Information processing method, information processing device, and program

An information processing method generates use case information and calculates anomaly degrees for communication packets, addressing the challenge of detecting anomalies in ICS and IoT systems, improving cyber threat detection through enhanced analysis.

WO2026034283A1PCT designated stage Publication Date: 2026-02-12PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/026757
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-09
Filing Date
2025-07-28
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing systems lack an efficient method for analyzing communication packets to accurately detect anomalies, particularly in environments like Industrial Control Systems (ICS) and Internet of Things (IoT), where communication is often clearly defined and not encrypted, necessitating a method that can easily and accurately analyze these packets to identify potential cyber attacks.

Method used

An information processing method that acquires specification information and generates use case information based on communication packets, followed by calculating the degree of anomaly using a use case extraction device and an anomaly degree calculation device, employing rule information and language models to determine and quantify anomalies in communication packets.

Benefits of technology

Enhances the ability to analyze communication packets, improving the detection of anomalies and facilitating the identification of potential cyber threats by leveraging use case information and anomaly degree calculation, thereby enhancing security in ICS and IoT environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025026757_12022026_PF_FP_ABST
    Figure JP2025026757_12022026_PF_FP_ABST
Patent Text Reader

Abstract

An information processing method according to one aspect of the present disclosure acquires at least one of specification information indicating communication specifications of a system and a first communication packet used in the system (S310), and generates use case information indicating one or more use cases of the system on the basis of the acquired at least one of the specification information and the first communication packet (S320).
Need to check novelty before this filing date? Find Prior Art

Description

Information processing method, information processing device, and program

[0001] The present disclosure relates to an information processing method, an information processing device, and a program.

[0002] Conventionally, there are methods for analyzing communication packets used in cyber attacks, etc. Non-Patent Document 1 discloses a tool for malware analysis.

[0003] Tammo Krueger, Hugo Gascon, Nicole Kramerm and Konrad Rieck, “Learning Stateful Models for Network Honeypots”, Proceedings of the 5th ACM workshop on Security and artificial intelligence (AISec 2012), October 2012, Pages 37-48

[0004] The present disclosure provides an information processing method and the like that can facilitate the analysis of communication packets.

[0005] An information processing method according to one aspect of the present disclosure acquires specification information indicating communication specifications in a system and / or a first communication packet used in the system, and generates use case information indicating one or more use cases of the system based on the acquired specification information and / or a first communication packet used in the system.

[0006] An information processing method according to one aspect of the present disclosure acquires communication packets used in a system and calculates the degree of anomaly of the acquired communication packets based on use case information indicating one or more use cases of the system.

[0007] An information processing device according to one aspect of the present disclosure includes a processor and a memory, and the processor uses the memory to acquire specification information indicating communication specifications in a system and / or a first communication packet used in the system, and generates use case information indicating one or more use cases of the system based on the acquired at least one.

[0008] An information processing device according to one aspect of the present disclosure includes a processor and a memory, acquires communication packets used in a system, and calculates the degree of anomaly of the acquired communication packets based on use case information indicating one or more use cases of the system.

[0009] A program according to one aspect of the present disclosure is a program for causing a computer to execute the information processing method described above.

[0010] According to the present disclosure, it is possible to provide an information processing method that makes it easier to analyze communication packets.

[0011] FIG. 1 is a diagram illustrating a configuration of a network system according to an embodiment. FIG. 2 is a diagram illustrating a configuration of a security system according to an embodiment. FIG. 3 is a diagram illustrating a specific example of a processing procedure of a use case extraction device according to an embodiment. FIG. 4 is a diagram illustrating asset information according to an embodiment. FIG. 5 is a diagram illustrating asset information according to an embodiment. FIG. 6 is a diagram illustrating asset information according to an embodiment. FIG. 7 is a diagram illustrating given use case information according to an embodiment. FIG. 8 is a diagram illustrating specification information according to an embodiment. FIG. 9 is a diagram illustrating a processing for extracting related context information according to an embodiment. FIG. 10 is a diagram illustrating a processing for extracting use cases according to an embodiment. FIG. 11 is a diagram illustrating a processing for improving the accuracy of use cases according to an embodiment. FIG. 12 is a diagram illustrating use case information according to an embodiment. FIG. 13 is a diagram illustrating a processing for quantifying anomalies using use case information according to an embodiment. FIG. 14 is a diagram illustrating a processing for generating rule information according to an embodiment. FIG. 15 is a diagram illustrating a processing for extracting higher-level use cases according to an embodiment. FIG. 16 is a diagram illustrating a processing for improving the accuracy of higher-level use cases according to an embodiment. FIG. 17 is a flowchart illustrating a processing procedure of a security system according to an embodiment. FIG. 18 is a flowchart showing a specific example of use case accumulation processing according to an embodiment. FIG. 19 is a flowchart showing a specific example of given use case accumulation processing according to an embodiment. FIG. 20 is a flowchart showing a specific example of use case accumulation processing based on communication data analysis according to an embodiment. FIG. 21 is a flowchart showing a specific example of anomalous packet detection processing according to an embodiment. FIG. 22 is a flowchart showing a specific example of use case determination processing according to an embodiment. FIG. 23 is a diagram showing the configuration of a security system according to a modified example. FIG. 24 is a flowchart showing a first example of an information processing method according to an embodiment. FIG. 25 is a flowchart showing a second example of an information processing method according to an embodiment.

[0012] (Knowledge forming the basis of the present disclosure) There are systems such as an IDS (Intrusion Detection System) that detect abnormal communication packets (also called abnormal packets) such as communication packets used in cyber attacks and output an alert to an SOC (Security Operation Center) or the like. When an SOC acquires such an alert, it analyzes the communication packet that caused the alert to be output. Therefore, there is a need for a method that can easily analyze communication packets performed by an SOC or the like. There is also a need for a method that can accurately detect such abnormal packets.

[0013] Here, the inventors of the present application focused on a use case of a system that includes a device to be monitored.

[0014] For example, in communication environments such as an Industrial Control System (ICS) or the Internet of Things (IoT), the use case of communication is often clearly defined according to the communication link (specifically, the source IP (Internet Protocol) address, the destination IP address, the port number, etc.). Furthermore, in communication environments such as an ICS or IoT, communication (specifically, communication packets) is often not encrypted. Therefore, by monitoring communication packets, deviations from the use case in the system can be detected. Thus, the inventors of the present application have discovered that monitoring communication packets using use cases is useful for detecting communication anomalies.

[0015] Hereinafter, the embodiments will be specifically described with reference to the drawings.

[0016] The embodiments described below are all comprehensive or specific examples. The numerical values, shapes, materials, components, component placement and connection configurations, steps, and step order shown in the following embodiments are merely examples and are not intended to limit the present disclosure. Furthermore, among the components in the following embodiments, components that are not recited in the independent claims of the present disclosure are described as optional components. Furthermore, the drawings are not necessarily strict illustrations. In the drawings, substantially identical components are denoted by the same reference numerals, and redundant descriptions may be omitted or simplified.

[0017] Furthermore, in this specification, ordinal numbers such as "first" and "second" do not refer to the number or order of components unless otherwise specified, but are used for the purpose of avoiding confusion and distinguishing between components of the same type.

[0018] Furthermore, in this specification, when a statement is made in contrast to, for example, "greater than a threshold value" or "less than a threshold value," it means that the distinction is made on the basis of the threshold value, and may mean "greater than the threshold value" or "less than the threshold value," respectively.

[0019] (Embodiment) [Configuration] FIG. 1 is a diagram showing the configuration of a network system 1 according to an embodiment.

[0020] The network system 1 is a system that detects abnormalities in communication packets transmitted or received by a monitoring target 20. The network system 1 includes a security system 10 and a monitoring target 20.

[0021] The security system 10 is a system for receiving communication packets sent or received by the monitoring target 20, i.e., communication packets used by the monitoring target 20, and detecting anomalies in the received communication packets (i.e., determining whether or not there is an anomaly in the communication packets). Specifically, the security system 10 calculates the degree of anomaly in the communication packets.

[0022] The degree of abnormality is the degree of possibility that a communication packet is abnormal. For example, the higher the degree of abnormality, the more likely the communication packet is an abnormal packet used in a cyber attack, etc. On the other hand, for example, the lower the degree of abnormality, the more likely the communication packet is a harmless communication packet that is normally used by the monitoring target 20.

[0023] The monitoring target 20 is a communication device capable of sending and receiving communication packets. The device employed as the monitoring target 20 may be determined arbitrarily and is not particularly limited. For example, the monitoring target 20 is a communication-capable device (e.g., IoT device) such as an air conditioning device or lighting device (lighting equipment) used in a building or other structure.

[0024] The security system 10 and the monitored object 20 each include, for example, one or more computers. The computers are realized, for example, by a communication interface, non-volatile memory storing programs, volatile memory serving as temporary storage for executing the programs, input / output ports for transmitting and receiving signals, and a processor for executing the programs. The communication interface may be realized, for example, by an antenna and a wireless communication circuit for enabling wireless communication, or by a connector to which a communication line is connected for wired communication.

[0025] The number of monitoring targets 20 included in the network system 1, that is, the number of monitoring targets 20 monitored by the security system 10, may be one or more.

[0026] FIG. 2 is a diagram showing the configuration of a security system 10 according to an embodiment.

[0027] The security system 10 includes a use case extraction device 100 and an anomaly degree calculation device 200 .

[0028] The use case extraction device 100 is a computer that generates use case information indicating one or more use cases of the network system 1 (specifically, the multiple monitoring targets 20 included in the network system 1). The use case extraction device 100 is an example of an information processing device.

[0029] A use case is, for example, information about a specific example of control (e.g., communication control) performed in the network system 1. Use case information is, for example, information indicating a use case, in other words, information including a use case. The use case information is, for example, information indicating a device that is the target of control performed in the network system 1 (e.g., one of the multiple monitored devices 20), a control source device that controls the device, the type (content) of control, timing of control, etc. For example, in this information, a group of devices that are the target of control and have specific common properties, or the same commands for performing control, are categorized into the same group, and information indicating the role of communication in the categorized group (e.g., on / off control, initialization, status notification, etc.) is linked to the device.

[0030] The use case information is information including, for example, text data that indicates such a use case in a sentence (context). In other words, the text data is information that indicates a sentence that explains the use case.

[0031] The use case extraction device 100 is realized, for example, by a communication interface, non-volatile memory in which programs are stored, volatile memory which is a temporary storage area for executing the programs, input / output ports for sending and receiving signals, and a processor that executes the programs.

[0032] The use case extraction device 100 includes a use case extraction unit 110 and a use case matching unit 120 .

