Vehicle safety analysis system, vehicle safety analysis method, and program

By introducing analytical judgment information into the vehicle safety analysis system and selectively analyzing sensor log data, the problem of high resource consumption in existing technologies is solved, and efficient resource reduction is achieved in vehicles without onboard safety devices.

CN122122585APending Publication Date: 2026-05-29NTT SECURITY (JAPAN) KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NTT SECURITY (JAPAN) KK
Filing Date
2024-10-03
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, vehicle safety analysis systems require a large amount of resources to analyze sensor log data, resulting in high costs and making it difficult to effectively reduce resource consumption in vehicles without onboard safety devices.

Method used

By introducing analysis and judgment information into the SOC server, the required sensor log data can be selectively analyzed. By utilizing the combination of the acquisition unit, analysis unit, and output unit, only the log data determined to require analysis is processed.

Benefits of technology

It effectively reduces the resources required for sensor log data analysis and processing, lowers the system's computing and storage requirements, and is suitable for vehicles without onboard safety devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122585A_ABST
    Figure CN122122585A_ABST
Patent Text Reader

Abstract

A vehicle safety analysis system of the present application has: an acquisition unit that acquires sensor log data related to an in-vehicle device mounted on a vehicle; an analysis unit that selectively analyzes sensor log data that needs to be analyzed among the sensor log data acquired by the acquisition unit, based on analysis determination information corresponding to the vehicle; and an output unit that outputs the analysis result of the analysis unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a vehicle safety analysis system, a vehicle safety analysis method, and a program. Background Technology

[0002] In order to detect cyberattacks against automobiles and other vehicles, there exists a vehicle security analysis system that acquires and analyzes sensor log data related to the onboard equipment installed in the vehicle.

[0003] In addition, a technique is known in which log information of a given device associated with attack information representing a network attack on the given device is extracted from the vehicle-mounted safety device of a vehicle equipped with the given device, and the extracted log information is sent to an attack countermeasure device (for example, see Patent Document 1).

[0004] <Prior art documents> <Patent Documents> Patent Document 1: Japanese Patent Application Publication No. 2022-089097 Summary of the Invention <Problem to be solved by this invention> In vehicle safety analysis systems that acquire and analyze sensor log data related to onboard devices, the high cost of processing this data is a significant issue. Specifically, the substantial resources required for analyzing the acquired sensor log data contribute to the high cost.

[0005] According to the technology disclosed in Patent Document 1, it is possible to reduce the sensor log data sent by the vehicle-mounted security device to the attack countermeasure device. However, this method cannot solve the aforementioned problem when the vehicle being analyzed does not have the vehicle-mounted security device.

[0006] Alternatively, the technology disclosed in Patent Document 1 can be implemented on the vehicle security analysis device side. However, in this case, the vehicle security analysis device must manage attack information on the on-board devices of multiple vehicles and sensor log information related to the on-board devices.

[0007] In the prior art, in vehicle safety analysis systems that acquire and analyze sensor log data related to onboard devices mounted in vehicles, it is difficult to suppress the resources required for the analysis and processing of sensor log data.

[0008] One embodiment of the present invention addresses the aforementioned issues by enabling a vehicle safety analysis system that acquires and analyzes sensor log data related to onboard devices mounted in a vehicle to easily reduce the resources required for analyzing and processing the sensor log data.

[0009] <Methods for solving problems> To address the aforementioned issues, an embodiment of the present invention provides a vehicle safety analysis system comprising: an acquisition unit that acquires sensor log data related to an onboard device mounted in a vehicle; an analysis unit that selectively analyzes sensor log data that needs to be analyzed from the sensor log data acquired by the acquisition unit based on analysis determination information corresponding to the vehicle; and an output unit that outputs the analysis results of the analysis unit.

[0010] <The Effects of the Invention> According to one embodiment of the present invention, in a vehicle safety analysis system that acquires and analyzes sensor log data related to onboard devices mounted in a vehicle, the resources required for analyzing and processing the sensor log data can be easily reduced. Attached Figure Description

[0011] Figure 1 This is a diagram illustrating a structural example of the vehicle safety analysis system according to this embodiment.

[0012] Figure 2 This is a diagram used to illustrate an example of the analysis and processing involved in this embodiment.

[0013] Figure 3 This is a diagram illustrating an example of the hardware structure of the computer involved in this embodiment.

[0014] Figure 4 This is a diagram illustrating an example of the functional structure of the SOC server according to this embodiment.

[0015] Figure 5 This is a schematic diagram illustrating an example of log data involved in this embodiment.

[0016] Figure 6 This is a schematic diagram illustrating an example of the analysis logic DB involved in this embodiment.

[0017] Figure 7A Figure (1) shows an example of the analysis and determination information involved in Embodiment 1.

[0018] Figure 7B Figure (2) shows an example of the analysis and determination information involved in Embodiment 1.

[0019] Figure 8 This is a flowchart illustrating a processing example of the SOC server involved in Embodiment 1.

[0020] Figure 9 This is a flowchart illustrating a management processing example involved in Embodiment 1.

[0021] Figure 10This is a flowchart illustrating a determination process example involved in Embodiment 1.

[0022] Figure 11 This is a flowchart illustrating the analysis and processing example involved in Example 1.

[0023] Figure 12 This is a schematic diagram illustrating an example of the analysis and determination information involved in Embodiment 2.

[0024] Figure 13 This is a flowchart illustrating a management processing example involved in Embodiment 2.

[0025] Figure 14 This is a flowchart illustrating a determination process example involved in Embodiment 2.

[0026] Figure 15 This diagram illustrates examples of other analysis and determination information and methods involved in this embodiment.

[0027] Figure 16 This is a flowchart illustrating a determination processing example involved in Embodiment 3. Detailed Implementation

[0028] Hereinafter, embodiments of the present invention (this embodiment) will be described with reference to the accompanying drawings. Furthermore, the embodiments described below are examples, and the application of the present invention is not limited to the following embodiments.

[0029] <System Architecture> Figure 1 This is a diagram illustrating a structural example of the vehicle safety analysis system according to this embodiment. The vehicle safety analysis system 1 includes, for example, a SOC (Security Operation Center) server 10 and a SIRT (Security Incident Response Team) server 40 that are able to communicate with each other via a communication network.

