Log determination device, log determination method, log determination program, and log determination system
Patent Information
- Application Number
- JP2022157425
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2025-06-30
- Estimated Expiration
- 2042-09-30
AI Technical Summary
Existing log analysis systems in vehicles are compromised by the inclusion of maintenance-related logs, which can decrease the accuracy of cyber attack analysis due to the mixing of logs from both cyber attacks and maintenance activities.
A log determination device that includes a log acquisition unit, a pattern storage unit, and a false positive log determination unit to identify and separate maintenance-related false positive logs from actual cyber attack logs by comparing security logs with predicted maintenance patterns.
Improves the accuracy of cyber attack analysis by distinguishing between maintenance-related logs and genuine cyber attack logs, thereby enhancing the reliability of security log analysis.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to a device for judging security logs generated in an electronic control system, and to a log judgment device, a log judgment method, a log judgment program, and a log judgment system. [Background technology]
[0002] In recent years, technologies for driving assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication and vehicle-to-infrastructure communication), have been attracting attention. As a result, vehicles are equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyber attacks such as unauthorized access is increasing. Therefore, there is an increasing need to analyze cyber attacks against vehicles and develop countermeasures.
[0003] For example, Patent Document 1 discloses a device that prevents the intrusion of unauthorized information by using the results of a determination of whether the defense functions and functions other than the defense functions installed in the electronic control device are normal or abnormal when the electronic control device detects an abnormality, to determine measures to block unauthorized information. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2022-17873 A Summary of the Invention [Problem to be solved by the invention]
[0005] Here, the present inventors have found the following problem as a result of detailed investigation. Anomalies that occur in a vehicle include not only anomalies caused by a cyberattack, but also anomalies caused by reasons other than a cyberattack. For example, when vehicle maintenance is performed, the electronic control system is in a different state during or immediately after the maintenance, and the sensor may determine this as an anomaly and generate a log. Therefore, the collected logs may contain a mixture of logs related to anomalies caused by such maintenance as well as logs related to anomalies caused by a cyberattack. However, if a cyberattack is analyzed in a state where such logs are mixed, the accuracy of the analysis may be reduced.
[0006] Therefore, an object of the present invention is to determine whether a log generated by a sensor is a log generated as a result of performing maintenance. [Means for solving the problem]
[0007] The log determination device (10, 11) of the present disclosure includes a log acquisition unit (101) that acquires a plurality of security logs each including anomaly information indicating an anomaly detected in an electronic control system and location information indicating the location within the electronic control system where the anomaly was detected; a pattern storage unit (103) that stores an occurrence pattern of security logs predicted to occur due to maintenance of the electronic control system, the occurrence pattern consisting of a plurality of sets each including predicted anomaly information indicating an anomaly predicted to be detected in the electronic control system and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly will be detected; and a false positive log determination unit (104) that compares the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated due to the detection of an anomaly caused by the maintenance, and outputs a determination result.
[0008] In addition, the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. Effect of the Invention
[0009] According to the configuration described above, it is possible to determine whether or not a log generated by the electronic control system is a log related to an abnormality that occurred due to vehicle maintenance, and by analyzing a cyber attack taking into account the determination result, it is possible to improve the accuracy of the cyber attack analysis. [Brief description of the drawings]
[0010] [Figure 1] FIG. 2 is an explanatory diagram illustrating the arrangement of a log determination device and an electronic control device system according to each embodiment. [Diagram 2] FIG. 2 is an explanatory diagram illustrating the configuration of an electronic control system and an electronic control device according to each embodiment. [Diagram 3] FIG. 2 is an explanatory diagram for explaining a security log generated by a security sensor of an electronic control device according to each embodiment. [Figure 4] FIG. 1 is a block diagram showing an example of the configuration of a log determination device according to a first embodiment. [Diagram 5] FIG. 1 is a diagram for explaining information stored in a log storage unit according to the first embodiment. [Figure 6] FIG. 1 is a diagram for explaining information stored in a pattern storage unit according to the first embodiment; [Figure 7] FIG. 1 is a diagram for explaining information stored in a pattern storage unit according to the first embodiment; [Figure 8] FIG. 1 is a diagram for explaining the operation of the log determination device according to the first embodiment. [Figure 9] FIG. 1 is a diagram for explaining the operation of the log determination device according to the first embodiment. [Figure 10] FIG. 11 is a block diagram showing a configuration example of a log determination device according to a second embodiment. [Figure 11] FIG. 10 is a diagram for explaining a method for determining a log according to the second embodiment; [Figure 12] FIG. 10 is a diagram for explaining a method for determining a log according to the second embodiment; [Figure 13] FIG. 11 is a diagram for explaining the operation of the log determination device according to the second embodiment. [Figure 14] FIG. 11 is a diagram for explaining the operation of the log determination device according to the second embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0012] The present invention means the invention described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks mean the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.
[0013] The configurations and methods described in the dependent claims are optional configurations and methods in the invention described in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, and the configurations and methods described only in the embodiments without being described in the claims, are optional configurations and methods in the present invention. The configurations and methods described in the embodiments when the description of the claims is broader than the description of the embodiments are also optional configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In either case, by being described in the independent claims, they become essential configurations and methods of the present invention.
[0014] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention possesses.
[0015] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in each of the multiple embodiments may be collected and combined.
[0016] The problem described in the section on problems that the invention is intended to solve is not a publicly known problem, but was discovered independently by the inventor, and this, together with the configuration and method of the present invention, is a fact that affirms the inventive step of the invention.
[0017] 1. Configuration underlying each embodiment (1) Arrangement of the log determination device 10 and the electronic control system S The log determination system 1 is a system composed of a log determination device 10 and an electronic control device 20 constituting an electronic control system S. The arrangement of the log determination device 10 in each embodiment constituting the log determination system 1 will be described with reference to FIG. 1. For example, as shown in FIG. 1(a) and FIG. 1(b), the log determination device 10 is "mounted" on a vehicle, which is a "moving body", together with the electronic control device 20 constituting the electronic control system S, and as shown in FIG. 1(c), the electronic control device 20 constituting the electronic control system S is "mounted" on a vehicle, which is a "moving body", and the log determination device 10 is realized by a server device or SOC (Security Operation Center) provided outside the vehicle.
[0018] Here, the term "mobile body" refers to an object that can move and can move at any speed. It also includes cases where the moving body is stationary. For example, it includes, but is not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these vehicles. In addition, "mounted" includes not only the case where the device is directly fixed to the moving body, but also the case where the device is not fixed to the moving body but moves with the moving body, such as the case where the device is carried by a person riding on the moving body, or the case where the device is mounted on cargo placed on the moving body.
[0019] In the example shown in Fig. 1(a), the log determination system 1 can also be said to be an electronic control system S. In the example shown in Fig. 1(c), the log determination system 1 is a system including a log determination device 10 provided outside the vehicle and electronic control systems S mounted on each of a plurality of vehicles.
