System and method for calculating cyber risk through ship drawing analysis
The system creates a network topology from ship drawings to identify and mitigate cyber risks by classifying devices and checking connections, addressing the limitations of conventional ship design in network visualization and risk identification.
Patent Information
- Application Number
- PCT/KR2025/008155
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-20
- Filing Date
- 2025-06-13
- Publication Date
- 2025-12-26
AI Technical Summary
Existing ship design processes fail to identify potential cyber risks due to the absence of an actual network during the design stage, and conventional techniques are costly and ineffective in visualizing network topologies and identifying device relationships and importance.
A system and method that utilizes ship drawing data to create a network topology, classifies devices using Ethernet, CAN, and NMEA protocols, assigns grades based on importance and function, and performs a security check to identify potential cyber risks and suggest countermeasures.
Enables the identification of cyber risks in advance by classifying devices and checking attack methods through ship drawings, and provides a visual representation of vulnerable points and areas, enhancing network security before installation.
Smart Images

Figure KR2025008155_26122025_PF_FP_ABST
Abstract
Description
System and method for calculating cyber risk through ship drawing analysis
[0001] The present invention relates to a system and method for calculating cyber risk through ship drawing analysis, which utilizes ship drawing data to create a network topology for ship equipment, performs a security check of the network topology based on a rating standard between connected devices, and identifies and responds to connections that may have potential cyber risks.
[0002] The problem is that potential cyber risks cannot be identified in advance because the ship is not connected to an actual network during the design stage.
[0003] Conventional techniques related to ship network management utilize general techniques for actual operating networks, such as protecting network data by using encryption / decryption modules during ship operation, installing VPNs in the middle of communication with external networks, or inspecting packets of nodes and edges of devices to construct network topologies.
[0004] In addition, there is another way to identify devices connected to the network, determine their relationships, and connect nodes to represent the network configuration, but there is a problem in that it is impossible to identify potential cyber risks based on the relationships and importance of connected devices, and since the network is not actually installed and operated at the ship design stage, there is a problem in that it is impossible to identify devices connected to the ship network.
[0005] In addition, in the past, OT security technologies such as power plants and smart factories had the problem of increasing ship prices due to the high cost of monitoring the operating network and inspecting packets between each node to visualize the network topology.
[0006] As a related prior art document, Republic of Korea Patent Publication No. 10-2023-0129091 (2023.09.06.) is published.
[0007] The purpose of the present invention is to provide a system and method for calculating cyber risk through ship drawing analysis, which can create a network topology for ship equipment using ship drawing data, perform a security check of the network topology based on the rating criteria of connected devices, and identify connections that may have potential risks and suggest countermeasures.
[0008] Another object of the present invention is to provide a system and method for calculating cyber risks through ship drawing analysis, which classifies devices supporting network communication such as Ethernet, NMEA, and CAN through drawings at the design stage and identifies attack methods for connection parts to identify possible cyber risks in advance, and confirms connection points and vulnerable parts between devices by checking the node-by-node connections of the topology displayed on a topology output device.
[0009] In order to achieve the above object, a method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention may include a drawing extraction step in which a drawing extraction unit receives a drawing created for a ship design from a user terminal, extracts the drawing to indicate the arrangement location of devices and connections between devices, and extracts connection points including the communication networks used; a network classification step in which the connections between devices are verified through the drawings extracted in the drawing extraction step, and a network classification unit classifies devices using Ethernet, CAN, and NMEA protocols between ship equipment; a grade assignment step in which a grade assignment unit assigns a grade to each device using each network classified through the network classification step according to the importance and function; a topology generation step in which a topology generation unit generates a device connection topology by connecting devices of the same grade or the same level to each other through the grade assignment step; and a security inspection step in which a security inspection unit identifies and inspects connection points between devices and cybersecurity vulnerabilities based on the topology generated through the topology generation step.
[0010] In addition, in the method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, the drawing extraction step may include a 1:1 connection between devices in the drawing as a single bundle, and include a communication network / protocol, device installation location, and accessible persons as detailed values.
[0011] In addition, in the method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, the grade assignment step assigns grades in three stages according to the importance and function of the device based on the criteria of Category 1, 2, and 3 presented by IACS UR; in the event of a violation of the navigation of the ship, a grade of Category 3 may be assigned according to a device having an important function.
[0012] In addition, in the method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, the grade assignment step classifies the deck (floor) on which the device is installed, and the deck can be classified into areas or floors such as engine, residence, and navigation, and assigned high, medium, and low grades.
