Information processing device, information processing system, information processing program, information processing method
The described system accurately identifies vehicle unit compromises by analyzing security logs and performing integrity verification, addressing the challenge of distinguishing attacks from other abnormalities in vehicle systems.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-09-30
- Publication Date
- 2026-03-25
AI Technical Summary
Existing security log analysis methods for vehicles fail to accurately distinguish between attacks and other causes of abnormalities, leading to decreased estimation accuracy.
An information processing device and method that includes a log acquisition unit, log analysis unit, verification instruction unit, breach determination unit, and attack estimation unit to determine the integrity of in-vehicle units based on security logs, using a multi-layered defense system with different security levels and integrity verification to identify potential attacks.
Enables high-accuracy determination of whether in-vehicle units have been compromised by attacks, reducing unnecessary communication and processing load, and accurately estimating the type of attack based on integrity verification results.
Smart Images

Figure 0007835142000001 
Figure 0007835142000002 
Figure 0007835142000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a technique for estimating an attack on a vehicle based on a security log indicating an abnormality that has occurred in the vehicle.
Background Art
[0002] The following Patent Document 1 describes a technique for making an estimation regarding an attack on a vehicle that causes an abnormality based on a security log indicating an abnormality that has occurred in the vehicle.
Prior Art Document
Patent Document
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, the security log not only indicates an abnormality that has occurred in the vehicle due to the vehicle being attacked and invaded, but may also indicate an abnormality that has occurred in the vehicle due to a cause different from the vehicle being attacked and invaded.
[0005]
[0006] As a result of the inventors' detailed examination, it has been found that when making an estimation regarding an attack on a vehicle based on a security log indicating an abnormality that has occurred in the vehicle due to a cause different from the vehicle being attacked and invaded, the accuracy of the estimation regarding the attack decreases.
Means for Solving the Problems
[0007] An information processing device according to one aspect of the present disclosure includes a log acquisition unit (112, S8), a log analysis unit (122, S10), a verification instruction unit (140, S13), a breach determination unit (124, S26), and an attack estimation unit (126, S27).
[0008] The log acquisition unit acquires security logs indicating abnormalities that occurred in the vehicle (4). Based on the security logs acquired by the log acquisition unit, the log analysis unit determines whether or not to instruct the vehicle verification unit (18, S17~S19) to verify the integrity of the in-vehicle units (10, 20, 30, 40, 50, 60). If the log analysis unit determines that it is appropriate to instruct the verification unit to verify the integrity of the in-vehicle units, the verification instruction unit instructs the verification unit to perform the integrity verification.
[0009] The intrusion detection unit determines whether the in-vehicle unit has been compromised based on the verification results of the integrity verification performed by the verification unit. The attack estimation unit makes estimations about the attack that caused the intrusion based on the intrusion detection result from the intrusion detection unit and the security log.
[0010] Other embodiments of the information processing program of this disclosure cause a computer to function as the aforementioned information processing device. Another aspect of this disclosure is an information processing method performed by the information processing device described above.
[0011] Information processing systems in other aspects of this disclosure include an in-vehicle information processing device (10, 20, 30, 40, 50, 60) and an external information processing device (100) that communicates with the in-vehicle information processing device.
[0012] The in-vehicle information processing device comprises a monitoring unit (12, S1, S2) and a verification unit (18, S17~S19). The monitoring unit generates security logs indicating abnormalities that occur in the vehicle (4). The verification unit verifies the integrity of the in-vehicle units (10, 20, 30, 40, 50, 60).
[0013] The external information processing device includes a log acquisition unit (112, S8), a log analysis unit (122, S10), a verification instruction unit (140, S13), a breach determination unit (124, S26), and an attack estimation unit (126, S27).
[0014] The log acquisition unit acquires security logs from the in-vehicle information processing device. The log analysis unit determines, based on the security logs acquired by the log acquisition unit, whether or not to instruct the vehicle verification unit to verify the integrity of the in-vehicle unit. If the log analysis unit determines that it is appropriate to instruct the verification unit to verify the integrity, the verification instruction unit instructs the verification unit to perform the integrity verification.
[0015] The intrusion detection unit determines whether the in-vehicle unit has been compromised based on the verification results of the integrity verification performed by the verification unit. The attack estimation unit makes estimations about the attack that caused the intrusion based on the intrusion detection result from the intrusion detection unit and the security log.
[0016] Another aspect of this disclosure is an information processing method performed by the aforementioned information processing system. With this configuration, it is possible to determine with high accuracy whether or not an in-vehicle unit has been compromised by an attack on the vehicle, based on the results of the integrity verification of the in-vehicle unit verified based on security logs.
[0017] As a result, based on the intrusion detection result indicating whether or not the in-vehicle unit was compromised by the attack on the vehicle, and the security log indicating the anomaly caused by this intrusion, it is possible to estimate the attack on the vehicle with high accuracy. [Brief explanation of the drawing]
[0018] [Figure 1] A block diagram showing the configuration of an information processing system. [Figure 2] A block diagram showing the configuration of the vehicle's multi-layered defense system. [Figure 3] A block diagram showing the configuration of an in-vehicle information processing unit. [Figure 4] A block diagram showing the configuration of the external information processing device. [Figure 5] Explanatory diagram showing the configuration of the security log. [Figure 6] Block diagram showing the configuration of the analysis unit of the off-vehicle information processing device. [Figure 7] Explanatory diagram showing the configuration of the abnormal attack table before modification. [Figure 8] Sequence diagram showing information processing. [Figure 9] Explanatory diagram showing the configuration of the abnormal attack table after modification.
