Log determination method, log determination device, and log determination program

The log determination method assesses sensor reliability by comparing operation information from multiple sensors to filter out unreliable logs, improving cyberattack analysis accuracy and reducing network load.

JP2025137250APending Publication Date: 2025-09-19DENSO CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024036349
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-08
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

Existing methods for determining the reliability of security logs from vehicle sensors do not account for sensor malfunctions, leading to inaccurate information transmission and increased processing load on monitoring systems.

Method used

A log determination method that acquires security logs from sensors and evaluates their reliability by comparing operation information from multiple sensors, discarding unreliable logs to reduce transmission and processing loads.

Benefits of technology

Enhances the accuracy of cyberattack analysis by ensuring only reliable security logs are transmitted, reducing network load and processing burden on monitoring systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025137250000001_ABST
    Figure 2025137250000001_ABST
Patent Text Reader

Abstract

To provide a log determination method, a device, and a program that determine reliability associated with an abnormal log which indicates an abnormal event.SOLUTION: A log determination method acquires a security log from a first security sensor that generates the security log when an event is detected, acquires first operation information that indicates whether the first security sensor is normally operating and second operation information that indicates whether the second security sensor being different from the first security sensor is normally operating when the security log is an abnormal log that indicates an abnormal event, determines reliability associated with the abnormal log on the basis of the first operation information and the second operation information, and outputs the reliability.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a log determination method, device, and program that can determine the reliability of security logs generated by security sensors of electronic control devices mounted on mobile objects such as automobiles. [Background technology]

[0002] In recent years, technologies for driver assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication) and vehicle-to-infrastructure communication, have been attracting attention. As a result, vehicles are increasingly equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyber attacks, such as unauthorized access, is increasing.

[0003] Therefore, it is necessary to analyze cyberattacks against vehicles and develop countermeasures. One possible solution is to transmit information about abnormalities occurring in the vehicle outside the vehicle and analyze the cyberattacks on a server device with sufficient resources. However, the server device installed outside the vehicle must process information transmitted from multiple vehicles, which places a heavy processing burden on the server device.

[0004] For example, Patent Document 1 describes a method in which detection information indicating that an abnormality has been detected is obtained from a monitoring sensor, and a determination is made as to whether or not to transmit the detection information based on the degree of influence of the abnormality indicated by the detection information on the vehicle and the degree of match in pattern matching between the detection information and an abnormality pattern indicating a combination of the location where the abnormality was detected and the type of abnormality, and only the detection information that is determined to need to be transmitted is transmitted to a monitoring system outside the vehicle. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2022-55558 Summary of the Invention [Problem to be solved by the invention]

[0006] Here, the present inventors have found the following problems as a result of detailed investigation. In Patent Document 1, a determination is made as to whether or not to transmit detection information acquired from a monitoring sensor, assuming that the detection information is accurate. However, if the monitoring sensor itself is not operating normally or if the detection information is generated due to some kind of malfunction, the detection information itself may be inaccurate. Sending inaccurate detection information to a monitoring system outside the vehicle not only reduces the analytical accuracy of the monitoring system using the detection information, but also increases the processing load on the monitoring system or the transmission load of transmitting the detection information from the vehicle to the monitoring system. Therefore, it is desirable to determine the reliability of the detection information and transmit only reliable detection information to the monitoring system, or to analyze cyberattacks, etc., taking the reliability of the detection information into consideration.

[0007] Therefore, an object of the present invention is to realize a log determination method and the like that can determine the reliability of a security log acquired from a security sensor. [Means for solving the problem]

[0008] The log determination method disclosed herein acquires a security log from a first security sensor that generates a security log when an event is detected (S101), and if the security log is an abnormal log indicating an abnormal event, acquires first operation information indicating whether the first security sensor is operating normally and second operation information indicating whether a second security sensor different from the first security sensor is operating normally (S106), determines the reliability of the abnormal log based on the first operation information and the second operation information (S107), and outputs the reliability (S108).

[0009] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]

[0010] With the above-described configuration, the log determination method and the like of the present disclosure can determine the reliability of a security log. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is an explanatory diagram illustrating the arrangement of a log determination device according to each embodiment and its relationship with related devices. [Figure 2] FIG. 1 is an explanatory diagram illustrating the arrangement of a log determination device according to each embodiment and its relationship with related devices. [Figure 3] FIG. 1 is an explanatory diagram illustrating an example of the configuration of an electronic control system according to each embodiment. [Figure 4] FIG. 1 is an explanatory diagram illustrating the configuration of an electronic control device according to each embodiment. [Figure 5] FIG. 10 is an explanatory diagram illustrating a security log generated by a security sensor of an electronic control device according to each embodiment. [Figure 6] FIG. 1 is a block diagram showing an example of the configuration of a log determination device according to a first embodiment. [Figure 7] FIG. 1 is an explanatory diagram illustrating an error log and a security log according to the first embodiment. [Figure 8] 1 is a flowchart illustrating the operation of the log determination device according to the first embodiment. [Figure 9] 1 is a flowchart illustrating the operation of the log determination device according to the first embodiment. [Figure 10] 10 is a flowchart illustrating the operation of the log determination device according to the second embodiment. [Figure 11] 10 is a flowchart illustrating the operation of the log determination device according to the third embodiment. [Figure 12] FIG. 10 is an explanatory diagram illustrating a configuration example of a log determination system according to a modified example of each embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0013] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.

[0014] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.

[0015] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.

[0016] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined.

[0017] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.

[0018] 1. Configuration underlying each embodiment (1) Location of the log determination device and its relationship with related devices 1 and 2 are diagrams illustrating the arrangement of the log determination device in each embodiment and its relationship with related devices. For example, as shown in FIG. 1, a case is assumed in which the log determination device 100 is "mounted" on a vehicle, which is a "moving body," together with an electronic control device 10 constituting an electronic control system S. Alternatively, as shown in FIG. 2, a case is assumed in which the electronic control device 10 constituting the electronic control system S is mounted on the vehicle, and the log determination device 100 is realized by a server device or the like provided outside the vehicle. In each embodiment described below, a case in which the log determination device 100 is mounted on a vehicle as shown in FIG. 1 is described. Even when the log determination device 100 is not mounted on a vehicle as shown in FIG. 2, the same is true for each embodiment except for the communication method with the electronic control device 10, and therefore the description of each embodiment will be quoted.

[0019] Here, "mobile body" refers to an object that can move at any speed. It also naturally includes cases where the moving body is stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these vehicles. "Mounted" includes not only cases where the device is directly fixed to the mobile body, but also cases where the device is not fixed to the mobile body but moves with the mobile body. For example, cases where the device is carried by a person riding on the mobile body, or cases where the device is mounted on cargo placed on the mobile body, are included.

[0020] The log determination device 100 is connected to "electronic control devices" (hereinafter referred to as ECUs (Electronic Control Units)) that constitute the electronic control system S. The log determination device 100 is a device that acquires security logs generated by security sensors mounted in multiple ECUs 10 that constitute the electronic control system S, and determines the security logs.

[0021] Here, the "electronic control device" may be a physically independent electronic control device, or may be a virtualized electronic control device realized using virtualization technology.

