Monitoring device, monitoring method, and program product

By using the acquisition and judgment mechanism of the monitoring device, the problem of the monitored object being removed from the monitoring when the system restarts is solved, thereby improving security and efficiency in complex environments.

CN120406218APending Publication Date: 2025-08-01PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510067247.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-06-04
Filing Date
2025-01-16
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In electronic control devices, when other monitoring devices restart the system, the monitored object may escape the monitoring of the monitoring device, resulting in reduced security.

Method used

The monitoring device acquires monitoring requests after the system restarts via the acquisition unit, and the determination unit determines whether to restart monitoring, including the determination of the number of processes and memory tampering, to ensure that the monitored object is restored to monitoring.

Benefits of technology

Even when other monitoring devices restart the system, it can effectively prevent the monitored object from escaping monitoring, thereby improving system security and analysis efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120406218A_ABST
    Figure CN120406218A_ABST
Patent Text Reader

Abstract

The invention relates to a monitoring device, a monitoring method, and a program product. Provided is a monitoring device or the like capable of suppressing a monitored object from being out of monitoring of a monitoring device even when a system is restarted by another monitoring device. A monitoring device for monitoring a monitored object existing in the general world, the monitored object being also monitored by another monitoring device different from the monitoring device, the monitoring device being provided with: an acquisition unit (for example, a monitoring request reception unit (53)); an acquisition unit that, when another monitoring device restarts a system including the monitoring object and the monitoring device on the basis of the monitoring result of the monitoring object, acquires a monitoring request from the monitoring object after the system is restarted; and a determination unit (for example, a state determination unit (56)) that determines whether or not to restart monitoring of the object to be monitored when a monitoring request is acquired.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a monitoring device, a monitoring method, and a program product. Background Art

[0002] Conventionally, a plurality of electronic control devices connected to each other via an in-vehicle network have been mounted in an automobile. When some abnormality occurs in these electronic control devices, it is sought to determine the cause of the abnormality by collecting and analyzing various logs related to the operation of the electronic control devices. Patent Document 1 discloses an electronic control device that can reliably collect logs related to an abnormality in a highly secure area when an abnormality occurs in an electronic control device using virtualization technology.

[0003] Prior Art Documents

[0004] Patent Documents

[0005] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2020-129238 Summary of the Invention

[0006] Problems to be Solved by the Invention

[0007] In addition to the monitoring device that monitors the monitoring target, other monitoring devices are sometimes provided in the electronic control device. In this case, when the other monitoring device detects an abnormality in the monitoring target and restarts the system including the monitoring target and the monitoring device, the monitoring target may sometimes be out of the monitoring range of the monitoring device after the restart.

[0008] Therefore, the present disclosure provides a monitoring device, a monitoring method, and a program product that can suppress the monitoring target from being out of the monitoring range of the monitoring device even when the system is restarted by another monitoring device.

[0009] Means for Solving the Problems

[0010] The monitoring device according to one aspect of the present disclosure monitors a monitoring target existing in the Normal World, wherein the monitoring target is also monitored by another monitoring device different from the monitoring device. The monitoring device includes: an acquisition unit that, when the other monitoring device restarts the system including the monitoring target and the monitoring device based on the monitoring result of the monitoring target, acquires a monitoring request from the monitoring target after the system restart; and a determination unit that determines whether to restart the monitoring of the monitoring target when the monitoring request is acquired.

[0011] The monitoring method according to one aspect of the present disclosure is executed by a monitoring device that monitors a monitoring object existing in the ordinary world, where the monitoring object is also monitored by another monitoring device different from the monitoring device. In the monitoring method, when the other monitoring device restarts the system including the monitoring object and the monitoring device based on the monitoring result of the monitoring object, a monitoring request is obtained from the monitoring object after the system restarts. When the monitoring request is obtained, it is determined whether to restart the monitoring of the monitoring object.

[0012] A program product according to one aspect of the present disclosure is a program product for causing a computer to execute the above-described monitoring method.

[0013] Effects of the Invention

[0014] According to one aspect of the present disclosure, it is possible to implement a monitoring device or the like that can suppress the monitoring object from being out of the monitoring range of the monitoring device even when the system is restarted by another monitoring device. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a diagram showing the structure of the monitoring system according to the embodiment.

[0016] Figure 2 It is a block diagram showing the functional structure of the second monitoring unit according to the embodiment.

[0017] Figure 3 It is a flowchart showing the operation of the second monitoring unit according to the embodiment.

[0018] Figure 4 It shows Figure 3 It is a flowchart showing the detailed operation of step S50 shown.

[0019] Figure 5 It is a flowchart showing the operation of the first monitoring unit according to the embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] In addition, the embodiments to be described below all represent general or specific examples. The numerical values, shapes, constituent elements, arrangement positions and connection manners of the constituent elements, steps, and the order of steps shown in the following embodiments are examples and are not intended to limit the present disclosure. In addition, the constituent elements in the following embodiments that are not described in the independent claims are described as optional constituent elements.

[0021] In addition, each figure is a schematic diagram and is not necessarily strictly illustrated. Therefore, for example, the scales in each figure are not necessarily the same. In addition, in each figure, the same reference numerals are given to substantially the same structures, and repeated descriptions are omitted or simplified.

