Information processing method, information processing device, and program
The method addresses the challenge of distinguishing cyberattacks in power systems by visually associating and prioritizing anomalies, enabling swift and effective incident response in power infrastructures.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
- Filing Date
- 2025-12-10
- Publication Date
- 2026-07-23
AI Technical Summary
In power infrastructures connected via the Internet, distinguishing between cyberattacks and other anomalies in power systems is challenging, leading to potential delays in incident response and increased damage.
An information processing method that acquires log information from power equipment, detects communication and power anomalies, associates their locations with a map, and generates display information to visualize and prioritize incident responses.
Enhances the ability to promptly and effectively respond to anomalies by clearly identifying and prioritizing cyberattacks and other incidents in power systems, reducing potential damage.
Smart Images

Figure JP2025043113_23072026_PF_FP_ABST
Abstract
Description
Information Processing Method, Information Processing Apparatus, and Program
[0001] The present disclosure relates to an information processing method, an information processing apparatus, and a program.
[0002] Recently, for example, due to the expansion of the use of distributed energy sources (DERs: Distributed Energy Resources), each power device in the power infrastructure including DERs has come to be connected via the Internet. In such a power infrastructure, since the impact at the time of an accident can be extremely large, it has become even more important to promptly implement appropriate incident response.
[0003] For example, Patent Document 1 discloses a technique for reducing the human cost required to determine whether there is an abnormality in an actual power system and enabling a prompt response at the time of an abnormality in the actual power system by visualizing the distinction between an abnormality (power outage) in the power system and an abnormality in a smart meter.
[0004] For example, Patent Document 2 discloses a technique for grouping photovoltaic power generation devices in consideration of the solar radiation amount and detecting an abnormality in a photovoltaic power generation device from the difference in the power generation amount within the group.
[0005] Japanese Patent No. 7400354, Japanese Patent No. 5496933
[0006] However, in a power infrastructure connected to the Internet, cases have been reported in which a third party conducts a cyberattack via a DER or on the DER itself. For example, if it is not possible to easily determine whether an abnormality that has occurred in the power system is due to a cyberattack, there is a risk of increased damage, such as a delay or inability to implement incident response with a cyberattack in mind.
[0007] The present disclosure has been made in view of the above, and one of its purposes is to assist in incident response according to an abnormality that has occurred in a power system.
[0008] The information processing method relating to this disclosure is an information processing device comprising at least one processor, in which at least one processor executes the information processing method. The information processing method acquires log information relating to communication and power from power equipment in a target area, detects communication anomalies and / or power anomaly precursors in the power system of the target area based on the log information, associates the location of each of the at least one anomalies detected by the detection with a map of the target area divided into multiple areas, associates the positional relationship of the detection areas for the communication anomalies and / or power anomaly precursors, generates display information that visualizes the result of the association, and outputs the generated display information.
[0009] Figure 1 is a diagram showing an example of the configuration of a power system according to the first embodiment. Figure 2 is a diagram showing an example of the configuration of each part of the power system according to the first embodiment. Figure 3 is a diagram showing an example of the configuration of power information according to the first embodiment. Figure 4 is a diagram showing an example of the configuration of communication information according to the first embodiment. Figure 5 is a diagram showing an example of the hardware configuration of an information processing device that realizes each device of the power system according to the first embodiment. Figure 6 is a flowchart showing an example of the flow of information processing performed by the abnormality visualization system according to the first embodiment. Figure 7 is a diagram showing an example of screen display in information processing according to the first embodiment. Figure 8 is a diagram showing an example of screen display in information processing according to the second embodiment. Figure 9 is a diagram showing an example of screen display in information processing according to the third embodiment. Figure 10 is a diagram showing an example of screen display in information processing according to the fourth embodiment.
[0010] Hereinafter, embodiments of the information processing method, information processing apparatus, information processing system, program, and recording medium related to this disclosure will be described with reference to the drawings.
[0011] In this disclosure, components having the same or substantially the same function as those described above in previously shown drawings are denoted by the same reference numerals, and explanations may be omitted as appropriate. Furthermore, even when representing the same or substantially the same parts, the dimensions and proportions may be shown differently in different drawings. In addition, for example, from the viewpoint of ensuring the readability of the drawings, reference numerals may be assigned only to the main components in the explanation of each drawing, and reference numerals may not be assigned to components having the same or substantially the same function as those described above in previously shown drawings.
[0012] In addition, in the descriptions of this disclosure, components having the same or substantially the same function may be distinguished by adding alphanumeric characters and / or symbols to the end of the reference numeral. Alternatively, if multiple components having the same or substantially the same function are not to be distinguished, they may be described together by omitting the alphanumeric characters and / or symbols to the end of the reference numeral.
[0013] (First Embodiment) The power system 1 according to this embodiment is a system that connects distributed energy resources (DERs) located in a region to the upstream power grid via the power grid and operates them as a single integrated system. Here, distributed energy resources include renewable energy sources such as solar power generation facilities and wind power generation facilities, EVs (electric vehicles) and charging stations, and various storage batteries installed in homes, etc. Furthermore, the upstream power grid may include not only large-scale power generation facilities such as power plants, but also distributed energy resources from other regions.
[0014] Figure 1 is a diagram showing an example of the configuration of a power system 1 according to the first embodiment. As shown in Figure 1, the power system 1 includes a plurality of power devices 2-1, 2-2, 2-3 and an anomaly visualization system 4.
[0015] Multiple power devices 2-1, 2-2, and 2-3 are power infrastructure directly or indirectly connected to public telecommunication lines such as the Internet. Power device 2-1 is at least one power device, such as a transformer or substation, installed in the local power grid or between the local power grid and an upstream power grid. Power device 2-2 is at least one power device, such as a renewable energy source present in the local power grid, such as a solar power generation facility or a wind power generation facility. Power device 2-3 is at least one power device, such as various types of storage batteries present in the local power grid, such as storage batteries installed in EVs (onboard batteries), storage batteries installed in charging stations, or storage batteries installed in homes. In other words, the power system 1 according to this disclosure includes power devices related to at least one distributed energy source.
[0016] The number and types of power devices 2-1, 2-2, and 2-3 included in power system 1 are arbitrary and can be changed as appropriate.
[0017] Anomaly Visualization System 4 is an anomaly analysis system (information processing system) that performs each process of an anomaly visualization method (anomaly analysis method, information processing method) relating to power infrastructure directly or indirectly connected to public telecommunication lines such as the Internet. This anomaly visualization method includes associating the locations of communication anomalies and power anomaly precursors detected in anomaly detection with respect to the power infrastructure of a target area, and visualizing (e.g., displaying) the results of this association. The anomaly visualization method also includes generating and displaying information related to the detected anomalies. This information related to the detected anomalies is information from a response manual (items) corresponding to the results of the association. The anomaly visualization method may also include performing anomaly detection to detect communication anomalies and power anomaly precursors, or it may include obtaining the results of anomaly detection from an external source.
[0018] As shown in Figure 1, the anomaly visualization system 4 includes a server 5 and a client terminal 6. The server 5 and the client terminal 6 are connected to each other via a public telecommunications line such as the Internet, and / or a dedicated telecommunications line such as a LAN (Local Area Network). This communication may be wired, wireless, or a combination of both.
[0019] Server 5 is various types of computers, such as servers, personal computers (PCs), tablet PCs, smartphones, and smartwatches. In the anomaly visualization method according to the embodiment, Server 5 is an anomaly analysis device (information processing device) that performs processes such as associating the occurrence locations of communication anomalies and power anomaly predictions. As an example, Server 5 generates visualization information (display information) of the association results and / or information based on the association results, and outputs the generated display information to the client terminal 6.
