Attack Detection System
The attack detection system addresses the inefficacy of existing vehicle cyber defense by redirecting and simulating vehicle communications, effectively neutralizing threats without alerting attackers, ensuring vehicle security.
Patent Information
- Application Number
- JP2022178333
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-11-07
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2042-11-07
AI Technical Summary
Existing technologies for protecting connected vehicles from cyber attacks are ineffective as attackers can adapt their methods when blocked, leading to a cat-and-mouse game between defense and offense.
An attack detection system with a first device that monitors communications and activates a honeypot server simulating the vehicle system, redirecting attack packets to a second device, which processes them, while concealing the honeypot server's presence.
Protects connected vehicles from cyber attacks by neutralizing threats without alerting the attacker, conserving resources, and maintaining system integrity.
Smart Images

Figure 0007760989000001 
Figure 0007760989000002 
Figure 0007760989000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to network security. [Background technology]
[0002] There are technologies for protecting vehicles connected to a network from attacks. For example, Patent Document 1 discloses a communication system that detects when an unauthorized device is connected to a network and blocks communications performed by that device. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-139883 [Patent Document 2] Japanese Patent Application Laid-Open No. 2013-009185 Summary of the Invention [Problem to be solved by the invention]
[0004] The present disclosure aims to protect connected vehicles from cyber attacks. [Means for solving the problem]
[0005] One aspect of an embodiment of the present disclosure is An attack detection system including a first device and a second device, wherein the first device has a first control unit that performs the following: monitoring communications made to a first vehicle connected to a network; and, when detecting that an attack on the first vehicle is being made from an attack source device, sending a first command to the second device to activate a honeypot server that simulates the vehicle system of the first vehicle; and sending a second command to a communication device that relays communications to the first vehicle within the network to forward packets sent from the attack source device to the first vehicle to the second device; and the second device has a second control unit that processes packets sent from the attack source device to the first vehicle and forwarded by the communication device by the honeypot server that simulates the vehicle system of the first vehicle.
[0006] Other aspects include a method executed by the above-described device, a program for causing a computer to execute the method, or a computer-readable storage medium non-transitoryly storing the program. [Effects of the Invention]
[0007] According to the present disclosure, connected vehicles can be protected from cyber attacks. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a schematic diagram of a communication system according to a first embodiment. [Figure 2] FIG. 2 is a diagram showing components of an in-vehicle device. [Figure 3] FIG. 1 is a diagram showing components of an attack detection device. [Figure 4] FIG. 2 is a diagram showing components of a relay device. [Figure 5] 10 is an example of a conversion table generated by a relay device. [Figure 6] FIG. 1 illustrates components of a decoy device. [Figure 7]FIG. 3 is a sequence diagram of processing performed in the first embodiment. [Figure 8] 10 is a flowchart of a process executed by an attack detection device. DETAILED DESCRIPTION OF THE INVENTION
[0009] In recent years, the number of vehicles that can connect to wireless networks has increased as automobiles have become more connected. By communicating with a server device, it becomes possible to provide vehicles with information that contributes to road safety and the latest traffic information.
[0010] In such systems, attacks via the network can be a problem. For example, an attacker may send false traffic information to a vehicle or steal data transmitted from the vehicle. Attacks can include vulnerability scans and brute force attacks that attempt to infiltrate vehicle systems.
[0011] There are known technologies for detecting attacks against specific devices via a network. However, if an attacker is detected and communication is immediately blocked, the attacker may recognize that they have been removed from the network and continue their attacks by changing their attack method or source. In other words, the attacker may become trapped in a cat-and-mouse game between attack and defense. An information processing device according to an aspect of the present disclosure solves such a problem.
[0012] An attack detection system according to a first aspect of the present disclosure is a system including a first device and a second device. Specifically, the first device has a first control unit that monitors communications made to a first vehicle connected to the network, and when it detects that an attack on the first vehicle is being made from an attack source device, sends a first command to the second device to start a honeypot server that simulates the vehicle system of the first vehicle, and sends a second command to a communication device that relays communications to the first vehicle within the network to forward packets sent from the attack source device to the second device. The second device also has a second control unit that processes packets sent from the attack source device to the first vehicle and forwarded by the communication device by the honeypot server that simulates the vehicle system of the first vehicle.
