Detection device, detection method, and detection program
By setting up a monitoring unit and a detection unit in the detection device, the existence of an illegal communication connection is detected based on the monitoring results of the communication connection in the network, and the problem of insufficient detection accuracy in the prior art is solved, and more accurate detection of an illegal communication connection is achieved.
Patent Information
- Application Number
- CN202380068772.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-18
- Filing Date
- 2023-07-21
- Publication Date
- 2025-05-06
AI Technical Summary
The prior art is difficult to detect more accurately the presence of illegal communication connections in the network, especially when illegal devices impersonate legitimate communication devices.
By providing a monitoring unit and a detection unit in the detection device, the communication connection established in the network for exchange of prescribed messages is monitored, and the existence of an illegal communication connection is detected based on the monitoring results of the multiple communication connections. The specific method includes monitoring the period, frequency and ratio of the connection period of the stateful message to judge the existence of an illegal communication connection.
It realizes more accurately detecting the existence of illegal communication connections in the network, and can accurately judge and output alarms when illegal communication connections cause changes in network communication conditions.
Smart Images

Figure CN119948844A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a detection device, a detection method and a detection program.
[0002] This application claims the benefit of priority based on Japanese patent application No. 2022-184950, filed on November 18, 2022, and incorporates herein all the contents disclosed. Background Art
[0003] Patent document 1 (International Publication No. 2022 / 153839) discloses the following detection device. That is, the detection device detects the presence of illegal messages in the vehicle network, and the detection device includes: a state detection unit that detects the transition to a state of sending periodic messages, i.e., periodic messages, in the vehicle network based on the content of the message sent in the vehicle network; and a processing unit that performs detection processing to detect the presence of the illegal message based on the reception status of multiple periodic messages in the state detected by the state detection unit.
[0004] Prior art literature
[0005] Patent Literature
[0006] Patent Document 1: International Publication No. 2022 / 153839 Summary of the invention
[0007] The detection device disclosed in the present invention detects the existence of illegal communication connections in a network, and the detection device comprises: a monitoring unit that monitors communication connections established to exchange specified messages in the network; and a detection unit that detects the existence of the illegal communication connections based on the monitoring results of the monitoring unit on multiple communication connections.
[0008] One aspect of the present disclosure can be realized not only as a detection device including such a characteristic processing unit but also as a semiconductor integrated circuit realizing a part or all of the detection device, or as a system including the detection device. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 It is a diagram showing the structure of a network involved in an embodiment of the present disclosure.
[0010] Figure 2 It is a diagram showing the structure of a relay device according to an embodiment of the present disclosure.
[0011] Figure 3 This is a diagram showing an example of messages transmitted and received in a network according to an embodiment of the present disclosure.
[0012] Figure 4This is a diagram showing another example of messages transmitted and received in the network according to the embodiment of the present disclosure.
[0013] Figure 5 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0014] Figure 6 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0015] Figure 7 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0016] Figure 8 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0017] Fig. 9 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0018] Fig.10 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0019] Fig.11 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0020] Fig.12 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure.
[0021] Fig.13 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure monitors a communication connection.
[0022] Fig.14 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
[0023] Fig.15 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
[0024] Fig.16 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
[0025] Fig.17 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
[0026] Fig.18 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. DETAILED DESCRIPTION
[0027] In the past, technologies have been developed to improve security in networks.
[0028] [Technical Problems to be Solved by the Present Disclosure]
[0029] There is a need for a technology that can more accurately detect the presence of an illegal communication connection in a network beyond the technology described in Patent Document 1.
[0030] The present disclosure is completed to solve the above-mentioned technical problems, and its purpose is to provide a detection system, a verification device, a response device and a detection method that can more accurately detect the existence of illegal communication connections in the network.
[0031] [Effects of the present disclosure]
[0032] According to the present disclosure, the presence of an illegal communication connection in a network can be detected more accurately.
[0033] [Description of Embodiments of the Present Disclosure]
[0034] First, the contents of the embodiments of the present disclosure are listed and described.
[0035] (1) The detection device involved in the embodiment of the present disclosure detects the existence of illegal communication connections in a network, and the detection device comprises: a monitoring unit that monitors communication connections established to exchange specified messages in the network; and a detection unit that detects the existence of the illegal communication connections based on the monitoring results of the monitoring unit on multiple communication connections.
[0036] In this way, the structure for detecting the existence of illegal communication connections based on the monitoring results of multiple communication connections can determine that an illegal communication connection exists when the status of the communication connection in the network changes due to the establishment of an illegal communication connection. Therefore, the existence of illegal communication connections in the network can be detected more accurately.
[0037] (2) In the above (1), the detection unit may detect the presence of the illegal communication connection based on a cycle in which the communication connection is established.
[0038] According to such a configuration, it is possible to detect an illegal communication connection based on a change in the occurrence cycle of the communication connection caused by the establishment of the illegal communication connection.
[0039] (3) In the above (1) or (2), the presence of the illegal communication connection may be detected based on the frequency of establishing the communication connection.
[0040] According to such a configuration, it is possible to detect an illegal communication connection based on a change in the frequency of occurrence of the communication connection due to the establishment of the illegal communication connection.
[0041] (4) In any one of (1) to (3) above, the detection unit may detect the presence of the illegal communication connection based on a ratio of a period in which the communication connection is established per unit time.
[0042] According to such a configuration, it is possible to detect an illegal communication connection based on a change in the period during which the communication connection is established per unit time caused by the establishment of the illegal communication connection.
[0043] (5) In any of the above (1) to (4), the monitoring unit may monitor the communication connection established using a SubscribeAck message in accordance with SOME / IP (Scalable service-oriented MiddlewarE over IP) and terminated using a StopOffer message or a StopSubscribe message in accordance with SOME / IP.
[0044] According to such a configuration, the presence of an illegal communication connection can be detected more accurately in a network that transmits and receives messages in accordance with SOME / IP.
[0045] (6) In any one of the above (1) to (4), the monitoring unit may monitor a TCP (Transmission Control Protocol) connection as the communication connection.
[0046] According to such a configuration, the presence of an illegal communication connection can be detected more accurately in a network that transmits and receives messages according to TCP.
[0047] (7) In any one of the above (1) to (4), the monitoring unit may monitor the communication connection established using a create_subscriber message in accordance with DDS (Data Distribution Service) and terminated using a delete_subscriber message in accordance with DDS.
[0048] According to such a configuration, the presence of an illegal communication connection can be detected more accurately in a network that transmits and receives messages in accordance with DDS.
[0049] (8) The detection method involved in the embodiment of the present disclosure is a detection method in a detection device for detecting the existence of illegal communication connections in a network, and the detection method includes the following steps: monitoring the communication connections established for exchanging specified messages in the network; and detecting the existence of the illegal communication connections based on the monitoring results of multiple communication connections.
[0050] In this way, the method for detecting the existence of illegal communication connections based on the monitoring results of multiple communication connections can determine that an illegal communication connection exists when the status of the communication connection in the network changes due to the establishment of an illegal communication connection. Therefore, the existence of illegal communication connections in the network can be detected more accurately.
[0051] (9) The detection program involved in the embodiment of the present disclosure is a detection program used in a detection device for detecting the existence of illegal communication connections in a network. The detection program is a program for causing a computer to function as a monitoring unit and a detection unit. The monitoring unit monitors the communication connection established for exchanging prescribed messages in the network, and the detection unit detects the existence of the illegal communication connection based on the monitoring result of the plurality of communication connections by the monitoring unit.
[0052] In this way, the structure for detecting the existence of illegal communication connections based on the monitoring results of multiple communication connections can determine that an illegal communication connection exists when the status of the communication connection in the network changes due to the establishment of an illegal communication connection. Therefore, the existence of illegal communication connections in the network can be detected more accurately.
[0053] The following is an explanation of the embodiments of the present disclosure using the accompanying drawings. It should be noted that the same or corresponding parts in the drawings are marked with the same reference numerals, and their descriptions are not repeated. In addition, at least a part of the embodiments described below can also be arbitrarily combined.
[0054] [Structure and basic movements]
[0055] Figure 1 is a diagram showing a structure of a network according to an embodiment of the present disclosure. Figure 1 The network 12 includes a relay device 101 and a plurality of communication devices 111. The communication device 111 is connected to the relay device 101 via a transmission line 14. The transmission line 14 is, for example, an Ethernet (registered trademark) cable.
[0056] For example, the network 12 is an in-vehicle network. In this case, the communication device 111 is an in-vehicle ECU (Electronic Control Unit). Specifically, the communication device 111 is an electric power steering system (Electric Power Steering: EPS), a brake control device, an accelerator control device, a steering control device, a driving assistance device or a sensor that instructs various devices in a driving assistance system (Advanced Driver-Assistance System: ADAS), etc.
