Analysis system, analysis method, analysis device, analysis program, linkage device, and linkage program

The analysis system uses secure communication paths and packet analysis to minimize cyberattack risks on monitoring devices, enabling secure network information collection and analysis without direct network connection.

JP2025112879APending Publication Date: 2025-08-01OKI ELECTRIC INDUSTRY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024007400
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

Conventional monitoring devices for network traffic analysis can become targets of cyberattacks due to their connection within the network being monitored.

Method used

An analysis system comprising an analysis device and a cooperation device that utilize secure communication paths to transmit and receive cooperation information, enabling network analysis while minimizing the risk of becoming a cyberattack target by using secure communication path information, observation, packet extraction, and analysis to determine the state of the network.

Benefits of technology

The system effectively suppresses the risk of the monitoring device becoming a target of cyberattacks by using secure communication paths, allowing information collection and analysis without direct network connection, thus enhancing network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025112879000001_ABST
    Figure 2025112879000001_ABST
Patent Text Reader

Abstract

To provide an analysis system capable of suppressing a possibility that an analysis apparatus for analyzing a network to be analyzed becomes a target of a cyber attack.SOLUTION: An analysis system includes: an analysis device that analyzes an analysis target network; and a linkage device that is connected to the analysis target network, and cooperates with the analysis device. The analysis apparatus holds secret communication path information including setting information on a cooperation information packet to be used in a secret communication path with the cooperation apparatus, observes a packet at an observation point on the analysis target network, acquires cooperation information from the packet in which any setting information matches setting information of the secret communication path information, and uses the cooperation information for analysis of the analysis target network. The cooperation apparatus collects the cooperation information, holds the secret communication path information common to the analysis apparatus, and transmits a cooperation information packet in which any setting information of the secret communication path information is set, to the analysis apparatus.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an analysis system, an analysis method, an analysis device, an analysis program, a cooperation device, and a cooperation program, and can be applied to, for example, a system that analyzes network traffic data to analyze the state of a network.

Background Art

[0002] Conventionally, as a technique for collecting (for example, collecting traffic data via a mirror port of a network switch) and analyzing communication traffic regarding communication of terminals on a network, there is a monitoring device described in Non-Patent Document 1.

[0003] The monitoring device described in Non-Patent Document 1 is configured to detect cyberattacks such as malware activities from the collected traffic data. Conventionally, as a method for detecting cyberattacks such as malware activities from traffic data, the technique described in Patent Document 1 can be cited.

[0004] In addition, the monitoring device described in Non-Patent Document 1 uses a different interface from the mirror port connection for collecting traffic data, and performs network information collection and control based on the detection result, thereby performing network control (for example, network control in cooperation with a network switch) for blocking malware communication and malware-infected terminals.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Non-Patent Documents

[0006]

Non-Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0007] However, with the conventional monitoring devices as described above, although it is possible to detect and take countermeasures against cyberattacks, they can also become targets of cyberattacks because they are connected within the network to be monitored.

[0008] In view of the above problems, an analysis system capable of suppressing the possibility of becoming a target of cyberattacks for an analysis device (for example, a monitoring device) that analyzes a network to be analyzed is desired.

Means for Solving the Problems

[0009] The first aspect of the present invention is an analysis system comprising an analysis device for analyzing an analysis target network to be analyzed and a cooperation device connected to the analysis target network and cooperating with the analysis device. The analysis device includes: a secure communication path holding means for holding secure communication path information including one or more pieces of setting information of a cooperation information packet transmitted through a secure communication path for data transmission of the cooperation information collected by the cooperation device from the cooperation device to the analysis device; an observation means for observing packets at observation points on the analysis target network; a secure communication path determination means for performing a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secure communication path information from the observed packets observed by the observation means; a secure communication analysis means for analyzing the packet extracted by the secure communication path determination means through the packet extraction process to obtain the cooperation information; and an analysis means for analyzing the state of the analysis target network based on the cooperation information obtained by the secure communication analysis means and the observed packets. The cooperation device includes: an information holding means for holding the secure communication path information common to the analysis device and role definition information for performing a role of collecting the cooperation information; a role execution means for collecting the cooperation information according to the role definition information; and a secure communication transmission means for generating the cooperation information packet in which the cooperation information collected by the role execution means is set using any of the setting information of the secure communication path information held by the information holding means, and transmitting the generated cooperation information packet onto the analysis target network. An analysis system characterized by the above is provided.

[0010] In a second aspect of the present invention, in an analysis method performed by an analysis system including an analysis device that analyzes an analysis target network to be analyzed and a cooperation device that is connected to the analysis target network and cooperates with the analysis device, the analysis device has a secure communication path holding means, an observation means, a secure communication path determination means, a secure communication analysis means, and an analysis means, the cooperation device has an information holding means, a role execution means, and a secure communication transmission means, the secure communication path holding means holds secure communication path information including one or more pieces of setting information of a cooperation information packet transmitted through a secure communication path for data-transmitting cooperation information collected by the cooperation device from the cooperation device to the analysis device, the observation means observes packets at observation points on the analysis target network, the secure communication path determination means performs a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secure communication path information from the observed packets observed by the observation means, the secure communication analysis means analyzes the packets extracted by the secure communication path determination means by the packet extraction process to obtain the cooperation information, the analysis means analyzes the state of the analysis target network based on the cooperation information obtained by the secure communication analysis means and the observed packets, the information holding means holds role definition information for performing a role of collecting the secure communication path information and the cooperation information common to the analysis device, the role execution means collects the cooperation information according to the role definition information, and the secure communication transmission means generates a cooperation information packet in which the cooperation information collected by the role execution means is set, using any of the setting information of the secure communication path information held by the information holding means, and transmits the generated cooperation information packet onto the analysis target network.

