Vehicle attack analysis device, attack analysis system, attack analysis method, and attack analysis program

JP7920799B2Active Publication Date: 2026-09-15DENSO CORP
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2022157431
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-09-30
Publication Date
2026-09-15
Estimated Expiration
2042-09-30

AI Technical Summary

Benefits of technology

【0009】 上述のような構成により、本開示の車両用攻撃分析装置等は、攻撃·異常関係情報の生成に必要な情報を収集し、攻撃·異常関係情報を効率的に生成することが可能となる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007920799000001
    Figure 0007920799000001
  • Figure 0007920799000002
    Figure 0007920799000002
  • Figure 0007920799000003
    Figure 0007920799000003
Patent Text Reader

Abstract

To collect information necessary for generating attack / anomaly related information for an electronic control system, to efficiently generate the attack / anomaly related information.SOLUTION: An attack analysis apparatus 11 for a vehicle includes: a storage unit 111 which stores vehicle configuration basic information which is information held by a vehicle out of information on the configuration of the vehicle; a receiving unit 112 which receives vehicle configuration additional information which is information not held by the vehicle; a vehicle configuration information classifying unit 115 which classifies vehicle configuration information comprising the vehicle configuration basic information and the vehicle configuration additional information into first and second vehicle configuration information; a transmission unit 113 which transmits the first vehicle configuration information to an external device; an attack / anomaly related information generation unit 116 which generates second attack / anomaly related information based on the second vehicle configuration information; an attack / anomaly related information combining unit 117 which combines the first and second attack / anomaly related information to generate attack / anomaly related information; and an attack estimation unit 118 which estimates an attack. The receiving unit also receives the first attack / anomaly related information generated in the external device.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to an apparatus for analyzing attacks on electronic control systems installed in vehicles including automobiles, and specifically relates to a vehicle attack analysis apparatus, an attack analysis system, an attack analysis method, and an attack analysis program. Background Art

[0002] In recent years, technologies for driving assistance and automatic driving control, including V2X such as vehicle-to-vehicle communication and road-to-vehicle communication, have attracted attention. Along with this trend, vehicles have come to be equipped with communication functions, and so-called connected vehicles have been increasingly developed. As a result, the possibility that vehicles may suffer cyberattacks such as unauthorized access has increased. Therefore, it is required to analyze cyberattacks on vehicles and develop countermeasures therefor.

[0003] There are various methods for detecting abnormalities occurring in a vehicle and analyzing cyberattacks based on the detected abnormalities. For example, Patent Document 1 describes that detected abnormality data is collected, a combination of items in which an abnormality is detected is compared with an abnormality detection pattern specified in advance for each attack, and the type of attack corresponding to the abnormality is specified. Prior Art Documents Patent Documents

[0004] Patent Document 1 Japanese Unexamined Patent Application Publication No. 2020-123307 Summary of the Invention Problem to be Solved by the Invention

[0005] Here, the inventor of the present invention has found the following problems. Existing attack identification methods, such as those described in Patent Document 1, compare detected anomaly data with anomaly detection patterns. However, anomaly detection patterns vary depending on the vehicle manufacturer, model, and year. Furthermore, even for the same model year, patterns can differ due to dealer options, destination differences, and even the results of ECU replacements or software updates. If these diverse anomaly detection patterns can be automatically generated and managed, it is expected that the man-hours required for generating and managing them can be dramatically reduced.

[0006] Therefore, the present invention aims to realize a vehicle attack analysis device, etc., that collects information necessary for generating attack-anomaly relationship information and efficiently generates attack-anomaly relationship information. [Means for solving the problem]

[0007] The vehicle attack analysis device (11) of this disclosure is a vehicle attack analysis device that analyzes attacks against electronic control systems installed in a vehicle, This includes information on the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A storage unit (111) that stores basic vehicle configuration information, which is information possessed by the vehicle, among the information relating to the configuration of the vehicle, A receiving unit (112) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A vehicle configuration information classification unit (115) classifies the vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information, A transmitting unit (113) transmits the first vehicle configuration information to an external device (31), Based on the above-mentioned second vehicle configuration information, The system calculates which security sensor of which electronic control unit will detect an anomaly in response to the anticipated attack. An attack / anomaly relationship information generation unit (116) generates a second attack / anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. Based on the above-mentioned first vehicle configuration information , calculate which security sensor of which electronic control unit will detect an anomaly in response to the anticipated attack.The receiving unit (112) receives the first attack / anomaly relationship information generated by the external device from the external device, An attack / anomaly relationship information combining unit (117) combines the first attack / anomaly relationship information and the second attack / anomaly relationship information to generate attack / anomaly relationship information, An attack estimation unit (118) estimates the attack the electronic control system has suffered using the aforementioned attack / anomaly relationship information, It is equipped with.

[0008] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]

[0009] With the configuration described above, the vehicle attack analysis device, etc. of this disclosure can collect information necessary for generating attack-anomaly relationship information and efficiently generate attack-anomaly relationship information. [Brief explanation of the drawing]

[0010] [Figure 1] This diagram illustrates the relationship between the vehicle attack analysis device, the electronic control system S, and other devices in each embodiment. [Figure 2] Explanatory diagram illustrating the configuration of the electronic control system in each embodiment. [Figure 3] Diagram illustrating the attack / anomaly relationship table for each embodiment. [Figure 4] Block diagram showing an example configuration of the vehicle attack analysis device 11 of Embodiment 1. [Figure 5] This diagram illustrates an example of operation 1 of the attack / anomaly relationship information coupling unit of the vehicle attack analysis device 11 of Embodiment 1. [Figure 6] This diagram illustrates an example of operation 2 of the attack / anomaly relationship information coupling unit of the vehicle attack analysis device 11 of Embodiment 1. [Figure 7] Block diagram showing an example configuration of the SOC server 31 in Embodiment 1. [Figure 8]Flow diagram illustrating the operation of the attack analysis system 1 according to Embodiment 1 [Figure 9] Block diagram showing a configuration example of the vehicle attack analysis apparatus 11 according to a modification of Embodiment 1 [Figure 10] Block diagram showing a configuration example of the SOC server 31 according to a modification of Embodiment 1 [Figure 11] Flow diagram illustrating the operation of the attack analysis system 1 according to a modification of Embodiment 1 [Figure 12] Block diagram showing a configuration example of the vehicle attack analysis apparatus 12 according to Embodiment 2 [Figure 13] Block diagram showing a configuration example of the SOC server 32 according to Embodiment 2 [Figure 14] Flow diagram illustrating the operation of the attack analysis system 2 according to Embodiment 2 [Figure 15] Block diagram showing a configuration example of the vehicle attack analysis apparatus 13 according to Embodiment 3 [Figure 16] Block diagram showing a configuration example of the SOC server 33 according to Embodiment 3 [Figure 17] Flow diagram illustrating the operation of the attack analysis system 3 according to Embodiment 3 [Mode for Carrying Out the Invention]

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0012] The present invention refers to the invention described in the claims or the section of means for solving the problem, and is not limited to the following embodiments. In addition, at least the terms in angle brackets mean the terms described in the claims or the section of means for solving the problem, and are also not limited to the following embodiments.

[0013] The configurations and methods described in the dependent claims are optional configurations and methods in the invention described in the independent claims. The configurations and methods in embodiments corresponding to the configurations and methods described in the dependent claims, as well as configurations and methods described only in embodiments and not in the claims, are optional configurations and methods in the present invention. The configurations and methods described in embodiments when the claims are broader than the descriptions in embodiments are also optional configurations and methods in the present invention, in the sense that they are illustrative examples of the configurations and methods of the present invention. In any case, by describing them in the independent claims, they become essential configurations and methods of the present invention.