[0030] The SOC server (vehicle security analysis device) 10 is, for example, an information processing device with a computer architecture, or a system including multiple computers. The SOC server 10 is an example of a vehicle security analysis device that acquires and analyzes sensor log data related to the on-board devices 21a, 21b, ... installed in the vehicle 20 in order to detect network attacks (hereinafter referred to as "attacks") against vehicles such as automobiles 20. Furthermore, in the following description, "on-board device 21" will be used to refer to any of the on-board devices 21a, 21b, ...

[0031] When the SOC server 10 performs analysis and processing 11 on the acquired sensor log data (hereinafter referred to as "log data"), it sends a report related to the detected attack to the SIRT server 40, etc., if an attack on the vehicle 20 is detected.

[0032] exist Figure 1 In the example, the SOC server 10 obtains log data related to the on-board unit 21 installed in the vehicle 20 from the OEM (Original Equipment Manufacturing) server 30, which collects log data 31 from one or more vehicles 20. However, it is not limited to this; the SOC server 10 may also obtain log data related to the on-board unit 21 installed in the vehicle 20 from one or more vehicles 20 without going through the OEM server 30.

[0033] Furthermore, the SOC server 10 can obtain security information 51, for example, from an external server 50 operated by Auto-ISAC (Automotive Information Sharing and Analysis Center) via communication networks such as the Internet. This security information 51 includes, for example, various types of cybersecurity information such as network threats associated with connected vehicles and potential vulnerabilities. The SOC server 10 can detect attacks on the vehicle 20 based on the obtained log data 31 and security information 51.

[0034] In addition, the SOC server 10 may also have the function of temporarily taking action against the vehicle 20 based on the security information 51 obtained or instructions from the SIRT server 40 when an attack on the vehicle 20 is detected.

[0035] SIRT server 40 is an information processing device with a computer architecture, or a system comprising multiple computers. SIRT server 40 is, for example, a server operated by an organization (SIRT) that provides security responses to external threats to the products manufactured and sold by a vehicle manufacturer or in-vehicle device manufacturer to ensure the security of those products. SIRT is also known as PSIRT (Product Security Incident Response Team) or CSIRT (Computer Security Incident Response Team).

[0036] SIRT server 40 has the function of implementing permanent measures on vehicle 20, including the response strategy, based on reports sent by SOC server 10, such as input of response strategies determined for each manufacturer. Furthermore, SIRT server 40 may also have the function of sharing security information 51 with external server 50 and instructing SOC server 10 or vehicle 20 on provisional measures for vehicle 20 based on security information 51.

[0037] (Example of analysis and processing) Figure 2 This diagram illustrates an example of the analysis processing involved in this embodiment. For example, the SOC server 10 performs analysis processing 11 on log data 31 related to the vehicle-mounted device 21 installed in the vehicle 20, running multiple analysis logics 201.

[0038] Multiple analysis logics 201 describe each attack to be detected. For example, if an attack is detected by analysis logic B among the multiple analysis logics 201 through analysis processing 11, the SOC server 10 can determine the detected attack based on the description of analysis logic B. Preferably, the SOC server 10 generates a report 202 containing information about the detected attacks and outputs the generated report 202 to a given output destination such as the SIRT server 40.

[0039] As such, vehicle safety analysis system 1 faces the problem of consuming a large amount of resources (computing resources) such as CPU (Central Processing Unit) and memory because it performs multiple analysis logics on log data that becomes the object of analysis.

[0040] To address the aforementioned issues, the technology disclosed in Patent Document 1 involves an in-vehicle security device extracting log information of a given device related to attack information indicating a network attack on that device, and sending the extracted log information to a given destination. However, this method fails to solve the problem when the vehicle being analyzed does not possess the in-vehicle security device.

[0041] Alternatively, the technology disclosed in Patent Document 1 can be executed on the SOC server 10 side. However, in this case, there is a problem that the SOC server 10 must manage attack information on the vehicle-mounted devices of multiple vehicles and sensor log information related to the vehicle-mounted devices.

[0042] In the prior art, in a vehicle safety analysis system 1 that acquires and analyzes log data related to onboard devices mounted on a vehicle, it is difficult to suppress the resources required for analyzing and processing the log data.

[0043] Therefore, the SOC server 10 according to this embodiment has the following functions: acquiring log data related to the on-board device 21 installed in the vehicle 20, and selectively analyzing the log data that needs to be analyzed from the acquired log data based on the analysis and determination information corresponding to the vehicle 20. Thus, even if the vehicle 20 being analyzed does not possess the on-board safety device disclosed in Patent Document 1, the vehicle safety analysis system 1 according to this embodiment can suppress the resources required for analysis processing of log data.

[0044] Here, the analysis and decision information is used to determine whether to analyze the acquired log data. This information may include, for example, the number of log data occurrences, the presence or absence of sensor logs suggesting an attack, the status of vehicle 20, or the presence or absence of known vulnerabilities. Specific examples of analysis and decision information will be described later.

[0045] Preferably, when the SOC server 10 obtains log data, it determines whether to analyze the obtained log data based on the analysis and judgment information and the log data. Therefore, the vehicle security analysis system 1 according to this embodiment does not need to manage attack information on the in-vehicle devices of multiple vehicles 20, or the log data of the in-vehicle devices.

[0046] Thus, according to this embodiment, in the vehicle safety analysis system 1 that acquires and analyzes log data (sensor log data) related to the on-board device 21 mounted on the vehicle 29, the resources required for log data analysis and processing can be easily reduced.

[0047] <Hardware Structure> Figure 1 The SOC server 10, OEM server 30, SIRT server 40, and external server 50 described herein, for example, have... Figure 3 The hardware structure of computer 300 is shown. Alternatively, SOC server 10, OEM server 30, SIRT server 40, and external server 50 may be composed of multiple computers 300.

[0048] Figure 3 This is a diagram illustrating an example of the hardware structure of a computer according to one embodiment. The computer 300 includes, for example, a CPU (Central Processing Unit) 301, a memory 302, a storage device 303, a network I / F (Interface) 304, an external connection I / F 305, an output device 306, an input device 307, and an internal bus 308.