[0022] In addition, in this specification, terms indicating the relationship between elements such as consistency, numerical values, and numerical ranges are not expressions that represent only strict meanings, but rather represent substantially equivalent ranges, for example, expressions that also include ranges with a difference of about a few percent (or about 10%).

[0023] (Embodiment)

[0024] Next, a monitoring system including a monitoring device according to this embodiment will be described.

[0025] [1. Structure of the Monitoring System]

[0026] Figure 1 FIG. shows the structure of the monitoring system 1 according to this embodiment. The monitoring system 1 is a system mounted on a vehicle for monitoring a monitoring target. The monitoring system 1 is implemented, for example, by an ECU (Electronic Control Unit) mounted on the vehicle, and this ECU is a computer including a processor (microprocessor) and a memory, etc. The memory is a ROM (Read Only Memory) and a RAM (Random Access Memory), etc., and can store programs executed by the processor.

[0027] As Figure 1 shown, the monitoring system 1 includes hardware 10 ( Figure 1 H / W in), and a kernel layer 20 and a user layer 30 that constitute the OS (Operating System) hierarchy. The kernel layer 20 and the user layer 30 are provided in a normal world (non-secure area) different from the trust zone. The trust zone is a secure area that restricts access from the normal world where the OS and application programs operate. In addition, in this embodiment, an example in which the software of the monitoring system 1 operates on the OS of Linux (registered trademark, the same applies hereinafter) will be described, but it is not limited thereto.

[0028] The hardware 10 is a chip (for example, a SoC (System on Chip)), and represents a machine or device that can receive data, perform logical operations on data, store data, or display data. It is not limited to a machine or device, and may also include a processor and a memory. In addition, the kernel layer 20 operates on the chip, and the user layer 30 operates on the kernel layer 20. The kernel layer 20 is also called the kernel space. In addition, the user layer 30 is also called the user space, and is a layer whose executable actions are restricted compared to the kernel layer 20.

[0029] In the kernel layer 20, in addition to including a kernel (not shown) which serves as the basic function of the OS, the second monitoring unit 50 is also included. In the user layer 30, application programs for implementing various functions are included. In this embodiment, the application unit 31 ( Figure 1 the application in) and the hypervisor 32 are included, where the application unit 31 includes application programs (also referred to as applications hereinafter). In addition, as long as the number of application units 31 existing in the user layer 30 (that is, the number of applications) is one or more, there is no particular limitation.

[0030] The application unit 31 has, for example, one or more processes and the memory required for one or more processes. A process is the execution unit of the program executed by the application unit 31. As an application, for example, an application for implementing WiFi (registered trademark) communication, an application for implementing communication under Bluetooth (registered trademark), an application for controlling the image displayed to the person riding in the vehicle (for example, an application for IVI (In-Vehicle Infotainment)), an application related to the control of the vehicle (for example, an application for implementing an autonomous driving function), etc. are exemplified, but are not limited to these applications. The functions implemented by the application are appropriately set according to the object on which the monitoring system 1 is mounted.

[0031] The application unit 31 is the monitoring object of the second monitoring unit 50. Specifically, one or more processes and the memory possessed by the application unit 31 are the monitoring objects of the second monitoring unit 50. In addition, the application unit 31 is also monitored by the hypervisor 32.

[0032] The application unit 31 exists in the normal world where security is not firm, and sometimes the process no longer operates normally due to external attacks or the like. In addition, the application unit 31 sometimes causes the process to no longer operate normally due to factors other than security factors.

[0033] In addition, it may be that the application unit 31 can communicate with the integrated ECU mounted on the vehicle. The integrated ECU is the center of the regional ECU and is the ECU that controls the entire vehicle.

[0034] The hypervisor 32 is a program for starting and monitoring the application unit 31 (for example, a program executed as the basic function of the OS). The hypervisor 32 and the execution unit (not shown) of the hypervisor 32 are an example of other monitoring devices. That is, the other monitoring device is configured to be able to execute the hypervisor 32 in the normal world (specifically, the user layer 30). In this embodiment, the other monitoring device is implemented by the monitoring function of the OS (for example, Linux) operating in the monitoring system 1.

[0035] The hypervisor 32 monitors the application unit 31 independently of the second monitoring unit 50. Moreover, the hypervisor 32 has the following function: when it detects that a process is not operating normally (an example of a monitoring result), it restarts the entire monitoring system 1 without notifying the second monitoring unit 50. That is to say, the hypervisor 32 can restart the monitoring system 1 independently of the second monitoring unit 50 and does not notify the second monitoring unit 50 of the restart. The hypervisor 32 can also be a program such as "systemd" in a computer of a Unix system like Linux.

[0036] In addition, regarding the object to be restarted here, in addition to the application unit 31, all other applications in the user layer 30, the kernel layer 20, the hardware 10, etc. are objects. The first monitoring unit 40 and the second monitoring unit 50 are also objects to be restarted. That is to say, the restart means restarting the entire monitoring system 1. Hereinafter, restarting the monitoring system 1 is also referred to as system reset.

[0037] In addition, Linux has a structure in which the information in the memory changes every time it is restarted. Thus, when restarted by the hypervisor 32, the application unit 31 after restart is continuously monitored by the hypervisor 32 but is out of the monitoring of the second monitoring unit 50. That is to say, the security of the monitoring object may be reduced after restart. Therefore, the application unit 31 includes a request function 31a, which is a function for making a monitoring request for restarting monitoring to the second monitoring unit 50. That is to say, the application unit 31 includes a program capable of executing the request function 31a.