[0013] The honeypot server is a server that has a function of virtually simulating the vehicle system of the first vehicle that is the target of the attack. The honeypot server may be realized by software. The first device monitors network communications, and when it detects an attack on the first vehicle, it sends a command (first command) to the second device to activate a honeypot server that simulates the vehicle system of the first vehicle. Furthermore, the first device sends a second command to a communication device that relays communications to the first vehicle, causing the communication device to forward packets related to the attack to the second device. An example of the communication device is a network switch on a path through which the packets related to the attack pass.
[0014] The second command may be, for example, a command to rewrite the destination of a packet sent from the attacking device to the first vehicle from the first vehicle to the second device, thereby causing the attack-related packet addressed to the first vehicle to be forwarded to the second device. The communication device that receives the second command, for example, replaces the destination (e.g., the destination IP address included in the IP header) of a packet sent from the attacking device to the first vehicle with an IP address corresponding to the second device. This ensures that all packets sent from the attacking device are directed to the honeypot server running on the second device. The honeypot server simulates the vehicle system (on-board computer system) of the first vehicle, so the attacker can communicate without realizing that the communication partner is not the first vehicle. , it becomes possible to protect the first vehicle from attacks.
[0015] As described above, the second command may instruct the communication device to change the destination of a packet sent from the attacking device to the first vehicle from the IP address of the first vehicle to the IP address of the second device. Furthermore, the second command may instruct the communication device to replace the source of a packet sent from the second device to the attacking device from the IP address of the second device to the IP address of the first vehicle. According to this configuration, the source of the packet sent from the second device (honeypot server) is replaced with the IP address of the first vehicle, so that it is possible to conceal the fact that the honeypot server is responding.
[0016] Furthermore, the first command may further include information (first information) about the first vehicle. The first information is typically information necessary to simulate the first vehicle. When responding to an attack using a honeypot server, if the make and model name of the simulated vehicle differs from that of the actual vehicle, the attacker may be aware of the attack. Therefore, the first command may be used to send information about the first vehicle to the second device, and the second device may operate the honeypot server based on this information. This allows, for example, the honeypot server to simulate the make and model of the target vehicle, reducing the risk of being detected by an attacker.
[0017] The first information may include data on the traveling of the first vehicle, in addition to information on the first vehicle itself (such as the type and model name). For example, if the current location and speed of the first vehicle can be obtained, this information may be used to make the honeypot server simulate the traveling of the first vehicle. This allows the honeypot server to behave as if the virtual first vehicle were traveling in the same place as a real vehicle.
[0018] Furthermore, when the first device determines that the attack on the first vehicle has ended, the first device may instruct the second device to stop the honeypot server. With this configuration, the honeypot server is activated only while the attack is occurring, thereby saving computer resources.
[0019] Specific embodiments of the present disclosure will be described below with reference to the accompanying drawings. Unless otherwise specified, the hardware configuration, module configuration, functional configuration, etc. described in each embodiment are not intended to limit the technical scope of the disclosure to those configurations.
[0020] (First embodiment) An overview of a communication system according to a first embodiment will be described with reference to Fig. 1. The communication system according to this embodiment is a system in which vehicles 10 equipped with on-vehicle devices 100 are connected to a network wirelessly. The system may include a plurality of vehicles 10 (on-vehicle devices 100).
[0021] The vehicle 10 is a connected car having a wireless communication function. The vehicle 10 is equipped with an in-vehicle device 100. The in-vehicle device 100 can connect to a predetermined wireless network (hereinafter referred to as a vehicle network) and communicate with any device via the Internet. The vehicle network may be a mobile communication network using a cellular communication method, or a wireless communication network using Wi-Fi (registered trademark) or Bluetooth (registered trademark). The vehicle network is connected to the Internet. A server device 600 is disposed in the vehicle-mounted device 100 to provide predetermined services to the vehicle-mounted device 100. Although the vehicle network and the Internet are connected in this example, a wide area network or a private network other than the Internet may be connected to the vehicle network.
