Surveillance system

The monitoring system with multiple authority units addresses the challenge of determining the overall state of virtualization systems by accurately detecting and responding to abnormalities, enhancing system reliability.

JP7702476B2Active Publication Date: 2025-07-03PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023503377
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-03-01
Filing Date
2021-11-18
Publication Date
2025-07-03
Estimated Expiration
2041-11-18

AI Technical Summary

Technical Problem

Existing virtualization systems lack the ability to determine the overall state of the system when an abnormality is detected in a virtual machine (VM), which can lead to broader system failures, particularly in devices like vehicles equipped with virtualization systems.

Method used

A monitoring system with multiple monitoring units of varying authority monitors the virtualization system, including VM monitoring units, request monitoring units, and optionally HV monitoring units, to detect abnormalities and a determination unit that determines the system's state based on their combined results.

Benefits of technology

Enables accurate determination of the entire virtualization system's state, improving detection accuracy and preventing false positives or negatives, allowing for targeted responses to maintain system integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007702476000001
    Figure 0007702476000001
  • Figure 0007702476000002
    Figure 0007702476000002
  • Figure 0007702476000003
    Figure 0007702476000003
Patent Text Reader

Abstract

A monitoring system (1) serves to monitor a virtualized system, and comprises a VM monitoring unit (21) and a request monitoring unit (32) each having a different right, which monitor the virtualized system and detect an abnormality thereof, and a determination unit (35) that determines the state of the virtualized system on the basis of the result of monitoring by the VM monitoring unit (21) and the request monitoring unit (32).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a monitoring system for monitoring a virtualization system.

Background Art

[0002] Conventionally, in a virtualization system virtualized by a hypervisor (HV) or the like, each of a plurality of functions can be realized by a virtual machine (VM) on one chip. However, since there is no physical barrier between VMs, if the virtualization system is attacked by an attacker, the impact of the attack may spread widely.

[0003] In contrast, techniques such as a technique for stopping a VM (for example, Patent Document 1) and a technique for blocking communication of a VM (for example, Patent Document 2) are disclosed when an abnormality of the VM is detected.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the techniques disclosed in Patent Documents 1 and 2 above, when an abnormality of a VM is detected, only the abnormality of that VM is focused on, and the state of the entire virtualization system is not determined. In this case, it may cause a problem in the function of the entire virtualization system, and thus the function of a device (such as a vehicle) equipped with the virtualization system.

[0006] Therefore, the present disclosure provides a monitoring system capable of determining the state of the entire virtualization system.

Means for Solving the Problems

[0007] A monitoring system according to one aspect of the present disclosure is a monitoring system that monitors a virtualization system, and includes a plurality of monitoring units with different authorities that monitor the virtualization system to detect abnormalities, and a determination unit that determines the state of the virtualization system based on the monitoring results of the plurality of monitoring units.

Effect of the Invention

[0008] According to the monitoring system according to one aspect of the present disclosure, the state of the entire virtualization system can be determined.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2A

Figure 2B

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7A

Figure 7B

Figure 8

Figure 9

Figure 10

Embodiments for Carrying Out the Invention

[0010] (Embodiment 1) Hereinafter, the monitoring system in Embodiment 1 will be described with reference to the drawings.

[0011] FIG. 1 is a configuration diagram showing an example of the monitoring system 1 in Embodiment 1.

[0012] The monitoring system 1 is a system that monitors a virtualization system and includes an HV 10, a VM 20, and a security VM 30. The virtualization system is a virtualized system and is a system having a plurality of virtual environments managed by a virtualization infrastructure. Here, the HV 10 is shown as the virtualization infrastructure, and the VM 20 and the security VM 30 are shown as the plurality of virtual environments. Note that the virtualization system includes, for example, a plurality of VMs 20, but here, one VM 20 out of the plurality of VMs 20 will be described. For example, when the virtualization system is mounted on a vehicle, the VM 20 can operate as an ECU (Electronic Control Unit).

[0013] The monitoring system 1 includes a processor and a memory. The memory is a ROM (Read Only Memory), a RAM (Random Access Memory), etc., and can store programs executed by the processor. The HV 10, the VM 20, and the security VM 30 are realized by a processor or the like that executes programs stored in the memory.

[0014] HV10 is a functional component for realizing a VM, and manages VM20 and security VM30. HV10 is also called a virtualization monitor or a virtualization OS. HV10 includes a request execution unit 11, a request transfer unit 12, and a virtual communication unit 13.

[0015] The request execution unit 11 acquires a request from VM20 (for example, a communication request or a hypercall, etc.) and executes the request. The communication request includes information for specifying a communication partner, etc. The hypercall includes information indicating the content of the process to be executed by HV10, etc.

[0016] The request transfer unit 12 transfers the acquired request from VM20 to the security VM30.

[0017] The virtual communication unit 13 communicates with VM20, the security VM30, etc. The virtual communication unit 13 transfers, for example, the monitoring result of the VM monitoring unit 21 described later to the security VM30.

[0018] VM20 is a VM managed by HV10. The operation of a computer can be reproduced by VM20, and by managing a plurality of VM20 by HV10, a plurality of independent functions can be realized on one computer. For example, a plurality of ECUs can be operated on one computer. VM20 includes a VM monitoring unit 21, a request generation unit 22, and an application 23.

[0019] The VM monitoring unit 21 monitors VM20 in the virtualization system. Specifically, the VM monitoring unit 21 monitors the operation of the application 23 in VM20, more specifically, access control violations or system call abnormalities, etc. The VM monitoring unit 21 notifies the monitoring result to HV10. The VM monitoring unit 21 is an example of a virtual environment monitoring unit that monitors the virtual environment in the virtualization system, and is one of a plurality of monitoring units with different authorities that monitor the virtualization system and detect abnormalities.

