Detection system, detection method, and program

By designing a detection system to monitor and determine temporary port communication from the terminal to the IoT device, the problem of the inability to identify temporary port attacks of IoT devices in the prior art is solved, and more appropriate security attack detection on IoT devices is achieved.

CN120303907APending Publication Date: 2025-07-11PANASONIC INTELLECTUAL PROPERTY MANAGEMENT CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380082499.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-02
Filing Date
2023-10-25
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The prior art is difficult to detect security attacks on IoT devices via communication, especially those using temporary ports, because traditional methods mainly target familiar ports and cannot identify temporary ports.

Method used

A detection system is designed, including a monitoring unit, a determination unit and an output unit, which monitors communication from the terminal to the client device, determines whether an attack is included, especially a communication of a temporary port, and outputs a judgment result to identify a potential security attack.

Benefits of technology

The security attacks on IoT devices through communications can be properly detected, including attacks that identify temporary ports, and the security detection capabilities of IoT devices are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303907A_ABST
    Figure CN120303907A_ABST
Patent Text Reader

Abstract

A detection system (10) is provided with: an internal communication monitoring unit (12) that monitors at least a first communication from a terminal (22) to a device (21); a determination unit (13) that determines whether or not the first communication monitored by the internal communication monitoring unit (12) includes an attack of the terminal (22) on the device (21); and an output unit (15) that outputs information indicating the result of the determination by the determination unit (13), and when the determination unit (13) determines that the first communication includes an attack, the determination unit (13) determines that the first communication is communication from the terminal (22) to the temporary port of the device (21).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a detection system, a detection method, and a program. Background Art

[0002] IoT (Internet of Things) devices such as household appliances are utilized. In addition, countermeasures against security attacks on IoT devices are disclosed (for example, refer to Patent Document 1).

[0003] Prior Art Documents

[0004] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2017-175462 Summary of the Invention

[0005] Problems to be Solved by the Invention

[0006] However, there is a problem that security attacks on IoT devices via communication are sometimes undetectable by conventional methods for detecting security attacks on server devices and the like.

[0007] Therefore, the present invention provides a detection system and the like that can appropriately detect security attacks on devices via communication.

[0008] Technical Means for Solving the Problems

[0009] A detection system according to one aspect of the present invention includes: a monitoring unit that monitors at least first communication from a terminal to a client device; a determination unit that determines whether the first communication monitored by the monitoring unit includes an attack by the terminal on the client device; and an output unit that outputs information indicating a result of determination by the determination unit. The determination unit determines that the first communication includes the attack when it determines that the first communication is communication to an ephemeral port of the client device from the terminal.

[0010] In addition, these general or specific technical means can be implemented by a device, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or can be implemented by any combination of a system, a device, a method, an integrated circuit, a computer program, and a recording medium.

[0011] Advantages of the Invention

[0012] The detection system of the present invention can appropriately detect security attacks on devices via communication. Brief Description of the Drawings

[0013] Figure 1It is an explanatory diagram schematically showing the configuration of the detection system in the embodiment and the communication system including the detection system.

[0014] Figure 2 It is an explanatory diagram showing a list of applications (APPs) used by the detection system in the embodiment.

[0015] Figure 3 It is a flowchart showing the processes related to communication monitoring performed by the detection system in the embodiment.

[0016] Figure 4 It is an explanatory diagram showing a list of regular servers in the embodiment.

[0017] Figure 5 It is an explanatory diagram showing a list of improper (fraudulent, malicious) servers in the embodiment.

[0018] Figure 6 It is a flowchart showing the process of detecting host scanning performed by the detection system in the embodiment.

[0019] Figure 7 It is a flowchart showing the process of determining a temporary port performed by the detection system in the embodiment.

[0020] Figure 8 It is an explanatory diagram showing the temporary ports of the devices in the embodiment.

[0021] Figure 9 It is a flowchart showing the processes of detecting attacks and detecting eavesdropping performed by the internal communication monitoring unit in the embodiment. Detailed Embodiments

[0022] (Insights underlying the present invention)

[0023] Regarding the technologies related to security measures described in the "Background Art" section, the present inventors have found the following problems.

[0024] In the past, security attacks on server devices, etc. were carried out, for example, by sending communication data packets (also simply referred to as packets) to the TCP (Transmission Control Protocol) ports or UDP (User Datagram Protocol) ports (also simply referred to as ports) used to provide services to the server devices. In addition, security attacks are usually also called cyber attacks.

[0025] The ports used by server devices to provide services are, in principle, ports managed by the IANA (Internet Assigned Numbers Authority) as well-known ports, which are pre-determined ports. For example, the port used by an HTTP (Hypertext Transfer Protocol) server (so-called web server) to provide services (that is, to provide web pages) is port 80 of TCP. In addition, the ports used by an FTP (File Transfer Protocol) server to provide services (that is, file transfer and control for file transfer) are port 20 and port 21 of TCP.

[0026] Therefore, to detect past security attacks on servers, it is useful to verify whether a communication device conducts communications including attacks on well-known ports of the server. As a system for detecting such security attacks, a system called a honeypot is used. In the honeypot, by connecting a server device that may be an attack target to the Internet and exposing it to attackers from the Internet side, communications to the above well-known ports are monitored, thereby detecting security attacks.

[0027] Here, in recent years, IoT devices such as household appliances connected to the network have been utilized. IoT devices can work while communicating with a terminal (such as a smartphone) or a server that controls the IoT device.

[0028] There may be security attacks on IoT devices via communication. Security attacks on IoT devices via communication are attacks from application software (also simply referred to as an app) that is illegally installed on a terminal that controls the IoT device, or an illegal server, etc., which can cause abnormal operation of the IoT device. Countermeasures against security attacks on IoT devices have been publicly disclosed (for example, refer to Patent Document 1).