[0022] The vehicle network includes an access point that wirelessly communicates with the in-vehicle device 100 and a relay device 300 that relays packets. The access point is a device that provides wireless access to the vehicle network. If the vehicle network is a mobile communication network, the access point is a base station. The relay device 300 is connected to the access point, and packets destined for the in-vehicle device 100 pass through the access point.
[0023] Furthermore, an attack detection device 200 (first device) and a decoy device 400 (second device) are disposed in the vehicle network. The attack detection device 200 detects an attack on a vehicle 10 (on-vehicle device 100) connected to a vehicle network, and executes a predetermined process to deal with the attack. The decoy device 400 is a device that processes packets related to the attack on behalf of the on-vehicle device 100 that is the target of the attack. The decoy device 400 is configured to be able to run a honeypot server. Specific methods for dealing with attacks will be described later.
[0024] The in-vehicle device 100 is a computer for collecting and providing information. In this embodiment, the in-vehicle device 100 has a function of collecting information related to the traveling of the vehicle 10 and transmitting the information to the server device 600, and a function of providing information to the occupants of the vehicle 10 based on the information received from the server device 600. The in-vehicle device 100 may be a device that provides information to a passenger in the vehicle 10 (for example, a car navigation device), or may be an electronic control unit (ECU) included in the vehicle 10. The in-vehicle device 100 may also be a data communication module (DCM) having a communication function.
[0025] The in-vehicle device 100 can be configured as a computer having a processor such as a CPU or GPU, a main memory such as a RAM or ROM, and an auxiliary memory such as an EPROM, a hard disk drive, or removable media. The auxiliary memory stores an operating system (OS), various programs, various tables, etc., and by executing the programs stored therein, various functions that match predetermined purposes, as described below, can be realized. However, some or all of the functions may be realized by hardware circuits such as ASICs or FPGAs.
[0026] FIG. 2 is a diagram showing components of the in-vehicle device 100. As shown in FIG. The in-vehicle device 100 includes a control unit 101 , a storage unit 102 , a communication unit 103 , and an input / output unit 104 .
[0027] The control unit 101 is a calculation unit that executes a predetermined program to realize various functions of the in-vehicle device 100. The control unit 101 may be realized by, for example, a CPU or the like. The control unit 101 is configured to have a function providing unit 1011 as a functional module. The functional module may be realized by executing a stored program by a CPU.
[0028] The function providing unit 1011 executes various functions provided by the in-vehicle device 100. The functions provided by the in-vehicle device 100 include, for example, the following. Navigation function This is a function that provides route navigation based on map data provided by the server device 600. ·Traffic information provision function This is a function to obtain and provide traffic information from the server device 600. The traffic information may be provided to the occupants of the vehicle 10, or may be provided to an electronic control unit that controls the autonomous or semi-autonomous driving of the vehicle 10. Data transmission function This is a function of collecting information relating to the travel of the vehicle 10 (speed information, position information, etc.) and transmitting it to the server device 600. These functions can be provided, for example, via the input / output unit 104 (touch panel). In order to provide these functions, the in-vehicle device 100 may also have a GPS antenna, a GPS module, and the like. The function providing unit 1011 is configured to be able to execute these functions by communicating with the server device 600 .
[0029] The storage unit 102 is a memory device including a main storage device and an auxiliary storage device. The auxiliary storage device stores an operating system (OS), various programs, various tables, etc., and by loading the programs stored therein into the main storage device and executing them, various functions that meet predetermined purposes, as will be described later, can be realized. The main memory may include RAM (Random Access Memory) and ROM (Read Only Memory). The auxiliary memory may include EPROM (Erasable Programmable ROM) and hard disk. It may also include a disk drive (HDD, Hard Disk Drive). may include removable media, i.e., portable recording media.
