Intrusion path analysis device and intrusion path analysis method
The intrusion path analysis device obtains security warnings and event history records, combined with intrusion in-depth analysis, solves the problem of difficult to master the on-board network attack path, and achieves accurate attack analysis and security improvement.
Patent Information
- Application Number
- CN202080034305.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-01-14
- Filing Date
- 2020-12-18
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2040-12-18
AI Technical Summary
The existing technology cannot effectively grasp the intrusion paths of on-board cyber attacks, and it is difficult to conduct quick response and security analysis.
It provides an intrusion path analysis device, which obtains security warnings and event history records through security sensors connected to the control network system, combines intrusion depth analysis of attack paths, and outputs analysis results.
It can accurately analyze the intrusion path of attacks, improve the accuracy and security of attack analysis, help security analysts formulate response strategies, and improve vehicle network security.
Smart Images

Figure CN113924750B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an intrusion path analysis device and an intrusion path analysis method for analyzing an intrusion path of an attack on a network (eg, an in-vehicle network). Background Art
[0002] In recent years, automotive systems have been equipped with numerous devices called electronic control units (ECUs). The network connecting these ECUs is called the in-vehicle network. Numerous standards exist for in-vehicle networks, but one of the most popular is the Controller Area Network (CAN). Furthermore, with the increasing popularity of autonomous driving and connected cars, in-vehicle network traffic is expected to increase, leading to the widespread adoption of in-vehicle Ethernet.
[0003] On the other hand, the prevalence of connected cars has also led to the threat of attackers invading the vehicle network from a network outside the vehicle and improperly controlling the vehicle, leading to security research.
[0004] As solutions to improve the security of in-vehicle networks, methods such as using encrypted communications to prevent communication from unauthorized nodes, or protecting control networks through regional separation, as previously proposed in Non-Patent Documents 1 and 2, have been proposed for Internet Protocol (IP) communications. On the other hand, given the difficulty of maintaining continuous protection for the long expected lifespan of a vehicle using only factory-installed security features when new vulnerabilities are discovered or the attacker environment continues to change, solutions that monitor and respond to security anomalies within the network have also attracted attention (e.g., Patent Document 1).
[0005] Prior art literature
[0006] Patent Document 1: Japanese Patent No. 6508631
[0007] Non-Patent Document 1: RFC5406: Guidelines for Specifying the Use of IPsec Version 2
[0008] Non-Patent Document 2: IEEE 802.1AE: MAC Security Summary of the Invention
[0009] Technical problem to be solved by the invention
[0010] Understanding the intrusion path of an attack is useful for attack analysis and can lead to rapid response. Therefore, understanding the intrusion path of an attack is desirable. However, methods such as those described in Patent Document 1 can detect an attack on a control network but cannot fully understand the intrusion path of the attack.
[0011] Therefore, the present disclosure provides an intrusion path analysis device and an intrusion path analysis method that output information on an intrusion path of an attack on a control network.
[0012] Technical solutions to solve problems
[0013] In order to solve the above-mentioned problem, a technical solution of the present disclosure involves an intrusion path analysis device, which is an intrusion path analysis device connected to a control network system in a communicative manner, wherein the control network system is connected to one or more electronic control devices and communication devices, and one or more security sensors are configured in the control network system. When the security sensor detects a sign of security infringement in at least one of the one or more electronic control devices and the communication devices on the network, the security sensor sends a security warning containing the status of detecting the sign of the security infringement to the network. The intrusion path analysis device includes: a warning acquisition unit, which acquires the security warning from the one or more security sensors; an event acquisition unit, which acquires an event history record of an event generated in the control network system; and an intrusion path analysis unit, which analyzes the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputs the analysis result.
[0014] In addition, in order to solve the above-mentioned problem, a technical solution disclosed in the present invention involves an intrusion path analysis method, which is an intrusion path analysis method in a control network system connected with one or more electronic control devices and communication devices, wherein the control network system is configured with one or more security sensors, and when the security sensors detect signs of security violations in at least one of the one or more electronic control devices and the communication devices on the network, the security sensors send a security warning containing the status of detecting the signs of the security violations to the network, and the intrusion path analysis method includes: a step of obtaining the security warning from the one or more security sensors; a step of obtaining an event history record of events generated in the control network system; and an intrusion path analysis step of analyzing the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputting the analysis result.
[0015] Effects of the Invention
[0016] According to an intrusion path analysis device and the like according to one technical solution of the present disclosure, information on an intrusion path of an attack on a control network can be output. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 FIG. 4 is an overall configuration diagram of the in-vehicle network monitoring system in an embodiment.
[0018] Figure 2 This is a diagram showing the configuration of an in-vehicle network mounted on a vehicle in an embodiment.
[0019] Figure 3 It is a structural diagram of the TCU in the embodiment.
[0020] Figure 4 This is a structural diagram of the central ECU in the embodiment.
[0021] Figure 5 It is a structural diagram of an Ethernet switch in an embodiment.
[0022] Figure 6 It is a structural diagram of the ECU in the embodiment.
[0023] Figure 7 It is a structural diagram of a server in an embodiment.
[0024] Figure 8 This is a diagram showing an example of a safety warning output by the safety sensor unit in the embodiment.
[0025] Figure 9 This is a diagram showing an example of history information included in an analysis report generated by the central ECU in the embodiment.
[0026] Figure 10 This is a diagram showing an example of the security warning history stored in the security warning history storage unit according to the embodiment.
[0027] Figure 11 This is a diagram showing an example of the vehicle event history stored in the vehicle event history storage unit in the embodiment.
[0028] Figure 12 This is a diagram showing a first intrusion path analysis sequence in the central ECU according to the embodiment.
[0029] Figure 13 This is a diagram showing a second intrusion path analysis sequence in the central ECU according to the embodiment.
[0030] Figure 14 This is a flowchart of the process until the analysis report is notified in the central ECU according to the embodiment.
[0031] Figure 15 Yes Figure 14 Detailed flowchart of step S204 is shown.
[0032] Figure 16 This is a diagram showing an example of a safety sensor configuration database in another modified example of the embodiment.
[0033] Figure 17 This is a flowchart for determining a response according to an intrusion path analysis result by a central ECU in another modified example of the embodiment.
[0034] Figure 18 This is a diagram showing an example of the relationship between the target ECU to call attention to and the response of each ECU according to the depth of the safety warning in another modification of the embodiment.
[0035] Figure 19 It is a diagram showing an example of an analysis report in another modified example of the embodiment.
[0036] Figure 20 This is a diagram showing an example of a threat database held by the central ECU in another modified example of the embodiment. DETAILED DESCRIPTION
[0037] (Insights that form the basis of this disclosure)
[0038] Hereinafter, an in-vehicle network will be described as an example of a network.
[0039] As also described in the "Technical Problem to be Solved by the Invention," understanding the intrusion path of an attack (e.g., a cyber attack) is useful for attack analysis and can be related to rapid response. For example, understanding the entry point (the point of initial attack) from which the attack began or the intrusion path through which the attack was carried out is useful for attack analysis.
[0040] After detecting an attack, analyzing the cause of the attack, identifying the vulnerability, and remediating it are crucial to maintaining vehicle safety. Attack analysis requires providing security analysts with information that makes it easier to determine the cause of the attack, and information indicating the intrusion path is also useful in this regard.
[0041] For these reasons, it is desired to grasp the invasion path of the attack. However, the technology described in the prior art documents cannot grasp even the invasion path of the attack.
[0042] Therefore, the inventors of the present application have conducted intensive research on an intrusion path analysis device and the like that can grasp the intrusion path of an attack, and have invented the intrusion path analysis device and the like described below.
[0043] A technical solution disclosed herein involves an intrusion path analysis device that is connected to a control network system in a communicative manner, wherein the control network system is connected to one or more electronic control devices and communication devices, and one or more security sensors are configured in the control network system. When the security sensor detects a sign of a security violation in at least one of the one or more electronic control devices and the communication devices on the network, the security sensor sends a security warning containing the status of the detection of the sign of the security violation to the network. The intrusion path analysis device includes: a warning acquisition unit that acquires the security warning from the one or more security sensors; an event acquisition unit that acquires an event history of an event generated in the control network system; and an intrusion path analysis unit that analyzes the intrusion path of the attack based on the security warning, the event history, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputs the analysis result.
[0044] Thus, the intrusion path analysis device can analyze the intrusion path of an attack on the control network based on security warnings, event history records, and intrusion depth. By including event history records, for example, the intrusion path can also be analyzed using the relationship between successfully completed events and the intrusion depth of security warnings. This allows the intrusion path analysis device to analyze the intrusion path with greater accuracy than when event history records are not included. Thus, the intrusion path analysis device can output analysis results that include information about the intrusion path of the attack on the control network.
[0045] For example, a security analyst conducting attack-related analysis can obtain the results of the analysis of the intrusion path of the control network from the analysis results, and can easily infer the response method to the attack result, the location that will become the next target of the attack, etc., which is effective in responding to the attack.
[0046] In addition, for example, it can also be: the control network system is composed of more than two subnetworks, the communication device is configured on at least one of the more than two subnetworks, and is a device for communicating with a network or device outside the control network system, and the intrusion depth is determined by the number of physical or logical paths from the communication device to the monitoring object of the safety sensor, the one or more electronic control devices, the more than two subnetworks, and at least one of the gateway devices connecting the more than two subnetworks to each other.
[0047] Thus, from the perspective of an external attacker, the deeper the security warning output from a security sensor located in a hard-to-reach location, the greater the intrusion depth. This allows the analysis results to further reflect the intrusion status of the attack. This allows the intrusion path analysis device to output analysis results that make it easier to understand the intrusion status of the attack, effectively analyzing the attack.
[0048] In addition, for example, it can also be: as the analysis, when there are multiple security warnings, the intrusion path analysis unit determines whether the event is caused by the attack based on the time change of the intrusion depth of multiple security warnings and the event generated in the time period when multiple security warnings are detected.