[0029] However, there is a problem that security attacks on IoT devices cannot sometimes be detected by the conventional method of detecting security attacks on servers. This is because IoT devices use ports temporarily used for connecting to servers (usually also called ephemeral ports or dynamic ports) instead of well-known ports to connect to servers. Therefore, even if it is verified whether a communication device conducts communications including attacks on well-known ports of the IoT device, it is impossible to determine whether there are security attacks on the IoT device. In addition, the ports used as ephemeral ports are selected from the range of ports managed by the IANA as ephemeral ports.

[0030] Therefore, the present invention provides a detection system and the like that can appropriately detect a security attack on a device via communication.

[0031] Hereinafter, the inventions obtained from the disclosure of this specification will be exemplified, and the effects and the like obtained from these inventions will be described.

[0032] (1) A detection system includes: a monitoring unit that monitors at least a first communication from a terminal to a client device; a determination unit that determines whether the first communication monitored by the monitoring unit includes an attack from the terminal to the client device; and an output unit that outputs information indicating the result determined by the determination unit. When the determination unit determines that the first communication is a communication from the terminal to a temporary port of the client device, it determines that the first communication includes the attack.

[0033] According to the above technical solution, when a communication is made from a terminal to a temporary port of a client device, the detection system determines that a security attack (also simply referred to as an attack) has been made from the terminal to the client device. Therefore, an attack that cannot be detected even by monitoring communication to a well-known port of the client can be detected. In this way, the detection system can appropriately detect a security attack on a device via communication.

[0034] (2) According to the detection system described in (1), the monitoring unit further monitors a second communication from the client device to a communication device connected via an external network. When the communication from the client device to a specified legitimate server is included in the second communication, the determination unit further obtains the port of the client device used in the second communication, uses the obtained port as the temporary port, and determines whether the first communication includes the attack.

[0035] According to the above technical solution, the detection system can detect an attack from a terminal on the temporary port actually used by the client device in communication with a legitimate server. In this way, the detection system can appropriately detect a security attack on the temporary port actually used by the device.

[0036] (3) According to the detection system described in (2), the monitoring unit further monitors a third communication between the terminal and a communication device connected via an external network. The determination unit further determines whether the third communication includes a communication from the terminal to an improper server, where the improper server is a server different from the legitimate server. When it is determined that the third communication includes a communication from the terminal to the improper server, it is determined that the third communication is related to the attack.

[0037] Based on the above technical solution, it is possible to detect that the terminal has communicated with an improper server and determine that the terminal has communicated related to an attack. It can be considered that the probability (likelihood) of the terminal detected to have communicated related to an attack to attack the client device is relatively high. Therefore, the detection system can more appropriately detect security attacks on the device via communication.

[0038] (4) For the detection system according to any one of (1) to (3) above, the monitoring unit further monitors the internal communication of the terminal with an address included in the internal network as the destination, and the determination unit further determines whether the internal communication includes packets related to a host scan targeting the internal network.

[0039] Based on the above technical solution, the detection system can detect that the terminal has performed a host scan. It can be considered that the probability of the terminal detected to have performed a host scan to attack the client device is relatively high. This is because the communication devices discovered during the host scan may become targets of attacks. Thus, in this way, the detection system can more appropriately detect security attacks on the device via communication.

[0040] (5) For the detection system according to (4) above, when the determination unit determines that the first communication includes the attack and determines that the internal communication does not include the packets related to the host scan, it is determined that the terminal is suspected of having performed an eavesdropping attack.

[0041] Based on the above technical solution, it is possible to detect that the terminal has attacked the client device without performing a host scan. It can be considered that such a terminal is suspected of having performed a security attack using communication eavesdropping. Thus, the detection system can more appropriately detect security attacks on the device via communication.

[0042] (6) For the detection system according to (2) above, the monitoring unit further monitors the internal communication of the terminal with an address included in the internal network as the destination, and the determination unit further determines whether the internal communication includes packets related to a host scan targeting the internal network. When it is determined that the first communication includes the attack, it is determined that the internal communication does not include the packets related to the host scan, and it is determined that the time difference from the communication from the client device to the legitimate server to the attack included in the first communication is within the reference time, it is determined that the terminal is suspected of having performed an eavesdropping attack.

[0043] According to the above technical solution, it is possible to detect that the terminal attacks the client device without performing a host scan. Furthermore, it is possible to detect that the terminal attacks the client device within a relatively short time after communicating with a legitimate server. It can be considered that such a terminal is suspected of carrying out a security attack using communication eavesdropping. Thus, the detection system can more appropriately detect security attacks on devices via communication.

[0044] (7) The detection system according to any one of (1) to (6) above, wherein the terminal is installed with an application software for performing a first communication, and when the determination unit determines that the first communication includes the attack, it determines that the application software has a function of performing an attack.

[0045] According to the above technical solution, the detection system can detect an application that attacks the client device. Therefore, the detection system can appropriately detect an application that performs a security attack on a device via communication.

[0046] (8) A detection method, which is a method for detecting an attack executed by a detection system, includes: at least monitoring a first communication from a terminal to a client device, determining whether the monitored first communication includes an attack by the terminal on the client device, outputting information indicating the result of the determination, and in the determination, when it is determined that the first communication is a communication from the terminal to a temporary port of the client device, it is determined that the first communication includes the attack.

[0047] According to the above technical solution, it has the same effect as the above detection system.

[0048] (9) A program for causing a computer to execute the detection method described in (8).

[0049] According to the above technical solution, it has the same effect as the above detection system.

