DETECTION SYSTEM, DETECTION DEVICE, RESPONSE DEVICE AND DETECTION METHOD
The detection system improves network security by using dedicated and main transmission paths to detect anomalies and unauthorized changes through response data comparisons, ensuring network integrity.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Applications
- Current Assignee / Owner
- NAT UNIV CORP YOKOHAMA NAT UNIV
- Filing Date
- 2024-06-03
- Publication Date
- 2026-04-23
AI Technical Summary
Existing network communication technologies lack sufficient security measures to detect anomalies and unauthorized changes in network configurations, which can compromise network integrity.
A detection system comprising a detection device and a response device that transmit and receive response data generation information via dedicated and main transmission paths, allowing for the detection of anomalies based on network configuration and response data comparisons.
Enhances network security by detecting unauthorized changes and anomalies, such as unauthorized devices or rerouting paths, without disrupting primary communication pathways.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL AREA
[0001] The present disclosure relates to a detection system, a detection device, a response device and a detection method.
[0002] This application claims priority over Japanese patent application No. 2023-125266, filed on August 1, 2023, the entire contents of which are incorporated herein by reference. STATE OF THE ART
[0003] PATENT LITERATURE 1 (Japanese Patent Publication No. 2003-191804) discloses a vehicle communication system as follows. That is, the vehicle communication system is a vehicle communication system in which a plurality of electrical devices mounted or arranged on a vehicle are provided with communication means for conducting data communication via communication lines installed in the vehicle to allow the transmission and reception of data between the electrical devices. Each of the electrical devices is provided with: a plurality of communication means for communicating the same data, each using different communication lines; and selection means for selecting normal received data from a plurality of pieces or...Elements of received data, which are or were obtained through communication using the majority of communication means. One of the majority of communication means is configured to be a low-speed communication means for conducting data communication at a communication speed slower than that of the other communication means, so that the reliability of data communication via the low-speed communication means is higher than that via the other communication means. LITERATURE LIST [PATENT LITERATURE]
[0004] PATENT LITERATURE 1: Japanese Patent Disclosure Publication No. 2003-191804 SUMMARY OF THE INVENTION
[0005] A detection system of the present disclosure comprises: a responding device; and a detection device configured to detect an anomaly in a network that includes the responding device and a transmission path. The detection device transmits response data generation information, to be used in generating response data, to the responding device via a first transmission path. The responding device generates the response data based on the response data generation information received from the detection device and transmits the generated response data to the detection device via a second transmission path. The detection device detects an anomaly in the network based on reference information derived from a network configuration and the response data transmitted by the responding device.At least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network.
[0006] An aspect of the present disclosure can be realized or implemented not only as a detection system which includes such a characteristic processing unit, but also as a program to cause a computer to perform such characteristic process steps, or as an integrated semiconductor circuit which realizes or forms part or all of the detection system. BRIEF DESCRIPTION OF THE DRAWINGS [ Fig. 1] Fig. Figure 1 shows a configuration of a detection system according to a first embodiment of the present disclosure. [ Fig. 2] Fig. Figure 2 shows a configuration of a detection device in the detection system according to the first embodiment of the present disclosure. [ Fig. 3] Fig. Figure 3 shows a configuration of a response device in the detection system according to the first embodiment of the present disclosure. [ Fig. 4] Fig. Figure 4 shows a configuration of a detection system according to a modification 1 of the first embodiment of the present disclosure. [ Fig. 5] Fig. Figure 5 shows a configuration of a detection system according to a modification 2 of the first embodiment of the present disclosure. [ Fig. 6] Fig. Figure 6 shows an example of the sequence of a detection process which is carried out in the detection system according to the first embodiment of the present disclosure. [ Fig. 7] Fig. Figure 7 shows an example of the sequence of a detection process which is carried out in the detection system according to modification 1 of the first embodiment of the present disclosure. [ Fig. 8] Fig. Figure 8 shows a configuration of a detection system according to a second embodiment of the present disclosure. [ Fig. 9] Fig. Figure 9 shows a configuration of a detection device in the detection system according to the second embodiment of the present disclosure. [ Fig. 10] Fig. Figure 10 shows a configuration of a response device in the detection system according to the second embodiment of the present disclosure. [ Fig. 11] Fig. Figure 11 shows a configuration of a detection system according to a modification 3 of the second embodiment of the present disclosure. [ Fig. 12] Fig. Figure 12 shows a configuration of a response device in the detection system according to modification 3 of the second embodiment of the present disclosure. [ Fig. 13] Fig. Figure 13 shows an example of the sequence of a detection process which is carried out in the detection system according to the second embodiment of the present disclosure. [ Fig. 14] Fig. Figure 14 shows an example of the sequence of a detection process which is carried out in the detection system according to modification 3 of the second embodiment of the present disclosure. DETAILED DESCRIPTION
[0007] Currently, technologies are being developed to improve the reliability of data communication in a network. [Problems to be solved by the present disclosure]
[0008] A technology that can improve security in a network is desired in addition to the technology according to PATENT LITERATURE 1.
[0009] The present disclosure was made to solve the above problem. One objective or subject of the present disclosure is to provide a detection system, a detection device, a response device, and a detection method that can improve security in a network. [Effects of the present revelation]
[0010] According to the present disclosure, security in a network can be improved. [Description of an embodiment of the present disclosure]
[0011] First, the contents of embodiments of the present disclosure are listed and described. (1) A detection system according to an embodiment of the present disclosure comprises: a response device; and a detection device configured to detect an anomaly in a network that includes the response device and a transmission path. The detection device transmits response data generation information, which is to be used in generating response data, to the response device via a first transmission path. The response device generates the response data based on the response data generation information received from the detection device and transmits the generated response data to the detection device via a second transmission path.The detection device detects an anomaly in the network based on reference information derived from a network configuration and the response data transmitted by the responding device. At least one of the first and second transmission paths includes a primary transmission path for carrying a main signal within the network.
[0012] In this way, due to the configuration in which an anomaly in the network is detected based on the reference information, which is based on the network's configuration or structure, and the response data transmitted via the transmission path, a change in the network configuration can be detected as an anomaly in the network based on the result of a comparison between, for example, the reference information and the response data. Therefore, network security can be improved.
[0013] (2) In (1) above, the detection system can be configured or set up such that the first transmission path is the main transmission path and the second transmission path is a dedicated leased line which is used when an anomaly is detected in the network, or the second transmission path is the main transmission path and the first transmission path is a leased line which is used when an anomaly is detected in the network.
[0014] Because of this configuration, while an impact on communication using the main transmission path is suppressed, an anomaly in the network can be detected.
[0015] (3) In (2) above, the first transmission path can be the leased line, and the second transmission path can be the main transmission path.
[0016] Because of this configuration, for example, the transmission of response data generation information to a multiple response devices can be carried out flexibly using the leased line.
[0017] (4) In any of (1) to (3) above, the responding device can generate the response data, further based on unique information of the responding device, and transmit the generated response data to the detecting device via the second transmission path. The reference information can include the unique information. The detecting device can generate data based on the unique information contained in the reference information and the response data generation information transmitted to the responding device, verify the received response data against the generated data, and detect an anomaly in the network based on the result of the verification.
[0018] Due to this configuration, for example, based on the result of a check between the response data generated in the responding device and the response data generated based on the reference information in the detection device, the presence of an unauthorized device that masks or masquerades as a responding device can be detected as an anomaly in the network.
[0019] (5) In any one of (1) to (4) above, the detection device can detect an anomaly in the network based on the number of pieces or elements of the received response data.
[0020] Because of this configuration, it is possible, for example, if the number of pieces or elements of received response data is greater than the number of responding devices in the network, to determine that a rerouting path has been inserted in the network, and if the number of pieces or elements of received response data is less than the number of responding devices in the network, it is possible to determine that a blockage of a path has occurred in the network.
[0021] (6) In any one of (1) to (5) above, the detection device can detect an anomaly in the network based on a time of receipt of the received response data.
[0022] Because of this configuration, if, for example, the time of receipt of the response data differs from the time corresponding to the transmission time of the response data generation information, it is possible to determine that a rerouting path is used through which response data generated or created in another network is transmitted.
[0023] (7) In any of (1) to (6) above, when using a physical transmission line that is shared, the first transmission path, which is a logical path, and the second transmission path, which is a logical path, may be provided, and the detection device and the response device may multiplex the response data generation information and the response data on the transmission line in order to transmit the response data generation information and the response data.
[0024] Because of this configuration, an anomaly in the network can be detected without using a transmission line different from the main transmission path in the network.
[0025] (8) In any one of (1) to (7) above, the detection system may further include an aggregation or collection device, and the aggregation device may generate aggregation data in which a plurality of pieces of the response data, each generated by a plurality of the response devices, are aggregated or collected, and the generated aggregation data are transmitted to the detection device.
[0026] This configuration allows for the suppression of an increase in communication traffic due to the transmission of response data, and enables efficient verification or checking of response data in the detection device.
[0027] (9) A detection system according to one embodiment of the present disclosure comprises: a first responder; a second responder; and a detection device configured to detect an anomaly in a network comprising the first responder, the second responder, and a transmission path. The detection device transmits response data generation information, to be used in generating response data, to the first responder and the second responder via a first transmission path. The first responder generates initial response data, which constitutes the response data, based on the response data generation information received from the detection device, and transmits the generated initial response data to the second responder via a second transmission path.The second responding device generates second response data, which is based on the response data generation information received from the detection device, and transmits the generated second response data and the first response data received from the first responding device to the detection device. The detection device detects an anomaly in the network based on reference information derived from a network configuration, the first response data transmitted by the first responding device, and the second response data transmitted by the second responding device. At least one of the first and second transmission paths includes a main transmission path for transmitting a main signal in the network.
[0028] In this way, due to the configuration in which an anomaly in the network is detected based on the reference information, which is based on the network configuration, and the response data transmitted over the transmission path, a change in the network configuration can be detected as an anomaly in the network based on the result of a comparison between, for example, the reference information and the response data. Therefore, network security can be improved.
[0029] (10) A detection device according to an embodiment of the present disclosure comprises: a transmission unit configured to transmit response data generation information, to be used in generating response data, to a response device in a network via a first transmission path; a receiving unit configured to receive, via a second transmission path, the response data based on the response data generation information and transmitted by the response device; and a detection unit configured to detect an anomaly in the network based on reference information based on a network configuration and the response data received by the receiving unit.At least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network.
