Anomalous communication detection device, anomalous communication detection method, and anomalous communication detection program
By constructing directed graphs from flow data and comparing subgraph combinations, the method efficiently detects abnormal communications in large traffic data sets, addressing the inefficiencies of existing methods.
Patent Information
- Application Number
- JP2022060172
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-05-12
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Existing methods for detecting abnormal communications in traffic data are inefficient due to the large volume of data, which takes a long time to process as a graph, and struggle to distinguish between normal and abnormal communications, especially in cases like host scan attacks.
The proposed solution involves constructing a directed graph using flow data as nodes, extracting communication order subgraphs by comparing edge weights with a threshold, adding communication content subgraphs, and detecting abnormal communications by comparing combinations of these subgraphs.
This approach reduces processing costs and effectively detects abnormal communications that are difficult to distinguish from normal communications, improving the efficiency of abnormality detection in large volumes of traffic data.
Smart Images

Figure 0007675045000001 
Figure 0007675045000002 
Figure 0007675045000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an apparatus, a method, and a program for detecting abnormal communications. [Background technology]
[0002] Conventionally, methods that target packet data have been the mainstream for detecting anomalies in traffic data. For example, Non-Patent Document 1 proposes a method that focuses on subgraphs by constructing a graph with hosts as nodes and communications between hosts as edges, because some malware has communication patterns that mimic normal communications. This method detects standard patterns from subgraphs of normal communications, and defines subgraphs that are close to the standard as patterns but whose occurrence probability is below a threshold as anomalous communications.
[0003] Non-Patent Document 2 proposes a method for detecting abnormal communications such as DoS attacks by constructing feature vectors from each attribute of packet data, such as communication volume and number of packets, and extracting the behavior of traffic data as a graph structure based on these.
[0004] Non-Patent Document 3 proposes StrGNN, an anomaly detection method that combines a subgraph of a dynamic graph with an RNN (Recurrent Neural Network) in order to capture the characteristics of traffic data whose structure changes over time. Similar to Non-Patent Documents 1 and 2, the graph is constructed with hosts as nodes and communications between hosts as edges, but StrGNN focuses on each edge of the graph and constructs a subgraph by tracing nodes from the two nodes that make up an edge for k hops. When traffic data is given in a time series, a list of subgraphs made up of edges in a time interval is input into the RNN, which learns whether the corresponding edge is normal or abnormal. [Prior art documents] [Non-patent literature]
[0005] [Non-Patent Document 1] Eberle, W., & Holder, L. (2013). Incremental anomaly detection in graphs. Proceedings - IEEE 13th International Conference on Data Mining Workshops, ICDMW 2013, 521-528. [Non-patent document 2] Yu, X., Tian, Z., Qiu, J., Su, S., & Yan, X. (2019). An Intrusion Detection Algorithm Based On Feature Graph. Computers, Materials & Continua, 61(1), 255-274. [Non-patent document 3] Cai, L., Chen, Z., Luo, C., Gui, J., Ni, J., Li, D., & Chen, H. (2021). Structural Temporal Graph Neural Networks for Anomaly Detection in Dynamic Graphs; ACM International Conference on Information & Knowledge Management, 3747-3756. Summary of the Invention [Problem to be solved by the invention]
[0006] The methods in Non-Patent Documents 1 to 3 are all anomaly detection methods that target packet data, but because the traffic data has a huge amount of communication volume per unit time, it takes a very long time to process it as a graph.
[0007] Furthermore, because these existing technologies are methods for detecting anomalous communications based on packet features, it is easy to detect anomalous communications such as DoS attacks, which cause a sudden increase in communication volume compared to normal communications, where abnormalities appear in the packet attribute information. However, it has been difficult to detect anomalous communications that are difficult to distinguish from normal communications when viewed as packet data, such as host scan attacks carried out when malware infections spread.
[0008] The present invention aims to provide an anomalous communication detection device, an anomalous communication detection method, and an anomalous communication detection program that can reduce processing costs and detect anomalous communication that is difficult to distinguish from normal communication. [Means for solving the problem]
[0009] The anomalous communication detection device of the present invention comprises a graph construction unit that constructs a directed graph in which flow data having a common source and a common function that performed communication are connected by edges in the order in which the flow data are generated, and in which the flow data are nodes; a subgraph extraction unit that extracts a communication order subgraph by comparing edge weights that indicate the relationships between nodes in the directed graph with a predetermined threshold; a data addition unit that adds to the communication order subgraph a communication content subgraph having, as attribute information, communication content with hosts included in the flow data that constitute the graph as nodes; and an anomaly detection unit that detects anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph.
