Threat handling method, program, and threat handling system

The threat response method for IoT devices addresses the issue of excessive inconvenience by limiting functions based on device characteristics, maintaining essential operations, and preventing unauthorized use during cyber attacks.

WO2026018531A1PCT designated stage Publication Date: 2026-01-22PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/016886
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-17
Filing Date
2025-05-08
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Existing SOAR systems applied to IoT devices impose excessive inconvenience to users by shutting down or disconnecting networks during cyber attacks, rendering the devices unusable.

Method used

A threat response method that determines control content based on the functional characteristics of IoT devices, limiting functions to the minimum necessary, and outputs instructions to maintain essential operations, thereby minimizing user inconvenience.

Benefits of technology

The method effectively restricts functions according to device characteristics, ensuring only essential operations are maintained, thus reducing user inconvenience and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025016886_22012026_PF_FP_ABST
    Figure JP2025016886_22012026_PF_FP_ABST
Patent Text Reader

Abstract

A threat handling method involves: when it is determined that there is an abnormality in a device to be monitored, executing a playbook for coping with the abnormality of the device (S201-S206); when executing the playbook, determining, in accordance with a function characteristic related to a function of the device, the control content in which a function usable in the device is limited (S204); and outputting, to the device, an instruction of operation based on the determined control content (S204).
Need to check novelty before this filing date? Find Prior Art

Description

Threat response method, program, and threat response system

[0001] The present disclosure relates to a threat response method, a program, and a threat response system.

[0002] Patent Document 1 discloses a response procedure generation device that generates a response procedure for an event related to an information system as a playbook.

[0003] Japanese Patent Application Laid-Open No. 2021-082083

[0004] The present disclosure provides a threat response method that can easily reduce inconvenience to users who use devices that have been subjected to a cyber attack.

[0005] In a threat response method according to one aspect of the present disclosure, when it is determined that an abnormality exists in a monitored device, a playbook for dealing with the abnormality in the device is executed, and when the playbook is executed, control content that limits the functions available to the device is determined based on functional characteristics related to the functions possessed by the device, and instructions for operation based on the determined control content are output to the device.

[0006] A program according to one aspect of the present disclosure causes one or more processors to execute the threat response method described above.

[0007] A threat response system according to one aspect of the present disclosure includes a processing unit and an output unit. When the processing unit determines that an abnormality exists in a monitored device, it executes a playbook to deal with the abnormality in the device. When executing the playbook, it determines control content that limits the functions available to the device based on functional characteristics related to the functions possessed by the device, and the output unit outputs instructions for operation based on the determined control content to the device.

[0008] The present disclosure has the advantage of making it easier to reduce inconvenience to users who use devices that have been subjected to cyber attacks.

[0009] FIG. 1 is a block diagram showing an example of an overall configuration including a threat response system according to an embodiment. FIG. 2 is a block diagram showing an example of a functional configuration of an SIEM according to an embodiment. FIG. 3 is a diagram showing an example of an operation log of a device. FIG. 4 is a diagram showing an example of a detection rule. FIG. 5 is a block diagram showing an example of a functional configuration of an SOAR according to an embodiment. FIG. 6 is a diagram showing an example of anomaly determination data. FIG. 7 is a diagram showing an example of a playbook. FIG. 8 is a diagram showing an example of functions included in a workflow. FIG. 9 is a diagram showing an example of control content information. FIG. 10 is a diagram showing an example of detailed information. FIG. 11 is a block diagram showing an example of a functional configuration of a device according to an embodiment. FIG. 12 is a sequence diagram showing an example of operation of an overall configuration including an SOAR according to an embodiment. FIG. 13 is a flowchart showing an example of operation of an SIEM according to an embodiment. FIG. 14 is a flowchart showing an example of operation of an SOAR according to an embodiment. FIG. 15 is a flowchart showing a control processing flow according to an embodiment. FIG. 16 is a flowchart showing a flow for determining a limit value range according to an embodiment. FIG. 17 is a diagram showing an example of detailed information according to a modified example. FIG. 18 is a flowchart showing a flow for determining a limit value range according to a modified example.

[0010] (Knowledge forming the basis of the present disclosure) In recent years, SIEM (Security Information and Event Management) has become known, which monitors whether or not an anomaly due to a cyber-attack has occurred on an IT device, such as a personal computer, by collecting and analyzing operation logs from the IT device. Also, SOAR (Security Orchestration, Automation and Response) is known, which, when an anomaly due to a cyber-attack on an IT device is detected by SIEM, deals with the anomaly by executing a predefined playbook.

[0011] However, when SOAR is applied to IoT (Internet of Things) devices rather than IT devices, if SOAR takes the same measures as those taken to deal with abnormalities in IT devices, there is a problem in that the convenience for users of the devices is reduced, for example, if the network is cut off or the power is turned off, the IoT devices will become unusable.

[0012] In view of the above, the present disclosure aims to provide a threat response method etc. that can easily reduce inconvenience to users who use devices when they are subjected to a cyber attack.

[0013] More specifically, in the threat response method according to the first aspect of the present disclosure, when it is determined that an abnormality exists in a monitored device, a playbook for dealing with the abnormality in the device is executed, and when the playbook is executed, control content that limits the functions available to the device is determined based on the functional characteristics of the functions possessed by the device, and instructions for operation under the determined control content are output to the device.

[0014] This has the advantage that the available functions are restricted according to the functional characteristics of the device that has been cyber-attacked, so that, for example, only the minimum necessary functions specific to the device can be made available, which makes it easier to minimize inconvenience to users who use the device.