[0014] The effects described in the embodiments are those that occur when the configuration is set up as an example of the present invention, and are not necessarily effects that the present invention possesses.

[0015] When there are multiple embodiments, the configuration disclosed in each embodiment is not confined to that embodiment alone, but can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Alternatively, the configuration disclosed in each of multiple embodiments may be combined.

[0016] The problems described in the section on the problems that the invention aims to solve are not publicly known problems, but rather problems that the inventors have discovered independently, and together with the structure and method of the present invention, these facts affirm the inventive step of the invention.

[0017] 1. Configurations that serve as the basis for each embodiment (1) Relationship between the vehicle attack analysis device, the electronic control system S, and other devices Figure 1 illustrates the relationship between the vehicle attack analysis device, the electronic control system S, and other devices in each embodiment. As shown in Figure 1, the vehicle attack analysis device 11(12, 13) and the electronic control system S in each embodiment are "mounted" in a "vehicle". Here, the vehicle attack analysis device 11(12, 13) is described as a separate device from the electronic control system S, but the vehicle attack analysis device 11(12, 13) may be considered as one of the devices included in the electronic control system S. Here, "Vehicles" include, but are not limited to, automobiles, motorcycles, and bicycles. "Being mounted" includes not only cases where something is directly fixed to the vehicle, but also cases where it is not fixed to the vehicle but moves with the vehicle. For example, this includes cases where it is carried by a person in the vehicle, or where it is mounted as cargo on the vehicle.

[0018] The vehicle attack analysis device 11 (12, 13) is a device for analyzing cyberattacks against the electronic control system S. Specifically, it is a device that analyzes cyberattacks by acquiring security logs generated by security sensors installed in multiple electronic control units (hereinafter referred to as ECUs (Electronic Control Units)) that constitute the electronic control system S.

[0019] Figure 2 shows an example of the configuration of an electronic control system S. The electronic control system S is composed of multiple ECUs 20. Figure 2 shows five ECUs (ECU20a to ECU20e) as an example, but naturally, the electronic control system S can be composed of any number of ECUs. In the following explanation, when describing the entire electronic control unit, one or more, we will refer to them as ECU20 or each ECU20, and when describing individual electronic control units, we will refer to them as ECU20a, ECU20b, ECU20c, ...

[0020] In the electronic control system S shown in Figure 2, security sensors are installed in ECU20a, ECU20c, ECU20d, and ECU20e. In contrast, ECU20b does not have a security sensor. Thus, it is sufficient for multiple ECU20s that make up the electronic control system S to have security sensors, and it is not necessarily required that all ECU20s have security sensors.

[0021] The electronic control system S can be composed of any ECUs. Examples include a drivetrain electronic control unit that controls the engine, steering wheel, brakes, etc., a vehicle system electronic control unit that controls meters, power windows, etc., an information system electronic control unit that controls navigation systems, etc., or a safety control system electronic control unit that controls collisions with obstacles or pedestrians. Furthermore, the ECUs may not be in parallel, but may be classified as master and slave units. In addition, the electronic control system S may be equipped with a mobility computer (MC) that has a gateway function to connect the electronic control units, or an external communication ECU that communicates with the outside world. For example, ECU 20a may be the external communication ECU and ECU 20c may be the MC. Furthermore, ECU20 may be a physically independent ECU, or it may be a virtually implemented virtual ECU (sometimes called a virtual machine).

[0022] In the cases of Figures 1 and 2, the vehicle attack analysis device 11 (12, 13) and each ECU 20 constituting the electronic control system S are connected via an in-vehicle communication network such as CAN (Controller Area Network) or LIN (Local Interconnect Network). Alternatively, they may be connected using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®. Connection refers to a state in which data can be exchanged, and includes not only cases where different hardware is connected via a wired or wireless communication network, but also cases where virtual machines implemented on the same hardware are virtually connected to each other.

[0023] The SOC (Security Operation Center) server 31 (32, 33) (corresponding to "external device") is a device that detects and analyzes cyberattacks outside the vehicle. For example, it receives security logs from the electronic control system S installed in the vehicle and analyzes cyberattacks. In terms of analyzing cyberattacks, it has the same function as the vehicle attack analysis device 11 (12, 13), but it can analyze security logs from multiple vehicles using abundant hardware resources, making it suitable for statistical analysis of complex and large volumes of data. However, since the SOC server 31 (32, 33) is located remotely from the vehicle, it is more appropriate to perform the analysis using the vehicle attack analysis device 11 (12, 13) installed in the vehicle in order to detect cyberattacks on individual vehicles in real time.

[0024] The OEM center server 40 is a device that manages and stores information on vehicles and parts manufactured and sold by, for example, a vehicle manufacturer or parts manufacturer. Details of the information will be described in Embodiment 1.

[0025] Vehicle attack analysis device 11 (12, 13) and electronic control system S, and SOC server 31 (32, 33) and the OEM center server 40 are connected via a communication network using wireless communication and / or wired communication methods. Examples of wireless communication methods include IEEE 802.11 (Wi-Fi®), IEEE 802.16 (WiMAX®), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, and 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. Examples of wired communication methods include LANs (Local Area Networks) such as Ethernet®, the Internet, fiber optic lines, and landline telephone lines. When a vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method.

[0026] In addition, the communication line may be a combination of a wireless communication line and a wired communication line. For example, the vehicle attack analysis device 11 (12, 13) and the base station equipment in the cellular system may be connected by a wireless communication method such as 4G, and the base station equipment and the SOC server 31 (32, 33) or OEM center server 40 may be connected by a wired communication method such as a backbone line of a telecommunications carrier or the internet. A gateway device may be provided at the point of contact between the backbone line and the internet. Furthermore, communication between the SOC server 31 (32, 33) and the OEM center server 40 can be conducted using any available line, including the internet.

[0027] In each embodiment, the vehicle attack analysis device 11 (12, 13) and the SOC server 31 (32, 33) are combined to form the attack analysis system 1 (2, 3).

[0028] (2) Attack / Anomaly Relationship Table Figure 3 illustrates the attack / anomaly relationship tables used in each embodiment. The attack / anomaly relationship table (corresponding to "attack / anomaly relationship information") is a table that shows the correspondence between attack information, which indicates the type of attack that the electronic control system S is expected to be subjected to; predicted anomaly information, which indicates anomalies that are expected to occur in the electronic control system S if it is attacked; and predicted anomaly location information, which indicates the location within the electronic control system S where the predicted anomaly occurs.

[0029] Figure 3 shows an example of an attack-anomaly relationship table. In the attack-anomaly relationship table shown in Figure 3, for each type of cyberattack (attack A to X), the anomalies that occur when the electronic control system S is subjected to a cyberattack (corresponding to predicted anomaly information) and the type of ECU in which the anomaly occurs (corresponding to predicted anomaly location information) are shown. When a cyberattack occurs, it is expected that multiple anomalies will occur in multiple ECUs. Therefore, it is preferable that the attack-anomaly relationship table shows the combination of multiple anomalies that occur when an attack occurs and the ECU in which the anomaly occurs. In the example shown in Figure 3, in addition to the type of cyberattack (attack A to X), the attack information also includes the expected starting location of the attack and the target location of the attack when the cyberattack occurs.

[0030] For example, if a cyberattack of type A occurs, it is predicted that the external communication ECU in the electronic control system S will experience abnormalities A, C, and D. Furthermore, the origin of attack A is outside the electronic control system S, and the target of the attack is the external communication ECU. The origin of the attack can be either inside or outside the electronic control system S. An origin of attack outside the electronic control system S means that the cyberattack is coming from outside the vehicle.

[0031] The attack / anomaly relationship table in Figure 3 is in a table format, but any database format will work. The name of the attack / anomaly relationship table is also arbitrary. For example, it may also be called a pattern matching table (PMT) or anomaly detection pattern.

