Attack estimation verification device, attack estimation verification method, and attack estimation verification program
By grouping electronic control units in vehicles based on characteristics and verifying the appropriateness of these groupings, the method addresses the high processing load and complexity of anomaly detection in multifunctional electronic control systems, enabling efficient and accurate cyberattack analysis.
Patent Information
- Application Number
- JP2022119114
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-07-26
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-07-26
AI Technical Summary
The increasing complexity of electronic control systems in vehicles due to multifunctionality leads to a high processing load for anomaly detection and analysis, making it difficult to accurately identify cyberattacks without setting numerous patterns and rules for each configuration, which is undesirable for development and maintenance.
The electronic control system is divided into groups based on characteristics of the electronic control units, allowing for common anomaly detection patterns and analysis rules to be applied across systems with different configurations, and an attack estimation verification device verifies the appropriateness of these groupings.
This approach reduces processing load and enables accurate analysis of cyberattacks by ensuring appropriate grouping, facilitating easier development and maintenance.
Smart Images

Figure 0007786314000001 
Figure 0007786314000002 
Figure 0007786314000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an attack estimation verification device, an attack estimation verification method, and an attack estimation verification program that estimate attacks against electronic control systems mounted on mobile objects such as automobiles and verify the estimation results. [Background technology]
[0002] In recent years, technologies for driver assistance and autonomous driving control, including V2X (vehicle-to-vehicle communication) and vehicle-to-infrastructure communication, have been attracting attention. Accordingly, vehicles are increasingly equipped with communication functions, and so-called connected vehicles are becoming more common. As a result, the possibility of vehicles being subject to cyberattacks, such as unauthorized access, is increasing. Therefore, it is necessary to analyze cyberattacks against vehicles and develop countermeasures.
[0003] There are various methods for detecting abnormalities that occur in a vehicle and analyzing cyber attacks based on the detected abnormalities. For example, Patent Document 1 describes a method for collecting detected abnormality data and comparing the combination of items in which an abnormality was detected with an abnormality detection pattern that has been specified in advance for each attack to identify the type of attack corresponding to the abnormality.
[0004] However, since the configuration of an electronic control system installed in a vehicle varies depending on the vehicle type, model year, and manufacturer, the items in which an abnormality is detected due to a cyber-attack and the location where the abnormality occurs may differ depending on the configuration of the electronic control system. Therefore, in order to identify a cyber-attack using a combination of items in which an abnormality is detected, it is necessary to set an abnormality detection pattern and analysis rules for each configuration of the electronic control system. However, in recent years, as vehicles have become more multifunctional, the number of electronic control devices that make up an electronic control system has been increasing, so setting an abnormality detection pattern and analysis rules that correspond to many electronic control devices not only increases the processing load, but is also undesirable from the perspectives of development and maintenance. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2020-123307 Summary of the Invention [Problem to be solved by the invention]
[0006] Therefore, after detailed investigation, the inventors discovered a method for reducing the amount of analysis processing required for cyberattacks against an electronic control system by dividing multiple electronic control units that make up an electronic control system into several groups and setting anomaly detection patterns and analysis rules for each group. This method reduces the number of anomaly detection patterns and analysis rules that need to be set for the entire electronic control system. Furthermore, by grouping the electronic control units so that common anomaly detection patterns and analysis rules can be applied to multiple electronic control systems with different configurations, it becomes possible to analyze cyberattacks regardless of the electronic control system configuration. However, if the electronic control units are not grouped appropriately, attacks may not be analyzed accurately. Therefore, when analyzing cyberattacks using this method, it is desirable to verify whether the grouping of the electronic control units is appropriate.
[0007] Therefore, the present invention aims to provide an apparatus, method, and program that can divide multiple electronic control devices that make up an electronic control system into several groups, analyze cyber attacks, and then verify whether the analysis method is appropriate. [Means for solving the problem]
[0008] An attack estimation verification device according to one aspect of the present disclosure includes a log acquisition unit (101) that acquires a security log including identification information indicating an abnormal electronic control device that is an electronic control device in which an abnormality has been detected among a plurality of electronic control devices that constitute an electronic control system, abnormality information indicating the abnormality detected in the abnormal electronic control device, and group information indicating the group to which the abnormal electronic control device belongs, which is a group obtained by grouping one or more electronic control devices among the plurality of electronic control devices according to characteristics that each of the plurality of electronic control devices actually has and is assumed to have; attack information indicating a type of attack; predicted abnormality information indicating an abnormality that is predicted to occur when the attack is received; and group information indicating the group in which the predicted abnormality will occur. an attack-anomaly relationship table storage unit (102) that stores an attack-anomaly relationship table that indicates the correspondence between the predicted anomaly information and the predicted group information; an attack estimation unit (104) that estimates an attack that the electronic control system has received from a combination of the predicted anomaly information and the predicted group information that corresponds to the combination of the anomaly information and the group information; a verification unit (105) that determines that the grouping of the group is inappropriate or that the characteristics that the abnormal electronic control device is assumed to have are inappropriate when the attack estimated by the attack estimation unit is an attack related to the characteristics that the abnormal electronic control device indicated by the identification information is assumed to have; and a notification unit (106) that notifies the verification result by the verification unit.
[0009] It should be noted that the claims and the numbers in parentheses attached to the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described below, and are not intended to limit the present invention. [Effects of the Invention]
[0010] The above-described configuration reduces the processing load required to analyze cyber attacks on electronic control systems, making development and maintenance easier. In addition, by verifying whether the attack analysis method is appropriate, it becomes possible to perform analysis using an appropriate analysis method, and ultimately makes it possible to accurately analyze abnormalities when they occur in electronic control systems. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a block diagram showing an example of the configuration of an attack analysis system according to a first embodiment. [Figure 2] FIG. 1 is an explanatory diagram illustrating the layout of an attack analysis system according to a first embodiment. [Figure 3] FIG. 1 is a diagram illustrating an example of the configuration of an electronic control system that is an analysis target of the attack analysis system according to the first and second embodiments. [Figure 4] FIG. 1 is a block diagram showing an example of the configuration of an attack estimation log generation device according to the first and second embodiments. [Figure 5] FIG. 10 is a diagram showing an example of a feature table according to the first and second embodiments. [Figure 6] FIG. 10 is a diagram showing an example of a feature table according to the first and second embodiments. [Figure 7] FIG. 1 is a diagram illustrating an example of the configuration of an electronic control system according to first and second embodiments. [Figure 8] FIG. 1 is a block diagram showing an example of the configuration of an attack estimation and verification device according to first and second embodiments. [Figure 9] FIG. 10 is a diagram showing an example of an attack-anomaly relationship table according to the first and second embodiments. [Figure 10] 1 is a flowchart showing the operation of the attack analysis system according to the first and second embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.
