-
公开(公告)号:US10536261B2
公开(公告)日:2020-01-14
申请号:US15510742
申请日:2015-09-17
Applicant: NEC Corporation
Inventor: Masato Yamane , Yuki Ashino , Masafumi Watanabe
Abstract: Provided is an analysis system including a memory acquisition unit that is configured to acquire at least part of data stored in a memory unit in an information communication apparatus including a computing unit and the memory unit; a communication processing unit that is configured to instruct the memory acquisition unit to acquire data stored in the memory unit when determining that key data including an encryption key for cryptographic communication protocol are stored in the memory unit; and a cryptanalysis unit that is configured to extract one or more key data candidates that are candidates of the key data, from the stored in the memory unit, and extract, from one or more of the key data candidates, correct key data that enables to decrypt correctly the encrypted communication data. The communication processing unit is further configured to execute specific processing according to the decrypted communication data.
-
公开(公告)号:US12061730B2
公开(公告)日:2024-08-13
申请号:US17430069
申请日:2019-02-14
Applicant: NEC Corporation
Inventor: Taniya Singh , Masafumi Watanabe , Hirofumi Ueda
CPC classification number: G06F21/73 , G06F21/554 , G06F21/577 , G06F2221/034
Abstract: The present disclosure provides a security assessment apparatus, a method, and a program capable of making an assessment of a security risk simply and appropriately. The security assessment apparatus according to the present disclosure is a security assessment apparatus of a facility to be controlled using a controller, including: an identification unit (15) configured to identify a compromised component which puts the facility into an unsafe situation based on data regarding a plurality of components provided in the facility and control program code of the controller, thereby generating a list of the compromised component; and a compromised behavior generating unit (16) configured to generate a compromised behavior of a selected component selected from the list of the compromised component.
-
3.
公开(公告)号:US20240297896A1
公开(公告)日:2024-09-05
申请号:US18571986
申请日:2021-06-24
Applicant: NEC Corporation
Inventor: Masafumi Watanabe , Hirofumi Ueda
IPC: H04L9/40
CPC classification number: H04L63/1441
Abstract: An attack scenario generating apparatus including: first attack step detection unit executes an attack simulation on a first virtual model obtained from a storage device in which a plurality of virtual models used to represent a target system are stored, and detects a first attack step that satisfies a damage condition with which damage occurs in the first virtual model; an input/output condition extraction unit extracts an input condition or an output condition of the first virtual model from the detected first attack step, or both the input condition and the output condition; a second attack step detection unit executes an attack simulation on a second virtual model obtained from the storage device, and detects a second attack step in which output of the second virtual model satisfies the input condition; and a combination unit combines the first attack step and the second attack step to generate an attack scenario.
-
公开(公告)号:US11640463B2
公开(公告)日:2023-05-02
申请号:US16453244
申请日:2019-06-26
Applicant: NEC Corporation
Inventor: Masafumi Watanabe , Yuki Ashino
IPC: G06F21/56 , G06F16/2455 , G06F21/55 , H04L9/40
Abstract: Provided is an analysis device with which it is possible to find information relating to the intention and purpose of an attacker. The analysis device is provided with a purpose estimating means that estimates the purpose of behavior, based on predetermined behavior in the computer and knowledge information that includes the relation between the behavior and the purpose of executing the behavior.
-
5.
公开(公告)号:US12045342B2
公开(公告)日:2024-07-23
申请号:US17767558
申请日:2019-10-28
Applicant: NEC Corporation
Inventor: Masafumi Watanabe
IPC: G06F21/55
CPC classification number: G06F21/554 , G06F2221/034
Abstract: An information processing device (10) includes an anomaly receiving means (11) for receiving an anomaly detected by a monitoring device installed in a control system, a collating means (12) for receiving the anomaly from the anomaly receiving means (11), making a first determination to determine whether the anomaly matches each of predetermined collating conditions for collating an event contained in an attack procedure and the anomaly, and when the first determination results in a match, making a further second determination to determine whether an event contained in each of predefined attack procedures matches the collating condition determined to match the anomaly, and when the second determination results in a match, specifying an attack procedure containing the event, and an extracting means (13) for extracting an event matching a predetermined extraction condition from the specified attack procedure.