[0030] In this way, due to the configuration in which the response data generation information is transmitted to the responding device via the transmission path, an anomaly in the network can be detected based on the reference information, which is based on the network configuration, and the response data received via the transmission path. Thus, a change in the network configuration can be detected as an anomaly in the network based on the result of a comparison between, for example, the reference information and the response data. In this way, network security can be improved.
[0031] (11) A response device according to one embodiment of the present disclosure is a response device that is fixed or arranged on a communication device in a network. The response device comprises: a receiving unit configured to receive, via a first transmission path, response data generation information to be used in generating response data from a detection device configured to detect an anomaly in the network; a generation unit configured to generate the response data based on the response data generation information received by the receiving unit; and a transmission unit configured to transmit the response data generated by the generation unit to another device via a second transmission path.At least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network.
[0032] Due to the configuration in which a responding device, fixed to a communication device or apparatus in a network, transmits response data based on response data generation information received via a transmission path to another device via a transmission path, it is possible in the other device to detect, for example, a change in the network configuration as an anomaly in the network, based on the result of a comparison between information based on the network configuration and the response data received by the responding device. Therefore, network security can be improved.
[0033] (12) A response device according to an embodiment of the present disclosure comprises: a receiving unit configured to receive, via a first transmission path, response data generation information to be used in generating response data from a detection device configured to detect an anomaly in the network; a generation unit configured to generate the response data based on the response data generation information received by the receiving unit; and a transmission unit configured to transmit the response data generated by the generation unit to another device via a second transmission path.The first transmission path is a main transmission path for transmitting a main signal in the network, and the second transmission path is a leased line used when an anomaly is detected in the network, or the second transmission path is the main transmission path and the first transmission path is a leased line used when an anomaly is detected.
[0034] In this way, due to the communication in which response data generation information is received and response data is transmitted to another device using the main transmission path for transmitting the main signal in the network and the leased line, it is possible, for example, to detect a change in the network configuration as an anomaly in the network in the other device based on the result of the discrepancy between information based on the network configuration and the response data received by the responding device, while suppressing any influence on the communication using the main transmission path. Therefore, network security can be improved.
[0035] (13) A detection method according to an embodiment of the present disclosure is a detection method carried out in a detection system comprising a response device and a detection device that detects an anomaly in a network comprising the response device and a transmission path. The transmission method comprises: a step carried out by the detection device of transmitting response data generation information, to be used in generating response data, to the response device via a first transmission path; a step carried out by the response device of generating orThe process involves generating response data based on response data generation information received by the detection device and transmitting the generated response data to the detection device via a second transmission path; and a step performed by the detection device of detecting an anomaly in the network based on reference information derived from a network configuration and the response data transmitted by the response device. At least one of the first and second transmission paths includes a primary transmission path for transmitting a primary signal in the network.
[0036] In this way, due to the method in which an anomaly in the network is detected based on the reference information, which is based on the network configuration, and the response data transmitted over the transmission path, a change in the network configuration can be detected as an anomaly in the network based on the result of a comparison between, for example, the reference information and the response data. Therefore, network security can be improved.
[0037] Embodiments of the present disclosure will be described below with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and descriptions thereof are not repeated. At least some parts of the embodiments described below can be combined with one another as desired. <Erste Ausführungsform>[Configuration and basic operation]
[0038] Fig. Figure 1 shows a configuration or structure of a detection system according to a first embodiment of the present disclosure. With reference to Fig. 1 comprises a detection system 401: responders 101A, 101B, each of which is a responder 101; communication devices 111A, 111B, each of which is a communication device 111; a gateway device 121; and detection devices 301A, 301B, each of which is a detection device 301. For example, the detection system 401 comprises M responders 101A, M communication devices 111A, N responders 101B, and N communication devices 111B. M and N are each an integer equal to or greater than 2. The detection system 401 can be configured to include one responder 101A and one communication device 111A, or it can be configured to include one responder 101B and one communication device 111B.
[0039] For example, the detection system 401 is used in a network within an industrial control system of a factory, plant, or similar facility. In this case, the communication device 111 is a PLC (programmable logic controller) for regulating or controlling, for example, a power supply control unit, a robot, a sensor, or an actuator / actuator.
[0040] The 401 detection system can be used in a home network or a network in a vehicle. When the 401 detection system is used in a network in a vehicle, the communication device 111 and the detection device 301 each constitute an ECU (electronic control unit) in the vehicle.
[0041] For example, the response device 101 is a connector that can be fixed to the communication device 111. In the Fig. In the example shown, a response device 101A is or will be specified on each of the communication devices 111A, and a response device 101B is or will be specified on each of the communication devices 111B.
[0042] The gateway device 121 and the responding devices 101A are connected in a one-to-many relationship. More specifically, the gateway device 121, the responding devices 101A, and the detection device 301A are connected to each other via a transmission line 2A, which is transmission line 2. Additionally, the detection device 301A and the responding devices 101A are connected to each other via a transmission line 1A, which is transmission line 1. Transmission lines 1 and 2 each constitute a physical transmission path.
[0043] The gateway device 121 and the responding devices 101B are connected in a one-to-many or one-to-many relationship. More specifically, the gateway device 121, the responding devices 101B, and the detection device 301B are connected to each other via a transmission line 2B, which is transmission line 2. Additionally, the detection device 301B and the responding devices 101B are connected to each other via a transmission line 1B, which is transmission line 1.
[0044] The detection system 401 includes networks NWa and NWb. Network NWa consists of the gateway device 121, the responding devices 101A, the communication devices 111A, and the transmission line 2A. Network NWb consists of the gateway device 121, the responding devices 101B, the communication devices 111B, and the transmission line 2B. Hereinafter, each of the networks NWa and NWb will also be referred to as a network NW.
[0045] Transmission line 2A contains a main transmission path for transmitting a main signal in network NWa. Transmission line 2B contains a main transmission path for transmitting a main signal in network NWb. Transmission line 1A is a dedicated leased line used when an anomaly is detected in network NWa. Transmission line 1B is a dedicated leased line used when an anomaly is detected in network NWb. Transmission line 1 is an example of a first transmission path, and transmission line 2 is an example of a second transmission path.
[0046] Transmission lines 1 and 2 are each a transmission line for serial communication according to a standard, such as RS (Recommended Standard)-232C, RS-422A, or RS-485. Transmission lines 1 and 2 can each be a transmission line according to another standard, such as CAN (Controller Area Network) (registered trademark) or LIN (Local Interconnect Network).
[0047] A communication device 111A communicates with the gateway device 121 and another communication device 111A via a corresponding answering device 101A and the transmission line 2A. A communication device 111B communicates with the gateway device 121 and another communication device 111B via a corresponding answering device 101B and the transmission line 2B. As an example, a communication device 111 transmits a message according to Modbus (registered trademark), which is addressed to another communication device 111, to the gateway device 121 and the other communication device 111 via a corresponding answering device 101 and a corresponding transmission line 2.
[0048] The gateway device 121 performs a relay or forwarding process, for example, of a message exchanged between communication devices 111, which are connected via different transmission lines 2 through answering devices 101, and a message exchanged between an external network (not shown) outside the detection system 401 and a communication device 111. For example, communication device 111A transmits and receives messages with low confidentiality and is or becomes capable of communicating with the external network via the gateway device 121. In contrast, communication device 111B transmits and receives messages with high confidentiality and is prevented from being or becoming capable of communicating with the external network.
[0049] Detection device 301A transmits, periodically or non-periodically, response data generation information Ga, which is to be used when generating response data Ra, to each response device 101A via transmission line 1A. Detection device 301B transmits, periodically or non-periodically, response data generation information Gb, which is to be used when generating response data Rb, to each response device 101B via transmission line 1B. Hereinafter, each of the response data Ra, Rb will also be referred to as response data R, and each of the response data generation information Ga, Gb will also be referred to as response data generation information G.
[0050] Each responding device 101A generates response data Ra, based on the response data generation information Ga received by the detection device 301A, and transmits the generated response data Ra to the detection device 301A via transmission line 2A. For example, the responding device 101A multiplexes or divides the response data Ra onto transmission line 2A, through which the main signal in the network NWa is transmitted, using a frequency-division multiplexing, time-division multiplexing, or code-division multiplexing method, thereby transmitting the response data Ra to the detection device 301A.
[0051] Each responding device 101B generates response data Rb based on the response data generation information Gb received by the detection device 301B and transmits the generated response data Rb to the detection device 301B via transmission line 2B. For example, the responding device 101B multiplexes or divides the response data Rb onto transmission line 2B, through which the main signal in the network NWb is transmitted, using a frequency-division multiplexing, time-division multiplexing, or code-division multiplexing technique, thereby transmitting the response data Rb to the detection device 301B.
[0052] Detection device 301A detects an anomaly in network NWa based on reference information RFa, which is based on the configuration or structure of network NWa, and the response data Ra, which is transmitted by response device 101A. Detection device 301B detects an anomaly in network NWb based on reference information RFb, which is based on the configuration of network NWb, and the response data Rb, which is transmitted by response device 101B. More specifically, detection device 301 detects a change in the network configuration of a corresponding network NW as an anomaly in network NW. That is, detection device 301 detects a change in the network topology of network NW as an anomaly in network NW.In the following, each reference information RFa, RFb will also be referred to as a reference information RF.
[0053] For example, the detection device 301 detects a path blockage in a corresponding network NW as an anomaly. The path blockage includes a physical path blockage, which is caused by cutting transmission line 1, and a logical path blockage, which is caused by adding an unauthorized filter device to transmission line 1 that discards some or all of the messages.
[0054] For example, the detection device 301 detects as an anomaly in the network NW the initiation of a rerouting path, which is a transmission path not via the gateway device 121, between the responding device 101A and the responding device 101B. The initiation of a rerouting path includes the initiation of a physical rerouting path, which is caused by changing the wiring of transmission lines 1A, 1B, and the initiation of a logical rerouting path, which is caused by the initiation of an unauthorized relay device that forwards a message transmitted on one of the transmission lines 1A, 1B to the other of the transmission lines 1A, 1B.
