Vulnerability evaluation device, vulnerability evaluation method, and vulnerability evaluation program
Patent Information
- Application Number
- PCT/JP2025/020546
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-21
- Filing Date
- 2025-06-06
- Publication Date
- 2026-09-24
Smart Images

Figure JP2025020546_24092026_PF_FP_ABST
Abstract
Description
Vulnerability assessment apparatus, vulnerability assessment method, and vulnerability assessment program
[0001] The present disclosure relates to a vulnerability assessment apparatus, a vulnerability assessment method, and a vulnerability assessment program.
[0002] In recent years, information security vulnerabilities have been continuously discovered and reported in systems, products, and open source software used therein. Vulnerabilities may be exploited by malicious attackers, and pose a risk of causing serious damage such as unauthorized access to systems, data leakage, or service outages.
[0003] Japanese Unexamined Patent Application Publication No. 2024-035327 describes a security risk assessment support method capable of grasping threats to a system.
[0004] Japanese Unexamined Patent Application Publication No. 2024-035327
[0005] In order to appropriately respond to vulnerabilities, it is important to evaluate the severity of each vulnerability in a system and prioritize which vulnerabilities should be addressed based on the evaluation.
[0006] An object of the present disclosure is to assess the severity of vulnerabilities.
[0007] A vulnerability assessment apparatus according to an aspect of the present disclosure is a vulnerability assessment apparatus that assesses vulnerabilities of a target system including an IT (Information Technology) system and an OT (Operational Technology) system. The vulnerability assessment apparatus comprises: an information storage unit that stores IT-related impact information including IT-related events occurring in the IT system based on vulnerabilities of the target system and impacts caused by the IT-related events, and OT-related damage information including OT-related events occurring in the OT system and damages caused by the OT-related events; an event correspondence unit that associates the IT-related events with the OT-related events to generate event correspondence information; and an OT-related severity assessment unit that obtains the severity of a vulnerability from the impact caused by the IT-related event and the damage caused by the OT-related event based on the correspondence in the event correspondence information, and stores OT-related severity information including the severity in the information storage unit.
[0008] The vulnerability assessment device can perform vulnerability assessments that take into account the damage to the OT system.
[0009] A diagram of the Purdue model according to Embodiment 1. A configuration diagram of the target system 200 according to Embodiment 1. A configuration diagram of the vulnerability assessment device 300 according to Embodiment 1. A configuration diagram of vulnerability information 312 and attack information 313 according to Embodiment 1. (a) is vulnerability information 312, (b) is attack information 313. A configuration diagram of IT impact information 314 and OT damage information 315 according to Embodiment 1. (a) is IT impact information 314, (b) is OT damage information 315. A diagram showing the cause of an OT event according to Embodiment 1. A diagram showing the mapping of the event response unit 306 according to Embodiment 1. A diagram showing the mapping of the event response unit 306 according to Embodiment 1. A diagram showing the mapping of the event response unit 306 according to Embodiment 1. A diagram showing the mapping of the event response unit 306 according to Embodiment 1. A configuration diagram of OT severity information 317 according to Embodiment 1. A flowchart of the vulnerability assessment method according to Embodiment 1. A hardware configuration diagram of the vulnerability assessment device 300 according to Embodiment 1. Configuration diagram of the vulnerability assessment device 300 according to Embodiment 2. Configuration diagram of the vulnerability assessment device 300 according to Embodiment 3.
[0010] The embodiments will be described below with reference to the figures. In each figure, the same or corresponding parts are denoted by the same reference numerals. In the description of the embodiments, the description of the same or corresponding parts will be omitted or simplified.
[0011] <Explanation of terms used in the following description> IT: Abbreviation for "Information Technology." Technology for processing, storing, and transmitting information. OT: Abbreviation for "Operational Technology." Technology used for monitoring and controlling physical equipment and physical systems. Target system: The system that is the target of vulnerability assessment. A system that has both IT and OT systems. Event: An event or phenomenon that occurs in a specific situation. Incidents related to system failures and security breaches. IT-related events: Events related to IT systems. Events in IT systems. Events related to information technology such as computers, networks, and software. OT-related events: Events related to OT systems. Events in OT systems. Events related to the operation and monitoring of physical equipment such as factory equipment and sensors.
[0012] Embodiment 1. <Purdue Model 100> Figure 1 is a diagram representing the Purdue Model 100, which hierarchically organizes the network architecture of an industrial control system (ICS). The Purdue Model 100 is a framework for managing the architecture of an industrial control system by dividing it into layers. The Purdue Model 100 is used to strengthen security measures at each layer and to effectively manage risks. The Purdue Model 100 clarifies the boundary between IT systems and OT systems. The Purdue Model 100 is used for the following purposes: 1. Recognition of different security requirements between IT systems and OT systems 2. Implementation of appropriate countermeasures for IT systems and OT systems 3. Analysis of the scope of impact of cyberattacks on IT systems and OT systems
[0013] To clarify the difference between IT systems and OT systems, the Purdue model in Figure 1 will be explained. Level 105 (Level 0) includes devices that directly control the process, such as sensors and actuators. Level 104 (Level 1) includes controllers for controlling the process, such as PLCs (Programmable Logic Controllers). Level 103 (Level 2) includes systems that monitor and control the entire process, such as SCADA (Supervisory Control and Data Acquisition) or HMIs (Human Machine Interface).
[0014] The boundary between Level 103 (Level 2) and Level 102 (Level 3) is the boundary between IT systems and OT systems. Level 102 (Level 3) includes MES (Manufacturing Execution System) for managing and optimizing the operation of manufacturing processes. Level 102 (Level 3) also includes Historian, etc., for managing data collected from sensors or control systems. Levels 101 (Levels 4 & 5) include IT systems, etc., for business activities.
[0015] The Purdue Model 100 distinguishes between IT systems (layers 101 and 102) and OT systems (layers 103, 104, and 105). The security measures required for IT systems and OT systems, as well as the impact of cyberattacks on IT and OT systems, will differ.
