Information processing method, information processing device, and program
The method integrates communication and power supply monitoring to detect spoofing in operational industrial equipment, enabling accurate detection and localized shutdown without power interruption.
Patent Information
- Application Number
- PCT/JP2025/024565
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-30
- Filing Date
- 2025-07-08
- Publication Date
- 2026-02-05
AI Technical Summary
Conventional spoofing detection methods in industrial equipment require temporarily stopping power supply to the target device, making it difficult to detect spoofing in operational systems.
An information processing method that acquires communication status and power supply status, including time series information, to detect spoofing without stopping power to the target device, using a relay device for communication monitoring and a power supply control device for power management.
Enables accurate spoofing detection in operational industrial equipment by linking network communication and power supply status, allowing selective shutdown methods to minimize disruption.
Smart Images

Figure JP2025024565_05022026_PF_FP_ABST
Abstract
Description
Information processing method, information processing device, and program
[0001] The present disclosure relates to an information processing method, an information processing device, and a program for causing a computer to execute the information processing method.
[0002] Recently, in the technical field of industrial equipment, equipment has become more versatile, smaller, and more functional, making it easier to replace equipment with a replacement when it breaks down. On the other hand, it has also become easier for a malicious third party (hereinafter also referred to as an attacker) to perform spoofing, in which a target device for spoofing detection (hereinafter also referred to as a target device) is replaced with an unauthorized device (hereinafter also referred to as an attacker device). Patent Document 1 discloses a conventional technology for detecting spoofing.
[0003] Patent Document 1 discloses an impersonation detection device that sets the power supply state of a target device to a predetermined state, monitors the communication state of the communication network, and detects the presence of a communication node that impersonates the target device, i.e., an attacker device disguised to impersonate the target device.
[0004] JP 2019-129500 A
[0005] However, in Patent Document 1, spoofing cannot be detected unless the power supply to the target device is temporarily stopped, which is a predetermined state.
[0006] Furthermore, when power supply is resumed, it may be necessary to inspect the effects of the temporarily stopped power supply and perform operations to return the target device to a state where it can be restarted.
[0007] Furthermore, in the technical field of industrial equipment, it is difficult to easily stop the supply of power to a target device that is in operation.
[0008] The present disclosure has been made to solve this problem, and aims to provide an information processing method and the like that can more appropriately detect the presence or absence of spoofing.
[0009] An information processing method according to one aspect of the present disclosure is an information processing method executed by a computer, and includes the steps of acquiring a communication status between a target device and a network, acquiring a power supply status including time series information of power supplied to the target device, and using the acquired communication status and power supply status to detect whether or not there is impersonation indicating that the target device has been replaced with an attacker's device.
[0010] An information processing device according to one aspect of the present disclosure includes a first acquisition unit that acquires a communication status between a target device and a network, a second acquisition unit that acquires a power supply status including time series information of power supplied to the target device, and a detection unit that uses the acquired communication status and power supply status to detect whether or not the target device has been impersonated, which indicates that the target device has been replaced with an attacker's device.
[0011] A program according to one aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.
[0012] According to the present disclosure, it is possible to more appropriately detect whether or not there is spoofing.
[0013] FIG. 1 is a schematic diagram illustrating the configuration of a spoofing detection device according to an embodiment. FIG. 2 is a block diagram illustrating details of an anomaly detection device having the above-described configuration according to an embodiment. FIG. 3 is a block diagram illustrating details of a relay device having the above-described configuration according to an embodiment. FIG. 4 is a block diagram illustrating details of a target device having the above-described configuration according to an embodiment. FIG. 5 is a block diagram illustrating details of a power supply control device and a power supply having the above-described configuration according to an embodiment. FIG. 6 is a diagram illustrating the recorded contents of a memory unit of a power supply control device having the above-described configuration according to an embodiment. FIG. 7 is a diagram illustrating the recorded contents of a memory unit of a relay device having the above-described configuration according to an embodiment. FIG. 8 is a diagram illustrating the recorded contents of a memory unit of an anomaly detection device having the above-described configuration according to an embodiment. FIG. 9 is a flowchart illustrating the processing procedure of the spoofing detection device according to an embodiment. FIG. 10 is a flowchart illustrating the spoofing detection processing procedure of the spoofing detection device according to an embodiment. FIG. 11 is a diagram illustrating the recorded contents of a memory unit of an anomaly detection device when communication spoofing occurs, during the spoofing determination processing of the spoofing detection device according to an embodiment. Fig. 12 is a diagram illustrating an example of the recorded contents of the storage unit of the anomaly detection device when power supply spoofing occurs in the spoofing determination process of the spoofing detection device according to the embodiment. Fig. 13 is a diagram illustrating an example of the recorded contents of the storage unit of the anomaly detection device when an abnormal restart occurs in the spoofing determination process of the spoofing detection device according to the embodiment. Fig. 14 is a flowchart illustrating the shutdown determination process procedure of the spoofing detection device according to the embodiment. Fig. 15 is a flowchart illustrating the processing procedure of the relay device and the power supply control device of the spoofing detection device according to the embodiment.
[0014] Hereinafter, the embodiments will be specifically described with reference to the drawings.
