Log analysis apparatus, log analysis method, and log analysis program

JP2024051324A5Pending Publication Date: 2025-07-22DENSO CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022157429
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Existing log analysis systems in vehicles are hindered by false positive security event logs, which decrease the accuracy of estimating cyber attacks and their routes, as these logs are not necessarily caused by actual cyber attacks.

Method used

A log analysis device that includes a log acquisition unit, a vehicle status information acquisition unit, and a false positive determination unit to identify and process false positive security event logs based on vehicle status information, determining whether abnormalities are caused by cyber attacks or not.

Benefits of technology

The system effectively distinguishes between genuine cyber attack indicators and false positives, enhancing the accuracy of cyber attack detection and reducing false alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a log analysis apparatus, method and program for excluding false positive security event logs before security event logs are used for attack estimation for an attack path, or the like.SOLUTION: A log analysis system includes a log analysis apparatus installed outside a vehicle, and a log analysis apparatus equipped in the vehicle and connected to an electronic control system. The log analysis apparatus 11 equipped in the vehicle includes: a log acquisition unit 101 which acquires a security event log indicating an anomaly detected by a security sensor of an electronic control apparatus mounted on the vehicle; a vehicle state information acquisition unit 102 which acquires vehicle state information indicating interior state or / and exterior state of the vehicle when the anomaly occurs; a false positive determination unit 104 which determines, based on the vehicle state information, whether an anomaly indicated by the security event log is false positive which is an anomaly not caused by a cyber attack; and a processing unit 106 which executes processing on the security event log determined to be false positive.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] The present invention relates to a log analysis device, which is a device for analyzing a security event log that is output when an attack occurs against an electronic control system mounted on a mobile object such as an automobile. [Background technology]

[0002] In recent years, technologies for driving assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication and vehicle-to-infrastructure communication), have been attracting attention. As a result, vehicles are equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyber attacks such as unauthorized access is increasing. Therefore, it is necessary to analyze cyber attacks against vehicles and develop countermeasures.

[0003] There are various methods for detecting an abnormality that occurs in a vehicle and analyzing a cyber attack based on the detected abnormality. For example, Patent Document 1 describes that an attack path analysis unit 203 of a center device 200 analyzes a received abnormality log and estimates an attack path of an attack on a vehicle, and that the abnormality log is generated by a security sensor of each ECU and transmitted to the center device 200. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] JP 2022-17873 A Summary of the Invention [Problem to be solved by the invention]

[0005] Here, the present inventors have found the following problem. If a security event log indicating anomalies detected by a security sensor of an electronic control device installed in a vehicle contains a false positive security event log, which is an anomaly that is not caused by a cyber attack, this can cause a decrease in the accuracy of estimating attacks and attack routes, etc., that are analyzed using the security event log.

[0006] Therefore, an object of the present invention is to provide a technology for determining whether an abnormality indicated in a security event log indicating an abnormality detected by a security sensor of an electronic control device installed in a vehicle is a false positive, that is, an abnormality not caused by a cyber attack. [Means for solving the problem]

[0007] The log analysis device (11, 12, 31, 32) of the present disclosure includes: A log acquisition unit (101, 301) that acquires a security event log indicating an abnormality detected by a security sensor of an electronic control device mounted on a vehicle; a vehicle state information acquisition unit (102, 302) that acquires vehicle state information indicating an internal state and / or an external state of the vehicle when the abnormality occurs; a false positive determination unit (104, 304) that determines whether or not the abnormality indicated by the security event log is a false positive, which is an abnormality not caused by a cyber attack, based on the vehicle state information; A processing unit (106, 306) that processes the security event log that is determined to be a false positive; Equipped with.

[0008] In addition, the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. Effect of the Invention

[0009] With the above-described configuration, the log analysis device disclosed herein can determine whether an abnormality indicated in a security event log indicating an abnormality detected by a security sensor of an electronic control device installed in a vehicle is a false positive, that is, an abnormality not caused by a cyber attack. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 is an explanatory diagram for explaining the arrangement of a log analysis device 11 and a log analysis device 31 according to the first embodiment. [Diagram 2] FIG. 13 is an explanatory diagram for explaining the arrangement of the log analysis device 12 according to the second embodiment. [Diagram 3] FIG. 13 is an explanatory diagram for explaining the arrangement of a log analysis device 32 according to the third embodiment. [Figure 4] FIG. 1 is a block diagram illustrating an example of the configuration of an electronic control system according to each embodiment. [Diagram 5] FIG. 2 is an explanatory diagram illustrating a security event log output from a security sensor of the electronic control system according to each embodiment. [Figure 6] FIG. 1 is a block diagram illustrating an example of the configuration of a log analysis device 11 according to a first embodiment. [Figure 7] FIG. 1 is an explanatory diagram for explaining a vehicle situation estimation table used in the first embodiment. [Figure 8] FIG. 1 is an explanatory diagram for explaining a power supply state table used in the first embodiment. [Figure 9] FIG. 1 is an explanatory diagram for explaining a power supply status, network status, and diagnostic status table used in the first embodiment. [Figure 10] FIG. 1 is an explanatory diagram for explaining an ECU state table used in the first embodiment. [Figure 11] FIG. 1 is a flow diagram illustrating the operation of the log analysis device according to the first embodiment. [Figure 12] FIG. 1 is a block diagram illustrating an example of the configuration of a log analysis device 31 according to a first embodiment. [Figure 13] FIG. 1 is an explanatory diagram for explaining a table that records the relationship between vehicle positions and known false positive log occurrence patterns used in the first embodiment. [Figure 14]FIG. 1 is an explanatory diagram for explaining a table used in the first embodiment, which records the relationship between vehicles and periods for disabling security event logs; [Figure 15] FIG. 1 is an explanatory diagram for explaining a table in which periods of communication failures and operating conditions of external devices are recorded, which is used in the first embodiment; [Figure 16] FIG. 11 is a block diagram illustrating a configuration example of a log analysis device 12 according to a second embodiment. [Figure 17] FIG. 13 is a block diagram illustrating a configuration example of a log analysis device 32 according to a third embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0012] The present invention means the invention described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks mean the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.

[0013] The configurations and methods described in the dependent claims are optional configurations and methods in the invention described in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, and the configurations and methods described only in the embodiments without being described in the claims, are optional configurations and methods in the present invention. The configurations and methods described in the embodiments when the description of the claims is broader than the description of the embodiments are also optional configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In either case, by being described in the independent claims, they become essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention possesses.

