Communication system, control device, and communication method
The communication system addresses the challenge of identifying and responding to network attacks by incorporating a control device that receives external threat information to implement unified defense processes, enhancing network security and response efficiency.
Patent Information
- Application Number
- JP2023172288
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-10-03
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2043-10-03
AI Technical Summary
As communication systems become more sophisticated and complex, it becomes difficult for a single communication system to effectively identify and respond to attacks on the network.
A communication system that includes a control device, such as a security collaboration unit, which receives threat information from external organizations and performs defense processes to protect communication devices using the network, utilizing threat intelligence to implement unified and rapid responses across the network.
Enables broader and more reliable detection and response to attacks, ensuring rapid and effective defense across the communication network, including filtering, blocking, and mitigating threats based on threat intelligence.
Smart Images

Figure 0007910536000001 
Figure 0007910536000002 
Figure 0007910536000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a communication system, a control device, and a communication method.
Background Art
[0002] Today, as exemplified by 5G (5 , , , ,
[0004] , , , , , ,<00003rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS);Stage 2(Release 18)3GPP(registered trademark) TS 23.502 V18.2.0 (2023-06) [Non-Patent Document 2] 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects;5G System Enhancements for Edge Computing; Stage 2(Release 18) 3GPP (registered trademark) TS 23.548 V18.3.0 (2023-09) [Overview of the project] [Problems that the invention aims to solve]
[0005] However, as communication systems become more sophisticated and the communication networks they provide become more complex, it becomes difficult for a single communication system managing the communication network to identify signals related to attacks on that network.
[0006] The objective of the embodiments of this disclosure is to enable a broader and more reliable understanding of attacks on communication networks than before, and to respond appropriately to such attacks. [Means for solving the problem]
[0007] Embodiments of the disclosure are exemplified by a communication system that provides a communication network to a communication device. The communication system includes a control device. The control device performs the following: receiving threat information from an organization outside the communication system regarding threats to the communication device using the communication network; and performing a defense process to protect the communication device based on the received threat information. [Effects of the Invention]
[0008] This communication system allows for a broader and more reliable detection of attacks on the communication network provided by the communication system, and enables appropriate responses to such attacks. [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 is a diagram illustrating the components that make up a fifth-generation mobile communication system. [Figure 2] Figure 2 illustrates the structure of threat intelligence. [Figure 3] Figure 3 shows an example configuration of an NF, AF, and other information processing device. [Figure 4] Figure 4 shows an example of a terminal configuration as a UE (Unified Element). [Figure 5] Figure 5 is a sequence diagram illustrating the reception and defense processing of threat information in the communication system of the first embodiment. [Figure 6] Figure 6 is a sequence diagram illustrating the reception and defense processing of threat information in the communication system of the first embodiment. [Figure 7] Figure 7 illustrates the format conversion process. [Figure 8] Figure 8 illustrates the process by which the security collaboration unit selects a defense action to be executed when it receives threat information in a different format. [Figure 9] Figure 9 is a sequence diagram illustrating the reception and defense processing of threat information in the communication system of the second embodiment. [Figure 10] Figure 10 is a sequence diagram illustrating the reception and defense processing of threat information in the communication system of the second embodiment. [Figure 11] Figure 11 is a sequence diagram illustrating the reception of threat information and honeypot induction processing in the communication system of the third embodiment. [Figure 12]FIG. 12 is a sequence diagram illustrating the reception of threat information and honeypot induction processing in the communication system of the third embodiment.
Embodiments for Carrying Out the Invention
[0010] Hereinafter, a communication system, a control device, and a communication method according to embodiments of the present disclosure will be described with reference to the drawings. Each of the following embodiments is merely an example for explanation, and the present disclosure is not limited to the configurations of the embodiments. For example, in the following, an example in which the present disclosure is applied to a fifth-generation mobile communication system will be described, but the present disclosure may be applied to a fourth-generation or subsequent fifth-generation mobile communication system. The present disclosure may also be applied to a mobile communication system defined by other than 3GPP (registered trademark), or may be applied to any wireless communication system or wired communication system other than the mobile communication system.
[0011] This communication system provides a communication network to a communication device. This communication system includes a control device that executes a process of receiving threat information regarding a threat to a communication device using the communication network from an organization outside the communication system, and a defense process of defending the communication device based on the received threat information. In addition, this communication system has a function called NEF11e (Network Exposure Function) illustrated in FIG. 1, for example, and discloses a function provided from the communication system to the outside. Further, NEF11e receives information provided to this communication system from an external application server or the like. The threat information includes information regarding a cyber attack on the communication network, information regarding the vulnerability of the communication network, and the like. A cyber attack generally refers to an attack on an information processing device or a terminal. In the present embodiment, mainly, an attack on a communication device (UE2 in FIG. 1) connected to the communication network will be described as an example. The threat information includes information related to cyber attacks on the communication network, information related to the vulnerability of the communication network, and the like. A cyber attack generally refers to an attack on an information processing device or a terminal. In the present embodiment, mainly, an attack on a communication device (UE2 in FIG. 1) connected to the communication network will be described as an example.
[0012] An organization outside this communication system, for example, connects to this communication system and uses a computer called an application server. The application server provides threat information to the control device either via the above-mentioned NEF11e or directly without using the NEF11e. This control device executes a defense process to defend the communication device based on the received threat information. Here, the threat information includes information for identifying an attacker 90 to the network (see, for example, FIG. 5). In each of the following embodiments, an "attacker" refers to an attack that poses a threat. It refers to a communication device, an information processing device, etc. that are the source of packets or traffic of an attack. Further, the threat information may include information for identifying a communication device that the attacker 90 targets, for example, a device called UE2 (User Equipment, see FIG. 1), or information for identifying a mobile body equipped with UE2.
[0013] The feature of this communication system is that it can execute a defense process on a communication device (UE2) using the communication network based on threat information received from an organization outside the communication system. That is, this communication system can effectively utilize not only the information that the communication system has alone but also threat information from external organizations to defend communication devices using the communication network provided by this communication system from attacks.
[0014] <First Embodiment> (Configuration of Communication System) Hereinafter, the first embodiment will be described based on the drawings. FIG. 1 illustrates components (constituent elements ) that constitute a fifth-generation mobile communication system (also called 5G network, 5GNW (Network)). In FIG. 1, UE2 is a user (subscriber)'s terminal. RAN (Radio Access Network) 3 is an access network to a 5G core network (5GC). RAN3 is composed of base stations (gNB (next Generation Node B)).
[0015] The 5G network has a 5G core network (5GC) and an access network ((R)AN), and the 5G network is connected to UE2, DN (Data Network)5, and AF (Application Function)12. Furthermore, the 5GC has NF11a~11k and 11n, shown in bold. Each of NF11a~11k and 11n is a function realized by one or more computers (information processing devices) executing a program. However, a single computer may realize two or more of NF11a~11k and 11n. In this embodiment, the components of the 5GC are collectively called NF11 (Network Function). Individually, the components of the 5GC are referred to as NEF11e, etc. In Figure 1, each component is given a general code along with its individual code in parentheses. The 5GC can be considered an example of a communication system.
