Determination circuit, and control system

The proposed determination circuit and control system for IoT devices utilize a full binary tree structure with optimized registers and comparators to reduce circuit scale, addressing the resource constraints and complexity of conventional security measures for efficient malware detection.

JP2025103875APending Publication Date: 2025-07-09KOGAKUIN UNIVERSITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023221567
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-07-09

AI Technical Summary

Technical Problem

Conventional security countermeasures for IoT devices are complex and resource-intensive, making them impractical for devices with severe resource constraints, and existing hardware-based malware detection methods require large circuit scales that are not suitable for IoT devices.

Method used

A determination circuit and control system using a full binary tree structure with reduced circuit scale, incorporating node information, feature quantity, and determination value registers, and a comparator to perform malware detection efficiently.

Benefits of technology

Enables effective malware detection on IoT devices with a reduced circuit scale, optimizing resource usage and maintaining detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025103875000001_ABST
    Figure 2025103875000001_ABST
Patent Text Reader

Abstract

To allow determination of a tree structure while reducing a circuit scale.SOLUTION: A determination circuit performs determination using a predetermined tree structure of a complete binary tree in a processor loaded on a device and comprises: a register unit comprising a node information register file having tables of thresholds and feature quantity numbers for every node, a feature quantity register file having a table of feature quantities allocated to each type of the feature quantities and being updated by output of a core, and a determination value register file having a table allocated with determination values of the number according to depth n; a comparator for calculating the next node; and a control circuit which determines a path from a route of the tree structure to leaves by referring to a value of the register unit and outputs a value of Value according to the determination value of the determination value register file corresponding to the path.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Conventionally, there has been a technology related to anomaly detection against cyberattacks.

[0002] For example, there is a technology related to a method that enables appropriate determination of the importance of logs (see Patent Document 1). In this technology, an analysis model using a random forest or the like is created, and an analysis device that operates a software program capable of determining the importance of log entries is disclosed.

[0003] In addition, there is a technology related to a method for verifying forgery of a startup program using a microcomputer (see Patent Document 2). In this technology, a hash value is calculated from the startup program and compared with the hash value of the signature data for verification.

[0004] Furthermore, a technology related to malware detection by circuit-level hardware using processor information has been studied (see Non-Patent Document 1). In this technology, the implementation of a detection circuit adjacent to the core in one LSI is being studied.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Patent Document 2

Patent Document 3

Non-Patent Documents

[0006]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] Recently, cases of IoT devices being infected with malware have been increasing. However, conventional security countermeasure software for PCs and servers is complex software and may slow down operations even on PCs and servers. Therefore, it is not practical to install it on IoT devices that need to be provided in a small size and at low cost. For example, security countermeasure software cannot be installed and operated on surveillance cameras. Also, verification such as in Patent Document 2 cannot handle the detection of various malware. On the other hand, as in Non-Patent Document 1, a technique for implementing a malware detection mechanism in hardware rather than software has been proposed.

[0008] In response to such existing technologies, the inventors of the present application developed an improved method that enables the tree structure and data of discriminators incorporated in hardware to be updated (see Patent Document 3). However, there are several problems with the improved method. First, it is necessary to hold a comparison circuit and a register for each node. Second, wiring for distributing data to the nodes needs to be drawn, and these increase according to the depth of the tree. That is, the circuit scale of the tree structure increases according to the depth of the tree. Since the resource constraints of IoT devices are severe, it is desirable to reduce the circuit scale as much as possible.

[0009] The present invention has been made to solve the above problems, and an object thereof is to provide a determination circuit and a control system that enable determination based on a tree structure while reducing the circuit scale.

Means for Solving the Problems

[0010] In order to achieve the above object, a determination circuit according to the present invention is a determination circuit that performs determination using a predetermined full binary tree structure in a processor mounted on a device, and includes a node information register file having a table of threshold values and feature quantity numbers for each node, a feature quantity register file having a table of feature quantities assigned to each type of feature quantity and updated by the output of a core, and a determination value register file having a table to which a number of determination values corresponding to depth n are assigned. The register unit includes a comparator for calculating the next node, and a control circuit that determines a path from the root to the leaf of the tree structure with reference to the values of the register unit and outputs a value of Value according to the determination value of the determination value register file corresponding to the path.

