Relay device and relay method
By combining whitelists and machine learning models in relay devices, the problem of excessive detection rules in whitelist-based attack detection is solved, achieving cost control and performance improvement.
Patent Information
- Application Number
- CN202080091166.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-15
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2040-01-15
AI Technical Summary
Existing whitelist-based attack detection methods require designing numerous detection rules for groups with minimal movement, leading to increased production costs and performance degradation.
A relay device is used to detect whitelist-based attacks. The whitelist is used to identify normal groups, and groups that do not meet the criteria are further judged by a machine learning model, thereby reducing the number of detection rules.
This effectively prevents increased costs associated with developing testing rules and improves testing efficiency and performance.
Smart Images

Figure CN114902615B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to relay devices and relay methods. Background Technology
[0002] In previous network attack detection for control systems, there were whitelist-based attack detection methods that used predefined detection rules for groups that did not meet the detection rules to identify groups as attacks (for example, see Patent Document 1).
[0003] Existing technical documents
[0004] Patent documents
[0005] Patent Document 1: Japanese Patent Application Publication No. 2001-034553 Summary of the Invention
[0006] The technical problem that the invention aims to solve
[0007] In traditional whitelist-based attack detection, detection rules must be designed even for packets with very little movement. Sometimes, this requires writing down a large number of detection rules, which can lead to increased production costs and performance degradation.
[0008] Therefore, the purpose of this disclosure is to prevent an increase in the cost of developing testing rules.
[0009] Technical means for solving technical problems
[0010] One embodiment of the relay device disclosed herein is characterized by comprising: a first input / output unit connected to a first network; a second input / output unit connected to a second network; a monitoring unit that determines whether packets input to the first input / output unit or the second input / output unit are normal; and a relay unit that outputs packets determined to be normal by the monitoring unit from the first input / output unit or the second input / output unit. The monitoring unit uses a whitelist, which represents a list of detection rules for elements that can be determined to be normal among the elements containing features in the packets, to perform whitelist-based attack detection to determine whether packets input to the first input / output unit or the second input / output unit are normal. For packets that are not determined to be normal in the whitelist-based attack detection, a machine learning attack detection is performed to determine whether they are normal using a learning model learned through machine learning.
[0011] The relay method disclosed herein, according to one embodiment, is characterized in that packets are input to a first input / output unit connected to a first network or a second input / output unit connected to a second network, and the normality of the packets input to the first input / output unit or the second input / output unit is determined. Packets determined to be normal are output from the first input / output unit or the second input / output unit. The relay method is further characterized in that, when determining whether packets input to the first input / output unit or the second input / output unit are normal, a whitelist is used to perform whitelist-based attack detection to determine whether packets input to the first input / output unit or the second input / output unit are normal. Furthermore, for packets not determined to be normal in the whitelist-based attack detection, a machine learning attack detection is performed using a learning model learned through machine learning to determine whether the packets are normal.
[0012] Invention Effects
[0013] According to one or more methods disclosed herein, it is possible to prevent an increase in the cost of creating detection rules. Attached Figure Description
[0014] Figure 1 This is a block diagram schematically representing the structure of a network system including the detection rule generation apparatus described in embodiments 1 to 3.
[0015] Figure 2 This is a block diagram schematically illustrating the functions of the detection rule generation apparatus involved in embodiments 1 and 2.
[0016] Figure 3 It is a block diagram representing an example of hardware structure.
[0017] Figure 4 This is a flowchart illustrating the process of the detection rule generation device in Implementation 1 selecting a detection rule.
[0018] Figure 5 This is a schematic diagram illustrating the outline of the process by which the detection rule generation unit generates detection rules before selection.
[0019] Figure 6 This is a schematic diagram illustrating a processing example when the detection rule selection unit selects a detection rule in Embodiment 1.
[0020] Figure 7 This is a flowchart illustrating the process of the detection rule generation device in Implementation 2 selecting a detection rule.
[0021] Figure 8 This is a schematic diagram illustrating a processing example when the detection rule selection unit selects a detection rule in Embodiment 2.
[0022] Figure 9 This is a block diagram schematically illustrating the function of the detection rule generation device involved in Implementation Method 3.
[0023] Figure 10 This is a flowchart illustrating the process by which the detection rule generation apparatus involved in Implementation 3 updates the selected detection rule.
[0024] Figure 11 This is a schematic diagram illustrating a processing example when the detection rule selection unit updates the selected detection rule in Embodiment 3. Detailed Implementation
[0025] Implementation method 1.
[0026] Figure 1 This is a block diagram schematically illustrating the structure of a network system 100 that includes the relay device, namely the detection rule generation device 110, as described in Embodiment 1.
[0027] The network system 100 includes a PC (Personal Computer) 101, a router 102, a detection rule generation device 110, an air conditioning unit 103, a lighting unit 104, and an anti-theft device 105.
[0028] PC101 is connected to the Internet 106, which is the primary network, via router 102. The Internet 106 is a global network.
[0029] The detection rule generation device 110 is connected to the Internet 106 and the LAN (Local Area Network) 107 as a second network.
