Log management device and log management analysis system
The log management device optimizes storage and communication by generating request messages and transmitting security logs at appropriate timings, addressing overflow and communication load issues in vehicles.
Patent Information
- Application Number
- JP2022067805
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-15
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2042-04-15
AI Technical Summary
Security logs from vehicles with limited storage capacity may overflow or consume storage resources when shared with other functions, and frequent communication with central devices increases load and communication volume.
A log management device that includes a log receiving unit, storage unit, transmission timing determination, and a transmitting unit to manage storage and communication efficiently by generating request messages for reception status and transmitting security logs and messages at optimized timings.
The solution effectively utilizes storage resources, reduces communication volume, and minimizes security log deletion processing by managing transmission and storage efficiently.
Smart Images

Figure 0007765872000001 
Figure 0007765872000002 
Figure 0007765872000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a log management analysis system for detecting and analyzing cyber attacks, which mainly consists of a log management device mounted on a mobile body and a center device installed outside the mobile body. [Background technology]
[0002] In recent years, technologies for driver assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication) and vehicle-to-infrastructure communication, have been attracting attention. Accordingly, vehicles are increasingly equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyberattacks is increasing. In light of this, various devices have been proposed that analyze security logs detected in in-vehicle networks and respond to cyberattacks.
[0003] For example, Patent Document 1 discloses a system that includes a log management device mounted on a vehicle and a center device installed outside the moving object. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Publication No. 2022-17889 Summary of the Invention [Problem to be solved by the invention]
[0005] Here, the present inventors have found the following problem. Security logs output from security sensors mounted on vehicles, which are moving objects, are temporarily stored in a storage device connected to a log management device installed on the vehicle. However, because the storage device has a limited capacity, if an overflow occurs, the security logs may not be stored in the storage device. Even if an overflow does not occur, if the storage device is shared with other functions, storing the security logs may consume the storage device's capacity.
[0006] In addition, in the past, when a security log was sent from a log management device to a central device, the log management device would delete the security log from the storage device on the condition that it received a receipt notification from the central device. However, since a receipt notification is generated each time a security log was sent to the central device, communication volume increases. Furthermore, since the security log deletion process occurs sporadically, the load on the log management device increases.
[0007] The present disclosure aims to realize a log management device and the like that can appropriately operate the resources of storage devices connected to the log management device. Another object of the present disclosure is to reduce the amount of communication between the center device and the log management device, and to reduce the amount of security log deletion processing in the log management device.
[0008] Although the above problem is described as an example of a case where the log management device is installed in a vehicle, this is described as an example of the problem. Even when the log management device is not installed in a vehicle, problems such as limited storage capacity and reduced communication volume with the center device can arise. [Means for solving the problem]
[0009] The log management device (100) of the present disclosure is a log management device (100) that transmits a security log generated by a security sensor to a center device (200), a log receiving unit (101) that receives the security log from the security sensor; a log storage unit (103) that stores the security log; a request message generating unit (107) that generates a request message inquiring about the reception status at the center device for all of the security logs stored in the log storage unit; a transmission timing determination unit (108) that determines a transmission timing that is a timing for transmitting the request message; a transmitting unit (105) that transmits the security log to the center device and also transmits the request message to the center device at the transmission timing; It has.
[0010] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]
[0011] With the above-described configuration, the resources of the storage devices connected to the log management device can be appropriately utilized. Furthermore, with the above-described configuration, it is possible to reduce the amount of communication with the center device, and it is also possible to reduce the amount of security log deletion processing in the log management device. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of a log management analysis system according to the present disclosure. [Figure 2] FIG. 1 is a block diagram illustrating a configuration example of a log management device according to an embodiment of the present disclosure. [Figure 3] FIG. 10 illustrates an example of a security log according to an embodiment of the present disclosure. [Figure 4] FIG. 10 illustrates an example of a request message according to an embodiment of the present disclosure. [Figure 5] FIG. 10 illustrates an example of a response message according to an embodiment of the present disclosure. [Figure 6] FIG. 1 is a block diagram illustrating a configuration example of a center device according to an embodiment of the present disclosure. [Figure 7]A flowchart showing the operation of the log management analysis system according to an embodiment of the present disclosure. [Figure 8] FIG. 1 is a block diagram illustrating a form or aspect of a log management device according to an embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0014] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.
[0015] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.
[0016] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.
[0017] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined. The same applies to the examples.
[0018] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.
[0019] 1. Embodiment (1) Overall configuration of log management analysis system 1 First, the overall configuration of a log management analysis system 1 according to this embodiment will be described with reference to FIG.