[0011] A control system according to the present invention is a control system including a determination circuit that performs determination using a predetermined full binary tree structure in a processor mounted on a device, and includes a node information register file having a table of threshold values and feature quantity numbers for each node, a feature quantity register file having a table of feature quantities assigned to each type of feature quantity and updated by the output of a core, and a determination value register file having a table to which a number of determination values corresponding to depth n are assigned. The register unit includes a comparator for calculating the next node, and a control circuit that determines a path from the root to the leaf of the tree structure with reference to the values of the register unit and outputs a value of Value according to the determination value of the determination value register file corresponding to the path.

Advantages of the Invention

[0012] According to the determination circuit and the control system of the present invention, it is possible to obtain an effect of enabling determination based on a tree structure while reducing the circuit scale.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Embodiments for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. First, the circuit configuration for implementing the tree structure that is a prerequisite in the embodiments of the present invention will be described. In the present embodiment, in order to realize a discriminator learned with the tree structure of a random forest on a circuit, a circuit for hardware-implementing the tree structure is assumed.

[0015] In this embodiment, attention is paid to the following characteristics of a complete binary tree. FIG. 1 is a schematic diagram showing an example of the tree structure of a complete binary tree. (1) The lengths from the root to the leaf nodes are all the same. (2) There are two nodes at the transition destination of one node (excluding the leaf nodes). (3) There are two judgment values at the transition destination of the leaf nodes. By utilizing these characteristics and changing the implementation method of the tree structure, the circuit scale is reduced.

[0016] In Non-Patent Document 1 and Patent Document 3, the tree structure of a complete binary tree is composed of a plurality of nodes and the edges connecting them. The number of nodes in the tree structure of a complete binary tree is 2 n -1 (n is the depth of the tree). The configuration of one node is such that there is one comparison circuit and three register files (each node holds a threshold value, a feature quantity number, and a feature quantity respectively). The wiring for transmitting and receiving the register values of each node requires 2 n -1 sets.

[0017] (Outline of the method of this embodiment) In this embodiment, the tree structure of a complete binary tree is composed only of a plurality of register files. The edges are implicitly represented. The circuit is assumed to have one comparison circuit and two register files, and the tree structure is configured by the operation of the comparison circuit that reads information from the register files. That is, instead of managing each node, the information indexed in the register files is held, and the values are obtained for calculation to configure the tree structure. In the register files, a register file for holding the values of the threshold and the feature quantity number, and a register file for holding the feature quantity are provided. Two sets of wiring for transmitting and receiving the values necessary for calculation are required between the control circuit and the register files.

[0018] (Configuration of the control system) The configuration of the control system according to the embodiment of the present invention will be described. FIG. 2 is a configuration example of the control system of this embodiment. As shown in FIG. 2, the control system 1 includes a device 2 and an external device 120. The device 2 includes a processor 10 (LSI) and a communication unit 30. In the processor 10 mounted on the device 2, a core 20 and a main circuit 100 are incorporated adjacent to each other. The core 20, the communication unit 30, and the main circuit 100 are connected via a communication bus 60. The main circuit 100 (determination circuit) includes a control circuit 110, a register unit 112, and a comparator 114. The main circuit 100 acquires a value for constructing a tree structure from the register unit 110 under the control of the control circuit 110, and discriminates the feature amount output from the core 20. The discrimination is, for example, discrimination as to whether it is malware or normal.

[0019] The core 20 is a circuit that executes a program as a CPU and performs calculations, and outputs a feature amount to the main circuit 100. Note that the processor information output by the CPU is input to the main circuit 100 as a feature amount via a multiplexer (not shown), but since this is not the main technical aspect of this method, the description is omitted. The communication unit 30 is connected to a network N such as the Internet, acquires update information of a register file, etc., and appropriately updates the register unit 112 of the main circuit 100.

[0020] The register unit 112 includes a node information register file (NIRF: Node Info Register File) 120, a feature amount register file (FVRF: Feature Value Register File) 122, and a determination value register file (DVRF: Decision Value Register File) 124. Each register file is connected to the control circuit 110 by each wiring.

