Information output device, information output method, and program

By receiving and analyzing logs generated by multiple monitoring devices, and utilizing monitoring and routing information from high-security privileged devices to determine log reliability, the problem of unreliable logs in existing technologies is solved, achieving reliable output and accurate analysis of monitoring information.

JP7840107B2Active Publication Date: 2026-04-03PANASONIC AUTOMOTIVE SYST CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-14
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

In the existing technology, the integrity of monitoring operations, log storage operations, and log transmission operations is not guaranteed, resulting in unreliable logs transmitted to the SOC and making it difficult to determine their reliability.

Method used

The system employs an information output device to receive logs generated by multiple monitoring devices, including a second monitoring device with higher security privileges monitoring the first monitoring device. The receiving unit receives logs containing device information and monitoring results. The management unit manages the abnormal states of the monitored targets. The storage unit stores transmission routing information. The judgment unit determines the abnormal state and log reliability based on the routing information. The output unit outputs monitoring information containing the logs.

Benefits of technology

It can effectively determine the reliability of logs, ensuring that receiving devices can easily judge the reliability of logs, thereby improving the accuracy and reliability of monitoring information analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007840107000001
    Figure 0007840107000001
  • Figure 0007840107000002
    Figure 0007840107000002
  • Figure 0007840107000003
    Figure 0007840107000003
Patent Text Reader

Abstract

To provide an information output apparatus that outputs monitoring information for allowing a device receiving a log to easily determine whether or not the log is reliable.SOLUTION: An information output apparatus 100 outputs monitoring information that includes a monitoring log generated by a monitoring device, the information output apparatus 100 including: a receiving unit 101 for successively receiving a monitoring log that includes a monitoring result indicative of whether or not a fault exists in a monitored object; a management unit 102 for managing a first state that is a fault status of the monitored object of a plurality of monitoring devices on the basis of the monitoring logs; a storage unit 103 for storing path information indicative of a plurality of transmission paths indicated by one or more devices through which the monitoring logs transmitted from transmission sources pass; a determination unit 104 for determining reliability of the received monitoring log on the basis of the first state and a first transmission path of the monitoring log; and an output unit 105 for outputting monitoring information that includes the monitoring log on the basis of the reliability.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information output device, an information output method, and a program.

Background Art

[0002] Patent Document 1 discloses a technique in which a monitoring unit in a non-secure area monitors an electronic control device to generate a log, and a log collection unit in a secure area collects the generated log. Further, it is disclosed that the collected log is transferred to a SOC (Security Operation Center).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, in the prior art such as Patent Document 1, since the integrity of the monitoring operation and the integrity of the log transmission operation to the SOC are not guaranteed, there is a risk that the log transmitted to the SOC may not be reliable.

[0005] The present disclosure provides an information output device that outputs monitoring information for easily determining whether a monitoring log is reliable by a device that has received the monitoring log.

Means for Solving the Problems

[0006] An information output device according to one aspect of the present disclosure is an information output device that receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs, and comprises a receiving unit that sequentially receives monitoring logs including device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the monitored target of the one monitoring device, a management unit that manages a first status which is the occurrence status of abnormalities in the monitored targets of each of the plurality of monitoring devices based on the monitoring results included in the sequentially received monitoring logs, and each of the plurality of monitoring devices The system includes: a storage unit that stores route information indicating a plurality of transmission routes, each of which is indicated by one or more devices through which the monitoring log transmitted from the source is transmitted; a determination unit that identifies a second status, which is the occurrence status of an abnormality of each of the monitoring targets of the one or more monitoring devices indicated by the device information included in the received monitoring log, based on the route information, and the first status, and determines the reliability of the received monitoring log based on the identified second status; and an output unit that outputs monitoring information including the monitoring log based on the reliability.

[0007] Furthermore, an information output method according to one aspect of this disclosure receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs. Information output device A method of outputting information, The aforementioned information output device isThe system sequentially receives monitoring logs that include device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the target being monitored by the one monitoring device. Based on the monitoring results included in the sequentially received monitoring logs, the system manages a first status which is the occurrence status of an abnormality in the target being monitored by each of the plurality of monitoring devices. The system acquires route information indicating a plurality of transmission paths, each of which is a transmission path from which the monitoring log transmitted from the source is taken by one or more devices. Based on the route information, the system identifies a second status which is the occurrence status of an abnormality in the target being monitored by one or more monitoring devices indicated in the first transmission path, based on the first transmission path associated with the target being monitored by the monitoring device indicated in the device information included in the received monitoring log and the first status. Based on the identified second status, the system determines the reliability of the received monitoring log and outputs monitoring information including the monitoring log based on the reliability.

[0008] These comprehensive or specific embodiments may be implemented as a system, method, integrated circuit, computer program, or recording medium such as a computer-readable CD-ROM, or as any combination of a system, method, integrated circuit, computer program, and recording medium. Furthermore, the recording medium may be a non-temporary recording medium. [Effects of the Invention]

[0009] According to the information output device of this disclosure, monitoring information can be output that allows a device receiving the monitoring log to easily determine whether or not the monitoring log is reliable. [Brief explanation of the drawing]

[0010] [Figure 1] Figure 1 is an overall diagram of the monitoring system in the embodiment. [Figure 2] Figure 2 shows the configuration of the monitoring server and the in-vehicle system in the embodiment. [Figure 3]FIG. 3 is a diagram showing the configuration of the information output device in the embodiment. [Figure 4] FIG. 4 is a diagram showing an example of abnormal information before the monitoring log is generated. [Figure 5] FIG. 5 is a diagram showing an example of abnormal information after the monitoring log is generated. [Figure 6] FIG. 6 is a diagram showing another example of abnormal information after the monitoring log is generated. [Figure 7] FIG. 7 is a diagram showing an example of route information in the embodiment. [Figure 8] FIG. 8 is a diagram showing an example of relationship information in the embodiment. [Figure 9] FIG. 9 is a diagram showing an example of the format of the monitoring log in the embodiment. [Figure 10] FIG. 1 is a diagram showing an example of the format of the monitoring information in the embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of the operation of the information output device in the embodiment. [Figure 12] FIG. 12 is a flowchart showing an example of the reset operation of the information output device in the embodiment. [Figure 13] FIG. 13 is a diagram for explaining the state of the monitoring result when the in-vehicle system is attacked. [Figure 14] FIG. 14 is a diagram showing the configuration of the monitoring server and the in-vehicle system in Modification 1. [Figure 15] FIG. 15 is a diagram showing the configuration of the monitoring server and the in-vehicle system in Modification 2. [Figure 16] FIG. 16 is a diagram showing the configuration of the information output device in Modification 2. [Figure 17] FIG. 17 is a diagram showing the configuration of the information output device in Modification 3. [[ID=四十三]]

Embodiments for Carrying Out the Invention

[0011] (Findings Leading to the Present Disclosure) It should be noted that in the translation, "FIG. 1" in the original text "図1は、実施の形態における監視情報のフォーマットの一例を示す図である。 " was corrected to "FIG. 11" according to the context consistency. If this is not allowed, please adjust it according to the actual requirements.Monitoring logs including monitoring results related to vehicle security are required to be safely collected, stored, and transmitted to the SOC. However, in the above prior art, since the integrity of the monitoring operation, the log storage operation, and the log transmission operation is not guaranteed, it is difficult to determine whether the logs transmitted to the SOC are reliable logs. That is, if the integrity of the monitoring operation, the log storage operation, and the log transmission operation is not guaranteed, these operations may be abnormal operations, and abnormal logs may be transmitted to the SOC. For example, if the monitoring operation is abnormal, there is a possibility of generating abnormal logs due to the abnormal monitoring operation. Also, for example, if the log storage operation or the log transmission operation is abnormal, these operations may change normal logs into abnormal logs, or conversely, abnormal logs may be changed into normal logs.