[0015] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in each of the multiple embodiments may be collected and combined.

[0016] The problem described in the section on problems that the invention is intended to solve is not a publicly known problem, but was discovered independently by the inventor, and this, together with the configuration and method of the present invention, is a fact that affirms the inventive step of the invention.

[0017] 1. Configuration underlying each embodiment (1) Placement of log analysis equipment First, the arrangement of the log analysis device in each embodiment will be described with reference to FIGS. FIG. 1 shows a log analysis device 11 and a log analysis device 31 according to the first embodiment. The device 11 is "installed in a vehicle" and is connected to an electronic control system S also installed in the "vehicle". The log analysis device 31 is installed outside the vehicle and is realized, for example, by a SOC (Security Operations Center) or other server device. The log analysis device 11 and the log analysis device 31 are collectively referred to as a log analysis system 1. Where: "Mounted on a vehicle" includes not only the case where the device is directly fixed to the vehicle, but also the case where the device is not fixed to the vehicle but moves with the vehicle, such as when the device is carried by a person in the vehicle or when the device is mounted on cargo placed on the vehicle. "Vehicle" refers to a movable object that can move at any speed. It also includes a vehicle that is stationary. Examples of the vehicle include, but are not limited to, automobiles, motorcycles, bicycles, and items mounted thereon.

[0018] The log analysis device 11 is connected to the electronic control system S and the electronic control units (hereinafter referred to as ECUs (Electronic Control Units)) constituting the electronic control system S via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the connection may be made using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). Although the log analysis device 11 is provided outside the electronic control system S in FIG. 1, the log analysis device 11 may be provided inside the electronic control system S, that is, as one of the components of the electronic control system S. In addition, a connection refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual machines realized on the same hardware are virtually connected to each other.

[0019] The log analysis device 31 and the electronic control system S, or the log analysis device 31 and the log analysis device 11, are connected via a communication network of a wireless communication method, such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, 5G, etc. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a LAN (Local Area Network) such as Ethernet (registered trademark), the Internet, an optical fiber line, or a fixed telephone line can be used. Alternatively, the line may be a combination of a wireless communication system and a wired communication system. For example, the electronic control system S and a base station device in a cellular system may be connected by a wireless communication system such as 4G, and the base station device and the log analysis device 31 may be connected by a wired communication system such as a trunk line of a telecommunications carrier or the Internet. A gateway device may be provided at the point of contact between the trunk line and the Internet.

[0020] The external device 40 is provided outside the vehicle, similar to the log analysis device 31, and is realized by, for example, a server device, etc. The external device 40 is, for example, a device that mainly provides various types of information to the log analysis device 31. The external device 40 and the log analysis device 31 are usually connected by a wired communication method. The external device 40 and the log analysis device 11 are connected by a wireless communication method or a wired communication method. Examples of the wired communication method and the wireless communication method have already been described.

[0021] The log analysis device 11 is provided in the vehicle, and is therefore suitable for mainly acquiring vehicle internal state information indicating the internal state of the vehicle from the electronic control system S, etc. The log analysis device 31 is provided outside the vehicle, and is therefore suitable for mainly acquiring vehicle external information indicating the external state of the vehicle from the external device 40, etc. The vehicle internal state information and the vehicle external information are collectively referred to as vehicle state information. In the first embodiment, the log analysis device that performs the log analysis is determined depending on the type of vehicle state information. However, this does not prevent the log analysis device 11 from acquiring vehicle external information, and the log analysis device 31 from acquiring vehicle internal state information.

[0022] 2 shows a log analysis device 12 of the second embodiment. Unlike the first embodiment, there is no log analysis device provided outside the vehicle, and the second embodiment is configured only with the log analysis device 12 provided in the vehicle. The log analysis device 12 of the second embodiment has the functions of both the log analysis device 11 and the log analysis device 31 of the first embodiment.

[0023] 3 shows a log analysis device 32 of the third embodiment. Unlike the first embodiment, there is no log analysis device provided in the vehicle, and the third embodiment is configured only with the log analysis device 32 provided outside the vehicle. The log analysis device 32 of the third embodiment has the functions of both the log analysis device 11 and the log analysis device 31 of the first embodiment.

[0024] (2) Electronic control system configuration Fig. 4 is a diagram showing an example of the configuration of an electronic control system S. The electronic control system S is composed of multiple ECUs, including an external communication ECU and an integrated ECU, which are connected via the in-vehicle communication network already described. Fig. 4 shows an example of one external communication ECU, one integrated ECU, and four individual ECUs (ECUs A, B, C, and D), but the electronic control system S is naturally composed of any number of ECUs. Hereinafter, the term "ECU" will be used to collectively refer to the external communication ECU, the integrated ECU, and the individual ECUs.

[0025] The external communication ECU is an ECU that communicates with the outside. The communication method used by the external communication ECU is as described above in the wireless communication method and the wired communication method. Note that in order to realize a plurality of communication methods, a plurality of external communication ECUs may be provided.

[0026] The integrated ECU is an ECU equipped with a gateway function that mediates between the individual ECUs and the external communication ECU. The integrated ECU may also be provided with a function for controlling the entire electronic control system S, such as a security function. The integrated ECU may also be called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU may also be a relay device or a gateway device.

[0027] The individual ECUs of the electronic control system S can be configured with ECUs having any desired functions. For example, they can be drive system electronic control devices that control the engine, steering, brakes, etc., vehicle body electronic control devices that control meters, power windows, etc., information system electronic control devices such as navigation devices, or safety control system electronic control devices that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may not be parallel to each other, but may be classified as master and slave.

[0028] Furthermore, the ECU may be a physically independent ECU, or may be a virtual ECU (also called a virtual machine) that is virtually realized.

[0029] In the electronic control system S in Fig. 4, a security sensor is mounted in each ECU. However, it is not necessarily required that a security sensor is mounted in every ECU.

[0030] When the log analysis device 11 (12) is provided outside the electronic control system S, it may be connected to the electronic control system S in Fig. 2 via an in-vehicle communication network or a network using another communication method. When the log analysis device 11 (12) is provided inside the electronic control system S, it may be provided inside any ECU, including the integrated ECU.