Mode for Carrying Out the Invention
[0019] Hereinafter, embodiments of the present disclosure will be described while referring to the drawings. [1. Configuration] As shown in FIG. 1, the information processing system 2 of the present embodiment includes ECUs 10, 20, 30, 40, 50, 60 which are information processing devices mounted on the vehicle 4, and a server 100 which is an off-vehicle information processing device. ECU is an abbreviation for Electronic Control Unit. ECU10 , at least any one of 20, 30, 40, 50, 60, the vehicle 4, and the server 100 communicate with each other via, for example, a wireless communication network 6.
[0020] On the vehicle 4, in order to enhance the security against malicious attacks from the outside such as cyber attacks, multiple layers of defense with different security levels are adopted. In the example of the multi-layer defense shown in FIG. 2, the vehicle 4 has three defense layers: a first layer, a second layer, and a third layer. In the example of the multi-layer defense shown in FIG. 2, the vehicle 4 has three defense layers: a first layer, a second layer, and a third layer.
[0021] In FIG. 2, ECU#1, ECU#2, and DLC belong to the first layer, ECU#3 belongs to the second layer, and ECU#4 and ECU#5 belong to the third layer. DLC is an abbreviation for Data Link Connector. ECUs can communicate with each other via a CAN or Ethernet network. CAN is an abbreviation for Controller Area Network. CAN and Ethernet are registered trademarks. trademarks.
[0022] ECU#1 and ECU#2, belonging to the first layer, function as a TCU and IVI, respectively, which have communication functions with the outside of the vehicle 4. TCU stands for Telematics Control Unit, and IVI is an abbreviation for Telematics Control Unit. ECU#1 and ECU#2 are abbreviations for In Vehicle Infotainment. Both devices are equipped with security features that monitor incoming data.
[0023] Furthermore, an external tool is connected to the DLC belonging to the first layer, for example, to acquire diagnostic information from the OBD2 (not shown) of vehicle 4. OBD stands for On Board Diagnostics. ECU#3, which belongs to the second layer, is a gateway ECU equipped with security functions that monitor data communicated between the network of ECU#1 and ECU#2 in the first layer and the network of ECU#4 and ECU#5 in the third layer.
[0024] ECU#3 implements different security measures than those described above for ECU#1 and ECU#2. The area monitored by ECU#3 has a different security level than the first layer, which is the area protected by ECU#1 and ECU#2.
[0025] ECU#4 and ECU#5, which belong to the third layer, are, for example, vehicle control ECUs that control the movement of vehicle 4. Only data that has passed the security function of ECU#3, which belongs to the second layer, is communicated to ECU#4 and ECU#5. The third layer is an area with a different security level than the second layer.
[0026] Figure 3 shows an example of the configuration of ECUs 10, 20, 30, 40, 50, and 60 installed in vehicle 4. As mentioned above, the configuration of security functions may differ depending on the ECUs 10, 20, 30, 40, 50, and 60.
[0027] ECUs 10, 20, 30, 40, 50, and 60 are equipped with microcomputers, for example, a CPU, ROM, RAM, flash memory, etc. (not shown). The CPUs of ECUs 10, 20, 30, 40, 50, and 60 execute programs stored in the ROM or flash memory, which in turn enables the monitoring unit 12 and verification unit 18, described later, to perform information processing.
[0028] The monitoring unit 12 has security sensors that detect abnormalities in in-vehicle units such as ECUs 10, 20, 30, 40, 50, 60 and the network, and monitors whether or not an abnormality has occurred in an in-vehicle unit. When the monitoring unit 12 detects an abnormality in an in-vehicle unit, it generates a security log.
[0029] The monitoring unit 12 has security sensors such as a firewall, HIDS, IDS for detecting abnormalities in networks such as CAN and Ethernet, and an Auth function. HIDS stands for Host Based Intrusion Detection System, IDS stands for Intrusion Detection System, and Auth stands for Authentication.
[0030] The analysis unit 14 analyzes whether the security log generated by the monitoring unit 12 may have been generated as a result of an attack on vehicle 4. For example, if the analysis unit 14 finds that the data cycle on the vehicle 4's network is out of sync, and that security logs indicate that processes that are not normally running are being executed on the ECU, it determines that an attack on vehicle 4 may be the cause. In this case, the analysis unit 14 sends the security logs from the communication unit 16 to the server 100.
[0031] In contrast, if, for example, the security log simply indicates a shift in the data cycle on the vehicle 4's network, the analysis unit 14 determines that there is no possibility that an attack on vehicle 4 is the cause. In this case, the analysis unit 14 does not send the security log from the communication unit 16 to the server 100.
[0032] The communication unit 16 communicates with the server 100 via the wireless communication network 6. When the verification unit 18 is instructed by the server 100 to verify the integrity of its own ECU or other ECUs, or in-vehicle units such as VMs or software running on the ECUs, it performs verification of the in-vehicle units. VM stands for Virtual Machine. The verification unit 18 performs security checks on hardware, etc. The functionality protects the verification unit 18 itself from being compromised by attacks.
[0033] As shown in Figure 4, the server 100 includes a communication unit 110, a log acquisition unit 112, a security log DB 114, an analysis unit 120, a verification instruction unit 140, and a reference value DB 142.