[0012] From the above, the inventors have found that in order to ensure the analysis accuracy and reliability of the monitoring logs in the SOC, it is necessary not only to protect the monitoring logs (e.g., confidentiality, anti-tampering), but also to ensure the integrity of the monitoring operation, the monitoring log storage operation, and the monitoring log transmission operation.

[0013] An information output device according to a first aspect of this disclosure is an information output device that receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs, the receiving unit sequentially receives monitoring logs that include device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the monitored object of the one monitoring device, a management unit that manages a first status which is the occurrence status of abnormalities in the monitored objects of each of the plurality of monitoring devices based on the monitoring results included in the sequentially received monitoring logs, and each of the plurality of monitoring devices The system includes: a storage unit that stores route information indicating a plurality of transmission paths, each of which is a plurality of transmission paths indicated by one or more devices through which the monitoring log transmitted from the source is transmitted; a determination unit that identifies a second situation, which is the occurrence of an abnormality in each of the monitoring targets of the one or more monitoring devices indicated by the device information included in the received monitoring log, based on the route information, and the first situation, and determines the reliability of the received monitoring log based on the identified second situation; and an output unit that outputs monitoring information including the monitoring log based on the reliability.

[0014] According to this, the reliability of the monitoring log is determined based on a second status, which is the occurrence status of abnormalities in one or more devices indicated in the transmission path. For example, if there is an abnormality in any of the one or more devices through which the monitoring log passed, the reliability of the monitoring log can be determined to be low. Therefore, monitoring information can be output that allows the receiving device to easily determine whether or not the log is reliable.

[0015] An information output device according to a second aspect of the present disclosure is an information output device according to a first aspect, wherein the plurality of devices, including the plurality of monitoring devices, constitute a plurality of monitoring relationships, each of the plurality of monitoring relationships indicates a set of monitoring source and monitoring target, the storage unit stores relationship information indicating the plurality of monitoring relationships, and the determination unit, based on the first transmission path, the first status and the relationship information, identifies as the second status: (i) normal, (ii) abnormal, or (iii) under the monitoring of an abnormal device among the plurality of devices where an abnormality has occurred.

[0016] According to this, the reliability of the monitoring log is determined based on a second status indicating (i) normal, (ii) abnormal, or (iii) under the monitoring of an abnormal device. For example, the reliability of the monitoring log can be determined to be low if there is an abnormality in one or more devices through which the monitoring log passed, or if one or more devices through which the monitoring log passed are under the monitoring of an abnormal device. Therefore, monitoring information can be output that allows the device receiving the log to easily determine whether or not the log is reliable.

[0017] An information output device according to a third aspect of this disclosure is an information output device according to a second aspect, wherein the first confidence level of a first monitoring log via a device under the monitoring of the abnormal device is determined to be higher than the second confidence level of a second monitoring log via the abnormal device.

[0018] Since devices under monitoring for malfunctions may not be experiencing any malfunctions, the reliability of monitoring logs can be accurately determined by setting the first confidence level higher than the second confidence level. This allows, for example, confidence levels to be used in the analysis of monitoring logs, enabling the acquisition of multifaceted analysis results. Furthermore, monitoring logs to be used for analysis can be extracted using confidence levels, potentially reducing the processing load associated with monitoring log analysis.

[0019] An information output device according to a fourth aspect of the present disclosure is an information output device according to any one of the first to third aspects, wherein the determination unit calculates the degree of abnormality of one or more devices shown in the first transmission path, and determines the reliability of the received monitoring log based on the sum of the one or more calculated degrees of abnormality.

[0020] Therefore, the reliability can be determined based on the occurrence of anomalies in all devices that the monitoring log has passed through.

[0021] An information output device according to the fifth aspect of this disclosure is an information output device according to any one aspect of the first to fourth aspects, wherein the management unit determines whether a predetermined reset condition has been met, and if it determines that the reset condition has been met, it updates the abnormality status of one or more specific devices identified by the reset condition from among the one or more devices that are shown to be abnormal in the first situation to normal.

[0022] Therefore, for example, if the monitoring device is updated to function correctly, the abnormality status of one or more specific devices can be updated correctly, allowing for an accurate determination of the reliability of the monitoring log even when the device returns to normal operation.

[0023] An information output device according to the sixth aspect of this disclosure is an information output device according to any one of the first to fifth aspects, wherein the monitoring information further includes reliability information indicating the reliability.

[0024] Therefore, a device that receives monitoring information can determine whether the monitoring logs included in the received monitoring information are reliable or not by referring to reliability information.

[0025] The information output device according to the seventh aspect of this disclosure is the information output device according to the sixth aspect, wherein the reliability information is information indicating whether or not the monitoring log included in the monitoring information is reliable.

[0026] An information output device according to the eighth aspect of this disclosure is an information output device according to the seventh aspect, wherein the reliability information indicates that the monitoring log is unreliable by invalidating the monitoring log of the monitoring information.

[0027] An information output device according to the ninth aspect of this disclosure is an information output device according to the sixth aspect, wherein the reliability indicated in the reliability information is a numerical value in which a larger value indicates higher reliability.

[0028] An information output device according to the tenth aspect of this disclosure is an information output device according to any one aspect of the first to ninth aspects, wherein the output unit determines whether the monitoring log is reliable based on the reliability level, and if the monitoring log is not reliable, it does not output the monitoring information.

[0029] Therefore, the device that receives the monitoring logs can determine that all of the received monitoring logs are reliable.

[0030] An information output device according to the eleventh aspect of this disclosure is an information output device according to any one of the first to tenth aspects, wherein the output unit determines whether the monitoring log is reliable based on the reliability level, and if the monitoring log is not reliable, outputs the monitoring information to a storage device that stores a history of the occurrence of anomalies.

[0031] Therefore, the storage device can store monitoring information, including unreliable monitoring logs.

[0032] An information output method relating to a twelfth aspect of this disclosure is an information output method that receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs, wherein the method sequentially receives monitoring logs that include device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the monitored target of the one monitoring device, manages a first status which is the occurrence status of an abnormality in the monitored target of each of the plurality of monitoring devices based on the monitoring results included in the sequentially received monitoring logs, and outputs monitoring information including the monitoring logs of the plurality of monitoring devices The system acquires route information indicating a plurality of transmission paths, each of which has a device as the source of a monitoring log, and each transmission path is indicated by one or more devices through which the monitoring log transmitted from the source passes. Based on the route information, the system identifies a second status, which is the occurrence status of an abnormality in each of the monitoring targets of the one or more monitoring devices indicated by the first transmission path, and the first status, and determines the reliability of the received monitoring log based on the identified second status. Based on the reliability, the system outputs monitoring information including the monitoring log.

[0033] According to this, the reliability of the monitoring log is determined based on a second status, which is the occurrence status of abnormalities in one or more devices indicated in the transmission path. For example, if there is an abnormality in any of the one or more devices through which the monitoring log passed, the reliability of the monitoring log can be determined to be low. Therefore, monitoring information can be output that allows the receiving device to easily determine whether or not the log is reliable.

[0034] The program relating to the 13th aspect of this disclosure is a program that causes a computer to execute the information output method relating to the 12th aspect.

[0035] The monitoring device according to the embodiments will be described below with reference to the drawings. The embodiments shown here are all specific examples of the present disclosure. Therefore, the numerical values, components, arrangement and connection configurations of components, and steps and the order of steps as elements of processing shown in the following embodiments are examples and do not limit the present disclosure. Among the components in the following embodiments, components not described in the independent claims are components that can be added at will. Also, each figure is a schematic diagram and is not necessarily a strict illustration.