[0021] The control circuit 110 controls the whole, determines the path from the root to the leaf of the tree structure by referring to the value in the register section 112, and outputs the value of Value according to the DVRF corresponding to the path. The comparator 114 compares the feature quantity with the threshold value. Note that the control circuit 110 is a state machine, and the comparator 114 uses a general-purpose circuit, so detailed description is omitted (hereinafter, the symbol of the comparator 114 is appropriately omitted for convenience of explanation).

[0022] To briefly explain the calculation mode of this embodiment, each term will be explained by taking a decision tree of depth 3 as an example. FIG. 3 is an example of a decision tree of depth 3. On the premise that it becomes a complete binary tree by node extension. Note that in FIG. 3, a decision tree of depth 3 is shown as an example, but in another figure, a tree of depth 2 may be used.

[0023] The node numbers (numbers assigned to each node) are [No. 1] for depth 1 (root), [No. 2, No. 3] from the left for depth 2, and [2 n-1 th ~ 2 n - 1st] from the left for depth n. The decision value is the label output by the tree (leaf) as the decision result. The label assigns normal (0) and attack (1). The decision value numbers assign Val.0 ~ 2 n - 1 from the left to the decision value.

[0024] The calculation methods of the next node and the decision value number will be explained. The calculation method of the next node (before optimization) is: (1) double the current node number; (2) add 0 if the node output is True, and add 1 if it is False. The calculation method of the decision value number (before optimization) is: (1) double the node number and subtract 2 n (n is the depth of the tree), (2) add 0 to the number if the node output is True, and add 1 if it is False. Note that these two calculation methods (before optimization) are for ease of explanation. They require multipliers and adders, and the circuit scale becomes large. In the control circuit 110 after optimization described below, a circuit capable of low-cost calculation can be realized.

[0025] The operation flow of the control circuit 110 is as follows: steps 1 to 9 below. Based on these steps, the details of the calculation mode will be described. Note that steps 8 and 9 only overwrite the register unit 110, so detailed descriptions will be omitted. 1. Set the current node as the root 2. Obtain the threshold value and the feature quantity number of the current node from the NIRF 3. Obtain the feature quantity corresponding to the feature quantity number (obtained in step 2) from the FVRF 4. Use a comparator to compare the feature quantity (obtained in step 3) with the threshold value (obtained in step 2) 5. Calculate the next node from the comparison result and set the calculation result as the current node 6. If the current node exists, go to step 2; otherwise, end (go to step 7) 7. Perform a determination (obtain a determination value from the DVRF and finalize the determination) 8. Set the feature quantity sent from the core at that time to the FVRF 9. If there are updates to the tree structure, set them to the NIRF and DVRF. Return to step 1

[0026] First, for 1 to 6, the operation flow of a series of calculation processes using NIRF and FVRF will be described. FIG. 4 is an example of data tables of NIRF, FVRF, and DVRF. FIG. 5 is an example of a decision tree to which NIRF and FVRF are assigned. NIRF has a table of "threshold value, feature quantity number" for each node. In the example, the values are held as node 1 "90, 0", node 2 "70, 1", node 3 "80, 2", and so on. FVRF has a table of feature quantities assigned to various types of feature quantities. The feature quantities are updated by the output of the core. In the example, the number assignments are such that for feature quantity number 0: instruction cache hit rate (IH), feature quantity number 1: data cache hit rate (DH), feature quantity number 2: branch prediction hit rate (BH), feature quantity number 3: program counter (PC), and so on, and the values of each feature quantity are held. The feature quantities are updated by the output of the processor 10. These are examples of options for a set of feature quantities. Since NIRF becomes a complete tree structure by extending branches as shown in Patent Document 3, the numbering is unique, which contributes to the simplification of the calculation of the next node. In DVRF, there is a table to which determination values of Val.0 to 2 n -1 (a number according to the depth n) are assigned and are referred to during determination. Note that NIRF not only holds information on the threshold value and feature quantity number, but also implicitly holds information on the edges connecting each node. For example, since the first entry of NIRF indicates node 1, after referring to the first entry, either the second or the third entry will be referred to. Because of this property, NIRF does not have edge information to the next node.

