Log management device, log management method, log management program, and log management system
The log management device generates alive/dead monitoring function detection logs based on reception status to enhance cyberattack analysis in vehicles, addressing the inefficiencies of existing log analysis devices by providing detailed sensor operation information and reducing unnecessary communication.
Patent Information
- Application Number
- JP2024081280
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-05-17
- Publication Date
- 2025-11-28
AI Technical Summary
Existing log analysis devices for cyberattack detection in vehicles do not effectively utilize survival signals from security sensors, as the loss of these signals in sleep-mode devices does not necessarily indicate sensor abnormalities, and the devices do not require all survival signals for analysis.
A log management device that receives detection and health monitoring logs from security sensors, generating alive/dead monitoring function detection logs based on reception status to provide information for log analysis, reducing unnecessary communication and enhancing cyberattack threat analysis.
The log management device provides the log analysis device with detailed information on security sensor operations, enabling accurate cyberattack identification and reducing communication overhead, allowing for timely and efficient threat detection.
Smart Images

Figure 2025174734000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a device, method, program, and system for managing security logs using alive monitoring logs generated by security sensors of electronic control devices mounted mainly on automobiles and other mobile objects. [Background technology]
[0002] In recent years, technologies for driver assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication) and vehicle-to-infrastructure communication, have been attracting attention. Accordingly, vehicles are increasingly equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyberattacks, such as unauthorized access, is increasing. Therefore, it is necessary to analyze cyberattacks against vehicles and develop countermeasures.
[0003] There are various methods for detecting abnormalities that occur in a vehicle and analyzing cyberattacks based on the detected abnormalities. For example, Patent Document 1 describes a method for detecting abnormalities that occur due to attacks on a network, collecting data on the detected abnormalities, and comparing the combination of items in which the abnormality was detected with an abnormality detection pattern that is specified in advance for each attack to identify the type of cyberattack corresponding to the abnormality.
[0004] Furthermore, Patent Document 2 describes that the accuracy of identification and estimation can be improved by also using survival signals from security sensors to identify the type of cyber-attack and estimate the attack path. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2020-123307 [Patent Document 2] Japanese Patent Publication No. 2023-6513 Summary of the Invention [Problem to be solved by the invention]
[0006] Here, the present inventors have found the following problem. A survival signal such as that in Patent Document 2 is transmitted periodically from a security sensor and is useful for a device that receives the survival signal to check whether there is an abnormality in the security sensor itself. However, if the electronic control device or bus on which the security sensor is mounted has a sleep function, the loss of the survival signal does not necessarily mean that there is an abnormality in the security sensor. Furthermore, a log analysis device that analyzes logs to analyze cyber-attack threats does not need all of the survival signals themselves; if the operation of the security sensor can be estimated from the reception status of the survival signals, information on the estimation results is sufficient.
[0007] Therefore, an object of the present disclosure is to realize a log management device or the like that provides a log analysis device with information useful for analyzing the threat of cyber attacks. [Means for solving the problem]
[0008] The log management device (100, 200) of the present disclosure includes: a detection log receiving unit (101) that receives a detection log indicating a detection result of a security sensor of an electronic control device (10) mounted on a vehicle; a health monitoring log receiving unit (102) that receives a health monitoring log indicating that the security sensor is operating; a health monitoring function detection log generation unit (105) that generates a health monitoring function detection log indicating the start and stop of operation of the security sensor based on the reception status of the health monitoring log; an output unit (108) that outputs the alive monitoring function detection log and the detection log received during a first period; Equipped with.
[0009] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]
[0010] With the above-described configuration, the log management device and the like of the present disclosure can provide the log analysis device with information useful for analyzing the threat of cyber attacks, and can reduce the amount of communication between the log management device and the log analysis device. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is an explanatory diagram illustrating the arrangement of a log management device and its relationship with related devices in each embodiment. [Figure 2] FIG. 1 is an explanatory diagram illustrating the arrangement of a log management device and its relationship with related devices in each embodiment. [Figure 3] FIG. 1 is a block diagram illustrating an example of the configuration of an electronic control system according to each embodiment. [Figure 4] FIG. 1 is a block diagram illustrating an example of the configuration of an electronic control device according to each embodiment. [Figure 5] FIG. 10 is an explanatory diagram illustrating a security log generated by a security sensor of an electronic control device according to each embodiment. [Figure 6] FIG. 1 is a block diagram showing an example of the configuration of a log management device according to a first embodiment. [Figure 7] FIG. 10 is an explanatory diagram illustrating the operation of generating a detection log of the operation monitoring function of the log management device according to the first embodiment. [Figure 8] FIG. 10 is an explanatory diagram illustrating an example of setting a grouping period according to the first embodiment. [Figure 9] FIG. 10 is an explanatory diagram illustrating a log to be transmitted according to the first embodiment. [Figure 10] FIG. 10 is an explanatory diagram illustrating a log to be transmitted according to the first embodiment. [Figure 11] FIG. 1 is a diagram for explaining information transmitted by an output unit according to the first embodiment. [Figure 12] 1 is a flowchart illustrating the operation of the log management device according to the first embodiment. [Figure 13]FIG. 1 is a block diagram showing an example of the configuration of a log analysis device according to a first embodiment. [Figure 14] FIG. 10 is a block diagram showing an example of the configuration of a log management device according to a second embodiment. [Figure 15] FIG. 10 is an explanatory diagram illustrating a log to be transmitted in the second embodiment. [Figure 16] FIG. 10 is a diagram for explaining information transmitted by an output unit according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0013] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.
[0014] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.
[0015] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.
[0016] When there are multiple embodiments (including variations and examples; the same applies in this section), the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined.
[0017] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.
