Vehicle security analysis system, vehicle security analysis method, and program
The vehicle security analysis system addresses the high resource costs of analyzing sensor log data by selectively analyzing data based on vehicle-specific information, reducing the resources required and improving efficiency even for vehicles without security devices.
Patent Information
- Application Number
- PCT/JP2024/035488
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-03
- Publication Date
- 2025-05-08
AI Technical Summary
The high cost and resource-intensive process of analyzing and processing sensor log data in vehicle security analysis systems, particularly due to the large amount of resources required for analysis, which is not effectively addressed by existing technologies when vehicles without vehicle security devices are analyzed.
A vehicle security analysis system that includes an acquisition unit for acquiring sensor log data, an analysis unit that selectively analyzes sensor log data based on analysis and judgment information corresponding to the vehicle, and an output unit for outputting analysis results, thereby reducing the resources required for analysis.
The system effectively reduces the resources needed for analyzing sensor log data, even when vehicles without vehicle security devices are analyzed, thereby lowering costs and improving efficiency.
Smart Images

Figure JP2024035488_08052025_PF_FP_ABST
Abstract
Description
Vehicle security analysis system, vehicle security analysis method, and program
[0001] The present invention relates to a vehicle security analysis system, a vehicle security analysis method, and a program.
[0002] In order to detect cyber attacks against vehicles such as automobiles, there is a vehicle security analysis system that acquires and analyzes sensor log data related to on-board devices installed in the vehicle.
[0003] In addition, a technology is known in which, in an on-board security device in a vehicle equipped with a specified device, log information of the specified device related to attack information indicating a cyber attack against the specified device is extracted and the extracted log information is transmitted to an attack countermeasure device (see, for example, Patent Document 1).
[0004] Japanese Patent Application Laid-Open No. 2022-089097
[0005] A vehicle security analysis system that acquires and analyzes sensor log data related to on-board devices installed in a vehicle faces the problem of high costs associated with analyzing the sensor log data. In particular, the cost is high because the analytical processing of the acquired sensor log data requires a large number of resources.
[0006] The technology disclosed in Patent Document 1 allows an in-vehicle security device installed in a vehicle to reduce the amount of sensor log data sent to an attack countermeasure device. However, this method cannot solve the above problem if the vehicle to be analyzed does not have the in-vehicle security device.
[0007] It is also possible to implement the technology disclosed in Patent Document 1 on the vehicle security analysis device side, but in this case, the vehicle security analysis device must manage attack information on the onboard devices of multiple vehicles, as well as sensor log information, etc., for the onboard devices.
[0008] As such, with conventional technology, it has been difficult to reduce the resources required for the analytical process of analyzing sensor log data in a vehicle security analysis system that acquires and analyzes sensor log data related to onboard devices installed in a vehicle.
[0009] One embodiment of the present invention has been made in consideration of the above-mentioned problems, and makes it possible to easily reduce the resources required for analyzing sensor log data in a vehicle security analysis system that acquires and analyzes sensor log data related to onboard devices installed in a vehicle.
[0010] In order to solve the above problems, a vehicle security analysis system according to one embodiment of the present invention has an acquisition unit that acquires sensor log data relating to onboard devices installed in a vehicle, an analysis unit that selectively analyzes sensor log data that requires analysis from the sensor log data acquired by the acquisition unit based on analysis determination information corresponding to the vehicle, and an output unit that outputs the analysis results by the analysis unit.
[0011] According to one embodiment of the present invention, in a vehicle security analysis system that acquires and analyzes sensor log data related to onboard devices installed in a vehicle, it becomes possible to easily reduce the resources required for analyzing the sensor log data.
[0012] FIG. 1 is a diagram illustrating an example of the configuration of a vehicle security analysis system according to the present embodiment. FIG. 2 is a diagram for explaining an example of an analysis process according to the present embodiment. FIG. 3 is a diagram illustrating an example of the hardware configuration of a computer according to the present embodiment. FIG. 4 is a diagram illustrating an example of the functional configuration of an SOC server according to the present embodiment. FIG. 5 is a diagram illustrating an example of log data according to the present embodiment. FIG. 6 is a diagram illustrating an example of an analysis logic DB according to the present embodiment. FIG. 7 is a diagram (1) illustrating an example of analysis determination information according to Example 1. FIG. 8 is a diagram (2) illustrating an example of analysis determination information according to Example 1. A flowchart illustrating an example of processing of an SOC server according to Example 1. A flowchart illustrating an example of management processing according to Example 1. A flowchart illustrating an example of determination processing according to Example 1. A flowchart illustrating an example of analysis determination information according to Example 2. A flowchart illustrating an example of management processing according to Example 2. A flowchart illustrating an example of determination processing according to Example 2. A diagram illustrating other examples of analysis determination information and a determination method according to the present embodiment. A flowchart illustrating an example of determination processing according to Example 3.
[0013] Hereinafter, an embodiment of the present invention (the present embodiment) will be described with reference to the drawings. Note that the embodiment described below is an example, and the embodiment to which the present invention is applied is not limited to the following embodiment.
[0014] 1 is a diagram showing an example of the configuration of a vehicle security analysis system according to this embodiment. The vehicle security analysis system 1 includes, for example, a Security Operation Center (SOC) server 10 and a Security Incident Response Team (SIRT) server 40 that can communicate with each other via a communication network.
