Communication monitoring device, communication monitoring program, and communication monitoring method
The communication monitoring device stabilizes operation by dynamically adjusting analysis unit priorities and storing data during high loads, ensuring continuous security functions and reduced load in edge networks.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- OKI ELECTRIC INDUSTRY CO LTD
- Filing Date
- 2022-02-09
- Publication Date
- 2026-05-26
AI Technical Summary
Existing communication monitoring devices in edge networks struggle to maintain stable operation and reduce load when communication rates suddenly increase, leading to potential data loss and impaired security functions.
A communication monitoring device with a capture unit, analysis units, and a resource control unit that dynamically adjusts the priority and operation of analysis units based on load state, storing restricted data for later processing and prioritizing real-time security functions during high loads.
Ensures stable operation and reduced load even during sudden increases in communication rates, maintaining critical security functions by prioritizing real-time analysis and temporarily restricting non-essential tasks.
Smart Images

Figure 0007865018000001 
Figure 0007865018000002 
Figure 0007865018000003
Abstract
Description
Technical Field
[0001] The present invention relates to a communication monitoring device, a communication monitoring program, and a communication monitoring method, and can be applied to a system for grasping and managing devices connected in a network, for example.
Background Art
[0002] Currently, IoT devices are being utilized in various environments of organizations such as offices and factories. In an organization such as a company, management of devices connected to the network within the organization is carried out, such as whether there are unmanaged devices connected to the organization's network or whether unauthorized communication is being generated due to malware infection or the like. Conventionally, there is a communication monitoring device that mirrors, captures, and analyzes communication traffic flowing through the connection point (such as a core switch) between the core network and the Internet to list up the connected devices and monitor whether the devices are conducting unauthorized communication (and in some cases, even block communication).
[0003] However, IoT devices are often not connected to the Internet under normal circumstances and are used in closed network environments (referred to as edge networks) such as the terminal production site or within an office. In such cases, monitoring only the core network may not be able to cover the entire network. Therefore, there is a need for a communication monitoring device that installs monitoring points in the edge network where IoT devices are installed and captures and analyzes the traffic flowing through them. Since the number of communication monitoring devices required for the edge network increases as the number of monitoring points increases, it is desirable to be able to introduce them at a low cost. Therefore, the computing resources available to a communication monitoring device for the edge network are inevitably limited.
[0004] Normally, edge networks have fewer connected devices compared to core networks, and the volume of communication traffic (communication rate) passing through monitoring points is also lower. Therefore, inexpensive computers can often perform their functions adequately. However, if cyberattacks targeting IoT devices from external sources or unauthorized communication from malware-infected internal IoT devices (such as vulnerability scans of internal devices) occur, the communication rate may temporarily surge, potentially causing communication monitoring devices to be unable to fully perform their role. For example, communication traffic capture loss may occur, resulting in missing data in analysis, or an overloaded analysis process may be killed (stopped) by the OS. If such situations occur, critical management functions such as the capture unit 101 and security functions may be impaired or stop, making it impossible to detect security incidents. This could lead to delays in countermeasures such as communication blocking after detection, potentially exacerbating the damage. Therefore, a method is needed to ensure that critical functions continue to operate even when the communication rate surges.
[0005] Conventionally, in communication monitoring equipment, technologies capable of reducing the load when the communication rate suddenly increases include those described in Patent Documents 1 and 2.
[0006] In the system described in Patent Document 1, packet capture devices are installed at each site to understand the quality status (communication quality and connection quality) of the monitored network, and quality information is periodically notified to a higher-level server. Furthermore, in the system described in Patent Document 1, the capture device manages the throughput (communication rate) for each communication session, and for high-load sessions, the measurement of quality information is temporarily stopped and resumed in the next cycle. In addition, in the system described in Patent Document 1, by excluding high-load sessions from the measurement target, the processing load can be reduced and the cost of the capture device can be lowered.
[0007] Furthermore, the system described in Patent Document 2 is designed to deal with slowDoS attacks on a web server. It measures the number of sessions established on the web server and the traffic flow through monitoring points. Based on this information, it detects resource anomalies in the web server, and triggers traffic capture to analyze the traffic. As described above, the system described in Patent Document 2 reduces the load compared to continuous capture by normally stopping traffic capture and activating it only when predetermined conditions are met. [Prior art documents] [Patent Documents]
[0008] [Patent Document 1] Japanese Patent Publication No. 2014-171076 [Patent Document 2] Japanese Patent Publication No. 2016-148939 [Overview of the project] [Problems that the invention aims to solve]
[0009] However, the system described in Patent Document 1 stops measuring the communication quality of high-throughput sessions. Therefore, in the case of security monitoring, high-throughput sessions are likely to be attack behavior, and the system cannot adequately address the challenge of reducing the load and continuing to operate stably when the communication rate suddenly increases.
[0010] Furthermore, while the system described in Patent Document 2 is based on the premise of detecting specific attacks, and therefore the trigger for activating traffic capture can be obtained from factors other than traffic data, in order to more generally detect a wide range of anomalies and to visualize not only security functions but also steady-state communication volume and communication destination information, it is necessary to run and analyze traffic capture continuously.
[0011] In light of the above-mentioned problems, there is a need for a communication monitoring device, a communication monitoring program, and a communication monitoring method that can continue to operate stably while reducing the load even when the communication rate suddenly increases. [Means for solving the problem]
[0012] The first aspect of the present invention includes: a capture means for holding flow information based on traffic data of communications flowing through a monitored network; an analysis means comprising a plurality of communication analysis units that analyze communications within the monitored network from different perspectives based on the flow information; and a resource control means for performing a load state determination process to determine the load state of the capture means and controlling the communication analysis units constituting the analysis means according to the determination result of the load state determination process, wherein the resource control means, while the capture means is determined to be in a high load state, selects a communication analysis unit with a lower priority and restricts its operation to operate at a lower load, and while the capture means is determined to be in a low load state, selects a communication analysis unit with a higher priority among the restricted units and controls it to relax the restriction. The system further includes a storage means for recording flow information generated while the communication analysis unit is functionally restricted, and the analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from the functionally restricted state, receives the flow information stored by the storage means and supplements the analysis processing of flow information that the analysis means was unable to analyze. It is characterized by the following:
[0013] The second communication monitoring program of the present invention includes a computer comprising: a capture means for holding flow information based on traffic data of communications flowing through a network to be monitored; an analysis means comprising a plurality of communication analysis units that analyze communications within the network to be monitored from different perspectives based on the flow information; a load state determination process for determining the load state of the capture means; and a resource control means for controlling the communication analysis units constituting the analysis means according to the determination result of the load state determination process; the resource control means, while the capture means is determined to be in a high load state, selects a communication analysis unit with a lower priority and restricts its operation to operate at a lower load; and while the capture means is determined to be in a low load state, selects a communication analysis unit with a higher priority from among the restricted units and controls it to relax the restriction. The computer also functions as a storage means for recording flow information generated while the communication analysis unit is functionally restricted. The analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from its functionally restricted state, receives the flow information stored by the storage means and supplements the analysis processing of flow information that the analysis means was unable to process. It is characterized by the following:
[0014] The third aspect of the present invention relates to a communication monitoring method performed by a communication monitoring device, comprising: capture means, analysis means , Source control means and storage means The capture means holds flow information based on traffic data of communications flowing through the monitored network; the analysis means comprises a plurality of communication analysis units that analyze communications within the monitored network from different perspectives based on the flow information; the resource control means performs a load state determination process to determine the load state of the capture means; controls the communication analysis units constituting the analysis means according to the determination result of the load state determination process; while the capture means is determined to be in a high load state, the resource control means selects a communication analysis unit with a lower priority and restricts its operation to operate at a lower load; while the capture means is determined to be in a low load state, it selects a communication analysis unit with a higher priority among the restricted units and eases the restriction. The control and storage means record flow information generated while the communication analysis unit is functionally restricted, and the analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from the functionally restricted state, receives the flow information stored by the storage means and supplements the analysis processing of flow information that the analysis means was unable to analyze. It is characterized by the following: [Effects of the Invention]
[0015] According to the present invention, it is possible to provide a communication monitoring device, a communication monitoring program, and a communication monitoring method that can continue to operate stably while reducing the load even when the communication rate increases sharply. [Brief explanation of the drawing]
[0016] [Figure 1] This is a block diagram showing the functional configuration of the communication monitoring device according to the first embodiment. [Figure 2] This is a block diagram showing the connection configuration of the devices related to the first and second embodiments. [Figure 3] This is a block diagram showing the hardware configuration (computational resource configuration) of the communication monitoring device according to the first and second embodiments. [Figure 4]It is a block diagram showing the configuration related to resource control in the communication monitoring device according to the embodiment. [Figure 5] It is a diagram showing a configuration example of priority information according to the first embodiment. [Figure 6] It is a diagram showing a configuration example of resource usage status information according to the first embodiment. [Figure 7] It is a flowchart (part 1) showing the operation of the communication monitoring device according to the first embodiment. [Figure 8] It is a flowchart (part 2) showing the operation of the communication monitoring device according to the first embodiment. [Figure 9] It is a flowchart (part 3) showing the operation of the communication monitoring device according to the first embodiment. [Figure 10] It is a block diagram showing the functional configuration of the communication monitoring device according to the second embodiment. [Figure 11] It is a block diagram showing an example of the internal configuration of the analysis unit that constitutes the communication monitoring device according to the second embodiment. [Figure 12] It is a flowchart (part 1) showing the operation of the communication monitoring device according to the second embodiment. [Figure 13] It is a flowchart (part 2) showing the operation of the communication monitoring device according to the second embodiment.