[0020] The log judgment device 10 is a device that acquires security logs from a plurality of electronic control units (hereinafter referred to as ECUs (Electronic Control Units)) 20 that constitute an electronic control system S, and judges the logs.
[0021] Fig. 2 is a diagram showing an example of the configuration of an electronic control system S. The electronic control system S is made up of multiple ECUs 20. Fig. 2 shows an example of five ECUs (ECU 20a to ECU 20e), but the electronic control system S may of course be made up of any number of ECUs. In the following explanation, when describing a single or multiple electronic control devices as a whole, they will be referred to as ECU 20 or each ECU 20, and when describing each individual electronic control device specifically, they will be referred to as ECU 20a, ECU 20b, ECU 20c, ....
[0022] 2, each of the ECUs 20a, 20c, 20d, and 20e has a security sensor 201. In contrast, the ECU 20b does not have a security sensor. In this way, it is sufficient that the multiple ECUs 20 constituting the electronic control system S are equipped with a security sensor, and it is not necessary that all of the ECUs 20 are equipped with a security sensor. The ECU 20 further has a log transmission unit 202 that transmits a security log generated by the security sensor.
[0023] The security sensor 201 (corresponding to a "log generating unit") generates a security log when it detects an abnormality that occurs in the electronic control system, for example, in the ECU 20 or in a network connected to the ECU 20. A security sensor that monitors communications on the network in the electronic control system S and detects abnormalities related to the content and frequency of communications is also called a network-type IDS (Intrusion Detection System). The log transmission unit 202 “transmits” the security log generated by the security sensor 201 to the log judgment device 10 .
[0024] Here, "transmit" may refer to transmission using either wired communication or wireless communication. In addition, transmission using wireless communication also includes transmission via a device having a communication function.
[0025] In each embodiment described below, an example is given in which the security log is a log generated by the security sensor 201 shown in Fig. 2. However, the security log in the present disclosure may be a log generated by a function called in-vehicle Security Information and Event Management (SIEM), which collects and manages information related to events that occur in an electronic control system.
[0026] The electronic control system S can be configured with any ECU. For example, the ECUs include a drive system electronic control device that controls an engine, a steering wheel, a brake, etc., a vehicle body electronic control device that controls a meter, a power window, etc., an information system electronic control device such as a navigation device, or a safety control system electronic control device that performs control to prevent collision with an obstacle or a pedestrian. The ECUs may be classified into a master and a slave, not parallel to each other. The electronic control system S may also be provided with a gateway ECU or a central ECU (C-ECU) that connects the electronic control devices to each other, and an external communication ECU that communicates with the outside. For example, the ECU 20a may be an external communication ECU, and the ECUc may be a C-ECU. Message authentication may be used for communication between the ECUs 20 to prevent spoofing by a third party. The ECU 20 may be a physically independent ECU, or may be a virtually realized virtual ECU (also called a virtual machine).
[0027] 1(a) and 1(b), the log determination device 10 and each ECU 20 are connected via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the connection may be made using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). Note that the term "connection" refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual machines realized on the same hardware are virtually connected to each other.
[0028] FIG. 1(a) shows an independent log judgment device 10 provided inside an electronic control system S, or the function of the log judgment device 10 is built into at least one of the ECUs 20 constituting the electronic control system S, such as a C-ECU or an external communication ECU.
[0029] FIG. 1(b) shows a log determination device 10 provided outside the electronic control system S, but from the viewpoint of the connection form, it is substantially the same as FIG. 1(a).
[0030] In the case of FIG. 1(c), the log determination device 10 is also provided outside the electronic control system S, but since the log determination device 10 is provided outside the vehicle, the connection form is different from that of FIG. 1(a) and FIG. 1(b). The log determination device 10 and the electronic control system S are connected via a communication network such as a wireless communication method such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a LAN (Local Area Network), the Internet, or a fixed telephone line can be used.
[0031] 1(c), one of the ECUs 20 (for example, ECU 20a) aggregates security logs generated by the security sensors 201 of the ECUs 20 and transmits them collectively to the log determination device 10. In this case, ECU 20a corresponds to an Intrusion Detection System Reporter (IDSR) of the specifications defined by AUTOSAR (AUTomotive Open System Architecture). Alternatively, ECU 20a may transmit security logs generated by the security sensors of the ECUs 20 to the log determination device 10 in sequence.
[0032] In the case of Fig. 1(a) and Fig. 1(b), by performing a log judgment process in the vehicle, only security logs that are not judged to be false positive logs (described later) can be transmitted to a server device or the like installed outside the vehicle. This makes it possible to reduce the amount of communication between the vehicle and the server device. Furthermore, since the server device only needs to analyze security logs other than the received false positive logs, the log analysis process in the server device can be suppressed.
[0033] In contrast, in the case of Fig. 1(c), the abundant resources of the server device can be used to execute the log determination process. Furthermore, the log determination process of each embodiment can be realized without installing new devices or programs in existing vehicles.
[0034] In the following embodiments, the arrangement shown in FIG. 1(c) will be described as an example. In each embodiment, the electronic control system S is described as an in-vehicle system mounted on a vehicle, but the electronic control system S is not limited to an in-vehicle system and can be applied to any electronic control system consisting of multiple ECUs. For example, the electronic control system S may be mounted on a stationary body instead of a moving body.
[0035] 1, the log judgment device 10 may be further connected to an attack analysis device (not shown) that analyzes the security log judged by the log judgment device 10 and analyzes cyber attacks made against the vehicle. Alternatively, each function of the log judgment device 10 described below may refer to a function built into the attack analysis device. Hereinafter, a cyber attack will be simply referred to as an attack.
[0036] In addition, in FIG. 1 and the above explanation of (1) related thereto, the log determination device 10 of embodiment 1 is used as an example. However, each arrangement shown in FIG. 1 can also be applied to the log determination device 11 of embodiment 2.
[0037] (2) Security log details FIG. 3 is a diagram showing an example of the contents of a security log generated by the security sensor 201 of the ECU 20. As shown in FIG.
[0038] The security log has fields such as an ECU-ID (corresponding to "location information") indicating identification information of the ECU in which the security sensor 201 is mounted, a sensor ID indicating identification information of the security sensor, an event ID (corresponding to "anomaly information") indicating identification information of an event detected by the security sensor, a counter indicating the number of times the event was detected, a timestamp (corresponding to "time information") indicating the time when the event was detected, and context data indicating details of the output of the security sensor. The security log may further have a header storing information indicating the protocol version and the state of each field.
[0039] According to the specifications defined by AUTOSAR, IdsM Instance ID corresponds to the ECU-ID, Sensor Instance ID corresponds to the sensor ID, Event Definition ID corresponds to the event ID, Count corresponds to the counter, Timestamp corresponds to the timestamp, Context Data corresponds to the context data, and Protocol Version and Protocol Header correspond to the header.
[0040] When the security sensor 201 detects an abnormality in the electronic control system, it generates a security log as shown in FIG. 3, which includes an event ID indicating the detected abnormality.