[0057] It should be noted that the network 12 may also be a network in an industrial control system of a factory or plant, etc. In this case, the communication device 111 is, for example, a PLC (Programmable Logic Controller) for controlling a power supply control unit, a robot, a sensor, or an actuator.
[0058] The communication device 111 establishes a communication connection for exchanging a predetermined message according to a connection-type protocol, thereby transmitting and receiving messages with other communication devices 111. More specifically, the communication device 111 establishes a communication connection with other communication devices 111 periodically or irregularly. Then, the communication device 111 generates a frame including a message addressed to the other communication device 111, and transmits the generated frame to the relay device 101 via the transmission line 14. For example, the communication device 111 can dynamically establish a communication connection with a plurality of different other communication devices 111.
[0059] The relay device 101 is, for example, a central gateway (CGW), and performs relay processing for relaying messages sent and received between a plurality of communication devices 111 connected to different transmission lines 14. More specifically, the relay device 101 receives a frame sent from the communication device 111 via the corresponding transmission line 14, and sends the received frame to the communication device 111 as the destination via the corresponding transmission line 14.
[0060] The relay device 101 also functions as a detection device, and performs a detection process for detecting the presence of an illegal communication connection in the network 12. Hereinafter, an illegal communication connection in the network 12 is also referred to as an "illegal communication connection."
[0061] <Relay Device>
[0062] Figure 2 2 is a diagram showing a structure of a relay device according to an embodiment of the present disclosure. Figure 2The relay device 101 includes a relay unit 51, a monitoring unit 52, a detection unit 53, an output unit 54, and a storage unit 55. Part or all of the relay unit 51, the monitoring unit 52, the detection unit 53, and the output unit 54 are implemented, for example, by a processing circuit (Circuitry) including one or more processors. The storage unit 55 is, for example, a non-volatile memory included in the above-mentioned processing circuit.
[0063] When the relay unit 51 receives a frame from a communication device 111 via the corresponding transmission line 14, it transmits the received frame to the communication device 111 as the destination according to the destination information of the frame via the corresponding transmission line 14. Here, the destination information of the frame is information indicating the destination of the frame, such as a destination MAC address, a destination IP address, and a message ID.
[0064] Figure 3 This is a diagram showing an example of messages transmitted and received in a network according to an embodiment of the present disclosure. Figure 3 1 is a sequence diagram showing messages transmitted and received by the communication devices 111A and 111B as the communication device 111 .
[0065] Reference Figure 3 The communication device 111A establishes a communication connection with the communication device 111B by exchanging one or more stateful messages MS with the communication device 111B via the relay device 101. The one or more stateful messages MS are messages for establishing a communication connection with other communication devices 111. In addition, the communication device 111A terminates the communication connection with the communication device 111B by exchanging one or more stateful messages ME with the communication device 111B via the relay device 101. The one or more stateful messages ME are messages for terminating the communication connection with other communication devices 111. The communication device 111A sends one or more messages to the communication device 111B via the relay device 101 during the period of establishing the communication connection with the communication device 111B, i.e., the connection period T1.
[0066] It should be noted that a communication connection may be established by sending a state message MS to the communication device 111B via the relay device 101 only in the communication device 111A and the communication device 111B. Alternatively, a communication connection may be terminated by sending a state message ME to the communication device 111B via the relay device 101 only in the communication device 111A and the communication device 111B. Alternatively, the communication device 111B may send a message to the communication device 111A via the relay device 101 during the connection period T1.
[0067] The monitoring unit 52 monitors the communication connection established in the network 12. More specifically, the monitoring unit 52 monitors the relay processing of the relay unit 51, and refers to the header information of the frame received by the relay unit 51 to confirm the content of the message carried in the frame.
[0068] When the message carried in the frame received by the relay unit 51 is a stateful message MS, the monitoring unit 52 determines that the communication device 111 as the transmission source of the stateful message MS has established a communication connection with the communication device 111 as the destination of the stateful message MS. For example, the monitoring unit 52 obtains the reception time ts when the relay unit 51 receives the frame carrying the stateful message MS, and stores the obtained reception time ts in the storage unit 55.
[0069] In addition, when the message carried in the frame received by the relay unit 51 is a state message ME, the monitoring unit 52 determines that the communication device 111 as the transmission source of the state message ME and the communication device 111 as the destination of the state message ME have terminated the communication connection. For example, the monitoring unit 52 obtains the reception time te when the relay unit 51 receives the frame carrying the state message ME, and stores the obtained reception time te in the storage unit 55.
[0070] The detection unit 53 detects the presence of an illegal communication connection based on the monitoring result of the plurality of communication connections by the monitoring unit 52. For example, the detection unit 53 detects the presence of an illegal communication connection based on the monitoring result of the plurality of communication connections in the group of two communication devices 111.
[0071] For example, the detection unit 53 detects the presence of an illegal communication connection based on at least any one of a cycle C1 of establishing a communication connection between the communication devices 111, a frequency F1 of establishing a communication connection between the communication devices 111, and a ratio R1 of the connection period T1 per unit time.
[0072] More specifically, the detection unit 53 calculates the cycle C1 and the frequency F1 based on the plurality of reception times ts stored in the storage unit 55 by the monitoring unit 52. In addition, the detection unit 53 calculates the connection period T1 based on the reception times ts and te stored in the storage unit 55 by the monitoring unit 52, and calculates the ratio R1 based on the connection period T1.
[0073] The detection unit 53 detects the presence of an illegal communication connection based on at least one of the calculated period C1, frequency F1, and ratio R1. When the detection unit 53 detects the presence of an illegal communication connection, it outputs the detection result to the output unit 54.
[0074] When receiving the detection result indicating that an illegal communication connection has been detected from the detection unit 53 , the output unit 54 outputs a warning indicating that an illegal communication connection has been detected to the user's terminal or the like, for example, via the communication device 111 having a wireless communication function.
[0075] Figure 4 This is a diagram showing another example of messages transmitted and received in the network according to the embodiment of the present disclosure. Figure 4 1 is a sequence diagram showing messages transmitted and received by the communication devices 111A, 111B, and 111C as the communication device 111 .
[0076] Reference Figure 4 In addition to the communication device 111A, there is also a communication device 111C that establishes a communication connection with the communication device 111B by exchanging one or more state messages MS with the communication device 111B via the relay device 101. The one or more state messages MS are messages for establishing a communication connection with other communication devices 111. In addition, the communication device 111C terminates the communication connection with the communication device 111B by exchanging one or more state messages ME with the communication device 111B via the relay device 101. The one or more state messages ME are messages for terminating the communication connection with other communication devices 111.
[0077] In this case, for example, the detection unit 53 detects the presence of an illegal communication connection based on the monitoring results of a plurality of communication connections in a group of different plurality of communication devices 111 .
[0078] More specifically, the detection unit 53 calculates the cycle C1 based on the reception time ts of the frame carrying the status message MS transmitted by the communication device 111C and the reception time ts of the frame carrying the status message MS transmitted by the communication device 111A. In addition, the detection unit 53 calculates the frequency F1 based on the number of times the communication connection between the communication device 111A and the communication device 111B is established and the number of times the communication connection between the communication device 111C and the communication device 111B is established. In addition, the ratio R1 is calculated based on the connection period T1 of the communication connection between the communication device 111A and the communication device 111B and the connection period T1 of the communication connection between the communication device 111A and the communication device 111B.
[0079] (Specific example 1 of detection processing)
[0080] Figure 5 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Figure 5 A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0081] Reference Figure 5 In the network 12, messages are sent and received according to TCP / IP. The communication device 111 establishes a communication connection according to TCP / IP, that is, a TCP connection, through a three-way handshake.
[0082] More specifically, the communication device 111A generates a SYN packet, which is a TCP packet in which the SYN flag in the TCP header is set to ON, and transmits the generated SYN packet to the communication device 111B via the relay device 101 .
[0083] The communication device 111B receives a SYN packet from the communication device 111A via the relay device 101, generates a SYN / ACK packet, and sends the generated SYN / ACK packet to the communication device 111A via the relay device 101. The SYN / ACK packet is a TCP packet in which the SYN flag and ACK flag in the TCP header are set to on.
[0084] The communication device 111A receives a SYN / ACK packet from the communication device 111B via the relay device 101, generates an ACK packet, and sends the generated ACK packet to the communication device 111B via the relay device 101. The ACK packet is a TCP packet in which the ACK flag in the TCP header is set to on. Thus, the nth TCP connection between the communication device 111A and the communication device 111B is established. The SYN packet, the SYN / ACK packet, and the ACK packet in the three-way handshake are an example of a state message MS.
[0085] When terminating the TCP connection with the communication device 111B, the communication device 111A generates a FIN packet, in which the FIN flag in the TCP header is turned on, and transmits the generated FIN packet to the communication device 111B via the relay device 101 .
