Attack analysis device
By calculating the shortest path distance between anomalies and safety events in the vehicle, the problem of distinguishing whether a vehicle anomaly is a cyber attack or a simple fault is solved, achieving fast and accurate attack judgment and reducing delayed response and costs.
Patent Information
- Application Number
- CN202380092680.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-22
- Filing Date
- 2023-08-25
- Publication Date
- 2025-09-05
AI Technical Summary
Existing technologies are unable to quickly and accurately distinguish whether vehicle anomalies are caused by cyber attacks or simple malfunctions, resulting in delayed responses and increased costs.
An attack analysis device is provided, which obtains abnormal information and security event information of a vehicle-mounted device, calculates the shortest path distance between the abnormality occurrence location and the security event occurrence location, and uses the distance to determine whether the abnormality is an external attack.
It can quickly and accurately determine whether a vehicle anomaly is due to an external attack, reducing labor and working hours and lowering the risk of delayed response.
Smart Images

Figure CN120604231A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an attack analysis device for determining, when an abnormality or a sign thereof occurs in an in-vehicle device mounted on a vehicle, whether the abnormality is caused by an attack from the outside. Background Art
[0002] As the Internet of Things (IoT) connects everything to the internet, the automotive industry is also seeing the adoption of connected cars and autonomous vehicles. While this automotive IoT brings convenience, it also increases the risk of cyberattacks via the internet.
[0003] Technologies for detecting cyberattacks against vehicles include Patent Documents 1 to 3. Patent Document 1 discloses a technology for comparing, for each adverse event that occurs, a group of phenomena indicating the adverse event's condition with a group of causes that caused the adverse event, thereby identifying the phenomena that occurred with the adverse event.
[0004] Patent document 2 discloses an information processing device comprising: a generating unit that generates a graph structure representing the corresponding association between a process and a target associated with the process based on a log obtained from a device; and a determining unit that, when any target of the device is specified, determines the process associated with the specified target and determines the target associated with the determined process based on the generated graph structure.
[0005] Patent Document 3 discloses a cyber-attack analysis system capable of collecting event information of cyber-attacks and determining which attacks are related to the cyber-attacks experienced by the driver.
[0006] Prior art literature
[0007] Patent Literature
[0008] Patent Document 1: Japanese Patent Application Laid-Open No. 07-013617
[0009] Patent Document 2: International Publication No. 2020 / 075808
[0010] Patent Document 3: Japanese Patent Application Laid-Open No. 2021-117568 Summary of the Invention
[0011] When a vehicle is attacked by a cyberattack, it's natural for some device to experience anomalies. However, cyberattacks have become increasingly sophisticated in recent years, and there's a high likelihood that the owner of a vehicle experiencing an anomaly will simply interpret the anomaly as a malfunction. This could lead to the owner taking the vehicle to a repair shop or reporting the problem to the customer service center as a malfunction claim, requiring the vehicle provider to take appropriate countermeasures.
[0012] However, if a vehicle anomaly is simply attributed to a malfunction despite being caused by a cyberattack, the vehicle owner will be unable to recognize the cyberattack, increasing the risk of further attacks. Furthermore, even if a later inspection confirms the anomaly is caused by a cyberattack, significant time may have passed since the anomaly occurred, potentially leading to further attacks. Therefore, it is crucial to rapidly determine whether a vehicle anomaly is caused by a cyberattack.
[0013] In order to distinguish between cyber attacks and simple failures, vehicle providers, for example, need to set up a PSIRT (Product Security Incident Response Team) to prepare for security management, security-related user support, and responses to product / service-related incidents aimed at improving the security level of the company's products and services. However, this not only increases time but also costs.
[0014] The techniques described in Patent Documents 1 to 3 also relate to techniques for diagnosing abnormalities occurring in vehicles by hacking or the like. However, these techniques cannot distinguish whether the abnormalities occurring in the vehicle are caused by an attack or a simple malfunction.
