. 8 suggests that the simulated operation status 33 (or the simulated attack details used to generate it) did not detect the cyberattack that actually occurred in the actual operation status 32. In this case, for example, the analysis unit 25 predicts a cyberattack that actually occurred in the actual operation status 32 and updates the history information 35 (or the simulated attack details) to newly include the cyberattack in the simulated attack details (S109).

[0042] Fig. 9 is a graph showing an example of calculation of the match rate by the comparison unit 22. The graph in Fig. 9 is obtained by adding the following calculation parameters to the graph in Fig. 8: X(t) = actual operating status 32 Y(t) = simulated operating status 33 D = maximum error between X(t) and Y(t) T = time interval during which X(t) and Y(t) do not match τ = simulation time Here, (Formula 1) is an equation that expresses the match rate as a numerical value between 0% and 100%, and the match rate can be defined as a function proportional to D x T.

[0043]

[0044] The comparison unit 22 calculates the match rate for each feature based on Equation 1 and sets the average value as the match score. Alternatively, if the comparison unit 22 wants to emphasize a specific feature, it may calculate the match score by multiplying the match rate associated with that feature by a coefficient that places a higher weight on the match rate associated with that feature (weighting the feature that the comparison unit 22 wants to emphasize).

[0045] FIG. 10 is a diagram of the statistical information screen for the operation status presented to the user in S103. The statistical information screen displays the display information of the individual comparison screens, such as those in FIGS. 7 and 8, in a consolidated view, and includes the following elements: The summary table on the individual comparison screen displays the match rate (%) and the start date and time of the mismatch for each individual feature. As described in FIG. 9, the match score is a representative value summarizing the match rate for each feature. The higher the value, the higher the match between the actual operation status 32 and the simulated operation status 33. The target score is a target value for the match score that can be edited via a text box. If the match score is greater than or equal to the target score, the comparison unit 22 determines that the comparison result in S103 is not significant (No in S104). The individual comparison button is a button for returning to the individual comparison screen, such as those in FIGS. 7 and 8. The start mismatch factor estimation button is a button for starting the process of estimating the attack details (S105, see FIG. 11 for details) by the estimation unit 23.

[0046] FIG. 11 is a flowchart showing the details of the process (S105) performed by the estimation unit 23 to estimate the attack details. The estimation unit 23 uses the history information 35 and the attack method DB 34 to estimate the simulated attack details (S201), as shown in the following example. As cyber-attacks that cannot be detected, attacks without a circle in the attack detection correspondence table (described later in FIG. 16) (such as forced shutdown of a control device) are preferentially selected because they are likely to have been missed. As cyber-attacks that are correlated in terms of chronological order with multiple detected cyber-attacks, for example, if a brute force attack (attack ID = 1) and an attack evidence destruction (attack ID = 3) are recorded as shown in FIG. 14, it can be inferred that an attack such as a process forced termination (attack ID = 2) occurred during the time between them. Furthermore, the time of the attack can be inferred in more detail from the actual operation status 32. As cyber-attacks learned through reinforcement learning, for example, simulated attack details that can achieve a higher matching score are learned. Furthermore, if an incorrect simulated attack affects an unrelated feature (such as the production volume of product C), a negative reward may be given and the next simulated attack may be attempted at that point. Attack details that have already been recorded in the history information 35 are not selected, as it is obvious that they will fail. Alternatively, the estimation unit 23 may use the cyber attack detected as the attack detection log 11B as the simulated attack details in S201.

[0047] The estimation unit 23 calls the calculation unit 21 and calculates the simulated operation status 33 using the simulated attack details estimated in S201 and the simulated system 31 (S202). The estimation unit 23 calls the comparison unit 22 and has it calculate a match score based on the actual operation status 32 and the simulated operation status 33 (S203). The estimation unit 23 updates the simulated attack details in the history information 35 to those estimated in S201 (S204), and determines whether the match score of the updated simulated attack details exceeds the target match score (S205). If the answer is Yes in S205, the estimation unit 23 ends the process, and if the answer is No, the process returns to S201.

