IP Library Granted Patent US 11,405,411
Granted Patent B2
US 11,405,411 · App. 16/493,930 · Granted Aug 2, 2022

Extraction apparatus, extraction method, computer readable medium

Inventors: Toshiki Watanabe (Tokyo, JP); Satoru Yamano (Tokyo, JP)
Assignee: NEC CORPORATION
H04L63/1416G06K9/6267H04L41/16H04L63/1425H04L63/1466H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,405,411
App. No.
16/493,930
Granted
Aug 2, 2022
Kind
B2
Abstract

An extraction apparatus can obtain a first alert and a second alert that are generated, when an anomaly occurs in a control system, in order to provide notification of the anomaly. The extraction apparatus includes: a classification unit configured to generate association information associating the first alert with the second alert; a learning unit configured to learn a generation pattern of the second alert when the anomaly occurs due to a cause other than a cyber-attack based on the association information generated by the classification unit and a generation pattern of the first alert when the anomaly occurs due to a cause other than a cyber-attack; and an extraction unit configured to extract, from among the second alerts, the second alert generated due to a cyber-attack based on the generation pattern of the second alert that is learned by the learning unit and output the extracted second alert.

Claims (28)

1. An extraction apparatus capable of obtaining a first alert and a second alert that are generated, when an anomaly occurs in a control system, in order to provide notification of the anomaly, wherein

the extraction apparatus comprises:

at least one memory storing one or more instructions; and

at least one processor configured to execute to one or more instruction to:

generate association information associating the first alert with the second alert;

learn a generation pattern of the second alert when the anomaly occurs due to a cause other than a cyber-attack based on the association information generated by the at least one processor and a generation pattern of the first alert when the anomaly occurs due to a cause other than a cyber-attack; and

extract, from among the second alerts, the second alert generated due to a cyber-attack based on the generation pattern of the second alert that is learned by the at least one processor and output the extracted second alert,

wherein the at least one processor is further configured to perform the learning by replacing the first alert in the generation pattern of the first alert when the anomaly occurs due to a cause other than the cyber-attack with the second alert associated with the first alert based on the association information.

2. The extraction apparatus according to claim 1 , wherein the at least one processor is further configured to estimate the first alert and the second alert that have been generated due to the same cause and generate the association information associating the estimated first alert with the estimated second alert.

3. The extraction apparatus according to claim 2 , wherein the cat least one processor is further configured to estimate the first alert and the second alert that have been generated due to the same cause based on information about the occurrence time of the anomaly included in the first alert and the second alert.

4. The extraction apparatus according to claim 2 , wherein the at least one processor is further configured to estimate the first alert and the second alert that have been generated due to the same cause based on information about the occurrence location of the anomaly included in the first alert and the second alert.

5. The extraction apparatus according to claim 2 , wherein the at least one processor is further configured to estimate the first alert and the second alert that have been generated due to the same cause based on information about the type of the anomaly included in the first alert and the second alert.

6. The extraction apparatus according to claim 1 , wherein the at least one processor is further configured to:

determine that among the second alerts, the second alert that matches the generation pattern of the second alert learned by the at least one processor is the second alert generated due to a cause other than the cyber-attack, and

determine that among the second alerts, the second alert that does not match the generation pattern of the second alert learned by the at least one processor is the second alert generated due to a cyber-attack.

7. The extraction apparatus according to claim 1 , wherein the at least one processor is further configured to discard the second alert generated due to a cause other than the cyber-attack.

8. The extraction apparatus according to claim 1 , wherein the first alert is an alert that the control system itself generates, when an anomaly occurs in the control system, in order to provide notification of the anomaly, and

the second alert is an alert that a system other than the control system generates, when an anomaly occurs in the control system, in order to provide notification of the anomaly.

9. An extraction method performed by an extraction apparatus capable of obtaining a first alert and a second alert that are generated, when an anomaly occurs in a control system, in order to provide notification of the anomaly, the extraction method comprising:

a classification step of generating association information associating the first alert with the second alert;

a learning step of learning a generation pattern of the second alert when the anomaly occurs due to a cause other than a cyber-attack based on the association information generated by the classification step and a generation pattern of the first alert when the anomaly occurs due to a cause other than a cyber-attack; and

an extraction step of extracting, from among the second alerts, the second alert generated due to a cyber-attack based on the generation pattern of the second alert that is learned by the learning step and outputting the extracted second alert,

wherein the learning operation is performed by replacing the first alert in the generation pattern of the first alert when the anomaly occurs due to a cause other than the cyber-attack with the second alert associated with the first alert based on the association information.

10. A non-transitory computer readable medium storing a program for causing a computer capable of obtaining a first alert and a second alert that are generated, when an anomaly occurs in a control system, in order to provide notification of the anomaly to execute:

a classification process of generating association information associating the first alert with the second alert;

a learning process of learning a generation pattern of the second alert when the anomaly occurs due to a cause other than a cyber-attack based on the association information generated by the classification process and a generation pattern of the first alert when the anomaly occurs due to a cause other than a cyber-attack; and

an extraction process of extracting, from among the second alerts, the second alert generated due to a cyber-attack based on the generation pattern of the second alert that is learned by the learning process and outputting the extracted second alert,

wherein the learning process is performed by replacing the first alert in the generation pattern of the first alert when the anomaly occurs due to a cause other than the cyber-attack with the second alert associated with the first alert based on the association information.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2024
From: IP WAVE PTE LTD.
To: CLOUD BYTE LLC.
Reel/Frame 067944/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2024
From: NEC ASIA PACIFIC PTE LTD.
To: IP WAVE PTE LTD.
Reel/Frame 066376/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2023
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 063349/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2019
From: WATANABE, TOSHIKI; YAMANO, SATORU
To: NEC CORPORATION
Reel/Frame 050370/0450 →