[0049] CPU 301 is, for example, a processor that performs various functions by executing programs stored in storage media such as memory 302 or storage device 303. Memory 302 includes, for example, volatile RAM (Random Access Memory) used as temporary storage for CPU 301, and non-volatile ROM (Read Only Memory) used as boot programs for CPU 301. Storage device 303 is a high-capacity non-volatile storage device, such as SSD (Solid State Drive) or HDD (Hard Disk Drive). Network I / F 304 includes one or more communication interfaces for connecting computer 300 to a communication network.

[0050] External connection I / F 305 is an interface for connecting external devices to computer 300. Output device 306 is an output device (e.g., a monitor, speaker, or lamp) that outputs to the outside. Input device 307 is an input device (e.g., a keyboard, mouse, or microphone) that accepts input from the outside. Alternatively, input device 307 and output device 306 can be integrated into a single input / output device (e.g., a touch panel display). Internal bus 308 is commonly connected to the above-mentioned components and transmits, for example, address signals, data signals, and various control signals.

[0051] <Functional Structure> Next, the functional structure of the vehicle safety analysis system 1 involved in this embodiment will be described.

[0052] (Functional structure of a SOC server) Figure 4 This diagram illustrates an example of the functional structure of a SOC server according to this embodiment. For example, the SOC server 10 implements, for instance, by having one or more computers 300 included with the SOC server 10 execute a given program to perform... Figure 4 The functional structures are shown below. Figure 4 In the example, the SOC server 10 includes an acquisition unit 401, a management unit 402, a decision unit 403, an analysis unit 404, and an output unit 405. Furthermore, at least some of the above functional structures can also be implemented in hardware.

[0053] Furthermore, as an example, SOC server 10 in Figure 3The storage unit of the storage device 303, etc., stores analysis and judgment information DB (Database) 411 and analysis logic DB 412, etc. As another example, the SOC server 10 may also utilize the analysis and judgment information DB (Database) 411 or analysis logic DB 412 stored in an external storage server, cloud storage, etc.

[0054] The acquisition unit 401 performs acquisition processing to obtain log data 31 related to the on-board unit 21 installed in the vehicle 20. For example, the acquisition unit 401 obtains the log data 31 from an external server such as an OEM server 30 via a communication network. However, it is not limited to this; the acquisition unit 401 may also obtain the log data 31 from the vehicle 20 via a communication network.

[0055] Figure 5 This is a schematic diagram illustrating an example of log data involved in this embodiment. Figure 5 In the example, log data 31 includes information such as "date and time," "vehicle identification number," "sensor," "SRC," "DST," etc., as an item. "Date and time" indicates the date and time when the phenomenon causing log data 31 was detected, the date and time log data 31 was generated, or the date and time it was sent. The vehicle identification number is, for example, the VIN (Vehicle Identification Number), which identifies the vehicle 20.

[0056] “SENSOR,” “SRC,” “DST,” etc., are examples of data contained in log data 31. “SENSOR” is identification information (sensor ID, etc.) identifying the multiple onboard devices 21 or safety sensors mounted on vehicle 20. “SRC” is identification information (IP address, etc.) identifying the source of the communication that caused the generation of log data 31. “DST” is identification information (IP address, etc.) identifying the destination of the communication that caused the generation of log data 31. Here, return… Figure 4 Continuing with the explanation of the functional structure of SOC server 10.

[0057] The management unit 402 performs management processing for managing the analysis and determination information corresponding to each vehicle 20. For example, the management unit 402 updates, generates, or obtains the analysis and determination information. Preferably, the management unit 402 stores the analysis and determination information corresponding to each vehicle 20 in an analysis and determination information DB411 or similar file in a corresponding manner for management.

[0058] Furthermore, as mentioned above, the analysis determination information is used to determine whether to analyze the log data acquired by the acquisition unit 401. The analysis determination information may include, for example, various information such as the number of log data occurrences, the presence or absence of sensor logs indicating an attack, the status of the vehicle 20, or the presence or absence of known vulnerabilities.

[0059] The determination unit 403 performs a determination process based on analysis determination information to determine whether to analyze the log data 31 acquired by the acquisition unit 401. Preferably, when the acquisition unit 401 acquires the log data 31, the determination unit 403 determines whether to analyze the acquired log data 31 based on the analysis determination information and the acquired log data.

[0060] Furthermore, several specific examples of analyzing and determining information and the determination process performed by the determination unit 403 will be described later.

[0061] Based on the analysis determination information corresponding to the vehicle 20, the analysis unit 404 performs selective analysis on the log data 31 obtained by the acquisition unit 401 that needs to be analyzed. For example, based on the analysis determination information, the analysis unit 404 analyzes the log data 31 that the determination unit 403 determines should be analyzed, and does not analyze the log data 31 that the determination unit 403 determines should not be analyzed.

[0062] As an example, Analysis Department 404 uses Figure 6 The analysis logic DB412 shown analyzes the log data 31 that is determined by the determination unit 403 to be analyzed.

[0063] Figure 6 This is a schematic diagram illustrating an example of the analysis logic DB involved in this embodiment. For example... Figure 6 As shown, multiple analysis logics 201 are pre-registered in the analysis logic DB412. The analysis unit 404 analyzes the log data 31 that is the object of analysis by executing the multiple analysis logics 201 on the log data 31 that is determined by the determination unit 403 to be analyzed.

[0064] As described above, multiple analysis logics 201 are described for each attack to be detected. For example, analysis logic number 1 indicates that when the value of "SENSOR" in log data 31 is "1" and the value of "DST" is "10.0.0.1", it is an attack called "T001". Here, "T001" is identification information (attack ID, etc.) used to identify the attack.

[0065] Furthermore, the analysis logic for number 2 indicates that when the value of "SENSOR" in log data 31 is "2" and the value of "SIGNATURE" is "1", it is an attack known as "T002". Here, "SIGNATURE" is, for example, identification information (signature ID, etc.) that identifies data used to detect malware, specific communication patterns, specific files, etc.

[0066] The analysis unit 404 executes multiple analysis logics 201 on the log data 31 that the determination unit 403 determines to be analyzed. If an attack is detected, the information related to the detected attack is output as the analysis result.