[0015] The SOC server (vehicle security analysis device) 10 is, for example, an information processing device having a computer configuration, or a system including multiple computers. The SOC server 10 is an example of a vehicle security analysis device that acquires and analyzes sensor log data related to on-board devices 21a, 21b, ... mounted on a vehicle 20 in order to detect cyber-attacks (hereinafter simply referred to as "attacks") against the vehicle 20, such as an automobile. In the following description, the term "on-board device 21" will be used to refer to any of the on-board devices 21a, 21b, ....
[0016] The SOC server 10 performs an analysis process 11 on the acquired sensor log data (hereinafter simply referred to as "log data"), and if it detects an attack on the vehicle 20, it sends a report on the detected attack to the SIRT server 40, etc.
[0017] 1 , the SOC server 10 acquires log data related to the on-board devices 21 mounted on the vehicles 20 from an original equipment manufacturing (OEM) server 30 or the like that collects log data 31 from one or more vehicles 20. However, this is not limited thereto, and the SOC server 10 may acquire log data related to the on-board devices 21 mounted on the vehicles 20 from one or more vehicles 20 without going through the OEM server 30.
[0018] The SOC server 10 can also acquire security information 51 from an external server 50 operated by, for example, Automotive Information Sharing and Analysis Center (Auto-ISAC) or the like via a communication network such as the Internet. This security information 51 includes various cybersecurity information such as cyberthreats and potential vulnerabilities related to connected cars. The SOC server 10 may detect an attack on the vehicle 20 based on the acquired log data 31 and security information 51.
[0019] In addition, the SOC server 10 may have a function to implement temporary measures against the vehicle 20 based on the acquired security information 51 or instructions from the SIRT server 40 when an attack against the vehicle 20 is detected.
[0020] The SIRT server 40 is an information processing device having a computer configuration or a system including multiple computers. The SIRT server 40 is a server operated by an organization (SIRT) that handles security against external threats to the safety of products manufactured and sold by, for example, a vehicle manufacturer or an in-vehicle device manufacturer, in order to ensure the safety of the products manufactured and sold by the manufacturer. The SIRT is also called a Product Security Incident Response Team (PSIRT) or a Computer Security Incident Response Team (CSIRT).
[0021] The SIRT server 40 has a function of, when a response policy determined for each manufacturer is input based on the report transmitted by the SOC server 10, implementing permanent measures including the response policy on the vehicle 20. The SIRT server 40 may also have a function of sharing security information 51 with an external server 50 and instructing the SOC server 10 or the vehicle 20 to take temporary measures on the vehicle 20 based on the security information 51.
[0022] 2 is a diagram illustrating an example of the analysis process according to the present embodiment. The SOC server 10 executes an analysis process 11 in which a plurality of analysis logics 201 are executed on log data 31 related to an in-vehicle device 21 mounted on the vehicle 20.
[0023] The plurality of analysis logics 201 are written for each attack to be detected. For example, if the analysis process 11 detects an attack using analysis logic B among the plurality of analysis logics 201, the SOC server 10 can identify the detected attack based on the description of analysis logic B. Preferably, the SOC server 10 generates a report 202 including information about the detected attack and outputs the generated report 202 to a predetermined output destination such as the SIRT server 40.
[0024] As such, the vehicle security analysis system 1 has the problem of consuming a large amount of resources (computational resources) such as a CPU (Central Processing Unit) and memory, for example, because it executes a large number of analysis logics on the log data to be analyzed.
[0025] To solve the above-mentioned problems, the technology disclosed in Patent Literature 1 has an in-vehicle security device extract log information from a specified device related to attack information indicating a cyber attack against the specified device and transmit the extracted log information to a specified destination. However, this method cannot solve the problem if the vehicle to be analyzed does not have the in-vehicle security device.
[0026] It is also possible to implement the technology disclosed in Patent Document 1 on the SOC server 10 side, but in this case, there is a problem that the SOC server 10 must manage attack information on the on-board devices of multiple vehicles and sensor log information on the on-board devices.
[0027] As such, with conventional technology, it was difficult to reduce the resources required for the analysis process to analyze log data in a vehicle security analysis system 1 that acquires and analyzes log data related to onboard devices installed in a vehicle.
[0028] Therefore, the SOC server 10 according to this embodiment has a function of acquiring log data related to the on-board device 21 mounted on the vehicle 20, and selectively analyzing log data that requires analysis from the acquired log data based on the analysis determination information corresponding to the vehicle 20. As a result, the vehicle security analysis system 1 according to this embodiment can reduce resources required for the analysis process of analyzing log data even if the vehicle 20 to be analyzed does not have the on-board security device disclosed in Patent Document 1.
[0029] Here, the analysis determination information is information for determining whether or not to analyze the acquired log data. The analysis determination information includes, for example, the number of occurrences of log data, the presence or absence of a sensor log that suggests the occurrence of an attack, the state of the vehicle 20, or the presence or absence of a known vulnerability. Specific examples of the analysis determination information will be described later.
[0030] Preferably, when the SOC server 10 acquires the log data, the SOC server 10 determines whether to analyze the acquired log data based on the analysis determination information and the log data. This eliminates the need for the vehicle security analysis system 1 according to the present embodiment to manage attack information on the on-board devices of the multiple vehicles 20, log data of the on-board devices, and the like.