[0030] Air conditioning unit 103, lighting unit 104, and anti-theft device 105 are connected to LAN 107 as devices that are operated by PC 101, but the devices that are operated are not limited to these. In addition, the operating system 108 is composed of operating devices connected to LAN 107.
[0031] PC101 is an operating device used to operate the operating object device in the operating object system 108.
[0032] Router 102 is a relay device that relays data between the LAN (not shown) connected to PC 101 and the Internet 106.
[0033] The detection rule generation device 110 functions as a relay device that relays data between the Internet 106 and LAN 107. For example, the detection rule generation device 110 relays packets from the Internet 106 to LAN 107.
[0034] At this time, the detection rule generation device 110 collects packets sent by PC 101 via router 102 and the Internet 106 within a certain period, generates detection rules, and applies the generated detection rules to its own device or other network type attack detection devices. This certain period is also called the first period.
[0035] Air conditioning unit 103 adjusts the air conditioning in the organization including LAN 107.
[0036] Lighting device 104 illuminates the rooms in the organization that include LAN 107.
[0037] Anti-theft device 105 includes surveillance cameras and other devices in an organization such as LAN107.
[0038] Figure 2 This is a block diagram schematically representing the function of the detection rule generation device 110.
[0039] The detection rule generation device 110 includes a first input / output unit 111, a second input / output unit 112, a relay unit 113, a detection rule generation unit 114, a pre-selection rule storage unit 115, a communication statistics calculation unit 116, a detection rule statistics calculation unit 117, a detection rule efficiency calculation unit 118, a detection rule selection unit 119, a post-selection rule storage unit 120, and a security monitoring unit 121.
[0040] The first input / output unit 111 is connected to the Internet 106 and communicates with the Internet 106.
[0041] The second input / output unit 112 is connected to the LAN 107 and communicates with the LAN 107.
[0042] The relay unit 113 provides the packets received by the first input / output unit 111 or the second input / output unit 112 to the security monitoring unit 121, performs relaying of packets that are judged to be normal by the security monitoring unit 121, and outputs them from the first input / output unit 111 or the second input / output unit 112.
[0043] In addition, the relay unit 113 provides the packets received by the first input / output unit 111 within a certain period of time to the detection rule generation unit 114 and the communication statistics calculation unit 116, according to the instructions of the operator of the detection rule generation device 110.
[0044] The detection rule generation unit 114 generates detection rules based on the packets provided by the relay unit 113. The detection rule generation unit 114 stores the generated detection rules in the pre-selection rule storage unit 115 as pre-selection detection rules.
[0045] Pre-selection rule storage unit 115 stores pre-selection detection rules.
[0046] Here, the pre-selection detection rule is used to select all candidate detection rules from the whitelist used in whitelist-based attack detection.
[0047] The communication statistics calculation unit 116 calculates communication statistics based on the packets provided from the relay unit 113. These communication statistics are predetermined statistics for the communication of each element contained in a given feature. The communication statistics represent the number of packets containing that element for each element. For example, the proportion of communication volume is calculated as the communication statistics. The proportion of communication volume is the ratio of the number of packets containing the corresponding element to the number of packets provided from the relay unit 113. The calculated communication statistics are provided to the detection rule efficiency calculation unit 118.
[0048] The detection rule statistics calculation unit 117 calculates detection rule statistics based on the pre-selection detection rules stored in the pre-selection rule storage unit 115. These statistics represent the statistics of detection rules for each element included in a predetermined feature. The detection rule statistics, for each element, indicate the number of detection rules containing that element. For example, the number of detection rules or the proportion of the number of detection rules is calculated as the detection rule statistics. The number of detection rules is the number of detection rules containing the corresponding element included in the pre-selection detection rules. The proportion of the number of detection rules is the ratio of the number of detection rules containing the corresponding element to the number of pre-selection detection rules. The calculated detection rule statistics are provided to the detection rule efficiency calculation unit 118.
[0049] The detection rule efficiency calculation unit 118 calculates the detection rule efficiency for each element included in a predetermined feature based on communication statistics and detection rule statistics. Here, detection rule efficiency is a value that evaluates the communication frequency of detection rules; a high detection rule efficiency is determined when a group with high communication frequency can be detected with a smaller number of detection rules. For example, detection rule efficiency is the value obtained by dividing the communication statistics by the detection rule statistics for each element. Specifically, as detection rule efficiency, it is calculated as (proportion of communication volume) ÷ (number of detection rules) or (proportion of communication volume) ÷ (proportion of the number of detection rules). The calculated detection rule efficiency is provided to the detection rule selection unit 119.
[0050] The detection rule selection unit 119 selects detection rules included in the whitelist from the pre-selection detection rules stored in the pre-selection rule storage unit 115. For example, the detection rule selection unit 119 uses the detection rule efficiency calculated by the detection rule efficiency calculation unit 118 to select detection rules with high detection rule efficiency from the pre-selection detection rules stored in the pre-selection rule storage unit 115 as detection rules to be kept in the whitelist. Then, the detection rule selection unit 119 stores the selected detection rule as a post-selection detection rule in the post-selection rule storage unit 120.
[0051] The selected rule storage unit 120 stores the selected detection rules. The selected detection rules are the detection rules that are left as a whitelist.