[0036] (Embodiment) [Overall configuration diagram of the monitoring system] Figure 1 is an overall diagram of the monitoring system in the embodiment.

[0037] The monitoring system comprises a monitoring server 10 and an in-vehicle system 20. The monitoring server 10 and the in-vehicle system 20 are connected via an external network 30.

[0038] The external network 30 is, for example, the internet. The communication method for the external network 30 may be wired or wireless. Furthermore, the wireless communication method may be an existing technology such as Wi-Fi (registered trademark), 3G / LTE (Long Term Evolution), Bluetooth (registered trademark), V2X communication method, or a combination thereof.

[0039] The monitoring server 10 is a device that acquires monitoring results, which are information regarding the security status of the in-vehicle system 20, from the in-vehicle system 20, and displays and analyzes the monitoring results using a graphical user interface. The monitoring server 10 is used, for example, in a Security Operations Center (SOC) where security analysts can review the monitoring results and consider countermeasures such as program updates if an abnormality occurs in the in-vehicle system 20.

[0040] The in-vehicle system 20 controls communication, controls the vehicle, and outputs video, monitors the security status of the in-vehicle system 20, and notifies the monitoring server 10 of the security status monitoring results. Although only one in-vehicle system 20 is shown in Figure 1, each of the one or more in-vehicle systems 20 sends security status monitoring results to the monitoring server 10. Details of the in-vehicle system 20 will be described later.

[0041] [Configuration of monitoring server 10 and in-vehicle system 20] Figure 2 shows the configuration of the monitoring server and the in-vehicle system in the embodiment.

[0042] The monitoring server 10 is equipped with a SIEM (Security Information and Event Management) 11. The SIEM 11 is an integrated monitoring system that collects logs or data output from multiple systems, analyzes and visualizes these logs or data, and performs network monitoring and detects incidents such as cyberattacks or malware infections.

[0043] The in-vehicle system 20 comprises a plurality of in-vehicle devices 210, 220 and an information output device 100. In addition to the in-vehicle devices 210 and 220, the in-vehicle system 20 may also include other in-vehicle devices.

[0044] The in-vehicle device 210 comprises a monitored object 211, a monitoring device 212, an RI (Runtime Integrity) monitoring device 213, a monitoring root 214, and a transmitting device 215. Note that the monitored object 211, monitoring device 212, RI monitoring device 213, monitoring root 214, and transmitting device 215 may be referred to as multiple devices.

[0045] The monitored object 211 is implemented by an application, and its integrity is monitored by the monitoring device 212. The monitoring device 212 may also monitor the operation and communication of the application of the monitored object 211. Examples of applications of the monitored object 211 include external communication applications, control applications, and video applications. An external communication application is an application that communicates with the monitoring server 10 via an external network 30. A control application is an application that controls the operation of a vehicle equipped with an in-vehicle system 20. A video application is an application that acquires images from a camera, etc., and outputs the images to an infotainment system, instrument panel, or head-up display.

[0046] The monitoring device 212 monitors the monitored object 211. Specifically, the monitoring device 212 monitors whether an abnormality has occurred in the monitored object 211 by verifying the integrity of the program of the application that implements the monitored object 211. The monitoring device 212 may also monitor the communication data sent and received by the application that implements the monitored object 211, or it may monitor the memory and files accessed by the application. The monitoring device 212 sends a monitoring log, including the monitoring results, to the transmitting device 215 via the RI monitoring device 213.

[0047] For example, the monitoring device 212 reads data from the storage area of ​​the memory device where the program that implements the monitored object 211 is stored, generates a verification value by performing a predetermined operation on the data, and verifies the integrity of the program of the monitored object 211 by comparing the verification value with an expected value that has been previously stored in the memory device. The monitoring device 212 determines that the monitored object 211 is normal if the verification value and the expected value match, and determines that the monitored object 211 is abnormal if the verification value and the expected value do not match.

[0048] The expected value is a value generated by performing a predetermined operation on the data of a normal program that implements the monitored target 211 and has not been attacked. For example, the expected value may be generated when the program is created, or when the program is first started. Furthermore, the expected value may be generated from a portion of the normal data of the program that implements the monitored target 211, from configuration data referenced by the program that implements the monitored target 211, or a portion thereof, or from a combination of these.

[0049] Furthermore, the predetermined operation may be, for example, a hash operation for calculating a hash value. The expected value may be a hash value obtained by performing a hash operation on a normal program. The verified value may be a hash value obtained by performing a hash operation on the data in the memory area where the program of the monitored 211 is stored during verification. Note that the predetermined operation is not limited to a hash operation as long as it is a reproducible operation that uniquely converts a first value to a second value that is its counterpart to the first value.

[0050] The monitoring device 212 may be implemented, for example, by a virtual machine. Alternatively, it may be implemented as a program that operates in the same execution environment as the monitored object 211, or in the kernel space of the same execution environment. The monitoring device 212 is one example of a plurality of monitoring devices.

[0051] The RI monitoring device 213 monitors the monitoring device 212 and the transmitting device 215. Specifically, the RI monitoring device 213 monitors whether an abnormality has occurred in the monitoring device 212 by verifying the integrity of the program that implements the monitoring device 212. The RI monitoring device 213 also monitors whether an abnormality has occurred in the transmitting device 215 by verifying the integrity of the program that implements the transmitting device 215. The RI monitoring device 213 sends a monitoring log, including the monitoring results, to the transmitting device 215.

[0052] Furthermore, the integrity verification method using the RI monitoring device 213 is the same as the integrity verification method using the monitoring device 212. In other words, the integrity verification method using the RI monitoring device 213 can be explained by changing the subject of the verification from the monitoring device 212 to the RI monitoring device 213, and changing the object of the verification from the monitored object 211 to the monitoring device 212 or the transmitting device 215, in the explanation of the integrity verification method using the monitoring device 212.

[0053] The RI monitoring device 213 may be implemented by a virtual machine separate from monitoring device 212 and / or monitoring device 215, or it may be implemented as a program that operates in the same execution environment as the drying device 212 and / or monitoring device 215, or in the kernel space of the same execution environment. The RI monitoring device 213 is an example of one of several monitoring devices, and is an example of a monitoring device with higher security privileges than monitoring device 212.

[0054] Monitoring Root 214 monitors the RI monitoring device 213. Specifically, Monitoring Root 214 monitors whether or not an abnormality has occurred in the RI monitoring device 213 by verifying the integrity of the program that implements the RI monitoring device 213. Monitoring Root 214 sends a monitoring log, including the monitoring results, to the transmitting device 215.

[0055] Furthermore, the integrity verification method by monitoring Root 214 is the same as the integrity verification method by monitoring device 212. In other words, the integrity verification method by monitoring Root 214 can be explained by changing the subject of the verification from monitoring device 212 to monitoring Root 214 and the target of the verification from monitored target 211 to RI monitoring device 213, as described in the explanation of the integrity verification method by monitoring device 212.

[0056] The monitoring Root214 operates on a trusted operating system implemented to be free of vulnerabilities. Furthermore, because the operating system software is verified from the Root of Trust (ROT) of trusted hardware at system startup, it can be assumed to be the most trusted among applications, virtual machines, and hypervisors. Monitoring Root214 is implemented, for example, using execution environment control called TEE (Trusted Execution Environment). Monitoring Root214 can also be implemented, for example, by the TrustZone mechanism, which is a standard feature in the Cortex-A family of ARM-based CPUs (Central Processing Units). Monitoring Root214 can also be implemented by Apple's SEP (Secure Enclave Processor) or Google's TitanM. Monitoring Root214 is one example of multiple monitoring devices and is an example of a monitoring device with higher security privileges than RI monitoring device 213. Monitoring Root214 is the monitoring device with the highest security privileges among multiple monitoring devices. Alternatively, the program could operate in the same kernel space execution environment as the RI monitoring device 213, but with increased reliability due to tamper-resistant implementation.