[0018] 1. Configuration underlying each embodiment (1) Location of the log management device and its relationship with related devices 1 and 2 are diagrams illustrating the arrangement of the log management device in each embodiment and its relationship with related devices. For example, as shown in FIG. 1, a log management device 100 or a log management device 200 (hereinafter collectively referred to as the log management device 100, etc.) may be "mounted" on a "vehicle" together with an electronic control device 10 constituting an electronic control system S. Alternatively, as shown in FIG. 2, the electronic control device 10 constituting the electronic control system S may be "mounted" on a "vehicle," and the log management device 100, etc. may be implemented as a server device or the like provided outside the vehicle. In the embodiments described below, a case in which the log management device 100, etc. is mounted on a vehicle as shown in FIG. 1 will be described. Even when the log management device 100, etc. is not mounted on a vehicle as shown in FIG. 2, the same is true of each embodiment except for the communication method with the electronic control device 10. Therefore, the description of each embodiment will be quoted. where: "Vehicle" refers to a movable object, regardless of speed, and includes a stationary vehicle. Examples include, but are not limited to, automobiles, motorcycles, bicycles, and items mounted thereon. "Mounted" includes not only cases where the device is directly fixed to the vehicle, but also cases where the device is not fixed to the vehicle but moves with the vehicle, such as when the device is carried by a person in the vehicle or when the device is mounted on cargo placed on the vehicle.
[0019] The log management device 100 and the like are connected to "electronic control devices" (hereinafter referred to as ECUs (Electronic Control Units)) that constitute the electronic control system. The log management device 100 and the like are devices that acquire and manage security logs generated by security sensors mounted in multiple ECUs 10 that constitute the electronic control system S. Here, the "electronic control device" may be a physically independent electronic control device, or may be a virtualized electronic control device realized using virtualization technology.
[0020] The log analysis device 20 is provided outside the vehicle, receives security logs from the log management device 100, etc., and analyzes the logs to detect and analyze cyber-attacks. The log analysis device 20 is sometimes called a SOC (Security Operations Center).
[0021] In FIG. 1, the electronic control system S and the log analysis device 20 are connected via a communication network using a wireless communication method such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a local area network (LAN), the Internet, or a fixed telephone line can be used. Alternatively, the line may be a combination of a wireless communication system and a wired communication system. For example, the electronic control system S and a base station device in a cellular system may be connected by a wireless communication system such as 4G, and the base station device and the log analysis device 20 may be connected by a wired communication system such as a trunk line of a telecommunications carrier or the Internet. A gateway device may be provided at the point of contact between the trunk line and the Internet.
[0022] In FIG. 2, the electronic control system S and the log management device 100 and the like provided outside the vehicle are also connected via a communication network using the above-mentioned wireless communication method or wired communication method. In FIG. 2, the log management device 100 and the log analysis device 20 are shown as separate devices connected via a communication network, but the log management device 100 and the log analysis device 20 may be implemented as the same device.
[0023] (2) Configuration of electronic control system S Fig. 3 is a diagram showing an example of the configuration of an electronic control system S. The electronic control system S is made up of multiple ECUs 10 and an in-vehicle network connecting these. Fig. 3 shows eight ECUs (ECU10a to ECU10h) as an example, but the electronic control system S may naturally be made up of any number of ECUs. In the following explanation, when describing one or multiple electronic control devices collectively, they will be referred to as ECU10 or each ECU 10, and when describing individual electronic control devices specifically, they will be referred to as ECU10a, ECU10b, ECU10c, ...
[0024] 3, the ECUs 10 are connected to each other via an in-vehicle communication network such as a Controller Area Network (CAN) or a Local Interconnect Network (LIN). Alternatively, the ECUs 10 may be connected to each other using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). Note that connection refers to a state in which data can be exchanged, and includes not only cases in which different hardware is connected via a wired or wireless communication network, but also cases in which virtual ECUs (also called virtual machines) realized on the same hardware are virtually connected to each other.
[0025] The electronic control system S shown in FIG. 3 includes an integrated ECU 10a, an external communication ECU 10b, zone ECUs (10c, 10d), and individual ECUs (10e to 10h).
[0026] The integrated ECU 10a is an ECU that has a function of controlling the entire electronic control system S and also has a gateway function of mediating communication between the ECUs. The integrated ECU 10a is also called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU 10a may also be a relay device or a gateway device.
[0027] The external communication ECU 10b is an ECU having a communication unit that communicates with a log analysis device 20 provided outside the vehicle. The communication method used by the external communication ECU 10b is the wireless communication method or wired communication method described above. In order to realize a plurality of communication methods, a plurality of external communication ECUs 10b may be provided. Also, instead of providing the external communication ECU 10b, the integrated ECU 10a may include the functions of the external communication ECUb.
[0028] The zone ECUs (10c, 10d) are ECUs equipped with a gateway function that are appropriately arranged according to the location and function of the individual ECUs. For example, the zone ECU 10c is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10e and 10f arranged at the front of the vehicle and other ECUs 10, and the zone ECU 10d is an ECU equipped with a gateway function that mediates communication between the individual ECUs 10g and 10h arranged at the rear of the vehicle and other ECUs 10.
[0029] The individual ECUs (10e to 10h) can be configured with ECUs having any desired functions. Examples include drivetrain electronic control units that control the engine, steering, brakes, etc., body electronic control units that control meters, power windows, etc., information system electronic control units such as navigation systems, and safety control system electronic control units that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may be classified as master and slave rather than parallel.
[0030] In the electronic control system S in Fig. 3, a security sensor is installed in each ECU 10 other than the ECU 10h (abbreviated as SS in the figure). As such, it is not necessary for all ECUs 10 constituting the electronic control system S to be equipped with a security sensor. The log generated by the security sensor will be described later.
[0031] In each embodiment, the log management device 100 and the like are provided in the integrated ECU 10a. However, the log management device 100 and the like may be provided in the external communication ECU 10b, the zone ECUs (10c to 10d), or the individual ECUs (10e to 10h). When provided in one of the individual ECUs (10e to 10h), it is desirable to use a dedicated ECU for realizing the log management device 100 and the like.