Embodiments for Carrying Out the Invention
[0017] (A) The First Embodiment Hereinafter, the first embodiment of the communication monitoring device, communication monitoring program, and communication monitoring method according to the present invention will be described in detail with reference to the drawings.
[0018] (A-1) Configuration of the First Embodiment FIG. 2 is a diagram showing the connection relationship of each device related to the first embodiment. The reference numerals in parentheses in FIG. 2 are the reference numerals used in the second to fifth embodiments described later.
[0019] Here, the communication monitoring device 10 is assumed to perform processing to analyze traffic generated from communication terminals 30 (30-1, 30-2, ...) connected to the monitored network N1, which is the target of monitoring (analysis). In the configuration example shown in Figure 2, it is assumed that a network switch 20 (Layer 2 switch) is installed as network equipment in the monitored network N1.
[0020] In the configuration example shown in Figure 2, each communication terminal 30 is connected to a network switch 20 (Layer 2 switch), and the network switch 20 is connected to a path that allows communication to the Internet N2. The network configuration between the network switch 20 and the Internet N2 is not limited. Furthermore, the number of communication terminals 30 connected to the network switch 20 is not limited and may increase or decrease during operation.
[0021] The specific functions, configurations, and communication content of each communication terminal 30 are not limited. Various terminals can be used as communication terminals 30, such as IoT devices, client PCs, and server devices. Here, each communication terminal 30 will be described as basically communicating with communication devices on the Internet N2 (for example, a server that receives data from the communication terminal 30, or a terminal that accesses the communication terminal 30).
[0022] In the example shown in Figure 2, the communication monitoring device 10 is assumed to be connected to the network switch 20. Here, it is assumed that the network switch 20 is configured to mirror packets (Ethernet frames) sent and received on the LAN port (Ethernet® port) connected to the Internet N2 to the port to which the communication monitoring device 10 is connected (so-called port mirroring). As a result, the communication monitoring device 10 can collect traffic (packets) flowing between the communication terminal 30 under the network switch 20 and the Internet N2. In this embodiment, the network switch 20 is configured to supply data based on traffic flowing between the communication terminal 30 and the Internet N2 (hereinafter also simply referred to as "traffic data") to the communication monitoring device 10 through the port mirroring setting, but the specific configuration for supplying traffic data to the communication monitoring device 10 is not limited. In other words, in this embodiment, the network switch 20 is located at a monitoring point (analysis point) on the network N1 to be monitored, and the communication monitoring device 10 receives traffic data from this monitoring point and performs analysis processing.
[0023] The communication monitoring device 10 is a device that performs analysis on each communication terminal 30 based on traffic data.
[0024] Next, an example of the hardware configuration of the communication monitoring device 10 will be described.
[0025] The communication monitoring device 10 may be composed entirely of hardware (e.g., a dedicated chip), or it may be composed entirely of software (a program). The communication monitoring device 10 may also be configured, for example, by installing a program (including the communication monitoring program of the embodiment) on a computer having a processor and memory.
[0026] Figure 3 is a block diagram showing an example of the hardware configuration of the communication monitoring device 10.
[0027] Figure 3 shows an example of the hardware configuration when the communication monitoring device 10 is configured using software (computer).
[0028] The communication monitoring device 10 shown in Figure 3 has a computer 400 on which a program (including the communication monitoring program of this embodiment) is installed as a hardware component. The computer 400 may be a computer dedicated to the communication monitoring program, or it may be configured to be shared with programs for other functions.
[0029] The computer 400 shown in Figure 3 has a CPU 401, a primary storage unit 402, and a secondary storage unit 403. The primary storage unit 402 is a storage means that functions as the CPU 401's working memory, and can be a high-speed memory such as DRAM (Dynamic Random Access Memory). The secondary storage unit 403 is a storage means that records various data such as the OS (Operating System) and program data (including data for the communication monitoring program according to the embodiment), and can be a non-volatile memory such as FLASH memory, HDD, or SSD. In the computer 400 of this embodiment, when the CPU 401 starts up, it reads the OS and programs (including the communication monitoring program according to the embodiment) recorded in the secondary storage unit 403, loads them onto the primary storage unit 402, and executes them.
[0030] As described above, the computer 400 that constitutes the communication monitoring device 10 has a CPU 401 and a primary storage unit 402 (so-called memory) as its main computing resources.
[0031] Next, the internal configuration of the communication monitoring device 10 will be explained using Figures 1 and 4.
[0032] Figure 1 is a block diagram showing the functional configuration of the communication monitoring device 10.
[0033] Figure 4 is a block diagram showing the configuration related to resource control in the communication monitoring device 10.
[0034] As shown in Figure 1, the communication monitoring device 10 includes a capture unit 101, a database processing unit 102, a resource control unit 103, an analysis unit 104, and a display unit 105.
[0035] The communication monitoring device 10 can be implemented, for example, by installing a program (including a communication monitoring program according to the embodiment) on a computer 400.
[0036] The capture unit 101 processes the traffic data supplied by mirroring into flow units (for example, units classified by a combination of source IP address, source port number, destination IP address, and destination port number) and compiles them as flow information (flow data) for each flow. Here, flow information is defined as communication information necessary for traffic analysis, such as the number of communication bytes and packet arrival interval for each flow. The capture unit 101 supplies the flow information for each flow to the database processing unit 102 at regular or irregular intervals for storage. The capture unit 101 supplies the generated flow information to the database processing unit 102.
[0037] Furthermore, the capture unit 101 notifies the resource control unit 103 via the database processing unit 102 of information indicating the load status related to the communication monitoring device 10 (hereinafter referred to as "load information") at regular intervals or intervals corresponding to its own load status. The load information may include, for example, the communication rate of the communication monitoring device 10 (communication rate based on the traffic data reception status (e.g., packet reception interval, packet data volume, etc.)), the number of data waiting to be processed (e.g., the number of data that has been received but is not yet processed and remains unanalyzed), the number of managed flows (e.g., the number of active flows observed from traffic data (e.g., flows that have generated traffic within the most recent predetermined time)), etc.
[0038] The database processing unit 102 stores and manages the supplied data and performs processing to distribute it in response to requests from other elements. The specific configuration of the database processing unit 102 is not limited, and various configurations can be applied. In this embodiment, the database processing unit 102 is described as using a database equipped with a Publish-Subscribe type (hereinafter referred to as "Pub-Sub type") notification model (message model), prioritizing processing efficiency. However, the configuration of the database processing unit 102 is not limited to the Pub-Sub type and various configurations (for example, relational databases, etc.) can be applied.
[0039] In a Pub / Sub type database (message notification model), the sending client that creates and publishes (sends; notifies) data (messages) is called the "Publisher," and the receiving client that subscribes to (subscribes to; receives) the published data is called the "Subscriber." In a Pub / Sub type database, the published data is notified to the Subscriber side through a logical communication path called a "channel." As a Pub-Sub type database applicable to the database processing unit 102, a platform such as Redis can be used, for example.