[0032] The attack / anomaly relationship table can create and generate anomaly occurrence patterns by simulating which security sensors in which ECUs will detect anomalies in what order in the event of a given attack, based on the arrangement of ECUs constituting the electronic control system S, the connection relationships of the ECUs (also called network topology), and the arrangement of security sensors installed in the ECUs. Furthermore, it may also be based on information regarding the targets monitored by the security sensors and their rules. However, the creation and generation of attack / anomaly relationship tables are not limited to this method. For example, AI or machine learning may be used. Alternatively, the tables may be generated using anomaly occurrence patterns from security sensors in past attacks.

[0033] Furthermore, the arrangement of the ECUs constituting the electronic control system S, the connection relationships between the ECUs, and the arrangement of security sensors installed in the ECUs can be linked to information about the vehicle's configuration. Therefore, by using a database in which these are linked, if information about the vehicle's configuration can be obtained, it is possible to create patterns of abnormal occurrences through the arrangement and connection relationships of the ECUs, etc.

[0034] 2. Embodiment 1 (1) Configuration of the vehicle attack analysis device 11 Figure 4 is a block diagram showing the configuration of the vehicle attack analysis device 11 in this embodiment. The vehicle attack analysis device 11 comprises a storage unit 111, a receiving unit 112, a transmitting unit 113, and a control unit 114. The control unit 114 implements a vehicle configuration information classification unit 115, an attack / anomaly relationship information generation unit 116, an attack / anomaly relationship information merging unit 117, and an attack estimation unit 118.

[0035] The memory unit 111 stores basic vehicle configuration information, which is information possessed by vehicles equipped with the vehicle attack analysis device 11, among the information related to "vehicle configuration". Here, "vehicle configuration" includes not only the configuration related to the entire vehicle, but also the configuration related to the equipment and components installed in the vehicle. Furthermore, it includes not only tangible objects, but also intangible objects such as programs and networks.

[0036] The following are examples of basic vehicle configuration information. Information related to the vehicle as a whole includes the make, model, year of manufacture, and destination. Information related to the electronic control system S installed in the vehicle includes the type and version of hardware such as the ECU, the type and version of installed software (including middleware), and the type and version of security sensors. Other information includes the network topology and the placement and specifications of security sensors.

[0037] Furthermore, the vehicle configuration basic information may include a firing rule indicating which security sensor among the security sensors mounted on each ECU that constitutes the electronic control system S will detect an anomaly in response to a given attack. Alternatively, the vehicle configuration basic information may include information indicating the type of attack and the attack path. If this information is available, an attack-anomaly relationship table can be generated without performing a simulation.

[0038] The basic vehicle configuration information is stored in the storage unit 111 at various times, including when the vehicle is shipped, when dealer options are installed, when parts are repaired or replaced, and when software updates are performed. When the vehicle is shipped, information indicating the original configuration the vehicle had at the time of shipment is stored. Subsequently, when another configuration is added to the original configuration, or when the original configuration is changed to another configuration, information regarding the added or changed configuration is stored. In other words, the basic vehicle configuration information reflects information from the time the vehicle was shipped up to the present.

[0039] The storage unit 111 may be a non-volatile memory such as ROM, flash memory, or hard disk (HDD), or a volatile memory such as DRAM or SRAM. The basic vehicle configuration information stored in the non-volatile memory may be read and expanded into the volatile memory, in which case both correspond to the storage unit 111 of this embodiment.

[0040] The receiving unit 112 receives additional vehicle configuration information, which is information that is not present in vehicles equipped with the vehicle attack analysis device 11, among the information related to "vehicle configuration".

[0041] The source of the vehicle configuration information can be any device, but it is desirable that it be a reliable device. For example, the receiving unit 112 receives the vehicle configuration information from a device authenticated using device authentication or from a device that has been authenticated. Instead of device authentication, message authentication or the like may be used for each piece of information received. Examples of such source servers include the SOC server 31 and the OEM center server 40.

[0042] Examples of additional vehicle configuration information are the same as those given for basic vehicle configuration information. If the information listed as basic vehicle configuration information, such as the type and version of hardware or the type and version of installed software, is not stored in the storage unit 111 as basic vehicle configuration information, a request for this information is sent to the SOC server 31 or the OEM center server 40, and the information sent from them is received as additional vehicle configuration information. The received additional vehicle configuration information may also be stored in the storage unit 111.

[0043] Other examples of additional vehicle configuration information include information on software updated or modified by the manufacturer after the vehicle has been shipped, and information on the type, version, or connection destination of equipment or hardware added by the manufacturer after the vehicle has been shipped.

[0044] Whether certain vehicle configuration information is stored in the vehicle's memory unit 111 as basic vehicle configuration information, or whether it is not stored in the vehicle's memory unit 111 as basic vehicle configuration information but is received from the OEM center server 40 or the like as additional vehicle configuration information, can be determined by the vehicle manufacturer based on their own rules. For example, information that would cause significant damage if leaked, or information that the vehicle manufacturer wishes to keep confidential, may be centrally managed by the OEM center server 40 or the like. Furthermore, information regarding the "vehicle configuration" will be referred to as vehicle configuration information. Vehicle configuration information includes both basic vehicle configuration information and additional vehicle configuration information.

[0045] Although the receiving unit 112 is shown as a single block in Figure 4, it may be configured as multiple receiving units to correspond to the available communication methods.

[0046] In addition to the vehicle configuration information, the receiving unit 112 also receives the first attack / anomaly relationship table from an external device, which will be explained later.

[0047] The vehicle configuration information classification unit 115 classifies the vehicle configuration information, which consists of basic vehicle configuration information and additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information. The first vehicle configuration information is the vehicle configuration information to be transmitted to the SOC server 31 and is used by the SOC server 31 to generate the attack / anomaly relationship table described later. The second vehicle configuration information is not transmitted to the SOC server 31 and is used by the vehicle itself to generate the attack / anomaly relationship table described later. Vehicle configuration information is also called a vehicle profile.

[0048] There are various criteria for classifying vehicle configuration information into either the first or second category. For example, if the information security level of the vehicle configuration information is lower than a predetermined level, it is classified as the first category; if the information security level is higher than a predetermined level, it is classified as the second category. By processing information with a high security level within the vehicle rather than transmitting it to other devices via communication equipment, damage in the event of an information leak can be minimized. Here, "A predetermined level" means that the level may be constant, or it may vary depending on the conditions. "More than" may include cases where the security level of the information is the same as a given level, or it may not include cases where it is the same. The former is written as "≧" or [≦] in arithmetic symbols, and the latter as ">" or [<].

[0049] In addition, vehicle configuration information requiring a large amount of computation to generate the attack / anomaly relationship table may be classified as first vehicle configuration information, and vehicle configuration information requiring a small amount of computation to generate the attack / anomaly relationship table may be classified as second vehicle configuration information. By processing the vehicle configuration information requiring more computation on the SOC server 31, the use of internal vehicle resources can be minimized, and the attack / anomaly relationship table can be generated more quickly. Alternatively, information not related to privacy may be classified into the first vehicle configuration information, and information related to privacy may be classified into the second vehicle configuration information. Information that cannot be transmitted to external devices due to legal or contractual reasons may also be classified into the second vehicle configuration information. In addition, information on software updated or modified by the manufacturer after the vehicle's shipment, and information on the type, version, or connection destination of equipment or hardware added by the manufacturer after the vehicle's shipment, are assumed to contain information necessary for the SOC server 31 to generate the attack / anomaly relationship table, and may therefore be classified as the first vehicle information.

[0050] Furthermore, some of the vehicle configuration information may not be included in either the first or second vehicle configuration information. Furthermore, such information may be classified as a second type of vehicle configuration information. In this case, the second type of vehicle configuration information is the remainder of the vehicle configuration information after excluding the first type of vehicle configuration information.

