Equipment management device and equipment management system
The device management system addresses the challenge of differentiating security operations from cyberattacks in IoT devices by using a log management and alert control system to suppress false detections, ensuring secure and efficient operation.
Patent Information
- Application Number
- PCT/JP2024/045853
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-29
- Filing Date
- 2024-12-25
- Publication Date
- 2025-10-02
AI Technical Summary
Existing IoT devices face challenges in distinguishing between security operations and cyberattacks, leading to false detections and increased administrative burdens due to the difficulty in differentiating simulated attacks from actual cyber threats.
A device management system that includes a log management unit, a detection unit to identify suspicious operations, and an alert control unit to differentiate between security measures and cyberattacks, suppressing false alerts by comparing operation logs with pre-registered security measure permission information.
Enables secure security operations without false cyberattack detections, reducing the administrative burden by accurately identifying legitimate security measures and blocking unauthorized actions.
Smart Images

Figure JP2024045853_02102025_PF_FP_ABST
Abstract
Description
Equipment management device and equipment management system
[0001] The present invention relates to a device management device and a device management system.
[0002] The so-called "Internet of Things" (IoT), which gives communication capabilities to devices (things) that were previously not connected to networks such as the Internet, and enables them to connect to networks and operate, is rapidly spreading. However, with the spread of IoT, there are concerns about an increase in damage caused by cyber attacks on IoT devices via networks, and it is therefore important to establish more secure security measures.
[0003] A known prior art technique related to computer security measures is described in, for example, Patent Document 1. Patent Document 1 discloses an intrusion detection device for a computer that detects unauthorized intrusions into a monitored program, the intrusion detection device including: a storage means for storing system calls in the absence of unauthorized intrusions into the monitored program in association with path information to the system calls; an acquisition means for acquiring information indicating the system call and the path information to the system call when a system call is requested by execution of the monitored program; a determination means for determining whether the information indicating the requested system call and the path information to the system call match the stored system call and the path information corresponding to the system call; and an execution means for executing the requested system call when the determination means determines that they match.
[0004] Japanese Patent Application Laid-Open No. 2006-106939
[0005] For IoT devices that are used for business purposes over the long term, remote monitoring, strengthening countermeasures, and regular diagnostics are essential for maintaining security. However, these security operations require the implementation of simulated attacks and configuration changes on IoT devices, which are difficult to distinguish from cyberattacks. As a result, IoT device behavior associated with security operations is often mistakenly detected as a cyberattack, increasing the response burden on IoT device administrators who receive notifications of detected cyberattacks.
[0006] The present invention has been made in consideration of the above, and aims to provide a device management device and a device management system that can carry out security operation tasks while suppressing false detection of cyber attacks on IoT devices.
[0007] The present application includes multiple means for solving the above-mentioned problems. One example is a device management device that is connected to a plurality of IoT devices via a network and manages the plurality of IoT devices, the device including: a log management unit that collects logs related to the operation of the plurality of IoT devices via the network; a detection unit that detects an operation that is preset as a suspicious operation for each of the plurality of IoT devices based on the log; a determination unit that, when the suspicious operation is detected in at least one of the plurality of IoT devices, determines whether the detected suspicious operation is an operation caused by a security measure for the IoT device; and an alert control unit that, when it is determined that the suspicious operation is an operation caused by the security measure, controls not to output an alert to a user or administrator of the IoT device in which the suspicious operation was detected, and, when it is determined that the suspicious operation is not an operation caused by the security measure, controls to output the alert to the user or administrator of the IoT device.
[0008] According to the present invention, security operations can be carried out while suppressing false detection of cyber attacks on IoT devices.
[0009] 1 is a diagram schematically illustrating the overall configuration of a device management system according to a first embodiment; FIG. 2 is a diagram illustrating an example of the operation of the device management system, and is a diagram illustrating an attack detection operation in an attack detection unit of a device management device, extracted together with related operations; FIG. 3 is a diagram illustrating an example of transition of a registration operation screen displayed by a management application that supports the registration and management of security measure permission information; FIG. 4 is a diagram illustrating an example of a security measure permission list in which security measure permission information is registered; FIG. 5 is a diagram illustrating an abnormality determination sequence for IoT devices; FIG. 6 is a diagram illustrating an example of a log sent from an IoT device to a device management device; FIG. 7 is a diagram illustrating an example of an alert screen displayed on a maintenance staff PC 300 that has received an abnormality alert; FIG. 8 is a diagram illustrating an example of an alert screen displayed on a maintenance staff PC 300 that has received an abnormality alert; FIG. 9 is a diagram illustrating an example of an alert screen displayed on a maintenance staff PC 300 that has received an abnormality alert;
[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0011] First Embodiment A first embodiment of the present invention will be described with reference to FIGS.