[0020] The log management analysis system 1 includes a log management device 100 and a center device 200 .
[0021] The log management device 100 is connected to a center device 200 via a communication network 2. The log management device 100 transmits to the center device 200 a "security log" generated by a security sensor. where: The term "security log" does not matter what name it is called, as long as it contains the detection results of the security sensor or an evaluation of the detection results. The "center device" is not limited to a specific name, and may be any device that manages or analyzes security logs received from a log management device.
[0022] In this embodiment, the log management device 100 is "mounted" on a vehicle, which is a "moving body." However, the log management device 100 may also be mounted on a fixed object instead of a moving body. where: "Mobile object" refers to an object that can move at any speed. It also includes cases where the object is stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these. "Mounted" includes not only cases where the device is directly fixed to the mobile body, but also cases where the device is not fixed to the mobile body but moves with the mobile body. For example, cases where the device is carried by a person riding on the mobile body, or cases where the device is mounted on cargo placed on the mobile body, are included.
[0023] The communication lines that make up the communication network 2 may be either wireless communication lines or wired communication lines. Examples of wireless communication lines include communication lines based on mobile communication systems, such as W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. In addition, other communication lines may be used that use wireless communication methods such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), Bluetooth (registered trademark), UWB (Ultra Wide Band), or DSRC (Dedicated Short Range Communication). Examples of wired communication lines include a LAN (Local Area Network) such as Ethernet (registered trademark), an optical fiber line, or a fixed telephone line. Alternatively, the communication line may be a combination of a wireless communication line and a wired communication line. For example, the log management device 100 and a base station device in a cellular system may be connected by a wireless communication method, and the base station device and the center device 200 may be connected by a wired communication method such as a trunk line of a telecommunications carrier or the Internet.
[0024] In this embodiment, an example in which the log management device 100 is mounted on a vehicle will be described, but the log management device 100 does not have to be mounted on a vehicle. Also, an example in which the center device 200 is assumed to be a server device and is not mounted on a vehicle will be described, but the center device 200 may be mounted on a vehicle.
[0025] (2) Configuration of the Log Management Device 100 The configuration of the log management device 100 of this embodiment will be described with reference to FIG.
[0026] The log management device 100 comprises a log receiving unit 101, a buffer 102, a log saving unit 103, a control unit 104, a transmitting unit 105, and a receiving unit 106. The control unit 104 also has a request message generating unit 107, a transmission timing determining unit 108, a deletion instruction unit 109, and a priority setting unit 110.
[0027] The log management device 100 can be configured with a general-purpose CPU (Central Processing Unit), volatile memory such as RAM, non-volatile memory such as ROM, flash memory, or hard disk, various interfaces, and an internal bus connecting these. By executing software on this hardware, the log management device 100 can be configured to perform the functions of each functional block shown in Fig. 2. The same applies to the center device 200 shown in Fig. 6, which will be described later. Of course, the log management device 100 may be realized by dedicated hardware such as an LSI. The same applies to the center device 200.
[0028] In this embodiment, the log management device 100 is assumed to be in the form of an electronic control unit (ECU (Electric Control Unit), hereinafter abbreviated as ECU) as a semi-finished product, but is not limited to this. For example, the log management device 100 may be in the form of a component or a finished product. The log management device 100 may be configured with a single ECU or multiple ECUs. The same applies to the center device 200.
[0029] The log receiving unit 101 is connected to one or more ECUs connected to the log management device 100 via an in-vehicle network, and receives security logs generated by and transmitted from security sensors provided in each ECU. The security sensors monitor each ECU itself and the communications of each ECU, detect abnormalities such as attacks, and report normality or abnormality using the security logs.
[0030] Generally, security logs include both normal logs that report normality and abnormal logs that report abnormality, but this embodiment will be described on the assumption that the security log is an abnormality log, i.e., an abnormality log is received by the log management device 100. Of course, this embodiment may also be applied to cases where the security log is a normal log and an abnormality log, i.e., a case where the log management device 100 receives a normal log or an abnormality log.
[0031] 2, the log receiving unit 101 is connected to ECU1, ECU2, and ECU3 via an in-vehicle network. ECU1 and ECU2 are provided with security sensors that monitor the ECUs themselves and their communications. ECU3 is not provided with a security sensor.
[0032] In addition to the security sensors, ECU1, ECU2, and ECU3 may also have a defense function or a function for generating a log that notifies the operating status of each ECU. This log may be processed in this embodiment instead of or in addition to the security log.