[0055] As described above, communication device 111A is transmittable and capable of communicating with an external network via gateway device 121, while communication device 111B is prevented from transmitting and becoming transmittable and capable of communicating with the external network. When a rerouting path is inserted between response device 101A and response device 101B, communication device 111B becomes transmittable and capable of communicating with the external network via gateway device 121 and the rerouting path. Therefore, detection device 301 detects the insertion of the rerouting path as an anomaly in the network. (Transmission of response data generation information G)
[0056] Fig. Figure 2 shows a configuration of the detection device in the detection system according to the first embodiment of the present disclosure. With reference to Fig. 2 The detection device 301 comprises a transmission unit 31, a receiving unit 32, a detection unit 33, and a storage unit 34. Part or all of the transmission unit 31, the receiving unit 32, and the detection unit 33 are implemented, for example, by a processing circuit containing one or more processors. The storage unit 34 is a non-volatile memory, which is included, for example, in the processing circuit described above.
[0057] Detection unit 33 periodically or non-periodically generates a response data generation information G and a verification start command, and outputs the generated response data generation information G and the verification start command to transmission unit 31. The response data generation information G can be a random number value with a predetermined length or a predetermined value. For example, when generating response data generation information G with a predetermined value, detection unit 33 generates a response data generation information G with a value different from that of a response data generation information G generated in the past, and outputs the generated response data generation information G to transmission unit 31.Accordingly, even if an unauthorized device, which is posing or masking itself as a Response Device 101, has carried out a back-transmission attack, the presence of the unauthorized device can be detected more reliably.
[0058] For example, at a predetermined transmission time ta, the detection unit 33 in the detection device 301A generates a response data generation information Ga and a verification start command and outputs the generated response data generation information Ga and the verification start command to the transmission unit 31, and at a predetermined transmission time tb different from the transmission time ta, the detection unit 33 in the detection device 301B generates a response data generation information Gb and a verification start command and outputs the generated response data generation information Gb and the verification start command to the transmission unit 31.
[0059] The transmission unit 31 transmits the response data generation information G to each responding device 101 via transmission line 1. More specifically, the transmission unit 31 in the detection device 301A receives the response data generation information Ga from the detection unit 33, causes the received response data generation information Ga and the verification start command to be contained in a message, and transmits the message to each responding device 101A via transmission line 1A. The transmission unit 31 in the detection device 301B receives the response data generation information Gb from the detection unit 33, causes the received response data generation information Gb and the verification start command to be contained in a message, respectively, and transmits the message to each responding device 101B via transmission inlet 1B. (Transmission of response data R)
[0060] The following describes a transmission of response data R performed by the response device 101. The content concerning the transmission of response data R below applies to response devices 101A and 101B, unless otherwise specified.
[0061] Fig. Figure 3 shows a configuration of the response device in the detection system according to the first embodiment of the present disclosure. With reference to Fig. Figure 3 includes the response device 101, a connection unit 10, and a response unit 20. The response unit 20 includes a receiver unit 21, a transmission unit 22, a processing unit 23, and a storage unit 24. The processing unit 23 is an example of a generation unit. Some or all of the receiver unit 21, the transmission unit 22, and the processing unit 23 are implemented, for example, by a processing circuit containing one or more processors. The storage unit 24 is a non-volatile memory, which is included, for example, in the processing circuit described above.
[0062] The connection unit 10 electrically connects the transmission line 2 and the communication device 111. The communication device 111 receives a message transmitted by another communication device 111 via the transmission line 2 and the connection unit 10, and transmits a message addressed to another communication device 111 via the connection unit 10 and the transmission line 2.
[0063] The storage unit 24 in the response unit 20 of the response device 101 stores a key piece of information K, which is unique to the response device 101. The key piece of information K is an example of unique information.
[0064] The receiving unit 21 in the response unit 20 receives response data generation information G from the detection device 301 via transmission line 1. More specifically, the receiving unit 21 receives a message from the detection device 301 via transmission line 1 and acquires the response data generation information G from the received message. The receiving unit 21 outputs the acquired response data generation information G to the processing unit 23.
[0065] Processing unit 23 generates response data R based on response data generation information G. For example, processing unit 23 generates response data R based on key information K in storage unit 24. More specifically, processing unit 23 receives response data generation information G from receiving unit 21 and generates response data R using the received response data generation information G and key information K in storage unit 24. The response data R can be a digital signature or a message authenticator. Processing unit 23 outputs the generated response data R to transmission unit 22.
[0066] The transmission unit 22 transmits the response data R to the detection device 301 via the transmission line 2. More specifically, the transmission unit 22 receives the response data R from the processing unit 23, generates a message containing the received response data R, and transmits the generated message to the detection device 301 via the connection unit 10 and the transmission line 2. (Detection process)
[0067] Again, with reference to Fig. The receiving unit 32 in the detection device 301 receives the response data R, transmitted by the response device 101, via transmission line 2. Based on the reference information RF, which is based on the network configuration NW, and the response data R received by the receiving unit 32, the detection unit 33 performs a detection process to detect an anomaly in the network NW. The detection process, which is carried out in the detection device 301A, will be described representatively below.
[0068] For example, the storage unit 34 in the detection device 301A stores the reference information RFa, which indicates: the number of response devices 101A connected to the transmission line 1A; the key information K of each response device 101A connected to the transmission line 1A; and a required time TM, which is the time required from when response data generation information Ga is transmitted to the response device 101A until the response device 101A completes a transmission of the response data Ra.
[0069] The receiving unit 32 in the detection device 301A receives a message from each responding device 101 via the transmission line 2A. The receiving unit 32 receives or acquires response data R from the received message and outputs the acquired response data R and the ID of the responding device 101, which is the transmission source of the response data R, to the detection unit 33.
[0070] The detection unit 33 receives the response data R from the receiving unit 32 and verifies the received response data R against information based on the reference information RFa. For example, the detection unit 33 generates generation data Ma based on the key information K, which is contained in the reference information RFa, and the response data generation information Ga, which was transmitted to each responding device 101A, and verifies the response data R received by the receiving unit 32 against the generation data Ma. As a result of verifying the response data R, the detection unit 33 detects an anomaly in the network NWa, based on the number of pieces or elements of the response data R received by the receiving unit 32 and the time of receipt of the response data R.
[0071] More specifically, using the response data generation information Ga, which was transmitted to each response device 101A via the transmission unit 31, and pieces or elements of the key information K in the storage unit 34, the detection unit 33 generates a plurality of pieces or elements of generation data Ma corresponding to a plurality of pieces or elements of response data Ra, each corresponding to the plurality of response devices 101A connected to the transmission line 2A. For example, the generation data Ma can be a hash value.
[0072] Based on the response data Ra and the ID received by the receiving unit 32, the detection unit 33 checks the response data Ra against the generation data Ma for each responding device 101A. For example, if at least one piece of response data Ra among a plurality of pieces of response data Ra received by the receiving unit 32 does not match the generation data Ma corresponding to the responding device 101A, which is the transmission source of the response data Ra, the detection unit 33 determines that a detection condition C1 is met. Conversely, if the plurality of pieces of response data Ra received by the receiving unit 32 and the plurality of generated pieces of generation data Ma each match, the detection unit 33 determines that the detection condition C1 is not met.
[0073] Additionally, with reference to the reference information RFa, the detection unit 33 compares the number of pieces or elements of response data R received by the receiving unit 32 within a predetermined reception period TRa with the number of response devices 101A connected to the transmission line 1A. For example, the reception period TRa is preset or defined in accordance with the required time TM, indicated by the reference information RFa, and the transmission time of the response data generation information G in the detection system 401, etc. As an example, the reception period TRa is a period from the transmission time ta of the response data generation information Ga, transmitted by the detection device 301A, to the transmission time tb of the response data generation information Gb, transmitted by the detection device 301B.For example, if the number of pieces or elements of response data R received by the receiving unit 32 during the receiving period TRa does not match the number, i.e., N, of response devices 101A connected to the transmission line 1A, the detection unit 33 determines that a detection condition C2 is met. Conversely, if the number of pieces of response data R received by the receiving unit 32 during the receiving period TRa is N, the detection unit 33 determines that the detection condition C2 is not met.
[0074] Additionally, the detection unit 33 confirms the presence or absence of response data R received by the receiving unit 32 in a period different from the receiving period TRa. For example, if there is response data R received by the receiving unit 32 in a period different from the receiving period TRa, the detection unit 33 determines that a detection condition C3 is met. Conversely, if there is no response data R received by the receiving unit 32 in a period different from the receiving period TRa, the detection unit 33 determines that the detection condition C3 is not met.
[0075] In the detection process, detection unit 33 detects an anomaly in the network NWa based on the result of a determination of whether the detection conditions C1, C2, or C3 are met. More specifically, if it has been determined that at least one of the detection conditions C1, C2, or C3 is met, detection unit 33 determines that an anomaly has occurred in the network NWa.
[0076] For example, if detection condition C1 is met, detection unit 33 determines that an unauthorized device, which is impersonating or masking itself as a responding device 101A, is present. For example, if detection condition C2 is met and the number of pieces or elements of response data R received by receiving unit 32 in the receive period TRa is less than N, detection unit 33 determines that a path blockage has occurred in the network NWa. For example, if detection condition C2 is met and the number of pieces of response data R received by receiving unit 32 in the receive period TRa is greater than N, or if detection condition C3 is met, detection unit 33 determines that a rerouting path has occurred in the network NWa.
[0077] If an anomaly has been determined to have occurred in the NWa network, the detection unit 33 ensures that anomaly information indicating the occurrence of an anomaly is included in or recorded in a message and transmits the message to each responding device 101A via transmission line 1A. Additionally, the detection unit 33 notifies a user of the detection system 401 of the anomaly in the NWa network by means of an audible tone or a visual indication. The processing unit 23 can be configured to omit one or both of the transmissions of the anomaly information to the responding device 101A and the notification to the user.
[0078] Referring again to Fig. 3. Processing unit 23 in response unit 101A notifies the user of detection system 401, for example, when anomaly information is received by detection device 301A via transmission line 1A and receiving unit 21, by means of a tone or a display, that an anomaly has occurred in the NWa network. Additionally, when anomaly information is received by detection device 301A via transmission line 1A and receiving unit 21, processing unit 23 disconnects the electrical connection between transmission line 2A and communication device 111A at connection unit 10. Processing unit 23 can be configured to omit one or both of the notification to the user and the disconnection of the electrical connection between transmission line 2A and communication device 111A. (Modification 1)
[0079] Fig. Figure 4 shows a configuration of a detection system according to a modification or adaptation 1 of the first embodiment of the present disclosure. With reference to Fig. Compared to detection system 401, detection system 402 includes a detection device 302 instead of detection device 301A, and includes response devices 102A, each of which is a response device 102 instead of response devices 101A. Additionally, compared to detection system 401, detection system 402 further includes communication devices 111C, each of which is a communication device 111, response devices 102C, each of which is a response device 102, and collection or aggregation devices 201A, 201C. For example, detection system 402 includes L response devices 102C and L communication devices 111C. In the Fig. In the example shown in Figure 4, a communication device 111C is connected to each of the response devices 102C. L is an integer equal to or greater than 2. The detection system 402 can be configured to include one response device 102C and one communication device 111C. Hereinafter, each of the aggregation devices 201A, 201C will also be referred to as an aggregation device 201.