[0030] The communication unit 103 is a wireless communication interface for connecting the in-vehicle device 100 to a vehicle network. The communication unit 103 is configured to be able to communicate with the vehicle network using a communication standard such as mobile communication, wireless LAN, or Bluetooth (registered trademark).
[0031] The input / output unit 104 is a means for accepting input operations performed by the device user and presenting information. In this embodiment, it is made up of a single touch panel display. That is, it is made up of a liquid crystal display and its control means, and a touch panel and its control means.
[0032] Next, we will explain the attack detection device 200. The attack detection device 200 has a function of monitoring communications with multiple vehicles 10 (on-vehicle devices 100) connected to a vehicle network, and a function of determining, based on the monitoring results, that an attack is being made on one vehicle. The attack detection device 200 may be part of an IDS (Intrusion Detection System) or an IPS (Intrusion Prevention System).
[0033] When the attack detection device 200 detects an attack, it generates a command (first command, hereinafter referred to as a forwarding command) to change the destination of packets related to the attack and transmits it to the relay device 300. In accordance with the forwarding command, the relay device 300 changes the destination of packets related to the attack from the in-vehicle device 100 to the decoy device 400. As a result, the packets related to the attack are forwarded to the decoy device 400. Furthermore, when the attack detection device 200 detects an attack, it generates a command (second command, hereinafter referred to as a start command) for causing the decoy device 400 to start up a honeypot server, and transmits it to the decoy device 400 .
[0034] The attack detection device 200 includes a processor such as a CPU or a GPU, a main memory such as a RAM or a ROM, and The attack detection device 200 can be configured as a computer having auxiliary storage devices such as a hard disk drive, an EPROM, a hard disk drive, and removable media. The attack detection device 200 can be configured as a single computer, or can be configured as multiple computers that work together.
[0035] 3 is a diagram showing the components of the attack detection device 200. The attack detection device 200 includes a control unit 201, a storage unit 202, and a communication unit 203.
[0036] The control unit 201 is an arithmetic unit that controls the attack detection device 200. The control unit 201 can be realized by an arithmetic processing unit such as a CPU. The control unit 201 is configured to have two functional modules: an attack detection unit 2011 and a process command unit 2012. Each functional module may be realized by causing a CPU to execute a program stored in an auxiliary storage unit.
[0037] The attack detection unit 2011 determines the content of communications being made to multiple in-vehicle devices 100 connected to the vehicle network by monitoring packets passing through the relay device 300, and determines whether an attack is being made to one of the in-vehicle devices 100. The attack is made, for example, from an attack source device connected to the vehicle network or the Internet. The fact that an attack is taking place can be determined by a known method, such as a method of comparing the contents of packets passing through relay device 300 with a predetermined attack pattern. When the attack detection unit 2011 determines that an attack is being made against one of the vehicle-mounted devices 100, it identifies the IP address of the attacking device and the IP address of the vehicle-mounted device 100 that is the target of the attack (hereinafter referred to as the attacked device) based on the contents of the packet related to the attack.
[0038] When the attack detection unit 2011 detects an attack, the process command unit 2012 takes measures to deal with the attack. Specifically, the processing command unit 2012 first issues a forwarding command to the relay device 300 to rewrite the IP header of a packet related to the attack and forward the packet to the decoy device 400. For example, the processing command unit 2012 instructs the relay device 300 to rewrite the IP header of a packet whose source is the IP address of the attacking device and whose destination is the IP address of the attacked device, so that the packet is forwarded to the decoy device 400 instead of the in-vehicle device 100. Specifically, for a packet whose source is the IP address of the attacking device and whose destination is the IP address of the attacked device, the processing command unit 2012 issues a command to rewrite the destination from the IP address of the attacked device to the IP address of the decoy device 400. As a result, the packet related to the attack is forwarded to the decoy device 400 instead of the in-vehicle device 100 that is the target of the attack.
