Log determination device, log determination method, log determination program, and log determination system

The log determination device separates maintenance-related logs from cyberattack logs by using a pattern comparison method, improving the accuracy of cyberattack analysis in vehicle systems.

JP7896443B2Active Publication Date: 2026-07-29DENSO CORP
View PDF 6 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
DENSO CORP
Filing Date
2022-09-30
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing log analysis systems for vehicle electronic control systems face reduced accuracy in distinguishing between cyberattacks and anomalies caused by vehicle maintenance, leading to mixed logs that can misinterpret maintenance activities as cyberattacks.

Method used

A log determination device that includes a log acquisition unit, a pattern storage unit, and a false positive log determination unit to identify and separate logs generated during maintenance from those caused by cyberattacks by comparing security logs with expected maintenance patterns.

Benefits of technology

Improves the accuracy of cyberattack analysis by distinguishing between maintenance-related and attack-related logs, thereby enhancing the reliability of security log analysis in vehicle systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007896443000001
    Figure 0007896443000001
  • Figure 0007896443000002
    Figure 0007896443000002
  • Figure 0007896443000003
    Figure 0007896443000003
Patent Text Reader

Abstract

To provide a log determination device, method, program and system for determining whether a security log is a log that has been generated due to maintenance of a vehicle.SOLUTION: A log determination device 10 is configured to acquire a plurality of security logs each including anomaly information indicating an anomaly detected in an electronic control system and position information indicating a position in the electronic control system where the anomaly is detected, and store an occurrence pattern of a security log which is predicted to occur due to maintenance, the occurrence patterns each include predicted anomaly information indicating an anomaly predicted to be detected in the system, and predicted anomaly position information indicating a position in the system where the predicted anomaly is detected. The log determination device is configured to compare the plurality of security logs with the occurrence patterns to determine whether or not the plurality of security logs is a false positive log which is generated due to detection of an anomaly that is generated by maintenance, and output a result of the determination.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus for determining security logs generated by an electronic control system, a log determination apparatus, a log determination method, a log determination program, and a log determination system.

Background Art

[0002] In recent years, technologies for performing driving assistance and autonomous driving control, such as V2X including vehicle-to-vehicle communication and vehicle-to-roadside communication, have attracted attention. Along with this, vehicles have come to have communication functions, and so-called vehicle connectivity has been progressing. As a result, the possibility that a vehicle is subjected to cyberattacks such as unauthorized access has been increasing. Therefore, there is an increasing need to analyze cyberattacks against vehicles and build countermeasures therefor.

[0003] For example, in Patent Document 1, when an electronic control device detects an abnormality, measures for blocking unauthorized information are determined using the determination result as to whether functions other than the defense function and the defense function mounted on the electronic control device are normal or abnormal, thereby preventing the intrusion of unauthorized information.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Here, as a result of detailed examination, the present inventor has found the following problems. Vehicle malfunctions can be caused not only by cyberattacks but also by other reasons. For example, when vehicle maintenance is performed, the electronic control system is in a different state during or immediately after the maintenance, which may be detected as an anomaly by sensors and log entries may be generated. Therefore, the collected logs may contain a mix of logs related to anomalies caused by maintenance as well as logs related to anomalies caused by such maintenance. However, analyzing cyberattacks with such mixed logs may reduce the accuracy of the analysis.

[0006] Therefore, the present invention aims to determine whether or not a log generated by a sensor is a log generated as a result of maintenance. [Means for solving the problem]

[0007] The log determination device (10, 11) of this disclosure includes: a log acquisition unit (101) that acquires a plurality of security logs each including abnormality information indicating an abnormality detected in the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected; a pattern storage unit (103) that stores the occurrence pattern, which is a security log occurrence pattern expected to occur due to maintenance of the electronic control system, and which consists of a plurality of sets each including predicted abnormality information indicating an abnormality expected to be detected in the electronic control system and predicted abnormality location information indicating the location within the electronic control system where the predicted abnormality is detected; and a false positive log determination unit (104) that compares the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated due to the detection of an abnormality caused by the maintenance, and outputs the determination result.

[0008] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]

[0009] With the configuration described above, it is possible to determine whether the logs generated by the electronic control system are related to an anomaly caused by vehicle maintenance, and by considering this determination result when analyzing cyberattacks, it is possible to improve the accuracy of cyberattack analysis. [Brief explanation of the drawing]

[0010] [Figure 1] Diagram illustrating the arrangement of the log determination device and electronic control system in each embodiment. [Figure 2] Explanatory diagram illustrating the configuration of the electronic control system and electronic control device in each embodiment. [Figure 3] This diagram illustrates the security logs generated by the security sensors of the electronic control devices in each embodiment. [Figure 4] Block diagram showing an example configuration of the log determination device of Embodiment 1. [Figure 5] A diagram illustrating the information stored in the log storage unit of Embodiment 1. [Figure 6] A diagram illustrating the information stored in the pattern storage unit of Embodiment 1. [Figure 7] A diagram illustrating the information stored in the pattern storage unit of Embodiment 1. [Figure 8] Diagram illustrating the operation of the log determination device of Embodiment 1. [Figure 9] Diagram illustrating the operation of the log determination device of Embodiment 1. [Figure 10] Block diagram showing an example configuration of the log determination device of Embodiment 2. [Figure 11] Diagram illustrating the log determination method of Embodiment 2 [Figure 12] Diagram illustrating the log determination method of Embodiment 2 [Figure 13] Diagram illustrating the operation of the log determination device of Embodiment 2. [Figure 14] Diagram illustrating the operation of the log determination device of Embodiment 2.

Best Mode for Carrying Out the Invention

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0012] The present invention means the invention described in the claims or in the section of means for solving the problems, and is not limited to the following embodiments. Also, at least the phrases within parentheses mean the phrases described in the claims or in the section of means for solving the problems, and are not similarly limited to the following embodiments.

[0013] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claim of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods described only in the embodiments without being described in the claims, are arbitrary configurations and methods in the present invention. Even the configurations and methods described in the embodiments when the description in the claims is broader than the description in the embodiments are arbitrary configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In any case, by being described in the independent claim of the claims, they become the essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are the effects in the case of having the configurations of the embodiments as examples of the present invention, and are not necessarily the effects of the present invention.

[0015] When there are a plurality of embodiments, the configurations disclosed in each embodiment are not limited to each embodiment alone, and can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Also, the configurations disclosed in each of the plurality of embodiments may be collected and combined.

[0016] The problems described as the problems to be solved by the invention are not known problems, but are those uniquely found by the present inventor, and are facts affirming the inventive step together with the configurations and methods of the present invention.