[0034] Furthermore, as shown in Figure 6, the analysis unit 120 of the server 100 includes a log analysis unit 122, a breach detection unit 124, an attack estimation unit 126, an output unit 128, and an abnormal attack DB 130.
[0035] Server 100 is equipped with a computer having, for example, a CPU, ROM, RAM, flash memory, etc. (not shown). When the CPU of Server 100 executes a program stored in the storage device, information processing is performed by the log acquisition unit 112, the log analysis unit 122, the infringement determination unit 124, the attack estimation unit 126, and the verification instruction unit 140.
[0036] The communication unit 110 communicates with the vehicle 4 via the wireless communication network 6. The log acquisition unit 112 acquires the security log received by the communication unit 110 from the vehicle 4 and stores it in the security log DB 114.
[0037] As shown in Figure 5, the security log acquired by the log acquisition unit 112 consists of the vehicle ID, the time the anomaly was detected, the location within the vehicle 4 where the anomaly was detected, and the ID of the sensor that detected the anomaly. The security log may also include other information.
[0038] The log analysis unit 122 determines whether or not to instruct the vehicle 4's verification unit 18 to verify the integrity of the in-vehicle unit, based on the security logs acquired by the log acquisition unit 112 and stored in the security log DB 114.
[0039] For example, the log analysis unit 122 determines that if one or more of the following conditions (1) and (2) are met, it will instruct the vehicle 4's verification unit 18 to verify the integrity of the in-vehicle unit. (1) The security log was generated by the detection function of the security sensor to detect the compromise of vehicle 4 due to a cyberattack.
[0040] (2) The security log was generated when the defense functions from the second layer onward in the aforementioned multi-layer defense system successfully defended against the attack. However, from the time the verification unit 18 of vehicle 4 is instructed to perform a integrity check until the integrity check is completed During that time, it may be decided that no further verification of completeness is necessary.
[0041] The infringement determination unit 124 determines whether the in-vehicle unit has been infringed based on the determination result of the verification instruction unit 140 regarding the integrity verification result obtained from the vehicle 4 by the verification unit 18. The determination by the verification instruction unit 140 regarding the integrity verification result will be described later.
[0042] The attack estimation unit 126 estimates the attack that caused the breach based on the breach determination result from the breach determination unit 124, the security log, and the abnormal attack table of the abnormal attack DB. The output unit 128 outputs the estimation result from the attack estimation unit 126 to a DB or the like (not shown).
[0043] The abnormal attack DB130 has, for example, the structure of the abnormal attack table shown in Figure 7. The abnormal attack DB130 represents the relationship between the ECUs belonging to each layer of the multi-layered defense, the type of abnormality that occurs in each ECU, the attack that causes the abnormality in each ECU, the location of the attack's starting point, the location of the target that is attacked from the attack's starting point, and the evaluation value. The attack path is shown by the location of the attack's starting point and the location of the target.
[0044] In the attack origin, "0x00" indicates that the attack originates outside of vehicle 4. In the attack origin and target, "0x01" to "0x05" represent the numbers of the ECUs being attacked.
[0045] In Figure 7, the evaluation values "1" and "0" are pre-set values based on the system configuration of vehicle 4, the attacks expected to be carried out against vehicle 4, and the expected abnormalities caused by the attacks. An evaluation value of "1" indicates that the corresponding abnormality may occur if attacked. An evaluation value of "0" indicates that the corresponding abnormality will not occur in the expected attack.
[0046] In Figure 7, the abnormalities are classified by the type of abnormality that occurs in the ECU. In contrast, if multiple VMs are running in each ECU, the abnormalities may be classified by the type of abnormality that occurs in each VM. Furthermore, if multiple software programs are running in each ECU, the abnormalities may be classified by the type of abnormality that occurs in each software program.
[0047] The verification instruction unit 140, like the verification unit 18 of the vehicle 4, is protected by hardware and other security functions to prevent the verification instruction unit 140 itself from being compromised by attacks. When the verification instruction unit 140 determines that the log analysis unit 122 should instruct a integrity verification, it instructs the vehicle 4 to perform an integrity verification of the target in-vehicle unit.
[0048] Furthermore, the verification instruction unit 140 instructs the vehicle 4 to verify the integrity of the in-vehicle unit in one of the following patterns (1) to (4). (1) All onboard units installed in vehicle 4.
[0049] (2) The vehicle unit in which the abnormality was detected. (3) The vehicle unit in which the abnormality was detected, and any vehicle unit that is physically or logically related to the vehicle unit in which the abnormality was detected.
[0050] An in-vehicle unit that is physically or logically related to the in-vehicle unit in which an anomaly was detected refers to, for example, an in-vehicle unit that is connected to the in-vehicle unit in which the anomaly was detected via a network, or an in-vehicle unit that performs processing based on the processing results of the in-vehicle unit in which the anomaly was detected.
[0051] (4) Vehicle units other than the vehicle unit in which the abnormality was detected. For example, in response to the detection of an abnormality If a malfunction is detected in a reliable security sensor, the integrity of all vehicle units other than the one in which the security sensor detected the malfunction will be verified.
[0052] Furthermore, the verification instruction unit 140 instructs the vehicle 4 to verify the integrity of the in-vehicle unit with respect to items (1) and (2) described below, for example. (1) The designated location on the vehicle unit is one of the following (a) to (d).