[0080] The gateway device 121, the responding devices 102A, the aggregation device 201A, and the detection device 302 are interconnected via transmission line 2A. Additionally, the responding devices 102A and 102C, the aggregation devices 201A and 201C, and the detection device 302 are interconnected via transmission line 1A.
[0081] The gateway device 121, the response devices 102C and the aggregation device 201C are connected to each other via a transmission line 2C, which is a transmission line 2.
[0082] Compared to detection system 401, detection system 402 includes a network NW1a instead of network NWa, and also includes a network NWc. Network NW1a consists of gateway device 121, responding devices 102A, communication devices 111A, and transmission line 2A. Network NWc consists of gateway device 121, responding devices 102C, communication devices 111C, and transmission line 2C.
[0083] The detection device 302 transmits a response data generation information Ga to the response devices 102A, 102C and the aggregation devices 201A, 201C via the transmission line 1A.
[0084] Each responding device 102A causes response data Ra, which is based on the response data generation information Ga received by the detection device 302, to be included or recorded in a message and transmits the message to the aggregation device 201A via transmission line 2A. For example, the responding device 102A divides the response data Ra onto transmission line 2A, through which the main signal in the network NWa is transmitted, by means of a frequency-division multiplexing, time-division multiplexing, or code-division multiplexing technique, thereby transmitting the response data Ra to the aggregation device 201A.
[0085] Each responding device 102C causes response data Rc, based on the response data generation information Ga received by the detection device 302, to be included in a message and transmits the message to the aggregation device 201C via transmission line 2C. For example, the responding device 102C divides the response data Rc onto transmission line 2C, through which the main signal in the network NWc is transmitted, by means of a frequency-division multiplexing, time-division multiplexing, or code-division multiplexing technique, thereby transmitting the response data Rc to the aggregation device 201C.
[0086] The aggregation device 201A generates aggregation or collection data RxA, in which a plurality of pieces or elements of response data Ra, each generated by the plurality of response devices 102A, are aggregated or collected, and transmits the generated aggregation data RxA to the detection device 302.
[0087] More specifically, the aggregation device 201A receives the message from each response device 102A via transmission line 2A. The aggregation device 201A captures a plurality of response data pieces Ra from each plurality of messages received during the reception period TRa. The aggregation device 201A performs a predetermined process on the received plurality of response data pieces Ra to generate aggregation data RxA, which has a data set smaller than the total value of the data set of the plurality of response data pieces Ra. The aggregation device 201A ensures that the generated aggregation data RxA is contained in a message and transmits the message to the detection device 302 via transmission line 1A.
[0088] The aggregation device 201C generates aggregation or collection data RxC, in which a plurality of pieces or elements of response data Rc, each generated by the plurality of response devices 102C, are aggregated or collected, and transmits the generated aggregation data RxC to the detection device 302.
[0089] More specifically, the aggregation device 201C receives the message from each response device 102C via transmission line 2C. The aggregation device 201C captures or receives a plurality of pieces or elements of response data Rc from each plurality of messages received during the reception period TRa. The aggregation device 201C performs a predetermined process on the received plurality of response data pieces Rc to generate aggregation data RxC, which has a data set smaller than the total value of the data set of the plurality of response data pieces Rc. The aggregation device 201C causes the generated aggregation data RxC to be contained in a message and transmits the message to the detection device 302 via transmission line 1A.
[0090] Detection device 302 receives the aggregation data RxA and RxC from aggregation devices 201A and 201C, respectively, via transmission line 1A. Detection device 302 performs a detection process based on reference information RFac, which is based on the configurations of networks NW1A and NWc, and the aggregation data RxA and RxC received from aggregation devices 201A and 201C.
[0091] More specifically, the detection device 302 generates a plurality of pieces or elements of generation data Ma, each corresponding to a plurality of response devices 102A connected to the transmission line 2A, and a plurality of pieces or elements of generation data Mc, each corresponding to a plurality of response devices 102C connected to the transmission line 2C.
[0092] The detection device 302 checks the aggregation data RxA against the generation data Ma for each response device 102A, and checks the aggregation data RxC against the generation data Mc for each response device 102C.
[0093] If at least one piece or element of response data Ra, among a plurality of pieces of response data Ra aggregated or collected in the aggregation data RxA, does not correspond to the generation data Ma according to the response device 102A, which is the transmission source of the response data Ra, the detection device 302 determines that the detection condition C1 is met. Additionally, if at least one piece of response data Rc, among a plurality of pieces of response data Rc aggregated in the aggregation data RxC, does not correspond to the generation data Mc according to the response device 102C, which is the transmission source of the response data Rc, the detection device 302 determines that the detection condition C1 is met.
[0094] In contrast, if the majority of pieces of response data Ra, which are aggregated in the aggregation data RxA, each corresponds to the generated majority of pieces of generation data Ma, and the majority of pieces of response data Rc, which are aggregated in the aggregation data RxC, each corresponds to the generated majority of pieces of generation data Mc, the detection device 302 determines that the detection condition C1 is not met.
[0095] The aggregation device 201A can be configured to generate the aggregation data RxA by generating response data R based on the response data generation information Ga received by the detection device 302, and performing a predetermined process on the majority of pieces or elements of response data Ra and the generated response data R. The aggregation device 201C can be configured to generate the aggregation data RxC by generating the response data R based on the response data generation information Ga received by the detection device 302, and performing a predetermined process on the majority of pieces of response data Rc and the generated response data R.
[0096] Furthermore, similar to the detection device 302, the aggregation device 201 can be configured to detect an anomaly in the networks NW1a, NWc based on the number of pieces or elements of the received response data R and the time of receipt of the response data R. (Modification 2)
[0097] Fig. Figure 5 shows a configuration of a detection system according to a modification or adaptation 2 of the first embodiment of the present disclosure. With reference to Fig. 5 includes, compared to the detection system 401, a detection system 403, a detection device 303 instead of the detection device 301A, and includes response devices 103A instead of the response devices 101A.
[0098] The gateway device 121, the response devices 103A, and the detection device 303 are interconnected via transmission line 2A. By using the shared physical transmission line 2A, a logical transmission path 2A1 and a logical transmission path 2A2 are provided.
[0099] A communication device or apparatus 111A communicates with the gateway device 121 and other communication devices 111A via a corresponding response device 103A and the transmission path 2A1. As an example, a communication device 111A transmits a message according to Modbus, which is addressed to another communication device 111, to the gateway device 121 and the other communication device 111 via a corresponding response device 103A and the transmission path 2A1.
[0100] The detection device 303 and each response device 103A multiplex a response data generation information Ga and response data Ra on the transmission line 2A in order to transmit them.
[0101] More specifically, the detection device 303 transmits the response data generation information Ga to each response device 103A via transmission path 2A2 logically independently of and distinct from transmission path 2A1. For example, the detection device 303 multiplexes or divides the response data generation information Ga onto transmission line 2A, through which the main signal in the network NWa is transmitted, by means of a frequency division multiplexing method, a time division multiplexing method, or a code division multiplexing method, thereby transmitting the response data generation information Ga to the response device 103A.
[0102] The responding device 103A generates response data Ra based on the response data generation information Ga received by the detection device 303 and transmits the generated response data Ra to the detection device 303 via transmission path 2A1. For example, the responding device 103A divides the response data Ra onto transmission line 2A, through which the main signal in the network NWa is transmitted, by means of a frequency division multiplexing, a time division multiplexing, or a code division multiplexing, thereby transmitting the response data Ra to the detection device 303. [Operational process]
[0103] Fig. Figure 6 shows an example of the sequence of the detection process which is carried out in the detection system according to the first embodiment of the present disclosure. Fig. Figure 6 shows the detection process which is carried out in the detection device 301A.
[0104] With reference to Fig. 6 first transmits, upon occurrence of a predetermined transmission time ta, the detection device 301 a response data generation information Ga to each response device 101A via the transmission line 1A (step S11).
[0105] Next, each responding device 101A generates response data Ra using the response data generation information Ga received from the detection device 301A and the key information K (step S12).
[0106] Next, each response device 101A transmits the generated response data Ra to the detection device 301A via the transmission line 2A (step S13).
[0107] Next, the detection device 301A performs the detection process based on the reference information RFa, which is based on the network configuration NWa, and the response data Ra received from each responding device 101A. Specifically, the detection device 301A checks the received response data Ra against the generation data Ma for each responding device 101A, thereby determining whether the detection condition C1 is met. Additionally, with reference to the reference information RFa, the detection device 301A compares the number of received response data R during the receive period TRa with the number of responding devices 101A connected to the transmission line 1A, thereby determining whether the detection condition C2 is met.Additionally, based on the time of receipt of the response data R, the detection device 301A determines whether the detection condition C3 is met or not. The detection device 301A determines whether an anomaly has occurred in the network NWa or not, based on the result of a determination concerning the detection conditions C1, C2, C3 (step S14).
[0108] Fig. Figure 7 shows an example of the sequence of the detection process which is carried out in the detection system according to the modification or adaptation 1 of the first embodiment of the present disclosure. Fig. Figure 7 shows the detection process which is carried out in the detection device 302.
[0109] With reference to Fig. 7, when a predetermined transmission time ta occurs, the detection device 302 first transmits a response data generation information Ga to the response devices 102A, 102C and the aggregation or collection devices 201A, 201C via the transmission line 1A (step S21).
[0110] Next, each responding device 102A generates response data Ra using the response data generation information Ga received from the detection device 302 and the key information K. Additionally, each responding device 102C generates response data Rc using the response data generation information Ga received from the detection device 302 and the key information K (step S22).
[0111] Next, each response device 102A transmits the generated response data Ra to the aggregation device 201A via transmission line 2A. Additionally, each response device 102C transmits the generated response data Rc to the aggregation device 201C via transmission line 2C (step S23).
