Abnormal part identification device, abnormal part identification method, and abnormal part identification program
The abnormality part identification device addresses the challenge of identifying unauthorized access routes in dynamic communication networks by converting communication information into a graph, detecting abnormalities, and generating masking patterns to pinpoint abnormal portions.
Patent Information
- Application Number
- JP2022060173
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-31
- Publication Date
- 2025-05-12
- Estimated Expiration
- 2042-03-31
AI Technical Summary
Existing methods for detecting unauthorized access in large-scale communication networks struggle to quickly identify routes used for unauthorized access, especially in networks where hosts are frequently added or changed.
The proposed solution involves an abnormality part identification device that converts communication information into a graph structure, detects abnormalities, generates a masking pattern to rewrite the graph, and identifies the abnormal portion by applying the masking pattern.
This approach enables quick identification of unauthorized access routes in large-scale communication networks, even with frequent changes in hosts, by efficiently processing flow data and generating effective masking patterns.
Smart Images

Figure 0007675046000001 
Figure 0007675046000002 
Figure 0007675046000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an apparatus, a method, and a program for identifying an unauthorized access route in a network. [Background technology]
[0002] In general, detection of unauthorized access on a network is classified into a method of analyzing packet-based data (packet data) and a method of analyzing flow-based data (flow data). The former captures all packets and detects fraud. While this has a high detection rate, it has issues with the long processing time required to process all packets and the need for complex processing such as encryption. Therefore, a method has been proposed for analyzing network traffic using the latter flow data.
[0003] Flow data includes information such as source and destination IP addresses and port numbers, and communication protocols. Flow data is data that is limited to traffic information, and among this information, communications with the same IP address, for example, are considered to be the same flow, allowing for high-speed processing. In the method of analyzing flow data, this traffic information is analyzed to detect fraud, for example, if there is a sudden increase in access to multiple ports, a brute force attack is suspected.
[0004] There are various types of unauthorized access, some of which can be detected with a single flow data record, and some of which require multiple records. Examples of things that can be detected with a single record include DDoS attacks, which are caused by a sudden increase in access (traffic) to the same IP address and port, and host scans, which are caused by a sudden increase in access (traffic) to the same port. Examples of attacks that require multiple records include a brute force attack in which access to multiple ports and IP addresses increases suddenly, and a port scan in which access to multiple ports increases suddenly.
[0005] When detecting unauthorized access, it is necessary to detect all of these, so it is necessary to support detection of unauthorized access based on both a single record and multiple records. As a method for detecting an anomaly from flow data, for example, Non-Patent Document 1 proposes an unauthorized access detection method using a Recurrent Neural Network (RNN), and Patent Document 1 proposes an unauthorized access detection method using Autoencoders (AE).
[0006] Considering actual operations, it is difficult to take prompt measures by only identifying the presence or absence and type of unauthorized access. Therefore, it is necessary to quickly identify the route used for unauthorized access, such as the IP address used as a springboard and the destination of the attack. In view of this, a method may be considered in which the flow data is represented as a graph and unauthorized access to the entire graph structure or to a part of the graph structure is detected. The following are typical anomaly detection methods for a graph structure:
[0007] Non-Patent Document 2 proposes a method of inputting the graph structure itself into a Graph Neural Network (GNN) and detecting whether or not there is an anomaly in the entire graph. Patent Document 2 proposes a method of extracting a communication history consisting of a pair of a source host identifier and a destination host identifier from traffic data, and extracting features from the communication history graph to determine whether or not there are any abnormalities in the entire graph. Non-Patent Document 3 proposes a method of dividing a large-scale graph into subgraphs based on the generation time of data and detecting anomalies for each subgraph. Non-Patent Document 4 proposes a method for more directly detecting anomalies in graph nodes and edges. [Prior art documents]
Chartered Documents
[0008] [Patent Document 1] Special Publication No. 2019-3274 [Patent Document 2] Special Publication No. 2019-149681
Non-licensed documents
[0009]
Non-patent document 1
Non-patent document 2
Non-patent document 3
Non-patent document 4
[0010] However, while anomaly detection methods that apply to the entire graph structure can detect unauthorized access and have the advantage of being robust to the addition of nodes and edges, it is difficult to identify the route by which the unauthorized access occurred.