[0013] In addition, in the method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, the grade assignment step assigns a grade according to the position of the crew member who has access to the device; a high grade may be assigned to a device accessible only to the captain, and a low grade may be assigned to a device accessible to all crew members.
[0014] In addition, in a method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, after the topology generation step, a node-by-node connection of the generated topology can be confirmed, and a topology output step can be further included for visualizing and outputting the configuration of the topology through a topology output unit according to the level based on the deck among the assigned grades.
[0015] In addition, in the method for calculating cyber risk through ship drawing analysis according to one aspect of the present invention, the security inspection step is performed in five steps of Identify, Protect, Detect, Respond, and Recover by mapping with the process of IACS UR through ship drawing analysis; and a security inspection can be performed by selecting security measures to be applied through drawing analysis at each step.
[0016] In addition, according to another aspect of the present invention, the present invention may include a drawing extraction unit that receives a drawing created for the design of a ship from a user terminal, extracts the drawing to indicate the arrangement location of devices and the connection between devices, and extracts the connection points to include the communication network used; a network classification unit that checks the connection between devices through the drawing extracted from the drawing extraction unit and classifies devices using Ethernet, CAN, and NMEA protocols among ship equipment; a rating assignment unit that assigns a rating to devices using each network classified through the network classification unit according to the importance and function; a topology generation unit that connects devices of the same rating or the same level to each other through the rating assignment unit and generates a device connection topology; and a security inspection unit that identifies and performs an inspection of connection points between devices and vulnerable parts to cyber security based on the topology.
[0017] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, the drawing extraction unit may group 1:1 connections between devices in the drawing into one bundle and include communication networks / protocols, device installation locations, and accessible persons as detailed values.
[0018] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, the rating unit assigns ratings in three stages based on the importance and function of the device based on the criteria of Category 1, 2, and 3 presented by IACS UR; in the event of a violation of the navigation of the ship, a rating of Category 3 can be assigned based on a device having an important function.
[0019] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, the rating assigning unit classifies the deck (floor) on which the device is installed, and the deck can be classified into areas or floors such as engine, residence, and navigation, and assigned high, medium, and low ratings.
[0020] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, the rating assigning unit assigns a rating according to the position of a crew member who has access to the device; a high rating may be assigned to a device accessible only to the captain, and a low rating may be assigned to a device accessible to all crew members.
[0021] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, a topology output unit may be further included that enables the connection of each node of a topology generated through the topology generation unit to be confirmed, and that visualizes and outputs the configuration of a topology according to a level based on a deck among the grades assigned through the grade assignment unit.
[0022] In addition, in a system for calculating cyber risk through ship drawing analysis according to another aspect of the present invention, the security inspection unit performs the process of IACS UR through ship drawing analysis in five steps of Identify, Protect, Detect, Respond, and Recover; and can perform a security inspection by selecting security measures to be applied through drawing analysis at each step.
[0023] According to the present invention, it has the effect of generating a network topology for ship equipment by utilizing ship drawing data, performing a security check of the network topology based on a rating standard between connected devices, and identifying connections that may have potential risks and suggesting countermeasures.
[0024] In addition, according to the present invention, it is possible to identify possible cyber risks in advance by classifying devices supporting Ethernet communication through drawings at the design stage and checking attack methods for connection parts, and it has the effect of checking connection points and vulnerable parts between devices by checking connections by nodes of the topology displayed on the topology output device.
[0025] FIG. 1 is a diagram illustrating the concept of a cyber risk calculation system through ship drawing analysis according to one embodiment of the present invention.
[0026] FIG. 2 is a diagram showing the configuration of a cyber risk calculation system through ship drawing analysis according to one embodiment of the present invention.
[0027] FIG. 3 is a flowchart showing the flow of a method for calculating cyber risk through ship drawing analysis according to one embodiment of the present invention.
[0028] FIG. 4 is a drawing showing detailed steps of a drawing extraction step in a method for calculating cyber risk through ship drawing analysis according to one embodiment of the present invention.
[0029] FIG. 5 is a diagram showing detailed steps of a network classification step in a method for calculating cyber risk through ship drawing analysis according to one embodiment of the present invention.
[0030] FIG. 6 is a diagram showing detailed steps of a grade assignment step in a method for calculating cyber risk through ship drawing analysis according to one embodiment of the present invention.