[0039] Secondly, the process command unit 2012 issues a start command to the decoy device 400 to start up the honeypot server. By executing these two processes, a honeypot server is started in the decoy device 400, and packets related to the attack can be directed to the decoy device 400. In other words, the attack can be neutralized by the honeypot server.
[0040] The storage unit 202 is configured to include a main storage device and an auxiliary storage device. The main storage device is a memory in which the programs executed by the control unit 201 and the data used by the control programs are expanded. The auxiliary storage device is a device in which the programs executed by the control unit 201 and the data used by the control programs are stored.
[0041] The communication unit 203 is a communication interface for connecting the attack detection device 200 to a vehicle network. The communication unit 203 includes, for example, a network interface board and a wireless communication circuit for wireless communication.
[0042] Next, we will explain the relay device 300. The relay device 300 is a device that relays packets transmitted to and received from the in-vehicle device 100 that is wirelessly connected to the vehicle network. The relay device 300 is placed at a position in the vehicle network through which all packets destined for the in-vehicle device 100 pass. Furthermore, the relay device 300 has a function of rewriting the destination address and source address contained in the IP header of a packet passing through, based on a transfer command received from the attack detection device 200 .
[0043] Like the attack detection device 200, the relay device 300 can be configured as a computer having a processor such as a CPU or GPU, a main memory device such as a RAM or ROM, and an auxiliary memory device such as an EPROM, a hard disk drive, or removable media.
[0044] 4 is a diagram showing the components of relay device 300. Relay device 300 is configured to include control unit 301, storage unit 302, and communication unit 303.
[0045] The control unit 301 is an arithmetic unit that controls the relay device 300. The control unit 301 can be realized by an arithmetic processing unit such as a CPU. The control unit 301 is configured to have, as functional modules, a relay unit 3011 and an address conversion unit 3012. The functional modules may be realized by causing a CPU to execute a program stored in an auxiliary storage unit.
[0046] The relay unit 3011 relays packets addressed to the in-vehicle device 100 connected to the vehicle network. The packets may be transmitted from an external network such as the Internet, or may be transmitted from within the vehicle network. The relay unit 3011 also has a function of changing the relay destination of the packets based on a conversion table described later.
[0047] The address conversion unit 3012 generates a table (conversion table) for performing address conversion based on the transfer command received from the attack detection device 200, and rewrites the IP header included in the passing packet based on the conversion table. 5 shows an example of a conversion table generated based on a transfer command. When the address conversion unit 3012 receives a packet having an IP header with the contents shown in "Before Conversion," it rewrites the IP header of the packet as shown in "After Conversion." Here, the transfer command includes the IP address of the attacking device and the IP address of the attacked device.
[0048] Upon receiving the transfer command, the address conversion unit 3012 generates a conversion table for rewriting the destination and source included in the IP header. Specifically, a conversion table is generated to rewrite the destination of a packet whose source is the IP address of the attacking device and whose destination is the IP address of the attacked device to the IP address of the decoy device 400 (reference numeral 501). The address conversion unit 3012 rewrites the IP address included in the IP header of a passing packet based on a conversion table. The rewriting of the IP address can be realized by using a NAT (Network Address Translation) function. The packets with rewritten IP headers are processed by the relay unit 3011, so that all packets sent from the attacking device and destined for the attacked device are sent to the decoy device 400. become.
[0049] Furthermore, the address conversion unit 3012 generates a conversion table for rewriting the source of a packet whose source is the IP address of the decoy device and whose destination is the IP address of the attacking device to the IP address of the attacked device (reference numeral 502). As a result, the source IP address of the packet sent from the decoy device 400 and addressed to the attacking device is disguised as the IP address of the attacked device.
[0050] Packets with IP headers rewritten by the address conversion unit 3012 pass through the relay unit 3011, so that all packets sent from the attacking device to the attacked device are received by the decoy device 400 (honeypot server). In addition, the source of packets sent from the honeypot server is disguised as that of the attacked device. That is, even from the attack source device, it becomes difficult to determine that the packet is being processed by the honeypot server.
