Control Security Setting via Automated Threat and Countermeasure Scenarios
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing sophistication of control devices due to advancements in information and communication technology has led to a rise in security threats, requiring specialized knowledge for threat analysis, which is costly and burdensome for production engineers and equipment manufacturers.
Innovation Solution
A control system with a support device that includes a system-configuration input part, threat analysis database, threat-scenario creating part, countermeasure database, countermeasure creating part, and security setting part, which acquires device configuration and protected assets, analyzes threats, creates threat and countermeasure scenarios, and outputs security function settings to the security unit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If control devices are connected to external devices via network and processing becomes more sophisticated, then functionality and intelligence of the control system are improved, but security threats increase and require specialized knowledge for analysis
Solution Approach 1:
The patent introduces a support device as an intermediary between the control device and security analysis. This support device includes a threat-scenario creating part that automatically generates threat scenarios based on device configuration information, and a countermeasure creating part that formulates security countermeasures. This intermediary automates the security analysis process that would otherwise require specialized human expertise.
Solution Approach 2:
The control device performs self-security analysis by utilizing the support device to automatically create threat scenarios and countermeasures based on its own configuration information. The system enables producers to independently analyze security threats and generate countermeasures without requiring external security specialists, thus achieving self-service security analysis.
2Measurement precision
If specialized knowledge is required for threat analysis, then security analysis accuracy is improved, but labor cost and education time increase
Solution Approach 1:
The patent replaces the mechanical system of human security specialists performing manual threat analysis with an automated information processing system. The support device's threat-scenario creating part and countermeasure creating part automatically generate security analyses based on device configuration, substituting human expertise with algorithmic processing that maintains accuracy while eliminating labor costs and education requirements.
Solution Approach 2:
The system changes the parameter of security analysis from requiring human expert judgment to using automated parameter-based analysis. By inputting device configuration parameters into the support device, the system automatically generates threat scenarios and countermeasures, transforming security analysis from a knowledge-intensive human task to a parameter-driven automated process.
3Reliability
If threat analysis is performed manually by specialists, then comprehensive security assessment is achieved, but processing time and complexity increase
Solution Approach 1:
The patent segments the security analysis process into distinct functional modules: the threat-scenario creating part that generates threat scenarios, and the countermeasure creating part that formulates countermeasures. This segmentation allows each module to handle specific aspects of security analysis independently, simplifying the overall complex process while maintaining comprehensive security assessment through the coordinated operation of these modular components.
Data Source
AI summary
A control system including a controller system and a support device is provided. The controller system controls a control target. The support device supports setting of the controller system. The support device includes a system-configuration input part, a threat analysis database, a threat-scenario creating part, a countermeasure database, a countermeasure creating part, and a security setting part. The countermeasure creating part creates a countermeasure scenario containing a countermeasure for each of protected assets of the controller system according to a threat scenario and countermeasures of the countermeasure database.