[0031] FIG. 7 is a diagram showing detailed steps of a topology generation step in a method for calculating cyber risk through ship drawing analysis according to one embodiment of the present invention.
[0032] Figure 8 is a flowchart showing the flow of a method for calculating cyber risk through ship drawing analysis according to another embodiment of the present invention.
[0033] Figure 9 is a flowchart showing the flow of a method for calculating cyber risk through ship drawing analysis according to another embodiment of the present invention.
[0034] The purpose and technical configuration of the present invention and the resulting operation and effects will be more clearly understood through a detailed description based on the drawings attached to the specification of the present invention.
[0035] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. For example, terms such as "consist of" or "include" used herein should not necessarily be construed to include all of the various components or various steps described in the invention, but should be construed to mean that some of the components or some steps may not be included, or that additional components or steps may be included. Furthermore, the singular expression "a" or "an" as used herein includes the plural expression unless the context clearly dictates otherwise.
[0036] Hereinafter, the present invention will be described in detail by describing preferred embodiments thereof with reference to the attached drawings. The embodiments described below are provided to facilitate the technical concept of the present invention for those skilled in the art to understand, and should not be construed as limiting the present invention. It should be understood that the embodiments of the present invention will have various applications to those skilled in the art.
[0037] The system for calculating cyber risk through ship drawing analysis according to the present invention, referring to FIGS. 1 and 2, receives and extracts drawings created for the design of a ship from a user terminal (10), creates a network topology for ship equipment by utilizing ship drawing data, performs a security check of the network topology based on the rating criteria of connected devices, and can identify and respond to connections that may have potential cyber risks.
[0038] More specifically, the cyber risk calculation system (100) through ship drawing analysis may include a drawing extraction unit (110), a network classification unit (120), a rating unit (130), a topology generation unit (140), a topology output unit (150), and a security inspection unit (160).
[0039] The drawing extraction unit (110) receives a drawing created for the design of a ship from a user terminal (10) and extracts it to indicate the arrangement location of devices and connections between devices, and extracts the connection points to include the communication network used.
[0040] At this time, the drawing extraction unit (110) can utilize the cable schedule in the ship drawing data to indicate the device placement location and the connection between devices, and extract the connection points to include the communication network used.
[0041] In addition, the network classification unit (120) can check the connection between devices through the drawing extracted from the drawing extraction unit (110) and classify devices that use the Ethernet, CAN (Controller Area Network), and NMEA (National Marine Electronics Association) protocols between ship equipment.
[0042] Additionally, the rating unit (130) can assign a rating to each device using the network classified by the network classification unit (120) based on its importance and function.
[0043] In addition, the topology generation unit (140) can create a device connection topology by connecting devices of the same class or the same device to each other through the class assignment unit (130).
[0044] In addition, the topology output unit (150) can check the node-by-node connection of the topology generated through the topology generation unit (140), and can output the configuration of the topology according to the level by visualizing it based on the deck among the grades assigned through the grade assignment unit (130).
[0045] In addition, the security inspection unit (160) can check and inspect connection points between devices and areas vulnerable to cyber security based on the topology generated through the topology generation unit (140).
[0046] At this time, the drawing extraction unit (110) can group the 1:1 connection between devices in the drawing into one bundle and include the communication network / protocol, device installation location, and accessible person as detailed values.
[0047] In addition, the rating unit (130) can assign a rating in three stages according to the importance and function of the device based on the criteria of Category 1, 2, and 3 presented in IACS UR E22, and can assign a rating of Category 3 according to a device with an important function in case of an interference with the navigation of the ship.
[0048] In addition, the rating unit (130) classifies the deck (floor) on which the device is installed, and the deck can be classified into upper, middle, and lower grades according to the importance level according to the zone or floor, such as engine, residence, and navigation.
[0049] In addition, the rating unit (130) can assign a rating according to the position of the crew member who has access to the device, and can assign a high rating to a device accessible only to the captain and a low rating to a device accessible to all crew members.
[0050] Referring to FIGS. 3 to 7, a method for calculating cyber risk through ship drawing analysis according to the present invention may include a drawing extraction step (S110), a network classification step (S120), a rating assignment step (S130), a topology creation step (S140), a topology output step (S150), and a security check step (S160).
[0051] The drawing extraction step (S110) of the cyber risk calculation system (100) through ship drawing analysis receives a drawing created for the design of the ship from the user terminal (10) and extracts it, thereby indicating the arrangement location of the device and the connection between the devices, and the connection point can be extracted to include the communication network used.