[0050] In addition, these general or specific technical solutions can be implemented by a device, a method, an integrated circuit, a computer program, or a recording medium such as a computer-readable CD-ROM, or can be implemented by any combination of a device, a method, an integrated circuit, a computer program, and a recording medium.

[0051] Hereinafter, embodiments will be specifically described with reference to the drawings.

[0052] In addition, the embodiments described below all represent general or specific examples. The numerical values, shapes, materials, constituent elements, arrangement positions of the constituent elements, connection methods, steps, order of steps, etc. shown in the following embodiments are all examples, and the gist thereof is not to limit the present invention. In addition, for the constituent elements in the following embodiments that are not described in the independent claims representing the most general concept, they will be described as optional constituent elements.

[0053] (Embodiment)

[0054] In the present embodiment, a detection system that appropriately detects a security attack on a device via communication and the like will be described.

[0055] Figure 1 It is an explanatory diagram schematically showing the configuration of the detection system 10 in the present embodiment and the communication system 1 including the detection system 10.

[0056] The communication system 1 is a system that detects security attacks that the detection terminal 22 may perform on the device 21. First, the communication system 1 will be described.

[0057] As Figure 1 shown, the communication system 1 includes a base station 20, a device 21, and a terminal 22. The communication system 1 is connected to a legitimate server 31 and an illegitimate server 32 via a network N2.

[0058] The base station 20 is a communication device that connects the device 21 and the terminal 22 to the network N2 in a communicable manner. The base station 20 is, for example, an access point of a wireless LAN (Local Area Network) (e.g., Wi-Fi (registered trademark)) installed in a house, and this case will be described as an example.

[0059] The base station 20 is connected to the network N2 through a communication line (in other words, a wired LAN), and is also connected to the device 21 and the terminal 22 wirelessly. The base station 20 has a function of transmitting data packets transmitted and received between the connected devices. The device 21 or the terminal 22 may sometimes communicate with the legitimate server 31 or the illegitimate server 32 via the network N2. In addition, regarding whether the base station 20 and the device 21 and the terminal 22 and the network N2 are connected by wire or wirelessly, it is not limited to the above situation. That is to say, the base station 20 and the device 21 or the terminal 22 may also be connected by wire (in other words, a communication line), and the base station 20 and the network N2 may also be connected wirelessly.

[0060] Device 21 is a device that communicates with terminal 22 and legitimate server 31 via base station 20 while performing its own inherent functions, and is equivalent to a client device. Device 21 is, for example, a household appliance such as an air purifier or a washing machine. In addition, as device 21, it is not limited to household appliances, and client devices that are connected to a general server through communication can also be used.

[0061] Terminal 22 is an information terminal that causes device 21 to operate by providing information to device 21 via base station 20. Terminal 22 is a smartphone, a tablet computer, a personal computer, or the like. In terminal 22, application software (also simply referred to as an application) 23 runs (operates) on an OS (Operating System). Application 23 may include legitimate application 231 and illegitimate application 232. In addition, for the sake of convenience of explanation, it is shown that both legitimate application 231 and illegitimate application 232 run in terminal 22, but it is also possible that only at least one of legitimate application 231 and illegitimate application 232 runs in terminal 22.

[0062] Legitimate application 231 is an application that collects information from device 21, or gives a work instruction to device 21 or provides information to device 21. In addition, legitimate application 231 does not necessarily need to directly communicate with device 21, and the collection of information from device 21, or the provision of information to device 21 or the instruction of work can all be performed through legitimate server 31. In this case, legitimate application 231 does not directly communicate with device 21, and the only party with which legitimate application 231 communicates is legitimate server 31.

[0063] In contrast, illegitimate application 232 is an application that performs a security attack on device 21 or the like. As the security attack performed by illegitimate application 232, there may be: communicating with device 21 by disguising as communication from legitimate application 231 or legitimate server 31 and illegally collecting information from device 21; or causing device 21 to malfunction by giving an illegal work instruction or providing information to device 21. Therefore, detection system 10 can also be said to be a system that detects the security attacks that illegitimate application 232 may perform on device 21. In other words, illegitimate application 232 is the object for detection system 10 to determine whether a security attack is performed. Illegitimate application 232 can also be said to be the object for detection system 10 to detect a security attack.

[0064] In addition, there may be multiple terminals 22.

[0065] In addition, the number of malicious applications 232 running on the terminal 22 can be arbitrary. However, if the number of malicious applications 232 running on the terminal 22 is set to one, then when the detection system 10 detects a security attack, the malicious application 232 that launched the security attack is determined to be one, which is thus useful. In the present embodiment, the case where the number of malicious applications 232 running on the terminal 22 is set to one will be described as an example.

[0066] In addition, if the number of malicious applications 232 running on the terminal 22 is set to two or more, then when the detection system 10 detects a security attack, the malicious applications 232 that launched the security attack are determined to be one or more of the two or more malicious applications 232 running on the terminal 22. When multiple malicious applications 232 cooperate to launch a security attack on one terminal 22, by presetting the state in which such multiple malicious applications 232 run on one terminal 22, the detection system 10 can detect the above-mentioned security attack. This is an effective method for the following malicious applications 232: in a state where only a single malicious application 232 is installed on the terminal 22, the malicious application 232 lies dormant without launching a security attack to avoid detection by the detection system 10. Additionally, it is also an effective method in cases where the presence of a legitimate application 231 triggers a security attack by a malicious application 232.