[0033] The use case extraction unit 110 is a processing unit that extracts use cases for multiple monitoring targets 20 from information about the multiple monitoring targets 20. Specifically, the use case extraction unit 110 creates one or more use cases for one or more monitoring targets 20 based on information about the one or more monitoring targets 20, and generates use case information indicating the created one or more use cases. For example, the use case extraction unit 110 stores the created use case information in the use case list storage unit 300 as a use case list.

[0034] The use case list storage unit 300 is a storage device that stores use case information. The use case list storage unit 300 is realized by, for example, a hard disk drive (HDD) or a solid state drive (SSD). The use case list storage unit 300 is provided, for example, in a server device (not shown) provided in the network system 1. The use case extraction device 100 or the anomaly degree calculation device 200 may also include the use case list storage unit 300.

[0035] The use case matching unit 120 is a processing unit that determines which of one or more use cases included in use case information a use case based on a detection target packet 400, which is a communication packet for which the anomaly degree calculation device 200 calculates an anomaly degree, relates. Specifically, the use case matching unit 120 determines a use case based on the detection target packet 400. More specifically, the use case matching unit 120 acquires the detection target packet 400 from the monitoring target 20 or the like, and determines, based on the acquired detection target packet 400, whether to determine a use case based on the detection target packet 400 using rule information or to create a use case based on the detection target packet 400 using a language model (specifically, LLM (Large Language Models)). The use case matching unit 120 determines the use case of the detection target packet 400 using the determined method. The detection target packet 400 is an example of a second communication packet.

[0036] The use case matching unit 120, for example, determines whether a use case based on the detection target packet 400 can be determined using the rule information. For example, if the use case matching unit 120 determines that a use case based on the detection target packet 400 can be determined using the rule information, the use case matching unit 120 determines the use case based on the detection target packet 400 using the rule information. On the other hand, if the use case matching unit 120 determines that a use case based on the detection target packet 400 cannot be determined using the rule information, the use case matching unit 120 creates a use case based on the detection target packet 400 using a language model. For example, if the metadata included in the detection target packet 400 is the same as the metadata included in the rule information, the use case matching unit 120 determines that the use case can be determined using the rule information. On the other hand, if the metadata included in the detection target packet 400 is not the same as the metadata included in the rule information, the use case matching unit 120 determines that the use case cannot be determined using the rule information. The use case matching unit 120 outputs information indicating the use case based on the detection target packet 400 determined in this manner and the use case information generated by the use case extraction unit 110 to the anomaly degree calculation device 200.

[0037] The rule information is information for creating (determining) a use case based on the detection target packet 400. The rule information is also used to calculate the degree of anomaly of the detection target packet 400. The rule information includes, for example, metadata that is estimated to be included in the detection target packet 400. The metadata includes, for example, the IP address of the sender of the communication packet (source IP address), the IP address of the destination of the communication packet (destination IP address), and information indicating the content of the process to be executed at the destination by the communication packet. The type of metadata may be determined arbitrarily and is not particularly limited.

[0038] The use case matching unit 120, for example, acquires use case information from the use case list storage unit 300, and based on the acquired use case information, estimates metadata contained in communication packets used in the network system 1 (specifically, metadata that may be contained in the detection target packet 400), and generates rule information including the estimated metadata.

[0039] The abnormality degree calculation device 200 is a computer that calculates the abnormality degree of the detection target packet 400 based on use case information.

[0040] The abnormality degree calculation device 200 is realized, for example, by a communication interface, a non-volatile memory in which a program is stored, a volatile memory which is a temporary storage area for executing the program, an input / output port for sending and receiving signals, and a processor that executes the program.

[0041] The abnormality degree calculation device 200 includes an abnormality degree calculation unit 210 .

[0042] The anomaly degree calculation unit 210 is a processing unit that calculates the degree of anomaly of the detection target packet 400 based on use case information. Specifically, the anomaly degree calculation unit 210 calculates the degree of anomaly of the detection target packet 400 based on the use case information generated by the use case extraction device 100. For example, the anomaly degree calculation unit 210 calculates the degree of anomaly of the detection target packet 400 based on a use case based on the detection target packet 400 and the use case information.

[0043] Furthermore, the abnormality degree calculation unit 210 outputs abnormality degree information 410 indicating the calculated abnormality degree. For example, the abnormality degree calculation unit 210 transmits the abnormality degree information 410 to a terminal (computer) used in the SOC. For example, the computer notifies an analyst or the like of the abnormality degree information 410 using a display or audio equipment.

[0044] Each processing unit such as the use case extraction unit 110, the use case matching unit 120, and the anomaly degree calculation unit 210 is realized, for example, by a memory and a processor such as a CPU (Central Processing Unit) that executes a control program stored in the memory. Furthermore, for example, the memory provided in the processing units such as the use case extraction unit 110 and the use case matching unit 120 may be realized by a common memory, or may be realized by one or more independent memories. Furthermore, the processor provided in the processing units such as the use case extraction unit 110 and the use case matching unit 120 may be realized by a common processor for each processing unit, or may be realized by one or more independent processors for each processing unit.

[0045] [Specific Examples] Next, specific examples of various types of information used in the security system 10 and specific examples of various types of processing in the security system 10 will be described.

[0046] 3 is a diagram for explaining a specific example of a processing procedure of the use case extraction device 100 according to the embodiment. Specifically, FIG. 3 is a diagram specifically illustrating the flow of processing executed by the use case extraction unit 110.

[0047] First, the use case extraction device 100 acquires the public information 420 and the specification information 430 from a server device or the like.

[0048] The public information 420 is, for example, information about the network system 1 (specifically, a plurality of monitoring targets 20) that is generally publicly available on the Internet or the like.

[0049] The specification information 430 is information indicating the specifications of the network system 1 and the specifications of each of the multiple monitored objects 20. The information indicating the specifications of the network system 1 is, for example, information indicating communication specifications such as communication standards used in the network system 1. Furthermore, the information indicating the specifications of the monitored objects 20 is, for example, information indicating the type and performance of the equipment, such as if the monitored object 20 is a lighting device.

[0050] The use case extraction device 100 acquires this information from, for example, a server device and a monitoring target 20 that communicate with the use case extraction device 100 .

[0051] Next, the use case extraction device 100 performs a vector store creation process to create a vector store (vector store information) including information indicating the character strings and the vectors by converting the character strings included in this information into vectors (S10). That is, in step S10, the use case extraction device 100 converts sentences indicating information regarding the network system 1, specifications of the network system 1, and information regarding the specifications of each of the multiple monitoring targets 20 into vectors. The use case extraction device 100 outputs the created vector store to a server device or the like, where it is stored in the vector store storage unit 310, which is a storage device included in the server device.

[0052] The use case extraction device 100 also acquires given use case information 440. The given use case information 440 is information indicating known use cases of the monitoring target 20. The use case extraction device 100 acquires the given use case information 440 via an operation device such as a mouse, a keyboard, or a touch panel operated by a user, for example.

[0053] Next, the use case extraction device 100 performs a given use case information shaping process to convert the given use case information 440 into a predetermined format (S20). It is highly likely that the use cases represented by the given use case information 440 are represented in a unique format. Therefore, in step S20, the use case extraction device 100 converts the given use case information 440 into a format that can be used by the security system 10. The information shown in FIG. 7 (described later) is an example of the given use case information 440 before conversion, and some use cases (normalized use cases), such as use case 720 (described later) shown in FIG. 12 (described later), are examples of the given use case information 440 after conversion. For example, the use case information stored in the use case list storage unit 300 is text data representing a character string such as that shown in FIG. 12. The converted given use case information 440 is stored in the use case list storage unit 300.

[0054] Next, the use case extraction device 100 acquires the extraction target packet 450 and the asset information 460 from the server device or the monitoring target 20 or the like.

[0055] The extraction target packet 450 is a communication packet used by the monitoring target 20. For example, when executing step S30 described below, the use case extraction device 100 acquires a communication packet used by the monitoring target 20 during an arbitrary period in the past as the extraction target packet 450. The arbitrary period is set in advance, such as one week, but may be any period and is not particularly limited. The extraction target packet 400 is an example of a first communication packet.

[0056] The asset information 460 is information relating to the monitoring target 20. The asset information 460 includes information indicating the name, IP address, and MAC (Media Access Control) address of the monitoring target 20, for example.

[0057] The use case extraction device 100 performs an information acquisition query generation process to generate a query for generating related context information 470 based on the extraction target packet 450 and the asset information 460 (S30). Specifically, the use case extraction device 100 generates a query (e.g., query 500 shown in FIG. 9 ) for extracting use cases from the extraction target packet 450 and the asset information 460 based on the extraction target packet 450 and the asset information 460, and extracts (generates) use cases from the extraction target packet 450 and the asset information 460 using the generated query. Note that the query may be arbitrarily determined in advance. In this case, in step S30, the use case extraction device 100 extracts use cases from the extraction target packet 450 and the asset information 460 using the predetermined query.

[0058] Next, the use case extraction device 100 performs a related context information acquisition process to acquire related context information 470 based on the vector store generated in step S10 and the use cases extracted in step S30 (S40).

[0059] The related context information 470 is information indicating a sentence related to a use case of the monitoring target 20. For example, the use case extraction device 100 converts a sentence (character string) indicating the use case extracted in step S30 into a vector. The related context information 470 is information indicating a character string (sentence) corresponding to a vector that matches the converted vector, among the multiple vectors included in the vector store generated in step S10. The related context information 470 is an example of related information.

[0060] Next, the use case extraction device 100 performs a use case extraction query generation process (S50) to generate a query for generating (extracting) use cases based on the extraction target packet 450, asset information 460, and related context information 470. Specifically, the use case extraction device 100 generates a query (e.g., query 510 shown in FIG. 10 ) for extracting use cases from the extraction target packet 450, asset information 460, and related context information 470 based on the extraction target packet 450, asset information 460, and related context information 470, and then uses the generated query to extract (generate) use cases from the extraction target packet 450, asset information 460, and related context information 470. In other words, step S50 improves the accuracy of the use cases (sentences) extracted in step S40. The use case extraction device 100 stores use case information indicating the extracted use cases in the use case list storage unit 300. Note that the query may be determined in advance. In this case, in step S50, use cases are extracted from the extraction target packet 450, asset information 460, and related context information 470 using a predetermined query, and use case information indicating the extracted use cases is stored in the use case list storage unit 300.

[0061] Note that the use case extraction device 100 may acquire the public information 420, the specification information 430, the given use case information 440, the extraction target packet 450, and the asset information 460 by any method, and is not particularly limited. For example, the use case extraction device 100 may acquire the public information 420, the specification information 430, the given use case information 440, the extraction target packet 450, and the asset information 460 from a user via an operation device, from a server device other than the network system 1, or from a device such as the monitoring target 20 included in the network system 1. Furthermore, this information may be stored in a storage device included in the use case extraction device 100, and the use case extraction device 100 may acquire this information from the storage device.

[0062] The use case extraction device 100 may also include a vector store storage unit 310 .

