Abnormality detection method, abnormality detection device, and program
The GW device detects network anomalies through simple and detailed learning models, reducing resource consumption while improving detection accuracy. This solves the problem of high resource consumption and insufficient accuracy in existing technologies and achieves efficient network attack detection.
Patent Information
- Application Number
- CN202480014590.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-09
- Filing Date
- 2024-02-07
- Publication Date
- 2025-10-03
AI Technical Summary
Existing technologies require a large amount of processing resources when detecting network anomalies, resulting in high resource consumption and insufficient detection accuracy.
The GW device detects control information flowing through the network, and uses simple learning and detailed learning models to detect anomalies in communication information and control logs respectively. When an anomaly is detected, an alert message is sent to adjust the device mode, reducing processing volume while improving detection accuracy.
While reducing processing resources, it achieves high-precision network anomaly detection and can promptly detect and respond to network attacks.
Smart Images

Figure CN120752899A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an abnormality detection method, an abnormality detection device, and a program. Background Art
[0002] Conventionally, there are devices that detect abnormalities in communications such as cyber attacks (for example, see Patent Document 1).
[0003] The system disclosed in Patent Document 1 extracts features from system log data through natural language processing and identifies a network attack based on a system entropy measurement value obtained from the extracted features.
[0004] Prior art literature
[0005] Patent Literature
[0006] Patent Document 1: Japanese Patent Application Publication No. 2019-145081 Summary of the Invention
[0007] Problems to be solved by the invention
[0008] For example, if information such as control logs is continuously received from each device in the network and anomalies are detected, anomalies in the network can be easily and reliably detected. However, detecting anomalies in this method requires a large amount of resources, such as the processing power of the processor and the capacity of the memory.
[0009] The present disclosure provides an anomaly detection method and the like that can detect anomalies with high accuracy while reducing the amount of processing for detecting anomalies in a network.
[0010] Technical solutions to solve problems
[0011] A technical solution disclosed herein involves an anomaly detection method performed by an anomaly detection device capable of communicating with multiple devices that can communicate with each other via a predetermined network, comprising: a first detection step of detecting an anomaly in first control information flowing through the predetermined network; and a second detection step of, when an anomaly is detected in the first detection step, sending a first instruction to the multiple devices to cause the devices to send second control information indicating the control content executed by the devices, and detecting an anomaly in the received second control information.
[0012] A technical solution disclosed herein involves an anomaly detection device that is capable of communicating with multiple devices that can communicate with each other via a predetermined network, and comprises: a first detection unit that detects an anomaly in first control information flowing through the predetermined network; and a second detection unit that, when an anomaly is detected by the first detection unit, sends a first instruction to the multiple devices to cause the devices to send second control information indicating the control content executed by the devices, and detects an anomaly in the received second control information.
[0013] A program according to one aspect of the present disclosure is a program for causing a computer to execute the above-described abnormality detection method.
[0014] Effects of the Invention
[0015] According to the present disclosure, it is possible to provide an anomaly detection method or the like that can detect an anomaly with high accuracy while reducing the amount of processing for detecting an anomaly in a network. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 This is a diagram for explaining an overview of a communication system according to an embodiment.
[0017] Figure 2 This is a block diagram showing the functional configuration of a GW device according to an embodiment.
[0018] Figure 3 This is a diagram showing an example of a simplified learning result according to the embodiment.
[0019] Figure 4 This is a diagram showing an example of predefined information according to the embodiment.
[0020] Figure 5 This is a diagram showing an example of warning information according to the embodiment.
[0021] Figure 6 This is a diagram showing an example of a control log according to the embodiment.
[0022] Figure 7 This is a diagram showing an example of detailed learning results according to the embodiment.
[0023] Figure 8 It is a diagram showing a specific example of communication information involved in the embodiment.
[0024] Figure 9 It is a diagram showing a specific example of the control log according to the embodiment.
[0025] Figure 10 This is a flowchart showing a processing procedure (procedure, steps) of the GW device according to the embodiment.
[0026] Figure 11 This is a flowchart showing the processing procedure of the simplified detection process according to the embodiment.
[0027] Figure 12 This is a flowchart showing the processing procedure of the IoT device involved in the embodiment.
[0028] Figure 13 This is a flowchart showing a detailed processing procedure of the detection process according to the embodiment.
[0029] Figure 14 It is a sequence diagram showing the processing procedure of the communication system involved in the embodiment. DETAILED DESCRIPTION
[0030] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings.
[0031] In addition, the embodiments described below all represent general or specific examples. The numerical values, shapes, materials, constituent elements, configuration positions of constituent elements, and connection methods, steps, the order of steps, etc. shown in the following embodiments are examples and are not intended to limit the present disclosure. In addition, among the constituent elements in the following embodiments, the constituent elements that are not recorded in the independent claims of the present disclosure are described as arbitrary constituent elements. In addition, the figures are not necessarily strictly illustrated. In the figures, the same figure marks are marked for substantially the same structures, and repeated descriptions are sometimes omitted or simplified.
[0032] (Implementation Method)
[0033] [constitute]
[0034] Figure 1 It is a diagram for explaining an outline of a communication system 10 according to the embodiment.
[0035] Communication system 10 includes multiple devices that can communicate with each other via a predetermined network (network 600). Communication system 10 includes, for example, a GW (Gateway) device 100, a smart speaker 300, a PC (Personal Computer) 310, a smartphone 320, a refrigerator 330, an air conditioner 340, and a smart key 350.
[0036] Network 600 is, for example, a local area network within a home. GW device 100, smart speaker 300, PC 310, smartphone 320, refrigerator 330, air conditioner 340, and smart key 350 are appliances or other devices that communicate with each other within a closed network 600, such as an indoor network. In this embodiment, GW device 100, smart speaker 300, PC 310, smartphone 320, refrigerator 330, air conditioner 340, and smart key 350 communicate with each other using wireless communication such as Wi-Fi (registered trademark).
[0037] Furthermore, the communication standard adopted for communication in the communication system 10 can be arbitrarily determined.
[0038] Furthermore, the number and types of the plurality of devices included in the communication system 10 can be arbitrarily determined and are not particularly limited.
[0039] Figure 2 1 is a block diagram showing the functional structure of the GW device 100 according to the embodiment. The GW device 100 is an example of an abnormality detection device. Figure 2 In the figure, the devices possessed by the communication system 10, such as the smart speaker 300, PC 310, smart phone 320, refrigerator 330, air conditioning equipment 340 and smart key 350, are represented as two devices, IoT (Internet of Things) device 400 and IoT device 410.