[0049] Thus, the analysis result includes information indicating whether the event is caused by an attack, so the attack analysis can be performed taking the event into consideration. By using such analysis results, the accuracy of attack analysis is improved.
[0050] Furthermore, for example, as the analysis, the intrusion path analysis unit may determine that the event is caused by an attack when the occurrence distribution of the intrusion depth changes before and after the occurrence time of the event included in the event history record.
[0051] Thus, the intrusion path analysis device can determine whether an event that completed normally was caused by an attack based on the generation of a security warning, and can detect abnormal behavior that security sensors cannot detect. As a result, the intrusion path analysis device can output analysis results that include detection results of abnormal behavior that security sensors cannot detect, making attack analysis more efficient.
[0052] In addition, for example, as the analysis, the intrusion path analysis unit judges that the intrusion situation is an expansion of the intrusion when the intrusion depth of the security warning increases with the passage of time; judges that the intrusion situation is an attack caused by an abnormal device when the intrusion depth of the security warning decreases with the passage of time; and judges that the intrusion situation is no change when the intrusion depth of the security warning does not change with the passage of time.
[0053] Thus, the intrusion path analysis device can determine the current intrusion status based on the changes in the intrusion depth of multiple security warnings. By outputting analysis results including the judgment results, the intrusion path analysis device can enable security analysts to understand the current intrusion status, thereby outputting information useful for researching countermeasures to the attack.
[0054] In addition, for example, as the analysis, the intrusion path analysis unit further determines that the entry point of the attack is the area with the smallest intrusion depth when the intrusion condition is that the intrusion is expanding; determines that the entry point of the attack is the area with the largest intrusion depth when the intrusion condition is an attack caused by the abnormal device; and determines that the entry point of the attack is the area with the same intrusion depth when the intrusion condition is that there is no change.
[0055] This allows the intrusion path analysis device to determine the attack entry point. By outputting analysis results including the entry point, the intrusion path analysis device enables security analysts to understand the current entry point, thereby outputting information useful for studying countermeasures to the attack.
[0056] In addition, for example, as the analysis, the intrusion path analysis unit may further determine that the intrusion is caused by physical access or false detection when there is only one security warning and the intrusion depth of the security warning is higher than a predetermined threshold.
[0057] Thus, the intrusion path analysis device can make a judgment related to the analysis of the intrusion path even if there is only one security warning. By outputting the analysis results including the judgment results, the intrusion path analysis device can enable security analysts to understand the current intrusion situation, thereby outputting information useful for studying countermeasures to the attack.
[0058] Furthermore, for example, as the analysis, when there is the event associated with the security alert, the intrusion path analysis unit may further determine that the event is an event caused by the attack.
[0059] Thus, the intrusion path analysis device can determine whether an event is caused by an attack, even when there is only one security alert. This allows the intrusion path analysis device to output analysis results that include detection results of abnormal behavior that security sensors cannot detect, making attack analysis more efficient.
[0060] In addition, for example, it may also be that the intrusion path analysis unit performs at least one of strengthening the monitoring function of at least one of the one or more electronic control devices and the communication device, and limiting the function of at least one of the one or more electronic control devices and the communication device according to the intrusion depth of the security warning.
[0061] As a result, the intrusion path analysis device can suppress the impact caused by the attack by taking measures according to the depth of the intrusion, thereby improving the security of the control network system.
[0062] In addition, for example, when the intrusion path analysis unit determines that the intrusion situation is an expansion of the intrusion and the maximum intrusion depth among the intrusion depths detected in the security warning is above a predetermined threshold, the intrusion path analysis unit may output a notification to disable a portion of the function of the control network system.
[0063] As a result, the intrusion path analysis device can suppress the impact of the attack when the intrusion expands, and can effectively improve the security of the control network system.
[0064] In addition, for example, the analysis result may include at least one of the entry point of the attack, the penetration depth of the attack, and historical record information including one or more of the security warnings and the event history records.
[0065] Thus, the intrusion path analysis device enables security analysts to grasp at least one of the attack entry point, the attack penetration depth, and historical information. The intrusion path analysis device enables security analysts to analyze attacks efficiently by using the at least one information.
[0066] In addition, for example, the event may include at least one of the following: login to a device configured in the control network system, completion of installation and update of an application or firmware installed on the device, completion of firmware transmission, system diagnosis, and communication of a fault code.
[0067] Thus, the intrusion path analysis device can determine whether at least one of the events is caused by an attack. The intrusion path analysis device can output analysis results that match the purpose by appropriately selecting events based on the purpose of the control system network.
[0068] In addition, for example, the security sensor may include a network intrusion detection system that detects signs of intrusion from network traffic, a host intrusion detection system that detects signs of intrusion from abnormal behavior on one or more electronic control devices, an abnormal data packet detection system of a firewall configured in the control network system, a login failure detection sensor, a signature verification failure detection sensor, a message authentication code verification failure detection sensor contained in a message on the network, and at least one of a security access failure detection sensor.
[0069] As a result, the intrusion path analysis device can capture intrusion signs of an attack using multiple types of security sensors, thereby improving the accuracy of the generated analysis report.
[0070] In addition, for example, the control network system may be an in-vehicle network system.
[0071] Thus, the intrusion path analysis device can analyze the intrusion path to the in-vehicle network system, which is effective in countering attacks on the in-vehicle network system, for example, leading to improved vehicle driving safety.
[0072] In addition, a technical solution disclosed herein involves an intrusion path analysis method in a control network system connected to one or more electronic control devices and communication devices, wherein the control network system is configured with one or more security sensors, and when the security sensors detect signs of security violations in at least one of the one or more electronic control devices and the communication devices on the network, the security sensors send a security warning containing the status of detecting the signs of the security violations to the network, and the intrusion path analysis method includes: a step of obtaining the security warning from the one or more security sensors; a step of obtaining an event history record of events generated in the control network system; and an intrusion path analysis step of analyzing the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack envisioned when the security warning is generated, and outputting the analysis result.
[0073] This achieves the same effects as those of the aforementioned intrusion path analysis device.
[0074] Furthermore, these inclusive or specific technical solutions can be implemented by systems, devices, methods, integrated circuits, computer programs, or non-transitory recording media such as computer-readable CD-ROMs, or by any combination of systems, devices, methods, integrated circuits, computer programs, and recording media devices.
[0075] Hereinafter, the intrusion path analysis device and the like involved in the embodiments of the present disclosure will be described with reference to the accompanying drawings. In addition, the embodiments described below all represent a preferred specific example of the present disclosure. That is, the numerical values, shapes, materials, constituent elements, configuration positions of constituent elements, connection forms, steps, order of steps, etc. shown in the following embodiments are an example and are not intended to limit the present disclosure. The present disclosure is determined based on the description of the claims. Therefore, the constituent elements of the following embodiments that are not recorded in the independent claims representing the highest concept of the present disclosure are not necessarily required to solve the problems of the present disclosure, but are described as constituent elements that constitute a more preferred technical solution.
[0076] (Implementation Method)
[0077] The following describes an intrusion path analysis device installed in a vehicle equipped with an in-vehicle network (in-vehicle network system 10a). This in-vehicle network is a network in which multiple electronic control units (ECUs) communicate via a CAN bus and Ethernet (registered trademark). In addition, in-vehicle network system 10a is an example of a control network system that serves as the target of intrusion path analysis by the intrusion path analysis device.
[0078] [1.1 Overall Structure of the In-Vehicle Network Monitoring System 1]
[0079] Figure 1 This is a diagram of the overall structure of an in-vehicle network monitoring system 1 in this embodiment. The in-vehicle network monitoring system 1 includes a vehicle 10, a network 20, and a server 30. The vehicle 10 analyzes security warnings generated within the vehicle, generates an analysis report, and transmits this analysis report to the server 30 via the network 20. The network 20 may include the Internet or a dedicated line. The server 30 receives the report from the vehicle 10 and, based on the analysis report, notifies security analysts and others of the vehicle 10's security status (intrusion status).
[0080] [1.2 Network Structure of Vehicle 10]
[0081] Figure 2 This is a block diagram of an in-vehicle network system 10a installed in a vehicle 10 according to this embodiment. The in-vehicle network system 10a includes a TCU (Telematics Control Unit) 100, a central ECU 101, Ethernet switches 102 and 103, ECUs 104 to 111 (also referred to as ECU 104, etc.), Ethernet (registered trademark; hereinafter referred to as such) 11 and 12, and CANs 13 and 14 that communicatively connect these devices. Each device is equipped with a safety sensor (e.g., safety sensor units 1004, 1005, 1104, 1202, and 1303 (also referred to as safety sensor unit 1004, etc.) described later) that notifies the central ECU 101 of a safety warning via the network to which each device is connected. For example, in the in-vehicle network system 10a, one or more security sensors are configured on at least one of the sub-networks (described later), the ECU 104, and the TCU 100 to detect security breach signs. In other words, upon detecting a security breach sign, the security sensor transmits a security alert indicating that a security breach sign has been detected to the sub-network. Security breach signs are actions (such as verification failure) and information (such as the source IP address and signature ID) that indicate a potential attack, and are pre-defined.
[0082] In addition, the central ECU 101 generates an analysis report by collecting and analyzing the safety warnings notified from various devices. Figure 2 Although omitted, an in-vehicle network can include many ECUs. An ECU is a device that includes, for example, a processor (microprocessor), memory, digital circuits, analog circuits, and communication circuits. The memory, such as ROM or RAM, can store control programs (computer programs) executed by the processor. For example, the ECU implements various functions by operating the processor according to the control program. Furthermore, a computer program is composed of a combination of multiple command codes for the processor to achieve a predetermined function.
[0083] In the Ethernet 11 , the TCU 100 , the central ECU 101 , the ECU 104 , and the ECU 105 communicate via the Ethernet switch 102 .
[0084] In the Ethernet 12 , the central ECU 101 , the ECU 106 , and the ECU 107 communicate via the Ethernet switch 103 .