[0020] The client terminal 6 is a type of computer such as a server, personal computer (PC), tablet PC, smartphone, or smartwatch. The client terminal 6 is a terminal device used by user P, such as the administrator or maintenance worker of the power system 1. In the abnormality visualization method according to the embodiment, the client terminal 6 is an abnormality visualization device (information processing device) that performs visualization and display of the results of processing that associates the occurrence locations of communication abnormalities and power abnormality precursors. For example, the client terminal 6 acquires display information from the server 5 and displays the acquired display information. For example, the client terminal 6 accepts operations from user P and outputs operation information indicating the result of user P's operations to the server 5.
[0021] Furthermore, the server 5 and client terminal 6 may be integrated and implemented as a single device. In other words, the anomaly visualization system 4 according to this embodiment may be implemented as a single information processing device (anomaly visualization device, anomaly analysis device).
[0022] Figure 2 shows an example of the configuration of each part of the power system 1 according to the first embodiment.
[0023] Power equipment 2 is exemplified by each of the multiple power equipment 2-1, 2-2, and 2-3 shown in Figure 1. As shown in Figure 2, power equipment 2 has the functions of a power information transmission unit 21 and a communication information transmission unit 22.
[0024] The power information transmission unit 21 outputs power information, including power logs such as power transmission and reception, to the anomaly visualization system 4. Here, power information is an example of log information related to power. For example, the power information transmission unit 21 outputs power logs at a predetermined period stored in its internal memory. For example, the power information transmission unit 21 outputs power logs triggered by a request from the anomaly visualization system 4.
[0025] Figure 3 shows an example of the configuration of power information according to the first embodiment. The power information in Figure 3 exemplifies a power consumption log of power equipment 2. This power consumption log includes the items "Equipment," "Timestamp," and "Power Consumption." The "Equipment" item stores information to uniquely identify power equipment 2 that outputs the power log. The "Timestamp" item stores time information when the power consumption was recorded. The "Power Consumption" item stores the value of power consumption in power equipment 2. Note that the period for collecting power logs and the period for outputting them may be different. Figure 3 exemplifies a power log when the output period is longer than the period for collecting power logs. Note that the configuration of the power information in Figure 3 is merely an example, and its items and other details may be changed as appropriate.
[0026] The communication information transmission unit 22 outputs communication information, including communication logs such as the transmission and reception of control signals, to the anomaly visualization system 4. Here, the communication information is an example of log information related to communication. For example, the communication information transmission unit 22 outputs communication logs at predetermined intervals that are stored in the internal memory. For example, the communication information transmission unit 22 outputs communication logs triggered by a request from the anomaly visualization system 4.
[0027] Figure 4 shows an example of the configuration of communication information according to the first embodiment. The communication information in Figure 4 exemplifies a communication log in the power equipment 2. This communication log includes the items "destination," "transmission time," "command," "start time," and "period." The "destination" item stores information to uniquely identify the destination of the control signal, for example. The "transmission time" item stores information about the time the control signal was transmitted, for example. The "command" item stores information indicating the content of the control by the control signal, for example. The "start time" item stores information indicating the start time of the control by the control signal, for example. The "period" item stores information indicating the implementation period (application period) of the control by the control signal, for example. Note that the period for collecting the communication log and the period for outputting it may be different. Figure 4 exemplifies a communication log when the output period is longer than the period for collecting the communication log. Note that the configuration of the communication information in Figure 4 is merely an example, and its items and other details may be changed as appropriate.
[0028] As shown in Figure 2, the anomaly visualization system 4 has the functions of a power anomaly prediction unit 41, a communication anomaly determination unit 42, a geographic information database 43, an anomaly area mapping unit 44, a priority determination unit 45, an additional anomaly analysis unit 46, and a display unit 47.
[0029] The power anomaly prediction unit 41 acquires power information from the power equipment 2 and performs power anomaly prediction (detection) processing to detect power anomalies in the power grid of the target area based on the acquired power information. For example, the power anomaly prediction unit 41 verifies the log (power information) according to predetermined rules and detects a power anomaly if the actual power situation (actual value) does not meet predetermined conditions (e.g., threshold conditions). As an example, the power anomaly prediction unit 41 may detect a power anomaly if the difference between the planned value and the actual value of the amount of power and / or frequency in the power grid of the area including multiple power equipment 2 does not meet a threshold condition that is predetermined and stored in the internal memory. As an example, the power anomaly prediction unit 41 may detect a power anomaly if the difference between the predicted value that can be estimated from the climate, etc., of the amount of power generated and / or frequency in the power grid of the area including multiple power equipment 2 and the actual value does not meet a threshold condition that is predetermined and stored in the internal memory. For example, the power anomaly prediction unit 41 may detect a power anomaly if the actual power conditions, such as the amount of power generated, the amount of energy stored, the amount of power transmitted, and the frequency of each power device 2 in a regional power grid including multiple power devices 2, do not meet predetermined threshold conditions stored in the internal memory. These predetermined conditions may be based on past performance values or their statistical values. In other words, a power anomaly may be defined as a deviation from past power conditions.
[0030] The communication anomaly detection unit 42 acquires communication information from the power equipment 2 and performs communication anomaly detection processing to detect communication anomalies in the power grid of the target area based on the acquired communication information. For example, the communication anomaly detection unit 42 verifies the log (communication information) according to predetermined rules and detects a communication anomaly if the actual communication status (actual value) does not meet predetermined conditions (e.g., threshold conditions). As an example, the communication anomaly detection unit 42 may detect a communication anomaly if the amount of communication or the communication frequency does not meet predetermined threshold conditions stored in the internal memory. As an example, the communication anomaly detection unit 42 may detect a communication anomaly if the period during which communication information cannot be acquired (e.g., delay time) does not meet predetermined threshold conditions stored in the internal memory. As an example, the communication anomaly detection unit 42 may detect a communication anomaly if the communication partner is a different communication destination from the registered destinations stored in the internal memory. As an example, the communication anomaly detection unit 42 may detect a communication anomaly if there is an inconsistency between multiple commands (control contents). Past performance values or their statistical values may be used as these predetermined conditions. In other words, a communication anomaly can be defined as a deviation from past communication conditions.
[0031] For example, the communication information in Figure 4 includes a communication log ordering a "small power consumption reduction" for "15 minutes" starting from "2025 / 01 / 14 12:00:00", and a subsequent communication log ordering a "large power consumption reduction" for "2 hours" starting from "2025 / 01 / 14 12:15:00". The communication information in Figure 4 also includes a "power consumption reduction cancellation" command sent after these power consumption reduction commands. In such a case, the communication anomaly determination unit 42 may detect the "power consumption reduction cancellation" communication log, which is inconsistent with the power consumption reduction commands, as an "attack log," i.e., a communication anomaly.
[0032] The geographic information database 43 is a database that stores geographic information of the target area, such as map data of the target area, data on the layout of power infrastructure in the target area, and management data. The management data includes information that defines a grid for dividing the target area shown on the map into multiple areas, and information that uniquely identifies each divided area (e.g., a mesh code).
[0033] In the anomaly visualization system 4 relating to this disclosure, the target region (target area) is divided into multiple areas using, for example, grids along lines of latitude and longitude, but is not limited to this. For example, each grid may be divided based on the areas in which each power device is shared, such as dividing it into areas where power is transmitted via a common transformer, based on information such as the equipment connected to the transformer, the equipment connected to the substation, and the equipment connected to the microgrid.
[0034] In the anomaly visualization system 4 related to this disclosure, the area (grid) used as the unit for detecting communication anomalies and power anomaly precursors, and the area (grid) used as the unit for determining overlap, may, for example, coincide, but may also be different. Similarly, in the anomaly visualization system 4 related to this disclosure, the area (grid) used as the unit for detecting communication anomalies and the area (grid) used as the unit for detecting power anomaly precursors, may, for example, coincide, but may also be different. For example, in the overlap determination process for detection areas (anomaly occurrence locations), if there is an inclusion relationship based on the granularity of the areas, such as the area of the charging station < the area of the transformer < the area of the substation < the area of the microgrid < the area of the main grid, then it can be determined that the detection areas overlap.