[0015] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not recited in the independent claims of the present disclosure are described as optional components. Furthermore, the drawings are not necessarily strict illustrations. In the drawings, substantially identical components are denoted by the same reference numerals, and redundant descriptions may be omitted or simplified.
[0016] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.
[0017] Furthermore, in this specification, when a comparison is made, for example, with "above a threshold" or "below a threshold," it means that the distinction is made at the threshold, and may mean "greater than the threshold" or "below the threshold," respectively.
[0018] (Embodiment) [Configuration of Spoofing Detection Device] First, the configuration of a spoofing detection device according to an embodiment will be described.
[0019] 1 is a schematic diagram illustrating the configuration of a spoofing detection device according to an embodiment. The spoofing detection device 1 is an example of an information processing device, and is composed of a group of devices arranged across a plurality of areas.
[0020] The target device 12 is a device for which spoofing is to be detected. The target device 12 may be any device, such as a control device for a machine tool, a data logger, or a general-purpose computer.
[0021] The other devices 16 are devices that are not subject to spoofing detection.
[0022] The anomaly detection device 10 is a device that detects anomalies based on the information related to the target device 12 described above, that is, detects whether the target device 12 has been replaced with an attacker's device.
[0023] The relay device 11 is installed between the communication path of the communication network of the above-described abnormality detection device 10 and the above-described target device 12 or other devices 16, and is a device that monitors the communication status of the communication network by relaying communication between the target device 12 and other devices 16 via signal line 21 or signal line 24.
[0024] The power supply control device 13 is a device that supplies power to the target device 12 described above via the power line 22 and monitors the power supply status including time-series information of the power supplied to the target device 12 .
[0025] The power supply 14 supplies power to the power supply control device 13 described above via a power line 23 .
[0026] The other power source 15 supplies power to the other devices 16 described above via a power line 25 .
[0027] The abnormality detection device 10 is located in range 31 as a physical location range, the relay device 11 is located in range 32 as a physical location range, the target device 12 and other devices 16 are located in range 33 as a physical location range, and the power supply control device 13 and power supply 14 are located in range 34 as a physical location range.
[0028] It should be noted that the above-described anomaly detection device 10, relay device 11, target device 12, other device 16, power supply control device 13, power supply 14, other power supply 15, signal line 21, power line 22, power line 23, signal line 24, and power line 25 may be provided in plural. Furthermore, it is also possible to provide plural signal lines for the communication network between the above-described anomaly detection device 10 and relay device 11 or between the anomaly detection device 10 and power supply control device 13, which are necessary according to the embodiment.
[0029] Furthermore, the anomaly detection device 10 described above may be included as a physical location range or functional configuration in the relay device 11 or the power supply control device 13. Furthermore, the ranges 31, 32, and 34 described above may be the same range, may include each other, or each range may be further divided into multiple ranges.
[0030] [Installation Range of Spoofing Detection Device] The above-described ranges 31, 32, 33, and 34 may be defined by physical installation distances or boundaries such as walls, or may be defined by boundaries separated by an electronic authentication system, such as an access control system, that can restrict access by people, including attackers. In this embodiment, the above-described range 31 may be limited to a space in a secure building, such as a data center. The range 32 may be limited to, for example, a machine room or electrical room located on the same premises (or in the same building) as the space where the target device 12 or other devices 16 are installed. The range 33 is not limited to a particular installation location and may be any space. The range 34 may be limited to, for example, a machine room or electrical room located on the same premises (or in the same building) as the space where the target device 12 is installed.
[0031] [Configuration of the Anomaly Detection Device] FIG. 2 is a block diagram showing a detailed functional configuration of the anomaly detection device 10 described above. The anomaly detection device 10 includes an anomaly detection unit 101, a communication unit 102, and a storage unit 103. The storage unit 103 is implemented, for example, as a semiconductor memory and stores information received by the communication unit 102. The anomaly detection unit 101 is implemented by executing a predetermined program using a processor and memory and performs an anomaly detection process based on the information in the storage unit 103. When the anomaly detection unit 101 detects an anomaly, i.e., when spoofing is detected, it transmits a control signal to the relay device 11 or the power control device 13, preferably via the communication unit 102, to shut down communication with the target device 12 in which the anomaly was detected. The communication unit 102 is implemented by executing a predetermined program using a processor and memory and extracts information indicated by a signal from a physical communication port. In other words, the communication unit 102 has a functional configuration that doubles as a first acquisition unit and a second acquisition unit for acquiring information. The abnormality detection unit 101, the communication unit 102, and the storage unit 103 described above may be configured in such a manner that a plurality of units having the same configuration are provided.