[0012] FIG. 1 is a diagram showing an outline of the overall configuration of a device management system according to the present embodiment.
[0013] In Figure 1, the device management system manages multiple IoT devices connected via a network, and is roughly composed of multiple IoT devices to be managed (here, IoT device 200 is shown as a representative), a device management device 100 connected to the multiple IoT devices via a device management network 1, and a maintenance worker PC 300, which is an information terminal used by a user or administrator of the IoT device 200 and is connected to the device management device 100 via an information network 2.
[0014] The IoT device 200 includes a communication unit 230 that connects the IoT device 200 to the device management network 1, a log management unit 220 that collects logs related to the operation of the IoT device 200, and a control unit 210 that controls the operation of the IoT device 200 and transmits the logs related to the operation collected by the log management unit 220 from the communication unit 230 to the device management device 100 via the device management network 1.
[0015] The IoT device 200 is a device (thing) that operates by connecting to a network such as the Internet via a communication function and is compatible with the so-called "Internet of Things" (IoT). Examples of the IoT device 200 include medical devices including testing and analysis equipment, control and information devices installed in automobiles, and field devices that make up the control systems of plants, etc.
[0016] In this embodiment, IoT device 200 will be shown and described as representing the multiple IoT devices to be managed (referred to as an IoT device group as necessary), but the other IoT devices also have a configuration similar to IoT device 200, and each is connected to device management device 100 via device management network 1, and is managed by sending and receiving data such as operation logs and permission to execute security measures (described later) to and from device management device 100.
[0017] The maintenance staff PC 300 is an information terminal used by a user or administrator of the IoT device 200, and is equipped with a communication unit 320 that connects the maintenance staff PC 300 to the information network 2, and an alert notification unit 310 that notifies the user or administrator of information such as alerts received from the equipment management device 100 via the information network 2.
[0018] The alert notification unit 310 includes, for example, a display device such as a monitor, and displays various information related to the maintenance of the IoT device 200 in addition to information such as alerts.
[0019] The device management device 100 manages multiple IoT devices (IoT devices 200) connected via the device management network 1, and includes a communication unit 110 that connects the device management device 100 to the device management network 1 and the information network 2, an authentication unit 120 that performs so-called user authentication, determining whether the user using the IoT device 200 is a legitimate user based on user authentication information registered in a user authentication table 121, and permitting use after confirming that the user is a legitimate user, a log management unit 130 that collects logs related to the operation of the IoT device 200 via the device management network 1 and records them in a collected log management table 131, a device management unit 140 that calls up identification information of the IoT devices that are managed by the device management device 100 from the device management table 141, and an attack detection unit 150 that detects operations that have been preset as suspicious operations for each of the multiple IoT devices 200 based on the logs.
[0020] The attack detection unit 150 is a functional unit that performs attack detection by detecting suspicious behavior of the IoT device 200 as an attack, etc., and has the following functional units: a countermeasure permission information registration unit 151, a countermeasure permission determination unit 152, a security countermeasure permission list 153, and an alert output control unit 154.
[0021] Based on the operation of the administrator of the device management system, the countermeasure permission information registration unit 151 registers and manages the identification information of the IoT device 200 that is the target of attack detection in the security countermeasure permission list 153, and registers and manages security countermeasure permission information that includes the identification information of the IoT device 200 that is the target of security countermeasure implementation and the content of the security countermeasure in the security countermeasure permission list 153.
[0022] When a suspicious behavior is detected in at least one of the multiple IoT devices 200, the countermeasure permission determination unit 152 determines, based on security measure permission information registered in advance in the security measure permission list 153, whether the detected suspicious behavior is an behavior caused by a security measure for the IoT device 200. When the detected suspicious behavior matches the information registered in the security measure permission list 153, the countermeasure permission determination unit 152 outputs permission to implement the security measure to the IoT device 200. When the detected suspicious behavior does not match the information registered in the security measure permission list 153, the countermeasure permission determination unit 152 outputs an instruction to stop the security measure to the IoT device 200.