[0020] The request generation unit 22 generates a request to the HV 10 according to the operation of the application 23. For example, when the application 23 communicates with another VM 20 or an external device, the request generation unit 22 generates a request for communication with the other VM 20 or an external device. For example, when the application 23 causes the HV 10 to execute a predetermined process, the request generation unit 22 generates a hypercall including the content of the predetermined process. The request generation unit 22 notifies the generated request to the HV 10.

[0021] The application 23 executes an application program implemented by the VM 20. For example, when the VM 20 operates as an ECU, the application 23 executes an application program corresponding to the ECU. Note that one VM 20 may include a plurality of applications 23. That is, a plurality of application programs may be executed in one VM 20.

[0022] The security VM 30 is a VM that performs security-related processing of the virtualization system. For example, the security VM 30 is accessible to the VM 20 but is not accessible from the VM 20, and is less likely to be attacked than the VM 20. Therefore, functions related to security are implemented in the security VM 30. The security VM 30 includes a request reception unit 31, a request monitoring unit 32, a communication reception unit 33, a VM monitoring information reception unit 34, a determination unit 35, and a response unit 36.

[0023] The request reception unit 31 receives a request from the VM 20 to the HV 10 transferred from the HV 10.

[0024] The request monitoring unit 32 monitors requests from the VM 20 to the HV 10 in the virtualization system. Specifically, the request monitoring unit 32 monitors the content of the requests to the HV 10 or the frequency of requests to the HV 10 (i.e., the frequency at which the request receiving unit 31 receives requests to the HV 10). The request monitoring unit 32 notifies the determination unit 35 of the monitoring results. The request monitoring unit 32 is an example of a request monitoring unit that monitors requests from the virtual environment to the virtualization infrastructure in the virtualization system, and is one of a plurality of monitoring units with different authorities that monitor the virtualization system and detect abnormalities. As described above, the security VM 30 is accessible from the VM 20 but not accessible from the VM 20, and the security VM 30 and the VM 20 have different authorities. Therefore, the request monitoring unit 32 provided in the security VM 30 and the VM monitoring unit 21 provided in the VM 20 have different authorities respectively.

[0025] The communication receiving unit 33 receives the information transferred from the HV 10. Among the information transferred from the HV 10, the communication receiving unit 33 notifies the VM monitoring information receiving unit 34 of the monitoring results of the VM monitoring unit 21.

[0026] The VM monitoring information receiving unit 34 receives the monitoring results of the VM monitoring unit 21. The VM monitoring information receiving unit 34 notifies the determination unit 35 of the monitoring results of the VM monitoring unit 21.

[0027] The determination unit 35 determines the state of the virtualization system based on the monitoring results of the plurality of monitoring units. In Embodiment 1, the determination unit 35 determines the state of the virtualization system based on the monitoring results of the VM monitoring unit 21 and the request monitoring unit 32 as the monitoring results of the plurality of monitoring units. For example, the determination unit 35 determines the state of the virtualization system according to the combination of the monitoring results of the plurality of monitoring units. The determination unit 35 outputs the determined state of the virtualization system. For example, the determination unit 35 notifies the corresponding unit 36 of the determined state of the virtualization system. Note that the determination unit 35 may output the determined state of the virtualization system to a computer or a mobile terminal owned by a user who uses the device on which the virtualization system is installed, or may output it to a server or the like.

[0028] The corresponding unit 36 performs corresponding actions according to the determined state of the virtualization system. Details of the corresponding actions will be described later.

[0029] Next, an example of the monitoring results of a plurality of monitoring units and the operation of the determination unit 35 will be described with reference to FIG. 2A.

[0030] FIG. 2A is a diagram showing an example of the monitoring results of a plurality of monitoring units in the first embodiment. In the first embodiment, the monitoring results of the VM monitoring unit 21 and the request monitoring unit 32 are shown as the plurality of monitoring units.

[0031] As shown in FIG. 2A, assume that at 13:01:03, the monitoring result of the VM monitoring unit 21 was normal. Also, although not shown, assume that the monitoring result of the request monitoring unit 32 was also normal. For example, the determination unit 35 determines that the state of the virtualization system is normal according to the combination that the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is normal.

[0032] Next, assume that at 13:01:10, the monitoring result of the request monitoring unit 32 becomes abnormal. For example, the determination unit 35 determines that the state of the virtualization system is such that the request from VM20 is abnormal and there is a possibility that VM20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is abnormal.

[0033] Next, assume that at 13:01:13, the monitoring result of the VM monitoring unit 21 becomes abnormal. For example, the determination unit 35 determines that the state of the virtualization system is such that VM20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 is abnormal.

[0034] Next, assume that at 13:01:15, the monitoring result of the request monitoring unit 32 remains abnormal. For example, the determination unit 35 determines that the state of the virtualization system is such that VM20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 is abnormal.

[0035] Next, the operation of the corresponding unit 36 will be described with reference to FIG. 2B.

[0036] FIG. 2B is a diagram showing an example of the correspondence of the corresponding unit 36 in the first embodiment.

[0037] For example, when the virtualization system is determined to be in a normal state according to a combination where the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is normal, the corresponding unit 36 does not perform any specific correspondence.

[0038] For example, when the virtualization system is determined to be in a state where VM20 is abnormal and there is a possibility that the request from VM20 is abnormal according to a combination where the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 is normal, the corresponding unit 36 stops VM20 or strengthens the monitoring of the request monitoring unit 32 (specifically, shortens the monitoring period of the request monitoring unit 32 or adjusts the threshold value when the request monitoring unit 32 detects an abnormality).