[0086] Communication device 111B receives a FIN packet from communication device 111A via relay device 101, generates a FIN / ACK packet, and sends the generated FIN / ACK packet to communication device 111A via relay device 101. The FIN / ACK packet is a TCP packet in which the FIN flag and ACK flag in the TCP header are set to on.
[0087] The communication device 111A receives the FIN / ACK packet from the communication device 111B via the relay device 101, generates an ACK packet, and sends the generated ACK packet to the communication device 111B via the relay device 101. The ACK packet is a TCP packet in which the ACK flag in the TCP header is set to on. Thus, the TCP connection between the communication device 111A and the communication device 111B is terminated. The FIN packet, FIN / ACK packet, and ACK packet in the three-way handshake are an example of a state message ME.
[0088] The communication device 111A transmits one or more messages to the communication device 111B via the relay device 101 during the connection period T1A, which is the connection period T1 of the TCP connection with the communication device 111B.
[0089] Then, similarly, the establishment and termination of the TCP connection between the communication device 111A and the communication device 111B are repeated.
[0090] The monitoring unit 52 monitors a TCP connection which is an example of a communication connection established in the network 12. For example, the monitoring unit 52 monitors a TCP connection established in the network 12 for each application specified by a group of port numbers.
[0091] More specifically, when a SYN packet is included in a frame received by relay unit 51 , monitoring unit 52 determines that a TCP connection is established between communication device 111 as a transmission source of the frame and communication device 111 as a destination of the frame.
[0092] Then, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the SYN packet, and stores the obtained set of the source port number and the destination port number in the storage unit 55 as identification information DA indicating the communication connection to be monitored. In addition, the monitoring unit 52 generates state information indicating that the state of the communication connection to be monitored has changed to a state where the SYN packet has been exchanged, and stores the generated state information in the storage unit 55 in correspondence with the identification information DA. In addition, the monitoring unit 52 obtains the reception time tsa1, which is the reception time ts when the relay unit 51 receives the frame carrying the SYN packet, and stores the obtained reception time tsa1 in the storage unit 55 in correspondence with the identification information DA. The reception time tsa1 corresponds to the time when the state of the communication connection to be monitored has changed to a state where the SYN packet has been exchanged.
[0093] In addition, when the frame received by the relay unit 51 carries a SYN / ACK packet, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the SYN / ACK packet, and determines the identification information DA that matches the obtained set of the source port number and the destination port number from the identification information DA stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DA to state information indicating a transition to a state where SYN / ACK packets have been exchanged. In addition, the monitoring unit 52 obtains the receiving time tsa2, which is the receiving time ts when the relay unit 51 receives the frame carrying the SYN / ACK packet, and stores the obtained receiving time tsa2 in the storage unit 55 in correspondence with the determined identification information DA. The receiving time tsa2 corresponds to the time when the state of the communication connection to be monitored transitions to a state where SYN / ACK packets have been exchanged.
[0094] In addition, when the frame received by the relay unit 51 carries an ACK packet, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the ACK packet, and determines the identification information DA that matches the set of the obtained source port number and the destination port number from the identification information DA stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DA to state information indicating that the state has changed to the state where the ACK packet for the SYN / ACK packet has been exchanged. In addition, the monitoring unit 52 obtains the receiving time tsa3, which is the receiving time ts when the relay unit 51 receives the frame carrying the ACK packet, and stores the obtained receiving time tsa3 in the storage unit 55 in correspondence with the determined identification information DA. The receiving time tsa3 corresponds to the time when the state of the communication connection as the monitored object changes to the state where the ACK packet for the SYN / ACK packet has been exchanged.
[0095] In addition, when a frame received by the relay unit 51 carries a FIN packet, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the FIN packet, and determines the identification information DA that matches the obtained set of the source port number and the destination port number from the identification information DA stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DA to state information indicating a transition to a state where the FIN packet has been exchanged. In addition, the monitoring unit 52 obtains the receiving time tea1, which is the receiving time te of the frame carrying the FIN packet, and stores the obtained receiving time tea1 in the storage unit 55 in correspondence with the determined identification information DA. The receiving time tea1 corresponds to the time when the state of the communication connection to be monitored transitions to a state where the FIN packet has been exchanged.
[0096] In addition, when the frame received by the relay unit 51 carries a FIN / ACK packet, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the FIN / ACK packet, and determines the identification information DA that matches the obtained set of the source port number and the destination port number from the identification information DA stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DA to state information indicating a transition to a state where the FIN / ACK packet has been exchanged. In addition, the monitoring unit 52 then obtains the receiving time tea2, which is the receiving time te of the frame carrying the FIN / ACK packet, and stores the obtained receiving time tea2 in the storage unit 55 in correspondence with the determined identification information DA. The receiving time tea2 corresponds to the moment when the state of the communication connection to be monitored transitions to a state where the FIN / ACK packet has been exchanged.
[0097] In addition, when the frame received by the relay unit 51 carries an ACK packet, the monitoring unit 52 obtains the source port number and the destination port number from the TCP header of the ACK packet, and determines the identification information DA that matches the obtained set of the source port number and the destination port number from the identification information DA stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DA to state information indicating a transition to a state where an ACK packet has been exchanged for a FIN / ACK packet. In addition, the monitoring unit 52 obtains a receiving time tea3, which is a receiving time te when the relay unit 51 receives the frame carrying the ACK packet, and stores the obtained receiving time tea3 in the storage unit 55 in correspondence with the determined identification information DA. The receiving time tea3 corresponds to the moment when the state of the communication connection to be monitored transitions to a state where an ACK packet has been exchanged for a FIN / ACK packet.
[0098] The detection unit 53 calculates a cycle C1A, which is a cycle C1 for establishing a TCP connection between the communication device 111A and the communication device 111B, based on a plurality of reception times ts stored in the storage unit 55 by the monitoring unit 52. In more detail, each time the status information in the storage unit 55 is updated by the monitoring unit 52 and the reception time tsa3 is stored in the storage unit 55 by the monitoring unit 52, the detection unit 53 calculates the difference between the reception time tsa3 and the reception time tsa3 before the reception time tsa3 as the cycle C1A. It should be noted that the detection unit 53 may also be a structure that calculates the cycle C1A based on the reception time tsa2 or the reception time tsa1 instead of the reception time tsa3. In addition, the detection unit 53 may also be a structure that calculates the cycle C1A based on the reception time of a frame carrying a TCP data packet with the PSH flag set to on in the relay unit 51 in a state where the TCP connection is established.
[0099] For example, the detection unit 53 compares the calculated period C1A with the predetermined threshold values TcLA and TcHA. Here, it is assumed that the threshold value TcLA is smaller than the threshold value TcHA. For example, the threshold values TcLA and TcHA are preset based on the monitoring results of TCP connections established in the normal network 12 where no illegal communication connection exists.
[0100] When the period C1A is greater than or equal to the threshold value TcLA and less than or equal to the threshold value TcHA, the detection unit 53 determines that there is no illegal communication connection in the network 12. On the other hand, when the period C1A is less than the threshold value TcLA or the period C1A is greater than the threshold value TcHA, the detection unit 53 determines that there is an illegal communication connection in the network 12.
[0101] Figure 6 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Figure 6 A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0102] Reference Figure 6 For example, an illegal communication device, i.e., an illegal device, obtains the source port number and the destination port number from the TCP header in the frame sent from the communication device 111A to the communication device 111B, and impersonates the communication device 111A to send a SYN packet to the communication device 111B via the relay device 101. In addition, the illegal device impersonates the communication device 111A and sends an ACK packet to the communication device 111B via the relay device 101 as a response to the SYN / ACK packet from the communication device 111B, thereby establishing an illegal communication connection, i.e., an illegal TCP connection, with the communication device 111B.
[0103] After establishing a TCP connection with the communication device 111B, the illegal device sends an illegal message (not shown) to the communication device 111B via the relay device 101. Then, the illegal device impersonates the communication device 111A and sends a FIN packet to the communication device 111B via the relay device 101. In addition, the illegal device impersonates the communication device 111A and sends an ACK packet to the communication device 111B via the relay device 101 as a response to the FIN / ACK packet from the communication device 111B, thereby terminating the TCP connection with the communication device 111B.
[0104] For example, when an illegal TCP connection is established during the period between connection period T1A of the nth TCP connection between communication device 111A and communication device 111B and connection period T1A of the n+1th TCP connection between communication device 111A and communication device 111B, the number of ACK packets sent to communication device 111B in response to SYN / ACK packets increases compared to a case where the illegal TCP connection is not established.