[0051] The transmission unit 113 transmits the first vehicle configuration information to the SOC server 31 (corresponding to the "external device"). In this embodiment, the SOC server 31 is given as an example of an external device, but other devices may be used. Although the transmitter 113 is shown as a single block in Figure 4, it may be configured as multiple transmitters to correspond to the available communication methods.

[0052] The attack / anomaly relationship information generation unit 116 generates a second attack / anomaly relationship table (corresponding to "second attack / anomaly relationship information") which shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when the system is attacked, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs, based on the second vehicle configuration information. The contents and generation method of the attack / anomaly relationship table are as described in 1.(2). Here, "based on" includes not only cases where it is based on all of the second vehicle configuration information, but also cases where it is based on at least a part of it.

[0053] In response to this, the SOC server 31 generates a first attack / anomaly relationship table (corresponding to the "first attack / anomaly relationship information") "based on" the first vehicle configuration information transmitted from the transmission unit 113. The receiving unit 112 then receives the first attack / anomaly relationship table from the SOC server 31. Here, "based on" includes not only cases based on all of the first vehicle configuration information, but also cases based on at least a part of it.

[0054] The first attack / anomaly relationship table may be generated based on the first vehicle configuration information transmitted from the transmission unit 113, as well as third vehicle configuration information that is not possessed by vehicles equipped with the electronic control system S but is possessed by the SOC server 31. In other words, the first attack / anomaly relationship table may include a table generated based on the third vehicle configuration information, in addition to a table generated based on the first vehicle configuration information. Furthermore, the first attack-anomaly relationship table may include tables generated based on information other than the vehicle configuration information held by the SOC server 31. For example, anomaly occurrence patterns statistically determined based on security logs received from multiple vehicles may be included in the first attack-anomaly relationship table.

[0055] The attack / anomaly relationship information merging unit 117 merges the first attack / anomaly relationship table received from the SOC server 31 by the receiving unit 112 with the second attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 116 to generate an attack / anomaly relationship table (corresponding to "attack / anomaly relationship information"). The generated attack / anomaly relationship table may be stored in the storage unit 111.

[0056] Figures 5 and 6 illustrate how the first attack / anomaly relationship table and the second attack / anomaly relationship table are joined to generate the attack / anomaly relationship table.

[0057] In Figure 5, part (a) is the second attack / anomaly relationship table, and part (b) is the first attack / anomaly relationship table. (a) and (b) are joined to form the attack / anomaly relationship table. For example, the portion of the attack / anomaly relationship table that the vehicle had by default when it was shipped may be generated by the vehicle through means such as duplication, and the portion that needs to be generated using newly added vehicle configuration information after the vehicle has been shipped may be the first attack / anomaly relationship table. The first attack / anomaly relationship table may include anomaly occurrence patterns statistically determined by the SOC server 31.

[0058] This allows the generation of the attack / anomaly relationship table to be distributed among multiple devices. For example, the newly generated portion of the attack / anomaly relationship table is generated by the SOC server 31, which has abundant hardware resources, while the portion that was already present by default is generated by the vehicle, which has a lighter processing load. As a result, the attack / anomaly relationship table can be generated efficiently.

[0059] In Figure 6, part (a) is the second attack / anomaly relationship table, and part (b) is the first attack / anomaly relationship table. (a) and (b) are joined to form the attack / anomaly relationship table. In other words, the difference is that in Figure 5 the tables are separated by rows, while in Figure 6 they are separated by columns. For example, the vehicle may generate a second attack / anomaly relationship table related to ECUs specific to the vehicle, such as dealer options, and the SOC server 31 may generate a first attack / anomaly relationship table related to highly confidential ECUs containing proprietary information from the vehicle manufacturer.

[0060] This allows the SOC server 31 to centrally generate tables based on highly confidential information, thereby reducing the risk of information leakage.

[0061] The attack estimation unit 118 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated by the attack / anomaly relationship information merging unit 117. Specifically, the attack estimation unit 118 compares the anomaly occurrence patterns shown in the security logs generated by the security sensors of each ECU of the electronic control system S with those in the attack / anomaly relationship table. If the matching degree is above a predetermined percentage, it estimates that an attack identified by the attack information in the attack / anomaly relationship table has occurred.

[0062] Furthermore, the attack / anomaly relationship table may be used not only by the vehicle attack analysis device 11 but also by the SOC server 31. To this end, the transmission unit 113 may transmit the attack / anomaly relationship table generated by the attack / anomaly relationship information merging unit 117 to the SOC server 31.

[0063] (2) Configuration of SOC Server 31 Figure 7 is a block diagram showing the configuration of the SOC server 31 in this embodiment. The SOC server 31 comprises a storage unit 311, a receiving unit 312, a transmitting unit 313, and a control unit 314. The control unit 314 also implements an attack / anomaly relationship information generation unit 316 and an attack estimation unit 318.

[0064] The receiving unit 312 receives the first vehicle configuration information transmitted from the vehicle attack analysis device 11.

[0065] The attack / anomaly relationship information generation unit 316 generates a first attack / anomaly relationship table based on the first vehicle configuration information received by the receiving unit 312. The configuration and functions of the attack / anomaly relationship information generation unit 316 are the same as those of the attack / anomaly relationship information generation unit 116, so the description of the attack / anomaly relationship information generation unit 116 will be referenced.

[0066] The transmission unit 313 transmits the first attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 316 to the vehicle attack analysis device 11.

[0067] The receiving unit 312 receives the attack / anomaly relationship table transmitted from the vehicle attack analysis device 11, stores it in the storage unit 311, and may also use it for attack estimation in the attack estimation unit 318. The configuration and functions of the attack estimation unit 318 are basically the same as those of the attack estimation unit 118, so the description of the attack estimation unit 118 will be referenced.

[0068] (3) Configuration of Attack Analysis System 1 As explained in Figure 1, the vehicle attack analysis device 11 shown in Figure 4 and the SOC server 31 shown in Figure 7 are combined to form the attack analysis system 1. The same applies to the following modified examples and other embodiments.

[0069] (4) Operation of Attack Analysis System 1 Next, the operation of the attack analysis system 1 will be explained with reference to Figure 8. Figure 8 not only shows the attack analysis method performed by the attack analysis system 1, but also shows the operation of the vehicle attack analysis device 11 and the SOC server 31, which constitute the attack analysis system 1, as well as the processing procedure of the attack analysis program that can be executed by the vehicle attack analysis device 11 and the SOC server 31, respectively. Furthermore, these processes are not limited to the order shown in Figure 8. That is, the order may be changed unless there is a constraint such as a relationship where a step utilizes the result of a preceding step. The same applies to the flowcharts of modified examples and other embodiments below.

[0070] The storage unit 111 of the vehicle attack analysis device 11 stores basic vehicle configuration information, which is information possessed by the vehicle on which the vehicle attack analysis device 11 is installed, among the information related to the vehicle's configuration (S111). The receiving unit 112 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in the vehicle equipped with the vehicle attack analysis device 11 (S112). The vehicle configuration information classification unit 115 classifies the vehicle configuration information, which consists of basic vehicle configuration information and additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information (S113). The transmitting unit 113 transmits the first vehicle configuration information classified in S113 to the SOC server 31 (S114). The attack / anomaly relationship information generation unit 116 generates a second attack / anomaly relationship table (S115) that shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs, based on the second vehicle configuration information classified in S113.

[0071] The receiving unit 312 of the SOC server 31 receives the first vehicle configuration information transmitted from the vehicle attack analysis device 11 in S114 (S311). The attack / anomaly relationship information generation unit 316 generates a first attack / anomaly relationship table based on the first vehicle configuration information received in S311 (S312). The transmitting unit 313 transmits the first attack / anomaly relationship table generated in S312 to the vehicle attack analysis device 11 (S313).