[0038] The request function 31a makes a monitoring request to the second monitoring unit 50 after the application unit 31 is restarted or after recovering from a failure. In addition, the request function 31a can also determine which one of the second monitoring unit 50 and the hypervisor 32 has performed the restart, and makes a monitoring request to the second monitoring unit 50 when the restart is performed by the hypervisor 32. In addition, the request function 31a can also make a monitoring request to the second monitoring unit 50 when recovering from a failure state regardless of whether a restart has been performed.

[0039] The second monitoring unit 50 is a monitoring device that monitors monitoring targets such as applications existing in the ordinary world. It can also be said that the second monitoring unit 50 monitors applications and the like that operate in the user layer 30. In the present embodiment, the second monitoring unit 50 individually monitors one or more processes of the application unit 31. The second monitoring unit 50 monitors whether one or more processes possessed by the application unit 31 are alive and whether there is any tampering in the memory in the application unit 31 (for example, the memory of each of one or more processes). Details will be described later. The second monitoring unit 50 determines whether to restart monitoring based on the number of processes of the monitoring target (here, the application unit 31).

[0040] In addition, the second monitoring unit 50 cannot grasp the timing of the restart when the monitoring system 1 is restarted through the hypervisor 32. This is also the main reason why the application unit 31 gets out of the monitoring of the second monitoring unit 50.

[0041] Here, Linux has a structure that manages each process independently if the process exists. Linux determines whether each process of the application unit 31 exists through this structure. In Linux, for example, it determines whether each process possessed by all application units 31 in the user layer 30 exists at a specified time interval. By "exists", for example, it can also include the case of operating normally.

[0042] The second monitoring unit 50 acquires information related to the survival of each of one or more processes of each application unit 31 determined through the structure in Linux, and determines whether one or more processes possessed by the application unit 31 are alive based on the acquired information. In addition, the second monitoring unit 50 can also be configured to be able to directly monitor one or more processes and determine whether one or more processes are alive based on the monitoring results.

[0043] In addition, the second monitoring unit 50 monitors whether there has been any tampering with the memory of the process.

[0044] The first monitoring unit 40 is software that runs in the secure area, i.e., the trusted area, of the hardware 10, and monitors the second monitoring unit 50 from a secure area in the monitoring system 1. In addition, the first monitoring unit 40, for example, collects the monitoring logs of the second monitoring unit 50. That is to say, the first monitoring unit 40 collects the logs obtained by the second monitoring unit 50 through monitoring the monitoring target.

[0045] As described above, the monitoring system 1 has the following structure: The first monitoring unit 40 that operates on the trusted area, which is a security area, monitors the second monitoring unit 50 configured in the kernel layer 20, and the second monitoring unit 50 monitors the monitoring target that operates in the normal world (for example, the monitoring target existing in the user layer 30). The monitoring system 1 ensures the strengthening of security through chained monitoring. In addition, the monitoring system 1 only needs to include at least the second monitoring unit 50, and may also include the first monitoring unit 40.

[0046] In addition, each of the first monitoring unit 40 and the second monitoring unit 50 can restart the monitoring system 1. For example, restart is executed when at least one of the first monitoring unit 40 and the second monitoring unit 50 is in danger.

[0047] Here, with reference to Figure 2 the functional structure of the second monitoring unit 50 will be described. Figure 2 It is a block diagram showing the functional structure of the second monitoring unit 50 according to the present embodiment.

[0048] As Figure 2 shown, the second monitoring unit 50 includes a current process number monitoring unit 51, a memory tampering monitoring unit 52, a monitoring request receiving unit 53, a formal process number holding unit 54, a process number comparison unit 55, and a state determination unit 56.

[0049] The current process number monitoring unit 51 monitors the number of processes that are running (for example, existing) at the current time point among one or more processes of the monitoring target of the second monitoring unit 50, and outputs the process number ( Figure 2 the current process number shown in) to the process number comparison unit 55. When the OS of the monitoring system 1 is Linux, the current process number monitoring unit 51 can also obtain the process number through the following function that is a basic function of Linux, for example, the function of counting the number of currently running (for example, currently existing) processes based on the determination result of whether each process exists.

[0050] The memory tampering monitoring unit 52 monitors whether the memory of each of one or more processes of the monitoring target of the second monitoring unit 50 has been tampered with, and outputs the presence or absence of tampering ( Figure 2(The tampering monitoring result shown) is output to the state determination unit 56. The memory tampering monitoring unit 52 obtains, in the initial stage of start - up use, first information that has not been changed in the memory of the process from the application unit 31 or the like, and obtains second information corresponding to the first information stored in the memory of each of one or more processes of the application unit 31 at the current time point. By comparing the first information with the second information, it is determined whether memory tampering has occurred. For example, when the first information and the second information are consistent, the memory tampering monitoring unit 52 determines that no memory tampering has occurred; when the first information and the second information are inconsistent, it determines that memory tampering has occurred. It can also be said that when the first information is changed, the memory tampering monitoring unit 52 determines that tampering has occurred, and when the first information has not been changed, it determines that no tampering has occurred. In addition, the method for determining whether there is memory tampering is not limited to the above method, and any well - known method can also be used.