[0105] In this case, since the difference between the reception time tsa3 of the SYN packet transmitted from the illegal device and the reception time tsa3 of the SYN packet transmitted from the communication device 111A immediately before the SYN packet, that is, the period C1A, is smaller than the threshold value TcLA, the detection unit 53 determines that an illegal communication connection exists in the network 12. In addition, since the difference between the reception time tsa3 of the SYN packet transmitted from the communication device 111A and the reception time tsa3 of the SYN packet transmitted from the illegal device immediately before the SYN packet, that is, the period C1A, is smaller than the threshold value TcLA, the detection unit 53 determines that an illegal communication connection exists in the network 12.
[0106] It should be noted that the detection unit 53 can also be configured as follows: instead of the specific example 1 of the above-mentioned detection processing, or based on the specific example 1 of the detection processing, the variance of the period C1A is calculated, and based on the comparison result of the calculated variance with the specified threshold value, the existence of illegal communication connections in the network 12 is detected.
[0107] (Specific example 2 of detection processing)
[0108] Figure 7 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Figure 7 A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0109] Reference Figure 7 The detection unit 53 calculates the frequency F1, i.e., the frequency F1A, of establishing the TCP connection between the communication device 111A and the communication device 111B based on the multiple reception times tsa3 stored in the storage unit 55 by the monitoring unit 52. In more detail, for example, the detection unit 53 calculates the number of times the relay unit 51 receives an ACK packet as a response to the SYN / ACK packet in a unit time of a specified length as the frequency F1A at the detection timing according to the specified period. It should be noted that the detection unit 53 may also be a structure that calculates the frequency F1A based on the reception time tsa1, the reception time tsa3, the reception time tea1, the reception time tea2, or the reception time tea3 instead of the reception time tsa3.
[0110] For example, the detection unit 53 compares the calculated frequency F1A with the predetermined threshold values TfLA and TfHA. Here, it is assumed that the threshold value TfLA is smaller than the threshold value TfHA. For example, the threshold values TfLA and TfHA are preset based on the monitoring results of the TCP connection established in the normal network 12 where no illegal communication connection exists.
[0111] When the frequency F1A is greater than or equal to the threshold value TfLA and less than or equal to the threshold value TfHA, the detection unit 53 determines that there is no illegal communication connection in the network 12 during the period from the last detection timing to the current detection timing. On the other hand, when the frequency F1A is less than the threshold value TfLA or the frequency F1A is greater than the threshold value TfHA, the detection unit 53 determines that there is an illegal communication connection in the network 12 during the period from the last detection timing to the current detection timing.
[0112] Figure 8 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Figure 8A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0113] Reference Figure 8 When an illegal TCP connection is repeatedly established between an illegal device and the communication device 111B, the number of ACK packets sent to the communication device 111B in response to SYN / ACK packets increases compared to a case where no illegal TCP connection is established.
[0114] In this case, since the frequency F1A calculated at the detection timing is larger than the threshold value TfHA, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing.
[0115] It should be noted that the detection unit 53 may also be configured as follows: at the time point when the number of ACK packets for SYN / ACK packets sent to the communication device 111B before the unit time exceeds the threshold value TfLA, it is determined that an illegal communication connection exists in the network 12. In addition, the detection unit 53 may also be configured as follows: instead of calculating the frequency F1A at the detection timing according to the prescribed period, the frequency F1A in the most recent unit time of the prescribed length is calculated each time the reception time tsa3 is stored in the storage unit 55 by the monitoring unit 52.
[0116] (Specific example 3 of detection processing)
[0117] Refer again Figure 7 The detection unit 53 calculates the ratio R1 of the total of the connection period T1A per unit time, that is, the ratio R1A, based on the reception time tsa3 and the corresponding reception time tea3 stored in the storage unit 55 by the monitoring unit 52 at the detection timing according to the prescribed cycle.
[0118] For example, the detection unit 53 compares the calculated ratio R1A with the predetermined thresholds TrLA and TrHA. Here, it is assumed that the threshold TrLA is smaller than the threshold TrHA. For example, the thresholds TrLA and TrHA are preset based on the monitoring results of TCP connections established in the normal network 12 without any illegal communication connection.
[0119] When the ratio R1A is greater than or equal to the threshold value TrLA and less than or equal to the threshold value TrHA, the detection unit 53 determines that there is no illegal communication connection in the network 12 from the last detection timing to the current detection timing. On the other hand, when the ratio R1A is less than the threshold value TrLA or the ratio R1A is greater than the threshold value TrHA, the detection unit 53 determines that there is an illegal communication connection in the network 12 from the last detection timing to the current detection timing.
[0120] Refer again Figure 8 When an illegal TCP connection is repeatedly established between an illegal device and the communication device 111B, the total of the connection periods T1A per unit time increases compared to a case where no illegal TCP connection is established.
[0121] In this case, since the ratio R1A calculated at the detection timing is larger than the threshold value TrHA, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing.
[0122] It should be noted that the detection unit 53 may be configured such that, at a time point when the total value of each connection period T1A exceeds a prescribed value before a unit time has passed, it is determined that an illegal communication connection exists in the network 12. In addition, the detection unit 53 may be configured such that, instead of calculating the ratio R1A at a detection timing according to a prescribed period, the ratio R1A in the most recent unit time of a prescribed length is calculated each time the reception time tsa3 is stored in the storage unit 55 by the monitoring unit 52.
[0123] In addition, the detection unit 53 may also be configured as follows: based on the specific example 3 of the above-mentioned detection processing, whenever the connection period T1A is calculated based on the reception time tsa3 and the corresponding reception time tea3 stored in the storage unit 55 by the monitoring unit 52, it is determined whether there is an illegal communication connection in the network 12 based on the comparison result of the calculated connection period T1A and a specified threshold. Here, for example, the connection period T1A of the illegal TCP connection is greater than the normal value by a specified value or less than the normal value by a specified value. Therefore, the detection unit 53 can determine whether there is an illegal communication connection in the network 12 based on the comparison result of the connection period T1A and the specified threshold.
[0124] The monitoring unit 52 is not limited to a configuration that monitors communication connections established and terminated in accordance with a connection-type protocol, and may also be a configuration that monitors communication connections established and terminated in accordance with other protocols.
[0125] (Specific example 4 of detection processing)
[0126] Fig. 9 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 9 A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0127] Reference Fig. 9In the network 12, messages are sent and received according to SOME / IP, which is a protocol of the application layer of the Ethernet protocol suite. For example, the communication device 111 can send and receive messages according to SOME / IP instead of or in parallel with the sending and receiving of messages according to TCP / IP.
[0128] The communication device 111 establishes a communication connection for providing periodic services using the Publish / Subscribe function of SOME / IP. Hereinafter, the communication connection for providing periodic services under SOME / IP is also referred to as a "SOME / IP connection."
[0129] More specifically, when receiving provision of a service, the communication device 111B, as a client, broadcasts a Find message including a service ID corresponding to the service.
[0130] Among the multiple communication devices 111 that have received the Find message, the communication device 111A having an application that can provide a service corresponding to the service ID included in the Find message acts as a server and sends an Offer message indicating the start of providing the service to the communication device 111B via the relay device 101. The SOME / IP header of the Offer message carries the ID of the communication device 111A, that is, the server ID, etc.
[0131] Then, when requesting the communication device 111A to provide a periodic service, the communication device 111B uses the server ID acquired from the Offer message to transmit a Subscribe message including the server ID and the service ID to the communication device 111A via the relay device 101 .
[0132] The communication device 111A receives the Subscribe message and confirms the service ID included in the Subscribe message. Then, if the service ID is consistent with the service ID corresponding to the service that can be provided, the communication device 111A sends a message indicating consent to provide the service, that is, a SubscribeAck message, to the communication device 111B via the relay device 101. Thus, the nth SOME / IP connection between the communication device 111A and the communication device 111B is established. The Subscribe message and the SubscribeAck message are examples of a stateful message MS.
[0133] Furthermore, when the communication device 111B stops receiving provision of services, that is, when terminating the SOME / IP connection, it transmits a StopSubscribe message to the communication device 111A via the relay device 101. The StopSubscribe message is an example of a state message ME.
[0134] During the connection period T1B during which the SOME / IP connection with the communication device 111B is established, the communication device 111A periodically transmits a Notification message, which is a message in accordance with SOME / IP, to the communication device 111B via the relay device 101 as a service provision.
[0135] Then, similarly, the establishment and termination of the SOME / IP connection between the communication device 111A and the communication device 111B are repeated using the Subscribe message, the SubscribeAck message, and the StopSubscribe message.
[0136] It should be noted that the SOME / IP connection may be terminated by the communication device 111A instead of the communication device 111B. Specifically, the communication device 111A sends a StopOffer message to the communication device 111B via the relay device 101. As a result, the SOME / IP connection between the communication device 111A and the communication device 111B is terminated. In this case, the establishment and termination of the SOME / IP connection between the communication device 111A and the communication device 111B are repeated using the Find message, the Offer message, the Subscribe message, the SubscribeAck message, and the StopOffer message.