[0023] If the countermeasure permission determination unit 152 determines that the suspicious behavior is an operation caused by a security measure, the alert output control unit 154 controls so that an alert is not output to the user or administrator (maintenance staff PC 300) of the IoT device 200 in which the suspicious behavior was detected, and if it determines that the suspicious behavior is not an operation caused by a security measure, the alert output control unit 154 generates and outputs an alert to the user or administrator (maintenance staff PC 300) of the IoT device 200.
[0024] Note that networks such as the device management network 1 and the information network 2 include, but are not limited to, the Internet. The device management network 1 can collect logs from IoT devices and transmit permission to implement security measures, and the information network 2 can be any network that can output and send alerts when suspicious (abnormal) behavior of IoT devices is detected, and may be, for example, an in-facility network for managing in-facility devices. Furthermore, the device management network 1 and the information network 2 do not need to be different networks, and may be configured to connect the device management device 100, IoT devices 200, and maintenance personnel PC 300 to the same network.
[0025] FIG. 2 is a diagram showing an example of the operation of the device management system, and is a diagram showing an attack detection operation performed by the attack detection unit of the device management apparatus together with related operations.
[0026] 2 , the administrator of the device management system manages the status of the entire group of registered IoT devices in accordance with requests from device maintenance personnel, and registers and manages security measure permission information. The IoT device maintenance personnel are people who perform security maintenance on IoT devices 200 and are different from the users and administrators of IoT devices 200. An attacker of IoT device 200 is a person who attacks IoT device 200 (performs an action that is not on the security measure permission list).
[0027] In the operation of the device management system, while the administrator of the device management system is registering and managing the entire group of IoT devices including IoT device 200 (step (1)), an IoT device maintenance person (different from the user or administrator) who performs security maintenance on the IoT devices applies to the administrator of the device management system for registration of security measure permission information before implementing the security measures as a preliminary preparation for implementing security measures on IoT device 200 (step (2-1)).
[0028] In response to a request from an IoT device maintenance technician, the device management system administrator registers the security measure permission information in the security measure permission list 153 via the countermeasure permission information registration unit 151 of the attack detection unit 150 (step (2-2)). Note that the request to register the security measure permission information may be made by the IoT device maintenance technician to the crisis management system administrator via email or an application form via the maintenance technician PC 300, or the request may be made offline. Also, the IoT device maintenance technician may register the security measure permission information directly, but registration by a third party other than the device management system administrator and the IoT device maintenance technician is prohibited.
[0029] FIG. 3 shows an example of transition of a registration operation screen displayed by a management application that supports the registration and management of security measure permission information.
[0030] As shown in FIG. 3, the registration operation screen displayed by the management application is made up of screens for performing operations for registering and managing security measures permission information, and is made up of, for example, a top screen S2001, a new registration screen S2002, a list display screen S2003, a change screen S2004, a confirmation screen S2005, and a result screen S2006.
[0031] The top screen S2001 is a screen displayed as the initial screen of the registration operation screen, and is the screen that is displayed first when the management application is launched. On the top screen S2001, when a new IoT device 200 to be the target of security measures is to be registered, a new registration screen S2002 is displayed by selecting a "New Registration" button, and when a list of information on the IoT devices 200 that have already been registered as the target of security measures is to be displayed, a list display screen S2003 is displayed by selecting a "List Display" button.
[0032] The new registration screen S2002 is a screen for newly registering an IoT device 200 for which security measures are to be implemented. The new registration screen S2002 has input fields for each item of information about the IoT device 200 to be newly registered, such as product name, serial number, customer name, validity period, permission details, etc. When newly registering an IoT device 200 on the new registration screen S2002, the user inputs each item and selects a "Register" button to display a confirmation screen S2005. When canceling the new registration and returning to the top screen S2001, the user selects a "Go to Top" button to display the top screen S2001.