[0013] The present invention refers to the inventions described in the claims or in the Summary of the Invention section, and is not limited to the following embodiments. Furthermore, at least the words in quotation marks refer to the words described in the claims or in the Summary of the Invention section, and are not limited to the following embodiments.
[0014] The configurations and methods recited in the dependent claims are optional configurations and methods in the inventions recited in the independent claims. The configurations and methods of the embodiments corresponding to the configurations and methods recited in the dependent claims, as well as the configurations and methods recited only in the embodiments without being recited in the claims, are optional configurations and methods in the present invention. The configurations and methods recited in the embodiments when the recitation of the claims is broader than the recitation of the embodiments are also optional configurations and methods in the present invention, in the sense that they are examples of the configurations and methods of the present invention. In either case, by being recited in the independent claims, they become essential configurations and methods of the present invention.
[0015] The effects described in the embodiments are effects obtained when the configurations of the embodiments are provided as examples of the present invention, and are not necessarily effects that the present invention has.
[0016] When there are multiple embodiments, the configurations disclosed in each embodiment are not limited to each embodiment, but can be combined across the embodiments. For example, a configuration disclosed in one embodiment may be combined with another embodiment. Also, configurations disclosed in multiple embodiments may be collected and combined.
[0017] The problem described in the section on the problem to be solved by the invention is not a publicly known problem, but was discovered independently by the inventor, and this fact, together with the configuration and method of the present invention, affirms the inventive step of the invention.
[0018] 1. First embodiment (1) Attack Analysis System 1 (a) Configuration of Attack Analysis System 1 1 is a diagram illustrating the schematic configuration of an attack analysis system 1 according to this embodiment. The attack analysis system 1 includes an attack estimation verification device 100 and an attack estimation log generation device 200. The attack estimation verification device 100 is a device that estimates a cyber-attack against an electronic control system S (described later) and verifies the estimation results. The attack estimation log generation device 200 is a device that generates a log required for the attack estimation verification device 100 to estimate a cyber-attack.
[0019] (b) Arrangement of attack analysis system 1 and electronic control system S 2 is a diagram illustrating the arrangement of the attack analysis system 1 and the electronic control system S of this embodiment. The attack analysis system 1 can be arranged in any way that allows it to acquire necessary information from the electronic control system S. Hereinafter, a cyber attack will be abbreviated to "attack." Furthermore, an attack may be described as an abnormality from the perspective of the electronic control system S that is affected by the attack.
[0020] For example, as shown in Figure 2a, the electronic control system S and the attack analysis system 1 may be "mounted" on a vehicle, which is a "moving body," as shown in Figure 2b, the electronic control system S may be "mounted" on a vehicle, which is a "moving body," and the attack analysis system 1 may be realized on a server device installed outside the vehicle, as shown in Figure 2c, the electronic control system S and the attack estimation log generation device 200 of the attack analysis system 1 may be "mounted" on a vehicle, which is a "moving body," and only the attack estimation verification device 100 of the attack analysis system 1 may be realized on a server device.
[0021] Here, "mobile body" refers to an object that can move at any speed. It also naturally includes cases where the moving body is stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and objects mounted on these vehicles. Furthermore, "mounted" includes not only cases where the device is directly fixed to the mobile body, but also cases where the device is not fixed to the mobile body but moves with the mobile body. For example, cases where the device is carried by a person riding on the mobile body, or cases where the device is mounted on cargo placed on the mobile body, are included.
[0022] In the case of Figure 2a, the attack analysis system 1 and the electronic control system S are connected via an in-vehicle network such as a CAN (Controller Area Network) or a LIN (Local Interconnect Network). Alternatively, they can be connected using any communication method, whether wired or wireless, such as Ethernet (registered trademark), Wi-Fi (registered trademark), or Bluetooth (registered trademark). As another example, the functions of the attack estimation verification device 100 and the attack estimation log generation device 200 can be built into at least one of the electronic control devices constituting the electronic control system S.
[0023] In the case of FIG. 2a, when the electronic control system S is attacked, the attack analysis system 1 can analyze the attack without delay, and therefore can respond to the attack quickly.
[0024] In the case of FIG. 2b, the attack analysis system 1 and the electronic control system S can be connected using a communication means consisting of a wireless communication method such as IEEE802.11 (Wi-Fi (registered trademark)), IEEE802.16 (WiMAX (registered trademark)), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, or 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. When the vehicle is parked in a parking lot or in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a local area network (LAN), the Internet, or a fixed telephone line can be used.
[0025] In the case of Figure 2b, when an electronic control system S mounted on a vehicle is attacked, the server device receives from the vehicle via a wireless communication network a security log generated by a security sensor mounted on an electronic control device that constitutes the electronic control system S. Therefore, compared to when the attack analysis system 1 is mounted on a vehicle, it takes more time to analyze the attack and feed back the analysis results to the vehicle, but it is possible to reduce the processing load on the vehicle. In addition, since the abundant resources of the server device can be used, it is possible to perform complex and large-volume calculations.
[0026] In the case of Fig. 2c, the attack estimation verification device 100 and the attack analysis log generation device 200, which are realized by a server device, can be connected using communication means consisting of a wireless communication method or a wired communication method, as in the case of Fig. 2b. Since the processing load of the attack estimation and verification processing by the attack estimation verification device 100 is larger than the processing load by the attack estimation log generation device 200, only the processing with such a large processing load is realized using the resources of the server device.
[0027] In each embodiment described below, an example will be given in which the electronic control system S under attack is an in-vehicle system mounted on a vehicle. However, the electronic control system S is not limited to an in-vehicle system, and can be applied to any electronic control system. For example, the electronic control system S may not be mounted on a vehicle, but on a stationary object.
[0028] In addition, the attack analysis system 1 of this embodiment can be used not only to analyze attacks on an electronic control system S implemented in a vehicle, but also as a test system to verify whether the attack analysis method is appropriate for an electronic control system S before implementation.
[0029] Before explaining the attack estimation verification device 100 of the first embodiment, the configuration of the peripheral devices of the attack estimation verification device 100, i.e., the configuration of the electronic control system S under attack, and the configuration of the attack estimation log generation device 200 will be described below.