[0017] 1. Configurations that serve as the basis for each embodiment (1) Arrangement of log determination device 10 and electronic control system S The log determination system 1 is a system consisting of a log determination device 10 and an electronic control device 20 that constitutes the electronic control system S. The arrangement of the log determination device 10 in each embodiment that constitutes the log determination system 1 will be explained using Figure 1. For example, as shown in Figures 1(a) and 1(b), the log determination device 10 is "mounted" on a vehicle, which is a "mobile body," together with the electronic control device 20 that constitutes the electronic control system S. Alternatively, as shown in Figure 1(c), the electronic control device 20 that constitutes the electronic control system S is "mounted" on a vehicle, which is a "mobile body," and the log determination device 10 is implemented in a server device or SOC (Security Operation Center) located outside the vehicle.

[0018] Here, "moving object" refers to any object that can move, regardless of its speed. It also includes objects that are stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and items carried on them. Furthermore, "being mounted" includes not only cases where it is directly fixed to the moving object, but also cases where it is not fixed to the moving object but moves with it. Examples include cases where it is carried by a person riding on the moving object, or where it is mounted on cargo placed on the moving object.

[0019] In the example shown in Figure 1(a), the log determination system 1 can also be described as the electronic control system S. In the example shown in Figure 1(c), the log determination system 1 is a system consisting of a log determination device 10 installed outside the vehicle and individual electronic control systems S mounted on multiple vehicles.

[0020] The log determination device 10 is a device that acquires security logs from multiple electronic control units (hereinafter referred to as ECUs (Electronic Control Units)) 20 that constitute the electronic control system S and determines the logs.

[0021] Figure 2 shows an example of the configuration of an electronic control system S. The electronic control system S is composed of multiple ECUs 20. Figure 2 shows five ECUs (ECU20a to ECU20e) as an example, but naturally, the electronic control system S can be composed of any number of ECUs. In the following explanation, when describing the entire electronic control unit, one or more, we will refer to them as ECU20 or each ECU20, and when describing individual electronic control units, we will refer to them as ECU20a, ECU20b, ECU20c, etc.

[0022] In the electronic control system S shown in Figure 2, ECUs 20a, 20c, 20d, and 20e each have a security sensor 201. In contrast, ECU 20b does not have a security sensor. Thus, it is sufficient for multiple ECUs 20 constituting the electronic control system S to be equipped with security sensors; it is not necessarily required that all ECUs 20 have security sensors. The ECU 20 also has a log transmission unit 202 that transmits security logs generated by the security sensors.

[0023] The security sensor 201 (corresponding to the "log generation unit") generates a security log when it detects an abnormality occurring within the electronic control system, for example, in the ECU 20 or the network connected to the ECU 20. A security sensor that monitors network communication in the electronic control system S and detects abnormalities related to the content and frequency of communication is also called a network-type IDS (Intrusion Detection System). The log transmission unit 202 "transmits" the security log generated by the security sensor 201 to the log determination device 10.

[0024] Here, "transmit" means to transmit using either wired or wireless communication. Furthermore, when transmitting using wireless communication, this includes transmitting via a device with communication capabilities.

[0025] In the embodiments described below, the security log is described as being generated by the security sensor 201 shown in Figure 2. However, the security log in this disclosure may also be a log generated by a function called an in-vehicle SIEM (Security Information and Event Management), which collects and manages information about events occurring within an electronic control system.

[0026] The electronic control system S can be composed of any ECUs. Examples include a drivetrain electronic control unit that controls the engine, steering wheel, brakes, etc., a vehicle system electronic control unit that controls meters, power windows, etc., an information system electronic control unit that controls navigation systems, etc., or a safety control system electronic control unit that controls collisions with obstacles or pedestrians. Furthermore, the ECUs may not be in parallel, but may be classified as master and slave. In addition, the electronic control system S may be provided with a gateway ECU or a central ECU (C-ECU) that connects the electronic control units, and an external communication ECU that communicates with the outside world. For example, ECU20a may be the external communication ECU and ECUc may be the C-ECU. Furthermore, message authentication may be used for communication between ECU20 to prevent impersonation by a third party. In addition, ECU20 may be physically independent ECUs, or it may be a virtually implemented virtual ECU (sometimes called a virtual machine).

[0027] In the cases of Figure 1(a) and Figure 1(b), the log determination device 10 and each ECU 20 are connected via an in-vehicle communication network such as CAN (Controller Area Network) or LIN (Local Interconnect Network). Alternatively, they may be connected using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®. Note that connection refers to a state in which data can be exchanged, and includes not only cases where different hardware is connected via a wired or wireless communication network, but also cases where virtual machines implemented on the same hardware are virtually connected to each other.

[0028] Figure 1(a) shows a configuration in which an independent log determination device 10 is provided inside the electronic control system S, or in which the function of the log determination device 10 is built into at least one of the ECUs 20 that constitute the electronic control system S, such as the C-ECU or the external communication ECU.

[0029] Figure 1(b) shows a configuration in which the log determination device 10 is located outside the electronic control system S, but in terms of the connection configuration, it is essentially the same as Figure 1(a).

[0030] In the case of Figure 1(c), the log determination device 10 is also installed outside the electronic control system S, but since the log determination device 10 is installed outside the vehicle, the connection configuration is different from that of Figures 1(a) and 1(b). The log determination device 10 and the electronic control system S are connected via a communication network such as IEEE802.11 (Wi-Fi®), IEEE802.16 (WiMAX®), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, 5G, etc. Alternatively, DSRC (Dedicated Short Range Communication) can be used. If the vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a LAN (Local Area Network), the internet, or a fixed telephone line can be used.

[0031] In the case of Figure 1(c), one of the ECUs 20 (for example, ECU 20a) aggregates the security logs generated by the security sensors 201 of each ECU 20 and transmits them together to the log determination device 10. In this case, ECU 20a corresponds to the IDSR (Intrusion Detection System Reporter) as defined in AUTOSAR (AUTomotive Open System Architecture). Alternatively, ECU 20a may sequentially transmit the security logs generated by the security sensors of each ECU 20 to the log determination device 10.

[0032] In the cases shown in Figures 1(a) and 1(b), by performing log analysis on the vehicle, only security logs that were not determined to be false positive logs (as described later) can be sent to a server device located outside the vehicle. This reduces the amount of communication between the vehicle and the server device. Furthermore, since the server device only needs to analyze security logs other than the received false positive logs, the log analysis processing on the server device can be suppressed.

[0033] In contrast, in the case of Figure 1(c), the log judgment process can be executed using the abundant resources of the server device. Furthermore, the log judgment process of each embodiment can be realized without implementing new devices or programs in existing vehicles.

[0034] In each of the following embodiments, the arrangement shown in Figure 1(c) will be used as an example. In each embodiment, the electronic control system S is described as an in-vehicle system mounted on a vehicle, but the electronic control system S is not limited to in-vehicle systems and can be applied to any electronic control system consisting of multiple ECUs. For example, the electronic control system S may be mounted on a stationary body rather than a moving body.