[0010] The graph construction unit may acquire flow data obtained from a vehicle communication network through which vehicles and in-vehicle application servers communicate with each other, and the anomaly detection unit may detect anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other for each type of vehicle or each function of the in-vehicle application.
[0011] The graph construction unit may acquire communication log data transmitted and received between vehicles or between a vehicle and a road as flow data, and the abnormality detection unit may detect abnormal communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other for each type of vehicle or road.
[0012] The subgraph extraction unit may extract the communication order subgraph by setting a time interval between successive flow data in the directed graph as a weight of the edge and deleting edges whose time interval exceeds a predetermined threshold.
[0013] The subgraph extraction unit may extract the communication order subgraph by setting a conditional probability of occurrence of a statistic obtainable from immediately following flow data as a weight of the edge, based on the statistic obtainable from flow data in the directed graph, and deleting edges whose probability does not satisfy a predetermined threshold.
[0014] The anomalous communication detection method according to the present invention is executed by a computer, and includes the following steps: a graph construction step of constructing a directed graph in which flow data having a common source and a common function that have communicated are connected by edges in the order in which the flow data are generated, and the flow data are used as nodes; a subgraph extraction step of extracting a communication order subgraph by comparing edge weights indicating the relationships between nodes in the directed graph with a predetermined threshold; a data addition step of adding to the communication order subgraph a communication content subgraph having, as attribute information, communication content in which hosts included in the flow data that constitute the graph are used as nodes; and an anomaly detection step of detecting anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph.
[0015] The anomalous communication detection program according to the present invention is for causing a computer to function as the anomalous communication detection device. [Effects of the Invention]
[0016] According to the present invention, it is possible to reduce processing costs and detect abnormal communications that are difficult to distinguish from normal communications. [Brief explanation of the drawings]
[0017] [Figure 1] FIG. 1 illustrates a vehicle communication network according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating a functional configuration of an anomalous communication detection device according to an embodiment. [Figure 3] FIG. 2 is a diagram illustrating a directed graph configured from flow data in the embodiment. [Figure 4] FIG. 10 is a diagram illustrating a communication order subgraph in the embodiment. [Figure 5] FIG. 10 is a diagram illustrating a communication content subgraph in the embodiment. [Figure 6] FIG. 10 is a diagram showing a modified example of the embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0018] An example of an embodiment of the present invention will be described below. The anomalous communication detection method of this embodiment targets flow data such as IPFIX (IP Flow Information Export) or VPC (Virtual Private Cloud) flow logs, rather than packets, as a means of speeding up the detection process. In flow data, multiple packets are aggregated as statistical information, so the overall data volume can be compressed, which results in faster anomaly detection processing. For example, in vehicle communication networks, where large volumes of communication data are expected to flow at high speeds, it is possible to speed up anomaly detection by using lighter flow data rather than packet-by-packet anomaly detection, which takes a long time to process.
[0019] However, existing anomaly detection methods using flow data attempt to detect anomalous records by using statistical information contained in the records, but these methods are unable to detect anomalous communications that are indistinguishable from normal communications when viewed as a single flow data record, such as host scan attacks to spread malware or C&C (Command and Control) communications for DDoS attacks.
[0020] Therefore, the anomalous communication detection method of this embodiment treats a single communication pattern from source to destination as a temporal group of flow data, rather than a single flow data record, and represents the communication behavior across multiple records in a graph structure, thereby accurately detecting anomalous communication that is difficult to distinguish from normal communication when viewed as a single flow data record.
[0021] Hereinafter, a vehicle communication network (hereinafter referred to as a vehicle communication network) will be taken as an example of a communication network in which abnormal communication is to be detected, and an abnormal communication detection method will be described when each vehicle communicates with an in-vehicle application server.
[0022] FIG. 1 is a diagram illustrating a vehicle communication network according to this embodiment. Each of the multiple vehicles communicates with the corresponding in-vehicle application server via the vehicle communication network using the in-vehicle application installed in each vehicle. Note that all communication data reaches the vehicle or the in-vehicle application server via a specific point on the vehicle communication network.
[0023] A capture device installed at a specific point on the vehicle communication network captures communications, thereby obtaining all communications on the vehicle communication network, or communications relating to a specific vehicle model or specific application or function, etc.
[0024] The anomalous communication detection device 1 of this embodiment detects anomalous communication caused by malware infection, equipment failure, cyber-attacks, etc. occurring on a vehicle communication network using flow data such as IPFIX acquired by a capture device. The flow data includes statistical data including the source and destination of communication, as well as information indicating which function of an application (hereinafter referred to as an application function) each vehicle communicated with. Note that the application function may be acquired by other application identification means, etc.