[0085] The central ECU 101 , the ECU 108 , the ECU 109 , and the ECU 110 communicate via the CAN 13 .
[0086] The ECU 107 and the ECU 111 communicate with each other via the CAN 14 .
[0087] Ethernet 11, 12 and CAN 13, 14 are examples of subnetworks. In addition, each subnetwork is connected to at least one of one or more ECUs and one or more TCUs 100 in a communicative manner. In addition, the number of subnetworks constituting the in-vehicle network system 10a is not particularly limited, and can be one or more, for example, two or more. That is, the in-vehicle network system 10a can be composed of one or more subnetworks, for example, two or more subnetworks. In addition, the two or more subnetworks are connected in a manner that can communicate with each other (for example, in a manner that can communicate with each other by wire).
[0088] The TCU 100 includes a communication interface for communicating with a network or device external to the in-vehicle network monitoring system 1 (e.g., external network 20 ). The TCU 100 has the function of notifying the server 30 of analysis reports received from the central ECU 101 via the network 20 . The TCU 100 is configured on at least one of the one or more sub-networks. The TCU 100 is an example of a communication device, and the communication interface is an example of an external connection interface.
[0089] The central ECU 101 is the ECU that serves as the hub of the vehicle 10. It runs various applications and implements the functions of the vehicle 10. It also serves as a gateway for Ethernet 11, Ethernet 12, and CAN 13. The central ECU 101 collects and analyzes security alerts from security sensors installed in the vehicle 10, generating analysis reports on attack conditions and intrusion paths within the vehicle 10 and notifying the TCU 100. The analysis reports may include, for example, information that can identify the attack path.
[0090] The Ethernet switch 102 receives frames sent from devices connected to the Ethernet 11 and transfers the frames to appropriate ports based on the frame contents, thereby enabling communication between devices. The Ethernet switch 103 similarly transfers frames connected to the Ethernet 12.
[0091] ECUs 104-111 communicate sensor information within vehicle 10 and control actuators within vehicle 10, implementing controls related to vehicle 10's driving. For example, ECUs 104 and 105, connected to Ethernet 11, are infotainment system ECUs that exchange image and audio data. CAN 13 is a network for the vehicle body systems, and ECUs 108, 109, and 110, connected to CAN 13, control vehicle body systems such as doors, windows, and seats. Ethernet 12 is a network for exchanging sensor information from external cameras and radars. ECU 106 is, for example, a radar ECU or a camera ECU, while ECU 107 receives sensor information and implements automated driving or driver assistance functions. CAN 14 is a network for communicating information from the vehicle's powertrain and chassis systems, and can communicate control information from ECU 107. ECU 111 is, for example, a steering ECU or an engine ECU.
[0092] [1.3 Structure of TCU100]
[0093] Figure 3 1 is a block diagram of the TCU 100 in this embodiment. The TCU 100 includes an external vehicle communication unit 1001 , an application unit 1002 , an internal vehicle communication unit 1003 , and safety sensor units 1004 and 1005 .
[0094] The external communication unit 1001 is a communication interface for wireless communication via the network 20, communicates with the server 30, and sends and receives information with the application unit 1002. The external communication unit 1001 also notifies the safety sensor unit 1005 that monitors communication on the external network of the communication content.
[0095] In the application unit 1002 , an application that transmits data to the in-vehicle network operates based on data received from an application for notifying the server 30 of information about the in-vehicle network or from the network 20. A plurality of applications may operate in the application unit 1002 .
[0096] The in-vehicle communication unit 1003 is connected to the Ethernet 11 and notifies the application unit 1002 of the received frame.
[0097] The security sensor unit 1004 is a host IDS (Intrusion Detection System) that monitors the behavior of the application unit 1002 to ensure that the application is not performing abnormal operations. For example, the host IDS monitors the application's CPU and memory resource usage, communication volume, communication destinations, and access permissions, ensuring that they fall within baseline values. To issue a security alert if abnormal behavior is detected, the security sensor unit 1004 requests the application unit 1002 to send a security alert. For example, the security sensor unit 1004 monitors the application unit 1002.
[0098] The security sensor unit 1005 is a network IDS that monitors whether any abnormal communications have occurred based on frames notified from the external communication unit 1001. For example, the network IDS detects abnormalities in data packet traffic, identifies suspicious communication destinations, and detects port scans. To issue a security alert if abnormal communications occur, the security sensor unit 1005 sends a request to the application unit 1002. The security sensor unit 1005 monitors the external communication unit 1001 and the application unit 1002, for example, information transmitted and received, such as frames.
[0099] [1.4 Structure of Central ECU 101]
[0100] Figure 4 This is a diagram showing the structure of the central ECU 101 in this embodiment. The central ECU 101 includes a communication unit 1101, an application unit 1102, an analysis engine unit 1103, a safety sensor unit 1104, a safety warning history storage unit 1105, and a vehicle event history storage unit 1106. Furthermore, the central ECU 101 functions as an intrusion path analysis device.
[0101] The communication unit 1101 is a communication interface for communicating via Ethernet 11, Ethernet 12, and CAN 13. It has the function of transmitting received information to the appropriate network (subnet) according to the communication content. The communication unit 1101 also exchanges information with the application unit 1102. The communication unit 1101 functions as a warning acquisition unit that receives safety warnings from each safety sensor unit.
[0102] Upon receiving a security warning, the application unit 1102 activates a monitoring application for notifying the analysis engine unit 1103 of the security warning, thereby notifying (outputting) the security warning to the analysis engine unit 1103. Furthermore, the application unit 1102 extracts vehicle events and notifies the analysis engine unit 1103 of the extracted vehicle events. Vehicle events in the ECU 104, etc., can also be obtained from an application unit in the ECU 104, etc., via the communication unit 1101. Vehicle events will be described later. A vehicle event is an example of an event.
[0103] The analysis engine unit 1103 analyzes the intrusion path of the attack based on the security warning, the history of vehicle events (an example of an event history), and the depth indicating the degree of intrusion of the attack assumed in the event of the security warning, and outputs an analysis report. For example, the analysis engine unit 1103 can also be said to analyze the intrusion path based on the security warning, generate an analysis report, and notify the application unit 1102. The analysis engine unit 1103 is an example of an intrusion path analysis unit, and the analysis report is an example of an analysis result.
[0104] The analysis engine unit 1103 also collects safety warnings received from the in-vehicle network and stores them in the safety warning history storage unit 1105. The analysis engine unit 1103 also receives information related to vehicle events from the application unit 1102 and stores it in the vehicle event history storage unit 1106.
[0105] The security sensor unit 1104 is a host IDS that monitors the behavior of applications in the central ECU 101 or a network IDS that monitors the communication content of the in-vehicle network. If abnormal behavior or abnormal communication is detected, it notifies the application unit 1102 of a security warning.
[0106] The security warning history record holding unit 1105 holds (stores) the security warnings received previously. Figure 10 ) will be described later.
[0107] The vehicle event history record holding unit 1106 holds (stores) the history of the vehicle event notified from the application unit 1102. Figure 11 ) will be described later.
[0108] [1.5 Structure diagram of Ethernet switch 102]
[0109] Figure 5 1 is a block diagram of the Ethernet switch 102 in this embodiment. The Ethernet switch 103 has the same structure, and therefore its description is omitted.
[0110] The Ethernet switch 102 includes a communication unit 1201 and a security sensor unit 1202 .
[0111] The communication unit 1201 has four physical ports connected to the TCU 100, ECU 104, ECU 105, and central ECU 101, and transmits frames according to the content of received frames. In addition, the communication unit 1201 monitors received frames and notifies the security sensor unit 1202 of the frames.
[0112] The security sensor unit 1202 is a network IDS that monitors frames notified from the communication unit 1201 and checks whether there is any unauthorized communication. If the security sensor unit 1202 determines that unauthorized communication is occurring, it generates a security alert and requests the communication unit 1201 to send the security alert.
[0113] [1.6 ECU 104 structure diagram]
[0114] Figure 6 1 is a block diagram of the ECU 104 in this embodiment. ECUs 105 to 111 also have the same structure, and therefore their description is omitted.
[0115] The ECU 104 includes a communication unit 1301 , an application unit 1302 , and a security sensor unit 1303 .
[0116] The communication unit 1301 is a communication interface that is connected to the Ethernet 11 and transmits and receives frames.
[0117] The application unit 1302 executes application programs such as reading sensor values from sensors connected to the ECU 104 and controlling actuators.
[0118] The security sensor unit 1303 is a host IDS that monitors the behavior of the application unit 1302 and detects security-related events such as access errors in diagnostic commands and failure to verify the message authentication code contained in frames. If the security sensor unit 1303 detects an abnormal security event, it generates a security alert and requests the communication unit 1301 to send the security alert.
[0119] [1.7 Server 30 Structure Diagram]
[0120] Figure 7 3 is a block diagram of the server 30 in this embodiment. The server 30 includes a communication unit 3001 , an application unit 3002 , and a UI (User Interface) unit 3003 .
[0121] The communication unit 3001 is a communication interface for wireless communication via the network 20 , receives an analysis report notified from the vehicle 10 , and notifies the application unit 3002 .
[0122] The application unit 3002 is an application that performs secondary analysis of a received analysis report and the like.
[0123] UI 3003 is a user interface that presents the received analysis report to the security analyst. Based on the presented analysis report, the security analyst confirms that an attack has occurred on vehicle 10 and decides on a response. UI 3003 may be implemented, for example, by a display device or a voice output device, but is not limited thereto.
[0124] [1.8 An example of a security warning]
[0125] Figure 8 This figure shows an example of a safety warning output by the safety sensor unit 1004 and the like in this embodiment. The safety warning includes fields for notifying the time when the safety warning was generated, the location where the safety warning was generated, at least one of the depth determined based on the monitoring object of the safety sensor, a warning number that is a serial number of the warning, a warning ID for identifying the type of warning, and detailed information of the warning. Figure 8 , an example of a depth determined by a monitoring target of a safety sensor, including a location where a safety warning is generated and a depth determined by a monitoring target of a safety sensor, is shown.