[0031] Thus, according to this embodiment, in the vehicle security analysis system 1 that acquires and analyzes log data (sensor log data) related to the on-board device 21 installed in the vehicle 29, it becomes possible to easily reduce the resources required for the analysis processing of the log data.
[0032] <Hardware Configuration> The SOC server 10, the OEM server 30, the SIRT server 40, the external server 50, etc. described in Fig. 1 have, for example, the hardware configuration of a computer 300 as shown in Fig. 3. Alternatively, the SOC server 10, the OEM server 30, the SIRT server 40, the external server 50, etc. are configured by a plurality of computers 300.
[0033] 3 is a diagram illustrating an example of the hardware configuration of a computer according to an embodiment. The computer 300 includes, for example, a CPU (Central Processing Unit) 301, memory 302, a storage device 303, a network I / F (Interface) 304, an external connection I / F 305, an output device 306, an input device 307, and an internal bus 308.
[0034] The CPU 301 is a processor that realizes various functions by executing programs stored in a storage medium such as the memory 302 or the storage device 303. The memory 302 includes, for example, a random access memory (RAM), which is a volatile memory used by the CPU 301 as a temporary storage area, and a read-only memory (ROM), which is a non-volatile memory that stores programs for starting up the CPU 301. The storage device 303 is, for example, a large-capacity non-volatile storage device such as a solid state drive (SSD) or a hard disk drive (HDD). The network I / F 304 includes one or more communication interfaces for connecting the computer 300 to a communication network.
[0035] The external connection I / F 305 is an interface for connecting an external device to the computer 300. The output device 306 is an output device (e.g., a display, a speaker, or a lamp) that outputs to the outside. The input device 307 is an input device (e.g., a keyboard, a mouse, or a microphone) that receives input from the outside. Note that the input device 307 and the output device 306 may be an integrated input / output device (e.g., a touch panel display). The internal bus 308 is commonly connected to the above components and transmits, for example, address signals, data signals, and various control signals.
[0036] <Functional Configuration> Next, the functional configuration of the vehicle security analysis system 1 according to this embodiment will be described.
[0037] (Functional Configuration of SOC Server) FIG. 4 is a diagram illustrating an example of the functional configuration of the SOC server according to this embodiment. The SOC server 10 realizes, for example, each of the functional configurations illustrated in FIG. 4 by executing a predetermined program on one or more computers 300 included in the SOC server 10. In the example of FIG. 4, the SOC server 10 includes an acquisition unit 401, a management unit 402, a determination unit 403, an analysis unit 404, and an output unit 405. Note that at least a portion of each of the above functional configurations may be realized by hardware.
[0038] In addition, as an example, the SOC server 10 stores an analysis determination information DB (Database) 411, an analysis logic DB 412, etc. in a storage unit such as the storage device 303 in Fig. 3. As another example, the SOC server 10 may use the analysis determination information DB (Database) 411 or the analysis logic DB 412 stored in an external storage server, cloud storage, etc.
[0039] The acquisition unit 401 executes an acquisition process to acquire log data 31 related to the in-vehicle device 21 installed in the vehicle 20. For example, the acquisition unit 401 acquires the log data 31 from an external server such as the OEM server 30 via a communication network. However, the acquisition unit 401 is not limited to this, and may acquire the log data 31 from the vehicle 20 via the communication network.
[0040] 5 is a diagram showing an example of log data according to this embodiment. In the example of FIG. 5, the log data 31 includes information such as "date and time," "vehicle identification number," "SENSOR," "SRC," "DST," etc. The "date and time" is information indicating the date and time when an event that caused the log data 31 was detected, the date and time when the log data 31 was generated, or the date and time when the log data 31 was transmitted. The vehicle identification number is identification information that identifies the vehicle 20, such as a VIN (Vehicle Identification Number).
[0041] "SENSOR", "SRC", "DST", etc. are examples of data included in the log data 31. "SENSOR" is identification information (sensor ID, etc.) that identifies a plurality of on-board devices 21 mounted on the vehicle 20, or a security sensor, etc. "SRC" is identification information (IP address, etc.) that identifies the sender of the communication that caused the generation of the log data 31. "DST" is identification information (IP address, etc.) that identifies the destination of the communication that caused the generation of the log data 31. Now, returning to FIG. 4 , we will continue to explain the functional configuration of the SOC server 10.
[0042] The management unit 402 executes a management process for managing the analysis and determination information corresponding to each vehicle 20. For example, the management unit 402 updates, creates, or acquires the analysis and determination information. Preferably, the management unit 402 associates the analysis and determination information corresponding to each vehicle 20 with the vehicle identification number, and stores and manages the information in the analysis and determination information DB 411 or the like.
[0043] As described above, the analysis determination information is information for determining whether or not to analyze the log data acquired by the acquisition unit 401. The analysis determination information may include various information such as the number of occurrences of log data, the presence or absence of a sensor log suggesting the occurrence of an attack, the state of the vehicle 20, or the presence or absence of a known vulnerability.
[0044] The determination unit 403 executes a determination process to determine, based on the analysis determination information, whether to analyze the log data 31 acquired by the acquisition unit 401. Preferably, when the acquisition unit 401 acquires the log data 31, the determination unit 403 determines, based on the analysis determination information and the acquired log data, whether to analyze the acquired log data 31.