[0035] Furthermore, although not shown in Figure 1, the log determination device 10 may be connected to an attack analysis device (not shown) that analyzes the security logs determined by the log determination device 10 to analyze cyberattacks carried out against the vehicle. Alternatively, each function of the log determination device 10 described later may refer to a function built into the attack analysis device. Hereinafter, cyberattacks will be simply referred to as attacks.

[0036] In addition, although the log determination device 10 of Embodiment 1 was used as an example in Figure 1 and the above explanation in (1) thereof, each arrangement shown in Figure 1 can also be applied to the log determination device 11 of Embodiment 2.

[0037] (2) Details of the security log Figure 3 shows an example of the contents of the security log generated by the security sensor 201 of the ECU20.

[0038] The security log has the following fields: an ECU-ID (corresponding to "location information") indicating the identification information of the ECU on which the security sensor 201 is installed; a sensor ID indicating the identification information of the security sensor; an event ID (corresponding to "abnormal information") indicating the identification information of the event detected by the security sensor; a counter indicating the number of times the event was detected; a timestamp indicating the time the event was detected (corresponding to "time information"); and context data indicating the details of the security sensor's output. The security log may also have a header that stores information such as the protocol version and the status of each field.

[0039] According to the specifications defined by AUTOSAR, the IdsM Instance ID corresponds to the ECU-ID, the Sensor Instance ID to the sensor ID, the Event Definition ID to the event ID, the Count to the counter, the Timestamp to the timestamp, the Context Data to the context data, and the Protocol Version and Protocol Header to the header.

[0040] When the security sensor 201 detects an anomaly in the electronic control system, it generates a security log, as shown in Figure 3, which includes an event ID indicating the detected anomaly.

[0041] In the embodiments described below, the security log is determined using an event ID as information indicating an anomaly detected within the electronic control system, and an ECU-ID as information indicating the "location" within the electronic control system where the anomaly was detected. However, the information used by the log determination device 10 to determine the security log is not limited to the event ID and ECU-ID. For example, information stored in context data may be used as information indicating an anomaly detected within the electronic control system. Alternatively, a sensor ID may be used as information indicating the location within the electronic control system where the anomaly was detected. Or, if the anomaly is detected in the network, identification information of the network where the anomaly occurred may be used.

[0042] Here, "location" refers to, for example, the location of individual electronic control units, the functions installed in electronic control units, or the location of a network.

[0043] Figure 3 shows an example of a log generated when an anomaly occurs. However, the normal log generated when no anomaly occurs (for example, when an event is successful) may have the same specifications as Figure 3. In that case, for example, different event IDs can be used for when an anomaly occurs and when an event is successful to distinguish between anomaly logs and normal logs. Alternatively, a flag indicating the presence or absence of context data can be set in the header, and the log can be distinguished by checking this flag.

[0044] Furthermore, while Figure 3 shows a security log generated by a physically independent ECU20, it could also be a security log generated by a virtual ECU.

[0045] (3) Examples of security logs generated by maintenance When performing maintenance on the electronic control system S installed in a vehicle, the security sensor 201 is expected to generate specific security logs depending on the nature of the maintenance. Therefore, the following describes examples of maintenance on the electronic control system S (a) to (d) and the security logs that are expected to be generated by these maintenance procedures. Naturally, the content of the maintenance on the electronic control system S and the security logs generated by the maintenance are merely examples and are not limited to these.

[0046] (a) Maintenance example 1 (ECU replacement) This document describes a maintenance example in a repair shop or dealership where an ECU20 (e.g., ECU20c) that constitutes an electronic control system S is replaced with an ECU20c2. The ECU20c is an ECU that periodically sends messages to other ECU20s. When replacing an ECU20, the maintenance worker is expected to perform the following tasks (i) to (v).

[0047] (i) The worker replaces ECU20c with ECU20c2. (ii) Once the work in (i) is completed, the worker will turn on the vehicle's power and access the replaced ECU20c2 using the initial authentication information of the ECU20c2 in order to verify whether the ECU20c2 is functioning correctly. (iii) The operator sets a new shared key on ECU20c2 and ECU20d by synchronizing with another ECU20 (e.g., ECU20d) that performs message authentication using a shared key with ECU20c2. (iv) The operator sets the authentication information of the ECU20c2 from the default, less secure value to new authentication information. (v) The operator accesses ECU20c2 using the default authentication information to confirm that the change to the authentication information is complete. If ECU20c2 cannot be accessed using the default authentication information, the change to the authentication information of ECU20c2 is considered complete.

[0048] When the vehicle's power is turned on during the procedure described in (ii) above, ECU20c2 sends a periodic message to ECU20d. At this time, since the common key held by ECU20c2 immediately after replacement is different from that held by ECU20d, the security sensor 201d of ECU20d detects an anomaly indicating a key mismatch and generates a security log (a1). Furthermore, as a result of the above procedure (v), the security sensor 201c of the ECU20c detects an anomaly indicating that access was made using authentication information different from the normal authentication information (the initial value of the authentication information), and generates a security log (a2).

[0049] As described above, it is expected that security logs (a1) and (a2) will be generated by the maintenance involving the replacement of ECU20c.

[0050] (b) Maintenance example 2 (software changes) This document describes an example of maintenance involving changing the settings of the software installed in the ECU20. Specifically, it explains how to change the message transmission cycle of software installed in the ECU20 (for example, ECU20e) that periodically sends messages to other ECU20s.

[0051] While the settings of the software installed on ECU20e are being changed, the software cannot communicate. Therefore, a security sensor 201 installed on another ECU20 connected to ECU20e, for example using a health monitoring function, detects an anomaly indicating that ECU20e is not operating and generates a security log (b1). After the ECU20e software configuration changes are complete, the ECU20e software resumes sending messages. However, because the communication cycle of data sent and received on the in-vehicle network is different from before the configuration changes, the security sensor 201 (for example, security sensor 201c) that monitors the network detects this change in communication cycle as an anomaly and generates a security log (b2). Here, by adjusting the settings of security sensor 201c so that it does not detect the changed communication cycle as abnormal, security sensor 201c will no longer detect the change in the communication cycle as abnormal. However, another security sensor 201 (for example, security sensor 201d) will detect the adjustment of the settings in security sensor 201c as abnormal and generate security log (b3).

[0052] As described above, it is expected that security logs (b1), (b2), and (b3) will be generated by maintenance that changes the software settings of the ECU20e.

[0053] (c) Maintenance example 3 (Addition of ECU) This document describes a maintenance example for adding an ECU20 (e.g., ECU20f) to an electronic control system S.