[0126] exist Figure 8 : shows an example of a security warning with the following contents: a security warning was generated at 11:50:20, with a depth of 5, a warning No. of 10001, and a warning ID of 0001. The warning details are that verification of the message authentication code of ID 100 failed.
[0127] The depth is set so that the value increases as the number of devices or networks passed through before access from the external network and external connection device increases, so that when the safety sensor monitors the external network, it is 1; when the first device having an external connection device interface such as a USB (Universal Serial Bus) port, two OBD (On-Board Diagnostics) ports, Bluetooth (registered trademark, the same applies hereinafter) is the monitored target, it is 2; when the first in-vehicle network connected to the first device is the monitored target, it is 3; when the second device connected to the first in-vehicle network other than the first device is the monitored target, it is 4; when the second in-vehicle network other than the first in-vehicle network connected to the second device is the monitored target, it is 5.
[0128] For example, it can also be: Figure 2 In the example, the depth of TCU 100 is set to 1, the depth of Ethernet switch 102 is set higher than that of TCU 100 (for example, a depth of 2), the depth of central ECU 101 is set higher than that of Ethernet switch 102 (for example, a depth of 3), the depth of Ethernet switch 103 is set higher than that of central ECU 101 (for example, a depth of 4), and the depth of ECUs 106 and 107 is set higher than that of Ethernet switch 103 (for example, a depth of 5). In this way, the depth can also be set for each device, for example. Furthermore, if the number of devices passing through TCU 100 is the same, such as ECUs 106 and 107, the depth can be set to the same value. The depth is pre-set, and each security sensor unit can also store information related to the depth. Depth is an example of intrusion depth.
[0129] In addition, the depth of the monitored object can also be determined by at least one of the physical number of paths and the logical number of paths of at least one of the sub-networks such as ECU104 and the gateway device (central ECU101 in this embodiment) that connects the sub-networks to each other from the device that is assumed to be initially attacked, such as the external connection device (such as TCU100), to the monitored object (such as the monitored object) of the safety sensor unit. In this embodiment, when the number of devices or networks that are physically passed through increases, the depth of the monitored object is set to increase. In addition, the depth may not be determined by the physical number of paths, but only by the logical number of paths, which is the physical number of paths and the logical number of paths.
[0130] For example, in the case where the in-vehicle network is composed of a virtual network, when the devices or networks are physically adjacent but logically separated, the depth can be determined as non-traversable. In addition, it is not necessary to consider the number of routes from the external connection device to the monitored object. For example, the depth can also be determined based on the security strength of each monitored object, the risk in the event of an attack, etc. The depth can also be set in a manner that increases in the case of a monitored object that is more difficult for an attacker to access or that poses a significant security risk due to an attack. In addition, a large depth indicates that the attack has progressed to a deeper state of the in-vehicle network system 10a.
[0131] Furthermore, the generation time of the safety warning may also be the count of a timer from the ignition of the vehicle being turned on. In addition, the safety warning may be sent in an encrypted manner or may include a message authentication code.
[0132] [1.9 An example of an analysis report]
[0133] Figure 9 This diagram shows an example of historical information included in the analysis report generated by the central ECU 101 in this embodiment. The historical information includes, for each depth, the time a security warning or vehicle event occurred, the warning ID or vehicle event, and an indicator signal that indicates the nature of the attack. In this embodiment, the historical information includes not only the history of security warnings but also the history of vehicle events. However, it is not essential for the historical information to include vehicle events.
[0134] exist Figure 9 The following shows that a security alert with a depth of 1 and an alert ID of 0011 (port scan detection) was generated at 11:45:10. The source IP address, which served as an indicator signal for an attack, was aaa.bbb.ccc.ddd. At depth 2, neither a security alert nor a vehicle event was observed. Furthermore, a security alert with a depth of 3 and an alert ID of 0010 (network IDS alert) was generated at 11:47:15. The attack indicator signal matched the signature ID 0x12345 in the network IDS. Furthermore, a vehicle event with a depth of 4, indicating an update of an application in central ECU 101, was generated at 11:48:30. The indicator signal was the hash value of the application, which was 0x56ab78cd90ef. Furthermore, a security alert with a depth of 5 and an alert ID of 0001 (message authentication code verification failure) was generated at 11:50:20. The indicator signal was the CAN ID 0x100. Furthermore, depths 6 to 8 indicate that neither a safety warning nor a vehicle event has occurred.
[0135] The central ECU 101 can also generate a safety warning record by, for example, reading one or more safety warnings (safety warning history) from the safety warning history storage unit 1105 and one or more vehicle events (vehicle event history) from the vehicle event history storage unit 1106, and arranging the read one or more safety warnings and one or more vehicle events in the order of their occurrence time. Figure 9 The central ECU 101 can also use the start of the attack path analysis process as a trigger to generate Figure 9 The history information shown.
[0136] exist Figure 9 In the example of , historical record information is shown when the depth increases with time, but it is also possible that the depth decreases with time, or a safety warning is generated at the same depth even after time has passed.
[0137] Furthermore, no security warning was generated at depth 2. This is presumably because the security sensor unit of the device corresponding to depth 2 (e.g., security sensor unit 1202 of Ethernet switch 102) overlooked the abnormal behavior. In this embodiment, historical information is transmitted to server 30, allowing security analysts to verify that the abnormal behavior was overlooked. Historical information is an example of information that can identify the intrusion path of an attack.
[0138] Furthermore, the depth of a vehicle event is pre-set. The depth of a vehicle event can be set based on the device that executed the vehicle event (e.g., based on the number of devices physically passed through from the TCU 100), or it can be the same as the depth used when the safety sensor of the device detects abnormal behavior. Furthermore, the depth of a vehicle event can also be set based on the content of the vehicle event. The depth of a vehicle event can also be stored by the central ECU 101, for example, but is not limited to this.
[0139] Furthermore, in this embodiment, the analysis report including the history information is notified in plain text, but may be notified in encrypted form or may include a message authentication code.
[0140] In addition, the analysis report may include information about the device or area (network) that became the entry point of the attack, information indicating the path of the intrusion (such as the invasion expanding as the depth increases, or the attack remaining localized), and information about warnings corresponding to the depth of the current attack. An example of the information included in the analysis report will be described later (see Figure 19 ).
[0141] [1.10 An example of security warning history]
[0142] Figure 10 This is a diagram showing an example of a security warning history stored in the security warning history storage unit 1105 in this embodiment. Figure 8 The receipt history of security warnings such as those shown.
[0143] exist Figure 10 The following shows a history of three security alerts received. The first security alert was generated at 11:45:10, with a depth of 1, an alert number of 23042, and an alert ID of 0011. The alert details include the source IP address of aaa.bbb.ccc.ddd. The second security alert was generated at 11:47:15, with a depth of 3, an alert number of 5000, and an alert ID of 0010. The alert details include the signature ID of 0x12345. The third alert was generated at 11:50:20, with a depth of 5, an alert number of 10001, and an alert ID of 0001. The alert details include a verification failure of the message authentication code with ID 100.
[0144] also, Figure 10 The security warning history shown may also include other kinds of warnings.
[0145] [1.11 An example of a vehicle event history record]
[0146] Figure 11 This figure shows an example of a vehicle event history record stored in the vehicle event history record storage unit 1106 in this embodiment. The vehicle event history record storage unit 1106 stores a history record of vehicle events (vehicle events) that indicate state changes within the vehicle 10, other than safety warnings. Vehicle events can be acquired based on frames flowing through the vehicle network or state changes within the ECU 104, etc. For example, vehicle events can also be acquired by the application unit 1102 based on frames flowing through the vehicle network or state changes within the ECU 104, etc. The application unit 1102 functions as an event acquisition unit that acquires vehicle events that occur within the vehicle network.
[0147] Examples of vehicle events include, but are not limited to, logging into a device within the vehicle network, completing the installation and update of an application or firmware installed on the device, completing firmware transfer, system diagnostics, and communication of fault codes. Other examples of vehicle events include the opening and closing status of a vehicle door lock, the change in the ignition switch's on / off state, the start of driving, the activation / deactivation of a driver assistance function, the transition to autonomous driving mode, the completion of a firmware update to an in-vehicle ECU, the completion of an application update or new installation, the start of diagnostic communications, and system login notifications.
[0148] Even if these vehicle events were normally completed, they may still be carried out as a result of an attacker disabling the safety function. Therefore, the vehicle event history storage unit 1106 stores even vehicle events that have been completed normally. The stored vehicle events are combined with other safety warnings to determine whether they have been abused by an attacker. Furthermore, the stored vehicle events are also used to analyze the circumstances under which safety warnings were generated.
[0149] For example, it is also possible that the safety warning is generated due to false detection by the safety sensor unit 1004 or a malfunction in a vehicle system. Therefore, the analysis engine unit 1103 can analyze the vehicle event and the occurrence of the safety warning together, filter out the safety warnings caused by the occurrence of vehicle events that are prone to false detection, and filter out the safety warnings caused by malfunctions, thereby improving the accuracy of the analysis report.
[0150] exist Figure 11 In the figure, as vehicle events, it is shown that at time 11:24:00, the vehicle is ignited and started, at 11:26:06, the vehicle starts driving, at 11:31:35 the automatic driving mode is started, and at 11:48:30, the update of the application of the central ECU 101 is completed.
[0151] In addition, the vehicle event history record keeping unit 1106 can also Figure 11 The vehicle event history shown is further maintained by associating the depth of each vehicle event.
[0152] [1.12 Sequence of Intrusion Path Analysis in Central ECU 101]
[0153] Figure 12 This is a diagram showing a first intrusion route analysis sequence in the central ECU 101 according to the present embodiment. Figure 12 The first intrusion route analysis sequence shown is a sequence diagram showing the first half of the intrusion route analysis sequence of the central ECU 101 .
[0154] (S101) The TCU 100 notifies a safety warning (depth 1).