[0030] (2) Electronic Control System S (a) Overall configuration 3 is a diagram illustrating an example of the configuration of an electronic control system S. The electronic control system S is composed of a plurality of electronic control devices (hereinafter referred to as ECUs (Electric Control Units)). The electronic control system S illustrated in FIG. 3 includes a CGW 11, an ECU 12, an ECU 13, an ECU 14, an ECU 15, an ECU 16, and an ECU 17.
[0031] The CGW 11 (Central GateWay) mainly has a gateway (GW) function. For example, it transfers information received from outside the vehicle via wireless communication to ECUs 12 to 17 connected via an in-vehicle network. In FIG. 3, CANs 1 to 5 are shown as an example of the in-vehicle network, but a communication network such as LIN or Ethernet (ETH) may be used instead of CAN. The CGW 11 may also be equipped with functions other than the gateway function. The CGW 11 shown in FIG. 3 has two virtual machines (hereinafter referred to as VMs (Virtual Machines)), namely, VM111 and VM112.
[0032] The ECUs 12 to 17 are ECUs connected via a network to the CGW 11. The ECUs 12 to 17 are any ECUs that implement various vehicle functions, such as drivetrain electronic control devices that control the engine, steering, brakes, etc., body electronic control devices that control meters, power windows, etc., information system electronic control devices such as a navigation device, and safety control system electronic control devices that perform control to prevent collisions with obstacles or pedestrians.
[0033] In the following description, when attention is not paid to the unique features of the CGW 11 and the ECUs 12 to 17, they will be referred to as ECUs or simply as ECUs.
[0034] (b) Defense in depth and layers Many electronic control systems S employ defense in depth to enhance security against attacks. Defense in depth involves providing security functions in a hierarchical and multi-layered manner as a countermeasure against attacks. Even if one countermeasure (i.e., the first layer) is breached in an attack, the next countermeasure (i.e., the second layer) can defend against the attack, thereby enhancing the defensive capabilities of the electronic control system. Therefore, an electronic control system S employing defense in depth will have multiple layers with different "security levels." Therefore, the electronic control system S is divided into multiple layers according to security level, and each ECU is classified into one of the layers.
[0035] Here, the "security level" is an index indicating safety against attacks or deterrence against attacks.
[0036] 3 has three defense layers. In this example, the VM 111 of the CGW 11 and the ECUs 12 and 13 belong to the first layer, the VM 112 of the CGW 11 and the ECUs 14 and 15 belong to the second layer, and the ECUs 16 and 17 belong to the third layer.
[0037] Although the electronic control device system S in FIG. 3 has three defense layers, four or more defense layers may be provided. For example, an ECU connected via a sub-gateway ECU may be the fourth layer. Alternatively, ECUs called entry points, such as a TCU (Telematics Control Unit) or an IVI (In-Vehicle Infotainment system), may belong to a defense layer different from the ECUs shown in FIG. 3.
[0038] (c) Security Sensor Each ECU constituting the electronic control system S is equipped with one or more security sensors that monitor the inside of the ECU and the network to which the ECU is connected. When a security sensor detects an abnormality occurring inside the ECU or in the network, it generates and outputs a security log. The security log includes abnormality information indicating that the security sensor has detected the abnormality and identification information indicating the ECU in which the abnormality was detected. In the following embodiments, the ECU in which the abnormality is detected is referred to as an abnormal ECU, and the security log generated and output by the security sensor is referred to as an individual security log. Note that, for ease of explanation, in this specification, the combination of an ECU and a code (e.g., ECU12) is used as the identification information of the ECU. Examples of security sensors include, but are not limited to, a firewall, a proxy, and authentication.
[0039] In addition to the abnormality information and identification information of the abnormal ECU, the individual security log may also include identification information that identifies the electronic control system S, location information indicating the location where the abnormality detected by the security sensor occurred, the time the abnormality was detected, the number of times the abnormality was detected, the order in which the abnormality was detected, the content of the data received before the abnormality was detected, and information on the IP addresses (source and destination), etc.
[0040] (d) Domain Controller Although not shown in FIG. 3 , there is a system known as a domain architecture in which multiple ECUs constituting an electronic control system S are divided into units called domains according to their functions and roles, and the ECUs are managed for each domain. In such a domain architecture, an ECU called a domain controller manages the ECUs for each domain. When the electronic control system S of the present application is a domain architecture, the ECU that is the domain controller and the ECUs managed by the domain controller often have different security levels, even if they belong to the same defense layer. Therefore, the domain controller and the ECUs managed by the domain controller are not determined to be in the same group but are determined to be in different groups by the attack estimation log generation device 200 described below.
[0041] (3) Attack estimation log generation device 200 The configuration of the attack inference log generation device 200 of this embodiment will be described with reference to Figure 4. The attack inference log generation device 200 includes an individual log acquisition unit 201, a feature count information acquisition unit 202, a feature table storage unit 203, a group determination unit 204, and an output unit 205. As described above, the attack inference log generation device 200 is a device that generates logs necessary for the attack inference verification device 100 to infer attacks, and can be said to be a prerequisite device for the attack inference verification device 100.
[0042] The individual log acquisition unit 201 acquires an individual security log including abnormality information indicating an abnormality detected in the electronic control system S and identification information indicating the abnormal ECU (corresponding to an "abnormal electronic control device"), which is the ECU in which the abnormality was detected.
[0043] The feature number information acquisition unit 202 acquires feature number information indicating the maximum number of features assumed to be possessed by each ECU constituting the electronic control system S. For example, an arbitrary value is input into this feature number information by the user of the attack analysis system 1.
[0044] The feature table storage unit 203 is a storage unit that stores a feature table indicating the correspondence between the identification information of each ECU constituting the electronic control system S, the features that each ECU "actually" possesses, the features that each ECU is assumed to possess, and group information set according to the features. FIGS. 5 and 6 are diagrams showing examples of the feature table. The features that each ECU is assumed to possess vary depending on the feature count information acquired by the feature count information acquisition unit 202. Therefore, the feature table storage unit 203 stores multiple feature tables for each value of the feature count information.
[0045] Here, "in reality" means that some function can be realized by utilizing the features, and for example, the features of a virtual machine are included in the features that are actually possessed.
[0046] 5 and 6, for ease of explanation, the feature table includes the features that each ECU actually has and the features that each ECU is assumed to have. However, the feature table does not necessarily include these features. In other words, the feature table may simply be a table showing the correspondence between the identification information of each ECU and the group information. In this case, however, the group information in the feature table is set in advance according to the features that each ECU actually has and the features that each ECU is assumed to have.
[0047] If the feature count information is always set to a constant value, the feature table storage unit 203 does not need to store a feature table for each value indicated by the feature count information, and therefore stores only one feature table. In this case, the attack estimation log generation device 200 does not need to have the feature count information acquisition unit 202.