[0025] FIG. 2 is a diagram showing the functional configuration of the anomalous communication detection device 1 in this embodiment. The anomalous communication detection device 1 is an information processing device that includes a control unit 10, a storage unit 20, as well as various data input / output devices and communication devices.
[0026] The control unit 10 is a part that controls the entire anomalous communication detection device 1, and realizes each function of this embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a CPU. Specifically, the control unit 10 includes a graph construction unit 11, a subgraph extraction unit 12, a data addition unit 13, and an anomaly detection unit 14.
[0027] The storage unit 20 is a storage area for various programs and various data for causing the hardware group to function as the anomalous communication detection device 1, and may be a ROM, RAM, flash memory, hard disk drive (HDD), etc. Specifically, the storage unit 20 stores a program (anomalous communication detection program) for causing the control unit 10 to execute each function of this embodiment, and further stores flow data, graph data, anomaly detection models, various parameters, etc. received as processing targets.
[0028] The graph construction unit 11 connects the flow data that are common to the vehicle as the transmission source and the application function that performed the communication in order of generation with edges, and constructs a directed graph in which the flow data are nodes.
[0029] Specifically, we first define a set of flow data capturing communications from each vehicle to application function y as {v i ∈V}. The graph construction unit 11 sets each flow data as a node in the graph, and constructs a set of ordered pairs E={v i ,v j}(i <j; v i ,v j ∈V) and construct a directed graph G={V,E} with these as edges.
[0030] FIG. 3 is a diagram illustrating a directed graph formed from flow data in this embodiment. A directed graph G is a set of vehicles x k It is composed of connected subgraphs that represent communications from vehicle to application function y. The edges of the graph indicate the order in which communications are made from the vehicle to application function y, and since the processing content is roughly the same for communications to the same application function regardless of which vehicle the communications are from, it is expected that the topology of each subgraph will also be roughly the same.
[0031] The subgraph extraction unit 12 extracts a communication order subgraph by comparing the weight of an edge, which indicates the relationship between nodes in the directed graph G, with a predetermined threshold. The definition of the weight is not limited, but for example, the following method (1) or (2) can be applied.
[0032] (1) Time interval: The subgraph extraction unit 12 extracts a communication-order subgraph by using the time interval of successive flow data in the directed graph G as an edge weight and deleting edges whose time interval exceeds a predetermined threshold.
[0033] Node V i The communication start time and communication end time of (flow data) are respectively i ,et i Then, the edge e i,j ={v i ,v j}(i <j; vi ,v j ∈V) is an ordered pair consisting of the order in which the flow data is generated, so i <st j is. where e i,j The weight of |e i,j |=st j -et i It is defined as:
[0034] Communications between the vehicle and the server related to application function y can be broadly divided into operational communications triggered by operating the in-vehicle application, and steady-state communications in which the in-vehicle application periodically updates data, etc. In either case, one or more records of flow data are generated between the vehicle and the server related to application function y in one operation or one steady-state communication (hereinafter referred to as a block of communication). These blocks of communication occur intermittently in the case of operational communications, while they occur periodically at regular intervals in the case of steady-state communications, and therefore occur repeatedly as a communication pattern represented by a group of records at short time intervals. Therefore, the subgraph extraction unit 12 sets a threshold value θ that can separate the record groups into communication patterns, and satisfies θ<|e i,j |becomes e i,j Delete.
[0035] FIG. 4 is a diagram illustrating a communication order subgraph in this embodiment. Node v that composes graph G i ,v i+1 ,,v i+2 ,v i+3 ,… are weighted by |e i,i+1 |,|e i+1,i+2 |,|e i+2,i+3 are connected by edges |,... These weights are, in order, |e i,i+1 |≦θ,|e i+1,i+2 |≦θ,|e i+2,i+3 If |>θ,..., then edge e i+2,i+3 is deleted, and node v i to node v i+2 A communication order subgraph consisting of up to is extracted. In this way, a new graph G' is obtained in which a set of communications is represented by a connected subgraph.
[0036] (2) Conditional probability: The subgraph extraction unit 12 extracts a communication order subgraph by setting the conditional probability of occurrence of a statistic that can be obtained from the immediately following flow data as the weight of an edge, given the statistic that can be obtained from the flow data in the directed graph G, and deleting edges whose probability does not satisfy a predetermined threshold.
[0037] The operations and functions of communication between the vehicle and the in-vehicle application server are fixed depending on the application, so the order and pattern of communication are somewhat limited, for example, license authentication is performed at the beginning of communication. Therefore, when the statistics that can be obtained from flow data such as the number of packets or communication volume are U = {u1, u2, ...} and the communication order is t1, t2, ..., the conditional probability P(U t_k |U t_k-1 ,U t_k-2 ,…) and e i,j Instead of the time interval mentioned above, the weight of |e i,j |=1-P(U t_j |U t_i )(0<|e i,j |<1).