[0045] Specific examples of the analysis determination information and the determination process executed by the determination unit 403 will be described later using several examples.
[0046] The analysis unit 404 executes an analysis process to selectively analyze log data that needs to be analyzed from the log data 31 acquired by the acquisition unit 401, based on the analysis determination information corresponding to the vehicle 20. For example, the analysis unit 404 analyzes the log data 31 that the determination unit 403 has determined to be analyzed based on the analysis determination information, and does not analyze the log data 31 that the determination unit 403 has determined not to analyze.
[0047] As an example, the analysis unit 404 analyzes the log data 31 that the determination unit 403 has determined to be analyzed, using an analysis logic DB 412 as shown in FIG.
[0048] 6 is a diagram showing an example of an analysis logic DB according to this embodiment. As shown in Fig. 6, a plurality of analysis logics 201 are registered in advance in the analysis logic DB 412. The analysis unit 404 analyzes the log data 31 to be analyzed by executing the plurality of analysis logics 201 on the log data 31 that the determination unit 403 has determined to be analyzed.
[0049] As described above, multiple analysis logics 201 are written for each attack to be detected. For example, analysis logic No. 1 indicates that if the value of "SENSOR" in log data 31 is "1" and the value of "DST" is "10.0.0.1," the attack is "T001." Here, "T001" is identification information (such as an attack ID) that identifies the attack.
[0050] Furthermore, the analysis logic of No. 2 indicates that the attack is "T002" when the value of "SENSOR" in the log data 31 is "2" and the value of "SIGNATURE" is "1." Here, "SIGNATURE" is identification information (such as a signature ID) that identifies a signature, which is data used to detect malware, a specific communication pattern, a specific file, or the like.
[0051] The analysis unit 404 executes a plurality of analysis logics 201 on the log data 31 that the determination unit 403 has determined to be analyzed, and if an attack is detected, outputs information about the detected attack as the analysis result.
[0052] The above-described method of analyzing the log data 31 by the analysis unit 404 is an example. In this embodiment, the method of analyzing the log data 31 by the analysis unit 404 may be any other method.
[0053] The output unit 405 executes an output process to output the analysis result by the analysis unit 404 to a predetermined output destination. For example, the output unit 405 transmits the analysis result by the analysis unit 404 (e.g., report 202, etc.) to the SIRT server 40. Note that the report 202 may be generated by the output unit 405 based on the analysis result by the analysis unit 404.
[0054] The functional configuration of the SOC server 10 shown in Fig. 4 is an example. For example, the functional components of the SOC server 10 shown in Fig. 4 may be distributed across multiple devices. In this case, the functional components of the SOC server 10 shown in Fig. 4 may be included in any of the devices included in the vehicle security analysis system 1.
[0055] Furthermore, if the analysis and determination information created or acquired by the management unit 402 is information that does not need to be stored, the SOC server 10 (or the vehicle security analysis system 1) may not have the analysis and determination information DB 411. Furthermore, the management unit 402 may acquire and manage analysis and determination information (e.g., security information 51) that is not based on the log data 31 from an external server 50 or the like.
[0056] 7A and 7B are diagrams illustrating examples of analysis determination information according to Example 1. FIG. 7A illustrates an example of the analysis determination information according to Example 1. For example, as illustrated in FIG. 7A , the management unit 402 manages analysis determination information 701 for each vehicle 20 in association with the vehicle identification number of each of the multiple vehicles 20. FIG. 7A illustrates an example in which the analysis determination information 701 is a count value that counts predetermined events in each vehicle 20.
[0057] 7B shows an example of the analysis determination information 702 when the predetermined event is the number of occurrences of sensor logs (log data 31) that occurred within a predetermined time. For example, when the acquisition unit 401 acquires the log data 31 as shown in FIG. 5, the management unit 402 adds 1 to the "number of occurrences of sensor logs" corresponding to the vehicle identification number in the analysis determination information 702 as shown in FIG. 7B based on the "date and time" and "vehicle identification number" included in the log data 31.
[0058] In addition, if the “number of sensor log occurrences” corresponding to the vehicle identification number in the analysis determination information 702 as shown in FIG. 7B reaches (or exceeds) a predetermined threshold value, the determination unit 403 determines to analyze the log data 31 acquired by the acquisition unit 401.
[0059] As another example, the management unit 402 may manage the amount of log data generated within a predetermined time period as analysis determination information for each vehicle identification number. In this case, the determination unit 403 may determine to analyze the log data 31 acquired by the acquisition unit 401 when the amount of log data 31 corresponding to the vehicle identification number reaches (or exceeds) a predetermined threshold.
[0060] <Processing Flow> Next, a processing flow of the vehicle security analysis method according to the first embodiment will be described.
[0061] (Processing of SOC Server) Fig. 8 is a flowchart illustrating an example of processing of the SOC server according to the embodiment 1. This processing shows an overview of processing executed by the SOC server 10 having the functional configuration shown in Fig. 4, for example.
[0062] In step S801, the acquisition unit 401 acquires, for example, the log data 31 shown in FIG. 5 from the OEM server 30 or the like.
[0063] In step S802, when the acquisition unit 401 acquires the log data 31, the management unit 402 updates or creates analysis determination information, for example, as shown in Fig. 7A or 7B, based on the acquired log data 31. As a specific example, the management unit 402 executes a management process as shown in Fig. 9.