[0022] The external device 20 is any device provided outside the vehicle, and an example thereof is a Security Operations Center (SOC) that detects and analyzes cyber attacks.

[0023] In FIG. 1, the electronic control system S and the external device 20 are connected via a communication network using a wireless communication method such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a LAN (Local Area Network), the Internet, or a fixed telephone line can be used. Alternatively, the line may be a combination of a wireless communication system and a wired communication system. For example, the electronic control system S and a base station device in a cellular system may be connected by a wireless communication system such as 4G, and the base station device and the external device 20 may be connected by a wired communication system such as a trunk line of a telecommunications carrier or the Internet. A gateway device may be provided at the point of contact between the trunk line and the Internet.

[0024] In FIG. 2, the electronic control system S and the log determination device 100 provided outside the vehicle are also connected via a communication network using the above-mentioned wireless communication method or wired communication method. In FIG. 2, the log determination device 100 and the external device 20 are depicted as separate devices connected via a communication network, but the log determination device 100 and the external device 20 may be realized by the same device.

[0025] As shown in FIG. 1, a log determination device 100 mounted on a vehicle is also called a detection master in the specifications defined by AUTOSAR (AUTomotive Open System ARchitecture).

[0026] (2) Configuration of electronic control system S Fig. 3 is a diagram showing an example of the configuration of an electronic control system S. The electronic control system S is made up of multiple ECUs 10 and an in-vehicle network connecting these. Fig. 3 shows eight ECUs (ECU10a to ECU10h) as an example, but the electronic control system S may naturally be made up of any number of ECUs. In the following explanation, when describing one or multiple electronic control devices collectively, they will be referred to as ECU10 or each ECU 10, and when describing individual electronic control devices specifically, they will be referred to as ECU10a, ECU10b, ECU10c, ...

[0027] 3, the ECUs 10 are connected to each other via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the ECUs 10 may be connected to each other using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). Note that connection refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual ECUs (also called virtual machines) realized on the same hardware are virtually connected to each other.

[0028] The electronic control system S shown in FIG. 3 includes an integrated ECU 10a, an external communication ECU 10b, zone ECUs (10c, 10d), and individual ECUs (10e to 10h).

[0029] The integrated ECU 10a is an ECU that has a function of controlling the entire electronic control system S and also has a gateway function of mediating communication between the ECUs. The integrated ECU 10a is also called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU 10a may also be a relay device or a gateway device.

[0030] The external communication ECU 10b is an ECU having a communication unit that communicates with an external device 20 provided outside the vehicle. The communication method used by the external communication ECU 10b is the wireless communication method or wired communication method described above. In order to realize a plurality of communication methods, a plurality of external communication ECUs 10b may be provided. Also, instead of providing the external communication ECU 10b, the integrated ECU 10a may include the functions of the external communication ECUb.

[0031] The zone ECUs (10c, 10d) are ECUs equipped with a gateway function that are appropriately arranged according to the location and function of the individual ECUs. For example, the zone ECU 10c is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10e and 10f arranged at the front of the vehicle and other ECUs 10, and the zone ECU 10d is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10g and 10h arranged at the rear of the vehicle and other ECUs 10.

[0032] The individual ECUs (10e to 10h) can be configured with ECUs having any desired functions. Examples include drivetrain electronic control units that control the engine, steering, brakes, etc., body electronic control units that control meters, power windows, etc., information system electronic control units such as navigation systems, and safety control system electronic control units that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may be classified as master and slave rather than parallel.

[0033] In the electronic control system S in Fig. 3, each ECU 10 except for ECU 10h is equipped with a security sensor (abbreviated as SS in the figure). As such, it is not necessary for all ECUs 10 constituting the electronic control system S to be equipped with a security sensor. The security log generated by the security sensor will be described later.

[0034] In each embodiment, the log determination device 100 is provided in the integrated ECU 10a. However, the log determination device 100 may be provided in the external communication ECU 10b, the zone ECUs (10c to 10d), or the individual ECUs (10e to 10h). When the log determination device 100 is provided in one of the individual ECUs (10e to 10h), it is desirable to use a dedicated ECU for realizing the log determination device 100.

[0035] (3) Security Sensor 4 is a block diagram showing the configuration of an ECU (10a to 10g) equipped with a security sensor. The ECU (10a to 10g) includes a log generating unit 11, a receiving unit 12, an operation information generating unit 13, and a transmitting unit .

[0036] The log generation unit 11 generates a security log when it detects an event that occurs on the ECU 10 or the network to which the ECU 10 is connected. For example, when an abnormal event occurs due to a cyber-attack on the ECU 10 or the network, the log generation unit 11 generates a security log. Note that the log generation unit 11 may generate a security log not only when it detects an abnormal event, but also when it detects a normal event.

[0037] FIG. 5 is a diagram showing a specific example of a security log generated by the log generating unit 11. As shown in FIG. The security log has the following fields: an ECU ID indicating identification information of the ECU 10 on which the security sensor is mounted, a sensor ID indicating identification information of the security sensor, an event ID indicating identification information of the security event, a counter indicating the number of times the event has occurred, a timestamp indicating the time the event occurred, and context data indicating details of the output of the security sensor. The security log may further have a header storing information indicating the protocol version and the state of each field.

[0038] The receiver 12 receives a request to transmit operation information from the log determination device 100, which will be described later, via an in-vehicle network. If the security sensor and the log determination device 100 are mounted on the same ECU 10, the request is received directly from hardware or software that realizes the log determination device 100, without going through the in-vehicle network. The request to transmit operation information will be described later. In addition to the request to transmit operation information, the receiver 12 may also receive a request to conduct a test to determine whether the security sensor is operating normally.

[0039] When the receiving unit 12 receives a request to transmit operation information, the operation information generating unit 13 generates operation information that "indicates" whether the security sensor is operating normally. When the receiving unit 12 receives a request to transmit operation information and a request to conduct a test to determine whether the security sensor is operating normally, the operation information generating unit 13 conducts a test to determine whether the security sensor is operating normally and generates the "test result" as operation information. In this case, the operation information generating unit 13 may have a security sensor test function, or the security sensor may have a test conducting unit (not shown) separate from the operation information generating unit 13.

[0040] Here, "indicating" whether or not a security sensor is operating normally refers to information that directly or indirectly indicates whether or not the security sensor is operating normally. Directly indicating information refers to information that includes an evaluation, such as information that indicates whether the security sensor is operating normally or not. Indirectly indicating information refers to information that does not include an evaluation, such as the output value or setting value of the security sensor, which is evaluated based on an evaluation criterion to determine whether or not it is a normal value. The "test result" may be a result of the test indicating whether the security sensor is operating normally or not, or may be the data itself output by the test.

[0041] One example of a test to determine whether the security sensor is operating normally is to generate a pseudo event (hereinafter referred to as a pseudo event) in the ECU 10 and have the security sensor detect the event. For example, if the security sensor detects a pseudo event that has occurred in the ECU 10 and generates a security log that includes the event ID of the pseudo event, a counter for the number of occurrences of the pseudo event, or an appropriate ECU ID, it can be said that the security sensor is operating normally. Therefore, the operation information generator 13 generates operation information that indicates that the security sensor is operating normally.