[0137] The monitoring unit 52 monitors a SOME / IP connection as an example of a communication connection established in the network 12. As described above, a SOME / IP connection is established using a SubscribeAck message and terminated using a StopOffer message or a StopSubscribe message. For example, the monitoring unit 52 monitors a SOME / IP connection established in the network 12 for each service ID.
[0138] More specifically, when the frame received by the relay unit 51 carries a Subscribe message, the monitoring unit 52 determines that a SOME / IP connection is established between the communication device 111 as the transmission source of the frame and the communication device 111 as the destination of the frame.
[0139] Then, the monitoring unit 52 obtains the service ID from the SOME / IP header of the Subscribe message, and stores the obtained service ID in the storage unit 55 as the identification information DB indicating the communication connection to be monitored. In addition, the monitoring unit 52 generates state information indicating that the state of the communication connection to be monitored has changed to a state in which the Subscribe message has been exchanged, and stores the generated state information in the storage unit 55 in correspondence with the identification information DB. In addition, the monitoring unit 52 obtains the reception time tsb1, which is the reception time ts at which the relay unit 51 receives the frame carrying the Subscribe message, and stores the obtained reception time tsb1 in correspondence with the identification information DB in the storage unit 55. The reception time tsb1 corresponds to the time when the state of the communication connection to be monitored has changed to a state in which the Subscribe message has been exchanged.
[0140] In addition, when the frame received by the relay unit 51 carries a SubscribeAck message, the monitoring unit 52 obtains the service ID from the SOME / IP header of the SubscribeAck message, and determines the identification information DB that matches the obtained service ID from the identification information DB stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DB to state information indicating a transition to a state in which the SubscribeAck message has been exchanged. In addition, the monitoring unit 52 obtains the reception time tsb2, which is the reception time ts at which the relay unit 51 receives the frame carrying the SubscribeAck message, and stores the obtained reception time tsb2 in the storage unit 55 in correspondence with the determined identification information DB. The reception time tsb2 corresponds to the time when the state of the communication connection to be monitored transitions to a state in which the SubscribeAck message has been exchanged.
[0141] In addition, when the frame received by the relay unit 51 carries a StopSubscribe message, the monitoring unit 52 obtains the service ID from the SOME / IP header of the StopSubscribe message, and determines the identification information DB that matches the obtained service ID from the identification information DB stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DB to state information indicating a transition to a state in which the StopSubscribe message has been exchanged. In addition, the monitoring unit 52 obtains the reception time teb1, which is the reception time te of the frame carrying the StopSubscribe message, and stores the obtained reception time teb1 in the storage unit 55 in correspondence with the determined identification information DB. The reception time teb1 corresponds to the time when the state of the communication connection to be monitored transitions to a state in which the StopSubscribe message has been exchanged.
[0142] The detection unit 53 calculates a cycle C1B, which is a cycle C1 for establishing a SOME / IP connection between the communication device 111A and the communication device 111B, based on a plurality of reception times ts stored in the storage unit 55 by the monitoring unit 52. In more detail, each time the state information in the storage unit 55 is updated by the monitoring unit 52 and the reception time tsb2 is stored in the storage unit 55 by the monitoring unit 52, the detection unit 53 calculates the difference between the reception time tsb2 and the reception time tsb2 before the reception time tsb2 as the cycle C1B. It should be noted that the detection unit 53 may also be a structure that calculates the cycle C1B based on the reception time tsb1 instead of the reception time tsb2. In addition, the detection unit 53 may also be a structure that calculates the cycle C1B based on the reception time of the frame carrying the Notification message in the relay unit 51 in the state where the SOME / IP connection is established.
[0143] For example, the detection unit 53 compares the calculated cycle C1B with the predetermined threshold values TcLB and TcHB. Here, it is assumed that the threshold value TcLB is smaller than the threshold value TcHB. For example, the threshold values TcLB and TcHB are preset based on the monitoring results of the SOME / IP connection established in the normal network 12 without any illegal communication connection.
[0144] When the period C1B is greater than or equal to the threshold value TcLB and less than or equal to the threshold value TcHB, the detection unit 53 determines that there is no illegal communication connection in the network 12. On the other hand, when the period C1B is less than the threshold value TcLB or the period C1B is greater than the threshold value TcHB, the detection unit 53 determines that there is an illegal communication connection in the network 12.
[0145] Fig.10This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig.10 A sequence diagram of messages transmitted and received by the communication devices 111A and 111B as the communication device 111 is shown.
[0146] Reference Fig.10 For example, an illegal communication device, i.e., an illegitimate device, obtains a service ID from a SOME / IP header in a frame sent from the communication device 111A to the communication device 111B, and after the communication device 111B sends a Subscribe message, it impersonates the communication device 111A and sends a SubscribeAck message to the communication device 111B via the relay device 101, thereby establishing an illegal SOME / IP connection with the communication device 111B.
[0147] After establishing a SOME / IP connection with communication device 111B, the illegal device sends an illegal Notification message to communication device 111B via relay device 101. Then, communication device 111B sends a StopSubscribe message to the illegal device via relay device 101 to terminate the SOME / IP connection with the illegal device.
[0148] In addition, as a response to the Subscribe message sent by the communication device 111B, the communication device 111A, which is a legitimate server, sends a SubscribeAck message to the communication device 111B via the relay device 101. For example, when the communication device 111B receives a SubscribeAck message in response to the Subscribe message from the communication device 111A after establishing a SOME / IP connection with an illegal device by sending and receiving Subscribe messages and SubscribeAck messages, the communication device 111B ignores the SubscribeAck message received from the communication device 111A and does not establish a SOME / IP connection with the communication device 111A.
[0149] In addition, for example, an illegal device may sometimes pretend to be the communication device 111B as a client and send a Subscribe message to the communication device 111A via the relay device 101. In this case, an illegal SOME / IP connection between the illegal device and the communication device 111A is established by the communication device 111A sending a SubscribeAck message to the illegal device via the relay device 101. In this case, after the communication device 111A establishes the SOME / IP connection with the illegal device, it sends a Notification message to the illegal device via the relay device 101.
[0150] When an illegal SOME / IP connection is established between an illegal device and communication device 111, the number of SubscribeAck messages sent to communication device 111B or SubscribeAck messages sent by communication device 111A increases compared to a case where an illegal SOME / IP connection is not established.
[0151] In this case, since the difference between the reception time tsb2 of the SubscribeAck message sent from the communication device 111A and the reception time tsb2 of the SubscribeAck message sent from the illegal device just before the SubscribeAck message, that is, the cycle C1B, is smaller than the threshold TcLB, the detection unit 53 determines that an illegal communication connection exists in the network 12.
[0152] It should be noted that the detection unit 53 can also be configured as follows: instead of the specific example 4 of the above-mentioned detection processing, or based on the specific example 4 of the detection processing, the variance of the period C1B is calculated, and based on the comparison result between the calculated variance and the specified threshold value, it is determined whether there is an illegal communication connection in the network 12.
[0153] In addition, the detection unit 53 can also be configured as follows: instead of the specific example 4 of the above-mentioned detection processing, or on the basis of the specific example 4 of the detection processing, based on the multiple receiving times tsb2 stored in the storage unit 55 by the monitoring unit 52, the frequency F1, that is, the frequency F1B for establishing the SOME / IP connection between the communication device 111A and the communication device 111B is calculated, and based on the comparison result of the calculated frequency F1B with the specified threshold value, the existence of an illegal communication connection in the network 12 is detected.
[0154] In addition, the detection unit 53 can also be configured as follows: instead of the specific example 4 of the above-mentioned detection processing, or on the basis of the specific example 4 of the detection processing, based on the receiving time tsb2 and the corresponding receiving time teb1 stored in the storage unit 55 by the monitoring unit 52, the proportion R1 of the connection period T1B per unit time, that is, the proportion R1B, is calculated, and based on the comparison result of the calculated proportion R1B with the specified threshold value, the existence of an illegal communication connection in the network 12 is detected.
[0155] Furthermore, the detection unit 53 may be configured to detect the presence of an illegal communication connection in the network 12 based on the transmission timing of the Request message and the Response message according to SOME / IP in the network 12 in the above-mentioned specific example 4 of the detection process.
[0156] More specifically, the communication device 111B transmits a Request message including a server ID and a service ID to the communication device 111A via the relay device 101. In response to the Request message, the communication device 111A transmits a Response message including a server ID and a service ID via the relay device 101 to the communication device 111B.