[0015] Also, for example, in the threat response method according to the second aspect of the present disclosure, in the first aspect, the functional characteristics include the usage status of the device, and the control content is determined according to the usage status.

[0016] This has the advantage that it is possible to determine which functions to restrict depending on the usage status of the device, and therefore excessive function restrictions are unlikely to be imposed.

[0017] Also, for example, in the threat response method according to the third aspect of the present disclosure, in the second aspect, the usage situation includes at least one of a situation that may affect the safety of a user using the device, a situation that may affect the environment in which the user is placed, a situation that may affect the safety and hygiene of the user, and a situation that may affect the privacy of the user.

[0018] This has the advantage that it is possible to determine which functions to restrict depending on the usage status of the device, and therefore excessive function restrictions are unlikely to be imposed.

[0019] Furthermore, for example, in a threat response method relating to the fourth aspect of the present disclosure, in any one of the first to third aspects, if the function possessed by the device is a smart lock function, the control content is determined so as to maintain only the function of locking and unlocking by direct operation by the user using the device.

[0020] This has the advantage of making it easier to prevent attackers from fraudulently using the smart lock function of the device.

[0021] Also, for example, in a threat response method according to a fifth aspect of the present disclosure, in any one of the first to fourth aspects, the functional characteristics include the installation location where the equipment is installed, and the control content is determined according to the location of use.

[0022] This has the advantage that it is possible to determine which functions to restrict depending on the installation location of the device, making it difficult to restrict functions excessively.

[0023] Also, for example, in a threat response method relating to a sixth aspect of the present disclosure, in any one of the first to fifth aspects, the control content includes restricting the function of controlling the device through communication with an external device.

[0024] This has the advantage that it is easy to prevent an attacker from using an external device to illegally use the device.

[0025] Also, for example, in the threat response method relating to the seventh aspect of the present disclosure, in any one of the first to fifth aspects, if the control content includes maintaining a function for controlling a device through communication with an external device, it further includes limiting the range of setting values ​​that can be set for that function.

[0026] This has the advantage that it is easy to prevent an attacker from using an external device to operate the device with abnormal setting values.

[0027] Also, for example, in a threat response method according to an eighth aspect of the present disclosure, in the seventh aspect, the range of the setting value is determined in advance for each device.

[0028] This has the advantage that it is easier to quickly restrict the operation of the equipment compared to determining the range of setting values ​​each time a cyber attack occurs.

[0029] Also, for example, in a threat response method according to a ninth aspect of the present disclosure, in the seventh aspect, the range of setting values ​​is determined based on setting values ​​of the device in a past normal state.

[0030] This has the advantage that excessive function restrictions are unlikely to be imposed, since the range of setting values ​​is determined based on the setting values ​​of the device in the past normal state.

[0031] Also, for example, a program according to a tenth aspect of the present disclosure causes one or more processors to execute a threat response method according to any one of the first to ninth aspects.

[0032] This has the advantage that the available functions are restricted according to the functional characteristics of the device that has been cyber-attacked, so that, for example, only the minimum necessary functions specific to the device can be made available, which makes it easier to minimize inconvenience to users who use the device.

[0033] Furthermore, for example, a threat response system according to an eleventh aspect of the present disclosure includes a processing unit and an output unit. When the processing unit determines that a monitored device has an abnormality, the processing unit executes a playbook for dealing with the abnormality in the device, and when executing the playbook, determines control content that limits functions available to the device in accordance with functional characteristics related to functions possessed by the device. The output unit outputs an instruction for operation according to the determined control content to the device.

[0034] This allows the functions available to be restricted according to the functional characteristics of the device that has been cyber-attacked, so that, for example, only the minimum necessary functions specific to the device can be made available, which makes it easier to reduce inconvenience to users of the device.

[0035] Furthermore, these comprehensive or specific aspects may be realized in a system, an apparatus, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, or may be realized in any combination of a system, an apparatus, a method, an integrated circuit, a computer program, and a recording medium.

[0036] Hereinafter, embodiments will be described in detail with reference to the drawings. Note that the embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, or step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components not recited in independent claims will be described as optional components. Note that each figure is a schematic diagram and is not necessarily an exact illustration. Furthermore, in each figure, substantially identical components are assigned the same reference numerals, and duplicated descriptions may be omitted or simplified.

[0037] (Embodiment) [1. Configuration] A threat response system according to an embodiment will be described below. The threat response system is a system used to monitor whether or not there are any abnormalities due to cyber attacks on devices connected to a network, such as IoT devices. Fig. 1 is a diagram showing an example of the overall configuration including the threat response system according to an embodiment. As shown in Fig. 1, in the embodiment, a threat response system 2 is realized by a SOAR 2 included in an SOC (Security Operation Center) 100.

[0038] The SOC 100 is an organization that monitors, in real time, threats to information systems owned by, for example, individuals or companies. In the embodiment, the SOC 100 monitors, in real time, threats posed by cyber attacks to one or more devices 4 owned by users in a facility 200 such as a residential facility, an office, or a public facility. In the embodiment, the facility 200 is a residential facility such as a detached house or an apartment building, and the users are residents of the residential facility.

[0039] In addition, in the embodiment, the one or more devices 4 are all IoT devices and configured to be able to cooperate with other devices via a network device 3 such as a router and an external network N1 (here, the Internet). More specifically, in the embodiment, the one or more devices 4 include an air conditioner (referred to as "air conditioner" in FIG. 1) 4A, an induction heating (IH) cooking heater (referred to as "IH heater" in FIG. 1) 4B, a ventilation fan 4C, a refrigerator 4D, a robot vacuum cleaner 4E, a wireless speaker (referred to as "speaker" in FIG. 1) 4F, a smart lock 4G, and a surveillance camera 4H.