[0048] FIG. 12 is a screen diagram showing a list of analysis results by the analysis unit 25. The screen of FIG. 12 shows a table showing the list of analysis results, which associates the simulated attack details (attack ID, date and time, device, attack method) inferred by the estimation unit 23 with the analysis information (analysis status, correction details) resulting from the analysis performed by the analysis unit 25 using the analysis rules 36. The attack IDs in FIG. 12 correspond to the same numbers as the history IDs in the history information 35 in FIGS. 18 and 19. Assume that the administrator selects the attack ID to be analyzed from a pull-down menu (selecting "2" in the figure) and clicks the "Perform Analysis" button. In this case, the analysis unit 25 transitions to the setting screen of FIG. 13 for analyzing whether the attack with the selected attack ID = 2 actually occurred.

[0049] FIG. 13 is a screen diagram showing a setting screen for analysis by the analysis unit 25. The analysis unit 25 displays the range of intrusion traces of a cyber attack on the screen as shown in FIG. 13 and accepts input to confirm the presence or absence of intrusion traces. If no intrusion traces are present, the analysis unit 25 causes the estimation unit 23 to update the simulated attack details. The setting screen in FIG. 13 includes, from top to bottom, an attack information column 301, an analysis rule 36 editing column 302, and an analysis result column 303. Similar to FIG. 12, the attack information column 301 is a table that associates simulated attack details (attack ID, date and time, device, attack method) with analysis information (analysis status, correction details), and the record for the selected attack ID = 2 is extracted. Note that although the attack detection log 11B is recorded in the analysis status column, there is a possibility that a corresponding IoC was not found, resulting in a false positive. In this example, since an IoC was found, the status is switched to IoC confirmation. The input to switch is also reflected in the history information 35. In addition, if there is a discrepancy between the simulated attack details and the IoC that was actually discovered, the administrator is prompted to enter that information in the correction details field. In this example, the event occurred at 14:17, not 14:00, so the administrator is prompted to enter that correction information.

[0050] The analysis rule 36 editing field 302 has a text box for writing the analysis rule 36, an edit button, and an execute button. The analysis rule 36 output from the generation unit 24 is substituted for the initial value of the text box. The administrator can click the edit button to enter a mode for changing the contents of the text box, and manually edit the analysis rule 36 to fine-tune it. When the administrator clicks the execute button, the analysis unit 25 sends the analysis rule 36 written in the text box to the analysis execution unit 12. The analysis execution unit 12 extracts log information corresponding to the analysis rule 36 from the analysis target log 11C of the real system 10, and returns the extracted log information to the analysis unit 25.

[0051] The format for describing an analysis rule 36 for extracting a log corresponding to a recording time "zzz" from a log "xxx" on a device "yyy" is as follows: "search log_xxx from device_yyy time zzz" Furthermore, the analysis rule 36 for finding an attack record of "a log recorded when a process on a monitoring server is forcibly terminated" (see FIG. 16) is as follows: "search log -device_name "monitoring server A" --event_type_id 12345 --time_from 20XX-01-14 13:00 --time_to 20XX-01-14 15:00" Here, since the format of the analysis rule 36 may differ for each vendor, the analysis unit 25 may utilize generation AI to absorb (convert the format) the differences in how the analysis rule 36 (log search statement) is written, which differ for each vendor.

[0052] The analysis result column 303 is a column that displays the log information (corresponding data between the log recording time and the log content) returned from the analysis execution device 12. In the example of FIG. 13 , an IoC of an attack corresponding to the simulated attack content attack ID = 2 was discovered in the line with "CRITICAL" written at the beginning of the log content. After confirming this IoC, the administrator switches the radio button in the analysis status column of the attack information column 301 from "analysis not performed" to "IoC confirmed." Such an update result of the attack information column 301 (analysis information) is reflected on the analysis result list screen of FIG. 12 from the setting screen of FIG. 13 .