[0016] <Target System 200> Figure 2 shows the target system 200 to be evaluated for vulnerability. Figure 2 shows a system that mimics a control system. The target system 200 in this disclosure is not limited to a control system like the one in Figure 2, but may be other systems. In this disclosure, vulnerability severity is evaluated considering the damage to the OT system. For this reason, Figure 2 mainly shows the part corresponding to the OT system in Figure 1.
[0017] Figure 2 shows the following nine devices present in the target system 200. The monitoring and control device 201 is a terminal device for monitoring and controlling the system. The controller 202 receives data from various sensors under its control and generates commands for various actuators under its control based on this data. By generating commands, the controller 202 realizes the functions necessary for the purpose of the target system 200. The controller 203 controls the robot controller 204 connected under it. The robot controller 204 controls the robot 205 connected under it. By controlling the robot 205, the robot controller 204 realizes the functions necessary for the purpose of the target system 200.
[0018] <Configuration of the vulnerability assessment device 300> Figure 3 is a diagram showing the configuration of the vulnerability assessment device 300 according to Embodiment 1 of this disclosure.
[0019] The vulnerability assessment device 300 has a system information acquisition unit 302 that acquires system information 311 relating to a target system 200 having an IT (Information Technology) system and an OT (Operational Technology) system. The vulnerability assessment device 300 has a vulnerability / attack information acquisition unit 303 that acquires vulnerability information 312 and attack information 313 relating to the target system 200. The vulnerability assessment device 300 has an IT system impact assessment unit 304 that evaluates the impact of cyberattacks on the IT system based on the vulnerability information 312 and attack information 313 and stores the evaluation results as IT system impact information 314 in the information storage unit 310. The vulnerability assessment device 300 has an OT system damage evaluation unit 305 that evaluates OT system events occurring in the OT system and the damage caused by OT system events and stores the evaluation results as OT system damage information 315 in the information storage unit 310. The vulnerability assessment device 300 has an event matching unit 306 that associates IT events in IT impact information 314 with OT events in OT damage information 315. The vulnerability assessment device 300 has an OT severity assessment unit 307 that evaluates the severity of vulnerabilities considering damage to the OT system based on the results of the IT impact assessment unit, the OT damage assessment unit, and the event matching unit. The vulnerability assessment device 300 realizes the following functions with the processor 10 and the information storage unit 310.
[0020] ***Operation of the vulnerability assessment device 300*** <Interface unit 301> The interface unit 301 performs data input / output with the outside of the vulnerability assessment device 300 using a communication device such as a network interface card or an input device such as a keyboard.
[0021] <System Information Acquisition Unit 302> The system information acquisition unit 302 acquires information about the target system 200 that is the subject of vulnerability severity assessment. The system information acquisition unit 302 acquires information about the target system 200 using the interface unit 301. The system information acquisition unit 302 stores the acquired information as system information 311 in the information storage unit 310.
[0022] System information 311 includes the following: 1. Model numbers of the equipment constituting the system 2. Firmware and software included in the equipment constituting the system, and their version information 3. Network connection relationships between the equipment constituting the system 4. Access control information between the equipment constituting the system 5. Information on the information asset value of the data present in the system 6. Data flowing through the network of the target system 200 during system operation
[0023] A good example of information asset value is the following three elements of information security: 1. C (Confidentiality) 2. I (Integrity) 3. A (Availability) Information asset value indicates the value of data using these three elements as indicators. For example, a high information asset value in C means that the information is highly confidential and the damage in the event of a leak would be significant.
[0024] The system information acquisition unit 302 can acquire the following by using the interface unit 301: 1. General information about the devices constituting the target system 200 from the internet; 2. Firmware update information included in the devices; 3. Information about the target system 200 entered from the keyboard; 4. Data flowing through the network of the target system 200 during the operation of the target system 200.
[0025] <Vulnerability / Attack Information Acquisition Unit 303> The vulnerability / attack information acquisition unit 303 acquires vulnerability information and attack information related to the target system 200. The vulnerability / attack information acquisition unit 303 stores the acquired information in the information storage unit 310 as vulnerability information 312 and attack information 313. As shown in Figure 4(a), the vulnerability / attack information acquisition unit 303 stores the vulnerability information 312 in a way that identifies the equipment of the target system 200 and the vulnerability corresponding to that equipment. As shown in Figure 4(b), the vulnerability / attack information acquisition unit 303 stores the attack information 313 in a way that identifies the equipment of the target system 200 and the attack information corresponding to that equipment.
[0026] Generally, multiple vulnerabilities exist for each device, so vulnerability information will list multiple vulnerabilities for each device. Similarly, since multiple attack reports exist for each device, attack reports will list multiple attack reports for each device.
[0027] Vulnerability information refers to information about security flaws present in a specific version of firmware or a specific version of software included in a device. Vulnerability information is distributed in a standardized format with a unique identifier called CVE (Common Vulnerabilities and Exposures) and can be obtained from the CVE information provider. The vulnerability / attack information acquisition unit 303 obtains vulnerability information for the device from the provider and stores it as vulnerability information 312.
[0028] Attack information refers to information about cyberattacks. A cyberattack is an act in which an attacker exploits vulnerabilities in a system or network to gain unauthorized access, steal data, destroy data, tamper with data, or disrupt services. Attack information can be obtained from reports published by security vendors, security community forums, or academic papers. Attack information can also be obtained from MITRE Corporation's ATT&CK (registered trademark: Advanced Tactics, Techniques, and Common Knowledge). ATT&CK is a knowledge base that systematically organizes cyberattack methods, tactics, and techniques. The vulnerability / attack information acquisition unit 303 obtains attack information against the device from the provider and stores it as attack information 313.
[0029] The vulnerability assessment device 300 combines vulnerability information 312 and attack information 313 to evaluate what kinds of attacks could occur by exploiting vulnerabilities in the system, and what kind of impact those attacks would have. The vulnerability assessment device 300 performs a severity assessment based on the damage each of the multiple vulnerabilities would inflict on the OT system. Finally, the vulnerability assessment device 300 prioritizes the multiple vulnerabilities. The vulnerability assessment device 300 prioritizes the vulnerabilities using the IT impact assessment unit 304, the OT damage assessment unit 305, the event response unit 306, and the OT severity assessment unit 307, as described below.