[0067] Furthermore, the analysis method of the analysis unit 404 for the log data 31 described above is one example. In this embodiment, the analysis method of the analysis unit 404 for the log data 31 can also be any other arbitrary method.

[0068] The output unit 405 performs output processing, outputting the analysis results of the analysis unit 404 to a given output destination. For example, the output unit 405 sends the analysis results of the analysis unit 404 (such as report 202) to the SIRT server 40. Alternatively, report 202 may also be generated by the output unit 405 based on the analysis results of the analysis unit 404.

[0069] in addition, Figure 4 The functional architecture of the SOC server 10 shown is an example. For example, Figure 4 The functional structures of the SOC server 10 shown can be distributed across multiple devices. In this case, Figure 4 The functional structures of the SOC server 10 shown can be possessed by any device included in the vehicle safety analysis system 1.

[0070] Furthermore, if the analysis and judgment information generated or obtained by the management unit 402 is information that does not need to be retained, the SOC server 10 (or vehicle safety analysis system 1) may not have the analysis and judgment information DB411. In addition, the management unit 402 may also obtain and manage analysis and judgment information (such as security information 51) that is unrelated to log data 31 from external servers such as 50.

[0071] [Example 1] Figure 7A and Figure 7B This is a diagram illustrating an example of the analysis and determination information involved in Embodiment 1. Figure 7A This illustration shows an example of the analysis and determination information involved in Embodiment 1. For example, such as... Figure 7A As shown, the management unit 402 establishes corresponding analysis and judgment information 701 for managing each vehicle 20 in accordance with the vehicle identification number of the multiple vehicles 20. Figure 7A The example shown is a case where the analysis and judgment information 701 is a count of a given phenomenon in each vehicle 20.

[0072] Figure 7B An example of analysis and judgment information 702 is shown when a given phenomenon occurs within a given time period, as indicated by the number of occurrences in the sensor log (log data 31). For example, the management department 402 obtains data from the acquisition department 401. Figure 5 In the case of log data 31 as shown, based on the "date and time" and "vehicle identification number" contained in log data 31, the following steps are performed: Figure 7B The "Sensor Log Count" corresponding to the vehicle identification number shown in the analysis and judgment information 702 is incremented by 1.

[0073] In addition, the judgment department 403 in Figure 7B If the number of "sensor log occurrences" corresponding to the vehicle identification number shown in the analysis and judgment information 702 reaches a predetermined threshold (or exceeds the threshold), it is determined that the log data 31 acquired by the acquisition unit 401 will be analyzed.

[0074] As another example, the management unit 402 can also manage the data based on the amount of log data that will occur within a given time for each vehicle identification number. In this case, the determination unit 403 determines that the log data 31 obtained by the acquisition unit 401 should be analyzed if the amount of log data 31 corresponding to the vehicle identification number reaches a predetermined threshold (or exceeds the threshold).

[0075] <Processing Flow> Next, the processing flow of the vehicle safety analysis method involved in Example 1 will be described.

[0076] (SOC server processing) Figure 8 This is a flowchart illustrating a processing example of the SOC server involved in Embodiment 1. The processing demonstrates, for example, a process by a server with... Figure 4 A summary of the processes performed by the SOC server 10 in the shown functional structure.

[0077] In step S801, the acquisition unit 401 obtains, for example, from the OEM server 30, etc. Figure 5 Log data as shown in Figure 31.

[0078] In step S802, when the acquisition unit 401 acquires log data 31, the management unit 402 updates or generates, for example, based on the acquired log data 31. Figure 7A or Figure 7B The analysis and judgment information shown is as described. As a specific example, Management Department 402 executes... Figure 9 The management process is as shown.

[0079] Figure 9 This is a flowchart illustrating an example of the management process involved in Embodiment 1. The process is shown, for example, in... Figure 8 This is an example of a management process performed by the management department 402 in step S802.

[0080] In step S901, the management unit 402 extracts the vehicle identification number from the log data 31 obtained by the acquisition unit 401. For example, the log data 31 obtained by the acquisition unit 401 is... Figure 5 In the case of log data 31 as shown, the vehicle identification number "JP000000000000005" is extracted by the acquisition unit 401.

[0081] In step S902, the management unit 402 obtains analysis and determination information corresponding to the extracted vehicle identification number. For example, the management unit 402 obtains analysis and determination information from... Figure 7A In the analysis and judgment information shown, the analysis and judgment information "9" corresponding to the vehicle identification number "JP000000000000005" is obtained.

[0082] In step S903, the management unit 402 determines whether analysis and determination information exists. For example, if the management unit 402 has obtained analysis and determination information corresponding to the vehicle identification number, it determines that analysis and determination information exists. If analysis and determination information exists, the management unit 402 proceeds the process to step S904. On the other hand, if analysis and determination information does not exist, the management unit 402 proceeds the process to step S905.

[0083] When the process progresses to step S904, the management unit 402 updates the analysis and judgment information. For example, in Figure 7A In this context, the analysis and judgment information is assumed to be the number of times log data 31 occurs. In this case, the management department 402 will increment the analysis and judgment information "9" corresponding to the vehicle identification number "JP000000000000005" by 1 to update it to "10".

[0084] On the other hand, when the process proceeds to step S905, the management unit 402 generates new analysis and judgment information. For example, in Figure 7A In the process, if the analysis and judgment information corresponding to the vehicle identification number "JP000000000000005" has not been registered, the management department 402 determines that there is no analysis and judgment information. In this case, the management department 402 generates a new analysis and judgment information "1" indicating that the occurrence of log data 31 is 1.

[0085] In step S906, the management unit 402 stores the updated or newly generated analysis and judgment information in the analysis and judgment information DB411, etc.

[0086] In addition, in analyzing and judging information is Figure 7B In the case of analysis and judgment information as shown, the management unit 402 updates or generates new analysis and judgment information for the analysis and judgment information corresponding to the "date and time" of log data 31 in the analysis and judgment information corresponding to the vehicle identification number.

[0087] Here, return Figure 8 Continuing with the explanation of the SOC server's processing. In step S803, the determination unit 403 determines, based on the analysis determination information corresponding to the vehicle 20, whether it is necessary to analyze the log data 31 obtained by the acquisition unit 401. As a specific example, the determination unit 403 executes... Figure 10 The judgment and processing are as shown.

