Attack Analysis Equipment

The attack analysis device differentiates cyberattacks from malfunctions in vehicles by analyzing the distance and security level between event occurrence points, effectively addressing delayed recognition and reducing response time and costs.

JP7773498B2Active Publication Date: 2025-11-19ASTEMO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023045480
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-22
Publication Date
2025-11-19
Estimated Expiration
2043-03-22

AI Technical Summary

Technical Problem

Existing technologies fail to distinguish between cyberattacks and malfunctions in vehicles, leading to delayed recognition of cyberattacks and increased exposure to further attacks, necessitating a cost-effective and timely determination of abnormalities in on-board devices.

Method used

An attack analysis device that includes an abnormality acquisition unit, a security event detection unit, a distance acquisition unit, and a determination unit to determine the correlation between an abnormal event and a security event based on the distance between their occurrence points, utilizing a directed graph to weight distances by security level.

Benefits of technology

Enables rapid differentiation between cyberattacks and malfunctions by determining the correlation between abnormal events and security events, reducing response time and costs, and prioritizing further investigation where necessary.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007773498000001
    Figure 0007773498000001
  • Figure 0007773498000002
    Figure 0007773498000002
  • Figure 0007773498000003
    Figure 0007773498000003
Patent Text Reader

Abstract

To easily determine, when an abnormality occurs in an in-vehicle apparatus, whether or not the abnormality is due to an external attack.SOLUTION: An attack analysis device according to the present invention comprises: an abnormality acquisition unit that acquires information relating to an abnormal event of an in-vehicle device; a security event detection unit that detects a security event of the in-vehicle deice; a distance acquisition unit that acquires the distance of the shortest route connecting an abnormal event occurrence point, at which the abnormal event occurred, and a security event occurrence point, at which the security event occurred; and a determination unit that determines a relation between the abnormal event and the security event on the basis of the distance.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an attack analysis device that, when an abnormality or a symptom thereof occurs in an on-board device mounted on a vehicle, determines whether the abnormality is the result of an external attack. [Background technology]

[0002] As IoT advances, with everything becoming connected to the Internet, the automotive industry is also moving towards IoT, with connected cars and self-driving cars. However, while this IoT adoption of automobiles brings convenience, it also increases the risk of cyber attacks via the Internet.

[0003] Patent Documents 1 to 3 are examples of technologies for detecting cyber-attacks against vehicles. Patent Document 1 discloses a technology for identifying the phenomena that occurred in association with each malfunction event by comparing a group of phenomena that represent the circumstances of the malfunction event with a group of causes that caused the malfunction event.

[0004] Patent document 2 discloses an information processing device having a generation unit that generates a graph structure showing the association between a process and an object related to the process from a log acquired from a device, and an identification unit that, when any object of the device is specified, identifies a process related to the specified object based on the generated graph structure and identifies an object related to the identified process.

[0005] Patent Document 3 discloses a cyber-attack analysis system that can collect cyber-attack event information and identify which attacks are linked to cyber-attacks experienced by drivers. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Publication No. 07-013617 [Patent Document 2] International Publication No. 2020 / 075808 [Patent Document 3] Patent Publication No. 2021-117568 Summary of the Invention [Problem to be solved by the invention]

[0007] When a vehicle is the victim of a cyberattack, some kind of abnormality will naturally occur in some of the vehicle's equipment. However, in recent years, cyberattacks have become more sophisticated, and vehicle owners who experience an abnormality are likely to assume that the abnormality is simply due to a malfunction. Owners who make this judgment are likely to take their vehicle to a repair shop or report the malfunction to the customer center, and the vehicle provider will need to respond to this.

[0008] However, if an abnormality occurring in a vehicle is treated as simply a malfunction, even though it is actually the result of a cyberattack, the owner will not be aware that they have been subjected to a cyberattack, increasing the risk of exposure to further attacks by the attacker. Furthermore, even if it is discovered that the abnormality is the result of a cyberattack during a later inspection, it is likely that a long time has already passed since the abnormality occurred, and by the time this is discovered, the vehicle may have already been subjected to further attacks by the attacker. Therefore, it is necessary to quickly determine whether an abnormality occurring in a vehicle is the result of a cyberattack.