[0155] ( S102 ) The central ECU 101 receives the safety warning and saves (stores) it in the safety warning history storage unit 1105 .
[0156] (S103) The Ethernet switch 102 notifies a security warning (depth 3).
[0157] ( S104 ) The central ECU 101 receives the safety warning and stores it in the safety warning history storage unit 1105 .
[0158] ( S105 ) The central ECU 101 updates the application program and stores the update completion status in the vehicle event history storage unit 1106 .
[0159] ( S106 ) The ECU 110 notifies a safety warning (depth 5 ).
[0160] ( S107 ) The central ECU 101 receives the safety warning and stores it in the safety warning history storage unit 1105 .
[0161] (S108) The central ECU 101 starts the analysis of the intrusion path. The central ECU 101 may also start the analysis of the intrusion path when receiving a security warning with a depth higher than a predetermined threshold (e.g. Figure 14 In the case of "YES" in step S203 shown in the figure) or at the regular notification timing ("YES" in step S208), analysis of the intrusion path is started.
[0162] The trigger for the central ECU 101 to start analyzing the intrusion path will be described later. In steps S101 , S103 , and S105 , the central ECU 101 is not notified of the indicator signal of the security warning (information that indicates an attack).
[0163] In addition, the collection of safety warnings and vehicle events continues until the following Figure 13 The action shown.
[0164] Figure 13 This is a diagram showing a second intrusion route analysis sequence in the central ECU 101 according to the present embodiment. Figure 13 The second intrusion route analysis sequence shown is a diagram showing the second half of the intrusion route analysis sequence of the central ECU 101 . Figure 13 The action shown is Figure 12 The actions shown are then performed.
[0165] ( S109 ) The central ECU 101 requests an indicator signal of a safety warning (depth 1 ).
[0166] ( S110 ) The TCU 100 receives the index signal request and notifies (transmits) information of the transmission source IP address of the index signal serving as the security warning (depth 1 ).
[0167] ( S111 ) The central ECU 101 requests an indicator signal of a safety warning (depth 3 ).
[0168] (S112) The Ethernet switch 102 receives the index signal request and notifies (transmits) the signature ID of the index signal that becomes the security warning (depth 3).
[0169] ( S113 ) The central ECU 101 requests an indicator signal of a safety warning (depth 5 ).
[0170] ( S114 ) The ECU 110 receives the indicator signal request and notifies the ECU 110 of the CAN ID of the indicator signal of the safety warning (depth 5 ).
[0171] ( S115 ) The central ECU 101 generates an analysis report based on the obtained information and notifies (transmits) the analysis report to the TCU 100 .
[0172] ( S116 ) The TCU 100 notifies (transmits) the server 30 of the analysis report notified from the central ECU 101 .
[0173] Furthermore, the order in which the central ECU 101 requests the indicator signal of the safety warning is not limited to the order in which the safety warning is received.
[0174] In addition, in this embodiment, the central ECU 101 requests the indicator signal for the security warning when analyzing the intrusion path, but it is not necessary to collect and process the indicator signal, and it may be requested when the security warning is notified ( Figure 12 S101, S103 and S106 shown include indicator signals.
[0175] [1.13 Analysis report notification flow chart in central ECU]
[0176] Figure 14 This is a flowchart of the process until the analysis report is notified in the central ECU 101 according to the present embodiment. Figure 14 This can also be considered as a flowchart for the central ECU 101 to generate an analysis report. The following processing is executed, for example, by the analysis engine unit 1103 of the central ECU 101. While the following describes an example of vehicle events used to generate an analysis report, the use of vehicle events is not essential.
[0177] The central ECU 101 determines whether a security warning has been received ( S201 ). If the central ECU 101 has received a security warning (YES in S201 ), it proceeds to step S202 . If the central ECU 101 has not received a security warning (NO in S201 ), it proceeds to step S206 .
[0178] Next, when receiving a security warning, the central ECU 101 updates the security warning history in the security warning history storage unit 1105 ( S202 ). The central ECU 101 adds the security warning received in step S201 to the security warning history.
[0179] Next, the central ECU 101 determines whether the depth of the received security alert exceeds a predetermined threshold (S203). The central ECU 101 performs step S203 each time it receives a security alert. If the depth of the received security alert is below the predetermined threshold ("No" in S203), the central ECU 101 terminates the analysis report generation process. Alternatively, if the depth of the received security alert exceeds the predetermined threshold ("Yes" in S203), the central ECU 101 proceeds to step S204.
[0180] Next, the central ECU 101 analyzes the attack path (S204). The analysis of the attack path will be described later.
[0181] Next, the central ECU 101 generates an analysis report based on the analysis result, notifies the server 30 of the generated analysis report ( S205 ), and ends the analysis report generation process.
[0182] If the central ECU 101 has not received a safety warning, it determines whether a vehicle event update has occurred (S206). The central ECU 101 confirms whether a frame related to a vehicle event update has been received, whether an application program in the central ECU 101 has been updated, and so on. If a vehicle event update has occurred ("Yes" in S206), the central ECU 101 updates the vehicle event history stored in the vehicle event history storage unit 1106 (S207), and the analysis report generation process ends. In other words, if "Yes" in step S206, the vehicle event is simply added to the vehicle event history record, and no analysis report is generated.
[0183] In addition, when there is no update of the vehicle event ("No" in S206), the central ECU 101 determines whether it is the regular notification timing of the analysis report (S208). In the case that it is not the regular notification timing ("No" in S208), the central ECU 101 ends the process of generating the analysis report. In addition, when it is the regular notification timing ("Yes" in S208), the central ECU 101 collects the indicator signal corresponding to the safety warning stored in the safety warning history storage unit 1105 (S209). In addition, when there is no safety warning history, the indicator signal may not be collected in step S209. In addition, the processing of step S209 is, for example, the same as Figure 13 The processing corresponds to steps S109 to S114 shown.
[0184] The central ECU 101 generates an analysis report based on the collected information ( S210 ), notifies the server 30 of the generated analysis report ( S211 ), and terminates the analysis report generation process.
[0185] [1.14 Intrusion Path Analysis Flowchart in Central ECU 101]
[0186] Figure 15 Yes Figure 14 Detailed flowchart of step S204. Figure 15 The flowchart shown is executed when the depth of the security warning received in step S201 is greater than a predetermined threshold.
[0187] The central ECU 101 checks (determines) whether other types of security alerts are stored in the security alert history storage unit 1105 (S1201). For example, the central ECU 101 may perform the check in step S1201 based on whether the security alert history storage unit 1105 stores security alerts received within a predetermined period, based on the time at which the security alert was received in step S201. Other types of security alerts refer to security alerts that differ in at least one of the depth and alert ID contained in the security alert.
[0188] When there is no other type of safety warning ("No" in S1201), the central ECU 101 executes step S1210.
[0189] If another type of safety warning exists ("YES" in S1201), the central ECU 101 checks whether a vehicle event has occurred during the time period in which the safety warning was generated (e.g., from the time of the oldest safety warning recorded in the safety warning history to the present time) (S1202). If "YES" is determined in step S1201, the other type of safety warning includes two or more warnings of different types.
[0190] When no vehicle event has occurred ("No" in S1202), the central ECU 101 executes step S1205.
[0191] Furthermore, if a vehicle event occurs ("YES" in S1202), the central ECU 101 checks whether the depth of the safety warning has changed before and after the vehicle event (e.g., a previously unobserved depth has been observed) (S1203). For example, the central ECU 101 determines that the depth has changed if the depth of the safety warning increases or decreases before and after the vehicle event. Alternatively, the central ECU 101 may determine that the depth of the safety warning has changed in step S1203 if the change in the depth of the safety warning before and after the vehicle event exceeds a predetermined value.
[0192] Thus, when multiple other types of security alerts are detected, central ECU 101 determines whether the vehicle event was caused by an attack based on the temporal changes in the depth of the multiple security alerts and the vehicle events that occurred during the time period when the multiple security alerts were detected. For example, central ECU 101 determines that the vehicle event was caused by an attack if the occurrence distribution (temporal distribution) of the depth changes around the time of the occurrence of a vehicle event included in the vehicle event history.
[0193] When the depth of the safety warning has not changed (No in S1203 ), the central ECU 101 executes step S1209 .
[0194] If the depth of the safety warning changes ("Yes" in S1203), the central ECU 101 determines that the corresponding vehicle event is an abnormal vehicle event caused by an attack (S1204). In addition, the vehicle event can also be said to be a vehicle event related to the safety warnings before and after the occurrence of the vehicle event.
[0195] Next, the central ECU 101 checks whether the depth of the safety warning increases as the time of the safety warning stored in the safety warning history storage unit 1105 becomes later (S1205). In other words, the central ECU 101 determines whether the depth of the safety warning increases from the past to the present. In this case, the depth of the safety warning does not necessarily have to increase monotonically. For example, the central ECU 101 may determine that the depth of the safety warning increases if the order of the first observed safety warning at each depth is increasing. For example, if the depth of the safety warning history is arranged in order of the time of the safety warning, as 1, 2, 1, 2, 3, 2, 1, 3, 1, 4, the order of the first observed safety warning at each depth is 1, 2, 3, 4, and therefore the central ECU 101 determines that the depth increases with time.
[0196] When the depth of the safety warning increases with time (eg, is on an increasing trend) (YES in S1205 ), the central ECU 101 determines that the intrusion is expanding ( S1206 ) and executes step S1213 .
[0197] If the severity of the safety warning does not increase with the passage of time (No in S1205 ), the central ECU 101 executes step S1207 .
[0198] Next, the central ECU 101 checks whether the depth of the security warning has decreased over time (S1207). If the depth of the security warning has decreased over time ("YES" in S1207), the central ECU 101 determines that an unauthorized device is connected to the vehicle 10, indicating that the attack is occurring from a deeper location (S1208), and executes step S1213. For example, if the central ECU 101 does not detect an abnormality in a device with a lower depth of security warning, such as the TCU 100 or Ethernet switch 102, but suddenly detects an abnormality in a device with a higher depth of security warning, such as the ECU 111, the central ECU 101 determines that an unauthorized device is connected to the ECU 111, and that the attack is originating from the EUC 111.