[0064] 9 is a flowchart illustrating an example of a management process according to the embodiment 1. This process represents an example of the management process executed by the management unit 402 in step S802 of FIG.
[0065] In step S901, the management unit 402 extracts the vehicle identification number from the log data 31 acquired by the acquisition unit 401. For example, if the log data 31 acquired by the acquisition unit 401 is the log data 31 shown in FIG. 5 , the acquisition unit 401 extracts the vehicle identification number "JP000000000000005."
[0066] In step S902, the management unit 402 acquires the analysis determination information corresponding to the extracted vehicle identification number. For example, the management unit 402 acquires the analysis determination information "9" corresponding to the vehicle identification number "JP000000000000005" from the analysis determination information as shown in FIG. 7A.
[0067] In step S903, the management unit 402 determines whether analysis determination information is available. For example, if the management unit 402 has acquired analysis determination information corresponding to the vehicle identification number, it determines that analysis determination information is available. If analysis determination information is available, the management unit 402 shifts the process to step S904. On the other hand, if analysis determination information is not available, the management unit 402 shifts the process to step S905.
[0068] In step S904, the management unit 402 updates the analysis determination information. For example, in FIG. 7A, the analysis determination information is the number of occurrences of the log data 31. In this case, the management unit 402 adds 1 to the analysis determination information "9" corresponding to the vehicle identification number "JP000000000000005" to update it to "10."
[0069] On the other hand, when the process proceeds to step S905, the management unit 402 creates new analysis determination information. For example, in FIG. 7A , if analysis determination information corresponding to the vehicle identification number "JP000000000000005" is not registered, the management unit 402 determines that there is no analysis determination information. In this case, the management unit 402 creates new analysis determination information "1" indicating that the log data 31 has occurred once.
[0070] In step S906, the management unit 402 stores the updated or newly created analysis and determination information in the analysis and determination information DB 411 or the like.
[0071] In addition, when the analysis determination information is the analysis determination information as shown in Figure 7B, the management unit 402 updates or creates new analysis determination information for the analysis determination information corresponding to the "date and time" of the log data 31 among the analysis determination information corresponding to the vehicle identification number.
[0072] 8, the description of the processing of the SOC server will be continued. In step S803, the determination unit 403 determines whether or not analysis of the log data 31 acquired by the acquisition unit 401 is necessary, based on the analysis determination information corresponding to the vehicle 20. As a specific example, the determination unit 403 executes a determination process as shown in FIG.
[0073] 10 is a flowchart illustrating an example of the determination process according to the embodiment 1. This process illustrates an example of the determination process executed by the determination unit 403 in step S803 of FIG.
[0074] In step S1001, the determination unit 403 extracts the vehicle identification number from the log data 31 acquired by the acquisition unit 401. The determination unit 403 may acquire the log data 31 acquired by the acquisition unit 401 from the management unit 402 or from the acquisition unit 401.
[0075] In step S1002, the determination unit 403 acquires analysis determination information corresponding to the extracted vehicle identification number. For example, the determination unit 403 acquires analysis determination information corresponding to the vehicle identification number from the analysis determination information shown in FIG. 7A. Here, the acquired analysis determination information indicates the number of occurrences of log data in the vehicle 20 corresponding to the vehicle identification number.
[0076] In step S1003, the determination unit 403 determines whether the number of occurrences of the log data indicated by the acquired analysis determination information is equal to or greater than a predetermined threshold. Here, the threshold is a predetermined number of occurrences of the log data for determining that analysis of the log data 31 is necessary.
[0077] If the number of occurrences of the log data 31 is equal to or greater than the threshold, the determination unit 403 shifts the process to step S1004. On the other hand, if the number of occurrences of the log data 31 is less than the threshold, the determination unit 403 shifts the process to step S1005.
[0078] In step S1004, the determination unit 403 determines that it is necessary to analyze the log data 31 acquired by the acquisition unit 401. On the other hand, in step S1005, the determination unit 403 determines that it is not necessary to analyze the log data 31 acquired by the acquisition unit 401.
[0079] 8, the description of the SOC server process will be continued. In step S804, if the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is necessary, the process proceeds to step S805. On the other hand, if the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is unnecessary, the process in FIG. 8 ends.
[0080] In step S805, the analysis unit 404 executes an analysis process for analyzing the log data 31 acquired by the acquisition unit 401. As a specific example, the analysis unit 404 executes an analysis process as shown in FIG.
[0081] 11 is a flowchart illustrating an example of analysis processing according to Example 1. This processing represents an example of analysis processing executed by the analysis unit 404 in step S805 of FIG.
[0082] In step S1101 , the analysis unit 404 extracts the vehicle identification number from the log data acquired by the acquisition unit 401 .
[0083] In step S1102, the analysis unit 404 acquires an analysis logic group (plurality of analysis logics 201) from, for example, the analysis logic DB 412 shown in FIG.
[0084] In step S1103, the analysis unit 404 selects an unselected analysis logic from the acquired group of analysis logics.
[0085] In step S1104, the analysis unit 404 determines whether there is any unselected analysis logic. For example, if the analysis unit 404 was able to select an unselected analysis logic in step S1103, it determines that there is any unselected analysis logic. If there is any unselected analysis logic, the analysis unit 404 executes the selected analysis logic. On the other hand, if there is no unselected analysis logic, the analysis unit 404 transitions the process to step S1106.