[0039] For example, when the virtualization system is determined to be in a state where the request from VM20 (for example, a request for inter-VM communication) is abnormal and there is a possibility that VM20 is abnormal according to a combination where the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is abnormal, the corresponding unit 36 cuts off the inter-VM communication or strengthens the monitoring of the VM monitoring unit 21 (specifically, shortens the monitoring period of the VM monitoring unit 21 or adjusts the threshold value when the VM monitoring unit 21 detects an abnormality).

[0040] For example, when the virtualization system is determined to be in a state where VM20 is abnormal according to a combination where the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 is abnormal, the corresponding unit 36 restarts VM20.

[0041] Note that the determination unit 35 may determine the state of the virtualization system according to the combination of detailed information on the abnormalities detected by the plurality of monitoring units as a combination of the monitoring results of the plurality of monitoring units. The detailed information on the abnormality may be, for example, the application in which the abnormality occurred, VM20, the communication channel, or the memory address, etc., or may be the type of abnormality (for example, access control violation or abnormal communication frequency, etc.), or may be numerical information such as the degree of abnormality calculated by machine learning or the like. For example, the determination result of the state of the virtualization system may be different between the combination where the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is an abnormality in inter-VM communication, and the combination where the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is an abnormality in hypercall.

[0042] Next, the operation of the monitoring system 1 will be described with a specific example.

[0043] First, the operation of the monitoring system 1 when the VM monitoring unit 21 detects an abnormality in VM20 will be described with reference to FIG. 3.

[0044] FIG. 3 is a sequence diagram showing an example of the operation of the monitoring system 1 when the VM monitoring unit 21 detects an abnormality in VM20 in the first embodiment.

[0045] The VM monitoring unit 21 monitors VM20, detects an abnormality in VM20 (step S11), and notifies the determination unit 35 of the monitoring result indicating the abnormality (step S12). Although not shown, it is assumed that the determination unit 35 has acquired a monitoring result indicating normality from the request monitoring unit 32.

[0046] The determination unit 35 determines the state of the virtualization system (step S13). For example, according to the combination where the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 is normal, it is determined that the state of the virtualization system is such that VM20 is abnormal and there is a possibility that the request from VM20 is abnormal.

[0047] The corresponding unit 36 performs corresponding actions according to the determined state of the virtualization system (step S14). For example, the corresponding unit 36 strengthens the monitoring of the request monitoring unit 32 as a corresponding action according to the state where there may be an abnormality in the request from the VM 20. At this time, an ID for identifying the VM 20 in which an abnormality has been detected is notified to the request monitoring unit 32. This is to strengthen the monitoring of requests from the VM 20 in which an abnormality has been detected for the request monitoring unit 32.

[0048] The request monitoring unit 32 monitors the requests from the VM 20 and confirms that they are normal (step S15), and notifies the determination unit 35 of the monitoring result indicating normality (step S16).

[0049] The determination unit 35 determines the state of the virtualization system (step S17). For example, according to the combination where the monitoring result of the VM monitoring unit 21 is abnormal and the monitoring result of the request monitoring unit 32 after the monitoring is strengthened is normal, it is determined that the state of the virtualization system is a state where the VM 20 is abnormal and the requests from the VM 20 are normal. Note that the determination unit 35 may determine the state of the virtualization system as numerical information such as the degree of abnormality by machine learning or the like based on the monitoring results of the VM monitoring unit 21 and the request monitoring unit 32.

[0050] The corresponding unit 36 performs corresponding actions according to the determined state of the virtualization system (step S18). For example, as corresponding actions according to the state where VM20 is abnormal, the corresponding unit 36 determines whether it can identify the abnormal application 23 in VM20, and if it can identify the abnormal application 23, stops the abnormal application 23. If the corresponding unit 36 cannot identify the abnormal application 23, it restarts VM20. After the abnormal application 23 stops, or after VM20 restarts, if the monitoring result of the VM monitoring unit 21 returns to normal, the corresponding unit 36 ends the strengthening of the monitoring of requests from the VM20 that has returned to normal. On the other hand, if the monitoring result of the VM monitoring unit 21 remains abnormal, the corresponding unit 36 stops VM20. Note that when the state of the virtualization system is determined by numerical information such as the degree of abnormality, the corresponding unit 36 may perform corresponding actions according to the degree of abnormality. For example, the corresponding unit 36 may stop the application 23 when the degree of abnormality is low, and stop VM20 when the degree of abnormality is high.

[0051] Next, the operation of the monitoring system when the request monitoring unit 32 detects an abnormality in VM-to-VM communication will be described with reference to FIGS. 4 and 5.

[0052] FIG. 4 is a sequence diagram showing an example of the operation of the monitoring system 1 when the request monitoring unit 32 detects an abnormality in VM-to-VM communication in the first embodiment.

[0053] The request monitoring unit 32 monitors requests from VM20 and detects an abnormality in VM-to-VM communication (for example, an abnormality in the communication destination of the monitored VM20 or an abnormality in the frequency of communication requests from the monitored VM20, etc.) (step S21), and notifies the determination unit 35 of the monitoring result indicating the abnormality (step S22). Although not shown, it is assumed that the determination unit 35 has obtained a monitoring result indicating normality from the VM monitoring unit 21.

[0054] The determination unit 35 determines the state of the virtualization system (step S23). For example, according to the combination where the monitoring result of the VM monitoring unit 21 is normal and the monitoring result of the request monitoring unit 32 is an abnormality in inter-VM communication, it is determined that the state of the virtualization system is a state where inter-VM communication is abnormal and VM 20 may be abnormal.

[0055] The corresponding unit 36 takes corresponding actions according to the determined state of the virtualization system (step S24). For example, as a corresponding action according to the state where VM 20 may be abnormal, the corresponding unit 36 strengthens the monitoring of the VM monitoring unit 21.