[0199] If the depth of the security warning does not decrease with time (No in S1207 ), that is, if the depth of the security warning remains constant, the central ECU 101 determines that the attack occurrence status has not changed ( S1209 ) and executes step S1213 .
[0200] If no other safety warnings exist, for example, if there is only one safety warning, the central ECU 101 checks the vehicle event history storage unit 1106 to see if there was a vehicle event immediately prior to the safety warning being received (S1210). The determination in step S1210 is to determine whether there is a vehicle event related to the received safety warning.
[0201] In this case, when there is a vehicle incident in the recent period of receiving the safety warning, it is determined that the received safety warning is associated with the vehicle incident. In addition, the recent period is preset, for example, several minutes, tens of minutes, etc., but is not limited to this.
[0202] Next, if a vehicle event is present ("YES" in S1210), central ECU 101 determines the corresponding vehicle event as an abnormal vehicle event caused by an attacker (S1211) and executes step S1213. In other words, as part of the intrusion path analysis, central ECU 101 may also determine that a vehicle event associated with a security warning is caused by an attack.
[0203] If no vehicle event occurs ("No" in S1210), the central ECU 101 determines the security alert as either an intrusion caused by physical access, a malfunction, or a false detection (e.g., a false detection due to a malfunction, etc.) (S1212), and then proceeds to step S1213. Alternatively, if "No" in step S1210, the central ECU 101 may terminate the intrusion path analysis process.
[0204] Next, the central ECU 101 collects the indicator signals corresponding to the security warnings stored in the security warning history storage unit 1105 (S1213), generates an analysis report after the collection (S1214), and ends the process of analyzing the intrusion path. The process of generating the analysis report will be described later (see the following). Figure 17 ). In addition, the processing of step S1213 is, for example, Figure 13 The processing corresponds to steps S109 to S114 shown.
[0205] As described above, as part of the intrusion path analysis, the central ECU 101 may determine that the intrusion is expanding if the severity of the security warning increases over time, that the intrusion is caused by an unauthorized device if the severity of the security warning decreases over time, and that the intrusion is unchanged if the severity of the security warning remains unchanged over time. Furthermore, the central ECU 101 may include the determination results in an analysis report and output it.
[0206] This allows the security analyst to be informed of the current intrusion status, and thus the intrusion status can be utilized in the security analyst's attack analysis.
[0207] Alternatively, the determination in step S1210 may be omitted. In this case, as part of the intrusion path analysis, the central ECU 101 may determine that the intrusion is caused by physical access or a false detection if no other security warnings exist, that is, if there is only one security warning and the depth of the security warning exceeds a predetermined threshold.
[0208] [1.15 Effects of Implementation]
[0209] The central ECU 101 (an example of an intrusion path analysis device) in this embodiment collects security alerts notified by the security sensor unit 1004 and other devices installed in the vehicle 10. Using the depth of the collected security alerts, which is determined based on the monitoring targets of the security sensor unit 1004 and other devices, and the time of the security alert generation, it generates and distributes an analysis report that identifies the intrusion path of the attack. This allows the server 30 to provide security analysts with a detailed analysis report, enabling them to quickly understand and respond to the attack's occurrence, entry points, and other factors.
[0210] Furthermore, by analyzing both vehicle events and security warnings in the analysis engine unit 1103, even if a vehicle event completes normally, it can be determined whether it has been abused by an attacker. This allows the impact of attacks that cannot be detected by the security sensor unit 1004, etc. to be understood, allowing security analysts to better understand the overall attack situation and take appropriate countermeasures.
[0211] [Other modifications]
[0212] Furthermore, although the present disclosure has been described based on the above-mentioned embodiments, the present disclosure is not limited to the above-mentioned embodiments, and the following cases are also included in the present disclosure.
[0213] (1) In the above embodiment, an example using CAN and Ethernet (registered trademark) is shown as the in-vehicle network, but the present invention is not limited thereto and may use CAN-FD, Ethernet, LIN, FlexRay, or a combination of these.
[0214] (2) In the above embodiment, the intrusion path analysis is performed on the central ECU 101. However, the analysis may not be performed on the central ECU 101. For example, the analysis may be performed on the head unit or TCU 100, or the analysis may be performed on the server 30 by notifying the server 30 of a security warning. In other words, the functions of the analysis engine unit 1103 may be separated between the server 30 and the vehicle 10. Furthermore, if the analysis engine unit 1103 is provided on the server 30, the analysis engine unit 1103 and the vehicle network are connected in a communicative manner (e.g., a wireless communication manner).
[0215] (3) In the above embodiment, the security sensor unit 1004 and the like are shown as detecting network IDS, host IDS, or message authentication code verification failures. However, the anomalies detected by the security sensor unit are not limited to these. For example, diagnostic security access failures, SSH login failures, firewall filtering results, and update verification failures may also be used as detection results of the security sensor unit 1004 and the like. Furthermore, the configuration method of the security sensor unit is not limited to this embodiment and can be freely configured.
[0216] (4) In the above embodiment, the security warning includes depth, but it does not necessarily need to include depth. The security warning only needs to include information that allows the analysis engine unit 1103 to understand the monitoring target of the security sensor unit 1004 and other units and calculate the depth.
[0217] Figure 16 FIG. 1 is a diagram showing an example of a configuration database of a safety sensor in this modification. Figure 16 As shown, the analysis engine unit 1103 holds a database of the configuration of the security sensors. The analysis engine unit 1103 may be configured to be able to grasp (eg, calculate) the depth based on the warning ID and source information included in the security warning.
[0218] exist Figure 16In this example, the depth of the security alert output from the network IDS configured in TCU 100 is 1, and the depth of the security alert output from the host IDS also configured in TCU 100 is 2. In this way, even for security sensor units installed in the same device, different depths can be set depending on the security sensor unit's monitoring target. Furthermore, the depth of the security alert output from the network IDS configured in Ethernet switch 102 is 3, and the depth of the security alert output from the host IDS configured in central ECU 101 is 4. Furthermore, the depth of the security alert output based on the verification results of the message authentication code configured in central ECU 101, ECUs 108, 109, and 110 is 5, and the depth of the security alert output from the network IDS configured in Ethernet switch 103 is 6. Furthermore, the depth of the security alert output from the host IDS configured in ECU 107 is 7, and the depth of the security alert output from the network IDS configured in ECU 107 is 8.
[0219] (5) In the above embodiment, an example is shown in which one of the external connection devices is TCU 100. However, the external connection device is not limited to one. For example, a head unit or an OBD port having a Bluetooth or USB connection interface may also be present. In this case, the depth of the monitoring target of the safety sensor unit 1004 and the like will vary depending on which external connection device is viewed from. However, the depth may be calculated for each external connection device and the smallest value may be adopted as the depth.
[0220] (6) In the above embodiment, the analysis report is notified from the TCU 100 to the server 30. However, the method of notifying the server 30 is not limited to that via the TCU 100. For example, the central ECU 101 may include a communication interface for wireless communication via a mobile phone network and directly notify the server 30 of the analysis report. Alternatively, the central ECU 101 may store the analysis report internally as a log, rather than notifying the server 30, so that the log can be read out using a diagnostic command or the like.
[0221] (7) In the above embodiment, the central ECU 101 notifies the analysis report at regular intervals. However, the analysis report may not be notified at regular intervals. This is effective in reducing the amount of communication with the server 30.
[0222] (8) In the above embodiment, the central ECU 101 performs an intrusion path analysis and an analysis report notification when receiving a security warning whose depth exceeds a predetermined threshold. However, if the same security warning exists in the security warning history, the intrusion path analysis and the analysis report notification have already been performed, and therefore, these steps can be omitted. This is effective in reducing resource consumption of the central ECU and reducing the amount of communication with the server 30.
[0223] (9) In the above embodiment, the security warning history storage unit 1105 and the vehicle event history storage unit 1106 store the history of received security warnings and vehicle events. However, the history of security warnings and vehicle events may be deleted after a predetermined period of time. This can eliminate the influence of security warnings or vehicle events unrelated to the recent attack activity from the analysis of the intrusion path, which is effective in improving the accuracy of the analysis report.
[0224] (10) In the above embodiment, the central ECU 101 merely issues an analysis report without taking any action within the vehicle 10. However, the central ECU 101 may issue a warning based on the intrusion situation and, based on the warning, perform a provisional action within the vehicle 10. This can prevent the attack from escalating further, effectively improving safety.
[0225] Figure 17 The flowchart for determining the response according to the intrusion path analysis result by the central ECU 101 in this modification is shown. Figure 17 In the flowchart shown, use Figure 15 The judgment results of steps S1206, S1208 and S1209 shown above determine the attack entry point and response. Figure 17 The processing up to steps S1301 to S1307 shown is processing for determining an attack entry point.
[0226] Central ECU 101 confirms (judgments) Figure 15 The central ECU 101 determines whether the intrusion path analysis in step S1206 indicates an intrusion expansion state (S1301). If the central ECU 101 has performed the determination in step S1206, the determination in step S1301 is yes; if the determination in step S1206 has not been performed, the determination in step S1301 is no.
[0227] If the central ECU 101 determines that the attack is expanding (S1301: Yes), it determines that the attack entry point is the area (e.g., the area around the monitoring target area of the security sensor unit 1104, etc.) with the minimum depth in the security warning stored in the security warning history storage unit 1105 as the attack entry point (S1302), and then executes step S1308. Alternatively, the central ECU 101 may determine in step S1302 that the maximum depth in the security warning stored in the security warning history storage unit 1105 is the current attack intrusion depth. In this case, the depth of the attack entry point and the attack intrusion depth are different.