[0040] The GW device 100 is a device for detecting anomalies. The GW device 100 detects anomalies in devices of the communication system 10, such as the IoT device 400 and the IoT device 410 (in other words, anomalies in the network 600). In addition, the GW device 100 has a function as a gateway. For example, the GW device 100 is implemented by a communication interface for communicating with each device of the communication system 10 (for example, the IoT devices 400 and 410), a non-volatile memory storing a program, a volatile memory as a temporary storage area for executing the program, an input and output port for transmitting and receiving signals (sending and receiving), and a processor for executing the program. The communication interface is implemented, for example, by an antenna and a wireless communication circuit to enable wireless communication. The GW device 100 may also have a communication interface such as a connector for connecting a communication line for communicating with the server 500. In addition, the GW device 100 may also be implemented by a connector for connecting a communication line for communicating with a notification device such as a display and / or an audio device.
[0041] The GW device 100 includes a communication receiving unit 110 , a simple learning unit 120 , a simple abnormality determination unit 130 , a command transmission unit 140 , a log receiving unit 150 , a detailed learning unit 160 , a detailed abnormality determination unit 170 , an output unit 180 , a learning result storage unit 190 , and a predefined information storage unit 200 .
[0042] Communication receiving unit 110 is a processing unit that receives information (communication information) communicated between IoT device 400 and IoT device 410 via a communication interface included in GW device 100. Specifically, communication receiving unit 110 obtains communication information by intercepting (eavesdropping on) communication information flowing through network 600. Communication information is an example of first control information.
[0043] The simplified learning unit 120 is a processing unit that performs learning for the simplified abnormality determination unit 130 to determine abnormalities in communication information. For example, using communication information, the simplified learning unit 120 causes a learning model (a first learning model) to learn information such as the time at which IoT devices 400 and 410 communicated, and the communication partner at that time (e.g., the IP (Internet Protocol) address of the communicating device). For example, the simplified learning unit 120 causes the learning model to learn information in such a way that it receives communication information as input and outputs the degree of abnormality in that communication information.
[0044] Furthermore, the timing at which the simple learning unit 120 performs learning may be arbitrary.
[0045] The first learning model is, for example, a machine learning model that utilizes a neural network such as deep learning (for example, a convolutional neural network), but may also be another machine learning model.
[0046] Figure 3 This is a diagram showing an example of a simplified learning result according to the embodiment.
[0047] The simplified learning result includes, for example, "src_ip", "dst_ip", "protocol", "time_range", and "score".
[0048] "src_ip" is the IP address of the transmission source device of the communication information.
[0049] "dst_ip" is the IP address of the destination device of the communication information.
[0050] "Protocol" is the communication standard used for communication of information.
[0051] "time_range" is a period during which communication information is sent and received.
[0052] "score" is in Figure 3 The degree of abnormality of the communication information in the case of "src_ip", "dst_ip", "protocol" and "time_range" shown. For example, the higher the "score", the more abnormal it is determined by the simple abnormality determination unit 130. For example, a threshold value of "score" is arbitrarily determined in advance. For example, when the "score" is above the threshold value, the communication information including "src_ip", "dst_ip", "protocol" and "time_range" is determined to be abnormal. On the other hand, for example, when the "score" is below the threshold value, the communication information including "src_ip", "dst_ip", "protocol" and "time_range" is determined to be normal.
[0053] The simple learning unit 120 generates the following information based on the communication information: Figure 3 Such information is referred to as a simplified learning result, and the learning result storage unit 190 stores the generated simplified learning result.
[0054] The simple abnormality determination unit 130 is a processing unit that detects abnormality in communication information flowing through the network 600. Specifically, the simple abnormality determination unit 130 determines whether the communication information is abnormal. The simple abnormality determination unit 130 is an example of a first detection unit.
[0055] For example, the simplified abnormality determination unit 130 determines whether the communication information is abnormal using the above-mentioned first learning model (that is, the simplified learning result) and / or predefined information.
[0056] Figure 4 This is a diagram showing an example of predefined information according to the embodiment.
[0057] Predefined information is information used by the simplified abnormality determination unit 130 for abnormality detection. It is information predefined by a user or the like and stored in the predefined information storage unit 200. For example, depending on the devices that comprise the communication system 10, the communication counterpart may be predetermined. Therefore, the simplified abnormality determination unit 130 uses predefined information representing a so-called whitelist and / or blacklist, for example, to detect abnormalities. Predefined information includes, for example, "src_ip," "dst_ip," "protocol," and "type."
[0058] "type" means, for example, Figure 4 In the case of "src_ip", "dst_ip" and "protocol" shown in the table, whether it is judged to be abnormal. Figure 4 In the example shown, "type" is "white", so Figure 4The communication information communicated using the "src_ip", "dst_ip", and "protocol" shown is determined to be normal. On the other hand, for example, if "type" is "black", the communication information communicated using the "src_ip", "dst_ip", and "protocol" associated with this "type" is determined to be abnormal.
[0059] The instruction transmission unit 140 is a processing unit that transmits warning transmission information to the IoT devices 400 and 410 via the communication interface of the GW device 100 when the simple abnormality determination unit 130 detects an abnormality, that is, when the simple abnormality determination unit 130 determines that an abnormality exists. The warning transmission information is an example of the first instruction.
[0060] Furthermore, the command transmission unit 140 may transmit the alert information only to the source and destination devices of the communication information that has detected an abnormality, among the multiple devices included in the communication system 10. Furthermore, the command transmission unit 140 may also transmit the alert information to devices included in the communication system 10 other than the source and destination devices of the communication information that has detected an abnormality. Furthermore, the command transmission unit 140 may transmit the alert information only to the source device of the communication information that has detected an abnormality. Furthermore, the command transmission unit 140 may transmit the alert information only to the destination device of the communication information that has detected an abnormality.
[0061] Figure 5 This is a diagram showing an example of warning information according to the embodiment.
[0062] The alert communication information is information for switching the IoT device 400 and the IoT device 410 to the alert mode. The alert mode is a mode in which a control log indicating the processing performed by the device is sent to the GW device 100. The control log is an example of the second control information. For example, when a device that has switched to the alert mode has performed a process based on information received from the source and destination of the communication information in which an abnormality has been detected, the device sends a control log indicating the executed processing to the GW device 100. In addition, when a device that has switched to the alert mode receives information (for example, information that causes the device that has switched to the alert mode to perform control) from the source and destination of the communication information in which an abnormality has been detected after switching to the alert mode, the device performs the processing without blocking the processing from the perspective of availability, and sends the information indicating the processing to the GW device 100 as a control log.
[0063] The warning notification information includes, for example, "warning_flag", "warning_ip", "cancellation_condition", and "target_ip".