[0011] In addition, while methods for detecting unauthorized access to parts of a graph structure can identify more detailed access routes than if the entire graph were targeted, there was a problem in that it was not possible to determine with certainty that a subgraph in which an abnormality was detected was the unauthorized access route, or the route could only be identified in part. Furthermore, in a vehicle network, for example, multiple different vehicles (nodes) are added or changed, and the characteristics of the nodes change frequently. In such a graph structure, conventional methods cannot keep up with the addition or change of nodes and edges, making it difficult to detect anomalies directly from these nodes and edges.
[0012] An object of the present invention is to provide an abnormal part identifying device, an abnormal part identifying method, and an abnormal part identifying program that can quickly identify an unauthorized access path in a large-scale communication network where hosts are frequently added or changed. [Means for solving the problem]
[0013] The abnormality part identification device of the present invention includes a communication information graph conversion unit that extracts communication information including source and destination hosts from communication data and converts it into a communication information graph in which the hosts are nodes and communications between the hosts are edges; an anomaly detection unit that judges the presence or absence of a communication anomaly in the communication information graph and outputs the judgment result; a masking pattern generation unit that generates a masking pattern for rewriting the communication information graph when the judgment result shows that there is an abnormality; and an abnormality part identification unit that identifies a part corresponding to the masking pattern as an abnormal part when the judgment result shows that there is no abnormality when the communication information graph to which the generated masking pattern is applied is input to the anomaly detection unit.
[0014] The communication information graph conversion unit may extract flow data as the communication information and convert it into the communication information graph.
[0015] The anomaly detection unit may output an anomaly judgment score as the judgment result along with the presence or absence of a communication anomaly, and the masking pattern generation unit may generate the masking pattern by prioritizing nodes and edges of the communication information graph whose deletion would reduce the anomaly judgment score.
[0016] The anomaly detection unit may calculate a judgment contribution rate for each node and edge of the communication information graph to the judgment result, and the masking pattern generation unit may generate the masking pattern by prioritizing nodes and edges of the communication information graph that have a high judgment contribution rate that determines the judgment result to be abnormal.
[0017] The abnormal portion identifying unit may input a plurality of communication information graphs to which the masking pattern is applied in parallel to the abnormality detecting unit.
[0018] The communication information graph conversion unit may set an attribute to a node of the communication information graph according to a type of the host.
[0019] The masking pattern generation section may generate the masking pattern by giving priority to a combination of nodes having a predetermined attribute.
[0020] The masking pattern generation unit may generate the masking pattern by giving priority to a pattern that is pre-learned based on known communication anomalies.
[0021] The masking pattern generation unit may receive an input of a candidate node, and generate the masking pattern by giving priority to a node having the same attribute as the candidate node.
[0022] The communication information graph conversion unit may extract the communication information including a vehicle model or an in-vehicle application type from the vehicle communication data, set an attribute indicating the type for a node of the communication information graph, and include a vulnerability information storage unit that stores a vehicle model or an in-vehicle application having a vulnerability, and the masking pattern generation unit may generate the masking pattern by giving priority to a node having an attribute of the vehicle model or in-vehicle application stored in the vulnerability information storage unit.
[0023] The vulnerability information storage unit may store information on attack patterns in association with vehicle models or in-vehicle applications having the vulnerabilities, the anomaly detection unit may determine the attack pattern along with the presence or absence of a communication anomaly, and the masking pattern generation unit may generate the masking pattern by giving priority to nodes having attributes of the vehicle model or in-vehicle application corresponding to the determined attack pattern.
[0024] The abnormal part identifying device may include an unauthorized access blocking unit that blocks access to a corresponding node based on the abnormal part identified by the abnormal part identifying unit.