[0072] The receiving unit 112 of the vehicle attack analysis device 11 receives the first attack / anomaly relationship table transmitted from the SOC server 31 in S313 (S116). The attack / anomaly relationship information merging unit 117 merges the first attack / anomaly relationship table received in S116 with the second attack / anomaly relationship table generated in S115 to generate an attack / anomaly relationship table (S117). The transmission unit 113 sends the attack / anomaly relationship table generated in S117 to the SOC server 31 (S118). The attack estimation unit 118 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated in S117 (S119).

[0073] The receiving unit 312 of the SOC server 31 receives the attack / anomaly relationship table transmitted from the vehicle attack analysis device 11 in S117 (S314). The attack estimation unit 318 estimates the attack on the electronic control system S using the attack / anomaly relationship table received in S314 (S315).

[0074] (5) Summary As described above, according to this embodiment, an attack / anomaly relationship table is generated by receiving additional vehicle configuration information that the vehicle does not possess. Since the vehicle only needs to acquire the additional vehicle configuration information when generating the attack / anomaly relationship table, the risk of additional vehicle configuration information leaking from individual vehicles can be reduced compared to when the vehicle possesses the additional vehicle configuration information from the time of shipment. In other words, additional vehicle configuration information can be centrally managed by the SOC server 31 or the OEM center server 40, and the risk of additional vehicle configuration information leaking can be reduced. Furthermore, according to this embodiment, vehicle configuration information is distributed to the vehicle attack analysis device and the SOC server 31, and parts of the attack / anomaly relationship table are generated in each, so the attack / anomaly relationship table can be generated efficiently.

[0075] 2. Modified Examples of Embodiment 1 Embodiment 1 generates an attack / anomaly relationship table by combining a first attack / anomaly relationship table and a second attack / anomaly relationship table using a vehicle attack analysis device 11. In this modified example, the first attack / anomaly relationship table and the second attack / anomaly relationship table are joined by the SOC server 31 to generate an attack / anomaly relationship table.

[0076] (1) Configuration of the vehicle attack analysis device 11 Figure 9 is a block diagram showing the configuration of the vehicle attack analysis device 11 in this modified example. The vehicle attack analysis device 11 comprises a storage unit 111, a receiving unit 112, a transmitting unit 113, and a control unit 114. The control unit 114 implements a vehicle configuration information classification unit 115, an attack / anomaly relationship information generation unit 116, and an attack estimation unit 118. In this modified example of the vehicle attack analysis device 11, the attack / anomaly relationship information coupling unit 117 in Embodiment 1 is not included. In the following description, only the unique configurations and functions of this modified example will be explained. Configurations and functions common to Embodiment 1 will be omitted and referred to in the explanation in Figure 4.

[0077] The transmission unit 113 transmits the second attack / anomaly relationship table, generated by the attack / anomaly relationship information generation unit 116, in addition to the first vehicle configuration information, to the SOC server 31. The timing of the transmission may be simultaneous with the transmission of the first vehicle configuration information, or it may not be simultaneous.

[0078] The receiving unit 112 receives from the SOC server 31 an attack / anomaly relationship table generated by the SOC server 31 by combining the first attack / anomaly relationship table generated by the SOC server 31 based on the first vehicle configuration information and the second attack / anomaly relationship table transmitted from the transmitting unit 113.

[0079] The attack estimation unit 118 estimates the attack on the electronic control system S using the attack / anomaly relationship table received by the receiving unit 112.

[0080] (2) Configuration of SOC Server 31 Figure 10 is a block diagram showing the configuration of the SOC server 31 in this modified example. The SOC server 31 comprises a storage unit 311, a receiving unit 312, a transmitting unit 313, and a control unit 314. The control unit 314 also implements an attack / anomaly relationship information generation unit 316, an attack / anomaly relationship information merging unit 317, and an attack estimation unit 318. In addition to the configuration of the SOC server 31 of Embodiment 1, the SOC server 31 of this modified example includes an attack / anomaly relationship information merging unit 317. In the following description, only the unique configuration and function of this modified example will be explained. Configurations and functions common to Embodiment 1 will be omitted and referred to in the explanation of Figure 7.

[0081] The receiving unit 312 receives the second attack / anomaly relationship table from the vehicle attack analysis device 11, in addition to the first vehicle configuration information. The timing of reception may be simultaneous with the reception of the first vehicle configuration information, or it may not be simultaneous.

[0082] The attack / anomaly relationship information generation unit 316 generates a first attack / anomaly relationship table based on the first vehicle configuration information received by the receiving unit 312.

[0083] The attack / anomaly relationship information merging unit 317 merges the second attack / anomaly relationship table received by the receiving unit 312 with the first attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 316 to generate an attack / anomaly relationship table.

[0084] The transmission unit 313 transmits the first attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 316 to the vehicle attack analysis device 11.

[0085] (3) Operation of Attack Analysis System 1 Next, the operation of the attack analysis system 1 will be described with reference to Figure 11. The same steps as in Embodiment 1 are assigned the same step numbers.

[0086] The storage unit 111 of the vehicle attack analysis device 11 stores basic vehicle configuration information, which is information possessed by the vehicle on which the vehicle attack analysis device 11 is installed, among the information related to the vehicle's configuration (S111). The receiving unit 112 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in the vehicle equipped with the vehicle attack analysis device 11 (S112). The vehicle configuration information classification unit 115 classifies the vehicle configuration information, which consists of basic vehicle configuration information and additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information (S113). The transmitting unit 113 transmits the first vehicle configuration information classified in S113 to the SOC server 31 (S114). The attack / anomaly relationship information generation unit 116 generates a second attack / anomaly relationship table (S115) that shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs, based on the second vehicle configuration information classified in S113. The transmitting unit 113 sends the second attack / anomaly relationship table generated in S115 to the SOC server 31 (S151).

[0087] The receiving unit 312 of the SOC server 31 receives the first vehicle configuration information transmitted in S114 from the vehicle attack analysis device 11 (S311). The attack / anomaly relationship information generation unit 316 generates a first attack / anomaly relationship table based on the first vehicle configuration information received in S311 (S312). The receiving unit 312 receives the second attack / anomaly relationship table transmitted in S151 from the vehicle attack analysis device 11 (S351). The attack / anomaly relationship information merging unit 317 merges the first attack / anomaly relationship table generated in S312 with the second attack / anomaly relationship table received in S351 to generate an attack / anomaly relationship table (S352). The transmitting unit 313 transmits the attack / anomaly relationship table generated in S352 to the vehicle attack analysis device 11 (S353). The attack estimation unit 318 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated in S352 (S315).

[0088] The receiving unit 112 of the vehicle attack analysis device 11 receives the attack / anomaly relationship table transmitted from the SOC server 31 in S353 (S152). The attack estimation unit 118 estimates the attack on the electronic control system S using the attack / anomaly relationship table received in S152 (S119).

[0089] (4) Summary As described above, according to this embodiment, an attack / anomaly relationship table is generated by receiving additional vehicle configuration information that the vehicle does not possess. Since the vehicle only needs to acquire the additional vehicle configuration information when generating the attack / anomaly relationship table, the risk of additional vehicle configuration information leaking from individual vehicles can be reduced compared to when the vehicle possesses the additional vehicle configuration information from the time of shipment. In other words, additional vehicle configuration information can be centrally managed by the SOC server 31 or the OEM center server 40, and the risk of additional vehicle configuration information leaking can be reduced. Furthermore, according to this embodiment, vehicle configuration information is distributed to the vehicle attack analysis device and the SOC server 31, and parts of the attack / anomaly relationship table are generated in each, so the attack / anomaly relationship table can be generated efficiently.