[0051] The monitoring request receiving unit 53 obtains a monitoring request, which is a request to perform monitoring of the monitoring target, from the monitoring target of the second monitoring unit 50. For example, when the hypervisor 32 restarts the monitoring system 1 including the monitoring target and the monitoring device (such as the second monitoring unit 50) based on the monitoring result of the monitoring target, the monitoring request receiving unit 53 obtains the monitoring request from the monitoring target after the monitoring system 1 restarts. In the present embodiment, the monitoring request receiving unit 53 obtains the monitoring request of the process output by the operation of the request function 31a of the application unit 31. The monitoring request may also include information for determining the process of the application unit 31 that output the monitoring request. In addition, the monitoring request may be, for example, a request to restart the monitoring of the following process, which is a process that is the monitoring target of the second monitoring unit 50 and has been out of the monitoring of the second monitoring unit 50 due to the restart performed by the hypervisor 32. The monitoring request receiving unit 53 is an example of an obtaining unit.

[0052] The official process number holding unit 54 is a storage device for storing the correct number of processes to be monitored ( Figure 2 (the official process number shown) as the specification of the monitoring system 1. The official process number holding unit 54 stores the number of processes of the monitoring target predetermined as the specification of the monitoring system 1. In addition, it can also be said that the official process number holding unit 54 stores the number of processes set in advance that the monitoring target has. The official process number holding unit 54 is an example of a storage unit.

[0053] When the monitoring target of the second monitoring unit 50 is multiple applications, the formal process number holding unit 54 stores, as the formal process number, the number of processes obtained by totaling one or more processes of each of the multiple applications. Hereinafter, it is assumed that the formal process number holding unit 54 stores that the number of processes is M (M is a natural number of 1 or more) for explanation. M is an example of the first process number. In addition, the formal process number holding unit 54 outputs the formal process number to the process number comparison unit 55 as needed. The formal process number holding unit 54 is implemented by, for example, a semiconductor memory, but is not limited thereto.

[0054] The process number comparison unit 55 compares two process numbers and outputs the comparison result to the state determination unit 56. The process number comparison unit 55 compares the current process number from the current process number monitoring unit 51 with the formal process number from the formal process number holding unit 54 to determine whether they are the same. In the case of non - consistency, the magnitude relationship is output as the comparison result to the state determination unit 56. The formal process number is an example of the first process number, and the current process number is an example of the second process number.

[0055] The state determination unit 56 determines the state of each process (or the monitoring system 1) based on the comparison result of the process number comparison unit 55 and the tampering monitoring result of the memory tampering monitoring unit 52. The states include a normal state indicating normality, an attack state indicating a network attack from the outside or the like, and a failure state indicating a failure. The failure here does not include the abnormal operation of the process caused by a network attack. In addition, after the system reset is performed by the hypervisor 32, when the monitoring request receiving unit 53 acquires a monitoring request, the state determination unit 56 determines whether to restart the monitoring of the monitoring target based on the comparison result between the current process number of the monitoring target after restart and the formal process number. The state determination unit 56 is an example of the first determination unit. The first determination unit exists, for example, in the kernel layer 20.

[0056] [2. Operation of the Monitoring System]

[0057] Next, with reference to Figures 3 - 5 the operation of the monitoring system 1 configured as described above will be described. Figure 3 is a flowchart showing the operation (monitoring method) of the second monitoring unit 50 according to the present embodiment.

[0058] As Figure 3 shown, first, when the system (monitoring system 1) starts (S10), the process number comparison unit 55 reads out the process number (M) determined as the specification (S20). The process number (M) refers to the formal process number. The number of processes read out in step S20 is M.

[0059] Next, the second monitoring unit 50 starts monitoring the monitoring target (here, one or more processes of the application unit 31) (S30).

[0060] Next, the current process number monitoring unit 51 confirms the number of processes (N) being monitored (S40). Specifically, the current process number monitoring unit 51 obtains the number of processes (N) that exist at the current time point among one or more processes of the monitoring target. The current process number monitoring unit 51 obtains information related to the existing processes from the basic functions provided by Linux, for example, and obtains the process number (N) based on the obtained information related to the processes. The process number (N) refers to the current process number. The number of processes existing at the current time point in the monitoring system 1 is N. N is an example of the second process number. In addition, the current process number monitoring unit 51 can also periodically confirm the current process number of the monitoring target after the monitoring system 1 is started, for example.

[0061] Next, the second monitoring unit 50 executes a determination process using the process number (S50). Refer to Figure 4 to describe step S50. Figure 4 is a flowchart showing Figure 3 the detailed operation (monitoring method) of step S50 shown. In addition, for example, the operations shown Figure 4 can be executed for each of one or more application units 31, or the operations shown Figure 4 can be repeatedly executed for all application units 31.

[0062] As Figure 4 shown, the process number comparison unit 55 compares M as the process number with N (S151). The process number comparison unit 55 determines whether M and N are the same, and determines the size relationship by comparison in the case of non - consistency. In addition, after the monitoring system 1 is system - reset by the hypervisor 32, when step S151 is executed, since N = 0, it is determined that M is larger than N.