[0025] The abnormality part identification method of the present invention includes a communication information graph conversion step of extracting communication information including source and destination hosts from communication data, and converting the communication information into a communication information graph in which the hosts are nodes and communications between the hosts are edges; an anomaly detection step of judging the presence or absence of a communication anomaly in the communication information graph and outputting the judgment result; a masking pattern generation step of generating a masking pattern that rewrites the communication information graph when the judgment result of the anomaly detection step for the communication information graph to which the generated masking pattern has been applied is that there is no abnormality, the computer executing the above steps.
[0026] An abnormality portion specifying program according to the present invention is for causing a computer to function as the abnormality portion specifying device. Effect of the Invention
[0027] According to the present invention, unauthorized access routes can be quickly identified in a large-scale communication network where hosts are frequently added or changed. [Brief description of the drawings]
[0028] [Figure 1] FIG. 1 illustrates a vehicle communication network according to an embodiment. [Diagram 2] FIG. 2 is a diagram illustrating a functional configuration of an abnormality portion identifying device according to an embodiment. [Diagram 3] 1A to 1C are diagrams illustrating examples of masking patterns according to an embodiment. [Figure 4] FIG. 13 is a diagram illustrating an example of Attention-Score in an embodiment. [Diagram 5] FIG. 2 is a diagram illustrating an example of a route of unauthorized access to a vehicle communication network in an embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0029] An example of an embodiment of the present invention will now be described. The method for identifying an abnormality in this embodiment takes an approach of detecting whether or not there is unauthorized access to the entire graph structure converted from the communication information of the network, while also detecting anomalies in the nodes and edges by other means to identify the route of unauthorized access. Here, we will take a vehicle communication network as an example of the communication network to be observed, and explain a method of converting the communication information when each vehicle communicates with the in-vehicle application server into a graph structure, detecting unauthorized access, and identifying the location of the unauthorized access.
[0030] In vehicle communication networks to which connected cars are connected, it is expected that a large amount of communication data will flow at high speed from a huge number of vehicles. Therefore, it is necessary to detect fraud using lightweight flow data such as IPFIX, rather than using methods that analyze packet data, which takes a long time to process.
[0031] In a vehicle communication network, when there are vehicles, network servers (eg, load balancers, proxy servers, etc.), and in-vehicle application servers, each of these can be treated as a node in the graph. Generally, flow data contains information such as source and destination IP addresses and port numbers, and communication protocols. In this embodiment, a graph structure is constructed using this information. Here, IP addresses are used as an example, but any information that can identify each host (node), such as a MAC address or vehicle identification number, can be used. Note that by using identification information unique to a vehicle, it is possible to group together data for the same vehicle even if the IP address has been changed.
[0032] FIG. 1 is a diagram illustrating a vehicle communication network in this embodiment. Here, a case is shown in which a vehicle accesses a server on a network by specifying an IP address, and the server on the network accesses an in-vehicle application server by specifying an IP address. Each of the multiple vehicles communicates with the corresponding in-vehicle application server via the vehicle communication network using the in-vehicle application installed in each vehicle. Note that all communication data reaches the vehicle or the in-vehicle application server via a specific point on the vehicle communication network.
[0033] A capture device installed at a specific point on the vehicle communication network captures communications, thereby obtaining all communications on the vehicle communication network, or communications relating to a specific vehicle model or a specific application or function, etc.
[0034] The abnormal part identification device of this embodiment uses flow data such as IPFIX acquired by a capture device to graph the vehicle communication network, with the host vehicle, the network server, and the in-vehicle application server each defined as a node, and communications between the nodes defined as edges.
[0035] FIG. 2 is a diagram showing the functional configuration of the abnormal part identifying device 1 in this embodiment. The abnormal part identifying device 1 is an information processing device including a control unit 10, a storage unit 20, various data input / output devices, communication devices, and the like.