[0086] In step S1105, the analysis unit 404 executes the selected analysis logic on the log data 31 and returns the process to step S1103. Through the processes of steps S1103 to S1105, the analysis unit 404 executes, for example, all analysis logics included in the acquired analysis logic group on the log data 31 acquired by the acquisition unit 401.
[0087] In step S1106, the analysis unit 404 outputs to the output unit the vehicle identification number extracted from the log data 31 acquired by the acquisition unit 401 and the analysis results obtained in steps S1103 to S1105. The analysis results include, for example, information (such as an attack ID) for identifying the attack detected by the analysis logic group.
[0088] Returning to FIG. 8 , the processing of the SOC server will now be further described. In step S806, the output unit 405 outputs the analysis results of the analysis unit 404 to a predetermined output destination. For example, the output unit 405 generates a report 202 including information on the attack detected in the analysis process 11 by the analysis unit 404 and the vehicle identification number of the vehicle 20 in which the attack was detected, and transmits the generated report 202 to the SIRT server 40. Note that the report 202 may be generated in the analysis process 11 by the analysis unit 404, as described in FIG. 2 .
[0089] In the first embodiment, the log data 31 of the vehicle 20 in which the number of occurrences of the log data 31 is less than the threshold is not analyzed, so that the consumption of computational resources by the analysis process 11 can be easily suppressed.
[0090] 12 is a diagram illustrating an example of analysis determination information according to Example 2. As illustrated in Fig. 12 , the management unit 402 according to Example 2 manages, as analysis determination information 1201, information indicating whether or not log data 31 suggesting an attack has occurred, in association with the vehicle identification numbers of multiple vehicles 20.
[0091] 12, "FALSE" in the analysis determination information 1201 indicates that log data 31 strongly suggesting an attack has never been detected in the vehicle 20 corresponding to the vehicle identification number. On the other hand, "TRUE" in the analysis determination information 1201 indicates that log data 31 strongly suggesting an attack has been detected in the vehicle 20 corresponding to the vehicle identification number.
[0092] <Processing Flow> Next, a processing flow of a vehicle security analysis method according to Example 2 will be described. Note that the processing of the SOC server according to Example 2 may be similar to the processing of the SOC server according to Example 1 described with reference to Fig. 8. Furthermore, the analysis processing according to Example 2 may be similar to the analysis processing according to Example 1 described with reference to Fig. 11.
[0093] (Management Processing) Fig. 13 is a flowchart showing an example of management processing according to the second embodiment. This processing shows an example of management processing executed by the management unit 402 in step S802 in Fig. 8, for example. Note that detailed description of processing content similar to the management processing according to the first embodiment described in Fig. 9 will be omitted here.
[0094] In step S1301 , the management unit 402 extracts the vehicle identification number from the log data 31 acquired by the acquisition unit 401 .
[0095] In step S1302, the management unit 402 acquires analysis determination information corresponding to the extracted vehicle identification number. For example, the management unit 402 acquires analysis determination information corresponding to the extracted vehicle identification number from analysis determination information 1201 as shown in FIG.
[0096] In step S1303, the management unit 402 determines whether the log data 31 acquired by the acquisition unit 401 or the acquired analysis determination information contains information suggesting an attack on the vehicle 20. For example, if the log data 31 acquired by the acquisition unit 401 contains information suggesting an attack on the vehicle 20 and / or if the acquired analysis determination information is "TRUE", the management unit 402 determines that there is information suggesting an attack. On the other hand, if the log data 31 acquired by the acquisition unit 401 does not contain information suggesting an attack on the vehicle 20 and the acquired analysis determination information is "FALSE", the management unit 402 determines that there is no information suggesting an attack.
[0097] If there is information suggesting an attack, the management unit 402 shifts the process to step S1304. On the other hand, if there is no information suggesting an attack, the management unit 402 shifts the process to step S1305.
[0098] When proceeding to step S1304, the management unit 402 stores information indicating that there has been information suggesting an attack on the vehicle 20 ("TRUE" in the example of Figure 12) in the analysis determination information 1201 corresponding to the vehicle identification number of the vehicle 20.
[0099] On the other hand, when the process proceeds to step S1305, the management unit 402 stores information indicating that there has been no information suggesting an attack on the vehicle 20 ("FALSE" in the example of FIG. 12 ) in the analysis determination information 1201 corresponding to the vehicle identification number of the vehicle 20. Note that the management unit 402 may omit the process of step S1305 and maintain the analysis determination information corresponding to the vehicle identification number of the vehicle 20.
[0100] 13, the management unit 402 can store and manage, for example, the analysis determination information as shown in FIG. 12 in the analysis determination information DB 411 or the like.
[0101] (Determination Process) Fig. 14 is a flowchart showing an example of the determination process according to the second embodiment. This process shows an example of the determination process executed by the determination unit 403 in step S803 in Fig. 8. Note that detailed description of the process content similar to the determination process according to the first embodiment described in Fig. 10 will be omitted here.
[0102] In step S1401 , the determination unit 403 extracts the vehicle identification number from the log data 31 acquired by the acquisition unit 401 .
[0103] In step S1402, the determination unit 403 acquires analysis determination information corresponding to the extracted vehicle identification number. For example, the determination unit 403 acquires analysis determination information corresponding to the extracted vehicle identification number from analysis determination information 1201 as shown in FIG.