[0042] On the other hand, if the security sensor cannot detect a pseudo event or cannot generate an appropriate security log for the pseudo event, it can be said that the security sensor is not operating normally. In this case, the operation information generator 13 generates operation information indicating that the security sensor is not operating normally.

[0043] The operation information indicating the test result may be, but is not limited to, information indicating whether the security sensor is operating normally or not. For example, the operation information generator 13 may generate the security log itself generated for the pseudo event as the operation information. In this case, instead of the security sensor, the log determination device 100 uses the security log generated for the pseudo event to determine whether the security sensor is operating normally.

[0044] Furthermore, the operation information generator 13 may generate setting information of the security sensor as the operation information. The setting information of the security sensor may include, for example, the types of events that the security sensor can detect, and the criteria and thresholds for detecting events by the security sensor. Even when the operation information indicates the setting information of the security sensor, the log determination device 100 uses the operation information to determine whether the security sensor is operating normally.

[0045] In the following embodiment 1, the receiving unit 12 receives a request to transmit operation information together with a request to conduct a test, and the operation information generating unit 13 generates operation information indicating the results of the security sensor test. In addition, in embodiment 2, the receiving unit 12 receives only a request to transmit operation information, and the operation information generating unit 13 generates setting information of the security sensor as operation information.

[0046] The operation information generating unit 13 may further generate operation information at a timing when the receiving unit 12 does not receive a request to transmit operation information. For example, the operation information generating unit 13 may generate operation information at "fixed intervals" and / or at a timing when the log generating unit 11 generates a security log. When the operation information generating unit 13 generates operation information at fixed intervals, the intervals may be changed depending on the vehicle's traveling conditions. For example, the intervals may be shortened when the vehicle's traveling speed is equal to or greater than a predetermined speed, and lengthened when the vehicle's traveling speed is equal to or less than the predetermined speed.

[0047] The term "constant cycle" includes not only the case where the cycle is always constant, but also the case where the cycle is determined depending on conditions.

[0048] The operation information generating unit 13 may further generate operation information when the security sensor or the ECU 10 having the security sensor is activated. Furthermore, when the security sensor or the ECU 10 having the security sensor is stopped, the operation information generating unit 13 may generate stop information, which is operation information indicating that the security sensor is stopped.

[0049] "Stopping" refers to the security sensor going from an operating state to an inoperable state, and may be when the power goes from on to off, or when the power goes into a sleep state.

[0050] 4, the transmission unit 14 transmits the security log generated by the log generation unit 11 and the operation information generated by the operation information generation unit 13 to the log determination device 100 via the in-vehicle network. If the security sensor and the log determination device 100 are mounted on the same ECU 10, they are output directly to the hardware or software that realizes the log determination device 100 without going through the in-vehicle network.

[0051] A security log generated by a security sensor is called an SEv, and a qualified security log that has been narrowed down is called a QSEv. For example, a security sensor generates an SEv and reports it to an intrusion detection system manager (IdsM). If the SEv passes through a certification filter in the IdsM and meets specified criteria, the SEv is transmitted from an intrusion detection reporter to the outside of the vehicle as a QSEv. The security log in each embodiment is a concept that includes both an SEv and a QSEv. When the security log is QSEv, the range including the intrusion detection system manager (IdsM) corresponds to the log generator 11, and the intrusion detection reporter corresponds to the transmitter .

[0052] 2. Embodiment 1 (1) Configuration of the log determination device 100 6 is a block diagram showing an example of the configuration of a log determination device 100 according to this embodiment. The log determination device 100 includes a log acquisition unit 101, a control unit 102, a request transmission unit 105, an operation information acquisition unit 106, an external transmission unit 109, a log storage unit 110, and an operation information storage unit 111. The control unit 102 realizes two main functions: a log determination function and a log processing function. Specifically, the control unit 102 realizes, by hardware and / or software, an abnormality log detection unit 103, a request generation unit 104, and a reliability determination unit 107 as the log determination function, and a log processing unit 108 as the log processing function.

[0053] The log acquisition unit 101 acquires security logs generated by the security sensors from the security sensors. The log acquisition unit 101 acquires the security logs from the security sensors mounted on the ECUs 10 other than the integrated ECU 10a on which the log determination device 100 is mounted via an in-vehicle network, and acquires the security logs directly from the security sensor mounted on the integrated ECU 10a without going through the in-vehicle network.

[0054] The abnormal log detection unit 103 detects a security log indicating an abnormal event from the security logs acquired by the log acquisition unit 101. Hereinafter, a security log indicating an abnormal event will be referred to as an abnormal log. The abnormal log detection unit 103 detects an abnormal log based on one or more security logs. For example, if the event ID included in a security log is a specific event ID indicating an abnormal event, the abnormal log detection unit 103 detects the security log as an abnormal log. Alternatively, if the combination of event IDs of multiple security logs acquired by the log acquisition unit 101 per unit time is a specific combination of event IDs, the abnormal log detection unit 103 detects these security logs as abnormal logs. As another example, if the log acquisition unit 101 acquires more than a predetermined number of security logs having a specific event ID per unit time, the log acquisition unit 101 may detect these security logs as abnormal logs.

[0055] When the abnormality log detection unit 103 detects an abnormality log, the request generation unit 104 generates a transmission request to the security sensor (corresponding to the "first security sensor") that is the sender of the abnormality log, requesting the security sensor to send operation information (corresponding to the "first operation information") that "indicates" whether the security sensor is operating normally. Hereinafter, the security sensor that is the sender of the abnormality log will be referred to as the first security sensor, the operation information requested of the first security sensor will be referred to as the first operation information, and the transmission request requesting the transmission of the first operation information will be referred to as the first transmission request.

[0056] Here, when the abnormality log detection unit 103 detects multiple security logs as abnormal logs, the source of these security logs is not necessarily one security sensor. That is, the abnormality log detection unit 103 may detect multiple security logs transmitted from multiple security sensors as abnormal logs. In this case, the request generation unit 104 generates transmission requests to all security sensors that are the source of the abnormal logs.

[0057] The request generation unit 104 further selects one or more security sensors (corresponding to "second security sensors") different from the security sensor that sent the abnormality log, and generates a transmission request that requests the selected security sensors to transmit operation information (corresponding to "second operation information") that "indicates" whether the security sensors are operating normally. Hereinafter, a security sensor different from the first security sensor will be referred to as the second security sensor, the operation information requested of the second security sensor will be referred to as the second operation information, and the transmission request that requests the transmission of the second operation information will be referred to as the second transmission request. Details of the second security sensor selected by the request generation unit 104 will be described later.

[0058] In this embodiment, the request generation unit 104 generates a first transmission request and a second transmission request, which request the "test results" of whether the first security sensor and the second security sensor are operating normally as operation information.

[0059] The request generation unit 104 of this embodiment further generates an implementation request to request a test to be conducted to determine whether the security sensors are operating normally. Hereinafter, an implementation request requesting a first security sensor to conduct a test will be referred to as a first implementation request, and an implementation request requesting a second security sensor to conduct a test will be referred to as a second implementation request. The first implementation request and the second implementation request may further specify the content of a pseudo event to be used in the test on the security sensors.