[0090] 3. Embodiment 2 In Embodiment 1 and its modified form, the vehicle attack analysis device 11 and the SOC server 31 jointly generate an attack / anomaly relationship table. In this embodiment, the vehicle attack analysis device 12 generates the attack / anomaly relationship table independently.

[0091] (1) Configuration of the vehicle attack analysis device 12 Figure 12 is a block diagram showing the configuration of the vehicle attack analysis device 12 in this embodiment. The vehicle attack analysis device 12 comprises a storage unit 121, a receiving unit 122, a transmitting unit 123, and a control unit 124. The control unit 124 also implements an attack / anomaly relationship information generation unit 126 and an attack estimation unit 128. Hereinafter, only the unique configurations and functions of this embodiment will be described, and configurations and functions common to Embodiment 1 will be omitted from the description, with reference to the description in Figure 4. In Figure 12, the blocks corresponding to Figure 4 have the same last two digits as in Figure 4, so following this rule, Figure 4 and its corresponding description will be referenced with the same interpretation as the description in Figure 12.

[0092] The memory unit 121 stores basic vehicle configuration information, which is information possessed by vehicles equipped with the vehicle attack analysis device 12, among the information related to the vehicle's configuration.

[0093] The receiving unit 122 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in vehicles equipped with the vehicle attack analysis device 12.

[0094] The attack / anomaly relationship information generation unit 126 generates an attack / anomaly relationship table (corresponding to "attack / anomaly relationship information") that shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when an attack occurs, and predicted anomaly location information indicating the location within the electronic control system S where the predicted anomaly occurs, based on the vehicle configuration basic information and vehicle configuration additional information. The contents and generation method of the attack / anomaly relationship table are as described in 1.(2).

[0095] The transmission unit 123 sends the attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 126 to the SOC server 32.

[0096] The attack estimation unit 128 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 126.

[0097] (2) Configuration of SOC Server 32 Figure 13 is a block diagram showing the configuration of the SOC server 32 in this embodiment. The SOC server 32 comprises a storage unit 321, a receiving unit 322, a transmitting unit 323, and a control unit 324. The control unit 324 also implements an attack estimation unit 328. Hereinafter, only the unique configurations and functions of this embodiment will be described, and configurations and functions common to Embodiment 1 will be omitted from the description, with reference to the explanation in Figure 7. In Figure 13, the blocks corresponding to Figure 7 have the same last two digits as the numbers in Figure 7, so according to this rule, Figure 7 and its corresponding explanation will be referenced with the same interpretation as the explanation in Figure 13.

[0098] The receiving unit 322 receives the attack / anomaly relationship table transmitted from the vehicle attack analysis device 12.

[0099] The attack estimation unit 328 estimates the attack on the electronic control system S using the attack / anomaly relationship table received by the receiving unit 322.

[0100] (3) Operation of Attack Analysis System 2 Next, the operation of the attack analysis system 2 will be explained with reference to Figure 14.

[0101] The storage unit 121 of the vehicle attack analysis device 12 stores basic vehicle configuration information, which is information about the vehicle configuration that the vehicle equipped with the vehicle attack analysis device 12 possesses (S121). The receiving unit 122 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in the vehicle equipped with the vehicle attack analysis device 12 (S122). The attack / anomaly relationship information generation unit 126 generates an attack / anomaly relationship table (S123) that shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when the system is attacked, and predicted anomaly location information indicating the location within the electronic control system S where the predicted anomaly occurs, based on the basic vehicle configuration information stored in S121 and the additional vehicle configuration information received in S122. The transmission unit 123 sends the attack / anomaly relationship table generated in S123 to the SOC server 32. The attack estimation unit 128 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated in S123 (S125).

[0102] The receiving unit 322 of the SOC server 32 receives the attack / anomaly relationship table transmitted from the vehicle attack analysis device 12 in S124 (S321). The attack estimation unit 328 estimates the attack on the electronic control system S using the attack / anomaly relationship table received in S321 (S322).

[0103] (4) Summary As described above, according to this embodiment, an attack / anomaly relationship table is generated by receiving additional vehicle configuration information that the vehicle does not possess. Since the vehicle only needs to acquire the additional vehicle configuration information when generating the attack / anomaly relationship table, the risk of additional vehicle configuration information leaking from individual vehicles can be reduced compared to when the vehicle possesses the additional vehicle configuration information from the time of shipment. In other words, additional vehicle configuration information can be centrally managed by the SOC server 32 or the OEM center server 40, and the risk of additional vehicle configuration information leaking can be reduced. Furthermore, according to this embodiment, since the vehicle attack analysis device 12 generates the attack / anomaly relationship table, the generation of the attack / anomaly relationship table can be completed independently.

[0104] 4. Embodiment 3 In Embodiment 2, the vehicle attack analysis device 12 generated the attack / anomaly relationship table independently. In this embodiment, the SOC server 33 generates the attack / anomaly relationship table independently.

[0105] (1) Configuration of the vehicle attack analysis device 13 Figure 15 is a block diagram showing the configuration of the vehicle attack analysis device 13 in this embodiment. The vehicle attack analysis device 13 comprises a storage unit 131, a receiving unit 132, a transmitting unit 133, and a control unit 134. The control unit 134 also implements an attack estimation unit 138. Hereinafter, only the unique configurations and functions of this embodiment will be described, and configurations and functions common to Embodiment 1 will be omitted from the description, with reference to the description in Figure 4. In Figure 15, the blocks corresponding to Figure 4 have the same last two digits as the numbers in Figure 4, so in accordance with this rule, Figure 4 and its corresponding description will be referenced as the description in Figure 15.

[0106] The memory unit 131 stores basic vehicle configuration information, which is information possessed by vehicles equipped with the vehicle attack analysis device 13, among the information related to the vehicle's configuration.

[0107] The receiving unit 132 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in vehicles equipped with the vehicle attack analysis device 13.

[0108] The transmission unit 133 transmits basic vehicle configuration information and additional vehicle configuration information to the SOC server 33.

[0109] The receiving unit 132 receives the attack / anomaly relationship table generated by the SOC server 33 based on the vehicle configuration basic information and vehicle configuration additional information from the SOC server 33.

[0110] The attack estimation unit 138 estimates the attack on the electronic control system S using the attack / anomaly relationship table received by the receiving unit 132.

[0111] (2) Configuration of SOC Server 33 Figure 16 is a block diagram showing the configuration of the SOC server 33 in this embodiment. The SOC server 33 comprises a storage unit 331, a receiving unit 332, a transmitting unit 333, and a control unit 334. The control unit 334 also implements an attack / anomaly relationship information generation unit 336 and an attack estimation unit 328. Hereinafter, only the unique configurations and functions of this embodiment will be described, and configurations and functions common to Embodiment 1 will be omitted from the description, with reference to the explanation in Figure 7. In Figure 16, the blocks corresponding to Figure 7 have the same last two digits as the numbers in Figure 7, so in accordance with this rule, Figure 7 and its corresponding explanation will be referenced with the same interpretation as the explanation in Figure 16.

[0112] The receiving unit 332 receives basic vehicle configuration information and additional vehicle configuration information transmitted from the vehicle attack analysis device 13.

[0113] The attack / anomaly relationship information generation unit 336 generates an attack / anomaly relationship table based on the vehicle configuration basic information and vehicle configuration additional information, which shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when an attack occurs, and predicted anomaly location information indicating the location within the electronic control system S where the predicted anomaly occurs. The contents and generation method of the attack / anomaly relationship table are as described in 1.(2).

[0114] The transmission unit 333 transmits the attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 336 to the vehicle attack analysis device 13.