[0032] [Configuration of Relay Device] FIG. 3 is a block diagram showing the functional configuration of the relay device 11 described above. The relay device 11 includes a relay unit 111, a communication unit 112, and a storage unit 113. The relay unit 111 is implemented by executing a predetermined program using a processor and memory, and relays information transmitted from the target device 12 or another device 16 to the network, and information transmitted from the network to the target device 12 or another device 16. The communication unit 112 is implemented by executing a predetermined program using a processor and memory, and retrieves information indicated by a signal from a physical communication port connected to the network, and generates and outputs a signal to a physical communication port connected to the target device 12 or another device 16. The communication unit 112 also retrieves information indicated by a signal from a physical communication port connected to the target device 12 or another device 16, and generates and outputs a signal to a physical communication port connected to the network. The storage unit 113 stores information related to the communication history relayed by the relay unit 111. The storage unit 113 also stores information linking a device ID for distinguishing the target device 12 from other devices with a communication management ID related to communication between the target device 12 and the network (e.g., the ID of the signal line to which the target device 12 is connected). The storage unit 113 also stores information linking a device ID for distinguishing another device 16 from yet another device with a communication management ID related to communication between the other device 16 and the network (e.g., the ID of the communication port to which the other device 16 is connected). The relay unit 111, communication unit 112, and storage unit 113 described above may further include a plurality of similar configurations.
[0033] [Configuration of Target Device] FIG. 4 is a block diagram showing the functional configuration of the target device 12 described above. The target device 12 includes a device main body 121, a communication unit 122, and a power receiving unit 123. The device main body 121 is realized by executing a predetermined program using a processor and memory, and optionally by driving various actuators, and performs the main functions of the target device 12. The communication unit 122 is realized by executing a predetermined program using a processor and memory, and extracts information indicated by a signal from a physical communication port connected to the network. It also generates and outputs a signal to the physical communication port connected to the network. The power receiving unit 123 receives power from the power supply control device 13 to operate the device main body 121. Note that the communication unit 122 and power receiving unit 123 described above may be further configured in multiple units similar to them. Note that the other device 16 also has a functional configuration equivalent to that of the target device 12 shown in FIG. 4.
[0034] [Configuration of Power Supply Control Device] FIG. 5 is a block diagram showing the functional configuration of the power supply control device 13 and the power supply 14 described above. The power supply control device 13 includes a power supply control unit 131, a communication unit 132, a storage unit 133, a power receiving unit 134, and a power distribution unit 135. The power supply control unit 131 is implemented by executing a predetermined program using a processor and memory, and controls the power supply to the target device 12. The communication unit 132 is implemented by executing a predetermined program using a processor and memory, and generates and outputs a signal to a physical communication port connected to the network. The storage unit 133 stores information regarding the power supply history controlled by the power supply control unit 131. The storage unit 133 also stores information linking a device ID for distinguishing the target device 12 from other devices with a power management ID related to the power supply to the target device 12 (e.g., the ID of the power line to which the target device 12 is connected). The power receiving unit 134 receives power from the power supply 14. The power distribution unit 135 outputs the power received by the power receiving unit 134 to the target device 12 under the control of the power supply control unit 131 .
[0035] The power supply 14 includes a power distribution unit 141. The power distribution unit 141 receives power from, for example, a power grid and outputs it to the power supply control device 13. Note that the power supply control unit 131, communication unit 132, storage unit 133, power receiving unit 134, and power distribution unit 135 of the power supply control device 13 described above may further include a plurality of similar components. Furthermore, the power distribution unit 141 of the power supply 14 described above may further include a plurality of similar components.
[0036] [Physical configuration of each device] Although some of them have already been mentioned, the above-described anomaly detection device 10, relay device 11, target device 12, power supply control device 13, and the functional configurations of these devices are realized by communication interfaces such as communication ports for communicating with each device or function, non-volatile memory in which programs are stored, volatile memory that is a temporary storage area for executing programs, input / output ports for sending and receiving signals, processors that execute programs, AC / DC converters for sending and receiving power, and power supply components such as boost / buck and smoothing elements.
[0037] The processing units of the anomaly detection unit 101 of the anomaly detection device 10, the relay unit 111 of the relay device 11, and the power supply control unit 131 of the power supply control device 13 described above are realized, for example, by a memory and a processor such as a CPU (Central Processing Unit) that executes a control program stored in the memory. The memory included in these processing units may be realized by a common memory, or may be realized by one or more independent memories. Furthermore, the processors included in these processing units may be realized by a common processor, or may be realized by one or more independent processors.
[0038] The communication unit 102 of the anomaly detection device 10, the communication unit 122 of the target device 12, the communication unit 112 of the relay device 11, and the communication unit 132 of the power supply control device 13 described above are circuits realized by a signal processing processor and memory connected to a communication interface for communication between the devices. The communication interface may be realized by an antenna and a wireless communication circuit for wireless communication, or may be realized by a connector to which a communication line for wired communication is connected.
[0039] The storage unit 103 of the abnormality detection device 10, the storage unit 113 of the relay device 11, and the storage unit 133 of the power supply control device 13 described above are realized by storage devices such as semiconductor memories or HDDs (Hard Disc Drives), for example.
[0040] [Electrical Conditions of Each Device] It is assumed here that each device, such as the target device 12, the other devices 16, and the attacker device, cannot operate or communicate without a power supply.
[0041] [Communication conditions for target device] The range 33 to which the above-described target device 12 belongs, including other devices 16 that also belong to the range 33, and devices that are provided within the range 33 and communicate with each other must communicate via the relay device 11.