[0015] The present invention has been made in view of the above-mentioned problems, and an object of the present invention is to provide an attack analysis device that can easily determine whether an abnormality occurs in an in-vehicle device or not due to an attack from the outside.
[0016] In order to solve the above-mentioned problems, the present invention provides an attack analysis device, comprising: an anomaly acquisition unit, which acquires information related to an abnormal state of a vehicle-mounted device; a security event detection unit, which detects security events of the vehicle-mounted device; a distance acquisition unit, which acquires the distance of the shortest path connecting the abnormal occurrence location where the abnormal state occurs and the security event occurrence location where the security event occurs; and a determination unit, which determines the correlation between the abnormal state and the security event based on the distance.
[0017] According to the present invention, by utilizing the distance between an abnormal situation and a security event, it is possible to easily determine whether an abnormality occurring in an in-vehicle device is an attack from the outside.
[0018] Further features of the present invention will become apparent from the description of this specification and the accompanying drawings. In addition, other problems, structures, and effects than those described above will become apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 This is an overall overview diagram showing the operation of each department / organization's requirements in the maintenance phase among various phases related to automobile supply.
[0020] Figure 2 This is a block diagram showing an overview of the entire system including the attack analysis device (analysis server) according to the present invention.
[0021] Figure 3 This diagram illustrates the distance between abnormal situations and safety incidents.
[0022] Figure 4 This is a graph showing the distances between abnormal situations and security incidents in the form of a directed graph.
[0023] Figure 5 is a flowchart showing the processing performed by the attack analysis device. DETAILED DESCRIPTION
[0024] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings.
[0025] Hereinafter, embodiments will be described with reference to the accompanying drawings.
[0026] Figure 1 This is an overall overview diagram showing the operation of each department / organization's requirements in the maintenance phase among various phases related to automobile supply.
[0027] When supplying cars to demanders, car suppliers usually do the following: Figure 1 The operation of the stages from design to maintenance shown above. In recent years, there has been a particular demand for diversification in customer responses during the maintenance stage.
[0028] Specifically, when a customer experiences an issue with their vehicle, they first assume a fault and report it to the customer center, as described above. The customer center then relays various requests and information to the quality assurance department, development department, and suppliers, as shown in the diagram. Product modifications are then made, and the customer is provided with feedback on the investigation results.
[0029] In addition, in parallel with the above processing, when threat / vulnerability information and accident information (logs related to security incidents, etc.) are detected by external organizations such as dealers and repair shops, or by the VSOC (Vehicle Security Operation Center) that manages the security of vehicles after leaving the factory, reports are made to the above-mentioned PSIRT, and the PSIRT also conveys information to the quality assurance department, development department, and suppliers.
[0030] In this way, when PSIRT is set up from the perspective of ensuring safety as described above, when some abnormality occurs in the vehicle or the possibility of it occurs, the windows for initially receiving reports are also dispersed, and the labor and working hours related to the work of distinguishing between failures and cyber attacks increase, resulting in delays in responding to vehicle abnormalities.
[0031] The present invention has been completed based on such background. Figure 2 An overview of the entire system including the attack analysis device according to the present invention is shown.
[0032] The attack analysis device according to one embodiment of the present invention is installed as an analysis server 1 on the cloud. Figure 2 As shown, analysis server 1 is connected to VSOC 3 and vehicle 4 via network 2. The analysis server is not limited to being installed on the cloud, and may be installed in each vehicle as hardware including a CPU and memory.
[0033] The analysis server 1 includes a communication unit 11 , a display unit 12 , a determination unit 13 , a distance acquisition unit 14 , a security event acquisition unit 15 , an anomaly acquisition unit 16 , a location distance table 17 , a security event location table 18 , an abnormality location table 19 , a security event storage unit 20 , and an abnormality storage unit 21 .
[0034] VSOC 3 includes a communication unit 31 and a safety event detection unit 32. Vehicle 4 includes a communication unit 41 and a plurality of ECUs (Electronic Control Units) 42. ECUs 42 are onboard devices related to various vehicle control systems capable of performing safety-related self-diagnosis.