[0053] 14 is a table showing an example of the actual work log 11A. The actual work log 11A recorded in the actual system 10 associates the product type with the manufacturing record (dates and times of assembly completion, inspection completion, packaging completion, and shipping preparation completion) for each product ID. The simulated work log recorded in the simulated system 31 also has the same format as the actual work log 11A.

[0054] 15 is a table showing an example of the attack detection log 11B. The attack detection log 11B associates the circumstances under which the attack occurred (date and time, device), the attack method, and the detection source. The detection source may be, for example, a host-based intrusion detection system (HIDS) or a network-based intrusion detection system (NIDS), which are the cyber-attack detection devices (not shown) described in FIG. 1.

[0055] 16 is a table showing an example of the attack technique DB 34. The attack technique DB 34 associates an attack detection correspondence table with an attack record for each attack technique. The attack detection correspondence table is a table showing the attack detection response status of the cyber-attack detection device, and is either fully supported (marked with a circle), partially supported (marked with a triangle), or not supported (blank). The attack record shows an example of what kind of log is recorded as an IoC when an attack is made using the corresponding attack technique.

[0056] 17 is a table showing an example of the actual operation status 32. The actual operation status 32 associates, as feature quantities for each date and time, numerical feature quantities (production rates of product A, product B, and product C) with feature quantities evaluated using a binary value of True or False (quality assurance and remote monitoring). The simulated operation status 33 has the same format as the actual operation status 32.

[0057] FIG. 18 is a table showing an example of the history information 35. The history information 35 is information that associates simulated attack details (date and time, device, attack method), analysis information (analysis status, correction details), and a match score for each history ID, and can also be called past failure information. The simulated attack details for history ID = 1 were obtained by the calculation unit 21 from the attack detection log 11B, and three types of cyber attacks were detected with time differences. However, the match score is low at "65" (less than the threshold "98"), suggesting the existence of actual cyber attacks that were not detected or were falsely detected.

[0058] 19 is a table showing an example of the history information 35, and is a diagram continuing from FIG. 18. In the record with history ID=10, the estimation unit 23 added two new attack methods (process forced termination and control device forced termination) to the simulated attack content of history ID=1 (updating process of simulated attack content in S204). Then, the administrator was able to confirm each attack other than "control device forced termination on PLC B" from the analysis result column 303 in FIG. 13.

[0059] In the record with history ID = 15, the estimation unit 23 updated the simulated attack content of history ID = 10 from "Forced termination of control device on PLC B" to "Forced termination of process on control server B" (S204). The administrator could then confirm "Forced termination of process on control server B" from the analysis result column 303 in FIG. 13 . As a result, the match score became 100 (full marks), and the actual cyber-attack and the simulated attack content perfectly matched. With this match score = 100 (or a match score higher than a predetermined score, such as > 98), the estimation unit 23 may compare the simulated attack content with the detected cyber-attack and, based on the difference between the simulated attack content and the detected cyber-attack, extract a predetermined cyber-attack (an undetected or falsely detected actual cyber-attack).

[0060] Furthermore, the estimation unit 23 may evaluate the performance of a device that detects cyber-attacks in the real system 10 based on the comparison results of the comparison unit 22. For example, the estimation unit 23 intentionally generates a real cyber-attack in the real system 10 using a penetration test or the like, and evaluates the performance of the cyber-attack detection device installed in the real system 10 based on the comparison results between the real cyber-attack (actual operation status 32) and the detected cyber-attack (simulated operation status 33). The estimation unit 23 calculates one of the following values ​​as a performance evaluation value and outputs the calculation result to the output unit 26: - A match score between the actual operation status 32 and the simulated operation status 33. The higher this match score, the higher the performance of the cyber-attack detection device. - A false negative rate, which increases as the number of undetected cyber-attacks increases. The lower this false negative rate, the higher the performance of the cyber-attack detection device. - A false positive rate, which increases as the number of falsely detected cyber-attacks increases. The lower this false positive rate, the higher the performance of the cyber-attack detection device.