[0042] [Configuration of the Communication Unit of Each Device] The communication unit 102 of the anomaly detection device 10 described above communicates with the communication unit 112 of the relay device 11 or the communication unit 132 of the power supply control device 13, or both. The communication unit 102 of the anomaly detection device 10 receives (acquires) information on the communication status from the communication unit 112 of the relay device 11 and information on the power supply status from the communication unit 132 of the power supply control device 13. The communication unit 102 of the anomaly detection device 10 preferably transmits a control signal for cutting off communication with the target device 12 to the relay unit 111 via the communication unit 112 of the relay device 11 and to the power supply control unit 131 via the communication unit 132 of the power supply control device 13. In other words, the control signal for cutting off communication with the target device 12 includes a control signal sent to the relay unit 111 to cut off the relayed communication, and a control signal sent to the power supply control unit 131 to stop the supply of power to the target device 12 and stop operation of the target device 12, including communication.
[0043] [Configuration of power receiving and distribution unit of each device] The power supply control device 13 described above receives power from the power source 14 via the power line 23 and supplies, i.e. distributes, the received power to the target device 12. In the power supply control device 13, the power distribution unit 135 receives a command from the power supply control unit 131 and supplies power to the power receiving unit 123 of the target device 12 via the power line 22.
[0044] [Configuration of the storage unit of each device] The storage unit 103 of the anomaly detection device 10 described above may be provided in the storage unit 133 of the power supply control device 13. In this case, for example, by making the storage unit 133 a volatile storage area, when a power outage occurs in the range 34 described above and there is a change in the communication state and power supply state of the target device 12, it can be determined whether the change is due to a spoofing attack or a power outage.
[0045] [Configuration of the Storage Unit of the Power Supply Control Device] FIG. 6 is a table showing the contents recorded in the storage unit 133 of the power supply control device 13 described above. The power supply control device ID, the target device ID (device ID), and the power line ID (power management ID) are information indicating predetermined identifiers uniquely identifying the power supply control device 13, the target device ID (device ID), and the power line 22 described above, respectively, to distinguish them from other similar configurations. The power supply status is information indicating the power supply status, including time-series information on the power supplied from the power supply control device 13 to the target device 12. The information recorded in the power supply status may simply be a true / false value indicating whether power is being supplied per unit time, or a numerical value indicating the amount of power supplied per unit time. The detection notification is information indicating the content of the detection notification received from the anomaly detection device 10 for each target device ID described above. The information recorded in the detection notification may simply be a true / false value indicating whether the detection notification was received, or may be the time indicating when the detection notification was received. The detection notification may have any data structure. The shutdown request is information indicating the content of the shutdown request received from the anomaly detection device 10 for each target device ID described above. The shutdown request may simply be a true / false value indicating whether or not the shutdown request was received, or may be a time indicating when the shutdown request was received or until when the shutdown request should be made. The shutdown request may also have any data structure.
[0046] [Configuration of the Relay Device Storage Unit] FIG. 7 is a table showing the contents recorded in the storage unit 113 of the relay device 11 described above. The relay device ID, the target device ID, and the signal line ID (communication management ID) are information indicating predetermined identifiers that uniquely distinguish the relay device 11 described above, the target device ID, and the signal line 21 described above from other similar configurations. The communication status is information indicating the communication status between the target device 12 and the network relayed by the relay device 11. The information recorded in the communication status may simply be a true / false value indicating whether communication is taking place, or may be a numerical value indicating at least one of the upstream traffic volume from the target device 12 to the network and the downstream traffic volume from the network to the target device 12. The detection notification is information in the same format as the detection notification described in FIG. 6 described above. The shutdown request is information in the same format as the shutdown request described in FIG. 6 described above.
[0047] [Configuration of the storage unit of the anomaly detection device] Figure 8 is a table showing the recorded contents of the storage unit 103 of the anomaly detection device 10 described above. The measurement time is the time when the following information on the target device ID, power supply status, and communication status was recorded. The target device ID is information indicating a predetermined identifier that uniquely identifies the target device 12 described above. The power supply status is information shown in the recorded contents of the storage unit 133 of the power supply control device 13 described above. The communication status is information shown in the recorded contents of the storage unit 113 of the relay device 11 described above.
[0048] [Details of Processing in the Spoofing Detection Device] Hereinafter, details of processing in the above-described spoofing detection device 1 will be described with reference to FIGS.
[0049] [Information Acquisition] The anomaly detection unit 101 of the anomaly detection device 10 acquires the above-described network communication state and power supply state for a predetermined period of time for a single target device 12. For the network communication state, the anomaly detection unit 101 acquires communication state information stored in the memory unit 113 using the relay device 11. For the power supply state, the anomaly detection device 10 acquires power supply state information stored in the memory unit 133 using the power supply control device 13. The anomaly detection device 10 determines whether or not spoofing is being performed on the device main body 121, communication unit 122, and power receiving unit 123 of the target device 12, based on the contents recorded in the memory unit 113 of the relay device 11 (hereinafter, the network communication state) and the contents recorded in the memory unit 133 of the power supply control device 13 (hereinafter, the power supply state).