[0036] The control unit 10 is a part that controls the entire abnormal part identifying device 1, and realizes each function in this embodiment by appropriately reading and executing various programs stored in the storage unit 20. The control unit 10 may be a CPU. Specifically, the control unit 10 includes a communication information graph conversion unit 11 , an abnormality detection unit 12 , a masking pattern generation unit 13 , an abnormality portion identification unit 14 , and an unauthorized access blocking unit 15 .
[0037] The storage unit 20 is a storage area for various programs for causing the hardware group to function as the abnormal part identifying device 1, various data, and the like, and may be a ROM, a RAM, a flash memory, a hard disk drive (HDD), or the like. Specifically, the memory unit 20 stores a program (abnormal part identification program) for causing the control unit 10 to execute each function of this embodiment, flow data received as processing targets, graph data, anomaly detection models, various parameters, etc., and also includes a vulnerability information storage unit 21.
[0038] The vulnerability information storage unit 21 stores vehicle types or in-vehicle applications having vulnerabilities as known vulnerability information related to in-vehicle applications and the like. Furthermore, the vulnerability information storage unit 21 may store information on attack patterns in association with vehicle models or in-vehicle applications having vulnerabilities.
[0039] The communication information graph conversion unit 11 extracts flow data from the communication data as communication information including source and destination hosts, and converts the flow data into a communication information graph in which the hosts are nodes and communications between hosts are edges.
[0040] At this time, the communication information graph conversion unit 11 may set attributes to the nodes of the communication information graph according to the type of host, such as a vehicle, a network server, or an in-vehicle application server. Furthermore, the communication information graph conversion unit 11 may extract communication information including the vehicle model or the type of in-vehicle application from the vehicle communication data, and set an attribute indicating this type for a node of the communication information graph.
[0041] The anomaly detection unit 12 determines whether or not there is a communication anomaly in the communication information graph, and outputs the determination result. In this case, the anomaly detection unit 12 may output an anomaly judgment score indicating the possibility of an anomaly as a judgment result instead of or in addition to the presence or absence of a communication anomaly. Furthermore, the anomaly detection unit 12 may calculate and output a judgment contribution rate for each node and edge of the communication information graph to the judgment result. Furthermore, the anomaly detection unit 12 may determine the attack pattern that caused the communication anomaly.
[0042] Here, the anomaly part identification device 1 learns in advance a detection model for detecting a communication anomaly from a graph structure based on known information, and the anomaly detection unit 12 detects a communication anomaly (unauthorized access) using the learned detection model. The detection model may be a GNN or the like used in existing methods, but is not limited thereto, and may be configured, for example, by a method using an Auto-Encoder or a generative model-based method such as GAN. Also, a statistically-based detection method may be used instead of a deep learning-based method.
[0043] The masking pattern generating unit 13 generates a masking pattern for rewriting the communication information graph when the determination result by the abnormality detecting unit 12 indicates the presence of an abnormality. Specifically, the masking pattern generation unit 13 generates a masking pattern by prioritizing, among the nodes and edges of the communication information graph, those whose deletion would lower the anomaly judgment score or those whose deletion would have a high judgment contribution rate that results in an anomaly.
[0044] At this time, the masking pattern generation unit 13 may generate a masking pattern by giving priority to a combination of nodes with predetermined attributes, or by accepting input of a candidate node and giving priority to a node having the same attribute as this candidate node. Furthermore, the masking pattern generating unit 13 may generate a masking pattern by giving priority to a pattern that has been pre-learned based on known communication anomalies.
[0045] Furthermore, the masking pattern generation unit 13 may generate a masking pattern by prioritizing nodes having attributes of a vehicle model or in-vehicle application stored in the vulnerability information storage unit, or by prioritizing nodes having attributes of a vehicle model or in-vehicle application corresponding to the attack pattern determined by the anomaly detection unit 12.