[0016] As described above, 5GC is composed of a set of components called NF11, each having a predetermined function. Figure 1 illustrates the following as NF11 components that make up 5GC. In Figure 1, they are shown as rectangles with thick lines. UPF (User Plane Function) 11a AMF (Access and Mobility Management Function)11b SMF (Session Management Function)11c PCF(Policy Control Function)11d NEF(Network Exposure Function)11e NRF(Network Repository Function)11g NSSF(Network Slice Selection Function)11h AUSF(Authentication Server Function)11i UDM(Unified Data Management)11j NWDAF(Network Data Analytics Function)11k Security Integration Unit 11n In this embodiment, user plane packets transmitted and received by UE2 are called user packets. UPF11a performs routing and forwarding of user packets, packet inspection, and QoS processing. AMF11b is the location accommodation device for UE2 in 5GC. AMF11b accommodates RAN3 and performs subscriber authentication control, UE2 location (mobility) management, etc.
[0017] SMF11c manages PDU (Protocol Data Unit) sessions and QoS (Quality of Service). UPF11a is controlled to implement y of Service control and policy control. A PDU session is a virtual communication channel for data exchange between UE2 and DN5. DN5 is an external data network (such as the Internet) outside of 5GC.
[0018] PCF11d works in conjunction with SMF11c to perform QoS control, policy control, and billing control. QoS control involves controlling the quality of communication, such as prioritizing packet forwarding. Policy control involves communication control, such as QoS, packet forwarding eligibility, and billing, based on network or subscriber information.
[0019] NEF11e acts as an intermediary for communication between AF12 or nodes outside of 5GC and 3GPP® NF11s. For example, NEF11e securely exposes the functions and events of each NF11 to third parties, AF12, edge computers, etc. NEF11e also performs conversion between 5GC's internal and external information. For example, NEF11e converts information handled by AF12 to information handled by each 5GC NF11. For example, NEF11e converts service identifiers in AF12 to 5GC internal information.
[0020] AF12 is an element that interacts with 5GC to provide services to users, and is referred to as, for example, an external application server. AF12 that is considered trusted by the 5G network operator can directly access the relevant NF11 of 5GC. AF12 that is not authorized to directly access the relevant NF11 of 5GC utilizes an externally exposed interface via NEF11e to access the network functions of 5GC.
[0021] Information source AF12a is one of AF12. Information source AF12a is, for example, an application server accessible from organizations outside 5GC. Information source AF12a receives information from organizations outside 5GC, which is a communication system, regarding cyberattacks on communication devices such as UE2 that utilize the communication network. Organizations outside 5GC include, for example, CERT (Computer Emergency Response Team) outside the communication network operator that operates 5GC, NIST (National Institute of Standards and Technology) in the United States, JPCERT / CC (Japan Computer Emergency Response Team / Coordination Center), Industrial ISAC (Information Sharing and Analysis Center), individual terminal manufacturers, and mobile Manufacturers, distributors, and OEMs (Original Equipment Manufacturers) of moving parts Examples are given.
[0022] Information source AF12a is, for example, located in an organization outside of 5GC. Alternatively, information source AF12a is connected to a computer in an organization outside of 5GC, making it accessible from that organization. Information source AF12a provides threat information (in the form of STIX (Structured Threat Information eXpression), etc.) from the organization outside of 5GC to the security collaboration unit 11n.
[0023] In this embodiment, the threat information provided from information source AF12a to NEF11e or security collaboration unit 11n is provided, for example, in a request / response model. For example, information source AF12a sends a request message to NEF11e or security collaboration unit 11n for the provision of threat information. When NEF11e or security collaboration unit 11n receives the threat information, it sends a response message back to information source AF12a.
[0024] However, the threat information provided from information source AF12a to NEF11e or security collaboration unit 11n may be provided, for example, in a subscribe / notification model. That is, NEF11e or security collaboration unit 11n sends a subscribe message to information source AF12a. Then, information source AF12a receives notifications such as when the threat information is updated. When the trigger condition is met, a notification is sent to NEF11e or the security collaboration unit 11n. Then, NEF11e or the security collaboration unit 11n can access the information source AF12a to obtain threat information.
[0025] In this embodiment, a security linkage unit 11n is provided as one of the NF11s to respond to threat information provided from the information source AF12a. However, the security linkage unit 11n may also be provided as one of the AF12s. The information source AF12a is an example of a control device. For example, when the security linkage unit 11n receives threat information from a vehicle manufacturer (or distributor), it may perform attack defense processing on all UE2s installed in vehicles manufactured by the manufacturer that are connected to the communication network. Alternatively, the security linkage unit 11n may perform defense processing only on UE2s installed in specific vehicle models among vehicles manufactured by the manufacturer that are connected to the communication network. Here, the defense processing includes, for example, processing to filter threatening packets or traffic based on the threat information, processing to mitigate traffic exceeding a predetermined mitigation value and discard abnormal packets, and processing to analyze the attack.
[0026] The security collaboration unit 11n enables a unified and rapid response to threats within the communication network by implementing a unified defense process across the communication network against attacks based on threat intelligence. Based on information provided by CERT / NIST, the security collaboration unit 11n applies blocking or mitigation measures to threatening packets or traffic across the entire communication network, regardless of the UE2 manufacturer. The security collaboration unit 11n also responds to information such as vulnerabilities with a CVSS score of 10, i.e., information that has been publicly disclosed as having a "critical" severity level. For example, the security collaboration unit 11n selects UE2s that have the target computer program, etc., that has been found to be vulnerable, and applies a unified defense process across the communication network in the UPF11a to which the UE2 is connected.
[0027] The security linkage unit 11n is an example of a control device. That is, this communication system is a communication system that provides a communication network to a communication device, and includes a security linkage unit 11n as a control device. The security linkage unit 11n performs the following: receiving threat information from an organization outside the communication system regarding threats to a communication device (UE2) that uses the communication network, and performing a defense process to protect the communication device based on the received threat information. Here, the threat information may include, for example, data called signatures, which describe the characteristics of various attacks.
[0028] NRF11g stores and manages information on NF11s (e.g., AMF11b, SMF11c, UPF11a, etc.) within 5GC. In response to inquiries regarding NF11s that users wish to use, NRF11g can return multiple candidate NF11s to the inquirer.
[0029] NSSF11h has the function of selecting the network slice to be used by the subscriber from among the network slices generated by network slicing. A network slice is a virtual network with specifications tailored to its intended use.
[0030] AUSF11i is a subscriber authentication server that performs subscriber authentication under the control of AMF11b. UDM11j holds or manages subscriber-related information. Subscriber-related information can be considered an example of contract data. Contract data includes, for example, the user of the communication equipment (UE2) and the operator (MNO (Mobile Network Operator)) that manages the communication system. This information is based on a contract with (also known as). UDM11j provides subscriber-related information to each NF11, or retrieves, registers, deletes, and modifies the status of UE2.
[0031] The NWDAF11k has the function of collecting and analyzing data from each NF11, OAM (Operations, Administration, and Maintenance) terminal, etc. Here, the OAM terminal It is responsible for the operation, management, and maintenance of the network (5GC). In other words, NWDAF11k is an NF11 that provides network analysis information.