[0088] Figure 10 This is a flowchart illustrating an example of the determination process involved in Embodiment 1. This process demonstrates, for example, in... Figure 8 An example of the determination process performed by the determination unit 403 in step S803.

[0089] In step S1001, the determination unit 403 extracts the vehicle identification number from the log data 31 obtained by the acquisition unit 401. Alternatively, the determination unit 403 can obtain the log data 31 obtained by the acquisition unit 401 from the management unit 402, or it can obtain the data from the acquisition unit 401 itself.

[0090] In step S1002, the determination unit 403 obtains analysis and determination information corresponding to the extracted vehicle identification number. For example, the determination unit 403 obtains analysis and determination information from... Figure 7A From the analysis and determination information shown, the analysis and determination information corresponding to the vehicle identification number is obtained. Furthermore, here, let's assume that the obtained analysis and determination information represents the number of times log data occurs in the vehicle 20 corresponding to the vehicle identification number.

[0091] In step S1003, the determination unit 403 determines whether the number of occurrences of the log data represented by the acquired analysis determination information is above a predetermined threshold. Here, the threshold is a preset value for the number of occurrences of log data that is determined to require analysis of log data 31.

[0092] If the number of occurrences of log data 31 is above a threshold, the determination unit 403 transfers the processing to step S1004. On the other hand, if the number of occurrences of log data 31 is less than the threshold, the determination unit 403 transfers the processing to step S1005.

[0093] When the process moves to step S1004, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is required. On the other hand, when the process moves to step S1005, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is not required.

[0094] Here, let's return again. Figure 8 The explanation of the SOC server processing continues. In step S804, if the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is required, the processing moves to step S805. On the other hand, if the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is not required, the processing ends. Figure 8 The processing.

[0095] When the process proceeds to step S805, the analysis unit 404 performs analysis processing on the log data 31 acquired by the acquisition unit 401. As a specific example, the analysis unit 404 performs... Figure 11 The analysis and processing are shown below.

[0096] Figure 11 This is a flowchart illustrating an example of the analysis process involved in Embodiment 1. The process is shown, for example, in... Figure 8 An example of the analysis process performed by the analysis unit 404 in step S805.

[0097] In step S1101, the analysis unit 404 extracts the vehicle identification number from the log data obtained by the acquisition unit 401.

[0098] In step S1102, the analysis unit 404, for example, from... Figure 6 The analysis logic DB412 shown obtains the analysis logic group (multiple analysis logics 201).

[0099] In step S1103, the analysis unit 404 selects the unselected analysis logic from the acquired analysis logic group.

[0100] In step S1104, the analysis unit 404 determines whether there is any unselected analysis logic. For example, if the analysis unit 404 selected an unselected analysis logic in step S1103, it determines that there is unselected analysis logic. If there is unselected analysis logic, the analysis unit 404 executes the selected analysis logic. On the other hand, if there is no unselected analysis logic, the analysis unit 404 transfers the processing to step S1106.

[0101] When the process proceeds to step S1105, the analysis unit 404 executes the selected analysis logic on the log data 31 and returns the processing to step S1103. Through the processing of steps S1103 to S1105, the analysis unit 404, for example, executes all the analysis logic contained in the acquired analysis logic group on the log data 31 acquired by the acquisition unit 401.

[0102] When the process proceeds to step S1106, the analysis unit 404 outputs the vehicle identification number extracted from the log data 31 obtained by the acquisition unit 401, and the analysis results obtained through steps S1103 to S1105, to the output unit. These analysis results may include, for example, information (attack ID, etc.) used to determine attacks detected by the analysis logic group.

[0103] Here, let's return again. Figure 8 The processing of the SOC server will be further explained. In step S806, the output unit 405 outputs the analysis results of the analysis unit 404 to a given output destination. For example, the output unit 405 generates a report 202 containing information about the attack detected by the analysis processing 11 of the analysis unit 404 and the vehicle identification number of the vehicle 20 that detected the attack, and sends the generated report 202 to the SIRT server 40. Alternatively, the generation of report 202 can also be as follows: Figure 2 As explained, the analysis is performed by the analysis process 11 of the analysis unit 404.

[0104] In Example 1, since the log data 31 of vehicles 20 whose log data 31 occurs less than a threshold is not analyzed, the consumption of computing resources caused by the analysis processing 11 can be easily suppressed.

[0105] [Example 2] Figure 12 This is a schematic diagram illustrating an example of the analysis and determination information involved in Embodiment 2. The management unit 402 involved in Embodiment 2 is as follows: Figure 12 As shown, the information indicating the presence or absence of log data 31 that suggests an attack is managed by establishing a correspondence between the information 1201 and the vehicle identification numbers of multiple vehicles 20.

[0106] exist Figure 12 In the analysis judgment information 1201, "FALSE" indicates that no log data 31 strongly suggesting an attack was detected in the vehicle 20 corresponding to the vehicle identification number. On the other hand, "TRUE" in the analysis judgment information 1201 indicates that log data 31 strongly suggesting an attack was detected in the vehicle 20 corresponding to the vehicle identification number.

[0107] <Processing Flow> Next, the processing flow of the vehicle safety analysis method involved in Example 2 will be described. Furthermore, the processing of the SOC server involved in Example 2 can be compared with the reference... Figure 8 The processing of the SOC server described in Example 1 is the same. Furthermore, the analysis processing described in Example 2 can be the same as that described in the reference... Figure 11 The analytical processing involved in Example 1 is the same as that described above.

[0108] (Management Processing) Figure 13 This is a flowchart illustrating an example of the management process involved in Embodiment 2. The process is shown, for example, in... Figure 8 This is an example of the management process performed by the management department 402 in step S802. Furthermore, references are omitted here. Figure 9 The following is a detailed description of the same management process as that described in Example 1.

[0109] In step S1301, the management unit 402 extracts the vehicle identification number from the log data 31 obtained by the acquisition unit 401.