[0067] The legitimate server 31 is a server that controls the operation of the device 21 or provides information to the device 21. The legitimate server 31 provides an instruction for the normal operation of the device 21 to the device 21 through communication, thereby controlling the operation of the device 21. Additionally, the legitimate server 31 regularly obtains information related to the normal operation of the device 21 from the device 21 through communication. Moreover, the legitimate server 31 receives an operation instruction for the device 21 in the legitimate application 231 by communicating with the legitimate application 231. Further, by providing the information related to the operation regularly obtained from the device 21 to the legitimate application 231, operation information can be presented in the legitimate application 231. It is envisioned that the legitimate server 31 is a server prepared by the company that provides the device 21 and the legitimate application 231.

[0068] In addition, the legitimate server 31 provides information for the operation of the device 21 and the legitimate application 231 through communication (for example, firmware updates or application updates for the terminal, or time information, etc.). The legitimate server 31 can be a server prepared by the company that provides the device 21 and the application 23, or a server prepared to widely provide information to general terminals (for example, a time server that widely provides time information to general terminals through NTP (Network Time Protocol)). Therefore, there can be multiple legitimate servers 31 according to the tasks they perform.

[0069] The illegitimate server 32 is a server different from the legitimate server 31. For example, the illegitimate server 32 is a server related to the operation of the illegitimate application 232, and this case will be used as an example for explanation. In this case, the illegitimate server 32 provides instructions for the illegitimate operation of the illegitimate application 232 through communication with the terminal 22. In addition, the illegitimate server 32 obtains information related to the illegitimate operation of the device 21 that has been illegally collected by the illegitimate application 232 from the terminal 22 through communication. The illegitimate server 32 is equivalent to a server that controls the terminal 22 on which the illegitimate application 232 runs (so-called C&C (Command & Control) server). It is assumed that the illegitimate server 32 is a server prepared by a person or company different from the company that provides the device 21 and the legitimate application 231 and who wants the device 21 to operate illegally.

[0070] In addition, the illegitimate server 32 includes servers different from the servers registered as the legitimate server 31. Therefore, it not only includes servers related to the illegal operation of the device 21, but may also include servers that are not registered as the legitimate server 31 (for example, applications not intended for widespread use by ordinary people, applications not widely used by ordinary people, etc.).

[0071] The detection system 10 monitors the communication carried out through the communication line connecting the base station 20 and the network N2, as well as the communication carried out in the network N1. The network N2 is a network outside the residence and includes, for example, the Internet. The network N1 is a network inside the residence. By monitoring the above-mentioned communication, the detection system 10 can detect possible security attacks that the terminal 22 (or the application 23) may carry out. In other words, it can detect that the application 23 is an illegitimate application 232.

[0072] Next, the detection system 10 will be described.

[0073] As Figure 1As shown, the detection system 10 includes an external communication monitoring unit 11, an internal communication monitoring unit 12, a determination unit 13, a storage unit 14, and an output unit 15 as functional units. Part or all of the functions of the external communication monitoring unit 11, the internal communication monitoring unit 12, the determination unit 13, and the output unit 15 can be implemented by a processor (CPU (Central Processing Unit)) included in the detection system 10 executing a prescribed program using a memory.

[0074] The external communication monitoring unit 11 monitors external communication (also referred to as second communication). The external communication is communication performed on a communication line connecting the base station 20 and the network N2, and more specifically, is communication between the device 21 or the terminal 22 and the legitimate server 31 or the illegitimate server 32. The external communication monitoring unit 11 is disposed on the communication line connecting the base station 20 and the network N2, captures data packets transmitted (circulated) on the above communication line, and provides the captured data of the data packets to the determination unit 13.

[0075] The external communication monitoring unit 11 corresponds to one function of the monitoring unit. In other words, it corresponds to a monitoring unit that monitors communication from the device 21 to a communication device connected via the network N2 (also referred to as second communication).

[0076] The internal communication monitoring unit 12 monitors internal communication. The internal communication is communication wirelessly performed by the base station 20 in the network N1, and more specifically, is communication between the base station 20 and the device 21 or the terminal 22, in other words, communication in the network N1. The internal communication monitoring unit 12 is disposed at a position where it can receive radio waves transmitted and received by the base station 20 (in other words, at a position within the area where the base station 20 can perform wireless communication), captures data packets transmitted and received by the base station 20, the device 21, or the terminal 22 in the network N1, and provides the captured data of the data packets to the determination unit 13.

[0077] The internal communication monitoring unit 12 corresponds to one function of the monitoring unit. In other words, it corresponds to a monitoring unit that monitors at least communication from the terminal 22 to the device 21 (also referred to as first communication).

[0078] The determination unit 13 determines whether the communication monitored by the external communication monitoring unit 11 or the internal communication monitoring unit 12 includes a security attack. The determination unit 13 obtains the captured data of the data packets transmitted on the communication line connecting the base station 20 and the network N2 from the external communication monitoring unit 11, and also obtains the captured data of the data packets transmitted and received on the network N1 from the internal communication monitoring unit 12. Then, the determination unit 13 performs the above determination using the obtained captured data.

[0079] Specifically, when the determination unit 13 determines, based on the capture data of the data packets transmitted and received on the network N1, that the first communication is a communication from the terminal 22 to the ephemeral port of the device 21, it is determined that the first communication includes a security attack. At this time, the determination unit 13 can also determine that the application 23 installed on the terminal 22 has the function of performing a security attack.

[0080] An ephemeral port is typically a TCP port or UDP port on the communication device side that is temporarily used when a communication device connects to a server device via TCP or UDP. The ephemeral port is selected from within a range of numbers included in a pre-determined range. The above range is, for example, a range of 49152 or more and 65535 or less, and is managed by IANA.