[0011] A third aspect of the present invention is an analysis apparatus for analyzing an analysis target network to be analyzed. The analysis apparatus includes: a secure communication path holding means that holds secure communication path information including one or more pieces of setting information of a communication information packet transmitted through a secure communication path for data transmission of the cooperation information collected by a cooperation device connected to the analysis target network and cooperating with the own device from the cooperation device to the own device; an observation means that observes packets at observation points on the analysis target network; a secure communication path determination means that performs a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secure communication path information from the observed packets observed by the observation means; a secure communication analysis means that analyzes the packet extracted by the secure communication path determination means through the packet extraction process to obtain the cooperation information; and an analysis means that analyzes the state of the analysis target network based on the cooperation information obtained by the secure communication analysis means and the observed packets.

[0012] A fourth aspect of the present invention is a computer mounted on an analysis apparatus for analyzing an analysis target network to be analyzed. The computer functions as: a secure communication path holding means that holds secure communication path information including one or more pieces of setting information of a communication information packet transmitted through a secure communication path for data transmission of the cooperation information collected by a cooperation device connected to the analysis target network and cooperating with the own device from the cooperation device to the own device; an observation means that observes packets at observation points on the analysis target network; a secure communication path determination means that performs a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secure communication path information from the observed packets observed by the observation means; a secure communication analysis means that analyzes the packet extracted by the secure communication path determination means through the packet extraction process to obtain the cooperation information; and an analysis means that analyzes the state of the analysis target network based on the cooperation information obtained by the secure communication analysis means and the observed packets.

[0013] The fifth aspect of the present invention is a cooperation device that cooperates with an analysis device for analyzing an analysis target network. The cooperation device includes information holding means for holding one or more pieces of secret communication path information including setting information of a cooperation information packet transmitted through a secret communication path for transmitting cooperation information from the own device to the analysis device, and role definition information for performing the role of collecting the cooperation information; role execution means for collecting the cooperation information according to the role definition information; and secret communication transmission means for generating the cooperation information packet in which the cooperation information collected by the role execution means is set by using any of the setting information of the secret communication path information held by the information holding means, and transmitting the generated cooperation information packet onto the analysis target network. The cooperation device is characterized by having the above components.

[0014] The sixth aspect of the present invention is a cooperation program for causing a computer mounted on a cooperation device that cooperates with an analysis device for analyzing an analysis target network to function as information holding means for holding one or more pieces of secret communication path information including setting information of a cooperation information packet transmitted through a secret communication path for transmitting cooperation information from the own device to the analysis device, and role definition information for performing the role of collecting the cooperation information; role execution means for collecting the cooperation information according to the role definition information; and secret communication transmission means for generating the cooperation information packet in which the cooperation information collected by the role execution means is set by using any of the setting information of the secret communication path information held by the information holding means, and transmitting the generated cooperation information packet onto the analysis target network. The cooperation program is characterized by the above function.

Advantages of the Invention

[0015] According to the present invention, it is possible to provide an analysis system capable of suppressing the possibility of being a target of a cyber attack for an analysis device that analyzes a network to be analyzed.

Brief Description of the Drawings

[0016]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Mode for Carrying Out the Invention

[0017] (A) Main Embodiment Hereinafter, an embodiment of an analysis system, an analysis method, an analysis device, an analysis program, a cooperation device, and a cooperation program according to the present invention will be described in detail with reference to the drawings. In this embodiment, an example in which the analysis system, the analysis method, the analysis device, and the analysis program of the present invention are applied to a monitoring system, a monitoring method, a monitoring device, and a monitoring program, respectively, will be described.

[0018] (A-1) Configuration of the Embodiment FIG. 1 is a diagram showing the connection relationship of each device related to this embodiment (including the overall configuration of the monitoring system 1 according to the embodiment).

[0019] In this embodiment, the monitoring system 1 will be described as a system that monitors (analyzes) the communication of the network N1 to be monitored (the network to be analyzed). The network N1 to be monitored is connected to communication devices 30 (30-1, 30-2, ···). Each communication device 30 corresponds to various communication devices such as a PC, a server, and a network device (a communication device that performs IP communication). The number and connection positions of the communication devices 30 connected within the network N1 to be monitored are not limited. The monitoring system 1 is composed of two devices, a monitoring device 10 and a cooperation device 20.

[0020] In the network N1 to be monitored, a router 40 is arranged at a position (a position in the network connection configuration) where the traffic of each communication device 30 and the like concentrates. The monitoring device 10 regards this router 40 as an observation point on the network N1 to be monitored (in the example of this embodiment, the network interface 41 of the router 40), and analyzes the traffic transmitted and received (relayed) by the router 40 (network interface 41). Here, the data of the packets transmitted and received (relayed) by the router 40 (network interface 41) is also referred to as "traffic data". Here, it is assumed that the traffic data is supplied from the router 40 having the observation point to the monitoring device 10 (for example, supplied by a function such as port mirroring). In the router 40, only port mirroring is performed on the network interface 41 to which the monitoring device 10 is connected, and no routing setting is made to connect to the network N1 to be monitored (that is, although the monitoring device 10 is physically connected to the router 40, logically it is not connected to the inside of the network N1 to be monitored). Then, in the monitoring device 10, the network N1 to be monitored is analyzed and monitored using feature quantities based on the traffic data (for example, the packet interval time, the source port number (the port number of the transmitter), the destination port number (the port number of the destination), the packet length protocol, etc.). In this embodiment, the network interface 41 of the router 40 is applied as the observation point (observation point) for collecting the traffic data, but the position and number of the observation points are not limited.