[0228] If the central ECU 101 is not in the invasion expansion state (S1301: No), it checks whether the attack is caused by an abnormal internal device connection (S1303). If the central ECU 101 has performed the determination in step S1208, the determination in step S1303 is Yes. If the determination in step S1208 has not been performed, the determination in step S1303 is No.
[0229] If the attack is caused by an abnormal internal device connection (S1303: Yes), the central ECU 101 determines that the attack entry point is within the maximum depth of the security warning stored in the security warning history storage unit 1105 (S1304) and executes step S1308. Alternatively, the central ECU 101 may determine in step S1304 that the maximum depth of the security warning stored in the security warning history storage unit 1105 is the attack penetration depth. In this case, the depth of the attack entry point is consistent with the attack penetration depth.
[0230] If the central ECU 101 is not affected by an attack due to an abnormal internal device connection (S1303: No), it checks whether the attack status has not changed (S1305). If the central ECU 101 has performed the determination in step S1209, the determination in step S1305 is Yes. If the central ECU 101 has not performed the determination in step S1209, the determination in step S1305 is No.
[0231] If the attack status has not changed (S1305: Yes), the central ECU 101 determines that the attack entry point is the area at each depth of the security warning stored in the security warning history storage unit 1105 (S1306), and then executes step S1308. Alternatively, in step S1306, the central ECU 101 may determine that each depth (the same depth) is the attack penetration depth because the depths of the security warnings stored in the security warning history storage unit 1105 are the same. In this case, the attack entry point and the attack penetration depth are consistent.
[0232] If the attack situation does not remain unchanged (S1305: No), that is, if the attack situation has changed, the central ECU 101 determines that the depth of the security warning stored in the security warning history storage unit 1105 is the attack entry point and the intrusion depth (S1307), and then executes step S1308. In step S1307, the central ECU 101 determines that the attack entry point is within the warning depth. Alternatively, if the answer in step S1305 is "No," the central ECU 101 may not perform the attack entry point determination process. In other words, if the answer in step S1305 is "No," the central ECU 101 may not issue a warning.
[0233] In this manner, the central ECU 101 can analyze the intrusion path, for example, by determining that the attack entry point is the area with the smallest depth if the intrusion is expanding, the attack entry point is the area with the largest depth if the intrusion is caused by a malfunctioning device, and the attack entry point is the area with the same depth if the intrusion is unchanged. Furthermore, the central ECU 101 can include the determination results in an analysis report and output it.
[0234] Thus, the central ECU 101 can help security analysts understand the attack entry point. The security analyst can understand the attack path and intrusion method from the analysis report, and can obtain information useful for studying countermeasures.
[0235] Next, the central ECU 101 issues a warning corresponding to the depth of the intrusion to the target ECU 104, etc. (S1308). For example, the central ECU 101 may also perform at least one of the following: strengthening the monitoring function of at least one of the one or more ECUs 104, etc. and TCU 100, or limiting the function of at least one of the one or more ECUs 104, etc. and TCU 100, depending on the depth of the security warning. The decision and execution of the warning are executed before receiving the information indicating the response from the server 30. For example, the decision and execution of the warning may also be executed before sending the analysis report to the server 30. In addition, using Figure 18 An example of a warning is given.
[0236] Next, the central ECU 101 generates an analysis report (S1309) including the attack entry point and intrusion path information (intrusion expansion, spread of attack impact caused by internal abnormal device connection, no change in attack status, physical access or false detection). Figure 19 An example of an analysis report is described.
[0237] Figure 18 This is a diagram showing an example of the relationship between the target ECUs to call attention to and the responses of each ECU according to the depth of the safety warning in this modification.
[0238] exist Figure 18 The figure shows that when the depth (intrusion depth) is 1 or 2, the target ECU to be alerted is TCU 100, and the monitoring function of TCU 100 is enhanced. For example, the enhancement of the monitoring function can be enhanced by the network IDS from monitoring only the header information of received data packets to monitoring the payload information.
[0239] Furthermore, in cases where the penetration depth is 3 or 4, the target ECUs receiving the warning are the TCU 100, Ethernet switch 102, ECU 104, ECU 105, and central ECU 101. These ECUs restrict firmware and application updates to prevent further expansion of the attack. This is an example of partially disabling the functions of the in-vehicle network system 10a.
[0240] Furthermore, when the intrusion depth is 5 or 6, the target ECUs to be alerted are ECU 106 , ECU 107 , ECU 108 , ECU 109 , ECU 110 , Ethernet switch 103 , and central ECU 101 , and the monitoring function should be enhanced.
[0241] Furthermore, when the intrusion depth is 7 or 8, the ECUs receiving the warning are ECU 107 and ECU 111, and the response is to restrict the autonomous driving function. At intrusion depths of 7 or 8, the intrusion depth has increased, and the risk of affecting vehicle control is high. Therefore, by restricting the autonomous driving function, which has a high potential for abuse and improper vehicle control, damage is minimized. This is an example of partially disabling the functions of the in-vehicle network system 10a.
[0242] In this manner, the central ECU 101 may disable certain functions of the in-vehicle network system 10a if it determines that the intrusion is expanding and the maximum depth among the depths of the detected security warnings is greater than a predetermined threshold. Furthermore, the central ECU 101 may strengthen the monitoring function of certain devices in the in-vehicle network system 10a if it determines that the intrusion is expanding and the maximum depth among the depths of the detected security warnings is greater than a predetermined threshold. Furthermore, the central ECU 101 may output a notification indicating that certain functions of the in-vehicle network system 10a are disabled or that the monitoring function of certain devices in the in-vehicle network system 10a is strengthened.
[0243] Figure 19 This is a diagram showing an example of an analysis report in this modification.
[0244] The analysis report includes, for example, Figure 9 The historical information and entry points of the attack are shown. Figure 19shows an example where the device corresponding to depth 1 is the entry point. Furthermore, the analysis report only needs to include at least one of the attack entry point, the attack penetration depth, and historical record information. Furthermore, the analysis report may also include information related to the determined response (information indicating any one of monitoring function enhancements, update restrictions, monitoring function enhancements, and autonomous driving function restrictions). Furthermore, the analysis report may also include information indicating the estimated results of the ECU that is likely to generate a security warning next. The information indicating the estimated results may, for example, be information indicating the ECU directly connected to the device that most recently generated a security warning in the historical record information. Furthermore, as information indicating the extent of the attack, the analysis report may include both the depth of the most recent security warning and information indicating which phase of the seven phases of the Cyber Kill Chain the current situation is. The analysis report containing such information is generated by the central ECU 101.
[0245] (11) The analysis report in the above embodiment may also be output as threat intelligence. For example, the analysis report may be output in STIX (Structured Threat Information eXpression) format. This allows analysis reports to be used in a common format, enabling highly interchangeable information to be exchanged, which is effective.
[0246] (12) In the above embodiment, the central ECU 101 outputs an analysis report that determines the attack path. However, the central ECU 101 may also output a result obtained by matching the attack path with threat intelligence. For example, the central ECU 101 may maintain a threat database and determine the attack content when the number of matches of indicator signals included in the threat intelligence maintained in the threat database exceeds a predetermined threshold. Figure 20 An example of the threat database held by the central ECU 101 in this modification is shown.
[0247] exist Figure 20The metric stores three threat information items, each with its own indicator signal. The indicator signal for Threat A indicates that the source IP address is aaa.bbb.ccc.ddd, the firmware hash value is 0x56ab78cd90ef, and the CAN IDs are 0x100, 0x110, and 0x200. The indicator signal for Threat B indicates that the source IP address is www.xxx.yyy.zzz, the firmware hash value is 0x1234567890ab, and the CAN IDs are 0x50 and 0x70. The indicator signal for Threat C indicates that the source IP address is iii.jjj.kkk.lll, and the Ethernet frame value is 0xabcdef112233445566778899.
[0248] (13) Specifically, the device in the above-mentioned embodiment is a computer system composed of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is recorded in the RAM or hard disk unit. The microprocessor operates according to the computer program, and each device realizes its function. Here, the computer program is composed of a combination of multiple command codes representing instructions to the computer in order to realize a predetermined function.
[0249] (14) Each device in the above-described embodiment may be configured such that some or all of the components are formed by a single system LSI (Large Scale Integration). A system LSI is a highly multifunctional LSI manufactured by integrating multiple components on a single chip. Specifically, it is a computer system composed of a microprocessor, ROM, RAM, etc. Computer programs are stored in the RAM. The microprocessor operates according to the computer program, and the system LSI realizes its functions.
[0250] Furthermore, each component constituting each of the above-mentioned devices may be individually integrated into a single chip, or a part or all of the components may be integrated into a single chip.
[0251] Although referred to here as a system LSI, it is sometimes referred to as an IC, LSI, ultra-LSI, or very-LSI depending on the degree of integration. Furthermore, integrated circuitry is not limited to LSIs and can also be implemented using dedicated circuits or general-purpose processors. Alternatively, an FPGA (Field Programmable Gate Array) that can be programmed after LSI manufacturing or a reconfigurable processor that can reconfigure the connections and settings of circuit cells within the LSI can be used.
[0252] Furthermore, if integrated circuit technology that replaces LSIs emerges due to advances in semiconductor technology or other derived technologies, it is natural that this technology can also be used to integrate functional blocks.
[0253] (15) Some or all of the components of each of the above-mentioned devices may be composed of an IC card or a single module that can be detached from each device. The IC card or module is a computer system composed of a microprocessor, ROM, RAM, etc. The IC card or module may also include the above-mentioned ultra-multifunctional LSI. The IC card or module realizes its functions by the microprocessor operating according to the computer program. The IC card or module may also be tamper-resistant.
[0254] (16) The present disclosure may also be the methods shown above. In addition, the present disclosure may be a computer program that implements these methods on a computer, or a digital signal composed of the computer program.
[0255] Furthermore, the present disclosure may be recorded on a computer program or digital signal recording medium capable of being read by a computer, such as a floppy disk, hard disk, CD-ROM, MO, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray (registered trademark) disc), semiconductor memory, etc. Furthermore, the digital signal recorded on these recording media may also be used.