[0009] To distinguish between a cyber attack and a simple malfunction, vehicle providers must, for example, establish a Product Security Incident Response Team (PSIRT) to handle safety management aimed at improving the security level of their products and services, provide user support in terms of security, and prepare to respond when product / service-related incidents occur, but this increases both time and costs.

[0010] The technologies described in Patent Documents 1 to 3 also relate to diagnosing abnormalities that occur in vehicles, such as hacking, but even these technologies cannot distinguish between whether the abnormality that occurs in the vehicle is due to an attack or a simple malfunction.

[0011] The present invention has been made in consideration of the above-mentioned problems, and aims to provide an attack analysis device that can easily determine whether an abnormality occurring in an on-board device is the result of an external attack. [Means for solving the problem]

[0012] In order to solve the above problems, the attack analysis device of the present invention includes an abnormality acquisition unit that acquires information regarding an abnormal event in an on-board device, a security event detection unit that detects a security event in the on-board device, a distance acquisition unit that acquires the distance of the shortest path connecting the abnormal event occurrence point where the abnormal event occurred and the security event occurrence point where the security event occurred, and a determination unit that determines the correlation between the abnormal event and the security event based on the distance. [Effects of the Invention]

[0013] According to the present invention, by utilizing the distance between an abnormal event and a security event, it becomes possible to easily determine whether an abnormality occurring in an in-vehicle device is the result of an external attack. Further features related to the present invention will become apparent from the description of the present specification and the accompanying drawings. Furthermore, problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]

[0014] [Figure 1] This is an overview diagram showing the operations required of each department / organization during the maintenance phase of each phase related to automobile supply. [Figure 2] 1 is a block diagram showing an overview of an entire system including an attack analysis device (analysis server) according to the present invention. [Figure 3]FIG. 1 is a diagram for explaining the distance between an abnormal event and a security event. [Figure 4] A diagram showing the distance between abnormal events and security events in a directed graph. [Figure 5] 10 is a flowchart showing a process executed by an attack analysis device. DETAILED DESCRIPTION OF THE INVENTION

[0015] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0016] Hereinafter, an embodiment will be described with reference to the drawings. Figure 1 is an overview diagram showing the operations required of each department / organization in the maintenance phase of each phase related to automobile supply.

[0017] When supplying vehicles to consumers, automobile suppliers typically operate through the design to maintenance phases shown in Figure 1. In recent years, there has been a demand for diversification of customer support, especially in the maintenance phase.

[0018] Specifically, when a customer notices an abnormality in their vehicle, they first assume that a malfunction has occurred and report it to the customer center, as described above. After that, as shown in the figure, the customer center transmits various requests and information to the quality assurance department, development department, and supplier, who then repair the product and respond to the customer with the results of the investigation.

[0019] In parallel with the above process, if threat / vulnerability information or incident information (such as logs related to security events) is detected by external organizations such as dealers or repair shops, or by the Vehicle Security Operation Center (VSOC), which manages security during operation after a vehicle is shipped, it is reported to the PSIRT mentioned above, and the PSIRT then passes the information on to the quality assurance department, development department, and suppliers.

[0020] As mentioned above, if a PSIRT is established from the perspective of ensuring security, when any abnormality or the possibility of an abnormality occurs in a vehicle, the initial contact points for receiving reports will be dispersed, which increases the amount of work required to distinguish between malfunctions and cyber attacks, leading to delays in responding to vehicle abnormalities.

[0021] The present invention has been made based on this background. Figure 2 shows an overview of the entire system including the attack analysis device according to the present invention.

[0022] An attack analysis device according to an embodiment of the present invention is implemented, for example, as an analysis server 1 on a cloud. As shown in FIG. 2, the analysis server 1 is connected to a VSOC 3 and a vehicle 4 via a network 2. The analysis server is not limited to being implemented on a cloud, and may be installed in each vehicle as hardware equipped with a CPU and memory.

[0023] The analysis server 1 has a communication unit 11, a display unit 12, a judgment unit 13, a distance acquisition unit 14, a security event acquisition unit 15, an abnormality acquisition unit 16, a point-to-point distance table 17, a security event location table 18, an abnormal event location table 19, a security event memory unit 20, and an abnormal event memory unit 21.