[0033] The list display screen S2003 is a screen that displays a list of information about IoT devices 200 that have already been registered as targets for implementing security measures. The list display screen S2003 displays items such as permission ID, product name, serial number, and customer name as information about each registered IoT device 200. On the list display screen S2003, when changing information about an IoT device 200, the information to be changed is selected (e.g., a check box is selected) and a "Change" button is selected to display a change screen S2004. When deleting information about an IoT device 200 (removing it from targets for implementing security measures), the information to be deleted is selected (e.g., a check box is selected) and a "Delete" button is selected to display a confirmation screen S2005. Furthermore, on the list display screen S2003, if a new IoT device 200 to be subject to security measures is to be registered, the new registration screen S2002 is displayed by selecting the "New Registration" button, and if the user wishes to return to the top screen S2001, the top screen S2001 is displayed by selecting the "Go to Top" button.
[0034] The change screen S2004 is a screen for changing the information of an IoT device 200 that has already been registered as a target for implementing security measures, and is provided with input fields for each item of information for the IoT device 200 to be changed, such as product name, serial number, customer name, validity period, permission details, etc. Note that the input fields may display the registered information of the IoT device 200 to be changed, and this content may be changed. On the change screen S2004, when changing information, a confirmation screen S2005 is displayed by inputting each item and selecting the "Change" button, and when canceling the information change and returning to the list display screen S2003, the list display screen S2003 is displayed by selecting the "List Display" button or the "Go to Top" button.
[0035] The confirmation screen S2005 is a screen for final confirmation as to whether or not it is OK to make a new registration or change using the content entered or changed on the new registration screen S2002 or the change screen S2004, or whether or not it is OK to delete information selected for deletion on the list display screen S2003. On the confirmation screen S2005, if a new registration, change, or deletion is to be made, the "OK" button is selected to execute the new registration, change, or deletion, and the result screen S2006 is displayed. Furthermore, if the new registration, change, or deletion is to be canceled and the previous screen is to be returned to, the previously displayed screen (new registration screen S2002, list display screen S2003, or change screen S2004) is displayed by selecting the "Back" button.
[0036] The result screen S2006 is a screen that displays the completion of new registration, change, or deletion of information of the IoT device 200, which is the implementation measure of the security measure. By selecting the "Go to top" button on the result screen S2006, the top screen S2001 is displayed.
[0037] FIG. 4 is a diagram showing an example of a security measure permission list in which security measure permission information is registered.
[0038] 4, the security measure permission list is configured with items such as an authorization ID F3001, a product name F3002, a serial number F3003, a customer name F3004, an IP address F3005, an OSF F3006, a validity period F3007, permission details F3008, and a last update date and time F3009, which serve as security measure permission information for identifying each IoT device 200 that is a target of security measures and the details of the security measures to be implemented (operations resulting from the implementation of the security measures). For example, for an IoT device 200 registered with an authorization ID F3001 of "aaaa," the product name F3002 that identifies the target device is "Device A" and the serial number F3003 is "PR12345." Furthermore, the customer name F3004 that identifies the owner (customer) of the IoT device 200 is "X Hospital," the IP address F3005 is "10.3.1.10," and the installed OS (target software) F3006 is "OS1." The validity period F3007 of the information for which the permission ID F3001 is "aaaa," i.e., the period during which implementation of security measures for the IoT device 200 is permitted, is "2023 / 7 / 1 0:00-2023 / 7 / 14 23:59," and the permission content F3008, which is the content of the operations or behaviors that are permitted to be implemented as security measures, is "Network; eth1; 10.2.2.10; portScan," "Network; eth1; 10.2.2.10; filesize > 1G," and "Network; eth1; 10.2.2.10; DoS." The last update date and time F3009 of the information is "2023 / 6 / 23 11:30".
[0039] By pre-registering the target and implementation details of security measures in the security measure permission list described above as security measure permission information and using this security measure permission information, it becomes possible to determine whether operations on IoT devices (IoT device operations) are security measures or cyberattacks, which is difficult to determine from logs alone. Furthermore, by setting a validity period for the security measure information when registering and disabling security measures outside of that period, actions resulting from cyberattacks (e.g., unauthorized operations on IoT devices by attackers) can be identified and prevented as suspicious, further strengthening security. For example, for operations requiring two-factor authentication, such as changing security settings to disable antivirus software, unauthorized operations (including unauthorized security measures) can be prevented even if an attacker breaks through the two-factor authentication. Furthermore, previously registered security measure permission information is assigned a permission ID and a timestamp showing the creation and update date and time so that it can be viewed as a history for future audit purposes.