[0031] Furthermore, when the log analysis device 11 (12) is provided outside the electronic control system S and communicates with a device outside the vehicle, an independent communication device provided in the log analysis device 11 (12) may be used, or an external communication ECU of the electronic control system S may be used. When the log analysis device 11 (12) is provided inside the electronic control system S and communicates with a device outside the vehicle, the external communication ECU can naturally be used.

[0032] (3) Security event log details FIG. 5 is a diagram showing the contents of a security event log generated by a security sensor of an ECU constituting the electronic control system S. As shown in FIG.

[0033] The security event log has fields of an ECU ID indicating identification information of an ECU in which a security sensor is mounted, a sensor ID indicating identification information of a security sensor, an event ID indicating identification information of a security event, a counter indicating the number of occurrences of an event, a timestamp indicating the time of occurrence of an event, and context data indicating details of an output of a security sensor. The security event log may further have a header storing information indicating a protocol version and a state of each field.

[0034] According to the specifications defined by AUTOSAR (AUTomotive Open System ARchitecture), IdsM Instance ID corresponds to ECU ID, Sensor Instance ID corresponds to sensor ID, Event Definition ID corresponds to event ID, Count corresponds to counter, Timestamp corresponds to timestamp, Context Data corresponds to context data, Protocol Version corresponds to Protocol Header corresponds to header.

[0035] Although Fig. 5 is an example of an abnormality log indicating an abnormality, a normal log may have the same specifications as Fig. 5. In that case, the context data of the normal log can be omitted. Also, by setting a flag indicating the presence or absence of context data in the header, it is possible to distinguish between an abnormality log and a normal log by checking the flag.

[0036] Also, while FIG. 5 shows a security event log generated by a physically independent ECU, it may be a security event log generated by a virtual ECU.

[0037] The security event log generated by the security sensor is called SEv, and the narrowed down accurate security event log is called QSEv. For example, the security sensor of the individual ECU in Fig. 2 generates SEv and reports it to an intrusion detection system manager (IdsM) not shown, and when the SEv passes through a certification filter in the IdsM and meets a specified criterion, it is transmitted from the intrusion detection reporter to the outside of the vehicle as QSEv. The security event log in this embodiment is a concept that includes both SEv and QSEv.

[0038] (4) Overview of the log analysis device There is an attack analysis device as a device for analyzing cyber attacks against an electronic control system S. The attack analysis device acquires security event logs output from security sensors of the ECUs that constitute the electronic control system S, and analyzes the types of cyber attacks and the attack paths of the cyber attacks.

[0039] However, security event logs generated by detecting abnormalities in an ECU or a network are not necessarily caused by a cyber attack. Here, a security event log that is not caused by a cyber attack is called a false positive log, and something that is not caused by a cyber attack is called a false positive. The log analysis device of each embodiment determines whether an abnormality indicated by a security event log is a false positive, and performs processing on the false positive log.

[0040] The log analysis device having such functions in each embodiment may be included in the attack analysis device, or may be provided separately before the processing of the attack analysis device. Also, the log analysis device may be provided on the vehicle side, and the attack analysis device may be provided on the server side. The log analysis device may be realized by a dedicated hardware device, or may be realized by a general-purpose hardware device and software.

[0041] 2. Embodiment 1 (1) Configuration of the log analysis device 11 6 is a block diagram showing the configuration of the log analysis device 11 in this embodiment. The log analysis device 11 includes a log acquisition unit 101, a vehicle state information acquisition unit 102, a vehicle situation estimation unit 103, a false positive determination unit 104, a storage unit 105, and a processing unit 106.

[0042] The log acquisition unit 101 acquires a security event log indicating an abnormality detected by a security sensor of an ECU mounted on a vehicle. Since the log acquisition unit 101 is connected to the electronic control system S, the security event log acquired by the log acquisition unit 101 is, for example, SEv. The acquired security event log may be stored in a storage unit 105 described later. It is desirable to acquire a security event log each time a security event log occurs, but it is also possible to receive all security event logs accumulated on the electronic control system S side within a certain period of time at once.

[0043] The vehicle state information acquisition unit 102 acquires vehicle state information indicating the internal state and / or external state of the vehicle "when an abnormality occurs." Among the vehicle state information, information indicating the internal state of the vehicle is referred to as internal state information, and among the vehicle state information, information indicating the external state of the vehicle is referred to as external state information. Since the vehicle state acquisition unit 102 is provided in the vehicle, it mainly acquires internal state information. However, this does not prevent the acquisition of external state information from an external device 40 or the like. The acquired vehicle state information may be stored in a storage unit 105 described below. Here, "when an abnormality occurs" may refer to the time when the abnormality occurred, or it may be a time close to the time when the abnormality occurred, such as the time when a security event log indicating the abnormality was generated or the time when the security event log was received.

[0044] There are various methods for acquiring vehicle state information when an abnormality occurs. For example, the vehicle state information can be acquired by reading the timestamp of the security event log and requesting the ECU or a sensor of the electronic control system S to acquire vehicle state information that occurred at the same time or close to the time indicated by the timestamp. Alternatively, the vehicle state information can be acquired continuously and stored in the storage unit 105, and the vehicle state information that occurred at the same time or close to the time indicated by the timestamp can be acquired. Instead of the time indicated by the timestamp, the transmission time or reception time of the security event log can also be used to indicate when an abnormality occurred.

[0045] Specific examples of vehicle state information will be described later, but the vehicle state information may include the "time" at which an internal state or external state occurred, or the "duration" during which an internal state or external state continued. Where: The term "time" may refer to any point on a time axis, and includes not only time in the strict sense, but also indirect indications of time, such as timers and clocks. "Time" may refer to anything that indicates a length of time, and includes not only time in the strict sense, but also indirect indications of time, such as start and end times, timers, clock numbers, cycles, etc. Other specific examples of vehicle state information and methods of determining false positives using the information will be described in Examples 1 to 3.

[0046] The false positive determination unit 104 determines whether or not the abnormality indicated in the security event log acquired by the log acquisition unit 101 is a false positive, that is, an abnormality not caused by a cyber-attack, "based" on the vehicle state information acquired by the vehicle state information acquisition unit 102. For example, the determination may be made using a table that defines the vehicle state information and determination criteria, or based on the results of calculation based on the vehicle state information. Here, "based on" includes cases where the vehicle status information is directly used, as well as cases where the vehicle status information is indirectly used. That is, the vehicle status information is used to estimate intermediate facts, and the intermediate facts are used to calculate the vehicle status. This includes cases where a false positive is detected.