[0063] In step S10, the character strings extracted from the public information 420 and the specification information 430 may be converted into a predetermined format, and the converted character strings may be converted into vectors.

[0064] 4 to 6 are diagrams illustrating asset information 460 according to an embodiment. Specifically, FIG. 4 is a diagram illustrating a list (device list) of multiple monitoring targets 20 included in the network system 1, which is included in the asset information 460. FIG. 5 is a diagram illustrating the network configuration (more specifically, routing information) in the network system 1, which is included in the asset information 460. FIG. 6 is a diagram illustrating the network configuration (more specifically, firewall settings) in the network system 1, which is included in the asset information 460. That is, for example, the asset information 460 includes the device list illustrated in FIG. 4, the routing information illustrated in FIG. 5, and information indicating the firewall settings illustrated in FIG. 6.

[0065] The device list includes information indicating the name of the monitoring target 20 ("Device Name" shown in FIG. 4), information indicating the IP address of the monitoring target 20 ("IP Address" shown in FIG. 4), information indicating the MAC address of the monitoring target 20 ("MAC Address" shown in FIG. 4), information indicating the content of the processing executed by the monitoring target 20 ("Role" shown in FIG. 4), and information indicating the location where the monitoring target 20 is located ("Location" shown in FIG. 4).

[0066] For example, the No. 1 monitored object 20 has the name "BA server," the IP address "192.168.1.10," the MAC address "AA:AA:AA:AA:AA:AA:AA," monitors and controls other devices, and is located in the "Building safety control center."

[0067] The routing information includes information indicating the IP address of the destination ("Dst IP Address" shown in FIG. 5), information indicating the netmask ("Netmask" shown in FIG. 5), information indicating the IP address of the device through which the communication packet passes ("Next Hop Address" shown in FIG. 5), information indicating the type of communication interface ("Interface" shown in FIG. 5), information indicating the metric ("Metric" shown in FIG. 5), and information indicating the communication path ("Method" shown in FIG. 5).

[0068] The information indicating the firewall settings includes, for example, information indicating the source IP address ("Src IP Address" shown in FIG. 6), information indicating the destination IP address ("Dst IP Address" shown in FIG. 6), information indicating the communication protocol ("Protocol" shown in FIG. 6), information indicating the source port number ("Src Port" shown in FIG. 6), information indicating the destination port number ("Dst Port" shown in FIG. 6), and information indicating whether communication is permitted ("Action" shown in FIG. 6).

[0069] FIG. 7 is a diagram illustrating given use case information 440 according to an embodiment.

[0070] The given use case information 440 includes, for example, information indicating a source IP address ("Src IP Address" shown in FIG. 7), information indicating a destination IP address ("Dst IP Address" shown in FIG. 7), information indicating an application layer protocol ("Application Protocol" shown in FIG. 7), information indicating a port number and a transport layer protocol ("Port / Protocol" shown in FIG. 7), and information indicating the content of processing ("Usage" shown in FIG. 7). For example, No. 1 in the given use case information 440 indicates a use case in which a communication packet is sent from an IP address "192.168.1.20" to an IP address "192.168.1.10" using HTTP, a port number of 443, and TCP, for monitoring or operator control.

[0071] FIG. 8 is a diagram showing specification information 430 according to the embodiment.

[0072] The specification information 430 is information including text data that describes in sentences the contents of commands included in communication packets used in communications performed in the network system 1, such as "addListElement" or "removeListElement."

[0073] FIG. 9 is a diagram for explaining the extraction process of the related context information 470 according to the embodiment.

[0074] In step S30, for example, the use case extraction device 100 generates a query 500 including information contained in the extraction target packet 450 ("packet information" shown in FIG. 9 ) and asset information 460, along with a description such as "Estimate the purpose and effect of the next packet and extract a use case." The query 500 extracts a sentence (use case) corresponding to the description of the query 500 from the extraction target packet 450 and the asset information 460. Based on the extracted sentence, the related context information 470 is acquired (generated) in step S40. Specifically, the use case extraction device 100 converts the extracted sentence into a vector (S41). Furthermore, the use case extraction device 100 acquires (extracts) information indicating a character string (sentence) corresponding to a vector that matches the vector converted (generated) in step S41, from among multiple vectors contained in the vector store stored in the vector store storage unit 310, as the related context information 470 (S42). In this way, the use case extraction device 100 acquires the related context information 470.

[0075] FIG. 10 is a diagram illustrating the use case extraction process according to the embodiment.

[0076] In step S50, the use case extraction device 100 generates a query 510 that includes, for example, an explanatory statement such as "Estimate the purpose and effect of the next packet and extract a use case," as well as information included in the extraction target packet 450 ("Packet Information" shown in FIG. 10), asset information 460, and related context information 470 ("Related Context 1" and "Related Context 2" shown in FIG. 10). The query 510 extracts sentences corresponding to the explanatory statement of the query 510 from the extraction target packet 450, asset information 460, and related context information 470. The sentences extracted in this manner are input to the LLM 600.

[0077] The LLM 600 is a language model that receives a sentence as input and outputs a sentence indicating a use case corresponding to the sentence. The LLM 600 is a language model that has been trained to receive a sentence as input and output a sentence indicating a use case corresponding to the sentence.

[0078] The use case extraction device 100 uses the LLM 600 to extract (generate) a use case 700, such as "perform additional processing of an object linked to a schedule object of a lighting facility," from a sentence generated by the query 510. The LLM 600 is stored, for example, in a storage device included in the use case extraction device 100. In this way, the use case extraction device 100 generates use case information indicating the use case 700.

[0079] In this way, the use case extraction device 100 acquires information (e.g., public information 420, specification information 430, given use case information 440, and asset information 460) indicating communication specifications in the network system 1 (specifically, the multiple monitoring targets 20 included in the network system 1) and the extraction target packet 450, and generates use case information indicating one or more use cases in the network system 1 based on the acquired information. Note that all of this information may be used to generate the use case information, or at least one of this information may be used to generate the use case information. The public information 420, specification information 430, given use case information 440, and asset information 460 are each an example of specification information.

[0080] For example, the use cases indicated by the use case information may include use cases relating to control that is performed consecutively by any of the multiple monitoring targets 20 included in the network system 1. Use cases relating to control that is performed consecutively are, for example, use cases that summarize cases in which a certain process is always performed after a certain process. For example, the use case extraction device 100 may create one use case using multiple extraction target packets 450.

[0081] Furthermore, for example, when generating use case information, the use case extraction device 100 converts character strings indicated in this information (e.g., public information 420, specification information 430, and information indicating sentences extracted from extraction target packets 450 and asset information 460) into vectors, acquires related context information 470 based on these vectors, and generates use case information based on the acquired related context information 470. In this way, the use case extraction device 100 generates use case information using various information and LLM 600, for example, by applying RAG (Retrieval-Augmented Generation).

[0082] The created use case may be further improved to make it more appropriate.

[0083] Fig. 11 is a diagram for explaining the accuracy improvement process for a use case according to the embodiment. Note that the query 510 shown in Fig. 11 has the same content as the query 510 shown in Fig. 10, but some parts are omitted.

[0084] For example, the query 510 extracts sentences from the extraction target packet 450, the asset information 460, and the related context information 470. The sentences extracted in this manner are input to the LLM 610. As a result, the use case extraction device 100 creates a use case 710.

[0085] Like the LLM 600, the LLM 610 is a language model that takes a sentence as input and outputs a sentence indicating a use case corresponding to the sentence. The LLM 610 is a language model that has been trained to take a sentence as input and output a sentence indicating a use case corresponding to the sentence. Furthermore, the LLM 610 has been trained to output a sentence indicating a use case according to the content of the evaluation when an evaluation is input. For example, the LLM 610 has been trained to output a use case with different sentences when an evaluation is input and when an evaluation is not input. For example, the LLM 610 is stored in a storage device included in the use case extraction device 100.

[0086] The use case extraction device 100 displays the created use case (use case 710) on a display device such as a display connected to the use case extraction device 100. In this example, a sentence such as "Perform additional processing of objects linked to the schedule object (schedule, 101) of the lighting equipment" is displayed. The user checks the displayed use case 710 and inputs an evaluation (feedback) for the use case 710 using an operation device or the like. The use case extraction device 100 accepts the evaluation for the use case 710 via the operation device (S60).

[0087] For example, if the received (acquired) evaluation is low, the use case extraction device 100 recreates the use case using the LLM 610. Specifically, the LLM 610 receives the sentence extracted by the query 510 and information indicating the evaluation, and outputs the sentence and a sentence indicating a use case corresponding to the evaluation. In this way, the use case extraction device 100 recreates the use case.

[0088] The use case extraction device 100 displays the recreated use case (use case 711) on a display device such as a display connected to the use case extraction device 100. In this example, a sentence such as "Perform additional processing of objects linked to schedule objects of lighting equipment" is displayed. The user checks the displayed use case 711 and inputs an evaluation (feedback) for the use case 711 using an operation device or the like. The use case extraction device 100 accepts an evaluation for the use case via the operation device (S61). For example, if the received (acquired) evaluation is a high evaluation, the use case extraction device 100 terminates the processing. Note that the evaluation may be, for example, in two stages, high and low, but may be arbitrarily determined. For example, the LLM 610 may be trained to output use cases with different sentences for each evaluation stage.

[0089] FIG. 12 is a diagram illustrating use case information according to the embodiment.

[0090] The multiple use cases created as described above are hierarchically organized and displayed in use case information, for example, as shown in FIG. 12 . In other words, the use case information indicates one or more use cases classified into hierarchical levels. For example, the use case extraction device 100 assigns hierarchies to the created use cases. For example, the use case extraction device 100 associates a hierarchical level corresponding to the granularity of the sentences in the use case with the use case and stores the hierarchical level as use case information.

[0091] The granularity of a sentence is an index indicating the degree of detail of the information explained by the sentence. For example, the more specific the information explained by the sentence, in other words, the more detailed the content, the higher the granularity (fine). On the other hand, for example, the less specific the information explained by the sentence, in other words, the more abstract (vague), the lower the granularity (coarse). Furthermore, for example, use case information includes information indicating the degree of anomaly for each hierarchical level. For example, the lower the hierarchical level, the higher the granularity and the lower the anomaly level set. On the other hand, for example, the higher the hierarchical level, the lower the granularity and the higher the anomaly level set. Use case information includes, for example, information indicating these set granularity, hierarchical level, and anomaly level.

[0092] For example, the LLMs 600 and 610 output, along with the use cases, information indicating the granularity of the sentences indicating the use cases and / or the hierarchical level to which the use cases are assigned. Note that the given use case information 440 includes, for example, information indicating the granularity and / or hierarchical level of the use cases along with the use cases. For example, in step S20, the granularity and / or hierarchical level may be calculated using an LLM that inputs the use cases and outputs the granularity and / or hierarchical level of the use cases. Furthermore, the use case extraction device 100 may display the use cases on a display device, and the user may operate an operating device to set the granularity of the use cases or assign a hierarchical level to the use cases.