[0040] Returning to FIG. 2 , the device management device 100 collects logs from the IoT device 200 (step (3-2)) regarding operations related to maintenance work performed by IoT device maintenance personnel on the IoT device 200 (step (3-1)) and operations related to the implementation of security measures (step (3-1')), and the countermeasure permission determination unit 152 compares the logs with the list of security measure permission information. At this time, the device management device 100 also collects logs from the IoT device 200 (step (3-2'')) regarding unauthorized operations (cyberattacks) by attackers on the IoT device, for example, and compares the logs with the information in the security measure permission list. In other words, the device management device 100 collects logs at all times, regardless of whether the operations are those of the IoT device maintenance personnel or those of the attacker.
[0041] When the collected log is compared with the security measure permission list and any of the security measure permission information in the security measure permission list matches (matches / coincides) with the log, the operation on the IoT device that is the source of the log is determined to be an operation related to an authorized security measure, and permission to execute the security measure is sent to the IoT device, enabling the security measure to be executed (steps (3-3) and (3-3')). On the other hand, when the collected log is compared with the security measure permission list and any of the security measure permission information in the security measure permission list does not match (matches / coincides), the operation on the IoT device that is the source of the log is determined to be an unauthorized security measure (including an operation outside the validity period) or an operation related to a cyber attack (suspicious behavior), and a command not to permit the execution of the security measure or the like is sent to the IoT device, blocking the execution of the security measure or the like in the IoT device (step (3-3')). The alert output control unit 154 generates an abnormality alert and sends it to the maintenance technician PC 300 (step (3-4)).
[0042] Here, the flow of determining an abnormality in an IoT device in the device management system will be described.
[0043] FIG. 5 is a diagram showing an abnormality determination sequence for an IoT device.
[0044] As shown in Figure 5, when the control unit 210 of the IoT device 200 detects operation of the device (operation P5001), the log management unit 220 generates a log (operation P5002), and the log management unit 220 sends it to the device management device 100 via the communication unit 230 (operations P5003, P5004).
[0045] FIG. 6 is a diagram illustrating an example of a log sent from an IoT device to a device management device.
[0046] The logs sent from the IoT device 200 to the device management device 100 include various logs such as an access log D6001, an event log D6002 (security log), and an error log D6003 as shown in Figure 6, and are sent linked to identification information such as the product name and product number of the IoT device 200.
[0047] 5 , the device management apparatus 100 collects logs received from the IoT devices 200 via the communication unit 110 in the log management unit 130 (operation P5005) and analyzes the logs (operation P5006). In analyzing the logs, the device management unit 140 searches for target product information using identification information associated with the logs (product name, product number, etc.) (operation P5007), and acquires product information (customer name, IP address, OS, etc.) (operation P5008). Based on the acquired product information, the device management unit 100 searches the security measures permission list in the attack detection unit 150 (operation P5009). If relevant security measures permission information is found, the security measures permission information is acquired. If relevant security measures permission information is not found, information indicating no match is acquired (operation P5010).
[0048] If there is corresponding security measure permission information in the security measure permission list, the log management unit 130 sends the permission details (product information, validity period, permission details, etc.) included in the security measure permission information to the IoT device 200 via the communication unit 110 (operation P5011, P5012). When the log management unit of the IoT device 200 receives the permission details via the communication unit 230 (operation P5013), it sends permission to implement security measures to the control unit 210 based on the details (operation P5014).
[0049] Furthermore, if there is no corresponding security measure permission information in the security measure permission list (i.e., if information indicating no match is obtained), the log management unit 130 generates an abnormality alert and sends it to the maintenance technician PC 300 via the communication unit (operation P5015).
[0050] 7 to 10 are diagrams showing examples of alert screens that are displayed on the maintenance staff PC 300 when it receives an alert about an abnormality.
[0051] For example, Figure 7 shows an example of the display of an alert screen D7001 when a security diagnosis from the Internet detects an abnormality, and displays the time of occurrence, identification information of the IoT device, details of the abnormality (in this case, a message indicating that a large amount of access from a specific IP address has been detected), as well as information urging immediate contact with the administrator of the device management system.
[0052] Figure 8 shows an example of the display of an alert screen D7002 when a registry change made to enhance security is detected as an abnormality, and displays the time of occurrence, identification information of the IoT device, details of the abnormality (in this case, a message indicating that access to the registry of a specific account has been detected and blocked), as well as information urging immediate contact with the administrator of the device management system.