[0064] "warning_flag" is a flag that switches IoT device 400 and IoT device 410 to alert mode. For example, if "warning_flag" is "True," that is, if the warning notification information includes the flag, IoT device 400 and IoT device 410 switch to alert mode. The flag is an example of the first instruction.
[0065] “warning_ip” is information indicating the IP addresses of the device that received the communication information indicating abnormality detection by the simplified abnormality determination unit 130 and the device that transmitted the communication information indicating abnormality detection by the simplified abnormality determination unit 130 , among the plurality of devices included in the communication system 10 .
[0066] "cancellation_condition" is a cancellation instruction for canceling alert mode. Specifically, the cancellation instruction is information for instructing IoT devices 400 and 410 to stop transmitting control logs. The cancellation instruction is an example of a second instruction. For example, the cancellation instruction includes time information indicating the time when control log transmission will be stopped. If IoT devices 400 and 410 are in alert mode, they will transition from alert mode to normal mode at this time and stop transmitting control logs.
[0067] This time can be determined arbitrarily. For example, the instruction transmission unit 140 sets the time as the time when a predetermined time has passed since the abnormality was detected by the simple abnormality determination unit 130. The predetermined time can be determined arbitrarily in advance.
[0068] "target_ip" is the IP address of the destination where the alert notification information is sent.
[0069] As described above, the instruction transmission unit 140, for example, when an abnormality is detected by the simple abnormality determination unit 130, sends a flag to multiple devices included in the communication system 10 to cause the devices to send control logs indicating the content of the control performed by the devices. Furthermore, for example, when an abnormality is detected by the simple abnormality determination unit 130, the instruction transmission unit 140 sends a flag to the device (first device) that received the communication information indicating the abnormality detected by the simple abnormality determination unit 130 and the device (second device) that sent the communication information indicating the abnormality detected by the simple abnormality determination unit 130, among the devices included in the communication system 10. Furthermore, for example, the instruction transmission unit 140 sends a release instruction to the first device and the second device to stop sending the control log. In this embodiment, the flag and the release instruction are included in the alert transmission information.
[0070] Furthermore, the release instruction may be sent to the devices that have transitioned to the alert mode (for example, the first device and the second device described above) when a predetermined time has passed since the simple abnormality determination unit 130 detected the abnormality, for example.
[0071] The log receiving unit 150 is a processing unit that receives a control log from a device that has transitioned to the alert mode (in this example, the IoT device 400 and the IoT device 410 ) via a communication interface provided in the GW device 100 .
[0072] Figure 6 This is a diagram showing an example of a control log according to an embodiment. The control log is information transmitted from IoT device 410 to IoT device 400 as communication information in order to control IoT device 400, and is information stored in IoT device 400 as a control log.
[0073] The control log includes, for example, "timestamp", "src_ip", "dst_ip", "protocol", "object", "property", and "value".
[0074] "Timestamp" is information indicating the date and time when communication information including the control content (control instruction) indicated in the control log was transmitted.
[0075] "object" is information indicating the type of device. In "object", for example, it indicates the type of device such as refrigerator, washing machine or air conditioner. Figure 6 In the example shown, the type of device is indicated by a numerical value such as "0x30".
[0076] "Property" is information indicating the control content. In "property", for example, the control content such as temperature setting or humidity setting is indicated. Figure 6 In the example shown, the control content is expressed by a numerical value such as "0xB3".
[0077] "value" is information indicating a value (control value) for controlling the control content indicated by "property." For example, "value" indicates a numerical value such as "30."
[0078] For example, IoT device 400 receives the following information from IoT device 410: Figure 6If the control log (communication information indicating a control instruction) is received, control is performed as indicated in the control log. For example, if IoT device 400 is an air conditioner and the received communication information contains "object" indicating an air conditioner, "property" indicating a temperature setting, and "value" indicating 30, the air conditioner is controlled to maintain a temperature of 30°C.
[0079] "timestamp," "src_ip," "dst_ip," and "protocol" are examples of first information. For example, first information is information contained in the header of communication information (a communication packet containing communication information). For example, the first information contained in the communication information is unencrypted. In other words, the first information is unencrypted during communication between IoT device 400 and IoT device 410.
[0080] "object," "property," and "value" are examples of second information. For example, the second information included in the communication information is encrypted. On the other hand, for example, the second information included in the control log sent from IoT device 400 and / or IoT device 410 to GW device 100 is not encrypted.
[0081] Furthermore, the second information included in the control log transmitted from the IoT device 400 and / or the IoT device 410 to the GW device 100 may be encrypted. In this case, the GW device 100 may store an encryption key for decrypting the encrypted second information.
[0082] Detailed learning unit 160 is a processing unit that performs learning for use by detailed abnormality determination unit 170 in determining abnormalities in control logs. For example, detailed learning unit 160 uses learning logs received from server 500 to cause a learning model (second learning model) to learn the content and timing of the controls performed by IoT devices 400 and 410. For example, detailed learning unit 160 causes the learning model to learn by taking control logs as input and outputting the degree of abnormality in the control logs.
[0083] The learning logs are, for example, control logs of the IoT devices 400 and 410. The IoT devices 400 and 410 periodically transmit the control logs to the server 500. The server 500 periodically transmits the received control logs to the GW device 100 as learning logs.
[0084] The timing and frequency at which the IoT devices 400 and 410 transmit the control logs to the server 500 and the timing and frequency at which the server 500 transmits the control logs as learning logs to the GW device 100 can be arbitrarily determined.
[0085] In addition, the timing at which the detailed learning unit 160 performs learning may be arbitrary.
[0086] The second learning model is, for example, a machine learning model that utilizes a neural network such as deep learning (for example, a convolutional neural network), but may also be another machine learning model.
[0087] Figure 7 This is a diagram showing an example of detailed learning results according to the embodiment.
[0088] The detailed learning result includes, for example, "src_ip", "dst_ip", "protocol", and "value_range".
[0089] "value_range" is information indicating "score" corresponding to "object", "property" and "value". Figure 7 In the example shown, when "object" is "0x30," "property" is "0xB3," and "value" is "18 to 25," the "score" is 10. Alternatively, when "object" is "0x30," "property" is "0xB3," and "value" is "30 or greater," the "score" is 80. Furthermore, when "object" is "0x30," "property" is "0xB0," and "value" is "1," the "score" is 10. Furthermore, when "object" is "0x30," "property" is "0xB0," and "value" is "2," the "score" is 10.
[0090] In addition, when "object" represents "0x30", "property" represents "0xB0", and "value" represents "3", "score" is 60.