[0056] The VM monitoring unit 21 monitors VM 20 and confirms that it is abnormal (step S25), and notifies the determination unit 35 of the monitoring result indicating abnormality (step S26).

[0057] The determination unit 35 determines the state of the virtualization system (step S27). For example, according to the combination where the monitoring result of the VM monitoring unit 21 after enhanced monitoring is abnormal and the monitoring result of the request monitoring unit 32 is an abnormality in inter-VM communication, it is determined that the state of the virtualization system is a state where VM 20 is abnormal.

[0058] The corresponding unit 36 takes corresponding actions according to the determined state of the virtualization system (step S28). Since the processing in step S28 is the same as that in step S18, the description is omitted.

[0059] FIG. 5 is a sequence diagram showing another example of the operation of the monitoring system 1 when the request monitoring unit 32 detects an abnormality in inter-VM communication in the first embodiment. Since the processing from step S31 to step S34 in FIG. 5 is the same as the processing from step S21 to step S24 in FIG. 4, the description is omitted.

[0060] The VM monitoring unit 21 monitors VM 20 and confirms that it is normal (step S35), and notifies the determination unit 35 of the monitoring result indicating normality (step S36).

[0061] The determination unit 35 determines the state of the virtualization system (step S37). For example, according to the combination that the monitoring result of the VM monitoring unit 21 after enhanced monitoring is normal and the monitoring result of the request monitoring unit 32 is an abnormality in inter-VM communication, it is determined that the state of the virtualization system is a state in which inter-VM communication is abnormal.

[0062] The corresponding unit 36 performs corresponding actions according to the determined state of the virtualization system (step S38). For example, as a corresponding action according to the state in which inter-VM communication is abnormal, the corresponding unit 36 cuts off the communication channel in which the abnormality is detected. Since the monitoring result of the VM monitoring unit 21 is normal, there is a possibility that the abnormality in inter-VM communication is a false detection. Therefore, the corresponding unit 36 may cut off the communication channel in which the abnormality is detected when the same abnormality as this time has occurred in the past. In other words, the corresponding unit 36 does not have to cut off the communication channel in which the abnormality is detected when the same abnormality as this time has not occurred in the past, and may cut off the communication channel in which the abnormality is detected when the same abnormality occurs in the future. Alternatively, the corresponding unit 36 may cut off the communication channel in which the abnormality is detected when the abnormality in inter-VM communication continues for a certain period of time or more.

[0063] (Embodiment 2) Hereinafter, the monitoring system in Embodiment 2 will be described with reference to the drawings.

[0064] FIG. 6 is a configuration diagram showing an example of the monitoring system 1a in Embodiment 2.

[0065] The monitoring system 1a is different from the monitoring system 1 in Embodiment 1 in that it includes HV10a instead of HV10, includes security VM 30a instead of security VM 30, and further includes secure OS 40. Since other points are the same as those in Embodiment 1, detailed descriptions are omitted or simplified.

[0066] The monitoring system 1a is a system that monitors a virtualization system and includes an HV10a, a VM20, a security VM30a, and a secure OS40. A virtualization system is a virtualized system that has a plurality of virtual environments managed by a virtualization infrastructure. Here, the HV10a is shown as the virtualization infrastructure, and the VM20 and the security VM30a are shown as the plurality of virtual environments.

[0067] The monitoring system 1a includes a processor, a memory, etc. The memory is such as a ROM and a RAM and can store programs executed by the processor. The HV10a, the VM20, the security VM30a, and the secure OS40 are realized by a processor or the like that executes programs stored in the memory.

[0068] The HV10a is a functional component for realizing a VM and manages the VM20 and the security VM30a. The HV10a is also called a virtualization monitor or a virtualization OS. The HV10a includes a request execution unit 11, a request transfer unit 12, a virtual communication unit 13, and an HV monitoring information transfer unit 14. Since the request execution unit 11, the request transfer unit 12, and the virtual communication unit 13 are the same as those in the first embodiment, the description thereof is omitted.

[0069] The HV monitoring information transfer unit 14 acquires the monitoring results of the HV monitoring unit 41 described later and transfers them to the security VM30a.

[0070] Since the VM20 is the same as that in the first embodiment, the description thereof is omitted.

[0071] The security VM 30a is a VM that performs security-related processing of the virtualization system. For example, the security VM 30a is accessible to the VM 20 but not accessible from the VM 20, and is less vulnerable to attacks than the VM 20. Therefore, security-related functions are implemented in the security VM 30a. The security VM 30a includes a request receiving unit 31, a request monitoring unit 32, a communication receiving unit 33, a VM monitoring information receiving unit 34, a determination unit 35a, a corresponding unit 36a, and an HV monitoring information receiving unit 37. Since the request receiving unit 31, the request monitoring unit 32, the communication receiving unit 33, and the VM monitoring information receiving unit 34 are the same as those in the first embodiment, the description thereof is omitted.

[0072] The HV monitoring information receiving unit 37 receives the monitoring result of the HV monitoring unit 41. The HV monitoring information receiving unit 37 notifies the determination unit 35a of the monitoring result of the HV monitoring unit 41.

[0073] The determination unit 35a determines the state of the virtualization system based on the monitoring results of a plurality of monitoring units. In the second embodiment, the determination unit 35a determines the state of the virtualization system based on the monitoring results of the VM monitoring unit 21, the request monitoring unit 32, and the HV monitoring unit 41 as the monitoring results of a plurality of monitoring units. For example, the determination unit 35a determines the state of the virtualization system according to the combination of the monitoring results of a plurality of monitoring units. The determination unit 35a outputs the determined state of the virtualization system. For example, the determination unit 35a notifies the corresponding unit 36a of the determined state of the virtualization system. Note that the determination unit 35a may output the determined state of the virtualization system to a computer or a mobile terminal owned by a user who uses the device on which the virtualization system is installed, or may output it to a server or the like.