[0035] The abnormal area mapping unit 44 performs abnormal area mapping, which associates the location of each abnormality with the location of the detection area of each abnormality, based on the detection results of communication abnormalities, the detection results of power abnormality precursors, and the geographic information of the target area.
[0036] For example, the abnormal area mapping unit 44 associates the positional relationship between the detection area of power anomaly precursors and the detection area of communication anomalies on a map of the target area. For example, the abnormal area mapping unit 44 obtains geographic information of the target area from the geographic information database 43. The abnormal area mapping unit 44 also obtains the detection result of communication anomalies from the communication anomaly determination unit 42. The abnormal area mapping unit 44 also obtains the detection result of power anomaly precursors from the power anomaly precursor determination unit 41. For example, the abnormal area mapping unit 44 identifies a detection area on the map of the target area that indicates the location of the communication anomaly on the map of the target area, based on the communication anomaly detection result from the communication anomaly determination unit 42 and the geographic information of the target area stored in the geographic information database 43. The abnormal area mapping unit 44 also identifies a detection area on the map of the target area that indicates the location of the power anomaly precursor on the map of the target area, based on the power anomaly precursor detection result from the power anomaly prediction unit 41 and the geographic information of the target area stored in the geographic information database 43.
[0037] The priority determination unit 45 performs an overlap determination process based on the abnormal area mapping results from the abnormal area mapping unit 44 to determine whether there are any overlapping areas (grids) where the detection area for power anomaly warnings and the detection area for communication anomalies overlap. In other words, the priority determination unit 45 performs an overlap determination process to determine whether an incident has occurred in which power anomaly warnings and communication anomalies with overlapping detection areas have been detected (hereinafter referred to as a simultaneous incident). The priority determination unit 45 also determines the priority of the response to the detected anomalies (incident response).
[0038] For example, the priority determination unit 45 may determine the priority of each incident response based on the abnormal area mapping results from the abnormal area mapping unit 44, that is, the results of the mapping of abnormal occurrence locations. For example, if a power anomaly precursor and a communication anomaly are detected and their detection areas overlap, the priority determination unit 45 may treat them as a single incident (a simultaneously occurring incident). Also, for example, the priority determination unit 45 may set a higher priority for a simultaneously occurring incident response than for an incident in which only one of the communication anomaly or power anomaly precursor is detected. For example, if a power anomaly precursor and a communication anomaly are detected but their detection areas do not overlap, the priority determination unit 45 may treat them as different incidents. Also, for example, the priority determination unit 45 may set a lower priority for these incident responses than for simultaneously occurring incident responses. Also, for example, the priority determination unit 45 may set a higher priority for an incident response in which only a communication anomaly is detected than for an incident in which only a power anomaly precursor is detected.
[0039] For example, the priority determination unit 45 may set the highest priority for each incident response based on the order in which the detected anomalies occurred.
[0040] For example, the priority determination unit 45 may set individual priorities, which are pre-configured and stored in internal memory for each type of anomaly (event) or combination thereof, to each incident response.
[0041] Priority may be set by combining the above criteria, or by using other criteria.
[0042] The additional anomaly analysis unit 46 performs additional analysis processing on the detected simultaneous incidents.
[0043] As an example, the additional anomaly analysis unit 46 may perform additional analysis, for example, based on power information and / or communication information, after raising the alert level for each anomaly in a simultaneously occurring incident.
[0044] As an example, the additional abnormality analysis unit 46 may perform additional analysis for detecting an abnormality by strengthening the conditions for determining (detecting) an abnormality for each abnormality of the simultaneous incident. Here, strengthening the conditions for abnormality detection is an example of increasing the alert level, and for example, it is to enable the classification of simultaneous incidents such as extracting highly risky abnormalities by raising the threshold value or adding other conditions.
[0045] As an example, the additional abnormality analysis unit 46 may perform additional analysis for detecting an abnormality by relaxing the conditions for determining (detecting) an abnormality for other power equipment within the detection area of each abnormality of the simultaneous incident. Here, relaxing the conditions for abnormality detection is an example of increasing the alert level, and for example, it is to enable the detection of events that are not normally detected as abnormalities by lowering the threshold value or excluding some conditions.
[0046] Note that the other power equipment is, for example, power equipment of the same type as the power equipment in which an abnormality is detected, but it may also be power equipment of other types. Further, the other power equipment may be, for example, power equipment within the same facility as the power equipment in which an abnormality is detected. Further, the other power equipment may be, for example, power equipment arranged in another facility of the same type as the facility in which the power equipment in which an abnormality is detected is arranged.
[0047] Note that the additional analysis is not limited to within the detection area of each abnormality of the simultaneous incident, and may be performed including the adjacent area adjacent to the detection area, or may be performed for the entire area of the target region. Further, the additional analysis may be automatically performed triggered by the detection of the simultaneous incident, or may be performed by the user's instruction in accordance with, for example, a response manual presented to the user in response to the detection of the simultaneous incident. Further, the additional abnormality analysis unit 46 is not an essential component and may not be provided.
[0048] <0000 {0000|0001|0002|0003|0004|0005|0006|0007|000 |0009|0010|0011|0012|0013|0014|0015|0016|0017|0018|0019|0020|0021|0022|0023|0024|0025|0026|0027|0028|0029|0030|0031|0032|0033|0034|0035|0036|0037|0038|0039|0040|0041|0 => The display unit generates display information for supporting incident response according to an abnormality occurring in the power grid of the target region and outputs this.
[0049] As an example, the displayed information includes mapping information (see Figure 7) that visualizes the results of anomaly area mapping related to the power infrastructure of the target area, that is, the results of the correspondence between the locations of communication anomalies and power anomaly precursors that occurred in the power grid of the target area.
[0050] As an example, the displayed information includes incident information (see Figure 7) related to each detected power anomaly precursor and / or communication anomaly. This incident information includes information on the corresponding response manual (items) based on the matching results.
[0051] For example, the display unit 47 generates display information using the server 5 and outputs it to the client terminal 6. The display unit 47 also displays the display information obtained from the server 5 on a display installed in or connected to the client terminal 6.
[0052] For example, the display unit 47 outputs information to the client terminal 6 for the server 5 to generate display information. The display unit 47 also generates display information based on the information obtained from the server 5 by the client terminal 6 and displays it on a display installed in or connected to the client terminal 6.
[0053] Figure 5 shows an example of the hardware configuration of an information processing device 8 that realizes each device of the power system 1 according to the first embodiment. Note that one device of the power system 1 may be realized by one information processing device 8, or by the cooperation of two or more information processing devices 8. Similarly, two or more devices of the power system 1 may be integrated and realized by one information processing device 8. For example, the anomaly visualization system 4 may be realized by one information processing device 8, such as by integrating the server 5 and the client terminal 6.
[0054] As shown in Figure 5, the information processing device 8 includes a processor 81, a main memory 82, an auxiliary storage device 83, and an interface (I / F) 84. The processor 81, main memory 82, auxiliary storage device 83, and I / F 84 are interconnected by a bus or the like, resulting in a hardware configuration that utilizes a typical computer. Note that each component of the information processing device 8 may be realized by a combination of two or more components. Similarly, two or more components of the information processing device 8 may be integrated and realized by a single component.
[0055] The processor 81 is, for example, at least one CPU (Central Processing Unit). The processor 81 comprehensively controls the operation of the information processing device 8, for example by executing a program, and realizes each of the functions of the information processing device 8.