[0047] The storage unit 105 stores the security event log acquired by the log acquisition unit 101, the vehicle state information acquired by the vehicle state information acquisition unit 102, the determination result by the false positive determination unit 104, and other information. However, it is not essential to store these.

[0048] The processing unit 106 performs processing "on" the security event log that is determined to be a false positive. Here, "with respect to" includes not only a case where processing is performed directly on the security event log, but also a case where processing is performed indirectly on the security event log, such as reporting the result of a determination on the security event log.

[0049] The specific contents of the process may be determined according to the application or purpose, for example, deleting false positive logs determined to be false positives and preventing the log analysis device 11 from outputting false positive logs, setting a flag indicating that the false positive log is a false positive and outputting the flag to the attack analysis device, notifying an external device or the like that a false positive log has occurred, etc. In addition, the processing unit 106 outputs security event logs that have not been determined to be false positives to the attack analysis device.

[0050] (2) Types of vehicle condition information and method for determining false positives in the log analysis device 11 (Example 1) Information for estimating vehicle situation (internal state information) The first embodiment is an example in which the internal state information is information for estimating a vehicle situation.

[0051] In the first embodiment, the log analysis device 11 further includes a vehicle situation estimation unit 103 . The vehicle situation estimation unit 103 estimates a vehicle situation, which is a state related to the traveling of the vehicle, from internal state information indicating an internal state of the vehicle, among the vehicle state information acquired by the vehicle state information acquisition unit 102. Furthermore, it estimates a change in the power supply state of each ECU constituting the electronic control system S accompanying a change in the estimated vehicle situation.

[0052] First, a method for estimating a vehicle situation will be described. FIG. 7 is an example of a vehicle situation estimation table showing the relationship between the vehicle situation and the internal state information. The vehicle situation is a state related to the running of the vehicle, but in this example, it refers to the behavior and state of the vehicle. The vehicle situation estimation unit 103 uses the vehicle situation estimation table to estimate the vehicle situation from information related to the behavior and state of the vehicle as internal state information, which is output from the ECU and sensors mounted on the vehicle. The vehicle situation estimation table may be stored in the storage unit 105 and may be read out and referred to as appropriate.

[0053] 7 is used, the vehicle situation is estimated using, for example, information indicating the vehicle speed, mode, number of occupants, battery voltage, charge state, and shift position as internal state information. For example, when the vehicle speed is slow or medium speed, the mode is normal mode, the number of occupants is one or more, the battery voltage is within a predetermined value, the charge state is open, and the shift position is other than P or R, the vehicle situation is estimated to be urban driving. Alternatively, when the vehicle speed is high and the other internal state information is the same as the example of urban driving, the vehicle situation is estimated to be high-speed driving. These pieces of internal state information are merely examples, and other information may be used. It is not necessary to use all of these pieces of internal state information. When estimating the vehicle situation, external state information may also be used.

[0054] Next, a method for estimating a change in the power supply state of an ECU from an estimated change in the vehicle situation will be described. FIG. 8 is an example of a power supply state table showing the power supply state of the ECU for each vehicle situation. Each ECU in the electronic control system S only needs to be active when it is providing the required functions. Therefore, for example, by stopping the functions of some ECUs that are not required for control or putting them into sleep mode depending on the vehicle situation, it is possible to reduce the power consumption of the entire electronic control system S. The technology that enables this type of control is called a partial network.

[0055] For example, in Fig. 8, while driving in a city, ECUs A, B, D, E, F, G, and I are powered on and active, while ECUs C, H, and J are in sleep mode. In other words, if the vehicle situation can be estimated, it becomes possible to identify the power state of each ECU.

[0056] The vehicle situation estimation unit 103 acquires the power supply state of the ECU corresponding to the estimated vehicle situation by using the power supply state table in Fig. 8. The power supply state table may be stored in the storage unit 105 and may be read out and referred to as necessary.

[0057] Using such a method for estimating the power supply state, the vehicle situation estimation unit 103 detects a change in the vehicle situation and estimates a change in the power supply state of the ECU accompanying the change in the vehicle situation. For example, the vehicle situation estimation unit 103 estimates each vehicle situation from the internal state information before and after the occurrence of the abnormality indicated in the security event log. Then, when the vehicle situation estimation unit 103 detects that the vehicle situation has changed, it estimates the power supply states corresponding to the vehicle situation before the change and the vehicle situation after the change, and estimates how they have changed.

[0058] For example, assume that the vehicle was driving in a city before the abnormality occurred, and was driving at high speed after the abnormality occurred. According to Fig. 8, it can be estimated that ECUs C and H changed from the sleep state to the power-on state, and ECU G changed from the power-on state to the sleep state due to this change in the vehicle situation.

[0059] Then, the false positive determination unit 104 determines whether the abnormality indicated by the security event log is a false positive based on the change in the power supply state. Specifically, when the power supply state changes, the security event log output from the security sensor of the ECU whose power supply state has changed is determined to be a false positive, taking into consideration that the power supply state is left in an electrically unstable state for a certain period of time after the change in the power supply state.

[0060] For example, if the fixed period is 1 second, a security event log output from the security sensor of ECU C, G, or H within a period of 1 second after a change in the power supply state of ECU C, G, or H is determined to be a false positive.

[0061] There are various reasons why an electrically unstable state may occur, including, for example: When ACC is on, each ECU is initializing, so it cannot transmit the information necessary to judge whether the sensor is alive or not, resulting in a false judgment that the sensor is faulty. When the power supply voltage is unstable or does not reach a stable voltage, software modules cannot communicate with each other, resulting in erroneous judgments.

[0062] In the above example, both the change from the power ON state to the sleep state and the change from the sleep state to the power ON state are covered. However, when the power ON state changes to the sleep state, the possibility of transmitting the security event log is low in light of the fact that the sleep state is entered after the transmission of the security event log is completed, so it is also acceptable to only cover the change from the sleep state to the power ON state.

[0063] The method of acquiring the internal state information when an abnormality occurs is the same as the method of acquiring the vehicle state information described above. That is, the internal state information can be acquired by requesting the ECU or a sensor for internal state information based on the time or the like indicated by the time stamp in the security event log, or the internal state information can be acquired continuously and stored in the storage unit 105, and the internal state information that occurred at the time or the like indicated by the time stamp can be read out.