[0112] Next, aggregation device 201A receives a plurality of pieces or elements of response data Ra, each transmitted by the plurality of response devices 102A, and generates aggregation data RxA, in which the received plurality of pieces of response data Ra are aggregated. Aggregation device 201C receives a plurality of pieces of response data Rc, each transmitted by the plurality of response devices 102C, and generates aggregation data RxC, in which the received plurality of pieces of response data Rc are aggregated (step S24).
[0113] Next, the aggregation device 201A transmits the generated aggregation data RxA to the detection device 302 via transmission line 1A. The aggregation device 201C transmits the generated aggregation data RxC to the detection device 302 via transmission line 1A (step S25).
[0114] Next, the detection device 302 performs the detection process based on the reference information RFac, which is based on the configurations of the networks NW1a and NWc, and the aggregation data RxA and RxC received by the aggregation devices 201A and 201C. Specifically, the detection device 302 checks the received aggregation data RxA against the generation data Ma for each response device 102A and checks the received aggregation data RxC against the generation data Mc for each response device 102C, thereby determining whether the detection condition C1 is met. Additionally, with reference to a reference information RFa1, the detection device 302 compares the number of pieces or elements of response data R that are aggregated or collected in the aggregation data RxA and RxC.The number of response devices 102A and 102C, each connected to transmission lines 2A and 2C respectively, determines whether detection condition C2 is met. Additionally, based on the time of receipt of the response data R, detection device 302 determines whether detection condition C3 is met. Detection device 302 then determines whether an anomaly has occurred in the network NW1a and NWc, based on the result of a determination regarding detection conditions C1, C2, and C3 (step S26).
[0115] In the detection system 401 according to the first embodiment of the present disclosure, the detection device 301A is configured to transmit the response data generation information Ga to the response device 101A via transmission line 1A, although the present disclosure is not limited to this. The detection device 301A can be configured to transmit the response data generation information Ga to the response device 101A via transmission line 2A. In this case, the response device 101A transmits the transmission data Ra to the detection device 301A via transmission line 1A.
[0116] In the detection system 401 according to the first embodiment of the present disclosure, the detection device 301 can be configured to transmit the response data generation information G to the response device 101 via wireless communication, instead of transmitting the response data generation information G to the response device 101 via the transmission line 1. Additionally, the response device 101 can be configured to transmit the response data R to the detection device 301 via wireless communication, instead of transmitting the response data R to the detection device 301 via the transmission line 1.
[0117] In the detection device 301 according to the first embodiment of the present disclosure, the detection unit 33 is configured to detect an anomaly in the network NW based on the result of a determination of whether the detection conditions C1, C2, C3 are met or not, although the present disclosure is not limited thereto. The detection unit 33 can be configured to detect an anomaly in the network NW based on the result of a determination of whether one or two of the detection conditions C1, C2, C3 are met or not.
[0118] In contrast, there is now a growing demand for technologies that can improve network security. More specifically, if communication between devices on a network is encrypted, problems such as reduced communication speed and increased costs could arise.
[0119] In contrast, in the detection system according to the first embodiment of the present disclosure, the detection device 301 transmits response data generation information G, which is to be used in the generation of response data R, to the response device 101 via transmission line 1A. The response device 101 generates the response data R based on the response data generation information G received from the detection device 301 and transmits the generated response data R to the detection device 301 via transmission line 1B. The detection device 301 detects an anomaly in the network NW based on reference information RF, which is based on the configuration of the network NW, and the response data R transmitted by the response device 101.At least one of the transmission lines 1A, 1B includes a main transmission path for transmitting the main signal in the network NW.
[0120] In this way, due to the configuration in which an anomaly in the network NW is detected based on the reference information RF, which is based on the network NW configuration, and the response data R, which is transmitted or was transmitted via transmission path 2A, a change in the network configuration of the network NW can be detected as an anomaly in the network NW, based on the result of a comparison between, for example, the reference information RF and the response data R. In this way, security in the network NW can be improved. Additionally, compared to the configuration in which communication between communication devices 111 in the network NW is encrypted, an anomaly in the network NW can be detected, while a decrease in communication speed and an increase in costs are suppressed.Additionally, for example, due to the configuration in which the response device 101 is a connector or plug that can be specified on the communication device 111 in the network NW, an anomaly in the network NW can be detected without changing the specifications of the communication device 111.
[0121] Next, another embodiment of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and descriptions thereof are not repeated. <Zweite Ausführungsform> [Configuration and basic operation]
[0122] The present embodiment relates to a detection system 404 in which response devices are interconnected in a one-to-one relationship via a transmission path for transmitting a main signal, compared to the detection systems 401, 402, 403 according to the first embodiment. Except for the features described below, the configuration of the detection system 404 is the same as that of the detection systems 401, 402, 403 according to the first embodiment.
[0123] Fig. Figure 8 shows a configuration or structure of a detection system according to a second embodiment of the present disclosure. The detection system 404 comprises response devices 104A, 104B, 104C, 104D, each of which is a response device 104; response devices 105A, 105B, 105C, 105D, each of which is a response device 105; communication devices 112A, 112B, 112C, 112D, each of which is a communication device 112; switching devices 141A, 141B, each of which is a switching device 141; a gateway device 122; and detection devices 304A, 304B, 304C, 304D, each of which is a detection device 304. Response device 104 is an example of a second response device. Response device 105 is an example of a first response device. The detection system 404 need not necessarily include four detection devices 304 and can be configured to include a single or multiple detection devices.to include a single detection device 304. In this case, the detection device 304 monitors all networks NW2, which are described later in the detection system 404.
[0124] The gateway device 122 is connected to the switching devices 141A and 141B via transmission lines 5A and 5B, respectively. Hereinafter, each of the transmission lines 5A and 5B will also be referred to as a transmission line 5. Transmission line 5 is, for example, an Ethernet cable (registered trademark).
[0125] For example, the response device 104 is a connector or plug which can be fixed to the switching device 141. In the Fig. In the example shown, the response devices 104A, 104B are each fixed to two communication ports (not shown) in the switching device 141A, and the response devices 104C, 104D are each fixed to two communication ports (not shown) in the switching device 141B.
[0126] For example, the response device 105 is a connector that can be fixed to the communication device 112. In the Fig. In the example shown, the responding device 105A is or will be set to a communication port (not shown) in the communication device 112A, the responding device 105B is set to a communication port (not shown) in the communication device 112B, the responding device 105C is set to a communication port (not shown) in the communication device 112C, and the responding device 105D is set to a communication port (not shown) in the communication device 112D.
[0127] Response device 104 and response device 105 are connected to each other in a one-to-one relationship. More specifically, response device 104A and response device 105A are connected to each other via a transmission line 4A. Response device 104B and response device 105B are connected to each other via a transmission line 4B. Response device 104C and response device 105C are connected to each other via a transmission line 4C. Response device 104D and response device 105D are connected to each other via a transmission line 4D. Hereinafter, each of the transmission lines 4A, 4B, 4C, 4D will also be referred to as a transmission line 4. Transmission line 4 is a physical transmission path.
[0128] The detection device 304 and the response devices 104 and 105 are connected to each other. More specifically, the detection device 304A and the response devices 104A and 105A are connected to each other via a transmission line 3A. The detection device 304B and the response devices 104B and 105B are connected to each other via a transmission line 3B. The detection device 304C and the response devices 104C and 105C are connected to each other via a transmission line 3C. The detection device 304D and the response devices 104D and 105D are connected to each other via a transmission line 3D. Hereinafter, each of the transmission lines 3A, 3B, 3C, and 3D will also be referred to as a transmission line 3. Transmission line 3 is a physical transmission path.
[0129] The 404 detection system includes networks NW2a and NW2b. Network NW2a consists of switching device 141A, responding devices 104A, 104B, 105A, and 105B, communication devices 112A and 112B, and transmission lines 4A and 4B. Network NWb consists of switching device 141B, responding devices 104C, 104D, 105C, and 105D, communication devices 112C and 112D, and transmission lines 4C and 4D. Hereinafter, each of the networks NW2a and NW2b will also be referred to as network NW2.
[0130] Transmission lines 4A and 4B each contain a main transmission path for transmitting a main signal in network NW2a. Transmission lines 4C and 4D each contain a main transmission path for transmitting a main signal in network NW2b. Transmission lines 3A and 3B are each dedicated leased lines used when an anomaly is detected in network NW2a. Transmission lines 3C and 3D are each dedicated leased lines used when an anomaly is detected in network NW2b. Transmission line 3 is an example of the first transmission path, and transmission line 4 is an example of the second transmission path.
[0131] Transmission line 3 is a transmission line for serial communication according to a standard, such as RS-232C, RS-422A, or RS-485. Transmission line 4 is, for example, an Ethernet cable.
[0132] The communication device 112 and the switching device 141 communicate with each other via corresponding answering devices 104, 105 and a corresponding transmission line 4. As an example, a communication device 112 transmits an Ethernet frame, addressed to another communication device 112, to a switching device 141 via a corresponding answering device 105 and a corresponding transmission line 4. The switching device 141 transmits the Ethernet frame, which was received via the corresponding answering device 104, to the destination communication device 112 via a corresponding answering device 104 and a corresponding transmission line 4, in accordance with the destination address of the Ethernet frame, or transmits the Ethernet frame to the gateway device 122 via a corresponding transmission line 5.Additionally, the switching device 141 transmits an Ethernet frame, which was received by the gateway device 122, to the destination communication device 112 via a corresponding response device 104 and a corresponding transmission line 4, in accordance with the destination address of the Ethernet frame.
[0133] The gateway device 122 performs a forwarding process, for example, of a message exchanged between communication devices 112 and a message exchanged between an external network (not shown) outside the detection system 404 and a communication device 112. For example, communication devices 112C and 112D transmit and receive messages with low confidentiality and are or become connected to the external network via the gateway device 122. In contrast, communication devices 112A and 112B transmit and receive messages with high confidentiality and are restricted or prevented from being or becoming connected to the external network.
[0134] In detection system 404, an anomaly detection process is carried out in network NW2 during a detection period Pd, which is a period of predetermined length. Specifically, during detection period Pd, detection device 304A transmits response data generation information Ga, which is to be used when generating response data Ra, to response devices 104A and 105A via transmission line 3A. Similarly, during detection period Pd, detection device 304B transmits response data generation information Gb, which is to be used when generating response data Rb, to response devices 104B and 105B via transmission line 3B. The detection device 304C transmits response data generation information Gc during the detection period Pd, which is generated orThe detection device 304D transmits response data generation information Gd, which is to be used for generating response data Rd, to the response devices 104C and 105C via transmission line 3C during detection period Pd. Subsequently, each of the response data Ra, Rb, Rc, and Rd will also be referred to as response data R, and each of the response data generation information Ga, Gb, Gc, and Gd will also be referred to as response data generation information G. For example, detection period Pd is a period in which no communication using transmission line 4 takes place.