[0054] When a new ECU20f is added to the electronic control system S, the data transmitted by ECU20f is communicated to other ECU20 via the in-vehicle network. Since this data did not exist before the addition of ECU20f, the security sensor 201 (e.g., 201c) detects the communication of unprecedented data on the in-vehicle network as an anomaly and generates a security log (c1). Here, by adjusting the settings of security sensor 201c so that it does not detect data communication by the newly added ECU20f as abnormal, security sensor 201c will no longer detect abnormalities. However, another security sensor 201 (for example, security sensor 201d) will detect the adjustment in the settings of security sensor 201c as abnormal and generate a security log (c2).

[0055] As described above, it is expected that security logs (c1) and (c2) will be generated by the maintenance performed to add a new ECU20 to the electronic control system S.

[0056] While this example describes maintenance procedures when adding an ECU, it is expected that similar security logs will be generated when adding new software to ECU20.

[0057] (d) Maintenance example 4 (ECU removal) This document describes a maintenance example involving the removal of ECU20 (e.g., ECU20e) from the electronic control system S.

[0058] If ECU20e is removed from the electronic control system S, the security sensor 201c detects that the data from ECU20e, which should be communicated over the in-vehicle network, is not being communicated as an anomaly and generates a security log (d1). Similar to (c) above, by adjusting the settings of security sensor 201c, security sensor 201c will no longer detect anomalies. However, another security sensor 201 (for example, security sensor 201d) will detect the adjustment in the settings of security sensor 201c as an anomaly and generate security log (d2).

[0059] As described above, it is expected that security logs (d1) and (d2) will be generated by the maintenance process of removing software from ECU20.

[0060] In this case, the ECU Delete We have explained maintenance examples for the ECU20. from Software delete In that case, it is expected that similar security logs will be generated.

[0061] 2. Embodiment 1 (1) Configuration of the log determination device 10 Figure 4 is a block diagram showing the configuration of the log determination device 10 in this embodiment. The log determination device 10 comprises a log acquisition unit 101, a log storage unit 102, a pattern storage unit 103, a false positive log determination unit 104, an information assignment unit 105, and a transmission unit 107. In this embodiment, the information assignment unit 105 implements a false positive information assignment unit 106.

[0062] The log acquisition unit 101 acquires security logs generated by the security sensor 201 mounted on the ECU 20. The configuration of the electronic control system S is as described in Figure 2, and the contents of the security logs are as described in Figure 3.

[0063] When the log determination device 10 adopts the configuration shown in Figure 1(c), the log acquisition unit 101 acquires security logs by receiving them via a communication network using a wireless communication method. As described above, the log acquisition unit 101 may acquire multiple aggregated security logs at once, or it may acquire generated security logs sequentially.

[0064] The log storage unit 102 is a storage unit that stores logs acquired by the log acquisition unit 101. Figure 5 shows an example of the information stored in the log storage unit 102. In the example shown in Figure 5, the log storage unit 102 stores the ECU-ID, event ID, and detection time included in the security log, as well as the identification information of the vehicle equipped with the electronic control system S (hereinafter referred to as the vehicle ID), and the identification information of the log assigned to each security log (hereinafter referred to as the log ID). For the sake of simplicity, the log ID shown in Figure 5 is represented as a combination of the vehicle ID and the order in which the log acquisition unit 101 acquired the logs.

[0065] The pattern storage unit 103 is a storage unit that stores the patterns of security logs that are expected to occur due to "maintenance" of the electronic control system S. As described above in 1.(3), when the electronic control system S is maintained, it is expected that certain security logs will be generated depending on the content of the maintenance.

[0066] Here, "maintenance" of an electronic control system refers to making any changes to the electronic control devices that make up the electronic control system, the software installed in the electronic control devices, the network connecting the electronic control devices, etc. Examples include the deletion, addition, replacement, and updating of electronic control devices.

[0067] Figure 6 shows an example of information stored in the pattern storage unit 103. In the example in Figure 6, the pattern storage unit 103 stores the maintenance identification number (hereinafter referred to as the maintenance ID), the occurrence pattern, and the predicted period. The occurrence pattern in Figure 6 consists of multiple sets, including a predicted event ID (corresponding to "predicted abnormality information") indicating an abnormality that is expected to be detected by the electronic control system S, a predicted ECU-ID (corresponding to "predicted abnormality location information") indicating the "location" within the electronic control system where the predicted abnormality is detected, a predicted count indicating the "number of times" the predicted abnormality will occur, and the numbers of these sets, as well as the occurrence order of the multiple sets. 6 The prediction period shown refers to the predicted period from the time the predicted anomaly is first detected to the time the predicted anomaly is last detected. Note that the occurrence pattern shown in Figure 6 is merely an example and is not limited to Figure 6. For example, the occurrence pattern may consist only of multiple sets including the predicted event ID and the predicted ECU-ID.

[0068] The term "number of times" can be defined by a specific value, or it may be defined by a maximum and / or minimum value.

[0069] For example, the occurrence pattern for maintenance ID

[0001] shown in Figure 6 indicates that abnormality a is detected once by ECU20c (occurrence sequence: 1), abnormality b is detected twice by ECU20d (occurrence sequence: 2), and then abnormality b is detected twice by ECU20e (occurrence sequence: 3). Furthermore, the predicted period for maintenance ID

[0001] is 20 minutes, which indicates that the predicted period from the time abnormality a is detected by ECU20c to the time the second abnormality b is detected by ECU20e is within 20 minutes.

[0070] Furthermore, the occurrence pattern for maintenance ID

[0002] shown in Figure 6 indicates that abnormality c is detected two or more times in ECU20a, or abnormality c is detected two or more times in ECU20b (occurrence sequence: 1), then abnormality c is detected 2 to 4 times in ECU20d, and abnormality c is detected 2 to 4 times in ECU20e (occurrence sequence: 2), and then abnormality b is detected up to 5 times in ECU20c (occurrence sequence: 3). In addition, the predicted period for maintenance ID

[0002] is 30 minutes, which indicates that the predicted period from the time when the first abnormality c is detected in ECU20a or ECU20b to the time when abnormality b is last detected in ECU20c is within 30 minutes.

[0071] The pattern storage unit 103 may further store information regarding security logs (hereinafter referred to as "undetected logs") that are not expected to occur due to maintenance of the electronic control system S. Figure 7 shows an example of information regarding undetected logs stored in the pattern storage unit 103. In the example in Figure 7, the pattern storage unit 103 stores a set that includes a maintenance ID, an undetected ECU-ID indicating a "location" within the electronic control system where it is expected that no abnormality will be detected due to maintenance (corresponding to "predicted undetected location information"), and an undetected event type indicating an abnormality that is expected not to be detected by the ECU indicated by the undetected ECU-ID (corresponding to "predicted undetected abnormality information").

[0072] For example, in the case of maintenance ID

[0001] shown in Figure 7, it indicates that no abnormality c will be detected by ECU 20a within the predicted period of 20 minutes for maintenance ID

[0001] shown in Figure 6. Also, in the case of maintenance ID

[0002] , it indicates that no abnormality a will be detected by ECU 20a and no abnormality a will be detected by ECU 20b within the predicted period of 30 minutes for maintenance ID

[0002] .