[0060] The request sending unit 105 sends the first transmission request and the first implementation request generated by the request generating unit 104 to the first security sensor, and sends the second transmission request and the second implementation request to the second security sensor.

[0061] The motion information acquisition unit 106 acquires first motion information and second motion information from the first security sensor and the second security sensor, respectively.

[0062] Here, if the security sensor operation information generation unit 13 generates operation information when the security sensor is started or stopped, at regular intervals, or at the timing when the log generation unit 11 generates a security log, the operation information acquisition unit 106 further acquires the operation information generated at these timings.

[0063] The reliability determination unit 107 determines the reliability "regarding" the abnormality log based on the first operation information and the second operation information acquired by the operation information acquisition unit 106, and outputs the determined reliability to the log processing unit 108, which will be described later. How the reliability determination unit 107 determines the reliability of the abnormality log based on the first operation information and the second operation information will be described later.

[0064] Here, "reliability" is an index classified based on a predetermined evaluation standard, and the number of classifications may be plural. The term "related to" an error log includes not only the error log itself but also logs related to the error log.

[0065] Here, when the security log itself generated by the security sensor for a pseudo event is used as the operational information, the reliability determination unit 107 determines whether the security log acquired as operational information is appropriate as a security log generated for a pseudo event, for example, whether the security log includes the event ID of the pseudo event and an appropriate ECU ID, and uses the determination result to determine the reliability of the abnormality log.

[0066] In this embodiment, the reliability determination unit 107 determines whether the reliability of the abnormality log is high or low, but the reliability may be further classified. For example, the reliability may be classified into high, medium, or low, or the reliability may be determined numerically. For example, the reliability may be determined numerically based on the number of pieces of operation information obtained from the second security sensors that indicate that the security sensor is operating normally or not operating, or the ratio of the pieces of operation information that indicate that the security sensor is operating normally to the pieces of operation information that indicate that the security sensor is not operating normally.

[0067] For example, if the first operation information indicates that the first security sensor is operating normally, and among the multiple pieces of second operation information obtained from multiple second security sensors, 3 / 4 of the second operation information indicates that the sensor is operating normally and 1 / 4 of the second operation information indicates that the sensor is not operating normally, the reliability of the abnormality log is determined to be 75%.

[0068] However, if the first operation information indicates that the first security sensor is not operating normally, the reliability of the abnormality log generated by the first security sensor is likely to be low. Therefore, if the first operation information indicates that the first security sensor is not operating normally, it is desirable to determine that the reliability of the abnormality log is low even if the second operation information indicates that all of the multiple second security sensors are operating normally.

[0069] In addition, if the operation information acquisition unit 106 does not acquire the first operation information and the second operation information in response to the first transmission request and the second transmission request, the reliability determination unit 107 may determine that the security sensor from which the operation information has not been acquired is not operating normally.

[0070] The log processing unit 108 discards the abnormality log if the reliability output from the reliability determination unit 107 is "lower" than a predetermined reliability. If a cyber-attack analysis is performed using an abnormality log with low reliability, the accuracy of the analysis may decrease. Furthermore, transmitting an abnormality log with low reliability to the external device 20 increases the transmission load on the network between the electronic control system S and the external device 20. Therefore, by discarding abnormality logs with low reliability, the amount of processing required for attack analysis and the transmission load on the network are reduced.

[0071] The term "than" encompasses both cases where the value is the same as the value of the comparison target and cases where the value is not the same as the value of the comparison target.

[0072] The external transmission unit 109 transmits the abnormality log, the reliability of which is determined by the reliability determination unit 107 to be higher than a predetermined reliability, to the external device 20 via the external communication ECU 10b.

[0073] The external transmission unit 109 may further transmit, in addition to the abnormality log, security logs that are not determined to be abnormality logs to the external device 20. For example, in addition to the abnormality log, security logs acquired within a predetermined time from the time when the log determination device 100 acquired the abnormality log are transmitted to the external device 20 together with the abnormality log.

[0074] In this embodiment, a configuration will be described in which the log processing unit 108 discards abnormality logs whose reliability is lower than a predetermined reliability. However, the log processing unit 108 may store the abnormality logs instead of discarding them. In this case, the log processing unit 108 may store the abnormality logs with low reliability in the log storage unit 110 (described later), or may store the abnormality logs with low reliability in a memory (not shown) provided external to the log determination device 100. In another example, the abnormality logs with low reliability may also be transmitted to the external device 20 without being discarded. In this case, in order to analyze cyberattacks, etc., using the abnormality logs while taking into account the reliability of the abnormality logs, the reliability determined by the reliability determination unit 107 and / or the first operation information and the second operation information are transmitted to the external device 20 in addition to the abnormality logs. For example, the log processing unit 108 stores the reliability information in the context data of the abnormality log, and the external transmission unit 109 transmits the abnormality log in which the reliability information is stored to the external device 20.

[0075] The log storage unit 110 stores the security log acquired by the log acquisition unit 101 . The operation information storage unit 111 stores the operation information acquired by the operation information acquisition unit 106. The log storage unit 110 and the operation information storage unit 111 may be either an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, etc.). In addition, they may be volatile or non-volatile.

[0076] (2) Selection of security sensors and assessment of their reliability Next, the selection of the second security sensor by the request generator 104 and the determination of the reliability using the first operation information and the second operation information will be described.

[0077] (a) A security sensor mounted on the same ECU as the first security sensor As an example, the request generator 104 selects a security sensor mounted on the same ECU as the first security sensor as the second security sensor.

[0078] If the first security sensor is broken or malfunctioning, there is a possibility that a security sensor mounted on the same ECU as the first security sensor is also broken or malfunctioning. Therefore, by selecting a security sensor mounted on the same ECU as the first security sensor as the second security sensor and determining the reliability of the abnormality log based on the operation information of the first security sensor and the operation information of the second security sensor, the reliability of the abnormality log can be determined with higher accuracy.

[0079] For example, if neither the first nor the second security sensor is operating normally, there is a possibility that the ECU itself is malfunctioning, and it is highly likely that the first security sensor detected an abnormal event caused by the ECU malfunction. Therefore, the reliability of the log generated by this ECU, i.e., the abnormality log, will be low. In contrast, if both the first and the second security sensors are operating normally, it is highly likely that the first security sensor detected an abnormal event caused by a cyber attack, and the reliability of the abnormality log will be high.

[0080] The reliability determination unit 107 of this example may determine the reliability of the abnormality log, as well as the reliability of the logs generated by the first and second security sensors mounted on the same ECU. The reliability of the abnormality log includes, for example, the reliability of the logs generated by the first and second security sensors mounted on the same ECU within a predetermined time period from the time the abnormality log was generated (for example, on the same day, until the vehicle power was turned off, etc.).

[0081] The same ECU is not limited to a physically independent ECU. For example, a security sensor mounted on the same virtualized ECU as the first security sensor may be selected as the second security sensor.