[0093] In this way, for example, the multiple use cases 720 to 728 created as shown in Figure 12 are classified by tier. Note that in the example shown in Figure 12, the total number of tiers is three, 0, 1, and 2, but this may be determined arbitrarily. In the example shown in Figure 12, tier = 0 is assigned to use cases 726, 727, and 728. Also, in the example shown in Figure 12, tier = 1 is assigned to use cases 722, 723, 724, and 725. In the example shown in Figure 12, tier = 2 is assigned to use cases 720 and 721.

[0094] For example, the sentences indicated by use cases 726, 727, and 728, which are assigned tier = 0, are more detailed (specific) and have higher granularity (finer) than use cases 722, 723, 724, and 725, which are assigned tier = 1. For example, tier 0 is defined as granularity 2, tier 1 is defined as granularity 1, and tier 2 is defined as granularity 0, but the granularity may also be defined arbitrarily, just like the tiers.

[0095] Furthermore, for example, the use case information includes information linking one use case with another use case that is a higher-level conceptualization of the one use case. For example, in the example shown in Fig. 12, use case 720 is a use case (higher-level use case) that is a higher-level conceptualization of use cases 722 and 723. For example, in the example shown in Fig. 12, use case 723 is a use case that is a higher-level conceptualization of use case 726. A higher-level conceptualization use case is, for example, a use case with more relaxed conditions than the original use case.

[0096] Information linking related use cases that correspond to such higher-level and lower-level concepts may be acquired arbitrarily. For example, the use case extraction device 100 may display use cases on a display device, and the user may operate an operation device to acquire information indicating such associations. Furthermore, for example, information indicating such associations may be acquired by a process of extracting (creating) higher-level use cases, which will be described later.

[0097] In this way, for example, the use case extraction device 100 classifies one or more use cases into one or more hierarchies (three hierarchies in this example) and generates use case information including information indicating the hierarchies into which the one or more use cases are classified. In other words, for example, one or more use cases indicated in the use case information are classified into one or more hierarchies.

[0098] In this example, there is a one-to-one correspondence between the hierarchical level of a use case and the granularity. In other words, in this example, it can be said that the use case extraction device 100 generates use case information that includes granularity information that indicates the granularity of each of one or more use cases. In other words, for example, the use case information includes granularity information that indicates the granularity of each of one or more use cases.

[0099] Furthermore, for example, the use case extraction device 100 estimates a use case (also referred to as a third use case) in which the acquired detection target packet 400 is used, and selects a use case (also referred to as a fourth use case) related to the estimated third use case from among one or more use cases indicated by the use case information. For example, the use case extraction device 100 calculates the degree of anomaly of the detection target packet 400 based on the hierarchy in which the selected fourth use case is classified. Alternatively, for example, the anomaly degree calculation device 200 calculates the degree of anomaly of the detection target packet 400 based on the granularity of the selected fourth use case. Related use cases are, for example, use cases with the same content, use cases with the same granularity, or use cases that correspond to a higher or lower concept.

[0100] The abnormality degree calculation device 200 calculates the abnormality degree of the detection target packet 400 using, for example, the use case information generated in this way.

[0101] FIG. 13 is a diagram for explaining the process of quantifying the degree of abnormality using use case information according to the embodiment.

[0102] The use case extraction device 100 creates a use case 729 based on the detection target packet 400, for example, by using a query and an LLM stored in a storage device included in the use case extraction device 100, and assigns a hierarchical level to the created use case 729. In the example shown in FIG. 13 , the use case 729 ("List all properties possessed by individual lighting objects") is a use case that corresponds to a subordinate concept of the use case 721, and is assigned to hierarchical level 1. For example, the use case extraction device 100 outputs the use case information shown in FIG. 13 (specifically, information including use cases 720 to 729) to the anomaly degree calculation device 200.

[0103] In this case, the abnormality degree calculation device 200 calculates the degree of abnormality of the detection target packet 400 as the degree of abnormality corresponding to tier = 1. For example, the abnormality degree calculation device 200 calculates the degree of abnormality of the detection target packet 400 as 1. The abnormality degree calculation device 200 outputs, for example, abnormality degree information 410 including the detection target packet 400 and information indicating the degree of abnormality to a terminal used in the SOC.

[0104] For example, the use case extraction device 100 first creates a use case 729 based on the acquired detection target packet 400. Next, the use case extraction device 100 searches the use case information (use cases 720 to 728) for a use case that indicates a sentence that describes the same information as the information described in the sentence indicated by the created use case 729. If a use case that indicates a sentence that describes the same information is not found, the use case extraction device 100 superimposes the sentence indicated by the use case 729 using, for example, the query 530 and the LLM 620 described below. Furthermore, the use case extraction device 100 searches for a use case that indicates a sentence that describes the same information as the information described in the sentence indicated by the new use case 729 that indicates the superimposed sentence. In this way, the use case is searched for by repeatedly superimposing the sentence indicated by the use case 729 created based on the acquired detection target packet 400, that is, by repeatedly lowering the granularity of the sentence. In this example, for example, the content of the sentence obtained by superimposing the created use case 729 once is the same as the content of the use case 721. Therefore, use case 729 is linked to use case 721 and assigned a hierarchical level one level below use case 721. In this way, the use case extraction device 100 (specifically, the use case matching unit 120) performs a matching process of assigning a hierarchical level to use case 729 based on the detection target packet 400. In this example, use case 729 is an example of a third use case, and use case 721 is an example of a fourth use case.

[0105] The abnormality level is expressed as a numerical value such as 0, 1, or 2, but may be determined arbitrarily. The tier and the abnormality level are, for example, the same numerical value, but may be different numerical values.

[0106] Furthermore, the process of creating a use case 729 based on the detection target packet 400 and assigning a tier to the created use case 729 may be performed by the anomaly degree calculation device 200. In this case, for example, the anomaly degree calculation device 200 acquires the detection target packet 400 and the use case information shown in FIG. 12 , and creates a use case 729 based on the detection target packet 400 using a query and an LLM stored in a storage device included in the anomaly degree calculation device 200, and assigns a tier to the created use case 729. Furthermore, the anomaly degree calculation device 200 calculates the degree of anomaly of the detection target packet 400 as an anomaly degree corresponding to tier=1.

[0107] In addition, the use case extraction device 100 may generate rule information based on use case information in order to speed up and reduce costs (reduce the amount of processing) and improve accuracy in the process of creating use cases based on the detection target packets 400.

[0108] FIG. 14 is a diagram for explaining the process of generating rule information according to the embodiment.

[0109] The use case extraction device 100 generates a query 520 including a use case 726 together with an explanatory text such as, for example, "Write a rule for extracting packets of the following use case." The query 520 extracts a sentence corresponding to the explanatory text of the query 520 from the use case 726. The sentence extracted in this manner is input to the LLM 620.

[0110] The LLM 620 is a language model that receives a sentence as input and outputs metadata corresponding to the sentence. The LLM 620 is a language model that has been trained to receive a sentence as input and output metadata corresponding to the sentence, for example.

[0111] The metadata is data that may be included in the detection target packet 400, and includes, for example, as described above, the IP address of the sender of the communication packet (source IP address), the IP address of the destination of the communication packet (destination IP address), and information indicating the content of the processing to be performed at the destination by the communication packet.

[0112] The use case extraction device 100 uses the LLM 620 to generate a matching rule 480 including metadata such as, for example, "dst ip: 192.168.1.30," "service choice: addListElement," and "object id: (schedule, any)" from the sentence generated by the query 520. The LLM 620 is stored in, for example, a storage device included in the use case extraction device 100. In this way, the use case extraction device 100 generates rule information including the matching rule 480.

[0113] For example, if the metadata included in the detection target packet 400 is the same as the metadata included in the matching rule 480, the use case extraction device 100 determines that the use case based on the detection target packet 400 is the same as the use case 726. This allows the use case extraction device 100 to determine the use case based on the detection target packet 400 without using a query or an LLM. In this example, the use case 729 is an example of a third use case, and the use case 726 is an example of a fourth use case.

[0114] The use case matching unit 120 outputs use case information including a use case based on the detection target packet 400 as shown in Fig. 13 (use case 729 in the example shown in Fig. 13 ), for example, to the anomaly degree calculation device 200. Alternatively, the use case matching unit 120 outputs use case information as shown in Fig. 12 and information indicating a use case that matches the use case based on the detection target packet 400, among multiple use cases indicated by the use case information, to the anomaly degree calculation device 200. In this way, the anomaly degree calculation device 200 calculates the degree of anomaly of the detection target packet 400 based on the use case information and the use case based on the detection target packet 400.

[0115] The use case extraction device 100 may create a use case using the LLM 600 or the LLM 610, and then create a higher-level use case by conceptualizing the created use case. For example, a use case that is conceptualized most highly (top-level use case) may be determined in advance. In this case, for example, the use case extraction device 100 may conceptualize a use case until it has the same content or granularity as the top-level use case.

[0116] FIG. 15 is a diagram illustrating the process of extracting higher-level use cases according to the embodiment.

[0117] The use case extraction device 100 generates a query 530 that includes the created use case (use case 726 in this example) along with an explanatory statement such as, "Extract a superordinate use case of the use case below. If there is a corresponding use case among the existing use cases, return null if the granularity of that use case is already sufficiently coarse." The query 530 extracts a sentence corresponding to the explanatory statement of the use case 726. The sentence extracted in this manner is input to the LLM 630.

[0118] The LLM 630 is a language model that takes a sentence as input and outputs a sentence indicating a use case corresponding to the sentence. The LLM 630 is a language model that has been trained to take a sentence as input and output a sentence indicating a use case corresponding to the sentence, for example.

[0119] The use case extraction device 100 uses the LLM 630 to extract (generate) a use case 723, such as "Edit an object linked to a schedule object for lighting equipment," from the sentence generated by the query 530. The LLM 630 is stored, for example, in a storage device included in the use case extraction device 100. As a result, the use case extraction device 100 creates use case 723, which is an example of a higher-level use case that is a higher-level conceptualization of use case 726, and generates use case information that indicates (includes) the created use cases 723 and 726.

[0120] In this way, for example, when generating use case information, the use case extraction device 100 creates one or more use cases (also referred to as first use cases), creates one or more use cases (also referred to as second use cases) that are higher-level conceptualizations of the one or more first use cases, and generates use case information that indicates the one or more first use cases and one or more second use cases. In this example, use case 726 is an example of a first use case, and use case 723 is an example of a second use case.

[0121] The created use cases may continue to be generalized as much as possible.

[0122] Furthermore, a process may be performed to improve the created upper level use case into a more appropriate sentence (use case).