[0081] In addition, when determining whether the first communication includes an attack, the determination unit 13 can use the capture data of the data packets transmitted on the communication line connecting the base station 20 and the network N2. That is, when the communication from the device 21 to the legitimate server 31 is included in the second communication, the determination unit 13 obtains the port of the device 21 used in the second communication. Moreover, the determination unit 13 uses the obtained port as the ephemeral port to determine whether the first communication includes an attack.

[0082] The determination unit 13 corresponds to a determination unit that determines whether the first communication monitored by the determination monitoring unit includes an attack by the terminal 22 on the device 21.

[0083] The storage unit 14 is a volatile or non-volatile storage device that can store the information used by the determination unit 13 for processing and the information indicating the result of the determination by the determination unit 13. The storage unit 14 is, for example, a RAM (Random Access Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive), etc.

[0084] In the storage unit 14, as the information used by the determination unit 13 for processing and the information indicating the result of the determination by the determination unit 13, an application list (refer to Figure 2 ) is stored. In addition, a port list indicating the ephemeral ports of the device 21 (refer to Figure 8 ) is stored in the storage unit 14.

[0085] The output unit 15 outputs the result information indicating the result of the determination stored in the storage unit 14. The result information output by the output unit 15 at least includes information indicating whether the terminal 22 has carried out an attack (refer to Figure 2 ). In addition, the result information output by the output unit 15 may also include: the presence or absence of communication with an improper server, the presence or absence of performing a scan, the suspicion of performing eavesdropping, or the time difference (refer to Figure 2)。

[0086] The output unit 15 includes, for example, a prompting device that prompts the user with the result information. The prompting of the result information may include, for example: displaying the result information on a display screen as an example of the prompting device, or outputting the result information as sound through a speaker as an example of the prompting device. In addition, the output unit 15 may also have a communication interface to provide the result information to an external prompting device via the communication interface, and cause the external prompting device to perform the prompting.

[0087] As described above, when the determination unit 13 determines that the first communication includes a security attack, it is equivalent to the detection system 10 detecting a security attack. In addition, when the determination unit 13 determines that the application 23 has a function of performing a security attack, it is equivalent to the detection system 10 detecting that the application 23 is an improper application 232.

[0088] In addition, the functional units included in the detection system 10 may be included in one device, or may be dispersedly included in multiple devices. When the functional parts included in the detection system 10 are dispersedly included in multiple devices, information is exchanged via the communication interface between the devices that need to exchange information.

[0089] Figure 2 It is an explanatory diagram showing the application list used by the detection system 10 in the present embodiment. Figure 2 The shown application list is a list representing one or more applications that are the objects of detecting security attacks by the detection system 10. In other words, it is a list of applications that are the objects to be detected for whether they perform security attacks. The application list is stored in the storage unit 14, and its content can be updated by the determination unit 13.

[0090] In Figure 2 In the shown application list, for one or more applications, the IP (Internet Protocol) address, name, presence or absence of communication with an improper server, presence or absence of performing scanning, presence or absence of performing an attack, presence or absence of suspicion of performing eavesdropping, and time difference amount are shown.

[0091] The IP address is the IP address of the terminal 22 on which the application is installed. In addition, an identifier that can uniquely identify the terminal 22 can be used instead of the IP address.

[0092] The name is the name of the application. The name is the text information given to the application.

[0093] "Communication with an improper server" is information indicating whether the application has communicated with an improper server 32. When the determination unit 13 determines that the terminal 22 on which the application is installed has communicated with the improper server 32, "Communication with an improper server" is updated to information indicating that the application has communicated with the improper server 32 (that is, information indicating that there is communication with the improper server 32). The information indicating that there is communication with the improper server 32 is represented as a tick mark in Figure 2 but the form of the information is not limited to this. The same applies to the form of the information below.

[0094] In addition, "Communication with an improper server" only shows the result of the determination by the determination unit 13 and does not assert that the communication partner with which the application has communicated is an improper server.

[0095] "Whether scanning has been performed" is information indicating whether the application has performed host scanning. When the determination unit 13 determines that the terminal 22 on which the application is installed has performed host scanning, "Whether scanning has been performed" is updated to information indicating that the application has performed host scanning (that is, information indicating that scanning has been performed).

[0096] "Whether an attack has been performed" is information indicating whether the application has performed a security attack. When the determination unit 13 determines that the terminal 22 on which the application is installed has performed a security attack, "Whether an attack has been performed" is updated to information indicating that the application has performed a security attack (that is, information indicating that an attack has been performed).

[0097] "Whether there is a suspicion of eavesdropping" is information indicating whether the application has a suspicion of eavesdropping on communication. When the determination unit 13 determines that the terminal 22 on which the application is installed has a suspicion of eavesdropping on communication, "Whether there is a suspicion of eavesdropping" is updated to information indicating that the application has a suspicion of eavesdropping on communication (that is, information indicating that there is a suspicion of eavesdropping).

[0098] The time difference indicates the difference from the time of regular communication to the time of attack when the application has a suspicion of eavesdropping on communication.

[0099] The determination unit 13 updates the information in the application list according to the result of the determination using the captured data. The content of the application list at the time when the determination by the determination unit 13 ends represents the result of the determination by the detection system 10.

[0100] Specifically, Figure 2 The application list shown shows four applications #1 to #4.

[0101] The application #1 is an application named "CLUB-P" and installed in the terminal 22 with the IP address "192.168.1.2". The application #1 is determined by the determination unit 13 to have communication with an unauthorized server. The application #1 is an example of an application for sending and receiving information in a group of people or an organization. The application #1 is not an application that is expected to be widely used by the general public, but is an example of an unknown server that is not registered as a legitimate server 31.