[0091] For example, the higher the "score", the more abnormal the detailed abnormality determination unit 170 determines it to be. For example, a threshold value of "score" is arbitrarily determined in advance. For example, when the "score" is above the threshold value, the control log containing "src_ip", "dst_ip", "protocol", and "object", "property", and "value" contained in "value_range" is determined to be abnormal. On the other hand, for example, when the "score" is lower than the threshold value, the control log containing "src_ip", "dst_ip", "protocol", and "object", "property", and "value" contained in "value_range" is determined to be normal.
[0092] The detailed learning unit 160 generates the following information based on the learning log: Figure 7 Such information is indicated as a detailed learning result, and the learning result storage unit 190 stores the generated detailed learning result.
[0093] In addition, the threshold value used by the simple abnormality determination unit 130 to determine an abnormality and the threshold value used by the detailed abnormality determination unit 170 to determine an abnormality may be the same as or different from each other.
[0094] The detailed abnormality determination unit 170 is a processing unit that detects abnormalities in the control log received by the log receiving unit 150. The command transmission unit 140, the log receiving unit 150, and the detailed abnormality determination unit 170 are an example of a second detection unit.
[0095] For example, the detailed abnormality determination unit 170 uses the above-mentioned second learning model (that is, the detailed learning result) to determine whether the control log is abnormal.
[0096] As described above, for example, the simplified anomaly determination unit 130 detects anomalies in communication information. Specifically, the simplified anomaly determination unit 130 detects anomalies in the first information included in the communication information, such as "src_ip," "dst_ip," and "protocol." Meanwhile, for example, the detailed anomaly determination unit 170 detects anomalies based on a control log containing the first information and second information such as "object," "property," and "value." Thus, for example, the amount of information in the control log (the amount of data used to detect anomalies) is greater than the amount of information in the first information included in the communication information.
[0097] By detecting an abnormality in the above information, the GW device 100 detects an abnormality in the network 600 .
[0098] The output unit 180 is a processing unit that notifies a notification of abnormality when an abnormality is detected by the detailed abnormality determination unit 170. The output unit 180 is an example of a notification unit.
[0099] The output unit 180 notifies the user of the abnormality by transmitting detection information for notifying the user of the abnormality to a notification device such as a smartphone, PC, display, speaker, or server 500 used by the user, for example.
[0100] The detection information may be any information as long as it is used to notify the user of an abnormality, and may be image information, voice information, or information used to perform other notification methods.
[0101] The processing units such as the communication receiving unit 110, the simple learning unit 120, the simple abnormality determination unit 130, the instruction transmission unit 140, the log receiving unit 150, the detailed learning unit 160, the detailed abnormality determination unit 170, and the output unit 180 are implemented, for example, by a memory and a processor such as a CPU (Central Processing Unit) that executes the control program stored in the memory. The memory of these processing units can be implemented by a common memory or by one or more independent memories. In addition, the processors of these processing units can be implemented by a common processor or by one or more independent processors.
[0102] The learning result storage unit 190 is a storage device that stores the learning results of the simple learning unit 120 and the detailed learning unit 160. For example, the learning result storage unit 190 stores the learning models learned by the simple learning unit 120 and the detailed learning unit 160.
[0103] The predefined information storage unit 200 is a storage device that stores predefined information.
[0104] The learning result storage unit 190 and the predefined information storage unit 200 are implemented, for example, by a storage device such as a semiconductor memory or an HDD (Hard Disc Drive). Furthermore, the learning result storage unit 190 and the predefined information storage unit 200 can be implemented by a common storage device or by one or more independent storage devices. Furthermore, the one or more storage devices can also store control programs executed by each processing unit. In this case, each processing unit may not have a memory.
[0105] The IoT devices 400 and 410 are devices capable of communicating with each device included in the communication system 10 via the network 600 .
[0106] For example, IoT devices 400 and 410 are each implemented by a communication interface for communicating with various devices included in communication system 10, a non-volatile memory storing programs, a volatile memory serving as a temporary storage area for executing programs, input and output ports for transmitting and receiving signals, and a processor for executing programs. This communication interface is implemented, for example, by an antenna and wireless communication circuitry to enable wireless communication. IoT devices 400 and 410 may also each include a communication interface such as a connector for connecting to a communication line used for communicating with server 500.
[0107] Server 500 is a device capable of communicating with each device included in communication system 10. Server 500 can communicate with each device included in communication system 10 via network 600 or communicate with the devices not via network 600, such as the Internet.
[0108] For example, the server 500 is implemented by a communication interface for communicating with each device included in the communication system 10, a non-volatile memory storing a program, a volatile memory serving as a temporary storage area for executing the program, an input / output port for transmitting and receiving signals, and a processor for executing the program. The communication interface may be implemented, for example, by an antenna and a wireless communication circuit to enable wireless communication, or by a connector for connecting a communication line.
[0109] [Specific example]
[0110] Next, a specific example of the abnormality detection process executed by the GW device 100 will be described.
[0111] Figure 8 : is a diagram showing a specific example of communication information involved in the embodiment. Specifically, Figure 8 This is a diagram showing communication information intercepted by the GW device 100 .
[0112] For example, it is assumed that the IoT device 410 sends the communication information for controlling the IoT device 400 to the IoT device 400. Figure 8 The GW device 100 obtains the information by interception and detects abnormality in the obtained information.
[0113] like Figure 8 As shown, the communication information includes, for example, "timestamp", "src_ip", "dst_ip", "protocol", "object", "property", and "attribute".
[0114] “Timestamp” is information indicating the time when the IoT device 410 transmitted communication information to the IoT device 400 .
[0115] “src_ip” is information indicating the IP address of the IoT device 410 .
[0116] “dst_ip” is information indicating the IP address of the IoT device 400 .
[0117] “Protocol” is information indicating a communication standard for communication between the IoT device 400 and the IoT device 410 .
[0118] “object” is information indicating the type of the IoT device 400 .
[0119] “Property” is information indicating the content of control to be executed by the IoT device 400 .
[0120] "attribute" is information indicating processing for the control content indicated by "property." "attribute" is an example of the second information.
[0121] Here, "object" and "property" are as follows Figure 6 As shown, "0x30" and "0xB3" are indicated. For example, "attribute" indicates an instruction to request information indicating the current value of the control content indicated by "property" by "GET" or the like.
[0122] However, for example, in the communication information transmitted from the IoT device 410 to the IoT device 400 , the information is encrypted so that the GW apparatus 100 cannot read it.
[0123] For example, when a network attack such as a read attack of a setting value is carried out from the IoT device 410 to the IoT device 400, although the "attribute" is set to "GET", it is encrypted and therefore cannot be read by the GW device 100.
[0124] GW device 100 then detects an abnormality in the readable, unencrypted information (first information) within the communication information. For example, using the simplified learning results, GW device 100 determines the abnormality level (score) of the communication information to be, for example, 80. Furthermore, a threshold value is pre-determined, for example, to be 60, and the determined abnormality level is compared with the threshold value. In this example, GW device 100 determines that the communication information is abnormal. GW device 100 transmits a warning notification message to IoT device 400 and IoT device 410.