[0082] (b) Security sensors according to the security level of defense in depth An electronic control system S mounted on a vehicle may employ a defense-in-depth approach to enhance security against attacks. According to the defense-in-depth approach, security functions are provided in layers as a countermeasure against attacks. Even if one countermeasure (i.e., the first layer) is breached in an attack, the next countermeasure (i.e., the second layer) can defend against the attack, thereby enhancing the defensive capabilities of the electronic control system S. Therefore, an electronic control system S employing the defense-in-depth approach has multiple layers with different security levels. Each ECU constituting the electronic control system S belongs to one of the multiple layers divided according to its security level. Therefore, the request generation unit 104 selects a second security sensor according to the security level of the defense-in-depth approach. Specifically, the request generation unit 104 selects, as the second security sensor, a security sensor mounted on an ECU that provides a security level equal to or lower than the security level of the ECU equipped with the first security sensor.

[0083] As an example, a security sensor mounted on an ECU that provides a security level lower than the security level of an ECU equipped with the first security sensor is selected as the second security sensor. If an ECU belonging to the second layer of defense in depth is subjected to a cyberattack, the cyberattack will have passed through a layer with a security level lower than the second layer, i.e., the first layer. Therefore, it is highly likely that ECUs belonging to the first layer have also been subjected to a cyberattack. Therefore, the request generation unit 104 selects a security sensor mounted on an ECU that provides a security level lower than the ECU equipped with the first security sensor as the second security sensor. For example, if the first security sensor is mounted on an ECU belonging to the second layer, the request generation unit 104 selects a security sensor mounted on an ECU belonging to the first layer as the second security sensor.

[0084] If the second security sensor is operating normally and the ECU belonging to the first layer is not under cyber-attack, it is highly likely that the first security sensor installed in the ECU belonging to the second layer is also not under cyber-attack. Therefore, it is highly likely that the first security sensor detected an abnormal event due to a failure or malfunction, and the reliability of the abnormality log will be low. On the other hand, if there is a possibility that the ECU belonging to the first layer is under cyber-attack, it is highly likely that the first security sensor installed in the ECU belonging to the second layer is also under cyber-attack. Therefore, it is highly likely that the first security sensor detected an abnormal event caused by a cyber-attack, and the reliability of the abnormality log will be high.

[0085] In another example, the request generator 104 may select, as the second security sensor, a security sensor mounted on an ECU that provides the same security level as the ECU in which the first security sensor is mounted. In this case, if the first security sensor is mounted on an ECU belonging to the second tier, the request generator 104 selects, as the second security sensor, a security sensor mounted on an ECU that also belongs to the second tier.

[0086] If the second security sensor is not operating normally, there is a possibility that the first security sensor, which has the same security level, is also not operating normally. Therefore, it is highly likely that the first security sensor detected an abnormal event due to a malfunction or defect, and the reliability of the abnormality log will be low. In contrast, if the second security sensor is operating normally, it is highly likely that the first security sensor detected an abnormal event caused by a cyber attack, and the reliability of the abnormality log will be high.

[0087] In this example, the reliability determination unit 107 may determine the reliability of the abnormality log by determining, in addition to the abnormality log, the reliability of a log generated by a security sensor mounted on an ECU that provides the same security level as or a lower security level than the ECU on which the first security sensor is mounted.

[0088] (c) Security sensors responding to detected events As another example, the request generator 104 selects, as the second security sensor, a security sensor that detects an event related to the event detected by the first security sensor.

[0089] For example, if the first security sensor detects a message authentication error as an event, there is a possibility that an abnormality related to the message authentication function has occurred within the electronic control system S. Therefore, the request generation unit 104 selects another security sensor that detects an event related to message authentication as the second security sensor. Alternatively, a security sensor that monitors an HSM (Hardware Security Module) that stores a key used for message authentication may be selected as the second security sensor.

[0090] For example, if neither the first nor the second security sensor is operating normally, there is a possibility that the entire message authentication function within the electronic control system S is malfunctioning, and it is highly likely that the first security sensor detected an abnormal event due to a malfunction or failure. Therefore, the reliability of the abnormality log will be low. In contrast, if both the first and the second security sensors are operating normally, there is no malfunction in the message authentication function, and it is highly likely that the first security sensor detected an abnormal event caused by a cyber attack, and the reliability of the abnormality log will be high.

[0091] In this example, the reliability determination unit 107 may determine the reliability of the abnormality log, in addition to the abnormality log, by determining the reliability of a log generated by a second security sensor that detects an event related to the event detected by the first security sensor.

[0092] (d) The security sensor that generated the security log acquired within a predetermined time from the time when the abnormality log was acquired. When analyzing a cyber-attack, there is a possibility that traces of the cyber-attack may be contained not only in the abnormality log but also in the security logs acquired before and after the abnormality log. Therefore, not only the abnormality log but also the security logs acquired before and after the abnormality log may be transmitted to the external device 20. Therefore, the request generation unit 104 in this example selects, as the second security sensor, the security sensor that generated the security log to be transmitted to the external device 20 together with the abnormality log.

[0093] 7 is a diagram illustrating the second security log of this example. When the log acquisition unit 101 acquires an abnormality log, the request generation unit 104 selects, as the second security sensors, the security sensors that generated security logs acquired within a predetermined time from the time the abnormality log was acquired, i.e., within a designated period T1 immediately before the time (t) when the abnormality log was acquired, and the security sensors that generated security logs acquired within a designated period T2 immediately after the time (t) when the abnormality log was acquired. In the example of FIG. 7, the security sensors that transmitted security logs a and b are selected as the second security sensors, but the security sensor that transmitted security log c is not selected as the second security sensor.

[0094] Then, the external transmission unit 109 transmits to the external device 20 the security logs a2, a3, a4, and b2, b3, as well as the operation information of the security sensors that generated these security logs, together with the abnormality log.

[0095] For example, if both the first security sensor and the second security sensor are operating normally, it is highly likely that no failures or malfunctions occurred in the security sensors around the time the abnormality log was generated. Therefore, it is highly likely that the first security sensor detected an abnormal event caused by a cyber attack, and the reliability of the abnormality log will be high. Also, if both the first security sensor and the second security sensor are not operating normally, it is highly likely that some kind of malfunction occurred inside the vehicle around the time the abnormality log was generated. Therefore, it is highly likely that the first security sensor detected an abnormal event caused by a malfunction, and the reliability of the abnormality log will be low.

[0096] The reliability determining unit 107 of this example may determine the reliability of the abnormality log, for example, the reliability of the security logs acquired within the specified periods T1 and T2.

[0097] (e) A security sensor for which a security log has not been acquired within a predetermined time from the time when the abnormality log was acquired. In this example, the request generation unit 104 selects as the second security sensor a security sensor for which no security log has been acquired within a predetermined time prior to the time when the abnormality log was acquired. A security sensor for which a security log has been acquired most recently may be operating normally, whereas a security sensor for which a security log has not been acquired most recently may not have generated a security log because the security sensor is not operating normally. Therefore, the request generation unit 104 selects as the second security sensor a security sensor for which a security log has not been acquired within a predetermined time prior to the time when the abnormality log was acquired, and generates a request to transmit operation information.

[0098] In this example, it is desirable to determine the reliability of the abnormality log and the log generated by the second security sensor, taking into consideration the ECU in which the selected second security sensor is installed, the layer of multi-layer defense to which the ECU belongs, the functions provided by the ECU, etc.