[0102] Application #2 is an application named "Wi-Fi Analyze" installed in the terminal 22 with the IP address "192.168.1.3". Application #2 is determined by the determination unit 13 to have communication with an unauthorized server and to have performed a host scan. Application #2 is a tool for analyzing Wi-Fi communications and is not intended to be widely used by the general public, but rather intended to be used by people with knowledge or skills related to communications.

[0103] Application #3 is an application named "Google Map" and installed in the terminal 22 with the IP address "192.168.1.4". Application #3 is determined by the determination unit 13 to have communicated with an unauthorized server, performed a host scan, and carried out a security attack.

[0104] Application #4 is an application named "Pachimon Go" installed in the terminal 22 with the IP address "192.168.1.5". Application #4 is determined by the determination unit 13 to have communicated with an unauthorized server, to have carried out a security attack, and to be suspected of eavesdropping.

[0105] Next, the processing of the detection system 10 will be described.

[0106] Figure 3 1 is a flowchart showing the process related to the monitoring of the communication performed by the detection system 10 in the present embodiment. Figure 4 It is an explanatory diagram showing a list of authorized servers in this embodiment. Figure 5 FIG. 2 is an explanatory diagram showing a list of unauthorized servers in this embodiment. Figure 3 , Figure 4 as well as Figure 5 , the processing related to the monitoring of communication by the external communication monitoring unit 11 is explained.

[0107] In step S101, the determination unit 13 determines whether communication between the terminal 22 and an external device (equivalent to external communication) is detected. More specifically, the determination unit 13 obtains capture data of data packets transmitted on the communication line connecting the base station 20 and the network N2 from the external communication monitoring unit 11. When the data packets include data packets regarding communication between the terminal 22 and an external device, it is determined that external communication is detected. The external devices include a legitimate server 31 and an illegitimate server 32. When it is determined that external communication is detected (Yes in step S101), the process proceeds to step S102; otherwise (No in step S101), step S101 is executed again.

[0108] In step S102, the determination unit 13 determines whether the communication partner of the external communication, which is the object of the determination in step S101, is the illegitimate server 32. In this determination, a legitimate server list (refer to Figure 4 ) can be used. The legitimate server list shows the IP addresses of one or more servers that are pre-identified as legitimate servers 31 ( Figure 4 such as 123.45.67.89 in the example). When the IP address of the communication partner of the external communication, which is the object of the determination in step S101, is not included in the legitimate server list, the determination unit 13 determines that the communication partner of the external communication is the illegitimate server 32. When it is determined that the communication partner of the external communication is the illegitimate server 32 (Yes in step S102), the process proceeds to step S103; otherwise (No in step S102), step S101 is executed again.

[0109] In addition, the legitimate server 31 may be, for example, the communication partner with which the terminal 22 in the initial state communicates. The initial state means a state in which the OS and the applications provided with the OS are installed, and the application 23 is not yet installed. Servers that can be pre-identified as legitimate servers 31 can include, for example, servers that publish applications running on the OS, servers that publish time information, etc. The determination unit 13 can pre-generate a legitimate server list by determining the communication partner of the terminal 22 in the initial state. In addition, the legitimate server list can also register, together with or instead of the above, servers identified as legitimate servers by a manager or the like.

[0110] In step S103, the determination unit 13 determines that the external communication, which is the object of the determination in step S101, is communication between the terminal 22 and the illegitimate server 32. In addition, the communication partner of the above external communication is determined to be the illegitimate server 32. In addition, the determination unit 13 determines that the above communication is related to a security attack, and registers the communication partner of the above external communication in the illegitimate server list (refer to Figure 5)。The IP addresses of the servers determined to be improper servers are shown in the improper server list ( Figure 5 such as 98.76.54.32 in the example). The communication between the terminal 22 and the improper server 32 may include, for example, an indication of improper operation from the improper server 32 to the terminal 22, or the provision of information related to improper operation from the terminal 22 to the improper server 32. Information related to improper operation includes, for example, the IP address or model name of the device 21 discovered in the port scan (described later) performed by the terminal 22.

[0111] In step S104, the determination unit 13 determines that the application 23 installed on the terminal 22 is an improper server communication application. The determination unit 13 updates the information of "whether there is communication with an improper server" in the application list to the information indicating that the application 23 has communicated with the improper server 32.

[0112] After the process of step S104 is completed, step S101 is executed again.

[0113] Figure 6 is a flowchart showing the process of detecting a host scan performed by the detection system 10 in the present embodiment.

[0114] In step S201, the determination unit 13 determines whether communication with the terminal 22 as the source is detected. More specifically, the determination unit 13 obtains the capture data of the data packets transmitted and received in the network N1 from the internal communication monitoring unit 12, and determines that communication with the terminal 22 as the source is detected when the source of the above data packets is the terminal 22.

[0115] In step S202, the determination unit 13 determines whether the communication detected in step S201 is communication for a host scan. If it is determined that the above communication is communication for a host scan ( "Yes" in step S202), the process proceeds to step S203, otherwise ( "No" in step S202), step S201 is executed again.

[0116] Host scans are sometimes performed for the purpose of discovering communication devices existing in the network N1. In other words, sometimes improper applications are used to discover attack targets.

[0117] An example of a host scan is a Ping scan. A Ping scan means sending ICMP (Internet Control Message Protocol) echo requests (so-called Ping requests) one by one to the IP addresses that may exist in the network N1 as destinations. In addition, as another example of a host scan, there is also a method using ARP (Address Resolution Protocol) requests.

[0118] In step S203, the determination unit 13 determines that the application 23 installed on the terminal 22 is an application that performs scanning. In addition, the determination unit 13 determines the time when the host scanning was performed. The determination unit 13 updates the information of "whether scanning is performed" in the application list to the information indicating that the application 23 has performed scanning.