[0063] Next, the memory tampering monitoring unit 52 determines whether there is memory tampering in all monitored target processes when M and N are the same (M = N in S151) and when M is larger than N (M > N in S151) (S152, S157). In the Figure 1 example, only one application unit 31 is illustrated, but when there are multiple application units as the monitoring target of the second monitoring unit 50, the memory tampering monitoring unit 52 determines whether there is memory tampering in the memory of one or more processes of each of the multiple application units.

[0064] Next, when M and N match and the memory tampering monitoring unit 52 determines that there is memory tampering (Yes in S152), the state determination unit 56 determines the state of the monitoring system 1 as an attack state (S153) and performs a system reset (S164). Further, when M and N match and the memory tampering monitoring unit 52 determines that there is no memory tampering (No in S152), the state determination unit 56 determines the state of the monitoring system 1 as a normal state (S154).

[0065] Next, the state determination unit 56 determines whether there is a monitoring request from the request function 31a (S155). When there is a monitoring request from the monitoring target (Yes in S155), the state determination unit 56 rejects the reception of the monitoring request (S156). That is, the state determination unit 56 does not add the application unit (that is, one or more processes) for which there is a monitoring request to the monitoring target. The state determination unit 56 outputs the indication of non-reception as an acceptance / rejection indication (refer to Figure 2 ) to the monitoring request reception unit 53.

[0066] This is because when receiving a monitoring request, the number of processes of the monitoring target may exceed M, and thus there is currently a risk of spoofing attack. Further, when there is no monitoring request (No in S155), the state determination unit 56 does not perform any special processing.

[0067] In this way, when M and N match, the state determination unit 56 further determines the state of the monitoring target based on the determination result of whether the memory of the monitoring target has been tampered with. When the memory of the monitoring target has not been tampered with, the state determination unit 56 determines the state of the monitoring target as a normal state and determines not to restart monitoring for the monitoring request. When the memory of the monitoring target has been tampered with, the state determination unit 56 determines the state of the monitoring system 1 as an attack state and performs a system reset of the monitoring system 1 (S164).

[0068] In addition, when M is greater than N and the memory tampering monitoring unit 52 determines that there is memory tampering (Yes in S157), the state determination unit 56 determines the state of the monitoring system 1 as an attack state (S158) and performs a system reset of the monitoring system 1 (S164). In addition, when M is greater than N, there is no memory tampering, and the process does not exist (M > N in S151 and No in S157 and S159), the state determination unit 56 determines the state of the process as a failure state (S160). When there is a monitoring request from the monitored object (Yes in S161), it is determined that the failed process has been revived, and the monitoring request is received (S162). That is, the state determination unit 56 adds the application with the monitoring request (that is, one or more processes) to the monitored object. The state determination unit 56 outputs the indication of whether it can receive this instruction as the indication of whether it can receive to the monitoring request receiving unit 53. In addition, when there is no monitoring request (No in S161), the state determination unit 56 does not perform special processing. In addition, when a monitoring request is received, a structure for ensuring security can also be additionally added. For example, the state determination unit 56 can also determine whether the file size of the monitored object has changed. For example, it can also be that the state determination unit 56 determines to receive the monitoring request when the file size of the monitored object has not changed compared to the initial stage when it started to be used, and determines not to receive the monitoring request when the file size of the monitored object has changed compared to the initial stage when it started to be used. The method of determination is not limited to the above method, and any known method can also be used.

[0069] In this way, when M is greater than N, the state determination unit 56 further determines the state of the monitored object based on the determination result of whether the memory of the monitored object has been tampered with. For example, when the memory of the monitored object has not been tampered with and the monitored object exists (Yes in S159), the state determination unit 56 determines the state of the monitored object as a normal state and determines not to restart monitoring for the monitoring request. In addition, for example, when the memory of the monitored object has not been tampered with and the monitored object does not exist, the state determination unit 56 determines the state of the monitored object as a failure state and determines to restart monitoring for the monitoring request.

[0070] In addition, when N is greater than M (M < N in S151), a spoofing attack may have been performed, so the state determination unit 56 determines the state of the monitoring system 1 as an attack state (S163) and performs a system reset (S164). In addition, when N is greater than M, even if there is a monitoring request from the monitored object, the monitoring request is refused to be received. The state determination unit 56 outputs the indication of not receiving this instruction as the indication of whether it can receive to the monitoring request receiving unit 53.

[0071] In this way, the second monitoring unit 50 is configured to receive a monitoring request when the conditions that M is greater than N, there is no memory tampering, and the process is in a failure state are satisfied. For example, even when the system reset of the monitoring system 1 is performed by the hypervisor 32 and each process is removed from the monitoring target of the second monitoring unit 50, a monitoring request is received when the conditions are satisfied, so that the monitoring of the process can be restarted. In addition, when M = N, no monitoring request is received, so the security of the monitoring system 1 can be improved compared with the case of receiving a monitoring request regardless of the comparison result between M and N.

[0072] Next, the operation of the first monitoring unit 40 will be described with reference to Figure 5 FIG. Figure 5 is a flowchart showing other operations (monitoring methods) of the first monitoring unit 40 according to the present embodiment.

[0073] As Figure 5 shown, the first monitoring unit 40 determines whether the monitoring log from the second monitoring unit 50 is an attack log or a failure log (S201). The monitoring log includes, for example, the number of surviving processes, the presence or absence of memory tampering, the number of process restarts, and the like. It can also be said that the first monitoring unit 40 classifies the monitoring log into an attack log and a failure log in step S201. The first monitoring unit 40 can also identify and collect attack logs and failure logs, for example.