[0052] That is, the drawing extraction step (S110) can group the 1:1 connection between devices in the drawing into one bundle and include the communication network / protocol, device installation location, and accessible person as detailed values.
[0053] In addition, looking at the drawing extraction step (S110) in detail, as shown in FIG. 4, in the ship drawing input step (S111), a drawing created for ship design is received from the user terminal (10), in the device extraction and storage step (S112) within the drawing, devices in the drawing are extracted and stored, and in the device storage step (S113), only the extracted devices are individually stored.
[0054] Next, through the device-to-device connection point extraction and storage step (S114), device-to-device connection points are extracted and stored from the extracted devices.
[0055] The connection point storage step (S115) individually stores the extracted connection points.
[0056] By individually storing the devices and connection points extracted by this, it is possible to check how the connection points connected to the devices are arranged for each individual device.
[0057] The network classification step (S120) can verify the connection between devices through the drawing extracted in the drawing extraction step (S110) and classify devices using Ethernet, CAN, and NMEA protocols between ship equipment in the network classification section.
[0058] More specifically, as illustrated in FIG. 5, it may include a protocol verification step (S121) for verifying the protocol used between ship equipment (devices), a protocol classification step (S122) for classifying the verified protocol according to its type, and a protocol storage step (S123) for storing the classified protocol.
[0059] The rating assignment step (S130) can assign a rating to a device using each network classified through the network classification step (S120) based on its importance and function.
[0060] More specifically, as illustrated in Fig. 6, the connection points between devices are confirmed in the device confirmation step (S131) and the connection point confirmation step (S132), and the network protocol used is confirmed in the network confirmation step (S133).
[0061] Next, a grade can be assigned according to each category through the category grade assignment step (S134), a grade can be assigned according to deck position through the deck position setting step (S135), and a grade can be assigned according to access status through the access permission setting step (S136).
[0062] The topology creation step (S140) can create a device connection topology in the topology creation unit by connecting devices of the same class or the same device to each other through the rating assignment step (S130).
[0063] More specifically, as illustrated in Fig. 7, nodes for each device are created through a device-specific node creation step (S141), connection relationships for each node are confirmed through a node-specific connection step (S142) and connected to each node, and each node and connection relationship for each node can be visualized through a node visualization step (S143).
[0064] At this time, after the topology creation step (S140), a topology output step (S150) may be further included to enable the node-by-node connection of the created topology to be confirmed, and to visualize and output the topology configuration by level through the topology output unit (150) based on the deck among the assigned grades.
[0065] In addition, the security inspection step (S160) can perform an inspection by checking the connection points between devices and parts vulnerable to cyber security based on the topology generated through the topology generation step (S140) in the security inspection unit (160).
[0066] Figure 8 is a flowchart showing the flow of a method for calculating cyber risk through ship drawing analysis according to another embodiment of the present invention.
[0067] Referring to FIG. 8, a drawing extraction step (S215) in which a drawing created for the design of a ship is input from a user terminal (10) in a drawing extraction unit (110) (S210) and extracted to indicate the arrangement location of devices and the connection between devices and to extract connection points to include the communication network used, a network classification step (S225) in which the connection between devices is confirmed through the drawing extracted in the drawing extraction step (S215) and the communication cables used in the network classification unit (120) are classified (S220) and the Ethernet / network network used through the communication cables is classified, a rating assignment step (S230) in which a rating assignment unit assigns a rating based on the importance and function of the devices using each network classified through the network classification step (S225), a topology generation step (S240) in which a device connection topology is generated in a topology generation unit by connecting devices of the same rating or the same device to each other through the rating assignment step (S230), and a node-by-node connection of the generated topology can be confirmed, and the assigned rating It may include a topology output step (S250) that visualizes and outputs through a topology output unit (150) according to the level, and a security inspection step (S260) that performs an inspection by checking the connection points between devices and parts vulnerable to cyber security based on the topology generated through the topology generation step (S240) through the security inspection unit.
[0068] At this time, the grade assignment step (S230) classifies the deck (floor) on which the device is installed, and the deck can be classified into areas or floors such as engine, residence, and navigation, and assigned high, medium, and low grades.
[0069] In addition, the rating stage (S230) assigns ratings in three stages based on the importance and function of the device based on the criteria of Category 1, 2, and 3 presented in IACS UR E22, and can assign a rating of Category 3 based on the device having an important function in case of an interference with the navigation of the ship.