[0032] (3) Detection logs and alive monitoring logs 4 is a block diagram showing the configuration of an ECU (10a to 10g) equipped with a security sensor. The ECU (10a to 10g) includes a log generating unit 11 and a transmitting unit 12.
[0033] The log generation unit 11 generates two types of security logs: a detection log and an alive monitoring log. FIG. 5 is a diagram showing a specific example of a security log. The security log has the following fields: an ECU ID indicating the identification information of the ECU 10 on which the security sensor is installed; a sensor ID indicating the identification information of the security sensor; an event ID indicating the identification information of the security event; a counter indicating the number of times the event has occurred; a timestamp indicating the time the event occurred; and context data indicating details of the security sensor output. The security log may further have a header storing information indicating the protocol version and the state of each field. An event is an object or phenomenon detected by a security sensor.
[0034] The detection log is a security log generated when a security sensor detects an abnormality, and indicates the detection result of the security sensor. For example, the detection log is generated when an abnormality caused by a cyber attack on each ECU 10 equipped with the security sensor is detected. In other words, the detection log is generated when the abnormality is detected. However, the detection log may be generated when the security sensor detects an abnormality, or when it detects normality.
[0035] In contrast, a health monitoring log is a security log that indicates that a security sensor is "operating." Health monitoring logs are security logs that are generated to take advantage of the fact that the security sensor is operating based on the fact that a log has been generated. The health check log is also called a survival signal, keep-alive information, or heartbeat information. Here, "indicating that the security sensor is operating" is sufficient if it can be directly or indirectly determined that the security sensor is operating.
[0036] The alive / dead monitoring log may also have a configuration as shown in Figure 5. In this case, for example, by setting a value unique to the alive / dead monitoring log as the event ID, it is possible to identify the security log as an alive / dead monitoring log. For example, if the event ID is composed of 16 bits, the upper 4 bits may be set to 1 (i.e., in hexadecimal notation, 0xF*** (* is an arbitrary number)) to indicate that it is an alive / dead monitoring log. Furthermore, an ID different from that of the detection log may be assigned to an ID other than the event ID, i.e., an ECU ID or a sensor ID, or any combination of these three IDs.
[0037] The alive monitoring log may not have a field for context data. However, a field for context data may be provided and information indicating that the security log is an alive monitoring log may be stored in the context data, thereby identifying the security log as an alive monitoring log. Furthermore, the context data may store information specific to the security sensor, setting information for the security sensor, or other meaningful information.
[0038] The timing at which the alive monitoring log is generated is not related to the detection of an abnormality in the security sensor. For example, the alive monitoring log may be generated at a fixed interval, such as every 10 seconds or every minute. Alternatively, the alive monitoring log may be generated at a specific timing in addition to this, such as when the vehicle ignition is turned on. Note that the fixed interval may be always the same, or may be determined according to certain conditions.
[0039] In each embodiment, the alive monitoring log is generated and transmitted by the security sensor, but alternatively, another process or another ECU10 monitoring the security sensor may generate and transmit the monitoring results of the security sensor's operating status as an alive monitoring log.
[0040] 4, the transmitter 12 transmits the security log generated by the log generator 11 to the log management device 100, etc. via the in-vehicle network. If the security sensor and the log management device 100, etc. are mounted on the same ECU 10, the log is output directly to the hardware or software that realizes the log management device 100, etc., without going through the in-vehicle network.
[0041] A security log generated by a security sensor is called an SEv, and a qualified security log that has been narrowed down is called a QSEv. For example, a security sensor generates an SEv and reports it to an intrusion detection system manager (IdsM). If the SEv passes through a certification filter in the IdsM and meets specified criteria, the SEv is transmitted from an intrusion detection reporter to the outside of the vehicle as a QSEv. The security log in each embodiment is a concept that includes both an SEv and a QSEv. When the security log is QSEv, the range including the intrusion detection system manager (IdsM) corresponds to the log generator 11 , and the intrusion detection reporter corresponds to the transmitter 12 .
[0042] 2. Embodiment 1 (1) Configuration of the Log Management Device 100 6 is a block diagram showing the configuration of a log management device 100 according to this embodiment. The log management device 100 includes a detection log receiving unit 101, a health monitoring log receiving unit 102, a storage unit 103, a control unit 104, and an output unit 108. The control unit 104 implements a health monitoring function detection log generating unit 105, a threat detection unit 106, and an output target determining unit 107 in hardware and / or software.
[0043] The log management device 100 can be configured with a general-purpose CPU (Central Processing Unit), volatile memory such as RAM, non-volatile memory such as ROM, flash memory, or hard disk, various interfaces, and an internal bus connecting these. By executing software on this hardware, the log management device 100 can be configured to perform the functions of each functional block shown in Fig. 6. The same applies to the log analysis device 20 and the log management device 200 of the second embodiment.
[0044] The detection log receiving unit 101 receives detection logs indicating detection results of security sensors of the ECU 10. The detection log receiving unit 101 acquires detection logs via an in-vehicle network from security sensors mounted on ECUs 10 other than the integrated ECU 10a on which the log management device 100 is mounted, and acquires detection logs directly from the security sensor mounted on the integrated ECU 10a without going through the in-vehicle network.
[0045] The alive / dead monitoring log receiving unit 102 receives the alive / dead monitoring log. The detection log receiving unit 101 and the alive / dead monitoring log receiving unit 102 may be realized by a single receiving unit.
[0046] The storage unit 103 stores the detection log received by the detection log receiving unit 101 and the alive / dead monitoring log received by the alive / dead monitoring log receiving unit 102. The storage unit 103 may be either an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, etc.). In addition, the storage unit 103 may be volatile or non-volatile. The storage unit 103 also stores the alive monitoring function detection log and the detection log determined by the output target determination unit 107, which will be described later.