[0040] In the embodiment, the SOC 100 is provided with a SIEM 1 and a SOAR (Threat Response System) 2. That is, in the embodiment, the SIEM 1 and the SOAR 2 are operated on-premises. Note that the SIEM 1 and the SOAR 2 may be configured as a server device or the like and operated using cloud computing technology.

[0041] 2 is a block diagram showing an example of the functional configuration of the SIEM 1 according to the embodiment. The SIEM 1 includes a processor and a memory, and realizes its functions by the processor executing a program stored in the memory. As shown in FIG. 2, the SIEM 1 includes a log collection unit 11, an anomaly detection unit 12, an external function linkage unit 13, a communication unit 14, a log storage unit 15, and a detection rule storage unit 16.

[0042] The log collection unit 11 collects operation logs transmitted from each of the one or more monitored devices 4 via the external network N1. In this embodiment, the log collection unit 11 collects the operation log of the air conditioner 4A, the operation log of the induction heater 4B, the operation log of the ventilation fan 4C, the operation log of the refrigerator 4D, the operation log of the robot vacuum cleaner 4E, the operation log of the speaker 4F, the operation log of the smart lock 4G, and the operation log of the surveillance camera 4H. The log collection unit 11 stores the collected operation logs of each device 4 in the log storage unit 15.

[0043] Fig. 3 is a diagram showing an example of the operation log of device 4. In Fig. 3, the "Time Stamp" column indicates time information at the time when an operation of device 4 was performed, "Device ID (Identifier)" indicates an ID for identifying device 4, the "Device Type" column indicates the type of device 4, and the "Operation Log" column indicates the content of the operation of device 4. For example, in the example shown in Fig. 3, the log collection unit 11 collects an operation log indicating that device 4, whose device ID is "DA00001" and whose device type is "air conditioner," performed heating operation with the set temperature set to 37 degrees Celsius at 18:00 on April 1, 2024, in accordance with external communication from terminal "D1."

[0044] The anomaly detection unit 12 executes an anomaly detection process to determine whether or not an anomaly has occurred in each of the one or more devices 4, based on the operation logs of each of the one or more monitored devices 4 collected by the log collection unit 11. Here, an anomaly occurring in the device 4 means, for example, that the device 4 has been subjected to a cyber-attack, causing the device 4 to perform an operation that would not be possible under normal circumstances.

[0045] Specifically, the anomaly detection unit 12 refers to the detection rules stored in the detection rule storage unit 16, and if the operation log of the device 4 satisfies the detection rule, it determines that an abnormality has occurred in the device 4. Then, the anomaly detection unit 12 transmits abnormality determination data indicating that an abnormality has occurred in the device 4 to SOAR2. On the other hand, if the operation log of the device 4 does not satisfy the detection rule, the anomaly detection unit 12 determines that the device 4 is normal. In this case, the anomaly detection unit 12 does not transmit the abnormality determination data to SOAR2.

[0046] Fig. 4 is a diagram showing an example of a detection rule. In Fig. 4, the "Rule ID" column indicates an ID for identifying the detection rule, the "Device Type" column indicates the type of device 4, and the "Alert Generation Condition" column indicates the condition for SIEM 1 to generate an alert, i.e., the condition for determining that an abnormality has occurred in device 4. For example, in the example shown in Fig. 4, if device 4 is an air conditioner and its operation log satisfies the detection rule that "the temperature setting is 35 degrees Celsius or higher," the abnormality detection unit 12 determines that an abnormality has occurred in device 4.

[0047] 3, the log collection unit 11 collects an operation log indicating that device 4, whose device ID is "DA00001" and whose device type is "air conditioner," performed heating operation with the temperature set to 37 degrees Celsius at 18:00 on April 1, 2024, in accordance with external communication from terminal "D1." Since this operation log satisfies the detection rule that "the temperature setting is 35 degrees Celsius or higher," the anomaly detection unit 12 determines that an anomaly has occurred in device 4.

[0048] The external function linking unit 13 links with external functions other than the SIEM 1. Specifically, the external function linking unit 13 notifies the SOAR 2 that an abnormality has occurred in any of the one or more devices 4 to be monitored, for example, by transmitting abnormality determination data to the SOAR 2.

[0049] The communication unit 14 is a communication interface that performs wired or wireless communication with each of one or more devices 4 in the facility 200 via the external network N1. The communication unit 14 is also a communication interface that performs wired or wireless communication with the SOAR 2 in the SOC 100.

[0050] The log storage unit 15 is realized by an appropriate storage device, for example, a magnetic storage device such as a hard disk drive (HDD) or a semiconductor memory such as a solid state drive (SSD). The log storage unit 15 stores information indicating the contents of the operation logs collected by the log collection unit 11.

[0051] The detection rule storage unit 16 is realized by an appropriate storage device, such as a magnetic storage device such as an HDD, or a semiconductor memory such as an SSD, etc. The detection rule storage unit 16 stores information indicating the contents of the detection rules.

[0052] In the embodiment, the log storage unit 15 and the detection rule storage unit 16 are stored in separate storage devices, but this is not limiting. For example, the log storage unit 15 and the detection rule storage unit 16 may be implemented in a single storage device.