[0024] The VSOC 3 has a communication unit 31 and a security event detection unit 32. The vehicle 4 has a communication unit 41 and a plurality of ECUs (Electronic Control Units) 42. The ECUs 42 are in-vehicle devices related to various control systems of the vehicle, each capable of performing security self-diagnosis.

[0025] The communication unit 11 of the analysis server 1 transmits a request message to the communication unit 41 of each ECU 42 of the vehicle 4 and receives a response message from each ECU 42. The communication unit 11 also transmits and receives data to and from the communication unit 31 of the VSOC 3.

[0026] The display unit 12 is configured as a display that displays various information. The determination unit 13 determines the relevance between the abnormal phenomenon of the vehicle and the security event based on the distance acquired by the distance acquisition unit 14, as will be described in detail later.

[0027] The distance acquisition unit 14 acquires the physical or logical distance between a detected abnormal event of the vehicle and a security event. The security event acquisition unit 15 acquires and records a security event that has occurred in the vehicle in response to a security event detection signal received from the security event detection unit 32 of the VSOC 3. The abnormality acquisition unit 16 acquires information about an abnormality that has occurred in any ECU 42 of the vehicle 4.

[0028] Here, the information about the abnormality acquired by the abnormality acquisition unit 16 will be described. When some abnormality occurs in the ECU 42 of the vehicle 4, a diagnostic trouble code (DTC) indicating the type of the abnormality is issued. A DTC is a 3-byte code that indicates an abnormal state of the vehicle, and is defined in ISO 15031-6.

[0029] DTC codes have standardized parameter fields and OEM-defined parameter fields, the latter of which can be used independently by OEMs.DTCs use a one-byte status flag (FTB: Failure Type Byte) to indicate the status of the corresponding DTC code (whether it is a confirmed failure or an unconfirmed failure, etc.).

[0030] In addition, DTCs may also include DTC snapshot data, which records ECU control data at the time the DTC occurs, and DTC extended data, which records the frequency of malfunctions and the odometer value at the time the malfunction first occurred, in order to help determine the cause of the malfunction.

[0031] The abnormality acquisition unit 16 acquires and stores information about DTCs generated in one ECU and / or multiple ECUs together with time stamps as a history of abnormal events.

[0032] The point-to-point distance table 17 is a table that records information about the physical / logical distance between each component within the vehicle 4. Here, the physical / logical distance in this invention does not indicate a simple two-dimensional distance between the components, but represents a security gap, which will be described in detail later. The security event point table 18 is a table that records the association between a security event and the point within the vehicle 4 where the security event occurs. The abnormal event point table 19 is a table that records the association between an abnormal event and the point within the vehicle 4 where the abnormal event occurs.

[0033] Security events that have occurred in the past are recorded as time-series data in the security event storage unit 20. Similarly, abnormal events that have occurred in the past are recorded as time-series data in the abnormal event storage unit 21.

[0034] As described above, the VSOC 3 manages security during operation after the vehicle is shipped. The communication unit 31 receives threat and vulnerability information from the vehicle, and the security event detection unit 32 detects the information as a security event and transmits it to the communication unit 11 of the analysis server 1 via the communication unit 31.

[0035] When any threat or vulnerability information is detected, each ECU 42 in the vehicle 4 notifies the communication unit 31 of the VSOC 3 via the communication unit 41. When an abnormal event occurs, the ECU 42 transmits a DTC corresponding to the abnormality to the communication unit 11 of the analysis server 1.

[0036] Next, the physical / logical distance between an abnormal event occurring in the ECU 42 in the vehicle 4 and a security event will be described with reference to FIG.

[0037] As shown in Figure 3, components within a vehicle 4 are connected by physical elements (solid lines) based on hardware or logical elements (dotted lines) based on software. The numerical values ​​on each connection indicate the distance of the connection, and a value of 0 means that it takes virtually no time to send or receive data. This can also be said to correspond to the effort required for a third party to move between components in an attack. Note that for ease of explanation, distance values ​​in Figure 3 are only 0 and 1, but it goes without saying that the actual distance will vary depending on the vehicle model, etc.