[0074] Next, when the monitoring log is an attack log (attack log in S201), the first monitoring unit 40 transmits the attack log to the SOC (Security Operation Center) via the communication device mounted on the vehicle (S202), and when the monitoring log is a failure log (failure log in S201), the process ends. That is, the first monitoring unit 40 does not transmit the failure log to the SOC.

[0075] In this way, the first monitoring unit 40, for example, when the monitoring log obtained by monitoring the process is an attack log (for example, when the monitoring log is obtained when the monitoring system 1 is in an attack state), transmits the attack log to the monitoring center that monitors the object equipped with the monitoring device. In addition, it is not limited to determining whether the monitoring log is an attack log or a failure log based on whether the monitoring log is obtained when the monitoring system 1 is in an attack state, and any known method can be used for determination.

[0076] The SOC is an example of a monitoring center that remotely monitors the vehicle. In addition, the first monitoring unit 40 is an example of a second determination unit. The second determination unit exists in a trusted area, for example.

[0077] Accordingly, it is possible to suppress the transmission of unnecessary logs (such as failure logs) that may become noise in the analysis of the SOC to the SOC, and thus it is possible to make the analysis of the SOC more efficient.

[0078] (Other Embodiments)

[0079] As described above, the monitoring device and the like according to one or more aspects have been described based on the embodiments. However, the present disclosure is not limited to these embodiments. As long as it does not deviate from the gist of the present disclosure, the present disclosure may also include aspects obtained by various modifications that those skilled in the art can think of for the present embodiments, and aspects constructed by combining the constituent elements in different embodiments.

[0080] For example, in the above embodiment, an example in which the monitoring device is mounted on a vehicle has been described, but it is not limited thereto. The monitoring device may also be mounted on other moving bodies other than vehicles such as railways and aircraft, or electrical devices such as mobile phones and home appliances.

[0081] In addition, in the above embodiment, the monitoring device in the vehicle is configured. It can be implemented by an ECU (so-called area ECU) that controls resources within the configured area, or by an integrated ECU. The integrated ECU is a central ECU formed by integrating multiple ECUs. The integrated ECU is an ECU obtained by integrating functions that were previously separately mounted on multiple ECUs to address the problems of increased development time or cost associated with the complexity of in-vehicle systems. It is an ECU that utilizes virtualization technology to enable multiple virtual computers (virtual devices: VMs (Virtual Machines)) to operate in one ECU. The area ECU is connected to, for example, devices mounted on the vehicle to control the connected devices.

[0082] In addition, in the above embodiment, an example in which the other monitoring device includes a program that executes the basic functions of the OS has been described, but it is not limited thereto. As long as it can monitor applications independently of the second monitoring unit and can perform a system reset, it may also be implemented by a monitoring device (monitoring unit) other than the basic functions of the OS.

[0083] In addition, in the above embodiment, an example in which the OS is Linux and a kernel layer and a user layer are provided in the normal world has been described. However, the OS may also be a system other than Linux. In this case, an application program layer in which each application exists and a HAL (Hardware Abstraction Layer) configured between the hardware and the application program layer may also be provided in the normal world.

[0084] In addition, in the above-mentioned embodiments, each component may be formed by dedicated hardware, or implemented by executing a software program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.

[0085] In addition, the order of executing each step in the flowchart is exemplified for the purpose of specifically explaining the present disclosure, and may be an order other than the above order. In addition, part of the above steps may be executed simultaneously (in parallel) with other steps, or part of the above steps may not be executed.

[0086] The division of functional blocks in the block diagram is merely an example. It is also possible to implement multiple functional blocks as one functional block, divide one functional block into multiple blocks, or transfer some functions to other functional blocks. Furthermore, it is also possible to process the functions of multiple functional blocks having similar functions in parallel or in a time-sharing manner by a single piece of hardware or software.

[0087] Furthermore, the monitoring device described in the above embodiments may be implemented as a single device or as multiple devices. When the monitoring device is implemented as multiple devices, the components of the monitoring device may be distributed among the multiple devices in any manner. When the monitoring device is implemented as multiple devices, the communication method between the multiple devices is not particularly limited and may be wireless or wired communication. Furthermore, a combination of wireless and wired communication may be employed between the devices.

[0088] In addition, each of the components described in the above embodiments can also be implemented as software, and typically, as a large-scale integration (LSI) which is an integrated circuit. These components can be formed as a single chip individually, or as a single chip including some or all of the components. Here, it is assumed to be a large-scale integration, but depending on the degree of integration, it is sometimes referred to as an integrated circuit (IC), system large-scale integration, super large-scale integration, or ultra large-scale integration. In addition, the method of integrating into an integrated circuit is not limited to large-scale integration, and can also be implemented by a dedicated circuit (a general-purpose circuit that executes a dedicated program) or a general-purpose processor. After manufacturing the large-scale integration, an FPGA (Field Programmable Gate Array) that can be programmed, or a reconfigurable processor that can reconfigure the connection or setting of the circuit units inside the large-scale integration can also be used. And if there is an integrated circuit technology that replaces the large-scale integration by the progress or derivative of semiconductor technology, of course, this technology can also be used for the integration of the components.