[0053] 5 is a block diagram showing an example of the functional configuration of a threat response system (SOAR) 2 according to an embodiment. The SOAR 2 includes a processor and a memory, and the processor executes a program stored in the memory to realize its functions. As shown in FIG. 5 , the SOAR 2 includes an abnormality determination data collection unit 21, a playbook execution unit 22, an external function linkage unit 23, a communication unit 24, an abnormality determination data storage unit 25, a playbook storage unit 26, a function storage unit 27, and a function characteristic storage unit 28.

[0054] The abnormality determination data collection unit 21 collects the abnormality determination data transmitted from the SIME 1. The abnormality determination data collection unit 21 stores the collected abnormality determination data in the abnormality determination data storage unit 25.

[0055] FIG. 6 is a diagram illustrating an example of anomaly determination data. In FIG. 6 , the column “Timestamp at the time of anomaly detection execution” indicates the time information at which SIEM 1 determines that an anomaly has occurred in device 4 during the anomaly detection process, and the column “Rule ID” indicates the ID of the detection rule applied to device 4 in which an anomaly has been determined to have occurred. Also, in FIG. 6 , the column “Device Type” indicates the type of device 4 in which an anomaly has been determined to have occurred, the column “Device ID” indicates the ID of device 4 in which an anomaly has been determined to have occurred, and the column “Anomalous Detection Result” indicates the determination result of the anomaly detection process. For example, in the example illustrated in FIG. 6 , the anomaly determination data collector 21 collects anomaly determination data indicating that device 4, whose device ID is “DA00001” and whose device type is “air conditioner,” was determined to have occurred an anomaly at 14:20 on April 9, 2024, based on the detection rule whose rule ID is “RA00001” (specifically, the detection rule stating that “the temperature setting is 35 degrees Celsius or higher”).

[0056] When the anomaly determination data collection unit 21 collects anomaly determination data, the playbook execution unit 22 executes a playbook corresponding to the device 4 in which an anomaly has been determined to have occurred by referring to the playbook stored in the playbook storage unit 26. In other words, when it is determined that an anomaly has occurred in the monitored device 4, the playbook execution unit (processing unit) 22 executes a playbook for dealing with the anomaly in the device 4. In the embodiment, the playbook is a playbook for performing an initial response to the device 4 that has been subjected to a cyber-attack. Also, in the embodiment, when executing a playbook, the playbook execution unit 22 executes one or more functions included in the workflow of the playbook in a predetermined order by referring to each function stored in the function storage unit 27.

[0057] FIG. 7 is a diagram showing an example of a playbook. In FIG. 7, the "Playbook ID" column represents an ID for identifying the playbook, the "Trigger" column represents the trigger that causes the playbook execution unit 22 to execute the playbook, and the "Workflow" column represents the content of one or more functions that are executed sequentially in the workflow of the playbook. For example, in the example shown in FIG. 7, the playbook execution unit 22 executes each function included in the workflow in the order of "fB," "fA," and "fC" in response to a trigger of "obtaining abnormality determination data for rule ID: RA00001," that is, a trigger that determines that an abnormality has occurred in device 4, whose device ID is "DA00001" and whose device type is "air conditioner," based on a detection rule that "the temperature setting is 35 degrees Celsius or higher."

[0058] A workflow may branch along the way. For example, in a playbook that executes the functions included in the workflow in the order of "fB," "fA," "fC," and "fD," it may be possible to execute the function "fE" instead of the function "fD" after the execution of the function "fC," depending on the execution result of the function "fC."

[0059] FIG. 8 is a diagram illustrating an example of a function included in a workflow. In FIG. 8, the "Function ID" column represents an ID for identifying the function, the "Function Content" column represents the content executed by the function, the "Input Information" column represents information used when executing the function, and the "Output Information" column represents information acquired by executing the function. For example, in the example shown in FIG. 8, when executing the function "fA," the playbook execution unit 22 references the device type and device ID of the device 4 targeted for playbook execution and controls the device 4 (i.e., the device 4 that detected the abnormality). Furthermore, when executing the function "fB," the playbook execution unit 22 specifies the device ID of the device 4 targeted for playbook execution and requests the SIEM 1 for a past operation log of the device 4 (i.e., the device 4 that detected the abnormality). In this case, the playbook execution unit 22 acquires the log information of the device 4, i.e., the past operation log of the device 4, from the SIEM 1. In addition, when the playbook execution unit 22 executes the function "fC", it refers to the device ID of the device 4 that is the target of the playbook execution and obtains past abnormality judgment data (i.e., alert detection status) of the device 4 (i.e., the device 4 that detected the abnormality).In addition, when the playbook execution unit 22 executes the function "fD", it specifies the device ID of the device 4 that is the target of the playbook execution and checks the communication destination of the device 4 (i.e., the device 4 that detected the abnormality).

[0060] Here, when executing a playbook, the playbook execution unit (processing unit) 22 refers to the functional characteristics stored in the functional characteristic memory unit 28, and determines the control content that restricts the functions available on the device 4, depending on the functional characteristics related to the functions possessed by the device 4 on which the playbook is to be executed.

[0061] In the embodiment, the control content indicates whether or not to maintain a function for controlling the device 4 through communication with an external device such as a smartphone. Also, in the embodiment, the control content indicates which functions are to be restricted from use and which functions are to be maintained available. Hereinafter, functions that are maintained available are also referred to as "maintained functions."