[0125] The GW device 100 transitions to a detailed detection mode in which abnormality detection is performed by the detailed abnormality determination unit 170. In addition, the IoT devices 400 and 410 transition to an alert mode.
[0126] Figure 9 : is a diagram showing a specific example of a control log according to an embodiment of the present invention. Specifically, Figure 9 This is information indicating a control log transmitted from the IoT device 400 and / or the IoT device 410 .
[0127] like Figure 9 As shown, the control log includes, for example, "timestamp", "src_ip", "dst_ip", "protocol", "object", "property", "attribute", and "value".
[0128] "SET" indicated by "attribute" indicates an instruction to set the control content indicated by "property" to the value indicated by "value".
[0129] For example, when a network attack such as a setting value rewrite attack is carried out from the IoT device 410 to the IoT device 400 , “attribute” is set to “SET” or the like.
[0130] Figure 9 The control log shown is the same as Figure 8 The communication information shown is different in that “object”, “property”, “attribute” and “value” are not encrypted. In other words, the IoT device 400 and / or the IoT device 410 sends this information to the GW apparatus 100 without encryption.
[0131] As a result, the GW device 100 detects abnormality in the control log (the first information and the second information in this example).
[0132] Furthermore, as described above, the information transmitted from the IoT device 400 and / or the IoT device 410 to the GW apparatus 100 may also be encrypted.
[0133] For example, GW device 100 uses the detailed learning results to determine the abnormality level (score) of the communication information to be, for example, 80. Furthermore, a threshold value is pre-determined, for example, to be 60, and the determined abnormality level is compared with the threshold value. In this example, GW device 100 determines that there is an abnormality in the control log. GW device 100 outputs detection information for notifying a user of the abnormality. Thus, the user is notified of the abnormality detected by GW device 100.
[0134] [Processing process]
[0135] Next, the processing procedures of the GW device 100 and the IoT device 400 will be described. The IoT device 410 performs substantially the same processing as the IoT device 400.
[0136] Figure 10 This is a flowchart showing the processing procedure of the GW device 100 according to the embodiment. Figure 10 At the beginning of the flowchart, the state in which no abnormality in the communication information is detected is explained, and the GW device 100 is in a simple detection mode in which abnormality detection of the control log is not performed.
[0137] First, the GW device 100 detects an abnormality in the communication information (simple detection process) ( S110 ). The specific process procedure of the simple detection process will be described later.
[0138] Next, the simple abnormality determination unit 130 determines whether or not there is an abnormality in the communication information (whether or not there has been a simple detection) based on the result of the simple detection process executed in step S110 ( S120 ).
[0139] When the simplified abnormality determination unit 130 determines that there is no abnormality in the communication information ( S120 : No), the process returns to step S110 .
[0140] On the other hand, when the simple abnormality determination unit 130 determines that the communication information has an abnormality ( S120 : YES), the command transmission unit 140 obtains device information such as the IP address of each device used to communicate with the plurality of devices included in the communication system 10 ( S130 ).
[0141] Next, the instruction transmission unit 140 transmits the warning transmission information to the plurality of devices ( S140 ).
[0142] Furthermore, in steps S130 and S140, the command transmission unit 140 may also obtain device information of each of the multiple devices that received the communication information detected as abnormal in step S110 and the device that sent the communication information, and transmit the alert notification information to each device. Furthermore, in steps S130 and S140, the command transmission unit 140 may also obtain device information of multiple devices existing in the same network and transmit the alert notification information to these devices.
[0143] Next, the GW device 100 transitions to a detailed detection mode in which the detailed abnormality determination unit 170 detects abnormalities in the control log ( S150 ).
[0144] Next, the GW device 100 detects an abnormality in the control log (detailed detection processing) (S160). The specific processing procedure of the detailed detection processing will be described later.
[0145] Next, the detailed abnormality determination unit 170 determines whether or not there is an abnormality in the control log (whether or not there has been a detailed detection) based on the result of the detailed detection process executed in step S160 ( S170 ).
[0146] When the detailed abnormality determination unit 170 determines that the control log has an abnormality ( S170 : Yes), the output unit 180 outputs the detection information ( S180 ).
[0147] Next, the GW device 100 transitions to the simple detection mode ( S190 ), and returns the process to S110 .
[0148] On the other hand, if the detailed abnormality determination unit 170 determines that there is no abnormality in the control log (S170: No), it determines whether the conditions for releasing the alert mode are met. In this example, the detailed abnormality determination unit 170 determines whether a predetermined time has passed since the transition to the detailed detection mode, in other words, since the abnormality in the communication information was detected in step S120 (S200).
[0149] When the detailed abnormality determination unit 170 determines that the predetermined time has not elapsed ( S200 : NO), the process returns to S160 and performs detailed detection processing on a control log different from the control log for which detailed detection processing was previously performed.
[0150] On the other hand, when the detailed abnormality determination unit 170 determines that the predetermined time has elapsed ( S200 : YES), the process proceeds to S190 .
[0151] In addition, after step S180 , the process may proceed to step S200 .
[0152] Furthermore, the GW device 100 can also perform a simple detection process in the detailed detection mode.
[0153] Figure 11 Flowchart showing the process of the simplified detection process according to the embodiment. Figure 11 Yes Figure 10 Detailed flowchart of step S110 and step S120 is shown.
[0154] First, the simplified abnormality determination unit 130 obtains communication information from communications between multiple devices included in the communication system 10 via the network 600 (S210). Specifically, the simplified abnormality determination unit 130 obtains communication information flowing through the network 600. Specifically, the communication receiving unit 110 intercepts communication information flowing through the network and outputs the intercepted communication information to the simplified abnormality determination unit 130. Thus, the simplified abnormality determination unit 130 obtains the communication information.
[0155] Next, the simplified abnormality determination unit 130 extracts header information from the communication information (S220). The header information is, for example, the aforementioned "timestamp," "src_ip," "dst_ip," and / or "protocol" information.
[0156] Next, the simplified abnormality determination unit 130 compares the header information with predefined information ( S230 ).
[0157] Thereby, the simplified abnormality determination unit 130 determines whether or not there is an abnormality in the header information ( S240 ).
[0158] When the simplified abnormality determination unit 130 determines that the header information has an abnormality (S240: Yes), the process proceeds to Figure 10 Step S130 (S280) shown.
[0159] On the other hand, when the simple abnormality determination unit 130 determines that there is no abnormality in the header information ( S240 : No), it obtains the simple learning result from the simple learning unit 120 or the learning result storage unit 190 ( S250 ).