[0256] Furthermore, the present disclosure may be implemented by transmitting a computer program or a digital signal via a telecommunication line, a wireless or wired communication line, a network represented by the Internet, data broadcasting, or the like.
[0257] Furthermore, the present disclosure may be a computer system including a microprocessor and a memory, wherein the memory stores the computer program and the microprocessor operates according to the computer program.
[0258] Alternatively, the program or digital signal may be recorded on a recording medium and transferred, or may be transferred via a network or the like so that the program or digital signal can be executed by another independent computer system.
[0259] (17) In addition, in the above embodiment, the control network system is described as an example of the vehicle-mounted network system 10a, but the present invention is not limited to this. The control network system as the target of the intrusion path analysis device for analyzing the intrusion path may be a network system built in a home, a network system built in a factory or an enterprise, or a mobile network system installed in an aircraft (e.g., an airplane, a drone, etc.) or a train.
[0260] (18) The division of functional blocks in the structural diagram is merely an example. It is also possible to implement multiple functional blocks as a single functional block, divide a functional block into multiple blocks, or transfer some functions to other functional blocks. Furthermore, it is also possible for a single piece of hardware or software to process the functions of multiple functional blocks with similar functions in parallel or in a time-sharing manner.
[0261] (19) The order of the multiple processes described in the above embodiment is an example. The order of the multiple processes may be changed, and the multiple processes may be executed in parallel. In addition, some of the multiple processes may not be executed.
[0262] (20) In addition, the security sensor unit 1004 in the above-mentioned embodiment is implemented by any one of a network intrusion detection system that detects signs of intrusion from network traffic, a host intrusion detection system that detects signs of intrusion from abnormal behavior on one or more ECUs 104, an abnormal data packet detection system of a firewall configured in the vehicle network system 10a, a login failure detection sensor, a signature verification failure detection sensor, a message authentication code verification failure detection sensor contained in a message on the network, and a security access failure detection sensor, but is not limited to these.
[0263] (21) The above-mentioned embodiment and the above-mentioned modification examples may be combined.
[0264] Industrial applicability
[0265] The present disclosure can determine an attacker's intrusion path by analyzing security warnings notified from multiple security sensors configured in the vehicle network, and is effective in understanding the status of attack activities on the vehicle network system.
[0266] Description of labels
[0267] 1. Vehicle Network Monitoring System
[0268] 10 vehicles
[0269] 10a Vehicle network system (control network system)
[0270] 11.12 Ethernet
[0271] 13, 14 CAN
[0272] 20 Network
[0273] 30 servers
[0274] 100 TCU
[0275] 101 Central ECU (Intrusion Path Analysis Unit)
[0276] 102, 103 Ethernet switches
[0277] 104, 105, 106, 107, 108, 109, 110, 111 ECU
[0278] 1001 External Communication Department
[0279] 1002, 1102, 1302, 3002 Application Department
[0280] 1003 In-vehicle Communication Department
[0281] 1004, 1005, 1104, 1202, 1303 Safety sensor unit (safety sensor)
[0282] 1101, 1201, 1301, 3001 Communications Department
[0283] 1103 Analytical Engine Department
[0284] 1105 Safety Warning History Recording Unit
[0285] 1106 Vehicle event history record keeping unit
[0286] 3003 UI Department
Claims
1. An intrusion path analysis device connected to a control network system in a communicable manner, wherein the control network system is connected to one or more electronic control devices and communication devices, The control network system is provided with one or more security sensors, and when the security sensors detect a sign of a security violation on at least one of the one or more electronic control devices and the communication device on the network, the security sensors transmit a security warning including a status indicating that the sign of the security violation has been detected to the network. The intrusion path analysis device comprises: a warning acquisition unit configured to acquire the safety warning from the one or more safety sensors; an event acquisition unit that acquires an event history record of an event generated in the control network system; and an intrusion path analysis unit that analyzes the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputs the analysis result; As the analysis, the intrusion path analysis unit, when there are multiple security warnings, determines whether the event is an event caused by the attack based on the time changes of the intrusion depth of multiple security warnings and the events generated in the time period when multiple security warnings are detected.
2. An intrusion path analysis device connected to a control network system in a communicative manner, wherein the control network system is connected to one or more electronic control devices and communication devices, The control network system is provided with one or more security sensors, and when the security sensors detect a sign of a security violation on at least one of the one or more electronic control devices and the communication device on the network, the security sensors transmit a security warning including a status indicating that the sign of the security violation has been detected to the network. The intrusion path analysis device comprises: a warning acquisition unit configured to acquire the safety warning from the one or more safety sensors; an event acquisition unit that acquires an event history record of an event generated in the control network system; and an intrusion path analysis unit that analyzes the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputs the analysis result; As the analysis, the intrusion path analysis unit determines that the event is caused by an attack when the occurrence distribution of the intrusion depth changes before and after the occurrence time of the event included in the event history record.
3. The intrusion path analysis device according to claim 1 or 2, The control network system is composed of more than two sub-networks. The communication device is configured on at least one of the two or more sub-networks and is a device for communicating with a network or device outside the control network system. The intrusion depth is determined by the number of physical or logical paths from the communication device to the monitoring object of the safety sensor, including the one or more electronic control devices, the two or more subnetworks, and at least one gateway device connecting the two or more subnetworks to each other.
4. The intrusion path analysis device according to claim 1 or 2, As the analysis, the intrusion path analysis unit judges that the intrusion situation is an expansion of the intrusion when the intrusion depth of the security warning increases with the passage of time; judges that the intrusion situation is an attack caused by an abnormal device when the intrusion depth of the security warning decreases with the passage of time; and judges that the intrusion situation is no change when the intrusion depth of the security warning does not change with the passage of time.
5. The intrusion path analysis device according to claim 4, As the analysis, the intrusion path analysis unit further judges the entry point of the attack to be the area with the smallest intrusion depth when the intrusion condition is that the intrusion is expanding; judges the entry point of the attack to be the area with the largest intrusion depth when the intrusion condition is that the intrusion is caused by the abnormal device; and judges the entry point of the attack to be the area with the same intrusion depth when the intrusion condition is that there is no change.
6. The intrusion path analysis device according to claim 1 or 2, As the analysis, the intrusion path analysis unit further determines that the intrusion is caused by physical access or false detection when there is only one security warning and the intrusion depth of the security warning is higher than a predetermined threshold.
7. The intrusion path analysis device according to claim 6, As the analysis, when the event associated with the security warning exists, the intrusion path analysis unit further determines that the event is an event caused by the attack.
8. The intrusion path analysis device according to any one of claims 1, 2, 5, and 7, The intrusion path analysis unit performs at least one of strengthening the monitoring function of at least one of the one or more electronic control devices and the communication device and limiting the function of at least one of the one or more electronic control devices and the communication device according to the intrusion depth of the security warning.
9. The intrusion path analysis device according to claim 8, The intrusion path analysis unit outputs a notification to disable a portion of the functions of the control network system when determining that the intrusion status is an expanding intrusion and the maximum intrusion depth among the detected intrusion depths of the security warning is equal to or greater than a predetermined threshold.
10. The intrusion path analysis device according to any one of claims 1, 2, 5, 7, and 9, The analysis result includes at least one of the entry point of the attack, the intrusion depth of the attack, and history information including one or more security warnings and event history records.
11. The intrusion path analysis device according to any one of claims 1, 2, 5, 7, and 9, The event includes at least one of login to a device configured in the control network system, completion of installation and update of an application or firmware installed in the device, completion of firmware transfer, system diagnosis, and communication of a fault code.
12. The intrusion path analysis device according to any one of claims 1, 2, 5, 7, and 9, The security sensor includes a network intrusion detection system that detects signs of intrusion from network traffic, a host intrusion detection system that detects signs of intrusion from abnormal behavior on one or more electronic control devices, an abnormal data packet detection system of a firewall configured in the control network system, a login failure detection sensor, a signature verification failure detection sensor, a message authentication code verification failure detection sensor contained in a message on the network, and at least one of a security access failure detection sensor.
13. The intrusion path analysis device according to any one of claims 1, 2, 5, 7, and 9, The control network system is an in-vehicle network system.
14. An intrusion path analysis method for a control network system connected to one or more electronic control devices and communication devices. The control network system is provided with one or more security sensors, and when the security sensors detect a sign of a security violation on at least one of the one or more electronic control devices and the communication device on the network, the security sensors transmit a security warning including a status indicating that the sign of the security violation has been detected to the network. The intrusion path analysis method includes: The step of obtaining the safety warning from the one or more safety sensors; The step of obtaining an event history record of events generated in the control network system; as well as an intrusion path analysis step of analyzing the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputting the analysis result; As the analysis, in the intrusion path analysis step, when there are multiple security warnings, based on the time changes of the intrusion depth of multiple security warnings and the events generated in the time period when multiple security warnings are detected, it is determined whether the event is an event caused by the attack.
15. An intrusion path analysis method for a control network system connected to one or more electronic control devices and communication devices. The control network system is provided with one or more security sensors, and when the security sensors detect a sign of a security violation on at least one of the one or more electronic control devices and the communication device on the network, the security sensors transmit a security warning including a status indicating that the sign of the security violation has been detected to the network. The intrusion path analysis method includes: The step of obtaining the safety warning from the one or more safety sensors; The step of obtaining an event history record of events generated in the control network system; as well as an intrusion path analysis step of analyzing the intrusion path of the attack based on the security warning, the event history record, and the intrusion depth indicating the degree of intrusion of the attack assumed when the security warning is generated, and outputting the analysis result; As the analysis, in the intrusion path analysis step, when the occurrence distribution of the intrusion depth changes before and after the occurrence time of the event included in the event history record, the event is determined to be an event caused by an attack.
Citation Information
Patent Citations
Electronic control device, unauthorized use detection server, vehicle-mounted network system, vehicle-mounted network monitoring system, and vehicle-mounted network monitoring method
CN110226310A
System for vehicle and control method
JP2019125344A