[0074] The corresponding unit 36a performs corresponding actions according to the determined state of the virtualization system. Details of the corresponding actions will be described later.

[0075] The secure OS 40 is an OS that performs security-related processing for the HV 10a. For example, the secure OS 40 is accessible to the virtualization system but not accessible from the virtualization system, and is less vulnerable to attacks than the virtualization system. Therefore, functions related to the security of the HV 10a that realizes the virtualization system are implemented in the secure OS 40. The secure OS 40 includes an HV monitoring unit 41 and an HV monitoring information transmission unit 42.

[0076] The HV monitoring unit 41 monitors the HV 10a in the virtualization system. Specifically, the HV monitoring unit 41 monitors whether the memory of the HV 10a has been tampered with. The HV monitoring unit 41 notifies the monitoring result to the HV monitoring information transmission unit 42. The HV monitoring unit 41 is an example of a virtualization infrastructure monitoring unit that monitors the virtualization infrastructure in the virtualization system, and is one of a plurality of monitoring units with different authorities that monitor the virtualization system and detect abnormalities. As described above, the secure OS 40 is accessible to the virtualization system but not accessible from the virtualization system, and the secure OS 40 and the virtualization system have different authorities. Therefore, the HV monitoring unit 41 provided in the secure OS 40 and the VM monitoring unit 21 and the request monitoring unit 32 provided in the virtualization system have different authorities respectively.

[0077] The HV monitoring information transmission unit 42 transmits the monitoring result of the HV monitoring unit 41 to the HV 10a.

[0078] Next, an example of the monitoring results of a plurality of monitoring units and the operation of the determination unit 35a will be described with reference to FIG. 7A.

[0079] FIG. 7A is a diagram showing an example of the monitoring results of a plurality of monitoring units in the second embodiment. In the second embodiment, the monitoring results of the VM monitoring unit 21, the request monitoring unit 32, and the HV monitoring unit 41 are shown as a plurality of monitoring units.

[0080] As shown in FIG. 7A, assume that at 13:01:03, the monitoring result of the VM monitoring unit 21 was normal. Also, assume that although not shown, the monitoring results of the request monitoring unit 32 and the HV monitoring unit 41 were also normal. For example, the determination unit 35a determines that the state of the virtualization system is normal according to the combination that the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is normal, and the monitoring result of the HV monitoring unit 41 is normal.

[0081] Next, assume that at 13:01:10, the monitoring result of the request monitoring unit 32 becomes abnormal. For example, the determination unit 35a determines that the state of the virtualization system is such that the request from the VM 20 is abnormal, there is a possibility that the VM 20 is abnormal, and there is a possibility that the HV 10a is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal.

[0082] Next, assume that at 13:01:13, the monitoring result of the VM monitoring unit 21 becomes abnormal. For example, the determination unit 35a determines that the state of the virtualization system is a state where the VM 20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is abnormal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal.

[0083] Next, assume that at 13:01:15, the monitoring result of the request monitoring unit 32 remains abnormal. For example, the determination unit 35a determines that the state of the virtualization system is a state where the VM 20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is abnormal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal.

[0084] Next, assume that at 13:01:20, the monitoring result of the HV monitoring unit 41 remains normal. For example, the determination unit 35a determines that the state of the virtualization system is a state where the VM 20 is abnormal according to the combination that the monitoring result of the VM monitoring unit 21 is abnormal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal.

[0085] Next, the operation of the corresponding unit 36a will be described with reference to FIG. 7B.

[0086] FIG. 7B is a diagram showing an example of the correspondence of the corresponding unit 36a in the second embodiment.

[0087] For example, when the virtualization system is determined to be in a normal state according to a combination where the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is normal, and the monitoring result of the HV monitoring unit 41 is normal, the corresponding unit 36a does not perform any specific correspondence.

[0088] For example, when the virtualization system is determined to be in a state where VM20 is abnormal and there is a possibility that requests from VM20 are abnormal according to a combination where the monitoring result of the VM monitoring unit 21 is abnormal, the monitoring result of the request monitoring unit 32 is normal, and the monitoring result of the HV monitoring unit 41 is normal, the corresponding unit 36a stops VM20 or strengthens the monitoring of the request monitoring unit 32. Also, when the virtualization system is determined to be in a state where HV10a may be abnormal, the corresponding unit 36a may strengthen the monitoring of the HV monitoring unit 41 (specifically, shorten the monitoring period of the HV monitoring unit 41 or adjust the threshold value when the HV monitoring unit 41 detects an abnormality).

[0089] For example, when the virtualization system is determined to be in a state where requests from VM20 (such as requests for inter-VM communication) are abnormal and there is a possibility that VM20 is abnormal according to a combination where the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal, the corresponding unit 36a cuts off inter-VM communication or strengthens the monitoring of the VM monitoring unit 21. Also, when the virtualization system is determined to be in a state where HV10a may be abnormal, the corresponding unit 36a may strengthen the monitoring of the HV monitoring unit 41.

[0090] For example, when, according to a combination where the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is normal, and the monitoring result of the HV monitoring unit 41 is abnormal, the state of the virtualization system is determined to be a state where HV10a is abnormal, the corresponding unit 36a restarts the virtualization system (that is, restarts HV10a).

[0091] For example, when, according to a combination where the monitoring result of the VM monitoring unit 21 is abnormal, the monitoring result of the request monitoring unit 32 is abnormal, and the monitoring result of the HV monitoring unit 41 is normal, the state of the virtualization system is determined to be a state where VM20 is abnormal, the corresponding unit 36 restarts VM20.