[0062] The functional characteristics are broadly divided into control content information and detailed information. The control content information is information indicating the control content of the device 4 during execution of a playbook for each type of device 4. The detailed information is information indicating the detailed control content of the device 4 during execution of a playbook for each device 4.

[0063] 9 is a diagram showing an example of control content information. In FIG. 9, the "Category" column indicates classification based on the usage status of the device 4, the "Device Type" column indicates the type of the device 4, the "Installation Location" column indicates the installation location where the device 4 is installed, the "External Communication" column indicates whether communication with external devices is blocked, the "Maintenance Function" column indicates functions that are maintained available for use by the device 4, and the "Other Restrictions" column indicates whether or not there are restrictions on the maintenance functions of the device 4. Thus, in the embodiment, the functional characteristics include the usage status of the device 4. Also, in the embodiment, the functional characteristics include the installation location where the device 4 is installed.

[0064] Here, usage status is broadly classified into six categories: "Safety-oriented," "Comfortable environment," "Safety and hygiene," "Privacy," "Smart lock," and "Other."

[0065] The "safety-critical" category includes devices 4 that are used in situations that may affect the safety of users of the devices 4, such as an induction heater 4B or an elevator. For devices 4 that fall under the "safety-critical" category, the control content indicates, for example, cutting off the communication function with external devices and maintaining only the functions of safety devices, as shown in FIG. 9 .

[0066] The "comfortable environment" category includes devices 4 that are used in situations that may affect the user's environment, such as an air conditioner 4A or a ventilation fan 4C. For devices 4 that fall under the "comfortable environment" category, the control content indicates, for example, as shown in FIG. 9, that communication with external devices is permitted and that only the operating function and the function for adjusting temperature (or air volume) are maintained. The control content also indicates that the temperature (or air volume) can only be adjusted within a limited value range. The limited value range will be described later.

[0067] The "safety and hygiene" category includes appliances 4 that are used in situations that may affect the safety and hygiene of the user, such as a refrigerator 4D or a washing machine. For appliances 4 that fall under the "safety and hygiene" category, the control content indicates, for example, cutting off the communication function with external devices and maintaining only the refrigeration function or the freezing function, as shown in Fig. 9 .

[0068] The "privacy" category includes devices 4 that are used in situations that may affect the user's privacy, such as a robot vacuum cleaner 4E or a surveillance camera 4H. Note that the robot vacuum cleaner 4E is limited to devices equipped with a camera. For devices 4 classified in the "privacy" category, the control content indicates, for example, blocking the communication function with external devices, as shown in FIG. 9 . Furthermore, if the device 4 is a surveillance camera installed outdoors, the control content indicates that only the function of recording video is maintained. On the other hand, if the device 4 is a surveillance camera installed indoors or a robot vacuum cleaner 4E installed indoors, the control content indicates that the maintenance function is not present, i.e., all functions are restricted. In this way, the control content may differ depending on the installation location of the device 4.

[0069] The "smart lock" category includes a smart lock 4G. A device 4 classified into the "smart lock" category blocks communication with external devices and maintains only the locking and unlocking functions that can be directly operated by the user, as shown in FIG. 9 .

[0070] The "Other" category includes devices 4 that do not fall into any of the above five categories, such as a speaker 4F or an electric kettle. For devices 4 that fall into the "Other" category, the control content indicates that the communication function with external devices is cut off and that there is no maintenance function, i.e., all functions are restricted, as shown in Fig. 9 .

[0071] Thus, in the embodiment, the purpose of use includes at least one of emphasizing the safety of the user who uses the device 4, providing a comfortable environment for the user, ensuring the safety and hygiene of the user, and ensuring the privacy of the user. The playbook execution unit (processing unit) 22 determines the control content according to the usage status of the device 4. The playbook execution unit 22 also determines the control content according to the installation location of the device 4.

[0072] FIG. 10 shows an example of detailed information. As shown in FIG. 10, the detailed information indicates the device type, category, installation location, and maintenance function for each device 4, more specifically, for each device ID. The detailed information also indicates a limit value range for the maintenance function. In other words, the limit value range is the range of setting values ​​that can be set by the maintenance function. The maintenance function here corresponds to a function for controlling the device 4 through communication with an external device. In other words, when the control content includes maintaining the function for controlling the device 4 through communication with an external device, it also includes limiting the range of setting values ​​that can be set by the function.

[0073] For example, in the example shown in FIG. 10 , device 4, whose device ID is "DA00001" and whose device type is "air conditioner," maintains the function of adjusting the temperature through communication with an external device during execution of the playbook, but the minimum setting value is 15° C. and the maximum setting value is 27° C., limiting the settable temperature range. Also, in the example shown in FIG. 10 , device 4, whose device ID is "DB00001" and whose device type is "ventilation fan," maintains the function of adjusting the airflow rate through communication with an external device during execution of the playbook, but both the minimum setting value and the maximum setting value are "medium," limiting the settable airflow range. Thus, in the embodiment, the limit value range (i.e., the set value range) is predetermined for each device 4, as shown in the detailed information.

[0074] The external function linking unit 23 links with external functions other than SOAR 2. Specifically, the external function linking unit 23 notifies the SOC 100 of the progress of measures taken on the device 4 that is the target of execution of the playbook, for example, by transmitting the progress of the playbook to the SOC 100.

[0075] The communication unit 24 is a communication interface that performs wired or wireless communication with each of one or more devices 4 in the facility 200 via the external network N1. The communication unit 14 is also a communication interface that performs wired or wireless communication with the SIEM 1 in the SOC 100.