[0033] ECU1, ECU2, and ECU3 may be any ECU, but examples include drive system electronic control units that control the engine, steering, brakes, etc., vehicle body electronic control units that control meters, power windows, etc., information system electronic control units such as navigation systems, or safety control system electronic control units that perform control to prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may not be connected in parallel, but may be classified as master and slave.
[0034] The ECU1, ECU2, and ECU3 may be physical ECUs, or may be ECUs realized by virtual machines using virtualization technology.
[0035] The in-vehicle network can use any communication method, such as CAN (Controller Area Network) or LIN (Local Interconnect Network), as well as Ethernet (registered trademark), Wi-Fi (registered trademark), Bluetooth (registered trademark), etc.
[0036] 3 shows an example of the security log specifications. The security log has the following fields: an ECU ID indicating the identification information of the ECU in which the security sensor is installed; a sensor ID indicating the identification information of the security sensor; an event ID indicating the identification information of the security event; a counter indicating the number of times the event has occurred; and context data indicating details of the security sensor output. The security log may further have a header storing information indicating the protocol version and the state of each field.
[0037] Although Figure 3 shows an example of an abnormal log, normal logs may also have the same specifications as Figure 3. In this case, the context data for normal logs can be omitted. Also, by setting a flag in the header indicating the presence or absence of context data, abnormal logs and normal logs can be distinguished by checking this flag.
[0038] The buffer 102 temporarily stores the security log received by the log receiving unit 101. The buffer 102 may be configured as either a non-volatile memory or a volatile memory, but is preferably configured as a volatile memory with high read / write speeds.
[0039] The log storage unit 103 stores the security log received by the log receiving unit 101 by obtaining the log from the log receiving unit 101 or the buffer 102 via the control unit 104 or directly from the log receiving unit 101 or the buffer 102 . The log storage unit 103 may be configured as either a nonvolatile memory or a volatile memory, but a nonvolatile memory that has a large storage capacity and can store security logs independent of the power supply state is preferable.
[0040] It should be noted that the log storage unit 103 does not necessarily have to store all of the security logs received by the log receiving unit 101. This will be specifically described in the section on the priority setting unit 110.
[0041] The control unit 104 controls the operations of the log receiving unit 101, the buffer 102, the log saving unit 103, the transmitting unit 105, and the receiving unit 106. The control unit 104 also realizes a request message generating unit 107, a transmission timing determining unit 108, a deletion instruction unit 109, and a priority setting unit 110 by itself.
[0042] The request message generation unit 107 generates a "request message" that inquires about the reception status at the center device 200 for all security logs stored in the log storage unit 103. Specifically, the request message generation unit 107 reads the ECU ID, sensor ID, event ID, and counter of all security logs stored in the log storage unit 103, and generates a request message that stores these. This makes it possible to know the type and number of security logs that are stored in the log storage unit 103 and have not yet been deleted. Here, the "request message" may be called by any name as long as it can be understood as a request to the center device. In other words, it does not have to be called a message, and may be called, for example, a command, instruction, etc.
[0043] FIG. 4 is an example of a request message. The request message is assigned a serial number for each security log. The security log with serial number 1 is identified by ECU#1, sensor#1, event#1, and counter#1, which are all 1. The security log with serial number 2 is identified by ECU#1, sensor#2, event#2, and counter#1, which indicates that it was generated in the same ECU as the security log with serial number 1, but by a different security sensor. The security log with serial number 3 is identified by ECU#1, sensor#1, and event#1, which indicates that it is the second security log generated, but it is generated from the same ECU, same security sensor, and same event as the security log with serial number 1. The security log with serial number 4 is identified by ECU#2, sensor#3, event#3, and counter#1, which indicates that it was generated in a different ECU from the security logs with serial numbers 1 to 3.
[0044] Transmission timing determination unit 108 determines the "transmission timing," which is the timing at which the request message generated by request message generation unit 107 is transmitted from transmission unit 105, which will be described later. When determining the transmission timing, transmission timing determination unit 108 can refer to the storage status of the security log in log storage unit 103. A specific method for determining the transmission timing will be described later. Here, "transmission timing" is sufficient as long as the timing for sending the request message can be directly or indirectly identified, and may be, for example, time, duration, or period, or a correlation with the timing for sending the security log.
[0045] The transmitting unit 105 transmits the security log and the request message to the center device 200. That is, the transmitting unit 105 transmits the security log received by the log receiving unit 101 to the center device 200, and also transmits the request message generated by the request message generating unit 107 to the center device 200 at the transmission timing determined by the transmission timing determining unit 108. The security log that has been transmitted is deleted from the buffer 102. Here, "together" means that it is sufficient that the security log and the request message can be transmitted separately, and is not limited to the security log and the request message being transmitted simultaneously or consecutively.