[0056] As an example, the processor 81 of the power device 2 may implement each function of the power device 2, including the power information transmission unit 21 and the communication information transmission unit 22 as illustrated in Figure 1, by loading a program stored in the auxiliary storage device 83 into the main memory device 82 and executing it. As an example, in the abnormality visualization system 4, the processor 81 of the server 5 or client terminal 6 may implement each function of the abnormality visualization system 4, including the power abnormality prediction unit 41, the communication abnormality determination unit 42, the geographic information database 43, the abnormality area mapping unit 44, the priority determination unit 45, the additional abnormality analysis unit 46, and the display unit 47 as illustrated in Figure 1, by loading a program stored in the auxiliary storage device 83 into the main memory device 82 and executing it. For example, the processor 81 of the server 5 may implement each function of the abnormality visualization system 4, including the power abnormality prediction unit 41, the communication abnormality determination unit 42, the geographic information database 43, the abnormality area mapping unit 44, the priority determination unit 45, the additional abnormality analysis unit 46, and the display unit 47. For example, the processor 81 of the client terminal 6 may implement each function of the anomaly visualization system 4, including the display unit 47.
[0057] In the example shown in Figure 2, only the functions necessary for explaining the main parts of this embodiment are illustrated, but the functions of each device in the power system 1 are not limited to these. Furthermore, some or all of the functions of each device in the power system 1 may be implemented by dedicated hardware circuits.
[0058] Furthermore, in each device of the power system 1, two or more functions may be integrated and implemented as a single function. Similarly, in each device of the power system 1, one function may be divided and implemented as two or more functions. Furthermore, in the power system 1, the functions of two or more devices may be integrated and implemented as at least one function of any of the devices. Similarly, in the power system 1, the functions of one device may be divided and implemented as two or more functions of two or more devices.
[0059] Here, the processor 81 according to the embodiment is an example of at least one processor in the information processing device 8. Instead of the CPU, or in addition to the CPU, at least one other processor may be used as the at least one processor. As the other processor, various processors such as a CPU, GPU (Graphics Processing Unit), DSP (Digital Signal Processor), or dedicated arithmetic circuits implemented with ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array) can be used as appropriate.
[0060] The main memory 82 is, for example, RAM (Random Access Memory). The main memory 82 temporarily stores data necessary for various processes performed by the processor 81. Here, the main memory 82 in this embodiment is an example of the internal memory in the information processing device 8, and is an example of at least one memory.
[0061] The auxiliary storage device 83 is, for example, a ROM (Read Only Memory). The auxiliary storage device 83 stores programs and parameters that realize various processes by the processor 81. Here, the auxiliary storage device 83 according to this embodiment is an example of the internal memory in the information processing device 8, and is an example of at least one memory. In addition to or instead of ROM, various storage media and storage devices such as HDDs (Hard Disk Drives), SSDs (Solid State Drives), and Flash memory can be used as the auxiliary storage device 83 as appropriate.
[0062] As an example, in the anomaly visualization system 4, the main memory 82 and auxiliary memory 83 of the server 5 or client terminal 6 may implement a geographic information database 43.
[0063] I / F84 is an interface to the user and / or external devices. For example, I / F84 may be an output interface for connecting or implementing an output device that outputs audio, images, or video. Suitable output devices include various displays such as liquid crystal displays (LCDs), organic EL (Electroluminescence) displays, head-up displays (HUDs), and projectors, as well as speakers. I / F84 may also be an input interface for connecting or implementing an input device that acquires audio, images, video, or user input. Suitable input devices include keyboards, mice, touch panels, and microphones. Furthermore, I / F84 may be a communication interface for connecting or implementing a communication device that communicates with external devices. Suitable communication devices include wired or wireless communication circuits. For wireless communication, communication circuits compatible with various standards such as 3G, 4G, 5G, 6G, Wi-Fi®, Bluetooth®, and infrared communication can be used as appropriate.
[0064] As an example, the I / F 84 of the power equipment 2 may implement a communication interface (power information transmission unit 21 and communication information transmission unit 22) for communicating with the anomaly visualization system 4. As an example, the I / F 84 of the anomaly visualization system 4 may implement a communication interface (power anomaly prediction determination unit 41, communication anomaly determination unit 42) for communicating with the power equipment 2. As an example, the I / F 84 of the anomaly visualization system 4 may implement an output interface (display unit 47) for displaying information on the screen based on the display information. As an example, the I / F 84 of the server 5 may implement a communication interface (power anomaly prediction determination unit 41, communication anomaly determination unit 42) for communicating with the power equipment 2, and a communication interface (display unit 47) for communicating with the client terminal 6. As an example, the I / F 84 of the client terminal 6 may implement a communication interface (display unit 47) for communicating with the server 5. As an example, the I / F 84 of the client terminal 6 may implement an output interface (display unit 47) for displaying information on the screen based on the display information. Furthermore, the I / F 84 of the client terminal 6 may implement an input interface for acquiring user operations and a communication interface for sending operation information corresponding to the acquired user operations to the server 5.
[0065] Furthermore, the information processing device 8 that realizes each device of the power system 1 according to this embodiment may be implemented by an in-vehicle computer, such as when applied to a vehicle (mobile device). This in-vehicle computer may be an ECU (Electronic Control Unit) or a DCU (Domain Control Unit) such as a CDC (Cockpit Domain Controller) that integrates multiple ECUs, or an OBU (On Board Unit), etc., located inside the vehicle. Alternatively, the in-vehicle computer may be an external computer installed near the vehicle's dashboard. In addition, the information processing device 8 that realizes any of the devices of the power system 1 may be implemented by an information processing device 8 common to other in-vehicle devices, or each may be implemented by a different information processing device 8. As an example, the information processing device 8 that realizes the client terminal 6 of the power system 1 may be configured integrally with an in-vehicle car navigation system.
[0066] Furthermore, when the information processing device 8 that implements each device of the power system 1 according to the embodiment is applied to a vehicle (mobile body), it may send and receive information with other computers installed in the vehicle via an in-vehicle network including CAN (Controller Area Network), Ethernet (registered trademark), USB (Universal Serial Bus (registered trademark)), etc., or it may communicate with an information processing device outside the vehicle via a network such as the Internet.
[0067] The operation example of the power system 1 according to the embodiment will be described below with reference to the drawings. Note that the process described below is just one example, and it is possible to change the order of processing, delete some processes, or add other processes.
[0068] Figure 6 is a flowchart showing an example of the information processing flow performed by the anomaly visualization system 4 according to the first embodiment. Here, we will explain the case where both power information and communication information transmitted from each power device 2 are received as an example.
[0069] Power information and communication information may be transmitted from each power device 2 at predetermined intervals or timings. The transmission intervals or timings may be common to all power devices 2 or may differ. The flow in Figure 6 may also be executed periodically or regularly, for example, in accordance with the transmission intervals or timings of power information and / or communication information from each power device 2. Alternatively, the flow in Figure 6 may be triggered by the receipt of power information and / or communication information transmitted from each power device 2.
[0070] The power anomaly prediction unit 41 receives power information transmitted from each power device 2 (S101) and performs power anomaly prediction detection processing based on the received power information (S102). The communication anomaly determination unit 42 also receives communication information transmitted from each power device 2 (S103) and performs communication anomaly detection processing based on the received communication information (S104). After processing S102 and / or S104, the flow in Figure 6 proceeds to processing S105. After processing S102 and / or S104, the flow in Figure 6 proceeds to processing S105.
[0071] Note that the processes S101-S102 and S103-S104 are executed in parallel, for example, but it is acceptable for one of them to be executed first. Also, if the transmission timings for power information and communication information are different, the system may be configured to proceed to process S105 after either the processes S101-S102 or S103-S104 have been completed. Alternatively, if the transmission timings for power information and communication information are the same, the system may be configured to proceed to process S105 after both the processes S101-S102 and S103-S104 have been completed.