[0040] When the analysis unit 104 receives flow information from the flow information channel in the database processing unit 102, it performs traffic analysis processing from multiple different perspectives. The analysis unit 104 then supplies the output results of the traffic analysis function to the display unit 105.
[0041] The resource control unit 103 determines the load status of the capture unit 101 based on load information published by the capture unit 101, and controls resource usage by the traffic analysis function group of the analysis unit 104 according to that load status. In this embodiment, the resource control unit 103 may also consider the usage status of the computing resources of the entire communication monitoring device 10 (i.e., the computing resources of the computer 400) (for example, CPU usage rate and memory usage rate) to determine the load status of the capture unit 101 and the control content for the traffic analysis function group of the analysis unit 104.
[0042] The display unit 105 has a display means for displaying the output results of the traffic analysis function to the user. The configuration of the display means and the details of the display content of the display unit 105 are not limited. For example, the display unit 105 may display the amount of communication, communication destination information, and security detection information for a certain period of time in the past as a web page for each communication terminal 30.
[0043] Next, we will explain the details of the traffic analysis function that constitutes the analysis unit 104.
[0044] In the following, this collection of multiple traffic analysis functions will be referred to as the traffic analysis function group.
[0045] The analysis unit 104 will start and manage each traffic analysis function as a separate program (a program on the computer). In this embodiment, each element constituting the communication monitoring device 10 shares a pool of computing resources (computing resources of the computer 400) as described above, and similarly, within the analysis unit 104, a portion of the above computing resources is further divided among programs corresponding to multiple traffic analysis functions. The environment in which the analysis unit 104 manages and starts the programs corresponding to each traffic analysis function is not limited, but for example, one container (for example, a container managed on a platform such as Docker) may be assigned to a program corresponding to one traffic analysis function (hereinafter referred to as "analysis program") and the analysis program may be executed. The analysis unit 104 will be described as having a configuration that allows recognition and control of identifiers (program name, process name, program file name, etc.) for each analysis program and the computing resources (CPU usage rate and memory usage rate) that each analysis program has secured (used).
[0046] Here, the traffic analysis functions that make up the traffic analysis function group can be classified from a security perspective (security attribute) into either functions directly related to security (hereinafter referred to as "security functions") or functions not directly related to security (hereinafter referred to as "non-security functions"). Furthermore, here, the functions that make up the traffic analysis function group are described as being classified from a real-time perspective (real-time attribute) into either functions that require real-time processing (hereinafter referred to as "real-time required functions") or functions that do not require real-time processing (hereinafter referred to as "real-time non-required functions"). In addition, here, among the traffic analysis functions that make up the traffic analysis function group, the set of functions that have the attribute of security functions will be called the "security function group," and the set of functions that have the attribute of non-security functions will be called the "non-security function group."
[0047] Here, the non-security functions that make up the traffic analysis function group include analysis program PA101, which aggregates the communication volume of each communication terminal 30 (hereinafter referred to as the "communication volume aggregation function"), and analysis program PA102, which aggregates what kind of communication each communication terminal 30 is doing and with whom (hereinafter referred to as the "communication destination information aggregation function"). Here, the security functions that make up the traffic analysis function group include analysis program PA201, which detects malicious communication patterns that differ from the normal (steady) communication patterns of each communication terminal 30 (hereinafter referred to as the "anomaly detection function"), and analysis program PA202, which checks whether each communication terminal 30 has known vulnerabilities due to reasons such as having an outdated software version (hereinafter referred to as the "vulnerability check function").
[0048] Furthermore, each analysis program may be accompanied by additional information indicating its respective attributes (hereinafter referred to as "tag information"). Tag information may, for example, be included as part of the program name (process name; executable file name) of the analysis program. In this embodiment, the tag information (code) corresponding to security functions is represented as "Se," the tag information (code) corresponding to non-security functions as "HiSe," and the tag information (code) corresponding to functions not requiring real-time processing as "RiFu." Here, real-time required functions are not explicitly tagged, and analysis programs without the tag information (RiFu) corresponding to functions not requiring real-time processing are considered real-time required functions. However, analysis programs with real-time required functions may be explicitly tagged with "Ri" or similar. Additionally, the tag information corresponding to each attribute is not limited to the above format and various characters may be applied. For example, "Se" may be replaced with "S," "HiSe" with "NS," and "RiFu" with "NR."
[0049] Here, tag information is explained as being added (placed) to the beginning of the program name (process name) separated by an underscore "_". For example, a program name (process name) that begins with "Se_..." indicates that it is a security function and a real-time required function. Also, for example, a program name (process name) that begins with "Se_Ri_..." indicates that it is a security function and a real-time non-required function. Furthermore, for example, a program name (process name) that begins with "Hi_Se_..." indicates that it is a group of non-security functions and a real-time required function. Therefore, here, the program name (process name) of the anomaly detection function will be represented as "Se_Anomaly Detection Function", the program name (process name) of the vulnerability testing function as "Se_Ri_Vulnerability Testing Function", the program name (process name) of the communication volume display function as "Hi_Se_Communication Volume Display Function", and the program name (process name) of the communication destination information display function as "Hi_Se_Communication Destination Information Display Function".
[0050] Next, we will explain the information that the resource control unit 103 uses as reference when performing resource control processing.
[0051] As described above, the resource control unit 103 controls resource usage by the traffic analysis function group of the analysis unit 104 based on load information, etc. When determining the content of resource control (control content for each analysis program), the resource control unit 103 refers to priority information 103a, which is information indicating priority according to the attributes of the analysis program (traffic analysis function), and resource usage status information 103b, which indicates the resource usage status by each analysis program executed by the analysis unit 104.
[0052] Figure 5 shows an example of the configuration of priority information 103a.
[0053] Figure 5 shows the contents of priority information 103a in table format.
[0054] Figure 5 shows the priority levels for analysis programs (traffic analysis functions) according to their attributes, in three stages: "high," "medium," and "low." In Figure 5, "high" (1st priority) is defined for analysis programs that are security functions and require real-time functionality (analysis programs with tag information "SE_"). In Figure 5, "medium" (2nd priority) is defined for analysis programs that are not security functions and require real-time functionality (analysis programs with tag information "Hai_SE_"). Furthermore, in Figure 5, "low" (3rd priority) is defined for analysis programs that do not require real-time functionality (analysis programs with tag information "SE_RI_Fu_" or "Hai_SE_RI_Fu_"). Note that the number of priority levels and the combination of attributes (tag information) corresponding to each level in priority information 103a are not limited to the example in Figure 5, and various configurations can be applied.
[0055] Figure 6 shows an example of the configuration of resource usage information 103b.
[0056] Figure 6 shows the contents of resource usage information 103b in table format.
[0057] Figure 6 displays resource usage information for each program name (the program name of the analysis program). In the example in Figure 5, the resource usage information displays CPU utilization (in [%]) and memory usage (in [%]).
[0058] The resource control unit 103 acquires the resource usage of each analysis program in the analysis unit 104 at regular or irregular intervals and updates the resource usage status information 103b.
[0059] The method by which the resource control unit 103 obtains resource usage information for each analysis program is not limited. For example, if the communication monitoring device 10 is operating in a LINUX®-based (OS) environment, the resource usage information 103b can be updated by obtaining CPU utilization and memory usage information for each analysis program (each analysis program process) from the execution results of a command that obtains resource usage, such as the top command. The timing of when the resource control unit 103 updates the resource usage information 103b is not limited. For example, the resource control unit 103 may update the resource usage information 103b when it determines that the system has moved from a low-load state to a high-load state. Alternatively, the resource control unit 103 may periodically (for example, every 10 seconds) obtain resource usage information even when the system is in a low-load state, and input the average of the most recent few acquisition results into the resource usage information 103b when it determines that the system is in a high-load state.
[0060] Next, we will explain specific examples of resource control for the traffic analysis function suite.
[0061] The method by which the resource control unit 103 determines the load status of the communication monitoring device 10 is not limited. Here, the resource control unit 103 determines the load status of the communication monitoring device 10 based on load information, etc. As described above, the load information includes information on the communication rate, the number of pending processes, and the number of management flows. For example, the resource control unit 103 may set thresholds in advance for the communication rate, the number of pending processes, and the number of management flows, and determine the load status depending on whether any of the indicators exceeds the threshold. Alternatively, for example, the resource control unit 103 may determine that the system is in a high-load state if any of the indicators exceed the threshold, and that it is in a low-load state if none of the indicators exceed the threshold.