[0030] <IT Impact Assessment Unit 304> The IT Impact Assessment Unit 304 assesses the impact of a cyberattack on the IT system. The IT Impact Assessment Unit 304 assesses events (IT events) that occur in the IT system due to vulnerabilities in the target system and the impact of those IT events. The IT Impact Assessment Unit 304 stores the assessment results as IT impact information 314 in the information storage unit 310. The IT impact information 314 will be described later.
[0031] The IT impact assessment unit 304 uses the system information 311, vulnerability information 312, and attack information 313 to evaluate the following: 1. How can the vulnerabilities in the target system 200 be exploited? 2. What kind of cyberattacks may occur as a result of the exploitation? 3. If a cyberattack actually occurs, what impact will it have on the IT system?
[0032] The impact on IT systems is evaluated based on the events that occur within the IT system (IT-related events) and their degree of impact. Events that occur within the IT system include unauthorized access to the system, data leakage, and service interruptions.
[0033] <OT System Damage Assessment Unit 305> The OT system damage assessment unit 305 assesses events (OT system events) that occur in the OT system and the resulting damages. The OT system damage assessment unit 305 stores the assessment results as OT system damage information 315 in the information storage unit 310. The OT system damage information 315 will be described later.
[0034] Events occurring in OT systems (OT-related events) include production stoppages, quality degradation, safety risks, infrastructure downtime, and economic losses. The causes of these events can be analyzed using failure analysis methods such as FTA (Fault Tree Analysis) or FMEA (Failure Mode and Effect Analysis). FTA and FMEA are methods for analyzing events occurring in OT systems. FTA is a top-down method that analyzes the causes of major failures and accidents in a tree structure. FMEA is a bottom-up method that identifies how components and processes fail and evaluates their impact on the entire system. Both methods can analyze the causal relationships between events leading up to the final failure or accident, although the final failure or accident must be defined by the analyst.
[0035] <Event Response Unit 306> The event response unit 306 associates events in the IT system with events in the OT system. The event response unit 306 stores the association information as event response information 316 in the information storage unit 310. In some cases, the correspondence or causal relationship between events in the IT system and events in the OT system is relatively easy to understand, such as a service stoppage being an event in the IT system and a production stoppage being an event in the OT system. However, basically, it is necessary to clarify the relationship by analyzing the correspondence or causal relationship between events.
[0036] <OT Severity Assessment Unit 307> The OT Severity Assessment Unit 307 evaluates the severity of the vulnerability, taking into account the damage to the OT system, based on the IT impact information 314, the OT damage information 315, and the event response information 316. The OT Severity Assessment Unit 307 stores the evaluation results as OT severity information 317 in the information storage unit 310.
[0037] <IT Impact Information 314> Figure 5(a) is a diagram of IT Impact Information 314. IT Impact Information 314 lists the following items in a table format for each device: 1. Vulnerability: Vulnerability to the device. Vulnerability possessed by the device. 2. IT Event: IT event that may occur due to a cyberattack exploiting that vulnerability. 3. Probability: The probability of that IT event occurring. 4. Impact: The impact when that IT event occurs.
[0038] In the IT impact information 314 in Figure 5(a), it is shown that device A has vulnerability 1, there is a high probability that IT event 1 will occur, and the impact will be significant if IT event 1 occurs.
[0039] The IT impact assessment unit 304 registers each item of the IT impact information 314 as follows: 1. Vulnerability: Information about the vulnerability stored as vulnerability information 312 2. IT event: An IT event that occurs as a result of exploiting the vulnerability 3. Probability: The probability of a security threat occurring as evaluated by the security risk analysis 4. Impact: The risk value of the security threat as evaluated by the security risk analysis
[0040] <Evaluation of Impact by IT Impact Assessment Unit 304> The IT Impact Assessment Unit 304 identifies potential security threats to the system through security risk analysis and evaluates the impact (risk value) caused by them. Preferably, the risk value is evaluated by multiplying the probability of the threat occurring by the value of the information asset that is the target of the threat. The IT Impact Assessment Unit 304 calculates the risk value by multiplying the probability of occurrence stored in the IT impact information 314 by the value of the information asset stored in the system information 311. Since the value of the information asset can be interpreted as the magnitude of the impact when a threat actually occurs against it, the result of multiplying the value of the information asset by the probability of the threat occurring indicates the magnitude of the impact (expected value) caused by the threat.
[0041] Assume that the IT-related event 1 of device A in the IT-related impact information 314 of FIG. 5(a is data leakage, and device A contains data with high information asset value that is the target of data leakage. Due to the high information asset value, the impact is large if the data is leaked. However, if the possibility of data leakage from device A is low, the expected value of the impact is considered not large. However, since the possibility of occurrence of the IT-related event 1 (data leakage) of device A in FIG. 5(a is high, the expected value of the impact is considered large. As described above, the impact on device A is represented by the multiplication result (large) of occurrence possibility (large) and information asset value (high = large).
[0042] It should be noted that multiplication is performed here for non-numerical values, and the meaning thereof can be interpreted according to general common sense, for example, large×large=large, large×small=medium, small×small=small, etc. It is also conceivable to quantify occurrence possibility and information asset value as integers and perform actual multiplication. The same applies to the following description.
[0043] <Evaluation of Occurrence Possibility by IT-related Impact Assessment Unit 304> Security risk analysis is performed at the design or planning stage, which is an upstream process of product development. Therefore, the occurrence possibility evaluated in the upstream process is based on general knowledge or past knowledge. Initially, the IT-related impact assessment unit 304 uses occurrence possibility based on general knowledge or past knowledge. In contrast, the vulnerability / attack information acquisition unit 303 acquires the latest vulnerability information 312 and the latest attack information 313 at the time when the target system 200 is in operation. By acquiring the latest information, the IT-related impact assessment unit 304 can evaluate the occurrence possibility in consideration of the latest situation related to the system.