[0052] The security monitoring unit 121 is a monitoring unit that determines whether the packets received by the first input / output unit 111 or the second input / output unit 112 are normal.
[0053] For example, the security monitoring unit 121 first uses a whitelist, which serves as a list of detection rules, to perform whitelist-based attack detection, determining whether the groups input to the first input / output unit 111 or the second input / output unit 112 are normal. The detection rule list indicates the elements among the features contained in the groups that can be judged as normal. Then, the security monitoring unit 121 uses a learning model learned through machine learning to perform machine learning-based attack detection, determining whether the groups that were not judged as normal in the whitelist-based attack detection are normal.
[0054] Specifically, the security monitoring unit 121 uses the selected detection rules stored in the selected rule storage unit 120 as a whitelist for the packets provided by the relay unit 113, and performs whitelist-based attack detection.
[0055] In addition, if the packet provided by the relay unit 113 does not conform to the detection rules contained in the whitelist, the security monitoring unit 121 performs machine learning attack detection on the packet. The machine learning attack detection learns the feature values of normal packets from past data in advance and detects packets that deviate from the learned feature values as attacks.
[0056] Here, whitelist-based attack detection and machine learning-based attack detection can use well-known techniques, so detailed explanations are omitted.
[0057] Figure 3 This is a block diagram illustrating an example of the hardware structure of the detection rule generation device 110.
[0058] The detection rule generation device 110 includes a first communication I / F (Interface) 130, a second communication I / F 131, an auxiliary storage device 132, a main storage device 133, and a CPU 134.
[0059] The first communication I / F130 communicates with the Internet 106.
[0060] The second communication I / F131 communicates with LAN107.
[0061] The auxiliary storage device 132 stores the information and programs required by the detection rule generation device 110. For example, the auxiliary storage device 132 stores the program executed by the CPU 134. In addition, the auxiliary storage device 132 stores the results calculated by the CPU 134.
[0062] The main storage device 133 provides the working area for the CPU 134. For example, the CPU 134 reads a program stored in the secondary storage device 132 from the main storage device 133 and executes the program. In addition, the CPU 134 expands packets received by the first communication I / F 130 in the main storage device 133.
[0063] CPU 134 performs the processing in detection rule generation device 110 by reading a program stored in auxiliary storage device 132 from main storage device 133 and executing the program. For example, CPU 134 performs calculations for generating detection rules based on packets extended from first communication I / F 130 to main storage device 133.
[0064] For example, the first input / output unit 111 can be implemented via the first communication I / F 130, and the second input / output unit 112 can be implemented via the second communication I / F 131.
[0065] The pre-selection rule storage unit 115 and the post-selection rule storage unit 120 can be implemented by the auxiliary storage device 132.
[0066] The relay unit 113, the detection rule generation unit 114, the communication statistics calculation unit 116, the detection rule statistics calculation unit 117, the detection rule efficiency calculation unit 118, the detection rule selection unit 119, and the security monitoring unit 121 can be implemented by the CPU 134.
[0067] The programs described above can be provided via a network or recorded on a recording medium. That is, such programs can be provided, for example, as program products.
[0068] Figure 4 This is a flowchart illustrating the process of the detection rule generation device 110 in Implementation 1 selecting a detection rule.
[0069] First, the relay unit 113 provides the detection rule generation unit 114 and the communication statistics calculation unit 116 with packets received by the first input / output unit 111 within a certain period (S10). In addition, this is based on the premise that the packets received in this stage do not contain attack packets.
[0070] Next, the communication statistics calculation unit 116 calculates the communication statistics of each element contained in a predetermined feature based on the packets provided from the relay unit 113 (S11). The communication statistics calculated here are provided to the detection rule efficiency calculation unit 118. Furthermore, as described later, here, the communication statistics are calculated as the ratio of the number of packets containing the command to the number of packets received within a certain period, using each command contained in the command communicated using BACnet (Building Automation and Control Networking protocol).
[0071] The detection rule generation unit 114 generates a pre-selection detection rule based on the packets provided by the relay unit 113. This pre-selection detection rule is a candidate used as a whitelist (S12).
[0072] Figure 5 This is a schematic diagram illustrating the outline of the process by which the detection rule generation unit 114 generates detection rules before selection.
[0073] Here, we will use BACnet communication packets as an example for explanation.
[0074] The detection rule generation unit 114 extracts features from the groups provided by the relay unit 113. Figure 5 In the example, the detection rule generation unit 114 extracts the sending source IP, sending destination IP, BACnet communication command, and device ID executing BACnet communication as features from the BACnet communication packets.
[0075] In addition, Figure 5 In the table shown, the first group indicated by the No column represents the detection rules for the who-Is command, which is a command element. The second to fourth groups indicated by the No column are the detection rules for the i-Am command, which is a command element. Therefore, there is 1 detection rule for the who-Is command and 3 detection rules for the i-Am command. Pre-selection detection rules are generated based on the elements contained in the predetermined features extracted in this way. The generated pre-selection detection rules are stored in the pre-selection rule storage unit 115.
