Information Processing Device for Control System Anomaly Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In control systems, operators face challenges in promptly determining the cause and expected consequences of anomalies detected by monitoring devices, relying heavily on their knowledge and experience, which can lead to incorrect risk assessments and delayed actions.

Innovation Solution

An information processing device that receives anomalies from monitoring devices, uses collating and extraction conditions to identify matching attack procedures, and presents the causes and consequences to operators, thereby automating the risk determination process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If operators manually determine causes and consequences of anomalies based on their knowledge and experience, then flexibility and adaptability are maintained, but the determination time increases and accuracy decreases

Engineering Contradiction:
Improverisk determination accuracyVSAvoiddetermination time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an information processing device as an intermediary between the monitoring device and the operator. This device automatically determines causes and consequences by collating anomaly information with attack procedure information, acting as a mediator that reduces the operator's cognitive burden while maintaining accurate risk assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by pre-storing attack procedure information that includes various attack patterns, their causes, and consequences. When an anomaly occurs, the system quickly matches it against this pre-prepared information base, eliminating the need for operators to manually analyze from scratch

Inventive Principle:
Principle #10Preliminary action

2Reliability

If operators rely on their knowledge and experience to estimate causes and consequences, then subjective judgment is applied, but incorrect determinations and delayed actions occur

Engineering Contradiction:
Improvedetermination reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of attack procedure knowledge by storing structured attack procedure information in the information processing device. This copied knowledge base allows the system to objectively compare anomalies against known attack patterns, reducing reliance on individual operator expertise while improving consistency and reliability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system implements feedback by presenting the determined causes and consequences back to the operator for verification. This feedback loop allows the operator to review the automated determination and make corrections if necessary, improving reliability while maintaining system support

Inventive Principle:
Principle #23Feedback

3Measurement precision

If comprehensive attack procedure information is analyzed to determine risks, then accuracy improves, but information processing complexity increases

Engineering Contradiction:
Improverisk assessment precisionVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the comprehensive attack procedure information into distinct components: attack procedure information (describing attack steps), cause information, and consequence information. This segmentation allows the system to process and match specific segments against anomalies, reducing processing complexity while maintaining comprehensive analysis

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by focusing the information processing on specific relevant segments rather than processing all available information uniformly. The collating unit selectively matches anomaly information with corresponding segments in the attack procedure database, improving efficiency without sacrificing assessment precision

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12045342B2Information processing device, display method, and non-transitory computer readable medium
Publication Date: 2024.07.23 NEC CORP
  • US12045342B2 patent drawing
  • US12045342B2 patent drawing
  • US12045342B2 patent drawing

AI summary

An information processing device (10) includes an anomaly receiving means (11) for receiving an anomaly detected by a monitoring device installed in a control system, a collating means (12) for receiving the anomaly from the anomaly receiving means (11), making a first determination to determine whether the anomaly matches each of predetermined collating conditions for collating an event contained in an attack procedure and the anomaly, and when the first determination results in a match, making a further second determination to determine whether an event contained in each of predefined attack procedures matches the collating condition determined to match the anomaly, and when the second determination results in a match, specifying an attack procedure containing the event, and an extracting means (13) for extracting an event matching a predetermined extraction condition from the specified attack procedure.