[0064] As described above, according to the first embodiment, it is possible to identify a security event log that may have detected an abnormality caused by a change in the power supply state of the ECU due to a change in the vehicle situation estimated from the internal state information.

[0065] (Example 2) Information indicating the vehicle power supply state, communication network state, and diagnostic state (internal state information) The second embodiment is an example in which the internal state information is at least one of information indicating a power supply state of the vehicle, a state of the communication network, and a diagnostic state.

[0066] FIG. 9 is a table that records the relationship between the date and time, the vehicle power supply state, the communication network state, and the diagnostic state. The power supply state of the vehicle indicates the state of power supply to the devices that constitute the vehicle, and usually includes, but is not limited to, OFF, ACC, ON, and START modes. The table in Figure 9 shows examples of ACC ON and ACC OFF states. The communication network status indicates the type and status of the in-vehicle communication network. The table in Fig. 9 shows a case where the vehicle electronic control system S has three in-vehicle communication networks, Ethernet, CAN1, and CAN2. It also indicates whether each network is in a ready state (Ready) or in operation (Run). The diagnosis state indicates whether the vehicle is in a normal mode or a diagnosis mode. The table in Fig. 9 shows examples of the diagnosis mode and non-diagnosis mode states.

[0067] The vehicle state acquisition unit 102 acquires the table shown in Fig. 9 as the internal state information. The timing of acquisition is when the internal state information changes in Fig. 9. For example, 9:52:01 is when all in-vehicle communication networks change from Ready to Run, 11:08:00 is when the diagnostic state changes from non-diagnosis mode to diagnosis mode, 11:50:00 is when the power state changes from ACC ON to ACC OFF and all in-vehicle communication networks change from Run to Ready, and 12:10:00 is when the power state changes from ACC OFF to ACC ON. In this case, the date and time in FIG. 9 corresponds to the time when the internal state occurred.

[0068] In FIG. 9, the internal state information is recorded when the internal state of the vehicle changes, but instead of this, or in addition to this, the internal state information may be recorded periodically.

[0069] The false positive determination unit 104 determines whether or not the abnormality indicated by the security event log is a false positive, which is an abnormality not caused by a cyber attack, based on at least one of internal state information of the vehicle's power supply state, communication network state, and diagnosis state.

[0070] For example, from 11:08:00 to 11:40:00, the diagnostic mode continues and the in-vehicle communication network is in a standby state after switching from diagnostic mode to non-diagnostic mode, so the vehicle is not in a state expected for normal use due to repairs and diagnosis, and each security sensor is not in a state where it can make normal detections. Therefore, any abnormalities indicated by the security event log generated during this period are likely to be abnormalities not caused by a cyber attack, and are judged to be false positives.

[0071] For example, from 11:50:00 to 12:10:00, ACC is OFF and the in-vehicle communication network is not yet ready, and ACC is ON but the in-vehicle communication network is not yet ready, so normal communication is not possible over the in-vehicle communication network, and the security sensors are not in a state where they can perform normal detection. Therefore, any abnormalities indicated by the security event logs generated during this period are highly likely to be abnormalities not caused by a cyber attack, and are therefore determined to be false positives.

[0072] As described above, according to the second embodiment, by using internal state information consisting of at least one of the vehicle power state, the communication network state, and the diagnostic state to determine whether the security sensor is in a state where it can perform normal detection, it is possible to identify security event logs that may be false positives.

[0073] (Example 3) Information indicating the state of the ECU (internal state information) The third embodiment is an example in which the internal state information is information indicating the state of an ECU.

[0074] FIG. 10 is a table in which the date and time and the state of each ECU constituting the electronic control system S are recorded. The status of each ECU indicates whether the ECU is operating normally or not. In the table of Fig. 10, it indicates whether the ECU is operating normally (Run) or stopped (Stop).

[0075] The vehicle state acquisition unit 102 acquires the table shown in Fig. 10 as the internal state information. In Fig. 10, the timing of acquisition is when the internal state information changes. For example, 12:10:01 is when ECU A stops, 13:30:00 is when ECU B stops, and 13:35:00 is when ECU A and ECU B start operating. The operating state of the ECU may be determined based on, for example, the alive / dead information of each ECU. The alive / dead information may be stored in, for example, the event ID in Fig. 5. In this case, the date and time in FIG. 10 corresponds to the time when the internal state occurred.

[0076] In FIG. 10, the state of the ECU is recorded when the internal state of the vehicle changes, but instead of this, or in addition to this, the state of the ECU may be recorded periodically.

[0077] The false positive determination unit 104 determines, based on the state of the ECU, whether or not the anomaly indicated by the security event log is a false positive, which is an anomaly not caused by a cyber attack.

[0078] For example, ECU A is stopped during the period from 12:10:01 to 13:35:00, so it is highly likely that the security event log generated by the security sensor of ECU A during this period was generated due to a malfunction. Therefore, any abnormality indicated in the security event log generated by ECU A during this period is highly likely to be an abnormality not caused by a cyber attack, and is therefore determined to be a false positive.

[0079] For example, ECU B is stopped during the period from 13:30:00 to 13:35:00, so the security event log generated by the security sensor of ECU B during this period is likely to have been generated due to factors other than a cyber-attack. Therefore, any abnormality indicated in the security event log generated by ECU B during this period is likely to be an abnormality not caused by a cyber-attack, and is determined to be a false positive.

[0080] As described above, according to the third embodiment, by using internal state information representing the state of the ECU to determine whether a security event log has been generated that is inconsistent with whether the ECU is in an operating state or not, it is possible to identify security event logs that may be false positives.

[0081] (3) Operation of the log analysis device 11 Next, the operation of the log analysis device 11 will be described with reference to Fig. 11. Fig. 11 not only shows an attack analysis method executed by the log analysis device 11, but also shows the processing procedure of an attack analysis program that can be executed by the log analysis device 11. The order of these processes is not limited to the order shown in Fig. 11. In other words, the order may be changed as long as there are no constraints such as a relationship in which a certain step utilizes the result of the previous step. The same applies to flow diagrams of other embodiments.