[0062] In this embodiment, the resource control unit 103 determines whether the load state of the capture unit 101 is low load or high load. If it determines that the load state is high, it controls the analysis unit 104 to restrict (reduce) resource usage by the traffic analysis function group. If the load state transitions from high load to low load, it controls the relaxation of the restrictions imposed when the load state was high. For example, if the resource control unit 103 determines that the load state of the capture unit 101 is high load, it recognizes the priority based on the attributes of each analysis program (traffic analysis function) and instructs the analysis unit 104 to restrict and stop the functions of analysis programs with low priority. Then, if the resource control unit 103 determines that the load state of the capture unit 101 has transitioned from high load to low load, it instructs the analysis unit 104 to relax or start the restrictions on the analysis programs that were restricted / stopped.
[0063] Furthermore, the resource control unit 103 may determine high-load conditions and control content for each analysis program by considering the computing resource usage status of the communication monitoring device 10 (as a whole). Computing resource usage status includes, for example, the overall CPU usage rate and memory usage rate that can be obtained from the OS of the computer 400 that constitutes the communication monitoring device 10. For example, the resource control unit 103 may determine that the computing resources of the entire communication monitoring device 10 are strained (overloaded) when the CPU usage rate (usage rate of CPU 401) reaches 100%, the memory usage rate (usage rate of primary storage unit 402) exceeds a predetermined level, or memory swapping (swapping between primary storage unit 402 and secondary storage unit 403) occurs. The resource control unit 103 can, for example, use a command in the Linux OS (for example, the Free command) to determine the amount of data in the used swap area and the memory usage rate (for example, memory usage rate from used memory and free memory). The resource control unit 103 may determine, for example, that the computing resources of the communication monitoring device 10 are strained (overloaded) if the used swap space exceeds a predetermined amount (for example, greater than 0 kbytes).
[0064] In this embodiment, the resource control unit 103 publishes information to the database processing unit 102 for controlling the resource usage of the analysis unit 104 (hereinafter referred to as "resource control information"). Each analysis program of the analysis unit 104 then subscribes to the information on the resource control information channel, and if the destination of the resource control information is itself, it controls itself (the analysis program) according to the resource control information.
[0065] The resource control information may include an identifier for the analysis program to be controlled (for example, the program name) and information indicating the content of the resource control requested for the analysis program (hereinafter referred to as "control request information"). In this embodiment, the resource control content of the analysis program (control request information) may include at least one of the following instructions: a request to stop the analysis program, a request to restrict its functions, a request to start it, or a request to relax its functions.
[0066] As described above, the resource control unit 103 determines the content of resource control considering the priority based on the attributes of each analysis program.
[0067] For example, for functions that do not require real-time processing (e.g., vulnerability analysis programs), the amount of computing resources occupied by such functions can be reduced by limiting their functionality to increase the interval at which flow information is processed. Conversely, for functions that require real-time processing (e.g., communication volume display functions), the processing load can be reduced by limiting their functionality to randomly discard received flow information and not process it (thinning out the flow information to be processed).
[0068] In this embodiment, when the resource control unit 103 sets a restriction request / relaxation request in the control request information, information indicating the amount (magnitude) of the restriction (hereinafter referred to as the "restriction amount") is added to the restriction request / relaxation request. The restriction amount may be, for example, a value greater than 0 and less than or equal to 1. The analysis unit 104 has a restriction amount counter for each analysis program (hereinafter referred to as the "restriction amount counter") set, and when a restriction request is made for a certain analysis program, the value of the restriction amount counter for that analysis program is added (added by the added restriction amount), and when a relaxation request is made, the value of the restriction amount counter for that analysis program is subtracted (subtracted by the added restriction amount). Here, the initial value of the restriction amount counter is 0 and the upper limit is 1. That is, when the value of the restriction amount counter is 0, it means that it operates without any restrictions, and when the value of the restriction amount counter is 1, it means that it stops.
[0069] Furthermore, the analysis unit 104 may determine the length of the execution interval for analysis programs that do not require real-time processing, according to the value of the limit counter (for example, the larger the value of the limit counter, the longer the execution interval). Also, the analysis unit 104 may adjust the probability of discarding the flow information to be processed (hereinafter referred to as the "flow information discard rate") for real-time required functions, according to the value of the limit counter (for example, the larger the value of the limit counter, the higher the flow information discard rate). In addition, the analysis unit 104 may stop the operation of analysis programs when the value of the limit counter reaches the upper limit (in this case, 1).
[0070] For example, if the resource control unit 103 determines that the capture unit 101 is under heavy load, it may select analysis programs (traffic analysis function) in order of lowest priority according to the priority information 103a. For example, if the resource usage information 103b is as shown in Figure 6 under heavy load, the resource control unit 103 will select the "S_RI_F_Vulnerability Check Function," which has a low priority, as the analysis program with the lowest priority, and request a function restriction / stop for the "S_RI_F_Vulnerability Check Function."
[0071] For example, if the resource control unit 103 determines, based on additional information, that the capture unit 101 is under heavy load and that the computing resources of the entire communication monitoring device 10 are strained, it may request the analysis program selected as the control target to be stopped from the beginning. Alternatively, if the resource control unit 103 determines, based on additional information, that the capture unit 101 is under heavy load and that the computing resources of the entire communication monitoring device 10 are not strained, it may request a limit on the analysis program selected as the control target. In the resource control unit 103, there is no limit to the value of the limit amount set for a single limit request, but here, it is set to a fixed value of 0.2.
[0072] Furthermore, the resource control unit 103 may, for example, after sending a function restriction / stop request to a certain analysis program, continuously monitor the computing resources (CPU utilization and memory usage) of the communication monitoring device 10, and if the load becomes greater than before the function restriction / stop was applied, select the analysis program again and perform the function restriction / stop.
[0073] Next, we will explain an example of the processing that occurs after the resource control unit 103 selects the "Vulnerability Check Function" as the control target.
[0074] Here, we assume that the resource control unit 103 first selects the "Vulnerability Check Function" as the control target, generates resource control information with a request to restrict / stop the "Vulnerability Check Function," and publishes it to the database processing unit 102. Note that if a stop request is set in the resource control information, the limit amount does not need to be added. Alternatively, in the resource control information, instead of a stop request, a limit amount equivalent to a stop request (in this case, 1) may be set.
[0075] If the high load condition persists even after sending resource control information (request for function restriction / stop) for the "SeriFu Vulnerability Check Function" (including cases where the load becomes even greater), the resource control unit 103 repeats the process of selecting a new analysis program to be restricted and sending resource control information (request for function restriction / stop) in order to further reduce the load. At this time, the resource control unit 103 selects the analysis program with the lowest priority (if there are multiple analysis programs with the lowest priority, the analysis program with the highest load among them) and generates resource control information for the request for function restriction / stop. At this time, if the analysis program with the lowest priority is in a stopped state (including cases where the limit value counter has reached its upper limit), the resource control unit 103 selects the analysis program with the next lowest priority and makes a request for function restriction / stop. For example, if resource usage information 103b is as shown in Figure 6, the next lowest priority analysis program after "Vulnerability Check Function" would be "Communication Volume Display Function" or "Communication Destination Information Display Function." However, since "Communication Destination Information Display Function" has a higher load, "Communication Destination Information Display Function" will be selected.
[0076] Furthermore, when the resource control unit 103 determines that the high load state has been resolved and the system has transitioned to a low load state, it selects the analysis program with the highest priority from among the analysis programs that have been restricted or stopped (if there are multiple analysis programs with the same priority, it selects one of them by any method), generates resource control information for a start request or a relaxation request, and publishes it. In other words, at this time, the resource control unit 103 performs the reverse procedure of restricting / stopping the functions. Subsequently, if the resource control unit 103 detects a low load state while analysis programs with restricted or stopped functions still exist, it repeats the process of similarly selecting the analysis program with the highest priority from among the analysis programs with restricted or stopped functions, generating resource control information for a start request or a relaxation request, and publishing it.