[0050] The anomaly detection device 10 records the network communication status and power supply status for a predetermined period in the storage unit 103. Here, the predetermined period may be set arbitrarily in advance. For example, the predetermined period may be set to the entire past period, or the past month, week, or several days, such as three days or one day. The network communication status recorded by the anomaly detection device 10 in the storage unit 103 may be information regarding communications transmitted by the communication unit 122 of the target device 12, or may be information regarding communications transmitted by, for example, the communication unit 112 of the relay device 11. The power supply status recorded by the anomaly detection device 10 in the storage unit 103 may be information regarding power received by the power receiving unit 123 of the target device 12, or may be information regarding power transmitted by the power distribution unit 135 of the power supply control device 13. When acquiring these network communication status and power supply status, the anomaly detection device 10 may receive information from the relay device 11 or the power supply control device 13, or may request these devices to transmit the respective information. The anomaly detection device 10 also records the time at which the network communication status and power supply status are acquired as measurement time in the storage unit 103. Preferably, this time is synchronized with the system clock of the anomaly detection device 10. According to this processing content, the anomaly detection device 10 acquires the network communication status and power supply status by linking them together as information related to a single target device 12, and can identify the network communication status and power supply status by associating them with each other.
[0051] [Spoofing Determination] The anomaly detection device 10 evaluates the information recorded in the storage unit 103 using the anomaly detection unit 101 to determine whether or not a spoofing has occurred. For example, an anomaly may be determined when a change in the network communication status is detected even when the target device 12 is not receiving power. Alternatively, an anomaly may be determined when the time series transition between the network communication status of the target device 12 when power is initially supplied and the network communication status of the target device 12 when power is continuously supplied reaches a predetermined threshold. Alternatively, the network communication status and power supply status over a predetermined period may be analyzed for each group, such as by model of the target device 12 or by power control device 13 that distributes power to the target device 12, and a single target device 12 may be determined to be abnormal. Note that the predetermined period may be determined arbitrarily. According to this process, the detection process does not require the power supply to the target device 12 to be stopped (to be in a predetermined state), and the presence or absence of spoofing can be detected while the target device 12 continues to operate.
[0052] In this embodiment, spoofing refers to the replacement of the target device 12 with an attacker device, and a specific example of this is power spoofing, in which the attacker device operates by diverting power supplied to the target device 12, the target device 12 is not operating because no power is supplied to it, and only communication between the attacker device and the network is carried out disguised as communication between the target device 12 and the network. Another specific example is communication spoofing, in which the attacker device operates by a different power source without diverting power supplied to the target device 12, and communication between the network and the spoofed attacker device is carried out by blending in with communication between the normally operating target device 12 and the network.
[0053] [Notification and Shutdown] The anomaly detection unit 101 of the anomaly detection device 10 preferably shuts down communication with the target device 12 in which an anomaly has been detected. If an anomaly is found in the target device 12 as a result of analysis, the anomaly detection unit 101 notifies the target device 12 and further has the function of shutting down one or more target devices 12 if shutdown becomes necessary.
[0054] The notification is sent to the relay device 11 and the power supply control device 13 along with the identifier (device ID) of the target device 12. After sending the notification, the relay device 11 and the power supply control device 13 preferably determine whether shutdown is necessary and may respond to the notification to the anomaly detection unit 101 of the anomaly detection device 10, or the anomaly detection unit 101 of the anomaly detection device 10 may send a shutdown request using the identifier of the target device 12 based on the analysis result, regardless of whether there is a response to the notification described above.
[0055] For example, the shutdown can be performed in the following ways: the abnormality detection unit 101 sends a shutdown request to the communication unit 132 of the power supply control device 13 via the communication unit 102, and the power supply control unit 131 of the power supply control device 13 operates the power distribution unit 135 to stop power distribution to the target device 12 in which an abnormality has been detected; the abnormality detection unit 101 sends a shutdown request to the communication unit 112 of the relay device 11 via the communication unit 102, and the relay unit 111 of the relay device 11 stops relaying communications of the target device 12; or the abnormality detection unit 101 sends a shutdown request to the communication unit 122 of the target device 12 via the communication unit 102, and the device main body 121 of the target device 12 stops the communication unit 122 or the power receiving unit 123.
[0056] Preferably, the shutdown method can be selected for each identifier of the target device 12. For example, if the target device 12 requires a long time to resume normal operation after power supply is restored, selecting a method that only stops communication without stopping the power supply has the advantage of enabling selective shutdown of communications, thereby localizing the impact of the shutdown. Furthermore, given the variety of forms of spoofing described above, it is desirable to be able to selectively shut down communications depending on the form of spoofing. For example, in the case of power spoofing, stopping the power supply from the diverted power control device 13 to the attacker device is effective. On the other hand, in the case of communication spoofing, stopping the power supply from the power control device 13 only stops the operation of the normal target device 12, and does not stop the operation of the attacker device. Therefore, in this case, shutting down communications at the relay device 11 is effective.
[0057] The notification and blocking may or may not continue after a predetermined period has elapsed since the abnormality was detected. The predetermined period here may be determined arbitrarily.
[0058] According to this processing, the shutdown method can be selected, thereby localizing the impact of shutdown of the target device.