[0099] (f) A security sensor for which test results have not been obtained within a specified time from the time when the abnormality log was obtained. As another example, the request generator 104 selects as the second security sensor a security sensor for which no operational information, which is the result of a test conducted by the security sensor, has been acquired within a predetermined time prior to the time the abnormality log was acquired. In this example, it is desirable that each security sensor conducts a test at regular intervals or together with the generation of a security log, and transmits the operational information, which is the result of the test, to the log determination device 100.

[0100] As in the example (e) above, in this example too, the reliability of the abnormality log and the log generated by the second security sensor is determined taking into consideration the ECU in which the selected second security sensor is installed, the layer of multi-layer defense to which the ECU belongs, the functions provided by the ECU, etc.

[0101] (g) Critical Security Sensors The request generator 104 may select a security sensor with a high level of importance as the second security sensor.

[0102] For example, the request generation unit 104 selects a security sensor that monitors a firewall for communication between the electronic control system S and the outside of the vehicle as the second security sensor. Cyber-attacks from outside the vehicle will always pass through the firewall. Therefore, by obtaining operation information from the security sensor that monitors the firewall, the reliability of the abnormality log that indicates an abnormal event can be improved.

[0103] Although the above-mentioned (a) to (g) all describe examples of selecting the second security sensor, these may be combined to select the second security sensor. For example, when (a) and (e) are combined, among the security sensors mounted on the same ECU as the first security sensor, a security sensor from which no security log has been acquired within a predetermined time prior to the time when the abnormality log was acquired is selected as the second security sensor. In this way, by narrowing down the number of second security sensors and transmitting and receiving transmission requests and operation information to and from some sensors that meet specific conditions, it is possible to prevent an increase in the load on the in-vehicle network.

[0104] (h) Other The request generating unit 104 may select a security sensor that is not stopped among the security sensors (a) to (g) described above as the second security sensor. The request generating unit 104 can determine whether the security sensors (a) to (g) are stopped by acquiring stop information, which is operation information indicating that the security sensor is stopped, when the security sensor is stopped. In other words, the request generating unit 104 selects a security sensor from among the security sensors (a) to (g) for which stop information has not been acquired as the second security sensor.

[0105] Even if a request for operation information is made to a stopped security sensor, the operation information cannot be obtained. Therefore, requesting operation information from such a security sensor will unnecessarily increase the load on the network. Therefore, the request generation unit 104 does not select a stopped security sensor as the second security sensor.

[0106] (2) Operation of the Log Determination Device 100 Next, the operation of the log determination device 100 will be described with reference to Fig. 8. Fig. 8 not only shows the log determination method executed by the log determination device 100, but also shows the processing procedure of a log determination program that can be executed by the log determination device 100. The order of these processes is not limited to the order shown in Fig. 8. That is, the order may be changed as long as there are no constraints, such as a relationship in which a certain step uses the result of the previous step. The same applies to the diagrams showing the log determination methods of the embodiments described below.

[0107] The log acquisition unit 101 acquires a security log from a security sensor mounted on each ECU 10 (S101). The acquired security log is stored in the security log storage unit 110. Here, if the abnormality log detection unit 103 detects an abnormality log from the security log acquired by the log acquisition unit 101 (S102: Y), the request generation unit 104 selects a second security sensor different from the first security sensor (S103). The request generation unit 104 generates a first transmission request requesting the first security sensor to transmit first operation information, and a second transmission request requesting the second security sensor selected in S103 to transmit second operation information (S104). The request transmitting unit 105 transmits the first and second transmission requests generated in S104 (S105).

[0108] The motion information acquisition unit 106 acquires the first motion information and the second motion information from the first security sensor and the second security sensor, respectively (S106). The reliability determination unit 107 determines the reliability of the abnormality log based on the first operation information and the second operation information acquired in S106 (S107). The reliability determination unit 107 outputs the reliability determined in S107 to the log processing unit 108 (S108). Here, if the reliability output in S108 is lower than a predetermined reliability (S109: N), the log processor 108 discards the abnormality log (S110). On the other hand, if the reliability output in S108 is higher than the predetermined reliability (S109: Y), the log processor 108 transmits an abnormality log to the external device 20 (S111).

[0109] Fig. 9 shows the operation of the log determination device 100 when an abnormality log with a low reliability is not discarded. The processes of S101 to S108 in Fig. 10 are the same as those in Fig. 9. However, in Fig. 10, the abnormality log and the reliability output in S108 are transmitted to the external device 20 (S112). Note that, as described above, in S112, the first operation information and the second operation information may be transmitted to the external device 20 instead of or in addition to the reliability.

[0110] (3) Summary As described above, according to this embodiment, the reliability of an abnormality log can be determined based on the operation information of a first security sensor that generated the abnormality log, as well as the operation information of a second security sensor related to the first security sensor.

[0111] Furthermore, by discarding an abnormality log with a low reliability and not sending it to the external device, the communication load between the log determination device and the external device can be reduced. Furthermore, by discarding the abnormality log or sending the reliability of the abnormality log to an external device together with the abnormality log, the amount of processing required to analyze a cyber attack using the abnormality log can be reduced.

[0112] 3. Embodiment 2 In the first embodiment, the log determination device 100 requests a security sensor to conduct a test to determine whether the security sensor is operating normally, and determines the reliability using the test result as operation information. In this embodiment, the configuration in which the log determination device 100 determines the reliability using operation information, which is setting information of the security sensor, will be described, focusing on differences from the first embodiment. Note that the configuration of the log determination device 100 in this embodiment is the same as that in the first embodiment, and will be described with reference to FIG. 6.

[0113] (1) Security sensor configuration In this embodiment, the operation information generating unit 13 of the security sensor generates operation information, which is setting information of the security sensor, when the security sensor is “activated” in addition to when the receiving unit 12 receives a request to transmit operation information. Then, the transmitting unit 14 transmits the operation information generated when the security sensor is activated to the log determination device 100.

[0114] Here, "starting up" refers to the security sensor going from a non-operating state to an operating state, and may refer to the power being turned on from off, or may refer to the power being released from a sleep state.

[0115] (2) Configuration of the log determination device 100 When the abnormality log detection unit 103 detects an abnormality log, the request generation unit 104 of this embodiment generates a first transmission request to the first security sensor, requesting it to transmit "operation information" which is the setting information of the first security sensor. The request generation unit 104 further generates a second transmission request to the second security sensor, requesting it to transmit "operation information" which is the setting information of the second security sensor.

[0116] As in embodiment 1, the request sending unit 105 sends the first transmission request generated by the request generating unit 104 to the first security sensor and sends the second transmission request to the second security sensor, and the operation information acquiring unit 106 acquires the first operation information and the second operation information from the first security sensor and the second security sensor, respectively.

[0117] The reliability determination unit 107 determines the "reliability" of the abnormality log based on the first operation information and the second operation information. In the first embodiment, the reliability of the abnormality log is determined using only the operation information acquired in response to the transmission request for the operation information, i.e., the test results of the security sensor. In contrast, the reliability determination unit 107 of the present embodiment determines the reliability by comparing the operation information acquired by the operation information acquisition unit 106 when the security sensor is activated with the operation information acquired by the operation information acquisition unit 106 in response to the transmission request for the operation information.