[0076] The communication unit (output unit) 24 outputs to the device 4 an instruction for operation according to the control content determined by the playbook execution unit (processing unit) 22. In the embodiment, the communication unit 24 outputs a signal including an instruction for operation according to the control content determined by the playbook execution unit 22 by transmitting it to the device 4 that is the target of playbook execution. As a result, the device 4 that receives the signal controls itself according to the control content included in the signal.

[0077] The abnormality determination data storage unit 25 is realized by an appropriate storage device, such as a magnetic storage device such as an HDD, or a semiconductor memory such as an SSD, etc. The abnormality determination data storage unit 25 stores information indicating the contents of the abnormality determination data.

[0078] The playbook storage unit 26 is realized by an appropriate storage device, for example, a magnetic storage device such as an HDD, or a semiconductor memory such as an SSD. The playbook storage unit 26 stores information indicating the contents of the playbook.

[0079] The function storage unit 27 is realized by an appropriate storage device, such as a magnetic storage device such as an HDD, or a semiconductor memory such as an SSD, etc. The function storage unit 27 stores information indicating the content of each function included in the workflow.

[0080] The functional characteristic storage unit 28 is realized by an appropriate storage device, for example, a magnetic storage device such as an HDD, or a semiconductor memory such as an SSD. The functional characteristic storage unit 28 stores the above-mentioned control content information and detailed information as information indicating the content of the functional characteristics.

[0081] In the embodiment, the abnormality determination data storage unit 25, the playbook storage unit 26, the function storage unit 27, and the functional characteristics storage unit 28 are stored in separate storage devices, but this is not limiting. For example, the abnormality determination data storage unit 25, the playbook storage unit 26, the function storage unit 27, and the functional characteristics storage unit 28 may be realized by a single storage device.

[0082] 11 is a block diagram showing an example of the functional configuration of device 4 according to an embodiment. Device 4 includes a processor and a memory, and the processor executes a program stored in the memory to realize its functions. As shown in FIG. 11 , device 4 includes a function execution unit 41, a device linkage unit 42, a communication unit 43, and an operation log storage unit 44.

[0083] The function execution unit 41 executes various functions provided in the device 4. The function execution unit 41 can basically execute all functions under normal circumstances, that is, when no control command is received from the SOAR 2. Furthermore, when a control command is received from the SOAR 2, the function execution unit 41 can execute functions other than those restricted by the control command.

[0084] The device linking unit 42 links with external functions other than the device 4. Specifically, the device linking unit 42 links with an information processing terminal such as a smartphone owned by the user or with another device 4 by communicating with the device linking unit 42 via the communication unit 43. For example, when the device linking unit 42 receives a remote operation from the user on the smartphone, the device linking unit 42 causes the function executing unit 41 to execute a function corresponding to the remote operation.

[0085] The communication unit 43 is a communication interface that performs wired or wireless communication with each of the SIEM1 and SOAR2 in the SOC100 via the external network N1.

[0086] The operation log storage unit 44 is realized by an appropriate storage device such as a semiconductor memory such as a flash memory. The operation log storage unit 44 stores the operation log of the device 4.

[0087] [2. Operation] An example of operation of the SOAR (threat response system) 2 according to the embodiment will be described below. First, an overview of the operation of the overall configuration including the SOAR 2 according to the embodiment will be described with reference to Fig. 12. Fig. 12 is a sequence diagram showing an example of operation of the overall configuration including the SOAR 2 according to the embodiment. In the example shown in Fig. 12, there is one device 4 to be monitored, but there may be multiple devices 4 to be monitored.

[0088] The device 4 periodically transmits an operation log to the SIEM 1 (S1). Note that when step S1 is executed, the device 4 is assumed to be not under a cyber-attack. After collecting the operation log from the device 4, the SIEM 1 executes an anomaly detection process (S2). Here, since the device 4 is not under a cyber-attack, the SIEM 1 determines that the device 4 is normal (S3).

[0089] It is assumed that an attacker (third party) then launches a cyber attack against device 4 and illegally seizes control authority over device 4 (S4). By illegally controlling device 4, the attacker causes device 4 to perform abnormal operations that would not be possible under normal circumstances. Device 4 then transmits an operation log of the abnormal operations to SIEM 1 (S5).

[0090] When SIEM1 collects the operation log from device 4, it executes an anomaly detection process (S6). Here, device 4 has been subjected to a cyber-attack and is performing abnormal operation, so SIEM1 determines that an abnormality has occurred in device 4 (S7). SIEM1 then transmits the abnormality determination data to SOAR2 (S8). When SOAR2 collects the abnormality determination data, it executes the playbook corresponding to device 4 indicated by the abnormality determination data (S9).

[0091] FIG. 13 is a flowchart showing an example of the operation of the SIEM 1 according to the embodiment. After collecting an operation log from the device 4, the SIEM 1 executes the operation shown in FIG. 13 . First, the SIEM 1 determines whether the operation log of the device 4 satisfies the detection rule (S101). If the operation log of the device 4 does not satisfy the detection rule (S101: NO), the SIEM 1 determines that the device 4 is normal (S102). On the other hand, if the operation log of the device 4 satisfies the detection rule (S101: YES), the SIEM 1 determines that an abnormality has occurred in the device 4 (S103). Then, the SIEM 1 transmits the abnormality determination data to the SOAR 2 (S104).