[0047] The alive / dead monitoring function detection log generating unit 105 generates an alive / dead monitoring function detection log indicating the start and stop of security sensor operation based on the "reception status" of the alive / dead monitoring log in the alive / dead monitoring log receiving unit 102. More specifically, the alive / dead monitoring function detection log generating unit 105 generates an operation stop detection log, which is an alive / dead monitoring function detection log, when an alive / dead monitoring log is not received for a predetermined period (corresponding to the "second period"). Furthermore, when an alive / dead monitoring log is received for the first time, or when an alive / dead monitoring log is received again after the operation stop detection log was generated, the unit 105 generates an operation start detection log, which is an alive / dead monitoring function detection log. Here, the "reception status" may refer to the reception status of the alive-or-dead monitoring log itself, as well as the contents of the alive-or-dead monitoring log.
[0048] 7 is a diagram illustrating the operation of the alive / dead monitoring function detection log generation unit 105. In Fig. 7(a), the alive / dead monitoring log reception unit 102 receives an alive / dead monitoring log every minute. Then, when no alive / dead monitoring log is received for a predetermined period (corresponding to the "second period"), for example, five minutes, an operation stop detection log is generated. 7(b), it is assumed that the alive / dead monitoring log receiving unit 102 does not receive an alive / dead monitoring log for a while after generating the operation stop detection log. Then, when the alive / dead monitoring log receiving unit 102 receives an alive / dead monitoring log again, it generates an operation start detection log.
[0049] It is desirable that the predetermined period (corresponding to the "second period") be "longer" than the grouping period (corresponding to the "first period"). However, it is desirable that the difference between the two be small. For example, the difference between the two is set to within 10 seconds, such as 5 minutes for the former and 4 minutes 50 seconds for the latter. Here, "longer than" includes both cases where it is the same as the predetermined period (≧) and cases where it is not (>).
[0050] The operation stop detection log and the operation start detection log may also have the configuration shown in Fig. 5. For example, by setting a unique value for the operation stop detection log or the operation start detection log in the event ID, it is possible to identify it as an operation stop detection log or an operation start detection log.
[0051] Furthermore, it is desirable that the context data of the operation stop detection log and the operation start detection log include information identifying the security sensor that generated the alive monitoring log that caused these logs. For example, the context data may include the ECU ID, sensor ID, and event ID of the security sensor indicated by the alive monitoring log, or at least one of these. This allows the operation stop detection log and the operation start detection log to be generated for each ECU 10 or security sensor.
[0052] Furthermore, the operation stop detection log may include the latest time when the alive monitoring log was received, and the operation start detection log may include the latest time when the alive monitoring log was received.
[0053] The threat detection unit 106 determines whether or not one or more detection logs received by the detection log receiving unit 101 meet predetermined conditions. For example, the storage unit 103 stores a pattern matching table that describes the relationship between combinations of abnormalities indicated by the detection logs and the corresponding cyber attacks. The threat detection unit 106 then determines whether or not one or more detection logs received by the detection log receiving unit 101 match a pattern described in the pattern matching table, and if there is a match, it presumes that there is a threat of a cyber attack. Examples of specified conditions listed in the pattern matching table include, but are not limited to, when a specific combination of detection logs is received, when a specific detection log is received a specific number of times or more within a specific period of time, etc.
[0054] When the threat detection unit 106 determines that a predetermined condition is met, the output target determination unit 107 determines the range of security logs to be transmitted from the output unit 108, which will be described later. The output destination is the log analysis device 20 or the storage unit 103; in the former case, the output target is determined, and in the latter case, the storage target is determined. Whether to transmit to the log analysis device 20 or to output and store in the storage unit 103 can be determined based on any criteria. This embodiment will be described taking the case of transmission to the log analysis device 20 as an example, but the operation when outputting to the storage unit 103 is basically the same.
[0055] In this embodiment, the output target determination unit 107 sets a grouping period (corresponding to a "first period") as the time range of the detection logs to be sent. Specifically, when the threat detection unit 106 determines that the detection log satisfies a predetermined condition, the reception time of the detection log is set as the trigger time. In the case of a combination of multiple detection logs, the reception time of the last received detection log is set as the trigger time. Then, the grouping period is set based on the trigger time.
[0056] FIG. 8 is a diagram illustrating an example of setting a grouping period. In FIG. 8, it is assumed that three detection logs satisfy a predetermined condition. In this case, the time when the last detection log is received is set as the trigger time. Then, a T1 period before the trigger time and a T2 period after the trigger time are set, and these are collectively set as the grouping period. It is desirable to determine the lengths of the T1 and T2 periods in advance depending on the type of cyber-attack, but they may also be determined by other methods.
[0057] Then, the output target determination unit 107 determines the alive / dead monitoring function detection logs generated by the alive / dead monitoring function detection log generation unit 105 and the detection logs received by the detection log reception unit 101 during the grouping period as security logs to be transmitted from the output unit 108. In this embodiment, the alive / dead monitoring function detection log to be transmitted is the most recent alive / dead monitoring function detection log generated "before the trigger time." Here, "before the trigger time" includes both the case where the trigger time is included (≧) and the case where the trigger time is not included (>).
[0058] FIG. 9 shows an example of a detection log of the alive monitoring function to be sent. 9(a) to 9(e), all detection logs within the grouping period are to be sent. Naturally, these detection logs include detection logs that the threat detection unit 106 determines to meet predetermined conditions.
[0059] 9(a) shows the case where the most recent alive monitoring function detection log generated before the trigger time was generated before the grouping period. In this case, if the alive monitoring function detection log is an operation start detection log, it is clear that the security sensor was operating during the grouping period, and if the alive monitoring function detection log is an operation stop detection log, it is clear that the security sensor was stopped during the grouping period. Figure 9(b) shows the case where the most recent alive monitoring function detection log generated before the trigger time was generated within the grouping period. In this case, if the alive monitoring function detection log is an operation start detection log, it can be seen that the security sensor was stopped at the start of the grouping period, but has been operating since the operation start detection log was generated. In other words, as shown in Figures 9(a) and 9(b), as long as it is before the trigger time, it does not matter whether the alive monitoring function detection log was generated within the grouping period or before the grouping period.