[0077] As described above, the communication monitoring device 10 of the first embodiment captures communication traffic flowing through the connection points of the edge network (for example, the ports of the network switch 20) by mirroring the connection points. From the captured communication traffic data, it has a non-security function that visualizes information about connected devices (IP address, MAC address, etc.) and the communication volume and destination information of the devices, as well as a security function that detects abnormalities in the devices, such as the detection of malicious communication and vulnerability detection. When it detects that computing resources are about to be depleted due to an increase in processing load caused by a sudden increase in the communication rate, it secures computing resources by temporarily restricting or stopping functions with low management priority (for example, non-security functions).
[0078] (A-2) Operation of the first embodiment Next, the operation of the communication monitoring device 10 of the first embodiment having the above configuration (communication monitoring method according to the embodiment) will be explained using the flowcharts in Figures 7 to 9.
[0079] First, we will explain the flow of traffic data analysis processing performed by the communication monitoring device 10 using the flowchart in Figure 7.
[0080] When the capture unit 101 receives traffic data from the mirroring network switch 20 (S101), it extracts flows from the traffic data and creates extracted flow information (for example, communication information necessary for traffic analysis, such as the number of communication bytes per flow and the packet arrival interval) (S102). If the flow appears for the first time, the capture unit 101 adds the flow to the management flow along with the flow information. If the received flow is included in the management flow, the capture unit 101 updates the flow information in the management flow.
[0081] The capture unit 101 then publishes the flow information to the database processing unit 102 at a predetermined timing. The timing of when the capture unit 101 publishes the flow information is not limited, but methods such as notifying when the number of received packets for the flow is a multiple of 10, or notifying one minute after the last publication, may be applied.
[0082] When the database processing unit 102 receives a Publish of flow information, it notifies each analysis program (traffic analysis function) in the analysis unit 104 that is subscribed to the flow information channel of the flow information. Then, when each analysis program (traffic analysis function) in the analysis unit 104 receives the flow information, it performs traffic analysis from its respective analysis perspective (S103). At this time, if any of the analysis programs is in a restricted state, that analysis program determines whether or not to process the flow information with a probability corresponding to the magnitude of the restriction (value of the restriction value counter), and if it decides not to process the flow information, it discards the flow information.
[0083] When the analysis unit 104 completes processing for each analysis program, it notifies the display unit 105 of the analysis results. The display unit 105 stores the reception results received from the analysis unit 104 and outputs (displays) the analysis results when requested from a terminal (not shown) (for example, a terminal used by a user such as an operator).
[0084] Next, using Figures 8 and 9, we will explain the resource control flow of the analysis program (traffic analysis function) performed by the communication monitoring device 10.
[0085] First, the capture unit 101 periodically aggregates load information, including the communication rate with the monitored network N1, the number of data waiting to be processed, and the number of management flows, at regular or irregular intervals, and publishes this information to the database processing unit 102. The notification interval at which the capture unit 101 notifies the load information is dynamically changed depending on the magnitude of the load at the time of the previous aggregation. The notification interval may be shortened when the indicator values of the load information increase, and lengthened when the indicator values of the load information decrease. When the database processing unit 102 receives the published load information from the capture unit 101, it notifies the resource control unit 103, which is subscribing to the channel, of the load information (S201).
[0086] When the resource control unit 103 receives load information, it determines whether the capture unit 101 is in a high-load state (S202, S203). At this time, the resource control unit 103 determines that the system is in a high-load state if any of the indicator values of the load information exceeds a predetermined threshold, and that it is in a low-load state otherwise. If the communication monitoring device 10 determines in steps S202 and S203 that it is in a high-load state, it operates from step S204, which will be described later, and if it determines that it is in a low-load state, it returns to step S201 as described above and operates.
[0087] If a high load condition is determined in steps S202 and S203 described above, the resource control unit 103 selects an analysis program (traffic analysis function) to be controlled (target for function restriction / stopping) from the priority information 103a and resource usage information 103b (S204).
[0088] Here, if priority information 103a is represented in Figure 5, then analysis programs that do not require real-time processing and have a "low" priority will be subject to resource control. Also, if the content of resource usage information 103b is represented in Figure 6, since the only function that does not require real-time processing is the "vulnerability testing function," this analysis program will be selected for function restriction / shutdown.
[0089] Next, the resource control unit 103 determines whether to restrict the functionality or stop the analysis program that is the target of resource control (the target of function restriction / stopping) (S205).
[0090] For example, the resource control unit 103 checks the CPU usage and memory usage status (referred to as computing resource information) of the computer 400. If the CPU usage reaches 100% (for example, if the CPU usage per unit reaches 100% in the case of a multi-core CPU) or if swapping is occurring in the management of memory (primary storage unit 402), it determines that the computing resources of the communication monitoring device 10 (computer 400) are strained (overloaded), and decides to stop the analysis program subject to resource control. Otherwise, it decides to limit its functionality.
[0091] The resource control unit 103 publishes resource control information to the database processing unit 102, which sets the function restriction / stop for the target analysis program (traffic analysis function), according to the result of the function restriction / stop determination.
[0092] When the database processing unit 102 receives a Publish request for function restriction / suspension, it notifies the traffic analysis functions of the analysis unit 104 that are subscribed to that channel.
[0093] Each analysis program (traffic analysis function) in the analysis unit 104 checks whether the received resource control information (function restriction / stop request) is directed to it, and if it is, it performs a function restriction or stop according to the resource control information (S206). If the content set in the resource control information of the analysis program subject to resource control is a function restriction, it adds the limit value imposed on the function restriction to the limit value counter and updates it, and sets the probability of discarding received flow information or the interval for processing flows according to the updated value of the limit value counter. In addition, if the content set in the resource control information of the analysis program subject to resource control is a stop, it stops subscribing to the flow information channel.
[0094] Next, the resource control unit 103 checks the usage status of the computing resources of the communication monitoring device 10 (computer 400) (S207), and after the function restriction / stop in step S206, it checks whether the usage status of the computing resources of the communication monitoring device 10 (computer 400) has worsened (usage has increased) (S208).
[0095] After the function restriction / stop in step S206, if the usage of computing resources of the communication monitoring device 10 (computer 400) has deteriorated, the communication monitoring device 10 will start from step S204 (select the analysis program again and execute the function restriction / stop process), otherwise (if the resource usage of computer 400 has improved), it will start from step S209, which will be described later.
[0096] If, in step S208 described above, it is determined that the computing resource usage of the computer 400 has improved, the resource control unit 103 waits for and receives the next load information from the capture unit 101 (S209), and determines whether the capture unit 101 is in a high-load state or not based on the additional information (S210). If the communication monitoring device 10 determines in step S210 that the high-load state continues, it returns to step S207 described above (process to check the resource usage status of the computer 400), otherwise (if it determines that it is in a low-load state), it proceeds to the process of step S301 in Figure 9, which will be described later.
[0097] In step S210 described above, if a low load state is determined (i.e., the capture unit 101 transitions from a high load state to a low load state), the resource control unit 103 selects an analysis program to be relaxed / started from among the analysis programs that are currently restricted / stopped (S301). At this time, the resource control unit 103 selects the analysis programs to be relaxed / started in reverse order of the order in which they were restricted / stopped (i.e., in order of priority among the analysis programs that are currently restricted / stopped).
[0098] Next, the resource control unit 103 determines whether to relax or activate the selected analysis program, and generates and publishes resource control information for the analysis program according to the determination result. At this time, the resource control unit 103 may determine to relax the function of the selected analysis program if it was under functional restriction, and to activate the function of the selected analysis program if it was stopped. Here, if the resource control unit 103 has performed functional restrictions on the analysis program multiple times, it may determine to relax the function (subtract from the restriction value counter) by the magnitude of one functional restriction (i.e., a fixed value of 0.2). Then, when the database processing unit 102 receives the Publish of resource control information (function relaxation / activation request), it notifies each analysis program (each Subscriber of the channel). When each analysis program receives the resource control information, it checks whether it is the target (for example, whether it is the identifier (program name) set in the resource control information), and if it is the target, it performs functional relaxation / activation according to the resource control information (function relaxation / activation request) (S302). In this case, if a function relaxation is performed in the analysis program, it updates the limit value counter by subtracting the value of the relaxed limit value, and resets the probability of discarding flow information or the interval for processing the flow according to the updated limit value counter. In this case, if the analysis program is started, it restarts the subscription to the channel that notifies flow information and controls the flow information to flow to itself (control of restarting the analysis process).
[0099] After publishing resource control information in step S302, the resource control unit 103 waits for and receives load information notification from the capture unit 101 (S303).