[0035] The communication unit 11 of the analysis server 1 transmits a request message to the communication unit 41 of each ECU 42 of the vehicle 4 and receives a response message from each ECU 42. The communication unit 11 also transmits and receives data with the communication unit 31 of the VSOC 3.
[0036] The display unit 12 is configured as a display for displaying various information. The determination unit 13 determines the correlation between the abnormal state of the vehicle and the safety event based on the distance acquired by the distance acquisition unit 14, which will be described in detail later.
[0037] The distance acquisition unit 14 acquires the physical or logical distance between the detected abnormal state of the vehicle and the safety event. The safety event acquisition unit 15 acquires and records the safety event that occurred in the vehicle based on the safety event detection signal received from the safety event detection unit 32 of the VSOC 3. The abnormality acquisition unit 16 acquires information related to abnormalities that occurred in any ECU 42 of the vehicle 4.
[0038] Here, the information related to abnormalities acquired by the abnormality acquisition unit 16 will be described. When an abnormality occurs in the ECU 42 of the vehicle 4, a diagnostic trouble code (DTC) indicating the type of abnormality is issued. A DTC is a 3-byte code indicating an abnormal state of the vehicle and is defined in ISO 15031-6.
[0039] DTC codes have standardized parameter areas and OEM-defined parameter areas, the latter of which can be used independently by OEMs. In DTCs, a 1-byte status flag (FTB: Failure Type Byte) indicates the status of the corresponding DTC code (determined fault, undetermined fault, etc.).
[0040] In order to identify the cause of the abnormality, DTC may also include DTC snapshot data that records ECU control data when the DTC occurs, and DTC extended data that records the frequency of fault occurrence, the odometer value when the fault first occurs, etc.
[0041] The abnormality acquisition unit 16 acquires and stores information on DTCs generated in one ECU and / or a plurality of ECUs as a history of abnormal events together with a time stamp.
[0042] The inter-location distance table 17 is a table that records information regarding the physical / logical distances between various components within vehicle 4. In this context, physical / logical distances do not simply represent two-dimensional distances between components, but rather represent safety isolation, as will be described in detail later. The security event location table 18 is a table that records the associations between security events and the locations within vehicle 4 where they occurred. The abnormality location table 19 is a table that records the associations between abnormal events and the locations within vehicle 4 where they occurred.
[0043] The security event storage unit 20 records security events that occurred in the past as time series data. Similarly, the abnormal state storage unit 21 records abnormal state that occurred in the past as time series data.
[0044] The VSOC 3 manages the safety of the vehicle after shipment. The communication unit 31 receives threat / vulnerability information from the vehicle, and the security event detection unit 32 detects the information as a security event and transmits it to the communication unit 11 of the analysis server 1 via the communication unit 31 .
[0045] When any threat / vulnerability information is generated, each ECU 42 in the vehicle 4 transmits it to the communication unit 31 of the VSOC 3 via the communication unit 41. When an abnormality occurs, a DTC corresponding to the abnormality is transmitted to the communication unit 11 of the analysis server 1.
[0046] Next, use Figure 3 The physical and logical distances between an abnormal situation occurring in the ECU 42 in the vehicle 4 and a safety event will be described.
[0047] like Figure 3 As shown, the components in the vehicle 4 are connected by physical components based on hardware (solid lines) or logical components based on software (dashed lines). In addition, the numerical value on each connection represents the distance of the connection. When the numerical value is 0, it means that substantially no time is required for sending and receiving data. In addition, it can also be said to be equivalent to the labor required for a third party to move between components through an attack. In addition, Figure 3 In order to simplify the description, the distance values are set to only 0 and 1, but the actual distance will of course vary depending on the type of vehicle, etc.
[0048] And, in Figure 3 In the example, it is assumed that a DTC indicated by code: P0120 is issued from the throttle position sensor to the abnormality acquisition unit 16 of the analysis server 1 as an abnormality occurring in the ECU. This DTC indicates a short circuit or disconnection in the throttle position sensor circuit.