[0057] The transmitting device 215 transmits the monitoring logs obtained from the monitoring device 212, the RI monitoring device 213, and the monitoring root 214 to the information output device 100. The transmitting device 215 may be implemented, for example, by a virtual machine. Alternatively, the transmitting device 215 may be implemented as a program that operates in the same execution environment as the monitored target 211 and / or monitoring device 212 and / or RI monitoring device 213.

[0058] The in-vehicle device 210 is equipped with multiple monitoring devices. These multiple monitoring devices are, as described above, monitoring device 212, RI monitoring device 213, and monitoring Root 214.

[0059] The in-vehicle device 220, like the in-vehicle device 210, is equipped with multiple monitoring devices with different security privileges. And, like the in-vehicle device 210, each of the multiple monitoring devices in the in-vehicle device 220 is configured (chain of trust) to be monitored by a monitoring device with higher security privileges.

[0060] [Configuration of information output device 100] Figure 3 shows the configuration of the information output device in the embodiment.

[0061] The information output device 100 receives monitoring logs generated by multiple monitoring devices provided by the in-vehicle equipment 210 and 220, and outputs monitoring information including the monitoring logs. The information output device 100 comprises a receiving unit 101, a management unit 102, a storage unit 103, a determination unit 104, and an output unit 105.

[0062] The receiving unit 101 receives monitoring logs sequentially. The monitoring log includes device information indicating the monitoring source (i.e., the monitoring device that is the main monitoring device) and the monitoring result. The monitoring result is information indicating whether or not there is an abnormality in the object being monitored by one of the multiple monitoring devices (the monitoring source monitoring device). The monitoring result is the result of monitoring by one monitoring device. The device information is information that identifies the monitoring device that generated the monitoring log, i.e., the monitoring device that sent the monitoring log (e.g., device ID). The receiving unit 101 may also have a function to receive an aggregated monitoring log that includes multiple monitoring logs, extract each monitoring log included in the aggregated monitoring log, and output them as individual monitoring logs to a subsequent processing unit.

[0063] The management unit 102 manages abnormality information 111, which indicates the occurrence of an abnormality in each of the monitored targets in each of the multiple monitoring devices, based on the monitoring results contained in the monitoring logs received sequentially. The abnormality information 111 is stored in the storage unit 103, and the management unit 102 processes the monitoring results contained in the monitoring logs to reflect them in the abnormality information 111.

[0064] Figure 4 shows an example of abnormal information before a monitoring log is generated. Figure 5 shows an example of abnormal information after a monitoring log is generated.

[0065] Anomaly information 111 includes information shown in two sections: in-vehicle equipment and faulty device, as shown in Figures 4 and 5. The in-vehicle equipment section indicates the in-vehicle equipment that contains the faulty device. The faulty device section indicates the faulty device.

[0066] As shown in Figure 4, before the monitoring log is generated, Anomaly Information 111 is empty because no abnormalities have occurred in the monitored targets of each of the multiple monitoring devices, and the monitored targets of each of the multiple monitoring devices are operating normally. In other words, an empty Anomaly Information 111 indicates that all monitored targets of each of the multiple monitoring devices are operating normally. Anomaly Information 111 indicates that an abnormality has occurred in the monitoring device in which information is displayed.

[0067] For example, if the receiving unit 101 receives a monitoring log generated by monitoring Root 214 that indicates an abnormality has occurred in the RI monitoring device 213, the management unit 102 reflects the fact that an abnormality has occurred in the RI monitoring device 213 of the in-vehicle equipment 210 in the abnormality information 111 based on the monitoring log. As a result, as shown in Figure 5, information indicating the in-vehicle equipment 210 is added to the in-vehicle equipment item of the abnormality information 111, and information indicating the RI monitoring device 213 is added to the abnormal device item of the abnormality information 111.

[0068] Figure 6 shows another example of abnormal information after a monitoring log is generated.

[0069] In this case, the abnormal information 111 includes not only the two items of "in-vehicle equipment" and "abnormal device," but also the information indicated in the "abnormal situation" item. The "abnormal situation" item may indicate not only that an abnormality has occurred in the monitoring device, but also that the reliability of the monitoring device is low. For example, because the reliability of the monitoring operation by the malfunctioning monitoring device is low, the operation of the target device being monitored by the malfunctioning monitoring device may not be normal. Therefore, the abnormal situation of the target device being monitored by the malfunctioning monitoring device may be indicated as low reliability.

[0070] For example, if the receiving unit 101 receives a monitoring log generated by monitoring Root 214 that indicates an abnormality has occurred in the RI monitoring device 213, the management unit 102 will reflect the abnormality in the RI monitoring device 213 of the in-vehicle equipment 210 in the abnormality information 111 based on the monitoring log. At the same time, the management unit 102 may also reflect in the abnormality information 111 that the reliability of the operation of the monitoring device 212 and the transmitting device 215, which are under the monitoring of the RI monitoring device 213, is low. As a result, the abnormality status item in the abnormality information 111 will indicate that an abnormality has occurred in the RI monitoring device 213 of the in-vehicle equipment 210, as shown in Figure 6, as well as that the reliability of the monitoring device 212 and the transmitting device 215 of the in-vehicle equipment 210 is low. Note that being under the monitoring of a monitoring device where an abnormality has occurred is identified based on the related information 113 described later. Furthermore, devices under the monitoring of a monitoring device include not only those directly monitored by the monitoring device itself, but also those that are further monitored by those directly monitored. In other words, devices under the surveillance of a monitoring device are all one or more devices that belong to a lower level than the monitoring entity in the chain of surveillance.

[0071] Furthermore, the management unit 102 may determine whether a predetermined reset condition has been met, and if it determines that the reset condition has been met, it may update the abnormal status of one or more specific devices identified by the reset condition, which are among the one or more devices that are shown to be abnormal in the first situation indicated in the abnormality information 111, to normal. One or more specific devices that are subject to reset (update to normal) may be associated with the reset condition. In other words, if the reset condition is met, the abnormal status of all one or more specific devices associated with the reset condition will be updated to normal. One or more specific devices may be all of the monitoring targets of each of the multiple monitoring devices provided by the in-vehicle equipment 210, 220, or one or more devices that are part of the monitoring targets of each of the multiple monitoring devices. The reset condition may be the receipt of a reset request from an external device, the completion of a program update by a specific function (e.g., OTA (Over The Air)), the passage of a predetermined period of time, or the ignition being turned OFF in a vehicle equipped with the in-vehicle system 20.

[0072] The memory unit 103 stores abnormal information 111, route information 112, and relationship information 113. As the abnormal information 111 is as described above, the route information 112 and relationship information 113 will be explained below.

[0073] Figure 7 shows an example of route information in an embodiment.

[0074] Route information 112 is information indicating multiple transmission routes, each of which originates from one of the multiple monitoring devices as the source of the monitoring log. Each of the multiple transmission routes is indicated by one or more devices among the multiple devices, which the monitoring log transmitted from the source passes through.

[0075] For example, the routing information 112 includes information represented by two items: source and transmission route, as shown in Figure 7. The source item indicates the monitoring device that sent the monitoring log, that is, the monitoring device that generated the monitoring log. The transmission route item indicates the devices that the monitoring log passes through from the source of the monitoring log to the transmitting device 215.

[0076] For example, if the source device is monitoring device 212, the transmission path for the monitoring log is shown as monitoring device 212, RI monitoring device 213, and transmitting device 215. Also, for example, if the source device is RI monitoring device 213, the transmission path for the monitoring log is shown as RI monitoring device 213 and transmitting device 215. Also, for example, if the source device is monitoring Root 214, the transmission path for the monitoring log is shown as monitoring Root 214 and transmitting device 215.