[0021] The cooperation device 20 is connected to an arbitrary position on the monitored network N1 and can cooperate with the monitoring device 10 that is not directly connected to the inside of the monitored network N1 (the cooperation method will be described later).

[0022] Also, assume that there is a sub-network N2 in the monitored network N1. In this embodiment, the sub-network N2 (for example, a network switch not shown in the sub-network N2) is assumed to be connected to the network interface 42 of the router 40. And in this embodiment, the packets transmitted and received between the cooperation device 20 and the sub-network N2 are assumed to pass through the network interface 41 and the network interface 42 of the router 40.

[0023] Note that in this embodiment, the network address (range of IP addresses) assigned to the sub-network N2 is assumed to be 192.168.100.0 / 24 ( / 24 is the subnet mask length). That is, it is assumed that the IP addresses from 192.168.100.1 to 192.168.100.255 are assigned to the sub-network N2.

[0024] Next, the configuration overview within the monitoring system 1 will be described.

[0025] As described above, the monitoring system 1 includes the monitoring device 10 and the cooperation device 20, and by the cooperation of these devices, the function of monitoring the monitored network N1 is realized.

[0026] The monitoring device 10 analyzes the target network N1 using the traffic data obtained from the router 40 and the information supplied from the cooperation device 20 (hereinafter also referred to as "cooperation information"). Although the monitoring system 1 and the cooperation device 20 cannot directly transmit and receive packets, for the packets with the cooperation information set, by causing the cooperation device 20 to transmit them via the observation point (the network interface 41 of the router 40), the packets containing the cooperation information can be mixed into the traffic data and captured by the monitoring device 10. Regarding the method of causing the packets containing the cooperation information (hereinafter referred to as "cooperation information packets") sent from the cooperation device 20 to pass through the observation point (the network interface 41 of the router 40), there is no limitation. However, in this embodiment, the cooperation device 20 shall set an arbitrary IP address on the IP address on the subnet N2 for the cooperation information packets. Then, as described above, the packets sent from the cooperation device 20 to the subnet N2 will be transmitted to the subnet N2 via the observation point (the network interface 41). At this time, it is preferable that a dummy IP address not assigned to any device on the subnet N2 is set as the destination of the cooperation information packet.

[0027] Hereinafter, the data transmission path composed of the cooperation information packets from the cooperation device 20 to the monitoring device 10 is called the "secure communication path", and the communication using the secure communication path is called the "secure communication".

[0028] The cooperation device 20 communicates with each device in the target network N1 to collect information contributing to the analysis of the target network N1 (hereinafter referred to as "analysis contribution information"), and transmits the collected cooperation information including the analysis contribution information and the like to the monitoring device 10 through the secure communication path. Since the secure communication path between the monitoring device 10 and the cooperation device 20 can transmit the cooperation information without directly transmitting and receiving packets, it can be said that it is a highly secure data transmission path for the monitoring device 10.

[0029] It is assumed that the monitoring device 10 and the cooperation device 20 have registered setting information such as the destination IP address (hereinafter simply referred to as "preset") set in the cooperation information packet in advance. In this embodiment, it is assumed that the monitoring device 10 and the cooperation device 20 have registered information including a plurality of presets (preset candidates) (hereinafter referred to as "secure communication path information"). That is, the cooperation device 20 selects any one of the presets from the preset secure communication path information, and generates and transmits a cooperation information packet based on the selected preset. For example, the cooperation device 20 sets information based on the preset in the header of the cooperation information packet (for example, destination IP address, protocol, destination port number, etc.) and transmits it. Then, the monitoring device 10 can extract a packet that matches any one of the presets of the preset secure communication path information as the cooperation information packet.

[0030] Here, the specific data configuration of each preset constituting the secure communication path information will be described.

[0031] The preset may include, as information indicating the destination (hereinafter referred to as "destination information"), a destination address (IP address), a protocol (TCP or UDP), a port number, and the like. Although the number and combination of the information set in the destination information of the preset are not limited, it is necessary to include at least the destination address (IP address). Further, the preset may be added with information (hereinafter referred to as "extraction processing information") necessary for the monitoring device 10 side to extract the cooperation information from the cooperation information packet. As the extraction processing information, for example, the conversion format of the cooperation information to be transmitted (container part) (hereinafter referred to as "conversion format information"), key information for decrypting the cooperation information from the container part (for example, key data, password, etc.), information on the specific data format (data format after decryption) of the cooperation information (container part) (hereinafter referred to as "data format information") and the like may be included. Examples of the conversion format information include information indicating an encryption (unreadable) format, a compression format, and the like. Examples of the data format information include information indicating a data format such as JSON (JavaScript Object Notation) or XML (eXtensible Markup Language). Note that the number and combination of the information set in the preset extraction processing information are not limited.