[0053] Figure 9 shows an example of the display of an alert screen D7003 when temporary disabling of the whitelist for a software update is detected as an abnormality, and displays the time of occurrence, identification information of the IoT device, details of the abnormality (in this case, a message indicating that a stop command to the whitelist of a specific account has been detected), as well as information urging immediate contact with the administrator of the device management system.
[0054] Figure 10 shows an example of the display of an alert screen D7004 when an abnormality is detected in data output for product inspection, and displays the time of occurrence, identification information of the IoT device, details of the abnormality (in this case, a message stating that an attempt to add a file from a USB to a specific account has been detected and blocked), as well as information urging immediate contact with the administrator of the device management system.
[0055] The effects of the present embodiment configured as above will be described.
[0056] For IoT devices that are used for business purposes over the long term, remote monitoring, strengthening countermeasures, and regular diagnostics are essential for maintaining security. However, these security operations require the implementation of simulated attacks and configuration changes on IoT devices, which are difficult to distinguish from cyberattacks. As a result, IoT device behavior associated with security operations is often mistakenly detected as a cyberattack, increasing the response burden on IoT device administrators who receive notifications of detected cyberattacks.
[0057] In contrast, in this embodiment, a device management device that is connected to a plurality of IoT devices via a network and manages the plurality of IoT devices is configured to include a log management unit that collects logs related to the operation of the plurality of IoT devices via the network, a detection unit that detects operations that are pre-set as suspicious operations for each of the plurality of IoT devices based on the logs, a determination unit that, when suspicious operation is detected in at least one of the plurality of IoT devices, determines whether the detected suspicious operation is an operation caused by security measures for the IoT device, and an alert control unit that, when it is determined that the suspicious operation is an operation caused by security measures, controls not to output an alert to the user or administrator of the IoT device in which the suspicious operation was detected, and, when it is determined that the suspicious operation is not an operation caused by security measures, controls to output an alert to the user or administrator of the IoT device.Therefore, security operation tasks can be carried out while suppressing false detections of cyber attacks on IoT devices.
[0058] Second Embodiment A second embodiment of the present invention will be described with reference to FIG.
[0059] In this embodiment, log collection and determination of whether to allow countermeasures are performed by each IoT device. In this embodiment, the same components as those in the first embodiment are denoted by the same reference numerals, and descriptions thereof will be omitted as appropriate.
[0060] FIG. 11 is a diagram showing an outline of the overall configuration of a device management system according to this embodiment.
[0061] In Figure 11, the equipment management system is roughly composed of multiple IoT devices to be managed (here, IoT device 200A is shown as a representative), an equipment management device 100A connected to the multiple IoT devices via an equipment management network 1, and a maintenance worker PC 300 connected to the equipment management device 100 via an information network 2.
[0062] The IoT device 200A has a communication unit 230 that connects the IoT device 200A to the device management network 1, a log management unit 220A that collects logs related to the operation of the IoT device 200A and records them in a collected log management table 131A, and a control unit 210 that controls the operation of the IoT device 200A, as well as the following functional units: a countermeasure permission determination unit 152A that is a functional unit that performs attack detection to detect suspicious behavior of the IoT device 200A as an attack, a product-specific security countermeasure permission list 153A, and an alert output control unit 154A.
[0063] When a suspicious operation is detected in IoT device 200A, countermeasure permission determination unit 152A determines whether the detected suspicious operation is caused by a security measure for IoT device 200A, based on security measure permission information for each product pre-registered in product-specific security measure permission list 153A. If the detected suspicious operation matches the information registered in product-specific security measure permission list 153A, it outputs permission to implement the security measure to control unit 210. On the other hand, if the detected suspicious operation does not match the information registered in product-specific security measure permission list 153A, it outputs an instruction to stop the security measure to control unit 210.
[0064] If the countermeasure permission determination unit 152A determines that the suspicious behavior is an operation caused by a security measure, the alert output control unit 154A controls so that an alert is not output to the user or administrator (maintenance staff PC 300) of the IoT device 200A in which the suspicious behavior was detected, and if it determines that the suspicious behavior is not an operation caused by a security measure, the alert output control unit 154A generates an alert and outputs the alert to the user or administrator (maintenance staff PC 300) of the IoT device 200A via the communication unit 230 and the device management device 100A.