[0032] DN5 is an external network to the communication system, such as the internet. DN5 is connected to the communication network provided by this communication system (5GC) via one of the UPF11a. Note that the UPF11a can be configured in multiple stages. The final stage UPF11a connected to DN5 is called the PSA UPF (PDU Session Anchor User Plane Function). The UPF11a placed between RAN3 and the PSA UPF is called the I (Intermediary) UPF.
[0033] In the example in Figure 1, DN5 includes a security device 51, a router 52, and an information source EAS (Edge Application Server 50 is connected. Security device 51, for example, firewall This is a computer on which a wall has been constructed. Information source EAS50 is a computer on DN5 that notifies the security linkage unit 11n of the communication system of threat information. However, the security device 51 and router 52 may be one of the AF12. When the application program of information source EAS50 provides threat information to NEF11e or the security linkage unit 11n, the threat information is provided via one of the AF12. Therefore, in each of the following embodiments, the provision of threat information will be described as being by information source AF12a.
[0034] Figure 2 illustrates the structure of threat information. In this embodiment, threat information has a header and a body. However, threat information is not limited to the format shown in Figure 2. Threat information may also be written as a string according to the grammar of a language such as STIX. However, threat information may also be in binary data format.
[0035] The header may include at least one piece of information, such as the protocol, source IP address, source port number, destination IP address, destination port number, and packet direction. The security cooperation unit 11n identifies a potentially threatening packet or traffic to be monitored based on the information exemplified in Figure 2.
[0036] The protocol is the protocol through which packets to be monitored based on threat information are sent and received. The source IP address is the IP address of the packet's source, i.e., the attacker 90. The source port number is the port number from which the packet was sent. The destination IP address and destination port number are the IP address and port number that identify the packet's destination. The packet direction is the direction in which the monitored packet is sent, for example, from source to destination or from destination to source. In addition, the information described in the header can be omitted individually. If any of this information is omitted, the security linkage unit 11n should interpret it as, for example, "all" being specified for the omitted information. For example, if the destination IP address is omitted, all destinations will be monitored.
[0037] The body contains additional information to identify attacker 90. This additional information to identify attacker 90 includes, for example, at least one of the following: data specification within the packet, flow status, information identifying the application of the communication, packet header information, and application (HTTP, etc.) header information. However, some or all of the additional information to identify attacker 90 may be omitted.
[0038] Specifying data within a packet means, for example, specifying the data contained in the packet to be monitored. The data contained in the monitored packet may be, for example, string information. Alternatively, the data contained in the monitored packet may be binary data (bit pattern). The binary data (bit pattern) may be specified, for example, in hexadecimal.
[0039] The state of a flow is, for example, a TCP (Transmission Control Protocol) connection. This includes whether or not a connection has been established. Examples of information that identifies the communication application include application layer protocols such as HTTP (Hypertext Transfer Protocol). The packet header information includes, for example, the specification of fragment bits in the IP datagram header. The application header information includes, for example, the request method in HTTP and the specification of the request URI (Uniform Resource Identifier) specified in the method. Furthermore, additional information to identify the attacker 90 includes the packet transmission information. Information indicating the original domain may be included.
[0040] Furthermore, the body may contain additional information to identify the target communication device. This additional information to identify the target communication device may include, for example, the model of the communication device (UE2), the type and version of the OS (Operating System), the type and version of the computer program installed on the UE2, and information to identify the mobile device on which the UE2 is installed. Information to identify the mobile device on which the UE2 is installed may include, for example, the manufacturer (OEM), model, and year of manufacture (year of initial registration) if the mobile device is a vehicle.
[0041] The security linkage unit 11n may uniformly execute defensive processing on all UE2s connected to this communication system. "Uniformly" means that the UE2s targeted for defensive processing are not limited. However, as shown in Figure 2, threat information may also contain information that identifies a specific communication device (target UE2) that is the target of an attack by the threat. This identifying information may include the destination IP address, destination port number, and additional information that identifies the target UE2 being attacked. Therefore, the security linkage unit 11n may execute defensive processing on the target UE2 specified in the threat information.
[0042] <Configuration of information processing equipment and terminal> Figure 3 shows an example configuration of an information processing device 20 capable of operating as NF11a~11k, 11n, AF12, information source AF12a, security device 51, router 52, information source EAS50, etc. In Figure 3, the information processing device 20 can be configured using a dedicated or general-purpose information processing device (computer) such as a personal computer (PC), workstation (WS), or server machine. However, the information processing device 20 may also be a collection of one or more computers (cloud).
[0043] The information processing device 20 includes a processor 21 acting as a processing unit or control unit (controller), a storage device 22, a communication interface 23 (communication IF 23), an input device 24, and a display 25, all interconnected via a bus 26.
[0044] The storage device 22 includes main memory and auxiliary storage. The main memory is used as at least one of the following: a program and data storage area, a program deployment area, a program work area, and a communication data buffer area. The main memory consists of RAM (Random Access Memory), or a combination of RAM and ROM (Read Only Memory). The auxiliary storage is used as a data and program storage area. Non-volatile storage media are used for the auxiliary storage. Non-volatile storage media include, for example, hard disks, solid state drives (SSDs), flash memory, or EEPROM (Electrically Erasable Programmable Read-Only Memory). The storage device 22 may also include a drive device for a disk recording medium.
[0045] Communication IF23 is a circuit that performs communication processing. For example, communication IF23 is a network interface card (NIC). Communication IF23 also handles wireless communication (5G, wireless LAN (Wi-Fi®), BLE (Bluetooth® Low Energy)), etc. ) may be a wireless communication circuit. Alternatively, the communication IF23 may be a combination of a circuit that performs wired communication processing and a wireless communication circuit.
[0046] The input device 24 includes keys, buttons, pointing devices, and touch panels, and is used for inputting information. The display 25 is, for example, a liquid crystal display or an OEL (organic electro-luminescence) display. The display 25 displays information and data.
[0047] The processor 21 performs various processes by executing various programs stored in the storage device 22. By the processor 21 executing the programs stored in the storage device 22, the information processing device 20 can operate as NF11 (UPF11a, etc.), AF12, information source AF12a, security device 51, router 52, information source EAS50, etc.
[0048] Figure 4 shows an example configuration of a terminal 40 capable of operating as a UE2. The terminal 40 includes a processor 41, a storage device 42, a communication interface 43 (communication IF 43), an input device 44, and a display 45, all interconnected via a bus 46. The processor 41, storage device 42, communication IF 43, input device 44, and display 45 can be the same as those used for the processor 21, storage device 22, communication IF 23, input device 24, and display 25. Therefore, their descriptions are omitted.