[0046] The timing of sending the security log and the timing of sending the request message may be either related to each other (i.e., synchronized) or unrelated to each other (i.e., not synchronized). An example of the former will be described in Example 1 below, and an example of the latter will be described in Example 2 below.
[0047] The receiving unit 106 receives from the center device 200 a “response message” that is a response from the center device 200 to the request message sent from the sending unit 105 . Here, the "response message" may be any name as long as it can be understood as a response from the center device to a request message. In other words, it does not need to be called a message.
[0048] 5 is an example of a response message. The response message indicates the reception status of each security log identified in the request message. Specifically, the response message indicates whether each security log identified in the request message has been received by the center device 200.
[0049] 5, the security logs with serial numbers 1 and 2 have a reception flag of 1, which indicates that they have been received by the center device 200. In contrast, the security logs with serial numbers 3 and 4 have a reception flag of 0, which indicates that they have not been received by the center device 200. Based on the response message, the transmitting unit 105 may retransmit security logs that have not been received by the center device 200.
[0050] Based on the response message received by the receiving unit 106, the deletion instruction unit 109 deletes the security logs that have been received by the center device 200 from the log storage unit 103. Specifically, in Fig. 5, it has been confirmed that the security logs with serial numbers 1 and 2 have been received by the center device 200, so they are deleted from the log storage unit 103, and it has been confirmed that the security logs with serial numbers 3 and 4 have not been received by the center device 200, so they are not deleted from the log storage unit 103. Note that security logs that have been confirmed not to have been received by the center device 200 are retransmitted from the transmitting unit 105.
[0051] The priority setting unit 110 sets the priority of the security log received by the log receiving unit 101 based on a predetermined criterion. For example, the predetermined criterion may be the type of ECU that generated the security log, the type of security sensor, the type of security event, or / and the number of occurrences of the security event. Alternatively, the distance from the communication ECU or the central ECU (C-ECU) or the hierarchy level can be used as the predetermined criterion.
[0052] For example, if a drivetrain ECU is specified as the predetermined criterion, the priority of the security log generated by the security sensor of the drivetrain ECU is set higher than the priority of the security log generated by the security sensor of another ECU. For example, if a health check event is specified as the predetermined criterion, the priority of the security log relating to the health check event is set higher than the priority of the security log relating to other events. For example, if the predetermined standard specifies that the number of security event occurrences is 3, the priority of security logs in which security events have occurred 3 or more times is set higher than the priority of security logs in which security events have occurred 2 or less times.
[0053] The priority can be set to any number of levels, such as two levels, three levels, or more.
[0054] The priority can be used to determine the order in which security logs are sent and whether or not they need to be saved. For example, a security log set with a high priority is sent from the sending unit 105 before other security logs. Accordingly, a security log set with a high priority is sent immediately, so it is possible to prevent it from being saved in the log saving unit 103. This makes it possible to reduce the amount of data used by the log saving unit 103.
[0055] The priority can be used to determine the order in which security logs are stored in the log storage unit 103. For example, security logs with a higher priority may be stored in the log storage unit 103 before security logs with a lower priority. For example, if there are three levels of priority, high, medium, and low, the logs may be stored in the log storage unit 103 in the order of high, medium, and low. Alternatively, as in the previous paragraph, security logs with a higher priority may not be stored in the log storage unit 103 but may be immediately transmitted to the center device 200, and may be stored in the log storage unit 103 in the order of medium and low priorities.
[0056] (3) Configuration of the Center Device 200 The configuration of the center device 200 of this embodiment will be described with reference to FIG.
[0057] The center device 200 comprises a receiving unit 201 , a control unit 202 , a storage unit 204 , and a transmitting unit 205 .
[0058] The receiving unit 201 receives a security log and a request message from the log management device 100 .
[0059] The control unit 202 controls the operations of the receiving unit 201, the storage unit 204, and the transmitting unit 205. The control unit 202 also realizes a response message generating unit 203 by itself.
[0060] Response message generation unit 202 generates a response message for reporting the reception status of the security log specified in the request message in response to the request message received by reception unit 201. A specific example of the response message is as described in FIG.
[0061] The storage unit 204 stores the security log and the request message received by the receiving unit 201 .
[0062] The transmission unit 203 transmits the response message generated by the response message generation unit 202 to the log management device 100 .