[0048] The group determination unit 204 determines group information indicating the group to which the abnormal ECU belongs, based on the identification information of the abnormal ECU contained in the individual security log. Here, a group is a grouping of one or more ECUs from among the multiple ECUs that make up the electronic control system S. The ECUs are grouped according to the features that the ECUs "actually" possess and the features that are assumed to be possessed by the ECUs. Hereinafter, the features that the ECUs actually possess are referred to as actual features, and the features that are assumed to be possessed by the ECUs are referred to as provisional features. Of the ECUs that make up the electronic control system S, ECUs that have the same actual features and provisional features are grouped into the same group. The processing by the group determination unit 204 will be described later.
[0049] Here, the feature is, for example, a network. In this case, the feature that the ECU actually has is a network that is actually connected to the ECU, and the feature that the ECU is assumed to have is a network that is not actually connected to the ECU but is assumed to be connected.
[0050] In another example, the feature is a function of the ECU. In this case, the feature that the ECU actually has is a function that the ECU can actually perform, and the feature that the ECU is assumed to have is a function that the ECU cannot actually perform but is assumed to be able to perform. For example, in the case of an ECU that constitutes an in-vehicle system, the ECU's function may include a function for steering the vehicle, a function for controlling communication with the outside, a function related to the navigation system, etc. Alternatively, the ECU's function may be an anomaly detection function that each ECU has.
[0051] The output unit 205 outputs a security log including the abnormality information contained in the individual security log, the identification information of the abnormal ECU, and the group information determined by the group determination unit 204 to the attack estimation verification device 100. This security log may also include other information that was included in the individual security log.
[0052] Next, the determination process by the group determination unit 204 will be described. The group determination unit 204 determines the actual features and the provisional features using, for example, feature tables such as those shown in Fig. 5 and Fig. 6. Fig. 5 is a feature table when the value indicated by the feature number information is 1 and the feature is a network. Fig. 6 is a feature table when the value indicated by the feature number information is 2 and the feature is an ECU function.
[0053] When the individual log acquisition unit 201 acquires an individual security log, the group determination unit 204 refers to the maximum number of features indicated by the feature number information acquired by the feature number information acquisition unit 202. For example, assume that the identification information of the abnormal ECU included in the individual security log is ECU12 and the feature number information acquired by the feature number information acquisition unit 202 is 1. In this case, the group determination unit 204 uses the feature table shown in FIG. 5 to determine the group information [G-01] associated with the identification information [ECU12] of the abnormal ECU.
[0054] According to the feature table in FIG. 5, the actual feature of the abnormal ECU 12, i.e., the network to which the abnormal ECU 12 is actually connected, is CAN1, and the provisional feature of the abnormal ECU 12, i.e., the network to which the abnormal ECU 12 is assumed to be connected, is CAN2. VM 111 and ECU 13, which are actually connected to or assumed to be connected to the same network as the abnormal ECU 12, belong to the same group indicated by the group information [G-01] as ECU 12. FIG. 7 is a diagram in which networks that are provisional features are added using dashed lines to the electronic control system S shown in FIG. 3. It is assumed that CAN2 is connected to ECU 12. In FIG. 7, networks that are provisional features of ECU 14 and ECU 17 are also shown using dashed lines. It is clear from FIG. 7 that ECU 12, ECU 13, and VM 111 are connected to the same networks (CAN1 and CAN2).
[0055] As another example, suppose that the identification information of the abnormal ECU included in the individual security log is ECU14, and the feature number information acquired by the feature number information acquisition unit 202 is 2. In this case, the group determination unit 204 uses the feature table shown in FIG. 6 to determine the group information [G-02] associated with the identification information [ECU14] of the abnormal ECU.
[0056] 6, the actual features of the abnormal ECU 14, i.e., the functions that the abnormal ECU 14 actually has, are function A and function D, and the provisional feature of the abnormal ECU 14, i.e., the function that the abnormal ECU 14 is assumed to have, is function E. VM 112 and ECU 15, whose functions that the ECUs actually have or are assumed to have are the same as those of the abnormal ECU 14, belong to the group indicated by the group information [G-02], just like ECU 14.
[0057] 3, when defense in depth is adopted in the electronic control system S, the group determination unit 204 may determine the security level of the ECU as a feature in addition to the features such as the network and functions described above, and determine the group according to the layer to which the ECU belongs. In this case, it is desirable that ECUs with different security levels are not determined to be in the same group, but are determined to be in different groups.
[0058] For example, let us consider a case where the value indicated by the feature count information is 3, i.e., the maximum number of provisional features for each ECU is 3. If the provisional features of ECU 12 are CAN2, CAN3, and CAN4, the actual features and provisional features of ECU 12 are CAN1, CAN2, CAN3, and CAN4. Also, if the provisional features of ECU 14 are CAN1, CAN2, and CAN4, the actual features and provisional features of ECU 12 are CAN1, CAN2, CAN3, and CAN4. Therefore, ECU 12 and ECU 14 have the same actual features and provisional features. However, ECU 12 belongs to the first layer, while ECU 14 belongs to the second layer. Therefore, ECU 12 and ECU 14 are not determined to be in the same group.
[0059] Even if the physical configuration of an electronic control system differs depending on the vehicle model, electronic control systems that employ defense in depth have common security functions. Therefore, regardless of the configuration of the electronic control system, it is possible to divide the electronic control system into multiple layers according to the security level. Furthermore, even if the physical configuration of an electronic control system differs, there is often commonality among the ECUs that need to be protected by each defense layer. Therefore, by grouping ECUs according to the security level of the electronic control system and the networks and functions possessed by each ECU, a group of electronic control system S will be a group that has commonality with other groups of electronic control systems. As a result, it is possible to apply common attack analysis rules to electronic control system S and other electronic control systems.
[0060] Although the network and the function are exemplified as the characteristics of the ECU, the present invention is not limited to these. Furthermore, the group determination unit 204 may determine the group to which the ECU belongs based on a plurality of different types of characteristics of the ECU, that is, based on both the network and the function.
[0061] In this specification, one network or one function corresponds to one feature, but multiple networks or multiple functions of an ECU may be collectively referred to as a feature in this specification. In this case, the maximum number of features acquired by the feature number information acquisition unit 202 indicates the number of provisional features included in the feature.