[0077] Furthermore, the transmission path for monitoring logs is not limited to being determined according to the source device, but may also be determined according to both the source device and the type of monitoring log.

[0078] Figure 8 shows an example of related information in the embodiment.

[0079] Relationship information 113 indicates multiple monitoring relationships composed of multiple devices. Each of the multiple monitoring relationships indicates a pair of monitoring source and monitoring target. In other words, each of the multiple monitoring relationships indicates a monitoring device that is the monitoring source and a device that is the monitoring target of that monitoring device. Note that only multiple monitoring devices among the multiple devices can be the monitoring source. Also, the monitoring target can be any device other than monitoring Root214 among the multiple devices.

[0080] For example, as shown in Figure 8, related information 113 includes information represented by four items: in-vehicle equipment, monitoring source, monitored target, and monitoring content. The in-vehicle equipment item indicates the in-vehicle equipment on which the monitoring source and monitored target devices are installed. The monitoring source item indicates the monitoring device that is the main entity performing the monitoring. The monitored target item indicates the device that is the target of monitoring by the monitoring device of the monitoring source. The monitoring content item indicates the type of monitoring operation.

[0081] The relevant information indicates the relationship between the monitoring source and the monitoring target of the multiple devices provided by the in-vehicle equipment 210 and 220.

[0082] The determination unit 104 identifies a second status, which is the abnormality status of one or more devices indicated by the first transmission path, based on the route information 112, the first transmission path associated with the device information contained in the received monitoring log, and the first status. In this case, the second status indicates whether one or more devices indicated by the first transmission path are abnormal or normal. Then, the determination unit 104 determines the reliability of the received monitoring log based on the identified second status. Specifically, the determination unit 104 calculates the degree of abnormality for one or more devices indicated by the first transmission path, and determines the reliability of the received monitoring log based on the sum of the calculated degrees of abnormality.

[0083] First, we will explain a first example of the method for determining the reliability by the determination unit 104.

[0084] The first example is one in which abnormality information 111, shown in Figure 5, is stored in the storage unit 103, and a monitoring log from the monitoring device 212 is received by the receiving unit 101. The determination unit 104 identifies the transmission path from which the monitoring device 212 is the source, based on the route information 112. The determination unit 104 then identifies the abnormality status of each of the monitoring device 212, RI monitoring device 213, and transmission device 215 indicated by the identified transmission path, based on the abnormality information 111. In this case, since the determination unit 104 can identify that only the RI monitoring device 213 is abnormal in the abnormality information 111 in Figure 5, it can identify the second situation as that the monitoring device 212 is normal, the RI monitoring device 213 is abnormal, and the transmission device 215 is normal. The determination unit 104 calculates the abnormality level of the abnormal device as 100, and the abnormality level of the normal device as 0. Therefore, the abnormality score of the monitoring device 212 is calculated as 0, the abnormality score of the RI monitoring device 213 is calculated as 100, and the abnormality score of the transmitting device 215 is calculated as 0. The determination unit 104 then subtracts the sum of the abnormality scores of these three devices, which is 100, from a predetermined value of 100 to calculate the reliability score of the monitoring log as 0. Note that the numerical values ​​for abnormality scores exemplified here indicate that a larger value indicates a greater degree of abnormality. Similarly, the numerical values ​​for reliability exemplified here indicate that a larger value indicates higher reliability.

[0085] Next, a second example of the method for determining the reliability by the determination unit 104 will be described.

[0086] In the second example, the determination unit 104 may, in the process of identifying the second status, identify the second status based on the first transmission path, the first status, and the related information 113, as (i) normal, (ii) abnormal, or (iii) unreliable (i.e., under the monitoring of an abnormal device among multiple devices where an abnormality has occurred). In this case, the second status indicates whether each of the one or more monitoring devices indicated by the first transmission path is (i) normal, (ii) abnormal, or (iii) unreliable. The determination unit 104 then determines the reliability of the received monitoring log based on the identified second status. Specifically, the determination unit 104 calculates the degree of abnormality for each of the one or more monitoring devices indicated by the first transmission path, and determines the reliability of the received monitoring log based on the sum of the calculated degrees of abnormality.

[0087] For example, let's consider the case where the abnormality information 111 shown in Figure 6 is stored in the storage unit 103, and the monitoring log from the monitoring root 214 is received by the receiving unit 101. First, the decision unit 104 identifies the transmission path from which the monitoring root 214 is the source, based on the route information 112. Then, the decision unit 104 identifies the abnormality status of the monitoring root 214 and the transmitting device 215 indicated by the identified transmission path, based on the abnormality information 111. In this case, the decision unit 104 can identify that the RI monitoring device 213 is abnormal and the monitoring device 212 and transmitting device 215 are unreliable based on the abnormality information 111 in Figure 6. Therefore, as a second status indicating the abnormality status of the monitoring root 214 and transmitting device 215 indicated by the identified transmission path, the decision unit 104 can identify that the monitoring root 214 is normal and the transmitting device 215 is unreliable. For example, the decision unit 104 calculates the abnormality level of the unreliable device as 30 and the abnormality level of the normal device as 0. Therefore, the abnormality score of monitoring Root214 is calculated as 0, and the abnormality score of transmitting device 215 is calculated as 30. The determination unit 104 then subtracts the sum of the abnormality scores of these two devices, 30, from a predetermined value of 100 to calculate the reliability score of the monitoring log as 70.

[0088] In the second example of the method for determining reliability, the first reliability of the first monitoring log, which is routed through a monitoring device under the monitoring of the faulty device, may be determined to be higher than the second reliability of the second monitoring log, which is routed through the faulty device. For example, by calculating the first and second anomalies such that the first anomaly of a low-reliability device is greater than the second anomaly of the faulty device, the first reliability obtained by subtracting the first anomaly from a predetermined value will be determined to be higher than the second reliability obtained by subtracting the second anomaly from a predetermined value. The reliability may be expressed as a numerical value, for example, with a larger value indicating higher reliability, or a smaller value indicating higher reliability.

[0089] The output unit 105 outputs monitoring information, including monitoring logs, based on the determined confidence level. Specifically, the output unit 105 may generate monitoring information including confidence level information and monitoring logs, and output the generated monitoring information to the monitoring server 10 via the external network 30. In other words, the monitoring information in this case may include confidence level information.

[0090] Figure 9 shows an example of the monitoring log format in the embodiment. Figure 10 shows an example of the monitoring information format in the embodiment.

[0091] As shown in Figure 9, the monitoring log includes destination information indicating the destination device (e.g., IP address, device ID of the destination device), source information indicating the source device (e.g., IP address, device ID of the source device), a timestamp indicating the time the monitoring log was generated, an anomaly detection ID to identify the content of the anomaly detection (e.g., RI anomaly, memory access error, file access error, Keep Alive normal, etc.), and an anomaly detection detail log showing data related to the details of the anomaly detection (e.g., anomaly process ID, resource ID, memory address, etc.). Here, the content of the anomaly detection and the data related to the details of the anomaly detection are information indicating the monitoring result. The monitoring result may include information indicating the monitored target. The monitoring log may also include information indicating that no anomalies were found in the monitored device and that it is functioning normally, and the normality of the monitored target may be notified by using the anomaly detection ID or anomaly detection detail log to indicate the normal state.

[0092] As shown in Figure 10, the monitoring information includes various types of information contained in the monitoring log, plus additional confidence level information. The confidence level information may be expressed as a binary value indicating reliability or not, or as a numerical value indicating higher reliability, as mentioned above.