[0072] The abnormal area mapping unit 44 performs abnormal area mapping, mapping the locations of each abnormality on a map based on the detection results of communication abnormalities, the detection results of power abnormality precursors, and the geographic information of the target area (S105). Then, the priority determination unit 45 performs overlap determination processing to determine whether there is an area where two types of abnormality locations (detection areas) overlap, that is, whether there are simultaneous incidents (S106).
[0073] If there are simultaneous incidents (S106: Yes), the additional anomaly analysis unit 46 performs additional analysis processing for the detected simultaneous incidents (S107). Note that the processing in S107 is not a mandatory configuration and may not be provided.
[0074] After the additional analysis process, or if there are no simultaneous incidents (S106: No), the priority determination unit 45 determines the priority of each response (each incident response) for each detected anomaly. The display unit 47 also generates and displays display information to support incident responses corresponding to anomalies that have occurred in the power grid of the target area, based on the results of the anomaly area mapping (S108). This display process (S108) may be performed prior to the additional analysis process (S107). After that, the flow shown in Figure 6 ends.
[0075] Furthermore, if additional analysis detects any abnormalities in the power grid of the target area, the processes S105 to S108 may be performed in the same manner.
[0076] Figure 7 shows an example of a screen display in the information processing according to the first embodiment. Figure 7 illustrates the display screen 701 displayed in the information processing of Figure 6. As shown in Figure 7, the display screen 701 includes associated visualization information 710 and incident information 720.
[0077] The correspondence visualization information 710 includes a map 711 of the target area. The area on this map 711 of the target area is divided into a grid using a predetermined division method and includes multiple areas 712. The correspondence visualization information 710 also includes the locations where power system anomalies have occurred among the multiple areas 712 into which the target area has been divided, i.e., detection areas 712a to 712c. In the correspondence visualization information 710, the detection areas 712a to 712c have a display mode corresponding to the detection status of the power system anomaly. Specifically, the display mode of the detection areas 712a to 712c is determined so that it is possible to visually determine whether the detected anomaly is a communication anomaly, a power anomaly precursor, or both.
[0078] Detection area 712a exemplifies the display method for "Area X," a simultaneous incident in which both communication anomalies and power anomaly precursors are detected. In the example in Figure 7, this detection area 712a has a display method that shows both a dashed line frame indicating area 712 where a communication anomaly was detected and dot hatching indicating area 712 where a power anomaly precursor was detected. Detection area 712b exemplifies the display method for "Area Y," an incident in which only power anomaly precursors are detected. In the example in Figure 7, this detection area 712b has a display method that shows only dot hatching indicating area 712 where a power anomaly precursor was detected. Detection area 712c exemplifies the display method for "Area Z," an incident in which only a communication anomaly was detected. In the example in Figure 7, this detection area 712c has a display method that shows only a dashed line frame indicating area 712 where a communication anomaly was detected.
[0079] Note that the display methods for each detection status in Figure 7 are examples and can be changed as appropriate. For example, each detection status can be visually distinguished by varying various display methods such as the presence or absence of a frame or display within the frame, color, transparency, blinking, brightness, text, and icons.
[0080] Incident information 720 includes information indicating each incident based on at least one detected anomaly. In the example in Figure 7, the information indicating each incident is displayed as alert tickets 721a to 721c. Alert tickets 721a to 721c are displayed in order of priority for incident response, set according to the detection status of anomalies in the power system. Alert tickets 721a to 721c include the fields "Date and Time of Occurrence," "Summary," and "Response Procedure." Here, the "Response Procedure" field is an example of an incident response manual corresponding to the matching result.
[0081] Alert ticket 721a exemplifies information about a concurrent incident associated with detection area 712a in "Area X". In the example in Figure 7, alert ticket 721a includes items such as "Date and Time of Occurrence" (e.g., "xx / 10 / 5 03:00:00"), "Summary" (e.g., "DoS attack occurred in Area X"), and "Response Procedure" (e.g., "Incident Reporting Route..."). In the case of concurrent incidents, since there is already a high probability of a security incident occurring, the "Response Procedure" item displays the incident response procedure (response manual) for the concurrent incident that occurred, or a notification instructing or prompting such a response.
[0082] Alert ticket 721b exemplifies information regarding a power anomaly precursor incident associated with detection area 712b in "Area Y". In the example in Figure 7, alert ticket 721b includes items such as "Date and Time of Occurrence" (e.g., "xx / 10 / 5 01:00:00"), "Summary" (e.g., "Power anomaly occurred in Area Y"), and "Response Procedure" (e.g., "Contact management company..."). In the case of an incident where only a power anomaly precursor is detected, environmental factors or equipment failure are highly likely to be the cause, so the "Response Procedure" item displays the response procedure (response manual) for physical maintenance of the power anomaly precursor that occurred, or a notification instructing or prompting such action.
[0083] Alert ticket 721c exemplifies information regarding a communication anomaly incident associated with detection area 712c in "Area Z". In the example in Figure 7, alert ticket 721c includes items such as "Date and Time of Occurrence" (e.g., "xx / 10 / 5 02:00:00"), "Summary" (e.g., "Unauthorized access occurred in Area Z"), and "Response Procedure" (e.g., "Secondary analysis procedure..."). In the case of an incident where only a communication anomaly is detected, there is a high possibility of a cyberattack, so the "Response Procedure" item will display a normal analysis procedure document (response manual) or a notification instructing or prompting such a response.
[0084] As illustrated in Figure 7 as incident information 720, information regarding detected anomalies is displayed alongside, for example, the correspondence visualization information 710 showing the results of the correspondence, but is not limited to this. Information regarding detected anomalies may also be displayed via a screen transition from the information showing the results of the correspondence. This screen transition is not limited to a complete screen change, but may also be a partial change, a partial enlargement, or an overlay on part or the whole screen, such as a pop-up display.
[0085] Furthermore, it is sufficient that communication anomalies and power anomaly warnings are displayed together, and each area 712 may be displayed in a different display mode than the grid display, such as dots, arbitrary shapes, or icons, or any one area 712 may represent a single power device. In this case, overlap between the detection area for communication anomalies and the detection area for power anomaly warnings may mean that these detection areas are within a predetermined size range or are less than or equal to a predetermined distance.
[0086] As described above, the anomaly visualization system 4 according to this embodiment visualizes the results of the correspondence between communication anomalies and power anomaly predictions, and displays an appropriate manual based on the results of the correspondence. Specifically, the anomaly visualization system 4 receives communication logs and power logs, and makes a judgment (detection) of power anomalies and communication anomalies based on an analysis from a cybersecurity perspective. The anomaly visualization system 4 then maps the locations where power anomalies and communication anomalies are detected, that is, the locations where each anomaly occurs, and displays correspondence visualization information 710 that visualizes the results of the correspondence of the anomaly occurrence locations.
[0087] In recent years, the importance of cybersecurity in the power sector has increased due to the expansion of distributed energy resources (DERs) and renewable energy use. The impact of an accident in the power sector is enormous, and from the perspective of mitigating the damage caused by security incidents, smooth incident response is required. However, during the analysis of cyberattacks, there was a risk of delays in alert response due to a lack of understanding of what was happening on the ground.
[0088] In this context, according to the above configuration of the anomaly visualization system 4 of this embodiment, if a power anomaly caused by a cyberattack (communication anomaly) has already occurred, it will be represented as an overlap in the detection area based on the correspondence of its occurrence location. Therefore, users can easily identify incidents that are more likely to be dangerous and take appropriate action to address them. Accordingly, the anomaly visualization system 4 of this embodiment can support incident response in response to anomalies occurring in the power system.