[0053] (1a) Is the specified program code stored in memory? In this case, only program code that does not change during execution may be specified as the target of verification. Furthermore, program code verification may begin with the program code that is most likely to be compromised in the event of an attack.
[0054] (1b) Is the specified data stored in memory? For example, is the data in the software configuration file read when the software is executed at the specified value? Or, is the software control data generated when the software is executed at the specified value? In this case, only data that does not change during execution may be specified as the target of verification.
[0055] (1c) Hardware configuration. For example, is the device with the specified ID connected? Or is the specified interface being used? (1d) Software configuration. For example, whether the software is composed of a predetermined library, or whether the software's memory map is configured as predetermined, or whether the dynamic library is of a predetermined version.
[0056] (2) All components of the in-vehicle unit. For example, all of (a) to (d) mentioned above. Furthermore, the verification instruction unit 140 determines the order in which the in-vehicle units instruct the vehicle 4's verification unit 18 to perform integrity verification, for example, in one of the following patterns (1) to (3).
[0057] (1) Instruct all in-vehicle units to be verified to undergo integrity verification simultaneously. (2) In a multi-layered defense system, the integrity verification of in-vehicle units belonging to shallower layers is instructed to be performed first. For example, if an abnormality is detected in an in-vehicle unit of the second layer, the integrity verification of in-vehicle units belonging to the first layer, which is shallower than the second layer, is instructed to be performed first.
[0058] (3) In a multi-layered defense system, the system will first instruct that the integrity of the in-vehicle units belonging to deeper layers be verified. For example, if an abnormality is detected in an in-vehicle unit of the first layer, the system will first instruct that the integrity of the in-vehicle units belonging to the second layer, which is deeper than the first layer, be verified.
[0059] Furthermore, the verification instruction unit 140 compares the value of the integrity verification result performed by the verification unit 18 with the normal value of the integrity verification result stored in the reference value DB 142 to determine whether or not the integrity of the in-vehicle unit is maintained.
[0060] The verification instruction unit 140 determines that the integrity of the in-vehicle unit is maintained if the value of the integrity verification result performed by the verification unit 18 matches the normal value stored in the reference value DB 142. Conversely, the verification instruction unit 140 determines that the integrity of the in-vehicle unit is compromised if the value of the integrity verification result performed by the verification unit 18 does not match the normal value stored in the reference value DB 142.
[0061] [2. Processing] Based on Figure 8, the information processing performed by the information processing system 2, which includes ECUs 10, 20, 30, 40, 50, and 60 and server 100, will be described.
[0062] In S1 and S2, the monitoring unit 12 of the vehicle 4 monitors whether or not there are any abnormalities in its own ECU and the network to which it is connected. In S3 and S4, if the monitoring unit 12 detects an abnormality in the in-vehicle unit, it sends a security log to the analysis unit 14 of the vehicle 4, which consists of a vehicle ID that identifies the vehicle 4, the time the abnormality was detected, the location where the abnormality was detected, and the sensor ID of the security sensor that detected the abnormality.
[0063] In S7, the analysis unit 14 analyzes the security logs received from the monitoring unit 12 in S5 and S6 as described above and determines whether the logs should be sent to the server 100 or not. If the logs should be sent to the server 100, the analysis unit 14 sends the security logs to the server 100 from the communication unit 16.
[0064] In S8, the log acquisition unit 112 of the server 100 receives the security log transmitted from the vehicle 4 from the communication unit 110 and stores it in the security log DB 114 in the data structure shown in Figure 5.
[0065] In S10, the log analysis unit 122 of the analysis unit 120 analyzes the security logs obtained from the security log DB 114 in S9 and determines whether or not to instruct the vehicle 4 to verify the integrity of the in-vehicle unit of the vehicle 4 in question.
[0066] If the log analysis unit 122 determines in S10 that it should instruct vehicle 4 to verify the integrity of the vehicle's onboard unit, then in S11 it requests the verification instruction unit 140 to instruct vehicle 4 to verify the integrity of the vehicle's onboard unit.
[0067] In S13, when the verification instruction unit 140 receives a request from the log analysis unit 122 in S12 to verify the integrity of the vehicle-mounted unit of the relevant vehicle 4, it instructs the relevant vehicle 4 to verify the integrity of the vehicle-mounted unit.
[0068] In S15 and S16, for example, when the communication unit 16 of the ECU 50 has a verification unit 16, in S14 the verification unit 18 instructs the relevant ECUs, including itself ECU 50, to perform a integrity verification.
[0069] In S17, the verification unit 18 of the ECU 50 having the communication unit 16 performs a verification of the integrity of the ECU 50 if the ECU 50 is subject to integrity verification. In S18 and S19, the verification unit 18 of another ECU, which has been instructed by the verification unit 18 of the ECU 50 to verify its integrity, performs a verification of the integrity of its own ECU.
[0070] The verification unit 18, which performed the integrity verification, adds the latest startup time when its own ECU was started to the integrity verification result in S20 and S21, and transmits it to the ECU 50 which has the communication unit 16. In S23, the verification unit 18 of the ECU 50, which has a communication unit 16, transmits to the server 100 from the communication unit 16 the verification result of the integrity of its own ECU 50, which is the result of the integrity verification of its own ECU 50 plus the latest startup time when its own ECU 50 was started.
[0071] In S24, the verification instruction unit 140 of the server 100 obtains the integrity verification result, including the startup time, received by the communication unit 110 from the vehicle 4. The verification instruction unit 140 then performs a determination process to determine whether the integrity of the vehicle unit to be verified is maintained, whether its integrity is compromised, or whether it is impossible to determine whether its integrity is maintained or not.