[0062] As shown in FIG. 2b, when the attack analysis system 1 is a server device, the attack estimation log generation device 200 acquires individual security logs from multiple vehicles and generates security logs. Therefore, the feature table storage unit 202 needs to store multiple feature tables corresponding to the electronic control systems of each vehicle. Therefore, in order for the group determination unit 204 to easily identify the feature table to be used, it is desirable for the individual security log to include information identifying the electronic control system. This allows the group determination unit 204 to easily identify the feature table to be used to determine the features that the ECU included in the individual security log actually has or is assumed to have.
[0063] (4) Attack estimation verification device 100 Next, the attack estimation verification device 100 of this embodiment will be described with reference to Fig. 8. The attack estimation verification device 100 includes an attack estimation log acquisition unit 101, an attack-anomaly relationship table storage unit 102, a feature table storage unit 103, an attack estimation unit 104, a verification unit 105, and a notification unit 106.
[0064] The attack estimation log acquisition unit 101 (corresponding to the "log acquisition unit") "acquires" the security log for attack estimation output from the attack estimation log generation device 200. As described above, the security log acquired by the log acquisition unit 101 includes identification information indicating the abnormal ECU, abnormality information indicating the abnormality detected in the abnormal ECU, and group information indicating the group to which the abnormal ECU belongs.
[0065] The term "obtain" includes both cases where a security log is obtained from an external device and cases where the attack estimation verification device obtains the security log by generating it itself.
[0066] The attack-anomaly relationship table storage unit 102 is a storage unit that stores the attack-anomaly relationship table. The attack-anomaly relationship table is a table that shows the correspondence between attack information that indicates the type of attack that the electronic control system is expected to receive, predicted anomaly information that indicates an anomaly that is predicted to occur in the electronic control system if the attack is received, and predicted group information that indicates the group in which the predicted anomaly will occur. The attack-anomaly relationship table is not a table specific to the electronic control system S, but is also a table that can be used to estimate attacks on other electronic control systems that have a different configuration from the electronic control system S.
[0067] FIG. 9 is a diagram showing an example of an attack-anomaly relationship table. The attack-anomaly relationship table shown in FIG. 9 shows, for each type of attack (attacks A to X), the anomalies that will occur when the electronic control system is subjected to the attack, and the groups in which the anomalies may occur. FIG. 9 also shows the correspondence between the attack type and the assumed attack starting point and attack target when the electronic control system is subjected to the cyber attack. Note that the attack starting point and attack target do not refer to ECUs specific to the configuration of the electronic control system S, but rather to groups to which the attack starting point and attack target ECUs belong. Therefore, the attack starting point and attack target are referred to as the attack starting point group and attack target group, respectively. Furthermore, anomaly A in FIG. 9 indicates that an anomaly has occurred in function A of the ECU.
[0068] For example, if an attack of attack type A occurs in the electronic control system, it is predicted that abnormalities A and C will occur in the ECUs belonging to group [G-01]. Furthermore, the attack origin group for attack A is the group indicated by identification number [G-00], and the attack target group is the group indicated by identification number [G-01]. Note that the attack origin may be inside the electronic control system or outside the electronic control system. An attack originating from outside the electronic control system means that the attack is coming from outside the vehicle. Identification number [G-00] indicates that the attack origin is outside the electronic control system.
[0069] 9 shows one attack-anomaly relationship table, the attack-anomaly relationship table storage unit 102 stores an attack-anomaly relationship table for each value indicated by the feature count information. This is because if the maximum number of provisional features differs, the group to which the abnormal ECU belongs in the attack estimation log generation device 200 may differ, and the attack-anomaly relationship table to be used for attack estimation will also differ.
[0070] The feature table storage unit 103 is a storage unit that stores the same feature table as the feature table stored in the attack estimation log generation device 200. That is, the feature table storage unit 103 stores feature tables such as those shown in FIGS.
[0071] The attack estimation unit 104 estimates the type of attack that the electronic control system S has received, using the attack-anomaly relationship table. Specifically, the attack estimation unit 104 identifies, from the attack-anomaly relationship table, a combination of predicted anomaly information and predicted group information that "corresponds to the combination" of anomaly information and group information included in the security log acquired by the log acquisition unit 201. If a combination of predicted anomaly information and predicted group information that matches the combination of anomaly information and group information does not exist in the attack-anomaly relationship table, the attack estimation unit 104 identifies the closest combination from among the combinations of predicted anomaly information and predicted group information included in the attack-anomaly relationship table. Then, the attack estimation unit 104 estimates that the attack type indicating the closest combination is the type of attack that the electronic control system has received.
[0072] Here, "corresponding to a combination" means that the combination is the same or similar.
[0073] For example, a case will be described in which the anomaly information included in the security log indicates anomaly A and anomaly E, and the group information indicates G-02. In this case, the attack estimation unit 104 identifies a combination of predicted anomaly information and predicted group information corresponding to the combination of anomaly information (anomaly A, anomaly E) and group information (G-02) from the attack-anomaly relationship table. In the example of FIG. 9, the combination of predicted anomaly information and predicted group information for attack B matches the combination of anomaly information (anomaly A, anomaly E) and group information (G-02). Therefore, the attack estimation unit 104 estimates that the type of attack that the electronic control system S has received is attack B.
[0074] If the security log includes the order of occurrence and the number of times the anomaly indicated by the anomaly information occurs, the attack estimation unit 104 may further use this information when estimating the attack type. In this case, the attack-anomaly relationship table includes the order of occurrence and the number of times the anomaly occurred as predicted anomaly information.
[0075] If there are multiple closest combinations, the attack estimation unit 104 estimates that the type of attack received by the electronic control system S is one of the multiple corresponding attacks. For example, consider a case where the abnormality information indicates abnormality D and the group information indicates G-02. In FIG. 9, there is no combination of predicted abnormality information and predicted group information that matches the combination of the abnormality information (abnormality D) and the group information (G-02). However, there are attacks C and D that include the combination of the predicted abnormality information (abnormality D) and the group information (G-02). Therefore, the attack estimation unit 104 estimates that the type of attack received by the electronic control system S is either attack C or attack D.
[0076] The attack estimation unit 104 further estimates the attack starting group and the attack target group of the attack, in addition to estimating the type of attack that the electronic control system S has received. As shown in Fig. 9, the attack-anomaly relationship table stores the attack type in association with the attack starting group and the attack target group, so the attack estimation unit 104 can estimate the attack starting group and the attack target group using the attack-anomaly relationship table.