[0049] Processors 21 and 41 are, for example, Central Processing Units (CPUs). U is also called a Microprocessor Unit (MPU). Processors 21 and 41 are single-phase The configuration may be a processor-based or multiprocessor-based configuration. Furthermore, a single physical CPU connected via a single socket may have a multicore configuration. Processors 21 and 41 may include various circuit configurations of arithmetic units, such as Digital Signal Processors (DSPs) or Graphics Processing Units (GPUs). Processors 21 and 41 may also have configurations that interact with at least one of the following: integrated circuits (ICs), other digital circuits, and analog circuits. Integrated circuits include LSIs, Application Specific Integrated Circuits (ASICs), and Programmable Logic Devices (PLDs). PLD This includes, for example, a Field-Programmable Gate Array (FPGA). Processors 21 and 4 1 includes, for example, what are called microcontrollers (MCUs), SoCs (System-on-a-chip), system LSIs, or chipsets.
[0050] (Example of processing) Figures 5 and 6 are sequence diagrams illustrating the reception and defense processing of threat information in this communication system. Figures 5 and 6 are connected by terminals indicated by A1 to H1. In this process, first, the information source AF12a notifies NEF11e of the threat information (S1). The notification of threat information can also be called the notification of defense information. The threat information may include, for example, information that identifies the attacker 90 and information that identifies the target UE2 that is the target of the attack, as illustrated in Figure 2. NEF11e receives the threat information as an example of reception processing.
[0051] Then, NEF11e further notifies the security linkage unit 11n of the threat information (defense information) (S2). Note that if the information source AF12a is trusted by the MNO of the communication system, the information source AF12a can directly notify the security linkage unit 11n of the threat information (defense information) without going through NEF11e (S1A). The security linkage unit 11n receives the threat information as an example of the reception process.
[0052] Next, the security linkage unit 11n obtains information from the notified threat information to identify the target UE2 that is targeted in the threat information. Then, the security linkage unit 11n sends a message to the UDM11j requesting that it search for the target UE2 or the UPF information to which the target UE2 is connected (S3). The message requesting the search includes information to identify the target UE2. Examples of information to identify the target UE2 are shown in Figure 2. Examples include the destination IP address, destination port number, model of the target UE2, type and version of the OS, type and version of the installed computer program, and information identifying the mobile vehicle on which the target UE2 is installed (vehicle type).
[0053] The UDM11j then responds to the security linkage unit 11n with information about the target UE2, such as a unique identifier in 5GC or UPF information to which the target UE2 is connected (S4). Here, UPF information refers to an identifier that can uniquely identify any UPF within 5GC, such as an IP address or URI.
[0054] However, UDM11j may, in response to a search request (S3) from the security linkage unit 11n for information on target UE2s, obtain whether or not a defense process can be executed from the contract data in the subscriber-related information and respond to the security linkage unit 11n (S4). The security linkage unit 11n only needs to execute the defense process for UE2s for which the execution of the defense process is set to be possible in the contract data. Alternatively, the security linkage unit 11n may execute the defense process only for UE2s of users for whom the execution of the defense process is explicitly stated in the contract data.
[0055] When the security linkage unit 11n receives a response such as information about the target UE2 or information about the UPF to which the target UE2 is connected, it implements a defense setting against the threat for the corresponding UPF 11a to which the target UE2 is connected (S5). Here, the defense setting is, for example, a setting for the corresponding UPF 11a to block, filter, or mitigate packets or traffic from attacker 90. Packets or traffic from attacker 90 are identified by the threat information header and additional information that identifies attacker 90, as illustrated in Figure 2.
[0056] The security linkage unit 11n can, through this defense setting, block packets or traffic from attacker 90 at least in the UPF 11a where the target UE2 has established a UDP session. The security linkage unit 11n may also apply the defense setting to all UPF 11a, including those other than the one to which the target UE2 is connected. By applying the defense setting to all UPF 11a, the security linkage unit 11n can uniformly defend against attacks across the entire communication network managed by this communication system.
[0057] Similarly, the security linkage unit 11n uses the UPF 11a to which the target UE2 is connected as an anchor to perform threat defense settings on external security devices 51, routers 52, etc., connected via DN5 (S6). As already mentioned in Figure 1, the final stage UPF 11a connected to DN5 is called a PSA UPF. Also, the UPF 11a placed between RAN3 and the PSA UPF is called an I UPF. The above defense settings may be performed on either the PSA UPF or the I UPF.
[0058] However, the security device 51 and router 52 may also be one of the AF12. If the security device 51, router 52, etc. are one of the AF12, the security cooperation unit 11n may request the security device 51, router 52, etc. to notify the threat information and set up the defense process according to the threat information request / response model. Also, if the security device 51, router 52, etc. are one of the AF12, the security cooperation unit 11n may subs In accordance with the subscribe / notification model, information for configuring defense processing along with threat information may be provided to security devices 51, routers 52, etc. In the subscribe / notification model, when the security cooperation unit 11n receives a notification of threat information as a trigger condition, it notifies security devices 51, routers 52, etc. of the occurrence of threat information. Then, when security devices 51, routers 52, etc. are notified of the occurrence of threat information, they can obtain the threat information and information for configuring defense processing from the security cooperation unit 11n and configure the defense processing. With the defense settings described above, at least packets or traffic from attacker 90 will be blocked in security devices 51, routers 52, etc., to which the target UE2 is connected and a connection has been established.
[0059] When the defense settings are configured by the processing in S5 or S6, the target UE2 will have its communication with the attacker 90 blocked (S7-1). In addition, the target UE2 will have its communication with the attacker 90 blocked by the connected security device 51, router 52, etc. (S7-2). The security linkage unit 11n may also notify the target UE2 of the threat information via AMF 11b and have the target UE2 itself execute the defense settings against the threat. Next, the explanation will continue with reference to Figure 6.
[0060] As explained in Figure 5, the threat defense configuration blocks the attack from attacker 90 to target UE2 in UPF11a (S8). Additionally, the security device 51 and router 52 block the attack from attacker 90 to target UE2 (S9).
[0061] Subsequently, once the threat from attacker 90 is eliminated, information source AF12a receives confirmation from an organization outside the communication system that the threat has been removed. Then, information source AF12a notifies NEF11e of a message requesting that the defense be stopped (S10). Furthermore, NEF11e notifies security linkage unit 11n of a message requesting that the defense be stopped (S11). In cases where information source AF12a is trusted by the MNO of the communication system, information source AF12a can directly notify security linkage unit 11n of the message requesting that the defense be stopped without going through NEF11e (S10A).
[0062] Then, when the security linkage unit 11n is notified of a request to stop the defense, it sends a message to the UPF 11a requesting the deletion of the threat defense settings (S12). The security linkage unit 11n also sends messages to the security device 51, router 52, etc., requesting the deletion of the threat defense settings (S13).
[0063] Figure 7 illustrates a format conversion process performed by the security linkage unit 11n, etc., after the processing of S2 or S1A in Figure 5. The threat information provided from the information source AF12a is illustrated in Figure 2, for example. However, the format of the threat information that can be processed by the NF11 of this communication system may differ from the format of the threat information provided from the information source AF12a. In such cases, for example, the security linkage unit 11n converts the threat information provided from the information source AF12a into a format that can be processed by the NF11 of this communication system.