[0100] Next, the resource control unit 103 determines whether or not a high load state is present based on the load information received from the capture unit 101 (S304, S305).
[0101] If the communication monitoring device 10 determines in step S305 that it is under high load, it returns to step S204 (selection process of analysis program to limit / stop function) and operates; otherwise, it proceeds to the process of step S306 described later.
[0102] If a low load state is determined in step S305 described above, the resource control unit 103 checks whether there are any analysis programs that are still restricted or stopped (S306). If there are any analysis programs that are restricted or stopped, it returns to the process in step S301 described above (the process of selecting analysis programs to relax / start). If there are no analysis programs that are restricted or stopped, it returns to the process in step S201 described above.
[0103] (A-3) Effects of the first embodiment According to the first embodiment, the following effects can be achieved.
[0104] In the first embodiment of the communication monitoring device 10, the capture unit 101 notifies the resource control unit of load information, and the resource control unit 103 uses priority information 103a based on the characteristics of multiple traffic analysis functions and the resource usage status of the analysis program to restrict or stop the functions of analysis programs that have a low priority and use a lot of resources. In the first embodiment of the communication monitoring device 10, computing resources can be secured and resources can be managed so that management-important functions such as the capture unit 101 and security functions continue to operate. Furthermore, in the first embodiment of the communication monitoring device 10, by determining whether the system is under high load based on the load information of the capture unit 101, capture loss under high load conditions can be prevented, and by detecting signs of this before the communication monitoring device is fully overloaded, important functions can be prevented from being killed by the OS or delays in real-time analysis processing can be avoided. In addition, in the communication monitoring device 10, as a method of resource control, not only stopping but also imposing function restrictions can be used to keep analysis programs running even under high load conditions while preventing computing resource strain.
[0105] As described above, the communication monitoring device 10 of the first embodiment can collect and analyze communication traffic flowing through the edge network to which IoT devices are connected, visualize communication information of IoT devices (such as communication volume and destination), and detect anomalies such as cyberattacks. In particular, the communication monitoring device 10 can continue to operate important functions even when the analysis device is overloaded by attacks or scans from external networks, even when using an inexpensive computer with limited computing resources (computer 400) as the computing resource.
[0106] (B) Second Embodiment A second embodiment of the communication monitoring device, communication monitoring program, and communication monitoring method according to the present invention will be described in detail below with reference to the drawings.
[0107] (B-1) Configuration of the second embodiment The connection relationships of each device involved in the second embodiment can also be shown using Figure 2. Below, the differences between the second embodiment and the first embodiment will be explained.
[0108] Figure 10 is a block diagram showing the functional configuration of the communication monitoring device 10A according to the second embodiment, and the same or corresponding parts as in Figure 1 above are denoted by the same or corresponding reference numerals. The hardware configuration of the communication monitoring device 10A can also be shown using Figure 3 above. Note that the reference numerals in parentheses in Figures 2 and 3 are reference numerals used only in the second embodiment. Note that the hardware configuration of the communication monitoring device 10A according to the first embodiment can also be shown using Figure 3 in the same way as in the first embodiment.
[0109] The second embodiment of the communication monitoring device 10A differs from the first embodiment in that the display unit 105 is omitted and a storage unit 106 is added. Furthermore, the second embodiment of the communication monitoring device 10A differs from the first embodiment in that the resource control unit 103 and the analysis unit 104 are replaced by the resource control unit 103A and the analysis unit 104A.
[0110] In the second embodiment of the communication monitoring device 10A, the analysis program, which was restricted or stopped when the capture unit 101 was under high load, is allowed to analyze unprocessed flow information after the capture unit 101 transitions to a low load state, thereby supplementing the analysis.
[0111] The analysis unit 104A differs from the first embodiment in that it also operates programs (hereinafter referred to as "supplementary analysis programs") that correspond to functions that complement each analysis program (traffic analysis function) (hereinafter referred to as "supplementary traffic analysis functions"). Hereafter, the collection of supplementary traffic analysis functions will be referred to as the "supplementary traffic analysis function group".
[0112] First, we will explain the differences between the analysis unit 104A and the first embodiment.
[0113] Figure 11 shows an example of the configuration of the traffic analysis function group (analysis program group) and the complementary traffic analysis function group (interpolation analysis program group) in the analysis unit 104A. The same parts or corresponding parts as those in Figure 4 above are denoted by the same reference numerals or corresponding numerals.
[0114] As shown in Figure 11, the complementary traffic analysis function group includes non-security function groups, similar to the traffic analysis function group. Furthermore, as shown in Figure 11, the complementary traffic analysis function group includes PC101, a complementary analysis program for the communication destination information aggregation function, and PC102, a complementary analysis program for the communication volume aggregation function, within the non-security function group. Additionally, as shown in Figure 11, the security function group includes PC201, a complementary analysis program for the anomaly detection function, and PC202, a complementary analysis program for the vulnerability detection function. The complementary analysis programs, like the analysis programs, may be launched as Docker containers. Note that, for illustrative purposes, Figure 11 shows complementary analysis programs corresponding to all analysis programs; however, it is desirable to launch each complementary analysis program only when the corresponding analysis program requires complementary processing.
[0115] While the analysis program (traffic analysis function) processes flow information received from the database processing unit 102 in real time, the supplementary analysis program (supplementary traffic analysis function) is responsible for processing flow information that could not be analyzed during functional limitations / downtime. Each analysis program records the flow information it discarded and the generation time of that flow while its functionality is limited, and records the duration of the downtime (downtime and restart time) while it is downtime (hereinafter, this information will be referred to as the "unprocessed flow information list").
[0116] When the analysis unit 104A receives a request from the resource control unit 103A to start a supplementary analysis program (hereinafter referred to as a "supplementary analysis start request"), it subscribes to the request and starts the supplementary analysis program (supplementary traffic analysis function) corresponding to the request. When starting a supplementary analysis program, the analysis unit 104A supplies a list of unprocessed flow information for the analysis program (traffic analysis function) corresponding to the supplementary analysis program (supplementary traffic analysis function).
[0117] The supplementary analysis program subscribes to the channel from which the "targeted flow information" described later is published. Upon receiving the targeted flow information, it performs analysis only on the flow information included in the list of unprocessed flow information.
[0118] The analysis unit 104A (supplementary traffic analysis program) subscribes to the supplementary analysis stop request published by the resource control unit 103A, which will be described later. Upon receiving the request, the analysis unit 104A (supplementary traffic analysis program) terminates its subscription to the channel that notifies targeted flow information and deletes the processed flow information from the list of unprocessed flow information. Then, the analysis unit 104A stops the supplementary analysis program (for example, by stopping the corresponding Docker container).
[0119] Next, we will explain the differences between the resource control unit 103A and the first embodiment.
[0120] The resource control unit 103A differs from the first embodiment in that, after the capture unit 101 transitions from a high-load state to a low-load state, it performs processing to control the supplementary analysis of the traffic analysis function, which was in a functionally limited / stopped state under the high-load condition.
[0121] When the capture unit 101 enters a high-load state, the resource control unit 103A publishes information indicating that the system has entered a high-load state (hereinafter referred to as "high-load start information") to the database processing unit 102. Furthermore, when the capture unit 101 changes from a high-load state to a low-load state, and the functional relaxation / startup of the analysis programs that were restricted / stopped is completed, the resource control unit 103A publishes information indicating that the system has transitioned to a low-load state (hereinafter referred to as "high-load end information") to the database processing unit 102. In addition, the resource control unit 103A records the period during which each analysis program that requested functional restriction / stopping was restricted / stopped. Furthermore, when the capture unit 101 is in a low-load state, the resource control unit 103A performs supplemental analysis of the restricted / stopped analysis programs in order of priority (i.e., in order of highest priority in the priority information 103a and lowest resource usage load). To this end, the resource control unit 103A publishes a request to start supplemental analysis for the analysis programs targeted for execution to the database processing unit 102.
[0122] The resource control unit 103A monitors the usage of the computing resources of the entire communication monitoring device 10A (computing resources of computer 400), and as long as there is a predetermined amount of available computing resources in the entire communication monitoring device 10A, it executes supplementary analysis of analysis programs in order of priority. The resource control unit 103A also stops executing analysis programs if the available computing resources in the entire communication monitoring device 10A fall below a predetermined amount. Once the supplementary analysis of the analysis programs is complete and there is available computing resources in the communication monitoring device, the resource control unit 103A restarts the analysis programs that were stopped.