[0076] Return to Figure 4The detection rule statistics calculation unit 117 calculates the detection rule statistics for each element contained in the predetermined features based on the pre-selection detection rules stored in the pre-selection rule storage unit 115 (S13). The calculated detection rule statistics are provided to the detection rule efficiency calculation unit 118.
[0077] The detection rule efficiency calculation unit 118 uses the communication statistics of each element provided by the communication statistics calculation unit 116 and the detection rule statistics of each element provided by the detection rule statistics calculation unit 117 to calculate the detection rule efficiency of each element included in the predetermined features (S14). The calculated detection rule efficiency is provided to the detection rule selection unit 119.
[0078] The detection rule selection unit 119 determines the efficiency of a detection rule that has not yet been determined based on the detection rule efficiency of each element provided by the detection rule efficiency calculation unit 118 (S15).
[0079] Next, the detection rule selection unit 119 determines whether the efficiency of the determined detection rule is above or above the threshold (S16). If the efficiency of the determined detection rule is above or above the threshold (yes in S16), the process proceeds to step S17; if the efficiency of the determined detection rule is below the threshold (no in S16), the process proceeds to step S18.
[0080] In step S17, detection rules that contain elements with a detection rule efficiency of a threshold or higher are selected as detection rules to remain in the whitelist. Then, the process proceeds to step S18.
[0081] In step S18, it is determined whether there are any detection rule efficiencies among the detection rule efficiencies of each element included in the pre-determined features that were not determined in step S15. If there are undetermined detection rule efficiencies (yes in S18), the process returns to step S15; if there are no undetermined detection rule efficiencies (no in S18), the process ends.
[0082] Figure 6 This is a schematic diagram illustrating a processing example when the detection rule selection unit 119 selects a detection rule.
[0083] The processing example here is an example of extracting the BACnet protocol from packet dump data obtained from packets received by the dump detection rule generation device 110, and performing processing on packets based on BACnet communication.
[0084] Various commands flow through BACnet communication. In this example, BACnet commands are set to elements of predetermined characteristics.
[0085] The detection rule generation device 110 generates pre-selection detection rules using packets received within a certain period, and for each command, calculates the number of detection rules containing the corresponding command (i.e., the number of detection rules) and the proportion of the number of detection rules to the total number of rules (i.e., the detection rule quantity ratio). Here, the detection rule quantity ratio is a detection rule statistic.
[0086] Then, the proportion of communication volume for each command in the group is calculated as a communication statistic.
[0087] The detection rule efficiency is calculated by dividing the traffic volume ratio by the number of detection rules. If the detection rule efficiency calculated as described above is above a threshold (here, 1.00), the detection rule selection unit 119 selects the detection rule containing the command as the detection rule to be kept in the whitelist.
[0088] As described above, according to Implementation 1, detection rules with an efficiency exceeding a threshold are retained in a whitelist, thus enabling efficient detection rules to be included in the whitelist. Therefore, by transferring the grouping of detection rules that do not conform to the whitelist to machine learning, the overall processing time required for attack detection can be suppressed.
[0089] In addition, because the efficiency of calculating detection rules for each element is improved, the storage area used for storing communication volume ratios and other information can be reduced.
[0090] The detection rule generation device 110 described in Embodiment 1 is not limited to the Building Automation (BA) system that performs the aforementioned BACnet communication, but can also be applied to a whole control system, such as a factory control system, where the transmitted packets are fixed. Furthermore, the detection rules can be generated by devices other than the detection rule generation device 110. The device for generating the detection rules may or may not be included in the network system 100.
[0091] In addition, in the above-described embodiment 1, the detection rule efficiency is calculated for each element, but the detection rule efficiency can also be calculated for each detection rule.
[0092] For example, the traffic ratio could be the ratio of the number of packets containing the corresponding detection rules to the number of packets provided from the relay unit 113. Alternatively, the number of detection rules could be the number of corresponding detection rules included in the pre-selection detection rules. Furthermore, the ratio of the number of detection rules could be the ratio of the number of corresponding detection rules to the number of pre-selection detection rules.
[0093] Implementation method 2.
[0094] like Figure 1 As shown, the network system 200 including the detection rule generation device 210 according to embodiment 2 includes a PC 101, a router 102, a detection rule generation device 210, an air conditioning device 103, a lighting device 104, and an anti-theft device 105.
[0095] The PC101, router102, air conditioning equipment103, lighting equipment104, and anti-theft equipment105 of the network system 200 in Embodiment 2 are the same as those of the PC101, router102, air conditioning equipment103, lighting equipment104, and anti-theft equipment105 of the network system 100 in Embodiment 1.
[0096] like Figure 2 As shown, the detection rule generation device 210 according to Embodiment 2 includes a first input / output unit 111, a second input / output unit 112, a relay unit 113, a detection rule generation unit 114, a pre-selection rule storage unit 115, a communication statistics calculation unit 116, a detection rule statistics calculation unit 117, a detection rule efficiency calculation unit 118, a detection rule selection unit 219, a post-selection rule storage unit 120, and a security monitoring unit 121.