[0135] Response device 105A generates response data Ra based on the response data generation information Ga received from detection device 304A. It then incorporates the generated response data Ra into an Ethernet frame and transmits this frame to response device 104A via transmission line 4A. In other words, response device 105A multiplexes the response data Ra onto transmission line 4A, the same line through which the main signal in network NW2a is transmitted, using a time-division multiplexing technique. This allows response data Ra to be transmitted to response device 104A.The responding device 104A generates response data Ra based on the response data generation information Ga received from the detection device 304A, generates aggregation data Rx2a, in which the generated response data Ra and the response data Ra received via transmission line 4A are aggregated, and transmits the generated aggregation data Rx2a to the detection device 304A via transmission line 3A. The detection period Pd can be a period in which communication takes place using transmission line 4. In this case, the responding device 105A distributes the response data Ra to transmission line 4A using either frequency division multiplexing or code division multiplexing, thereby transmitting the response data Ra to the responding device 104A.
[0136] Similar to response device 105A, response device 105B transmits response data Rb to response device 104B via transmission line 4B. Similar to response device 104A, response device 104B generates aggregation data Rx2b and transmits the generated aggregation data Rx2b to detection device 304B via transmission line 3B.
[0137] Similar to the response device 105A, the response device 105C transmits response data Rc to the response device 104C via transmission line 4C. Similar to the response device 104A, the response device 104C generates aggregation data Rx2c and transmits the generated aggregation data Rx2c to the detection device 304C via transmission line 3C.
[0138] Similar to the response device 105A, the response device 105D transmits response data Rd to the response device 104D via transmission line 4D. Similar to the response device 104A, the response device 104D generates aggregation data Rx2d and transmits the generated aggregation data Rx2d to the detection device 304D via transmission line 3D.
[0139] The response data R generated by response device 105 is an example of first response data. The response data R generated by response device 104 is an example of second response data. Hereinafter, each of the aggregation data Rx2a, Rx2b, Rx2c, and Rx2d will also be referred to as aggregation data Rx2.
[0140] Detection device 304A detects an anomaly in network NW2a based on reference information RF2a, which is based on the configuration of network NW2a, and aggregation data Rx2a. Detection device 304B detects an anomaly in network NW2a based on reference information RF2a and aggregation data Rx2b. Detection device 304C detects an anomaly in network NW2b based on reference information RF2b, which is based on the configuration of network NW2b, and aggregation data Rx2c. Detection device 304D detects an anomaly in network NW2b based on reference information RF2b and aggregation data Rx2d. Hereinafter, each of the reference information RF2a and RF2b will also be referred to as reference information RF2.
[0141] For example, the detection device 304 detects a path blockage in network NW2 as an anomaly. The path blockage includes a physical path blockage, caused by cutting transmission line 4, and a logical path blockage, caused by adding an unauthorized filter device to transmission line 4, which blocks or discards some or all of the messages.
[0142] For example, the detection device 304 detects, as an anomaly in network NW2, the initiation of a rerouting path, which is a transmission path not via switching device 141 and gateway device 122, between networks NW2a and NW2b. The initiation of a rerouting path includes the initiation of a physical rerouting path, which is caused by changing a wiring connection between transmission line 4 in network NW2a and transmission line 4 in network NW2b, and the initiation of a logical rerouting path, which is caused by the initiation of an unauthorized relay or forwarding device that forwards the Ethernet frame transmitted on transmission line 4 in one of networks NW2a or NW2b to transmission line 4 in the other network NW2a or NW2b.
[0143] As described above, communication devices 112C and 112D are capable of communicating with an external network via gateway device 122, while communication devices 112A and 112B are prevented or restricted from being or becoming capable of communicating with the external network. When a diversion path is used between networks NW2a and NW2b, communication devices 112A and 112B are or become capable of communicating with the external network via gateway device 122, switching device 141B, and the diversion path. Therefore, the detection device 304 detects the implementation of the diversion path as an anomaly in network NW2.
[0144] (Transmission of response data generation information G)
[0145] Fig. Figure 9 shows a configuration of the detection device in the detection system according to the second embodiment of the present disclosure. With reference to Fig. The detection device 304 comprises a transmission and reception unit 41, a detection unit 42, and a storage unit 43. Part or all of the transmission and reception unit 41 and the detection unit 42 are implemented, for example, by a processing circuit containing one or more processors. The storage unit 43 is a non-volatile memory, which is included, for example, in the processing circuit described above.
[0146] During the detection period Pd, the detection unit 42 generates a response data generation information G and a verification start command, and outputs the generated response data generation information G and the verification start command to the transmission and reception unit 41.
[0147] For example, at a transmission time ta, the detection unit 42 in the detection device 304A, 304C generates response data generation information Ga, Gc and a verification start command and outputs the generated response data generation information Ga, Gc and the verification start command to the transmission and reception unit 41, and at a transmission time tb, different from the transmission time ta, the detection unit 42 in the detection device 304B, 304D generates response data generation information Gb, Gd and a verification start command and outputs the generated response data generation information Gb, Gd and the verification start command to the transmission and reception unit 41.
[0148] The transmission and reception unit 41 transmits the response data generation information G to corresponding response devices 104, 105 via transmission line 3. More specifically, the transmission and reception unit 41 receives the response data generation information Ga from the detection unit 42 in the detection device 304A, causes the received response data generation information Ga and the verification start command to be contained in one message, and transmits the message to the response devices 104, 105 via transmission line 3A. (Transmission of response data R)
[0149] The following describes a transmission of response data R, which is carried out by the response devices 104 and 105. The content concerning a transmission of response data R below is common to, and applies between, the response devices 104A, 104B, 104C, 104D, 105A, 105B, 105C, and 105D, unless otherwise specified or indicated.
[0150] Fig. Figure 10 shows a configuration of the response device in the detection system according to the second embodiment of the present disclosure. With reference to Fig. The response device 104 comprises a connecting switch 50 and a response unit 60. The response unit 60 includes a communication unit 61, a processing unit 63, and a storage unit 64. The communication unit 61 is an example of a receiving unit and a transmission unit. The processing unit 63 is an example of a generating unit. Part or all of the communication unit 61 and the processing unit 63 are implemented, for example, by a processing circuit containing one or more processors. The storage unit 64 is a non-volatile memory, which is included, for example, in the processing circuit described above. The storage unit 64 stores a key piece of information K, which is unique to the response device 104.The connecting switch 50 connects and disconnects the switching device 141 from the transmission line 4. The communication unit 61 and the switching device 141 may or may not be connected to each other via the connecting switch 50, or the connection state between them may be switchable. The transmission line 4 and the communication unit 61 may always be connected to each other via the connecting switch 50, or they may be disconnected from each other in a state where the transmission line 4 and the switching device 141 are connected.
[0151] The response device 105 includes a connecting switch 70 and a response unit 80. The response unit 80 includes a communication unit 81, a processing unit 83, and a storage unit 84. The communication unit 81 is an example of a receiving unit and a transmission unit. The processing unit 83 is an example of a generating unit. Part or all of the communication unit 81 and the processing unit 83 are implemented, for example, by a processing circuit that includes one or more processors. The storage unit 84 is a non-volatile memory, which is included, for example, in the processing circuit described above. The storage unit 84 stores a key piece of information K that is unique to the response device 105.The connecting switch 70 connects and disconnects the communication device 112 from and to the transmission line 4. The communication unit 81 and the communication device 112 may or may not be connected to each other via the connecting switch 70, or the connection state between them may be switchable. The transmission line 4 and the communication unit 81 may always be connected to each other via the connecting switch 70, or they may be disconnected from each other in a state where the transmission line 4 and the communication device 112 are connected.
[0152] The processing unit 63 in the response device 104 outputs a control signal to the connecting switch 50, enabling it to switch the state of the connecting switch 50 between a first state, where the transmission line 4 and the switching device 141 are electrically connected, and a second state, where the transmission line 4 and the switching device 141 are not connected and the transmission line 4 and the communication unit 61 are electrically connected. The processing unit 63 sets the state of the connecting switch 50 to the first state during a communication period Pc, which is a period in which communication is carried out using the transmission line 4.
[0153] The processing unit 83 in the response device 105 outputs a control signal to the connecting switch 70, enabling it to switch the state of the connecting switch 70 between a third state, where the transmission line 4 and the communication device 112 are electrically connected, and a fourth state, where the transmission line 4 and the communication device 112 are not connected and the transmission line 4 and the communication unit 81 are electrically connected. The processing unit 68 sets the state of the connecting switch 70 to the third state in the communication period Pc.
[0154] In the response device 105, the communication unit 81 receives a message from the detection device 304 via the transmission line 3 and acquires response data generation information G from the received message. The communication unit 81 outputs the acquired response data generation information G to the processing unit 83. The processing unit 83 receives the response data generation information G from the communication unit 81 and outputs a control signal to the connecting switch 70, thereby switching the state of the connecting switch 70 to the fourth state described above. Additionally, using the response data generation information G and the key information K in the storage unit 84, the processing unit 83 generates response data R, which includes the ID of the generation source response device 105.
[0155] In the response device 104, the communication unit 61 receives a message from the detection device 304 via the transmission line 3 and acquires response data generation information G from the received message. The communication unit 61 outputs the acquired response data generation information G to the processing unit 63. The processing unit 63 receives the response data generation information G from the communication unit 61 and outputs a control signal to the connecting switch 50, thereby switching the state of the connecting switch 50 to the second state described above. Additionally, using the response data generation information G and the key information K in the storage unit 64, the processing unit 63 generates response data R, which contains the ID of the generation source response device 104.Additionally, the processing unit 63 issues a transmission command to the communication unit 61, indicating that the response data R is to be transmitted. The communication unit 61 ensures that the transmission command received from the processing unit 63 is contained in or received within an Ethernet frame and transmits the Ethernet frame to the response device 105 via the connecting switch 50 and the transmission line 4.