[0070] In addition, the rating assignment step (S230) is characterized in that it assigns a rating according to the position of the crew member who has access to the device, and assigns a high rating to a device accessible only to the captain and a low rating to a device accessible to all crew members.
[0071] In addition, the topology output step (S250) assigns a grade to the network topology node, thereby enabling direct / indirect identification of whether nodes with differences in grades are connected.
[0072] Additionally, the security check step (S260) may provide a way to strengthen other security measures, including cybersecurity systems such as firewalls and trusted boundaries, in locations where there is a potential for security risks.
[0073] Referring to FIG. 9, it is a flowchart showing the flow of a method for calculating cyber risk through ship drawing analysis according to another embodiment of the present invention.
[0074] The security check step (S160) may more specifically include an identification step (S300), a protection step (S310), a detection step (S320), a response step (S330), and a restoration step (S340).
[0075] The identification step (300) checks whether two or more devices are connected to each other (S301), and if two or more devices are connected to each other, checks whether one or more devices have CBS characteristics (S302).
[0076] The protection step (S310) checks whether connected devices are located in different spaces and communicating with each other (S311), and if so, proceeds to the detection step (S320).
[0077] In addition, in the protection step (S310), if the connected devices are located in different spaces and communicate with each other, the step (S311) checks whether the two devices are configured with different protocols, and if not, it checks whether the two devices are configured with different protocols (S312). If the devices are configured with different protocols, end-to-end encryption can be set, and if the devices are not configured with different protocols, encrypted communication can be set.
[0078] In addition, the detection step (S320) checks whether it is located in a physically restricted access space (S321), and if it is located in a restricted access space, physical access is restricted, and if it is not located in a restricted access space, it checks whether the category (Cat) level is level 1 (S322).
[0079] If the category rating is not level 1 through the category rating verification step (S322), a firewall is installed, and if the category rating is level 1, the process proceeds to the response step (S340) to check whether the IACS UR E27 requirements are satisfied.
[0080] If the IACS UR E27 requirements are not satisfied through the response step (S340), measures are taken to satisfy the security requirements, and if they are satisfied, the process proceeds to the restoration step (S340).
[0081] The recovery phase (S340) checks whether cyber resilience is inherent, and if so, the security check phase is completed, and if not, a system recovery test can be established.
[0082] Accordingly, the drawing analysis is divided into the five steps of IACS UR E26: Identify, Protect, Detect, Respond, and Recover, and a security check can be performed by selecting the security measures to be applied through drawing analysis at each step. Therefore, the cyber risk level can be calculated through the analysis of ship drawings of the present invention by mapping it to the process of IACS UR E26.
[0083] Accordingly, according to the present invention, it is possible to create a network topology for ship equipment by utilizing ship drawing data, perform a security check of the network topology based on the rating criteria of connected devices, and identify connections that may have potential risks and suggest countermeasures.
[0084] In addition, according to the present invention, it is possible to identify possible cyber risks in advance by classifying devices supporting Ethernet communication through drawings at the design stage and checking attack methods for connection parts, and it has the effect of checking connection points and vulnerable parts between devices by checking connections by nodes of the topology displayed on the topology output device.
[0085] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.
[0086] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be construed as limiting the present invention thereby. It will be apparent to those skilled in the art that the embodiments of the present invention can be variously modified and altered without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be considered to fall within the scope of the claims of the present invention.
[0087] 100: Cyber Risk Assessment System through Ship Drawing Analysis
[0088] 110: Drawing Extraction Section
[0089] 120: Network Classification Department
[0090] 130: Grading Department
[0091] 140: Topology generation section
[0092] 150: Topology output section
[0093] 160: Security Inspection Department
Claims
1. A drawing extraction step in which a drawing created for the design of a ship is input from a user terminal in a drawing extraction section and extracted to indicate the arrangement location of devices and connections between devices, and to include the communication network used in the connection points; A network classification step for checking the connection between devices and devices through the drawings extracted in the above drawing extraction step and classifying devices using Ethernet, CAN, and NMEA protocols between ship equipment in the network classification section; A rating step in which a rating unit assigns a rating to each device using each network classified through the above network classification step according to its importance and function; A topology generation step for generating a device connection topology in a topology generation unit by connecting devices of the same grade or the same device to each other through the above-mentioned grading step; and A method for calculating cyber risk through ship drawing analysis, including a security inspection step in which a security inspection unit checks and inspects connection points between devices and cyber security vulnerabilities based on the topology generated through the above topology generation step.