[0082] The log acquisition unit 101 of the log analysis device 11 acquires a security event log indicating an abnormality detected by a security sensor of an electronic control device mounted on a vehicle (S101). The vehicle state information acquisition unit 102 acquires vehicle state information indicating the internal state and / or the external state of the vehicle when the abnormality detected by the security sensor occurs (S102). The false positive determination unit 104 determines whether or not the abnormality indicated by the security event log is a false positive, which is an abnormality not caused by a cyber attack, based on the vehicle state information acquired in S102 (S103). The processing unit 106 performs processing on the security event log determined to be a false positive in S103 (S104).

[0083] (4) Summary As described above, according to the log analysis device 11 of this embodiment, the internal state information among the vehicle state information is mainly used to determine whether a security event log is a false positive, so that measures can be taken against false positive logs that are mainly caused by the internal state of the vehicle. In addition, even if the security sensor itself does not have a mechanism for completely eliminating the detection of abnormalities that are not caused by a cyber-attack, it becomes possible to estimate whether an abnormality detected in a vehicle is an abnormality that is not caused by a cyber-attack.

[0084] (5) Configuration of the log analysis device 31 12 is a block diagram showing the configuration of the log analysis device 31 in this embodiment. The log analysis device 31 includes a log acquisition unit 301, a vehicle state information acquisition unit 302, a false positive determination unit 304, a storage unit 305, and a processing unit 306. The configuration of the log analysis device 31 is basically the same as that of the log analysis device 11, but the connection destination and the content of the processing are slightly different. The following description will focus on the differences from the log analysis device 11, and will omit descriptions of the same configuration and functions as the log analysis device 11 and will quote the description of the log analysis device 11.

[0085] The log acquisition unit 301 acquires a security event log indicating an abnormality detected by a security sensor of an ECU mounted on a vehicle. For example, the log is acquired by receiving a security event log transmitted from an external communication ECU of the electronic control system S. The security event log is, for example, QSEv, but may be SEv. Regarding the timing for acquiring security event logs, it is desirable to receive all security event logs accumulated in the vehicle over a certain period of time at once, but it is also possible to receive security event logs each time they occur.

[0086] The vehicle state information acquisition unit 302 acquires vehicle state information indicating the internal state and / or external state of the vehicle "when an abnormality occurs." Since the vehicle state acquisition unit 302 is provided outside the vehicle, it mainly acquires external state information. However, this does not prevent the acquisition of internal state information from the electronic control system S, the log analysis device 11, etc.

[0087] There are various methods for acquiring vehicle state information when an abnormality occurs. For example, the vehicle state information can be acquired by reading the time stamp of the security event log and requesting the external device 40 for vehicle state information that occurred at the same time or close to the time indicated by the time stamp. Alternatively, the vehicle state information can be acquired by continuously acquiring and storing the vehicle state information in the storage unit 305, and reading out vehicle state information that occurred at the same time or close to the time indicated by the time stamp. Instead of the time indicated by the time stamp, the transmission time or reception time of the security event log can also be used to indicate when an abnormality occurred.

[0088] Specific examples of vehicle state information will be described later, but the vehicle state information may include the "time" at which an internal state or external state occurred, or the "duration" during which an internal state or external state continued. Other specific examples of vehicle state information and methods of determining false positives using the information will be described in the fourth to sixth embodiments.

[0089] The false positive determination unit 304 determines, "based" on the vehicle status information acquired by the vehicle status information acquisition unit 302, whether or not the abnormality indicated in the security event log acquired by the log acquisition unit 301 is a false positive, that is, an abnormality not caused by a cyber attack.

[0090] The storage unit 305 stores the security event log acquired by the log acquisition unit 301, the vehicle state information acquired by the vehicle state information acquisition unit 302, the determination result by the false positive determination unit 304, and other information. However, it is not essential to store these.

[0091] The processing unit 306 performs processing "on" the security event log that is determined to be a false positive.

[0092] The specific contents of the process may be determined according to the application or purpose, for example, deleting false positive logs determined to be false positives and preventing false positive logs from being output from the log analysis device 11, setting a flag indicating that a false positive is present in a false positive log determined to be a false positive and outputting the false positive log to the attack analysis device, notifying an external device or the like that a false positive log has occurred, etc. In addition, the processing unit 306 outputs security event logs that have not been determined to be false positives to the attack analysis device.

[0093] (6) Types of vehicle condition information and method for determining false positives in the log analysis device 31 (Example 4) Location information (internal state information), known false positive log occurrence patterns (external state information) The fourth embodiment is an example in which the internal state information is vehicle position information, and the external state information is a known false positive log occurrence pattern linked to a position.

[0094] FIG. 13 is a table recording the relationship between the location and known false positive log occurrence patterns. In the event column, events for the vehicle are described. The event coordinates indicate the coordinates where the event is taking place. The event time indicates the period during which the event is taking place (corresponding to "time"). The known false positive log occurrence pattern indicates a known log occurrence pattern in an event (corresponding to "information indicating a log occurrence pattern").

[0095] The vehicle state information acquisition unit 302 acquires "location information" of the vehicle as internal state information. For example, the vehicle state information acquisition unit 302 acquires location information generated by the output of various sensors such as a GPS receiver and an acceleration sensor provided in the vehicle, by receiving the location information from an external communication ECU of an electronic control system S provided in the vehicle. The timing of acquisition is preferably simultaneous with and linked to a security event log. For example, the location information may be stored in context data of the security event log and received. Here, the "location information" may be information that specifies the location where the vehicle is located, in addition to location information specified by latitude and longitude acquired by a GPS or the like.

[0096] Further, the vehicle state information acquiring unit 302 acquires a table shown in Fig. 13. The vehicle state acquiring unit 302 desirably acquires the table from an external server 40 which is updated from time to time by, for example, a dealer A or a car accessory store B. The timing of acquisition is preferably when the table is updated, but it may be acquired periodically.

[0097] The false positive determination unit 304 determines whether the anomaly indicated by the security event log is a false positive, which is an anomaly not caused by a cyber-attack, based on the location information and the table shown in Fig. 13. Specifically, if the vehicle position indicated by the location information matches a predetermined range centered on the event coordinates, the time when the anomaly indicated by the security event log occurred is included in the range of the event time, and the security event log matches a known false positive log occurrence pattern, the security event log is determined to be a false positive.

[0098] For example, if the location information is longitude X1 east and latitude Y1 north, the timestamp of the security event log is within the range of t1 to t2, and the security event log is a log of an existing ECU being unconnected, the security event log is determined to be a false positive, as this is an abnormality detected due to an event that occurred at dealer A to remove and connect the existing ECU.