[0072] Here, if the startup time of the vehicle unit is later than the detection time when an abnormality was detected in the vehicle unit stored in the security log DB114, then the vehicle unit started up after the abnormality was detected. The anomaly may have been resolved when the system is started and integrity verification is performed.
[0073] Therefore, the verification instruction unit 140 cannot determine whether the integrity of the in-vehicle unit is maintained if the activation time is later than the detection time. In contrast, if the detection time is later than the startup time, the in-vehicle unit has not restarted from the time the abnormality is detected until the integrity verification is performed. Therefore, based on the integrity verification results, it is possible to determine whether or not the integrity of the in-vehicle unit is maintained.
[0074] Therefore, if the detection time is later than the startup time, the verification instruction unit 140 reads the verification result for a normal integrity verification from the reference value DB142 and determines whether the normal verification result matches the verification result obtained from the vehicle 4.
[0075] The verification instruction unit 140 determines that the integrity of the in-vehicle unit is maintained if the normal verification result matches the acquired verification result, and determines that the integrity of the in-vehicle unit is not maintained but is compromised if the normal verification result matches the acquired verification result.
[0076] In S25, the verification instruction unit 140 transmits the result of the judgment process for the aforementioned verification result to the infringement determination unit 124. In S26, the infringement determination unit 124 determines whether or not the in-vehicle unit has been infringed based on the determination result for the verification result obtained from the verification instruction unit 140.
[0077] The infringement determination unit 124 determines that the in-vehicle unit has not been infringed if the integrity of the in-vehicle unit is maintained. The infringement determination unit 124 determines that the in-vehicle unit has been infringed if the integrity of the in-vehicle unit has been compromised.
[0078] If the infringement determination unit 124 cannot determine whether the in-vehicle unit is in good condition, it cannot determine whether the in-vehicle unit is infringed. In S27, the attack estimation unit 126 sets an evaluation value for the attack that caused the intrusion into the in-vehicle unit based on the determination result of the intrusion determination unit 124, and then estimates what kind of attack was carried out against the in-vehicle unit.
[0079] First, the attack estimation unit 126 increases the evaluation value of the abnormality that is expected to occur in the in-vehicle unit, which has been determined to be compromised by the intrusion determination unit 124, by a predetermined amount.
[0080] For example, in Figure 7, if ECU#1 is determined to be compromised, the attack estimation unit 126 increases the evaluation value of the anomaly that is expected to occur in ECU#1 from "1" to "2", as shown in Figure 9.
[0081] In response, the attack estimation unit 126 lowers the evaluation value of the anomaly that is expected to occur in the vehicle unit by a predetermined amount for the vehicle unit that the intrusion determination unit 124 has determined not to have been compromised.
[0082] For example, in Figure 7, if ECU#2 is determined not to have been compromised, the attack estimation unit 126 lowers the evaluation value of the anomaly that is expected to occur in ECU#2 from "1" to "0", as shown in Figure 9.
[0083] Thus, security logs were generated for both ECU#1 and ECU#2, which are entry points in the same Layer 1. However, based on the integrity verification results, ECU#1 and ECU#2 and Of these, ECU#1 was determined to have been attacked, while ECU#2 was not.
[0084] For example, in this embodiment, if ECU#1 is the TCU and ECU#2 is the IVI, it is determined that only the TCU was attacked. Furthermore, for in-vehicle units whose compromise status the compromise determination unit 124 could not determine, the attack estimation unit 126 performs either (1) or (2) below on the evaluation value of the abnormality expected to occur in the in-vehicle unit.
[0085] (1) If it is determined that the vehicle unit from which the attack originated has been compromised, in the case of an in-vehicle unit that was not determined to have been compromised, the evaluation value of the anomaly that is expected to occur in the vehicle unit that was attacked will be increased by a value lower than the increase in the evaluation value of the vehicle unit from which the attack originated.
[0086] This is because the in-vehicle unit that initiates the attack and the in-vehicle unit that is under attack are physically or logically related via a network or other means. Therefore, if the in-vehicle unit that initiates the attack is compromised, the in-vehicle unit that is under attack may also be compromised.
[0087] For example, in Figure 7, ECU#3 is the target of attack C, which originates from ECU#1. In this case, it was determined that ECU#1 was compromised, but it was not possible to determine whether ECU#3 was compromised. In this case, since ECU#1 is compromised, the evaluation value of the anomaly that is expected to occur in ECU#3 in attack C is increased by a smaller amount than the increase from "1" to "2", for example, to "1.1".
[0088] (2) For an in-vehicle unit where it could not be determined whether or not it was compromised, either the in-vehicle unit that was the starting point of the attack targeting this unit was determined not to have been compromised, or it could not be determined whether or not the in-vehicle unit that was the starting point of the attack targeting this unit was compromised. In this case, the evaluation value of the anomaly that is expected to occur in the attacked in-vehicle unit will not be changed and will remain as is.
[0089] For example, in Figure 7, ECU#3 is the target of attack D, which originates from ECU#2. If it is determined that ECU#3 has been compromised and that ECU#2, the starting point of attack D, has not been compromised, the attack estimation unit 126 does not change the evaluation value of abnormality A, which is assumed to occur in ECU#3 in attack D, from "1".