[0046] When the communication information graph to which the generated masking pattern has been applied is input to the anomaly detection unit 12 and the judgment result is that there is no anomaly, the abnormality area identification unit 14 identifies the area corresponding to the masking pattern as the abnormal area. At this time, the abnormal part specifying unit 14 may input a plurality of communication information graphs to which the masking pattern has been applied in parallel to the abnormality detecting unit 12, and perform parallel processing to increase the speed.
[0047] In this way, when a communication abnormality (unauthorized access) is detected in the network, the abnormal part identification unit 14 masks a specific node or edge using the masking pattern generated by the masking pattern generation unit 13, and then performs unauthorized access detection again. If no abnormality is detected as a result of the masking, it is assumed that unauthorized access has been made to the masked area, that is, this area is the route of unauthorized access.
[0048] The unauthorized access detection result may be a binary classification of whether or not a communication abnormality is detected, but may also be output as an abnormality determination score as described above. In this case, the abnormal part identifying unit 14 may, for example, set a threshold value in advance and identify a masking region when the decrease in the abnormality determination score exceeds the threshold value as an unauthorized access route.
[0049] The unauthorized access blocking unit 15 blocks access to the corresponding node based on the abnormal portion identified by the abnormal portion identifying unit 14. In general IT services, in order to prioritize service availability, IDS (Intrusion Detection System) is often used, which only detects unauthorized access. However, in cases such as connected cars, where unauthorized access could cause a serious incident in the real world (property damage, personal injury, etc.), it is desirable to use an IPS (Intrusion Prevention System) to detect unauthorized access and then cut off communications.
[0050] Here, a method for generating a masking pattern by the masking pattern generating unit 13 will be described in detail. (1) Random masking pattern generation: The abnormal part identifying unit 14 disconnects the edge connection selected at random, or rewrites the feature amount held by the node to 0 or an average value, etc., and inputs it to the abnormality detecting unit 12. Also, instead of masking a single node or edge, a masking pattern combining multiple nodes and edges may be generated.
[0051] FIG. 3 is a diagram illustrating an example of a masking pattern in this embodiment. For example, suppose that a communication anomaly is detected by inputting a graph representing a vehicle communication network in which vehicles A and C communicate with servers B and D, respectively, into the GNN. Multiple masking patterns are applied to this graph, for example, masking node B, masking nodes A and D and the edges between them, and masking nodes C and D and the edges between them, and the changes in the GNN's judgment results for each are observed.
[0052] However, preparing all masking patterns and detecting unauthorized accesses would require a huge amount of calculations. Therefore, it is possible to process multiple masking patterns in parallel or to prioritize the generation of masking patterns that are more likely to be routes for unauthorized accesses, as in the following method.
[0053] (2)Generating masking patterns using attention: When a Graph-Attention model (for example, see the following document A) is used in learning the anomaly detection model, the anomaly detection unit 12 can obtain an Attention-Score as a judgment result. This Attention-Score is an index that indicates the degree of attention from node to node, and can calculate the degree of influence on the judgment result (contribution rate of judgment). Document A: P. Velickovic et al., "Graph attention networks," arXiv preprint arXiv:1710.10903 (2017).
[0054] FIG. 4 is a diagram illustrating an example of the Attention-Score in this embodiment. The anomaly detection unit 12 constructs a GNN (GAT) with an attention mechanism for anomaly detection, and calculates the Attention-Score (α AC ,α AD ,α BD ,α BC After that, the target nodes and edges are masked in descending order of value, or when the Attention-Score exceeds a certain value, and a masking pattern that is likely to be a route for unauthorized access is generated.
[0055] (3)Generating masking patterns using changes in anomaly judgment scores: The masking pattern generation unit 13 can also observe changes in the anomaly determination score obtained from the anomaly detection model and efficiently generate masking patterns. For example, if the anomaly determination score decreases (tends toward no anomaly) when a specific node A is masked, the masking pattern generation unit 13 generates a masking pattern to always mask node A. The masking pattern generation unit 13 repeats this process and, when the anomaly determination score decreases, masks the masked node in a fixed manner, thereby efficiently generating a masking pattern.