[0073] In Figures 6 and 7, ECU identification information (i.e., predicted ECU-ID) is used as information indicating the location within the electronic control system. However, the occurrence pattern may also use security sensor or network identification information as information indicating the location within the electronic control system.

[0074] Furthermore, the patterns generated by maintenance may differ depending on the type of vehicle (e.g., make, model, year). Therefore, the pattern storage unit 103 may store the occurrence patterns and predicted periods for each type of vehicle.

[0075] The occurrence patterns and prediction periods stored in the pattern storage unit 103 are set by the vehicle manufacturer, dealer, repair shop, etc. For example, the occurrence patterns and prediction periods may be set based on logs recorded during experimental work conducted by dealers, etc., to set estimated completion times for maintenance work and to create maintenance procedures. The occurrence patterns and prediction periods may also be set based on security logs that occurred when an actual cyberattack occurred, or when an experimental attack that simulated an actual cyberattack occurred. For example, even if a security log matches an occurrence pattern that is expected to occur due to maintenance, the occurrence patterns and prediction periods may be set in such a way that security logs that match a pattern that is expected to occur when a cyberattack occurs are not judged as false positives.

[0076] The false positive log determination unit 104 compares the multiple security logs stored in the log storage unit 103 and the occurrence order of the multiple security logs with the occurrence patterns stored in the pattern storage unit 103 to determine whether the multiple security logs acquired by the log acquisition unit 101 are false positive logs generated due to the detection of an anomaly caused by maintenance, and outputs the determination result. Here, a false positive log refers to a security log generated when a security sensor detects an anomaly different from an anomaly caused by an attack on the electronic control system S. In this disclosure, a false positive log is determined when a security sensor detects an anomaly caused by maintenance of the electronic control system S.

[0077] For example, the false positive log determination unit 104 compares the contents of the security log shown in Figure 5 with the occurrence pattern shown in Figure 6. According to Figures 5 and 6, the ECU-ID and event ID of log ID [01-2] shown in Figure 5 match the predicted ECU-ID and predicted event ID of set number [1] of maintenance ID

[0001] shown in Figure 6. The ECU-ID and event ID of log IDs [01-3] and [01-4], as well as the number of security logs (i.e., 2), match the predicted ECU-ID and predicted event ID and predicted number of occurrences of set number [2]. Also, the ECU-ID and event ID of log IDs [01-6] and [01-7], as well as the number of security logs (i.e., 2), match the predicted ECU-ID and predicted event ID and predicted number of occurrences of set number [3]. Furthermore, the occurrence order of log IDs [01-2], [01-3] and [01-4], [01-6] and [01-7] matches the occurrence order of the occurrence pattern for maintenance ID

[0001] .

[0078] The false positive log determination unit 104 further compares the period from the detection time (10:00:00) of log ID [01-2], which has the earliest detection time among the security logs mentioned above, to the detection time (10:14:00) of log ID [01-7], which has the latest detection time, with the predicted period shown in Figure 6. In this case, the period from the detection time (10:00:00) to (10:14:00) is within the predicted period.

[0079] The false positive log determination unit 104 further determines whether or not a security log corresponding to a non-detection log was detected between the earliest detection time and the latest detection time. According to Figure 5, 7 No security logs corresponding to the non-detection log shown (i.e., abnormal c in ECU20a) have been detected.

[0080] Therefore, the false positive log determination unit 104 determines that the security logs with log IDs [01-2], [01-3], [01-4], [01-6], and [01-7] are false positive logs.

[0081] In contrast, among the security logs stored in the log storage unit 102, security logs other than those with the aforementioned log IDs do not match the occurrence patterns stored in the pattern storage unit 103. Therefore, the false positive log determination unit 104 determines that these security logs are not false positive logs, that is, they are security logs generated as a result of detecting an abnormality that occurred in the electronic control system S.

[0082] The false positive log determination unit 104 of this embodiment performs false positive log determination processing periodically or at the timing of a predetermined event. Examples of the timing of a predetermined event include the timing of turning the vehicle's power on or off, the timing of the vehicle performing a specific action, or the timing of the log acquisition unit 101 acquiring a new security log.

[0083] In the block diagram shown in Figure 4, the false positive log determination unit 104 is shown as an example in which it outputs the determination result to the positive information assignment unit 105, which will be described later. However, the false positive log determination unit 104 may also output the determination result to memory (not shown), such as RAM (Random Access Memory).

[0084] The information assignment unit 105 assigns information to the security log based on the judgment result output from the false positive log determination unit 104. In this embodiment, the information assignment unit 105 implements the false positive information assignment unit 106.

[0085] The false positive information assignment unit 106 assigns "false positive information," which is information identifying a false positive log, to the security log based on the judgment result output from the false positive log determination unit 104. If the judgment result of the false positive log determination unit 104 is output to and stored in memory such as RAM (not shown), the false positive information assignment unit 104 assigns false positive information to the security log based on the judgment result stored in memory.

[0086] Here, "false positive information" refers not only to information indicating that a security log is a false positive, but also to information indicating that a security log is not a false positive.

[0087] For example, the false positive information assignment unit 106 assigns a flag as false positive information to security logs that the false positive log determination unit 104 has determined to be false positive logs, indicating that the security log is a false positive log. The false positive information may also be assigned by storing it in the context data of the security log, as shown in Figure 3. By assigning a flag as false positive information to security logs in this way, it becomes easy to distinguish between security logs generated by attacks and security logs generated due to maintenance.

[0088] The following embodiment describes a case in which the false positive information assignment unit 106 assigns false positive information to a security log that has been determined to be a false positive log. However, the false positive information assignment unit 106 may also assign false positive information to a security log that the false positive log determination unit 104 has determined not to be a false positive log. In this case, the false positive information indicates that the security log to which the information is assigned is not a false positive log.

[0089] The transmission unit 107 transmits security logs that have not been determined to be false positive logs, and security logs that have been determined to be false positive logs. For example, the transmission unit 107 transmits these security logs to an attack analysis device (not shown) that analyzes them. The attack analysis device that receives the security logs can determine whether or not a security log is a false positive log based on the false positive information attached to the security log.

[0090] Alternatively, the transmission unit 107 may transmit only security logs that have not been determined to be false positives. In the case of the log determination device 10 shown in Figures 1(a) and 1(b), the amount of communication between the vehicle and the attack analysis device can be reduced by transmitting only security logs that have not been determined to be false positives to an attack analysis device (not shown) located outside the vehicle.

[0091] In this embodiment, the transmission unit 107 is configured to transmit security logs from the log determination device 10. However, the transmission unit 107 may transmit the determination result from the false positive log determination unit 104 instead of, or in addition to, the security logs.