[0064] This process is activated, for example, when the security linkage unit 11n receives threat information in a format different from the format supported by the communication system's FN11 (S101). The security linkage unit 11n receives threat information in a format different from the format supported by the communication system's FN11 (referred to as a different format) from, for example, a dedicated API (Application Programming Interface) for different formats (S101). Therefore, if the security linkage unit 11n receives threat information in a format supported by the FN11 of this communication system, the process shown in Figure 7 will not be executed.
[0065] Then, the security linkage unit 11n converts the format of the threat information received from the API dedicated to different formats into a format supported by the communication system's FN11 (S102). For example, the security linkage unit 11n converts any components of different formats, such as the header and body, as illustrated in Figure 2, into a threat information format that can be processed by the communication system's NF11.
[0066] The security linkage unit 11n then transmits the format-converted threat information to the next NF11 of the communication system (S103). For example, in the process of S2 or S1A in Figure 5, the next NF11 is, for example, UDM11j. In addition, in the process of S6 in Figure 5, the security linkage unit 11n may select a configurable defense method for external security devices 51, routers 52, etc., based on the format-converted threat information. Figure 7 illustrates the format conversion process performed by the security linkage unit 11n. However, such format conversion may also be performed on other FN11, such as NEF11e, UDM11j, etc.
[0067] Figure 8 illustrates the process of selecting a defense process to be executed when the security linkage unit 11n receives threat information in a different format. That is, when the security linkage unit 11n receives threat information in a different format (S111), instead of converting the format, it may select a defense process corresponding to the threat information in the different format (S112). The security linkage unit 11n simply requests the selected defense process from the next FN11. The next FN11 is, for example, UDM11j, UPF11a, etc. in the process of S2 or S1A in Figure 5. However, in the process of S6 in Figure 5, the security linkage unit 11n may select the defense process to be set for the security device 51 or router 52 in S112. Then, the security linkage unit 11n simply sets the selected defense process for the security device 51 or router 52, etc. (S113). In other words, the security collaboration unit 11n can select a defense process that can be configured on the UDM 11j, UPF 11a, security device 51, or router 52 based on threat information in different formats.
[0068] (Effects of the first embodiment) As described above, the security linkage unit 11n, as an example of a control device, executes a process to receive threat information from an organization outside the communication system regarding UE2, which is a communication device that uses the communication network. The security linkage unit 11n also executes a defense process to protect UE2 based on the received threat information. Therefore, this communication system can quickly defend against attacks on UE2 using the communication network with a unified process within the communication network.
[0069] In this case, the security linkage unit 11n may uniformly execute defense processing at each UPF 11a connected to the communication system for all UE2s connected to the communication system. Therefore, all UE2s connected to the communication system can be protected without fail. Alternatively, the security linkage unit 11n may uniformly execute defense processing at all UPF 11a of the communication system. In this case, the entire communication system can respond to threat information.
[0070] However, the information source AF12a may include information that identifies a specific communication device (target UE2) that is the target of the attack within the threat information. In this case, the security coordination unit 11n only needs to perform defensive processing on the specific communication device. Therefore, the security coordination unit 11n can perform defensive processing with minimal impact on the processing of the communication system that provides the communication network.
[0071] Furthermore, if the target communication device is a mobile device, for example, a device mounted on a vehicle, The information source AF12a can include information such as the manufacturer, model, and year of manufacture of vehicles equipped with specific communication devices in its threat intelligence. The information source AF12a can then request a search from UDM11j based on information such as the vehicle model, and identify the target UE2 that is the target of the attack.
[0072] Furthermore, the security collaboration unit 11n receives threat information using NEF11e provided in 5GC. Therefore, the security collaboration unit 11n can receive threat information and set and deactivate threat defense settings in a manner consistent with the 5GC standard.
[0073] Furthermore, the security linkage unit 11n receives threat information directly without going through the NEF 11e. Therefore, if the information source AF12a is a trusted application server, the security linkage unit 11n can quickly receive threat information and configure and disable defense settings against the threat.
[0074] Furthermore, the security linkage unit 11n executes defense processing on security devices 51, routers 52, etc. connected to the communication network via DN5. In addition, the security linkage unit 11n executes defense processing on security devices 51, routers 52, etc. connected to this communication system (5GC, etc.) as one of AF12. In other words, based on threat information provided by an external organization of this communication system via information source AF12a, the security linkage unit 11n can execute defense settings against threats on security devices 51, routers 52, etc. on the communication network provided by this communication system.
[0075] Furthermore, NF11 units such as the security linkage unit 11n, NEF11e, and UDM11j convert threat information in a different format not supported by this communication system into a format supported by the FN11 of this communication system. The security linkage unit 11n also identifies and selects a defense process that can be performed by the FN11 in response to threat information in a different format not supported by the FN11 of this communication system. The FN11 units of this communication system, including the security linkage unit 11n, can then perform the identified defense process on this communication system. In addition, the security linkage unit 11n identifies a defense process that can be requested by the security device 51 or router 52 in response to threat information in a different format not supported by this communication system. The security linkage unit 11n can then configure the identified defense process on the security device 51 or router 52.
[0076] Furthermore, the aforementioned UDM11j holds subscriber-related information. Subscriber-related information can be considered an example of contract data. In other words, this communication system has a storage device (e.g., UDR (Unified Data Repository)) that stores contract data based on the contract between the UE2 user and the operator (MNO) managing this communication system. And the security linkage unit 11 n identifies or determines which of the multiple UE2s to which defensive processing should be applied, based on contract data held or managed by UDM11j. Therefore, this communication system can effectively utilize the above contract data to execute defensive processing. For example, as subscriber information, whether or not defensive processing can be performed by the security linkage unit 11n, or whether or not it is necessary to perform it, should be stored in the UDR. Thus, this communication system can identify or limit the UE2s to which defensive processing should be applied, based on the contract between the user and the MNO.
[0077] In other words, when the UDM 11j receives a search request for information on target UE2s from the security linkage unit 11n, it only needs to obtain from the UDR whether or not the defense process can be executed or whether it is actually necessary, and respond to the security linkage unit 11n. Therefore, the security linkage unit 11n only needs to execute the defense process for UE2s that are set in the contract data to be able to execute or to be required to execute the defense process.
[0078] As stated above, the information source AF12a is an AF connected to 5GC as a communication system. It is provided as one of the 12. Therefore, information source AF12a can obtain threat information from organizations outside the communication system in cooperation with FN11 of 5GC. As illustrated in Figure 1, information source AF12a may be provided in EAS etc. connected to DN5. Alternatively, information source AF12a may be provided in UE2.
[0079] <Second Embodiment> (Example of Processing) Referring to Figure 9, a communication system, control device, and communication method of a second embodiment will be described. In the first embodiment described above, the security linkage unit 11n performed a defense setting against the threat on the UPF 11a based on the threat information received via the NEF 11e or directly from the information source AF 12a, for example, blocking communication to the attacker 90. However, instead of this process, the security linkage unit 11n may request the PCF 11d to set a policy for defense settings. The PCF 11d may set the policy that was requested to be set, and then perform a defense setting on the UPF 11a via the SMF 11c or directly without going through the SMF 11c, according to the set policy.