[0093] The output unit 105 may determine that a monitoring log is reliable if its reliability is equal to or greater than a predetermined threshold (for example, 50), and may determine that a monitoring log is unreliable if its reliability is less than the predetermined threshold.

[0094] The output unit 105 may generate monitoring information by adding a numerical value (e.g., 0) to the monitoring log as reliability information if it determines that the monitoring log is reliable. Conversely, the output unit 105 may generate monitoring information by adding a numerical value (e.g., 1) to the monitoring log as reliability information if it determines that the monitoring log is unreliable. The output unit 105 may then send the generated monitoring information to the monitoring server 10.

[0095] Furthermore, if the output unit 105 determines that the monitoring log is unreliable, it may disable (e.g., mask) the monitoring log to generate monitoring information with confidence level information indicating that the monitoring log is unreliable. Conversely, if the output unit 105 determines that the monitoring log is reliable, it may not disable (e.g., mask) the monitoring log to generate monitoring information with confidence level information indicating that the monitoring log is reliable. The output unit 105 may then send the generated monitoring information to the monitoring server 10.

[0096] Furthermore, if the output unit 105 determines that the monitoring log is unreliable, it may output (transmit) the monitoring information, including the unreliable monitoring log, to a storage device that stores a history of the occurrence of anomalies. The storage device is a device (not shown) that is connected to the external network 30.

[0097] Furthermore, the output unit 105 does not need to output monitoring information if it determines that the monitoring log is unreliable.

[0098] [Operation of Information Output Device 100] Figure 11 is a flowchart showing an example of the operation of the information output device in the embodiment.

[0099] The information output device 100 sequentially receives multiple monitoring logs generated by the in-vehicle devices 210 and 220, calculates the reliability of each of the received monitoring logs, and outputs monitoring information including the monitoring log based on the calculated reliability. The in-vehicle devices 210 and 220 may output each of the multiple monitoring logs generated to the information output device 100 each time it is generated, or multiple monitoring logs that have been accumulated up to the predetermined timing and have not yet been output may be output to the information output device 100 when a predetermined timing arrives.

[0100] The operation of the information output device 100 shown in Figure 11 illustrates the processing for a single received monitoring log. In other words, each time the information output device 100 receives a monitoring log, it repeats the operation shown in Figure 11 for that single received monitoring log.

[0101] The information output device 100 receives the monitoring log (S101). The monitoring log includes device information indicating the monitoring source (i.e., the monitoring device that is the main monitoring device) and the monitoring results.

[0102] Next, the information output device 100 checks the source of the monitoring log included in the monitoring log (S102).

[0103] Next, the information output device 100 checks the monitoring results included in the monitoring log (S103). Specifically, the information output device 100 identifies the monitored target where the anomaly occurred based on the monitoring results, updates the anomaly information 111 so that the anomaly status of the monitored target where the anomaly occurred is marked as an anomaly, and does not update the anomaly information 111 if the monitoring results do not include the occurrence of an anomaly. A specific example of the process in step S103 is the process described as the process of the management unit 102.

[0104] Next, the information output device 100 determines the reliability of the monitoring log based on the abnormal information 111, route information 112, and relationship information 113 (S104). A specific example of the process in step S104 is the process described as the process of the determination unit 104.

[0105] Next, the information output device 100 generates monitoring information including reliability information indicating the reliability level and a monitoring log (S105).

[0106] Next, the information output device 100 determines whether the reliability indicated by the reliability information included in the monitoring information is less than a predetermined threshold (S106).

[0107] If the reliability is above a predetermined threshold (No in S106), the information output device 100 sends the monitoring information generated in step S105 to the monitoring server 10 (S107).

[0108] The information output device 100 performs a specific process (S108) if the reliability is below a predetermined threshold (Yes in S106). This specific process is, for example, the process described in the description of the output unit 105, which is performed when the monitoring log is determined to be unreliable.

[0109] A concrete example of the processing in steps S105 to S108 is the processing described as the processing of the output unit 105.

[0110] Figure 12 is a flowchart showing an example of the reset operation of the information output device in the embodiment. The reset operation is an operation to restore the abnormal status of a device whose abnormal status is recorded as abnormal or low reliability in the abnormal information 111 back to normal.

[0111] The information output device 100 determines whether or not a predetermined reset condition has been met (S111).

[0112] If the information output device 100 determines that the reset condition has been met (Yes in S111), it determines whether the device to be reset specified in the reset condition is one or more specific devices (S112). In other words, in step S112, it determines whether one or more specific devices, which are not all of the multiple devices but some of them, are specified as the device to be reset in the reset condition.

[0113] If the information output device 100 determines that the reset condition is not met (No in S111), it returns to step S111.

[0114] If the information output device 100 determines that the device to be reset is one or more specific devices (Yes in S112), it resets the abnormal status of one or more specific devices identified by the reset condition from among the one or more devices that are shown to be abnormal in the first situation indicated by the abnormal information 111, and updates it to normal (S113).

[0115] If the information output device 100 determines that the device to be reset is not one or more specific devices (No in S112), that is, if it determines that the device to be reset is all of multiple devices, it resets the abnormal status of all devices that are indicated as not normal in the first situation shown in the abnormal information 111 and updates them to normal (S114).

[0116] [Effects, etc.] The information output device 100 according to this embodiment receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs. The information output device 100 comprises a receiving unit 101, a management unit 102, a storage unit 103, a determination unit 104, and an output unit 105. The receiving unit 101 sequentially receives monitoring logs that include device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the monitored target of the one monitoring device. The management unit 102 manages a first status, which is the occurrence status of abnormalities in the monitored targets of each of the plurality of monitoring devices, based on the monitoring results included in the sequentially received monitoring logs. The storage unit 103 stores route information 112 indicating a plurality of transmission paths, each of which has a plurality of monitoring devices as the source of the monitoring logs, and which is indicated by one or more devices through which the monitoring logs transmitted from the source pass. The determination unit 104, based on the route information 112, identifies a second status, which is the occurrence status of an abnormality in each of the monitored targets of one or more devices indicated by the first transmission route, and the first status, and determines the reliability of the received monitoring log based on the identified second status. The output unit 105 outputs monitoring information, including the monitoring log, based on the reliability.

[0117] According to this, the reliability of the monitoring log is determined based on a second status, which is the occurrence status of abnormalities in one or more devices indicated in the transmission path. For example, if there is an abnormality in any of the one or more devices through which the monitoring log passed, the reliability of the monitoring log can be determined to be low. Therefore, monitoring information can be output that allows the receiving device to easily determine whether or not the log is reliable.

[0118] Furthermore, in the information output device 100 according to this embodiment, the multiple devices, including multiple monitoring devices, constitute multiple monitoring relationships. Each of the multiple monitoring relationships indicates a set of monitoring source and monitoring target. The storage unit 103 stores relationship information 113 indicating the multiple monitoring relationships. Based on the first transmission path, the first status, and the relationship information, the determination unit 104 identifies the second status as (i) normal, (ii) abnormal, or (iii) under the monitoring of an abnormal device among the multiple devices where an abnormality has occurred.

[0119] According to this, the reliability of the monitoring log is determined based on a second status indicating (i) normal, (ii) abnormal, or (iii) under the monitoring of an abnormal device. For example, the reliability of the monitoring log can be determined to be low if there is an abnormality in one or more devices through which the monitoring log passed, or if one or more devices through which the monitoring log passed are under the monitoring of an abnormal device. Therefore, monitoring information can be output that allows the device receiving the log to easily determine whether or not the log is reliable.