2. In claim 1, The above drawing extraction step is, A method for calculating cyber risk through ship drawing analysis, which groups 1:1 connections between devices in the drawing and includes detailed values for communication networks / protocols, device installation locations, and accessible persons.
3. In claim 1, The above grading steps are: The categories 1, 2, and 3 presented by IACS UR are graded into three levels according to the importance and function of the device; A method for calculating cyber risk through ship drawing analysis, which assigns a Category 3 rating to devices with important functions in the event of a violation of the ship's navigation.
4. In claim 1, The above grading steps are: A method for calculating cyber risk through ship drawing analysis that classifies the deck on which the device is installed, and classifies the deck into areas or floors such as engines, residences, and navigation, and assigns them high, medium, and low grades.
5. In claim 1, The above grading steps are: The equipment is rated according to the position of the crew member who has access to it; A method for calculating cyber risk through ship drawing analysis, which assigns a high rating to devices accessible only to the captain and a low rating to devices accessible to all crew members.
6. In claim 1, After the above topology generation step, A method for calculating cyber risk through ship drawing analysis, which further includes a topology output step for visualizing and outputting the configuration of the topology by level through a topology output section based on the deck among the assigned grades, and enabling the connection of each node of the generated topology to be confirmed.
7. In claim 1, The above security check steps are: Through ship drawing analysis, it is mapped to the process of IACS UR and is performed in 5 steps: Identify, Protect, Detect, Respond, and Recover; A method for calculating cyber risks through ship drawing analysis, which enables security inspections by selecting security measures to be applied through drawing analysis at each step.
8. A drawing extraction unit that receives drawings created for the design of a ship from a user terminal and extracts them to indicate the placement locations of devices and connections between devices, and extracts connection points to include the communication networks used; A network classification unit that checks the connection between devices and classifies devices using Ethernet, CAN, and NMEA protocols between ship equipment through drawings extracted from the above drawing extraction unit; A rating unit that assigns a rating to a device using each network classified through the above network classification unit according to its importance and function; A topology generation unit that connects devices of the same class or the same device to each other through the above-mentioned rating unit and generates a device connection topology; and A system for calculating cyber risk through ship drawing analysis, including a security inspection unit that identifies and inspects connection points between devices and cyber security vulnerabilities based on the above topology.
9. In claim 8, The above drawing extraction section, A cyber risk calculation system through ship drawing analysis that groups 1:1 connections between devices on the drawing and includes detailed values for communication networks / protocols, device installation locations, and accessible persons.
10. In claim 8, The above rating department, The categories 1, 2, and 3 presented by IACS UR are graded into three levels according to the importance and function of the device; A cyber risk assessment system based on ship drawing analysis that assigns a Category 3 rating to devices with important functions in the event of a breach in the ship's navigation.
11. In claim 8, The above rating department, A cyber risk calculation system through ship drawing analysis that classifies the deck (floor) on which the device is installed, and classifies the deck into areas or floors such as engine, residence, and navigation, and assigns high, medium, and low grades.
12. In claim 8, The above rating department, The equipment is rated according to the position of the crew member who has access to it; A cyber risk assessment system based on ship drawing analysis that assigns a high rating to devices accessible only to the captain and a low rating to devices accessible to all crew members.
13. In claim 8, A system for calculating cyber risk through ship drawing analysis, which further includes a topology output section that enables the connection of each node of a topology generated through the above-mentioned topology generation section to be confirmed, and that visualizes and outputs the configuration of the topology according to the level based on the deck among the grades assigned through the grade assignment section.
14. In claim 8, The above security inspection department, Through ship drawing analysis, it is mapped to the process of IACS UR and is performed in 5 steps: Identify, Protect, Detect, Respond, and Recover; A cyber risk calculation system through ship drawing analysis that can perform security inspections by selecting security measures to be applied through drawing analysis at each step.
Citation Information
Patent Citations
System for Managing Cyber Security of Autonomous Ship
KR102433928B1
Smart Risk Assessment System
KR102573540B1
Cyber risk quantitative evaluation system for autonomous ship and method performing thereof
KR102578059B1
Analyzing cyber-security risks in an industrial control environment
US20160050225A1
Cyber security risk model and index
US20200137101A1