[0092] (2) Operation of the log determination device 10 The operation of the log determination device 10 will be explained with reference to Figures 8 and 9. Figures 8 and 9 not only show the log determination method executed by the log determination device 10, but also the processing procedure of the log determination program that can be executed by the log determination device 10. Furthermore, these processes are not limited to the order shown in Figures 8 and 9. That is, the order may be changed unless there is a constraint such as a relationship where one step utilizes the result of the preceding step. The same applies to Figures 13 and 14 of Embodiment 2, which will be described later.

[0093] The log acquisition unit 101 acquires security logs generated when a security sensor 201 mounted on each of the multiple ECUs 20 constituting the electronic control system S detects an abnormality (S101). The log storage unit 102 stores the security logs acquired by the log acquisition unit 101 (S102). Here, the false positive log determination unit 104, when it is time to determine the log (S103:Y), for example, when the log determination process is performed at periodic intervals, determines whether the security log stored in the log storage unit 102 is a false positive log or not when a certain amount of time has elapsed since the last log determination (S104). Details of the process in S104 will be described later.

[0094] Based on the determination result in S104, if the security log is determined to be a false positive log (S105:Y), the false positive information assignment unit 106 assigns false positive information to the security log that has been determined to be a false positive log (S106). Next, the transmission unit 107 transmits security logs that have not been determined to be false positive logs, and security logs that have been determined to be false positive logs and to which false positive information has been added (S107).

[0095] Next, referring to Figure 9, the process for determining whether a security log is a false positive log in S104 will be explained. Although not explicitly shown in Figure 9, the process in Figure 9 is executed repeatedly for the number of occurrence patterns stored in the pattern storage unit 103.

[0096] The false positive log determination unit 104 compares multiple security logs stored in the log storage unit 102, and their occurrence order, with the occurrence patterns stored in the pattern storage unit 103 (S201). If, as a result of comparing the security logs with the occurrence pattern, multiple security logs and their occurrence order match the occurrence pattern (S202:Y), the false positive log determination unit 104 further compares the period from the earliest time information to the latest time information among the multiple security logs with the predicted period set in the occurrence pattern (S203). Then, if the period from the earliest time information to the latest time information falls within the prediction period (S203:Y), the false positive log determination unit 104 further determines whether the security logs detected during the period from the earliest time information to the latest time information include security logs corresponding to the undetected logs stored in the pattern storage unit 103 (S204). If no security logs corresponding to the non-detection log are included at this point (S204:N), the false positive log determination unit 104 determines that multiple security logs are false positive logs (S205). In contrast, if multiple security logs and their occurrence order and occurrence pattern do not match (S202:N), if the period from the earliest time information to the latest time information is not within the prediction period (S203:N), or if multiple security logs include security logs that correspond to undetected logs (S204:Y), the false positive log determination unit 104 determines that the multiple security logs are not false positive logs (S206). The false positive log determination unit 104 then outputs the determination result (S207).

[0097] (3) Summary As described above, according to this embodiment, security logs generated due to vehicle maintenance can be determined to be false positive logs. As a result, a device that analyzes attacks using security logs can analyze attacks using security logs excluding those generated due to vehicle maintenance, thereby improving the accuracy of attack analysis. Furthermore, according to this embodiment, by not transmitting security logs that have been determined to be false positives, the amount of communication between the log determination device and the attack analysis device can be reduced.

[0098] 3. Embodiment 2 This embodiment describes a method for determining whether a security log is a false positive log, using a method different from that of Embodiment 1. Figure 10 is a block diagram showing the configuration of the log determination device 11 of this embodiment. Components identical to those in the log determination device 10 of Embodiment 1 are denoted by the same reference numerals. The log determination device 11 of this embodiment will be described below, focusing on the differences from Embodiment 1.

[0099] (1) Configuration of the log determination device 11 In this embodiment, the false positive log determination unit 104 sequentially determines whether a security log is a false positive log when the log acquisition unit 101 acquires a security log. In the above-described embodiment 1, the timing of log determination was described as the timing when the log acquisition unit 101 acquires a new security log. In embodiment 1, the false positive log determination unit 104 compared a plurality of security logs stored in the log storage unit 102 with their occurrence order and occurrence pattern, and determined whether or not they were false positive logs based on whether or not they were a perfect match. In contrast, in this embodiment, the newly acquired security log is determined at the timing when the new security log is acquired to determine whether or not it matches a part of the security logs stored in the log storage unit 102 with their occurrence order and occurrence pattern.

[0100] The false positive log determination unit 104 of this embodiment determines whether the newly acquired security log (hereinafter referred to as the acquired security log) and the security log stored in the log storage unit 102 (hereinafter referred to as the stored security log), as well as their occurrence order and a part of the occurrence pattern, match. If the acquired security log and the stored security log, as well as their occurrence order and a part of the occurrence pattern, match, the degree of matching between the acquired security log and the stored security log, as well as their occurrence order and the occurrence pattern is calculated.

[0101] The false positive log determination unit 104 determines that the acquired security log and the stored security log are false positive logs if the calculated matching degree is 100%. In response to this, the false positive log determination unit 104 determines that if the matching degree does not reach 100% within the prediction period, the acquired security log and the stored security log are not false positive logs.

[0102] In this embodiment, the information assignment unit 105 implements a provisional information assignment unit 111 in addition to the false positive information assignment unit 106. The provisional information assignment unit 111 assigns provisional information to the acquired security log and the stored security log indicating that it may be a false positive log if the matching degree calculated by the false positive log determination unit 104 is higher than a predetermined threshold.

[0103] "More than" includes both cases where the comparison target has the same value and cases where it does not.

[0104] Referring to Figures 11 and 12, the false positive log determination unit 104 and the provisional information assignment unit 111 of this embodiment will be described in more detail. Figures 11 and 12 show a comparison of acquired security logs and stored security logs with the occurrence patterns and the degree of matching. In Figures 11 and 12, the rectangles represent security logs, with white rectangles representing security logs newly acquired by the log acquisition unit 101 and diagonal rectangles representing security logs stored in the log storage unit 102. In the example shown below, the matching threshold is assumed to be 70%.

[0105] Figure 11(a) shows the state in which the log acquisition unit 101 has acquired log A, indicating that abnormality a was detected in ECU20c. Log A and a portion of the occurrence pattern of maintenance ID

[0001] shown in Figure 5 match. Therefore, the false positive log acquisition unit 104 calculates the degree of matching. In this example, the occurrence pattern of maintenance ID

[0001] includes a total of five sets, namely one set of ECU20c and abnormality a, two sets of ECU20d and abnormality b, and two sets of ECU20e and abnormality b. Therefore, since one of the five sets matches, the degree of matching is 20%. This degree of matching is below the threshold.