[0123] FIG. 16 is a diagram illustrating the accuracy improvement process for the higher-level use cases according to the embodiment.

[0124] For example, sentences are extracted from the use case 726 by the query 530. The sentences extracted in this manner are input to the LLM 640. As a result, the use case extraction device 100 creates a use case 726A.

[0125] Like the LLM 630, the LLM 640 is a language model that receives a use case as input and outputs a sentence indicating a use case corresponding to the use case. The LLM 640 is a language model that is trained to receive, for example, a sentence as input and output a sentence indicating a use case corresponding to the sentence. Furthermore, the LLM 640 is trained to output a sentence indicating a use case according to the content of the evaluation when an evaluation is input. For example, the LLM 640 is trained to output different use case sentences when an evaluation is input and when an evaluation is not input. For example, the LLM 640 is stored in a storage device included in the use case extraction device 100.

[0126] The use case extraction device 100 displays the created use case (use case 726A) on a display device such as a display connected to the use case extraction device 100. In this example, a sentence such as "Perform object addition processing for lighting equipment" is displayed. The user checks the displayed use case 726A and inputs an evaluation (feedback) for use case 726A using an operation device or the like. The use case extraction device 100 accepts the evaluation for use case 726A via the operation device (S62).

[0127] For example, if the received (acquired) evaluation is low, the use case extraction device 100 recreates the use case using the LLM 640. Specifically, the LLM 640 receives the sentence extracted by the query 530 and information indicating the evaluation, and outputs the sentence and a sentence indicating a use case corresponding to the evaluation. In this way, the use case extraction device 100 recreates the use case.

[0128] The use case extraction device 100 displays the recreated use case (use case 726B) on a display device such as a display connected to the use case extraction device 100. In this example, a sentence such as "Set and edit the schedule for lighting equipment" is displayed. The user checks the displayed use case 726B and inputs an evaluation (feedback) for use case 726B using an operation device or the like. The use case extraction device 100 accepts the evaluation for the use case via the operation device (S63). For example, if the received (acquired) evaluation is a high evaluation, the use case extraction device 100 terminates the processing. Note that the evaluation may be, for example, in two stages, high and low, but may be arbitrarily determined. For example, the LLM 640 may be trained to output use cases with different sentences for each evaluation stage.

[0129] [Processing Procedure] Next, the processing procedure of the security system 10 will be described.

[0130] FIG. 17 is a flowchart showing the processing procedure of the security system 10 according to the embodiment.

[0131] First, the security system 10 performs a use case accumulation process (S100). Specifically, the security system 10 creates one or more use cases and generates use case information in which the one or more created use cases are hierarchically organized.

[0132] Next, the security system 10 performs an abnormal packet detection process (S200). Specifically, the security system 10 calculates the degree of abnormality of the detection target packet 400 based on the generated use case information.

[0133] FIG. 18 is a flowchart showing a specific example of the use case accumulation process (S100) according to the embodiment.

[0134] First, the security system 10 performs a given use case accumulation process (S110). Specifically, the use case extraction device 100 creates use cases based on the given use case information 440.

[0135] Next, the security system 10 performs a use case accumulation process based on the communication data analysis (S120). Specifically, the use case extraction device 100 creates a use case based on the extraction target packet 450.

[0136] Next, the security system 10 performs a use case editing process (S130). Specifically, the use case extraction device 100 displays the use cases created in steps S110 and S120 on a display device or the like. The user, for example, checks the displayed use cases and uses an operation device to modify the use case text or set or modify the hierarchy (and / or granularity) of the use cases. The use case extraction device 100 stores use case information that reflects the content received from the user via the operation device in the use case list storage unit 300.

[0137] FIG. 19 is a flowchart showing a specific example of the given use case accumulation process (S110) according to the embodiment.

[0138] First, the use case extraction device 100 acquires given use case information 440 and extracts use cases from the acquired given use case information 440 (S111). Specifically, the use case extraction unit 110 creates use cases by extracting sentences related to the use cases from sentences indicated by the given use case information 440. For example, LLM is used to extract use cases, but any method may be used.

[0139] Next, the use case extraction device 100 normalizes the extracted use cases (S112). Specifically, as in step S20 above, the use case extraction unit 110 converts the given use case information 440 (specifically, the extracted use cases) into a format that can be used by the security system 10. Furthermore, the use case extraction unit 110 assigns hierarchies to the use cases, for example, according to the granularity of the use cases (specifically, the granularity of the sentences indicating the use cases).

[0140] Next, the use case extraction device 100 super-conceptualizes the normalized use cases (S113). Specifically, the use case extraction unit 110 super-conceptualizes the use cases using the query 530, the LLM 630, and the like. The use case extraction unit 110 also assigns a hierarchical level to the super-conceptualized use cases. Each time a super-conceptualization is performed, a hierarchical level one level higher than the original use case may be assigned, or a hierarchical level may be assigned according to the granularity of the use case.

[0141] Next, the use case extraction device 100 determines whether the superordinated use case matches an existing use case, that is, an already created use case (S114).

[0142] If the use case extraction device 100 determines that the superordinated use case does not match any existing use case (No in S114), the process returns to step S113, and the superordinated use case is further superordinated. In this way, use cases are repeatedly superordinated.

[0143] On the other hand, if the use case extraction device 100 determines that the superordinated use case matches an existing use case (Yes in S114), it determines whether or not other use cases exist in the given use case information 440, that is, whether or not other use cases are included in the given use case information 440 (S115).

[0144] If the use case extraction device 100 determines that another use case exists in the given use case information 440 (Yes in S115), it returns the processing to step S111, extracts another use case from the given use case information 440, and repeats the processing from step S112 onwards.

[0145] When the use case extraction device 100 determines that no other use cases exist in the given use case information 440 (No in S115), it outputs the one or more use cases created by the processing of steps S111 to S115 to the use case list storage unit 300 (S116). Specifically, the use case extraction unit 110 stores use case information indicating the one or more hierarchical use cases that have been created in the use case list storage unit 300.

[0146] It should be noted that if the use case indicated by the given use case information 440 is in a format that can be used in the security system 10, steps S111 and S112 do not need to be performed.

[0147] FIG. 20 is a flowchart showing a specific example of the use case accumulation process (S120) based on communication data analysis according to the embodiment.

[0148] First, the use case extraction device 100 samples the extraction target packets 450 (S121). Specifically, the use case extraction unit 110 acquires, for example, one or more extraction target packets 450 used during a predetermined period.

[0149] Next, the use case extraction device 100 extracts a use case from one of the one or more acquired packets to be extracted 450 (S122). Specifically, the use case extraction unit 110 creates a use case based on the packet to be extracted 450. To create the use case, for example, LLM is used, but any method may be used. In addition, the use case extraction unit 110 assigns a hierarchical level to the use case according to, for example, the granularity of the use case.

[0150] Next, the use case extraction device 100 super-conceptualizes the extracted use cases (S123). Specifically, the use case extraction unit 110 super-conceptualizes the use cases using the query 530, the LLM 630, and the like. The use case extraction unit 110 also assigns a hierarchical level to the super-conceptualized use cases. Each time a super-conceptualization is performed, a hierarchical level one level higher than the original use case may be assigned, or a hierarchical level may be assigned according to the granularity of the use case.

[0151] Next, the use case extraction device 100 determines whether the superordinated use case matches an existing use case, that is, an already created use case (S124).

[0152] If the use case extraction device 100 determines that the superordinated use case does not match any existing use case (No in S124), the process returns to step S123, and the superordinated use case is further superordinated. In this way, use cases are repeatedly superordinated.

[0153] On the other hand, if the use case extraction device 100 determines that the superordinated use case matches an existing use case (Yes in S124), it determines whether or not there are other packets 450 to be extracted, that is, whether or not there are any packets 450 to be extracted that have not yet been processed in step S122 or later among the one or more packets 450 to be extracted acquired in step S121 (S125).

[0154] If the use case extraction device 100 determines that another extraction target packet 450 exists (Yes in S125), the process returns to step S122 and repeats the processes from step S122 onwards for the other extraction target packet 450.

[0155] If the use case extraction device 100 determines that there are no other packets to be extracted 450 (No in S125), it outputs the one or more use cases created by the processing of steps S121 to S125 to the use case list storage unit 300 (S126). Specifically, the use case extraction unit 110 stores use case information indicating the one or more hierarchical use cases that have been created in the use case list storage unit 300.

[0156] Through the above processing, use case information indicating one or more hierarchical use cases is generated.

[0157] FIG. 21 is a flowchart showing a specific example of the abnormal packet detection process (S200) according to the embodiment.

[0158] First, the use case extraction device 100 sets an anomaly degree for each of one or more use cases indicated by the use case information (S210). Specifically, the use case matching unit 120 associates an anomaly degree according to the hierarchical level with each of the one or more use cases. Note that information indicating the relationship between the hierarchical level and the anomaly degree may be stored in advance in a storage device provided in the use case extraction device 100. For example, by executing step S210, the use case matching unit 120 associates the use case (or hierarchical level) with the anomaly degree and updates the use case information.

[0159] Next, the use case extraction device 100 acquires one or more detection target packets 400 (S220).

[0160] Next, the use case extraction device 100 performs a use case determination process (S230) for the one or more acquired detection target packets 400. Specifically, the use case matching unit 120 infers (determines) a use case based on the detection target packets 400, and determines the hierarchy of the inferred use case.

[0161] Next, the abnormality degree calculation device 200 calculates the abnormality degree of the detection target packet 400 (S240). Specifically, the abnormality degree calculation unit 210 calculates the abnormality degree of the detection target packet 400 based on the hierarchy of the use case based on the detection target packet 400.

[0162] For example, after step S240, the abnormality degree calculation device 200 notifies the SOC of the abnormality degree information 410 by transmitting the abnormality degree information 410 indicating the calculation result of the abnormality degree of the detection target packet 400 to a terminal used in the SOC.

[0163] In addition, the abnormality degree calculation device 200 may, for example, transmit the abnormality degree information 410 to the terminal or the like if the abnormality degree of the detection target packet 400 is equal to or greater than a predetermined threshold, and may not need to transmit the abnormality degree information 410 to the terminal or the like if the abnormality degree of the detection target packet 400 is less than the predetermined threshold.

[0164] FIG. 22 is a flowchart showing a specific example of the use case determination process (S230) according to the embodiment.

[0165] First, the use case extraction device 100 selects one detection target packet 400 from the one or more acquired detection target packets 400 (S231).

[0166] Next, the use case extraction device 100 determines whether to perform a determination process using rule information on the selected detection target packet 400 (S232). Specifically, the use case matching unit 120 determines whether to use rule information to determine a hierarchy of use cases based on the detection target packet 400 (S232). More specifically, the use case matching unit 120 determines whether to determine a use case based on the detection target packet 400 using rule information or to create a use case using LLM. For example, the use case matching unit 120 determines whether a use case based on the detection target packet 400 can be determined using rule information. For example, if the metadata included in the detection target packet 400 is the same as the metadata included in the rule information, the use case matching unit 120 determines that a use case can be determined using rule information.