[0097] The first input / output unit 111, the second input / output unit 112, the relay unit 113, the detection rule generation unit 114, the pre-selection rule storage unit 115, the communication statistics calculation unit 116, the detection rule statistics calculation unit 117, the detection rule efficiency calculation unit 118, the post-selection rule storage unit 120, and the safety monitoring unit 121 of the detection rule generation device 210 according to Embodiment 2 are the same as those of the first input / output unit 111, the second input / output unit 112, the relay unit 113, the detection rule generation unit 114, the pre-selection rule storage unit 115, the communication statistics calculation unit 116, the detection rule statistics calculation unit 117, the detection rule efficiency calculation unit 118, the post-selection rule storage unit 120, and the safety monitoring unit 121 of the detection rule generation device 110 according to Embodiment 1.
[0098] The detection rule selection unit 219 selects detection rules with high detection efficiency from the pre-selection detection rules stored in the pre-selection rule storage unit 115 and keeps them in the whitelist. In Embodiment 1, the detection rule selection unit 119 selects detection rules with high detection efficiency by comparing them with a threshold. However, in Embodiment 2, the detection rule selection unit 219 sorts the pre-determined feature elements according to their detection rule efficiency from high to low. Then, the detection rule selection unit 219 sequentially selects detection rules that remain in the whitelist, starting with the pre-selection detection rules that contain elements with high rankings.
[0099] The detection rule selection unit 219 stores the selected detection rule as a post-selection detection rule in the post-selection rule storage unit 120.
[0100] Figure 7 This is a flowchart illustrating the process of the detection rule generation device 210 in Implementation 2 selecting a detection rule.
[0101] Regarding Figure 7 The flowchart shown contains steps and Figure 4 The flowchart shown contains steps that are identical to those in the original flowchart, and the labels are the same as those in the original flowchart. Figure 4 The same label, and its detailed description is omitted.
[0102] Figure 7 The processing in steps S10 to S14 and Figure 4 The processing in steps S10 to S14 is the same. However, in Figure 7 In step S14, the process proceeds to step S25.
[0103] In step S25, the detection rule selection unit 219 sorts the elements in descending order of the detection rule efficiency of each element provided by the detection rule efficiency calculation unit 118.
[0104] Next, the detection rule selection unit 219 calculates a threshold for the number of detection rules suitable for processing in whitelist-type attack detection using a predetermined method, and within the range that meets the threshold, sequentially selects detection rules that remain in the whitelist, starting from the detection rules that contain elements with high rankings (S26). In addition, the threshold here can also be predetermined.
[0105] Figure 8 This is a schematic diagram illustrating a processing example when the detection rule selection unit 119 selects a detection rule.
[0106] The processing example here is an example of extracting the BACnet protocol from packet dump data obtained from packets received by the dump detection rule generation device 210, and performing processing on packets based on BACnet communication.
[0107] The detection rule generation device 210 generates pre-selection detection rules using packets received within a certain period, and for each command, calculates the number of detection rules containing the corresponding command (i.e., the number of detection rules) and the proportion of the number of detection rules to the total number of rules (i.e., the detection rule number ratio). Here, the detection rule number ratio is a detection rule statistic.
[0108] Then, the proportion of communication volume for each command is calculated based on the group, which is used as a communication statistic.
[0109] The efficiency of detection rules is calculated by dividing the proportion of communication volume by the proportion of the number of detection rules.
[0110] exist Figure 8 In the example shown, the detection rule selection unit 219 sorts the commands in descending order of the detection rule efficiency calculated by the detection rule efficiency calculation unit 118.
[0111] The detection rule selection unit 219 selects the pre-selection detection rules that include the command, starting from the command with the highest position.
[0112] The detection rule selection unit 219 ensures that the number of selected detection rules meets a threshold (e.g., 4500). Figure 8 In the example shown, at the time point when the detection rule containing the 9th command "write Property Multiple (REQ)" is selected, the number of selected detection rules is "3160". In this case, if the detection rule containing the 10th command "read Range (ACK)" is selected, the number of selected detection rules becomes "8160", which exceeds the threshold. Therefore, the detection rule selection unit 219 selects the detection rule containing the next 11th command "writeProperty Multiple (REQ)".
[0113] Here, if the detection rule selection unit 219 selects a detection rule that includes an element at a certain position, then if the threshold is exceeded, the position is reduced to maximize the number of selected detection rules within the threshold. However, Embodiment 2 is not limited to such an example. For instance, if the detection rule selection unit 219 selects a detection rule that includes an element at a certain position, then if the threshold is exceeded, the selection of detection rules ends with the previous position.
[0114] As described above, according to Implementation 2, the number of detection rules is selected up to a number close to the set threshold, thus suppressing the number of detection rules reserved for the whitelist.
[0115] In addition, in Implementation 2, the efficiency of the detection rule can be calculated for each detection rule in the same way as in Implementation 1.
[0116] Implementation method 3.
[0117] like Figure 1 As shown, the network system 300 including the detection rule generation device 310 according to embodiment 3 includes a PC 101, a router 102, a detection rule generation device 310, an air conditioning device 103, a lighting device 104, and an anti-theft device 105.