[0157] The monitoring unit 52 in the relay device 101 obtains the reception time of the frame carrying the Request message and the reception time of the frame carrying the Response message received by the relay unit 51, and stores them in the storage unit 55. The detection unit 53 calculates the difference D between the reception time of the frame carrying the Request message and the reception time of the frame carrying the Response message stored in the storage unit 55, and detects an illegal communication connection in the network 12 based on the comparison result between the calculated difference D and a predetermined threshold. Here, for example, in the case where the Response message is sent to the communication device 111B via the relay device 101 by an illegal device instead of the communication device 111A, the difference D calculated by the detection unit 53 is greater than the normal value by a predetermined value or less than the normal value by a predetermined value. Therefore, the detection unit 53 can determine whether there is an illegal communication connection in the network 12 based on the comparison result between the difference D and the predetermined threshold.
[0158] (Specific example 5 of detection processing)
[0159] Fig.11 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig.11 A sequence diagram of messages transmitted and received by the communication devices 111D and 111E as the communication device 111 is shown.
[0160] Reference Fig.11 In the network 12, messages are sent and received according to DDS (Data Distribution Service). The communication device 111 establishes a communication connection for obtaining data from other communication devices 111 or cloud servers that function as DDS domains. Hereinafter, the communication connection for obtaining data under DDS is also referred to as a "DDS connection".
[0161] More specifically, the communication device 111E functions as a DDS domain, receives data periodically or irregularly from other communication devices 111 other than the communication devices 111D and 111E, and accumulates the received data.
[0162] When the communication device 111D obtains data related to a certain topic generated by using an application corresponding to the topic from the communication device 111E, it generates a create_subscriber message including a topic ID corresponding to the topic, and sends the generated create_subscriber message to the communication device 111E via the relay device 101. Thus, the nth DDS connection between the communication device 111D and the communication device 111E is established. The create_subscriber message is an example of a stateful message MS.
[0163] When communication device 111D ends acquiring data from communication device 111E, that is, when ending the DDS connection, communication device 111D transmits a Delete_subscriber message to communication device 111E via relay device 101. Thus, the DDS connection between communication device 111D and communication device 111E ends. The Delete_subscriber message is an example of a stateful message ME.
[0164] During connection period T1C, during which the DDS connection with communication device 111D is established, communication device 111E includes data indicated by the topic ID included in the create_subscriber message in an on_data_available message, which is a DDS message, and transmits the message to communication device 111D via relay device 101 .
[0165] Then, similarly, the establishment and termination of the DDS connection between the communication device 111D and the communication device 111E are repeated.
[0166] The monitoring unit 52 monitors a DDS connection, which is an example of a communication connection established in the network 12. As described above, a DDS connection is established using a create_subscriber message and terminated using a delete_subscriber message. For example, the monitoring unit 52 monitors a DDS connection established in the network 12 for each topic ID.
[0167] More specifically, when the frame received by the relay unit 51 carries a create_subscriber message, the monitoring unit 52 determines that a DDS connection is established between the communication device 111 that is the transmission source of the frame and the communication device 111 that is the destination of the frame.
[0168] Then, the monitoring unit 52 obtains the topic ID from the header of the create_subscriber message, and stores the obtained topic ID in the storage unit 55 as identification information DC indicating the communication connection to be monitored. In addition, the monitoring unit 52 generates state information indicating that the state of the communication connection to be monitored has changed to a state in which the create_subscriber message has been exchanged, and stores the generated state information in the storage unit 55 in correspondence with the identification information DC. In addition, the monitoring unit 52 obtains the reception time tsc1, which is the reception time ts at which the relay unit 51 receives the frame carrying the create_subscriber message, and stores the obtained reception time tsc1 in correspondence with the identification information DC in the storage unit 55. The reception time tsc1 corresponds to the time when the state of the communication connection to be monitored has changed to a state in which the create_subscriber message has been exchanged.
[0169] In addition, when the frame received by the relay unit 51 carries a Delete_subscriber message, the monitoring unit 52 obtains the topic ID from the header of the Delete_subscriber message, and determines the identification information DC that matches the obtained topic ID from the identification information DC stored in the storage unit 55. Then, the monitoring unit 52 updates the state information corresponding to the determined identification information DC to state information indicating a transition to a state in which the Delete_subscriber message has been exchanged. In addition, the monitoring unit 52 obtains a reception time tec1, which is a reception time te of the frame carrying the Delete_subscriber message, and stores the obtained reception time tec1 in the storage unit 55 in correspondence with the determined identification information DC. The reception time tec1 corresponds to the time when the state of the communication connection to be monitored transitions to a state in which the Delete_subscriber message has been exchanged.
[0170] The detection unit 53 calculates the ratio R1 of the connection period T1C per unit time, ie, the ratio R1C, based on the reception time tsc1 and the corresponding reception time tec1 stored in the storage unit 55 by the monitoring unit 52 at the detection timing in a predetermined cycle.
[0171] For example, the detection unit 53 compares the calculated ratio R1C with the predetermined threshold values TrLC and TrHC. Here, it is assumed that the threshold value TrLC is smaller than the threshold value TrHC. For example, the threshold values TrLC and TrHC are preset based on the monitoring results of the DDS connection established in the normal network 12 where no illegal communication connection exists.
[0172] When the ratio R1C is greater than or equal to the threshold value TrLC and less than or equal to the threshold value TrHC, the detection unit 53 determines that there is no illegal communication connection in the network 12 during the period from the last detection timing to the current detection timing. On the other hand, when the ratio R1C is less than the threshold value TrLC or the ratio R1C is greater than the threshold value TrHC, the detection unit 53 determines that there is an illegal communication connection in the network 12 during the period from the last detection timing to the current detection timing.
[0173] Fig.12 This is a diagram showing an example of a communication connection operation of a monitoring target by a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig.12 A sequence diagram of messages transmitted and received by the communication devices 111D and 111E as the communication device 111 is shown.
[0174] Reference Fig.12 For example, an illegal device obtains a topic ID from a header in a frame sent by communication device 111D to communication device 111E, and sends a create_subscriber message to communication device 111E via relay device 101, impersonating communication device 111D, thereby establishing an illegal DDS connection with communication device 111E.
[0175] After establishing a DDS connection with communication device 111E, the illegal device receives an on_data_available message from communication device 111E and obtains data from the received on_data_available message. Then, the illegal device sends a Delete_subscriber message to communication device 111E via relay device 101 by posing as communication device 111D, thereby terminating the DDS connection with communication device 111E.
[0176] For example, when an illegal DDS connection is repeatedly established between an illegal device and the communication device 111E, the total of the connection periods T1C per unit time increases compared to a case where an illegal DDS connection is not established.
[0177] In this case, since the ratio R1C calculated at the detection timing is larger than the threshold value TrHC, the detection unit 53 determines that an illegal communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing.
[0178] It should be noted that the detection unit 53 may be configured such that, at a time point when the total value of each connection period T1C exceeds a prescribed value before a unit time has passed, it is determined that an illegal communication connection exists in the network 12. In addition, the detection unit 53 may be configured such that, instead of calculating the ratio R1C at a detection timing according to a prescribed period, the ratio R1C in the most recent unit time of a prescribed length is calculated whenever the status information in the storage unit 55 is updated by the monitoring unit 52 and the reception time tsc1 is stored in the storage unit 55 by the monitoring unit 52, instead of calculating the ratio R1C at a detection timing according to a prescribed period.
[0179] In addition, the detection unit 53 can also be configured as follows: instead of the specific example 5 of the above-mentioned detection processing, or on the basis of the specific example 5 of the detection processing, based on the receiving time tsc1 stored in the storage unit 55 by the monitoring unit 52, the period C1, i.e., the period C1C, for establishing the DDS connection between the communication device 111D and the communication device 111E is calculated, and based on the comparison result of the calculated period C1C with the specified threshold value, the existence of an illegal communication connection in the network 12 is detected.
[0180] In addition, the detection unit 53 can also be configured as follows: instead of the specific example 5 of the above-mentioned detection processing, or on the basis of the specific example 5 of the detection processing, based on the multiple receiving times tsc1 stored in the storage unit 55 by the monitoring unit 52, the frequency F1, that is, the frequency F1C for establishing the DDS connection between the communication device 111D and the communication device 111E is calculated, and based on the comparison result of the calculated frequency F1C with the specified threshold value, the existence of an illegal communication connection in the network 12 is detected.
[0181] In addition, the detection unit 53 may also be a structure that does not perform part of the above-mentioned specific examples 1 to 5 of the detection processing.
[0182] [Action flow]
[0183] Fig.13 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure monitors a communication connection.
[0184] Reference Fig.13 The relay device 101 waits for the arrival of a frame from the communication device 111 ("No" in step S11). If a frame is received ("Yes" in step S11), the content of the message carried in the frame is confirmed by referring to the header information of the received frame (step S12).