[0060] In the case of Figure 9(b), the most recent detection log from the alive monitoring period that was generated before the start of the grouping period may also be the target of transmission. In other words, as shown in Figure 9(c), two alive monitoring function detection logs are targeted for transmission. 9(a) and 9(b), other alive monitoring function detection logs generated within the grouping period may be sent as normal detection logs. For example, as shown in FIG. 9(d), a alive monitoring function detection log generated within the grouping period after the trigger time (log G in the figure) may be sent as a normal detection log. Also, as shown in FIG. 9(e), a alive monitoring function detection log other than the most recent alive monitoring function detection log generated before the trigger time, but generated within the grouping period (log G in the figure), may be sent as a normal detection log.
[0061] 9 focuses on one ECU 10 and one security sensor, but normally there are multiple ECUs and multiple security sensors. In that case, the transmission target is determined for each ECU 10 and each security sensor.
[0062] Figure 10 shows an example of security logs to be sent when there are four ECUs: ECU 10a, ECU 10b, ECU 10c, and ECU 10d. Note that in the figure, the word "start" is added to the alive monitoring function detection logs for operation start detection logs, and the word "stop" is added to the alive monitoring function detection logs for operation stop detection logs. Also, the letters "a," "b," "c," and "d" added to the alive monitoring function detection logs and detection logs indicate which ECU generated the logs.
[0063] In FIG. 10, it is assumed that a trigger time and a grouping period are set based on a detection log ct that satisfies a predetermined condition. Here, the most recent alive monitoring function detection logs generated before the trigger time are operation start detection log a for ECU 10a, operation stop detection log b for ECU 10b, operation start detection log c for ECU 10c, and operation stop detection log d for ECU 10d, and therefore these alive monitoring function detection logs are determined to be transmitted. In addition, detection logs received during the grouping period are also determined to be transmitted. In FIG. 10, the detection logs included in the grouping period are detection logs received from ECU 10c and ECU 10d. Note that the detection logs may also include detection logs generated by ECUs 10 other than ECUs 10a to 10d. The lower part of FIG. 10 will be described later as a function of the log analysis device 20.
[0064] Returning to Fig. 6, the output unit 108 outputs the security log determined by the output target determination unit 107. That is, if the output destination is the log analysis device 20, it is sent to the log analysis device 20. If the output destination is the storage unit 103, it is output to the storage unit 103, and the storage unit stores the security log. In this embodiment, an example will be described in which the security log is sent to the log analysis device 20. When the output unit 108 transmits security logs to the log analysis device 20, it transmits all of the security logs determined by the output target determination unit 107, but instead, it may transmit only a portion of the logs. The range of logs to be transmitted may be determined by the output target determination unit 107 or the output unit 108, or may be determined by an external device, such as a diagnostic device or an external server. For example, if the log management device 100 is implemented by the integrated ECU 10a, the output unit 108 transmits the log to the log analysis device 20 via the external communication ECU 10b. In this embodiment, the alive-or-dead monitoring function detection log and the detection log received during the grouping period (corresponding to the "first period") are transmitted. Preferably, the alive-or-dead monitoring function detection log to be transmitted is the most recent alive-or-dead monitoring function detection log generated before the trigger time.
[0065] FIG. 11 is an example of information transmitted by the output unit 108. The output unit 108 first transmits the alive monitoring function detection log, and then transmits the detection log after the alive monitoring function detection log. Each log is transmitted in the order of its generation time and its reception time. Alternatively, the alive monitoring function detection log and the detection log may be transmitted in the order of their generation time or their reception time without distinction. The output unit 108 may further transmit information indicating the number of ECUs 10 or security sensors that are the targets of the alive monitoring function detection log to be transmitted. In the case of Fig. 11, there are four transmission sources identified as ECUs 10a to 10d, so the number of ECUs / SSs is four. The output unit 108 may further associate the creation time of the alive monitoring function detection log and the reception time of the detection log with each log and transmit them. In the case of Fig. 11, time information indicating the creation time and reception time is transmitted immediately after each log. In this embodiment, the alive / dead monitoring function detection log is transmitted, and therefore the alive / dead monitoring log received by the alive / dead monitoring log receiving unit 102 is not transmitted to the log analysis device 20.
[0066] The output unit 108 voluntarily transmits the alive-or-dead monitoring function detection log and the detection log. However, the output unit 108 may transmit the alive-or-dead monitoring function detection log and the detection log in response to a request from the log analysis device 20.
[0067] (2) Operation of the Log Management Device 100 Next, the operation of the log management device 100 will be described with reference to Fig. 12. Fig. 12 not only shows a log management method executed by the log management device 100, but also shows the processing procedure of a log management program that can be executed by the log management device 100. These processes are not limited to the order shown in Fig. 12. In other words, the order may be changed as long as there are no constraints, such as a relationship in which a certain step uses the result of the previous step. The same applies to other embodiments.
[0068] The detection log receiving unit 101 receives a detection log indicating the detection result of the security sensor of the ECU 10 mounted on the vehicle (S101). The alive-or-dead monitoring log receiving unit 102 receives the alive-or-dead monitoring log indicating that the security sensor is operating (S102). The alive-or-dead monitoring function detection log generation unit 105 generates an alive-or-dead monitoring function detection log indicating the start and stop of security sensor operation based on the reception status of the alive-or-dead monitoring log received in S102 (S103). The output unit 108 outputs the alive monitoring function detection log generated in S103 and the detection log received in S101 during the first period (S104).
[0069] (3) Configuration and Operation of the Log Analysis Device 20 13 is a block diagram showing the configuration of the log analysis device 20 according to this embodiment. The log analysis device 200 includes a receiving unit 201 and an event occurrence determining unit 202.
[0070] The receiving unit 201 receives the alive monitoring function detection log and the detection log transmitted from the log management device 100.