[0106] Figure 11(b) shows the state in which the log acquisition unit 101 has acquired log B, indicating that an anomaly b has been detected in ECU 20d. Since logs A and B and some of the occurrence patterns of maintenance ID

[0001] match, the false positive log acquisition unit 104 calculates the matching degree. In Figure 11(b), the matching degree is 40%, which is below the threshold. Similarly, Figure 11(c) shows the state in which the log acquisition unit 101 has acquired log C, indicating that an anomaly b has been detected in ECU 20d. Since logs A to C and some of the occurrence patterns of maintenance ID

[0001] match, the false positive log acquisition unit 104 calculates the matching degree. In Figure 11(c), the matching degree is 60%, which is below the threshold.

[0107] Figure 11(d) shows the state in which the log acquisition unit 101 has acquired log D, indicating that an anomaly b has been detected in ECU 20e. Since logs A to D and the occurrence pattern of maintenance ID

[0001] partially match, the false positive log acquisition unit 104 calculates the degree of matching. In Figure 11(d), the degree of matching is 80%, which is higher than the threshold for the degree of matching. Therefore, the temporary information assignment unit 111 assigns temporary information to logs A to D. Then, Figure 11(e) shows the state in which the log acquisition unit 101 has acquired log E, indicating that an anomaly b has been detected in ECU 20e. Since logs A to E and the occurrence pattern of maintenance ID

[0001] match, the false positive log acquisition unit 104 calculates the degree of matching. In Figure 11(e), the degree of matching is 100%. Therefore, the false positive log determination unit 104 determines that logs A to E are false positive logs. The false positive information assignment unit 116 then assigns false positive information to logs A to E.

[0108] Figures 12(a) to 12(d) are the same as Figures 11(a) to 11(d), but Figure 12(e) is different from Figure 11(e). In Figure 12(e), instead of log E, log F, which indicates that an anomaly c was detected by ECU20a, is obtained. According to Figure 6, the log indicating that an anomaly c was detected by ECU20a corresponds to the non-detection log for maintenance ID

[0001] . Therefore, in the case of Figure 12(e), the false positive log determination unit 104 determines that logs A to F are not false positive logs. The false positive log determination unit 104 then deletes the temporary information added in Figure 12(d). Note that Figure 12(e) is explained using the case where a non-detection log is obtained as an example, but the same applies if a log corresponding to log E in Figure 11(e) is not obtained within the prediction period from the time log A was obtained.

[0109] (2) Operation of the log determination device 11 The operation of the log determination device 11 will be explained with reference to Figures 13 and 14. Processes common to both the log determination device 10 and the log determination device 11 are denoted by the same reference numerals as in Figures 8 or 9.

[0110] Figure 13 shows a series of processes from when the log acquisition unit 101 acquires a security log, to when it determines whether the security log is a false positive log, and then sends the security log. Unlike Figure 8, Figure 13 does not include a process to determine whether or not it is time to determine the security log. Whenever the log acquisition unit 101 acquires a security log in S101 and saves the acquired security log in S102, the false positive log determination unit 104 always determines whether or not the security log is a false positive log (S104).

[0111] Next, referring to Figure 14, we will explain the process for determining whether the security log is a false positive log in S104 of Figure 13. The false positive log determination unit 104 compares the security log acquired in S101 of Figure 13 (i.e., the acquired security log) with the stored security log stored in the log storage unit 102, as well as their occurrence order and occurrence pattern (S301). If the acquired security log and the stored security log, as well as their occurrence order, match a part of the occurrence pattern (S302:Y), the false positive log determination unit 104 further compares the period from the earliest time information among the stored security logs to the time information of the acquired security log with the predicted period set in the occurrence pattern (S303). Then, if the period from the earliest time information to the time information of the acquired security log is within the predicted period (S303:Y), the false positive log determination unit 104 further determines whether the security logs detected from the earliest time information to the time information of the acquired security log include security logs that correspond to undetected logs (S304).

[0112] If no security logs corresponding to the non-detection log are included (S304:N), the false positive log determination unit 104 calculates the degree of matching between the acquired security logs and stored security logs and the occurrence pattern (S305). If the calculated matching degree is 100% (S306), it is determined that the acquired security log and the stored security log are false positive logs (S307). On the other hand, if the calculated matching degree is not 100%, the false positive log determination unit 104 further determines whether the matching degree is higher than a threshold (S306). If the matching degree is higher than the threshold, the temporary information assignment unit 111 assigns temporary information to the acquired security log and the stored security log (S309), and returns to the process shown in Figure 13. In contrast, if the matching degree is below the threshold, the process returns to S101 in Figure 13.

[0113] If the period from the earliest time information of the stored security log to the time information of the acquired security log is not within the predicted period (S303:N), or if the security log contains a non-detection log (S304:Y), the false positive log determination unit 104 determines whether or not provisional information has been attached to the determined security log (S310). If temporary information is attached to the security log, delete that temporary information (S311). The false positive log determination unit 104 then determines that the acquired security log and the stored security log are not false positive logs (S312).

[0114] Furthermore, in S302, even if the acquired security log and the stored security log do not match a part of the occurrence pattern (S302:N), the false positive log determination unit 104 determines that the acquired security log and the stored security log are not false positive logs (S312).

[0115] The false positive log determination unit 104 then outputs a determination result indicating whether or not the security log is a false positive log (S308).

[0116] (3) Summary As described above, according to this embodiment, even if not all security logs corresponding to the occurrence pattern have been acquired, it is possible to determine whether or not a security log may be a false positive log.

[0117] 4. Summary The features of the log determination device and the like in each embodiment of the present invention have been described above.

[0118] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.

[0119] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.

[0120] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.

[0121] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.

[0122] Each embodiment is based on a log determination device for a vehicle for determining security logs generated by a security sensor of an electronic control unit mounted on a vehicle. However, unless otherwise specifically limited by the claims, the present invention also includes dedicated or general-purpose devices other than those for vehicles.

[0123] Furthermore, the following are examples of the log determination device of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.

[0124] Furthermore, necessary functions such as an antenna and a communication interface may be added to the log determination device.

[0125] The log determination device of the present invention is intended to be used particularly on the server side for the purpose of providing various services. In connection with the provision of such services, the log determination device of the present invention will be used, the method of the present invention will be used, and / or the program of the present invention will be executed.

[0126] In addition, the present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.

[0127] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]

[0128] The log determination device of the present invention is primarily intended for determining security logs generated by security sensors of electronic control devices installed in electronic control systems mounted in automobiles, but it may also be intended for devices that analyze logs generated by ordinary systems or devices not installed in automobiles. [Explanation of Symbols]

[0129] 1 Log determination system, 10(11) Log determination device, 101 Log acquisition unit, 103 Pattern storage unit, 104 False positive log determination unit, 106 False positive information assignment unit, 107 Transmission unit, 111 Temporary information assignment unit, 201 Security sensor, 202 Log transmission unit

Claims

1. A log acquisition unit (101) acquires a plurality of security logs, each containing abnormality information indicating an abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected. A pattern storage unit (103) stores a pattern of occurrences of security logs that are expected to occur due to maintenance of the electronic control system, the pattern of occurrences comprising a plurality of sets, each including predicted anomaly information indicating an anomaly that is expected to be detected by the electronic control system, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly is detected. A false positive log determination unit (104) compares the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and outputs the determination result. A log determination device (10, 11) is provided.