[0089] Furthermore, the anomaly visualization system 4 according to this embodiment determines the priority of an incident based on the results of the correspondence between the locations where power anomalies and communication anomalies occurred. For example, if further signs of a power anomaly are detected at or near the location where a communication anomaly was detected from a cybersecurity perspective, it is determined to be an incident with a higher probability of being dangerous, i.e., an incident with a higher priority. The anomaly visualization system 4 also displays incident information 720, including an alert ticket 721 for each incident, in a display order and display items according to the determination result. This alert ticket includes, for example, a response manual based on the results of the correspondence between the locations where power anomalies and communication anomalies occurred for each event.
[0090] This configuration allows users to prioritize and respond smoothly to incidents that are more likely to be dangerous.
[0091] Other embodiments of this disclosure will be described below with reference to the drawings. In the following descriptions of each embodiment, the differences will be explained primarily, and any content that overlaps with the above will be omitted as appropriate.
[0092] (Second Embodiment) In the anomaly visualization system 4 according to this embodiment, the priority determination unit 45 determines the severity of the response (incident response) to the detected anomaly, and sets a higher priority for the incident response the higher the determined severity.
[0093] As an example, the priority determination unit 45 calculates the severity of each incident based on the abnormal area mapping results from the abnormal area mapping unit 44, that is, the results of the mapping of the location of the abnormality. For example, the priority determination unit 45 may set a higher severity level for simultaneously occurring incidents than for incidents in which only one of the communication abnormality or power abnormality precursor was detected. Also, for example, the priority determination unit 45 may set a higher severity level for incidents in which only the communication abnormality was detected than for incidents in which only the power abnormality precursor was detected.
[0094] For example, the priority determination unit 45 may set a higher severity level for each incident based on the order in which the detected anomalies occurred.
[0095] For example, the priority determination unit 45 may set individual severity levels, which are pre-configured and stored in internal memory for each type of abnormality (event) or combination thereof, for each incident.
[0096] As an example, the priority determination unit 45 may set the severity level based on the results of the additional analysis by the additional anomaly analysis unit 46 for the concurrently occurring incidents. For example, the priority determination unit 45 may set a higher severity level or update (reset) the already set severity level for concurrently occurring incidents in which additional communication anomalies and / or power anomaly precursors are detected in the additional analysis.
[0097] As an example, the priority determination unit 45 may, with respect to concurrently occurring incidents, set a higher severity level or update (reconfigure) an existing severity level if a causal relationship is found between the operation indicated in the log that caused the detection of the communication anomaly (the operation performed as recorded in the communication log) and the phenomenon of the power anomaly precursor. Here, a causal relationship between the phenomena means that the content of the communication log set for the target to be detected as a communication anomaly matches the phenomenon set for the target to be detected as a power anomaly precursor. In this case, these correspondences are, for example, predetermined and stored in internal memory. For example, if frequency manipulation due to unauthorized access is detected as a communication anomaly, and a frequency anomaly is detected as a power anomaly precursor, it is determined that the phenomena match.
[0098] Furthermore, the determination of a matching phenomenon may be based on the output of an Artificial Intelligence (AI) in response to inputs of communication information, power information, and a prompt instructing the output of a determination result of whether the phenomenon or the phenomenon matches based on this information. In this case, the input to the Artificial Intelligence may include, in addition to or in addition to logs such as communication information and power information, the results of anomaly detection based on the aforementioned logs, or the results of mapping the occurrence location.
[0099] The severity level may be determined by combining the above criteria, or by using other criteria.
[0100] Figure 8 shows an example of a screen display in the information processing according to the second embodiment. Figure 8 illustrates the display screen 702 displayed in the information processing of Figure 6. As shown in Figure 8, the display screen 702 includes correspondence visualization information 710 and incident information 720, similar to Figure 7.
[0101] Figure 8 illustrates the display mode of "Area X" in detection area 712a, where simultaneous incidents occur and the phenomena corresponding to communication anomalies and power anomaly precursors match. Detection area 712b illustrates the display mode of "Area Y" in incidents where only power anomaly precursors are detected. Detection area 712c illustrates the display mode of "Area Z" in simultaneous incidents.
[0102] In the example shown in Figure 8, alert tickets 721a and 721c for concurrently occurring incidents are displayed in a more emphasized manner than alert ticket 721b for an incident in which only one anomaly was detected. Furthermore, among the alert tickets 721a and 721c for concurrently occurring incidents, alert ticket 721c, whose severity has been increased due to matching symptoms, is displayed in a more emphasized manner than alert ticket 721a for a concurrently occurring incident in which there is no matching symptom.
[0103] Furthermore, in the example in Figure 8, the "Summary" section of alert ticket 721a displays "DoS attack occurred in Area X, power anomaly warning area, severity +2," indicating that the severity has been increased based on the simultaneous occurrence of incidents, and that severity "+2" is displayed. Similarly, the "Summary" section of alert ticket 721c displays "Unauthorized access occurred in Area Z, frequency manipulation log confirmed & frequency anomaly occurred, severity +4," indicating that the symptoms match, the severity has been increased based on the matching symptoms, and a severity of "+4" is set and displayed, which is higher than the "+2" of the simultaneous occurrence of incidents.
[0104] As described above, the anomaly visualization system 4 according to this embodiment calculates the importance of each incident response, sets priorities that take this importance into account, and displays the level of demand. Furthermore, for simultaneous incidents occurring in overlapping detection areas, the anomaly visualization system 4 increases the importance if the phenomena match between communication anomalies and power anomaly precursors, or if an anomaly is detected through additional analysis.
[0105] This configuration allows users to better understand and respond more quickly to potentially dangerous incidents by referring to their severity level or by displaying them in a severity-conscious manner.
[0106] (Third Embodiment) Here, we will mainly explain the differences from the anomaly visualization system 4 according to the second embodiment.
[0107] As an example, the priority determination unit 45 increases the severity level in the area surrounding the power anomaly detection area, or in an area with a granularity one level higher than the said detection area.
[0108] Figure 9 shows an example of a screen display in the information processing according to the third embodiment. Figure 9 illustrates the display screen 703 displayed in the information processing of Figure 6. As shown in Figure 9, the display screen 703 includes the mapping visualization information 710 and the incident information 720, similar to Figure 7.
[0109] Figure 9 illustrates three detection areas: detection area 712a where simultaneous incidents were detected, detection area 712b where only power anomaly precursors were detected, and detection area 712c where only communication anomalies were detected. In the example in Figure 9, detection area 712a, where simultaneous incidents were detected, is set to a severity level of "+2," similar to the example in Figure 8. Also, in the example in Figure 9, each of the detection areas 712a and 712b where power anomaly precursors were detected has an area 712d, the area surrounding the detection area, designated as "Area A." Consequently, detection area 712c, where only communication anomalies were detected, overlaps with the designated surrounding area 712d. Therefore, in the example in Figure 9, the alert ticket 721c corresponding to detection area 712c is highlighted, for example, in the same way as alert ticket 721a, and the "Summary" section displays a message such as "Severity +1 due to unauthorized access occurring in Area Z, power anomaly precursor, surrounding area."
[0110] Note that Figure 9 illustrates an example of increasing the severity in the surrounding area, but it is not limited to this. In terms of the granularity of areas, such as the charging station area < the transformer area < the substation area < the microgrid area < the main grid area, the severity may be increased in an area one level higher in granularity than the area where the power anomaly prediction is detected.
[0111] Thus, the anomaly visualization system 4 according to this embodiment increases the severity of incident response when the area surrounding or encompassing the detection area for power anomaly predictions overlaps with the detection area for communication anomalies.
[0112] This configuration allows for the identification of communication anomaly incidents that have a risk of power anomaly precursors occurring and could potentially exacerbate damage. As a result, users can better identify and respond more quickly to incidents that are more likely to be dangerous.