[0071] The event occurrence determination unit 202 determines whether an event has occurred in an ECU or a security sensor by using the alive-or-dead monitoring function detection log and the detection log received by the receiving unit 201. In particular, in this embodiment, the event occurrence determination unit 202 determines whether an event has occurred or the possibility of an event occurring based on a combination of whether the alive-or-dead monitoring function detection log is either an operation start detection log or an operation stop detection log, and the presence or absence of a detection log.
[0072] A method for determining the occurrence of an event in an ECU or a security sensor will be described using the lower part of Fig. 10. As already explained, the log management device 100 transmits the alive monitoring function detection log and the detection log shown in Fig. 10, and the log analysis device 20 receives these logs. According to FIG. 10, the ECUs 10a to 10d can make the following determinations based on the type of alive-or-dead monitoring function detection log and the presence or absence of the detection log.
[0073] The ECU 10a generates an operation start detection log but does not generate a detection log during the grouping period. In other words, although the security sensors are operating, it can be evaluated that no abnormal event has occurred because the normally operating security sensors have not detected any abnormal event, and therefore it can be determined that no event has occurred in the ECU 10a. The ECU 10b generates an operation stop detection log but does not generate a detection log during the grouping period. In other words, the security sensor is not operating and therefore no detection log is generated, but it can be evaluated that an abnormal event may have occurred, and therefore it can be determined that an event may have occurred in the ECU 10b.
[0074] The ECU 10c generates an operation start detection log and generates a detection log during the grouping period. In other words, it can be evaluated that the security sensor is operating and that the normally operating security sensor has detected an abnormal event, and therefore it can be determined that an event has occurred in the ECU 10c. The ECU 10d generates an operation stop detection log and generates a detection log during the grouping period. In other words, although the security sensor is not operating, the detection log is generated. However, since it can be evaluated that the security sensor, which is operating normally, has detected an abnormal event, it can be determined that an event has occurred in the ECU 10d. However, it can be determined that there may be some malfunction in the function for generating the alive monitoring function detection log or the function for sending and receiving the alive monitoring log.
[0075] (4) Summary As described above, according to this embodiment, a health monitoring function detection log indicating the start and stop of security sensor operation is generated based on the reception status of the health monitoring log and is transmitted to the log analysis device, thereby providing the log analysis device with information regarding the operation of the security sensor, and the log analysis device can determine the occurrence of an event in the ECU or security sensor based on this information. Furthermore, because the health monitoring function detection log is transmitted, there is no need to transmit the health monitoring log, and the amount of communication between the log management device and the log analysis device can be reduced. According to this embodiment, two types of logs, an operation stop detection log and an operation start detection log, are generated and transmitted as the alive monitoring function detection log, so that the log analysis device can make a more detailed judgment regarding the occurrence of an event using information that directly indicates the operation of the security sensor. According to this embodiment, since the grouping period is set based on the trigger time, it is possible to widely collect detection logs related to cyber-attacks and provide them to the log analysis device. In particular, since the grouping period is set to a period including both before and after the trigger time, it is possible to provide to the log analysis device detection logs that indicate the signs of a cyber-attack and detection logs that have been affected by a cyber-attack, and the log analysis device can accurately identify the cyber-attack and take measures against it. According to this embodiment, the most recent alive monitoring function detection log generated before the trigger time is sent, so that the alive monitoring function detection log that best reflects the operating status of the security sensor during the grouping period can be provided to the log analysis device. According to this embodiment, the alive monitoring function detection log generated during the grouping period is transmitted, so that information that the operating status of the security sensor has changed during the grouping period can be provided to the log analysis device. According to this embodiment, the alive monitoring function detection log and detection log are sent voluntarily, so information can be quickly provided to the log analysis device in situations where there is a high possibility of a cyber attack, and the log analysis device can quickly identify the cyber attack and take measures against it.
[0076] 3. Embodiment 2 The log management device 100 of the first embodiment sets a grouping period based on the trigger time, and sets the most recent alive monitoring function detection log generated before the trigger time as the transmission target. In the log management device 200 of this embodiment, the transmission target is determined based on a trip period that is determined based on a change in the power supply state of the vehicle. For example, the trip period is defined as the period from when the ignition (IG) is turned on to when it is turned off. Another example of the trip period is the period from when the accessory power supply is turned on to when it is turned off, but of course other power supply states may also be used. Alternatively, the transmission target may be determined based on a regular period such as 24 hours or 5 days, or a period specified by the period during which an optional function installed in the vehicle is in use. In such cases, since security logs cannot be received or generated when the vehicle power is off, these periods can also be considered trip periods. Even if these periods span multiple trip periods, each of them is still considered a trip period.
[0077] (1) Configuration of the Log Management Device 200 14 is a block diagram showing the configuration of a log management device 200 according to this embodiment. The same components as those in the log management device 100 according to the first embodiment are designated by the same component numbers as those in FIG. 6, and the description and drawings of the first embodiment are cited. The log management device 200 includes a detection log receiving unit 101, an alive / dead monitoring log receiving unit 102, a storage unit 103, a control unit 204, and an output unit 208. The control unit 204 realizes an alive / dead monitoring function detection log generating unit 105 and an output target determining unit 207 in hardware and / or software.
[0078] The output target determination unit 207 determines the range of security logs to be output from the output unit 208. As in the first embodiment, the output destination is the log analysis device 20 or the storage unit 103, and in the former case, the output target is determined, and in the latter case, the output target is determined. This embodiment will be described taking as an example a case where the log is sent to the log analysis device 20, but the operation when outputting to the storage unit 103 is basically the same.
[0079] In this embodiment, the time range of the detection log to be transmitted by the output target determination unit 207 is set to the trip period from IG-ON to IG-OFF of the vehicle (corresponding to the "first period").
[0080] Then, the output target determination unit 207 determines the alive / dead monitoring function detection log generated by the alive / dead monitoring function detection log generation unit 105 and the detection log received by the detection log reception unit 101 during the trip period as security logs to be transmitted from the output unit 208. In this embodiment, the alive / dead monitoring function detection log to be transmitted is the alive / dead monitoring function detection log generated during the trip period.