[0027] In FIG. 5, a decision tree of depth 2 is taken as an example. At node 1, "IH > 90" is compared. If true, it goes to node 2; if false, it goes to node 3. At node 2, "DH > 70" is compared, and at node 3, "IH < 80" is compared. Thereby, a label is output.

[0028] Figures 6 and 7 are diagrams for explaining the operation flow of the control circuit 110 and the reference relationship of the registers. In Figure 6, the reference relationships of (1-1) to (6-1) when the first node is set to the current node are shown. In Figure 7, the reference relationships of (1-2) to (6-2) when the second node is set to the current node are shown. 1. In (1-1), the first node is set. 2. In (2-1) and 3. (3-1), the threshold value 90 and the feature amount 98 corresponding to the first node are acquired. 4. In the comparator of (4-1), result = 0 (true) since "if(98>90)". 5. In (5-1), the calculation of the next node is "next node = current node << 1 + result". 6. In (6-1), since the current node is the second, it returns to 2. and processes the second node. Note that in 5., since the left 1-bit shift always has a shift direction to the left and a shift amount of always 1, it can be realized only by switching the connection of the wiring without using a shifter circuit. The connection of the wiring will be described later. The flow of (2-1) to (6-2) is the same for the second node. In (5-2), since there is no node and the upper limit of the node number is exceeded, (6-2) ends and it proceeds to 7. As described above, the operation flow of a series of calculation processes is repeated up to the upper limit of the node number.

[0029] Figures 8 and 9 are diagrams for explaining the configuration of the control circuit and the flow of number update. state_reg: A register that holds state. state indicates the number of the operation flow. Next_state: A circuit that updates state_reg according to the operation flow. Cur_node_reg: A register that holds the current node number or the determination value number. Th_reg: A register that holds the threshold value. FV_num_reg: A register that holds the feature amount number. FV_reg: A register that holds the feature amount. Bit_reg: A register (update register) that updates the number by changing the connection of the wiring representing the bit shift. Note that the numerical values held in each register are in binary for the part of the next node calculation surrounded by a dotted line and in decimal for other parts.

[0030] 5. Next, calculate the next node in Bit_reg. Set the value obtained from Cur_node_reg as a binary value and remove the most significant bit. In the example of the first node in Figure 8, the binary number "01" is set, the most significant bit 0 is removed, if the comparison result of the comparator is true, obtain the value of result and set 0 to the least significant bit at the end, and perform bit concatenation. If the comparison result is false, add 1. In the example of Figure 8, the next node becomes 2 and is set in Cur_node_reg. 6. Next, in Next_state, if the removed most significant bit is 0, there is a next node, if it is 1, there is no next node, and Cur_node_reg is used as the determination value number (Val.).

[0031] Figure 10 is a diagram showing an example of the wiring configuration of the update register. The example of the update register (Bit_reg) in Figure 10 is assumed to be configured with 5 bits (0 to 4), but the number of bits can be appropriately designed. Also, the wiring other than the calculation by reconnecting is omitted. In the update register, connect a comparator to the wiring at the end bit on the in side, and reconnect the wiring so that it shifts left by 1 bit from the out side to the in side. Since the left 1-bit shift always has the shift direction to the left and the shift amount is always 1, the calculation of the next node can be realized only by switching the connection of the wiring without using a shifter circuit. The update register is a register that can update the current node number by reconnecting the wiring by shifting each bit of the binary number to the left by 1 bit in this way.

[0032] Next, regarding 7., the determination mode will be described. The control circuit 110 accesses the DVRF using the determination value number as an index and obtains the determination value. The control circuit 110 determines that if the determination value is 1, it is an attack (malware), and if it is 0, it is normal. Although the determination values are 1 and 0 as an example, it is also possible to use integer values other than 1 and 0 for the determination values and obtain the final determination result from the determination values of multiple trees.

[0033] As described above, according to the control system and the control circuit of the present embodiment, it is possible to perform determination by a tree structure while reducing the circuit scale.