[0044] The IT-related impact assessment unit 304 identifies actual known vulnerabilities regarding the target system 200. Furthermore, the IT-related impact assessment unit 304 can combine attack methods that can be implemented by exploiting these actual vulnerabilities. As a result, the IT-related impact assessment unit 304 can analyze how an attacker can actually attack the system.
[0045] Furthermore, among publicly available vulnerability information or attack information, there may be cases where demonstration code called PoC (Proof of Concept) is included to show that it is possible to actually exploit the vulnerability for an attack. In such a case, an attacker can be determined to be able to exploit the vulnerability relatively easily. Through the above analysis, the IT impact assessment unit 304 can assess the occurrence probability in consideration of the latest situation.
[0046] <OT System Damage Information 315> FIG. 5(b) shows the OT system damage information 315. The OT system damage information 315 describes the following for each device in a table format. 1. OT events related to the device 2. Damage when the OT event occurs 3. Cause of the OT event
[0047] In the OT system damage information 315 of FIG. 5(b), it is indicated that the device B is related to the OT event 3, the damage is large when the OT event 3 occurs, and the cause of the OT event 3 is the cause 3.
[0048] <Damage Assessment by OT System Damage Assessment Unit 305> The OT system damage assessment unit 305 registers OT events that may occur in devices regardless of the presence or absence of a vulnerability and the presence or absence of an attack. That is, the OT system damage assessment unit 305 identifies possible OT events that may occur to the device and registers them in the OT system damage information 315.
[0049] The OT system damage assessment unit 305 registers, in the OT system damage information 315, damage that does not include the contribution of the occurrence probability of the OT event. That is, the damage in the OT system damage information 315 does not include the contribution of the occurrence probability of the OT event. The damage does not represent an expected value that also considers occurrence probability, but indicates the magnitude of damage when an OT event actually occurs. In the OT system damage information 315 of FIG. 5(b), assuming that the OT event 3 is production stoppage, the OT system damage assessment unit 305 considers that the damage will be large when production stoppage actually occurs, and enters "large" in the damage column.
[0050] If, as with IT-related impact information 314, the probability of occurrence of OT-related events can be assessed, then the damage can be described as an expected value that takes the probability of occurrence into account. For example, if the probability of OT-related event 3 being assessed as low, then even if OT-related event 3 results in a production stoppage, the expected value of the damage can be assessed as moderate. However, the method for identifying OT-related events cannot assess the probability of damage occurring. Therefore, the damage in OT-related damage information 315 is the magnitude of the damage that would occur if the OT-related event actually occurred.
[0051] <Evaluation of the cause by the OT-system damage assessment unit 305> The OT-system damage assessment unit 305 identifies the cause as follows:
[0052] In the OT-related damage information 315, the causes of OT-related events are briefly indicated as Causes 1 to 5. However, in reality, there are often multiple causes for a given OT-related event. These causes, in turn, are linked by other causes, creating a chain of causal relationships. The OT-related damage assessment unit 305 analyzes such chains of causal relationships and identifies the root cause that cannot be traced further. This allows for the implementation of effective measures to prevent OT-related events.
[0053] <Causes of OT System Events> Figure 6 is a diagram showing the cause information of OT system events. The cause information is stored in the information storage unit 310. The OT system damage assessment unit 305 analyzes the cause information, identifies the cause, and registers it in the OT system damage information 315. Figure 6 schematically represents a failure tree, which is the result of analysis by FTA, as a suitable example of cause analysis by the OT system damage assessment unit 305. The production stoppage, which is the OT system event being analyzed, is at the top, and the sequence of causes is analyzed. Each node that makes up the tree represents an event. Another node connected below a certain node indicates an event that caused the former. In Figure 6, the machine failure connected below the production stoppage indicates that the machine failure was the cause of the production stoppage. The sensor failure connected below the machine failure indicates that the sensor failure was the cause of the machine failure. Also, in Figure 6, the fact that multiple nodes are connected below a certain node indicates that there are multiple events that caused the former. In Figure 6, there are four events that cause production stoppages: machine failure, raw material shortage, human factors, and external factors. Furthermore, by connecting multiple nodes with AND or OR, it is possible to express that all causes are true in the case of AND, and that at least one of the causes is true in the case of OR.
[0054] The OT-system damage assessment unit 305 may set information corresponding to the entire tree in Figure 6 as each cause in Figure 5(b), or it may set information corresponding to one node in Figure 6, or it may set information corresponding to multiple nodes in Figure 6.
[0055] Along with the tree at the top of production stoppage, trees at the top of quality decline, safety risks, infrastructure disruption, and economic losses are also stored as cause information for OT-related events. The OT-related damage assessment unit 305 analyzes the trees corresponding to OT-related events to identify the causes.
[0056] <Event Response Unit 306> The event response unit 306 associates IT events in the IT impact information 314 with OT events in the OT damage information 315. The event response unit 306 associates IT events with OT events by using at least one of the matching methods described below.
[0057] <Matching based on the cause of OT-related events> Figure 7 will be used to explain the matching based on the cause of OT-related events. The event response unit 306 obtains IT-related events from IT-related impact information 314 and obtains the cause of OT-related events from OT-related damage information 315. The event response unit 306 uses system information 311 as necessary to match the IT-related events with the causes of OT-related events and outputs this as event response information 316.
[0058] In Figure 7, the event response unit 306 identifies that the supply delay and inventory management error, which are the causes of the production stoppage in the OT (Operational Technology) event, are due to data tampering, which is an IT (Information Technology) event caused by a cyberattack. In other words, the event response unit 306 identifies that the supply delay or inventory management error occurs because data related to supply or inventory management is tampered with. This reveals that the production stoppage, which is an OT event, is caused by a cyberattack. The causes of the IT and OT events shown in Figure 7 are just examples, and the operation of the event response unit 306 is not limited to these. In addition, some causes of OT events, such as power outages or natural disasters, are unrelated to cyberattacks. For causes unrelated to cyberattacks, the event response unit 306's matching results show that there is no correspondence with the IT event.