[0089] A system large-scale integration is a super multi-functional large-scale integration manufactured by integrating multiple processing units on a single chip. Specifically, it is configured to include a computer system such as a microprocessor and a ROM. A computer program is stored in the ROM. The microprocessor operates according to the computer program, and thus the system large-scale integration realizes its function.

[0090] In addition, one aspect of the present disclosure can also be a computer program that causes a computer to execute Figures 3 - 5 each of the characteristic steps included in the monitoring method shown in any of the figures.

[0091] In addition, for example, the program can also be a program for causing a computer to execute. In addition, one aspect of the present disclosure can also be a non-transitory computer-readable recording medium on which such a program is recorded. For example, such a program can be recorded on a recording medium and distributed or circulated. For example, by installing the distributed program on a device having another processor and causing the processor to execute the program, the device can perform the above-described various processes.

[0092] (Supplementary Note)

[0093] Based on the description of the above embodiments, the following technology is disclosed.

[0094] (Technology 1)

[0095] A monitoring device monitors a monitoring object existing in the ordinary world. Among them, the monitoring object is also monitored by other monitoring devices different from the monitoring device. The monitoring device includes: an acquisition unit. When the other monitoring device restarts the system including the monitoring object and the monitoring device based on the monitoring result of the monitoring object, the acquisition unit acquires a monitoring request from the monitoring object after the system restarts; and a determination unit. When the monitoring request is acquired, the determination unit determines whether to restart the monitoring of the monitoring object.

[0096] Thus, when it is determined by the determination unit to restart, the monitoring object that has been out of the monitoring of the monitoring device due to the restart by other monitoring devices can be restored to the monitoring object of the monitoring device. Therefore, even when the system is restarted by other monitoring devices, it is possible to prevent the monitoring object from getting out of the monitoring of the monitoring device.

[0097] (Technology 2)

[0098] The monitoring device according to Technology 1, wherein the monitoring device further includes a storage unit that stores a first number of processes preset for the monitoring object, and the determination unit determines whether to restart the monitoring of the monitoring object based on the comparison result between the second number of processes of the monitoring object after restart and the first number of processes.

[0099] Thus, it is possible to determine whether to restart the monitoring of the monitoring object based on the comparison result of the number of processes. Therefore, for example, it is possible to restore the monitoring object corresponding to the number of processes to the monitoring object of the monitoring device.

[0100] (Technology 3)

[0101] The monitoring device according to Technology 2, wherein when the second number of processes is less than the first number of processes, the determination unit further determines whether to restart the monitoring of the monitoring object based on the determination result of whether the memory of the monitoring object that has become unmonitorable due to the restart of the system has been tampered with.

[0102] Thus, when the second number of processes is smaller than the first number of processes, it is possible to restart the monitoring of an appropriate monitoring object corresponding to the determination result of whether the memory has been tampered with.

[0103] (Technology 4)

[0104] The monitoring device according to Technique 3, wherein, when the memory of the monitoring target that has become unmonitorable due to a restart of the system has not been tampered with, the determination unit determines to restart the monitoring of the monitoring target that has become unmonitorable due to the restart of the system.

[0105] Thereby, it is possible to restart the monitoring of the monitoring target that has become unmonitorable due to the restart of the system.

[0106] (Technique 5)

[0107] The monitoring device according to Technique 3 or 4, wherein, when the memory of the monitoring target that has become unmonitorable due to a restart of the system has been tampered with, the determination unit determines that the system is in an attacked state under attack.

[0108] Thereby, it is possible to suppress the restart of monitoring in a situation where a spoofing attack or the like may have been performed. In addition, for example, it is possible to improve the security of the system when the system has been restarted while in an attacked state.

[0109] (Technique 6)

[0110] The monitoring device according to any one of Techniques 2 to 5, wherein, when the number of second processes is the same as the number of first processes, the determination unit further determines the state of the monitoring target based on the determination result of whether the memory of the monitoring target has been tampered with.

[0111] Thereby, it is possible to restart the monitoring of an appropriate monitoring target corresponding to the determination result of whether the memory has been tampered with when the number of first processes is the same as the number of second processes.

[0112] (Technique 7)

[0113] The monitoring device according to Technique 6, wherein, when the memory of the monitoring target has not been tampered with, the determination unit determines the state of the monitoring target as a normal state and determines not to restart the monitoring for the monitoring request.

[0114] Thereby, it is possible to suppress the restart of monitoring when the number of second processes is larger than the number of first processes when restarting the monitoring, for example, when it is suspected that a spoofing attack has been performed.

[0115] (Technique 8)

[0116] The monitoring device according to Technique 6 or 7, wherein, when the memory of the monitoring target has been tampered with, the determination unit determines that the system is in an attacked state under attack.

[0117] Accordingly, it is possible to suppress restarting the monitoring in a case where a spoofing attack or the like may have been performed. In addition, for example, it is possible to improve the security of the system when the system is restarted while in an attack state.

[0118] (Technique 9)

[0119] The monitoring device according to any one of Techniques 2 to 8, wherein the determination unit determines that the system is in an attack state under attack when the number of second processes is greater than the number of first processes.

[0120] Accordingly, it is possible to suppress restarting the monitoring in a case where a spoofing attack or the like may have been performed. In addition, for example, it is possible to improve the security of the system when the system is restarted while in an attack state.