[0063] (4) Specific examples of transmission timing A specific example of a method for determining the transmission timing in transmission timing determination section 108 will be described. (a) Example 1: When the security log and request message transmission timing are asynchronous In this embodiment, the transmitting unit 105 periodically transmits the request message regardless of the timing of transmitting the security log. That is, the transmission timing determining unit 108 determines the "period" for transmitting the request message as the transmission timing. Here, the "period" is sufficient as long as it can specify the time interval for transmitting the request messages, and may be the time between request messages, the number of transmissions of the request messages per predetermined time, or the number of clock ticks. It may also be an increase or decrease from the current period.
[0064] As a more specific example, the transmission timing determination unit 108 determines the cycle based on the "amount of security logs" stored in the log storage unit 103 within a predetermined period. Here, the "amount of security logs" may refer to the number of security logs in addition to the size of the security logs. The number of security logs saved within a predetermined period can be evaluated as the saving frequency.
[0065] The size of the security logs can be used as the quantity of security logs. For example, transmission timing determination unit 108 shortens the cycle when the size of the security logs stored in log storage unit 103 within a predetermined period is equal to or greater than a first reference value, and lengthens the cycle when the size of the security logs stored in log storage unit 103 within a predetermined period is equal to or less than a second reference value. where: The term "equal to or greater than" includes both cases where the first reference value is included and cases where the first reference value is not included. The term "equal to or less than" includes both cases where the second reference value is included and cases where the second reference value is not included.
[0066] For example, the predetermined period is 1 hour, the first reference value is 2 GB, the second reference value is 500 MB, the standard cycle is 4 hours, and the increase / decrease amount is 20%. In this case, if the size of the security log stored in the log storage unit 103 within the past hour is 2 GB or more, the transmission timing determination unit 108 subtracts 20% from the cycle that had been applied up to that point, and if it is 500 MB or less, the transmission timing determination unit 108 adds 20% to the cycle that had been applied up to that point.
[0067] Alternatively, the number of security logs can be used as the quantity of security logs. For example, transmission timing determination unit 108 shortens the cycle when the number of security logs stored in log storage unit 103 within a predetermined period is equal to or greater than a first reference value, and lengthens the cycle when the number of security logs stored in log storage unit 103 within a predetermined period is equal to or less than a second reference value. The number of security logs stored in log storage unit 103 within a predetermined period is synonymous with the security log storage frequency.
[0068] For example, the predetermined period is 1 hour, the first reference value is 10, the second reference value is 1, the standard cycle is 4 hours, and the increase / decrease range is 20%. In this case, if the number of security logs stored in the log storage unit 103 within the past hour is 10 or more, the transmission timing determination unit 108 subtracts 20% from the cycle that had been applied up to that point, and if the number is 1 or less, the transmission timing determination unit 108 adds 20% to the cycle that had been applied up to that point.
[0069] The amount of security logs can also be determined by using both the size of the security logs and the number of security logs. For example, transmission timing determination unit 108 shortens the cycle when the size of the security logs stored in log storage unit 103 within a predetermined period is equal to or greater than a first reference value, and lengthens the cycle when the number of security logs stored in log storage unit 103 within a predetermined period is equal to or less than a second reference value.
[0070] The reason why the first reference value is the size of the security log is that the first reference value is intended to free up log storage unit 103, and therefore it is desirable to focus on the capacity of log storage unit 103. The reason why the second reference value is the number of security logs is that the reason why the second reference value is intended to evaluate the risk of cyber attacks, and therefore it is desirable to focus on the number of times security logs are received.
[0071] In the previous two examples, the first reference value and the second reference value are different values, but the first reference value and the second reference value may be the same value.
[0072] Alternatively, the size of the security logs stored in the log storage unit 103 or the ratio of the size of the security logs stored in the log storage unit 103 to the storage capacity of the log storage unit 103 can be used as the amount of security logs.
[0073] As described above, according to the transmission timing determination method of the transmission timing determination unit 108 of the first embodiment, a period is determined as the transmission timing, so that the request message can be sent regardless of the transmission timing of the security log, and as a result, the memory space of the log storage unit 103 can be released appropriately at an appropriate timing depending on the storage status of the security log in the log storage unit 103. Furthermore, since the reception status at the center device 200 for multiple security logs can be reported at once, the amount of communication traffic can be reduced, and the amount of security log deletion processing at the log management device 100 can also be reduced.