[0059] As shown in Figure 7, some correspondences are clear, such as the relationship between an IT-related event (illegal operation) and an OT-related event (illegal operation, intentional operation). However, usually, the correspondence is not so clear.
[0060] <Matching by Intermediate Factors> Figure 8 shows an example of a matching method. The event response unit 306 obtains IT-related events from IT-related impact information 314 and obtains the causes of OT-related events from OT-related damage information 315. Data falsification, which is an IT-related event, and supply delays or inventory management errors, which are the causes of OT-related events, are not directly linked. However, it is possible to identify the existence of an element that lies between them and connects them. Therefore, the event response unit 306 matches IT-related events and OT-related events by identifying intermediate factors. An intermediate factor is a factor that lies between IT-related events and OT-related events and on which OT-related events depend. Here, the following two intermediate factors are described: 1. Supply schedule 2. Inventory management data
[0061] The event response unit 306 uses the system information 311 to identify dependencies between functions or data in the target system 200. In the example in Figure 8, the event response unit 306 uses the system information 311 to identify that the supply of raw materials depends on the supply schedule, and that the inventory management of raw materials depends on inventory management data. On the other hand, it can be deduced from general knowledge that data tampering, an IT-related event, can occur with respect to data in the system. Thus, the event response unit 306 derives that data tampering, an IT-related event, can occur with respect to the supply schedule or inventory management data, and that this can result in supply delays or inventory management errors. By identifying these intermediate factors, the event response unit 306 can link the causes of the IT-related events identified in the IT-related impact information 314 with the causes of the OT-related events identified in the OT-related damage information 315.
[0062] <Matching by Event Response DB 901> Figure 9 shows another example of the matching method of the event response unit 306. In this example, the correspondence between IT events and OT events is created in advance as the event response DB (database) 901. The event response DB 901 has the correspondence registered based on past cases, etc.
[0063] In Figure 9, the following correspondences are registered in the event correspondence DB 901: 1. When data tampering, an IT-related event, occurs, quality degradation, an OT-related event, occurs. 2. When unauthorized operation, an IT-related event, occurs, production stoppage, an OT-related event, occurs. 3. When data leakage, an IT-related event, occurs, economic loss, an OT-related event, occurs.
[0064] The event response unit 306 acquires IT-related events from the IT-related impact information 314 and OT-related events from the OT-related damage information 315. Based on the event response DB 901, the event response unit 306 directly links the IT-related events identified in the IT-related impact information 314 with the OT-related events identified in the OT-related damage information 315.
[0065] <Matching by Inference> In the example in Figure 9, a method of directly matching IT events and OT events is shown, but in reality, it may be difficult to pre-register specific events that are unique to individual systems.
[0066] Figure 10 shows another example of the mapping method used by the event response unit 306. The event response unit 306 acquires IT-related events from the IT-related impact information 314 and OT-related events from the OT-related damage information 315. Although Figure 10 shows the system information 311 and the IT-related event knowledge base 1001, it is possible to use both, only one, or neither.
[0067] *Inference using IT-related event knowledge base 1001* Compared to the event response DB 901 in Figure 9, the IT-related event knowledge base 1001 stores a more general knowledge base. The IT-related event knowledge base 1001 registers the following knowledge as general knowledge that can be assumed regarding IT-related events: 1. Data tampering affects data integrity. 2. Unauthorized operation affects system availability. 3. Data leakage affects confidentiality.
[0068] As an example of the reasoning method of the event response unit 306, AI (Artificial Intelligence) technologies such as machine learning, deep learning, or LLM (Large Language Model) can be used. For an OT (Operational Technology) event such as a production stoppage, the event response unit 306 uses an LLM-based dialogue system to ask which of the following affects the production stoppage: integrity, availability, or confidentiality. From the answers to the questions, the event response unit 306 learns that the production stoppage is affected by availability. On the other hand, the event response unit 306 learns from the IT event knowledge base 1001 that unauthorized operation affects availability. From these, it can infer the correspondence between the unauthorized operation and the production stoppage.
[0069] *Inference using AI technology alone* The event response unit 306 may perform inference using only the LLM without using the IT event knowledge base 1001. The event response unit 306 inputs a list of IT events such as data falsification and unauthorized operations, and a list of OT events such as production stoppages and quality degradation, into an LLM-based dialogue system. The event response unit 306 requests the LLM to output the correspondence between the lists. The LLM responds with the correspondence between the IT events and the OT events. In this way, the event response unit 306 establishes the association between the IT events and the OT events. This method is considered quite practical because the LLM is expected to acquire a wider range of knowledge in the future.
[0070] *Inference using system information 311* The event response unit 306 can perform inference using only system information 311 in the following way. System information 311 includes the system information of the target system 200 in Figure 2. The event response unit 306 uses this system information 311 to infer the following correspondence.
[0071] 1. Inference of the correspondence between unauthorized controller operation and production stoppage The event response unit 306 learns from the system information 311 that a large number of sensors and actuators are connected to the controller 202. From the information that a large number of sensors and actuators are connected, and the information on the specific number of them, the event response unit 306 infers that that part is a production line. The event response unit 306 also infers that if that part stops, it will lead to a production stoppage. As a result, the event response unit 306 infers that unauthorized operation of the controller 202 will lead to a production stoppage.
[0072] 2. Inference of the correspondence between robot malfunction and safety risks The event response unit 306 learns from the system information 311 that the robot controller 204 is connected to the controller 203, and the robot 205 is connected to the robot controller 204. From this, the event response unit 306 infers the correspondence that a malfunction of the robot 205 will lead to a safety risk.
[0073] 3. Correspondence between data tampering with the controller and safety risks The event response unit 306 also infers the correspondence between data tampering with the robot controller 204 that controls the robot 205, or data tampering with the controller 203 that controls the robot controller 204, and safety risks. The event response unit 306 may perform the above inferences independently, or it may perform them using AI technology such as LLM.