[0185] Next, when the message carried in the received frame is not a stateful message MS such as the SYN packet and SYN / ACK packet according to TCP / IP, the Subscribe message and SubscribeAck message according to SOME / IP, and the create_subscriber message according to DDS, and is not a stateful message ME such as the FIN packet and FIN / ACK packet according to TCP / IP, the StopOffer message and StopSubscribe message according to SOME / IP, and the Delete_subscriber message according to DDS ("No" in step S13), the relay device 101 sends the received frame to the communication device 111 as the destination (step S14).
[0186] On the other hand, when the message carried in the received frame is a stateful message MS or a stateful message ME ("Yes" in step S13), the relay device 101 determines that the state of the communication connection between the communication device 111 as the transmission source of the frame and the communication device 111 as the destination of the frame has changed, and obtains the identification information DA, DB, DC indicating the communication connection as the monitoring object and the reception time of the frame. The relay device 101 stores the reception time of the frame in the storage unit 55 in correspondence with the identification information DA, DB, DC. In addition, the relay device 101 generates or updates the state information indicating that the state of the communication connection as the monitoring object has changed (step S15).
[0187] Next, the relay device 101 transmits the frame to the communication device 111 as the destination (step S14).
[0188] Next, the relay device 101 waits for arrival of a new frame from the communication device 111 (No in step S11 ).
[0189] Fig.14 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. Fig.14 This is a flowchart showing a specific example 1 of the above-mentioned detection process.
[0190] Reference Fig.14 , the detection unit 53 in the relay device 101 waits for the status information in the storage unit 55 to be updated by the monitoring unit 52 and the receiving time tsa3 to be saved in the storage unit 55 ("No" in step S21). If the status information is updated and the receiving time tsa3 is saved in the storage unit 55 ("Yes" in step S21), the difference between the receiving time tsa3 and the previous receiving time tsa3 corresponding to the same identification information DA is calculated as the period C1A (step S22).
[0191] Next, the detection unit 53 compares the calculated period C1A with predetermined threshold values TcLA and TcHA (step S23 ).
[0192] Next, when the period C1A is equal to or greater than the threshold value TcLA and equal to or less than the threshold value TcHA (YES in step S24 ), the detection unit 53 determines that there is no illegal communication connection in the network 12 (step S25 ).
[0193] Next, the detection unit 53 waits for the monitoring unit 52 to update the status information in the storage unit 55 and stores the new reception time tsa3 in the storage unit 55 (No in step S21).
[0194] On the other hand, when the cycle C1A is smaller than the threshold value TcLA or the cycle C1A is larger than the threshold value TcHA (No in step S24), the detection unit 53 determines that an illegal communication connection exists in the network 12 (step S26).
[0195] Next, the output unit 54 outputs a warning to the effect that an illegal communication connection has been detected to the user's terminal or the like (step S27 ).
[0196] Next, the detection unit 53 waits for the monitoring unit 52 to update the status information in the storage unit 55 and stores the new reception time tsa3 in the storage unit 55 (No in step S21).
[0197] Fig.15 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. Fig.15 This is a flowchart showing a specific example 2 of the above-mentioned detection processing.
[0198] Reference Fig.15 The detection unit 53 in the relay device 101 waits for the arrival of the detection opportunity according to the specified period ("No" in step S31). If the detection opportunity arrives ("Yes" in step S31), based on the multiple receiving times tsa3 stored in the storage unit 55, the number of times the relay unit 51 receives an ACK data packet as a response to the SYN / ACK data packet in a unit time of a specified length is calculated as a frequency F1A (step S32).
[0199] Next, the detection unit 53 compares the calculated frequency F1A with predetermined threshold values TfLA and TfHA (step S33).
[0200] Next, when frequency F1A is greater than threshold TfLA and less than threshold TfHA (YES in step S34), detection unit 53 determines that no illegal communication connection exists in network 12 during the period from the last detection timing to this detection timing (step S35).
[0201] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S31 ).
[0202] On the other hand, when the frequency F1A is less than the threshold TfLA, or the frequency F1A is greater than the threshold TfHA ("No" in step S34), the detection unit 53 determines that there is an illegal communication connection in the network 12 during the period from the last detection timing to the current detection timing (step S36).
[0203] Next, the output unit 54 outputs a warning to the effect that an illegal communication connection has been detected to the user's terminal or the like (step S37 ).
[0204] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S31 ).
[0205] Fig.16 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. Fig.16 This is a flowchart showing a specific example 3 of the above-mentioned detection processing.
[0206] Reference Fig.16 The detection unit 53 in the relay device 101 waits for the arrival of the detection opportunity according to the prescribed period ("No" in step S41). If the detection opportunity arrives ("Yes" in step S41), based on the receiving time tsa3 and the corresponding receiving time tea3 stored in the storage unit 55, the proportion R1A of the connection period T1A per unit time is calculated (step S42).
[0207] Next, the detection unit 53 compares the calculated ratio R1A with predetermined threshold values TrLA and TrHA (step S43).
[0208] Next, when ratio R1A is greater than or equal to threshold TrLA and less than or equal to threshold TrHA (YES in step S44), detection unit 53 determines that no illegal communication connection exists in network 12 from the last detection timing to this detection timing (step S45).
[0209] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S41 ).
[0210] On the other hand, when the ratio R1A is smaller than the threshold TrLA or larger than the threshold TrHA (No in step S44), the detection unit 53 determines that an illegal communication connection exists in the network 12 during the period from the last detection timing to the current detection timing (step S46).
[0211] Next, the output unit 54 outputs a warning to the effect that an illegal communication connection has been detected to the user's terminal or the like (step 47 ).
[0212] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S41 ).
[0213] Fig.17 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. Fig.17 It is a flowchart showing a specific example 4 of the above-mentioned detection processing.
[0214] Reference Fig.17 , the detection unit 53 in the relay device 101 waits for the status information in the storage unit 55 to be updated by the monitoring unit 52 and the receiving time tsb2 to be saved in the storage unit 55 ("No" in step S51). If the status information is updated and the receiving time tsb2 is saved in the storage unit 55 ("Yes" in step S51), the difference between the receiving time tsb2 and the previous receiving time tsb2 corresponding to the same identification information DB is calculated as the period C1B (step S52).
[0215] Next, the detection unit 53 compares the calculated cycle C1B with predetermined threshold values TcLB and TcHB (step S53 ).
[0216] Next, when the cycle C1B is equal to or greater than the threshold value TcLB and equal to or less than the threshold value TcHB (YES in step S54 ), the detection unit 53 determines that there is no illegal communication connection in the network 12 (step S55 ).
[0217] Next, the detection unit 53 waits for the monitoring unit 52 to update the status information in the storage unit 55 and stores the new reception time tsb2 in the storage unit 55 (No in step S51).
[0218] On the other hand, when the cycle C1B is smaller than the threshold value TcLB or the cycle C1B is larger than the threshold value TcHB (No in step S54), the detection unit 53 determines that an illegal communication connection exists in the network 12 (step S56).
[0219] Next, the output unit 54 outputs a warning to the effect that an illegal communication connection has been detected to the user's terminal or the like (step S57 ).
[0220] Next, the detection unit 53 waits for the monitoring unit 52 to update the status information in the storage unit 55 and stores the new reception time tsb2 in the storage unit 55 (No in step S51).
[0221] Fig.18 This is a flowchart that defines an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing. Fig.18 This is a flowchart showing a specific example 5 of the above-mentioned detection processing.
[0222] Reference Fig.18 The detection unit 53 in the relay device 101 waits for the arrival of the detection opportunity according to the prescribed period ("No" in step S61). If the detection opportunity arrives ("Yes" in step S61), based on the receiving time tsc1 and the corresponding receiving time tec1 stored in the storage unit 55, the proportion R1C of the connection period T1C per unit time is calculated (step S62).
[0223] Next, the detection unit 53 compares the calculated ratio R1C with predetermined threshold values TrLC and TrHC (step S63).
[0224] Next, when ratio R1C is greater than or equal to threshold TrLC and ratio R1A is less than or equal to threshold TrHC (YES in step S64), detection unit 53 determines that no illegal communication connection exists in network 12 from the last detection timing to this detection timing (step S65).
[0225] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S61 ).
[0226] On the other hand, when the ratio R1C is smaller than the threshold TrLC or the ratio R1C is larger than the threshold TrHC (No in step S64), the detection unit 53 determines that an illegal communication connection exists in the network 12 during the period from the last detection timing to the current detection timing (step S66).
[0227] Next, the output unit 54 outputs a warning to the effect that an illegal communication connection has been detected to the user's terminal or the like (step 67 ).
[0228] Next, the detection unit 53 waits for a new detection timing to arrive (No in step S61 ).