[0041] In each embodiment described below, a configuration is described in which the security log is judged using an event ID as information indicating an abnormality detected in the electronic control system and an ECU-ID as information indicating the "location" in the electronic control system where the abnormality was detected. However, the information used by the log judgment device 10 to judge the security log is not limited to the event ID and the ECU-ID. For example, information stored in the context data may be used as information indicating an abnormality detected in the electronic control system. Also, a sensor ID may be used as information indicating the location in the electronic control system where the abnormality was detected. Alternatively, when an abnormality is detected in a network, identification information of the network in which the abnormality occurred may be used.
[0042] Here, the "location" refers to, for example, an individual electronic control device, a function installed in the electronic control device, or a network location.
[0043] Fig. 3 is an example of a log that is generated when an abnormality occurs, but a normal log that is generated when no abnormality occurs (for example, when an event is successful) may have the same specifications as Fig. 3. In that case, for example, by using different event IDs for when an abnormality occurs and when an event is successful, it is possible to distinguish between an abnormal log and a normal log. Also, by setting a flag indicating the presence or absence of context data in the header, it is possible to distinguish between an abnormal log and a normal log by checking the flag.
[0044] Also, while FIG. 3 shows a security log generated by the physically independent ECU 20, it may be a security log generated by a virtual ECU.
[0045] (3) Examples of security logs generated by maintenance When performing maintenance on the electronic control system S mounted on a vehicle, the security sensor 201 is expected to generate a specific security log depending on the content of the maintenance. Therefore, below, examples (a) to (d) of maintenance for the electronic control system S and security logs that are expected to be generated by these maintenances are explained. Naturally, the content of the maintenance of the electronic control system S and the security logs generated by the maintenances are merely examples and are not limited to these.
[0046] (a) Maintenance example 1 (ECU replacement) An example of maintenance in which an ECU 20 (e.g., ECU 20c) constituting an electronic control system S is replaced with an ECU 20c2 at a repair shop or dealer will be described. The ECU 20c is an ECU that periodically transmits messages to other ECUs 20. In replacing the ECU 20, it is assumed that a maintenance worker will perform the following tasks (i) to (v).
[0047] (i) An operator replaces the ECU 20c with the ECU 20c2. (ii) When the worker completes the work in (i), the worker turns on the vehicle power and accesses the replaced ECU 20c2 using the initial value of the authentication information of ECU 20c2 to check whether ECU 20c2 operates normally. (iii) The worker sets a new common key in the ECU 20c2 and the ECU 20d by synchronizing with another ECU 20 (for example, the ECU 20d) that performs message authentication using a common key with the ECU 20c2. (iv) The worker changes the authentication information of the ECU 20c2 from the initial value, which has low security, to new authentication information. (v) In order to confirm that the change of the authentication information has been completed, the worker accesses the ECU 20c2 using the initial value of the authentication information. If the worker cannot access the ECU 20c2 using the initial value of the authentication information, the worker assumes that the change of the authentication information of the ECU 20c2 has been completed.
[0048] When the vehicle is turned on in the above operation (ii), the ECU 20c2 transmits a periodic message to the ECU 20d. At this time, the common key held by the ECU 20c2 immediately after the replacement is different from that held by the ECU 20d, so the security sensor 201d of the ECU 20d detects an abnormality indicating a mismatch of the keys and generates a security log (a1). In addition, by performing the above operation (v), the security sensor 201c of the ECU 20c detects an abnormality indicating that access has been made using authentication information (initial value of the authentication information) different from the normal authentication information, and generates a security log (a2).
[0049] As described above, it is predicted that the security logs (a1) and (a2) will be generated as a result of the maintenance for replacing the ECU 20c.
[0050] (b) Maintenance Example 2 (Software Changes) An example of maintenance will be described in which settings of software installed in the ECU 20 are changed. Specifically, the example will be described in which the software installed in the ECU 20 (e.g., ECU 20e) periodically transmits messages to other ECUs 20, and the period during which messages are transmitted will be changed.
[0051] While the settings of the software installed in the ECU 20e are being changed, the software cannot communicate. Therefore, the security sensor 201 installed in another ECU 20 connected to the ECU 20e uses, for example, an alive monitoring function to detect an abnormality indicating that the ECU 20e is not operating, and generates a security log (b1). After the setting change of the software of the ECU 20e is completed, the software of the ECU 20e resumes sending messages. However, since the communication cycle of data transmitted and received on the in-vehicle network is different from that before the setting change, the security sensor 201 (for example, the security sensor 201c) that monitors the network detects such a change in the communication cycle as an abnormality and generates a security log (b2). Here, by adjusting the settings of the security sensor 201c so that the changed communication cycle is not detected as an abnormality, the security sensor 201c no longer detects the change in the communication cycle as an abnormality. However, another security sensor 201 (for example, security sensor 201d) detects the setting adjustment in the security sensor 201c as an abnormality and generates a security log (b3).
[0052] As described above, it is predicted that the security logs (b1), (b2), and (b3) will be generated by the maintenance that changes the settings of the software of the ECU 20e.
[0053] (c) Maintenance example 3 (adding an ECU) An example of maintenance in which an ECU 20 (for example, ECU 20f) is added to the electronic control system S will be described.
[0054] When a new ECU 20f is added to the electronic control system S, data transmitted by the ECU 20f is communicated to other ECUs 20 via the in-vehicle network. Since this data did not exist before the ECU 20f was added, the security sensor 201 (for example, 201c) detects the communication of data that has not previously existed on the in-vehicle network as an anomaly, and generates a security log (c1). Here, by adjusting the settings of the security sensor 201c so that the data communication by the newly added ECU 20f is not detected as an abnormality, the security sensor 201c no longer detects the abnormality. However, another security sensor 201 (for example, the security sensor 201d) detects the setting adjustment in the security sensor 201c as an abnormality and generates a security log (c2).
[0055] As described above, it is predicted that the security logs (c1) and (c2) will be generated by the maintenance of adding a new ECU 20 to the electronic control system S.
[0056] In this example, an example of maintenance when an ECU is added has been described, but it is expected that a similar security log will be generated when new software is added to the ECU 20.
[0057] (d) Maintenance Example 4 (ECU Removal) An example of maintenance for removing the ECU 20 (for example, the ECU 20e) from the electronic control system S will be described.
[0058] When the ECU 20e is removed from the electronic control system S, the security sensor 201c detects that data from the ECU 20e that should be communicated on the in-vehicle network is not being communicated, as an abnormality, and generates a security log (d1). As in (c) above, by adjusting the settings of the security sensor 201c, the security sensor 201c no longer detects an abnormality. However, another security sensor 201 (for example, security sensor 201d) detects the adjustment in the settings of the security sensor 201c as an abnormality and generates a security log (d2).
[0059] As described above, it is predicted that the security logs (d1) and (d2) will be generated by the maintenance that deletes software from the ECU 20.
[0060] In this example, an example of maintenance when an ECU is added has been described, but it is expected that a similar security log will be generated when new software is added to the ECU 20.