[0080] In this embodiment, processes other than (1) and (2) below are the same as in the first embodiment. (1) The security linkage unit 11n sets a policy for setting up defenses against threats in the PCF 11d. (2) The PCF 11d sets up defenses in the UPF 11a either via the SMF 11c or directly without the SMF 11c. Therefore, the explanation of processes that are the same as in the first embodiment is omitted. In addition, the processes of the first embodiment other than the processes by the PCF 11d and the processes by the SMF 11c are executed as they are in this embodiment as well.
[0081] Figures 9 and 10 are sequence diagrams illustrating the defensive processing in this communication system. Note that the processing of S1, S2, and S1A in Figure 5 is assumed to have been executed before Figure 9. Furthermore, the processing in Figure 9 is continued to Figure 10 via terminals B1, K1, L1, C1, D1, and E1. Also, in Figure 9, the processing of S3 and S6 is the same as in Figure 5, so their explanation is omitted.
[0082] Figure 9 shows the processing that occurs after the security linkage unit 11n receives a response (S4) containing information about the target UE2 or information about the UPF to which the target UE2 is connected. In this embodiment, the security linkage unit 11n requests the PCF 11d to set a policy for implementing threat defense settings for the UPF 11a to which the target UE2 is connected (S51). The PCF 11d then sets a policy for implementing threat defense settings. The PCF 11d then requests the SMF 11c to perform defense settings for the UPF 11a to which the target UE2 is connected, according to the set policy (S52). The SMF 11c then performs defense settings for the UPF 11a to which the target UE2 is connected (S53). Note that the PCF 11d may also perform defense settings directly for the UPF 11a without going through the SMF 11c, according to the set policy (S54). Subsequently, in Figure 9, the processing in S6 is executed as in Figure 5. Also, similar to S7-1 and S7-2, communication will be interrupted.
[0083] Next, the explanation continues with Figure 10. Here, as in Figure 6, processes S8 to S11 and S10A are executed, but their explanation is omitted. Also, these processes are omitted in Figure 10. In Figure 10, when the security linkage unit 11n is notified of the suspension of defense (S11, S10A in Figure 6), it requests PCF11d to release the policy for implementing the defense settings against the threat (S121). Then PCF11d releases the policy for implementing the defense settings. Then PCF11d requests SMF11c to stop the defense against the threat (S122). Then SMF11c stops the defense (S123). Note that PCF11d releases the policy for implementing the defense settings The shield may be released, and the defense may be stopped directly on the UPF11a without going through the SMF11c (S124). Subsequently, in Figure 10, the process in S13 is executed as in Figure 6.
[0084] In this embodiment as well, a format conversion process similar to the one described in Figure 7 of Embodiment 1 may be performed. That is, the FN11 of the communication system, such as the security linkage unit 11n, may convert threat information in a different format into a threat information format that can be processed by the NF11 of the communication system. Also, similar to the process described in Figure 8, the security linkage unit 11n may identify and select a defense process corresponding to the received threat information when it receives threat information in a different format.
[0085] (Effects of the second embodiment) As described above, the security linkage unit 11n requests the PCF 11d to set a policy for defense processing, and executes defense processing in the UPF 11a via the PCF 11d. The PCF 11d also sets the defense settings for the relevant UPF 11a either via the SMF 11c or directly without the SMF 11c. Therefore, the security linkage unit 11n can execute defense processing in response to threat information in a unified manner across the communication network.
[0086] Furthermore, the security linkage unit 11n performs processing when the format of the threat information differs from the format for which the FN11 of the communication system can perform defensive processing, similar to the processing in Figure 7 of Embodiment 1. That is, the security linkage unit 11n converts the format of the threat information into a format for which the FN11 can perform defensive processing. Also, similar to the processing in Figure 8 of Embodiment 1, the security linkage unit 11n identifies and selects the defensive processing to be executed in the UPF11a, security device 51, router 52, etc., in response to the threat information when the format of the threat information differs from the format for which the defensive processing can be executed. Furthermore, the security linkage unit 11n executes the identified defensive processing in the UPF11a, security device 51, router 52, etc. Therefore, this communication system can perform defensive processing based on threat information in various formats from outside the communication system.
[0087] <Third Embodiment> (Example of Processing) The communication system of Embodiment 3 will be described with reference to Figures 11 and 12. Embodiment 1 exemplifies a communication system in which defense processing is set based on threat information. Embodiment 2 exemplifies a process in which, in addition to the processing of Embodiment 1, the security linkage unit 11n requests the PCF 11d to set a policy for threat defense settings. Furthermore, it exemplifies a process in which the PCF 11d sets a threat defense setting in the UPF 11a either via the SMF 11c or directly without going through the SMF 11c, according to the policy for which it received the setting request.
[0088] In this embodiment, an example is given of a process that redirects traffic from attacker 90 to a honeypot built on MEC (Multi-access Edge Computing) based on threat intelligence. A honeypot is a computer built on the MEC infrastructure 55 that directs the traffic of an attacker 90 to it. Within the honeypot, an application that responds to the attacker 90's traffic runs. A system that provides MEC by applying virtualization technology to multiple computers, network equipment, etc., is called the MEC infrastructure 55.
[0089] Furthermore, the processing of this embodiment can be carried out independently of the processing of Embodiment 1 and Embodiment 2. Therefore, this communication system can freely select and carry out the processing of Embodiment 1, Embodiment 2, or Embodiment 3.
[0090] Figures 11 and 12 are sequence diagrams illustrating the reception of threat information and honeypot induction processing in this communication system. Figures 11 and 12 are shown in sections A2 through H2. The terminals are connected. In this process, first, information source AF12a notifies NEF11e of the request to initiate honeypot induction along with threat information (S21).
[0091] Then, NEF11e further notifies the security cooperation unit 11n of the threat information and the request to initiate honeypot induction (S22). In situations where the information source AF12a is trusted by the MNO of the communication system, the information source AF12a can directly notify the security cooperation unit 11n of the threat information and the request to initiate honeypot induction without going through NEF11e (S21A).
[0092] Next, the security collaboration unit 11n obtains information from the notified threat information and the request to initiate honeypot induction to identify the target UE2 that is targeted in the threat information. Then, the security collaboration unit 11n sends a message to the UDM 11j requesting that it search for the target UE2 or the UPF information to which the target UE2 is connected (S23).
[0093] The UDM11j then responds to the security linkage unit 11n with information about the target UE2, such as a unique identifier in 5GC or UPF information to which the target UE2 is connected (S24). Here, UPF information refers to an identifier that can uniquely identify any UPF within 5GC, such as an IP address or URI.
[0094] However, UDM11j may, in response to a search request (S3) from the security linkage unit 11n for information on target UE2s, obtain from the UDR, etc., whether or not honeypot induction processing can be performed or is necessary, and respond to the security linkage unit 11n (S24). The security linkage unit 11n only needs to perform honeypot induction processing for UE2s that are configured in the contract data to be able to perform honeypot induction processing or to be required to perform it.