[0156] In the responder unit 105, the communication unit 81 receives the Ethernet frame from the responder unit 104 via transmission line 4 and the connecting switch 70, detects the transmission command from the received Ethernet frame, and outputs the detected transmission command to the processing unit 83. The processing unit 83 receives the transmission command from the communication unit 81 and outputs the response data R, which was generated by using the response data generation information G and the key information K, to the communication unit 81. The communication unit 81 causes the response data R, which was received from the processing unit 63, to be included in an Ethernet frame and transmits the Ethernet frame to the responder unit 104 via the connecting switch 70 and the transmission line 4.Response device 104 can be configured not to transmit the transmission command to response device 105. In this case, response device 105 receives a message containing response data generation information G from detection device 304 and spontaneously transmits the response data R to response device 104.
[0157] In the response device 104, the communication unit 61 acquires the response data R from the Ethernet frame, which was received via transmission line 4 and connection switch 50 during the receive period TRa, and outputs the acquired response data R to the processing unit 63. The processing unit 63 receives the response data R from the communication unit 61 and performs a predetermined process on the received response data R and the generated response data R to create aggregation data Rx2, which has a data set smaller than the total value of the data sets of the two pieces or elements of response data R. The processing unit 63 outputs the generated aggregation data Rx2 to the communication unit 61. The communication unit 61 then generates or...generates a message containing the aggregation data Rx2 received by the processing unit 63 and transmits the generated message to the detection device 304 via transmission line 3. (Detection process)
[0158] Again, with reference to Fig. 9. The transmission and reception unit 41 in the detection device 304 receives the aggregation data Rx2 via transmission line 3. This data aggregates or collects fragments or elements of response data R generated by the response devices 104 and 105. Based on the reference information RF2, which is based on the configuration of the network NW2, and the aggregation data Rx2 received by the transmission and reception unit 41, the detection unit 42 performs a detection process to detect an anomaly in the network NW2. The detection process, which is carried out in the detection device 304A, will be described representatively below.
[0159] For example, the storage unit 43 in the detection device 304A stores the reference information RF2a, which indicates two types of key information K of the response devices 104A, 105A, which are connected to the transmission line 4A.
[0160] The transmission and reception unit 41 in the detection device 304A receives a message from the response device 104 via the transmission line 3A. The transmission and reception unit 41 acquires aggregation data Rx2a from the received message and outputs the acquired aggregation data Rx2a to the detection unit 42.
[0161] Using the response data generation information Ga, which was transmitted to the response devices 104A, 105A via the transmission and reception unit 41, and the pieces or elements of key information K in the storage unit 43, the detection unit 42 generates two pieces or elements of generation data Ma corresponding to two pieces of response data Ra, each corresponding to the response devices 104A, 105A, which are connected to the transmission line 3A.
[0162] The detection unit 42 checks the aggregation data Rx2a, received by the transmission and reception unit 41, against the generation data Ma according to the response device 104A and the generation data Ma according to the response device 105A. For example, if at least one of the two response data pieces Ra aggregated in the aggregation data Rx2a does not match the corresponding generation data Ma, the detection unit 42 determines that the detection condition C1 is met. Conversely, if the two response data pieces Ra aggregated in the aggregation data Rx2a received by the transmission and reception unit 41 each match the two generated generation data pieces Ma, the detection unit 42 determines that the detection condition C1 is not met.
[0163] If the number of pieces or elements of response data R that are aggregated in the aggregation data Rx2a is not two, detection unit 42 determines that the detection condition C2 is met. Conversely, if the number of pieces of response data R that are aggregated in the aggregation data Rx2a is two, detection unit 42 determines that the detection condition C2 is not met.
[0164] The detection unit 42 confirms the presence or absence of response data R received by the transmission and reception unit 41 in a period different from the reception period TRa. For example, if there is response data R received by the transmission and reception unit 41 separately from the aggregation data Rx2a, the detection unit 42 determines that the detection condition C3 is met. Conversely, if there is no response data R received by the transmission and reception unit 41 separately from the aggregation data Rx2a, the detection unit 42 determines that the detection condition C3 is not met.
[0165] In the detection process, the detection unit 42 detects an anomaly in the network NW2a based on the result of a determination of whether the detection conditions C1, C2, or C3 are met. More specifically, if it has been determined that at least one of the detection conditions C1, C2, or C3 is met, the detection unit 42 determines that an anomaly has occurred in the network NW2a.
[0166] For example, if detection condition C1 is met, detection unit 42 determines that an unauthorized device, masking or posing as a response device 104A, 105A, is present. For example, if detection condition C2 is met and the number of response data pieces R aggregated in the aggregation data Rx2a is less than two, detection unit 42 determines that a path blockage has occurred in network NW2a. For example, if detection condition C2 is met and the number of response data pieces R aggregated in the aggregation data Rx2a is greater than two, or if detection condition C3 is met, detection unit 42 determines that a rerouting path has been implemented in network NW2a.
[0167] If an anomaly has been determined to have occurred in the NW2a network, the detection unit 42 ensures that anomaly information indicating the occurrence of an anomaly is included in a message and transmits the message to the responding devices 104A and 105A via transmission line 3A. Additionally, the detection unit 42 notifies the user of the detection system 404 of the anomaly in the NW2a network by means of an audible signal or a visual indication. The detection unit 42 can be configured to omit one or both of the transmissions of the anomaly information to the responding devices 104A and 105A and the notification to the user.The detection unit 42 can be configured to transmit, via a network (not shown), a message indicating that an anomaly has occurred in the network NW2a to a user-owned terminal.
[0168] Again, with reference to Fig. 10 disconnects, for example, when the anomaly information is received from the detection device 304A via the transmission line 3A and the communication unit 81, the processing unit 83 in the response device 105A disconnects the electrical connection between the transmission line 4A and the communication device 112A at the connection switch 70. The processing unit 83 can be configured not to disconnect the electrical connection between the transmission line 4A and the communication device 112A.
[0169] In the response device 104, the processing unit 63 can be configured to output the response data R, which is generated in the response device 105, and the response data R generated by the processing unit 63, to the communication unit 61, instead of generating the aggregation data Rx2. In this case, the communication unit 61 generates a message containing two pieces or elements of response data R received from the processing unit 63 and transmits the generated message to the detection device 304 via transmission line 3.
[0170] Additionally, similar to the detection device 304, the response device 104 can be configured to detect an anomaly in the network NW2a, NW2b based on the number of pieces of response data R received by the response device 104 and the time of receipt of the response data R.
[0171] The detection system 404 can be configured to include, in addition to or instead of the responding devices 104, 105, and the detection device 304: two responding devices, each fixed to the gateway device 122 and the switching device 141, respectively, and connected to each other via a transmission line 5; and a detection device that detects an anomaly in the network comprising the gateway device 122, the switching device, and the transmission line 5. In this case, the detection device detects a path blockage and the initiation of a diversion path between the gateway device 122 and the switching device based on the response data R received by the two responding devices.
[0172] As described above, the detection system 404 does not necessarily have to include four detection devices 304 and can be configured to include a single detection device 304 that monitors all networks NW2. In this case, this detection device 304 transmits a response data generation information Ga to the response devices 104A and 105A via transmission line 3A, transmits a response data generation information Gb to the response devices 104B and 105B via transmission line 3B, transmits a response data generation information Gc to the response devices 104C and 105C via transmission line 3C, and transmits a response data generation information Gd to the response devices 104D and 105D via transmission line 3D.Then the detection device 304 detects an anomaly in the network NW2a, based on the reference information RF2a and the aggregation data Rx2a, Rx2b, and detects an anomaly in the network NW2b, based on the reference information RF2b and the aggregation data Rx2c, Rx2d. (Modification 3)
[0173] Fig. Figure 11 shows a configuration of a detection system according to a modification or adaptation 3 of the second embodiment of the present disclosure. With reference to Fig. 11, compared to the detection system 404, includes the detection system 405 a detection device 305 instead of the detection device 304, includes response devices 106A, 106B, 106C, 106D, each of which is a response device 106, instead of the response devices 104A, 104B, 104C, 104D, and includes response devices 107A, 107B, 107C, 107D, each of which is a response device 107, instead of the response devices 105A, 105B, 105C, 105D.
[0174] The detection device 305 is or will be connected to the gateway device 122 via a transmission line 6. The transmission line 6 is, for example, an Ethernet cable.
[0175] During detection period Pd, detection device 305 transmits response data generation information G, which is to be used when generating response data R, to response devices 106 and 107. More specifically, detection device 305 defines detection periods Pda, Pdb, Pdc, and Pdd, which are obtained by subdividing detection period Pd into four. During detection period Pda, detection device 305 ensures that response data generation information Ga is included in an Ethernet frame and transmits the Ethernet frame to response devices 106A and 107A via multicasting. During the detection period Pdb, the detection device 305 causes a response data generation information Gb to be included in an Ethernet frame and transmits the Ethernet frame to the response devices 106B, 107B by multicasting.During detection period Pdc, detection device 305 causes response data generation information Gc to be included in an Ethernet frame and transmits the Ethernet frame to response devices 106C and 107C via multicasting. During detection period Pdd, detection device 305 causes response data generation information Gd to be included in an Ethernet frame and transmits the Ethernet frame to response devices 106D and 107D via multicasting.
[0176] Fig. Figure 12 shows a configuration of the response device in the detection system according to modification 3 of the second embodiment of the present disclosure. With reference to Fig. Compared to response device 104, response device 106 includes a relay or forwarding unit 51 instead of the connecting switch 50. Compared to response device 105, response device 107 includes a relay or forwarding unit 71 instead of the connecting switch 70. The relay units 51 and 71 perform a relay or forwarding process of forwarding an Ethernet frame.
[0177] Again, with reference to Fig. 11. The responding device 106 receives response data generation information G from the detection device 305 via the gateway device 122 and a corresponding switching device 141, and generates response data R based on the received response data generation information G. The responding device 106 causes the generated response data R to be contained in an Ethernet frame and transmits the Ethernet frame to the detection device 305 via a corresponding switching device 141 and the gateway device 122.
[0178] The responding device 107 receives response data generation information G from the detection device 305 via the gateway device 122, a corresponding switching device 141, and a corresponding responding device 106, and generates response data R based on the received response data generation information G. The responding device 107 causes the generated response data R to be contained in an Ethernet frame and transmits the Ethernet frame to the detection device 305 via a corresponding responding device 106, a corresponding switching device 141, and the gateway device 122.
[0179] Similar to detection device 304, detection device 305 detects an anomaly in network NW2 based on reference information RF2, which is based on the configuration of network NW2, and fragments or elements of response data R, which were transmitted by response devices 106 and 107, respectively. In contrast to detection system 404, detection system 405 can detect an anomaly in network NW2 without using transmission line 3.