[0110] In step S1302, the management unit 402 obtains analysis and determination information corresponding to the extracted vehicle identification number. For example, the management unit 402 obtains analysis and determination information from... Figure 12 In the analysis and judgment information 1201 shown, the analysis and judgment information corresponding to the extracted vehicle identification number is obtained.

[0111] In step S1303, the management unit 402 determines whether there is any information in the log data 31 or the analysis and judgment information obtained by the acquisition unit 401 that suggests an attack on the vehicle 20. For example, if the log data 31 obtained by the acquisition unit 401 contains information suggesting an attack on the vehicle 20, and / or if the obtained analysis and judgment information is "TRUE", the management unit 402 determines that there is information suggesting an attack. On the other hand, if the log data 31 obtained by the acquisition unit 401 does not contain information suggesting an attack on the vehicle 20, and the obtained analysis and judgment information is "FALSE", the management unit 402 determines that there is no information suggesting an attack.

[0112] If information suggesting an attack is present, the management unit 402 transfers the process to step S1304. On the other hand, if information suggesting an attack is not present, the management unit 402 transfers the process to step S1305.

[0113] When the process moves to step S1304, the management unit 402 will display information indicating that there is currently information suggesting an attack on vehicle 20 (in...). Figure 12In the example, “TRUE” is stored in the analysis and judgment information 1201 corresponding to the vehicle identification number of the vehicle 20.

[0114] On the other hand, when the process moves to step S1305, the management unit 402 will indicate that there is currently no information suggesting an attack on vehicle 20 (in...). Figure 12 In the example, "FALSE" is stored in the analysis and determination information 1201 corresponding to the vehicle identification number of the vehicle 20. Alternatively, the management unit 402 may omit the processing in step S1305 and maintain the analysis and determination information corresponding to the vehicle identification number of the vehicle 20.

[0115] pass Figure 13 For example, the management department 402 can handle the processing. Figure 12 The analysis and judgment information shown is stored in the analysis and judgment information DB411 and managed accordingly.

[0116] (Judgment and processing) Figure 14 This is a flowchart illustrating an example of the determination process involved in Embodiment 2. The process is shown, for example, in... Figure 8 This is an example of the determination process performed by the determination unit 403 in step S803. Furthermore, references are omitted here. Figure 10 The following is a detailed description of the same processing content as the determination process involved in Example 1.

[0117] In step S1401, the determination unit 403 extracts the vehicle identification number from the log data 31 obtained by the acquisition unit 401.

[0118] In step S1402, the determination unit 403 obtains analysis and determination information corresponding to the extracted vehicle identification number. For example, the determination unit 403 obtains analysis and determination information from... Figure 12 In the analysis and judgment information 1201 shown, the analysis and judgment information corresponding to the extracted vehicle identification number is obtained.

[0119] In step S1403, the determination unit 403 determines whether the obtained analysis determination information is "TRUE". If the obtained analysis determination information is "TRUE", the determination unit 403 transfers the processing to step S1404. On the other hand, if the obtained analysis determination information is not "TRUE" (is "FALSE"), the determination unit 403 transfers the processing to step S1405.

[0120] When the process moves to step S1404, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is required. On the other hand, when the process moves to step S1405, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is not required.

[0121] Thus, in Embodiment 2, since the analysis of the log data 31 of vehicle 20, for which no information indicating an attack has been detected so far, is not performed, the consumption of computing resources caused by the analysis process 11 can be easily suppressed.

[0122] (Examples of other analytical and judgment information) The analysis and judgment information described in Examples 1 and 2 is one example. The vehicle safety analysis system 1 can also utilize, for example, the analysis and judgment information described in Examples 1. Figure 15 Various other analysis and judgment information, as shown, are used to determine whether to analyze the log data 31 obtained by the acquisition unit 401.

[0123] Figure 15 This diagram illustrates examples of other analysis and determination information involved in this embodiment. As an example, the vehicle safety analysis system 1... Figure 15 As shown, the amount of sensor log data per unit time for each vehicle can also be used as information for analysis and judgment. In this case, Management Department 402 replaces... Figure 7B The analysis and determination unit 403 calculates the "number of sensor log occurrences" as shown, and manages the "data volume of sensor logs" in a corresponding manner with the vehicle identification information of each vehicle 20. Furthermore, if the "data volume of sensor logs" in the analysis and determination information is above a threshold, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is necessary. Conversely, if the "data volume of sensor logs" in the analysis and determination information is below the threshold, the determination unit 403 determines that analysis of the log data 31 obtained by the acquisition unit 401 is unnecessary. Additionally, the threshold can be an absolute value or a statistical measure (variance, etc.).

[0124] As another example, vehicle safety analysis system 1 Figure 15 As shown, "whether the vehicle is in operation" can also be used as the analysis and determination information. In this case, the management unit 402 can obtain information indicating whether the vehicle 20 is in operation from an external vehicle management system that manages the status of the vehicle 20, or from the vehicle 20 itself. Alternatively, the management unit 402 can also obtain information indicating whether the vehicle 20 is in operation from the log data 31. If the vehicle 20 is in operation, the determination unit 403 determines that it is necessary to obtain and analyze the log data 31 obtained by the unit 401. If the vehicle 20 is not in operation, the determination unit 403 determines that it is not necessary to obtain and analyze the log data 31 obtained by the unit 401. This is based on the premise that even if the vehicle 20 is attacked while in operation, the impact is not related to the driver's life and is therefore acceptable.

[0125] As another example, such as Figure 15As shown, the vehicle safety analysis system 1 can also use "vehicle location" as analysis and judgment information. In this case, the management unit 402 can obtain location information indicating the location of the vehicle 20 from an external vehicle management system that manages the status of the vehicle 20, or from the vehicle 20 itself. Alternatively, the management unit 402 can also obtain location information indicating the location of the vehicle 20 from log data 31.

[0126] For example, the determination unit 403 may determine that the analysis of the log data 31 obtained by the acquisition unit 401 is unnecessary when the vehicle 20 is located at the vehicle 20's production or maintenance site. This is based on the premise that even if the vehicle 20 is attacked while not in operation, the impact is unrelated to the driver's life and is therefore acceptable. Furthermore, it is conceivable that various log data 31 that would not occur during normal use may occur during production or maintenance operations.