[0074] <Model Retraining> When using LLM, it is possible to retrain the model by inputting knowledge that the LLM has not yet acquired, as well as specific knowledge about the system and domain. One method is to retrain the model first and then perform inference. However, since it is difficult to know the scope of knowledge that the model possesses in advance, it is also possible to retrain the model as needed during inference. In the inference method using the LLM described above, if the LLM does not provide an appropriate inference result, the event response unit 306 has a human perform the inference and uses that knowledge to retrain the model. By retraining, the LLM will be able to perform appropriate inference from the next time onward.
[0075] Furthermore, the correspondence method shown in Figure 8, when generalized, has a similar structure to that shown in Figure 10, and it is possible to derive the correspondence shown in Figure 8 using AI technology.
[0076] <Reverse Lookup Method> The event response unit 306 may perform a reverse lookup method in its correspondence inference, in which it infers the IT-related event that is the cause of the resulting OT-related event. The reverse lookup method is important for the following reasons: It is important to prioritize vulnerability countermeasures by considering the damage that may actually occur in the OT system. For this reason, the relationship between OT-related events and IT-related events is such that OT-related events are primary and IT-related events are secondary. Specifically, OT-related event 2 identified in the OT-related damage information 315 shown in Figure 5(b) is evaluated as having minor damage. Because the damage is minor, it may be judged that even if this OT-related event 2 occurs, it will not cause a problem, and therefore, there is no need to address the vulnerability that would cause it. As a result, the event response unit 306 omits the process of correspondence between OT-related event 2 and IT-related events.
[0077] Conversely, in the method of inferring correspondence from the IT-related events, it is only after the inference is performed that it becomes clear that IT-related event 2 corresponds to OT-related event 2, and only after this is understood that there is no need to address vulnerability 2, which is linked to IT-related event 2. In other words, because the correspondence between IT-related event 2 and OT-related event 2 is not known until the inference is made, it results in the inference of unnecessary results that do not require any action.
[0078] <OT Severity Information 317> Figure 11 shows the OT severity information 317 stored in the information storage unit 310. The OT severity information 317 shown in Figure 11 is formally a combination of the IT impact information 314 and the OT damage information 315 shown in Figure 5. The OT severity information 317 indicates that device A has vulnerability 1, and that an attack exploiting this vulnerability could cause IT event 1, and that IT event 1 is the cause of OT event 1. The damage caused by OT event 1 is moderate, and the probability of the IT event 1 causing it occurring is high, so the overall severity is moderate. Possible methods for evaluating severity include multiplying the probability of occurrence by the damage.
[0079] For the sake of explanation, the equipment in the IT impact information 314 and OT damage information 315 in Figure 5 is assumed to be common, and the OT severity information 317 in Figure 11 is simply a combination of the items corresponding to each common equipment. However, in reality, it is not such a simple combination. In reality, the event response unit 306 performs event mapping processing, and by using the results, the event response unit 306 maps the IT impact information 314 and OT damage information 315 to create the OT severity information 317. The OT severity information 317 in Figure 11 is a table created when the event response unit 306 maps the causes 1 to 5 of the OT events with the same number to IT events 1 to 5, respectively.
[0080] ***Features of the Vulnerability Assessment Device 300*** The features of the vulnerability assessment device 300 are described below.
[0081] The vulnerability assessment device 300 evaluates the vulnerabilities of a target system 200 that has an IT (Information Technology) system and an OT (Operational Technology) system. The vulnerability assessment device 300 comprises an information storage unit 310, an event response unit 306, and an OT system severity assessment unit 307.
[0082] The information storage unit 310 stores IT impact information 314, which includes IT events that occur in the IT system based on vulnerabilities in the target system 200 and the effects of those IT events. The information storage unit 310 also stores OT damage information 315, which includes OT events that occur in the OT system and the damage caused by those OT events.
[0083] The event response unit 306 associates IT-related events with OT-related events to create event response information 316. Based on the association of the event response information 316, the OT severity evaluation unit 307 determines the severity of the vulnerability from the impact of the IT-related event and the damage caused by the OT-related event, and stores the OT severity information 317, including the severity, in the information storage unit 310.
[0084] The OT system damage assessment unit 305 evaluates the actual damage caused by an OT system event, rather than damage that considers the probability of the OT system event occurring. The OT system damage assessment unit 305 stores OT system damage information 315, which includes OT system events occurring in the OT system and the actual damage caused by the OT system event, in the information storage unit 310.
[0085] The IT impact assessment unit 304 evaluates the likelihood of an IT event occurring as an impact of an IT event, and stores IT impact information 314, which includes the IT event and the likelihood of it occurring, in the information storage unit 310.
[0086] The OT (Operational Technology) Severity Assessment Unit 307 uses the actual damage caused by OT events as the damage caused by OT events. The OT Severity Assessment Unit 307 uses the probability of occurrence of IT events as the impact of IT events. When assessing severity, the OT Severity Assessment Unit 307 uses the probability of occurrence of IT events and the actual damage caused by OT events.
[0087] The event response unit 306 associates IT-related events with OT-related events by utilizing the causes of OT-related events.
[0088] The event response unit 306 associates IT events with OT events by identifying intermediate factors between IT events and OT events. The event response unit 306 associates IT events with OT events by utilizing the event response DB 901, in which the correspondence between IT events and OT events is pre-registered. The event response unit 306 associates IT events with OT events by utilizing the event knowledge base 1001, in which knowledge about IT events is registered.
[0089] The event response unit 306 infers an IT-related event that corresponds to an OT-related event from an OT-related event.
[0090] The event response unit 306 omits the correspondence between IT-related events and OT-related events based on the damage caused by OT-related events.
[0091] The event response unit 306 uses AI technology to associate IT-related events with OT-related events.
[0092] If the AI-based matching fails, the event response unit 306 requests a human to perform the matching and uses the results of the human matching to retrain the AI model.
[0093] Figure 12 is a flowchart of a vulnerability assessment method according to Embodiment 1 of the present disclosure. In step S1201, the system information acquisition unit 302 acquires system information 311 relating to the target system 200 using the interface unit 301. In step S1202, the vulnerability / attack information acquisition unit 303 acquires vulnerability information 312 and attack information 313 relating to the target system 200 for which vulnerability severity assessment is performed.