[0115] The attack estimation unit 338 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated by the attack / anomaly relationship information generation unit 336.

[0116] (3) Operation of Attack Analysis System 2 Next, the operation of the attack analysis system 2 will be explained with reference to Figure 17.

[0117] The storage unit 131 of the vehicle attack analysis device 13 stores basic vehicle configuration information, which is information possessed by the vehicle on which the vehicle attack analysis device 13 is installed, among the information related to the vehicle's configuration (S131). The receiving unit 132 receives additional vehicle configuration information, which is information about the vehicle's configuration that is not present in the vehicle equipped with the vehicle attack analysis device 13 (S132). The transmitting unit 133 transmits the basic vehicle configuration information stored in S131 and the additional vehicle configuration information received in S132 to the SOC server 33 (S133).

[0118] The receiving unit 332 of the SOC server 33 receives the basic vehicle configuration information and additional vehicle configuration information transmitted from the vehicle attack analysis device 13 in S133 (S331). The attack / anomaly relationship information generation unit 336 generates an attack / anomaly relationship table (S332) that shows the correspondence between attack information indicating an attack on the electronic control system S, predicted anomaly information indicating anomalies that are expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system S where the predicted anomaly occurs, based on the vehicle configuration basic information and vehicle configuration additional information received in S331. The transmitting unit 333 transmits the attack / anomaly relationship table generated in S332 to the vehicle attack analysis device 13. The attack estimation unit 338 estimates the attack on the electronic control system S using the attack / anomaly relationship table generated in S332 (S322).

[0119] The receiving unit 132 of the vehicle attack analysis device 13 receives the attack / anomaly relationship table transmitted from the SOC server 33 in S333 (S134). The attack estimation unit 138 estimates the attack on the electronic control system S using the attack / anomaly relationship table received in S134 (S135).

[0120] (4) Summary As described above, according to this embodiment, an attack / anomaly relationship table is generated by receiving additional vehicle configuration information that the vehicle does not possess. Since the vehicle only needs to acquire the additional vehicle configuration information when generating the attack / anomaly relationship table, the risk of additional vehicle configuration information being leaked from individual vehicles can be reduced compared to when the vehicle possesses the additional vehicle configuration information from the time of shipment. In other words, additional vehicle configuration information can be centrally managed by the SOC server 33 or the OEM center server 40, etc., and the risk of additional vehicle configuration information being leaked can be reduced. Furthermore, according to this embodiment, since the attack / anomaly relationship table is generated on the SOC server 33, the attack / anomaly relationship table can be generated using abundant hardware resources.

[0121] 5. Others In embodiments 1 and 3, the vehicle attack analysis device 11(13) acquires additional vehicle configuration information by receiving it from the SOC server 31(33). However, when receiving additional vehicle configuration information from the SOC server 31(33), it is not necessary to send the same information to the SOC server 31(33) again. Furthermore, the timing for generating the attack / anomaly relationship table in each embodiment may be when the vehicle is shipped, when the vehicle configuration changes, when the software used in the vehicle is updated, or when it becomes necessary to add a new pattern to the SOC server 31 (32, 33), etc.

[0122] 6. Summary The features of the vehicle attack analysis device and the like in each embodiment of the present invention have been described above.

[0123] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.

[0124] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.

[0125] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.

[0126] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.

[0127] Each embodiment is based on a vehicle-mounted attack analysis device, but the present invention also includes dedicated or general-purpose devices other than those for vehicles, unless otherwise specifically limited by the claims.

[0128] Furthermore, the following are examples of the vehicle attack analysis device of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.

[0129] Furthermore, necessary functions such as antennas and communication interfaces may be added to the vehicle attack analysis device.

[0130] The external device of the present invention is intended to be used particularly on the server side for the purpose of providing various services.

[0131] In addition, the present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.

[0132] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]

[0133] The vehicle attack analysis device of the present invention is primarily intended for analyzing cyberattacks on electronic control systems installed in automobiles, but it may also be intended for analyzing attacks on ordinary systems not installed in automobiles. [Explanation of Symbols]

[0134] 11,12,13 Vehicle attack analysis device, 111 Storage unit, 112 Receiving unit, 113 Transmitting unit, 114 Control unit, 115 Vehicle configuration information classification unit, 116 Attack / anomaly relationship information generation unit, 117 Attack / anomaly relationship information merging unit, 118 Attack estimation unit, 31,32,33 SOC server, 40 OEM center server, 1,2,3 Attack analysis system

Claims

1. A vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, A storage unit (111) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A receiving unit (112) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A vehicle configuration information classification unit (115) classifies the vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information, A transmitting unit (113) transmits the first vehicle configuration information to an external device (31), Based on the second vehicle configuration information, the attack / anomaly relationship information generation unit (116) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates second attack / anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. Based on the first vehicle configuration information, the receiving unit (112) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack and receives the first attack / anomaly relationship information generated by the external device from the external device, An attack / abnormal relationship information combining unit (117) combines the first attack / abnormal relationship information and the second attack / abnormal relationship information to generate attack / abnormal relationship information, The system includes an attack estimation unit (118) that estimates the attack the electronic control system has been subjected to using the aforementioned attack / anomaly relationship information. Vehicle attack analysis device (11).

2. A vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, A storage unit (111) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A receiving unit (112) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A vehicle configuration information classification unit (115) classifies the vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information, A transmitting unit (113) transmits the first vehicle configuration information to an external device (31), Based on the second vehicle configuration information, the attack / anomaly relationship information generation unit (116) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates second attack / anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. The transmitting unit (113) transmits the second attack / anomaly relationship information to the external device, Based on the first vehicle configuration information, the receiving unit (112) receives attack / anomaly relationship information generated by combining the first attack / anomaly relationship information generated by the external device and the second attack / anomaly relationship information, which is calculated by combining the first attack / anomaly relationship information generated by the external device with the security sensor of the electronic control unit that will detect an anomaly in response to a hypothetical attack, from the external device. The system includes an attack estimation unit (118) that estimates the attack the electronic control system has been subjected to using the aforementioned attack / anomaly relationship information. Vehicle attack analysis device (11).

3. The aforementioned additional vehicle configuration information is received from a device authenticated using equipment authentication or from an authenticated device. Vehicle attack analysis device according to claim 1 or 2.

4. The first vehicle configuration information is such that the security level of the information is lower than a predetermined level. Vehicle attack analysis device according to claim 1 or 2.

5. The second vehicle configuration information has a security level higher than a predetermined level. Vehicle attack analysis device according to claim 1 or 2.

6. The external device generates the first attack / abnormality relationship information based on the first vehicle configuration information, as well as a third vehicle configuration information that the vehicle does not possess but the external device possesses. Vehicle attack analysis device according to claim 1 or 2.

7. The attack / anomaly relationship information generation unit further generates the second attack / anomaly relationship information using the anomaly occurrence pattern of the security sensor in past attacks. Vehicle attack analysis device according to claim 1 or 2.

8. The basic vehicle configuration information further includes the ignition rules for the security sensor, Vehicle attack analysis device according to claim 1 or 2.

9. The basic vehicle configuration information further includes information indicating the type of attack and the attack path. Vehicle attack analysis device according to claim 1 or 2.

10. A vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, A storage unit (121) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A receiving unit (122) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. Based on the vehicle configuration information consisting of the vehicle configuration basic information and the vehicle configuration additional information, the attack / anomaly relationship information generation unit (126) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates attack / anomaly relationship information showing the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. The system includes an attack estimation unit (128) that estimates the attack on the electronic control system using the aforementioned attack / anomaly relationship information. Vehicle attack analysis device (12).