[0167] When the use case extraction device 100 determines that a determination process using the rule information should be executed on the selected detection target packet 400 (Yes in S232), the use case extraction device 100 executes the determination process using the rule information (S233). Specifically, the use case matching unit 120 determines, based on the rule information, the use case used when metadata included in the rule information that matches the metadata included in the detection target packet 400 was estimated (extracted), as the use case based on the detection target packet 400. Furthermore, the use case extraction device 100 determines a hierarchy of the use case based on the detection target packet 400, based on the use case information.

[0168] On the other hand, if the use case extraction device 100 determines not to perform a determination process using rule information on the selected detection target packet 400 (No in S232), it performs a determination process using the LLM (S234). Specifically, the use case matching unit 120 creates a use case based on the detection target packet 400 using the LLM and determines the hierarchy of the created use case based on the use case information. The use case matching unit 120 generates a query including the detection target packet 400 along with a description such as, for example, "Estimate the purpose and effect of the next packet and extract a use case." The use case matching unit 120 then uses the generated query to extract a sentence corresponding to the description of the detection target packet 400 and inputs the extracted sentence into the LLM 600 or the like to create a use case based on the detection target packet 400. Furthermore, for example, the use case matching unit 120 searches for a use case whose content matches that of the created use case among one or more use cases indicated by the use case information. Here, if the use case matching unit 120 finds a use case with matching content from one or more use cases, it determines the hierarchical level of the found use case as the hierarchical level of the use case based on the detection target packet 400. On the other hand, for example, if the use case matching unit 120 does not find a use case with matching content from one or more use cases, it superordinates the use case based on the detection target packet 400 using the query 530, the LLM 630, or the like. Furthermore, the use case matching unit 120 searches for a use case with the same content as the superordinated use case from one or more use cases indicated by the use case information. If the use case matching unit 120 finds a use case with the same content as the superordinated use case from one or more use cases indicated by the use case information, it determines the hierarchical level of the use case based on the detection target packet 400 based on the hierarchical level of the found use case. For example, the use case matching unit 120 determines the hierarchical level of the use case based on the detection target packet 400 to be the hierarchical level of the use case based on the detection target packet 400, which is the hierarchical level of the found use case minus the number of times the use case has been superordinated.

[0169] Alternatively, for example, an LLM is used to create a use case based on the detection target packet 400. Furthermore, a use case that matches the created use case is determined (estimated) from among one or more use cases indicated in the use case information. The use case matching unit 120 generates a query including the detection target packet 400 along with a description such as, for example, "Among the use cases that match the input packet, return the one with the lowest hierarchical value, or if there is no match, respond accordingly." The generated query is used to extract a sentence corresponding to the description, and the extracted sentence is input to the LLM 600 or the like, thereby estimating a matching use case. In other words, the use case matching unit 120 provides, for example, input (text data) indicating the description to the LLM 600 or the like and obtains a response, thereby matching the use case based on the detection target packet 400 with one or more use cases indicated by the use case information. In this way, for example, the use case matching unit 120 acquires the detection target packet 400 used in the network system 1, and uses the LLM to estimate a use case that matches the use case based on the detection target packet 400, from among one or more use cases indicated by the use case information. The LLM is a trained language model that is trained to receive, for example, a communication packet as input, and output a use case that matches the use case based on the communication packet, from among one or more use cases.

[0170] In addition, the use case matching unit 120 may predetermine the hierarchy and abnormality level in the event that no use case with matching content is found among the one or more use cases indicated by the use case information even when the created use case is conceptualized as a higher level.

[0171] Furthermore, the use case matching unit 120 may use, for example, LLM to calculate the granularity of the sentence indicated by the use case based on the detection target packet 400, and determine the hierarchy of the use case based on the calculated granularity.

[0172] After step S233 or step S234, the use case extraction device 100 determines whether or not there are other detection target packets 400, that is, whether or not there are any detection target packets 400 among the one or more extraction target packets 450 acquired in step S220 that have not yet been subjected to processing from step S231 onwards (S235).

[0173] If the use case extraction device 100 determines that another detection target packet 400 exists (Yes in S235), the use case extraction device 100 returns the process to step S231, selects another detection target packet 400, and repeats the processes from step S232 onwards.

[0174] If the use case extraction device 100 determines that there are no other detection target packets 400 (No in S235), it outputs the use case information and information indicating each layer of the one or more detection target packets 400 to the anomaly degree calculation device 200.

[0175] This allows the abnormality degree calculation device 200 to calculate the abnormality degree of each of the one or more detection target packets 400 based on the use case information and information indicating the layer of each of the one or more detection target packets 400 .

[0176] [Summary] As described above, the security system 10 generates use case information based on information related to the monitoring target 20, and detects abnormalities in communication packets sent or received by the monitoring target 20 based on the generated use case information.

[0177] For example, the security system 10 extracts a portion corresponding to a use case of the monitoring target 20 from the specification information 430 or the like. Also, for example, the security system 10 automatically extracts a use case of communication in the monitoring target 20 by analyzing the extraction target packet 450. Also, for example, the security system 10 automatically hierarchizes the extracted multiple use cases. Also, for example, the security system 10 extracts a use case of the detection target packet 400 and quantifies the degree of anomaly of the detection target packet 400 using the hierarchized multiple use cases.

[0178] For example, the above-mentioned Non-Patent Document 1 can extract a communication packet template, but cannot determine in what use case a communication packet matching a template occurs, in other words, in what use case it is used. Furthermore, the above-mentioned Non-Patent Document 1 cannot determine what effect the communication packet has. On the other hand, the security system 10 extracts a use case for the monitoring target 20 and notifies, for example, the SOC of information indicating the extracted use case, thereby allowing the SOC to easily confirm the use case of the monitoring target 20, thereby facilitating analysis of communication packets in the SOC. Furthermore, among multiple detection target packets 400, only communication packets that do not match the use case can be detected as abnormal packets, thereby enabling accurate detection of abnormal packets.

[0179] Furthermore, for example, although the specifications for the monitored object 20 may include use cases for the processes executed by the monitored object 20, it is technically difficult to extract such use cases. Therefore, for example, the security system 10 uses the LLM to automatically identify descriptions of use cases from the specification information 430 and the like, and extracts the main points of the descriptions as use cases.

[0180] Furthermore, it is difficult to identify the use case of the monitoring target 20 based on, for example, the communication packets used by the monitoring target 20. Therefore, for example, the security system 10 uses the metadata of the communication packets as well as specification information 430 indicating the protocol specifications and the specifications (equipment specifications) of the monitoring target 20 to estimate the use case in which the communication packets are used, in other words, the use case that generates the communication packets.

[0181] Furthermore, for example, there is a possibility that a large number of communication packets may exist in the same communication link. In such a case, unless an arbitrary number of communication packets are selected from the plurality of communication packets and the use case extraction process is performed only on the selected portion of the communication packets, that is, unless appropriate sampling of the plurality of communication packets is performed, the load of the use case extraction process becomes large. Therefore, for example, the security system 10 efficiently determines the extraction target packet 450 by clustering the plurality of communication packets. The clustering of the communication packets can be performed, for example, by defining the Levenshtein distance between the communication packet and the payload and performing spectral clustering.

[0182] Furthermore, payload-based anomaly detection using, for example, the frequency of occurrence of byte sequences has a high rate of false positives. Therefore, for example, the security system 10 detects anomalies in communication packets based on use cases. This allows the security system 10 to accurately detect anomalous communication packets.

[0183] Furthermore, for example, in the use case extraction process, the security system 10 uses Few-shot to show a portion of the information shown in the specification information 430 in the LLM and the use cases to be extracted from that portion. This allows the security system 10 to improve the accuracy of use case extraction and extract use cases at the intended granularity.

[0184] Furthermore, for example, the security system 10 automatically creates a use case (higher-level use case) of higher granularity (coarser granularity) for one use case. When extracting use cases from specification information 430 or the like, the security system 10 may extract a group of multiple operations (e.g., consecutive processes) as one use case. For example, the security system 10 may create one use case based on multiple packets to be extracted 450, or may create one use case based on multiple packets to be detected 400.

[0185] Furthermore, for example, when extracting a use case, the security system 10 may generate and store information indicating a pointer to a section of the specification indicated by the specification information 430 that describes the extracted use case, or to a representative communication packet that fulfills the role of the extracted use case.

[0186] Furthermore, for example, the security system 10 creates rule information (for example, the above-mentioned matching rule 480 and granularity information linked to the matching rule 480 and indicating granularity) for calculating the degree of anomaly of the detection target packet 400 based on the extracted use case.

[0187] Furthermore, for example, the security system 10 detects anomalies in communication packets (specifically, calculates the degree of anomaly) using rule information or LLMs in order from the finest granularity of the use case. For example, the security system 10 calculates the degree of anomaly according to the granularity of the use case that matches the use case created based on the detection target packet 400.

[0188] [Modification] Each processing unit included in the security system 10 may be arbitrarily assigned to one or more devices.

[0189] 23 is a diagram showing the configuration of a security system 11 according to a modified example. For example, the network system 1 shown in FIG.

[0190] Similar to the security system 10, the security system 11 is a device for receiving communication packets sent or received by the monitored object 20, i.e., communication packets used by the monitored object 20, and detecting abnormalities in the received communication packets. Specifically, the security system 11 calculates the degree of abnormality of the communication packets.

[0191] The security system 11 includes, for example, one or more computers. The computers are realized, for example, by a communication interface, non-volatile memory storing programs, volatile memory serving as temporary storage for executing the programs, input / output ports for transmitting and receiving signals, and a processor for executing the programs. The communication interface may be realized, for example, by an antenna and a wireless communication circuit for wireless communication, or by a connector to which a communication line is connected for wired communication.

[0192] The security system 11 includes a use case extraction device 101 and an abnormality degree calculation device 201 .

[0193] Similar to the use case extraction device 100, the use case extraction device 101 is a computer that generates use case information indicating one or more use cases of the network system 1 (specifically, a plurality of monitoring targets 20). The use case extraction device 101 is realized by, for example, a communication interface, a non-volatile memory that stores a program, a volatile memory that is a temporary storage area for executing the program, an input / output port for sending and receiving signals, and a processor that executes the program.

[0194] The use case extraction device 101 includes a use case extraction unit 110. The use case extraction device 101 differs from the use case extraction device 100 in that the use case extraction device 101 does not include a use case matching unit 120.