[0090] Furthermore, in Figure 7, ECU#5 is both the starting point and target of attack Z. If it is not possible to determine whether or not ECU#5 has been compromised in this instance, the starting point of attack X against ECU#5 is ECU#5 itself, so the attack estimation unit 126 does not change the evaluation values of abnormalities B and C, which are assumed to occur in ECU#5 during attack X, from "1".
[0091] In this way, the attack estimation unit 126 adjusts the anomaly evaluation value corresponding to the attack shown in Figure 7, which is stored as an anomaly attack table in the anomaly attack DB, based on the integrity verification results as shown in Figure 9. Then, after adjusting the evaluation value, the attack estimation unit 126 estimates which type of attack, as shown in Figure 9, was carried out.
[0092] The estimation is calculated by measuring the similarity between the measured anomaly information, which shows the combination of anomalies actually observed in vehicle 4, and the predicted anomaly information, which is stored in the anomaly attack DB as an anomaly attack table and shows the combination of anomalies and anomaly evaluation values that are predicted to occur in the electronic control system when attacked for each type of attack.
[0093] Specifically, this involves representing the data sequence of actual anomaly information as a vector, and the data sequence of predicted anomaly information as a vector. The dot product of the vector representation of the data column and the result of dividing the dot product by the number of elements with values greater than 0 in the predicted anomaly information vector is calculated, and the row in the anomaly attack table with the highest result is extracted. If the calculation result exceeds a predetermined value, it is estimated that the corresponding attack was carried out against the ECU, which is an in-vehicle unit.
[0094] For example, if abnormalities A, B, and C are observed in ECU#1 as measured abnormality information, referring to Figure 9, in the case of attack A, the evaluation values of abnormalities A and C in ECU#1 are each 2, and the evaluation value of abnormality B in ECU#1 is 0, so the result of calculating the dot product is 4. Since there are two abnormalities, abnormalities A and C, whose evaluation values are greater than 0, dividing 4 by 2 gives 2, which is the similarity between attack A and the measured abnormality information.
[0095] On the other hand, in the case of attack C, the evaluation value of anomaly C in ECU#1 is 2, and the evaluation values of anomalies A and B in ECU#1 are 0, so the result of the dot product calculation is 2. Furthermore, the anomalies with evaluation values greater than 0 are anomaly C in ECU#1 and anomalies A and B in ECU#3, so 2 divided by 3 is 2 / 3, which is the similarity between attack C and the measured anomaly information.
[0096] Furthermore, since the evaluation values corresponding to anomalies A, B, and C in ECU#1 for attacks B, D, and X are all 0, the final similarity will also be 0. Therefore, we evaluate whether the similarity between attack A, which has the largest value, and the measured anomaly information is above a predetermined value, and estimate whether or not attack A occurred.
[0097] Although multiple cases are described for increasing the evaluation value by a predetermined amount and decreasing it by a predetermined amount, you may apply all of them, or you may selectively apply one or more of them. When the attack estimation unit 126 estimates that an attack has been carried out against the in-vehicle unit, the output unit 128 outputs the estimation result to a database (not shown) or the like.
[0098] [3. Effects] According to the embodiments described above, the following effects can be obtained. (3a) Based on the results of the verification of the integrity of the in-vehicle unit, which has been verified based on the security logs, it is possible to determine with high accuracy whether or not the in-vehicle unit has been compromised by an attack on vehicle 4.
[0099] As a result, based on the intrusion determination result indicating whether or not the in-vehicle unit was compromised by the attack on vehicle 4, and the security log indicating the anomaly caused by this intrusion, the attack on vehicle 4 can be estimated with high accuracy.
[0100] (3b) If it could not be determined whether an in-vehicle unit was compromised, and the in-vehicle unit that targeted this unit was determined to be compromised, then any other in-vehicle units that are physically or logically related to the attack may also have been compromised by the attack.
[0101] Therefore, in the above-described embodiment, if it is determined that the in-vehicle unit that initiated the attack has been compromised, the evaluation value of the target in-vehicle unit, which could not be determined to have been compromised, is increased by a value lower than the increase in the evaluation value of the compromised in-vehicle unit. This makes it possible to set the evaluation value of the anomaly that is expected to occur in the in-vehicle unit where an anomaly was detected but it could not be determined whether or not it was compromised, with high accuracy.
[0102] (3c) Before sending security logs from vehicle 4 to server 100, the analysis unit 14 of vehicle 4 analyzes in advance whether or not the security logs should be sent to server 100, that is, whether or not they should be sent to server 100. This minimizes the amount of communication between vehicle 4 and server 100.
[0103] (3d) For multiple in-vehicle units belonging to the same layer, security logs were generated, but based on the integrity verification results, it can be determined that only one of the in-vehicle units was attacked, and the other in-vehicle units were not.
[0104] For example, in this embodiment, security logs were generated for ECU#1 and ECU#2, but the integrity verification results indicate that only ECU#1 was attacked and ECU#2 was not. This allows for highly accurate determination of which ECU was attacked, even if they belong to the same entry point, based on the integrity verification results.
[0105] (3e) Since the integrity verification of the target in-vehicle unit is triggered by the security log, the processing load can be reduced compared to performing integrity verification on the in-vehicle unit on a regular basis.