[0061] 2. Embodiment 1 (1) Configuration of the log determination device 10 4 is a block diagram showing the configuration of the log determination device 10 in this embodiment. The log determination device 10 includes a log acquisition unit 101, a log storage unit 102, a pattern storage unit 103, a false positive log determination unit 104, an information attachment unit 105, and a transmission unit 107. The information attachment unit 105 in this embodiment realizes a false positive information attachment unit 106.
[0062] The log acquisition unit 101 acquires a security log generated by a security sensor 201 mounted on the ECU 20. The configuration of the electronic control system S is as described in FIG. 2, and the contents of the security log are as described in FIG.
[0063] When the log judgment device 10 is arranged as shown in Fig. 1(c), the log acquisition unit 101 acquires the security log by receiving it via a communication network using a wireless communication method. As described above, the log acquisition unit 101 may acquire a plurality of aggregated security logs together, or may acquire the generated security logs sequentially.
[0064] The log storage unit 102 is a storage unit that stores the logs acquired by the log acquisition unit 101. Fig. 5 shows an example of information stored in the log storage unit 102. In the example shown in Fig. 5, the log storage unit 102 stores identification information of the vehicle equipped with the electronic control system S (hereinafter, vehicle ID) and identification information of the logs assigned to each security log (hereinafter, log ID) in addition to the ECU-ID, event ID, and detection time included in the security log. For ease of explanation, the log ID shown in Fig. 5 is represented by a combination of the vehicle ID and the order in which the log acquisition unit 101 acquired the logs.
[0065] The pattern storage unit 103 is a storage unit that stores security log occurrence patterns that are predicted to occur due to "maintenance" of the electronic control system S. As described above in 1.(3), when maintenance is performed on the electronic control system S, it is possible to predict that a certain security log will occur depending on the content of the maintenance.
[0066] Here, "maintenance" of an electronic control system refers to making any changes to the electronic control devices that make up the electronic control system, the software installed in the electronic control devices, the network that connects the electronic control devices, etc., and examples of this include deleting, adding, replacing, updating, etc. of electronic control devices.
[0067] FIG. 6 shows an example of information stored in the pattern storage unit 103. In the example of FIG. 6, the pattern storage unit 103 stores a maintenance identification number (hereinafter, maintenance ID), an occurrence pattern, and a prediction period. The occurrence pattern of FIG. 6 is composed of a plurality of sets including a prediction event ID (corresponding to "predicted abnormality information") indicating an abnormality predicted to be detected in the electronic control system S, a prediction ECU-ID (corresponding to "predicted abnormality position information") indicating a "position" in the electronic control system where the predicted abnormality is detected, a predicted number of times indicating the "number of times" the predicted abnormality will occur, and the number of these sets, and an occurrence order of the plurality of sets. In addition, the prediction period shown in FIG. 5 indicates a predicted period from the time when the predicted abnormality is first detected to the time when the predicted abnormality is last detected. Note that the occurrence pattern shown in FIG. 6 is merely an example and is not limited to FIG. 6. For example, the occurrence pattern may be a pattern consisting of only a plurality of sets including a prediction event ID and a prediction ECU-ID.
[0068] The "number of times" may of course be defined by a specific value, but may also be defined by a maximum and / or minimum value.
[0069] 6 shows that after abnormality a is detected once in ECU 20c (occurrence order: 1), abnormality b is detected twice in ECU 20d (occurrence order: 2), and then abnormality b is detected twice in ECU 20e (occurrence order: 3). Furthermore, the predicted period for maintenance ID
[0001] is 20 minutes, which indicates that the predicted period from the time when abnormality a is detected in ECU 20c to the time when abnormality b is detected for the second time in ECU 20e is within 20 minutes.
[0070] 6 indicates that the occurrence pattern in the case of the maintenance ID
[0002] is that the ECU 20a detects the abnormality c two or more times, or the ECU 20b detects the abnormality c two or more times (occurrence order: 1), then the ECU 20d detects the abnormality c two to four times, and the ECU 20e detects the abnormality c two to four times (occurrence order: 2), and then the ECU 20c detects the abnormality b up to five times (occurrence order: 3). Furthermore, the prediction period in the case of the maintenance ID
[0002] is 30 minutes, which indicates that the predicted period from the time when the first abnormality c is detected in the ECU 20a or ECU 20b to the time when the last abnormality b is detected in the ECU 20c is within 30 minutes.
[0071] The pattern storage unit 103 may further store information about a security log (hereinafter, referred to as a non-detection log) that is predicted not to occur due to maintenance of the electronic control system S. Fig. 7 shows an example of information about the non-detection log stored in the pattern storage unit 103. In the example of Fig. 7, the pattern storage unit 103 stores a set including a maintenance ID, a non-detection ECU-ID (corresponding to "predicted non-detection position information") indicating a "position" in the electronic control system where an abnormality is predicted not to be detected due to maintenance, and a non-detection event type (corresponding to "predicted non-detection abnormality information") indicating an abnormality that is predicted not to be detected in the ECU indicated by the non-detection ECU-ID.
[0072] For example, in the case of maintenance ID
[0001] shown in Fig. 7, it is indicated that abnormality c will not be detected by ECU 20a within 20 minutes, which is the prediction period for maintenance ID
[0001] shown in Fig. 6. Also, in the case of maintenance ID
[0002] , it is indicated that abnormality a will not be detected by ECU 20a and abnormality a will not be detected by ECU 20b within 30 minutes, which is the prediction period for maintenance ID
[0002] .
[0073] 6 and 7, the identification information of the ECU (i.e., predicted ECU-ID) is used as the information indicating the position in the electronic control system. However, the occurrence pattern may use the identification information of a security sensor or a network as the information indicating the position in the electronic control system.
[0074] Note that the patterns occurring due to maintenance may differ depending on the type of vehicle (e.g., vehicle type, year, model). Therefore, the pattern storage unit 103 may store occurrence patterns and prediction periods for each vehicle type.
[0075] The occurrence pattern and the prediction period stored in the pattern storage unit 103 are set by the vehicle manufacturer, dealer, repair shop, etc. For example, the occurrence pattern and the prediction period may be set based on a log recorded in a trial work performed for setting the estimated time for completing maintenance work at a dealer, etc. and creating a maintenance procedure. The occurrence pattern and the prediction period may further be set based on a security log that occurred during an actual cyber attack or a trial attack simulating an actual cyber attack. For example, even if a security log matches an occurrence pattern predicted to occur due to maintenance, the occurrence pattern and the prediction period may be set so as to avoid the security log matching a pattern predicted to occur during a cyber attack being determined to be a false positive log.