[0095] When the security linkage unit 11n receives a response such as information about the target UE2 or information about the UPF to which the target UE2 is connected, it launches one or more honeypots in the MEC that can be accessed using the corresponding UPF 11a to which the target UE2 is connected as an anchor (S25). Furthermore, the honeypot is not limited to one anchored to the UPF11a to which the target UE2 is connected. In short, the security linkage unit 11n only needs to guide packets or traffic from attacker 90 to the honeypot via multiple layers of UPF11a. The honeypot to be launched is, for example, started by executing an application of a type corresponding to the threat information. Alternatively, the honeypot to be launched is launched with parameters corresponding to the threat information set in the application. The type or setting corresponding to the threat information means, for example, the protocol of the communication from attacker 90, the source domain, the destination IP address, the destination port number, the type of source application, and additional information that identifies the attacker. The MEC infrastructure 55 then returns a response to the security linkage unit 11n indicating that the honeypot has been launched (S26).
[0096] Here, the MEC base 55 is an example of an information processing environment connected to the outside of the communication system in DN5, which is connected to the anchor PSA UPF. Therefore, starting a honeypot is an example of creating a simulated receiving system that mimics the environment inside a communication device or a mobile vehicle equipped with a communication device. The environment inside a mobile vehicle refers, for example, to the honeypot running the OS, applications, etc., installed on the UE2 inside the mobile vehicle.
[0097] Then, the security linkage unit 11n configures the UPF 11a to which the target UE2 is connected to direct the traffic to the honeypot on the MEC infrastructure 55 (S27). Note that the redirection may also go through multiple UPF 11a stages. The security linkage unit 11n and the associated NF11 may perform the same procedures as those described in Embodiment 2. That is, the security linkage unit 11n may configure a policy for the PCF11d and a redirection request from the PCF11d to the SMF11c for the relevant UPF11a to redirect the traffic to the honeypot of the MEC infrastructure 55.
[0098] In this case, PCF11d may configure traffic to be directed directly to the relevant UPF11a without going through SMF11c, thereby directing the traffic to the honeypot on the MEC infrastructure 55.
[0099] The following is an example of the specific steps taken to redirect an attacker's traffic to a honeypot. For example, in section 6.3 Edge Relocation of 3GPP® TS 23.548 V18.3.0 (2023-09), Procedure for relocating the EAS (Edge Application Server) on DN5 that UE2 accesses. The procedure for relocating the PSA UPF to which the EAS is connected is also described. Section 6.3 above describes how this PSA UPF handles traffic related to applications using EAS. The documentation describes replacing the EAS's IP address and port number with those of the EAS. It also describes the request that AF12 make to the communication system (5GC) to simultaneously connect to both the source PSA and the target PSA during the EAS migration, and how this request is processed. Here, the source PSA refers to the PSA to which UE2 was connected before the EAS migration, and the target PSA refers to the PSA to which UE2 was connected after the EAS migration. These standards concern the process of replacing the EAS and PSA UPF that UE2 accesses. In this embodiment, the procedures of these standards are modified and applied to the procedures of the security cooperation unit 11n, which directs attack packets or traffic to the honeypot.
[0100] Furthermore, the specific procedure for luring attacker traffic to the honeypot involves applying the traditional NAT (Network Address Translation) procedure at the gateway on the network. This is possible. The procedure is illustrated as follows:
[0101] (1) The security linkage unit 11n associates a target destination address and target destination port number pair with a source destination address and source destination port number pair in the UPF 11a, either directly or via the PCF 11d and SMF 11c. The security linkage unit 11n then sets the source-target association in the address translation table for guidance. Here, the source destination address and source destination port number refer to the destination address and destination port number before address translation, and represent the destination of the packet or traffic by the attacker 90. The target destination address and target destination port number refer to the destination address and destination port number after address translation, and represent the destination address and destination port number to the honeypot.
[0102] (2) The security linkage unit 11n instructs the UPF 11a to perform address translation processing using the address translation table for guidance described in (1) above for source packets or traffic having the characteristics illustrated in Figure 2. The security linkage unit 11n instructs the UPF 11a to perform address translation processing either directly or via the PCF 11d and SMF 11c.
[0103] (3) From this point onward, UPF11a directs the attacker's packets to the honeypot. The session between UE2 and attacker 90 will terminate, for example, due to a timeout. As already mentioned, UPF11a may be configured in a multi-stage configuration between RAN3 and DN5. The above settings (1) and (2) can be applied to either PSA UPF or I UPF.
[0104] Next, the explanation continues with Figure 12. Here, the security linkage unit 11n attacks the above attack Redirecting attacker 90's packets or traffic to the MEC infrastructure 55 honeypot is an example of redirecting attacks from both inside and outside the communication network provided by the communication system to a simulated receiving system. Attacks from within the communication network are expected to originate from other UEs within the MNO to which UE2 is connected, or from a 5GC function hijacked by attacker 90. The attack content is expected to be the same as external attacks, such as DoS (Denial of Service Attack) / DDoS (Distributed Denial of Service Attack) or attacks exploiting various vulnerabilities. Here, DoS is a cyberattack that takes advantage of the congestion of server processing due to concentrated access and sends a large amount of data to information processing devices such as servers with malicious intent. DDoS, on the other hand, is the act of sending a large amount of packets from multiple computers to information processing devices such as servers, thereby disrupting the normal operation of those servers.
[0105] Similar to S27, the security linkage unit 11n may configure the external router 52, etc., to which the target UE2 is connected via DN5 and the PSA UPF to direct the relevant traffic to the honeypot on the MEC infrastructure 55 (S28). The external router 52, etc., may be one of the AF12s connected to the communication system. With this traffic redirection setting, at least in the router 52, etc., to which the target UE2 is connected and a connection has been established, the traffic from the attacker 90 does not reach the target UE2 but is received at the honeypot (S29).
[0106] Subsequently, once the threat from attacker 90 is eliminated, information source AF12a receives confirmation from an organization outside the communication system that the threat has been removed. Information source AF12a then notifies NEF11e to cease redirecting to the honeypot (S30). Furthermore, NEF11e requests the security coordination unit 11n to cease defense (S31). Note that if information source AF12a is trusted by the communication system's MNO, information source AF12a can directly notify the security coordination unit 11n to cease redirecting to the honeypot without going through NEF11e (S30A).
[0107] Then, when the security coordination unit 11n is notified that the defense has been stopped, it instructs the UPF 11a to stop redirecting to the honeypot. Here, stopping the settings includes, for example, clearing or deleting the address translation table used for redirection. The security coordination unit 11n also sends a message to the MEC infrastructure 55 requesting that the honeypot be stopped and various settings deleted (S32). Once the MEC infrastructure 55 has completed stopping the honeypot and deleting various settings, it notifies the security coordination unit 11n of this and responds (S33).
[0108] (Effects of Embodiment 3) As described above, due to the traffic redirection, at least the traffic from attacker 90 to target UE2 does not reach target UE2 but is received by the honeypot. Therefore, the communication system and NF11 of this embodiment can effectively defend against attacks from outside the communication system. Furthermore, the communication system and NF11 of this embodiment can buy time before further processing can be taken against attacks from outside the communication system.