[0104] In step S1403, the determination unit 403 determines whether the acquired analysis determination information is "TRUE." If the acquired analysis determination information is "TRUE," the determination unit 403 shifts the process to step S1404. On the other hand, if the acquired analysis determination information is not "TRUE" (if it is "FALSE"), the determination unit 403 shifts the process to step S1405.
[0105] In step S1404, the determination unit 403 determines that it is necessary to analyze the log data 31 acquired by the acquisition unit 401. On the other hand, in step S1405, the determination unit 403 determines that it is not necessary to analyze the log data 31 acquired by the acquisition unit 401.
[0106] In this way, in Example 2, analysis of log data 31 of a vehicle 20 in which information suggesting an attack has not been detected to date is not performed, so that the consumption of computational resources by the analysis process 11 can be easily suppressed.
[0107] (Other Examples of Analysis and Determination Information) The analysis and determination information described in Examples 1 and 2 is an example. The vehicle security analysis system 1 may determine whether to analyze the log data 31 acquired by the acquisition unit 401 using various other analysis and determination information, for example, as shown in FIG.
[0108] FIG. 15 is a diagram illustrating another example of analysis and determination information according to this embodiment. As an example, the vehicle security analysis system 1 may use the "amount of sensor log data per unit time for each vehicle" as the analysis and determination information, as shown in FIG. 15 . In this case, the management unit 402 manages the "amount of sensor log data" in association with the vehicle identification information of each vehicle 20, instead of the "number of sensor log occurrences" in the analysis and determination information as shown in FIG. 7B . Furthermore, if the "amount of sensor log data" in the analysis and determination information is equal to or greater than a threshold, the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is necessary. On the other hand, if the "amount of sensor log data" in the analysis and determination information is less than the threshold, the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is unnecessary. The threshold may be a statistical quantity (such as variance) rather than an absolute value.
[0109] As another example, the vehicle security analysis system 1 may use "whether the vehicle is in operation" as the analysis determination information, as shown in FIG. 15 . In this case, the management unit 402 may acquire information indicating whether the vehicle 20 is in operation from an external vehicle management system that manages the status of the vehicle 20, the vehicle 20, or the like. Alternatively, the management unit 402 may acquire information indicating whether the vehicle 20 is in operation from the log data 31. Furthermore, when the vehicle 20 is in operation, the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is necessary. On the other hand, when the vehicle 20 is not in operation, the determination unit 403 determines that analysis of the log data 31 acquired by the acquisition unit 401 is unnecessary. This is based on the premise that even if the vehicle 20 is attacked when it is not in operation, the impact is not endangering the driver's life and is therefore acceptable.
[0110] 15 , the vehicle security analysis system 1 may use "vehicle location" as the analysis determination information. In this case, the management unit 402 may acquire location information indicating the location of the vehicle 20 from an external vehicle management system that manages the status of the vehicle 20, or from the vehicle 20 itself. Alternatively, the management unit 402 may acquire location information indicating the location of the vehicle 20 from the log data 31.
[0111] For example, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is unnecessary when the vehicle 20 is at a production base, a maintenance base, or the like for the vehicle 20. This is based on the premise that even if the vehicle 20 is attacked when it is not in operation, the impact is not at risk to the driver's life and is therefore acceptable. It is also assumed that various log data 31 that are not generated during normal use are generated during production or maintenance work.
[0112] Alternatively, when the vehicle 20 is in a predetermined location (for example, a country or a region), the determination unit 403 may determine that it is necessary to analyze the log data 31 acquired by the acquisition unit 401. This is based on the premise that the presence or absence of an attack varies depending on the region.
[0113] As another example, as shown in FIG. 15 , the vehicle security analysis system 1 may use “whether the vehicle is connected to the outside” as the analysis determination information. In this case, the management unit 402 may acquire information indicating whether the vehicle 20 is connected to an external network (such as the Internet or V2X) or an external device (such as a diagnostic device) from an external vehicle management system that manages the status of the vehicle 20, or from the vehicle 20 itself. Alternatively, the management unit 402 may acquire information indicating whether the vehicle 20 is connected to the outside from the log data 31. Note that V2X stands for “Vehicle to everything” and is a general term for technologies that enable communication and cooperation between the vehicle 20 and something (such as another vehicle, pedestrian, infrastructure, or network). In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary if the vehicle 20 is connected to the outside. This is based on the premise that attacks against the vehicle 20 are mostly external threats and that other threats are acceptable.
[0114] 15, the vehicle security analysis system 1 may use a "time period or period" as the analysis determination information. In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary (or unnecessary), for example, during a specific time period or period. This is based on the premise that attacks against the vehicle 20 are likely (or unlikely) to occur during a specific time period or a specific period (such as during a long holiday).
[0115] As another example, the vehicle security analysis system 1 may use "occurrence of a campaign" as the analysis and determination information, as shown in FIG. 15 . Here, a campaign includes, for example, information indicating that an attack is occurring against a specific vehicle type, etc. In this case, the management unit 402 may acquire information indicating whether or not a campaign is occurring from, for example, the external server 50 or the SIRT server 40. Furthermore, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary when a campaign is occurring against a vehicle type, etc. corresponding to the vehicle 20. Similarly, the vehicle security analysis system 1 may use "vehicle type" as the analysis and determination information.