[0119] After the processing of step S203 is completed, step S201 is executed again.

[0120] Figure 7 It is a flowchart showing the process of determining a temporary port performed by the detection system 10 in the present embodiment. Figure 8 It is an explanatory diagram showing a port list of the temporary ports of the device 21 in the present embodiment. Refer to Figure 7 and Figure 8 , the process of determining the temporary port of the detection system 10 will be described.

[0121] In step S301, the determination unit 13 determines whether communication between the device 21 and the legitimate server 31 (equivalent to legitimate communication) is detected. More specifically, the determination unit 13 obtains capture data of data packets transmitted on the communication line connecting the base station 20 and the network N2 from the external communication monitoring unit 11, and determines that communication between the device 21 and the legitimate server 31 is detected when the data packets include data packets regarding the communication between the device 21 and the legitimate server 31. The communication between the device 21 and the legitimate server 31 may include, for example, an indication of normal operation from the legitimate server 31 to the device 21, or provision of information related to normal operation from the device 21 to the legitimate server 31. When it is determined that communication between the device 21 and the legitimate server 31 is detected ( "Yes" in step S301), the process proceeds to step S302, otherwise ( "No" in step S301), step S301 is executed again.

[0122] In step S302, the determination unit 13 determines the port used by the device 21 in the communication detected in step S301 as the temporary port. In addition, the determination unit 13 determines the time of the communication detected in step S301. The determination unit 13 registers the determined temporary port and the time of the communication in the port list (refer to Figure 8 ). In addition, when the same temporary port has already been registered in the port list, the time corresponding to the temporary port is updated.

[0123] In Figure 8 the shown port list, for example, it shows that the device 21 used port number 49513 as a temporary port to communicate with the legitimate server 31 at 7:05:03.001 on January 5, 2022.

[0124] In addition, the port list is updated whenever regular communication is detected in step S301. Further, information in the port list that is older than a specified time from the current time can also be eliminated by the determination unit 13. The specified time can be set to, for example, several seconds to several minutes, but is not limited thereto.

[0125] In addition, in the case where there are multiple devices 21, a port list is prepared for each device 21.

[0126] Figure 9 It is a flowchart showing the processes of detecting an attack and detecting eavesdropping performed by the internal communication monitoring unit 12 in the present embodiment.

[0127] In step S401, the determination unit 13 determines whether communication from the terminal 22 to the device 21 is detected. More specifically, the determination unit 13 obtains capture data of data packets transmitted and received in the network N1 from the internal communication monitoring unit 12, and determines that communication from the terminal 22 to the device 21 is detected when the source of the above data packet is the terminal 22 and the destination is the device 21. When it is determined that communication from the terminal 22 to the device 21 is detected (\"Yes\" in step S401), the process proceeds to step S402, otherwise (\"No\" in step S401), step S401 is executed again.

[0128] In step S402, the determination unit 13 determines whether the target port of the communication, which is the object of the determination in step S401, is a temporary port of the device 21. In the above determination, a port list showing the temporary ports of the device 21 can be used (refer to Figure 8 ). The determination unit 13 determines whether the target port of the communication, which is the object of the determination in step S401, is included in the temporary ports of the device 21 included in the communication log. When it is determined that the target port of the above communication is a temporary port of the device 21 (\"Yes\" in step S402), the process proceeds to step S403, otherwise (\"No\" in step S402), step S401 is executed again.

[0129] In step S403, the determination unit 13 determines whether the time of the communication with the temporary port, which is the object of the determination in step S402, as the target port is within a reference time from the most recent regular communication. The time of the most recent regular communication can be obtained based on Figure 8 the time of the communication on the temporary port, which is the object of the determination in step S402, in the port list of the device 21 shown. The reference time can be set to, for example, about 1 second, but is not limited thereto. When it is determined that the time of the above communication is within the reference time from the most recent regular communication (\"Yes\" in step S403), the process proceeds to step S404, otherwise (\"No\" in step S403), step S401 is executed again.

[0130] In addition, step S403 may not be executed. In the case where step S403 is not executed, when the determination unit 13 determines in step S402 that the target port of communication is the temporary port of device 21 (i.e., "yes" in step S402), the process proceeds to step S404.

[0131] In step S404, the determination unit 13 determines that the application 23 installed on the terminal 22 is an application that implements a security attack, in other words, an application that has the function of performing a security attack. In this case, the communication using the temporary port, which is the object of the determination in step S402, as the target port is equivalent to a security attack. The determination unit 13 updates the information of "whether an attack has been implemented" in the application list to information indicating that the application 23 has implemented a security attack.

[0132] In addition, it is conceivable that the above security attack is a security attack that determines the temporary port of device 21 used in the previous regular communication when the terminal 22 (or application 23) discovers the previous regular communication. Regarding the security attack that is considered to be triggered by the regular communication within how much time from the regular communication, it can be adjusted according to the reference time in step S403.

[0133] In step S405, the determination unit 13 determines whether the time of the security attack is within the reference time from the last host scan before the security attack. The time of the security attack is the time of the communication using the temporary port, which is the object of the determination in step S402, as the target port. The time of the host scan is the time when the communication of the host scan is detected ( Figure 6 in steps S202 and S203). The reference time can be set to, for example, several minutes to several hours, but it is not limited to this. If it is determined that the time of the security attack is within the reference time from the last host scan (i.e., "yes" in step S405), step S401 is executed again; otherwise (i.e., "no" in step S405), the process proceeds to step S406.