[0049] Meanwhile, VSOC 3 detects a MAC error in the communication path between the engine ECU and the CGW (Central Gateway) in the vehicle as security event 1, and a user authentication error when executing an IVI (In-Vehicle Infotainment) application as security event 2, and notifies the security event acquisition unit 15 of the analysis server 1 of these events. A MAC error here means a failure in access control using the MAC address unique to each ECU, and a user authentication error means a failure in user authentication control required for computer startup.
[0050] Furthermore, the shortest path between abnormal state A and safety event 1 is safety event 1 → engine ECU: CAN3 → engine ECU: OS → engine ECU: application → throttle position sensor: sensor, and its distance is 2.
[0051] On the other hand, the shortest path between abnormal event A and security event 2 is security event 2 → IVI: application → IVI: OS → IVI: Ethernet 2 → CGW: Ethernet X → CGW: OS → CGW: CAN X → engine ECU: CAN3 → engine ECU: OS → engine ECU: application → throttle position sensor: sensor, and its distance is 8.
[0052] Based on the above, abnormal event A is determined to be highly correlated with security event 1. By presetting the distance threshold to a predetermined value, if an abnormal event occurs and there are no security events occurring within the threshold, it can be quickly determined that the abnormal event is not an attack but a simple malfunction.
[0053] In the above description, Figure 3 In the distance between components, the direction is not considered. On the other hand, the direction is also considered in the distance between components. The result of connecting the nodes of the components with directed edges and forming a directed graph is Figure 4 .like Figure 4 As shown, the distances in the incoming and outgoing directions may differ depending on the security level of the component, etc. Specifically, the distance to a directed edge toward a component with a high security level is weighted relatively more than the distance to a directed edge toward a component with a low security level, and is determined to be a long distance.
[0054] By utilizing the result of such directed graphing, the correlation between abnormal situations and safety events can be determined more accurately. In addition, the directed graph and edge distance are associated with, for example, the vehicle model identification number or the vehicle individual identification number of the vehicle equipped with the vehicle-mounted device.
[0055] Figure 5 This is a flowchart showing the processing executed by the attack analysis device according to the present invention described above.
[0056] First, the abnormality acquisition unit 16 receives the DTC code from the ECU in the vehicle to obtain the abnormality log (step 501). Next, the abnormality acquisition unit 16 refers to the abnormality location table 19, identifies the location where the abnormality occurred, and stores it in the abnormality storage unit 21 (step 502).
[0057] Next, the security event acquisition unit 15 refers to the security event storage unit 20 and extracts security events that occurred within a predetermined period before the abnormal event received in step 501 (step 503). Next, the security event acquisition unit 15 refers to the security event location table 18 for each security event extracted in step 503 and identifies its occurrence location (step 504).
[0058] Next, the determination unit 13 refers to the inter-point distance table 17 and calculates the shortest route and distance between the abnormality occurrence points / security incident occurrence points identified in steps 502 and 504 (step 505). The calculation of this shortest route can be performed using, for example, the Dijkstra method, which is an algorithm for finding the shortest path starting from a certain point on a graph (solving the single-starting point shortest path problem).
[0059] Next, the determination unit 13 compares the distance calculated in step 505 to see if it is below a predetermined threshold (step 506). If the distance is below the threshold, it is determined that there is a correlation between the abnormal situation and the security incident (step 507); if the distance is greater than the threshold, it is determined that there is no correlation (step 508). Finally, the determination unit 13 tabulates the results of the determination for all security incidents and returns them to the display unit 12 for display (step 509). Alternatively, if a correlation is determined in step 507, it may be determined that a log analysis of the path between the location where the abnormal situation occurred and the location where the security incident occurred is necessary, and this information may be output.
[0060] As explained in the anomaly description, the present invention determines the correlation between abnormal events and security incidents by focusing on the distance between the occurrence locations. Therefore, security incidents with a high probability of causing abnormal events can be investigated first, thus preventing increased labor and man-hours and overlooking attacks.