[0065] The maintenance staff PC 300 is an information terminal used by a user or administrator of the IoT device 200A, and is equipped with a communication unit 320 that connects the maintenance staff PC 300 to the information network 2, and an alert notification unit 310 that notifies the user or administrator of information such as alerts received from the IoT device 200A via the information network 2 and the device management device 100.
[0066] The alert notification unit 310 includes, for example, a display device such as a monitor, and displays various information related to the maintenance of the IoT device 200A in addition to information such as alerts.
[0067] The device management device 100A manages multiple IoT devices (IoT devices 200A) connected via the device management network 1, and includes a communication unit 110 that connects the device management device 100A to the device management network 1 and the information network 2, an authentication unit 120 that performs user authentication, determining whether the user using the IoT device 200 is a legitimate user based on user authentication information registered in a user authentication table 121, and permitting use after confirming that the user is a legitimate user, a device management unit 140 that calls up identification information of the IoT devices that are the management targets of the device management device 100A from the device management table 141, and an attack detection unit 150A that performs some functions, such as managing security measure permission information used to detect attacks performed by the IoT device 200.
[0068] The attack detection unit 150A has a countermeasure permission information registration unit 151 and a security countermeasure permission list 153. Based on the operation of the administrator of the device management system, the countermeasure permission information registration unit 151 registers and manages the identification information of the IoT device 200 that is the target of attack detection in the security countermeasure permission list 153, and registers and manages security countermeasure permission information, including the identification information of the IoT device 200 that is the target of security countermeasures and the details of the security countermeasures, in the security countermeasure permission list 153. The countermeasure permission information registration unit 151 also distributes the security countermeasure permission information of each IoT device 200 that is the target of management to each IoT device 200 and registers it in the product-specific security countermeasure permission list 153A. In other words, each IoT device 200 only has security countermeasure permission information related to itself. It is desirable that the security countermeasure permission information registered in the security countermeasure permission list 153 or the security countermeasure permission list 153 (DB) be encrypted. In addition, in order to prevent tampering or duplication of the security measures permission information when it is sent from the device management device 100A to the IoT device 200, it is desirable to use a communication method that can assign a "digital signature" and a "nonce (disposable random number)" to the security measures permission information when it is sent.
[0069] In the operation of the device management system according to the present embodiment configured as described above, while the administrator of the device management system is registering and managing the entire group of IoT devices, including IoT device 200A, an IoT device maintenance person (different from the user or administrator) who performs security maintenance on the IoT devices requests the administrator of the device management system to register security measure permission information before implementing the security measures as advance preparation for implementing security measures on IoT device 200A. In response to the request from the IoT device maintenance person, the device management system administrator registers the security measure permission information in security measure permission list 153 via measure permission information registration unit 151 of attack detection unit 150A. In addition, measure permission information registration unit 151 distributes information on security measures implemented by each IoT device 200A (security measure permission information).
[0070] The IoT device 200A collects logs of operations performed by maintenance personnel on the IoT device 200A related to maintenance work on the IoT device 200A and operations related to the implementation of security measures, and the countermeasure permission determination unit 152A compares the logs with the product-specific security measure permission information registered in the product-specific security measure permission list 153A. At this time, logs are also collected for unauthorized operations (cyberattacks) by an attacker on the IoT device 200A, for example, and compared with the security measure permission information in the product-specific security measure permission list 153A. In other words, the collection of logs for the IoT device 200A is always performed regardless of whether the operations are those of a maintenance personnel or an attacker on the IoT device.
[0071] When the collected log is compared with the security measure permission information in the product-specific security measure permission list 153A and the security measure permission information matches (conforms / matches) the log, the operation on the IoT device that is the source of the log is determined to be an operation related to a permitted security measure, and permission to execute the security measure is sent to the control unit 210, allowing the security measure to be executed. Also, when the collected log is compared with the security measure permission information and the security measure permission information does not match (conforms / matches) the log, the operation on the IoT device 200A that is the source of the log is determined to be an unauthorized security measure (including an operation outside the validity period) or an operation related to a cyber-attack (suspicious behavior), and a command to not permit the implementation of the security measure is sent to the control unit 210, blocking the execution of security measures, etc. in the IoT device 200. The alert output control unit 154A generates an abnormality alert and sends it to the maintenance technician PC 300 via the device management device 100A.