[0094] In step S1203, the IT impact assessment unit 304 assesses the impact of a cyberattack on the IT system. In step S1204, the OT damage assessment unit 305 assesses events occurring in the OT system and the resulting damage.
[0095] In step S1205, the event response unit 306 associates the event in the IT system with the event in the OT system. In step S1206, the OT system severity evaluation unit 307 evaluates the severity of the vulnerability, taking into account the damage to the OT system, based on the evaluation results of the IT system impact evaluation unit 304, the evaluation results of the OT system damage evaluation unit 305, and the correspondence relationship derived by the event response unit 306.
[0096] The following describes the characteristics of the vulnerability assessment method.
[0097] Vulnerability assessment methods utilize the likelihood of events occurring in IT systems to perform vulnerability assessments.
[0098] Vulnerability assessment methods, when mapping events in IT systems and events in OT systems, map events that do not directly correspond to each other by identifying intermediate factors between them.
[0099] In vulnerability assessment methods, when associating events in IT systems with events in OT systems, the IT system event is determined by looking up the OT system event.
[0100] In the vulnerability assessment method, if an event in the OT system meets the prescribed criteria, the mapping process is omitted.
[0101] The vulnerability assessment method utilizes AI technologies such as LLM to correlate events in IT systems with events in OT systems.
[0102] In the vulnerability assessment method, if the mapping by AI technology such as LLM fails, a human will perform an appropriate mapping instead, and the model in the AI technology such as LLM will be retrained using the results of the appropriate mapping.
[0103] The vulnerability assessment method evaluates the severity of vulnerabilities, taking into account the damage to the OT system, by utilizing the magnitude of the damage to the OT system and the likelihood of the IT system event that causes the damage to the OT system occurring.
[0104] Vulnerability assessment methods involve mapping IT-related events that may occur as a result of cyberattacks exploiting vulnerabilities with OT-related events that may occur as damage to OT systems.
[0105] Vulnerability assessment methods allow for the evaluation of vulnerability severity by considering the potential damage to OT systems. Furthermore, these methods enable the prioritization of vulnerability responses appropriate to the OT system.
[0106] Figure 13 is a hardware configuration diagram of the vulnerability assessment device 300.
[0107] The vulnerability assessment device 300 comprises a processor 10. The vulnerability assessment device 300 comprises a memory 20 and a storage device 30 for recording data. The vulnerability assessment device 300 comprises an output interface 40 and an input interface 50. The vulnerability assessment device 300 comprises a timing calendar 60 for obtaining the date and time. The vulnerability assessment device 300 comprises a communication interface 70. The vulnerability assessment device 300 comprises a bus 80 connecting the processor 10, memory 20, storage device 30, output interface 40, input interface 50, timing calendar 60, and communication interface 70.
[0108] The "part" in each of the interface unit 301, system information acquisition unit 302, vulnerability / attack information acquisition unit 303, IT impact assessment unit 304, OT damage assessment unit 305, event response unit 306, and OT severity assessment unit 307 may be read as "process," "procedure," or "step." Furthermore, the "process" in each of the parts may be read as "program," "program product," or "computer-readable recording medium containing a program." The vulnerability assessment program causes a computer to execute each process, procedure, or step, where the "part" in each part is read as "process," "procedure," or "step." The vulnerability assessment method is a method performed by executing the vulnerability assessment program. The vulnerability assessment program may be provided stored on a computer-readable non-volatile recording medium. The vulnerability assessment program may also be provided as a program product.
[0109] The functions of each part may be implemented by a single electronic circuit, or they may be implemented by distributing them across multiple electronic circuits. Furthermore, some of the functions of each part may be implemented by electronic circuits, while the remaining functions are implemented by software. Also, some or all of the functions of each part may be implemented by firmware.
[0110] Both the processor and the electronic circuit are also called processing circuits. In other words, the function of each device is realized by the processing circuits.
[0111] ***Effects of the Embodiment*** The vulnerability assessment device 300 can assess the severity of vulnerabilities in each device in the target system 200 and prioritize which vulnerabilities should be addressed based on that assessment. Therefore, the vulnerability assessment device 300 can continuously and appropriately address vulnerabilities.
[0112] The events and effects evaluated in Japanese Patent Publication No. 2024-035327 are those related to the processing, storage, transmission, and management of information. In other words, they are events and effects in IT systems. The disclosure in Japanese Patent Publication No. 2024-035327 cannot evaluate damages that may occur in OT systems. On the other hand, the vulnerability assessment device 300 can evaluate events and damages related to the monitoring and control of physical processes and machines in OT systems. The vulnerability assessment device 300 can perform vulnerability assessments even when the possibility of damage to the OT system is unknown. The vulnerability assessment device 300 can perform vulnerability assessments while considering actual damage to the OT system.
[0113] There are methods for defining damage that occurs in OT systems and analyzing the causal relationships between events leading to that damage. However, these methods cannot link the events that can be identified with events in IT systems caused by cyberattacks. The vulnerability assessment device 300 makes a final priority decision by considering the different damages for each piece of equipment in the OT system, while referring to the evaluation results of events and impacts that occur in the IT system. The vulnerability assessment device 300 can perform a vulnerability severity assessment that takes into account the damage that occurs in the OT system corresponding to events and impacts that occur in the IT system.
[0114] The vulnerability assessment device 300 performs a severity assessment for each device present in the OT system, making it possible to take individual countermeasures for each device.
[0115] Embodiment 2. This embodiment will describe the differences from Embodiment 1. In this embodiment, components similar to those in Embodiment 1 are denoted by the same reference numerals, and their descriptions are omitted.
[0116] Figure 14 is a configuration diagram of a vulnerability assessment device 300 according to Embodiment 2. Figure 14 is the same as the vulnerability assessment device 300 in Figure 3, but with the interface unit 301, system information acquisition unit 302, and vulnerability / attack information acquisition unit 303 removed. In the vulnerability assessment device 300 of Figure 14, system information 311, vulnerability information 312, and attack information 313 are pre-stored in the information storage unit 310 by another system not shown. If the information is pre-stored in the information storage unit 310, the interface unit 301, system information acquisition unit 302, and vulnerability / attack information acquisition unit 303 may not be necessary.