[0081] 15 shows an example of security logs to be sent when there are two ECUs, ECU 10a and ECU 10b. Note that in the figure, among the alive / dead monitoring function detection logs, the operation start detection log is marked with the word "start" and the operation stop detection log is marked with the word "stop." Also, the "a" and "b" marked in the alive / dead monitoring function detection log and detection log indicate which ECU generated the log.
[0082] 15, the operation start detection log a of ECU 10a, the operation start detection log b of ECU 10b, the operation stop detection log a of ECU 10a, the operation stop detection log b of ECU 10b, and the operation start detection log a of ECU 10a are generated in chronological order during the trip period, and therefore these alive monitoring function detection logs are determined to be the ones to be transmitted. In addition, the detection logs received during the trip period are also determined to be the ones to be transmitted. In FIG. 15, the detection logs included in the trip period are the two detection logs received from ECU 10b. The lower part of FIG. 15 will be described later as a function of the log analysis device 20.
[0083] 14, the output unit 208 transmits the security log determined by the output target determination unit 207 to the log analysis device 20. In this embodiment, the output unit 208 transmits the alive monitoring function detection log and the detection log received during the trip period (corresponding to the "first period").
[0084] FIG. 16 is an example of information transmitted by the output unit 208. The output unit 208 transmits the alive-or-dead monitoring function detection log and the detection log. In this embodiment, the alive-or-dead monitoring function detection log and the detection log are transmitted in any order, and are transmitted in the order of generation time or reception time. The output unit 208 may further transmit information indicating the number of ECUs 10 or security sensors that are the targets of the alive monitoring function detection log to be transmitted. In the case of Fig. 11, there are two transmission sources identified by ECU 10a to ECU 10b, so the number of ECUs / SSs is 2. The output unit 208 may further associate the creation time of the alive monitoring function detection log and the reception time of the detection log with each log and transmit them. In the case of Fig. 16, time information indicating the creation time and reception time is transmitted immediately after each log. In this embodiment, the alive / dead monitoring function detection log is transmitted, and therefore the alive / dead monitoring log received by the alive / dead monitoring log receiving unit 102 is not transmitted to the log analysis device 20.
[0085] The output unit 208 transmits the alive / dead monitoring function detection log and the detection log in response to a request from the log analysis device 20. For example, the output unit 208 transmits the alive / dead monitoring function detection log and the detection log for one or more trip periods included in the past 10 days together. However, the output unit 208 may also transmit the alive / dead monitoring function detection log and the detection log of its own accord.
[0086] (2) Operation of the Log Management Device 200 The operation of the log management device 200 is the same as that of the log management device 100, so FIG. 12 and its description will be cited.
[0087] (3) Configuration and Operation of the Log Analysis Device 20 The configuration of the log analysis device 20 of this embodiment is the same as the configuration of the log analysis device 20 of the first embodiment, so FIG. 13 and its description will be cited.
[0088] A method for detecting an abnormality in a security sensor will be described with reference to Fig. 15. As already explained, the log management device 200 transmits the alive monitoring function detection log and the detection log shown in Fig. 15, and the log analysis device 20 receives these logs. According to FIG. 15, the ECUs 10a and 10b can make the following determinations based on the type of alive-or-dead monitoring function detection log and the presence or absence of the detection log.
[0089] The ECU 10a generates an operation start detection log at the start of the t1 period and the start of the t3 period, but does not generate a detection log during these periods. In other words, although the security sensors are operating, it can be evaluated that no abnormal event has occurred because the normally operating security sensors have not detected any abnormal event, and therefore it can be determined that no event has occurred in the ECU 10a. The ECU 10a generates an operation stop detection log at the start of the period t2, but does not generate a detection log during the period t2. In other words, the security sensor is not operating and therefore does not generate a detection log, but it can be evaluated that an abnormal event may have occurred, and therefore it can be determined that an event may have occurred in the ECU 10a.
[0090] The ECU 10b generates an operation start detection log at the start of the period t4, and generates a detection log during the period t4. In other words, it can be evaluated that the security sensor is operating, and that the normally operating security sensor has detected an abnormal event, and therefore it can be determined that an event has occurred in the ECU 10b. ECU 10b generates an operation stop detection log at the start of period t5, and generates a detection log during period t5. In other words, the detection log is generated even though the security sensor is not operating. However, since it can be evaluated that the security sensor, which is operating normally, has detected an abnormal event, it can be determined that an event has occurred in ECU 10b. However, it can be determined that there may be some kind of malfunction in the function for generating the alive monitoring function detection log or the function for sending and receiving the alive monitoring log.
[0091] (4) Summary As described above, according to this embodiment, a health monitoring function detection log indicating the start and stop of security sensor operation is generated based on the reception status of the health monitoring log and is transmitted to the log analysis device, thereby providing the log analysis device with information regarding the operation of the security sensor, and the log analysis device can determine the occurrence of an event in the ECU or security sensor based on this information. Furthermore, because the health monitoring function detection log is transmitted, there is no need to transmit the health monitoring log, and the amount of communication between the log management device and the log analysis device can be reduced. According to this embodiment, two types of logs, an operation stop detection log and an operation start detection log, are generated and transmitted as the alive monitoring function detection log, so that the log analysis device can make a more detailed judgment regarding the occurrence of an event using information that directly indicates the operation of the security sensor. According to this embodiment, a trip period is set, so that detection logs related to cyber attacks can be widely collected and provided to the log analysis device. According to this embodiment, the alive monitoring function detection log generated during the trip period is transmitted, so that the log analysis device can be informed of changes in the operating status of the security sensor during the trip period. According to this embodiment, the alive monitoring function detection log and the detection log are sent in response to a request from the log analysis device, so that only the security logs that the log analysis device determines are necessary are sent, thereby reducing the amount of communication.
[0092] 4. Summary The features of the log management device and the like in each embodiment of the present invention have been described above.
[0093] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.
[0094] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.
[0095] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.
[0096] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.