[0092] Note that the determination unit 35a may determine the state of the virtualization system according to a combination of detailed information on abnormalities detected by a plurality of monitoring units as a combination of monitoring results of the plurality of monitoring units. The detailed information on abnormalities may be, for example, the application in which the abnormality occurred, VM20, the communication channel, or the memory address, etc., or may be the type of abnormality (for example, access control violation or communication frequency abnormality, etc.), or may be numerical information such as the degree of abnormality calculated by machine learning or the like.

[0093] Next, the operation of the monitoring system 1a when the request monitoring unit 32 detects an abnormality in the hypercall will be described with reference to FIGS. 8 and 9.

[0094] FIG. 8 is a sequence diagram showing an example of the operation of the monitoring system 1a when the request monitoring unit 32 detects an abnormality in the hypercall in the second embodiment.

[0095] The request monitoring unit 32 monitors requests from VM20, detects an abnormality in the hypercall (step S41), and notifies the determination unit 35a of the monitoring result indicating the abnormality (step S42). Although not shown, it is assumed that the determination unit 35a has acquired monitoring results indicating normality from the VM monitoring unit 21 and the HV monitoring unit 41.

[0096] The determination unit 35a determines the state of the virtualization system (step S43). For example, according to the combination where the monitoring result of the VM monitoring unit 21 is normal, the monitoring result of the request monitoring unit 32 is a hypercall abnormality, and the monitoring result of the HV monitoring unit 41 is normal, it is determined that the state of the virtualization system is a state where the hypercall is abnormal, there is a possibility that VM20 is abnormal, and there is a possibility that HV10a is abnormal. Note that the determination unit 35a may determine the state of the virtualization system as numerical information such as an abnormality degree by machine learning or the like based on the monitoring results of the VM monitoring unit 21 and the request monitoring unit 32.

[0097] The corresponding unit 36a takes actions corresponding to the determined state of the virtualization system (steps S44 and S45). For example, as an action corresponding to the state where there is a possibility that VM20 is abnormal, the corresponding unit 36a strengthens the monitoring of the VM monitoring unit 21, and as an action corresponding to the state where there is a possibility that HV10a is abnormal, the corresponding unit 36a strengthens the monitoring of the HV monitoring unit 41. Note that when the state of the virtualization system is determined by numerical information such as an abnormality degree, the corresponding unit 36a may take actions according to the abnormality degree. For example, when the abnormality degree is low, the corresponding unit 36a may strengthen the monitoring of the VM monitoring unit 21, and when the abnormality degree is high, the corresponding unit 36a may strengthen the monitoring of the HV monitoring unit 41.

[0098] The VM monitoring unit 21 monitors VM20 and confirms that it is normal (step S46), and notifies the determination unit 35a of the monitoring result indicating normality (step S47).

[0099] The HV monitoring unit 41 monitors HV10a and confirms that it is normal (step S48), and notifies the determination unit 35a of the monitoring result indicating normality (step S49).

[0100] The determination unit 35a determines the state of the virtualization system (step S50). For example, according to the combination where the monitoring result of the VM monitoring unit 21 after monitoring strengthening is normal, the monitoring result of the request monitoring unit 32 is a hypercall abnormality, and the monitoring result of the HV monitoring unit 41 after monitoring strengthening is normal, it is determined that the state of the virtualization system is a state where the hypercall is abnormal.

[0101] The corresponding unit 36a performs corresponding operations according to the determined state of the virtualization system (step S51). For example, as a corresponding operation according to the state where the hypercall is abnormal, the corresponding unit 36a restarts or stops the VM 20 that requested the hypercall. Since the monitoring result of the VM monitoring unit 21 is normal, there is a possibility that the hypercall abnormality is misdetected. Therefore, if the same abnormality as this time has occurred in the past, the corresponding unit 36a may restart or stop the VM 20 that requested the hypercall. In other words, if the same abnormality as this time has not occurred in the past, the corresponding unit 36a does not have to restart or stop the VM 20 that requested the hypercall, and when the same abnormality occurs in the future, the corresponding unit 36a may restart or stop the VM 20 that requested the hypercall. Alternatively, if the hypercall abnormality continues for a certain period of time or more, the corresponding unit 36a may restart or stop the VM 20 that requested the hypercall.

[0102] FIG. 9 is a sequence diagram showing another example of the operation of the monitoring system 1a when the request monitoring unit 32 detects an abnormality in the hypercall in the second embodiment. The processes from step S61 to step S67 in FIG. 9 are the same as the processes from step S41 to step S47 in FIG. 8, and thus the description thereof is omitted.

[0103] The HV monitoring unit 41 monitors the HV 10a and confirms that it is abnormal (step S68), and notifies the determination unit 35a of the monitoring result indicating the abnormality (step S69).

[0104] The determination unit 35a determines the state of the virtualization system (step S70). For example, according to the combination where the monitoring result of the VM monitoring unit 21 after the monitoring enhancement is normal, the monitoring result of the request monitoring unit 32 is an abnormality in the hypercall, and the monitoring result of the HV monitoring unit 41 after the monitoring enhancement is abnormal, the state of the virtualization system is determined to be a state where the HV 10a is abnormal.

[0105] The corresponding unit 36a performs corresponding operations according to the determined state of the virtualization system (step S71). For example, the corresponding unit 36a restarts, updates, or stops HV10a as corresponding operations according to the state where HV10a is abnormal. For example, the corresponding unit 36a restarts HV10a, and after HV10a restarts, if the monitoring results of the request monitoring unit 32 and the HV monitoring unit 41 return to normal, the enhancement of the monitoring of each monitoring unit ends. If the monitoring results of the request monitoring unit 32 and the HV monitoring unit 41 remain abnormal after HV10a restarts, the corresponding unit 36a updates the memory of HV10a. For example, the corresponding unit 36a updates the memory of HV10a, and after the monitoring results of the request monitoring unit 32 and the HV monitoring unit 41 return to normal, the enhancement of the monitoring of each monitoring unit ends. If the monitoring results of the request monitoring unit 32 and the HV monitoring unit 41 remain abnormal after the memory of HV10a is updated, the corresponding unit 36a stops HV10a.