[0123] If the load information of the capture unit 101 transitions to a high load state while the complementary analysis program is being executed, the resource control unit 103A publishes a request to stop the complementary analysis program to the database processing unit 102 in order to stop the currently running complementary analysis program.
[0124] Next, the configuration of the memory unit 106 will be described.
[0125] The memory unit 106 stores flow information when the capture unit 101 is under high load, and publishes the stored flow information to the database processing unit 102 when it is under low load.
[0126] The storage unit 106 subscribes to the channel from which the resource control unit 103A publishes high-load start information. Upon receiving the high-load start information, the storage unit 106 begins subscribing to the channel from which the capture unit 101 publishes flow information and stores the received flow information and the generation time of the flow information. The storage unit 106 also subscribes to the channel from which the resource control unit 103A publishes high-load end information. Upon receiving the high-load end information, the storage unit 106 stops subscribing to the channel that receives flow information. Furthermore, the storage unit 106 subscribes to the channel from which the resource control unit 103A publishes supplemental analysis start requests. Upon receiving a supplemental analysis start request, the storage unit 106 obtains the target analysis program and the function restriction / downtime from the supplemental analysis start request message, and publishes the flow information for the function restriction / downtime of the analysis program to the database processing unit 102 as target-specified flow information in order of the flow information generation time. Finally, the storage unit 106 subscribes to the channel from which the resource control unit 103A publishes supplemental analysis stop requests. Upon receiving the stop request, the storage unit 106 stops publishing target-specified flow information.
[0127] As described above, in the communication monitoring device 10A of the second embodiment, flow information while the analysis program is restricted / stopped is stored in the storage unit 106, and after the analysis program returns from the restriction / stop, the storage unit 106 supplies the stored flow information to the supplementary analysis program, which then supplements (takes over) the analysis processing of flow information that the analysis program could not process while it was restricted / stopped.
[0128] (B-2) Operation of the second embodiment Next, the operation of the communication monitoring device 10A of the second embodiment having the above configuration (communication monitoring method according to the embodiment) will be described.
[0129] The following section will focus on explaining the differences in the operation of the communication monitoring device 10A in the second embodiment compared to the first embodiment.
[0130] Figures 12 and 13 are flowcharts illustrating the flow information storage process associated with high load transitions of the capture unit 101 and the complementary traffic analysis process associated with low load transitions of the capture unit 101 in the communication monitoring device 10A. The communication monitoring device 10A of the second embodiment performs the processes shown in the flowcharts of Figures 12 and 13 in addition to the operation of the first embodiment.
[0131] First, let's assume that the capture unit 101 has published load information to the database processing unit 102 (S401).
[0132] When the resource control unit 103A receives the load information, it determines whether the capture unit 101 is in a high-load state (S402). If it determines that the unit is in a high-load state, it proceeds to step S403 described later; otherwise, it returns to step S401 and continues its operation.
[0133] In step S402, if the capture unit 101 is determined to be under high load, the resource control unit 103A publishes high load initiation information to the database processing unit 102. This high load initiation information is subscribed to by the storage unit 106 (S403).
[0134] When the storage unit 106 receives notification of high load initiation, it begins accumulating subsequent flow information (subscribing to the flow information channel) (S404). Subsequently, the storage unit 106 subscribes to the channel from which the capture unit 101 publishes flow information, and upon receiving flow information, saves (records) the flow information along with its generation time.
[0135] Next, the resource control unit 103A continues to receive load information from the capture unit 101 as long as the high load condition persists (S405, S406), and during that time the storage unit 106 accumulates flow information.
[0136] Subsequently, when the capture unit 101 changes from a high-load state to a low-load state, the resource control unit 103A proceeds to the process of step S501 in Figure 13.
[0137] When the capture unit 101 determines that the system has transitioned from a high-load state to a low-load state, the resource control unit 103A publishes high-load termination information to the database processing unit 102. This high-load termination information is then subscribed to by the storage unit 106 (S501).
[0138] When the storage unit 106 receives high-load termination information, it terminates the storage of flow information. To this end, the storage unit 106 stops subscribing to the channel from which the flow information is published (S502).
[0139] After transmitting the high load termination information, the resource control unit 103A checks the usage status of the computing resources of the communication monitoring device 10A (computer 400) and acquires load information from the capture unit 101 (S503, S504).
[0140] Next, the resource control unit 103A determines whether the capture unit 101 is in a low-load state (S505). If it determines that it is in a low-load state, it proceeds to step S507, which will be described later. If it determines that it is in a high-load state, it proceeds to step S506.
[0141] If it is determined in step S505 that the system is not in a low-load state (i.e., in a high-load state), the resource control unit 103A stops any running complementary analysis programs (does nothing if there are no running complementary analysis programs) (S506) and returns to step S403 described above. At this time, the resource control unit 103A publishes a complementary analysis stop request to the database processing unit 102, requesting that any running complementary analysis programs be stopped. The database processing unit 102 notifies the storage unit 106, the analysis unit 104A, and each of the complementary analysis programs in the analysis unit 104A of this complementary analysis stop request. As a result, when the storage unit 106 receives this stop request, it stops publishing target-specified flow information. Also, when each of the complementary analysis programs in the analysis unit 104A receives this stop request, it updates the list of unprocessed flow information (i.e., removes flow information that has been processed from the list) and stops its function. After that, the analysis unit 104A stops the complementary analysis program (for example, by stopping the corresponding Docker container).
[0142] If the capture unit 101 is determined to be in a low-load state in step S505 described above, the resource control unit 103A determines whether there is a predetermined amount of available computing resources in the communication monitoring device 10A (whether the amount of computing resources used is below a predetermined level) (S507). If it determines that there is a predetermined amount of available computing resources, it operates from step S509 described later; otherwise, it operates from step S508 described later. Whether there is a predetermined amount of available computing resources in the communication monitoring device 10A (whether the load on computing resources is below a predetermined level) may be determined, for example, based on whether the CPU usage rate and memory usage rate are below a predetermined level (for example, whether both the CPU usage rate and memory usage rate are 70% or less).
[0143] If, in step S507 described above, it is determined that the computing resources of the communication monitoring device 10A do not have a predetermined amount of available capacity, the resource control unit 103A checks whether there is a running complementary analysis program (S508). If there is a running complementary analysis program, it proceeds to step S510 described later; otherwise, it returns to step S503 described above and continues its operation.
[0144] In step S507 described above, if it is determined that the communication monitoring device 10A has more than a predetermined amount of computing resources available, the resource control unit 103A selects the analysis program with the highest priority from among the analysis programs that the capture unit 101 had restricted or stopped when it was under high load. The resource control unit 103A publishes a request to start a supplementary analysis targeting the selected analysis program to the database processing unit 102, and instructs the analysis unit 104A to start a supplementary analysis program (S509). At this time, the request to start a supplementary analysis includes the target analysis program and the period during which the analysis program was restricted or stopped. The request to start a supplementary analysis published by the resource control unit 103A is notified to the analysis unit 104A and the storage unit 106 that subscribe to the channel for the request to start a supplementary analysis. When the analysis unit 104A receives the request to start a supplementary analysis, it starts a supplementary analysis program corresponding to the analysis program described in the request (for example, by starting a Docker container for the supplementary analysis program). At this time, the analysis unit 104A passes the list of unprocessed flow information for the analysis program to the supplementary analysis program, which then reads it. When the storage unit 106 receives a request to start supplementary analysis, it retrieves the flow information for the function restriction / downtime described in the request and publishes the specified type flow information targeting the analysis program described in the request to the database processing unit 102 in chronological order of the flow information generation time. The specified type flow information published by the storage unit 106 is notified to the supplementary analysis program that subscribes to the channel of the specified type flow information. When the supplementary analysis program receives the specified type flow information, if it is flow information described in the list of unprocessed flow information, it performs a traffic analysis on the flow information. If the flow information of the specified type flow information is not described in the list of unprocessed flow information, the supplementary analysis program discards the flow information.
[0145] Next, the analysis unit 104A checks whether the complementary analysis program has processed (completed analysis of) all the flow information listed in the unprocessed flow information list (S510). If it confirms that the analysis is complete, it proceeds from step S511 described later; otherwise, it returns to step S503 as described above.