[0127] Alternatively, the determination unit 403 may determine that it is necessary to analyze the log data 31 obtained by the acquisition unit 401 if the vehicle 20 is in a given location (e.g., a country or region). This is based on the premise that the presence or absence of an attack is geographically specific.

[0128] As another example, such as Figure 15 As shown, the vehicle security analysis system 1 can also use "whether the vehicle is connected to the outside world" as analysis and determination information. In this case, the management unit 402 can obtain information indicating whether the vehicle 20 is connected to an external network (Internet or V2X, etc.) or an external device (diagnostic machine, etc.) from an external vehicle management system or the vehicle 20 itself, which manages the status of the vehicle 20. Alternatively, the management unit 402 can also obtain information indicating whether the vehicle 20 is connected to the outside world from log data 31. In addition, V2X stands for "Vehicle to everything," which is a general term for technologies that enable communication and mutual cooperation between the vehicle 20 and everything else (other vehicles, pedestrians, infrastructure, networks, etc.). In this case, the determination unit 403 can also determine that it is necessary to obtain the log data 31 obtained by the unit 401 for analysis if the vehicle 20 is connected to the outside world. This is based on the premise that most of the attacks on the vehicle 20 are external threats, and other threats are acceptable.

[0129] As another example, such as Figure 15 As shown, the vehicle safety analysis system 1 can also use "time period or duration" as analysis and determination information. In this case, the determination unit 403 can, for example, determine whether the analysis of the log data 31 obtained by the acquisition unit 401 is necessary (or not necessary) within a specific time period or duration. This is based on the premise that an attack on the vehicle 20 is likely to occur (or is unlikely to occur) during a specific time period or duration (such as a long holiday).

[0130] As another example, such as Figure 15 As shown, the vehicle security analysis system 1 can also use "campaign occurrence" as analysis determination information. Here, "campaign" includes, for example, information indicating that an attack has occurred targeting a specific vehicle model. In this case, the management unit 402 can obtain information indicating whether a campaign has occurred from an external server 50 or SIRT server 40, for example. Furthermore, if a campaign occurs for a vehicle model corresponding to vehicle 20, the determination unit 403 can determine that analysis of the log data 31 obtained by the determination unit 401 is required. Similarly, the vehicle security analysis system 1 can also use "vehicle model" as analysis determination information.

[0131] As another example, such as Figure 15 As shown, the vehicle security analysis system 1 can also use "owner attributes" as analysis determination information. In this case, the determination unit 403 can determine that it is necessary to analyze the log data 31 obtained by the acquisition unit 401 if the vehicle 20 is owned by an owner with specific attributes. This is based on the premise that an attack targeting the owner with specific attributes has occurred. Similarly, the vehicle security analysis system 1 can also use "driver or passenger attributes" as analysis determination information.

[0132] As another example, such as Figure 15 As shown, the vehicle safety analysis system 1 can also use the presence or absence of known vulnerabilities as analysis determination information. In this case, if the vehicle 20 has known vulnerabilities, the determination unit 403 can determine that it is necessary to analyze the log data 31 obtained by the acquisition unit 401.

[0133] As another example, such as Figure 15 As shown, the vehicle security analysis system 1 can also use "whether it is a modified vehicle" as analysis determination information. In this case, if vehicle 20 is a modified vehicle, the determination unit 403 can determine that the analysis of the log data 31 obtained by the acquisition unit 401 is unnecessary. This is based on the assumption that the success rate of attacks on vehicles 20 with structures different from the standard is low. Furthermore, modified vehicles can also be considered as objects of analysis by the vehicle security analysis system 1.

[0134] As another example, such as Figure 15 As shown, the vehicle safety analysis system 1 can also use the "version of the installed software" as analysis and determination information. In this case, when the version of the software installed in the vehicle 20 is a specific version, the determination unit 403 can determine whether or not the analysis of the log data 31 obtained by the acquisition unit 401 is required (or not required).

[0135] In addition, the vehicle safety analysis system 1 can also combine the above-mentioned multiple analysis and judgment information to determine whether it is necessary to obtain the log data 31 obtained by the unit 401 for analysis.

[0136] [Third Implementation] Figure 16 This is a flowchart illustrating an example of the determination process according to the third embodiment. The process demonstrates an example of analysis processing when the analysis determines two things: "the number of log data occurrences" and "whether the vehicle is connected to an external system."

[0137] Furthermore, the processing of the SOC server involved in Example 3 can be compared with the reference. Figure 8 The processing of the SOC server described in Example 1 is the same. Furthermore, the management processing described in Example 3 can be the same as that described in the reference. Figure 9 The management processes described in Example 1 are the same. Furthermore, the analysis processes described in Example 3 can be the same as those described in the reference... Figure 11 The analytical processing involved in Example 1 is the same as that described above.

[0138] also, Figure 16 Processing and reference for steps S1001 and S1002 Figure 10 The determination process described in Example 1 is the same, so its description is omitted here. Furthermore, detailed descriptions of processes identical to those described in Example 1 are also omitted here.

[0139] In step S1601, the determination unit 403 determines whether the number of occurrences of the log data shown in the obtained analysis determination information is above a predetermined threshold. If the number of occurrences of the log data 31 is above the threshold, the determination unit 403 transfers the processing to step S1602. On the other hand, if the number of occurrences of the log data 31 is less than the threshold, the determination unit 403 transfers the processing to step S1603.

[0140] When the process moves to step S1602, the determination unit 403 determines that it is necessary to analyze the log data 31 obtained by the acquisition unit 401.

[0141] On the other hand, when the process proceeds to step S1603, the determination unit 403 determines whether the vehicle 20 is connected to the outside (an external network or an external device). If the vehicle 20 is connected to the outside, the determination unit 403 transfers the process to step S1602. On the other hand, if the vehicle 20 is not connected to the outside, the determination unit 403 transfers the process to step S1604.

[0142] When the process moves to step S1604, the determination unit 403 determines that the analysis of the log data 31 obtained by the acquisition unit 401 is not required.

[0143] In this way, the determination unit 403 can also combine multiple analysis and determination information to determine whether it is necessary to analyze the log data 31 obtained by the acquisition unit 401.