[0106] (Summary) The monitoring system is a system that monitors a virtualization system (a system composed of HVs, VMs, etc.), and includes a plurality of monitoring units with different authorities that monitor the virtualization system to detect abnormalities, and a determination unit that determines the state of the virtualization system based on the monitoring results of the plurality of monitoring units.

[0107] According to this, since the entire virtualization system is monitored by a plurality of monitoring units instead of a single monitoring unit, the state of the entire virtualization system can be determined based on the monitoring results of the plurality of monitoring units. In addition, since a plurality of monitoring units with different authorities are used, the detection accuracy of abnormalities can be improved, and false detection or detection omission can be suppressed.

[0108] For example, the plurality of monitoring units may include at least one of a VM monitoring unit that monitors VMs in the virtualization system, a request monitoring unit that monitors requests from VMs to HVs in the virtualization system, and an HV monitoring unit that monitors HVs in the virtualization system.

[0109] According to this, based on the monitoring result of the VM, the monitoring result of the request from the VM to the HV, or the monitoring result of the HV, the state of the entire virtualization system can be determined in detail.

[0110] For example, the determination unit may determine the state of the virtualization system according to the combination of the monitoring results of a plurality of monitoring units.

[0111] According to this, the state of the virtualization system can be predicted to a certain extent by the combination of the monitoring results of a plurality of monitoring units. Therefore, the state of the virtualization system can be accurately determined by the combination of the monitoring results of a plurality of monitoring units.

[0112] For example, the monitoring system may further include a response unit that performs a response according to the determined state of the virtualization system.

[0113] According to this, a response can be made according to the state of the entire virtualization system. For example, a response can be made that suppresses the influence on the function of the device (such as a vehicle) on which the virtualization system is mounted.

[0114] (Other Embodiments) As described above, embodiments have been described as examples of the technology according to the present disclosure. However, the technology according to the present disclosure is not limited to this, and is also applicable to embodiments in which appropriate changes, replacements, additions, omissions, etc. are made. For example, the following modification examples are also included in one embodiment of the present disclosure.

[0115] For example, in the above embodiment, an example in which the virtualization system is an HV type system has been described, but it may also be a container or a host OS type system.

[0116] For example, in the above embodiment, an example of detecting an abnormality in inter-VM communication by monitoring a request from a VM to an HV has been described, but the present invention is not limited to this. For example, the virtualization system may include a gateway VM that mediates communication between VMs, and the communication content of the inter-VM communication may be monitored in the gateway VM, and an abnormality in the inter-VM communication may be detected according to the communication content.

[0117] For example, in the above embodiment, an example of the determination unit determining the state of the virtualization system according to a combination of the monitoring results of a plurality of monitoring units has been described, but the present invention is not limited to this.

[0118] For example, the determination unit may determine the state of the virtualization system according to the detection order of abnormalities detected by a plurality of monitoring units. For example, when the monitoring results of the VM monitoring unit and the request monitoring unit are both normal, if the monitoring result of the VM monitoring unit becomes abnormal first and then the monitoring result of the request monitoring unit becomes abnormal, and when the monitoring result of the request monitoring unit becomes abnormal first and then the monitoring result of the VM monitoring unit becomes abnormal, the determination results of the state of the virtualization system may be different. Here, specific examples of the determination of the state of the virtualization system and the corresponding measures according to the detection order of abnormalities detected by a plurality of monitoring units will be described with reference to FIG. 10.

[0119] FIG. 10 is a diagram showing an example of the determination of the determination unit and the corresponding measures of the corresponding unit in other embodiments. For example, in a monitoring system including a VM monitoring unit, a request monitoring unit, and an HV monitoring unit as a plurality of monitoring units, the determination of the state of the virtualization system and the corresponding measures according to the detection order of abnormalities detected by the plurality of monitoring units will be described. It is assumed that the monitoring system described here includes not only VMs equipped with a VM monitoring unit but also VMs not equipped with a VM monitoring unit. Hereinafter, a VM equipped with a VM monitoring unit will be referred to as VM_A, and a VM not equipped with a VM monitoring unit will be referred to as VM_B.

[0120] For example, when the monitoring result of the VM monitoring unit becomes abnormal and subsequently the monitoring result of the request monitoring unit becomes abnormal, the determination unit determines that the state of the virtualization system is a state where an abnormality may have spread outside VM_A after an abnormality occurred in VM_A, and the response unit restarts VM_A according to the state. For example, when the monitoring result of the request monitoring unit becomes abnormal and subsequently the monitoring result of the VM monitoring unit becomes abnormal, the determination unit determines that the state of the virtualization system is a state where an abnormality may have spread to VM_A after an abnormality occurred in VM_B, and the response unit restarts VM_A and VM_B according to the state. For example, when the monitoring result of the VM monitoring unit becomes abnormal, subsequently the monitoring result of the request monitoring unit becomes abnormal, and subsequently the monitoring result of the HV monitoring unit becomes abnormal, the determination unit determines that the state of the virtualization system is a state where an abnormality may have spread to the HV after an abnormality occurred in VM_A, and the response unit restarts the HV according to the state and strengthens the monitoring of the VM monitoring unit. For example, when the monitoring result of the request monitoring unit becomes abnormal, subsequently the monitoring result of the HV monitoring unit becomes abnormal, and subsequently the monitoring result of the VM monitoring unit becomes abnormal, the determination unit determines that the state of the virtualization system is a state where an abnormality may have spread to the HV and VM_A after an abnormality occurred in VM_B, and the response unit restarts the HV according to the state and strengthens the monitoring of the request monitoring unit.