[0059] [Processing Procedure] FIG. 9 is a flowchart showing the processing procedure of the spoofing detection device according to the embodiment. First, the anomaly detection unit 101 of the anomaly detection device 10 acquires the above-described network communication status and power supply status for a single target device 12 for a predetermined period. The network communication status is acquired from the storage unit 113 of the relay device 11 (S101). The power supply status is acquired from the storage unit 133 of the power supply control device 13 (S102). Subsequently, spoofing detection is performed (S103). If it is determined that the target device 12 is possibly spoofed (Yes in S104), the relay device 11 or the power supply control device 13 is notified of the determination of the possibility of spoofing (S105). Subsequently, it is determined whether or not shutdown is necessary (S106). If shutdown is necessary (Yes in S107), the target device 12 is shut down (S108). If it is determined in step S104 that there is no possibility of spoofing (No in S104), the processing ends. If it is determined in step S107 that no cutoff is necessary (No in S107), the process ends. After the process of step S108 is executed, the process ends.
[0060] [Details of Spoofing Determination Process] FIG. 10 is a flowchart showing the procedure of the spoofing determination process (S103) of the spoofing detection device according to the embodiment. The anomaly detection unit 101 associates information on the network communication status and the power supply status with the identifier of the target device (S1031), stores the information in the storage unit 103 (S1032), and performs spoofing determination based on the information. At this time, communication spoofing detection (S1033) and power supply spoofing detection (S1034) are performed. Note that steps S1033 and S1034 may be performed simultaneously, or one of them may be performed first. Thereafter, the detection results are output (S1035). A specific example of communication spoofing detection is shown below using FIG. 11, and a specific example of power supply spoofing detection is shown below using FIG. 12.
[0061] [Specific Example of Spoofing Determination Process] FIGS. 11, 12, and 13 show examples of data detected in the spoofing determination process of the spoofing detection device according to the embodiment.
[0062] 11 shows data that can detect changes in the network communication state even when the power supply to the target device 12 has been stopped. By checking this data, it is possible that an attacker device is present within range 33, spoofing communications by using the same identifier as the target device 12. In other words, it is possible to detect communications spoofing.
[0063] 12 shows data that can detect changes in the network communication state between one period and another when the power supply state of the target device 12 changes periodically. By checking this data, it is possible that an attacker device spoofing the same identifier as the target device 12 exists within the range 33. For example, an attacker device within the same range 33 as the target device 12 may be receiving power from a power source other than the power source 14 of the target device 12, such as another power source 15 of another device 16 shown in FIG. 1, and operating as such. In other words, power source spoofing can be detected. The period here may simply be a unit of time such as one day or one hour, or it may be the average time over which the power supply state changes.
[0064] 13 shows data that can detect changes in the power supply state between one period and another period when the power supply state of the target device 12 changes periodically. In addition to the communication spoofing shown in FIG. 12, this data can also detect spoofing that involves momentary power supply interruptions, and failures such as power outages and equipment failures.
[0065] [Details of Shutdown Determination Process] FIG. 14 is a flowchart showing the processing procedure of the shutdown process (S106) of the spoofing detection device according to the embodiment. Based on the detection result of step S1033 described above, the anomaly detection unit 101 determines the possibility of communication spoofing (S1061). If there is a possibility of communication spoofing, a communication shutdown request is issued (S1062). Based on the detection result of step S1034 described above, the anomaly detection unit 101 also determines the possibility of power supply spoofing (S1063). If there is a possibility of power supply spoofing, a power shutdown request is issued (S1064). Steps S1061 and S1063 may be executed simultaneously, or one of them may be executed first. The issued shutdown request is then output (S1065). To prevent the same target device 12 from being notified of detection or shutdown requests multiple times, the anomaly detection unit 101 may store, for each target device ID, whether a detection notification has been sent or whether a shutdown request has been sent.
[0066] [Details of Relay Processing and Power Supply Control Device Processing] FIG. 15 is a flowchart showing the processing steps of the relay device 11 and the power supply control device 13 involved in the spoofing detection processing of the spoofing detection device 1 according to the embodiment. These devices acquire information on the network communication status and power supply status by linking the target device 12's identifier with the power line ID or signal line ID, and store the information in the storage unit 113 or 133 (S1041). When a spoofing detection notification is received (Yes in S1042), preparations are made to disconnect the power line with the power line ID or the signal line with the signal line ID corresponding to the target device ID (S1043). This may be, for example, a notification of disconnection from each device to the user. Furthermore, when a disconnection request is received (Yes in S1044), the power line or signal line connected to the target device is preferably disconnected (S1045). When the disconnection is completed, the disconnection preparation for the target device ID is canceled (S1046). If no spoofing detection notification is received in step S1042 (No in S1042), the process skips step S1043 and proceeds to step S1044. If no shutdown request is received in step S1044 (No in S1044), the process ends.
[0067] [Effects] The effects obtained from the disclosure of this specification will be described below.
[0068] Effect 1: By connecting to a target device using a relay device and a power control device, the network communication status and power supply status can be linked and acquired as information related to a single target device, making it possible to detect spoofing.