[0092] 14 is a flowchart showing an example of the operation of SOAR2 according to the embodiment. When SOAR2 collects anomaly determination data from SIEM1, it executes the operation shown in FIG. 14. First, SOAR2 selects a playbook corresponding to the device 4 in which an anomaly has been determined to have occurred, i.e., a playbook to be executed (S201). Next, SOAR2 sequentially selects one or more functions included in the workflow indicated by the selected playbook (S202). When executing step S202 for the first time, SOAR2 selects the first function in the workflow.

[0093] If the function selected in step S202 is not a function for controlling the device 4 in which it is determined that an abnormality has occurred, i.e., it is not a control processing flow (S203: NO), SOAR2 executes the selected function (S205). If not all of the workflows have been executed (S206: NO), SOAR2 returns to step S202 and executes the processing from step S202 onwards.

[0094] On the other hand, if the function selected in step S202 is a control process flow (S203: YES), SOAR2 executes the control process flow (S204). In the control process flow, SOAR2 determines the control content of the device 4 by referring to the functional characteristics of the device 4 that is the target of the playbook execution, and outputs an instruction for operation based on the determined control content to the device 4. Details of the control process flow will be described later.

[0095] Thereafter, until all of the workflows have been executed (S206: NO), SOAR2 repeats the processes of steps S202 to S205. Then, when all of the workflows have been executed (S206: YES), SOAR2 ends the playbook execution process.

[0096] 15 is a flowchart showing a control process flow according to an embodiment. First, SOAR2 checks the control content of the device 4 by referencing the control content information of the device 4 to which the playbook is to be executed (S301). If the control content of the device 4 does not include a maintenance function (S302: NO), SOAR2 determines control content indicating that all functions of the device 4 are restricted, and outputs an instruction to operate under the control content to the device 4, i.e., sends a command to turn off all functions to the device 4 (S303). On the other hand, if the control content of the device 4 includes a maintenance function (S302: YES), SOAR2 then checks whether the device 4 has a limit value range (S304).

[0097] If there is no limit value range (S304: NO), SOAR2 determines control content indicating that functions other than the maintenance function of the device 4 are to be restricted, and outputs an instruction for operation under the control content to the device 4, i.e., sends a command to turn off functions other than the maintenance function to the device 4 (S305). On the other hand, if there is a limit value range (S304: YES), SOAR2 executes a flow for determining the limit value range (S306). In the flow for determining the limit value range, SOAR2 determines the range of setting values ​​that can be set in the maintenance function of the device 4 by referring to detailed information about the device 4 that is the target of the playbook execution. Details of the flow for determining the limit value range will be described later.

[0098] After executing the flow for determining the limit value range, SOAR2 determines control content that limits functions other than the maintenance function of the device 4 and indicates the range of setting values ​​that can be set for the maintenance function, and outputs instructions for operation under the control content to the device 4, that is, sends an instruction to the device 4 that adds the limit value range and leaves the maintenance function (S307).

[0099] After executing steps S301 to S307, SOAR2 refers to the control content information of the device 4 that is the target of playbook execution, and determines whether to block the function of controlling the device 4 through communication with an external function, i.e., whether to block external communication (S308). If it determines to block external communication (S308: YES), SOAR2 determines control content indicating that the function of controlling the device 4 through communication with an external device is restricted, and outputs instructions for operation under the control content to the device 4, i.e., sends a command to block external communication to the device 4 (S309). Then, SOAR2 ends the control processing flow. On the other hand, if it determines to allow external communication (S308: NO), SOAR2 ends the control processing flow without sending the above command to the device 4.

[0100] 16 is a flowchart showing a flow of determining a limit value range according to an embodiment. First, SOAR2 acquires setting values ​​(here, minimum and maximum setting values) corresponding to the maintenance function of the device 4 by referring to detailed information about the device 4 on which the playbook is to be executed (S401). Then, SOAR2 determines a limit value range based on the acquired setting values ​​(S402). Here, SOAR2 determines the range of setting values ​​that can be set by the maintenance function from the acquired minimum setting value to the maximum setting value.

[0101] [3. Advantages] Advantages of the threat response system (threat response method) according to the embodiment will be described below. As described above, when executing a playbook, the threat response system (SOAR) 2 according to the embodiment determines control content that limits functions available to the device 4 in accordance with the device characteristics of the device 4 on which the playbook is to be executed, and outputs instructions for operation under the determined control content to the device 4.

[0102] In this way, the threat response system 2 of the embodiment limits the functions that can be used depending on the functional characteristics of the device 4 that has been subjected to a cyber attack, so that, for example, only the minimum necessary functions specific to the device 4 can be made available, which has the advantage of making it easier to reduce inconvenience to users who use the device 4.

[0103] 4. Other Embodiments Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments. Modifications of the embodiments will be described below.

[0104] (Variant) SOAR (Threat Response System) 2 of the variant example differs from SOAR 2 of the embodiment in that the limit value range (i.e., the range of setting values) for the function of controlling device 4 through communication with external devices is determined based on the setting values ​​of the device 4 in a normal state.

[0105] FIG. 17 is a diagram showing an example of detailed information in a modified example. As shown in FIG. 17, the detailed information in the modified example differs from the detailed information in the embodiment (see FIG. 10) in that it has a column of data for "Limit Value Range Control" instead of columns for "Minimum Setting Value" and "Maximum Setting Value." Specifically, in the example shown in FIG. 17, the detailed information indicates whether limit value range control is required for each device 4, and more specifically, for each device ID. For example, in the example shown in FIG. 17, device 4 with device ID "DA00001" and device type "air conditioner" maintains the function of adjusting the temperature through communication with an external device during execution of the playbook, but the settable temperature range is limited.