[0032] As described above, the preset contains at least destination information, and extraction processing information may be added as needed. Specifically, for example, for a preset indicating the content "Transfer data at 60000 / udp with the destination IP being 192.168.100.100. The data transfer format is JSON format, the encryption (unreadable or compressed) method of the received data is ZIP, and the key information is XXX.", it may be described as a character string (text) of "192.168.100.100,60000,UDP,JSON,AES128,XXX". In this case, "192.168.100.100,60000,UDP" (destination IP address, port number, and protocol respectively) corresponds to the destination information, and "JSON,AES128,XXX" (data format, encryption format, and key information respectively) corresponds to the extraction processing information. Note that the preset itself may be described in various data structures such as JSON or XML. The secret communication path information held by the secret communication path holding unit 11 includes a plurality of presets in the above format. And in the secret communication path information, a priority order applicable to each preset may be assigned. For example, in the secret communication path information, an identification number may be assigned to each preset in ascending order (for example, assigned in the order of 1, 2, 3,...), and the preset with a smaller identification number in the monitoring system 1 may be treated as having a higher priority. In the cooperation device 20, the presets with higher priority are applied to the secret communication path in order.

[0033] Next, the internal configuration of the monitoring device 10 will be described.

[0034] FIG. 2 is a block diagram showing the functional configuration of the monitoring device 10.

[0035] The monitoring device 10 includes a secure communication path holding unit 11, a cooperation device determination unit 12, a secure communication path determination unit 13, a network interface unit 14, a secure communication analysis unit 15, and a cyber attack analysis unit 16. The monitoring device 10 may be configured partly or entirely by software. The monitoring device 10 can be configured by installing a program (including the analysis program according to the embodiment) on a computer including a processor and a memory.

[0036] The secure communication path holding unit 11 is responsible for the function of holding secure communication path information common to the cooperation device 20.

[0037] The network interface unit 14 is responsible for the function of connecting to a network (in this case, connecting to the router 40). The network interface unit 14 connects to the router 40 and receives packets (including mirrored traffic data). The secure communication path determination unit 13 checks the headers of the packets received by the network interface unit 14 and sorts the packets that match any preset (preset of the secure communication path information supplied from the cooperation device determination unit 12) and the packets that do not match. The secure communication path determination unit 13 regards the packets that match any preset as cooperation information packets and supplies them to the cooperation device determination unit 12 and the secure communication analysis unit 15, and supplies the packets that do not match to the cyber attack analysis unit 16.

[0038] The cooperation device determination unit 12 excludes inappropriate presets (for example, presets that are common with settings used by devices other than the cooperation device 20 on the sub-network N2; hereinafter referred to as "inappropriate presets") from the secure communication path information supplied from the secure communication path holding unit 11 and supplies them to the secure communication path determination unit 13. When the cooperation device determination unit 12 extracts a packet other than the cooperation information packet transmitted from the cooperation device 20 (hereinafter referred to as "non-cooperation information packet") from the packets supplied from the secure communication path determination unit 13, it determines the preset corresponding to the destination of the non-cooperation information packet as an inappropriate preset. For example, the cooperation device determination unit 12 may attempt to extract cooperation information from the payload of each packet supplied from the secure communication path determination unit 13, and determine a packet from which cooperation information could not be extracted (for example, a packet from which the cooperation information could not be decoded from the payload or a packet whose data format extracted from the payload is different from the cooperation information) as a non-cooperation information packet.

[0039] The secure communication analysis unit 15 extracts cooperation information from the packets supplied from the secure communication path determination unit 13 and writes the extracted cooperation information into the cooperation information DB 151. The cooperation information DB 151 is a database for holding cooperation information. The secure communication analysis unit 15 provides the data written in the cooperation information DB 151 to the cyber attack analysis unit 16.

[0040] The cyber attack analysis unit 16 performs a process of analyzing the situation (for example, an abnormality such as a cyber attack) in the monitored network N1 based on the analysis target packets (that is, traffic data to be analyzed) supplied from the secure communication path determination unit 13 and the information in the cooperation information DB 151 to detect an abnormality (hereinafter referred to as "abnormality detection process"). The method by which the cyber attack analysis unit 16 performs the abnormality detection process is not limited, and various methods can be applied. For example, the cyber attack analysis unit 16 may perform the abnormality detection process by the methods described in Patent Document 1 and Non-Patent Document 1.

[0041] FIG. 3 is a block diagram showing the functional configuration of the cooperation device 20.

[0042] The cooperation device 20 includes a secure communication response analysis unit 21, a preset determination unit 22, a secure communication transmission unit 23, a network interface unit 24, an information storage unit 25, and a role execution unit 26. The cooperation device 20 may be configured by software (computer program) for some or all of its components. The cooperation device 20 can be configured by installing a program (including the cooperation program according to the embodiment) on a computer equipped with a processor and a memory. The cooperation device 20 may be a dedicated device that cooperates with the monitoring device 10, or may be a device that also undertakes other functions (for example, functions such as a file server or a network device).

[0043] The network interface unit 14 is responsible for the function of connecting to a network (in this case, the monitored network N1) and communicating (packet transmission and reception).

[0044] The information storage unit 25 stores the secure communication path information common to the monitoring device 10 and information (hereinafter referred to as "role definition information") that defines the role of the cooperation device 20 with respect to the monitoring device 10.

[0045] The role execution unit 26 communicates with devices in the monitored network N1 according to the role definition information held by the information holding unit 25, and performs a process of collecting cooperation information (i.e., information including analysis contribution information contributing to the analysis of the monitored network N1) to be provided to the monitoring device 10 (hereinafter referred to as "cooperation information collection process"). For example, the role execution unit 26 may communicate with a communication device 30 having a predetermined network function in the monitored network N1 (such as a router or a switching hub specified in the role definition information in advance) using SNMP (Simple Network Management Protocol) to collect management information such as data of MIB (Management Information Base) as cooperation information. The items (OID (Object IDentifier)) of the MIB collected by the role execution unit 26 are not limited, and any items can be applied. Further, for example, the role execution unit 26 may collect event logs of predetermined items (such as information such as login history and file operation logs) as cooperation information from a communication device 30 having a predetermined server function in the monitored network N1 (for example, a file server specified in the role definition information in advance) according to the role definition information. Furthermore, when the own device (cooperation device 20) supports other functions (such as functions of a file server, etc.), the role execution unit 26 may acquire cooperation information (such as log information of the file server, etc.) from the program of the other function. That is, the role execution unit 26 may acquire the local information of the own device (cooperation device 20) as cooperation information.

[0046] The secure communication transmission unit 23 transmits the cooperation information collected by the role execution unit 26 to the monitoring device 10 via the secure communication path. Specifically, the secure communication transmission unit 23 generates a cooperation information packet with the cooperation information (or data obtained by processing the cooperation information such as compression in a predetermined manner) set in the payload, and causes it to be sent from the network interface unit 14. At that time, the secure communication transmission unit 23 acquires a preset from the information holding unit 25 and sets it in the header (destination part) of the cooperation information packet.

[0047] The secure communication response analysis unit 21 monitors the packets received by the network interface unit 24, and extracts response packets (hereinafter simply referred to as "response packets") for the cooperation information packets sent from the secure communication transmission unit 23. Then, the secure communication response analysis unit 21 analyzes the response packets, attempts to detect inappropriate presets (presets that should not be used as presets set for the cooperation information packets), and notifies the preset discrimination unit 22 of the information on the inappropriate presets.

[0048] By the way, when there is no destination corresponding to the preset set in the cooperation information packet, in a normal IP network, the content of the response packet is an error indicating that the packet of ICMP (Internet Control Message Protocol) is unreachable (Host Unreachable; hereinafter referred to as "unreachable error"). On the other hand, when there is a response packet other than the unreachable error, or when no response comes back, it means that there may be a host corresponding to the destination of the preset. Continuously sending cooperation information packets to a host where the destination actually exists means that the host side continues to receive unnecessary packets, which is not preferable (that is, control such as changing to a preset of another destination is desirable). Therefore, in the example of this embodiment, when the response packet has content other than the unreachable error, or when no response packet comes back (for example, when there is no response packet for a predetermined time or more even though the transmission of the cooperation information packet continues), the secure communication response analysis unit 21 may determine the preset currently set in the secure communication transmission unit 23 as an inappropriate preset.

[0049] The preset discrimination unit 22 controls the secure communication transmission unit 23 not to use the inappropriate preset for the secure communication path. The preset discrimination unit 22 may recognize inappropriate presets from network interface information and routing information held by the own device (local host; network interface unit 24) in addition to the information notified from the secure communication response analysis unit 21. For example, the preset discrimination unit 22 may delete inappropriate presets from the secure communication path information held by the information holding unit 25 as the information of the secure communication path, so that the inappropriate presets are not used by the secure communication transmission unit 23.

[0050] (A-2) Operations of the Embodiment Next, the operations of the monitoring system 1 (monitoring device 10 and cooperation device 20) (monitoring method according to the embodiment) will be described.

[0051] Here, as a premise of the operation description, it is assumed that common secure communication path information is held by the monitoring device 10 (secure communication path holding unit 11) and the cooperation device 20 (information holding unit 25) when the monitoring device 10 is installed. Note that the secure communication path information may be processed (for example, excluding inappropriate presets, etc.) within each device.

[0052] Next, the processing related to the secure communication path in the cooperation device 20 will be described.

[0053] In the cooperation device 20 (information holding unit 25), it is assumed that role definition information describing the acquisition of information on predetermined items from a predetermined network device (for example, a router, a switching hub, etc.) and a server (for example, a file server, etc.) within the monitored network N1 is held. Then, the role execution unit 26 executes processing for a predetermined role (for example, collection of event logs inside a predetermined server, or collection of MIB information using SNMP from a router specified as the default gateway via the network interface unit 24) according to the role definition information acquired from the information holding unit 25 to collect cooperation information, and supplies the collected cooperation information to the secure communication transmission unit 23. The secure communication transmission unit 23 obtains secure communication path information from the information holding unit 25, and uses any one of the presets of the secure communication path information (for example, the preset with the highest priority among a plurality of presets) to transmit a cooperation information packet from the network interface unit 24.

[0054] Next, the operation of the secure communication response analysis unit 21 will be described.

[0055] The secure communication response analysis unit 21 monitors the reception status of response packets for the cooperation information packets in the network interface unit 24, and determines whether the preset currently used by the secure communication transmission unit 23 (hereinafter referred to as the "in-use preset") is an inappropriate preset according to the monitoring result. When the secure communication response analysis unit 21 determines that the in-use preset is an inappropriate preset, it notifies the preset discrimination unit 22 to that effect.

[0056] FIG. 4 is a flowchart showing an example of the specific operation of the secure communication response analysis unit 21.

[0057] First, the secure communication response analysis unit 21 observes the reception status of response packets for the cooperation information packets in the network interface unit 24 (S101). The secure communication response analysis unit 21 may, for example, perform monitoring (observation) for a certain period and then shift to the processing of step S102 described later.

[0058] Based on the reception status of the response packet in step S101, the secure communication response analysis unit 21 determines whether the preset currently used by the secure communication transmission unit 23 is an inappropriate preset (S102). For example, when the response packet observed in step S101 contains content other than the unreachable error (ICMP Host Unreachable), or when the response packet cannot be observed in step S101 (when the response packet cannot be observed during a certain period of observation), the currently used preset may be determined to be an inappropriate preset. Also, for example, when the response packet observed by monitoring in step S101 is only the unreachable error (ICMP Host Unreachable), the currently used preset may be determined not to be an inappropriate preset (to be an appropriate preset).

[0059] In step S102, when it is determined that the currently used preset is not an inappropriate preset, the secure communication response analysis unit 21 determines to directly use the currently used preset (S103), and returns to the above-mentioned step S101 to operate.

[0060] On the other hand, in step S102, when it is determined that the currently used preset is an inappropriate preset, the secure communication response analysis unit 21 notifies the preset discrimination unit 22 that the currently used preset is an inappropriate preset (S104), and returns to the above-mentioned step S101 to operate.

[0061] Next, the operation of the preset discrimination unit 22 will be described.

[0062] FIG. 5 is a flowchart showing the operation of the preset discrimination unit 22.

[0063] First, the preset discrimination unit 22 acquires the secure communication path information of the information holding unit 25 (S201).

[0064] Next, the preset determination unit 22 refers to information such as the IP address and routing table assigned to the network interface unit 24 (interface within the local host) (hereinafter referred to as "local network information") (S202).

[0065] Next, the preset determination unit 22, also considering the information acquired in step S202, notifies (updates the preset) the secret communication transmission unit 23 from the information holding unit 25 about the preset determined to have the highest priority among the unused presets (presets that have no history of being used by the secret communication transmission unit 23 yet) from the presets of the secret communication path information (S203). Note that the preset determination unit 22 may select a preset to be used (for example, the one with the highest priority among the unused presets) based only on the priority of the presets in the secret communication path information.

[0066] Thereafter, the preset determination unit 22 checks whether there is a notification from the secret communication response analysis unit 21 within the most recent predetermined period (notification that the preset in use is an inappropriate preset) (S204).

[0067] If there is no notification of an inappropriate preset from the secret communication response analysis unit 21, the preset determination unit 22 determines to use the preset in use as it is (S205) and proceeds to step S204 described above.

[0068] On the other hand, when notified by the secure communication response analysis unit 21, the preset determination unit 22 notifies the information holding unit 25 of the information on the inappropriate preset (S206), controls the information holding unit 25 to delete the information on the inappropriate preset from the secure communication path information held thereby, and returns to the above-described step S201 to shift to the operation (operation of setting a new preset). At this time, the preset determination unit 22 can determine that at least the preset in use is an inappropriate preset and notify the information holding unit 25. Further, at this time, the preset determination unit 22 may grasp, as the range of the preset (inappropriate preset) to be deleted, in consideration of the local network information acquired in step S202, that since a packet does not pass through a router for a preset in which the destination IP address is the same as the local network.

[0069] Next, processing related to the secure communication path in the monitoring device 10 will be described.

[0070] FIG. 6 is a flowchart showing the operation of the secure communication path determination unit 13.

[0071] First, the secure communication path determination unit 13 acquires secure communication path information (preset) via the cooperation device determination unit 12 and starts observing packets for the network interface unit 14 (S301).

[0072] Then, when the secure communication path determination unit 13 observes a packet in the network interface unit 14 (S302), the secure communication path determination unit 13 collates the packet (the destination IP address, protocol, port number, etc. of the packet) with each preset of the secure communication path information to confirm the presence or absence of a matching preset (S303).

[0073] When the packet matches any preset, the secure communication path determination unit 13 supplies the packet to the cooperation device determination unit 12 and the secure communication analysis unit 15 (S304), and returns to the above-described step S302 to operate.

[0074] On the other hand, if the packet does not match any preset, the secure communication path determination unit 13 supplies the packet to the cyber attack analysis unit 16 (S305), and returns to the above-described step S302 to operate.

[0075] FIG. 7 is a flowchart showing the operation of the cooperation device determination unit 12.

[0076] First, the cooperation device determination unit 12 acquires secure communication path information from the secure communication path holding unit 11 and notifies the secure communication path determination unit 13 (S401).

[0077] Next, when a packet (a packet that matches any preset; the packet obtained by the process of step S304 above) is supplied from the secure communication path holding unit 11 to the cooperation device determination unit 12 (S402), the cooperation device determination unit 12 determines whether the packet is a cooperation information packet or a non-cooperation information packet (a packet other than the cooperation information packet) (S403). For example, the cooperation device determination unit 12 attempts decoding processing or the like defined in advance in the secure communication path (preset) to determine whether the packet is a cooperation information packet or a non-cooperation information packet.

[0078] If the packet is a cooperation information packet, the cooperation device determination unit 12 determines to use the currently used preset as it is (S404), and proceeds to the above-described step S402.