[0195] The anomaly degree calculation device 201 is a computer that calculates the degree of anomaly of the detection target packet 400 based on use case information, similar to the anomaly degree calculation device 200. The anomaly detection device 201 is another example of an information processing device. The anomaly degree calculation device 201 is realized by, for example, a communication interface, a non-volatile memory in which a program is stored, a volatile memory that is a temporary storage area for executing the program, an input / output port for sending and receiving signals, and a processor that executes the program.

[0196] The abnormality degree calculation device 201 includes a use case matching unit 120 and an abnormality degree calculation unit 210. The abnormality degree calculation device 201 differs from the abnormality degree calculation device 200 in that the use case matching unit 120 is included.

[0197] In this example, the anomaly degree calculation device 201 acquires a communication packet (more specifically, a detection target packet 400) used in the monitoring target 20, and calculates the degree of anomaly of the acquired communication packet based on use case information. Specifically, in this example, the anomaly degree calculation device 201 acquires the detection target packet 400, estimates a use case based on the acquired detection target packet 400, and calculates the degree of anomaly of the detection target packet 400 based on the estimated use case and the use case information. For example, in calculating the degree of anomaly of the detection target packet 400, the anomaly degree calculation device 201 estimates a use case (third use case) in which the acquired detection target packet 400 is used, selects a use case (fourth use case) related to the estimated third use case from one or more use cases indicated by the use case information, and calculates the degree of anomaly of the detection target packet 400 based on the tier to which the selected fourth use case is classified. Alternatively, for example, when calculating the degree of abnormality of the detection target packet 400, the abnormality degree calculation device 201 calculates the degree of abnormality of the detection target packet 400 based on the granularity of the selected fourth use case.

[0198] For example, the anomaly degree calculation device 201 uses the above rule information or the above query and the above LLM to estimate the third use case. The rule information may be created by the use case extraction device 101 and output to the anomaly degree calculation device 201, or may be created by the anomaly degree calculation device 201. Also, for example, the above query and the above LLM for creating a use case based on the detection target packet 400 may be stored in a storage device included in the anomaly degree calculation device 201. For example, the anomaly degree calculation device 201 estimates (determines) the third use case using the rule information, or estimates (creates) the third use case using the query and the LLM.

[0199] For example, the memories provided in the processing units such as the use case matching unit 120 and the anomaly degree calculation unit 210 may be realized by a common memory or by one or more independent memories. Also, the processors provided in the processing units such as the use case extraction unit 110 and the use case matching unit 120 may be realized by a common processor for each processing unit or by one or more independent processors for each processing unit.

[0200] [Representative Example] FIG. 24 is a flowchart showing a first example of an information processing method according to an embodiment.

[0201] For example, an information processing device (first information processing device) includes a processor and a memory, and the processor uses the memory to perform processing according to the following first example (first information processing method). The information processing device is, for example, the above-mentioned use case extraction device 100.

[0202] First, the information processing device acquires at least one of specification information indicating the communication specification in the system and a first communication packet used in the system (S310).

[0203] The system is, for example, the network system 1 described above. The system includes, for example, a plurality of devices. The plurality of devices are, for example, the monitoring target 20 described above. The specification information is, for example, the public information 420, the specification information 430, and / or the asset information 460. The first communication packet is, for example, a communication packet used in communication between the plurality of devices, and is the extraction target packet 450 described above. The first communication packet may be a communication packet transmitted from outside the system to the system, or may be a communication packet transmitted from the system to outside the system.

[0204] The information processing device may, for example, acquire this information from a user via an operation device, acquire this information from a server device or the like outside the system, or acquire this information from one of a plurality of devices included in the system. The specification information and the first communication packet may be stored in a memory included in the information processing device, or the information processing device may acquire this information from the memory.

[0205] Next, the information processing device generates use case information indicating one or more use cases of the system based on at least one of the specification information and the first communication packet acquired in step S310 (S320). The information processing device creates use cases from at least one of the specification information and the first communication packet using, for example, an LLM, and generates use case information including information indicating the created use cases. For example, the information processing device determines a hierarchy of the use cases based on the granularity of the sentences in the use cases, and generates use case information indicating one or more hierarchical use cases based on the determined hierarchy.

[0206] The LLM is, for example, the above-mentioned LLMs 600 and 610, and is a language model trained to input specification information and the first communication packet and output use cases (specifically, text data indicating the use cases in sentences) and the hierarchy of the use cases. The use cases are, for example, the above-mentioned use cases 700, 710, 711, 720, 721, 722, 723, 724, 725, 726, 726A, 726B, 727, 728, and 729. The use case information is, for example, information indicating these use cases.

[0207] The information processing device uses the specification information, the first communication packet, and the LLM to generate use case information indicating a plurality of hierarchical use cases, for example, as shown in Fig. 12. The LLM is stored in advance in a memory provided in the information processing device, for example.

[0208] The one or more use cases may be one use case or multiple use cases.

[0209] FIG. 25 is a flowchart illustrating a second example of the information processing method according to the embodiment.

[0210] For example, the information processing device (second information processing device) includes a processor and a memory, and the processor uses the memory to perform processing according to the second example (second information processing method) described below. The information processing device is, for example, the above-mentioned anomaly degree calculation device 201.

[0211] First, the information processing device acquires communication packets used in the system (S410).

[0212] The system is, for example, a network system 1 that includes a security system 11 instead of the security system 10. The system includes, for example, a plurality of devices. The plurality of devices are, for example, the above-mentioned monitoring targets 20. The communication packet is, for example, a communication packet used in communication between the plurality of devices, and is the above-mentioned detection target packet 400. The communication packet may be a communication packet transmitted from outside the system to the system, or a communication packet transmitted from the system to outside the system. The information processing device acquires the communication packet from, for example, one of the plurality of devices included in the system. The information processing device may also acquire the communication packet from, for example, a server device outside the system.

[0213] Next, the information processing device calculates the degree of anomaly of the acquired communication packet based on use case information indicating one or more use cases of the system (S420). For example, the information processing device detects anomalies in the communication packet using the use case information generated by the use case extraction device 100. The use case information is, for example, information in which use cases 720 to 728 are hierarchically organized, such as use cases 720 to 728 shown in FIG. 12 . Furthermore, for example, the use case information has a predetermined degree of anomaly for each hierarchical level. For example, the information processing device estimates the use case of the acquired communication packet, determines a use case related to the estimated use case from one or more use cases indicated by the use case information, and determines the degree of anomaly of the acquired communication packet to be the degree of anomaly defined for the hierarchical level of the determined use case.

[0214] The information processing device creates a use case (third use case) from the acquired communication packets, for example, using an LLM. Next, the information processing device searches for a use case (fourth use case) related to the created use case from among one or more use cases indicated in the use case information. In other words, the fourth use case is any one of the one or more use cases indicated in the use case information. Here, if a fourth use case related to the third use case is found, the information processing device calculates (determines) the anomaly level of the acquired communication packets based on the layer of the fourth use case.

[0215] An example of the third use case is use case 729 shown in Fig. 13. In the example shown in Fig. 13, a fourth use case related to the third use case is use case 721. For example, since use case 729 is one tier below use case 721, the anomaly degree of the communication packet is calculated to be the anomaly degree corresponding to the one tier below use case 721.

[0216] The abnormality level to be used when the fourth use case related to the third use case is not found may be determined in advance. In this case, for example, the predetermined abnormality level is determined as the calculated abnormality level.

[0217] The one or more use cases are categorized into hierarchical levels according to, for example, the sentences describing the content of the use cases. For example, the closer the content of the third use case is to a use case at a lower hierarchical level among the one or more use cases, the more likely the acquired communication packet is to be used in the system. In this way, the degree of anomaly of the communication packet is calculated based on the hierarchical level into which the third use case is estimated to be classified.

[0218] The hierarchical level is expressed by a numerical value such as 0, 1, 2, etc., but may be determined arbitrarily. The abnormality level is expressed by a numerical value such as 0, 1, 2, etc., but may be determined arbitrarily. The hierarchical level and the abnormality level may be expressed by the same numerical value or different numerical values.

[0219] In step S420, the degree of abnormality of the communication packet may be calculated based on rule information generated based on the use case information.

[0220] (Effects, etc.) Hereinafter, examples of techniques that can be obtained from the disclosure of this specification will be given, and effects, etc. that can be obtained from the exemplified techniques will be described.

[0221] Technique 1 is an information processing method that acquires at least one of specification information indicating communication specifications in a system and a first communication packet used in the system (S310), and generates use case information indicating one or more use cases of the system based on at least one of the acquired specification information and a first communication packet (S320).

[0222] This allows an analyst or the like of the SOC who monitors and analyzes communication packets used in communication performed in the system to easily understand use cases such as information related to control performed in the system by checking one or more use cases. Therefore, the one or more use cases make it easier for the analyst or the like of the SOC to analyze communication packets.

[0223] Technique 2 is the information processing method according to Technique 1, wherein the one or more use cases include a use case relating to control that is performed consecutively in the system. For example, a use case is generated that compiles cases where a certain process is always performed after a certain process.

[0224] According to this, the control that is continuously performed in the system is explained collectively in one use case, so that SOC analysts and the like can easily understand such control.

[0225] Technique 3 is an information processing method according to Technique 1 or 2, in which, in generating use case information, a character string indicated in at least one of the methods is converted into a vector, related information about the system is obtained based on the vector, and use case information is generated based on the obtained related information.

[0226] That is, in the information processing method according to Technique 3, for example, a use case may be generated by citing the public information 420 and the specification information 430 using RAG. In other words, the specification information 430 may be cited for the use case using RAG. The related information is, for example, the related context information 470 described above.

[0227] This makes it easier to generate use case information that indicates use cases that describe accurate information using related information.

[0228] Technique 4 is an information processing method according to any one of Techniques 1 to 3, further comprising estimating metadata contained in communication packets used in the system based on use case information, and generating rule information including the estimated metadata.

[0229] The metadata is, for example, information indicating the IP address of the source of the communication packet, a command, etc. The rule information is, for example, the above-mentioned matching rule 480.

[0230] This makes it possible to use the rule information to facilitate monitoring and analysis of communication packets used in communications carried out in the system.

[0231] Technique 5 is an information processing method according to any one of Techniques 1 to 4, in which use case information is generated by creating one or more first use cases based on at least one of the acquired data, creating one or more second use cases by conceptualizing the one or more first use cases as a higher level concept, and generating use case information indicating the one or more first use cases and the one or more second use cases.

[0232] In other words, the one or more first use cases and the one or more second use cases are each an example of the one or more use cases indicated by the use case information.

[0233] The superordinate use case is, for example, the superordinate use case described above. For example, the one or more first use cases referred to here are use cases that are not superordinated, such as use cases 700, 711, 722, 724, 726, 726B, 727, 728, and 729, and the one or more second use cases referred to here are the above-mentioned use cases 720, 721, 723, and 725.