[0180] The detection system 405 can be configured to include, in addition to or instead of the response devices 106 and 107, two response devices, each fixed at the gateway device 122 and the switching device 141, respectively, and connected to each other via a transmission line 5. In this case, the detection device 305 detects a path blockage and the initiation of a diversion path between the gateway device 122 and the switching device based on the response data R received by the two response devices. [Operational process]
[0181] Fig. Figure 13 shows an example of the sequence of the detection process which is carried out in the detection system according to the second embodiment of the present disclosure. Fig. Figure 13 shows the detection process which is carried out in the detection device 304A.
[0182] With reference to Fig. 13 first transmits, upon occurrence of the transmission time ta, the detection device 304A a response data generation information Ga to the response devices 104A, 105A via the transmission line 3A (step S31).
[0183] Next, the response device 104A switches the state of the connecting switch 50 to the second state, which is described above. The response device 105A switches the state of the connecting switch 70 to the fourth state, which is described above (step S32).
[0184] Next, the response devices 104A and 105A each generate response data Ra using the response data generation information Ga received from the detection device 304A and the key information K (step S33).
[0185] Next, the responding device 104A transmits a transmission command to the responding device 105A via transmission line 4A (step S34).
[0186] Next, the responding device 105A receives the transmission command and transmits response data Ra to the responding device 104A via the transmission line 4A (step S35).
[0187] Next, the responding device 104A generates aggregation or collection data Rx2a, in which the response data Ra received from the responding device 105A and the generated response data Ra are aggregated or collected (step S36).
[0188] Next, the response device 104A transmits the generated aggregation data Rx2a to the detection device 304A via the transmission line 3A (step S37).
[0189] Next, the detection device 304A performs the detection process based on the reference information RF2a, which is based on the configuration of the network NW2a, and the aggregation data Rx2A, which was received by the corresponding response device 104A (step S38).
[0190] Fig. Figure 14 shows an example of the sequence of the detection process which is carried out in the detection system according to modification 3 of the second embodiment of the present disclosure.
[0191] With reference to Fig. 14 first causes the detection device 305, upon occurrence of the transmission time ta, to receive or contain a response data generation information Ga in an Ethernet frame, and transmits the Ethernet frame by multicasting to the response devices 106A, 107A (step S41).
[0192] Next, the response devices 106A and 107A each generate response data Ra using the response data generation information Ga received from the detection device 305 and the key information K (step S42).
[0193] Next, the response device 106A causes the generated response data R to be included in an Ethernet frame and transmits the Ethernet frame to the detection device 305 via the switching device 141A and the gateway device 122 (step S43).
[0194] The response device 107A causes the generated response data R to be included in an Ethernet frame and transmits the Ethernet frame to the detection device 305 via the response device 106A, the switching device 141A and the gateway device 122 (step S44).
[0195] Next, the detection device 305 performs the detection process based on the reference information RF2a, which is based on the configuration of the network NW2a, and the pieces or elements of response data Ra, which were received by the response devices 106A and 107A respectively (step S45).
[0196] The disclosed embodiments are purely illustrative in all aspects and should not be considered or interpreted as limiting. The scope of this disclosure is defined more by the scope of the claims than by the above description, and it is intended to encompass a meaning equivalent to the scope of the claims and all modifications or variations within that scope.
[0197] The above description includes the features in the additional note below. [Additional Note 1]
[0198] A detection system, including: a detection device; and a response device, wherein The detection device transmits response data generation information, which is to be used when generating response data, to the response device via a first transmission path. The responding device transmits the response data, based on the response data generation information received from the detection device, to the detection device via a second transmission path. Based on reference information derived from a network configuration and response data transmitted by the responding device, the detection device detects an anomaly in the network. the first transmission path is a leased line, which is used when an anomaly is detected in the network, the second transmission path is a main transmission path for transmitting a main signal in the network, and The network includes the response device and the second transmission path. REFERENCE MARK LIST 1, 1A, 1B, 2, 2A, 2B, 2C, 3, 3A, 3B, 3C, 3D, 4, 4A, 4B, 4C, 4D, 5, 5A, 5B, 6 transmission line 2A1, 2A2 transmission path or route 10 connection unit 20 answer units 21 receiving unit 22 transmission unit 23 Processing unit (production unit) 24 storage units 31 transmission unit 32 receiver units 33 Detection unit 34 storage units 41 Transmission and reception unit (transmission unit, reception unit) 42 Detection unit 43 storage units 50 connecting switches 51 Relay or forwarding unit 60 response units 61 Communication unit (transmission unit, receiving unit) 63 Processing unit (production unit) 64 storage units 70 connecting switches 71 Relay or forwarding unit 80 response units 81 Communication unit (transmission unit, receiving unit) 83 Processing unit (production unit) 84 storage units 101, 101A, 101B, 102, 102A, 102C, 103A, 104, 104A, 104B, 104C, 104D, 105, 105A, 105B, 105C, 105D, 106, 106A, 106B, 106C, 106D, 107, 107A, 107B, 107C, 107D Response Device 111, 111A, 111B, 111C, 112, 112A, 112B, 112C, 112D Communication device or apparatus 121, 122 Gateway device 141, 141A, 141B Switching device 201, 201A, 201B Aggregation or collection device 301, 301A, 301B, 302, 303, 304, 304A, 304B, 304C, 304D, 305 detection device 401, 402, 403, 404, 405 detection system NW, NWa, NWb, NWc, NW1a, NW2, NW2a, NW2b Network QUOTES INCLUDED IN THE DESCRIPTION
[0000] This list of documents cited by the applicant was automatically generated and is included solely for the reader's convenience. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions. Cited patent literature
[0000] JP 2023-125266
[0002] JP 2003-191804 [0003, 0004]
Claims
[1] Detection system, comprising: a response device; and a detection device configured to detect an anomaly in a network, which includes the response device and a transmission path, wherein The detection device transmits response data generation information, which is to be used when generating response data, to the response device via a first transmission path. The responding device generates the response data based on the response data generation information received from the detection device and transmits the generated response data to the detection device via a second transmission path. The detection device detects an anomaly in the network based on reference information derived from a network configuration and response data transmitted by the responding device. at least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network. [2] Detection system according to claim 1, wherein the first transmission path is the main transmission path and the second transmission path is a leased line which is used when an anomaly is detected in the network, or the second transmission path is the main transmission path and the first transmission path is a leased line which is used when an anomaly is detected in the network. [3] Detection system according to claim 2, wherein the first transmission path is the leased line, and The second transmission path is the main transmission path. [4] Detection system according to one of claims 1 to 3, wherein The responding device generates the response data, further based on unique information from the responding device, and transmits the generated response data to the detection device via the second transmission path. The reference information contains the unique information, and The detection device generates generation data based on the unique information contained in the reference information and the response data generation information transmitted to the response device, verifies the received response data against the generation data, and detects an anomaly in the network based on the result of the verification. [5] Detection device according to any one of claims 1 to 4, wherein The detection device detects an anomaly in the network based on the number of pieces of the received response data. [6] The one according to any one of claims 1 to 5, wherein The detection device detects an anomaly in the network based on the time of receipt of the received response data. [7] Detection system according to any one of claims 1 to 6, wherein When using a physical transmission line that is shared, the first transmission path, which is a logical path, and the second transmission path, which is also a logical path, are provided, and The detection device and the response device multiplex the response data generation information and the response data on the transmission line in order to transmit the response data generation information and the response data. [8] Detection system according to any one of claims 1 to 7, further comprising an aggregation device, wherein The aggregation device generates aggregation data in which a plurality of pieces of the response data, each generated by a plurality of response devices, are aggregated or collected, and transmits the generated aggregation data to the detection device. [9] Detection system, comprising: a first response device; a second response device; and a detection device configured to detect an anomaly in a network comprising the first response device, the second response device and a transmission path, wherein The detection device transmits response data generation information, which is to be used when generating response data, to the first response device and the second response device via a first transmission path. The first responding device generates initial response data, which is the response data, based on the response data generation information received from the detection device, and transmits the generated initial response data to the second responding device via a second transmission path. The second responding device generates second response data, which are the response data, based on the response data generation information received from the detection device, and transmits the generated second response data and the first response data received from the first responding device to the detection device. The detection device detects an anomaly in the network based on reference information derived from a network configuration, the first response data transmitted by the first response device, and the second response data transmitted by the second response device. at least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network. [10] Detection device comprising: a transmission unit configured to transmit response data generation information, to be used when generating response data, to a response device in a network via a first transmission path; a receiving unit configured to receive, via a second transmission path, the response data based on the response data generation information transmitted by the responding device; and a detection unit configured to detect an anomaly in the network based on reference information derived from a network configuration and response data received by the receiving unit, wherein at least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network. [11] Response device which is fixed to a communication device in a network, the response device comprises: a receiving unit configured to receive, via a first transmission path, response data generation information to be used in generating response data from a detection device configured to detect an anomaly in the network; a generation unit configured to generate the response data based on the response data generation information received by the receiving unit; and a transmission unit configured to transmit the response data generated by the generation unit to another device via a second transmission path, wherein at least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network. [12] Response device comprising: a receiving unit configured to receive, via a first transmission path, response data generation information to be used in generating response data from a detection device configured to detect an anomaly in the network; a generation unit configured to generate the response data based on the response data generation information received by the receiving unit; and a transmission unit configured to transmit the response data generated by the generation unit to another device via a second transmission path, wherein the first transmission path is a main transmission path for transmitting a main signal in the network and the second transmission path is a leased line used when an anomaly is detected in the network, or the second transmission path is the main transmission path and the first transmission path is a leased line used when an anomaly is detected. [13] Detection method which is carried out in a detection system which includes a response device and a detection device which detects an anomaly in a network which includes the response device and a transmission path, wherein the transmission method comprises: a step which is carried out by the detection device, of transmitting response data generation information, which is to be used in generating response data, to the response device via a first transmission path; a step performed by the responding device, namely generating the response data based on the response data generation information received from the detection device, and transmitting the generated response data to the detection device via a second transmission path; and a step which is performed by the detection device, of detecting an anomaly in the network, based on reference information which is based on a configuration of the network, and the response data which was transmitted by the responding device, wherein at least one of the first transmission path and the second transmission path includes a main transmission path for transmitting a main signal in the network.
Citation Information
Patent Citations
Communication system for vehicle
JP2003191804A
Repair support system
JP2023125266A
2003-191804
JAPANISCHENPATENTANMELDUNGNR.2023-125266