[0077] The verification unit 105 verifies whether the grouping of ECUs in the attack estimation log generation device 200 or the characteristics assumed to be possessed by abnormal ECUs are appropriate. Specifically, if the attack type estimated by the attack estimation unit 104 is an attack related to the characteristics assumed to be possessed by abnormal ECUs, the verification unit 105 determines that the grouping of ECUs or the characteristics assumed to be possessed by abnormal ECUs are inappropriate. Detailed processing by the verification unit 105 will be described later.
[0078] The notification unit 106 notifies the user of the attack analysis system 1 of the verification result by the verification unit 105. The notification unit 106 may notify the user of the attack analysis system 1 in any manner. For example, the notification unit 106 may notify the user of the verification result by voice or text. Note that the notification unit 106 may notify the user of the verification result only when it is determined that the grouping of ECUs in the attack estimation log generation device 200 or the characteristics assumed to be possessed by abnormal ECUs is inappropriate.
[0079] Next, a description will be given of a verification method performed by the verification unit 105. First, a description will be given of a verification method performed by the verification unit 105 when the feature is a network.
[0080] For example, assume that the attack estimation unit 104 estimates that the attack type is attack D shown in Fig. 9, the attack starting group is [G-02], and the attack target group is [G-03]. According to Fig. 3 or Fig. 7, since group [G-02] and group [G-03] are connected via CAN4, the attack path of attack D is via CAN4. Therefore, CAN4 is a network related to attack D.
[0081] Here, the verification unit 105 refers to the feature table stored in the feature table storage unit 103 to identify the tentative feature of the abnormal ECU indicated by the identification information included in the security log. When the identification information indicates ECU 15, the feature table shown in FIG. 5 indicates that there is no network assumed to be connected to ECU 15. In other words, attack D estimated by the attack estimation unit 104 is not an attack related to the network assumed to be connected to the abnormal ECU 15 indicated by the identification information. In this case, the verification unit 105 can determine that the grouping of ECUs is appropriate. On the other hand, when the identification information indicates ECU 14, the network assumed to be connected to ECU 14 is CAN4 according to the feature table shown in Fig. 5, and the verification unit 105 identifies the provisional feature of the abnormal ECU as CAN4. As described above, attack D estimated by the attack estimation unit 104 is an attack carried out via CAN4, and is an attack via the network assumed to be connected to the abnormal ECU 14. Therefore, the verification unit 105 determines that the grouping of ECUs is inappropriate, or that the feature assumed to be possessed by the abnormal ECU 14 is inappropriate.
[0082] Next, a verification method by the verification unit 105 when the feature is an ECU function will be described. For example, assume that the attack estimation unit 104 estimates that the attack type shown in Fig. 9 is attack A. As in the above example, the verification unit 105 refers to the feature table stored in the feature table to identify the tentative feature of the abnormal ECU indicated by the identification information included in the security log.
[0083] When the identification information indicates ECU 12, the function assumed to be possessed by ECU 12 is function B according to the feature table shown in FIG. 6, and the verification unit 105 identifies function B as the provisional feature of the abnormal ECU 12. Here, attack A estimated by the attack estimation unit 104 is an attack when abnormalities A and C occur, and is an attack when abnormalities occur in functions A and C. Therefore, it is not an attack related to the feature (function B) assumed to be possessed by the abnormal ECU 12 indicated by the identification information. In this case, the verification unit 105 can determine that the grouping of ECUs and the functions assumed to be possessed by the abnormal ECU are appropriate. On the other hand, when the identification information indicates ECU 13, according to the feature table shown in Fig. 6, the functions assumed to be possessed by ECU 13 are function A and function B, and the verification unit 105 identifies the provisional features of the abnormal ECU 13 as function A and function B. As described above, attack A estimated by the attack estimation unit 104 is an attack when abnormality A occurs, and is an attack on the function (function A) assumed to be possessed by the abnormal ECU 13. Therefore, the verification unit 105 determines that the grouping of ECUs is inappropriate, or that the features assumed to be possessed by the abnormal ECU 13 are inappropriate.
[0084] The user of the attack analysis system 1 can improve the accuracy of attack estimation and verification by reconfiguring the feature table and the features assumed to be possessed by the ECU based on the notification from the notification unit 106. In particular, when the attack analysis system 1 is a test system, the appropriateness of the feature table and the features assumed to be possessed by the ECU can be verified in a test environment before conducting attack analysis using an actual vehicle. This allows attack estimation that takes into account appropriate feature tables and features after operation. Even if the feature table and the features assumed to be possessed by the ECU are verified in the test system, if an attack related to the features assumed to be possessed by the abnormal ECU occurs after operation, there is a possibility that the feature table has been tampered with. In such a case, the user who received the notification from the notification unit 106 may verify the tampering of the feature table using a hash value.
[0085] (5) Operation of the Attack Analysis System 1 and the Attack Estimation Verification Device 100 Next, the operation of the attack analysis system 1 will be described with reference to Fig. 10. Fig. 10 not only shows a method executed by the attack analysis system 1, but also shows the processing procedure of a program that can be executed by the attack analysis system 1. These processes are not limited to the order shown in Fig. 10. In other words, the order may be changed as long as there are no constraints, such as a relationship in which a certain step uses the result of the previous step.
[0086] The individual log acquisition unit 201 of the attack estimation log generation device 200 acquires individual security logs generated by the ECUs that configure the electronic control system S (S10). When an individual security log is acquired in S101, the feature number information acquisition unit 202 acquires feature number information indicating the maximum number of provisional features (S11). The group determination unit 204 determines the group to which the abnormal ECU belongs based on the identification information of the abnormal ECU contained in the individual security log (S12). The output unit 205 then outputs to the attack estimation verification device 100 a security log that includes the anomaly information contained in the individual security log, the identification information, and the group information indicating the group determined in S12.
[0087] The log acquisition unit 101 of the attack estimation verification device 100 acquires the security log output from the attack estimation log generation device 200 (S101). The attack estimation unit 104 estimates the attack that the electronic control system S has received from the combination of predicted anomaly information and predicted group information in the attack-anomaly relationship table that corresponds to the combination of anomaly information and group information contained in the security log (S102). The verification unit 105 determines the provisional characteristics of the abnormal ECU based on the identification information (S103). Next, if the attack estimated in S102 is an attack related to the tentative features determined in S103, the verification unit 105 performs a verification process to determine that the grouping of the groups is inappropriate or that the features assumed to be possessed by the ECU are inappropriate (S104). Then, the notification unit 106 notifies the user of the attack estimation verification device 100 of the verification result by the verification unit 105 (S105).
