[論文レビュー] Highly Scalable and Flexible Model for Effective Aggregation of Context-based Data in Generic IIoT Scenarios
本稿では、産業用インターネット(IIoT)環境における異種のコンテキストベースのデータのスケーラブルで柔軟な集約を実現する3段階のイベント中心のモデルを提案する。すべてのシステム情報に対して離散的で時系列順のイベントとして扱うことで、低レベルのネットワークパケットやログを、ネットワークフロー やシステム全体の挙動といった高レベルの抽象化と関連付ける。これにより、複数のIIoTユースケースにおいて、異常やセキュリティ脅威の効果的検出が可能になる。
Interconnectivity of production machines is a key feature of the Industrial Internet of Things (IIoT). This feature allows for many advantages in producing. Configuration and maintenance gets easier, as access to the given production unit is not necessarily coupled to physical presence. Customized production of goods is easily possible, reducing production times and increasing throughput. There are, however, also dangers to the increasing talkativeness of industrial production machines. The more open a system is, the more points of entry for an attacker exist. Furthermore, the amount of data a production site also increases rapidly due to the integrated intelligence and interconnectivity. To keep track of this data in order to detect attacks and errors in the production site, it is necessary to smartly aggregate and evaluate the data. In this paper, we present a new approach for collecting, aggregating and analysing data from different sources and on three different levels of abstraction. Our model is event-centric, considering every occurrence of information inside the system as an event. In the lowest level of abstraction, singular packets are collected, correlated with log-entries and analysed. On the highest level of abstraction, networks are pictured as a connectivity graph, enriched with information about host-based activities. Furthermore, we describe our work in progress of evaluating our aggregation model on two different system settings. In the first scenario, we verify the usability of our model in a remote maintenance application. In the second scenario, we evaluate our model in the context of network sniffing and correlation with log-files. First results show that our model is a promising solution to cope with increasing amounts of data and to correlate information from different types of sources.
研究の動機と目的
- 相互接続されたIIoTシステムにおける急増する異種データの管理という課題に対処する。
- PLC、ネットワークトラフィック、保守システムなど多様なソースからのデータの文脈認識による相関を可能にする。
- リモート保守、不正侵入検出、異常検出といった重要なIIoTユースケースを支援する。
- 複数の抽象化レベルをサポートするスケーラブルなデータ処理を実現する、柔軟で拡張可能なフレームワークを提供する。
- 複数のソース間でのイベント相関を通じて、整合性の欠如や悪意ある行動を検出することにより、システムのレジリエンスを向上させる。
提案手法
- IIoTにおける複雑イベント処理(CEP)を可能にするために、すべてのシステム情報を離散的で時系列順のイベントとしてモデル化する。
- 3段階の抽象化を実装する:レベル1(生データ)は個々のパケット、ログ、設定変更を収集する。レベル2はネットワークフローと履歴設定に抽象化する。レベル3は複数のマシンやシステム間でのデータ相関を実現する。
- 評価環境では、データ収集、保存、可視化にオープンソースツール(Elasticsearch、Logstash、Packetbeat、Kibana)を活用する。
- イベント相関技術を適用し、保守チケットがログエントリに対応しない、または予期しない設定変更といった整合性の欠如を検出する。
- ネットワークトラフィック、ホストログ、チケット管理システム(OTRS)、設定設定からの複数のソースのデータを統合する。
- 将来的な機械学習統合による自動異常検出を想定し、拡張性を備えたモデルを設計する。
実験結果
リサーチクエスチョン
- RQ1ネットワーク、ログ、設定、チケットといった多様なIIoTソースからの異種データを、スケーラブルに効果的に集約・相関させることは可能か?
- RQ2複数レベルのイベント中心モデルは、産業システムにおける異常や悪意ある行動の検出をどの程度向上できるか?
- RQ3本稿で提案するモデルは、リモート保守やシステムログとのネットワークトラフィック相関といった実用的IIoTユースケースをサポートできるか?
- RQ43段階の粒度の抽象化は、イベントレベルの忠実度を損なうことなく、状況認識をどのように向上させるか?
- RQ5実際のIIoT環境へのこのモデルの導入における実用的課題は何か。また、それらをどのように軽減できるか?
主な発見
- モデルは低レベルのネットワークパケットやホストログを高レベルのシステム挙動と効果的に相関させ、保守チケットがログエントリに対応しないなどの整合性の欠如を検出できた。
- リモート保守ユースケースにおいて、保守前後での設定とトラフィックパターンの比較を通じて、潜在的な誤設定を同定した。
- PLCログとトラフィックの相関シナリオでは、ログに記録されていない不審な設定変更を検出でき、スプーフィングや不正アクセスの兆候を示した。
- レベル2およびレベル3への抽象化により、高いエラー率や異常な設定頻度を示すマシンやシステムの異常挙動パターンを特定できた。
- 標準のオープンソースツールを用いた実環境でのテスト環境で、本モデルの実用的妥当性が確認された。産業監視分野への応用可能性が示された。
- 予備的な結果から、本モデルは、セキュリティおよび保守目的の文脈認識型で複数ソースにまたがる相関を可能にするという点で、IIoTにおけるビッグデータ管理の有望なソリューションであると確認された。
より良い研究を、今すぐ始めましょう
論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。
クレジットカード登録不要
このレビューはAIが作成し、人間の編集者が確認しました。