[0061] According to the embodiments of the present invention described above, the following effects are achieved.
[0062] (1) The attack analysis device involved in the present invention comprises: an abnormality acquisition unit for acquiring information related to an abnormal state of an on-board device; a security event detection unit for detecting a security event of the on-board device; a distance acquisition unit for acquiring the distance of the shortest path connecting the abnormal state occurrence location and the security event occurrence location of the security event; and a determination unit for determining the correlation between the abnormal state and the security event based on the distance.
[0063] With the above configuration, when an abnormality occurs in the vehicle-mounted device, it is possible to easily determine whether the abnormality is an attack from the outside.
[0064] (2) The distance acquisition unit acquires the distance based on any of the physical components of hardware or the logical components of software that exist between the abnormality occurrence location and the security event occurrence location.
[0065] (3) The distance acquisition unit acquires the distance by weighting the physical or logical components according to their security categories. The higher the security level, the higher the barrier to attacking the component, that is, the longer the distance. This is therefore preferable.
[0066] (4) The distance acquisition unit acquires the distance based on a directed graph in which nodes of the physical components or logical components are connected by directed edges. The processing of (3) is specifically performed as follows.
[0067] (5) The distance acquisition unit weights the directed edges of the directed graph according to the edge distances assigned thereto, and the directed graph and the edge distances are associated with the vehicle model identification number or the vehicle individual identification number of the vehicle equipped with the vehicle-mounted device. Thus, the processes of (3) and (4) can be appropriately executed based on the information of each vehicle.
[0068] (6) The determination unit further determines whether to perform log analysis on the path between the abnormality occurrence location and the security incident occurrence location based on the distance. This allows simultaneous determination of whether a more detailed investigation and prioritization are required based on the correlation between the abnormality and the security incident.
[0069] The technical scope of the present invention is not limited to the scope of the above-mentioned embodiment, and includes various modifications without departing from the main features of the present invention. Therefore, the above-mentioned embodiment is only a simple illustration and should not be interpreted in a limiting sense. In addition, about a part of the structure of each embodiment, other structures can be added, deleted, or replaced, and all are included in the scope of the present invention.
[0070] (Explanation of Symbols)
[0071] 1: Analysis server (attack analysis device); 13: Determination unit; 14: Distance acquisition unit; 15: Security event acquisition unit; 16: Abnormality acquisition unit; 42: ECU.
Claims
1. An attack analysis device, characterized in that: have: an abnormality acquisition unit that acquires information related to an abnormal state of the vehicle-mounted device; A security event detection unit, configured to detect security events of the vehicle-mounted device; a distance acquisition unit that acquires the distance of the shortest path between the abnormality occurrence location where the abnormality occurred and the security incident occurrence location where the security incident occurred; as well as The determination unit determines the relevance between the abnormal state and the security incident based on the distance.
2. The attack analysis device according to claim 1, characterized in that: The distance acquisition unit acquires the distance based on any one of a physical component of hardware or a logical component of software that exists between the abnormality occurrence location and the security event occurrence location.
3. The attack analysis device according to claim 2, characterized in that: The distance acquisition unit acquires the distance by performing weighting according to the security category of the physical component or the logical component.
4. The attack analysis device according to claim 3, characterized in that: The distance acquisition unit acquires the distance based on a directed graph in which nodes of the physical components or the logical components are connected by directed edges.
5. The attack analysis device according to claim 4, characterized in that: The distance acquisition unit performs the weighting according to the edge distance assigned to the directed edge of the directed graph, The directed graph and the edge distance are associated with a vehicle model identification number or a vehicle individual identification number of a vehicle on which the vehicle-mounted device is mounted.
6. The attack analysis device according to claim 1, characterized in that: The determination unit further determines, based on the distance, whether to perform log analysis on a path between the abnormality occurrence location and the security incident occurrence location.
Citation Information
Patent Citations
Cause estimating method for nonconformity event
JP1995013617A
Cyber attack analysis support device
JP2021117568A
Information processing device, log analysis method, and program
WO2020075808A1