[0106] Then, when it is necessary to control the limit value range, the playbook execution unit 22 executes the limit value range determination flow shown in Fig. 18. That is, in terms of the operation example (see Fig. 15) of the SOAR (threat response system) 2 in the embodiment, "when it is necessary to control the limit value range" corresponds to step S304: YES, and "when it is not necessary to control the limit value range" corresponds to step S304: NO.

[0107] 18 is a flowchart showing a flow for determining the limit value range in the modified example. First, SOAR2 requests SIEM1 to acquire the past operation log of the device 4 that requires limit value range control, i.e., the corresponding device 4 (S501). In step S501, SOAR2 acquires the operation log of the device 4 for a predetermined period, such as one week. Next, SOAR2 acquires the setting value of the device 4 when it is in a normal state from the acquired past operation log (S502).

[0108] If the acquired normal state setting value is not a numeric value (S503: NO), SOAR2 determines the acquired setting value to be within the limit value range (i.e., the settable range) (S504). For example, for device 4 whose device type is a "ventilation fan," the target airflow setting is expressed by a non-numeric setting value such as "large," "medium," or "small." If the previous normal state setting value of the ventilation fan was "medium," SOAR2 determines the limit value range to be "medium."

[0109] On the other hand, if the acquired normal state setting value is a numeric value (S503: YES), SOAR2 determines the limit value range by determining the minimum and maximum values ​​based on the acquired setting value (S505). For example, in device 4 whose device type is "air conditioner," the temperature to be set is represented by a numeric setting value. If the air conditioner's previous normal state setting value was within the range of 20°C to 24°C, SOAR2 determines the limit value range with a minimum value of 20°C and a maximum value of 24°C.

[0110] As described above, in the modified example, the range of the setting value is determined based on the setting value of the device 4 in the past in a normal state, which has the advantage that excessive function restrictions are unlikely to be imposed.

[0111] (Other Modifications) In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.

[0112] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0113] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0114] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a method, an integrated circuit, a computer program, or a computer-readable recording medium such as a CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a method, an integrated circuit, a computer program, and a recording medium.

[0115] For example, the present disclosure may be realized as a threat response method executed by a computer, or as a program for causing a computer to execute the threat response method. The present disclosure may also be realized as a computer-readable non-transitory recording medium on which such a program is recorded.

[0116] In addition, this disclosure also includes forms obtained by applying various modifications to the embodiments that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of the embodiments within the scope that does not deviate from the intent of this disclosure.

[0117] The present disclosure is useful for monitoring whether or not a device is at risk of a cyberattack.

[0118] DESCRIPTION OF SYMBOLS 1 SIEM 11 Log collection unit 12 Anomaly detection unit 13 External function linkage unit 14 Communication unit 15 Log storage unit 16 Detection rule storage unit 2 SOAR (Threat Response System) 21 Anomaly determination data collection unit 22 Playbook execution unit (processing unit) 23 External function linkage unit 24 Communication unit (output unit) 25 Anomaly determination data storage unit 26 Playbook storage unit 27 Function storage unit 28 Function characteristic storage unit 3 Network device 4 Device 41 Function execution unit 42 Device linkage unit 43 Communication unit 44 Operation log storage unit 4A Air conditioner 4B IH heater 4C Ventilation fan 4D Refrigerator 4E Robot vacuum cleaner 4F Speaker 4G Smart lock 4H Surveillance camera 100 SOC 200 Facility N1 External network

Claims

1. A threat response method comprising the steps of: when a monitored device is determined to have an abnormality, executing a playbook to deal with the abnormality in the device; when executing the playbook, determining control content that limits the functions available to the device in accordance with the functional characteristics of the device's functions; and outputting instructions to the device for operation under the determined control content.

2. The threat response method according to claim 1, wherein the functional characteristics include a usage status of the device, and the control content is determined according to the usage status.

3. The threat response method described in claim 2, wherein the usage situation includes at least one of situations that may affect the safety of a user who uses the device, situations that may affect the environment in which the user is placed, situations that may affect the safety and hygiene of the user, and situations that may affect the privacy of the user.

4. The threat response method described in claim 1, wherein, if the function of the device is a smart lock function, the control content is determined so as to maintain only the function of locking and unlocking by direct operation by the user of the device.

5. The threat response method according to claim 1, wherein the functional characteristics include an installation location where the device is installed, and the control content is determined according to the installation location.

6. The threat response method according to claim 1, wherein the control content includes restricting a function for controlling the device through communication with an external device.

7. The threat response method according to claim 1, wherein the control content further includes limiting the range of setting values ​​that can be set for a function that controls the device through communication with an external device, if the control content includes maintaining the function that controls the device through communication with an external device.

8. The threat response method according to claim 7, wherein the range of the set value is determined in advance for each of the devices.

9. The threat response method according to claim 7, wherein the range of the setting value is determined based on the setting value in a past normal state of the device.

10. A program that causes one or more processors to execute the threat response method according to any one of claims 1 to 9.

11. A threat response system comprising a processing unit and an output unit, wherein the processing unit, when it is determined that a monitored device has an abnormality, executes a playbook to deal with the abnormality in the device, and when executing the playbook, determines control content that limits the functions available to the device in accordance with functional characteristics related to the functions of the device, and the output unit outputs instructions for operation based on the determined control content to the device.

Citation Information

Patent Citations

  • Behavioral analytics to automate direct and indirect local monitoring of Internet of Things device health

    JP2018513457A

  • Information processing device, information processing method, and program

    JP2020065242A