[0061] The security breach analysis device 20 of the present embodiment described above compares the actual operation status 32 calculated from the actual operation log 11A of the actual system 10 subjected to a real cyber-attack with the simulated operation status 33 calculated from the simulated operation log of the simulated system 31 and the simulated attack details, and infers the attack details (predetermined cyber-attack) that will fill the gap. By comparing the actual operation status 32 and the simulated operation status 33 in chronological order (aligning the time axes as shown in Figures 7 and 8), the security breach analysis device 20 can create analysis rules 36 that take into account the location and time of the event. When a cyber-attack occurs, the scope of the attack's impact can be identified through breach analysis using the analysis rules 36, allowing the threat to be quickly contained and damage minimized.

[0062] Furthermore, the present invention is not limited to the above-described embodiments, and various other applications and modifications are possible without departing from the spirit of the present invention as set forth in the claims. For example, the above-described embodiments provide detailed and specific descriptions of the configuration of the security intrusion analysis device 20 in order to clearly explain the present invention, and are not necessarily limited to devices that include all of the components described. Furthermore, it is possible to replace part of the configuration of one embodiment with a component of another embodiment. It is also possible to add a component of another embodiment to the configuration of one embodiment. It is also possible to add, replace, or delete other components from part of the configuration of each embodiment.

[0063] Furthermore, some or all of the above-described configurations, functions, processing units, etc. may be implemented in hardware, for example, by designing them as integrated circuits. Broad processor devices such as FPGAs (Field Programmable Gate Arrays) and ASICs (Application Specific Integrated Circuits) may also be used as hardware. Furthermore, each component of the security breach analysis device 20 according to the above-described embodiment may be implemented in any hardware as long as the respective hardware can transmit and receive information to and from each other via a network. Furthermore, the processing performed by a certain processing unit may be implemented by a single piece of hardware, or may be implemented by distributed processing using multiple pieces of hardware.

[0064] DESCRIPTION OF SYMBOLS 10 Actual system 11 Information collection device 11A Actual business log 11B Attack detection log 11C Analysis target log 12 Analysis execution device 20 Security infringement analysis device 21 Calculation unit 22 Comparison unit 23 Estimation unit 24 Generation unit 25 Analysis unit 26 Output unit 27 Collection unit 31 Simulation system 32 Actual operation status 33 Simulation operation status 34 Attack method DB 35 History information 36 Analysis rule 37 Analysis rule notation 100 Security analysis system

Claims

1. A security intrusion analysis device comprising: a calculation unit that calculates the actual operating status from the actual business log recorded in the actual system to be analyzed, and calculates the simulated operating status when a cyber-attack detected in the actual system is executed as the simulated attack content on a simulated system that simulates the actual system; a comparison unit that compares the actual operating status with the simulated operating status; an estimation unit that, based on the comparison result of the comparison unit, estimates a specified cyber-attack that is inconsistent between the cyber-attack that occurred in the actual system and the cyber-attack detected in the actual system; and an output unit that outputs at least one piece of information from the comparison result of the comparison unit and information about the specified cyber-attack estimated by the estimation unit.

2. The security intrusion analysis device according to claim 1, wherein the calculation unit calculates the actual operation status and the simulated operation status as one or more feature quantities that indicate the system operation status and are defined in a time series.

3. The security intrusion analysis device according to claim 2, wherein the comparison unit generates a comparison result including the location and time of the cyber-attack by comparing the feature quantities of the actual operation status with the feature quantities of the simulated operation status in chronological order.

4. The security intrusion analysis device of claim 2, wherein the inference unit infers that a cyber-attack that actually occurred in the real system but went undetected is the specified cyber-attack when an abnormal value of the feature due to a cyber-attack is observed in the actual operating condition and a normal value of the feature is observed in the simulated operating condition.

5. The security intrusion analysis device of claim 2, wherein the inference unit infers that a cyber-attack that did not actually occur in the real system but was falsely detected is the specified cyber-attack when a normal value of the feature is observed in the actual operating condition and an abnormal value of the feature due to a cyber-attack is observed in the simulated operating condition.