[0160] Next, the simple abnormality determination unit 130 compares the header information with the simple learning result ( S260 ).
[0161] Thereby, the simplified abnormality determination unit 130 determines whether or not there is an abnormality in the header information ( S270 ).
[0162] When the simplified abnormality determination unit 130 determines that the header information has an abnormality (S270: Yes), the process proceeds to Figure 10 Step S130 (S280) shown.
[0163] On the other hand, if the simplified abnormality determination unit 130 determines that there is no abnormality in the header information (S270: No), the process ends. For example, the simplified abnormality determination unit 130 returns the process to Figure 10 Step S110 shown (that is, step S210).
[0164] Figure 12 It is a flowchart showing the processing process of the IoT device 400 involved in the embodiment. Figure 12 At the beginning of the flowchart, the IoT device is in normal mode for explanation.
[0165] First, the IoT device 400 determines whether a flag has been received (S310). For example, the IoT device 400 determines whether a warning notification message has been received. Furthermore, if the warning notification message has been received, the IoT device 400 determines whether the warning notification message includes a flag (e.g., whether "warning_flag" is "True").
[0166] When the IoT device 400 determines that the flag has not been received ( S310 : NO), the process returns to step S310 .
[0167] When the IoT device 400 determines that the flag has been received ( S310 : Yes), it transitions to the alert mode ( S320 ).
[0168] Next, the IoT device 400 determines whether a control instruction to cause the device to execute control is received from a device that has transmitted or received communication information indicating that an abnormality has been detected by the simple detection process, for example, included in the warning notification information.
[0169] When the IoT device 400 determines that a control instruction has been received ( S330 : YES), the IoT device 400 extracts a control log indicating that a process based on the control instruction has been executed from a storage device included in the IoT device 400 ( S340 ).
[0170] Next, the IoT device 400 transmits the extracted control log to the GW apparatus 100 ( S350 ).
[0171] After step S350, or if it is determined that no control instruction has been received (S330: No), a determination is made as to whether the conditions for canceling the alert mode (i.e., the conditions for transitioning to normal mode), i.e., the cancellation conditions, have been met (S360). For example, the IoT device 400 determines whether the current time has exceeded the time indicated by the "cancellation_condition" field included in the alert notification information. The IoT device 400 may also include a timekeeping unit such as an RTC (Real Time Clock) for measuring time.
[0172] When the IoT device 400 determines that the release condition is satisfied ( S360 : YES), it releases the alert mode and transitions to the normal mode ( S370 ), and returns the process to step S310 .
[0173] On the other hand, when the IoT device 400 determines that the release condition is not satisfied ( S360 : NO), the process returns to step S330 .
[0174] Figure 13 This is a flowchart showing a detailed processing procedure of the detection process according to the embodiment.
[0175] Specifically, Figure 13 Yes Figure 10 Detailed flowchart of step S160 and step S170 is shown.
[0176] First, the detailed abnormality determination unit 170 determines whether a control log has been received ( S410 ). Specifically, the detailed abnormality determination unit 170 determines whether the log receiving unit 150 has received a control log of a device from which the command transmission unit 140 has transmitted the alert transmission information.
[0177] When the detailed abnormality determination unit 170 determines that the control log has not been received (S410: No), the process proceeds to Figure 10 Step S200 (S460) shown.
[0178] On the other hand, when the detailed abnormality determination unit 170 determines that the control log has been received ( S410 : Yes), it acquires the detailed learning result from the detailed learning unit 160 or the learning result storage unit 190 ( S420 ).
[0179] Next, the detailed abnormality determination unit 170 compares the control log with the detailed learning result ( S430 ).
[0180] Thereby, the detailed abnormality determination unit 170 determines whether or not there is an abnormality in the control log ( S440 ).
[0181] When the detailed abnormality determination unit 170 determines that the control log has an abnormality (S440: Yes), the process proceeds to Figure 10 Step S180 (S450) shown.
[0182] On the other hand, when the detailed abnormality determination unit 170 determines that there is no abnormality in the control log (S440: No), the process returns to Figure 10 Step S200 (S460) shown.
[0183] [summary]
[0184] Figure 14 It is a sequence diagram showing the processing procedure of the communication system 10 according to the embodiment.
[0185] First, it is assumed that the IoT device 410 transmits first control information to the IoT device 400 ( S510 ). The first control information is, for example, communication information transmitted and received in communication between a plurality of devices on the network 600 .
[0186] The IoT device 400 receives the first control information transmitted from the IoT device 410 (S520). For example, the IoT device 400 performs a process based on the received first control information.
[0187] Furthermore, the GW device 100 receives the first control information transmitted from the IoT device 410 to the IoT device 400 (S530). Specifically, the GW device 100 intercepts the first control information flowing through the network 600, for example, to obtain the first control information.
[0188] Next, the GW device 100 detects an anomaly in the received first control information ( S540 ). The GW device 100 then determines whether the received first control information has an anomaly ( S550 ). By executing steps S530 to S550 , the GW device 100 detects an anomaly in the first control information flowing through the network 600 .
[0189] When the GW device 100 determines that the received first control information has no abnormality ( S550 : No), it intercepts new first control information flowing through the network 600 to obtain the first control information and detects abnormality in the obtained first control information.
[0190] On the other hand, if the GW device 100 determines that the received first control information contains an anomaly, that is, if an anomaly is detected in the received first control information (S550: Yes), it sends a first instruction to multiple devices to cause the devices to transmit second control information indicating the control content executed by the devices (S560). In this example, the first instruction is sent to IoT device 400 and IoT device 410. The first instruction is, for example, a flag included in the alert notification information. As a result, the GW device 100 causes IoT device 400 and IoT device 410 to transmit second control information. The second control information is, for example, a control log such as a control value.
[0191] The IoT device 410 receives the first instruction ( S570 ).
[0192] Likewise, the IoT device 400 receives the first instruction ( S580 ).
[0193] The IoT device 400 is a device that has received the second control information, and therefore transmits the second control information to the GW apparatus 100 ( S590 ).
[0194] Furthermore, the IoT device 410 , which is the device that has transmitted the first control information, may also transmit the second control information to the GW apparatus 100 .
[0195] The GW device 100 receives the second control information from the IoT device 400 ( S600 ).
[0196] Next, the GW device 100 detects an abnormality in the received second control information ( S610 ), and thereby determines whether the received second control information has an abnormality ( S620 ).
[0197] As described above, when an abnormality is detected in step S550, the GW apparatus 100 transmits a first instruction to a corresponding device among the plurality of devices, causing the device to transmit second control information indicating the content of the control executed by the device, and detects an abnormality in the received second control information. For example, if the GW apparatus 100 determines that the first control information has an abnormality, it obtains the second control information and determines whether the obtained second control information has an abnormality.