[0056] (4)Generating masking patterns taking into account the characteristics of vehicular communication networks: The vehicle communication network is made up of multiple types of hosts, such as vehicles, network servers, and in-vehicle application servers. The communication information graph conversion unit 11 does not treat these as nodes of the same type, but sets them as nodes of different types and generates a graph.
[0057] A graph that has multiple types of nodes, rather than a single type of node, is called a Heterogeneous Graph (see, for example, the following document B). Unauthorized access to vehicle communication networks is not an indiscriminate attack that targets all multiple types of nodes, but is considered to be an attack that is biased toward a specific type of node. For example, an attack on a vulnerable vehicle will result in increased access to vehicle nodes, as shown in the following diagram. Literature B: X. Wang et al., "Heterogeneous graph attention network," The World Wide Web Conference. 2019.
[0058] FIG. 5 is a diagram illustrating an example of a route of unauthorized access to the vehicle communication network in this embodiment. In this example, an attack (unauthorized access) is being carried out from vehicle A via server B in the network to vehicles C and D.
[0059] In this case, since the in-vehicle application server is not included in the unauthorized access path, even when generating a masking pattern for the purpose of identifying the unauthorized access path, the masking pattern generation unit 13 efficiently generates a masking pattern by biasing masking to a specific type of node.
[0060] For example, when the masking pattern generation unit 13 randomly generates a masking pattern, it sets a high probability that a specific type of node will be masked. The specific type of node may be determined by learning the ratio of nodes used in unauthorized access from attack patterns collected in advance. Alternatively, in generating a masking pattern using the changes in the abnormality judgment score or Attention-Score described above, if there is a node whose abnormality judgment score has decreased or whose Attention-Score is high, a node of the same type may be preferentially selected.
[0061] (5)Generating masking patterns based on vehicle model and in-vehicle application type: In automotive applications, authentication is usually performed when communication starts, and this authentication allows the vehicle model to be identified. Since an IP address is assigned to the vehicle during communication, it is possible to link the vehicle model with the IP address.
[0062] Here, the in-vehicle software (software that runs on the vehicle's hardware, such as the in-vehicle OS and in-vehicle applications) is not necessarily the same for all vehicle models, with different versions depending on the vehicle model. Therefore, security vulnerabilities may occur in specific parts depending on the vehicle model. When a security vulnerability occurs, there is a high possibility that unauthorized access will be focused on this vehicle model. Therefore, the masking pattern generation unit 13 preferentially masks the nodes corresponding to the vehicle model or in-vehicle application in which a security vulnerability has occurred.
[0063] Specifically, the abnormal part identification device 1 stores a list of vulnerable vehicles, the vulnerability types of those vehicles, and attack patterns against the vulnerabilities in the vulnerability information storage unit 21, and creates a communication information graph by the communication information graph conversion unit 11 that includes vehicle type information in the node attributes. When an attack pattern can be identified using the anomaly detection model, such as a tendency for a particular vehicle model to have a high Attention-Score, if the identified attack pattern is one listed, the masking pattern generation unit 13 will preferentially mask the corresponding vehicle model.
[0064] According to this embodiment, the abnormal part identification device 1 converts communication information into a communication information graph in which hosts are nodes and communications between hosts are edges, and judges the presence or absence of a communication abnormality for this graph. Furthermore, when the judgment result shows that there is an abnormality, the abnormal part identification device 1 identifies, as the abnormal part, a part corresponding to the masking pattern when the judgment result of the communication information graph to which the masking pattern is applied shows that there is no abnormality. Therefore, the abnormal part identifying device 1 can use the abnormality detection unit 12 to take an approach of detecting unauthorized access to the entire graph structure, while the abnormal part identifying unit 14 can identify an abnormal part of a node or edge. As a result, the abnormal part identifying device 1 can quickly identify an unauthorized access route in a large-scale communication network where hosts are frequently added or changed.
[0065] The abnormal part identifying device 1 extracts flow data as communication information and converts it into a communication information graph, so that it can identify an abnormal part more efficiently than by processing a huge amount of packet data.