[0113] Furthermore, this embodiment can be appropriately combined with the embodiments described above.
[0114] (Fourth Embodiment) This section will mainly describe the differences from the anomaly visualization system 4 according to the third embodiment.
[0115] As an example, in the power system 1 according to this embodiment, the transmission and distribution lines connecting power equipment 2 to other power equipment 2 in an area one level higher in granularity than the area of the equipment itself are redundant. For example, any transformer (power equipment 2) is connected to each of two substations by transmission and distribution lines, and is configured to transmit power to one of the substations under normal circumstances.
[0116] As an example, the power anomaly prediction unit 41 according to this embodiment switches the power transmission and distribution route to the redundant power transmission and distribution route when it detects a power anomaly. For example, the power anomaly prediction unit 41 switches the power transmission and distribution route of the transformer (power equipment 2) that has detected a power anomaly from the power transmission and distribution route to one substation that normally transmits power to the redundant power transmission and distribution route to the other substation that is not normally used for power transmission.
[0117] Furthermore, the power anomaly prediction unit 41 monitors whether the detected power anomaly is resolved when the power transmission and distribution route is switched to the redundant side. If the detected power anomaly is not resolved, the power anomaly prediction unit 41 identifies the detection area from the location of the power equipment 2 that detected the power anomaly. On the other hand, if the detected power anomaly is resolved by the change to the redundant side of the power transmission and distribution route, the power equipment 2 that detected the power anomaly is normal, and the power anomaly prediction unit 41 identifies the detection area from the location of other power equipment 2 that formed a power transmission and distribution route with that power equipment 2 before the switch. For example, if the power anomaly is resolved after the power transmission and distribution route with the transformer (power equipment 2) that detected the power anomaly is switched to the power transmission and distribution route with the redundant substation, the power anomaly prediction unit 41 identifies the detection area from the location of the substation that forms the normal power transmission and distribution route. In other words, the power anomaly prediction unit 41 determines, based on the monitoring results before and after the switchover, whether the detected power anomaly occurred in the area of its own equipment or in the area of the next higher granularity.
[0118] Figure 10 is a diagram showing an example of screen display in information processing according to the fourth embodiment. Figure 10 illustrates the display screen 704 displayed in the information processing of Figure 6. As shown in Figure 10, the display screen 704 includes correspondence visualization information 710 and incident information 720, similar to Figure 7. Figure 10 illustrates a detection area 712a where simultaneous incidents are detected and a detection area 712b where only power anomaly precursors are detected. In the example of Figure 10, the detection area 712a where simultaneous incidents are detected is set to a severity level of "+2", similar to the examples in Figures 8 and 9. Also, in the example of Figure 10, each of the detection areas 712a and 712b where power anomaly precursors are detected has an area 712d surrounding "Area A". In the display screen 704 according to this embodiment, this surrounding area 712d is an area of a higher granularity. In the example shown in Figure 10, when switching to a redundant configuration connected to the next higher granularity area, corresponding visualization information 710 and incident information 720 are generated based on the monitoring results to determine whether the detected power anomaly warning has been resolved.
[0119] Thus, when a power anomaly precursor is detected, the anomaly visualization system 4 according to this embodiment isolates the location of the power anomaly precursor by verifying it using a redundant configuration, and uses this result to associate the location of the anomaly.
[0120] This configuration allows for a more granular correspondence between power anomaly predictions and communication anomalies, enabling more appropriate setting of priorities and severity levels, and the presentation of incident response strategies. In other words, the anomaly visualization system 4 according to this embodiment can support appropriate countermeasures aimed at resolving the root cause of power anomaly predictions.
[0121] Furthermore, this embodiment can be appropriately combined with the embodiments described above.
[0122] In the embodiments described above, examples were given in which map information (correspondence visualization information 710) and response manuals (incident information 720) are presented to the user primarily through screen displays, but the invention is not limited to these cases.
[0123] As an example, the anomaly visualization system 4 according to this disclosure may be configured as an analysis system (information processing system) that generates display information for displaying the screen according to each embodiment described above and outputs the generated display information to the outside. The anomaly visualization system 4 according to this disclosure may further include other display devices (information processing devices) of the client terminal 6 described above that acquire this display information directly or indirectly via the Internet, etc., and perform screen display based on the acquired display information. Furthermore, the output of display information from the anomaly visualization system 4 according to this disclosure may be performed together with the screen display according to each embodiment described above, or may be performed in place of said screen display.
[0124] As an example, the anomaly visualization system 4 according to this disclosure may include a printer that forms images corresponding to the screen displays according to each embodiment described above on various types of paper, and a speaker that outputs the content of the screen display as sound. The printer and / or speaker may be provided together with the client terminal 6 according to each embodiment described above, or may be provided in place of the client terminal 6. Furthermore, the anomaly visualization system 4 according to this disclosure may be configured as a system that outputs print information for image formation on paper to the printer, or as a system that outputs sound output information for sound output to the speaker.
[0125] Furthermore, the anomaly visualization system 4 relating to this disclosure may be applied to various types of mobile devices such as vehicles. For example, the anomaly visualization system 4 relating to this disclosure may be realized through cooperation with or integration with various infotainment systems such as navigation systems mounted on mobile devices. As an example, part or all of the anomaly visualization system 4 relating to this disclosure may be realized by a display device of the vehicle's in-vehicle infotainment system or by an in-vehicle device (computer) externally attached to the vehicle's dashboard, etc.
[0126] Here, the term "mobile entity" can refer to various types of vehicles, including electric vehicles (EVs) powered by a motor, automobiles powered by an engine (internal combustion engine), and hybrid vehicles powered by both an engine and a motor. Furthermore, while the mobile entity may be, for example, a passenger car, truck, or motorcycle, it may also be an electric bicycle, electric scooter, electric wheelchair, construction machinery, agricultural machinery, ship, train, or airplane. Additionally, the mobile entity may be configured to move autonomously, or to move in response to direct and / or remote operation by a user.
[0127] In this disclosure, "is A" means at least one of "is A" or "is not A". In other words, in each of the embodiments described above, the determination of "is A" may be achieved by determining that "is A", by determining that "is not A", or by determining both of these.
[0128] The programs executed by each device of the power system 1 of this disclosure may be provided as installable or executable files recorded on a computer-readable recording medium (Computer Program Product) such as a CD-ROM, floppy disk, CD-R, or DVD.
[0129] Furthermore, the programs executed by each device of the power system 1 of this disclosure may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. Alternatively, the programs executed by each device of the power system 1 of this disclosure may be provided or distributed via a network such as the Internet.
[0130] Furthermore, the program executed by each device of the power system 1 of this disclosure may be pre-installed and provided in ROM or the like.
[0131] According to at least one embodiment described above, it is possible to support incident response in response to anomalies occurring in the power system.
[0132] While several embodiments of the present invention have been described, these embodiments are presented as examples and are not intended to limit the scope of the invention. These embodiments can be carried out in a variety of other forms, and various omissions, substitutions, and modifications can be made without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents.