[0198] If the GW device 100 determines that the received second control information is not abnormal (S620: No), it detects an abnormality in the newly received second control information. Alternatively, if the alert mode release condition is satisfied, the GW device 100 intercepts new first control information flowing through the network 600 to obtain the first control information and detects an abnormality in the obtained first control information.
[0199] On the other hand, when the GW device 100 determines that the received first control information has an abnormality, that is, when an abnormality is detected in the received second control information (S620: YES), the GW device 100 notifies the user, for example, via a smartphone, a display device such as a monitor, or an audio device such as a speaker that outputs sound, that an abnormality has occurred within the network 600 (S630). Thus, when the GW device 100 determines that the second control information has an abnormality, for example, it determines that an abnormality has occurred in the network 600 (specifically, a device that sent or received the first control information determined to have an abnormality, or a device that sent the second control information determined to have an abnormality), and notifies the user of the abnormality.
[0200] [Effects, etc.]
[0201] Hereinafter, technologies obtainable based on the disclosure of this specification will be exemplified, and effects and the like obtained based on the exemplified technologies will be described.
[0202] Technology 1 is an anomaly detection method, which is an anomaly detection method performed by an anomaly detection device that can communicate with multiple devices that can communicate with each other via a predetermined network, including: a first detection step (for example, S530 to S550) of detecting an anomaly in first control information flowing through a predetermined network; and when an anomaly is detected in the first detection step (for example, S550: yes), a first instruction is sent to multiple devices to cause the devices to send second control information indicating the control content executed by the devices, and a second detection step (for example, S560 to S620) of detecting an anomaly in the received second control information.
[0203] The abnormality detection device is, for example, the GW device 100. The predetermined network is, for example, the network 600. The plurality of devices are, for example, IoT devices 400 and 410 (specifically, the smart speaker 300, PC 310, smartphone 320, refrigerator 330, air conditioner 340, and smart key 350). The first detection step is performed by, for example, a first detection unit such as a processor. The first detection unit is, for example, a simple abnormality determination unit 130. In addition, the second detection step is performed by, for example, a second detection unit such as a processor. The second detection unit is, for example, the instruction transmission unit 140, the log receiving unit 150, and the detailed abnormality determination unit 170.
[0204] For example, if control logs and other information are continuously received from each device on a predetermined network and anomalies are detected, anomalies within the predetermined network can be easily and reliably detected. However, detecting anomalies with this method requires significant resources, such as processor power and memory capacity. For example, if home appliances communicate with each other using an indoor network, communications between them are considered to be confined to the indoor network. Therefore, early detection of network attacks such as unauthorized control within the indoor network requires devices connected to the indoor network. However, detecting anomalies such as these attacks within the indoor network requires performing anomaly detection processes such as evaluating the appropriateness of all communications within the indoor network, which may result in insufficient resources. Furthermore, even if communications between home appliances are intercepted, since some of the information in the communications is considered encrypted, devices other than the communicating appliances are unlikely to be able to understand the content of the communications. Furthermore, decrypting all encrypted communications also raises concerns about insufficient resources.
[0205] Therefore, in the anomaly detection method involved in technology 1, first, a first control information such as communication information sent and received between multiple devices in a predetermined network is received (intercepted), and the readable information contained in the first information, such as unencrypted information, is used to detect anomalies. Assuming that an anomaly is detected, that is, when information such as an assumed anomaly is detected, a second control information such as a control log is received from the device, and the second control information is used to detect in detail whether an anomaly has occurred. In this way, when it is believed that no anomaly has occurred, the anomaly is detected with a relatively small amount of information, and when an anomaly is detected in this way, the anomaly is further detected with a relatively large amount of information. That is, this anomaly detection method performs a simple detection of the IP level as a first-order filtering, and when an anomaly is detected in this way, a detailed secondary detection such as a careful inspection of the log content is performed. For example, in this anomaly detection method, a command is sent to send log information such as control instructions from a device related to the device in which the anomaly was detected in the simple detection, and a detailed secondary detection is performed based on the log information.
[0206] This makes it possible to detect anomalies with high accuracy while reducing the amount of processing required to detect anomalies in the network.
[0207] Technology 2 is an abnormality detection method according to Technology 1. In the second detection step, when an abnormality is detected in the first detection step, a first indication is sent to the first device among multiple devices that receives the first control information that the abnormality is detected in the first detection step, and the second device that sends the first control information that the abnormality is detected in the first detection step.
[0208] According to this, the control content of the device considered to be particularly related to the detected abnormality is used for the detection of the abnormality in the second detection step. Therefore, it is possible to appropriately detect the abnormality in the predetermined network.
[0209] Technique 3 is the abnormality detection method according to Technique 2, wherein in the second detection step, a second instruction for causing the first device and the second device to stop transmitting the second control information is sent to each of the first device and the second device.
[0210] The second instruction is, for example, a release instruction included in the alert notification information.
[0211] This can prevent the slave device from unnecessarily transmitting the second control information, for example, when the detected abnormality is resolved.
[0212] Technique 4 is the abnormality detection method according to Technique 3, wherein the second instruction includes time information indicating a time at which transmission of the second control information is stopped.
[0213] For example, if an abnormality is detected in the first detection step but not in the second detection step, there is a high probability that no particularly problematic abnormality has occurred in the multiple devices. In this case, even if the second control information is repeatedly received from each device and abnormality detection is performed for a long period of time, there is a high probability that no abnormality will be detected. Therefore, if no abnormality is detected within the predetermined time, a second instruction to stop the transmission of the second control information is sent in the second detection step. This simple process can prevent the unnecessary transmission of the second control information from the device.
[0214] Technique 5 is the abnormality detection method according to any one of Techniques 1 to 4, further comprising a notification step (for example, S630 ) of notifying the abnormality when the abnormality is detected in the second detection step.
[0215] The notification step is executed by a notification unit such as a processor, for example. The notification unit is, for example, the output unit 180 .
[0216] This allows the user to easily notice abnormalities.
[0217] Technique 6 is the abnormality detection method according to any one of Techniques 1 to 5, wherein in the first detection step, abnormality of first information included in the first control information is detected, and the amount of information in the second control information is larger than that in the first information.
[0218] The first information is, for example, header information included in communication information.
[0219] This allows for anomaly detection using a relatively small amount of information when no anomaly is considered to have occurred, and further anomaly detection using a relatively large amount of information when an anomaly is detected. This allows for anomaly detection in the network without requiring all information from multiple devices to be used for anomaly detection. This reduces the amount of processing required to detect anomalies in the network, while also enabling more accurate anomaly detection.