[0118] Specifically, when the first security sensor is activated, the operation information acquisition unit 106 of this embodiment acquires operation information (corresponding to "third operation information") which is setting information of the first security sensor. When the second security sensor is activated, the operation information acquisition unit 106 further acquires operation information (corresponding to "fourth operation information") which is setting information of the second security sensor. Then, this operation information is stored in the operation information storage unit 111.

[0119] The reliability determination unit 107 then determines whether the first security sensor and the second security sensor are operating normally, based on whether the first operational information acquired in response to the first transmission request is the same as the operational information acquired when the first security sensor was activated, and whether the second operational information acquired in response to the second transmission request is the same as the operational information acquired when the second security sensor was activated. Specifically, if the first operational information is the same as the operational information acquired when the first security sensor was activated, the reliability determination unit 107 determines that the first security sensor is operating normally. Similarly, if the second operational information is the same as the operational information acquired when the second security sensor was activated, the reliability determination unit 107 determines that the second security sensor is operating normally. On the other hand, if the first operational information is different from the operational information acquired when the first security sensor was activated, or if the second operational information is different from the operational information acquired when the second security sensor was activated, the reliability determination unit 107 determines that each security sensor is not operating normally.

[0120] If the operational information, which is the setting information of the security sensor, is different between when the sensor is started and when an abnormality log is detected, there is a high possibility that the security sensor is not operating normally due to a malfunction or the like. Therefore, if the operational information of the security sensor when an abnormality log is detected is different from the operational information at the time of the sensor start-up, it can be determined that a malfunction has occurred in the security sensor and that the security sensor is not operating normally. In contrast, if the operational information of the security sensor is the same between when the sensor is started and when an abnormality log is detected, it can be said that the security sensor is operating under at least the same conditions as when the sensor started up, and it is determined that the security sensor is operating normally.

[0121] Here, the security sensor operation information that the reliability determination unit 107 compares with the operation information acquired before the abnormal log was detected may be operation information acquired before the abnormal log was detected, and does not necessarily have to be operation information acquired at the time of startup of the security sensor. However, if the security sensor is equipped with a secure boot function, the accuracy and reliability of the operation information transmitted at startup is considered to be high because the integrity of the software installed in the sensor is verified by secure boot. Therefore, it is desirable for the reliability determination unit 107 to determine the reliability of the abnormal log by comparing it with the operation information acquired at the time of startup of the security sensor.

[0122] As in the first embodiment, in this embodiment, the reliability is not limited to being expressed as high or low, and the reliability may be determined by a numerical value.

[0123] (3) Operation of the Log Determination Device 100 Next, the operation of the log determination device 100 of this embodiment will be described with reference to FIG. FIG. 10 is a diagram illustrating the operation of the log determination device 100 to acquire operation information when a security sensor is activated.

[0124] The operation information acquisition unit 106 acquires operation information of the activated security sensor (S201). The motion information storage unit 111 stores the motion information acquired in S201 (S202).

[0125] Next, the operation of the log determination device 100 of this embodiment will be described. The determination operation of the log determination device 100 of this embodiment is basically the same as the log determination operation shown in Fig. 8 of embodiment 1. However, a difference is that in embodiment 1, the reliability of the abnormality log is determined in S107 using only the first operation information and the second operation information acquired in S106, whereas in this embodiment, the reliability is determined in S107 using the first operation information and the second operation information acquired in S106 and the operation information of the security sensor acquired in S201 of Fig. 10.

[0126] (4) Summary As described above, according to this embodiment, the reliability of the abnormality log can be determined using the operational information acquired when the security sensor is started, without performing a test on the security sensor, thereby reducing the processing load on the security sensor.

[0127] 4. Embodiment 3 In the first and second embodiments, a configuration has been described in which the log determination device 100 requests the first and second security sensors to transmit operation information, and determines the reliability of an abnormality log using the operation information transmitted in response to the request. In this embodiment, a configuration in which the log determination device 100 determines the reliability of an abnormality log using operation information acquired together with a security log will be described, focusing on differences from the first and second embodiments. Note that the configuration of the log determination device 100 in this embodiment is the same as that in the first embodiment, and therefore will be described with reference to FIG. 6.

[0128] (1) Security sensor configuration In this embodiment, the operation information generation unit 13 included in the security sensor generates operation information of the security sensor when the log generation unit 11 generates a security log. Then, the transmission unit 14 transmits the security log generated by the log generation unit 11 and the operation information generated by the operation information generation unit 13 to the log determination device 100.

[0129] In this embodiment, the transmission unit 14 transmits the security log and the operation information as separate data to the log determination device 100. However, the operation information generated by the operation information generation unit 13 may be stored, for example, in the context data of the security log generated by the log generation unit 11. In this case, the operation information acquisition unit 106 of the log determination device 100 acquires the operation information stored in the context data by acquiring the security log.

[0130] (2) Configuration of the log determination device 100 In this embodiment, the operation information acquisition unit 106 acquires operation information along with a security log. Here, even if the abnormality log detection unit 103 detects an abnormality log, the request generation unit 104 of this embodiment does not generate a first transmission request that requests the first security sensor to transmit the first operation information. This is because the first operation information has been acquired from the first security sensor along with the security log.

[0131] In response to this, similarly to the first embodiment, the request generating unit 104 generates a second transmission request that requests the second security sensor to transmit second operation information, and the request transmitting unit 105 transmits the second transmission request.

[0132] (3) Operation of the Log Determination Device 100 The operation of the log determination device 100 of this embodiment will be described with reference to Fig. 11. The same processes as those in Fig. 8 of the first embodiment are denoted by the same reference numerals as in Fig. 8, and the description thereof will be omitted.

[0133] In this embodiment, the log acquisition unit 101 acquires the security log, and the operation information acquisition unit 106 acquires the operation information (S301). In the first embodiment, the request generation unit 104 generates a first transmission request and a second transmission request, whereas in the present embodiment, the request generation unit 104 generates only a second transmission request (S302). The request transmitting unit 105 transmits a second transmission request to the second security sensor (S303). Then, the motion information acquisition unit 106 acquires the second motion information transmitted from the second security sensor (S304).

[0134] Next, the reliability determination unit 107 determines the reliability of the abnormality log (S107). Here, in the first and second embodiments, the reliability is determined using the first operation information and the second operation information acquired by the operation information acquisition unit 106 in response to the first transmission request and the second transmission request, whereas in this embodiment, the reliability is determined based on the first operation information acquired in S301 and stored in the operation information storage unit 111, and the second operation information acquired by the operation information acquisition unit 106 in response to the second transmission request.

[0135] (4) Summary As described above, according to this embodiment, since there is no need to request the security sensor that generated the abnormality log to send operation information, it is possible to reduce the communication load on the in-vehicle network between the log determination device 100 and the ECU 10.

[0136] 5. Modifications of each embodiment In the first to third embodiments, a configuration has been described in which the log determination process is executed in the log determination device 100 mounted on a vehicle or provided outside the vehicle. In the present embodiment, a configuration will be described in which the log determination process executed by the log determination device 100 in each embodiment is realized by a log determination system 1 consisting of multiple devices.