[0133] (Note) The above description of embodiments discloses the following technologies: (1) An information processing method performed by at least one processor in an information processing apparatus comprising at least one processor, comprising: acquiring log information relating to communication and power from at least one power device in a target area; detecting communication anomalies and / or power anomaly precursors in the power system of the target area based on the log information; associating the positional relationship of the detection areas for the communication anomaly and / or power anomaly precursors from the occurrence locations of each of the at least one anomalies detected by the detection on a map of the target area divided into multiple areas; generating display information that visualizes the result of the association; and outputting the generated display information. (2) The information processing method according to (1) above, wherein the detection of power anomaly precursors includes detecting them as power anomaly precursors when the actual power conditions relating to the amount of power and / or frequency do not meet predetermined threshold conditions. (3) If the detection areas for the communication anomaly and the power anomaly warning overlap based on the results of the correspondence, the incident is treated as a single incident, and the severity of the incident response is set higher than for an incident in which only one of the communication anomaly or the power anomaly warning is detected. If a causal relationship is found between the operation indicated by the log information that caused the detected communication anomaly and the phenomenon of the detected power anomaly warning, the severity of the incident response is set even higher. The information processing method described in (1) or (2) above. (4) If the detection areas for the communication anomaly and the power anomaly warning overlap based on the results of the correspondence, an additional analysis is performed, which involves raising the alert level for each anomaly and then performing an analysis based on the log information. The information processing method described in any one of (1) to (3) above. (5) If the communication anomaly and / or the power anomaly warning are additionally detected in the additional analysis, the severity of the incident response for the additionally detected anomaly is increased. The information processing method described in (4) above.(6) When a power anomaly is detected, the information processing method according to any one of (1) to (5) above, wherein the severity of the incident response to the anomaly associated with the area surrounding the detection area of the power anomaly among the multiple areas or with an area of a higher granularity is increased. (7) The information processing method according to any one of (1) to (6) above, wherein the power equipment has redundant transmission and distribution lines connected to other power equipment in an area of a higher granularity among the multiple areas, and when a power anomaly is detected, the information processing method according to any one of (1) to (6) above, wherein the power equipment monitors whether the detected power anomaly is resolved when the redundant transmission and distribution lines are switched, and based on the result of the monitoring, identifies whether the detected power anomaly occurred in the area of the equipment or in the area of a higher granularity. (8) The information processing method according to any one of (1) to (7) above, wherein the display information is information for displaying incident information, including a response manual with content corresponding to the result of the correspondence, for each of at least one incidents for at least one anomaly detected by the detection. (9) The information processing method according to (8) above, wherein the incident information includes a severity level set for at least one incident. (10) The information processing method according to any one of (1) to (9) above, wherein each of the plurality of areas is an area obtained by dividing the target area on the map using a grid along lines of latitude and longitude. (11) The information processing method according to any one of (1) to (9) above, wherein each of the plurality of areas is an area obtained by dividing the target area on the map based on an area in which the power equipment is shared. (12) The information processing method according to any one of (1) to (11) above, wherein the at least one power equipment includes power equipment related to a distributed energy source.(13) An information processing device comprising at least one processor, wherein the at least one processor acquires log information relating to communication and power from power equipment in the target area, detects communication anomalies and / or power anomaly precursors in the power system of the target area based on the log information, associates the location of each of the at least one anomalies detected by the detection with a map of the target area divided into multiple areas, associates the positional relationship of the detection areas for the communication anomalies and / or power anomaly precursors, generates display information that visualizes the result of the association, and outputs the generated display information. (14) An information processing device comprising at least one processor, wherein the at least one processor executes the information processing method described in any one of (1) to (12) above. (15) A program to cause a computer to perform the following actions: acquire log information relating to communication and power from power equipment in the target area; detect communication anomalies and / or signs of power anomalies in the power system of the target area based on the log information; associate the location of each of the at least one anomalies detected by the detection with a map of the target area divided into multiple areas to associate the positional relationship of the detection areas for the communication anomalies and / or signs of power anomalies; generate display information that visualizes the result of the association; and output the generated display information. (16) A program to cause a computer to perform the information processing method described in any one of the above items (1) to (12).
[0134] 1 Power System 2, 2-1, 2-2, 2-3 Power Equipment 21 Power Information Transmission Unit 22 Communication Information Transmission Unit 4 Anomaly Visualization System 41 Power Anomaly Prediction Unit 42 Communication Anomaly Determination Unit 43 Geographic Information Database 44 Anomaly Area Mapping Unit 45 Priority Determination Unit 46 Additional Anomaly Analysis Unit 47 Display Unit 5 Server 6 Client Terminals 701-704 Display Screen 710 Correspondence Visualization Information 711 Map of Target Area 712 Area 712a-712c Detection Area 712d Area 720 Incident Information 721a-721c Alert Ticket 8 Information Processing Device 81 Processor 82 Main Memory 83 Auxiliary Memory 84 I / F P User
Claims
1. An information processing method performed by at least one processor in an information processing apparatus comprising at least one processor, comprising: acquiring log information relating to communication and power from at least one power device in a target area; detecting communication anomalies and / or power anomaly precursors in the power system of the target area based on the log information; associating the positional relationship of the detection areas for the communication anomalies and / or power anomaly precursors from the occurrence locations of each of the at least one anomalies detected by the detection on a map of the target area divided into multiple areas; generating display information that visualizes the result of the association; and outputting the generated display information.
2. The information processing method according to claim 1, wherein the detection of the power anomaly precursor includes detecting the actual power conditions relating to the amount of energy and / or frequency as a power anomaly precursor when they do not meet predetermined threshold conditions.
3. If the detection areas for the communication anomaly and the power anomaly warning overlap based on the results of the correspondence, the incident is treated as a single incident, and the severity of the incident response is set higher than that of an incident in which only one of the communication anomaly or the power anomaly warning is detected. If a causal relationship is found between the operation indicated by the log information that caused the detected communication anomaly and the phenomenon of the detected power anomaly warning, the severity of the incident response is set to an even higher level, as described in claim 1.
4. If the detection areas for the communication anomaly and the power anomaly prediction overlap based on the results of the correspondence, the information processing method according to claim 1, further comprising raising the alert level for each anomaly and performing an additional analysis based on the log information.
5. The information processing method according to claim 4, wherein if additional communication anomalies and / or power anomaly precursors are detected in the additional analysis, the severity of the incident response to the additionally detected anomalies is increased.
6. The information processing method according to claim 1, wherein, when the power anomaly precursor is detected, the severity of the incident response to the anomaly associated with the area surrounding the detection area of the power anomaly precursor among the plurality of areas, or an area of a higher granularity, is increased.
7. The power equipment has redundant power transmission and distribution lines connecting it to other power equipment in an area one level higher in granularity than the area of the equipment itself among the multiple areas, and when a power anomaly is detected, the system monitors whether the detected power anomaly is resolved when the redundant power transmission and distribution lines are switched over, and based on the results of the monitoring, identifies whether the detected power anomaly occurred in the area of the equipment itself or in the area one level higher in granularity.
8. The information processing method according to claim 1, wherein the display information is information for displaying incident information, including a response manual with content corresponding to the result of the correspondence, for each of the at least one incidents for each of the at least one anomalies detected by the detection.
9. The information processing method according to claim 8, wherein the incident information includes a severity level set for at least one incident.
10. The information processing method according to claim 1, wherein each of the plurality of areas is an area obtained by dividing the target region on the map using a grid along lines of latitude and longitude.
11. The information processing method according to claim 1, wherein each of the plurality of areas is an area obtained by dividing the target area on the map based on the area in which the power equipment is shared.
12. The information processing method according to claim 1, wherein the at least one power device includes a power device related to a distributed energy source.
13. An information processing device comprising at least one processor, wherein the at least one processor acquires log information relating to communication and power from power equipment in a target area, detects communication anomalies and / or power anomaly precursors in the power system of the target area based on the log information, associates the location of each of the at least one anomalies detected by the detection with a map of the target area divided into multiple areas, associates the positional relationship of the detection areas for the communication anomalies and / or power anomaly precursors, generates display information that visualizes the result of the association, and outputs the generated display information.
14. A program to cause a computer to perform the following actions: acquire log information related to communication and power from power equipment in the target area; detect communication anomalies and / or signs of power anomalies in the power system of the target area based on the log information; associate the location of each of the at least one anomalies detected by the detection with a map of the target area divided into multiple areas, thereby associating the positional relationship of the detection areas for the communication anomalies and / or signs of power anomalies; generate display information that visualizes the results of the association; and output the generated display information.