[0074] (b) Example 2: When the security log and request message transmission timing are synchronized In this embodiment, the transmitting unit 105 transmits a request message at the same time as the security log is transmitted. However, a request message is not transmitted at every security log transmission timing. In other words, the transmission timing determining unit 108 determines whether or not to transmit the request message "simultaneously" with the transmission of the security log. In this embodiment, the timing at which the transmission timing is determined by the transmission timing determining unit 108 is the time when the security log is transmitted. Here, "simultaneous" includes not only simultaneous in the narrow sense, but also consecutive.
[0075] As a more specific example, the transmission timing determination unit 108 determines whether to send a request message at the same time as sending the security log based on the "amount of security logs" stored in the log storage unit 103 within a predetermined period. Here, the "amount of security logs" may refer to the number of security logs in addition to the size of the security logs. The number of security logs saved within a predetermined period can be evaluated as the saving frequency.
[0076] The size of the security log can be used as the amount of security logs. For example, if the size of the security logs stored in the log storage unit 103 within a predetermined period is equal to or greater than a first reference value, the transmission timing determination unit 108 determines to transmit a request message simultaneously with the transmission of the security log. Here, "equal to or greater than" includes both cases where the first reference value is included and cases where the first reference value is not included.
[0077] For example, the predetermined period is set to one hour, and the first reference value is set to 2 GB. In this case, if the size of the security log stored in the log storage unit 103 within the past hour is 2 GB or more, the transmission timing determination unit 108 determines to transmit a request message at the same time as transmitting the security log.
[0078] Alternatively, the number of security logs can be used as the amount of security logs. For example, if the number of security logs stored in log storage unit 103 within a predetermined period is equal to or greater than a first reference value, transmission timing determination unit 108 determines to transmit a request message simultaneously with the transmission of the security logs.
[0079] For example, the predetermined period is one hour, and the first reference value is 10. In this case, if the number of security logs stored in the log storage unit 103 within the past hour is 10 or more, the transmission timing determination unit 108 determines to send a request message at the same time as sending the security logs.
[0080] In this embodiment, the transmission timing determination unit 108 determines the transmission timing when the security log is transmitted, but this may be unrelated to the time when the security log is transmitted. For example, the transmission timing may be determined periodically, and a request message may be sent simultaneously with the security log sent to the center device 200 immediately after the transmission timing is determined. In this case, the period for determining the transmission timing may be fixed or variable. For example, the period for determining the transmission timing may be changed based on the frequency with which the amount of security logs stored in the log storage unit 103 within a predetermined period exceeds a first reference value.
[0081] As described above, according to the transmission timing determination method of the transmission timing determination unit 108 of the second embodiment, whether or not to send a request message is determined to coincide with the time when the security log is sent as the transmission timing, so that the request message can be sent at a timing that coincides with the transmission timing of the security log, and as a result, the memory space of the log storage unit 103 can be released appropriately at an appropriate timing depending on the storage status of the security log in the log storage unit 103. Furthermore, since the reception status at the center device 200 for multiple security logs can be reported at once, the amount of communication traffic can be reduced, and the amount of security log deletion processing at the log management device 100 can also be reduced.
[0082] (5) Example of operation of the log management analysis system The operation of the log management analysis system 1 of this embodiment, that is, the log management device 100 and the center device 200, will be described using the flowchart of FIG. The following operations not only indicate a log management method executed by the log management device 100 or the center device 200 but also indicate the processing procedures of a log management program that can be executed by the log management device 100 or the center device 200. These processes are not limited to the order shown in Fig. 7. In other words, the order may be changed as long as there are no constraints, such as a relationship in which a step uses the result of a previous step.
[0083] The log receiving unit 101 of the log management device 100 receives a security log from a security sensor (S101). The log storage unit 103 stores the security log received in S101 (S102). The request message generating unit 107 generates a request message inquiring about the reception status at the center device 200 for all security logs stored in the log storage unit 103 (S103). The transmission timing determination unit 108 determines the transmission timing, which is the timing for transmitting the request message (S104). The transmitting unit 105 transmits the request message generated in S103 to the center device 200 at the transmission timing determined in S104 (S105).
[0084] The receiving unit 201 of the center device 200 receives a request message from the log management device 100 (S201). In response to the request message received in S201, the response message generation unit 203 generates a response message for reporting the reception status of the security log specified in the request message (S202). The transmitting unit 205 transmits the response message generated in S202 to the log management device 100 (S203).
[0085] The receiving unit 106 of the log management device receives from the center device 200 a response message that is a response to the request message generated in S103 and transmitted in S105 (S106). Based on the response message received in S106, the deletion instruction unit 109 deletes the security log already received by the center device 200 from the log storage unit 103 (S107).