[0076] The false positive log determination unit 104 compares the multiple security logs stored in the log storage unit 103 and the order of occurrence of the multiple security logs with the occurrence pattern stored in the pattern storage unit 103 to determine whether the multiple security logs acquired by the log acquisition unit 101 are false positive logs generated due to the detection of an abnormality caused by maintenance, and outputs the determination result. Here, a false positive log refers to a security log generated by a security sensor detecting an abnormality different from an abnormality caused by an attack on the electronic control system S. In the present disclosure, a false positive log generated by a security sensor detecting an abnormality caused by maintenance of the electronic control system S is determined.
[0077] For example, the false positive log determination unit 104 compares the contents of the security log shown in Fig. 5 with the occurrence pattern shown in Fig. 6. According to Fig. 5 and Fig. 6, the ECU-ID and event ID of the log ID [01-2] shown in Fig. 5 match the predicted ECU-ID and predicted event ID of the set number [1] of the maintenance ID
[0001] shown in Fig. 6. The ECU-ID and event ID of the log IDs [01-3] and [01-4], and the number of security logs (i.e., two) match the predicted ECU-ID and predicted event ID of the set number [2], and the number of predictions. In addition, the ECU-ID and event ID of the log IDs [01-6] and [01-7], and the number of security logs (i.e., two) match the predicted ECU-ID and predicted event ID of the set number [3]. Furthermore, the occurrence order of the log IDs [01-2], [01-3] and [01-4], and [01-6] and [01-7] matches the occurrence order of the occurrence pattern of the maintenance ID
[0001] .
[0078] The false positive log determination unit 104 further compares the period from the detection time (10:00:00) of the log ID [01-2] with the earliest detection time to the detection time (10:14:00) of the log ID [01-7] with the latest detection time among the above security logs with the prediction period shown in Fig. 6. In this case, the period from the detection time (10:00:00) to (10:14:00) falls within the prediction period.
[0079] The false positive log determination unit 104 further determines whether or not a security log corresponding to the non-detection log has been detected between the earliest detection time and the latest detection time. According to Fig. 5, a security log corresponding to the non-detection log shown in Fig. 6 (i.e., abnormality c in ECU 20a) has not been detected.
[0080] Therefore, the false positive log determining unit 104 determines that the security logs with log IDs [01-2], [01-3], [01-4], [01-6], and [01-7] are false positive logs.
[0081] In contrast, among the security logs stored in the log storage unit 102, security logs other than the above-mentioned log IDs do not match the occurrence patterns stored in the pattern storage unit 103. Therefore, the false positive log determination unit 104 determines that these security logs are not false positive logs, that is, that they are security logs that were generated due to the detection of an abnormality that occurred in the electronic control system S.
[0082] The false positive log determination unit 104 of this embodiment performs false positive log determination processing periodically or at the timing of occurrence of a predetermined event. Examples of the timing of occurrence of a predetermined event include the timing of turning on or off the power of the vehicle, the timing of the vehicle performing a specific behavior, or the timing of the log acquisition unit 101 acquiring a new security log.
[0083] In the block diagram shown in Figure 4, the false positive log determination unit 104 is illustrated as being configured to output the determination result to the positive information assignment unit 105 described later, but the false positive log determination unit 104 may also output the determination result to a memory (not shown) such as a RAM (Random Access Memory).
[0084] The information adding unit 105 adds information to the security log based on the determination result output from the false positive log determining unit 104. The information adding unit 105 of this embodiment realizes a false positive information adding unit .
[0085] The false positive information assigning unit 106 assigns "false positive information", which is information for identifying a false positive log, to the security log based on the determination result output from the false positive log determining unit 104. If the determination result of the false positive log determining unit 104 is output and stored in a memory such as a RAM (not shown), the false positive information assigning unit 104 assigns the false positive information to the security log based on the determination result stored in the memory.
[0086] Here, the "false positive information" may be information indicating that the security log is not a false positive, as well as information indicating that the security log is a false positive.
[0087] For example, the false positive information assigning unit 106 assigns a flag indicating that the security log is a false positive log as false positive information to the security log that the false positive log determining unit 104 has determined to be a false positive log. The false positive information may be assigned by being stored in the context data of the security log shown in Fig. 3, for example. In this way, by assigning a flag as false positive information to the security log, it becomes possible to easily distinguish between security logs generated due to an attack and security logs generated due to maintenance.
[0088] In the embodiment described below, a case is described in which the false positive information assigning unit 106 assigns false positive information to a security log that has been determined to be a false positive log, but the false positive information assigning unit 106 may assign false positive information to a security log that has been determined not to be a false positive log by the false positive log determining unit 104. In this case, the false positive information indicates information indicating that the security log to which the information has been assigned is not a false positive log.
[0089] The transmitting unit 107 transmits security logs that are not determined to be false positive logs and security logs that are determined to be false positive logs. For example, the transmitting unit 107 transmits the security logs to an attack analysis device (not shown) that analyzes these security logs. The attack analysis device that receives the security logs can determine whether or not the security logs are false positive logs based on the false positive information added to the security logs.
[0090] Alternatively, the transmission unit 107 may transmit only security logs that are not determined to be false positives. In the case of the log determination device 10 shown in Fig. 1(a) and Fig. 1(b), by transmitting only security logs that are not determined to be false positive logs to an attack analysis device (not shown) provided outside the vehicle, the amount of communication between the vehicle and the attack analysis device can be reduced.
[0091] In this embodiment, the transmitting unit 107 is configured to transmit a security log from the log determination device 10. However, the transmitting unit 107 may transmit a determination result by the false positive log determination unit 104 instead of or in addition to the security log.
[0092] (2) Operation of the Log Judgment Device 10 The operation of the log determination device 10 will be described with reference to Fig. 8 and Fig. 9. Fig. 8 and Fig. 9 not only show a log determination method executed by the log determination device 10, but also show a processing procedure of a log determination program executable by the log determination device 10. The order of these processes is not limited to the order shown in Fig. 8 and Fig. 9. In other words, the order may be changed as long as there is no constraint such as a relationship in which a certain step utilizes the result of the previous step. The same applies to Figs. 13 and 14 of the second embodiment described later.
[0093] The log acquisition unit 101 acquires a security log generated when the security sensor 201 mounted in each of the multiple ECUs 20 constituting the electronic control system S detects an abnormality (S101). The log storage unit 102 stores the security log acquired by the log acquisition unit 101 (S102). Here, if it is time to judge the log (S103: Y), for example, when the log judgment process is performed at periodic timing and a certain time has passed since the previous log judgment, the false positive log judgment unit 104 judges whether the security log stored in the log storage unit 102 is a false positive log or not (S104). The details of the process of S104 will be described later.
[0094] If it is determined that the security log is a false positive log based on the determination result in S104 (S105: Y), the false positive information assigning unit 106 assigns false positive information to the security log determined to be a false positive log (S106). Next, the transmitting unit 107 transmits security logs that have not been determined to be false positive logs, and security logs that have been determined to be false positive logs and to which false positive information has been added (S107).
[0095] Next, the process of determining whether or not the security log is a false positive log in S104 will be described with reference to Fig. 9. Although not shown in Fig. 9, the process of Fig. 9 is repeatedly executed the number of times corresponding to the number of occurrence patterns stored in the pattern storage unit 103.