[0038] 3, it is assumed that an abnormal event has occurred in the ECU and that a DTC represented by code P0120 has been issued from the throttle position sensor to the abnormality acquisition unit 16 of the analysis server 1. This DTC indicates that a short circuit or an open circuit has occurred in the throttle position sensor circuit.

[0039] Meanwhile, the VSOC 3 detects that a MAC error has occurred in the communication path between the engine ECU and the CGW (Central Gate Way) in the vehicle as security event 1, and that a user authentication error has occurred when an IVI (In-Vehicle Infotainment) application is executed as security event 2, and notifies the security event acquisition unit 15 of the analysis server 1. Here, the MAC error means that access control using the MAC address unique to each ECU has failed, and the user authentication error means that user authentication control required when starting up the computer has failed.

[0040] The shortest path between abnormal event A and security event 1 is security event 1 → engine ECU:CAN3 → engine ECU:OS → engine ECU:application → throttle position sensor:sensor, and the distance is 2.

[0041] On the other hand, the shortest path between abnormal event A and security event 2 is security event 2 → IVI:Application → IVI:OS → IVI:Ethernet2 → CGW:EthernetX → CGW:OS → CGW:CAN X → Engine ECU:CAN3 → Engine ECU:OS → Engine ECU:Application → Throttle Position Sensor:Sensor, and the distance is 8.

[0042] From the above, it is determined that abnormal event A is highly related to security event 1. By setting the distance threshold to a predetermined value, when an abnormal event occurs, if there are no security events that have occurred within a range of the threshold, it becomes possible to quickly determine that the abnormal event is not an attack but simply a malfunction.

[0043] In Figure 3 used in the above explanation, the direction of the distance between components is not taken into consideration. On the other hand, Figure 4 shows a directed graph in which the nodes of the components are connected by directed edges, taking into consideration the direction of the distance between components. As shown in Figure 4, the distance in the incoming direction and the outgoing direction may differ depending on the security level of the component, etc. In other words, the distance of a directed edge in the direction toward a component with a high security level is weighted relatively more heavily than the distance of a directed edge in the direction toward a component with a low security level, and is determined to be a long distance.

[0044] By using such a directed graph, it becomes possible to more accurately determine the relationship between an abnormal phenomenon and a security event. Note that this directed graph and edge distance are linked to, for example, the vehicle model identification number or the vehicle individual identification number of the vehicle in which the on-board device is installed.

[0045] FIG. 5 is a flowchart showing the processing executed by the attack analysis device according to the present invention described above.

[0046] First, the abnormality acquisition unit 16 acquires an abnormality log by receiving a DTC code from an ECU in the vehicle (step 501). Next, the abnormality acquisition unit 16 refers to the abnormal event location table 19 to identify the location where the abnormal event occurred and stores it in the abnormal event storage unit 21 (step 502).

[0047] Next, the security event acquisition unit 15 refers to the security event storage unit 20 and extracts security events that occurred within a predetermined time before the occurrence of the abnormal event accepted in step 501 (step 503). Subsequently, the security event acquisition unit 15 refers to the security event location table 18 for each security event extracted in step 503 to identify the location of occurrence (step 504).

[0048] Next, the determination unit 13 refers to the point-to-point distance table 17 and calculates the shortest path and its distance between the anomaly occurrence point and the security event occurrence point identified in steps 502 and 504 (step 505). This shortest path can be calculated using Dijkstra's algorithm, which is an algorithm for finding the shortest route starting from a certain point on a graph (solving the single-source shortest route problem).

[0049] The determination unit 13 then compares the distance calculated in step 505 to determine whether it is equal to or less than a predetermined threshold (step 506). If the distance is equal to or less than the threshold, it determines that there is an association between the abnormal phenomenon and the security event (step 507), and if the distance is greater than the threshold, it determines that there is no association (step 508). Finally, the determination unit 13 lists the results of the determination for all security events and returns them to the display unit 12 for display (step 509). Furthermore, if it determines that there is an association in step 507, it may determine that it is necessary to perform a log analysis of the route between the point where the abnormal phenomenon occurred and the point where the security event occurred, and output this information as well.

[0050] As explained above, according to the present invention, the correlation between an anomalous event and a security event is determined by focusing on the distance between the points of occurrence. This makes it possible to prioritize the investigation of security events that are likely to have caused the anomalous event, thereby preventing an increase in man-hours and the overlooking of attacks.