[0066] The abnormal part identification device 1 can efficiently identify the abnormal part by generating a masking pattern by prioritizing, among the nodes and edges of the communication information graph, those whose deletion will lower the abnormality judgment score, or those whose judgment contribution rate is high in determining that there is an abnormality.
[0067] The abnormal part identifying device 1 can quickly identify an abnormal part by inputting a plurality of communication information graphs to which a masking pattern has been applied in parallel to the abnormality detection unit 12 and processing them in parallel.
[0068] The abnormal part identifying device 1 can express the characteristics of each node by setting attributes to the nodes of the communication information graph according to the type of host, and therefore can accurately detect an abnormality and identify the abnormal part. Furthermore, the abnormal part identification device 1 may generate a masking pattern by giving priority to a combination of nodes with predetermined attributes, giving priority to a pattern pre-learned based on known communication anomalies, or receiving an input of a candidate node and giving priority to a node having the same attribute as the candidate node. This enables the abnormal part identification device 1 to efficiently narrow down and identify the abnormal part.
[0069] The abnormal part identification device 1 may generate a masking pattern by prioritizing nodes having attributes of vehicle models or in-vehicle applications with vulnerabilities in the vehicle communication network, or by prioritizing nodes having attributes of vehicle models or in-vehicle applications corresponding to the determined attack pattern. This allows the abnormal part identification device 1 to efficiently narrow down and identify abnormal parts by prioritizing nodes with a high probability of unauthorized access.
[0070] The abnormal part identifying device 1 blocks access to the corresponding node based on the identified abnormal part by using the IPS. To apply IPS, it is preferable to narrow the scope of communication blocking as much as possible, so it is necessary to accurately identify the unauthorized access route. When a communication abnormality (unauthorized access) occurs, the abnormal part identification device 1 can quickly identify the unauthorized access route, so it can appropriately isolate only the parts that need attention while minimizing the performance degradation of the entire network.
[0071] In addition, the above-mentioned embodiment makes it possible to identify unauthorized access routes in a network, for example, and therefore contribute to Goal 9 of the United Nations-led Sustainable Development Goals (SDGs), which is to "build resilient infrastructure, promote sustainable industrialization and foster innovation."
[0072] Although the embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments. Furthermore, the effects described in the above-described embodiments are merely a list of the most preferable effects resulting from the present invention, and the effects of the present invention are not limited to those described in the embodiments.
[0073] In the above embodiment, a vehicle communication network is used as an example, but the target of communication anomaly detection is not limited to this. This embodiment can be applied to various communication data, such as IoT communication data from sensors, or communication data obtained from base stations in a mobile communication network.
[0074] The abnormal part identifying method by the abnormal part identifying device 1 is realized by software. When realized by software, a program constituting this software is installed in an information processing device (computer). Moreover, these programs may be recorded on a removable medium such as a CD-ROM and distributed to users, or may be distributed by being downloaded to the user's computer via a network. Furthermore, these programs may be provided to the user's computer as a Web service via a network without being downloaded. [Explanation of symbols]
[0075] 1 Abnormal part identification device 10 Control section 11 Communication information graph conversion unit 12 Anomaly detection section 13 Masking pattern generator 14 Abnormal part identification part 15 Unauthorized Access Blocking Section 20 Memory section 21 Vulnerability information storage section
Claims
1. a communication information graph conversion unit that extracts communication information including a source host and a destination host from the communication data and converts the extracted communication information into a communication information graph in which the hosts are nodes and communications between the hosts are edges; an anomaly detection unit that determines whether or not a communication anomaly exists in the communication information graph and outputs a determination result; a masking pattern generating unit that generates a masking pattern for rewriting the communication information graph when the determination result indicates that an abnormality exists; and an abnormality part identifying unit that, when a communication information graph to which the generated masking pattern has been applied is input to the anomaly detection unit and a determination result shows that there is no abnormality, identifies a part corresponding to the masking pattern as an abnormal part.