[0086] Note that S102 and S103 do not necessarily need to be consecutive in time, and may be executed independently. For example, in the case of the first embodiment, the request message may be generated in accordance with the period for transmitting the request message, regardless of the timing of S102. Furthermore, in the case of the second embodiment, the request message may be generated following the timing of S102, but the amount of security logs stored in the log storage unit 103 may be referenced and the request message may be generated as appropriate, regardless of the timing of S102.
[0087] 7, the transmission timing of the security log stored in S102 may be appropriately transmitted from the transmitting unit 105. For example, in the case of the first embodiment, the security log received in S101 or the security log stored in S102 may be transmitted sequentially in the order in which they were stored in the buffer 102 or in the order of priority. In the case of the second embodiment, when transmitting the security log, S103 to S104 may be executed, and if the conditions are met, a request message may be transmitted in S105 together with the security log.
[0088] (6) Summary As described above, according to this embodiment, a request message is generated for all security logs stored in the log storage unit 103, and security logs already received by the center device 200 are deleted from the log storage unit 103 based on a response message that is a response to the request message. This reduces the amount of communication between the log management device 100 and the center device 200, and also reduces the amount of security log deletion processing in the log management device 100. Furthermore, according to this embodiment, the timing for sending a request message is determined based on the amount of security logs stored in the log storage unit 103, thereby preventing the log storage unit 103 from overflowing or becoming overwhelmed with storage space.
[0089] (7) Aspects of the Log Management Device 100 8(a) is the log management device 100 of the embodiment already described. The log management device 100 is realized by an ECU that is capable of communicating with a center device 200, which is an external device, i.e., has a communication function. The log management device 100 shown in Fig. 8(b) is an embodiment in which the ECU that realizes the log management device 100 and the communication ECU are separated. In this case, the transmitter 105 and receiver 106 of the log management device 100 transmit and receive request messages and response messages to and from the center device 200 via the in-vehicle network and the communication ECU. The log management device 100 in the embodiment shown in Fig. 8(a) or 8(b) can be realized as one function of the communication ECU, central ECU, or gateway ECU. The log management device 100 shown in FIG. 8(c) is realized by a dedicated ECU that realizes the log management function. The log management device 100 shown in FIG. 8(d) is realized by a general-purpose ECU having a security sensor (SS).
[0090] In this way, the log management device 100 can be realized by various ECUs in an in-vehicle network.
[0091] 2. Summary The features of the log management device, center device, and log management analysis system in each embodiment of the present invention have been described above.
[0092] The terms used in each embodiment are merely examples and may be replaced with synonymous terms or terms having the same functions.
[0093] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.
[0094] The order of the functional blocks that can be understood as the processes, flows, and methods described in each embodiment may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.
[0095] The terms first, second, through Nth (N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same type, and do not limit the order or superiority or inferiority.
[0096] Each embodiment is based on a vehicle log management device that is installed in a vehicle, but the present invention also includes dedicated or general-purpose log management devices other than those for vehicles, unless otherwise limited in the claims.
[0097] In each embodiment, the log management device disclosed in each embodiment has been described on the assumption that it is mounted on a vehicle, but it may also be carried by a pedestrian.
[0098] The log management device and center device of the present invention may take the following forms. The components may take the form of semiconductor elements, semiconductor circuits, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU), an electronic control unit, and a system board. Finished product forms include mobile phones, smartphones, mobile routers, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.
[0099] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log management device and the center device.
[0100] It is assumed that the center device of the present invention is used for the purpose of providing various services, and in providing such services, the center device of the present invention is used, the method of the present invention is used, and / or the program of the present invention is executed.
[0101] In addition, the present invention can be realized not only by dedicated hardware having the configuration and functions described in each embodiment, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.
[0102] A program for the device of the present invention that is stored in a non-transient physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can also be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]
[0103] The log management device of the present invention has been described as an electronic control device for vehicles primarily mounted on automobiles, but it can also be applied to all types of moving objects, including motorcycles, motorized bicycles, trains, pedestrians, ships, aircraft, etc. The present invention is also applicable to devices used for a variety of purposes, such as mobile phones, tablets, and game consoles. [Explanation of symbols]
[0104] 100 Log management device, 101 Log receiving unit, 102 Buffer, 103 Log storage unit, 104 Control unit, 105 Transmission unit, 106 Reception unit, 107 Request message generation unit, 108 Transmission timing determination unit, 109 Delete instruction unit, 110 Priority setting unit, 200 Center device, 201 Reception unit, 202 Control unit, 203 Response message generation unit, 204 Storage unit, 205 Transmission unit
Claims
1. A log management device (100) that transmits a security log generated by a security sensor to a center device (200), a log receiving unit (101) that receives the security log from the security sensor; a log storage unit (103) for storing the security log; a request message generating unit (107) that generates a request message inquiring about the reception status at the center device for all of the security logs stored in the log storage unit; a transmission timing determination unit (108) that determines a transmission timing that is a timing for transmitting the request message; a transmission unit (105) that transmits the security log to the center device and transmits the request message to the center device at the transmission timing; Log management device (100).