[0051] According to the embodiment of the present invention described above, the following advantageous effects are achieved. (1) The attack analysis device of the present invention includes an abnormality acquisition unit that acquires information about an abnormal event in an on-board device, a security event detection unit that detects a security event in the on-board device, a distance acquisition unit that acquires the distance of the shortest path connecting an abnormal event occurrence point where the abnormal event occurred and a security event occurrence point where the security event occurred, and a determination unit that determines the correlation between the abnormal event and the security event based on the distance.

[0052] With the above configuration, when an abnormality occurs in an in-vehicle device, it becomes possible to easily determine whether or not the abnormality is the result of an external attack.

[0053] (2) The distance acquisition unit acquires the distance based on either a physical hardware component or a logical software component that exists between the point where the abnormality occurred and the point where the security event occurred.

[0054] (3) The distance acquisition unit acquires the distance by weighting according to the security type of the physical or logical component. The more critical the security, the higher the barrier to attacking the component, i.e., the longer the distance, so it is preferable to deal with it in this way.

[0055] (4) The distance acquisition unit acquires the distance based on a directed graph in which each node of the physical or logical component is connected by a directed edge. The process of (3) is specifically executed in this manner.

[0056] (5) The distance acquisition unit weights the directed edges of the directed graph based on the edge distances assigned to them, and the directed graph and edge distances are linked to the vehicle model identification number or the individual vehicle identification number of the vehicle in which the on-board device is installed. This makes it possible to appropriately execute the processes (3) and (4) based on the information of each vehicle.

[0057] (6) The determination unit further determines whether to perform log analysis on the path between the location where the abnormality occurred and the location where the security event occurred based on the distance, thereby making it possible to determine, while prioritizing, whether further detailed investigation is necessary based on the correlation between the abnormality and the security event.

[0058] The technical scope of the present invention is not limited to the scope of the above-described embodiments, and various modifications are included without departing from the main features of the present invention. Therefore, the above-described embodiments are merely illustrative and should not be interpreted as limiting. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations, and all of these are within the scope of the present invention. [Explanation of symbols]

[0059] 1 Analysis server (attack analysis device), 13 Judgment unit, 14 Distance acquisition unit, 15 Security event acquisition unit, 16 Abnormality acquisition unit, 42 ECU

Claims

1. an abnormality acquisition unit that acquires information about an abnormal event in the in-vehicle device; a security event detection unit that detects a security event of the in-vehicle device; a distance acquisition unit that acquires the distance of the shortest path connecting the abnormality occurrence point where the abnormal event occurred and the security event occurrence point where the security event occurred; a determination unit that determines a relevance between the abnormal event and the security event based on the distance, An attack analysis device characterized by:

2. 2. The attack analysis device of claim 1, the distance acquisition unit acquires the distance based on either a physical hardware component or a logical software component that exists between the abnormality occurrence point and the security event occurrence point; An attack analysis device characterized by:

3. 3. The attack analysis device according to claim 2, the distance acquisition unit acquires the distance by weighting the physical configuration item or the logical configuration item in accordance with the security type of the physical configuration item or the logical configuration item. An attack analysis device characterized by:

4. 4. The attack analysis device according to claim 3, the distance acquisition unit acquires the distance based on a directed graph in which each node of the physical configuration element or the logical configuration element is connected by a directed edge; An attack analysis device characterized by:

5. 5. The attack analysis device according to claim 4, the distance acquisition unit performs the weighting based on an edge distance assigned to the directed edge of the directed graph; the directed graph and the edge distance are associated with a vehicle model identification number or a vehicle individual identification number of a vehicle in which the on-vehicle device is installed; An attack analysis device characterized by:

6. 2. The attack analysis device of claim 1, the determination unit further determines, based on the distance, whether to perform log analysis on the route between the abnormality occurrence point and the security event occurrence point. An attack analysis device characterized by:

Citation Information

Patent Citations

  • Cause estimating method for nonconformity event

    JP1995013617A

  • System for vehicle and control method

    JP2019125344A

  • Cyber attack analysis support device

    JP2021117568A

  • Information processing device, log analysis method, and program

    WO2020075808A1