2. 2. The abnormal part identifying device according to claim 1, wherein the communication information graph conversion unit extracts flow data as the communication information and converts it into the communication information graph.
3. The anomaly detection unit outputs an anomaly determination score as the determination result together with the presence or absence of a communication anomaly, 3. The abnormality part identification device according to claim 1, wherein the masking pattern generation unit generates the masking pattern by giving priority to nodes and edges of the communication information graph whose deletion would result in a decrease in the abnormality determination score.
4. The anomaly detection unit calculates a determination contribution rate for each node and edge of the communication information graph with respect to the determination result, 4. The abnormality part identification device according to claim 1, wherein the masking pattern generation unit generates the masking pattern by giving priority to nodes and edges of the communication information graph that have a high judgment contribution rate that determines that there is an abnormality in the judgment result.
5. 5. The abnormality part identifying device according to claim 1, wherein the abnormality part identifying unit inputs a plurality of communication information graphs to which the masking pattern is applied in parallel to the abnormality detection unit.
6. 6. The abnormal part identifying device according to claim 1, wherein the communication information graph conversion unit sets attributes to nodes of the communication information graph according to the type of the host.
7. 7. The abnormal part identifying device according to claim 6, wherein the masking pattern generating section generates the masking pattern by giving priority to a combination of nodes having a predetermined attribute.
8. 8. The abnormality portion identifying device according to claim 6, wherein the masking pattern generating unit generates the masking pattern by giving priority to a pattern that has been learned in advance based on a known communication abnormality.
9. 9. The abnormal part identifying device according to claim 6, wherein the masking pattern generating unit receives an input of a candidate node, and generates the masking pattern by giving priority to a node having the same attribute as the candidate node.
10. the communication information graph conversion unit extracts the communication information including a vehicle model or a type of in-vehicle application from the vehicle communication data, and sets an attribute indicating the type for a node of the communication information graph; A vulnerability information storage unit stores vehicle models or in-vehicle applications having vulnerabilities, 10. The abnormal part identification device according to claim 1, wherein the masking pattern generation unit generates the masking pattern by giving priority to a node having an attribute of a vehicle model or an in-vehicle application stored in the vulnerability information storage unit.
11. The vulnerability information storage unit stores information on attack patterns in association with vehicle models or in-vehicle applications having the vulnerabilities, The anomaly detection unit determines the attack pattern along with the presence or absence of a communication anomaly, 11. The abnormal part identification device according to claim 10, wherein the masking pattern generation unit generates the masking pattern by giving priority to a node having an attribute of a vehicle type or an in-vehicle application corresponding to the determined attack pattern.
12. 12. The abnormal part identifying device according to claim 1, further comprising an unauthorized access blocking unit that blocks access to a corresponding node based on the abnormal part identified by the abnormal part identifying unit.
13. a communication information graph conversion step of extracting communication information including a source and destination host from the communication data and converting the extracted communication information into a communication information graph in which the hosts are nodes and communications between the hosts are edges; an anomaly detection step of determining whether or not a communication anomaly exists in the communication information graph and outputting a determination result; a masking pattern generating step of generating a masking pattern for rewriting the communication information graph when the determination result indicates that an abnormality exists; and an abnormality part identification step of identifying a part corresponding to the generated masking pattern as an abnormal part when the judgment result of the anomaly detection step for the communication information graph to which the masking pattern has been applied is no abnormality, the abnormality part identification step being executed by a computer.
14. An abnormality portion identifying program for causing a computer to function as the abnormality portion identifying device according to any one of claims 1 to 12.
Citation Information
Patent Citations
Method of anomaly alignment across plurality of attribute networks
CN112422571A
Network analysis support device and method, program, and recording medium
JP2008052524A
Program, device and method for specifying abnormal portion
JP2011004034A
Detection system, detection method and detection program
JP2019003274A
Traffic abnormality sensing device, traffic abnormality sensing method, and traffic abnormality sensing program
JP2019149681A