[0079] On the other hand, if the packet is a non-cooperation information packet, the cooperation device determination unit 12 notifies and sets the secure communication path information (i.e., the updated secure communication path information) obtained by excluding the preset (i.e., the inappropriate preset) corresponding to the packet from the secure communication path information to the secure communication path determination unit 13 (S405), and returns to the above-described step S402 to operate. At this time, the cooperation device determination unit 12 may send an alert indicating that the inappropriate preset is included in the secure communication path information (i.e., there may be a duplication with the communication device existing in the preset of the secure communication path information) by a predetermined communication (for example, sending an e-mail to a system administrator or the like or sending various telegrams).

[0080] (A-3) Effects of the Embodiment According to this embodiment, the following effects can be achieved.

[0081] In the monitoring system 1 of this embodiment, even if the monitoring device 10 is not connected inside the monitored network N1, the information inside the monitored network N1 can be collected and known through the secure communication channel with the cooperation device 20. As a result, in the monitoring system 1 of this embodiment, there is a vulnerability in the monitoring device 10 itself, and when an attacker successfully breaks into the monitoring device, the risk that the monitoring device 10 allows an attack into the monitored network N1 that it is monitoring can be suppressed.

[0082] (B) Other Embodiments The present invention is not limited to the above-described embodiments, and modified embodiments as exemplified below can also be cited.

[0083] (B-1) In the above embodiment, an example in which the analysis device and the analysis program of the present invention are applied mainly to a monitoring device that monitors cyberattacks on a network has been described. However, the analysis device and the analysis program of the present invention may be applied to other devices for the purpose of observing and analyzing traffic, such as a network quality measurement device or a fault location estimation device. For example, in the above embodiment, the cyberattack analysis unit 16 that constitutes the monitoring device 10 may be replaced with means for performing various analyses as described above.

[0084] (B-2) In the above embodiment, the destination of the cooperation information packet (the preset destination IP address) is set as the IP address on the subnet N2, but it may be set as the IP address of the observation point (the IP address set in the network interface 41 of the router 40). Thereby, the occurrence of an error (destination does not exist) can be suppressed within the monitored network N1.

[0085] (B-3) In the above embodiment, although one cooperation device 20 for setting a secure communication path (transmitting a cooperation information packet) with one monitoring device has been described, a plurality of cooperation devices 20 may be arranged, and each cooperation device 20 may set a secure communication path with the monitoring device 10.

[0086] When there are a plurality of cooperation devices 20, the destination of the cooperation information packet transmitted from the first cooperation device 20 may be set to the IP address of the second cooperation device 20. In this way, by having the cooperation devices 20 mutually transmit cooperation information packets to each other, errors (non-existent destinations) within the monitored network N1 can be suppressed.

[0087] (B-4) In the above embodiment, the cooperation device 20 and the monitoring device 10 may have the same hash function and Seed as preset (secure communication path information), and the cooperation device 20 may send the hash value it generates. Thereby, in the cooperation device determination unit 12 of the monitoring device 10, the reliability of the acquired cooperation information packet (the reliability of the cooperation device 20) can be checked.

[0088] (B-5) In the above embodiment, the packets supplied from the secure communication path determination unit 13 to the cyber attack analysis unit 16 do not include the packets extracted by the secure communication path determination unit 13 by regarding them as cooperation information packets, but all the packets observed at the observation points may be supplied to the secure communication path determination unit 13.

Explanation of Signs

[0089] 1... Monitoring system, 10... Monitoring device, 11... Secure communication path holding unit, 12... Cooperation device determination unit, 13... Secure communication path determination unit, 14... Network interface unit, 15... Secure communication analysis unit, 16... Cyber attack analysis unit, 20... Cooperation device, 21... Secure communication response analysis unit, 22... Preset discrimination unit, 23... Secure communication transmission unit, 24... Network interface unit, 25... Information holding unit, 26... Role execution unit, 30... Communication device, 40... Router, 41... Network interface, 42... Network interface.

Claims

1. In an analysis system comprising an analysis device that analyzes an analysis target network to be analyzed and a cooperation device that is connected to the analysis target network and cooperates with the analysis device, the analysis device includes: a secure communication path holding means that holds secure communication path information including one or more pieces of setting information of a cooperation information packet transmitted through a secure communication path for data transmission of the cooperation information collected by the cooperation device from the cooperation device to the analysis device; an observation means that observes packets at observation points on the analysis target network; a secure communication path determination means that performs a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secure communication path information from the observed packets observed by the observation means; a secure communication analysis means that analyzes the packets extracted by the secure communication path determination means through the packet extraction process to obtain the cooperation information; an analysis means that analyzes the state of the analysis target network based on the cooperation information obtained by the secure communication analysis means and the observed packets; the cooperation device includes: an information holding means that holds the secure communication path information common to the analysis device and role definition information for performing the role of collecting the cooperation information; a role execution means that collects the cooperation information according to the role definition information; a secure communication transmission means that generates the cooperation information packet in which the cooperation information collected by the role execution means is set using any of the setting information of the secure communication path information held by the information holding means, and transmits the generated cooperation information packet onto the analysis target network The analysis system is characterized by the above.

2. The analysis system according to claim 1, wherein when the cooperation information packet is transmitted from the cooperation device onto the analysis target network, destination information constituting the secure communication path information is described so as to pass through the observation point.