[0144] As described above, according to this embodiment, in the vehicle safety analysis system 1 that acquires and analyzes sensor log data related to the on-board device 21 mounted on the vehicle 20, the resources required for analyzing and processing the sensor log data can be easily reduced.

[0145] <Summary of Implementation Methods> This specification discloses at least the following vehicle safety analysis systems, vehicle safety analysis methods, and procedures.

[0146] (Item 1) A vehicle safety analysis system, which has the following features: The acquisition unit acquires sensor log data related to onboard devices installed in the vehicle; The analysis unit, based on analysis and determination information corresponding to the vehicle, selectively analyzes the sensor log data that needs to be analyzed from the sensor log data acquired by the acquisition unit; and The output unit outputs the analysis results from the analysis unit.

[0147] (Item 2) The vehicle safety analysis system according to item 1 has a determination unit. When the acquisition unit acquires the sensor log data, the determination unit determines whether to analyze the sensor log data acquired by the acquisition unit based on the analysis determination information and the sensor log data.

[0148] (Item 3) According to the vehicle safety analysis system described in item 1 or item 2, wherein, The analysis and determination information includes information indicating the state of the vehicle. It has a determination unit that determines, based on the state of the vehicle, whether to analyze the sensor log data acquired by the acquisition unit.

[0149] (Item 4) The vehicle safety analysis system according to any one of items 1 to 3, wherein, The analysis and determination information includes information on the number of times the sensor log data occurred in the vehicle. If the number of occurrences does not reach the threshold, the analysis unit will not analyze the sensor log data acquired by the acquisition unit.

[0150] (Item 5) The vehicle safety analysis system according to any one of items 1 to 4, wherein, When the vehicle is not in operation, the analysis unit does not analyze the sensor log data acquired by the acquisition unit.

[0151] (Item 6) The vehicle safety analysis system according to any one of items 1 to 3, wherein, When the vehicle is connected to an external network or external device, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

[0152] (Item 7) The vehicle safety analysis system according to any one of items 1 to 3, wherein, In cases where the vehicle has known vulnerabilities, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

[0153] (Item 8) The vehicle safety analysis system according to any one of items 1 to 3, wherein, In the event of an attack targeting the same vehicle model as the vehicle in question, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

[0154] (Item 9) A vehicle safety analysis method, wherein a computer performs the following processing: Obtain and process sensor log data related to onboard devices installed in the vehicle; The analysis and processing, based on the analysis and judgment information corresponding to the vehicle, selectively analyzes the sensor log data that needs to be analyzed from the sensor log data obtained by the acquisition process; and Output processing: Output the analysis results of the analysis processing.

[0155] (Item 10) A program that causes a computer to perform the following processing: Obtain and process sensor log data related to onboard devices installed in the vehicle; The analysis and processing, based on the analysis and judgment information corresponding to the vehicle, selectively analyzes the sensor log data that needs to be analyzed from the sensor log data obtained by the acquisition process; and Output processing: Output the analysis results of the analysis processing.

[0156] The embodiments of the present invention have been described in detail above, but the present invention can be modified and applied in various ways within the scope of the spirit described in the claims.

[0157] This application claims priority to basic application No. 2023-186501 filed with the Japan Patent Office on October 31, 2023, the entire contents of which are incorporated herein by reference.

[0158] Symbol Explanation 1: Vehicle Safety Analysis System 10: SOC Server (Vehicle Safety Analysis Device) 20: Vehicles 21, 21a, 21b: Vehicle-mounted devices 31: Log data (sensor log data) 300: Computer 401: Obtaining Department 402: Management Department 403: Judgment Department 404: Analysis Department 405: Output Section 411: Analysis and Judgment Information DB 412: Analyze the logical DB 701, 702, 1201: Analysis and judgment information.

Claims

1. A vehicle safety analysis system, comprising: The acquisition unit acquires sensor log data related to onboard devices installed in the vehicle; The analysis unit selectively analyzes the sensor log data that needs to be analyzed from the sensor log data acquired by the acquisition unit, based on the analysis and determination information corresponding to the vehicle. as well as The output unit outputs the analysis results from the analysis unit.

2. The vehicle safety analysis system according to claim 1, wherein, The vehicle safety analysis system has a decision-making unit. When the acquisition unit acquires the sensor log data, the determination unit determines whether to analyze the sensor log data acquired by the acquisition unit based on the analysis determination information and the sensor log data.

3. The vehicle safety analysis system according to claim 1, wherein, The analysis and determination information includes information indicating the state of the vehicle. The vehicle safety analysis system has a determination unit that determines, based on the state of the vehicle, whether to analyze the sensor log data acquired by the acquisition unit.

4. The vehicle safety analysis system according to claim 1, wherein, The analysis and determination information includes information on the number of times the sensor log data occurred in the vehicle. If the number of occurrences does not reach the threshold, the analysis unit will not analyze the sensor log data acquired by the acquisition unit.

5. The vehicle safety analysis system according to any one of claims 1 to 4, wherein, When the vehicle is not in operation, the analysis unit does not analyze the sensor log data acquired by the acquisition unit.

6. The vehicle safety analysis system according to any one of claims 1 to 4, wherein, When the vehicle is connected to an external network or external device, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

7. The vehicle safety analysis system according to any one of claims 1 to 4, wherein, In cases where the vehicle has known vulnerabilities, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

8. The vehicle safety analysis system according to any one of claims 1 to 4, wherein, In the event of an attack targeting the same vehicle model as the vehicle in question, the analysis unit analyzes the sensor log data acquired by the acquisition unit.

9. A vehicle safety analysis method, wherein, The computer performs the following processing: Obtain and process sensor log data related to onboard devices installed in the vehicle; The analysis and processing involves selectively analyzing the sensor log data that needs to be analyzed from the sensor log data obtained by the acquisition process, based on the analysis and judgment information corresponding to the vehicle. as well as Output processing: Output the analysis results of the analysis processing.

10. A program for causing a computer to perform the following processes: Obtain and process sensor log data related to onboard devices installed in the vehicle; The analysis and processing, based on the analysis and determination information corresponding to the vehicle, selectively analyzes the sensor log data that needs to be analyzed from the sensor log data obtained by the acquisition process; and Output processing: Output the analysis results of the analysis processing.