[0096] The false positive log determination unit 104 compares a plurality of security logs stored in the log storage unit 102 and their occurrence order with the occurrence pattern stored in the pattern storage unit 103 (S201). If, as a result of comparing the security logs with the occurrence pattern, it is found that the multiple security logs and their occurrence order match the occurrence pattern (S202: Y), the false positive log determination unit 104 further compares the period from the earliest time information to the latest time information among the multiple security logs with the predicted period set in the occurrence pattern (S203). Then, if the period from the earliest time information to the latest time information is within the predicted period (S203: Y), the false positive log determination unit 104 further determines whether or not the security logs detected in the period from the earliest time information to the latest time information include a security log equivalent to a non-detected log stored in the pattern storage unit 103 (S204). Here, if no security log equivalent to the non-detection log is included (S204: N), the false positive log determining unit 104 determines that the multiple security logs are false positive logs (S205). In contrast, if the multiple security logs and their occurrence order do not match the occurrence pattern (S202:N), if the period from the earliest time information to the latest time information is not within the predicted period (S203:N), or if the multiple security logs include a security log equivalent to a non-detection log (S204:Y), the false positive log determination unit 104 determines that the multiple security logs are not false positive logs (S206). Then, the false positive log determining unit 104 outputs the determination result (S207).
[0097] (3) Summary As described above, according to this embodiment, it is possible to determine that a security log generated due to vehicle maintenance is a false positive log. As a result, in a device that analyzes attacks using security logs, it is possible to analyze attacks using security logs excluding security logs generated due to vehicle maintenance, thereby improving the accuracy of attack analysis. Furthermore, according to this embodiment, security logs that are determined to be false positive logs are not transmitted, thereby making it possible to reduce the amount of communication between the log determination device and the attack analysis device.
[0098] 3. Embodiment 2 In this embodiment, a method for determining whether or not a security log is a false positive log will be described using a method different from that of embodiment 1. FIG. 10 is a block diagram showing the configuration of a log determination device 11 of this embodiment. The same components as those in the log determination device 10 of embodiment 1 are assigned the same reference numerals. The log determination device 11 of this embodiment will be described below, focusing on the differences from embodiment 1.
[0099] (1) Configuration of the log determination device 11 In the present embodiment, when the log acquisition unit 101 acquires a security log, the false positive log determination unit 104 sequentially determines whether the security log is a false positive log. In the above-described first embodiment, the timing when the log acquisition unit 101 acquires a new security log has been described as an example of the timing at which the log is determined. In the first embodiment, the false positive log determination unit 104 compares a plurality of security logs stored in the log storage unit 102 and their occurrence order and occurrence pattern, and determines whether the log is a false positive log depending on whether there is a complete match. In the present embodiment, however, the false positive log determination unit 104 determines whether the newly acquired security log and the security log stored in the log storage unit 102 and their occurrence order and a part of the occurrence pattern match at the timing at which the new security log is acquired.
[0100] The false positive log determination unit 104 of this embodiment determines whether a newly acquired security log (hereinafter, acquired security log) and a security log stored in the log storage unit 102 (hereinafter, stored security log), as well as their occurrence order, match a part of the occurrence pattern. If the acquired security log and the stored security log, as well as their occurrence order, match a part of the occurrence pattern, the unit calculates the degree of matching between the acquired security log and the stored security log, as well as their occurrence order, and the occurrence pattern.
[0101] If the calculated matching degree is 100%, the false positive log determining unit 104 determines that the acquired security log and the stored security log are false positive logs. On the other hand, if the matching degree does not reach 100% within the prediction period, the false positive log determination unit 104 determines that the acquired security log and the stored security log are not false positive logs.
[0102] The information assigning unit 105 of this embodiment realizes a provisional information assigning unit 111 in addition to the false positive information assigning unit 106. If the matching degree calculated by the false positive log determination unit 104 is higher than a predetermined threshold, the provisional information assigning unit 111 assigns provisional information to the acquired security log and the stored security log, indicating that they may be false positive logs.
[0103] The term "more than" encompasses both cases where the value is the same as the comparison target and cases where the value is not the same.
[0104] The false positive log determination unit 104 and provisional information assignment unit 111 of this embodiment will be described in more detail with reference to Figs. 11 and 12. Figs. 11 and 12 show a comparison of acquired and stored security logs with occurrence patterns, and the degree of matching. Squares in Figs. 11 and 12 represent security logs, white squares represent security logs newly acquired by the log acquisition unit 101, and shaded squares represent security logs stored in the log storage unit 102. In the example shown below, the threshold for the degree of matching is assumed to be 70%.
[0105] FIG. 11(a) shows a state where the log acquisition unit 101 has acquired a log A indicating that an abnormality a has been detected in the ECU 20c. A part of the occurrence pattern of the log A and the maintenance ID
[0001] shown in FIG. 5 match. Therefore, the false positive log acquisition unit 104 calculates the matching degree. In this example, the occurrence pattern of the maintenance ID
[0001] includes a total of five sets, that is, one set of the ECU 20c and the abnormality a, two sets of the ECU 20d and the abnormality b, and two sets of the ECU 20e and the abnormality b. Therefore, one set out of the five sets matches, so the matching degree is 20%. This matching degree is below the threshold value.
[0106] FIG. 11(b) shows a state where the log acquisition unit 101 has acquired a log B indicating that an abnormality b has been detected in the ECU 20d. Since the logs A and B partially match the occurrence pattern of the maintenance ID
[0001] , the false positive log acquisition unit 104 calculates the matching degree. In FIG. 11(b), the matching degree is 40%, which is below the threshold. Similarly, FIG. 11(c) shows a state where the log acquisition unit 101 has acquired a log C indicating that an abnormality b has been detected in the ECU 20d. Since the logs A to C partially match the occurrence pattern of the maintenance ID
[0001] , the false positive log acquisition unit 104 calculates the matching degree. In FIG. 11(c), the matching degree is 60%, which is below the threshold.
[0107] FIG. 11(d) shows a state where the log acquisition unit 101 has acquired a log D indicating that an abnormality b has been detected in the ECU 20e. Since the occurrence patterns of the logs A to D and the maintenance ID
[0001] are partially identical, the false positive log acquisition unit 104 calculates the degree of matching. In FIG. 11(d), the degree of matching is 80%, which is higher than the threshold value of the degree of matching. Therefore, the provisional information assignment unit 111 assigns provisional information to the logs A to D. Then, FIG. 11(e) shows a state where the log acquisition unit 101 has acquired a log E indicating that an abnormality b has been detected in the ECU 20e. Since the occurrence patterns of the logs A to E and the maintenance ID
[0001] are identical, the false positive log acquisition unit 104 calculates the degree of matching. The degree of matching in FIG. 11(e) is 100%. Therefore, the false positive log determination unit 104 determines that the logs A to E are false positive logs. Then, the false positive information assigning unit 116 assigns false positive information to the logs A to E.