[0137] 12 is a diagram illustrating an example of a log determination system 1 according to the present embodiment. The log determination system 1 includes a log determination device 200a mounted on a vehicle and a log processing device 200b external to the vehicle. The log determination device 200a includes the components of the log determination device 100 of each embodiment, namely, the log acquisition unit 101, the request transmission unit 105, the operation information acquisition unit 106, the external transmission unit 109, the abnormal log detection unit 103 implemented by the control unit 102, the request generation unit 104, the log storage unit 110, and the operation information storage unit 111. In contrast, the log determination device 200b includes the components of the log determination device 100 of each embodiment, namely, the reliability determination unit 107 and the log processing unit 108 implemented by the control unit 102, and further includes a receiving unit 211 that acquires information transmitted from the log determination device 200a.

[0138] Among the components of the log determination device 200a and the log determination device 200b, the components that are the same as those of the log determination device 100 in embodiments 1 to 3 have the same functions as those in embodiments 1 to 3. However, in this embodiment, the external transmission unit 109 transmits to the log processing device 211 the security log acquired by the log acquisition unit 101 and the operation information acquired by the operation information acquisition unit 106 in response to the request generated by the request generation unit 104.

[0139] The receiving unit 211 of the log determination device 200b acquires the security log and operation information transmitted from the log determination device 200a. The reliability determination unit 107 determines the reliability of the security log acquired by the receiving unit 211 based on the operation information acquired by the receiving unit 211 . Then, the log processor 108 discards the abnormality log based on the reliability, or outputs the reliability and the abnormality log to a SOC or the like that analyzes the abnormality log.

[0140] In this modification, the log judgment process executed by the log judgment device 100 in each embodiment is executed by either the log judgment device 200a or the log judgment device 200b.

[0141] According to this modification, the log determination device 200a mounted on the vehicle needs to transmit security logs and operation information to the log determination device 200b installed outside the vehicle, which increases the communication load on the network between the log determination device 200a and the log determination device 200b. However, by performing the high-load process of determining the reliability of the abnormality log outside the vehicle, it is possible to reduce the processing load on the device mounted on the vehicle.

[0142] 6. Summary The features of the log determination device and the like in each embodiment of the present invention have been described above.

[0143] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.

[0144] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.

[0145] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.

[0146] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.

[0147] The following are examples of the configuration of the log determination device of the present invention. Examples of the component include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU) and a system board. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.

[0148] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log determination device.

[0149] The log determination device of the present invention is expected to be used, particularly on the server side, for the purpose of providing various services, and in connection with the provision of such services, the log determination device of the present invention, the method of the present invention, and / or the program of the present invention will be used.

[0150] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.

[0151] A program stored in a non-transitory physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]

[0152] The log judgment method of the present invention is primarily intended to be a method for judging logs generated by an ECU that constitutes an electronic control system installed in an automobile, but it may also be intended to be a method for judging logs generated by a general-purpose device that is not installed in an automobile. [Explanation of symbols]

[0153] 100 Log determination device, 101 Log acquisition unit, 106 Operation information acquisition unit, 107 Reliability determination unit

Claims

1. A security log is acquired from a first security sensor that generates a security log when an event is detected (S101); If the security log is an abnormality log indicating an abnormal event, first operation information indicating whether the first security sensor is operating normally and second operation information indicating whether a second security sensor different from the first security sensor is operating normally are acquired (S106). determining the reliability of the abnormality log based on the first operation information and the second operation information (S107); Output the reliability (S108). Log determination method.

2. The log determination method further includes: If the security log is the abnormality log, the first security sensor is requested to provide the first operational information, and the second security sensor is requested to provide the second operational information (S104, S105). The log determination method according to claim 1 .

3. the first operational information is a result of a test to determine whether the first security sensor is operating normally; the second operational information being a result of a test as to whether the second security sensor is operating normally; The log determination method according to claim 1 .

4. The log determination method further includes: acquiring third operation information of the first security sensor when the first security sensor is activated; acquiring fourth operation information of the second security sensor when the second security sensor is activated; In determining the reliability, If the first operation information is the same as the third operation information, it is determined that the first security sensor is operating normally; If the second operation information is the same as the fourth operation information, it is determined that the second security sensor is operating normally. The log determination method according to claim 1 .

5. The log determination method includes: Acquire the first operation information together with the abnormality log; requesting the second operational information from the second security sensor; The log determination method according to claim 1 .

6. the second security sensor is a security sensor that generated a security log acquired within a predetermined time from the time when the abnormality log was acquired; The log determination method according to claim 1 .

7. the second security sensor is a security sensor mounted on the same electronic control device as the first security sensor; The log determination method according to claim 1 .

8. the second security sensor is a security sensor mounted on an electronic control device that provides a security level equal to or lower than the security level of the electronic control device on which the first security sensor is mounted; The log determination method according to claim 1 .

9. the second security sensor is a security sensor that detects an event related to the abnormal event; The log determination method according to claim 1 .

10. the second security sensor is a security sensor from which no security log has been acquired within a predetermined time prior to the time when the abnormality log was acquired; The log determination method according to claim 1 .

11. The log determination method further includes acquiring, from the second security sensor, operation information that is a result of a test to determine whether the second security sensor is operating normally, at regular intervals or together with a security log generated by the second security sensor; the second security sensor is a security sensor from which the test result has not been acquired within a predetermined time prior to the time when the abnormality log was acquired; The log determination method according to claim 1 .

12. the second security sensor is a security sensor of high importance; The log determination method according to claim 1 .

13. The log determination method further includes, when the second security sensor is stopped, acquiring stop information from the second security sensor, the stop information being operation information indicating that the second security sensor is stopped; the second security sensor is a security sensor from which the stop information has not been acquired; The log determination method according to any one of claims 7 to 12.

14. The log determination method is executed by a log determination device (100) mounted on a moving body, The log determination method further includes: If the reliability is higher than a predetermined reliability, the abnormality log is transmitted to the outside of the mobile unit (S111). If the reliability is lower than the predetermined reliability, the abnormality log is not transmitted to an outside of the mobile body. The log determination method according to claim 1 .

15. The log determination method is executed by a log determination device (100) mounted on a moving body, The log determination method further includes: Transmitting the abnormality log, the reliability and / or the first operation information and the second operation information to an outside of the mobile object (112); The log determination method according to claim 1 .

16. A log determination device (100) mounted on a moving body, a log acquisition unit (101) that acquires a security log from a first security sensor that generates a security log when an event is detected; an operation information acquisition unit (106) that, when the security log is an abnormality log indicating an abnormal event, acquires first operation information indicating whether the first security sensor is operating normally or not, and second operation information indicating whether a second security sensor different from the first security sensor is operating normally or not; a reliability determination unit (107) that determines and outputs reliability of the abnormality log based on the first operation information and the second operation information; A log determination device comprising:

17. A log determination program executable by a log determination device (100), A security log is acquired from a first security sensor that generates a security log when an event is detected (S101); If the security log is an abnormality log indicating an abnormal event, first operation information indicating whether the first security sensor is operating normally and second operation information indicating whether a second security sensor different from the first security sensor is operating normally are acquired (S106). determining the reliability of the abnormality log based on the first operation information and the second operation information (S107); The reliability is output (S108). A log determination program that causes the log determination device to execute a process.

Citation Information

Patent Citations

  • Information transmitter, server, and information transmitting method

    JP2022055558A