[0051] The storage unit 302 and the communication unit 303 are similar to the storage unit 202 and the communication unit 203, and therefore a description thereof will be omitted.
[0052] Next, the decoy device 400 will be described. The decoy device 400 is a device that processes attack-related packets sent from the attack source device. The decoy device 400 is configured to be able to execute a honeypot server by software, and processes attack-related packets by the honeypot server. The honeypot server is a virtual server device that simulates the in-vehicle device 100.
[0053] Like the attack detection device 200, the decoy device 400 can be configured as a computer having a processor such as a CPU or GPU, a main memory device such as a RAM or ROM, and an auxiliary memory device such as an EPROM, a hard disk drive, or removable media.
[0054] 6 is a diagram showing the components of decoy device 400. Decoy device 400 is configured to include a control unit 401, a storage unit 402, and a communication unit 403.
[0055] The control unit 401 is an arithmetic unit that controls the decoy device 400. The control unit 401 can be realized by an arithmetic processing unit such as a CPU. The control unit 401 is configured to have, as a functional module, an execution unit 4011. The functional module may be realized by causing a CPU to execute a program stored in an auxiliary storage unit.
[0056] The execution unit 4011 executes a honeypot server that simulates the in-vehicle device 100, which is the attacked device, based on a start-up command received from the attack detection device 200.
[0057] The startup command may include information about the on-board device 100 (or the vehicle 10 on which the on-board device 100 is mounted), which is the device being attacked. For example, the execution unit 4011 can simulate the operation of the on-board device 100 using the make and model name of the vehicle 10, etc., included in the startup command. Furthermore, if the functions of the on-board device 100 are executed by a virtual machine, the execution unit 4011 may obtain an instance of the virtual machine and execute a honeypot server using the instance.
[0058] The storage unit 402 and the communication unit 403 are similar to the storage unit 202 and the communication unit 203, and therefore a description thereof will be omitted.
[0059] 2, 3, 4, and 6 are merely examples, and all or part of the illustrated functions may be performed using dedicated circuits. Furthermore, programs may be stored or executed using a combination of main and auxiliary storage devices other than those illustrated.
[0060] Next, the flow of countermeasures against an attack using the attack detection device 200, the relay device 300, and the decoy device 400 will be described in more detail. FIG. 7 is a sequence diagram of the processing executed in the system when an attack occurs.
[0061] When an attack is made from an attack source device to a specific in-vehicle device 100, the attack detection device 20 0 detects this (step S11). Attacks can be detected by, for example, monitoring packets passing through relay device 300. When the attack detection device 200 detects an attack, it generates a transfer command and a startup command. Specifically, the attack detection device 200 generates a transfer command including the IP address of the attacking device and the IP address of the in-vehicle device 100, which is the attacked device, and transmits the transfer command to the relay device 300 (step S12). Upon receiving the transfer command, the relay device 300 generates a conversion table as described with reference to FIG. 5 based on the transfer command (step S13).
[0062] Furthermore, the attack detection device 200 generates a command to start a honeypot server and transmits it to the decoy device 400. Upon receiving the command, the decoy device 400 starts up the honeypot server (step S14).
[0063] When the attacking device subsequently transmits a packet related to the attack, the relay device 300 performs address conversion according to the conversion table (step S15). As a result, the destination IP address of the attacking packet is rewritten from the IP address of the in-vehicle device 100, which is the attacked device, to the IP address of the decoy device 400. Furthermore, the packet is forwarded by the relay unit 3011, and thus the packet reaches the decoy device 400. The decoy device 400 processes the packet using the honeypot server (step S16). Specifically, the honeypot server behaves as if the in-vehicle device 100 had responded to the packet related to the attack, and generates a response. The response is transmitted to the relay device 300.