[0118] The PC101, router102, air conditioning equipment103, lighting equipment104, and anti-theft equipment105 of the network system 300 in Embodiment 3 are the same as those of the PC101, router102, air conditioning equipment103, lighting equipment104, and anti-theft equipment105 of the network system 100 in Embodiment 1.
[0119] Figure 9 This is a block diagram schematically illustrating the function of the detection rule generation device 310 involved in Embodiment 3.
[0120] The detection rule generation device 310 includes a first input / output unit 111, a second input / output unit 112, a relay unit 313, a detection rule generation unit 314, a pre-selection rule storage unit 315, a communication statistics calculation unit 316, a detection rule statistics calculation unit 317, a detection rule efficiency calculation unit 318, a detection rule selection unit 319, a post-selection rule storage unit 320, a security monitoring unit 121, a detection rule addition unit 322, and a communication statistics storage unit 323.
[0121] The first input / output unit 111, the second input / output unit 112, and the safety monitoring unit 121 of the detection rule generation device 310 in Embodiment 3 are the same as those of the first input / output unit 111, the second input / output unit 112, and the safety monitoring unit 121 of the detection rule generation device 110 in Embodiment 1.
[0122] In addition to performing the same processing as in Embodiment 1, the relay unit 313, after selecting a detection rule to be retained in the whitelist, will, for example, provide the packets received by the first input / output unit 111 within a certain period to the detection rule generation unit 314 and the communication statistics calculation unit 316 according to the instructions of the operator of the detection rule generation device 310 or the like. This certain period is also referred to as the second period.
[0123] In addition to performing the same processing as in Embodiment 1, the detection rule generation unit 314 generates detection rules based on the grouping provided by the relay unit 313 after selecting the detection rules to be kept in the whitelist. After selecting the detection rules to be kept in the whitelist, the detection rule generation unit 314 provides the generated detection rules to the detection rule addition unit 322.
[0124] The detection rule addition unit 322 adds the detection rules provided by the detection rule generation unit 314 to the pre-selection rule storage unit 315. For example, the detection rule addition unit 322 stores the detection rules provided by the detection rule generation unit 314 as pre-selection detection rules in the pre-selection rule storage unit 315 to avoid duplication with pre-selection detection rules already stored in the pre-selection rule storage unit 315. Here, the pre-selection detection rule after the detection rules are added by the detection rule addition unit 322 is called the added pre-selection detection rule.
[0125] The pre-selection rule storage unit 315 stores pre-selection detection rules or adds pre-selection detection rules.
[0126] Before selecting a detection rule to remain in the whitelist, the communication statistics calculation unit 316, as in Embodiment 1, calculates the communication statistics of each element contained in a predetermined feature based on the packets provided from the relay unit 313. The communication statistics calculation unit 316 provides the calculated communication statistics to the detection rule efficiency calculation unit 318 and stores them in the communication statistics storage unit 323.
[0127] Furthermore, after selecting the detection rules to be included in the whitelist, the communication statistics calculation unit 316 calculates the communication statistics of each element contained in a predetermined feature based on the grouping provided by the relay unit 313, and sums the calculated communication statistics with the communication statistics stored in the communication statistics storage unit 323. The communication statistics calculation unit 316 provides the summed communication statistics to the detection rule efficiency calculation unit 318 and stores it in the communication statistics storage unit 323.
[0128] In addition to performing the same processing as in Embodiment 1, the detection rule statistics calculation unit 317 also calculates detection rule statistics based on the additional pre-selection detection rules stored in the pre-selection rule storage unit 315 after selecting the detection rules to be retained in the whitelist. These detection rule statistics are the statistics of the detection rules for each element contained in a predetermined feature. The detection rule statistics calculated here are called the updated detection rule statistics.
[0129] In addition to performing the same processing as in Embodiment 1, the detection rule efficiency calculation unit 318, after selecting the detection rules to be retained in the whitelist, calculates the updated detection rule efficiency based on the total communication statistics and the updated detection rule statistics. This updated detection rule efficiency is a predetermined detection rule efficiency for each element contained in a feature. The calculated updated detection rule efficiency is provided to the detection rule selection unit 319.
[0130] In addition to performing the same processing as in Embodiment 1 or Embodiment 2, the detection rule selection unit 319, after selecting a detection rule to be kept in the whitelist, selects a detection rule with high update detection rule efficiency from the additional pre-selection detection rules stored in the pre-selection rule storage unit 315, and uses it as a detection rule to be kept in the whitelist. The selection method can be the same as in Embodiment 1 or Embodiment 2. Then, the detection rule selection unit 319 stores the selected detection rule as a post-selection detection rule in the post-selection rule storage unit 320. The post-selection detection rule stored here is also called an updated post-selection detection rule.
[0131] Subsequently, the security monitoring unit 121 uses the updated selection post-detection rules stored in the selection post-rule storage unit 320 as a whitelist for the packets provided from the relay unit 113, and performs whitelist-based attack detection.
[0132] In addition, the communication statistics storage unit 323 can be used through Figure 3 The auxiliary storage device 132 shown is used to implement this.
[0133] In addition, the detection rule addition section 322 can pass Figure 3 The CPU134 shown is used for implementation.
[0134] Figure 10 This is a flowchart illustrating the process by which the detection rule generation apparatus 310, according to Embodiment 3, updates the selected detection rule.