[0099] As described above, according to the fourth embodiment, by using internal state information consisting of the vehicle position and external state information consisting of false positive log occurrence patterns linked to the position, it is possible to identify security event logs that may be false positives.

[0100] (Example 5) Information for identifying a vehicle (internal state information), information indicating conditions for disabling a security event log (external state information) The fifth embodiment is an example in which the internal state information is information for identifying a vehicle, and the external state information is information indicating a condition for invalidating a security event log.

[0101] FIG. 14 is a table recording the relationship between vehicles and periods during which security event logs are disabled. The vehicle indicates the vehicle for which the security event log should be disabled. The state indicates the state in which the vehicle is placed. The start time indicates the time when the state starts (corresponding to a "time" or a "period"). The end time indicates the time when the state ends (corresponding to a "time" or a "period"). That is, in FIG. 14, a period is defined as a condition for invalidating the security event log.

[0102] The vehicle state information acquisition unit 302 acquires information identifying the vehicle as the internal state information. For example, the vehicle state information acquisition unit 302 acquires the information identifying the vehicle stored in the vehicle by receiving the information from an external communication ECU of the electronic control system S provided in the vehicle. The timing of acquisition is preferably simultaneous with and linked to the security event log. For example, the vehicle state information may be received by storing the information identifying the vehicle in context data of the security event log.

[0103] Further, the vehicle state information acquiring unit 302 acquires a table shown in Fig. 14. The vehicle state acquiring unit 302 desirably acquires the table from an external device 40 which is updated from time to time by, for example, a manufacturer or a dealer. The timing of acquisition is preferably when the table is updated, but it may be acquired periodically.

[0104] The false positive determination unit 304 determines whether or not the anomaly indicated by the security event log is a false positive, which is an anomaly not caused by a cyber-attack, based on the information identifying the vehicle and the table shown in Fig. 14. Specifically, if the vehicle indicated by the information identifying the vehicle matches the vehicle in the table in Fig. 14, and the time when the anomaly indicated by the security event log occurred is within the range of the start time and end time in the table in Fig. 14, the security event log is determined to be a false positive.

[0105] As described above, according to Example 5, by using internal state information consisting of information that identifies a vehicle and external state information consisting of information that indicates the conditions for invalidating a security event log, it is possible to identify security event logs that may be false positives.

[0106] (Example 6) Communication failure, operating status of external device (external status information) The sixth embodiment is an example in which the external state information is an event that invalidates a security event log and the time or time period of the event. Here, information indicating a communication failure or an operating state of an external device will be described.

[0107] FIG. 15 is a table recording periods of communication failures and operating conditions of external devices. The event described here is an event related to an external communication device or a communication failure. The start time indicates the time when the event starts (corresponding to "time" or "period"). The end time indicates the time when the event ends (corresponding to "time" or "period").

[0108] The vehicle state information acquisition unit 302 acquires the table shown in Fig. 15. The vehicle state information acquisition unit 302 desirably acquires the table from the external device 40, which is updated from time to time by, for example, a server operator or a communication carrier. The acquisition is desirably performed when the table is updated, but may be performed periodically.

[0109] The false positive determination unit 304 determines whether or not the anomaly indicated by the security event log is a false positive, which is an anomaly not caused by a cyber-attack, based on the table shown in Fig. 15. Specifically, if the time at which the anomaly indicated by the security event log occurred is within the range of the start time and end time in the table in Fig. 15, the security event log is determined to be a false positive.

[0110] In addition to the example of Figure 5, the event may be an event based on information obtained as external condition information, such as when the outside air temperature is higher or lower than a predetermined temperature, when the amount of rainfall is greater than a predetermined amount, etc., and is provided by a source other than the manufacturer or dealer as in Example 5.

[0111] As described above, according to the sixth embodiment, by using external state information including information indicating a communication failure and the operating state of an external device, it is possible to identify security event logs that may be false positives.

[0112] (7) Operation of the log analysis device 31 Since the operation of the log analysis device 31 is the same as that of the log analysis device 11, the description of the operation of the log analysis device 11 and FIG.

[0113] (8) Summary As described above, according to the log analysis device 31 of this embodiment, the external condition information among the vehicle condition information is mainly used to determine whether a security event log is a false positive, so that measures can be taken against false positive logs that are mainly caused by the external condition of the vehicle. In addition, even if the security sensor itself does not have a mechanism for completely eliminating the detection of abnormalities that are not caused by a cyber-attack, it becomes possible to estimate whether an abnormality detected in a vehicle is an abnormality that is not caused by a cyber-attack.

[0114] 3. Embodiment 2 2, the log analysis device 12 of this embodiment does not include a log analysis device provided outside the vehicle, but is configured only by the log analysis device 12 provided in the vehicle. The log analysis device 12 of this embodiment has the functions of both the log analysis device 11 and the log analysis device 31 of the first embodiment.

[0115] 16 is a block diagram showing the configuration of the log analysis device 12 in this embodiment. The log analysis device 12 includes a log acquisition unit 101, a vehicle state information acquisition unit 102, a vehicle situation estimation unit 103, a false positive determination unit 104, a storage unit 105, and a processing unit 106. The configuration of the log analysis device 12 is basically the same as the configuration of the log analysis device 11, so the description of the log analysis device 11 will be quoted.

[0116] However, in this embodiment, since the log analysis device 12 installed in the vehicle also executes the examples 4, 5, and 6 of the first embodiment, the vehicle state information acquisition unit 102 can also acquire external state information. The external state information can be acquired from the external device 40, for example, by using a wireless communication method.

[0117] 4. Embodiment 3 3, the log analysis device 32 of this embodiment does not include a log analysis device provided in the vehicle, but is configured only with the log analysis device 32 provided outside the vehicle. The log analysis device 32 of this embodiment has the functions of both the log analysis device 11 and the log analysis device 31 of the first embodiment.

[0118] 17 is a block diagram showing the configuration of the log analysis device 32 in this embodiment. The log analysis device 32 includes a log acquisition unit 301, a vehicle state information acquisition unit 302, a vehicle situation estimation unit 303, a false positive determination unit 304, a storage unit 305, and a processing unit 306. The configuration of the log analysis device 32 is basically the same as the configuration of the log analysis device 31 except for the vehicle situation estimation unit 303, so the description of the log analysis device 31 will be cited. In addition, the vehicle situation estimation unit 303 of the log analysis device 32 is basically the same as the configuration of the vehicle situation estimation unit 103 of the log analysis device 11, so the description of the log analysis device 11 will be cited.