[0097] The following are examples of the configuration of the log management device of the present invention. Examples of the component include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU) and a system board. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.
[0098] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log management device.
[0099] The log management device of the present invention is expected to be used, particularly on the server side, for the purpose of providing various services. In providing such services, the log management device of the present invention will be used, the method of the present invention will be used, and / or the program of the present invention will be executed.
[0100] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.
[0101] A program stored in a non-transitory physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]
[0102] The log management device of the present invention is primarily intended for use as a device for analyzing cyber attacks on electronic control systems installed in automobiles, but may also be used as a device for analyzing attacks on ordinary systems not installed in automobiles. [Explanation of symbols]
[0103] 10 ECU, 100,200 log management device, 101 detection log receiving unit, 102 alive monitoring log receiving unit, 103 storage unit, 104,204 control unit, 105 alive monitoring function detection log generating unit, 106 threat detection unit, 107,207 output target determining unit, 108,208 output unit, 20 log analysis device
Claims
1. a detection log receiving unit (101) that receives a detection log indicating a detection result of a security sensor of an electronic control device (10) mounted on a vehicle; a health monitoring log receiving unit (102) that receives a health monitoring log indicating that the security sensor is operating; a health monitoring function detection log generation unit (105) that generates a health monitoring function detection log indicating the start and stop of operation of the security sensor based on the reception status of the health monitoring log; an output unit (108) that outputs the alive monitoring function detection log and the detection log received during a first period; Log management device (100, 200).
2. The alive monitoring function detection log generation unit generating an operation stop detection log, which is the alive-or-dead monitoring function detection log, when the alive-or-dead monitoring log is not received for a second period; generating an operation start detection log, which is the alive-or-dead monitoring function detection log, when the alive-or-dead monitoring log is received for the first time or when the alive-or-dead monitoring log is received again after the operation stop detection log is generated; The log management device according to claim 1.
3. The output unit outputs the alive monitoring function detection log and the detection log for each of the electronic control devices or the security sensors. The log management device according to claim 1.
4. The output unit further transmits information indicating the number of the electronic control devices or the security sensors that are targets of the alive monitoring function detection log. The log management device according to claim 1.
5. the output unit transmits the detection log after the alive monitoring function detection log. The log management device according to claim 1.
6. The output unit further transmits time information indicating the time when the alive monitoring function detection log was generated. The log management device according to claim 1.
7. The output unit does not transmit the alive monitoring log to a log analysis device (20). The log management device according to claim 1.
8. The system further includes a threat detection unit (106) that determines whether or not one or more of the detection logs received by the detection log receiving unit correspond to a predetermined condition, the first period is set based on a trigger time, which is a time when the detection log that meets the predetermined condition is received; The log management device (100) according to claim 1.
9. the first period includes a period before and after the trigger time; 9. The log management device according to claim 8.
10. the output unit outputs the most recent alive-or-dead monitoring function detection log generated before the trigger time.
10. The log management device according to claim 9.
11. the output unit outputs the alive monitoring function detection log generated during the first period as the detection log.
10. The log management device according to claim 9.
12. The output unit voluntarily transmits the alive monitoring function detection log and the detection log to a log analysis device.
12. The log management device according to claim 10 or 11.
13. the alive-or-death monitoring function detection log generation unit generates an operation stop detection log, which is the alive-or-death monitoring function detection log, when the alive-or-death monitoring log is not received for a second period; The second period is longer than the first period.
9. The log management device according to claim 8.
14. the first period is a trip period determined based on a change in the power supply state of the vehicle; The log management device (200) according to claim 1.
15. the output unit outputs the alive monitoring function detection log generated during the first period as the detection log.
15. The log management device according to claim 14.
16. the output unit transmits the alive monitoring function detection log and the detection log to the log analysis device in response to a request from the log analysis device.
16. The log management device according to claim 15.
17. The log management device is mounted on the vehicle. The log management device according to claim 1.
18. The log management device is provided outside the vehicle. The log management device according to claim 1.
19. A log management method executed by a log management device (100, 200), A detection log showing the detection results of the security sensor of the electronic control device (10) mounted on the vehicle is received (S101); A monitoring log indicating that the security sensor is operating is received (S102). Based on the reception status of the alive-or-dead monitoring log, a alive-or-dead monitoring function detection log is generated which indicates the start and stop of operation of the security sensor (S103); outputting the alive monitoring function detection log and the detection log received during the first period (S104); Log management methods.
20. A log management program executable by a log management device (100, 200), the log management program for the log management device: A detection log showing the detection results of the security sensor of the electronic control device (10) mounted on the vehicle is received (S101); A monitoring log indicating that the security sensor is operating is received (S102). Based on the reception status of the alive-or-dead monitoring log, a alive-or-dead monitoring function detection log is generated which indicates the start and stop of operation of the security sensor (S103); Outputting the alive monitoring function detection log and the detection log received during the first period (S104), and executing processing. Log management program.
21. A log management system comprising a log management device (100, 200) and a log analysis device (20), The log management device a detection log receiving unit (101) that receives a detection log indicating a detection result of a security sensor of an electronic control device (10) mounted on a vehicle; a health monitoring log receiving unit (102) that receives a health monitoring log indicating that the security sensor is operating; a health monitoring function detection log generation unit (105) that generates a health monitoring function detection log including an operation start detection log indicating the start of operation of the security sensor and an operation stop detection log indicating the stop of operation of the security sensor based on the reception status of the health monitoring log; an output unit (108) that outputs the alive monitoring function detection log and the detection log received during a first period, The log analysis device a receiving unit (201) for receiving the alive monitoring function detection log and the detection log; and an event occurrence determination unit (202) that determines whether an event has occurred in the electronic control device or the security sensor based on a combination of the alive monitoring function detection log, the operation start detection log, the operation stop detection log, and the presence or absence of the detection log. Log management system (1).
Citation Information
Patent Citations
Security device, attack specification method, and program
JP2020123307A
Attack analysis device, attack analysis method, and attack analysis program
JP2023006513A