[0064] When a response is sent from the decoy device 400, the relay device 300 rewrites the IP header according to the conversion table (step S17). As a result, the source IP address included in the response is rewritten from the IP address of the decoy device 400 to the IP address of the in-vehicle device 100, which is the attacked device. The converted response is sent to the attack source device via the relay unit 3011.
[0065] 8 is a flowchart of the processing executed by the attack detection device 200. The attack detection device 200 has the function of detecting an attack and initiating countermeasures against the attack, as described above, as well as the function of detecting the end of the attack and performing post-processing. The illustrated process is performed periodically.
[0066] First, in step S21, the attack detection unit 2011 determines that an attack has occurred on any of the in-vehicle devices 100. If it is determined that an attack has occurred, the process proceeds to step S22. In step S22, the attack detection unit 2011 determines the IP address of the attacking device and the IP address of the attacked device.
[0067] Next, in step S23, the processing command unit 2012 generates a start command and transmits it to the decoy device 400. The start command may include information about the vehicle 10 or the in-vehicle device 100 that is the target of the attack. Next, in step S24, the process command unit 2012 generates a transfer command and transmits it to the relay device 300. The transfer command includes the IP address of the attacking device and the IP address of the attacked device.
[0068] If it is determined in step S21 that an attack has not occurred, the process proceeds to step S25. In step S25, the attack detection unit 2011 determines whether an attack has already occurred and whether the attack has ended. In this step, for example, if the attack has not been performed for a certain period of time or more (if no communication from the attack source has occurred or if no attack packets have been detected), it can be determined that the attack has ended. If it is determined that the attack has ended, the process proceeds to step S26. If the attack has not ended, the process is repeated.
[0069] In step S26, the process command unit 2012 generates an end command and sends it to the decoy device 400. The end command is a command to end the execution of the honeypot server that is running. This causes the execution of the honeypot server by the decoy device 400 to end. In step S27, the process command unit 2012 generates a transfer cancellation command and transmits it to the relay device 300. The transfer cancellation command commands the relay device 300 to delete the conversion table. This causes the relay device 300 to terminate forwarding of packets to the decoy device 400.
[0070] As described above, in the communication system of the first embodiment, when the attack detection device 200 detects an attack on any of the in-vehicle devices 100, it instructs the decoy device 400 to start a honeypot server and instructs the relay device 300 to start forwarding packets. The honeypot server simulates the on-board device 100, which is the attacked device, and the relay device 300 rewrites the IP header, so that the attacker can process packets related to the attack without realizing that the guidance to the honeypot has begun.
[0071] (Second embodiment) The second embodiment is an embodiment in which the attack detection device 200 notifies the decoy device 400 of information regarding the driving of the vehicle 10 in which the attacked device, the on-board device 100, is installed, and the decoy device 400 runs a honeypot server based on this information.
[0072] When a connected vehicle is targeted for attack, the attacker may monitor the behavior of the vehicle 10 to confirm the success of the attack. However, if the honeypot server does not return the response the attacker expects, the attacker may change the method and continue the attack. In other words, it is not enough for the honeypot server to simply simulate the response of the in-vehicle device 100; it is preferable that the honeypot server also simulate the driving of the vehicle 10. Therefore, in this embodiment, the attack detection device 200 includes information regarding the driving of the target vehicle 10 (hereinafter referred to as vehicle information) in the startup command, and the decoy device 400 uses the information to simulate the driving of the vehicle 10 using the honeypot server.
[0073] Examples of the vehicle information include the position information, traveling direction, and speed of the vehicle 10. The vehicle information may include other information. The attack detection device 200 collects vehicle information corresponding to the vehicle 10 at the timing of detecting an attack, and transmits a start command including the collected vehicle information to the decoy device 400. In addition, the honeypot server executed by the decoy device 400 generates a virtual vehicle information based on the vehicle information included in the start command. The honeypot server may simulate the behavior of the virtual vehicle under attack and return a response to the attack.
[0074] According to this embodiment, it is possible to provide the attacker with false data showing the success of the attack.