[0106] In the embodiments described above, ECUs 10, 20, 30, 40, 50, and 60 correspond to in-vehicle information processing devices and in-vehicle units, while server 100 corresponds to an information processing device outside the vehicle. Furthermore, in Figure 8, S8 corresponds to the processing of the log acquisition unit 112, S10 corresponds to the processing of the log analysis unit 122, S13 corresponds to the processing of the verification instruction unit 140, S17 to S19 correspond to the processing of the verification unit 18, S26 corresponds to the processing of the infringement determination unit 124, and S27 corresponds to the processing of the attack estimation unit 126.
[0107] Furthermore, the abnormal attack table shown in the structure of the abnormal attack DB130 corresponds to a correspondence table between the type of abnormality, the attack, and the evaluation value. [4. Other Embodiments] Although embodiments of this disclosure have been described above, this disclosure is not limited to the embodiments described above and can be implemented in various modified forms.
[0108] (4a) In the embodiment described above, the external server 100 is equipped with the functions of a log analysis unit 122, a breach determination unit 124, an attack estimation unit 126, and a verification instruction unit 140, but is not limited to this.
[0109] For example, in addition to the functions of the verification unit 18, vehicle 4 may also have some of the functions of the log analysis unit 122, the infringement determination unit 124, the attack estimation unit 126, and the verification instruction unit 140. Alternatively, vehicle 4 may not communicate with server 100 and may have all the functions of the verification unit 18, log analysis unit 122, intrusion determination unit 124, attack estimation unit 126, and verification instruction unit 140.
[0110] (4b) In the embodiment described above, the server 100 was used as an external information processing device and performed attack estimation processing for multiple vehicles 4, but the embodiment is not limited to this. For example, a service tool or personal computer may be connected to the vehicle 4 wirelessly or via a wired connection as an external information processing device, and one external information processing device may be used to estimate an attack against the vehicle 4 for each vehicle 4.
[0111] (4c) The in-vehicle unit mentioned above may not be a physical information processing device, but rather an information processing device composed of software, such as a VM. (4d) In the embodiments described above, an abnormal attack table was used to estimate attacks against vehicle 4, but this is not limited to this. For example, attacks against vehicle 4 may be estimated without using an abnormal attack table based on security logs and integrity verification results.
[0112] (4e) The ECUs 10, 20, 30, 40, 50, 60 and the server 100 and its method described herein perform one or more functions embodied by a computer program. This may be achieved by a dedicated computer provided by configuring a processor and memory programmed to do so.
[0113] Alternatively, the ECUs 10, 20, 30, 40, 50, 60 and the server 100 and the method described herein may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits.
[0114] Alternatively, the ECUs 10, 20, 30, 40, 50, 60 and the server 100 and their methods described herein may be implemented by one or more dedicated computers comprising a combination of a processor and memory programmed to perform one or more functions and a processor comprising one or more hardware logic circuits.
[0115] Furthermore, the computer program may be stored on a computer-readable, non-transitional tangible recording medium as instructions executed by the computer. The method for realizing the functions of each part included in ECUs 10, 20, 30, 40, 50, 60 and server 100 does not necessarily have to include software; all of these functions may be realized using one or more hardware components.
[0116] (4f) Multiple functions of one component in the above-described embodiment may be realized by multiple components, or one function of one component may be realized by multiple components. Also, multiple functions of multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Furthermore, some of the configurations of the above-described embodiments may be omitted. Furthermore, at least some of the configurations of the above-described embodiments may be added to or replaced with the configurations of other above-described embodiments.
[0117] (4g) In addition to the above-mentioned in-vehicle information processing devices ECUs 10, 20, 30, 40, 50, 60 and the external information processing device server 100, the present disclosure can also be realized in various forms, such as an information processing system 2 comprising the ECUs 10, 20, 30, 40, 50, 60 and the server 100, an information processing program for causing the ECUs 10, 20, 30, 40, 50, 60 and the server 100 to function as a computer, a non-transitional physical recording medium such as semiconductor memory on which this program is recorded, and an information processing method. [Explanation of symbols]
[0118] 2: Information processing system, 4: Vehicle, 10, 20, 30, 40, 50, 60: ECU (In-vehicle information processing unit, in-vehicle unit), 12: Monitoring unit, 18: Verification unit, 100: Server (In-vehicle information processing unit), 112: Log acquisition unit, 122: Log analysis unit, 124: Intrusion detection unit, 126: Attack estimation unit, 140: Verification instruction unit
Claims
1. A log acquisition unit (112, S8) configured to acquire security logs indicating abnormalities that occurred in the vehicle (4), A log analysis unit (122, S10) is configured to determine whether or not to instruct the vehicle's verification unit (18, S17-S19) to verify the integrity of the in-vehicle units (10, 20, 30, 40, 50, 60) based on the security log acquired by the log acquisition unit, When the log analysis unit determines that it should instruct the verification unit to verify the integrity of the in-vehicle unit, a verification instruction unit (140, S13) configured to instruct the verification unit to perform the integrity verification is provided, An infringement determination unit (124, S26) is configured to determine whether or not the in-vehicle unit has been infringed based on the verification results of the integrity verification by the verification unit, An attack estimation unit (126, S27) is configured to estimate the attack that caused the breach based on the breach determination result from the breach determination unit and the security log, An information processing device equipped with the following features.
2. An information processing apparatus according to claim 1, The attack estimation unit is configured to raise the evaluation value of the attack causing the infringement by a predetermined amount for the in-vehicle unit that the infringement determination unit has determined to have been compromised, and to lower the evaluation value by a predetermined amount for the in-vehicle unit that the infringement determination unit has determined not to have been compromised, and to perform estimations regarding the attack based on the evaluation values. Information processing device.