[0134] In step S406, the determination unit 13 determines that the application 23 installed on the terminal 22 is an application suspected of implementing eavesdropping, in other words, an application that has the suspicion of having the function of performing eavesdropping. This is because, in this case, it is determined in steps S404 and S405 that the terminal 22 (or application 23) has carried out an attack without performing a host scan, so there is a high probability of discovering device 21, which is the target of the attack, through eavesdropping. The determination unit 13 updates the information of "whether there is a suspicion of implementing eavesdropping" in the application list to information indicating that the application 23 has the suspicion of eavesdropping on communication.

[0135] After the process of step S406 is completed, step S401 is executed again.

[0136] By performing the processing of step S404 to step S405 described above, the determination unit 13 can determine that the terminal 22 is suspected of having performed an eavesdropping attack when it is determined that the first communication includes an attack and it is determined that the internal communication does not include a data packet related to host scanning.

[0137] In addition, by performing the processing of step S403 to step S405 described above, the determination unit 13 can determine that the terminal 22 is suspected of having performed an eavesdropping attack when it is determined that the first communication includes an attack, it is determined that the internal communication does not include a data packet related to host scanning, and it is determined that the time difference from the communication from the own device 21 to the legitimate server 31 to the attack included in the first communication is within the reference time.

[0138] In this way, the detection system 10 can appropriately detect a security attack on the device 21 by the terminal 22 (or the application 23) via communication.

[0139] In addition, in each of the above embodiments, each component can be constituted by dedicated hardware, or can be implemented by executing a software program suitable for each component. Each component can be implemented by a program execution unit such as a CPU or a processor reading and executing a software program recorded in a recording medium such as a hard disk or a semiconductor memory. Here, the software for implementing the detection system and the like of the above embodiments is as follows.

[0140] That is, this program is a program that causes a computer to execute a detection method, which is a method for detecting an attack executed by a detection system, including: at least monitoring a first communication from a terminal to a client device, determining whether the monitored first communication includes an attack by the terminal on the client device, outputting information indicating the result of the determination, and in the determination, when it is determined that the first communication is a communication from the terminal to a temporary port of the client device, it is determined that the first communication includes the attack.

[0141] As described above, the detection system and the like related to one or more technical solutions have been described based on the embodiments, but the present invention is not limited to the embodiments. As long as it does not deviate from the gist of the present invention, the ways obtained by making various modifications thought of by those skilled in the art to the present embodiment and the ways constructed by combining the components in different embodiments can be included within the scope of one or more technical solutions.

[0142] Industrial Applicability

[0143] The present invention can be used in a system for detecting an application that performs a security attack.

[0144] Description of Reference Numerals

[0145] 1: Communication system

[0146] 10: Detection system

[0147] 11: External communication monitoring unit

[0148] 12: Internal communication monitoring unit

[0149] 13: Judgment unit

[0150] 14: Storage unit

[0151] 15: Output unit

[0152] 20: Base station

[0153] 21: Device

[0154] 22: Terminal

[0155] 23: Application

[0156] 31: Legitimate server

[0157] 32: Illegitimate server

[0158] 231: Legitimate application

[0159] 232: Illegitimate application

[0160] N1, N2: Network

Claims

1. A detection system, comprising: A monitoring unit that monitors at least the first communication from the terminal to the client device; A determination unit that determines whether the first communication monitored by the monitoring unit includes an attack from the terminal to the client device; and An output unit that outputs information indicating the result of the determination made by the determination unit, When the determination unit determines that the first communication is a communication to a temporary port of the client device from the terminal, it determines that the first communication includes the attack.

2. The detection system according to claim 1, The monitoring unit further monitors the second communication from the client device to a communication device connected via an external network, The determination unit further, When the communication from the client device to a specified legitimate server is included in the second communication, obtains the port of the client device used in the second communication, Uses the obtained port as the temporary port to determine whether the first communication includes the attack.

3. The detection system according to claim 2, The monitoring unit further monitors the third communication conducted between the terminal and a communication device connected via an external network, The determination unit further, Determines whether the third communication includes a communication from the terminal to an illegitimate server, which is a server different from the legitimate server, When it is determined that the third communication includes a communication from the terminal to the illegitimate server, it is determined that the third communication is related to the attack.

4. The detection system according to any one of claims 1 to 3, The monitoring unit further monitors the internal communication in which the terminal uses an address included in the internal network as the destination, The determination unit further determines whether the internal communication includes a data packet related to a host scan targeting the internal network.

5. The detection system according to claim 4, When the determination unit determines that the first communication includes the attack and determines that the internal communication does not include the data packet related to the host scan, it determines that the terminal is suspected of having conducted an eavesdropping attack.

6. The detection system according to claim 2, The monitoring unit further monitors the internal communication in which the terminal uses an address included in the internal network as the destination, The determination unit further, Determines whether the internal communication includes a data packet related to a host scan targeting the internal network, When it is determined that the first communication includes the attack, it is determined that the internal communication does not include the data packet related to the host scan, and it is determined that the time difference from the communication from the client device to the legitimate server to the attack included in the first communication is within the reference time, it is determined that the terminal is suspected of having conducted an eavesdropping attack.

7. The detection system according to claim 1, An application software for conducting the first communication is installed on the terminal, When the determination unit determines that the first communication includes the attack, it determines that the application software has a function of conducting an attack.

8. A detection method, which is a method for detecting an attack executed by a detection system, includes: At least monitoring a first communication from a terminal to a client device, Determining whether the monitored first communication includes an attack by the terminal on the client device, Outputting information representing the result of the determination, In the determination, if it is determined that the first communication is a communication from the terminal to a temporary port of the client device, it is determined that the first communication includes the attack.

9. A program for causing a computer to execute the detection method according to claim 8.

Citation Information

Patent Citations

  • Communication control device, communication control method and program

    JP2017175462A