[0038] Since the flow data contained in a group of communications is expected to occur consecutively in a specific order with a high probability, by setting an appropriate threshold θ, the group of communications can be treated as a communication order subgraph.
[0039] The data addition unit 13 adds a communication content subgraph to the extracted communication order subgraph, the communication content subgraph having, as attribute information, the communication content of which nodes are hosts included in the flow data that constitute this subgraph.
[0040] The communication order subgraph S that constitutes graph G' indicates the communication order of a set of communications between each vehicle and the server related to application function y. Since application function y provides the same service to all vehicles, not only the communication order but also the communication content is configured in the same pattern. Therefore, the data addition unit 13 defines a host on the vehicle network as x, one or more hosts that constitute the application function y as y1, y2, ..., and adds a communication content subgraph S' to graph G', in which the hosts are nodes and communications occurring between the hosts are edges, to construct a new graph G''. At this time, the edges and nodes of the communication content subgraph S' hold, as attributes, information such as the amount of communication between hosts, the number of communication packets, host addresses, and other statistics that can be obtained from flow data.
[0041] FIG. 5 is a diagram illustrating a communication content subgraph in the embodiment. A graph G' including a communication order subgraph S is constructed for communication from a vehicle x to a server related to an application function y. In this case, the hosts included in the communication order subgraph S include the vehicle x as well as servers y1, y2, and y3 related to the application function y, and a graph G'' is constructed to which a communication content subgraph S' representing the communication between x and each server is added.
[0042] The abnormality detection unit 14 detects abnormal communication by comparing combinations of communication order subgraphs and communication content subgraphs with each other for each vehicle type or application function.
[0043] The graph G'' constructed by the data addition unit 13 consists of a communication order subgraph that represents the order of communication and a communication content subgraph that represents the content of communication for a group of communications occurring between the vehicle x and the server related to the application function y. When abnormal communication occurs in a vehicle communication network, a graph is generated that significantly deviates from a graph composed of a normal group of communications in terms of the graph topology or the attributes of the nodes or edges. For example, a host scan attack carried out when spreading malware is difficult to distinguish from normal communications when viewed as a single flow data record, but when viewed as a graph in this embodiment, it is thought to show a communication sequence that is significantly different from normal communications in a group of communications. Note that a host scan indiscriminately sends short communications to multiple hosts, so abnormalities occur not only in the topology of the graph composed of the communication sequence, but also in the topology of the graph of the communication content.
[0044] Therefore, by constructing a graph G'' from the vehicle communication network and applying an anomaly detection method that detects anomalies in the topology of the subgraph or in the nodes or edges, the anomaly detection unit 14 detects anomalous communications that are difficult to detect using flow data records alone. Note that the specific anomaly detection method may be any of various existing methods, such as an anomaly detection method using a machine learning model, and is not limited to an anomaly detection method that targets a directed graph.
[0045] As described above, in this embodiment, an example has been given of detecting an abnormality in communication between a vehicle and an in-vehicle application server in a vehicle communication network, but the scope of application is not limited to this. For example, the graph construction unit 11 may acquire communication log data transmitted and received between vehicles or between a vehicle and a road as flow data, and the abnormality detection unit 14 may detect abnormal communications by comparing combinations of communication order subgraphs and communication content subgraphs for each type of vehicle or road.
[0046] FIG. 6 is a diagram showing a modified example of this embodiment. In this case, each vehicle keeps a communication log for a certain period of time for vehicle-to-vehicle or vehicle-to-road communication. After keeping the communication log for a certain period of time, each vehicle periodically transmits the communication log via the network to a server installed at a base station. The communication log includes information based on flow data, such as the communication source, communication destination, and communication volume.
[0047] The communication sources and destinations of the communication log data collected in the server are separately classified by vehicle type or road type. The classified communication log data is equivalent to the collection of flow data described above. In this collection of communication log data, by constructing a graph in the same manner as described above from those that have a common "source vehicle or road" and a common "destination vehicle or road," it is possible to detect abnormal communication between vehicles or between vehicles and roads based on the communication log data aggregated on the server.
[0048] According to this embodiment, the anomalous communication detection device 1 uses flow data instead of packets, thereby making it possible to reduce the processing cost required for the detection processing of anomalous communication. Furthermore, by representing a group of communications as a combination of a communication order subgraph and a communication content subgraph, the anomalous communication detection device 1 can detect anomalous communications that are difficult to distinguish from normal communications when viewed as individual flow data records as abnormalities in the behavior of a series of communications.