[0135] First, the relay unit 313 provides the detection rule generation unit 314 and the communication statistics calculation unit 316 with packets received by the first input / output unit 111 within a certain period (S30).
[0136] Next, the communication statistics calculation unit 316 calculates the communication statistics of each element contained in a predetermined feature based on the grouping provided from the relay unit 113, and sums them with the communication statistics stored in the communication statistics storage unit 323 (S31). Here, the summed communication statistics are provided to the detection rule efficiency calculation unit 318 and stored in the communication statistics storage unit 323.
[0137] The detection rule generation unit 314 generates detection rules based on the packets provided by the relay unit 313 (S32). The generated detection rules are then provided to the detection rule addition unit 322.
[0138] The detection rule addition unit 322 adds the detection rules provided by the detection rule generation unit 314 to the pre-selection rule storage unit 315 to avoid duplication with the pre-selection detection rules already stored in the pre-selection rule storage unit 315 (S33).
[0139] The detection rule statistics calculation unit 317 calculates the detection rule statistics for each element contained in the predetermined features as updated detection rule statistics based on the additional pre-selection detection rules stored in the pre-selection rule storage unit 315 (S34). The calculated updated detection rule statistics are provided to the detection rule efficiency calculation unit 318.
[0140] The detection rule efficiency calculation unit 318 uses the total communication statistics provided by the communication statistics calculation unit 316 and the updated detection rule statistics provided by the detection rule statistics calculation unit 317 to calculate the updated detection rule efficiency, which is the detection rule efficiency of each element included in the predetermined features (S35). The calculated updated detection rule efficiency is provided to the detection rule selection unit 319.
[0141] The detection rule selection unit 319 uses the updated detection rule efficiency provided by the detection rule efficiency calculation unit 318 to select the detection rule that remains in the whitelist from the additional pre-selection detection rules stored in the pre-selection rule storage unit 315 as the updated post-selection detection rule (S36). The selection method here can be the same as in embodiment 1, comparing the updated detection rule efficiency with the threshold, or it can be the same as in embodiment 2, selecting sequentially starting from the updated detection rule with high efficiency.
[0142] Figure 11 This is a schematic diagram illustrating a processing example when the detection rule selection unit 319 updates the selected detection rule.
[0143] The processing example here is an example of extracting the BACnet protocol from packet dump data obtained from packets received by the dump detection rule generation device 310, and performing processing on packets based on BACnet communication.
[0144] The detection rule generation device 310 adds detection rules generated based on packets received within a certain period to the pre-selection detection rules, and for each command, calculates the number of detection rules containing the corresponding command (i.e., the number of detection rules) and the proportion of the number of detection rules to the total number of rules (i.e., the detection rule number ratio). Here, the detection rule number ratio is an update detection rule statistic.
[0145] Then, the proportion of communication volume for each command is calculated based on the group, which is used as a communication statistic, and then summed with the communication statistics that have already been stored.
[0146] The efficiency of updating detection rules is calculated by dividing the total communication volume ratio by the ratio of the number of updated detection rules.
[0147] The detection rule selection unit 319 selects additional detection rules that include commands that are efficient for updating detection rules.
[0148] As described above, according to Embodiment 3, even after a detection rule has been selected once, a preferred detection rule can be selected again by adding new groups. Therefore, the accuracy of the whitelist can be improved.
[0149] In addition, in Implementation 3, the efficiency of updating detection rules can be calculated for each detection rule, just like in Implementation 1.
[0150] Label Explanation
[0151] 100, 200, 300 network systems
[0152] 101 PC
[0153] 102 Router
[0154] 103 Air Conditioning Equipment
[0155] 104 Lighting equipment
[0156] 105 Anti-theft equipment
[0157] 106 Internet
[0158] 107 LAN
[0159] 110, 210, 310 Detection Rule Generation Device
[0160] 111 First Input / Output Section
[0161] 112 Second Input / Output Section
[0162] 113, 313 Relay Units
[0163] 114 and 314 Detection Rule Generation Department
[0164] 115, 315 Pre-selection rule storage department
[0165] 116, 316 Communication Statistics Calculation Department
[0166] 117 and 317 Inspection Rule Statistical Calculation Department
[0167] Efficiency Calculation Department for Detection Rules 118 and 318
[0168] 119, 219, 319 Inspection Rule Selection Department
[0169] 120, 320 after selection rule storage department
[0170] 121 Security Monitoring Department
[0171] 322 Additional Inspection Rules
[0172] 323 Communication Statistics Storage Department.