11. A vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, A storage unit (131) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangements of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangements of security sensors provided in the electronic control devices. A receiving unit (132) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A transmission unit (133) transmits vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, to an external device (33). Based on the vehicle configuration information, the receiving unit (132) receives attack-anomaly relationship information from the external device, which is generated by calculating which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and which indicates the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. The system includes an attack estimation unit (138) that estimates the attack the electronic control system has been subjected to using the aforementioned attack / anomaly relationship information. Vehicle attack analysis device (13).

12. An attack analysis system comprising a vehicle attack analysis device and an external device for analyzing attacks on electronic control systems installed in a vehicle, The aforementioned vehicle attack analysis device (11) is A storage unit (111) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A receiving unit (112) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A vehicle configuration information classification unit (115) classifies the vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information, A transmitting unit (113) that transmits the first vehicle configuration information to an external device, Based on the second vehicle configuration information, the attack / anomaly relationship information generation unit (116) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates second attack / anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. The receiving unit (112) receives the first attack / abnormality relationship information generated by the external device based on the first vehicle configuration information from the external device, An attack / abnormal relationship information combining unit (117) combines the first attack / abnormal relationship information and the second attack / abnormal relationship information to generate attack / abnormal relationship information, The system includes an attack estimation unit (118) that estimates the attack on the electronic control system using the aforementioned attack / anomaly relationship information, The external device (31) is A receiving unit (312) that receives the first vehicle configuration information, Based on the first vehicle configuration information, the attack / anomaly relationship information generation unit (316) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack and generates the first attack / anomaly relationship information, The system includes a transmitting unit (313) that transmits the first attack / anomaly relationship information to the vehicle attack analysis device, Attack analysis system (1).

13. An attack analysis system comprising a vehicle attack analysis device and an external device for analyzing attacks on electronic control systems installed in a vehicle, The aforementioned vehicle attack analysis device (11) is A storage unit (111) stores basic vehicle configuration information, which is information possessed by the vehicle, among information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices. A receiving unit (112) receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess. A vehicle configuration information classification unit (115) classifies the vehicle configuration information, consisting of the basic vehicle configuration information and the additional vehicle configuration information, into first vehicle configuration information and second vehicle configuration information, A transmitting unit (113) that transmits the first vehicle configuration information to an external device, Based on the second vehicle configuration information, the attack / anomaly relationship information generation unit (116) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates second attack / anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs. The transmitting unit (113) transmits the second attack / anomaly relationship information to the external device, The receiving unit (112) receives attack / abnormal relationship information generated by combining the first attack / abnormal relationship information and the second attack / abnormal relationship information generated by the external device based on the first vehicle configuration information from the external device, The system includes an attack estimation unit (118) that estimates the attack on the electronic control system using the aforementioned attack / anomaly relationship information, The external device (31) is A receiving unit (312) that receives the first vehicle configuration information, Based on the first vehicle configuration information, the attack / anomaly relationship information generation unit (316) calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack and generates the first attack / anomaly relationship information, The receiving unit (312) receives the second attack / anomaly relationship information from the vehicle attack analysis device, An attack / abnormal relationship information merging unit (317) combines the first attack / abnormal relationship information and the second attack / abnormal relationship information to generate attack / abnormal relationship information, The system includes a transmitting unit (313) that transmits the aforementioned attack / abnormality relationship information to the vehicle attack analysis device, Attack analysis system (1).

14. The external device further includes an attack estimation unit (318) that estimates the attack suffered by the electronic control system using the attack / anomaly relationship information. The attack analysis system according to claim 12 or 13.

15. An attack analysis method performed by a vehicle attack analysis device for analyzing attacks on electronic control systems installed in a vehicle, The system stores basic vehicle configuration information, which is information possessed by the vehicle, among the information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices (S111). The system receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess (S112). The vehicle configuration information consisting of the basic vehicle configuration information and the additional vehicle configuration information is classified into first vehicle configuration information and second vehicle configuration information (S113). The first vehicle configuration information is transmitted to an external device (S114), Based on the second vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates a second attack-anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs (S115). Based on the first vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and receives the first attack / anomaly relationship information generated by the external device from the external device (S116). The first attack / anomaly relationship information and the second attack / anomaly relationship information are combined to generate attack / anomaly relationship information (S117), Using the aforementioned attack / anomaly relationship information, the attack on the electronic control system is estimated (S119). Attack analysis methods.

16. An attack analysis method performed by a vehicle attack analysis device for analyzing attacks on electronic control systems installed in a vehicle, The system stores basic vehicle configuration information, which is information possessed by the vehicle, among the information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices (S111). The system receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess (S112). The vehicle configuration information consisting of the basic vehicle configuration information and the additional vehicle configuration information is classified into first vehicle configuration information and second vehicle configuration information (S113). The first vehicle configuration information is transmitted to an external device (S114), Based on the second vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates a second attack-anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs (S115). The second attack / anomaly relationship information is transmitted to the external device (S151), Based on the first vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and receives attack / anomaly relationship information generated by combining the first attack / anomaly relationship information and the second attack / anomaly relationship information generated by the external device from the external device (S152). Using the aforementioned attack / anomaly relationship information, the attack on the electronic control system is estimated (S119). Attack analysis methods.

17. An attack analysis program executable by a vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, The system stores basic vehicle configuration information, which is information possessed by the vehicle, among the information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices (S111). The system receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess (S112). The vehicle configuration information consisting of the basic vehicle configuration information and the additional vehicle configuration information is classified into first vehicle configuration information and second vehicle configuration information (S113). The first vehicle configuration information is transmitted to an external device (S114), Based on the second vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates a second attack-anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs (S115). Based on the first vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and receives the first attack / anomaly relationship information generated by the external device from the external device (S116). The first attack / anomaly relationship information and the second attack / anomaly relationship information are combined to generate attack / anomaly relationship information (S117), Using the aforementioned attack / anomaly relationship information, the attack on the electronic control system is estimated (S119). An attack analysis program that causes the vehicle attack analysis device to perform a process including the above.

18. An attack analysis program executable by a vehicle attack analysis device that analyzes attacks on electronic control systems installed in a vehicle, The system stores basic vehicle configuration information, which is information possessed by the vehicle, among the information relating to the vehicle's configuration, including the types and arrangement of multiple electronic control devices in the electronic control system, the connection relationships of the electronic control devices, and the types and arrangement of security sensors provided in the electronic control devices (S111). The system receives additional vehicle configuration information, which is information about the vehicle's configuration that the vehicle does not possess (S112). The vehicle configuration information consisting of the basic vehicle configuration information and the additional vehicle configuration information is classified into first vehicle configuration information and second vehicle configuration information (S113). The first vehicle configuration information is transmitted to an external device (S114), Based on the second vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and generates a second attack-anomaly relationship information that shows the correspondence between attack information indicating an attack on the electronic control system, predicted anomaly information indicating an anomaly that is expected to occur when the attack occurs, and predicted anomaly location information indicating the location within the electronic control system where the predicted anomaly occurs (S115). The second attack / anomaly relationship information is transmitted to the external device (S151), Based on the first vehicle configuration information, the system calculates which security sensor of which electronic control unit will detect an anomaly in response to a hypothetical attack, and receives attack / anomaly relationship information generated by combining the first attack / anomaly relationship information and the second attack / anomaly relationship information generated by the external device from the external device (S152). Using the aforementioned attack / anomaly relationship information, the attack on the electronic control system is estimated (S119). An attack analysis program that causes the vehicle attack analysis device to perform a process including the above.

Citation Information

Patent Citations

  • Vehicle security monitoring device, method and program

    JP2020119090A

  • Security device, attack specification method, and program

    JP2020123307A

  • Cyber attack analysis support device

    JP2021117568A

  • Log management apparatus, and security attack detection and analysis system

    JP2022017889A

  • State diagnosing device and state diagnosing method

    JP2022086181A