[0049] In particular, the abnormal communication detection device 1 can efficiently detect abnormal communication from among a huge amount of communication data in a vehicle communication network where vehicles and in-vehicle application servers communicate with each other. In addition, when the anomalous communication detection device 1 acquires communication log data transmitted and received between vehicles or between a vehicle and a road, it can detect anomalous communication by treating this data as flow data and processing it in the same way.
[0050] Furthermore, since the abnormal communication detection device 1 can individually recognize abnormal communications that occur between vehicles and servers in the vehicle communication network, it can not only determine whether an abnormality has occurred overall, but also identify which vehicle and which application function the abnormal communication occurred in. Furthermore, depending on the anomaly detection method, it is possible to distinguish between an anomaly occurring in the topology of the graph and an anomaly occurring in the attributes of the nodes or edges that make up the graph, making it possible to classify patterns of anomalous communication, such as an anomaly in the number of packets that is characteristic of DoS attacks, or an anomaly in topology that occurs in C&C communications.
[0051] When extracting a communication order subgraph, the anomalous communication detection device 1 compares the time interval of the flow data with a threshold value, or compares the conditional probability related to the statistical quantity with a threshold value, thereby appropriately separating the directed graph of the flow data into groups of communications, thereby enabling accurate detection of anomalous communications.
[0052] Furthermore, the above-described embodiment makes it possible to detect, for example, abnormal communications associated with attacks on a network, thereby contributing to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "Develop resilient infrastructure, promote sustainable industrialization and foster innovation."
[0053] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0054] The anomalous communication detection method by the anomalous communication detection device 1 is realized by software. When realized by software, the programs constituting this software are installed in an information processing device (computer). These programs may be recorded on removable media such as CD-ROMs and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a web service via a network without being downloaded. [Explanation of symbols]
[0055] 1. Abnormal communication detection device 10 Control Unit 11 Graph construction section 12 Subgraph Extraction 13 Data appending section 14. Anomaly detection unit 20 Memory section
Claims
1. a graph constructing unit that constructs a directed graph in which flow data having a common source and a common function that performed communication are connected by edges in order of generation, and the flow data is a node; a subgraph extraction unit that extracts a communication order subgraph by comparing a weight of an edge indicating a relationship between nodes in the directed graph with a predetermined threshold; a data addition unit that adds, to the communication order subgraph, a communication content subgraph having, as attribute information, communication content with a host included in the flow data constituting the graph as a node; and an anomaly detection unit that detects anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other.
2. The graph construction unit acquires flow data acquired from a vehicle communication network through which a vehicle and an in-vehicle application server communicate with each other, The anomalous communication detection device according to claim 1 , wherein the anomaly detection unit detects anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other for each type of vehicle or each function of the in-vehicle application.
3. The graph construction unit acquires communication log data transmitted and received between vehicles or between a vehicle and a road as flow data, The anomalous communication detection device according to claim 1 , wherein the anomaly detection unit detects anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other for each type of vehicle or road.
4. 4. The anomalous communication detection device according to claim 1, wherein the subgraph extraction unit extracts the communication order subgraph by setting a time interval between successive flow data in the directed graph as a weight of the edge and deleting edges whose time interval exceeds a predetermined threshold.
5. 4. The anomalous communication detection device according to claim 1, wherein the subgraph extraction unit extracts the communication order subgraph by setting a conditional probability of occurrence of a statistic obtainable from immediately following flow data as a weight of the edge, based on the statistic obtainable from flow data in the directed graph, and deleting edges whose probability does not satisfy a predetermined threshold.
6. a graph construction step of constructing a directed graph in which flow data having a common source and a common function that performed communication are connected in order of generation with edges, and the flow data is used as nodes; a subgraph extraction step of extracting a communication order subgraph by comparing edge weights indicating relationships between nodes in the directed graph with a predetermined threshold; a data addition step of adding, to the communication order subgraph, a communication content subgraph having, as attribute information, communication content with a host included in the flow data constituting the graph as a node; an anomaly detection step of detecting anomalous communication by comparing combinations of the communication order subgraph and the communication content subgraph with each other, the anomaly detection step being executed by a computer.
7. An anomalous communication detection program for causing a computer to function as the anomalous communication detection device according to any one of claims 1 to 5.
Citation Information
Patent Citations
Attack detection and analysis device and attack detection method
JP2019009549A
Network abnormality detection device, network abnormality detection system, and network abnormality detection method
JP2020092332A
Alerting unusual activities in an enterprise production environment
US20220092182A1