3. The cooperation device observes the reception status of a response packet for the cooperation information packet transmitted by the secure communication transmission means, analyzes the reception status of the response packet, and performs a setting information determination process for determining whether the setting information being used by the secure communication transmission means is appropriate. As a result of the setting information determination process, when it is determined that the setting information being used by the secure communication transmission means is inappropriate, the analysis system according to claim 1 further comprises setting information discrimination means for controlling to exclude the setting information being used by the secure communication transmission means from the setting information that can be used by the secure communication transmission means.

4. The analysis system according to claim 1 is characterized in that a cooperation device determination process is performed to determine whether an extraction packet extracted by the secure communication path determination means by the packet extraction process is a cooperation information packet sent from the cooperation device. When, as a result of the cooperation device determination process, it is determined that the extraction packet is not a cooperation information packet sent from the cooperation device, the setting information corresponding to the extraction packet is determined to be inappropriate, and the secure communication path determination means is controlled to exclude the inappropriate setting information from the secure communication path information used by the secure communication path determination means in the packet extraction process.

5. In an analysis method performed by an analysis system comprising an analysis device for analyzing an analysis target network to be analyzed and a cooperation device connected to the analysis target network and cooperating with the analysis device, the analysis device has a secure communication path holding means, an observation means, a secure communication path determination means, a secure communication analysis means, and an analysis means, the cooperation device has an information holding means, a role execution means, and a secure communication transmission means, the secure communication path holding means holds secure communication path information including one or more pieces of setting information for a cooperation information packet transmitted through a secure communication path for data-transmitting cooperation information collected by the cooperation device from the cooperation device to the analysis device, the observation means observes packets at an observation point on the analysis target network, the secure communication path determination means performs a packet extraction process of extracting, as a cooperation information packet, a packet that matches any of the setting information of the secure communication path information from among the observed packets observed by the observation means. The secret communication analysis means analyzes the packets extracted by the secret communication path determination means through the packet extraction process to obtain the cooperation information, Based on the cooperation information obtained by the secret communication analysis means and the observed packets, the analysis means analyzes the state of the analysis target network. The information holding means holds role definition information for performing the role of collecting the secret communication path information and the cooperation information common to the analysis device. The role execution means collects the cooperation information according to the role definition information. The secret communication transmission means generates a cooperation information packet in which the cooperation information collected by the role execution means is set, using any of the setting information of the secret communication path information held by the information holding means, and sends the generated cooperation information packet onto the analysis target network. A characteristic analysis method.

6. In an analysis device that analyzes an analysis target network to be analyzed, A secret communication path holding means that holds secret communication path information including one or more pieces of setting information of a cooperation information packet transmitted through a secret communication path for data transmission of cooperation information collected by a cooperation device connected to the analysis target network and cooperating with the own device from the cooperation device to the own device; Observation means for observing packets at an observation point on the analysis target network; Secret communication path determination means for performing a packet extraction process of extracting, as the cooperation information packet, a packet that matches any of the setting information of the secret communication path information from the observed packets observed by the observation means; Secret communication analysis means for analyzing the packets extracted by the secret communication path determination means through the packet extraction process to obtain the cooperation information; Analysis means for analyzing the state of the analysis target network based on the cooperation information obtained by the secret communication analysis means and the observed packets. An analysis device characterized by comprising:

7. A computer installed in an analysis device that analyzes an analysis target network to be analyzed, A secret communication path holding means that holds secret communication path information including one or more pieces of setting information of a cooperation information packet transmitted through a secret communication path for data transmission of cooperation information collected by a cooperation device connected to the analysis target network and cooperating with the own device from the cooperation device to the own device; Observation means for observing packets at an observation point on the analysis target network; For the observation packet observed by the observation means, a secret communication path determination means that performs a packet extraction process of extracting a packet that matches any of the setting information of the secret communication path information as the cooperation information packet, A secret communication analysis means that analyzes the packet extracted by the secret communication path determination means by the packet extraction process to obtain the cooperation information, Based on the cooperation information obtained by the secret communication analysis means and the observation packet, it functions as an analysis means for analyzing the state of the analysis target network An analysis program characterized by this.

8. In a cooperation device that cooperates with an analysis device that analyzes an analysis target network to be analyzed, Information holding means that holds one or more pieces of setting information of a cooperation information packet transmitted through a secret communication path for transmitting cooperation information from the own device to the analysis device, and role definition information for performing the role of collecting the cooperation information, Role execution means for collecting the cooperation information according to the role definition information, Using any of the setting information of the secret communication path information held by the information holding means, generating a cooperation information packet in which the cooperation information collected by the role execution means is set, and having a secret communication transmission means for sending the generated cooperation information packet onto the analysis target network A cooperation device characterized by this.

9. A computer installed in a cooperation device that cooperates with an analysis device that analyzes an analysis target network to be analyzed, Information holding means that holds one or more pieces of setting information of a cooperation information packet transmitted through a secret communication path for transmitting cooperation information from the own device to the analysis device, and role definition information for performing the role of collecting the cooperation information, Role execution means for collecting the cooperation information according to the role definition information, Using any of the setting information of the secret communication path information held by the information holding means, functioning as a secret communication transmission means for generating a cooperation information packet in which the cooperation information collected by the role execution means is set, and sending the generated cooperation information packet onto the analysis target network A cooperation program characterized by this.

Citation Information

Patent Citations

  • Network monitor, network monitoring program and network monitoring method

    JP2018186428A