6. The security intrusion analysis device according to claim 1, wherein the estimation unit updates the simulated attack content and causes the calculation unit to recalculate the simulated operation status so that the actual operation status and the simulated operation status coincide more closely as a result of the comparison by the comparison unit.

7. The security intrusion analysis device described in claim 6, wherein the estimation unit updates the simulated attack content with at least one of a cyber attack that cannot be detected by the actual system, a cyber attack that is correlated in a chronological order with multiple detected cyber attacks, and a cyber attack learned by reinforcement learning.

8. The security intrusion analysis device according to claim 6, further comprising a generation unit that generates analysis rules for detecting intrusion traces of the specified cyber-attack inferred by the inference unit from the analysis target log of the actual system, and the generation unit generates the analysis rules by referring to attack records that indicate the characteristics of intrusion traces caused by each cyber-attack in the past.

9. The security intrusion analysis device according to claim 8, further comprising an analysis unit that uses the analysis rules generated by the generation unit to extract the range of traces of intrusion of the specified cyber-attack inferred by the inference unit from the analysis target log of the real system.

10. The security intrusion analysis device described in claim 9, wherein the analysis unit displays on a screen the extent to which traces of intrusion from a cyber attack exist, accepts input to confirm the presence or absence of traces of intrusion, and if no traces of intrusion exist, causes the estimation unit to update the details of the simulated attack.

11. The security intrusion analysis device according to claim 1, wherein the estimation unit performs a performance evaluation of the device for detecting cyber attacks in the real system based on the comparison results of the comparison unit.

12. A security breach analysis device comprising a calculation unit, a comparison unit, an estimation unit, and an output unit, wherein the calculation unit calculates the actual operating status from the actual business log recorded in the actual system to be analyzed, and also calculates a simulated operating status when a cyber-attack detected in the actual system is executed as the simulated attack content on a simulated system that simulates the actual system, the comparison unit compares the actual operating status with the simulated operating status, the estimation unit estimates a specified cyber-attack that is inconsistent between the cyber-attack that occurred in the actual system and the cyber-attack detected in the actual system based on the comparison result of the comparison unit, and the output unit outputs at least one of information from the comparison result of the comparison unit and information about the specified cyber-attack estimated by the estimation unit.

13. A system comprising a real system and a security intrusion analysis device, wherein the real system comprises: an information collection device that collects real business logs and analysis target logs recorded in the real system to be analyzed, and information on cyber-attacks detected in the real system; an analysis execution device that executes an analysis process to extract, from the analysis target logs, an area where there are traces of intrusion of a predetermined cyber-attack that are inconsistent between the cyber-attack that occurred in the real system and the information on the cyber-attack detected in the real system, using analysis rules; and the security intrusion analysis device comprises: a calculation unit that calculates a real operation status from the real business log provided by the information collection device, and calculates a simulated operation status when executed on a simulated system that simulates the real system as a simulated attack content indicating the cyber-attack information provided by the information collection device; a comparison unit that compares the real operation status with the simulated operation status; an estimation unit that infers the predetermined cyber-attack based on the comparison result of the comparison unit; and a generation unit that generates the analysis rule to be used in the analysis process of the predetermined cyber-attack inferred by the estimation unit. a security analysis system comprising: an analysis unit that provides the analysis rule generated by the generation unit to the analysis execution device, thereby causing the analysis execution device to execute the analysis process; and an output unit that outputs at least one piece of information among information on the comparison results of the comparison unit, information on the specified cyber attack inferred by the inference unit, and information on the result of the analysis unit causing the analysis execution device to execute the analysis process.

Citation Information

Patent Citations

  • Communication control system and information processing apparatus

    JP2022044964A

  • Rule generation device, rule generation method, and computer readable storage medium

    WO2020246227A1

  • Method, systems and apparatus for intelligently emulating factory control systems and simulating response data

    WO2023043623A1