[0121] (Technique 10)

[0122] The monitoring device according to any one of Techniques 5, 8, and 9, wherein the determination unit further determines a log obtained by monitoring the monitoring target while in the attack state as an attack log, and sends the attack log to a monitoring center that monitors an object on which the monitoring device is mounted.

[0123] Accordingly, it is possible to suppress sending unnecessary logs that may become noise in the analysis at the monitoring center, and thus it is possible to streamline the analysis and the like at the monitoring center.

[0124] (Technique 11)

[0125] The monitoring device according to any one of Techniques 1 to 10, wherein the other monitoring device is implemented by a monitoring function of an OS that operates in the system.

[0126] Accordingly, it is possible to suppress the monitoring target from escaping the monitoring of the monitoring device when the system is restarted by the function of the OS.

[0127] (Technique 12)

[0128] A monitoring method is executed by a monitoring device that monitors a monitoring target existing in the ordinary world, wherein the monitoring target is also monitored by another monitoring device different from the monitoring device. In the monitoring method, when the other monitoring device restarts a system including the monitoring target and the monitoring device based on a monitoring result of the monitoring target, a monitoring request is obtained from the monitoring target after the restart of the system, and when the monitoring request is obtained, it is determined whether to restart the monitoring of the monitoring target.

[0129] Accordingly, the same effects as those of the above-described monitoring device are achieved.

[0130] (Technology 13)

[0131] A program product for causing a computer to execute the monitoring method according to Technology 12.

[0132] Thereby, the same effect as that of the above-described monitoring device is exhibited.

[0133] Industrial applicability

[0134] The present disclosure is useful for a monitoring device that monitors a monitoring object such as a monitoring application.

[0135] Explanation of reference numerals

[0136] 1: Monitoring system; 10: Hardware; 20: Kernel layer; 30: User layer; 31: Application unit; 31a: Request function; 32: Hypervisor; 40: First monitoring unit (second determination unit); 50: Second monitoring unit; 51: Current process number monitoring unit; 52: Memory tampering monitoring unit; 53: Monitoring request receiving unit (acquisition unit); 54: Official process number holding unit (storage unit); 55: Process number comparison unit; 56: Status determination unit (first determination unit).

Claims

1. A monitoring device monitors a monitoring object existing in the ordinary world, wherein, the monitoring object is also monitored by other monitoring devices different from the monitoring device, the monitoring device includes: an acquisition unit, when the other monitoring device restarts the system including the monitoring object and the monitoring device based on the monitoring result of the monitoring object, the acquisition unit acquires a monitoring request from the monitoring object after the system restarts; and a determination unit, when the monitoring request is acquired, the determination unit determines whether to restart the monitoring of the monitoring object.

2. The monitoring device according to claim 1, wherein, the monitoring device further includes a storage unit, and the storage unit stores a first number of processes set in advance that the monitoring object has, the determination unit determines whether to restart the monitoring of the monitoring object based on the comparison result between the second number of processes that the monitoring object has after restart and the first number of processes.

3. The monitoring device according to claim 2, wherein, when the second number of processes is less than the first number of processes, the determination unit further determines whether to restart the monitoring of the monitoring object based on the determination result of whether the memory of the monitoring object that has become unmonitorable due to the restart of the system has been tampered with.

4. The monitoring device according to claim 3, wherein, when the memory of the monitoring object that has become unmonitorable due to the restart of the system has not been tampered with, the determination unit determines to restart the monitoring of the monitoring object that has become unmonitorable due to the restart of the system.

5. The monitoring device according to claim 3, wherein, when the memory of the monitoring object that has become unmonitorable due to the restart of the system has been tampered with, the determination unit determines that the system is in an attacked state under attack.

6. The monitoring device according to claim 2, wherein, when the second number of processes is the same as the first number of processes, the determination unit further determines the state of the monitoring object based on the determination result of whether the memory of the monitoring object has been tampered with.

7. The monitoring device according to claim 6, wherein, when the memory of the monitoring object has not been tampered with, the determination unit determines the state of the monitoring object as a normal state and determines not to restart the monitoring for the monitoring request.

8. The monitoring device according to claim 6, wherein, when the memory of the monitoring object has been tampered with, the determination unit determines that the system is in an attacked state under attack.

9. The monitoring device according to claim 2, wherein, when the second number of processes is more than the first number of processes, the determination unit determines that the system is in an attacked state under attack.

10. The monitoring device according to any one of claims 5, 8, and 9, wherein, The determination unit also determines the log obtained by monitoring the monitoring target in the attack state as an attack log, and sends the attack log to a monitoring center that monitors the object on which the monitoring device is mounted.

11. The monitoring device according to any one of claims 1 to 9, wherein the other monitoring device is implemented by a monitoring function of an operating system (OS) that operates in the system.

12. A monitoring method, which is executed by a monitoring device that monitors a monitoring target existing in the ordinary world, wherein the monitoring target is also monitored by another monitoring device different from the monitoring device, in the monitoring method, when the other monitoring device restarts the system including the monitoring target and the monitoring device based on the monitoring result of the monitoring target, a monitoring request is obtained from the monitoring target after the system restarts, when the monitoring request is obtained, it is determined whether to restart the monitoring of the monitoring target.

13. A program product for causing a computer to execute the monitoring method according to claim 12.

Citation Information

Patent Citations

  • Electronic control device

    JP2020129238A