2. The occurrence pattern consists of the plurality of sets, plus the occurrence order of the plurality of sets. The false positive log determination unit compares the plurality of security logs, the occurrence order of the plurality of security logs, and the occurrence pattern to determine whether the plurality of security logs are false positive logs. The log determination device according to claim 1.

3. The aforementioned multiple security logs each further include time information indicating the time when the anomaly was detected. The pattern storage unit further stores a prediction period, which indicates the predicted period from the time when the predicted anomaly is first detected to the time when the predicted anomaly is last detected. The false positive log determination unit further compares the period from the first time information, which is the earliest time information among the time information, to the second time information, which is the latest time information, with the predicted period, and determines whether the plurality of security logs are false positive logs. The log determination device according to claim 1.

4. The aforementioned sets further include a predicted number indicating the number of times the predicted anomaly will occur, The false positive log determination unit compares the number of security logs among the plurality of security logs that share the abnormal information and the location information with the predicted number of times to determine whether or not the plurality of security logs are false positive logs. The log determination device according to claim 1.

5. The pattern storage unit further stores predicted undetected location information indicating a location within the electronic control system where it is predicted that no abnormality will be detected by the maintenance, and predicted undetected abnormality information indicating an abnormality where it is predicted that no abnormality will be detected at the location indicated by the predicted undetected location information. The false positive log determination unit further compares the plurality of security logs with the predicted non-detection anomaly information and the predicted non-detection location information to determine whether the plurality of security logs are false positive logs. The log determination device according to claim 1.

6. The log determination device further includes a false positive information assignment unit (106) that assigns false positive information to the plurality of security logs to identify the false positive log based on the determination result, The system includes a transmission unit (107) that transmits the security log to which the false positive information has been added, The log determination device according to claim 1.

7. The false positive log determination unit further calculates the degree of matching between the plurality of security logs and the occurrence pattern. The log determination device further, The system includes a provisional information assignment unit (111) that assigns provisional information to the multiple security logs indicating that the multiple security logs may be false positive logs when the matching degree is higher than a threshold. The log determination device according to claim 1.

8. The aforementioned multiple security logs each further include time information indicating the time when the anomaly was detected. The pattern storage unit further stores a prediction period, which indicates the predicted period from the time when the predicted anomaly is first detected to the time when the predicted anomaly is last detected. If the matching degree does not reach 100% within the time period elapsed from the earliest time information among the aforementioned time information, the false positive log determination unit determines that the multiple security logs are not false positive logs and deletes the provisional information. The log determination device according to claim 7.

9. The aforementioned electronic control system and log determination device are mounted on a mobile body. A log determination device according to any one of claims 1 to 8.

10. The aforementioned electronic control system is mounted on a mobile body, The log determination device is located outside the mobile body. A log determination device according to any one of claims 1 to 8.

11. A log determination method performed by log determination devices (10, 11), The log determination device includes a pattern storage unit (103) that stores a plurality of occurrence patterns, each consisting of predicted anomaly information indicating an anomaly that is expected to be detected by the electronic control system and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly is detected, which are occurrence patterns of security logs that are expected to occur due to maintenance of the electronic control system. The log determination method is: Multiple security logs are acquired, each containing abnormality information indicating an abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected (S101). The multiple security logs are compared with the occurrence pattern to determine whether the multiple security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and the determination result is output (S104). Log analysis method.

12. A log determination program that can be executed by a log determination device (10, 11), The log determination device includes a pattern storage unit (103) that stores a plurality of occurrence patterns, each consisting of predicted anomaly information indicating an anomaly that is expected to be detected by the electronic control system and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly is detected, which are occurrence patterns of security logs that are expected to occur due to maintenance of the electronic control system. The log determination program is performed in the log determination device, Multiple security logs are acquired, each containing abnormality information indicating an abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected (S101). The multiple security logs are compared with the occurrence pattern to determine whether the multiple security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and the determination result is output (S104). Log analysis program.

13. A log determination system (1) having an electronic control system (S) and log determination devices (10, 11), The aforementioned electronic control system is A log generation unit (201) generates a security log that includes abnormality information indicating the abnormality and location information indicating the location within the electronic control system where the abnormality was detected, when an abnormality is detected within the electronic control system. The system includes a log transmission unit (202) that transmits the security log to the log determination device, The log determination device is A log acquisition unit (101) that acquires multiple security logs transmitted from the log transmission unit, A pattern storage unit (103) stores a pattern of occurrences of security logs that are expected to occur due to maintenance of the electronic control system, the pattern of occurrences comprising a plurality of sets, each including predicted anomaly information indicating an anomaly that is expected to be detected by the electronic control system, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly is detected. The system includes a false positive log determination unit (104) that compares the plurality of security logs with the occurrence pattern to determine whether the plurality of security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and outputs the determination result. Log analysis system.

14. A log acquisition unit (101) acquires a plurality of security logs, each containing abnormality information indicating an abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected. A storage unit (103) that stores characteristics of security logs that are expected to be generated by maintenance of the electronic control system, A false positive log determination unit (104) compares the plurality of security logs with the characteristics to determine whether the plurality of security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and outputs the determination result. A log determination device equipped with the following features.

15. The aforementioned electronic control system is installed in the vehicle. The aforementioned maintenance includes vehicle maintenance at the factory, The log determination device according to claim 14.

16. A log determination program that can be executed by a log determination device (10, 11), The log determination device includes a storage unit (103) that stores characteristics of security logs that are expected to be generated by maintenance of the electronic control system. The log determination program is performed in the log determination device, Multiple security logs are acquired, each containing abnormality information indicating an abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected (S101). The plurality of security logs are compared with the characteristics to determine whether the plurality of security logs are false positive logs generated because an anomaly caused by the maintenance was detected, and the determination result is output (S104). Log analysis program.

17. A system comprising a vehicle and a log determination device installed outside the vehicle, The vehicle is equipped with an electronic control system having multiple electronic control units, each electronic control unit having a security sensor for detecting abnormalities. The log determination device is A log acquisition unit (101) acquires a plurality of security logs, each including abnormality information indicating the abnormality detected within the electronic control system and location information indicating the location within the electronic control system where the abnormality was detected. A storage unit (103) that stores characteristics of security logs that are expected to be generated by maintenance of the electronic control system, The system includes a false positive log determination unit (104) that compares the plurality of security logs with the characteristics to determine whether the plurality of security logs are false positive logs generated due to the detection of an anomaly caused by the maintenance, and outputs the determination result. system.