[0117] Embodiment 3. This embodiment will describe the differences from Embodiment 1. In this embodiment, components similar to those in Embodiment 1 are denoted by the same reference numerals, and their descriptions are omitted.
[0118] Figure 15 is a configuration diagram of the vulnerability assessment device 300 according to Embodiment 3. Figure 15 is the same as the vulnerability assessment device 300 in Figure 14, but with the IT impact assessment unit 304, OT damage assessment unit 305, vulnerability information 312, and attack information 313 removed. In the vulnerability assessment device 300 of Figure 15, system information 311, IT impact information 314, and OT damage information 315 are pre-stored in the information storage unit 310 by another system not shown. If the information is pre-stored in the information storage unit 310, the IT impact assessment unit 304, OT damage assessment unit 305, vulnerability information 312, and attack information 313 may not be necessary.
[0119] Multiple parts of the above-described embodiments may be combined and implemented. Alternatively, only one part of these embodiments may be implemented. Furthermore, these embodiments may be combined and implemented in any way, either as a whole or in part.
[0120] 10 Processor, 20 Memory, 30 Storage device, 40 Output interface, 50 Input interface, 60 Timing calendar, 70 Communication interface, 80 Bus, 100 Purdue model, 200 Target system, 201 Monitoring and control equipment, 202 Controller, 203 Controller, 204 Robot controller, 205 Robot, 300 Vulnerability assessment device, 301 Interface unit, 302 System information acquisition unit, 303 Vulnerability / attack information acquisition unit, 304 IT impact assessment unit, 305 OT damage assessment unit, 306 Event response unit, 307 OT severity assessment unit, 310 Information storage unit, 311 System information, 312 Vulnerability information, 313 Attack information, 314 IT impact information, 315 OT damage information, 316 Event response information, 317 OT severity information, 901 Event correspondence database, 1001 IT-related event knowledge base.
Claims
1. A vulnerability assessment device for evaluating the vulnerability of a target system having an IT (Information Technology) system and an OT (Operational Technology) system, comprising: an information storage unit that stores IT-related impact information including IT-related events occurring in the IT system and the effects of the IT-related events, and OT-related damage information including OT-related events occurring in the OT system and the damage caused by the OT-related events, based on the vulnerability of the target system; an event response unit that creates event response information by associating the IT-related events with the OT-related events; and an OT-related severity assessment unit that determines the severity of the vulnerability from the effects of the IT-related events and the damage caused by the OT-related events based on the association of the event response information, and stores OT-related severity information including the severity in the information storage unit.
2. The vulnerability assessment device according to claim 1, further comprising an OT damage assessment unit that stores in the information storage unit OT damage information including OT events occurring in the OT system and actual damage caused by OT events, rather than damage considering the probability of the OT events occurring as damage caused by OT events.
3. The vulnerability assessment device according to claim 1 or 2, further comprising an IT impact assessment unit that evaluates the likelihood of the occurrence of the IT event and stores the IT impact information, including the IT event and the likelihood of occurrence caused by the IT event, in the information storage unit.
4. The vulnerability assessment device according to claim 3, wherein the OT system severity assessment unit uses the actual damage caused by the OT system event as damage caused by the OT system event, the OT system severity assessment unit uses the probability of occurrence of the IT system event as the impact of the IT system event, and the OT system severity assessment unit uses the probability of occurrence of the IT system event and the actual damage caused by the OT system event when evaluating the severity.
5. The vulnerability assessment device according to any one of claims 1 to 4, wherein the event response unit associates the IT event with the OT event by utilizing the cause of the OT event.
6. The vulnerability assessment device according to any one of claims 1 to 5, wherein the event response unit associates the IT event with the OT event by utilizing at least one of the following: an event response database in which intermediate factors between the IT event and the OT event and the correspondence between the IT event and the OT event are pre-registered, and an event knowledge base in which knowledge about the IT event is registered.
7. The vulnerability assessment device according to any one of claims 1 to 6, wherein the event response unit infers the IT event corresponding to the OT event from the OT event.
8. The vulnerability assessment device according to claim 7, wherein the event response unit omits the correspondence between the IT event and the OT event based on the damage caused by the OT event.
9. The vulnerability assessment device according to any one of claims 1 to 8, wherein the event response unit uses AI (Artificial Intelligence) technology to associate the IT-related events with the OT-related events.
10. The vulnerability assessment device according to claim 9, wherein if the matching by the AI technology fails, the event response unit requests matching by a human and retrains the model in the AI technology using the results of the matching by the human.
11. A vulnerability assessment method for a vulnerability assessment device that assesses the vulnerability of a target system having an IT (Information Technology) system and an OT (Operational Technology) system, wherein the device stores in an information storage unit IT impact information including IT events occurring in the IT system and the effects of the IT events, and OT damage information including OT events occurring in the OT system and the damage caused by the OT events, based on the vulnerability of the target system; an event response unit creates event response information by associating the IT events and the OT events; and an OT severity assessment unit determines the severity of the vulnerability from the effects of the IT events and the damage caused by the OT events based on the association of the event response information, and stores OT severity information including the severity in the information storage unit.
12. A vulnerability assessment program that causes a computer to evaluate the vulnerability of a target system having an IT (Information Technology) system and an OT (Operational Technology) system to execute the following: information storage processing, which stores in an information storage unit IT-related impact information, which includes IT-related events occurring in the IT system and the effects caused by the IT-related events, and OT-related damage information, which includes OT-related events occurring in the OT system and the damage caused by the OT-related events, based on the vulnerability of the target system; event response processing, which creates event response information by associating the IT-related events with the OT-related events; and OT-related severity evaluation processing, which determines the severity of the vulnerability from the effects caused by the IT-related events and the damage caused by the OT-related events, based on the association of the event response information, and stores OT-related severity information, including the severity, in the information storage unit.