Analysis system, analysis method, and storage medium

    公开(公告)号:US10536261B2

    公开(公告)日:2020-01-14

    申请号:US15510742

    申请日:2015-09-17

    Abstract: Provided is an analysis system including a memory acquisition unit that is configured to acquire at least part of data stored in a memory unit in an information communication apparatus including a computing unit and the memory unit; a communication processing unit that is configured to instruct the memory acquisition unit to acquire data stored in the memory unit when determining that key data including an encryption key for cryptographic communication protocol are stored in the memory unit; and a cryptanalysis unit that is configured to extract one or more key data candidates that are candidates of the key data, from the stored in the memory unit, and extract, from one or more of the key data candidates, correct key data that enables to decrypt correctly the encrypted communication data. The communication processing unit is further configured to execute specific processing according to the decrypted communication data.

    ATTACK SCENARIO GENERATING APPARATUS, ATTACK SCENARIO GENERATING METHOD, AND COMPUTER READABLE RECORDING MEDIUM

    公开(公告)号:US20240297896A1

    公开(公告)日:2024-09-05

    申请号:US18571986

    申请日:2021-06-24

    CPC classification number: H04L63/1441

    Abstract: An attack scenario generating apparatus including: first attack step detection unit executes an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detects a first attack step that satisfies a damage condition with which damage occurs in the first virtual model; an input/output condition extraction unit extracts an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition; a second attack step detection unit executes an attack simulation on a second virtual model obtained from the storage device, and detects a second attack step in which output of the second virtual model satisfies the input condition; and a combination unit combines the first attack step and the second attack step to generate an attack scenario.

    Information processing device, display method, and non-transitory computer readable medium

    公开(公告)号:US12045342B2

    公开(公告)日:2024-07-23

    申请号:US17767558

    申请日:2019-10-28

    CPC classification number: G06F21/554 G06F2221/034

    Abstract: An information processing device (10) includes an anomaly receiving means (11) for receiving an anomaly detected by a monitoring device installed in a control system, a collating means (12) for receiving the anomaly from the anomaly receiving means (11), making a first determination to determine whether the anomaly matches each of predetermined collating conditions for collating an event contained in an attack procedure and the anomaly, and when the first determination results in a match, making a further second determination to determine whether an event contained in each of predefined attack procedures matches the collating condition determined to match the anomaly, and when the second determination results in a match, specifying an attack procedure containing the event, and an extracting means (13) for extracting an event matching a predetermined extraction condition from the specified attack procedure.

    Analysis assistance apparatus, analysis assistance method, and computer-readable recording medium

    公开(公告)号:US11860604B2

    公开(公告)日:2024-01-02

    申请号:US17261410

    申请日:2018-07-26

    CPC classification number: G05B19/406 G05B23/0216 G05B2219/50193

    Abstract: An analysis assistance apparatus 10 includes: a control program obtainment unit 11 that obtains a control program of a plant based on sensor data from a sensor installed in the plant; an event information obtainment unit 12 that obtains event information, which includes a variable that defines a state of the plant when a predetermined event has occurred and a value thereof, as information necessary for searching the control program for a safety barrier for avoiding the occurrence of the predetermined event in the plant; and a safety barrier search unit 13 that extracts, from the control program, a causal relationship between an input variable and an output variable, and searches the control program for the safety barrier based on the variable and the value included in the event information and on the extracted causal relationship.

    Analysis device, analysis method, and storage medium in which analysis program is recorded

    公开(公告)号:US11436325B2

    公开(公告)日:2022-09-06

    申请号:US16682068

    申请日:2019-11-13

    Abstract: Provided is an analysis apparatus including a first storage device configured to store data, and a processing circuitry that is configured to control the own apparatus to function as: a dispatcher that is communicably connected to an analysis target device that performs operational processing by use of a processor and a memory unit, and generates collection target data for reproducing at least part of a state of the operational processing in the analysis target device, in accordance with data being transmitted and received between the processor and the memory unit; a data mapper that assigns, to one or more areas included in the collection target data, tag information for identifying the area; and a data writer that saves the one or more areas into the first storage device in accordance with a first policy defining a procedure of saving the collection target data into the first storage device.

    Analysis system, analysis method, and storage medium

    公开(公告)号:US10931468B2

    公开(公告)日:2021-02-23

    申请号:US15510730

    申请日:2015-09-17

    Abstract: Provided is an analysis system configured to obtain an encryption key for encryption communication between an information communication apparatus and a communication network, from memory space provided in the information communication apparatus. The analysis system including a processing circuitry configured to function as: a memory acquisition unit that is configured to acquire at least part of data stored in a memory unit in an information communication apparatus including a computing unit and the memory unit; and a communication processing unit that is configured to determine whether key data including an encryption key used for encryption processing in a cryptographic communication protocol are stored in the memory unit, based on communication data transmitted and received in accordance with the cryptographic communication protocol between the information communication apparatus and a communication network, and instruct the memory acquisition unit to acquire data stored in the memory unit, based on the determination result.

    PHYSICAL MODEL GENERATION APPARATUS, CONTROL METHOD, AND COMPUTER-READABLE STORAGE MEDIUM

    公开(公告)号:US20240311525A1

    公开(公告)日:2024-09-19

    申请号:US18283059

    申请日:2021-03-23

    CPC classification number: G06F30/17

    Abstract: A physical model generation apparatus (2000) acquires architecture information (10), state information (20), and template information (30). The architecture information (10) describes physical components (52) included in a target control system (50), and connections (54) for each physical component (52). The state information (20) describes associations between a state of the physical component and one or more working connections through which signals are transferred in the corresponding state. The template information (30) describes associations between a behavior template and a connection condition. The behavior template describes behaviors that are common to the physical components (52) whose working connections satisfy the connection condition corresponding thereto. The physical model generation apparatus (2000) generates a physical model (40) that includes, for each physical component (52), behavior information (42) that describes behaviors of the physical component (52) for each of its possible states.

Patent Agency Ranking