[0220] Technique 7 is the abnormality detection method according to Technique 6, wherein the first information included in the first control information is not encrypted.
[0221] This makes it possible to detect abnormality in the first detection step without using information such as an encryption key.
[0222] Technique 8 is the abnormality detection method according to Technique 6 or 7, wherein the first control information includes the encrypted second information, and the second control information includes the unencrypted second information.
[0223] That is, the first information is, for example, unencrypted information such as an IP address included in the communication information. On the other hand, the second information is, for example, information indicating a control value for controlling a device included in the communication information.
[0224] Information used to control devices, such as control values, is typically transmitted and received encrypted. Furthermore, it's believed that encrypted information is often important. Therefore, when detecting an anomaly in the second detection step, this second information, which is likely to be important, is used to detect the anomaly. This allows for more accurate anomaly detection.
[0225] Technology 9 is an anomaly detection device that is capable of communicating with multiple devices that can communicate with each other via a predetermined network, and comprises: a first detection unit that detects an anomaly in first control information flowing through the predetermined network; and a second detection unit that, when an anomaly is detected by the first detection unit, sends a first instruction to multiple devices to cause the devices to send second control information indicating the control content executed by the devices, and detects an anomaly in the received second control information.
[0226] This achieves the same effect as the abnormality detection method according to one technical solution of the present disclosure.
[0227] Technique 10 is a program for causing a computer to execute the abnormality detection method according to any one of Techniques 1 to 8.
[0228] This achieves the same effect as the abnormality detection method according to one technical solution of the present disclosure.
[0229] (Other embodiments)
[0230] As mentioned above, although embodiment was described, this disclosure is not limited to the said embodiment.
[0231] For example, in the above-described embodiment, the GW device 100 functions as an abnormality detection device, but any device in the communication system 10 may perform abnormality detection. Furthermore, for example, the first detection unit and the second detection unit may be configured in different devices. Furthermore, for example, the first detection unit may be configured in a device within a local area network, such as a residence, while the second detection unit may be configured in a server, etc., that can communicate with the devices within the local area network via the Internet, etc.
[0232] Alternatively, for example, machine learning may be performed by a device other than the abnormality detection device, and the simplified learning results and detailed learning results may be pre-stored in the learning result storage unit 190. In this case, the abnormality detection device may not include the simplified learning unit 120 and the detailed learning unit 160.
[0233] In addition, the communication system 10 may or may not include the server 500 .
[0234] Furthermore, for example, the abnormality detection device described in the above-mentioned embodiment may be realized as a single device including all the components, or may be realized by distributing each function among a plurality of devices and making the plurality of devices cooperate with each other.
[0235] Furthermore, in the above-described embodiment, the processing performed by a specific processing unit may be performed by another processing unit. Furthermore, the order of multiple processing may be changed, and multiple processing may be performed in parallel.
[0236] In the above embodiments, each component may be implemented by executing a software program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU or a processor reading and executing a software program recorded on a recording medium such as a hard disk or a semiconductor memory.
[0237] In addition, each component can also be implemented by hardware. For example, each component can also be a circuit (or integrated circuit). These circuits can constitute a circuit as a whole, or they can be different circuits. In addition, these circuits can be general circuits or dedicated circuits.
[0238] Furthermore, the overall or specific technical solutions of the present disclosure may also be implemented by a device, system, method, integrated circuit, computer program, or non-transitory recording medium such as a computer-readable CD-ROM. Furthermore, the overall or specific technical solutions of the present disclosure may also be implemented by any combination of devices, systems, methods, integrated circuits, computer programs, and recording media.
[0239] Furthermore, the present disclosure also includes forms obtained by applying various modifications that can be conceived by those skilled in the art to the embodiments, or forms achieved by arbitrarily combining the components and functions in the embodiments without departing from the gist of the present disclosure.
[0240] Industrial availability
[0241] The present disclosure is useful for IoT devices.
[0242] Description of Reference Numerals
[0243] 10: Communication System
[0244] 100: GW device
[0245] 110: Communication receiving unit
[0246] 120: Simple Learning Department
[0247] 130: Simple Abnormality Judgment Unit
[0248] 140: Command Transmission Department
[0249] 150: Log receiving unit
[0250] 160: Detailed Study Department
[0251] 170: Detailed abnormality determination unit
[0252] 180: Output
[0253] 190: Learning result storage unit
[0254] 200: Pre-defined information storage unit
[0255] 300: Smart speakers
[0256] 310: PC
[0257] 320: Smartphone
[0258] 330: Refrigerator
[0259] 340: Air conditioning equipment
[0260] 350: Smart Key
[0261] 400, 410: IoT devices
[0262] 500: Server
[0263] 600: Network
Claims
1. An anomaly detection method, performed by an anomaly detection apparatus capable of communicating with a plurality of devices capable of communicating with each other via a predetermined network, comprising: a first detection step of detecting an abnormality in first control information flowing through the predetermined network; and The second detection step is to send a first instruction to the plurality of devices to cause the devices to send second control information indicating the control content executed by the devices when an abnormality is detected in the first detection step, and detect an abnormality in the received second control information.
2. The anomaly detection method according to claim 1, In the second detection step, when an abnormality is detected in the first detection step, the first indication is sent respectively to the first device among the multiple devices that receives the first control information that the abnormality is detected in the first detection step, and the second device that sends the first control information that the abnormality is detected in the first detection step.
3. The anomaly detection method according to claim 2, In the second detection step, a second instruction for causing the first device and the second device to stop transmitting the second control information is sent to each of the first device and the second device.
4. The anomaly detection method according to claim 3, The second instruction includes time information indicating a time at which transmission of the second control information is stopped.
5. The anomaly detection method according to claim 1, The method further includes a notification step of notifying the abnormality when abnormality is detected in the second detection step.
6. The anomaly detection method according to claim 1, In the first detection step, an abnormality of the first information included in the first control information is detected, The amount of information of the second control information is larger than that of the first information.
7. The anomaly detection method according to claim 6, The first information included in the first control information is not encrypted.
8. The anomaly detection method according to claim 6, The first control information includes the encrypted second information, The second control information includes the unencrypted second information.
9. An anomaly detection device capable of communicating with a plurality of devices capable of communicating with each other via a predetermined network, comprising: a first detection unit configured to detect an abnormality in first control information flowing through the predetermined network; and The second detector, when the first detector detects an abnormality, transmits a first instruction to the plurality of devices to cause the devices to transmit second control information indicating control content executed by the devices, and detects an abnormality in the received second control information. 10 . A program for causing a computer to execute the abnormality detection method according to claim 1 .
Citation Information
Patent Citations
Method and system for detecting event of vehicle cyber-attack
JP2019145081A