[0121] In this way, since the state of the virtualization system can be predicted to some extent based on the detection order of the abnormalities detected by the multiple monitoring units, the state of the virtualization system can be accurately determined based on the detection order of the abnormalities detected by the multiple monitoring units.

[0122] For example, the determination unit may determine the state of the virtualization system according to the duration of the anomalies detected by the plurality of monitoring units. For example, when the monitoring results of the VM monitoring unit and the request monitoring unit are both normal, if the monitoring result of the VM monitoring unit becomes abnormal and then becomes normal before the elapse of the specified time, the abnormal monitoring result of the VM monitoring unit may be a false detection. Therefore, the determination unit may determine that the state of the virtualization system is normal. Since the state of the virtualization system can be predicted to some extent based on the duration of the anomalies detected by the plurality of monitoring units, the state of the virtualization system can be accurately determined based on the duration of the anomalies detected by the plurality of monitoring units.

[0123] For example, when determining the state of the virtualization system, the determination unit may weight the monitoring results of the plurality of monitoring units according to the respective authorities of the plurality of monitoring units. In that case, the monitoring result of the monitoring unit with a higher authority may be preferentially used for the determination. For example, even if the monitoring result of the VM monitoring unit is normal, if the monitoring result of the HV monitoring unit is abnormal, the determination and response may be carried out with priority given to the monitoring result of the HV monitoring unit.

[0124] Note that the present disclosure can be realized not only as a monitoring system, but also as a monitoring method including the steps (processes) performed by each component constituting the monitoring system.

[0125] For example, the steps in the monitoring method may be executed by a computer (computer system). And the present disclosure can be realized as a program for causing a computer to execute the steps included in the monitoring method.

[0126] Furthermore, the present disclosure can be realized as a non-transitory computer-readable recording medium such as a CD-ROM recording the program.

[0127] For example, when the present disclosure is implemented by a program (software), each step is executed by using hardware resources such as a computer's CPU, memory, and input / output circuits. That is, each step is executed by the CPU acquiring data from the memory or input / output circuits, etc., performing calculations, or outputting the calculation results to the memory or input / output circuits, etc.

[0128] In addition, each component included in the monitoring system of the above embodiment may be realized as a dedicated or general-purpose circuit.

[0129] In addition, each component included in the monitoring system of the above embodiment may be realized as an LSI (Large Scale Integration) which is an integrated circuit (IC: Integrated Circuit).

[0130] In addition, the integrated circuit is not limited to an LSI, and may be realized by a dedicated circuit or a general-purpose processor. A programmable FPGA (Field Programmable Gate Array), or a reconfigurable processor in which the connection and setting of circuit cells inside the LSI can be reconfigured may be used.

[0131] Furthermore, if a technology for integrating circuits that replaces the LSI appears due to the progress of semiconductor technology or another derived technology, naturally, each component included in the monitoring system may be integrated using that technology.

[0132] In addition, forms obtained by applying various modifications that those skilled in the art can come up with to the embodiments, and forms realized by arbitrarily combining the components and functions in each embodiment without departing from the spirit of the present disclosure are also included in the present disclosure.

Industrial Applicability

[0133] The present disclosure can be applied to, for example, a system for monitoring a virtualization system mounted on a vehicle.

Explanation of Signs

[0134] 1. 1a Monitoring system 10, 10a HV 11 Request execution unit 12 Request transfer unit 13 Virtual communication unit 14 HV monitoring information transfer unit 20 VM 21 VM monitoring unit 22 Request generation unit 23 Application 30, 30a Security VM 31 Request reception unit 32 Request monitoring unit 33 Communication reception unit 34 VM monitoring information reception unit 35, 35a Judgment unit 36, 36a Response unit 37 HV monitoring information reception unit 40 Secure OS 41 HV monitoring unit 42 HV monitoring information transmission unit

Claims

1. A monitoring system for monitoring a virtualization system, comprising: a plurality of monitoring units that monitor the virtualization system to detect anomalies and have different access rights to each other; a determination unit that determines the state of the virtualization system based on the monitoring results of the plurality of monitoring units. The monitoring system.

2. The plurality of monitoring units include at least one of a virtual environment monitoring unit that monitors a virtual environment in the virtualization system, a request monitoring unit that monitors requests from the virtual environment in the virtualization system to the virtualization infrastructure, and a virtualization infrastructure monitoring unit that monitors the virtualization infrastructure in the virtualization system. The monitoring system according to Claim 1.

3. The determination unit determines the state of the virtualization system according to the combination of the monitoring results of the plurality of monitoring units. The monitoring system according to Claim 1 or 2.

4. The determination unit determines the state of the virtualization system according to the detection order of the anomalies detected by the plurality of monitoring units. The monitoring system according to any one of Claims 1 to 3.

5. The determination unit determines the state of the virtualization system according to the duration of the anomalies detected by the plurality of monitoring units. The monitoring system according to any one of Claims 1 to 4.

6. Furthermore, it comprises a response unit that implements a response according to the determined state of the virtualization system. The monitoring system according to any one of Claims 1 to 5.

Citation Information

Patent Citations

  • Optical fiber type rotary tachometer

    JP1985079218A

  • Virtual computer system

    JP2008269194A

  • System capable of selectively switching between secure mode and non-secure mode

    JP2019066995A

  • Monitoring program, monitoring apparatus and monitoring method

    JP2019144785A

  • Electronic control unit and electronic control system

    JP2019185130A