[0108] 12(a) to 12(d) are the same as FIG. 11(a) to FIG. 11(d), but FIG. 12(e) is different from FIG. 11(e). FIG. 12(e) shows a state in which a log F indicating that an abnormality c has been detected in the ECU 20a has been acquired instead of the log E. According to FIG. 6, the log indicating that an abnormality c has been detected in the ECU 20a corresponds to a non-detection log of the maintenance ID
[0001] . Therefore, in the case of FIG. 12(e), the false positive log determination unit 104 determines that the logs A to F are not false positive logs. Then, the false positive log determination unit 104 deletes the provisional information added in FIG. 12(d). Note that FIG. 12(e) illustrates an example in which a non-detection log has been acquired, but the same applies to a case in which a log equivalent to the log E in FIG. 11(e) is not acquired within a prediction period from the time when the log A was acquired.
[0109] (2) Operation of the log determination device 11 The operation of the log judgment device 11 will be described with reference to Figures 13 and 14. The same processes as those in the log judgment device 10 are denoted by the same reference numerals as in Figures 8 and 9.
[0110] Fig. 13 shows a series of processes from when log acquisition unit 101 acquires a security log, to when it is determined whether the security log is a false positive log, and to when it is transmitted. Unlike Fig. 8, Fig. 13 does not include a process for determining whether it is time to judge the security log, and when log acquisition unit 101 acquires a security log in S101 and stores the acquired security log in S102, false positive log judgment unit 104 always judges whether the security log is a false positive log (S104).
[0111] Next, the process of determining whether or not the security log is a false positive log in S104 of FIG. 13 will be described with reference to FIG. The false positive log determination unit 104 compares the security log acquired in S101 of FIG. 13 (i.e., the acquired security log) with the security log stored in the log storage unit 102, as well as their occurrence order and occurrence pattern (S301). If the acquired security log and the stored security log, and their order of occurrence, match part of the occurrence pattern (S302: Y), the false positive log determination unit 104 further compares the period from the earliest time information of the stored security log to the time information of the acquired security log with the predicted period set in the occurrence pattern (S303). Then, if the period from the earliest time information to the time information of the acquired security log is within the predicted period (S303: Y), the false positive log determination unit 104 further determines whether the security logs detected from the earliest time information to the time information of the acquired security log include a security log equivalent to a non-detected log (S304).
[0112] If a security log equivalent to a non-detection log is not included (S304: N), the false positive log determination unit 104 calculates the degree of matching between the acquired security log and the stored security log and the occurrence pattern (S305). If the calculated matching degree is 100% (S306), it is determined that the acquired security log and the stored security log are false positive logs (S307). On the other hand, if the calculated matching degree is not 100%, the false positive log determination unit 104 further determines whether the matching degree is higher than a threshold value (S306). If the degree of matching is higher than the threshold, the provisional information attachment unit 111 attaches provisional information to the acquired security log and the stored security log (S309), and the process returns to FIG. On the other hand, if the matching degree is equal to or less than the threshold value, the process returns to S101 in FIG.
[0113] If the period from the earliest time information of the stored security log to the time information of the acquired security log is not within the predicted period (S303:N), or if a security log equivalent to a non-detected log is included (S304:Y), the false positive log determination unit 104 determines whether or not provisional information has been assigned to the determined security log (S310). If provisional information has been added to the security log, the provisional information is deleted (S311). Then, the false positive log determination unit 104 determines that the acquired security log and the stored security log are not false positive logs (S312).
[0114] Also, in S302, if the acquired security log and the stored security log do not match a part of the occurrence pattern (S302: N), the false positive log determination unit 104 also determines that the acquired security log and the stored security log are not false positive logs (S312).
[0115] Then, the false positive log determination unit 104 outputs the determination result as to whether or not the security log is a false positive log (S308).
[0116] (3) Summary As described above, according to this embodiment, even if all security logs corresponding to an occurrence pattern have not been acquired, it is possible to determine whether or not a security log is likely to be a false positive log.
[0117] 4. Summary The features of the log determination device and the like in each embodiment of the present invention have been described above.
[0118] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.
[0119] The block diagrams used to explain the embodiments classify and organize the configuration of the device by function. The blocks showing the respective functions are realized by any combination of hardware or software. In addition, since the block diagrams show the functions, they can also be understood as disclosures of a method invention and a program invention that realizes the method.
[0120] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints such as a relationship in which one step utilizes the results of another step prior to it.
[0121] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.
[0122] Each embodiment is based on a log judgment device for a vehicle for judging a security log generated by a security sensor of an electronic control device installed in a vehicle, but the present invention also includes dedicated or general-purpose devices other than for vehicles, unless specifically limited in the claims.
[0123] Moreover, examples of the form of the log determination device of the present invention include the following. Examples of the component form include a semiconductor element, an electronic circuit, a module, and a microcomputer. Examples of semi-finished products include electronic control units (ECUs (Electric Control Units)) and system boards. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.
[0124] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log determination device.
[0125] The log determination device of the present invention is expected to be used, particularly on the server side, for the purpose of providing various services. In providing such services, the log determination device of the present invention is used, the method of the present invention is used, and / or the program of the present invention is executed.
[0126] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as a memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing the program.
[0127] A program stored in a non-transient physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]
[0128] The log judgment device of the present invention is intended primarily as a device for judging security logs generated by a security sensor of an electronic control device installed in an electronic control system installed in an automobile, but it may also be intended as a device for analyzing logs generated by ordinary systems or devices not installed in an automobile. [Explanation of symbols]
[0129] 1 Log judgment system, 10 (11) Log judgment device, 101 Log acquisition unit, 103 Pattern storage unit, 104 False positive log judgment unit, 106 False positive information assignment unit, 107 Transmission unit, 111 Provisional information assignment unit, 201 Security sensor, 202 Log transmission unit
Claims
1. A log acquisition unit (101) that acquires a plurality of security logs each including anomaly information indicating an anomaly detected within an electronic control system and position information indicating a position within the electronic control system where the anomaly was detected; A pattern storage unit (103) that stores the occurrence pattern of security logs predicted to occur due to maintenance of the electronic control system, the occurrence pattern including a plurality of sets each including predicted anomaly information indicating an anomaly predicted to be detected by the electronic control system and predicted anomaly position information indicating a position within the electronic control system where the predicted anomaly is detected; A false positive log determination unit (104) that compares the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated by detecting an anomaly generated by the maintenance, and outputs a determination result; A log determination device (10, 11) comprising the above.
2. In addition to the plurality of sets, the occurrence pattern includes the occurrence order of the plurality of sets, The false positive log determination unit compares the plurality of security logs, the occurrence order of the plurality of security logs, and the occurrence pattern to determine whether the plurality of security logs are false positive logs. The log determination device according to Claim 1.