[0120] This will be explained in detail using Figure 13. Figure 13 is a diagram illustrating the state of monitoring results when an in-vehicle system is attacked. In this example, we will first explain the state transitions of the monitoring results by monitoring device 212, the monitoring results of monitoring device 212 by RI monitoring device 213, the monitoring results of transmitting device 215 by RI monitoring device 213, the monitoring results of RI monitoring device 213 by monitoring root 214, and the Keep Alive notification by monitoring root 214, using the example of an attack that occurs in the order of RI monitoring device 213, transmitting device 215, and monitoring root 214. In Figure 13, the squares, triangles, circles with diagonal hatching, and white circles indicate the timing when the monitoring log containing the corresponding monitoring result or notification was generated. The horizontal axis in Figure 13 represents time. The white rectangles on the lines of the monitoring results from monitoring device 212, the monitoring results of the transmitter 215 by RI monitoring device 213, and the monitoring results of the RI monitoring device 213 by monitoring Root 214 indicate that the target of each monitoring is under attack and an abnormality has occurred in that target.

[0121] If the RI monitoring device 213 is attacked, the anomaly status of the RI monitoring device 213 will become abnormal, and the anomaly status of the monitoring device 212 and the transmitting device 215, which are monitored by the RI monitoring device 213, will become unreliable. In this case, the monitoring log, which includes the monitoring results of the RI monitoring device by the RI monitoring device 213, will pass through the transmitting device 215, and although it can be transmitted as indicated by the triangle mark, it can be determined to be an unreliable log.

[0122] When the transmitting device 215 is attacked, an abnormality occurs in the transmitting device 215, which outputs monitoring logs to the information output device 100. As a result, any monitoring logs generated afterward can be determined to be logs that have been attacked and cannot be transmitted, as indicated by the square mark.

[0123] Furthermore, in the information output device 100 according to this embodiment, the first reliability of the first monitoring log, which has been monitored by the abnormal device, is determined to be more reliable than the second reliability of the second monitoring log, which has been monitored by the abnormal device.

[0124] Since devices under monitoring for malfunctions may not actually be experiencing any malfunctions, the reliability of monitoring logs can be accurately determined by setting the first confidence level higher than the second confidence level. This allows, for example, confidence levels to be used in the analysis of monitoring logs, enabling the acquisition of multifaceted analysis results. Furthermore, monitoring logs to be used for analysis can be extracted using confidence levels, potentially reducing the processing load associated with analyzing monitoring logs.

[0125] Furthermore, in the information output device 100 according to this embodiment, the determination unit 104 calculates the degree of abnormality for each of the one or more devices indicated in the first transmission path, and determines the reliability of the received monitoring log based on the sum of the calculated degrees of abnormality. Therefore, the reliability can be determined according to the occurrence status of abnormalities in all devices through which the monitoring log has passed.

[0126] Furthermore, in the information output device 100 according to this embodiment, the management unit 102 determines whether a predetermined reset condition has been met, and if it determines that the reset condition has been met, it updates the abnormality status of one or more specific devices identified by the reset condition from among the one or more devices that were shown to be abnormal in the first situation to normal.

[0127] Therefore, for example, if the monitoring device is updated to function correctly, the abnormality status of one or more specific devices can be updated correctly, allowing for an accurate determination of the reliability of the monitoring log even when the device returns to normal operation.

[0128] Furthermore, in the information output device 100 according to this embodiment, the monitoring information also includes reliability information indicating the level of reliability. Therefore, a device that receives the monitoring information can determine whether or not the monitoring log included in the received monitoring information is reliable by referring to the reliability information.

[0129] Furthermore, in the information output device 100 according to this embodiment, the output unit 105 determines whether the monitoring log is reliable or not based on its reliability level, and if the monitoring log is not reliable, it does not output the monitoring information. Therefore, a device that receives a monitoring log can determine that all of the received monitoring logs are reliable.

[0130] Furthermore, in the information output device 100 according to this embodiment, the output unit 105 determines whether the monitoring log is reliable or not based on its reliability level, and if the monitoring log is unreliable, it outputs the monitoring information to a storage device that stores a history of the occurrence of anomalies. Therefore, the storage device can store monitoring information, including unreliable monitoring logs.

[0131] [Differentiation] (Variation 1) In the above embodiment, the in-vehicle system 20 was described as being equipped with an information output device 100, but the system is not limited to this, and the monitoring server may also be equipped with an information output device 100.

[0132] Figure 14 shows the configuration of the monitoring server and in-vehicle system in Modification Example 1.

[0133] The monitoring server 10A includes a SIEM 11 and an information output device 100.

[0134] The in-vehicle system 20A includes in-vehicle devices 210 and 220, but does not include an information output device 100. The in-vehicle system 20A transmits monitoring logs generated by the in-vehicle devices 210 and 220 to the monitoring server 10A via the external network 30. The information output device 100 of the monitoring server 10A performs the same processing on the received monitoring logs as in the embodiment and outputs the monitoring information to the SIEM 11.

[0135] (Modification 2) In the above embodiment, the in-vehicle system 20 was described as being equipped with an information output device 100, but the system is not limited to this, and the monitoring server may also be equipped with an information output device 100.

[0136] Figure 15 shows the configuration of the monitoring server and in-vehicle system in Modification 2. Figure 16 shows the configuration of the information output device in Modification 2.

[0137] The monitoring server 10B is equipped with a SIEM 11B, and the SIEM 11B is equipped with an information output device 100B. In other words, the modified example 2 is an example in which the SIEM 11B has the functions of the information output device 100 described in the embodiment.

[0138] The in-vehicle system 20B includes in-vehicle devices 210 and 220, but does not include an information output device 100. The in-vehicle system 20B transmits monitoring logs generated by the in-vehicle devices 210 and 220 to the monitoring server 10B via the external network 30.

[0139] The information output device 100B of the monitoring server 10B performs the same processing on the received monitoring log as in the embodiment and outputs the monitoring information to the analysis unit 106.

[0140] The analysis unit 106 collects logs or data output from multiple systems and analyzes these logs or data to monitor the network and detect incidents such as cyberattacks or malware infections. The analysis unit 106 may also have a function to display the analysis results.

[0141] (Variation 3) In the modified example 2, the storage unit 103 of the information output device 100B provided by the SIEM 11B is configured to store abnormal information 111, route information 112, and relationship information 113. However, the invention is not limited to this configuration, and static information based on the configuration of the in-vehicle system 20B, such as route information 112 and relationship information 113, may be stored in the vehicle information server 120.

[0142] Figure 17 shows the configuration of the information output device in modified example 3.

[0143] The information output device 100C according to Modification 3 differs from the information output device 100B according to Modification 2 in that it does not store route information 112 and related information 113, but has a storage unit 103C that stores abnormal information 111. Furthermore, the information output device 100C differs from the information output device 100B according to Modification 2 in that it is communicably connected to the vehicle information server 120 and acquires route information 112 and related information 113 from the vehicle information server 120.

[0144] The vehicle information server 120 comprises a communication unit 121 and a storage unit 122. When the communication unit 121 receives a request for route information 112 and related information 113 from the information output device 100C, it transmits the route information 112 and related information 113 based on the request to the information output device 100C.

[0145] The storage unit 122 stores route information 112 and related information 113. In this case, the route information 112 and related information 113 may be managed separately for each type of vehicle and each type of in-vehicle system 20B. The communication unit 121 reads the route information 112 and related information 113 from the storage unit 122 according to the type of vehicle or type of in-vehicle system 20B indicated in the request, and transmits the read route information 112 and related information 113 to the information output device 100C.

[0146] The verification system of this disclosure has been described above based on the embodiments and their modifications, but this disclosure is not limited to these embodiments and modifications. Any modifications to the embodiments and modifications that a person skilled in the art could conceive of, without departing from the spirit of this disclosure, may also be included in this disclosure.

