Information Processing Device for Control System Anomaly Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In control systems, operators face challenges in promptly determining the cause and expected consequences of anomalies detected by monitoring devices, relying heavily on their knowledge and experience, which can lead to incorrect risk assessments and delayed actions.
Innovation Solution
An information processing device that receives anomalies from monitoring devices, uses collating and extraction conditions to identify matching attack procedures, and presents the causes and consequences to operators, thereby automating the risk determination process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If operators manually determine causes and consequences of anomalies based on their knowledge and experience, then flexibility and adaptability are maintained, but the determination time increases and accuracy decreases
Solution Approach 1:
The patent introduces an information processing device as an intermediary between the monitoring device and the operator. This device automatically determines causes and consequences by collating anomaly information with attack procedure information, acting as a mediator that reduces the operator's cognitive burden while maintaining accurate risk assessment
Solution Approach 2:
The system performs preliminary action by pre-storing attack procedure information that includes various attack patterns, their causes, and consequences. When an anomaly occurs, the system quickly matches it against this pre-prepared information base, eliminating the need for operators to manually analyze from scratch
2Reliability
If operators rely on their knowledge and experience to estimate causes and consequences, then subjective judgment is applied, but incorrect determinations and delayed actions occur
Solution Approach 1:
The patent creates a virtual copy of attack procedure knowledge by storing structured attack procedure information in the information processing device. This copied knowledge base allows the system to objectively compare anomalies against known attack patterns, reducing reliance on individual operator expertise while improving consistency and reliability
Solution Approach 2:
The system implements feedback by presenting the determined causes and consequences back to the operator for verification. This feedback loop allows the operator to review the automated determination and make corrections if necessary, improving reliability while maintaining system support
3Measurement precision
If comprehensive attack procedure information is analyzed to determine risks, then accuracy improves, but information processing complexity increases
Solution Approach 1:
The patent segments the comprehensive attack procedure information into distinct components: attack procedure information (describing attack steps), cause information, and consequence information. This segmentation allows the system to process and match specific segments against anomalies, reducing processing complexity while maintaining comprehensive analysis
Solution Approach 2:
The system applies local quality by focusing the information processing on specific relevant segments rather than processing all available information uniformly. The collating unit selectively matches anomaly information with corresponding segments in the attack procedure database, improving efficiency without sacrificing assessment precision
Data Source
AI summary
An information processing device (10) includes an anomaly receiving means (11) for receiving an anomaly detected by a monitoring device installed in a control system, a collating means (12) for receiving the anomaly from the anomaly receiving means (11), making a first determination to determine whether the anomaly matches each of predetermined collating conditions for collating an event contained in an attack procedure and the anomaly, and when the first determination results in a match, making a further second determination to determine whether an event contained in each of predefined attack procedures matches the collating condition determined to match the anomaly, and when the second determination results in a match, specifying an attack procedure containing the event, and an extracting means (13) for extracting an event matching a predetermined extraction condition from the specified attack procedure.