[0075] (Variation) The above-described embodiment is merely an example, and the present disclosure can be modified and implemented as appropriate within the scope that does not deviate from the gist of the disclosure. For example, the processes and means described in this disclosure can be freely combined and implemented as long as no technical contradiction occurs.
[0076] In addition, in the description of the embodiment, the attack detection device 200 and the in-vehicle device 100 are illustrated as separate devices, but the attack detection device 200 and the in-vehicle device 100 may be the same device. In this case, when the in-vehicle device 100 detects that it is under attack, it may notify the relay device 300 and the decoy device 400 of this fact, and in response, each device may start the processing from step S13 onwards.
[0077] Furthermore, even if the attack detection device 200 and the in-vehicle device 100 are separate entities, the in-vehicle device 100 may detect an attack by itself. In this case, the in-vehicle device 100 may notify the attack detection device 200 that it is under attack, and the attack detection device 200, upon receiving the notification, may start processing from step S12 onwards.
[0078] Furthermore, the attack detection device 200 may be divided into a device that only detects attacks and a device that issues first and second commands based on the detection results. Furthermore, the relay device 300 may be divided into a device that generates a conversion table based on a first command and a communication device that performs address conversion based on the conversion table.
[0079] Furthermore, the decoy device 400 may be configured to log the details of the attack received, which makes it possible to collect detailed information about the attack.
[0080] Furthermore, a process described as being performed by one device may be shared and executed by multiple devices. Alternatively, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is realized can be flexibly changed.
[0081] The present disclosure can also be realized by providing a computer program implementing the functions described in the above embodiments to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer via a non-transitory computer-readable storage medium connectable to the computer's system bus or via a network. Non-transitory computer-readable storage media include, for example, any type of disk, such as a magnetic disk (e.g., a floppy disk, a hard disk drive (HDD), etc.), an optical disk (e.g., a CD-ROM, a DVD disk, a Blu-ray disk), a read-only memory (ROM), a random access memory (RAM), an EPROM, an EEPROM, a magnetic card, a flash memory, an optical card, or any type of medium suitable for storing electronic instructions. [Explanation of symbols]
[0082] 10. Vehicle 100...In-vehicle equipment 200 Attack detection device 300 Relay device 400 Decoy Device
Claims
1. An attack detection system including a first device and a second device, The first device comprises: monitoring communications made to a first vehicle connected to the network; When it is detected that an attack on the first vehicle is being carried out from an attack source device, sending a first command to the second device to activate a honeypot server that simulates a vehicle system of the first vehicle; transmitting a second command to a communication device that relays communication to the first vehicle within the network, the second command causing the packet transmitted from the attack source device addressed to the first vehicle to be forwarded to the second device; a first control unit that executes The second device comprises: a second control unit that processes packets sent from the attack source device to the first vehicle and forwarded by the communication device by the honeypot server that simulates a vehicle system of the first vehicle; Attack detection system.
2. the second command includes a command to, when a packet is received having a first IP address corresponding to the attack source device as a source and a second IP address corresponding to the first vehicle as a destination, replace the destination included in the packet from the second IP address with a third IP address corresponding to the second device; The attack detection system according to claim 1 .
3. the second command further includes a command to, when a packet having the third IP address as a source and the first IP address as a destination is received, replace the source included in the packet from the third IP address to the second IP address; The attack detection system according to claim 2 .
4. the first command further includes first information regarding the first vehicle; the second device causes the honeypot server to simulate the first vehicle based on the first information; The attack detection system according to any one of claims 1 to 3.
5. the first control unit transmits a third command to the second device to stop the honeypot server when the attack on the first vehicle is stopped; The attack detection system according to any one of claims 1 to 3.
Citation Information
Patent Citations
Communication monitoring system and method, communication monitoring device, virtual host device, and communication monitoring program
JP2013009185A
Relay device, terminal device, and communication method
JP2016139883A
Server system control device, server system, server system control method, and server system control program
JP2018082288A
System and method for detection and deflection of attacks on in-vehicle controllers and networks
US20220239694A1