[0146] Upon confirming the completion of the analysis by the supplementary analysis program, the analysis unit 104A stops the supplementary analysis program (for example, by stopping the corresponding Docker container) (S511).
[0147] Next, the resource control unit 103A checks whether there are any analysis programs remaining that are subject to complementary analysis (S512). If there are, it proceeds from step S503 described above; otherwise, it terminates the series of complementary processes.
[0148] (B-3) Effects of the second embodiment According to the second embodiment, the following effects can be achieved.
[0149] In the second embodiment, the communication monitoring device 10A includes a storage unit 106 that stores flow information during periods of high load in the capture unit 101. The capture unit 101 then performs unprocessed traffic analysis on analysis programs that were restricted or stopped during high load conditions after transitioning to a low load state. This allows the communication monitoring device 10A in the second embodiment to compensate for traffic analysis processing during periods of restricted / stopped functionality, eliminating analysis omissions due to resource control. Furthermore, in the communication monitoring device 10A in the second embodiment, the resource control unit 103A can determine whether to perform complementary analysis based on the load information of the capture unit 101 and the computing resource usage status of the communication monitoring device, thereby enabling complementary analysis without affecting the processing of the capture unit 101 or the analysis programs.
[0150] (C) Other embodiments The present invention is not limited to the embodiments described above, and modified embodiments such as those exemplified below can also be cited.
[0151] (C-1) In the first and second embodiments, the resource control units 103 and 103A specified a single analysis program during a single control process (function restriction / stop, relaxation / start, supplemental analysis start / stop), but are not limited to this. For example, the resource control units 103 and 103A specify tag information (e.g., "Real-time processing not required" or "Non-security" indicating "non-security functions") and priority (e.g., "High", "Medium", "Low") of the priority information 103a, and each analysis program performs control processing if it matches the specified tag information or priority. In this way, analysis programs can be controlled collectively, enabling earlier allocation of computing resources and functional recovery.
[0152] (C-2) In the first embodiment, the load information of the capture unit 101 (communication rate, number of data waiting to be processed, number of management flows) was used to determine whether each indicator of the load information exceeded a threshold, and the analysis program was restricted / stopped when a high load state was detected. However, the embodiment is not limited to this. For example, the resource control unit 103 can learn the relationship between the past load information of the capture unit 101 and the computing resources (CPU usage and memory usage) of the communication monitoring device 10 (computer 400) at that time using a machine learning machine, and predict the trend of the load information of the capture unit 101 before the computing resources of the communication monitoring device 10 become strained, thereby securing the computing resources of the communication monitoring device earlier.
[0153] (C-3) In the first embodiment, the magnitude of the restriction was set to a fixed value when the resource control unit 103 requested a functional restriction of the analysis program, but it is not limited to this. For example, based on the computing resource usage status of the communication monitoring device 10 (computer 400), a small value can be set for the magnitude of the restriction when there is ample usage, and a large value can be set for the magnitude of the restriction when the usage status is becoming strained. In this way, by dynamically changing the magnitude of the restriction according to the computing resource usage status of the communication monitoring device 10, it is possible to suppress analysis omissions due to functional restrictions and suppress analysis omissions of important analysis programs when computing resources are strained.
[0154] (C-4) In the second embodiment, the interval at which the memory unit 106 notifies flow information during the execution of complementary analysis by the analysis program was not mentioned, but various methods are possible. For example, one method is to use the generation time of the flow information as a relative time and notify it at the same interval as the original flow information. This allows the analysis program to receive flow information within the range expected in the design (at an interval that can withstand its own throughput) by adhering to the notification interval of the original flow information, thus avoiding excessive processing load on the analysis program. Another method is for the resource control unit 103 to dynamically change the notification interval of flow information through the database processing unit 102 based on the computing resource status of the communication monitoring device. For example, if there is sufficient computing resources, a short notification interval is notified to the memory unit 106, and if computing resources are increasing, a long notification interval is notified to the memory unit 106. By dynamically changing the notification interval, complementary analysis can be performed intensively while computing resources are available, which is expected to shorten the time it takes to start the complementary analysis program.
[0155] (C-5) In the communication monitoring devices 10 and 10A of the above embodiments, capture loss of the capture unit 101 is suppressed by restricting / stopping the functionality of the analysis program of the analysis unit 104. However, if the high load condition cannot be resolved by restricting / stopping the functionality of the analysis program alone, the functionality of the capture unit 101 itself may be restricted (for example, by processing to discard packets to be captured with a predetermined probability). [Explanation of Symbols]
[0156] 10...Communication monitoring device, 10A...Communication monitoring device, 20...Network switch, 30...Communication terminal, 101...Capture unit, 102...Database processing unit, 103...Resource control unit, 103a...Priority information, 103b...Resource usage information, 104...Analysis unit, 105...Display unit, 106...Storage unit, 400...Computer, 401...CPU, 402...Primary storage unit, 403...Secondary storage unit.
Claims
1. A capture means that holds flow information based on communication traffic data flowing through the monitored network, An analysis means comprising multiple communication analysis units that analyze communications within the monitored network from different perspectives based on the flow information, The system includes a load state determination process that determines the load state of the capture means, and a resource control means that controls the communication analysis unit constituting the analysis means according to the determination result of the load state determination process, The resource control means, while the capture means determines that it is under high load, selects a communication analysis unit with lower priority and restricts its operation to operate under lower load, and while the capture means determines that it is under low load, it selects a communication analysis unit with higher priority from among the restricted units and controls it to relax the restriction. The communication analysis unit further includes a storage means for recording flow information that occurred while its functionality was restricted, The analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from a state in which its functions were limited, receives flow information stored in the storage means and supplements the analysis processing of flow information that the analysis means was unable to analyze. A communication monitoring device characterized by the following features.
2. The communication monitoring device according to claim 1, characterized in that the resource control means sets priorities based on the functional attributes of the communication analysis unit.
3. The communication monitoring device according to claim 2, characterized in that the resource control means sets a lower priority when the processing content of the communication analysis unit does not require real-time processing.
4. The communication monitoring device according to claim 3, characterized in that the resource control means sets a higher priority when the processing content of the communication analysis unit relates to security.
5. The communication monitoring device according to any one of claims 1 to 4, characterized in that the resource control means determines the control content for the communication analysis unit constituting the analysis means, taking into consideration the usage status of the computing resources of the communication monitoring device.
6. Computers, A capture means that holds flow information based on communication traffic data flowing through the monitored network, An analysis means comprising multiple communication analysis units that analyze communications within the monitored network from different perspectives based on the flow information, A load state determination process is performed to determine the load state of the capture means, and according to the determination result of the load state determination process, the resource control means is configured to control the communication analysis unit that constitutes the analysis means. The resource control means, while the capture means determines that it is under high load, selects a communication analysis unit with lower priority and restricts its operation to operate under lower load, and while the capture means determines that it is under low load, it selects a communication analysis unit with higher priority from among the restricted units and controls it to relax the restriction. The aforementioned computer also functions as a storage means for recording flow information that occurred while the communication analysis unit was functionally limited. The analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from a state in which its functions were limited, receives flow information stored in the storage means and supplements the analysis processing of flow information that the analysis means was unable to analyze. A communication monitoring program characterized by the following features.
7. In a communication monitoring method performed by a communication monitoring device, It has a capture means, an analysis means, a resource control means, and a storage means, The capture means holds flow information based on communication traffic data flowing through the monitored network, The analysis means comprises a plurality of communication analysis units that analyze communications within the monitored network from different perspectives based on the flow information. The resource control means performs a load state determination process to determine the load state of the capture means, and controls the communication analysis unit that constitutes the analysis means according to the determination result of the load state determination process. The resource control means, while the capture means determines that it is under high load, selects a communication analysis unit with lower priority and restricts its operation to operate under lower load, and while the capture means determines that it is under low load, it selects a communication analysis unit with higher priority from among the restricted units and controls it to relax the restriction. The storage means records flow information generated while the communication analysis unit is functionally limited. The analysis means further includes a supplementary communication analysis unit that, after the communication analysis unit has recovered from a state in which its functions were limited, receives flow information stored in the storage means and supplements the analysis processing of flow information that the analysis means was unable to analyze. A communication monitoring method characterized by the following: