Detection device, detection method, and detection program

JPWO2024105935A5Pending Publication Date: 2025-07-28
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024558643
Authority / Receiving Office
JP · JP
Patent Type
Applications
Filing Date
2025-03-10
Publication Date
2025-07-28

AI Technical Summary

Technical Problem

Conventional detection systems are inadequate in accurately identifying unauthorized communication connections in networks, particularly when unauthorized devices impersonate legitimate ones and establish connections using stateful messages.

Method used

A detection device and method that monitor communication connections in a network, utilizing a monitoring unit to track the establishment and termination of connections based on stateful messages, and a detection unit to analyze these patterns to identify unauthorized connections, employing protocols like TCP/IP, SOME/IP, and DDS to detect anomalies in connection cycles, frequencies, and durations.

Benefits of technology

This approach enables more accurate detection of unauthorized communication connections by analyzing the patterns of communication in the network, allowing for timely identification and alerting of potential security breaches.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

This detection device is for detecting the existence of an unauthorized communication connection on a network. The detection device comprises: a monitoring unit for monitoring a communication connection established for exchanging prescribed messages on the network; and a detection unit for detecting the existence of said unauthorized communication connection on the basis of the results of monitoring, by the monitoring unit, of a plurality of the communication connections.
Need to check novelty before this filing date? Find Prior Art

Description

Detection device, detection method, and detection program

[0001] This application claims priority from Japanese Patent Application No. 2022-184950, filed November 18, 2022, the disclosure of which is incorporated herein by reference in its entirety.

[0002] Patent Document 1 (WO 2022 / 153839) discloses the following detection device: That is, the detection device detects the presence of fraudulent messages in an in-vehicle network, and includes a state detection unit that detects a transition to a state in which periodic messages that are periodic messages are transmitted in the in-vehicle network based on the content of a message transmitted in the in-vehicle network, and a processing unit that performs detection processing to detect the presence of the fraudulent messages based on reception statuses of a plurality of the periodic messages in the state detected by the state detection unit.

[0003] International Publication No. 2022 / 153839

[0004] The detection device of the present disclosure is a detection device that detects the presence of an unauthorized communication connection in a network, and includes a monitoring unit that monitors communication connections established to exchange specified messages in the network, and a detection unit that detects the presence of the unauthorized communication connection based on the monitoring results of multiple communication connections by the monitoring unit.

[0005] One aspect of the present disclosure can be realized not only as a detection device equipped with such a characteristic processing unit, but also as a semiconductor integrated circuit that realizes part or all of the detection device, or as a system that includes the detection device.

[0006] FIG. 1 is a diagram illustrating a network configuration according to an embodiment of the present disclosure. FIG. 2 is a diagram illustrating a configuration of a relay device according to an embodiment of the present disclosure. FIG. 3 is a diagram illustrating an example of a message transmitted and received in the network according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating another example of a message transmitted and received in the network according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 9 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 10 is a diagram illustrating an example of a communication connection operation of a communication target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of a communication connection operation of a communication target of a monitoring unit in a relay device according to an embodiment of the present disclosure. FIG. 12 is a diagram illustrating an example of a communication connection operation of a communication target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 13 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure monitors a communication connection. Fig. 14 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 15 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 16 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 17 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 18 is a flowchart defining an example of an operational procedure when a relay device according to an embodiment of the present disclosure performs a detection process.

[0007] Conventionally, techniques have been developed to improve security in networks.

[0008] [Problem to be Solved by the Present Disclosure] There is a need for a technology that goes beyond the technology described in Patent Document 1 and is capable of more accurately detecting the presence of unauthorized communication connections on a network.

[0009] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide a detection system, verification device, response device, and detection method that can more accurately detect the presence of unauthorized communication connections in a network.

[0010] Effect of the Present Disclosure According to the present disclosure, the presence of an unauthorized communication connection in a network can be detected more accurately.

[0011] [Description of Embodiments of the Present Disclosure] First, the contents of the embodiments of the present disclosure will be listed and described.

[0012] (1) A detection device according to an embodiment of the present disclosure is a detection device that detects the presence of an unauthorized communication connection in a network, and includes a monitoring unit that monitors communication connections established to exchange specified messages in the network, and a detection unit that detects the presence of the unauthorized communication connection based on the monitoring results of the monitoring unit of multiple communication connections.

[0013] In this way, by detecting the presence of an unauthorized communication connection based on the results of monitoring multiple communication connections, it is possible to determine the presence of an unauthorized communication connection when, for example, the status of communication connections in the network changes due to the establishment of an unauthorized communication connection, thereby more accurately detecting the presence of an unauthorized communication connection in the network.

[0014] (2) In the above (1), the detection unit may detect the presence of the unauthorized communication connection based on a cycle at which the communication connection is established.

[0015] With this configuration, it is possible to detect an unauthorized communication connection based on a change in the occurrence cycle of communication connections due to the establishment of an unauthorized communication connection.

[0016] (3) In the above (1) or (2), the presence of the unauthorized communication connection may be detected based on the frequency with which the communication connection is established.

[0017] With this configuration, it is possible to detect an unauthorized communication connection based on a change in the frequency of occurrence of communication connections due to the establishment of an unauthorized communication connection.

[0018] (4) In any of (1) to (3) above, the detection unit may detect the existence of the unauthorized communication connection based on the proportion of the period during which the communication connection is established per unit time.

[0019] With this configuration, it is possible to detect an unauthorized communication connection based on a change in the period during which a communication connection is established per unit time due to the establishment of the unauthorized communication connection.

[0020] (5) In any of (1) to (4) above, the monitoring unit may monitor the communication connection that is established using a SubscribeAck message conforming to SOME / IP (Scalable service-oriented middleware over IP) and that is terminated using a StopOffer message or a StopSubscribe message conforming to SOME / IP.

[0021] With this configuration, it is possible to more accurately detect the presence of unauthorized communication connections in a network where messages are sent and received according to SOME / IP.

[0022] (6) In any one of (1) to (4) above, the monitoring unit may monitor a TCP (Transmission Control Protocol) connection as the communication connection.

[0023] With this configuration, it is possible to more accurately detect the presence of unauthorized communication connections in a network where messages are sent and received according to TCP.

[0024] (7) In any of (1) to (4) above, the monitoring unit may monitor the communication connection that is established using a create_subscriber message conforming to a DDS (Data Distribution Service) and that is terminated using a Delete_subscriber message conforming to the DDS.

[0025] With this configuration, it is possible to more accurately detect the presence of unauthorized communication connections in a network where messages are sent and received according to DDS.

[0026] (8) A detection method according to an embodiment of the present disclosure is a detection method in a detection device that detects the presence of an unauthorized communication connection in a network, and includes a step of monitoring communication connections established in the network to exchange specified messages, and a step of detecting the presence of the unauthorized communication connection based on monitoring results of multiple of the communication connections.

[0027] In this way, by using a method for detecting the presence of an unauthorized communication connection based on the results of monitoring multiple communication connections, it is possible to determine the presence of an unauthorized communication connection when, for example, the status of communication connections in the network changes due to the establishment of an unauthorized communication connection, thereby more accurately detecting the presence of an unauthorized communication connection in the network.

[0028] (9) A detection program according to an embodiment of the present disclosure is a detection program used in a detection device that detects the presence of an unauthorized communication connection in a network, and is a program that causes a computer to function as a monitoring unit that monitors communication connections established to exchange specified messages in the network, and a detection unit that detects the presence of the unauthorized communication connection based on the monitoring results of multiple communication connections by the monitoring unit.

[0029] In this way, by detecting the presence of an unauthorized communication connection based on the results of monitoring multiple communication connections, it is possible to determine the presence of an unauthorized communication connection when, for example, the status of communication connections in the network changes due to the establishment of an unauthorized communication connection, thereby more accurately detecting the presence of an unauthorized communication connection in the network.

[0030] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, identical or corresponding parts are designated by the same reference numerals, and their description will not be repeated. Furthermore, at least some of the embodiments described below may be combined in any manner.

[0031] [Configuration and Basic Operation] Fig. 1 is a diagram illustrating a configuration of a network according to an embodiment of the present disclosure. Referring to Fig. 1, a network 12 includes a relay device 101 and a plurality of communication devices 111. The communication devices 111 are connected to the relay device 101 via a transmission line 14. The transmission line 14 is, for example, an Ethernet (registered trademark) cable.

[0032] For example, the network 12 is an in-vehicle network. In this case, the communication device 111 is an in-vehicle ECU (Electronic Control Unit). Specifically, the communication device 111 is a driving assistance device that issues instructions to various devices in an electric power steering (EPS), a brake control device, an accelerator control device, a steering control device, an advanced driver-assistance system (ADAS), or a sensor.

[0033] The network 12 may be a network in an industrial control system such as a factory or plant. In this case, the communication device 111 is, for example, a power supply control unit, a robot, a sensor, or a PLC (Programmable Logic Controller) for controlling an actuator.

[0034] The communication device 111 transmits and receives messages to and from other communication devices 111 by establishing a communication connection for exchanging predetermined messages in accordance with a connection-oriented protocol. More specifically, the communication device 111 periodically or irregularly establishes a communication connection with another communication device 111. The communication device 111 then generates a frame containing a message addressed to the other communication device 111 and transmits the generated frame to the relay device 101 via the transmission line 14. For example, the communication device 111 can dynamically establish communication connections with multiple different other communication devices 111.

[0035] The relay device 101 is, for example, a central gateway (CGW), and performs relay processing to relay messages transmitted and received between a plurality of communication devices 111 connected to different transmission lines 14. More specifically, the relay device 101 receives a frame transmitted from a communication device 111 via the corresponding transmission line 14, and transmits the received frame to the destination communication device 111 via the corresponding transmission line 14.

[0036] The relay device 101 also functions as a detection device and performs a detection process to detect the presence of an unauthorized communication connection in the network 12. Hereinafter, an unauthorized communication connection in the network 12 will also be referred to as an "unauthorized communication connection."

[0037] <Relay Device> Fig. 2 is a diagram illustrating the configuration of a relay device according to an embodiment of the present disclosure. Referring to Fig. 2, relay device 101 includes relay unit 51, monitoring unit 52, detection unit 53, output unit 54, and storage unit 55. Some or all of relay unit 51, monitoring unit 52, detection unit 53, and output unit 54 are implemented by, for example, a processing circuit including one or more processors. Storage unit 55 is, for example, a non-volatile memory included in the processing circuit.

[0038] When the relay unit 51 receives a frame from a certain communication device 111 via the corresponding transmission line 14, it transmits the received frame to the destination communication device 111 in accordance with the destination information of the frame via the corresponding transmission line 14. Here, the destination information of the frame is information indicating the destination of the frame, such as a destination MAC address, a destination IP address, and a message ID.

[0039] 3 is a diagram illustrating an example of messages transmitted and received in a network according to an embodiment of the present disclosure, and is a time chart illustrating messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0040] 3 , the communication device 111A establishes a communication connection with the communication device 111B by exchanging one or more stateful messages MS, which are messages for establishing a communication connection with another communication device 111, with the communication device 111B via the relay device 101. The communication device 111A also terminates the communication connection with the communication device 111B by exchanging one or more stateful messages ME, which are messages for terminating the communication connection with the other communication device 111, with the communication device 111B via the relay device 101. The communication device 111A transmits one or more messages to the communication device 111B via the relay device 101 during a connection period T1, which is a period during which the communication connection with the communication device 111B is established.

[0041] Note that the configuration may be such that only the communication device 111A of the communication devices 111A and 111B transmits a stateful message MS to the communication device 111B via the relay device 101 to establish a communication connection. Alternatively, the configuration may be such that only the communication device 111A of the communication devices 111A and 111B transmits a stateful message ME to the communication device 111B via the relay device 101 to terminate the communication connection. Alternatively, the communication device 111B may transmit a message to the communication device 111A via the relay device 101 during the connection period T1.

[0042] The monitoring unit 52 monitors communication connections established in the network 12. More specifically, the monitoring unit 52 monitors the relay process by the relay unit 51, and by referring to the header information of a frame received by the relay unit 51, checks the contents of the message stored in the frame.

[0043] When the message stored in the frame received by the relay unit 51 is a stateful message MS, the monitoring unit 52 determines that a communication connection is established between the communication device 111 that is the sender of the stateful message MS and the communication device 111 that is the destination of the stateful message MS. For example, the monitoring unit 52 obtains the reception time ts of the frame storing the stateful message MS by the relay unit 51, and stores the obtained reception time ts in the memory unit 55.

[0044] Furthermore, when the message stored in the frame received by the relay unit 51 is a stateful message ME, the monitoring unit 52 determines that the communication connection between the communication device 111 that is the sender of the stateful message ME and the communication device 111 that is the destination of the stateful message ME is terminated. For example, the monitoring unit 52 obtains the reception time te of the frame storing the stateful message ME by the relay unit 51, and stores the obtained reception time te in the storage unit 55.

[0045] The detection unit 53 detects the presence of an unauthorized communication connection based on the results of monitoring the multiple communication connections by the monitoring unit 52. For example, the detection unit 53 detects the presence of an unauthorized communication connection based on the results of monitoring the multiple communication connections in a pair of two communication devices 111.

[0046] For example, the detection unit 53 detects the existence of an unauthorized communication connection based on at least one of the period C1 at which a communication connection is established between the communication devices 111, the frequency F1 at which a communication connection is established between the communication devices 111, and the proportion R1 of the connection period T1 per unit time.

[0047] More specifically, the detection unit 53 calculates the cycle C1 and the frequency F1 based on the multiple reception times ts stored in the storage unit 55 by the monitoring unit 52. The detection unit 53 also calculates the connection period T1 based on the reception times ts and te stored in the storage unit 55 by the monitoring unit 52, and calculates the ratio R1 based on the connection period T1.

[0048] The detection unit 53 detects the presence of an unauthorized communication connection based on at least one of the calculated period C1, frequency F1, and ratio R1. When the detection unit 53 detects the presence of an unauthorized communication connection, it outputs the detection result to the output unit 54.

[0049] When the output unit 54 receives a detection result from the detection unit 53 indicating that an unauthorized communication connection has been detected, it outputs an alert to the user's terminal, etc., via a communication device 111 having wireless communication capabilities, for example.

[0050] 4 is a diagram illustrating another example of messages transmitted and received in a network according to an embodiment of the present disclosure. Fig. 4 is a time chart illustrating messages transmitted and received by communication devices 111A, 111B, and 111C, which are communication devices 111.

[0051] 4, in addition to the communication device 111A, the communication device 111C establishes a communication connection with the communication device 111B by exchanging one or more stateful messages MS, which are messages for establishing a communication connection with another communication device 111, with the communication device 111B via the relay device 101. Furthermore, the communication device 111C terminates the communication connection with the communication device 111B by exchanging one or more stateful messages ME, which are messages for terminating the communication connection with the other communication device 111, with the communication device 111B via the relay device 101.

[0052] In this case, for example, the detection unit 53 detects the presence of an unauthorized communication connection based on the results of monitoring a plurality of communication connections in a set of a plurality of different communication devices 111 .

[0053] More specifically, the detection unit 53 calculates the period C1 based on the reception time ts of a frame containing a stateful message MS transmitted by the communication device 111C and the reception time ts of a frame containing a stateful message MS transmitted by the communication device 111A. The detection unit 53 also calculates the frequency F1 based on the number of times a communication connection is established between the communication device 111A and the communication device 111B and the number of times a communication connection is established between the communication device 111C and the communication device 111B. The detection unit 53 also calculates the ratio R1 based on the connection duration T1 of the communication connection between the communication device 111A and the communication device 111B and the connection duration T1 of the communication connection between the communication device 111A and the communication device 111B.

[0054] 5 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. The diagram illustrates a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0055] 5, messages are transmitted and received in accordance with TCP / IP on network 12. Communication device 111 establishes a TCP connection, which is a communication connection conforming to TCP / IP, by a three-way handshake.

[0056] More specifically, the communication device 111A generates a SYN packet, which is a TCP packet with the SYN flag set to ON in the TCP header, and transmits the generated SYN packet to the communication device 111B via the relay device 101.

[0057] Communication device 111B receives a SYN packet from communication device 111A via relay device 101, generates a SYN / ACK packet, which is a TCP packet with the SYN flag and ACK flag set to on in the TCP header, and transmits the generated SYN / ACK packet to communication device 111A via relay device 101.

[0058] The communication device 111A receives a SYN / ACK packet from the communication device 111B via the relay device 101, generates an ACK packet, which is a TCP packet with the ACK flag set to ON in the TCP header, and transmits the generated ACK packet to the communication device 111B via the relay device 101. This establishes the nth TCP connection between the communication device 111A and the communication device 111B. The SYN packet, SYN / ACK packet, and ACK packet in the three-way handshake are examples of a stateful message MS.

[0059] In addition, when communication device 111A terminates the TCP connection with communication device 111B, it generates a FIN packet, which is a TCP packet with the FIN flag set to on in the TCP header, and transmits the generated FIN packet to communication device 111B via relay device 101.

[0060] Communication device 111B receives a FIN packet from communication device 111A via relay device 101, generates a FIN / ACK packet, which is a TCP packet with the FIN flag and ACK flag set to on in the TCP header, and transmits the generated FIN / ACK packet to communication device 111A via relay device 101.

[0061] The communication device 111A receives the FIN / ACK packet from the communication device 111B via the relay device 101, generates an ACK packet, which is a TCP packet with the ACK flag set to ON in the TCP header, and transmits the generated ACK packet to the communication device 111B via the relay device 101. This terminates the TCP connection between the communication device 111A and the communication device 111B. The FIN packet, FIN / ACK packet, and ACK packet in the three-way handshake are examples of a stateful message ME.

[0062] The communication device 111A transmits one or more messages to the communication device 111B via the relay device 101 during a connection period T1A, which is the connection period T1 of the TCP connection with the communication device 111B.

[0063] Thereafter, similarly, the establishment and termination of a TCP connection between the communication device 111A and the communication device 111B is repeated.

[0064] The monitoring unit 52 monitors TCP connections as an example of communication connections established in the network 12. For example, the monitoring unit 52 monitors TCP connections established in the network 12 for each application identified by a set of port numbers.

[0065] More specifically, if a SYN packet is stored in a frame received by the relay unit 51, the monitoring unit 52 determines that a TCP connection is established between the communication device 111 that is the sender of the frame and the communication device 111 that is the destination of the frame.

[0066] The monitoring unit 52 then acquires the source port number and the destination port number from the TCP header of the SYN packet, and stores the acquired pair of source port number and destination port number in the storage unit 55 as identification information DA indicating the communication connection being monitored. The monitoring unit 52 also generates state information indicating that the state of the communication connection being monitored has transitioned to a state in which a SYN packet has been exchanged, and stores the generated state information in association with the identification information DA in the storage unit 55. The monitoring unit 52 also acquires a reception time tsa1, which is the reception time ts of the frame containing the SYN packet by the relay unit 51, and stores the acquired reception time tsa1 in association with the identification information DA in the storage unit 55. The reception time tsa1 corresponds to the time when the state of the communication connection being monitored has transitioned to a state in which a SYN packet has been exchanged.

[0067] Furthermore, when a SYN / ACK packet is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires the source port number and the destination port number from the TCP header of the SYN / ACK packet and identifies, from the identification information DA stored in the storage unit 55, identification information DA that matches the acquired set of source port number and destination port number.The monitoring unit 52 then updates the state information corresponding to the identified identification information DA to state information indicating that a transition has occurred to a state in which a SYN / ACK packet has been exchanged.The monitoring unit 52 also acquires a reception time tsa2, which is the reception time ts of the frame in which the SYN / ACK packet is stored by the relay unit 51, and stores the acquired reception time tsa2 in the storage unit 55 in association with the identified identification information DA.The reception time tsa2 corresponds to the time when the state of the communication connection being monitored transitioned to a state in which a SYN / ACK packet has been exchanged.

[0068] Furthermore, when an ACK packet is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires the source port number and the destination port number from the TCP header of the ACK packet and identifies, from the identification information DA stored in the storage unit 55, identification information DA that matches the acquired pair of source port number and destination port number. The monitoring unit 52 then updates the state information corresponding to the identified identification information DA to state information indicating that a transition has occurred to a state in which an ACK packet has been exchanged in response to the SYN / ACK packet. The monitoring unit 52 also acquires a reception time tsa3, which is the reception time ts of the frame in which the ACK packet is stored by the relay unit 51, and stores the acquired reception time tsa3 in the storage unit 55 in association with the identified identification information DA. The reception time tsa3 corresponds to the time at which the state of the communication connection being monitored transitioned to a state in which an ACK packet has been exchanged in response to the SYN / ACK packet.

[0069] Furthermore, when a FIN packet is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires the source port number and the destination port number from the TCP header of the FIN packet, and identifies, from the identification information DA stored in the storage unit 55, identification information DA that matches the acquired set of source port number and destination port number. The monitoring unit 52 then updates the state information corresponding to the identified identification information DA to state information indicating that a transition has occurred to a state in which a FIN packet has been exchanged. The monitoring unit 52 also acquires a reception time tea1, which is the reception time te of the frame in which the FIN packet is stored, and stores the acquired reception time tea1 in the storage unit 55 in association with the identified identification information DA. The reception time tea1 corresponds to the time when the state of the communication connection to be monitored transitioned to a state in which a FIN packet has been exchanged.

[0070] Furthermore, when a FIN / ACK packet is stored in a frame received by the relay unit 51, the monitor unit 52 acquires the source port number and the destination port number from the TCP header of the FIN / ACK packet and identifies, from the identification information DA stored in the memory unit 55, identification information DA that matches the acquired pair of source port number and destination port number. The monitor unit 52 then updates the state information corresponding to the identified identification information DA to state information indicating that a transition has occurred to a state in which a FIN / ACK packet has been exchanged. The monitor unit 52 also acquires a reception time tea2, which is the reception time te of the frame in which the FIN / ACK packet is stored, and stores the acquired reception time tea2 in the memory unit 55 in association with the identified identification information DA. The reception time tea2 corresponds to the time when the state of the communication connection being monitored transitioned to a state in which a FIN / ACK packet has been exchanged.

[0071] Furthermore, when an ACK packet is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires the source port number and the destination port number from the TCP header of the ACK packet and identifies, from the identification information DA stored in the storage unit 55, identification information DA that matches the acquired pair of source port number and destination port number. The monitoring unit 52 then updates the state information corresponding to the identified identification information DA to state information indicating that a transition has occurred to a state in which an ACK packet has been exchanged in response to the FIN / ACK packet. The monitoring unit 52 also acquires a reception time tea3, which is the time te at which the relay unit 51 received the frame in which the ACK packet is stored, and stores the acquired reception time tea3 in the storage unit 55 in association with the identified identification information DA. The reception time tea3 corresponds to the time at which the state of the communication connection being monitored transitioned to a state in which an ACK packet has been exchanged in response to the FIN / ACK packet.

[0072] The detection unit 53 calculates the period C1A, which is the period C1 during which a TCP connection between the communication device 111A and the communication device 111B is established, based on multiple reception times ts stored in the storage unit 55 by the monitoring unit 52. More specifically, each time the monitoring unit 52 updates the state information in the storage unit 55 and stores a reception time tsa3 in the storage unit 55, the detection unit 53 calculates the period C1A as the difference between the reception time tsa3 and the reception time tsa3 immediately before the reception time tsa3. Note that the detection unit 53 may be configured to calculate the period C1A based on the reception time tsa2 or the reception time tsa1 instead of the reception time tsa3. Furthermore, the detection unit 53 may be configured to calculate the period C1A based on the reception time at the relay unit 51 of a frame containing a TCP packet with the PSH flag set to on when the TCP connection is established.

[0073] For example, the detection unit 53 compares the calculated period C1A with predetermined thresholds TcLA and TcHA. Here, the threshold TcLA is assumed to be smaller than the threshold TcHA. For example, the thresholds TcLA and TcHA are set in advance based on the monitoring results of TCP connections established in a normal network 12 where no unauthorized communication connections exist.

[0074] If the period C1A is equal to or greater than the threshold value TcLA and equal to or less than the threshold value TcHA, the detection unit 53 determines that no unauthorized communication connection exists in the network 12. On the other hand, if the period C1A is less than the threshold value TcLA or greater than the threshold value TcHA, the detection unit 53 determines that an unauthorized communication connection exists in the network 12.

[0075] 6 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 6 illustrates a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0076] 6, for example, an unauthorized communication device acquires a source port number and a destination port number from the TCP header of a frame sent by communication device 111A and addressed to communication device 111B, and masquerades as communication device 111A and transmits a SYN packet to communication device 111B via relay device 101. In response to the SYN / ACK packet from communication device 111B, the unauthorized device masquerades as communication device 111A and transmits an ACK packet to communication device 111B via relay device 101, thereby establishing an unauthorized TCP connection, which is an unauthorized communication connection with communication device 111B.

[0077] After establishing a TCP connection with communication device 111B, the unauthorized device transmits an unauthorized message (not shown) to communication device 111B via relay device 101. Thereafter, the unauthorized device masquerades as communication device 111A and transmits a FIN packet to communication device 111B via relay device 101. Furthermore, in response to the FIN / ACK packet from communication device 111B, the unauthorized device masquerades as communication device 111A and transmits an ACK packet to communication device 111B via relay device 101, thereby terminating the TCP connection with communication device 111B.

[0078] For example, if an unauthorized TCP connection is established in the period between the connection period T1A of the nth TCP connection between communication device 111A and communication device 111B and the connection period T1A of the n+1th TCP connection between communication device 111A and communication device 111B, the number of ACK packets in response to SYN / ACK packets sent to communication device 111B will increase compared to when an unauthorized TCP connection is not established.

[0079] In this case, because the period C1A, which is the difference between the reception time tsa3 of the SYN packet transmitted from the unauthorized device and the reception time tsa3 of the SYN packet transmitted from communication device 111A immediately before the SYN packet, is less than the threshold value TcLA, detection unit 53 determines that an unauthorized communication connection exists in network 12. Furthermore, because the period C1A, which is the difference between the reception time tsa3 of the SYN packet transmitted from communication device 111A and the reception time tsa3 of the SYN packet transmitted from the unauthorized device immediately before the SYN packet, is less than the threshold value TcLA, detection unit 53 determines that an unauthorized communication connection exists in network 12.

[0080] In addition, instead of or in addition to the above-mentioned specific example 1 of the detection process, the detection unit 53 may be configured to calculate the variance of the period C1A and detect the presence of an unauthorized communication connection in the network 12 based on the results of comparing the calculated variance with a predetermined threshold value.

[0081] 7 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 7 shows a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0082] 7, the detection unit 53 calculates a frequency F1A, which is the frequency F1 at which a TCP connection is established between the communication device 111A and the communication device 111B, based on a plurality of reception times tsa3 stored in the storage unit 55 by the monitoring unit 52. More specifically, for example, the detection unit 53 calculates the frequency F1A as the number of times that the relay unit 51 receives an ACK packet, which is a response to a SYN / ACK packet, within a unit time of a predetermined length at a detection timing according to a predetermined cycle. Note that the detection unit 53 may be configured to calculate the frequency F1A based on the reception time tsa1, the reception time tsa3, the reception time tea1, the reception time tea2, or the reception time tea3, instead of the reception time tsa3.

[0083] For example, the detection unit 53 compares the calculated frequency F1A with predetermined thresholds TfLA and TfHA. Here, the threshold TfLA is assumed to be smaller than the threshold TfHA. For example, the thresholds TfLA and TfHA are set in advance based on the monitoring results of TCP connections established in a normal network 12 where no unauthorized communication connections exist.

[0084] If the frequency F1A is equal to or greater than the threshold TfLA and equal to or less than the threshold TfHA, the detection unit 53 determines that no unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing. On the other hand, if the frequency F1A is less than the threshold TfLA or greater than the threshold TfHA, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing.

[0085] 8 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 8 illustrates a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0086] Referring to Figure 8, when an unauthorized TCP connection is repeatedly established between an unauthorized device and communication device 111B, the number of ACK packets sent to communication device 111B in response to a SYN / ACK packet increases compared to when an unauthorized TCP connection is not established.

[0087] In this case, the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection time to the current detection time, since the frequency F1A calculated at the detection time is greater than the threshold value TfHA.

[0088] The detection unit 53 may be configured to determine that an unauthorized communication connection exists in the network 12 when the number of ACK packets in response to a SYN / ACK packet transmitted to the communication device 111B exceeds the threshold value TfLA before the unit time has elapsed. The detection unit 53 may also be configured to calculate the frequency F1A in the most recent unit time of a predetermined length each time the monitoring unit 52 stores the reception time tsa3 in the storage unit 55, instead of calculating the frequency F1A at the detection timing according to the predetermined cycle.

[0089] (Specific example 3 of detection processing) Referring again to FIG. 7 , the detection unit 53 calculates, at a detection timing according to a predetermined cycle, a ratio R1A, which is the ratio R1 of the total sum of the connection periods T1A per unit time, based on the reception time tsa3 and the corresponding reception time tea3 stored in the memory unit 55 by the monitoring unit 52.

[0090] For example, the detection unit 53 compares the calculated ratio R1A with predetermined thresholds TrLA and TrHA. Here, the threshold TrLA is assumed to be smaller than the threshold TrHA. For example, the thresholds TrLA and TrHA are set in advance based on the monitoring results of TCP connections established in a normal network 12 in which no unauthorized communication connections exist.

[0091] If the ratio R1A is equal to or greater than the threshold value TrLA and equal to or less than the threshold value TrHA, the detection unit 53 determines that no unauthorized communication connection exists in the network 12 during the period from the previous detection time to the current detection time. On the other hand, if the ratio R1A is less than the threshold value TrLA or greater than the threshold value TrHA, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 during the period from the previous detection time to the current detection time.

[0092] Referring again to FIG. 8, when an unauthorized TCP connection is repeatedly established between the unauthorized device and the communication device 111B, the total connection period T1A per unit time increases compared to when no unauthorized TCP connection is established.

[0093] In this case, the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection time to the current detection time, since the ratio R1A calculated at the detection time is greater than the threshold value TrHA.

[0094] The detection unit 53 may be configured to determine that an unauthorized communication connection exists in the network 12 when the total value of each connection period T1A exceeds a predetermined value before the unit time has elapsed. The detection unit 53 may also be configured to calculate the ratio R1A in the most recent unit time of a predetermined length each time the monitoring unit 52 stores the reception time tsa3 in the storage unit 55, instead of calculating the ratio R1A at the detection timing according to a predetermined cycle.

[0095] Furthermore, in addition to the above-described specific example 3 of the detection process, the detection unit 53 may be configured to determine whether or not an unauthorized communication connection exists in the network 12 based on the result of comparing the calculated connection period T1A with a predetermined threshold each time the monitoring unit 52 calculates the connection period T1A based on the reception time tsa3 and the corresponding reception time tea3 stored in the memory unit 55. Here, for example, the connection period T1A of an unauthorized TCP connection is greater than or equal to a predetermined value than a normal value, or is less than or equal to a predetermined value than a normal value. Therefore, the detection unit 53 can determine whether or not an unauthorized communication connection exists in the network 12 based on the result of comparing the connection period T1A with the predetermined threshold.

[0096] Furthermore, the monitoring unit 52 is not limited to a configuration that monitors communication connections that are established and terminated according to a connection-oriented protocol, but may be configured to monitor communication connections that are established and terminated according to another protocol.

[0097] 9 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. The diagram illustrates a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0098] 9, messages are transmitted and received in accordance with SOME / IP, which is an application layer protocol of the Ethernet protocol suite, in network 12. For example, communication device 111 can transmit and receive messages conforming to SOME / IP instead of or in parallel with transmitting and receiving messages conforming to TCP / IP.

[0099] The communication device 111 establishes a communication connection for providing periodic services using the Publish / Subscribe function of SOME / IP. Hereinafter, the communication connection for providing periodic services in SOME / IP will also be referred to as a "SOME / IP connection."

[0100] More specifically, when receiving the provision of a service, the communication device 111B, as a client, broadcasts a Find message including a service ID corresponding to the service.

[0101] Of the multiple communication devices 111 that received the Find message, communication device 111A, which has an application that can provide the service corresponding to the service ID included in the Find message, acts as a server and transmits an Offer message indicating that it will begin providing the service to communication device 111B via relay device 101. The SOME / IP header of the Offer message stores a server ID, which is the ID of communication device 111A, etc.

[0102] Thereafter, when communication device 111B requests communication device 111A to provide periodic services, it uses the server ID obtained from the Offer message to send a Subscribe message, which is a message including the server ID and service ID, to communication device 111A via relay device 101.

[0103] The communication device 111A receives the Subscribe message and checks the service ID included in the Subscribe message. If the service ID matches the service ID corresponding to a service that can be provided, the communication device 111A transmits a SubscribeAck message, which is a message indicating approval of the provision of the service, to the communication device 111B via the relay device 101. This establishes the nth SOME / IP connection between the communication device 111A and the communication device 111B. The Subscribe message and the SubscribeAck message are examples of a stateful message MS.

[0104] Furthermore, when the communication device 111B stops receiving the service, that is, when it terminates the SOME / IP connection, it transmits a StopSubscribe message to the communication device 111A via the relay device 101. The StopSubscribe message is an example of a stateful message ME.

[0105] During connection period T1B, during which a SOME / IP connection is established with communication device 111B, communication device 111A periodically transmits a Notification message, which is a message conforming to SOME / IP, to communication device 111B via relay device 101 as a service.

[0106] Thereafter, in a similar manner, the establishment and termination of a SOME / IP connection between the communication device 111A and the communication device 111B is repeated using a Subscribe message, a SubscribeAck message, and a StopSubscribe message.

[0107] Note that the configuration may be such that the communication device 111A terminates the SOME / IP connection instead of the communication device 111B. Specifically, the communication device 111A transmits a StopOffer message to the communication device 111B via the relay device 101. This terminates the SOME / IP connection between the communication device 111A and the communication device 111B. In this case, the establishment and termination of the SOME / IP connection between the communication device 111A and the communication device 111B are repeated using a Find message, an Offer message, a Subscribe message, a SubscribeAck message, and a StopOffer message.

[0108] The monitoring unit 52 monitors a SOME / IP connection as an example of a communication connection established in the network 12. As described above, a SOME / IP connection is established using a SubscribeAck message and terminated using a StopOffer message or a StopSubscribe message. For example, the monitoring unit 52 monitors the SOME / IP connections established in the network 12 for each service ID.

[0109] More specifically, if a Subscribe message is stored in a frame received by the relay unit 51, the monitoring unit 52 determines that a SOME / IP connection is established between the communication device 111 that sent the frame and the communication device 111 that is the destination of the frame.

[0110] The monitoring unit 52 then acquires a service ID from the SOME / IP header of the Subscribe message and stores the acquired service ID in the storage unit 55 as an identification information DB indicating the communication connection of the monitoring target. The monitoring unit 52 also generates state information indicating that the state of the communication connection of the monitoring target has transitioned to a state in which a Subscribe message has been exchanged, and stores the generated state information in association with the identification information DB in the storage unit 55. The monitoring unit 52 also acquires a reception time tsb1, which is the reception time ts of the frame in which the Subscribe message is stored, by the relay unit 51, and stores the acquired reception time tsb1 in association with the identification information DB in the storage unit 55. The reception time tsb1 corresponds to the time when the state of the communication connection of the monitoring target has transitioned to a state in which a Subscribe message has been exchanged.

[0111] Furthermore, when a SubscribeAck message is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires a service ID from the SOME / IP header of the SubscribeAck message and identifies an identification information DB that matches the acquired service ID from among the identification information DBs stored in the storage unit 55. The monitoring unit 52 then updates the state information corresponding to the identified identification information DB to state information indicating that a transition has occurred to a state in which a SubscribeAck message has been exchanged. The monitoring unit 52 also acquires a reception time tsb2, which is the reception time ts of the frame in which the SubscribeAck message is stored, by the relay unit 51, and stores the acquired reception time tsb2 in the storage unit 55 in association with the identified identification information DB. The reception time tsb2 corresponds to the time at which the state of the communication connection to be monitored transitioned to a state in which a SubscribeAck message has been exchanged.

[0112] Furthermore, when a StopSubscribe message is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires a service ID from the SOME / IP header of the StopSubscribe message and identifies an identification information DB that matches the acquired service ID from among the identification information DBs stored in the storage unit 55. The monitoring unit 52 then updates the state information corresponding to the identified identification information DB to state information indicating that the state has transitioned to a state in which a StopSubscribe message has been exchanged. The monitoring unit 52 also acquires a reception time teb1, which is the reception time te of the frame in which the StopSubscribe message is stored, and stores the acquired reception time teb1 in the storage unit 55 in association with the identified identification information DB. The reception time teb1 corresponds to the time when the state of the communication connection to be monitored transitioned to a state in which a StopSubscribe message has been exchanged.

[0113] The detection unit 53 calculates a period C1B, which is the period C1 during which a SOME / IP connection between the communication device 111A and the communication device 111B is established, based on multiple reception times ts stored in the storage unit 55 by the monitoring unit 52. More specifically, each time the monitoring unit 52 updates the state information in the storage unit 55 and stores a reception time tsb2 in the storage unit 55, the detection unit 53 calculates the period C1B as the difference between the reception time tsb2 and the reception time tsb2 immediately before the reception time tsb2. Note that the detection unit 53 may be configured to calculate the period C1B based on the reception time tsb1 instead of the reception time tsb2. Alternatively, the detection unit 53 may be configured to calculate the period C1B based on the reception time at the relay unit 51 of a frame containing a Notification message when the SOME / IP connection is established.

[0114] For example, the detection unit 53 compares the calculated cycle C1B with predetermined thresholds TcLB and TcHB. Here, the threshold TcLB is assumed to be smaller than the threshold TcHB. For example, the thresholds TcLB and TcHB are set in advance based on the monitoring results of SOME / IP connections established in a normal network 12 where no unauthorized communication connections exist.

[0115] If the period C1B is equal to or greater than the threshold value TcLB and equal to or less than the threshold value TcHB, the detection unit 53 determines that no unauthorized communication connection exists in the network 12. On the other hand, if the period C1B is less than the threshold value TcLB or greater than the threshold value TcHB, the detection unit 53 determines that an unauthorized communication connection exists in the network 12.

[0116] 10 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 10 illustrates a time chart of messages transmitted and received by communication devices 111A and 111B, which are communication devices 111.

[0117] Referring to Figure 10, for example, an unauthorized communication device obtains a service ID from the SOME / IP header in a frame sent by communication device 111A and addressed to communication device 111B, and after communication device 111B sends a Subscribe message, the unauthorized device impersonates communication device 111A and sends a SubscribeAck message to communication device 111B via relay device 101, thereby establishing an unauthorized SOME / IP connection with communication device 111B.

[0118] After establishing a SOME / IP connection with communication device 111B, the unauthorized device transmits an unauthorized message, i.e., an unauthorized Notification message, to communication device 111B via relay device 101. Thereafter, communication device 111B transmits a StopSubscribe message to the unauthorized device via relay device 101, thereby terminating the SOME / IP connection with the unauthorized device.

[0119] Furthermore, the communication device 111A, which is a legitimate server, transmits a SubscribeAck message to the communication device 111B via the relay device 101 in response to the Subscribe message transmitted by the communication device 111B. For example, if the communication device 111B establishes a SOME / IP connection with an unauthorized device by transmitting and receiving a Subscribe message and a SubscribeAck message, and then receives a SubscribeAck message from the communication device 111A in response to the Subscribe message, the communication device 111B ignores the SubscribeAck message received from the communication device 111A and does not establish a SOME / IP connection with the communication device 111A.

[0120] Furthermore, for example, an unauthorized device may masquerade as communication device 111B, which is a client, and send a Subscribe message to communication device 111A via relay device 101. In this case, communication device 111A sends a SubscribeAck message to the unauthorized device via relay device 101, thereby establishing an unauthorized SOME / IP connection between the unauthorized device and communication device 111A. In this case, after establishing a SOME / IP connection with the unauthorized device, communication device 111A sends a Notification message to the unauthorized device via relay device 101.

[0121] When an unauthorized SOME / IP connection is established between an unauthorized device and communication device 111, the number of SubscribeAck messages sent to communication device 111B or the number of SubscribeAck messages sent by communication device 111A increases compared to when an unauthorized SOME / IP connection is not established.

[0122] In this case, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 because the period C1B, which is the difference between the reception time tsb2 of the SubscribeAck message sent from the communication device 111A and the reception time tsb2 of the SubscribeAck message sent from the unauthorized device immediately before the SubscribeAck message, is less than the threshold value TcLB.

[0123] In addition, instead of or in addition to the above-mentioned specific example 4 of the detection process, the detection unit 53 may be configured to calculate the variance of the period C1B and determine whether or not an unauthorized communication connection exists in the network 12 based on the results of comparing the calculated variance with a predetermined threshold value.

[0124] Furthermore, instead of or in addition to the above-mentioned specific example 4 of the detection process, the detection unit 53 may be configured to calculate a frequency F1B, which is the frequency F1 at which a SOME / IP connection is established between the communication device 111A and the communication device 111B, based on multiple reception times tsb2 stored in the memory unit 55 by the monitoring unit 52, and detect the presence of an unauthorized communication connection in the network 12 based on the result of comparing the calculated frequency F1B with a predetermined threshold value.

[0125] Furthermore, instead of or in addition to the above-described specific example 4 of the detection process, the detection unit 53 may be configured to calculate a ratio R1B, which is the ratio R1 of the connection period T1B per unit time, based on the reception time tsb2 and the corresponding reception time teb1 stored in the memory unit 55 by the monitoring unit 52, and detect the presence of an unauthorized communication connection in the network 12 based on the result of comparing the calculated ratio R1B with a predetermined threshold value.

[0126] In addition to the above-described specific example 4 of the detection process, the detection unit 53 may also be configured to detect the presence of an unauthorized communication connection in the network 12 based on the timing of transmission of a request message and a response message conforming to SOME / IP in the network 12.

[0127] More specifically, the communication device 111B transmits a Request message including a server ID and a service ID to the communication device 111A via the relay device 101. In response to the Request message, the communication device 111A transmits a Response message including the server ID and the service ID to the communication device 111B via the relay device 101.

[0128] The monitoring unit 52 in the relay device 101 acquires the reception time of a frame containing a Request message and the reception time of a frame containing a Response message by the relay device 51 and stores them in the storage unit 55. The detection unit 53 calculates a difference D between the reception time of the frame containing the Request message and the reception time of the frame containing the Response message, both of which are stored in the storage unit 55, and detects an unauthorized communication connection in the network 12 based on a comparison result between the calculated difference D and a predetermined threshold. Here, for example, if an unauthorized device, instead of the communication device 111A, transmits a Response message to the communication device 111B via the relay device 101, the difference D calculated by the detection unit 53 will be greater than a normal value by a predetermined value or more, or smaller than the normal value by a predetermined value or more. Therefore, the detection unit 53 can determine whether an unauthorized communication connection exists in the network 12 based on a comparison result between the difference D and the predetermined threshold.

[0129] 11 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 11 shows a time chart of messages transmitted and received by communication devices 111D and 111E, which are communication devices 111.

[0130] 11 , messages are sent and received in accordance with the Data Distribution Service (DDS) in the network 12. A communication device 111 establishes a communication connection for acquiring data from another communication device 111 or a cloud server functioning as a DDS domain. Hereinafter, a communication connection for acquiring data in the DDS is also referred to as a "DDS connection."

[0131] More specifically, the communication device 111E functions as a DDS domain, receives data periodically or irregularly from communication devices 111 other than the communication devices 111D and 111E, and stores the received data.

[0132] When the communication device 111D obtains data related to a certain topic that has been generated using an application corresponding to the topic from the communication device 111E, the communication device 111D generates a create_subscriber message including a topic ID corresponding to the topic, and transmits the generated create_subscriber message to the communication device 111E via the relay device 101. This establishes the nth DDS connection between the communication device 111D and the communication device 111E. The create_subscriber message is an example of a stateful message MS.

[0133] Furthermore, when the communication device 111D terminates the acquisition of data from the communication device 111E, i.e., when the communication device 111D terminates the DDS connection, it transmits a Delete_subscriber message to the communication device 111E via the relay device 101. This terminates the DDS connection between the communication device 111D and the communication device 111E. The Delete_subscriber message is an example of a stateful message ME.

[0134] During connection period T1C, during which a DDS connection with communication device 111D is established, communication device 111E includes the data indicated by the topic ID included in the create_subscriber message in an on_data_available message, which is a message conforming to DDS, and transmits it to communication device 111D via relay device 101.

[0135] Thereafter, in the same manner, the establishment and termination of the DDS connection between the communication device 111D and the communication device 111E is repeated.

[0136] The monitoring unit 52 monitors DDS connections as an example of communication connections established in the network 12. As described above, DDS connections are established using a create_subscriber message and terminated using a delete_subscriber message. For example, the monitoring unit 52 monitors DDS connections established in the network 12 for each topic ID.

[0137] More specifically, if a create_subscriber message is stored in a frame received by the relay unit 51, the monitoring unit 52 determines that a DDS connection is established between the communication device 111 that sent the frame and the communication device 111 that is the destination of the frame.

[0138] The monitoring unit 52 then acquires a topic ID from the header of the create_subscriber message and stores the acquired topic ID in the storage unit 55 as identification information DC that indicates the communication connection being monitored. The monitoring unit 52 also generates state information that indicates that the state of the communication connection being monitored has transitioned to a state in which the create_subscriber message has been exchanged, and stores the generated state information in association with the identification information DC in the storage unit 55. The monitoring unit 52 also acquires a reception time tsc1, which is the reception time ts of the frame in which the create_subscriber message is stored, by the relay unit 51, and stores the acquired reception time tsc1 in association with the identification information DC in the storage unit 55. The reception time tsc1 corresponds to the time at which the state of the communication connection being monitored has transitioned to a state in which the create_subscriber message has been exchanged.

[0139] Furthermore, when a Delete_subscriber message is stored in a frame received by the relay unit 51, the monitoring unit 52 acquires a topic ID from the header of the Delete_subscriber message and identifies identification information DC that matches the acquired topic ID from among the identification information DC stored in the storage unit 55. The monitoring unit 52 then updates the state information corresponding to the identified identification information DC to state information indicating that a transition has occurred to a state in which a Delete_subscriber message has been exchanged. The monitoring unit 52 also acquires a reception time tec1, which is the reception time te of the frame in which the Delete_subscriber message is stored, and stores the acquired reception time tec1 in the storage unit 55 in association with the identified identification information DC. The reception time tec1 corresponds to the time at which the state of the communication connection to be monitored transitioned to a state in which a Delete_subscriber message has been exchanged.

[0140] At a detection timing that follows a predetermined cycle, the detection unit 53 calculates a ratio R1C, which is the ratio R1 of the connection period T1C per unit time, based on the reception time tsc1 and the corresponding reception time tec1 stored in the memory unit 55 by the monitoring unit 52.

[0141] For example, the detection unit 53 compares the calculated ratio R1C with predetermined thresholds TrLC and TrHC. Here, the threshold TrLC is assumed to be smaller than the threshold TrHC. For example, the thresholds TrLC and TrHC are set in advance based on the monitoring results of DDS connections established in a normal network 12 in which no unauthorized communication connections exist.

[0142] If the ratio R1C is equal to or greater than the threshold value TrLC and equal to or less than the threshold value TrHC, the detection unit 53 determines that no unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing. On the other hand, if the ratio R1C is less than the threshold value TrLC or greater than the threshold value TrHC, the detection unit 53 determines that an unauthorized communication connection exists in the network 12 during the period from the previous detection timing to the current detection timing.

[0143] 12 is a diagram illustrating an example of a communication connection operation of a monitoring target of a monitoring unit in a relay device according to an embodiment of the present disclosure. Fig. 12 illustrates a time chart of messages transmitted and received by communication devices 111D and 111E, which are communication devices 111.

[0144] Referring to Figure 12, for example, an unauthorized device obtains a topic ID from the header of a frame sent by communication device 111D to communication device 111E, and establishes an unauthorized DDS connection with communication device 111E by impersonating communication device 111D and sending a create_subscriber message to communication device 111E via relay device 101.

[0145] After establishing a DDS connection with the communication device 111E, the unauthorized device receives an on_data_available message from the communication device 111E and acquires data from the received on_data_available message. Thereafter, the unauthorized device masquerades as the communication device 111D and transmits a Delete_subscriber message to the communication device 111E via the relay device 101, thereby terminating the DDS connection with the communication device 111E.

[0146] For example, if an unauthorized DDS connection is repeatedly established between an unauthorized device and the communication device 111E, the total sum of connection periods T1C per unit time increases compared to when an unauthorized DDS connection is not established.

[0147] In this case, the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection time to the current detection time, since the ratio R1C calculated at the detection time is greater than the threshold value TrHC.

[0148] The detection unit 53 may be configured to determine that an unauthorized communication connection exists in the network 12 when the total value of each connection period T1C exceeds a predetermined value before the unit time has elapsed. Moreover, instead of calculating the ratio R1C at a detection timing according to a predetermined cycle, the detection unit 53 may be configured to calculate the ratio R1C for the most recent unit time of a predetermined length each time the monitoring unit 52 updates the state information in the storage unit 55 and the monitoring unit 52 stores the reception time tsc1 in the storage unit 55.

[0149] Furthermore, instead of or in addition to the above-described specific example 5 of the detection process, the detection unit 53 may be configured to calculate a period C1C, which is the period C1 at which a DDS connection between the communication device 111D and the communication device 111E is established, based on the reception time tsc1 stored in the memory unit 55 by the monitoring unit 52, and to detect the presence of an unauthorized communication connection in the network 12 based on the result of comparing the calculated period C1C with a predetermined threshold value.

[0150] Furthermore, instead of or in addition to the above-mentioned specific example 5 of the detection process, the detection unit 53 may be configured to calculate a frequency F1C, which is the frequency F1 at which a DDS connection is established between the communication device 111D and the communication device 111E, based on multiple reception times tsc1 stored in the memory unit 55 by the monitoring unit 52, and detect the presence of an unauthorized communication connection in the network 12 based on the result of comparing the calculated frequency F1C with a predetermined threshold value.

[0151] Furthermore, the detection unit 53 may be configured not to perform some of the above-described specific examples 1 to 5 of the detection process.

[0152] [Operation Flow] FIG. 13 is a flowchart defining an example of an operation procedure when a relay device according to an embodiment of the present disclosure monitors a communication connection.

[0153] Referring to Figure 13, the relay device 101 waits for the arrival of a frame from the communication device 111 (NO in step S11), and when it receives a frame (YES in step S11), it checks the contents of the message stored in the frame by referring to the header information of the received frame (step S12).

[0154] Next, if the message stored in the received frame is not a stateful message MS such as a SYN packet and SYN / ACK packet according to TCP / IP, a Subscribe message and SubscribeAck message according to SOME / IP, or a create_subscriber message according to DDS, and is not a stateful message ME such as a FIN packet and FIN / ACK packet according to TCP / IP, a StopOffer message and StopSubscribe message according to SOME / IP, or a Delete_subscriber message according to DDS (NO in step S13), the relay device 101 transmits the received frame to the destination communication device 111 (step S14).

[0155] On the other hand, if the message stored in the received frame is a stateful message MS or a stateful message ME (YES in step S13), the relay device 101 determines that the state of the communication connection between the communication device 111 that sent the frame and the communication device 111 that is the destination of the frame has changed, and acquires the identification information DA, DB, and DC that indicate the communication connection to be monitored and the reception time of the frame. The relay device 101 associates the reception time of the frame with the identification information DA, DB, and DC and stores them in the storage unit 55. The relay device 101 also generates or updates state information that indicates that the state of the communication connection to be monitored has changed (step S15).

[0156] Next, the relay device 101 transmits the frame to the destination communication device 111 (step S14).

[0157] Next, the relay device 101 waits for the arrival of a new frame from the communication device 111 (NO in step S11).

[0158] 14 is a flowchart illustrating an example of an operation procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 14 is a flowchart illustrating a specific example 1 of the above-described detection process.

[0159] Referring to Figure 14, the detection unit 53 in the relay device 101 waits for the monitoring unit 52 to update the state information in the memory unit 55 and store the reception time tsa3 in the memory unit 55 (NO in step S21), and when the state information is updated and the reception time tsa3 is stored in the memory unit 55 (YES in step S21), it calculates the difference between the reception time tsa3 and the immediately previous reception time tsa3 corresponding to the same identification information DA as the period C1A (step S22).

[0160] Next, the detection unit 53 compares the calculated period C1A with predetermined thresholds TcLA and TcHA (step S23).

[0161] Next, if the period C1A is equal to or greater than the threshold value TcLA and equal to or less than the threshold value TcHA (YES in step S24), the detection unit 53 determines that no unauthorized communication connection exists in the network 12 (step S25).

[0162] Next, the detection unit 53 waits for the monitoring unit 52 to update the state information in the storage unit 55 and store a new reception time tsa3 in the storage unit 55 (NO in step S21).

[0163] On the other hand, if the period C1A is less than the threshold value TcLA or greater than the threshold value TcHA (NO in step S24), the detection unit 53 determines that an unauthorized communication connection exists in the network 12 (step S26).

[0164] Next, the output unit 54 outputs an alarm to the user's terminal or the like to the effect that an unauthorized communication connection has been detected (step S27).

[0165] Next, the detection unit 53 waits for the monitoring unit 52 to update the state information in the storage unit 55 and store a new reception time tsa3 in the storage unit 55 (NO in step S21).

[0166] 15 is a flowchart illustrating an example of an operation procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 15 is a flowchart illustrating a specific example 2 of the detection process described above.

[0167] Referring to Figure 15, the detection unit 53 in the relay device 101 waits for the arrival of a detection timing according to a predetermined period (NO in step S31), and when the detection timing arrives (YES in step S31), it calculates the number of times the relay unit 51 receives an ACK packet, which is a response to a SYN / ACK packet, within a predetermined unit time period as frequency F1A based on the multiple reception times tsa3 stored in the memory unit 55 (step S32).

[0168] Next, the detection unit 53 compares the calculated frequency F1A with predetermined thresholds TfLA and TfHA (step S33).

[0169] Next, if the frequency F1A is greater than or equal to the threshold value TfLA and less than or equal to the threshold value TfHA (YES in step S34), the detection unit 53 determines that there is no unauthorized communication connection in the network 12 during the period from the previous detection timing to the current detection timing (step S35).

[0170] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S31).

[0171] On the other hand, if the frequency F1A is less than the threshold value TfLA or greater than the threshold value TfHA (NO in step S34), the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection timing to the current detection timing (step S36).

[0172] Next, the output unit 54 outputs an alarm to the user's terminal or the like to the effect that an unauthorized communication connection has been detected (step S37).

[0173] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S31).

[0174] 16 is a flowchart illustrating an example of an operation procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 16 is a flowchart illustrating a specific example 3 of the detection process described above.

[0175] Referring to Figure 16, the detection unit 53 in the relay device 101 waits for the arrival of a detection timing according to a predetermined period (NO in step S41), and when the detection timing arrives (YES in step S41), it calculates the proportion R1A of the connection period T1A per unit time based on the reception time tsa3 and the corresponding reception time tea3 stored in the memory unit 55 (step S42).

[0176] Next, the detection unit 53 compares the calculated ratio R1A with predetermined thresholds TrLA and TrHA (step S43).

[0177] Next, if the ratio R1A is greater than or equal to the threshold value TrLA and less than or equal to the threshold value TrHA (YES in step S44), the detection unit 53 determines that there is no unauthorized communication connection in the network 12 during the period from the previous detection timing to the current detection timing (step S45).

[0178] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S41).

[0179] On the other hand, if the ratio R1A is less than the threshold value TrLA or greater than the threshold value TrHA (NO in step S44), the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection timing to the current detection timing (step S46).

[0180] Next, the output unit 54 outputs an alarm to the user's terminal or the like to the effect that an unauthorized communication connection has been detected (step 47).

[0181] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S41).

[0182] 17 is a flowchart illustrating an example of an operation procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 17 is a flowchart illustrating a specific example 4 of the detection process described above.

[0183] Referring to Figure 17, the detection unit 53 in the relay device 101 waits for the monitoring unit 52 to update the state information in the memory unit 55 and store the reception time tsb2 in the memory unit 55 (NO in step S51), and when the state information is updated and the reception time tsb2 is stored in the memory unit 55 (YES in step S51), it calculates the difference between the reception time tsb2 and the immediately previous reception time tsb2 corresponding to the same identification information DB as the period C1B (step S52).

[0184] Next, the detection unit 53 compares the calculated period C1B with predetermined thresholds TcLB and TcHB (step S53).

[0185] Next, if the period C1B is equal to or greater than the threshold value TcLB and equal to or less than the threshold value TcHB (YES in step S54), the detection unit 53 determines that no unauthorized communication connection exists in the network 12 (step S55).

[0186] Next, the detection unit 53 waits for the monitoring unit 52 to update the state information in the storage unit 55 and store the new reception time tsb2 in the storage unit 55 (NO in step S51).

[0187] On the other hand, if the period C1B is less than the threshold value TcLB or greater than the threshold value TcHB (NO in step S54), the detection unit 53 determines that an unauthorized communication connection exists in the network 12 (step S56).

[0188] Next, the output unit 54 outputs an alarm to the user's terminal or the like to the effect that an unauthorized communication connection has been detected (step S57).

[0189] Next, the detection unit 53 waits for the monitoring unit 52 to update the state information in the storage unit 55 and store the new reception time tsb2 in the storage unit 55 (NO in step S51).

[0190] 18 is a flowchart illustrating an example of an operation procedure when a relay device according to an embodiment of the present disclosure performs a detection process. Fig. 18 is a flowchart illustrating a specific example 5 of the detection process described above.

[0191] Referring to Figure 18, the detection unit 53 in the relay device 101 waits for the arrival of a detection timing according to a predetermined period (NO in step S61), and when the detection timing arrives (YES in step S61), it calculates the proportion R1C of the connection period T1C per unit time based on the reception time tsc1 and the corresponding reception time tec1 stored in the memory unit 55 (step S62).

[0192] Next, the detection unit 53 compares the calculated ratio R1C with predetermined thresholds TrLC and TrHC (step S63).

[0193] Next, if the ratio R1C is greater than or equal to the threshold value TrLC and the ratio R1A is less than or equal to the threshold value TrHC (YES in step S64), the detection unit 53 determines that there is no unauthorized communication connection in the network 12 during the period from the previous detection timing to the current detection timing (step S65).

[0194] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S61).

[0195] On the other hand, if the ratio R1C is less than the threshold value TrLC or greater than the threshold value TrHC (NO in step S64), the detection unit 53 determines that an unauthorized communication connection existed in the network 12 during the period from the previous detection timing to the current detection timing (step S66).

[0196] Next, the output unit 54 outputs an alarm to the user's terminal or the like to the effect that an unauthorized communication connection has been detected (step 67).

[0197] Next, the detection unit 53 waits for a new detection timing to arrive (NO in step S61).

[0198] In the network 12 according to the embodiment of the present disclosure, the relay device 101 functioning as a detection device is directly connected to the transmission line 14, but this is not limiting. The detection device may be connected to the transmission line 14 via the communication device 111. In this case, the detection device detects the presence of an unauthorized communication connection by, for example, monitoring messages sent and received by the communication device 111.

[0199] Furthermore, although the network 12 according to the embodiment of the present disclosure is configured to transmit and receive messages in accordance with TCP / IP, SOME / IP, and DDS, this is not limiting. For example, the network 12 may be configured to transmit and receive messages in accordance with Modbus TCP. In this case, the relay device 101 detects the presence of an unauthorized communication connection by monitoring messages in accordance with Modbus TCP that are transmitted and received by the communication device 111.

[0200] Furthermore, in the relay device 101 according to the embodiment of the present disclosure, the monitor 52 is configured to generate and update state information, but this is not limited to this. The monitor 52 may be configured not to generate and update state information. In other words, the monitor 52 may be configured not to monitor the state transition of the communication connection being monitored. In this case, the monitor 52 acquires the reception time ts of a frame containing a specific message and stores the acquired reception time ts in the memory 55. The detection unit 53 detects the presence of an unauthorized communication connection based on the reception time ts of the specific message.

[0201] More specifically, for example, when a SYN packet is stored in a frame received by relay unit 51, monitoring unit 52 acquires reception time tsa1 of the frame and stores the acquired reception time tsa1 in memory unit 55 in association with identification information DA. Each time monitoring unit 52 stores reception time tsa1 in memory unit 55, detection unit 53 calculates, as a period C1A, the difference between reception time tsa1 and the reception time tsa1 immediately before reception time tsa1, and detects the presence of an unauthorized communication connection based on the multiple periods C1A.

[0202] Alternatively, when a SYN / ACK packet is stored in a frame received by relay unit 51, monitoring unit 52 acquires a reception time tsa2 of the frame and stores the acquired reception time tsa2 in association with identification information DA in storage unit 55. Each time monitoring unit 52 stores a reception time tsa2 in storage unit 55, detection unit 53 calculates a difference between the reception time tsa2 and the reception time tsa2 immediately before the reception time tsa2 as a period C1A, and detects the presence of an unauthorized communication connection based on the multiple periods C1A.

[0203] Alternatively, when a Subscribe message is stored in a frame received by relay unit 51, monitoring unit 52 acquires reception time tsb1 of the frame and stores the acquired reception time tsb1 in association with the identification information DB in storage unit 55. Each time reception time tsb1 is stored in storage unit 55 by monitoring unit 52, detection unit 53 calculates, as a period C1B, the difference between reception time tsb1 and the reception time tsb1 immediately before reception time tsb1, and detects the presence of an unauthorized communication connection based on the multiple periods C1B.

[0204] However, there is a demand for a technology that can more accurately detect the presence of an unauthorized communication connection in the network 12. More specifically, with conventional technology, when an unauthorized device masquerades as a legitimate communication device 111 and establishes an unauthorized communication connection with another communication device 111 using stateful messages MS and ME, it may not be possible to detect the unauthorized communication connection.

[0205] In contrast, in the relay device 101 according to the embodiment of the present disclosure, the monitoring unit 52 monitors communication connections established for exchanging predetermined messages over the network 12. The detection unit 53 detects the presence of an unauthorized communication connection based on the results of monitoring the multiple communication connections by the monitoring unit 52.

[0206] In this way, by configuring to detect the presence of an unauthorized communication connection based on the monitoring results of multiple communication connections, it is possible to determine the presence of an unauthorized communication connection when, for example, the status of communication connections in the network 12 changes due to the establishment of an unauthorized communication connection, thereby making it possible to more accurately detect the presence of an unauthorized communication connection in the network 12.

[0207] Each process (each function) in the above-described embodiments is realized by a processing circuit (circuitry) including one or more processors. The processing circuit may be configured as an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or may execute each of the processes according to a logic circuit designed in advance to execute each of the processes. The processor may be any of various processors suitable for computer control, such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and an ASIC (Application Specific Integrated Circuit). Note that the physically separated processors may cooperate with each other to execute the processes. For example, the processors installed in the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the processes. The program may be installed into the memory from an external server device or the like via the network, or may be distributed in a state stored on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), or a semiconductor memory, and then installed into the memory from the recording medium.

[0208] The above-described embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.

[0209] The above description includes the following additional features: [Supplementary Note 1] A detection device that detects the presence of an unauthorized communication connection in a network, comprising: a monitoring unit that monitors communication connections established for exchanging predetermined messages in the network; and a detection unit that detects the presence of the unauthorized communication connection based on monitoring results of a plurality of the communication connections by the monitoring unit, wherein the monitoring unit monitors a first stateful message that is a message for establishing the communication connection and a second stateful message that is a message for terminating the communication connection.

[0210] [Supplementary Note 2] A detection device for detecting the presence of an unauthorized communication connection in a network, comprising a processing circuit, wherein the processing circuit monitors communication connections established for exchanging predetermined messages in the network, and detects the presence of the unauthorized communication connection based on monitoring results of a plurality of the communication connections.

[0211] 12 Network 14 Transmission line 51 Relay unit 52 Monitoring unit 53 Detection unit 54 Output unit 55 Storage unit 101 Relay device 111, 111A, 111B, 111C, 111D, 111E Communication device

Claims

1. A detection device for detecting the presence of unauthorized communication connections in a network, comprising: a monitoring unit that monitors communication connections established for exchanging a predetermined message in the network; and a detection unit that detects the presence of the unauthorized communication connection based on monitoring results of a plurality of the communication connections by the monitoring unit.

2. The detection device according to claim 1, wherein the detection unit detects the presence of the unauthorized communication connection based on a period at which the communication connection is established.

3. The detection device according to claim 1, wherein the detection unit detects the presence of the unauthorized communication connection based on a frequency at which the communication connection is established.

4. The detection device according to claim 1, wherein the detection unit detects the presence of the unauthorized communication connection based on a ratio of a period during which the communication connection is established to a unit time.

5. The monitoring unit according to any one of claims 1 to 4 monitors the communication connection established using a SubscribeAck message compliant with SOME / IP (Scalable service-Oriented MiddlewarE over IP) and terminated using a StopOffer message or a StopSubscribe message compliant with SOME / IP.

6. The detection device according to any one of claims 1 to 4, wherein the monitoring unit monitors a TCP (Transmission Control Protocol) connection as the communication connection.

7. The detection device according to any one of claims 1 to 4, wherein the monitoring unit monitors the communication connection established using a create_subscriber message compliant with DDS (Data Distribution Service) and terminated using a Delete_subscriber message compliant with DDS.

8. The monitoring unit monitors at least one of a first stateful message that is a stateful message for establishing the communication connection and a second stateful message that is a stateful message for terminating the communication connection, and the detection unit detects the presence of the unauthorized communication connection based on a reception time of the stateful message in the network. The detection device according to claim 1.

9. A detection method in a detection device for detecting the presence of an illegal communication connection in a network, comprising: monitoring a communication connection established for exchanging a predetermined message in the network; detecting the presence of the illegal communication connection based on monitoring results of a plurality of the communication connections.

10. A detection program used in a detection device for detecting the presence of an illegal communication connection in a network, the program causing a computer to function as: a monitoring unit that monitors a communication connection established for exchanging a predetermined message in the network; a detection unit that detects the presence of the illegal communication connection based on monitoring results of a plurality of the communication connections by the monitoring unit. A detection program. ​