Claims
1. A relay device, characterized in that, include: A first input / output unit, which is connected to a first network; A second input / output unit, which is connected to a second network; The monitoring unit determines whether the packets input to the first input / output unit or the second input / output unit are normal. as well as A relay unit outputs packets deemed normal by the monitoring unit from either the first or second input / output unit. The monitoring unit first performs whitelist-based attack detection, that is, it uses a whitelist—a list of detection rules representing the elements containing features in a group that can be judged as normal—to determine whether the group input to the first input / output unit or the second input / output unit is normal. Then, for groups that are not judged as normal in the whitelist-based attack detection, it performs machine learning-based attack detection, that is, it uses a learning model learned through machine learning to determine whether the group is normal. Also includes: A detection rule generation unit generates multiple detection rules as multiple pre-selection detection rules based on multiple groups input to the first input / output unit within a predetermined first period; and The selection unit selects the detection rule included in the whitelist from the plurality of pre-selection detection rules. During a predetermined first period, none of the packets input to the first input / output unit contain attack packets. Also includes: The detection rule statistics calculation unit calculates a detection rule statistic for each element contained in a predetermined feature based on a plurality of pre-selection detection rules. The detection rule statistic represents the number of detection rules that contain the corresponding element in the plurality of pre-selection detection rules. A communication statistics calculation unit calculates a communication statistic for each element included in the predetermined features, the communication statistic representing the number of groups containing the corresponding element among the plurality of groups; and The detection rule efficiency calculation unit calculates the detection rule efficiency for each element included in the predetermined features by dividing the communication statistic by the detection rule statistic. The selection unit uses the detection rules to perform the selection efficiently.
2. The relay device as described in claim 1, characterized in that, The detection rule statistics are the proportion of detection rules containing the corresponding elements among the multiple pre-selection detection rules, or the number of detection rules containing the corresponding elements.
3. The relay device as described in claim 1, characterized in that, The communication statistic is the proportion of the group containing the corresponding element among the multiple groups.
4. The relay device as described in claim 2, characterized in that, The communication statistic is the proportion of the group containing the corresponding element among the multiple groups.
5. The relay device as described in claim 1, characterized in that, Also includes: The detection rule statistics calculation unit calculates a detection rule statistic for each detection rule included in the plurality of pre-selection detection rules. The detection rule statistic represents the number of corresponding detection rules among the plurality of pre-selection detection rules. A communication statistics calculation unit calculates a communication statistic for each detection rule included in the plurality of pre-selection detection rules, the communication statistic representing the number of corresponding detection rules in the plurality of groups; as well as The detection rule efficiency calculation unit calculates the detection rule efficiency for each element included in a predetermined feature by dividing the communication statistic by the detection rule statistic. The selection unit uses the detection rules to perform the selection efficiently.
6. The relay device as described in claim 5, characterized in that, The detection rule statistic is the proportion of the corresponding detection rule among the multiple pre-selection detection rules, or the number of the corresponding detection rules among the multiple pre-selection detection rules.
7. The relay device as described in claim 5, characterized in that, The communication statistic is the proportion of the group containing the corresponding detection rule among the multiple groups.
8. The relay device as described in claim 6, characterized in that, The communication statistic is the proportion of the group containing the corresponding detection rule among the multiple groups.
9. The relay device as described in any one of claims 1 to 8, characterized in that, The selection unit performs the selection by comparing the efficiency of the detection rule with a predetermined threshold.
10. The relay device as described in any one of claims 1 to 8, characterized in that, The selection unit performs the selection in descending order of efficiency according to the detection rules.
11. The relay device as described in claim 1, characterized in that, The detection rule generation unit generates multiple detection rules based on multiple groups input to the first input / output unit during a predetermined second period, and generates multiple additional pre-selection detection rules by adding them in a manner that does not overlap with the multiple pre-selection detection rules. The selection unit selects the detection rule included in the whitelist from among the multiple additional pre-selection detection rules.
12. A relay method, In this relay method, packets are input to a first input / output unit connected to a first network or a second input / output unit connected to a second network. The system determines whether the packets input to the first input / output unit or the second input / output unit are normal. The relay method is characterized by outputting packets determined to be normal from either the first or second input / output unit. When determining whether a group input to the first input / output unit or the second input / output unit is normal, a whitelist-based attack detection is performed. This involves using a whitelist—a list of detection rules representing the elements of a group that can be judged as normal—to determine whether the group input to the first input / output unit or the second input / output unit is normal. Then, for groups that are not judged as normal in the whitelist-based attack detection, a machine learning attack detection is performed. This involves using a learning model acquired through machine learning to determine whether the group is normal. Furthermore, based on multiple groups input to the first input / output unit within a predetermined first period, multiple detection rules are generated as multiple pre-selection detection rules, and a detection rule included in the whitelist is selected from the multiple pre-selection detection rules. During a predetermined first period, none of the packets input to the first input / output unit contain attack packets. Based on the multiple pre-selection detection rules, for each element contained in the predetermined features, a detection rule statistic is calculated. This detection rule statistic represents the number of detection rules that include the corresponding element among the multiple pre-selection detection rules. For each element contained in the predetermined features, a communication statistic is calculated, which represents the number of groups containing the corresponding element among the multiple groups. For each element included in the predetermined features, the value obtained by dividing the communication statistic by the detection rule statistic is calculated as the detection rule efficiency, and the selection is made using the detection rule efficiency.
Citation Information
Patent Citations
Network access control method and device therefor
JP2001034553A
Fast Flux botnet detection method based on DNS anomaly mining
CN106713371A
Attack feature detection method and device
CN108111472A
Communication device
JP2017005402A
Specifying device, specifying method, and specifying program
WO2019225710A1