2. a receiving unit (106) for receiving a response message from the center device, the response message being a response to the request message; a deletion instruction unit (109) that deletes the security log that has been received by the center device from the log storage unit based on the response message; The log management device according to claim 1.
3. the transmission timing determination unit determines a period for transmitting the request message as the transmission timing. The log management device according to claim 1.
4. the transmission timing determination unit determines the period based on the amount of the security logs stored in the log storage unit within a predetermined period.
4. The log management device according to claim 3.
5. the transmission timing determination unit shortens the period when the amount of security logs is equal to or greater than a first reference value, and lengthens the period when the amount of security logs is equal to or less than a second reference value; 5. The log management device according to claim 4.
6. the transmission timing determination unit shortens the cycle when the size of the security logs stored in the log storage unit within a predetermined period is equal to or greater than a first reference value, and lengthens the cycle when the number of the security logs stored in the log storage unit within a predetermined period is equal to or less than a second reference value; 5. The log management device according to claim 4.
7. the transmission timing determination unit determines, as the transmission timing, whether to transmit the request message simultaneously with the transmission of the security log; The log management device according to claim 1.
8. the transmission timing determination unit determines whether to transmit the request message simultaneously with transmitting the security log based on the amount of the security log stored in the log storage unit within a predetermined period.
8. The log management device according to claim 7.
9. the transmission timing determination unit determines to transmit the request message simultaneously with transmitting the security log when the volume of the security log is equal to or greater than a first reference value; 9. The log management device according to claim 8.
10. Furthermore, a priority setting unit (110) is provided for setting the priority of the security log based on a predetermined standard, Among the security logs received by the log receiving unit, the security logs for which a high priority has been set by the priority setting unit are not stored in the log storage unit. The log management device according to claim 1.
11. The log management device is mounted on a mobile object. The log management device according to any one of claims 1 to 10.
12. A log management analysis system (1) comprising a log management device (100) that transmits security logs generated by security sensors to a center device (200) and the center device (200), The log management device (100) a log receiving unit (101) that receives the security log from the security sensor; a log storage unit (103) for storing the security log; a request message generating unit (107) that generates a request message inquiring about the reception status at the center device for all of the security logs stored in the log storage unit; a transmission timing determination unit (108) that determines a transmission timing that is a timing for transmitting the request message; a transmitting unit (105) that transmits the security log to the center device and also transmits the request message to the center device at the transmission timing; a receiving unit (106) for receiving a response message from the center device, the response message being a response to the request message; a deletion instruction unit (109) that deletes the security log already received by the center device from the log storage unit based on the response message, The center device (200) a receiving unit (201) that receives the security log and the request message from the log management device; a response message generating unit (203) that generates the response message for reporting the reception status of the security log specified in the request message in response to the request message; a transmission unit (205) that transmits the response message to the log management device, Log management analysis system (1).
13. A log management method executed by a log management device (100) that transmits a security log generated by a security sensor to a center device (200), comprising: Receive the security log from the security sensor (S101); The security log is stored in a log storage unit (S102). A request message is generated to inquire about the reception status at the center device for all of the security logs stored in the log storage unit (S103). A transmission timing is determined as a timing for transmitting the request message (S104). Transmitting the security log to the center device and transmitting the request message to the center device at the transmission timing (S105); Log management methods.
14. A log management program executable by a log management device (100) that transmits a security log generated by a security sensor to a center device (200), Receive the security log from the security sensor (S101); The security log is stored in a log storage unit (S102). A request message is generated to inquire about the reception status at the center device for all of the security logs stored in the log storage unit (S103). A transmission timing is determined as a timing for transmitting the request message (S104). Transmitting the security log to the center device and transmitting the request message to the center device at the transmission timing (S105); Log management program.
Citation Information
Patent Citations
Program data rewriting program
JP2003271410A
Operation log collection system and operation log collection method
JP2009070059A
Information management system
JP2010033467A
Log management apparatus, and security attack detection and analysis system
JP2022017889A