[0072] The other configurations are the same as those of the first embodiment.
[0073] The present embodiment configured as above can also achieve the same effects as the first embodiment.
[0074] Furthermore, by configuring registration in the security measures permission list 153 to be performed on the equipment management device 100A, or by configuring additional authentication to be performed at the time of registration and providing concentrated defense on the equipment management device 100A side, it is possible to more reliably prevent attackers from performing fraudulent registration operations, and the security measures permission list 153 can be stored safely.
[0075] <Notes> The present invention is not limited to the above-described embodiments, and includes various modifications and combinations within the scope of the gist thereof. Furthermore, the present invention is not limited to those including all of the configurations described in the above-described embodiments, and also includes those in which some of the configurations are omitted. Furthermore, the above-described configurations, functions, etc. may be realized in part or in whole by designing them as, for example, integrated circuits. Furthermore, the above-described configurations, functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function.
[0076] 1...Device management network, 2...Information network, 100, 100A...Device management device, 110...Communication unit, 120...Authentication unit, 121...User authentication table, 130...Log management unit, 131, 131A...Collected log management table, 140...Device management unit, 141...Device management table, 150, 150A...Attack detection unit, 151...Countermeasure permission information registration unit, 152, 152A...Countermeasure permission determination unit, 153...Security measure permission list, 153A...Product-specific security measure permission list, 154, 154A...Alert output control unit, 200, 200A...IoT device, 210...Control unit, 220, 220A...Log management unit, 230...Communication communication unit, 300...maintenance staff PC, 310...alert notification unit, 320...communication unit, D6001...access log, D6002...event log, D6003...error log, D7001, D7002, D7003, D7004...alert screen, F3001...permission ID, F3002...product name, F3003...serial number, F3004...customer name, F3005...IP address, F3006...OS, F3007...validity period, F3008...permission details, F3009...last update date and time, S2001...top screen, S2002...new registration screen, S2003...list display screen, S2004...change screen, S2005...confirmation screen, S2006...result screen
Claims
1. A device management device connected to a plurality of IoT devices via a network and managing the plurality of IoT devices, comprising: a log management unit that collects logs related to the operation of the plurality of IoT devices via the network; a detection unit that detects operations that have been preset as suspicious operations for each of the plurality of IoT devices based on the logs; a determination unit that, when suspicious operation is detected in at least one of the plurality of IoT devices, determines whether the detected suspicious operation is an operation caused by a security measure for the IoT device; and an alert control unit that, when it is determined that the suspicious operation is an operation caused by the security measure, controls not to output an alert to a user or administrator of the IoT device in which the suspicious operation was detected, and, when it is determined that the suspicious operation is not an operation caused by the security measure, controls to output the alert to the user or administrator of the IoT device.
2. A device management device as described in claim 1, further comprising an authorization information registration unit that registers, among information related to security measures for the IoT device, at least information related to operations caused by the security measures in a security measures authorization list, and the determination unit determines whether suspicious operations for the IoT device are operations caused by the security measures based on the security measures authorization list.
3. A device management system having a device management device connected to a plurality of IoT devices via a network and managing the plurality of IoT devices, comprising: a log management unit that collects logs related to the operation of the plurality of IoT devices; a detection unit that detects, based on the logs, operations that have been preset as suspicious operations for the plurality of IoT devices; a determination unit that, when the suspicious operation is detected, determines whether the suspicious operation is an operation caused by a security measure for the IoT device; and an alert control unit that, when it is determined that the suspicious operation is an operation caused by the security measure, controls not to output an alert to a user or administrator of the IoT device in which the suspicious operation was detected, and, when it is determined that the suspicious operation is not an operation caused by the security measure, controls to output the alert to the user or administrator of the IoT device.
4. A device management system as described in claim 3, wherein the device management device has an authorization information registration unit that registers, among information related to security measures for the IoT devices, at least information related to operations caused by the security measures in a security measures authorization list, and the plurality of IoT devices each have the judgment unit and alert control unit, and the judgment unit judges whether suspicious operations for the IoT devices are operations caused by the security measures based on the security measures authorization list of the device management device.
Citation Information
Patent Citations
Control device and integrated production system
JP2017111532A
Methods and devices for protecting network endpoints
US20180091553A1
Information processing device
WO2024018747A1