[0109] <Effects of the First to Third Embodiments> Manufacturers, OEMs, and vendors that manufacture and sell UE2 or mobile devices equipped with UE2 will be able to defend against cyberattacks on their communication networks and mitigate the damage caused by attacks. For example, they will be able to buy time to prepare correction patches for the OS or applications. Meanwhile, mobile network operators (MNOs), which manage and provide the communication network to users, will be able to protect their users. In addition, MNOs will have a means of billing the aforementioned manufacturers, OEMs, vendors, and Over The Top (OTT) providers that provide media content to users, as well as vendors of OS or terminals.
[0110] <Other Embodiments> The embodiments described above are merely examples, and this disclosure may be modified as appropriate without departing from its essence. Furthermore, the processes and means described in this disclosure can be freely combined and implemented as long as no technical inconsistencies arise.
[0111] Furthermore, a process described as being performed by a single device may be divided and executed by multiple devices. Conversely, a process described as being performed by different devices may be executed by a single device. In a computer system, the hardware configuration (server configuration) by which each function is implemented can be flexibly changed.
[0112] The present disclosure can also be realized by supplying a computer program implementing the functions described in the embodiments above to a computer, and having one or more processors in the computer read and execute the program. Such a computer program may be provided to the computer by a non-temporary computer-readable storage medium that can be connected to the computer's system bus, or it may be provided to the computer via a network. The non-temporary computer-readable storage medium includes any type of disk, such as magnetic disks (floppy disks, hard disk drives (HDDs), etc.), optical disks (CD-ROMs, DVDs, Blu-ray discs, etc.), read-only memory (ROM), random access memory (RAM), EPROM, EEPROM, magnetic cards, flash memory, or optical cards, and any other type of medium suitable for storing electronic instructions. [Explanation of Symbols]
[0113] 2 UE 3 RAN 5 DN 11 FN 12 AF 12A Source AF 20 Information Processing Devices 40 devices 50 Source EAS 51 Security device 52 Routers
Claims
1. A communication system that provides a communication network to a communication device, A receiving process for receiving threat information from an organization outside the communication system regarding threats to the communication device using the communication network, The system includes a control device that performs a defense process to protect the communication device based on the received threat information, The aforementioned threat information includes information that identifies a specific communication device that is the target of an attack by the aforementioned threat. The control device executes the defense process on the specified communication device. The aforementioned specific communication device is a device installed in a vehicle, The information to be identified includes, as information to identify the vehicle, the manufacturer of the vehicle, the model of the vehicle, and the year of manufacture of the vehicle. The aforementioned communication network includes a 5G core network, The control device is a Network Exposure Function provided in the 5G core network. (NEF) is used to receive the threat information relating to the aforementioned threat, The control device is provided in the 5G core network as a Policy Control Function ( The defense process is executed in the User Plane Function (UPF) via the PCF. If the format of the threat information is different from the format in which the defense process can be executed, the control device performs the following actions to convert the format of the threat information, which includes at least information identifying the vehicle, into a format that can be processed by a plurality of Network Functions (NFs) provided in the 5G core network, which include at least the NEF and the PCF, in order to make it a format in which the defense process can be executed: Furthermore, a communication system that performs the defense processing corresponding to the converted threat information in the UPF.
2. The communication system according to claim 1, wherein the control device uniformly performs the defense process on the communication device connected to the communication system.
3. The communication system according to claim 1, wherein the control device performs the defense process on a router connected to the communication network or a security device connected to the communication network.
4. The communication system according to claim 3, wherein the control device performs the defense processing corresponding to the converted threat information in the router or the security device.
5. The device has a storage device that stores contract data based on a contract between the user of the communication device and the business operator that manages the communication system, The communication system according to claim 1, wherein the control device determines, among a plurality of communication devices, the communication device to which the defense processing is applied based on the contract data.
6. The communication system according to claim 1, wherein the control device creates a simulated receiving system that mimics the environment inside the communication device or a mobile vehicle equipped with the communication device in an information processing environment connected to the outside of the communication system, and directs attacks from inside or outside the communication network provided by the communication system to the simulated receiving system.
7. The communication system according to claim 1, wherein the control device is provided in the 5G core network.
8. The communication system according to claim 1, wherein the control device is provided as an Application Function (AF) connected to the 5G core network.
9. A control device for a communication system that provides a communication network to a communication device, A receiving process for receiving threat information from an organization outside the communication system regarding threats to the communication device using the communication network, Based on the received threat information, a defense process is performed to protect the communication device. The aforementioned threat information includes information that identifies a specific communication device that is the target of an attack by the aforementioned threat. The control device executes the defense process on the specified communication device. The aforementioned specific communication device is a device installed in a vehicle, The information to be identified includes, as information to identify the vehicle, the manufacturer of the vehicle, the model of the vehicle, and the year of manufacture of the vehicle. The aforementioned communication network includes a 5G core network, The control device is a Network Exposure Function provided in the 5G core network. (NEF) is used to receive the threat information relating to the aforementioned threat, The control device is provided in the 5G core network as a Policy Control Function ( The defense process is executed in the User Plane Function (UPF) via the PCF. If the format of the threat information is different from the format in which the defense process can be executed, the control device performs the following actions to convert the format of the threat information, which includes at least information identifying the vehicle, into a format that can be processed by a plurality of Network Functions (NFs) provided in the 5G core network, which include at least the NEF and the PCF, in order to make it a format in which the defense process can be executed: Furthermore, a control device that executes the defense process corresponding to the converted threat information in the UPF.
10. A communication method in a communication system that provides a communication network to a communication device, The control device of the aforementioned communication system A receiving process for receiving threat information from an organization outside the communication system regarding threats to the communication device using the communication network, Based on the received threat information, a defense process is performed to protect the communication device. The aforementioned threat information includes information that identifies a specific communication device that is the target of an attack by the aforementioned threat. The control device executes the defense process on the specified communication device, The aforementioned specific communication device is a device installed in a vehicle, The information to be identified includes, as information to identify the vehicle, the manufacturer of the vehicle, the model of the vehicle, and the year of manufacture of the vehicle. The aforementioned communication network includes a 5G core network, The control device is a Network Exposure Function provided in the 5G core network. (NEF) is used to receive the threat information relating to the aforementioned threat, The control device is provided with a Policy Control Function in the 5G core network. The defense process is executed in the User Plane Function (UPF) via the PCF. If the format of the threat information is different from the format in which the defense process can be executed, the control device performs the following actions to convert the format of the threat information, which includes at least information identifying the vehicle, into a format that can be processed by a plurality of Network Functions (NFs) provided in the 5G core network, which include at least the NEF and the PCF, in order to make it a format in which the defense process can be executed: Furthermore, the UPF executes the defense process corresponding to the converted threat information. Communication method.
11. The communication method according to claim 10, further comprising the control device creating a simulated receiving system that mimics the environment inside the communication device or a mobile vehicle equipped with the communication device in an information processing environment connected to the outside of the communication system, and directing attacks from inside or outside the communication network provided by the communication system to the simulated receiving system.
Citation Information
Patent Citations
Security management method, security management apparatus, and security management program
JP2006146297A
Management device and management method
JP2018005282A
Systems and methods for application-friendly protocol data unit (PDU) session management
JP2019536305A
Control device
JP2020025220A
Information processor, information processing method and program
JP2020064590A