[0234] This makes it easier for analysts at the SOC to grasp the overall picture of information relating to the control performed in the system.

[0235] The one or more first use cases may be one use case or multiple use cases. The one or more second use cases may be one use case or multiple use cases. All of the one or more first use cases may be superordinate conceptualized, or some of the one or more first use cases may be superordinate conceptualized.

[0236] Technique 6 is an information processing method according to any one of Techniques 1 to 5, further acquiring a second communication packet used in the system, using the communication packet as input, and using a language model that outputs a use case, out of one or more use cases, that matches a use case based on the second communication packet, to estimate a use case, out of one or more use cases, that matches a use case based on the second communication packet.

[0237] The second communication packet is, for example, the detection target packet. The language model is, for example, the LLM. For example, the LLM is used to create a use case based on the second communication packet. Furthermore, a use case that matches the created use case is determined (estimated) from among one or more use cases indicated in the use case information.

[0238] This allows an analyst at the SOC or the like to check the estimated use case, making it easier to analyze the communication packet (second communication packet).

[0239] Technique 7 is an information processing method that acquires communication packets used in a system (S410) and calculates the degree of anomaly of the acquired communication packets based on use case information that indicates one or more use cases of the system (S420).

[0240] According to this, even when a communication packet for executing a control that is not normally performed in the system is transmitted or received in the system, the communication packet can be appropriately detected using the use case information. Therefore, for example, it is possible to detect only communication packets that do not conform to the use case. Therefore, it is possible to detect anomalous communication with high accuracy. As such, according to the information processing method of Technology 7, it is possible to easily analyze communication packets using use case information, specifically, one or more use cases, by a computer, thereby accurately detecting anomalous communication packets.

[0241] Technique 8 is an information processing method according to Technique 7, in which one or more use cases indicated in the use case information are classified into one or more hierarchical levels, and in calculating the degree of abnormality of a communication packet, a third use case in which the acquired communication packet is used is estimated, a fourth use case related to the estimated third use case is selected from the one or more use cases, and the degree of abnormality of the communication packet is calculated based on the hierarchical level in which the selected fourth use case is classified.

[0242] That is, in the information processing method according to technique 8, a third use case is created based on the acquired communication packets, and a fourth use case related to the third use case is searched for from among one or more use cases. That is, the fourth use case is any one of the one or more use cases indicated in the use case information. Here, if a fourth use case related to the third use case is found, the degree of anomaly of the acquired communication packets is calculated (determined) based on the hierarchy of the fourth use case.

[0243] An example of the third use case is use case 729 shown in Fig. 13. In the example shown in Fig. 13, a fourth use case related to the third use case is use case 721. For example, since use case 729 is one tier below use case 721, the anomaly degree of the communication packet is calculated to be the anomaly degree corresponding to the one tier below use case 721.

[0244] This allows the degree of anomaly to be calculated according to the tier into which the third use case is estimated to be classified, and therefore allows the degree of anomaly in the communication packet to be calculated.

[0245] Technique 9 is an information processing method according to Technique 7 or 8, in which the use case information includes granularity information indicating the granularity of each of the one or more use cases, and in calculating the degree of abnormality of the communication packet, a third use case in which the acquired communication packet is used is estimated, a fourth use case related to the estimated third use case is selected from the one or more use cases, and the degree of abnormality of the communication packet is calculated based on the granularity of the selected fourth use case.

[0246] In other words, in the information processing method according to Technology 9, when a fourth use case related to the third use case is found, the degree of anomaly of the acquired communication packet is calculated (determined) based on the granularity of the fourth use case.

[0247] For example, for each of one or more use cases, a granularity is set according to the text indicating the content of the use case. Also, for example, an abnormality level is set in advance according to the granularity. For example, the higher the granularity, the lower the abnormality level is set. On the other hand, for example, the lower the granularity, the higher the abnormality level is set. The use case information includes, for example, information indicating these set granularities and abnormality levels. In the above example, information indicating the hierarchy is the granularity information.

[0248] For example, the closer the content of the third use case is to a use case with a lower degree of anomaly among the one or more use cases, the more likely the acquired communication packet is to be used in the system. This allows a degree of anomaly to be calculated according to the granularity of the fourth use case with which the third use case is estimated to be related. Therefore, this allows anomalies in the communication packets to be calculated.

[0249] The granularity is expressed as a numerical value such as 0, 1, or 2, but may be determined arbitrarily. The granularity and the abnormality level may be expressed by the same numerical value or by different numerical values. The granularity may be determined for each hierarchical level.

[0250] Technique 10 is an information processing device that includes a processor and a memory, and the processor uses the memory to acquire specification information indicating the communication specifications of the system and / or communication packets used in the system, and generates use case information indicating one or more use cases of the system based on the acquired specification information.

[0251] The information processing device according to Technique 10 is, for example, the use case extraction device 100 described above.

[0252] This provides the same effects as the information processing method according to Technique 1.

[0253] Technique 11 is an information processing device that includes a processor and a memory, and the processor uses the memory to acquire communication packets used in a system and calculates the degree of anomaly of the acquired communication packets based on use case information that indicates one or more use cases of the system.

[0254] The information processing device according to technique 12 is, for example, the abnormality degree calculation device 201 described above.

[0255] This provides the same effect as the information processing method according to Technology 7.

[0256] Technique 13 is a program for causing a computer to execute the information processing method according to any one of techniques 1 to 9.

[0257] This provides the same effects as the information processing method according to any one of techniques 1 to 9.

[0258] (Other Embodiments) Although the embodiments have been described above, the present disclosure is not limited to the above-described embodiments.

[0259] For example, the protocol used for the communication packets may be determined arbitrarily, and may be an OT protocol, an IT protocol, or any other arbitrary protocol, and may be determined arbitrarily.

[0260] Furthermore, for example, the number of monitoring targets 20 included in the network system 1 may be one or more.

[0261] Furthermore, for example, the above-mentioned LLM is a language model constructed by deep learning or the like, but the data used to train the LLM may be arbitrary.

[0262] Furthermore, for example, the information processing devices described in the above embodiments may be realized as a single device that includes all of the components, or may be realized by allocating functions to multiple devices and coordinating these multiple devices. For example, the security system 10 includes the use case extraction device 100 and the anomaly degree calculation device 200, but may also be realized by a single information processing device such as a computer that realizes the functions of both the use case extraction device 100 and the anomaly degree calculation device 200.

[0263] In the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. The order of multiple processing operations may be changed, or multiple processing operations may be performed in parallel.

[0264] In the above-described embodiments, each component may be realized by executing a software program suitable for that component, or by a program execution unit such as a CPU or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory.

[0265] Furthermore, each component may be realized by hardware. For example, each component may be a circuit (or integrated circuit). These circuits may form a single circuit as a whole, or each may be a separate circuit. Furthermore, each of these circuits may be a general-purpose circuit or a dedicated circuit.

[0266] Furthermore, the general or specific aspects of the present disclosure may be realized as an apparatus, a system, a method, an integrated circuit, a computer program, or a non-transitory recording medium such as a computer-readable CD-ROM, etc. Furthermore, the general or specific aspects of the present disclosure may be realized as any combination of an apparatus, a system, a method, an integrated circuit, a computer program, and a recording medium.

[0267] In addition, this disclosure also includes forms obtained by applying various modifications to each embodiment that a person skilled in the art would think of, or forms realized by arbitrarily combining the components and functions of each embodiment within the scope of this disclosure.

[0268] The present disclosure is useful for a computer that detects packet anomalies.

[0269] 1 Network system 10, 11 Security system 20 Monitoring target 100, 101 Use case extraction device 110 Use case extraction unit 120 Use case matching unit 200, 201 Anomaly degree calculation device 210 Anomaly degree calculation unit 300 Use case list storage unit 310 Vector store storage unit 400 Detection target packet 410 Anomaly degree information 420 Public information 430 Specification information 440 Given use case information 450 Extraction target packet 460 Asset information 470 Related context information 480 Matching rule 500, 510, 520, 530 Query 600, 610, 620, 630, 640 LLM 700, 710, 711, 720, 721, 722, 723, 724, 725, 726, 726A, 726B, 727, 728, 729 Use Cases

Claims

1. An information processing method comprising: acquiring specification information indicating communication specifications in a system and / or a first communication packet used in the system; and generating use case information indicating one or more use cases of the system based on the acquired specification information and / or a first communication packet used in the system.

2. The information processing method according to claim 1, wherein the one or more use cases include a use case relating to control that is performed continuously in the system.

3. The information processing method according to claim 1, wherein the generation of the use case information comprises converting the character string indicated in at least one of the fields into a vector, obtaining related information about the system based on the vector, and generating the use case information based on the obtained related information.

4. The information processing method according to claim 1, further comprising: estimating metadata to be included in communication packets used in the system based on the use case information; and generating rule information including the estimated metadata.

5. The information processing method of claim 1, wherein the generation of the use case information comprises creating one or more first use cases based on at least one of the acquired use cases, creating one or more second use cases that are a higher-level conceptualization of the one or more first use cases, and generating the use case information indicating the one or more first use cases and the one or more second use cases.

6. The information processing method according to claim 1, further comprising: acquiring a second communication packet used in the system; and using a language model that takes the communication packet as input and outputs a use case from the one or more use cases that matches a use case based on the second communication packet, estimating a use case from the one or more use cases that matches a use case based on the second communication packet.

7. An information processing method comprising: acquiring communication packets used in a system; and calculating an anomaly level of the acquired communication packets based on use case information indicating one or more use cases of the system.

8. The information processing method according to claim 7, wherein the one or more use cases indicated in the use case information are classified into one or more hierarchies, and the calculation of the degree of abnormality of the communication packet comprises estimating a third use case in which the acquired communication packet is used, selecting a fourth use case related to the estimated third use case from the one or more use cases, and calculating the degree of abnormality of the communication packet based on the hierarchical level in which the selected fourth use case is classified.

9. The information processing method of claim 7, wherein the use case information includes granularity information indicating the granularity of each of the one or more use cases, and the calculation of the degree of abnormality of the communication packet comprises: estimating a third use case in which the acquired communication packet is used; selecting a fourth use case related to the estimated third use case from the one or more use cases; and calculating the degree of abnormality of the communication packet based on the granularity of the selected fourth use case.

10. An information processing device comprising: a processor; and a memory, wherein the processor uses the memory to acquire at least one of specification information indicating communication specifications in a system and a first communication packet used in the system, and generates use case information indicating one or more use cases of the system based on the acquired at least one.

11. An information processing device comprising a processor and a memory, acquiring communication packets used in a system, and calculating the degree of anomaly of the acquired communication packets based on use case information indicating one or more use cases of the system.

12. A program for causing a computer to execute the information processing method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Framework development assisting device and framework development assisting method

    JP2002157117A

  • System analysis method, system analysis apparatus and system analysis program

    JP2012108607A