[0088] (6) Summary As described above, according to the attack analysis system 1 and the attack estimation verification device 100 of the present disclosure, when an electronic control system S is attacked, the attack is estimated by grouping the multiple ECUs that make up the electronic control system S, taking into consideration not only the characteristics that the ECUs actually have but also the characteristics that the ECUs are assumed to have, and the attack estimation result is used to verify whether the process of grouping the ECUs is appropriate. As a result, if the grouping of the ECUs is inappropriate or if the characteristics that the ECUs are assumed to have are inappropriate, the verification result can be fed back to the user, making it possible to achieve highly accurate attack estimation.
[0089] Furthermore, the attack analysis system 1 and attack estimation verification device 100 of the present disclosure eliminate the need to provide a tool for estimating and verifying attacks for each of the many ECUs that make up the electronic control system S, or for each of multiple electronic control systems with different configurations, making it easier to manage devices and programs for estimating attacks and reducing the processing load required for estimating attacks. Furthermore, this system can be applied even if the number or configuration of ECUs that make up the electronic control system changes in the future.
[0090] (7) Variations In the first embodiment described above, the attack estimation verification device 100 stores the same feature table as the attack estimation log generation device 200 in the feature table storage unit 103. In this modified example, a configuration will be described in which the attack estimation verification device 100 does not have a feature table.
[0091] If the attack estimation verification device 100 does not have a feature table, the verification unit 105 of the attack estimation verification device 100 cannot determine the features assumed to be possessed by the abnormal ECU, and therefore cannot verify whether the grouping of ECUs and the features assumed to be possessed by the abnormal ECU are appropriate. Therefore, the attack estimation log acquisition unit 101 of this modification acquires a security log including information indicating the tentative features of the abnormal ECU from the attack estimation log generation device 200, in addition to the anomaly information, identification information, and group information. This makes it possible for the attack estimation verification device 100 to verify whether the grouping of ECUs and the features assumed to be possessed by the abnormal ECU are appropriate, even without having a feature table.
[0092] Alternatively, the attack estimation log acquisition unit 101 of this modification may acquire a security log including information indicating the actual characteristics of the abnormal ECU instead of information indicating the provisional characteristics of the abnormal ECU. In this case, however, the attack estimation verification device 100 needs to store in advance in a memory or the like which actual and provisional characteristics each group has. Then, the difference between the actual and provisional characteristics stored in a memory or the like and the actual characteristics included in the security log is determined to be the provisional characteristics of the abnormal ECU.
[0093] 2. Second embodiment In the first embodiment, the case where the attack estimation verification device 100 and the attack estimation log generation device 200 are different devices has been described. In contrast to this, in this embodiment, the attack estimation verification device 100 and the attack estimation log generation device 200 are configured as an integrated device. The device in which the attack estimation verification device 100 and the attack estimation log generation device 200 are configured as an integrated device is referred to as an attack analysis device (corresponding to an "attack estimation verification device") 110.
[0094] The configurations, functions, and operations of the attack estimation verification device 100 and the attack estimation log generation device 200 in this embodiment are the same as those in the first embodiment, and therefore will not be described again. Note that in the first embodiment, the feature table storage unit 103 of the attack estimation verification device 100 and the feature table storage unit 203 of the attack estimation log generation device 200 each stored a feature table, but in this embodiment, it is sufficient for the attack analysis device 110 to have only one feature table storage unit. The same feature table is referenced in the process of generating a security log by the attack estimation log generation device 200 and the process of verifying the attack estimation result by the attack estimation verification device 100.
[0095] The attack analysis device 110 and electronic control system S of this embodiment can be arranged in the same manner as in Figures 2a and 2b of the first embodiment. That is, the attack analysis device 110 may be mounted on a vehicle, which is a "mobile body," or may be realized by a server device.
[0096] 3. Summary The features of the attack estimation verification device and the like according to the embodiment of the present invention have been described above.
[0097] The terms used in the embodiments are merely examples and may be replaced with synonymous terms or terms having the same functions.
[0098] The block diagrams used to explain the embodiments classify and organize the device configuration by function. The blocks representing each function can be realized by any combination of hardware or software. Furthermore, because they represent functions, the block diagrams can also be understood as disclosures of method inventions and program inventions that realize the methods.
[0099] The order of the functional blocks that can be understood as the processes, flows, and methods described in the embodiments may be changed as long as there are no constraints, such as one step utilizing the results of another step that precedes it.
[0100] The terms first, second, through Nth (N is an integer) used in the embodiments and claims are used to distinguish between two or more similar configurations or methods, and do not limit the order or superiority or inferiority.
[0101] The embodiments are based on an attack analysis system and an attack estimation verification device for vehicles for analyzing attacks against electronic control systems installed in the vehicles, but the present invention also includes dedicated or general-purpose devices other than those for vehicles, unless otherwise limited in the claims.
[0102] Furthermore, examples of the configuration of the attack estimation and verification device of the present invention include the following. Examples of the component include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include an electronic control unit (ECU) and a system board. Finished product forms include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other examples include devices with communication functions, such as video cameras, still cameras, and car navigation systems.
[0103] Furthermore, necessary functions such as an antenna and a communication interface may be added to the attack estimation and verification device.
[0104] The present invention can be realized not only by dedicated hardware having the configuration and functions described in the embodiments, but also by a combination of a program for realizing the present invention recorded on a recording medium such as a memory or hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory that can execute the program.
[0105] A program stored in a non-transitory physical recording medium (for example, an external storage device (hard disk, USB memory, CD / BD, etc.) or an internal storage device (RAM, ROM, etc.)) of dedicated or general-purpose hardware can be provided to the dedicated or general-purpose hardware via a recording medium, or via a communication line from a server without using a recording medium. This makes it possible to always provide the latest functions through program upgrades. [Industrial Applicability]
[0106] The attack estimation and verification device of the present invention is primarily intended for devices that estimate and verify the results of attacks on on-board electronic control systems installed in automobiles, but it may also be intended for devices that estimate and verify attacks on systems other than on-board electronic control systems. [Explanation of symbols]
[0107] 100 Attack estimation verification device, 101 Log acquisition unit, 102 Attack-anomaly relationship table storage unit, 103 Feature table storage unit, 104 Attack estimation unit, 105 Verification unit, 106 Notification unit, 201 Individual log acquisition unit, 204 Group determination unit, 205 Output unit
Claims
1. a log acquisition unit (101) that acquires a security log including identification information indicating an abnormal electronic control device that is an electronic control device in which an abnormality has been detected among a plurality of electronic control devices that constitute an electronic control system, abnormality information indicating the abnormality detected in the abnormal electronic control device, and group information indicating the group to which the abnormal electronic control device belongs, which is a group obtained by grouping one or more electronic control devices among the plurality of electronic control devices according to the characteristics that each of the plurality of electronic control devices actually has and is assumed to have; an attack / anomaly relationship table storage unit (102) for storing an attack / anomaly relationship table showing the correspondence between attack information indicating the type of attack, predicted anomaly information indicating an anomaly predicted to occur when the attack is received, and predicted group information indicating a group in which the predicted anomaly will occur; an attack estimation unit (104) that estimates an attack that the electronic control system has received from a combination of the predicted abnormality information and the predicted group information corresponding to a combination of the abnormality information and the group information; a verification unit (105) that determines that the grouping of the groups is inappropriate or that the characteristics assumed to be possessed by the abnormal electronic control device are inappropriate when the attack estimated by the attack estimation unit is an attack related to the characteristics assumed to be possessed by the abnormal electronic control device indicated by the identification information; a notification unit (106) that notifies the verification result by the verification unit; An attack estimation verification device (100, 110) comprising:
2. The feature is a network that is actually connected or assumed to be connected to each of the plurality of electronic control units, When the estimated attack is an attack via a network assumed to be connected to the abnormal electronic control device, the verification unit determines that the grouping of the groups is inappropriate or that the network assumed to be connected to the abnormal electronic control device is inappropriate. The attack estimation verification device according to claim 1 .