[0119] However, in this embodiment, since Example 1, Example 2, and Example 3 of the first embodiment are also executed by the log analysis device 32 provided outside the vehicle, the vehicle state information acquisition unit 302 can also acquire internal state information. The internal state information can be acquired by using a wireless communication method, for example, via the external communication ECU of the electronic control system S of the vehicle.

[0120] 3. Summary The features of the log analysis device and the like in each embodiment of the present invention have been described above.

[0121] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.

[0122] The block diagrams used to explain the embodiments classify and organize the configuration of the device by function. The blocks showing the respective functions are realized by any combination of hardware or software. In addition, since the block diagrams show the functions, they can also be understood as disclosures of a method invention and a program invention that realizes the method.

[0123] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints such as a relationship in which one step utilizes the results of another step prior to it.

[0124] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.

[0125] Moreover, examples of the form of the log analysis device of the present invention include the following. Examples of the component form include a semiconductor element, an electronic circuit, a module, and a microcomputer. Examples of semi-finished products include electronic control units (ECUs (Electric Control Units)) and system boards. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.

[0126] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log analysis device.

[0127] It is assumed that the log analysis device of the present invention will be used, particularly on the server side, for the purpose of providing various services. In providing these services, the log analysis device of the present invention will be used, the method of the present invention will be used, and / or the program of the present invention will be executed.

[0128] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as a memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing the program.

[0129] A program stored in a non-transient physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]

[0130] The log analysis device of the present invention may be used to analyze security event logs generated by security sensors in electronic control systems installed other than in vehicles. [Explanation of symbols]

[0131] 11, 12, 31, 32 log analysis device, 101, 301 log acquisition unit, 102, 302 vehicle state information acquisition unit, 103, 303 vehicle situation estimation unit, 104, 304 false positive determination unit, 105, 305 storage unit, 106, 306 processing unit, 40 external device

Claims

1. A log acquisition unit (101, 301) that acquires a security event log indicating an abnormality detected by a security sensor of an electronic control unit mounted on a vehicle; A vehicle state information acquisition unit (102, 302) that acquires vehicle state information indicating an internal state and / or an external state of the vehicle when the abnormality occurred; A false positive determination unit (104, 304) that determines, based on the vehicle state information, whether the abnormality indicated by the security event log is a false positive that is not caused by a cyber attack; A processing unit (106, 306) that performs processing on the security event log determined to be a false positive, A log analysis device (11, 12, 31, 32).

2. The vehicle state information includes a time when the internal state or the external state occurred, or a time during which the internal state or the external state continued, The log analysis device according to Claim 1.

3. Furthermore, a vehicle situation estimation unit (103, 303) is provided that estimates a vehicle situation, which is a state related to the running of the vehicle, from the internal state information indicating the internal state among the vehicle state information, and estimates a change in the power supply state of the electronic control unit accompanying a change in the vehicle situation, The false positive determination unit determines whether the abnormality indicated by the security event log is the false positive based on the change in the power supply state. The log analysis device according to Claim 2.

4. The internal state information indicating the internal state among the vehicle state information is at least one of information indicating a power supply state of the vehicle, a state of a communication network of the vehicle, and a diagnostic state of the vehicle. The log analysis device according to Claim 2.

5. The internal state information indicating the internal state among the vehicle state information is information indicating a state of the electronic control unit. The log analysis device according to Claim 2.

6. The internal state information indicating the internal state among the vehicle state information is position information of the vehicle, The external state information indicating the external state among the vehicle state information is information indicating a log generation pattern of a security event log generated by an abnormality not caused by a cyber attack associated with a position. The log analysis device according to Claim 2.

7. The internal state information indicating the internal state among the vehicle state information is information for identifying the vehicle, The external state information is further information indicating a condition for invalidating the security event log. The log analysis device according to claim 2.

8. Among the vehicle state information, the external state information indicating the external state is information indicating a communication failure when the vehicle communicates with an external device. The log analysis device according to claim 2.

9. Among the vehicle state information, the external state information indicating the external state is information indicating the operating state of the external device when the vehicle communicates with the external device. The log analysis device according to claim 2.

10. The log analysis device is provided in the vehicle. The log analysis device (11, 12) according to any one of claims 1 to 5.

11. The log analysis device is provided outside the vehicle. The log analysis device (31, 32) according to any one of claims 1 to 2, 6 to 9.

12. A log analysis method executed by a log analysis device (11, 12, 31, 32), comprising: Obtaining a security event log indicating an abnormality detected by a security sensor of an electronic control unit mounted on a vehicle (S101); Obtaining vehicle state information indicating the internal state and / or external state of the vehicle when the abnormality occurred (S102); Based on the vehicle state information, determining whether the abnormality indicated by the security event log is a false positive that is not caused by a cyber attack (S103); Performing processing on the security event log determined to be a false positive (S104). Log analysis method.

13. A log analysis program executable by a log analysis device (11, 12, 31, 32), the log analysis program comprising: The log analysis program causes the log analysis device to: Obtain a security event log indicating an abnormality detected by a security sensor of an electronic control unit mounted on a vehicle (S101); Obtain vehicle state information indicating the internal state and / or external state of the vehicle when the abnormality occurred (S102); Based on the vehicle state information, determine whether the abnormality indicated by the security event log is a false positive that is not caused by a cyber attack (S103); Perform processing on the security event log determined to be a false positive (S104). Log analysis program.

14. Among the vehicle state information, the internal state information indicating the internal state is the position information of the vehicle. The log analysis device according to claim 2.

15. A system comprising a vehicle and a log analysis device provided outside the vehicle. The vehicle is equipped with an electronic control system having a plurality of electronic control units, and each electronic control unit has a security sensor for detecting an abnormality. The log analysis device a log acquisition unit (101, 301) that acquires a security event log indicating an abnormality detected by the security sensor of the electronic control unit mounted on the vehicle; a vehicle state information acquisition unit (102, 302) that acquires vehicle state information indicating the internal state and / or external state of the vehicle when the abnormality occurs; a false positive determination unit (104, 304) that determines, based on the vehicle state information, whether the abnormality indicated by the security event log is a false positive that is not caused by a cyber attack; a processing unit (106, 306) that performs processing based on the determination result of the false positive determination unit. System.