3. An information processing apparatus according to claim 2, The attack estimation unit is configured to increase the evaluation value by a value lower than the increase in the attack estimation unit if the in-vehicle unit that the infringement determination unit could not determine whether or not it was compromised is physically or logically related to the in-vehicle unit that the infringement determination unit determined to be compromised. Information processing device.
4. An information processing apparatus according to claim 2, The vehicle unit and the security log further comprise a correspondence table between the type of anomaly indicated by the security log, the attack, and the evaluation value. The attack estimation unit is configured to perform an estimation of the attack based on the sum of the evaluation values in the corresponding table corresponding to the attack. Information processing device.
5. An information processing apparatus according to claim 1, The verification instruction unit is configured such that, when the log analysis unit determines that it should instruct the verification unit to perform the integrity verification based on the security log, it instructs the verification unit to perform the integrity verification for all of the in-vehicle units, or for the in-vehicle units whose security logs indicate the abnormality, or for the in-vehicle units other than the in-vehicle units whose security logs indicate the abnormality, or for the in-vehicle units that have a physical or logical relationship with the in-vehicle units whose security logs indicate the abnormality. Information processing device.
6. An information processing apparatus according to claim 1, When the verification instruction unit determines that the log analysis unit has instructed the verification unit to perform the integrity verification based on the security log, the verification instruction unit performs the integrity verification as follows: program code and The system is configured to instruct the verification unit to verify at least one of the following: data, hardware configuration, and software configuration. Information processing device.
7. An information processing apparatus according to claim 1, The infringement detection unit is configured to instruct the verification unit to perform integrity verification if one or more of the following conditions are met: the security log is generated when the vehicle's detection function detects the anomaly, or when the defense function of the second layer or later of the vehicle's multi-layered defense has defended against the attack. If none of the above conditions are met, the unit is not instructed to perform integrity verification. Information processing device.
8. An information processing apparatus according to claim 1, The verification instruction unit is configured not to instruct the verification unit to perform the integrity verification from the time it is instructed to perform the integrity verification until the integrity verification is completed. Information processing device.
9. An information processing apparatus according to claim 1, The infringement determination unit is configured to determine that the in-vehicle unit is infringed if its integrity is compromised, that the in-vehicle unit is not infringed if its integrity is maintained, and that it cannot determine whether or not the in-vehicle unit is infringed if it is not possible to verify its integrity. Information processing device.
10. An information processing program that causes a computer to function as an information processing device according to any one of claims 1 to 9.
11. An information processing method performed by a computer, A security log indicating an anomaly that occurred in vehicle (4) is obtained. Based on the acquired security log, a determination is made as to whether or not to instruct the vehicle's verification unit to verify the integrity of the in-vehicle unit. When it is determined that the verification unit should be instructed to perform the integrity verification, the verification unit is instructed to perform the integrity verification of the in-vehicle unit. Based on the verification results of the integrity verification by the verification unit, it is determined whether or not the in-vehicle unit has been compromised. Based on the in-vehicle unit's compromise determination result and the security log, an estimation is made regarding the attack that caused the compromise. Information processing methods.
12. An information processing system comprising an in-vehicle information processing device (10, 20, 30, 40, 50, 60) and an external information processing device (100) that communicates with the in-vehicle information processing device, The in-vehicle information processing device is A monitoring unit (12, S1, S2) is configured to generate a security log indicating an anomaly that occurred in the vehicle (4), A verification unit (18, S17-S19) configured to verify the integrity of the in-vehicle units (10, 20, 30, 40, 50, 60), Equipped with, The aforementioned external information processing device is: A log acquisition unit (112, S8) configured to acquire the security log from the in-vehicle information processing device, A log analysis unit (122, S10) is configured to determine whether or not to instruct the verification unit to verify the integrity of the in-vehicle unit based on the security log acquired by the log acquisition unit, When the log analysis unit determines that it should instruct the verification unit to perform the integrity verification, a verification instruction unit (140, S13) configured to instruct the verification unit to perform the integrity verification is provided, An infringement determination unit (124, S26) is configured to determine whether or not the in-vehicle unit has been infringed based on the verification results of the integrity verification by the verification unit, An attack estimation unit (126, S27) is configured to estimate the attack that caused the breach based on the breach determination result from the breach determination unit and the security log, Equipped with, Information processing system.
13. An information processing method performed by a computer, A security log indicating an anomaly that occurred in vehicle (4) is generated. The generated security log is obtained, Based on the acquired security log, a determination is made as to whether or not to instruct the verification of the integrity of the in-vehicle units (10, 20, 30, 40, 50, 60). If it is determined that the vehicle unit should be instructed to perform the integrity verification, the vehicle unit will be instructed to perform the integrity verification. When instructed to perform the aforementioned integrity verification, the aforementioned integrity verification is performed, Based on the results of the integrity verification, it is determined whether or not the in-vehicle unit has been compromised. Based on the in-vehicle unit's compromise determination result and the security log, an estimation is made regarding the attack that caused the compromise. Information processing methods.
Citation Information
Patent Citations
Management method, management program, management apparatus, management system, and information processing method
JP2016149655A
Security device, attack specification method, and program
JP2020123307A
Vehicle security monitoring device, method, and program
WO2020153122A1
Log management device and security attack detection / analysis system
WO2022014193A1