3. The feature further includes the step of dividing the electronic control system into a plurality of layers according to security levels, to which each of the plurality of electronic control devices belongs. The attack estimation verification device according to claim 2.
4. The features are functions that each of the plurality of electronic control devices actually has or is assumed to have, When the estimated attack is an attack on a function assumed to be possessed by the abnormal electronic control device, the verification unit determines that the grouping of the groups is inappropriate or that the function assumed to be possessed by the abnormal electronic control device is inappropriate. The attack estimation verification device according to claim 1 .
5. The feature further includes the step of dividing the electronic control system into a plurality of layers according to security levels, to which each of the plurality of electronic control devices belongs. The attack estimation verification device according to claim 4.
6. The attack estimation verification device further comprises: a feature table storage unit (103) for storing a feature table indicating a correspondence between the identification information and features that the abnormal electronic control unit actually has or is assumed to have, the verification unit uses the feature table to identify features that are assumed to be possessed by the abnormal electronic control unit; The attack estimation verification device according to claim 1 .
7. The security log further includes information indicating characteristics that the abnormal electronic control device is assumed to have. The attack estimation verification device according to claim 1 .
8. The attack estimation verification device further comprises: an individual log acquisition unit (201) that acquires an individual security log including the identification information and the abnormality information; a group determination unit (204) that determines a group to which the abnormal electronic control unit belongs based on the identification information; an output unit (205) that outputs the security log including the identification information, the abnormality information, and the group information indicating the group determined by the group determination unit, The attack estimation verification device (110) according to claim 1.
9. The attack estimation verification device further includes a feature number information acquisition unit (202) that acquires feature number information indicating the maximum number of features assumed to be possessed by each of the plurality of electronic control devices, The group determination unit determines the characteristics that are assumed to be possessed by the abnormal electronic control unit based on the characteristic number information. The attack estimation verification device according to claim 8.
10. The attack estimation verification device and the electronic control system are mounted on a moving body. The attack estimation and verification device according to any one of claims 1 to 9.
11. the electronic control system is an electronic control system mounted on a moving body, the attack estimation verification device is a server device located outside the mobile body; The attack estimation and verification device according to any one of claims 1 to 9.
12. An attack estimation verification method executed by an attack estimation verification device, the attack estimation and verification device includes an attack / anomaly relationship table storage unit that stores an attack / anomaly relationship table that indicates a correspondence relationship between attack information indicating a type of attack, predicted anomaly information indicating an anomaly predicted to occur when the attack is received, and predicted group information indicating a group in which the predicted anomaly will occur; The attack estimation verification method includes: Acquire a security log including identification information indicating an abnormal electronic control device that is an electronic control device in which an abnormality has been detected among a plurality of electronic control devices constituting an electronic control system, abnormality information indicating the abnormality detected in the abnormal electronic control device, and group information indicating the group to which the abnormal electronic control device belongs, which is a group obtained by grouping one or more electronic control devices among the plurality of electronic control devices according to the characteristics that each of the plurality of electronic control devices actually has and is assumed to have; estimating an attack on the electronic control system from a combination of the predicted abnormality information and the predicted group information corresponding to the combination of the abnormality information and the group information; In a verification unit, when the estimated attack is an attack related to the characteristics assumed to be possessed by the abnormal electronic control device indicated by the identification information, it is determined that the grouping of the groups is inappropriate or that the characteristics assumed to be possessed by the abnormal electronic control device are inappropriate; notifying the verification result by the verification unit; Attack estimation verification method.
13. An attack estimation verification program executable by an attack estimation verification device, the attack estimation and verification device includes an attack / anomaly relationship table storage unit that stores an attack / anomaly relationship table that indicates a correspondence relationship between attack information indicating a type of attack, predicted anomaly information indicating an anomaly predicted to occur when the attack is received, and predicted group information indicating a group in which the predicted anomaly will occur; The attack estimation verification program Acquire a security log including identification information indicating an abnormal electronic control device that is an electronic control device in which an abnormality has been detected among a plurality of electronic control devices constituting an electronic control system, abnormality information indicating the abnormality detected in the abnormal electronic control device, and group information indicating the group to which the abnormal electronic control device belongs, which is a group obtained by grouping one or more electronic control devices among the plurality of electronic control devices according to the characteristics that each of the plurality of electronic control devices actually has and is assumed to have; estimating an attack on the electronic control system from a combination of the predicted abnormality information and the predicted group information corresponding to the combination of the abnormality information and the group information; In a verification unit, when the estimated attack is an attack related to the characteristics assumed to be possessed by the abnormal electronic control device indicated by the identification information, it is determined that the grouping of the groups is inappropriate or that the characteristics assumed to be possessed by the abnormal electronic control device are inappropriate; notifying the verification result by the verification unit; Attack estimation verification program.
Citation Information
Patent Citations
Security device, attack specification method, and program
JP2020123307A
Unauthorized intrusion prevention device, unauthorized intrusion prevention method, and unauthorized intrusion prevention program
JP2022017873A
Attack analysis device, attack analysis method, and attack analysis program
JP2022153081A
Autonomous Vehicle Systems
JP2022524920A
Unauthorized intrusion prevention device, unauthorized intrusion prevention method, and unauthorized intrusion prevention program
US20220017041A1