[0069] Effect 2: By analyzing the communication status and power supply status of the network described above from the time the target device is started up, it is possible to detect spoofing without stopping the power supply to the target device during the detection process.
[0070] Effect 3: When shutdown is necessary based on the detection results described above, the shutdown method can be selected, thereby localizing the impact of shutdown on the target device.
[0071] The above-described effects are achieved by one or more combinations of the effects of the following aspects of the present disclosure and the respective aspects.
[0072] An information processing method according to a first aspect of the present disclosure is an information processing method executed by a computer, and includes step S101 of acquiring a communication status between a target device 12 and a network, step S102 of acquiring a power supply status including time series information of power supplied to the target device 12, and step S103 of using the acquired communication status and power supply status to detect whether or not there has been impersonation, which would indicate that the target device 12 has been replaced with an attacker's device.
[0073] According to the information processing method of the first aspect, the presence or absence of spoofing can be detected by taking into account the time-series information of supplied power included in the acquired power supply status and determining whether the acquired communication status between the target device 12 and the network includes communications that indicate spoofing, in which the target device 12 has been replaced with an attacker's device. In other words, if the time-series information of supplied power can be acquired, the presence or absence of spoofing can be detected without setting the power supply to the target device 12 to a predetermined state. Therefore, the presence or absence of spoofing can be detected more appropriately in accordance with the circumstances of use of the industrial equipment.
[0074] In addition, the information processing method according to the second aspect is the information processing method according to the first aspect, in which a step of acquiring a communication status is performed using a relay device 11 that relays communication between the target device 12 and the network, and a step of acquiring a power supply status is performed using a power supply control device 13 that controls the power supplied to the target device 12.
[0075] According to the second aspect of the information processing method, by taking into consideration the time series information of the supplied power contained in the power supply status acquired using the power supply control device 13, it is possible to determine whether the communication status acquired using the relay device 11 includes any communication indicating impersonation in which the target device 12 has been replaced by an attacker device, thereby detecting whether impersonation has occurred.
[0076] Furthermore, the information processing method according to the third aspect is the information processing method according to the second aspect, in which, in the relay device 11, a device ID for distinguishing the target device 12 from other devices 16 is linked to a communication management ID (e.g., a signal line ID) related to communication between the target device 12 and the network, and, in the power supply control device 13, the device ID for distinguishing the target device 12 from other devices 16 is linked to a power management ID (e.g., a power line ID) related to the power supply to the target device 12.
[0077] According to the information processing method of the third aspect, it is possible to detect whether or not a certain device ID of a target device 12 is being spoofed by taking into account time-series information on supplied power included in the power supply status acquired using the power supply control device 13, and determining whether or not the communication status acquired using the relay device 11 includes communications indicating spoofing in which the target device 12 has been replaced with an attacker's device. Then, depending on the detection result of whether or not the target device 12 is being spoofed, by transmitting a handling instruction using the device ID to the power supply control device 13 and the relay device 11, the communication management ID and power management ID are substituted in each device, and handling using the communication management ID and power management ID can be performed.
[0078] In addition, an information processing method according to a fourth aspect is an information processing method according to any one of the first to third aspects, and executes a detection step using a communication status acquired during a period in which the power supply status indicates that power is being supplied to the target device 12.
[0079] According to the information processing method of the fourth aspect, even during a period when the power supply status indicates that power is being supplied to the target device 12, it is possible to detect whether or not the target device 12 is being impersonated based on the power supply status and communication status.
[0080] In addition, an information processing method according to a fifth aspect is an information processing method according to any one of the first to fourth aspects, in which the spoofing includes power spoofing in which an attacker device diverts power supplied to the target device 12 and disguises communication between the target device 12 and the network.
[0081] According to the information processing method of the fifth aspect, it is possible to detect whether or not power supply spoofing has occurred in the target device 12.
[0082] In addition, an information processing method according to a sixth aspect is an information processing method according to any one of the first to fifth aspects, in which the spoofing includes communication spoofing in which the attacker device does not divert power supplied to the target device 12 and disguises communication between the target device 12 and the network.
[0083] According to the information processing method of the sixth aspect, it is possible to detect whether or not communication spoofing has occurred in the target device 12.
[0084] In addition, an information processing method according to a seventh aspect is an information processing method according to any one of the first to sixth aspects, further including a step of cutting off communication between the attacker device and the network based on the detection result in the detection step, and the cutting off step includes at least one of cutting off the power supply to the attacker device and cutting off communication between the attacker device and the network.
[0085] According to the information processing method of the seventh aspect, it is possible to cut off communication between the attacker device and the network based on the detection result in the detecting step. Specifically, it is possible to indirectly cut off communication between the attacker device and the network by stopping the operation of the attacker device by cutting off the power supply to the attacker device, or to directly cut off communication between the attacker device and the network.
[0086] Furthermore, an information processing method according to an eighth aspect is the information processing method according to the seventh aspect, wherein the spoofing includes power spoofing, in which the attacker device diverts power supplied to the target device 12 and disguises communication between the target device 12 and the network, and communication spoofing, in which the attacker device does not divert power supplied to the target device 12 and disguises communication between the target device 12 and the network, and in the blocking step, if the detection result detects that there is power spoofing, the power supply to the attacker device is cut off, and if the detection result detects that there is communication spoofing, the communication between the attacker device and the network is cut off.