[0229] It should be noted that, in the network 12 involved in the embodiment of the present disclosure, it is assumed that the relay device 101 functioning as the detection device is directly connected to the transmission line 14, but the present invention is not limited thereto. The detection device may also be a structure connected to the transmission line 14 via the communication device 111. In this case, the detection device detects the existence of an illegal communication connection by, for example, monitoring messages sent and received by the communication device 111.
[0230] In addition, in the network 12 involved in the embodiment of the present disclosure, it is assumed that the structure of sending and receiving messages is in accordance with TCP / IP, SOME / IP and DDS, but it is not limited to this. For example, it is also possible to have a structure of sending and receiving messages in accordance with Modbus TCP in the network 12. In this case, the relay device 101 detects the existence of an illegal communication connection by monitoring the messages sent and received by the communication device 111 in accordance with Modbus TCP.
[0231] In addition, in the relay device 101 involved in the embodiment of the present disclosure, the monitoring unit 52 is assumed to be a structure that generates and updates the status information, but is not limited to this. The monitoring unit 52 may also be a structure that does not generate and update the status information. That is, the monitoring unit 52 may also be a structure that does not monitor the state transition of the communication connection that is the monitored object. In this case, the monitoring unit 52 obtains the reception time ts of the frame carrying a specific message, and stores the obtained reception time ts in the storage unit 55. The detection unit 53 detects the existence of an illegal communication connection based on the reception time ts of the specific message.
[0232] More specifically, for example, when a frame received by the relay unit 51 carries a SYN packet, the monitoring unit 52 obtains the reception time tsa1 of the frame, and stores the obtained reception time tsa1 in association with the identification information DA in the storage unit 55. Whenever the monitoring unit 52 stores the reception time tsa1 in the storage unit 55, the detection unit 53 calculates the difference between the reception time tsa1 and the reception time tsa1 immediately before the reception time tsa1 as a cycle C1A, and detects the presence of an illegal communication connection based on a plurality of cycles C1A.
[0233] Alternatively, when a SYN / ACK packet is carried in a frame received by the relay unit 51, the monitoring unit 52 obtains the reception time tsa2 of the frame, and stores the obtained reception time tsa2 in association with the identification information DA in the storage unit 55. Whenever the monitoring unit 52 stores the reception time tsa2 in the storage unit 55, the detection unit 53 calculates the difference between the reception time tsa2 and the reception time tsa2 immediately before the reception time tsa2 as a cycle C1A, and detects the presence of an illegal communication connection based on a plurality of cycles C1A.
[0234] Alternatively, when a Subscribe message is carried in a frame received by the relay unit 51, the monitoring unit 52 obtains the reception time tsb1 of the frame, and stores the obtained reception time tsb1 in correspondence with the identification information DB in the storage unit 55. Whenever the monitoring unit 52 stores the reception time tsb1 in the storage unit 55, the detection unit 53 calculates the difference between the reception time tsb1 and the reception time tsb1 before the reception time tsb1 as a cycle C1B, and detects the presence of an illegal communication connection based on a plurality of cycles C1B.
[0235] In other words, it is desirable to have a technology that can more accurately detect the presence of illegal communication connections in the network 12. More specifically, in the prior art, when an illegal device impersonates a legitimate communication device 111 and establishes an illegal communication connection with another communication device 111 using stateful messages MS and ME, the illegal communication connection may not be detected.
[0236] In contrast, in the relay device 101 according to the embodiment of the present disclosure, the monitoring unit 52 monitors the communication connection established to exchange a predetermined message in the network 12. The detection unit 53 detects the presence of an illegal communication connection based on the monitoring result of the monitoring unit 52 on the plurality of communication connections.
[0237] In this way, according to the structure of detecting the existence of illegal communication connection based on the monitoring results of multiple communication connections, when the state of communication connection in network 12 changes due to the establishment of illegal communication connection, it can be determined that there is an illegal communication connection. Therefore, the existence of illegal communication connection in network 12 can be detected more accurately.
[0238] Each process (function) of the above-mentioned embodiment is implemented by a processing circuit (Circuitry) including one or more processors. The above-mentioned processing circuit can also be composed of an integrated circuit that is combined with one or more memories, various analog circuits, various digital circuits, etc. in addition to the above-mentioned one or more processors. The above-mentioned one or more memories store programs (commands) that enable the above-mentioned one or more processors to perform the above-mentioned processes. The above-mentioned one or more processors can perform the above-mentioned processes according to the above-mentioned programs read from the above-mentioned one or more memories, or they can perform the above-mentioned processes according to the logic circuits pre-designed to perform the above-mentioned processes. The above-mentioned processor can be a CPU (Central Processing Unit: Central Processing Unit), GPU (Graphics Processing Unit: Graphics Processing Unit), DSP (Digital Signal Processor: Digital Signal Processor), FPGA (Field Programmable Gate Array: Field Programmable Gate Array) and ASIC (Application Specific Integrated Circuit: Application Specific Integrated Circuit) and other various processors suitable for computer control. It should be noted that the above-mentioned multiple processors separated physically can also cooperate with each other to perform the above-mentioned processes. For example, the processors installed in each of the physically separated computers may perform the above-mentioned processes in cooperation with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), and the Internet. The above-mentioned program may be installed in the above-mentioned memory from an external server device or the like via the above-mentioned network, or may be circulated in a state stored in a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disk Read Only Memory), and a semiconductor memory, and installed in the above-mentioned memory from the above-mentioned recording medium.
[0239] It should be considered that the above embodiments are illustrative in all aspects and not restrictive. The scope of the present invention is shown by the claims rather than the above description, and is intended to include all changes within the meaning and scope equivalent to the claims.
[0240] The above description includes the following additional features.
[0241] [Note 1]
[0242] A detection device for detecting the presence of illegal communication connections in a network, the detection device comprising:
[0243] a monitoring unit that monitors a communication connection established to exchange a prescribed message in the network; and
[0244] a detection unit, which detects the existence of the illegal communication connection based on the monitoring result of the plurality of communication connections by the monitoring unit,
[0245] The monitoring unit monitors a first state message and a second state message, wherein the first state message is a message for establishing the communication connection, and the second state message is a message for terminating the communication connection.
[0246] [Note 2]
[0247] A detection device for detecting the presence of illegal communication connections in a network, the detection device comprising a processing circuit,
[0248] The processing circuit monitors communication connections established to exchange prescribed messages in the network, and detects the presence of the illegal communication connection based on monitoring results of a plurality of the communication connections.
[0249] Description of Reference Numerals
[0250] 12 Network
[0251] 14 Transmission Line
[0252] 51 Relay Department
[0253] 52 Monitoring Department
[0254] 53. Inspection Department
[0255] 54 Output
[0256] 55 Storage
[0257] 101 Relay Device
[0258] 111, 111A, 111B, 111C, 111D, 111E communication devices.
Claims
1. A detection device for detecting the presence of an illegal communication connection in a network, the detection device comprising: a monitoring unit that monitors a communication connection established to exchange a prescribed message in the network; and The detection unit detects the existence of the illegal communication connection based on the monitoring result of the plurality of communication connections by the monitoring unit.
2. The detection device according to claim 1, wherein: The detection unit detects the presence of the illegal communication connection based on a cycle in which the communication connection is established.
3. The detection device according to claim 1, wherein: The detection unit detects the presence of the illegal communication connection based on the frequency of establishing the communication connection.
4. The detection device according to claim 1, wherein: The detection unit detects the presence of the illegal communication connection based on the ratio of the period in which the communication connection is established per unit time.
5. The detection device according to any one of claims 1 to 4, wherein: The monitoring unit monitors the communication connection established using a SubscribeAck message in accordance with SOME / IP (Scalable service-oriented Middleware over IP) and terminated using a StopOffer message or a StopSubscribe message in accordance with SOME / IP.
6. The detection device according to any one of claims 1 to 4, wherein: The monitoring unit monitors a TCP (Transmission Control Protocol) connection as the communication connection.
7. The detection device according to any one of claims 1 to 4, wherein: The monitoring unit monitors the communication connection established using a create_subscriber message in accordance with DDS (Data Distribution Service) and terminated using a delete_subscriber message in accordance with DDS.
8. A detection method, in a detection device for detecting the presence of an illegal communication connection in a network, comprising the following steps: monitoring a communication connection established for exchanging specified messages in said network; as well as Based on the monitoring results of the plurality of communication connections, the existence of the illegal communication connection is detected.
9. A detection program used in a detection device for detecting the presence of an illegal communication connection in a network, The detection program is used to make the computer function as a monitoring unit and a detection unit: The monitoring unit monitors a communication connection established for exchanging a predetermined message in the network. The detection unit detects the presence of the illegal communication connection based on the monitoring result of the plurality of communication connections by the monitoring unit.
Citation Information
Patent Citations
Extended range mode transmission method and apparatus
JP2022184950A
Detection device, detection method, and detection program
WO2022153839A1