[0147] In the above embodiments, each component may be implemented by dedicated hardware or by executing a software program suitable for each component. Each component may also be implemented by a program execution unit such as a CPU (Central Processing Unit) or processor reading and executing a software program recorded on a recording medium such as a hard disk or semiconductor memory. Here, the software that implements the verification device, etc., of each of the above embodiments is a computer program that causes a computer to execute each step of the flowchart or sequence diagram shown in Figures 7 to 10.

[0148] The following cases are also included in this disclosure.

[0149] (1) The at least one device described above is specifically a computer system consisting of a microprocessor, ROM, RAM, hard disk unit, display unit, keyboard, mouse, etc. A computer program is stored in the RAM or hard disk unit. The at least one device described above achieves its function by the operation of the microprocessor in accordance with the computer program. Here, the computer program is composed of a combination of multiple instruction codes that indicate instructions to the computer in order to achieve a predetermined function.

[0150] (2) Some or all of the components constituting at least one of the above-described devices may be made up of a single system LSI (Large Scale Integration). The system LSI is a multi-functional LSI manufactured by integrating multiple components onto a single chip, and specifically, it is a computer system comprising a microprocessor, ROM, RAM, etc. The RAM stores a computer program. The system LSI achieves its function by operating the microprocessor in accordance with the computer program.

[0151] (3) Some or all of the components constituting at least one of the above-described devices may consist of an IC card or a standalone module that is detachable from the device. The IC card or module is a computer system consisting of a microprocessor, ROM, RAM, etc. The IC card or module may include the above-described multi-function LSI. The IC card or module achieves its function by the operation of the microprocessor in accordance with a computer program. The IC card or module may be tamper-resistant.

[0152] (4) The disclosure may also be the methods described above. Alternatively, it may be a computer program that implements these methods using a computer, or a digital signal consisting of a computer program.

[0153] Furthermore, this disclosure may also refer to a computer program or digital signal recorded on a computer-readable recording medium, such as a flexible disk, hard disk, CD (Compact Disc)-ROM, DVD, DVD-ROM, DVD-RAM, BD (Blu-ray® Disc), semiconductor memory, etc. Alternatively, it may refer to a digital signal recorded on such a recording medium.

[0154] Furthermore, this disclosure may also include the transmission of computer programs or digital signals via telecommunications lines, wireless or wired communication lines, networks such as the Internet, data broadcasting, etc.

[0155] Alternatively, the program or digital signal may be implemented by another independent computer system by recording it on a recording medium and transferring it, or by transferring the program or digital signal via a network or the like. [Industrial applicability]

[0156] The information output devices disclosed herein can be applied, for example, to electronic devices, servers, etc., mounted in vehicles. [Explanation of symbols]

[0157] 10, 10A, 10B monitoring servers 11, 11B SIEM 20, 20A, 20B In-vehicle systems 30 External Network 100, 100A, 100B, 100C Information Output Devices 101 Receiving Unit 102 Management Department 103, 103C storage section 104 Decision Section 105 Output section 106 Analysis Department 111 Abnormal information 112 Route Information 113 Related Information 210, 220 Automotive equipment 211 Monitoring targets 212 Monitoring equipment 213 RI monitoring equipment 214 Monitoring Root 215 Transmitter

Claims

1. An information output device that receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs, A receiving unit that sequentially receives monitoring logs including device information indicating one of the plurality of monitoring devices and monitoring results indicating whether or not there is an abnormality in the object being monitored by the one monitoring device, A management unit manages a first status, which is the occurrence status of an abnormality of the monitored target in each of the plurality of monitoring devices, based on the monitoring results included in the monitoring log that is received sequentially. A storage unit that stores route information indicating multiple transmission paths, each of which has a plurality of monitoring devices as the source of the monitoring log, and each transmission path is indicated by one or more devices through which the monitoring log transmitted from the source passes; Based on the route information, a determination unit identifies a second status, which is the occurrence status of an abnormality in each of the monitored targets of one or more monitored devices indicated by the device information included in the received monitoring log, and determines the reliability of the received monitoring log based on the identified second status. The system includes an output unit that outputs monitoring information, including the monitoring log, based on the aforementioned reliability level. Information output device.

2. The plurality of devices, including the plurality of monitoring devices, constitute a plurality of monitoring relationships. Each of the aforementioned monitoring relationships represents a pair of monitoring source and monitoring target, The memory unit stores relational information indicating the multiple monitoring relationships. Based on the first transmission path, the first status, and the related information, the determination unit determines the second status as follows: (i) normal, (ii) abnormal, or (iii) under the monitoring of the abnormal device among the multiple devices where the abnormality has occurred. The information output device according to claim 1.

3. The first confidence level of the first monitoring log, which has passed through the device under the monitoring of the aforementioned faulty device, is determined to be higher than the second confidence level of the second monitoring log, which has passed through the aforementioned faulty device. The information output device according to claim 2.

4. The determination unit calculates the degree of abnormality for each of the one or more devices shown in the first transmission path, and determines the reliability of the received monitoring log based on the sum of the calculated degrees of abnormality. An information output device according to any one of claims 1 to 3.

5. The management unit determines whether a predetermined reset condition has been met, and if it determines that the reset condition has been met, it updates the abnormality status of one or more specific devices identified by the reset condition from among the one or more devices that were shown to be abnormal in the first situation to normal. An information output device according to any one of claims 1 to 3.

6. The monitoring information further includes confidence information indicating the confidence level. An information output device according to any one of claims 1 to 3.

7. The aforementioned reliability information is information indicating whether or not the monitoring logs included in the monitoring information are reliable. The information output device according to claim 6.

8. The aforementioned reliability information indicates that the monitoring log is unreliable because the monitoring log of the monitoring information is invalidated. The information output device according to claim 7.

9. The reliability information mentioned above indicates that a higher reliability value indicates greater reliability. The information output device according to claim 6.

10. The output unit determines whether the monitoring log is reliable based on the reliability level, and if the monitoring log is unreliable, it does not output the monitoring information. An information output device according to any one of claims 1 to 3.

11. The output unit determines whether the monitoring log is reliable based on the reliability level, and if the monitoring log is unreliable, it outputs the monitoring information to a storage device that stores a history of the occurrence of anomalies. An information output device according to any one of claims 1 to 3.

12. An information output method for an information output device that receives monitoring logs generated by a plurality of monitoring devices, including a first monitoring device and a second monitoring device that monitors the first monitoring device and has higher security privileges than the first monitoring device, and outputs monitoring information including the monitoring logs, The aforementioned information output device is The system sequentially receives monitoring logs that include device information indicating one of the multiple monitoring devices and monitoring results indicating whether or not there is an abnormality in the object being monitored by the one monitoring device. Based on the monitoring results included in the monitoring log received sequentially, a first status, which is the occurrence status of an anomaly in the monitored target in each of the multiple monitoring devices, is managed. The method involves acquiring route information indicating multiple transmission paths, each of which has a plurality of monitoring devices as the source of the monitoring log, and each transmission path being represented by one or more devices through which the monitoring log transmitted from the source passes. Based on the route information, a second status is identified, which is the occurrence status of an abnormality in each of the monitored targets of one or more monitoring devices indicated by the first transmission route, and the first status, in relation to the first transmission route, which is the first transmission route, and the device information included in the received monitoring log. Based on the identified second situation, the reliability of the received monitoring log is determined. Based on the aforementioned reliability, monitoring information including the monitoring log is output. Information output method.

13. A program for causing a computer to execute the information output method described in claim 12.

Citation Information

Patent Citations

  • Crt monitoring device

    JP1996211925A

  • Wavelength division multiplex transmission device and signal light monitoring method thereof

    JP2011086980A

  • Electronic control device

    JP2020129238A

  • Providing a visual representation of patient monitoring data from a plurality of patient monitors

    WO2021069279A1