[0087] According to the information processing method of the eighth aspect, communication between the attacker device and the network can be blocked based on the detection result in the detection step. Specifically, if the detection result detects power supply spoofing, the target device 12 is being powered by other devices and only the attacker device is operating, so by cutting off the power supply to the attacker device, the operation of the attacker device can be stopped, and communication between the attacker device and the network can be indirectly blocked. Furthermore, if the detection result detects communication spoofing, the target device 12 is operating without being powered by other devices, so without cutting off the power supply, the operation of the target device 12 is not stopped by cutting off the power supply, but rather, communication between the attacker device and the network can be directly blocked by cutting off communication between the attacker device and the network, for example, by cutting off communication between the attacker device and the target device 12.
[0088] A program according to a ninth aspect is a program for causing a computer to execute the information processing method according to any one of the first to eighth aspects.
[0089] According to the program of the ninth aspect, when executed by a computer, it is possible to achieve the same effects as the information processing method described above.
[0090] In addition, the information processing device (impersonation detection device 1) according to the tenth aspect includes a first acquisition unit that acquires the communication status between the target device and the network, a second acquisition unit that acquires the power supply status including time series information of the power supplied to the target device, and a detection unit that uses the acquired communication status and power supply status to detect whether or not there is impersonation indicating that the target device has been replaced with an attacker device.
[0091] According to the information processing device of the tenth aspect, it is possible to achieve the same effects as the information processing method described above.
[0092] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.
[0093] For example, the impersonation detection device described in the above embodiment may be realized as a single device that has all of the components, or may be realized by allocating each function to multiple devices and having these multiple devices work together.
[0094] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.
[0095] Furthermore, the communication standard or power supply standard used by each device may be any standard and is not particularly limited.
[0096] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.
[0097] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.
[0098] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a system, a method, an integrated circuit, a computer program, and a recording medium.
[0099] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope of this disclosure.
[0100] The present disclosure is useful for detecting spoofing of industrial devices to which the power supply cannot be inadvertently cut off.
[0101] 1 Spoofing detection device 10 Anomaly detection device 11 Relay device 12 Target device 13 Power supply control device 14 Power supply 15 Other power supply 16 Other device 21, 24 Signal line 22, 23, 25 Power line 31, 32, 33, 34 Range 101 Anomaly detection unit 102, 112, 122, 132 Communication unit 103, 113, 133 Storage unit 111 Relay unit 121 Device main body 123, 134 Power receiving unit 131 Power supply control unit 135, 141 Power distribution unit
Claims
1. An information processing method executed by a computer, comprising: steps of acquiring a communication status between a target device and a network; acquiring a power supply status including time-series information on power supplied to the target device; and using the acquired communication status and power supply status to detect whether or not the target device has been spoofed, which indicates that the target device has been replaced with an attacker's device.
2. The information processing method according to claim 1, further comprising: executing a step of acquiring the communication status using a relay device that relays communication between the target device and a network; and executing a step of acquiring the power supply status using a power control device that controls the power supplied to the target device.
3. An information processing method as described in claim 2, wherein in the relay device, a device ID for distinguishing the target device from other devices is linked to a communication management ID related to communication between the target device and a network, and in the power supply control device, a device ID for distinguishing the target device from other devices is linked to a power management ID related to power supply to the target device.
4. The information processing method according to claim 1, wherein the detecting step is performed using the communication status acquired during a period in which the power supply status indicates that power is being supplied to the target device.
5. The information processing method according to claim 1, wherein the spoofing includes power spoofing in which the attacker device diverts power supplied to the target device and disguises communication between the target device and a network.
6. The information processing method according to claim 1, wherein the spoofing includes communication spoofing in which the attacker device does not divert power supplied to the target device and disguises communication between the target device and a network.
7. An information processing method as described in claim 1, further comprising a step of cutting off communication between the attacker device and the network based on the detection result in the detection step, wherein the cutting off step includes cutting off at least one of the power supply to the attacker device and the communication between the attacker device and the network.
8. The information processing method of claim 7, wherein the spoofing includes power spoofing, in which the attacker device diverts power supplied to the target device and spoofs communications between the target device and the network, and communication spoofing, in which the attacker device does not divert power supplied to the target device and spoofs communications between the target device and the network, and wherein the blocking step, if the detection result detects that there is power spoofing, cuts off the power supply to the attacker device, and if the detection result detects that there is communications spoofing, cuts off communications between the attacker device and the network.
9. A program for causing a computer to execute the information processing method according to any one of claims 1 to 8.
10. An information processing device comprising: a first acquisition unit that acquires the communication status between a target device and a network; a second acquisition unit that acquires the power supply status including time series information of the power supplied to the target device; and a detection unit that uses the acquired communication status and power supply status to detect whether or not there is impersonation indicating that the target device has been replaced with an attacker's device.
Citation Information
Patent Citations
Spoofing detection device, spoofing detection method and computer program
JP2019129500A
In-vehicle system
JP2022160932A
Attack detection device
WO2016185514A1