[0034] Supplement to the method of the above-described embodiment. FIG. 11 is an example of the tree structure and the register reference relationship when the depth is increased from 2 to 3. Even if the depth is 4 or more, only the entry and the bit width increase, and the operation is the same. In the example of FIG. 11, it is assumed that the structure of the decision tree transitions as 1st → 3rd → 6th → Val.4 as shown by the thick frame here. Actually, the binary calculation method is adopted, but the case of decimal notation is exemplified. In decimal notation, it is calculated as "1st × 2 + False(1) = 3rd" and transitions to the 3rd. Next, it is calculated as "3rd × 2 + True(0) = 6th" and transitions to the 6th. Next, it is calculated as "6th × 2 + True(0) = 12th (exceeding the upper limit) → determination value number: 12th - 2 3 = Val.4", and Val.4 is referred to from the calculation result. For the same example, the calculation in binary notation is exemplified. In binary notation, [ ] is the bit to be deleted. "[0]01st <bit concatenation> False(1) = 011st" → "[0]11st <bit concatenation> True(0) = 110th" → "[1]10th <bit concatenation> True(0) = 100th" is calculated, and since it is 100 in binary notation, the value of the Value of Val.4 can be obtained in decimal notation.

[0035] The number of registers related to the circuit scale when the depth of the tree is increased is NIRF: 2 n - 1 entry (number of entries = number of nodes), DVRF: 2 n entries (number of entries = number of nodes + 1), and the relationship with Cur_node_reg: bit width n. Also, regarding the circuit scale, in the prior art, 2 n - 1 set of wirings for sending the feature amount to the comparator was required. On the other hand, in the method of this embodiment, only 1 set of wirings for sending the feature amount from the FVRF to the comparator is sufficient.

[0036] Note that the present invention is not limited to the above-described embodiment, and various modifications and applications are possible without departing from the gist of the present invention.

Explanation of Reference Numerals

[0037] 1 Control system 2 Device 10 Processor 20 Core 100 Main Circuit 110 Control Circuit 112 Register Section 114 Comparator

Claims

1. A determination circuit that performs determination using a predetermined full binary tree structure in a processor mounted on a machine, a node information register file having a table of threshold values and feature quantity numbers for each node, a feature quantity register file having a table of feature quantities assigned to various types of feature quantities and updated by the output of a core, and a determination value register file having a table to which a number of determination values corresponding to depth n are assigned; a register unit comprising: a comparator for calculating the next node; a control circuit that determines a path from the root to the leaf of the tree structure with reference to the values of the register unit and outputs a Value according to the determination value of the determination value register file corresponding to the path; A determination circuit including the above.

2. The control circuit: acquires the threshold value and the feature quantity number of the current node from the feature quantity register file, acquires the feature quantity corresponding to the feature quantity number of the current node from the feature quantity register file, compares the feature quantity with the threshold value using the comparator, calculates the next node from the comparison result, and sets the calculation result in the current node. As an operation flow of a series of calculation processes, this is repeated up to the upper limit of the node number. The determination circuit according to claim 1.

3. In the calculation of the next node, the control circuit updates the current node number by deleting the most significant bit and updating the least significant bit with the value of the comparator using an update register capable of updating the current node number by rewiring by a left 1-bit shift of each bit of the binary number. The determination circuit according to claim 2.

4. A control system including a determination circuit that performs determination using a predetermined full binary tree structure in a processor mounted on a machine, a node information register file having a table of threshold values and feature quantity numbers for each node, a feature quantity register file having a table of feature quantities assigned to various types of feature quantities and updated by the output of a core, and a determination value register file having a table to which a number of determination values corresponding to depth n are assigned; a register unit comprising: a comparator for calculating the next node; a control circuit that determines a path from the root to the leaf of the tree structure with reference to the values of the register unit and outputs a Value according to the determination value of the determination value register file corresponding to the path; A control system including the above.

Citation Information

Patent Citations

  • Image processing apparatus, control method therefor, and program

    JP2019128792A

  • METHOD FOR OPERATING A HEAD-WEARABLE ELECTRONIC DISPLAY DEVICE AND DISPLAY SYSTEM FOR DISPLAYING VIRTUAL CONTENT

    JP2023052450A