3. The plurality of security logs further each include time information indicating the time when the anomaly was detected, The pattern storage unit further stores a predicted period indicating a predicted period from the time when the predicted anomaly is first detected to the time when the predicted anomaly is last detected, The false positive log determination unit further compares the period from the first time information, which is the earliest time information among the time information, to the second time information, which is the latest time information, with the predicted period to determine whether the plurality of security logs are false positive logs. The log determination device according to Claim 1.
4. The plurality of sets further each include a predicted number of occurrences indicating the number of times the predicted anomaly occurs, The false positive log determination unit compares the number of security logs among the plurality of security logs in which the anomaly information and the position information are common with the predicted number of occurrences to determine whether the plurality of security logs are false positive logs. The log determination device according to claim 1.
5. The pattern storage unit further stores predicted non-detection position information indicating a position within the electronic control system where it is predicted that no abnormality will be detected by the maintenance, and predicted non-detection abnormality information indicating an abnormality that is predicted not to be detected at the position indicated by the predicted non-detection position information. The false positive log determination unit further compares the plurality of security logs with the predicted non-detection abnormality information and the predicted non-detection position information to determine whether the plurality of security logs are false positive logs. The log determination device according to claim 1.
6. The log determination device further includes a false positive information adding unit (106) that adds false positive information for specifying the false positive logs to the plurality of security logs based on the determination result. And a transmission unit (107) that transmits the security logs to which the false positive information is added. The log determination device according to claim 1.
7. The false positive log determination unit further calculates a matching degree between the plurality of security logs and the occurrence pattern. The log determination device further includes a temporary information adding unit (111) that adds temporary information indicating that the plurality of security logs may be false positive logs to the plurality of security logs when the matching degree is higher than a threshold value. The log determination device according to claim 1.
8. The plurality of security logs further each include time information indicating the time when the abnormality was detected. The pattern storage unit further stores a predicted period indicating a predicted period from the time when the predicted abnormality is first detected to the time when the predicted abnormality is last detected. If the matching degree does not reach 100% until the predicted period has elapsed from the earliest time information among the time information, the false positive log determination unit determines that the plurality of security logs are not false positive logs and deletes the temporary information. The log determination device according to claim 7.
9. The electronic control system and the log determination device are mounted on a moving body. The log determination device according to any one of claims 1 to 8.
10. The electronic control system is mounted on a moving body. The log determination device is provided outside the moving body. The log determination device according to any one of claims 1 to 8.
11. A log determination method executed by a log determination device (10, 11), wherein the log determination device includes a pattern storage unit (103) that stores the occurrence pattern of security logs that are predicted to occur due to maintenance of an electronic control system, the occurrence pattern including a plurality of sets each including prediction abnormality information indicating an abnormality that is predicted to be detected by the electronic control system and prediction abnormality position information indicating a position within the electronic control system where the predicted abnormality is detected, and the log determination method includes: acquiring a plurality of security logs each including abnormality information indicating an abnormality detected within the electronic control system and position information indicating a position within the electronic control system where the abnormality is detected (S101); comparing the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated when an abnormality occurring due to the maintenance is detected, and outputting a determination result (S104); A log determination method.
12. A log determination program executable by a log determination device (10, 11), wherein the log determination device includes a pattern storage unit (103) that stores the occurrence pattern of security logs that are predicted to occur due to maintenance of an electronic control system, the occurrence pattern including a plurality of sets each including prediction abnormality information indicating an abnormality that is predicted to be detected by the electronic control system and prediction abnormality position information indicating a position within the electronic control system where the predicted abnormality is detected, and the log determination program causes the log determination device to: acquire a plurality of security logs each including abnormality information indicating an abnormality detected within the electronic control system and position information indicating a position within the electronic control system where the abnormality is detected (S101); compare the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated when an abnormality occurring due to the maintenance is detected, and output a determination result (S104); A log determination program.
13. A log determination system (1) having an electronic control system (S) and a log determination device (10, 11), wherein the electronic control system includes: When an abnormality is detected in the electronic control system, a log generation unit (201) that generates a security log including abnormality information indicating the abnormality and position information indicating the position within the electronic control system where the abnormality was detected; A log transmission unit (202) that transmits the security log to the log determination device; The log determination device includes: A log acquisition unit (101) that acquires a plurality of security logs transmitted from the log transmission unit; A pattern storage unit (103) that stores a generation pattern of security logs that is predicted to occur due to maintenance of the electronic control system, the generation pattern including a plurality of sets each including predicted abnormality information indicating an abnormality predicted to be detected in the electronic control system and predicted abnormality position information indicating the position within the electronic control system where the predicted abnormality is detected; A false positive log determination unit (104) that compares the plurality of security logs with the generation pattern to determine whether the plurality of security logs are false positive logs generated by detecting an abnormality generated by the maintenance, and outputs a determination result; A log determination system.
14. A log acquisition unit (101) that acquires a plurality of security logs each including abnormality information indicating an abnormality detected in an electronic control system and position information indicating the position within the electronic control system where the abnormality was detected; A storage unit (103) that stores characteristics of security logs predicted to occur due to maintenance of the electronic control system; A false positive log determination unit (104) that compares the plurality of security logs with the characteristics to determine whether the plurality of security logs are false positive logs generated by detecting an abnormality generated by the maintenance, and outputs a determination result; A log determination device comprising the above.
15. The electronic control system is mounted on a vehicle, The maintenance includes maintenance of the vehicle at a factory, The log determination device according to Claim 14.
16. A log determination program executable by a log determination device (10, 11), The log determination device includes a storage unit (103) that stores characteristics of security logs predicted to occur due to maintenance of the electronic control system, The log determination program, in the log determination device, Obtain a plurality of security logs each including anomaly information indicating an anomaly detected within the electronic control system and position information indicating a position within the electronic control system where the anomaly was detected (S101). Compare the plurality of security logs with the feature to determine whether the plurality of security logs are false positive logs generated due to the detection of anomalies caused by the maintenance, and output the determination result (S104). Log determination program.
17. A system comprising a vehicle and a log determination device provided outside the vehicle, wherein the vehicle is equipped with an electronic control system having a plurality of electronic control devices, and each electronic control device has a security sensor for detecting anomalies. The log determination device is a log acquisition unit (101) that acquires a plurality of security logs each including anomaly information indicating the anomaly detected within the electronic control system and position information indicating a position within the electronic control system where the anomaly was detected; a storage unit (103) that stores features of security logs predicted to occur due to maintenance of the electronic control system; a false positive log determination unit (104) that compares the plurality of security logs with the feature to determine whether the plurality of security logs are false positive logs generated due to the detection of anomalies caused by the maintenance, and outputs the determination result. System.
18. A log acquisition unit (101) that acquires a plurality of security logs each including anomaly information indicating an anomaly detected within the electronic control system and position information indicating a position within the electronic control system where the anomaly was detected; a storage unit (103) that stores rules for determining security logs resulting from maintenance of the electronic control system; a false positive log determination unit (104) that compares the plurality of security logs with the rules to determine whether the plurality of security logs are false positive logs not caused by a cyber attack, and outputs the determination result. A log determination device comprising the above.