-
6.
公开(公告)号:US11860604B2
公开(公告)日:2024-01-02
申请号:US17261410
申请日:2018-07-26
Applicant: NEC Corporation
Inventor: Masafumi Watanabe
IPC: G05B23/02 , G05B19/406
CPC classification number: G05B19/406 , G05B23/0216 , G05B2219/50193
Abstract: An analysis assistance apparatus 10 includes: a control program obtainment unit 11 that obtains a control program of a plant based on sensor data from a sensor installed in the plant; an event information obtainment unit 12 that obtains event information, which includes a variable that defines a state of the plant when a predetermined event has occurred and a value thereof, as information necessary for searching the control program for a safety barrier for avoiding the occurrence of the predetermined event in the plant; and a safety barrier search unit 13 that extracts, from the control program, a causal relationship between an input variable and an output variable, and searches the control program for the safety barrier based on the variable and the value included in the event information and on the extracted causal relationship.
-
7.
公开(公告)号:US11436325B2
公开(公告)日:2022-09-06
申请号:US16682068
申请日:2019-11-13
Applicant: NEC Corporation
Inventor: Masato Yamane , Yuki Ashino , Yoichiro Morita , Masafumi Watanabe
Abstract: Provided is an analysis apparatus including a first storage device configured to store data, and a processing circuitry that is configured to control the own apparatus to function as: a dispatcher that is communicably connected to an analysis target device that performs operational processing by use of a processor and a memory unit, and generates collection target data for reproducing at least part of a state of the operational processing in the analysis target device, in accordance with data being transmitted and received between the processor and the memory unit; a data mapper that assigns, to one or more areas included in the collection target data, tag information for identifying the area; and a data writer that saves the one or more areas into the first storage device in accordance with a first policy defining a procedure of saving the collection target data into the first storage device.
-
公开(公告)号:US10931468B2
公开(公告)日:2021-02-23
申请号:US15510730
申请日:2015-09-17
Applicant: NEC Corporation
Inventor: Masato Yamane , Yuki Ashino , Masafumi Watanabe
Abstract: Provided is an analysis system configured to obtain an encryption key for encryption communication between an information communication apparatus and a communication network, from memory space provided in the information communication apparatus. The analysis system including a processing circuitry configured to function as: a memory acquisition unit that is configured to acquire at least part of data stored in a memory unit in an information communication apparatus including a computing unit and the memory unit; and a communication processing unit that is configured to determine whether key data including an encryption key used for encryption processing in a cryptographic communication protocol are stored in the memory unit, based on communication data transmitted and received in accordance with the cryptographic communication protocol between the information communication apparatus and a communication network, and instruct the memory acquisition unit to acquire data stored in the memory unit, based on the determination result.
-
公开(公告)号:US10360378B2
公开(公告)日:2019-07-23
申请号:US15505498
申请日:2014-08-22
Applicant: NEC Corporation
Inventor: Masafumi Watanabe , Yuki Ashino
Abstract: Provided is an analysis device with which it is possible to find information relating to the intention and purpose of an attacker. The analysis device is provided with a purpose estimating means that estimates the purpose of behavior, based on predetermined behavior in the computer and knowledge information that includes the relation between the behavior and the purpose of executing the behavior.
-
10.
公开(公告)号:US20240311525A1
公开(公告)日:2024-09-19
申请号:US18283059
申请日:2021-03-23
Applicant: NEC Corporation
Inventor: Taniya SINGH , Masafumi Watanabe
IPC: G06F30/17
CPC classification number: G06F30/17
Abstract: A physical model generation apparatus (2000) acquires architecture information (10), state information (20), and template information (30). The architecture information (10) describes physical components (52) included in a target control system (50), and connections (54) for each physical component (52). The state information (20) describes associations between a state of the physical component and one or more working connections through which signals are transferred in the corresponding state. The template information (30) describes associations between a behavior template and a connection condition. The behavior template describes behaviors that are common to the physical components (52) whose working connections satisfy the connection condition corresponding thereto. The physical model generation apparatus (2000) generates a physical model (40) that includes, for each physical component (52), behavior information (42) that describes behaviors of the physical component (52) for each of its possible states.
-
-
-
-
-
-
-
-
-