[0116] As another example, the vehicle security analysis system 1 may use "owner attributes" as the analysis and determination information, as shown in FIG. 15 . In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary when the vehicle 20 is owned by an owner with specific attributes. This is based on the premise that an attack targeting an owner with specific attributes will occur. Similarly, the vehicle security analysis system 1 may use "driver or passenger attributes" as the analysis and determination information.
[0117] As another example, the vehicle security analysis system 1 may use "presence or absence of known vulnerabilities" as the analysis determination information, as shown in Fig. 15. In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary when the vehicle 20 has a known vulnerability.
[0118] As another example, the vehicle security analysis system 1 may use "whether the vehicle is a modified vehicle" as the analysis determination information, as shown in FIG. 15. In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is unnecessary if the vehicle 20 is a modified vehicle. This is because it is assumed that a vehicle 20 with a configuration that differs from the standard configuration has a low success rate of attack. Also, modified vehicles may be excluded from the analysis target of the vehicle security analysis system 1.
[0119] As another example, the vehicle security analysis system 1 may use the "version of the installed software" as the analysis determination information, as shown in Fig. 15. In this case, the determination unit 403 may determine that analysis of the log data 31 acquired by the acquisition unit 401 is necessary (or unnecessary) when the version of the software installed in the vehicle 20 is a specific version.
[0120] The vehicle security analysis system 1 may combine the above-mentioned multiple pieces of analysis determination information to determine whether or not analysis of the log data 31 acquired by the acquisition unit 401 is necessary.
[0121] 16 is a flowchart showing an example of a determination process according to a third embodiment. This process shows an example of an analysis process in which the analysis determination information includes two items: "the number of occurrences of log data" and "whether or not the vehicle is connected to an external device."
[0122] The processing of the SOC server according to the third embodiment may be similar to the processing of the SOC server according to the first embodiment described with reference to Fig. 8. The management processing according to the third embodiment may be similar to the management processing according to the first embodiment described with reference to Fig. 9. The analysis processing according to the third embodiment may be similar to the analysis processing according to the first embodiment described with reference to Fig. 11.
[0123] 16 is the same as the determination process according to the first embodiment described with reference to Fig. 10, and therefore will not be described here. Also, detailed description of the process contents that are the same as the determination process according to the first embodiment will be omitted here.
[0124] In step S1601, the determination unit 403 determines whether the number of occurrences of the log data indicated by the acquired analysis determination information is equal to or greater than a predetermined threshold. If the number of occurrences of the log data 31 is equal to or greater than the threshold, the determination unit 403 shifts the process to step S1602. On the other hand, if the number of occurrences of the log data 31 is less than the threshold, the determination unit 403 shifts the process to step S1603.
[0125] In step S1602, the determining unit 403 determines that the log data 31 acquired by the acquiring unit 401 needs to be analyzed.
[0126] On the other hand, when the process proceeds to step S1603, the determination unit 403 determines whether the vehicle 20 is connected to the outside (an external network or an external device). If the vehicle 20 is connected to the outside, the determination unit 403 proceeds to step S1602. On the other hand, if the vehicle 20 is not connected to the outside, the determination unit 403 proceeds to step S1604.
[0127] In step S1604, the determining unit 403 determines that analysis of the log data 31 acquired by the acquiring unit 401 is unnecessary.
[0128] In this way, the determination unit 403 may combine a plurality of pieces of analysis determination information to determine whether or not analysis of the log data 31 acquired by the acquisition unit 401 is necessary.
[0129] As described above, according to this embodiment, in the vehicle security analysis system 1 that acquires and analyzes sensor log data related to the on-board device 21 installed in the vehicle 20, it becomes possible to easily reduce the resources required for analyzing the sensor log data.
[0130] Summary of Embodiments This specification discloses at least the vehicle security analysis system, vehicle security analysis method, and program of the following paragraphs: (1) A vehicle security analysis system comprising: an acquisition unit that acquires sensor log data related to an on-board device mounted on a vehicle; an analysis unit that selectively analyzes sensor log data that requires analysis from the sensor log data acquired by the acquisition unit based on analysis determination information corresponding to the vehicle; and an output unit that outputs the analysis result by the analysis unit. (2) The vehicle security analysis system described in paragraph 1, further comprising: a determination unit that, when the acquisition unit acquires the sensor log data, determines whether or not to analyze the sensor log data acquired by the acquisition unit based on the analysis determination information and the sensor log data. (3) The vehicle security analysis system described in paragraph 1 or 2, further comprising: a determination unit that determines whether or not to analyze the sensor log data acquired by the acquisition unit based on the vehicle state, wherein the analysis determination information includes information indicating the state of the vehicle. (4) The vehicle security analysis system according to any one of paragraphs 1 to 3, wherein the analysis determination information includes information on the number of occurrences of the sensor log data in the vehicle, and wherein the analysis unit does not analyze the sensor log data acquired by the acquisition unit if the number of occurrences does not reach a threshold. (5) The vehicle security analysis system according to any one of paragraphs 1 to 4, wherein the analysis unit does not analyze the sensor log data acquired by the acquisition unit if the vehicle is not in operation. (6) The vehicle security analysis system according to any one of paragraphs 1 to 3, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit if the vehicle is connected to an external network or an external device. (7) The vehicle security analysis system according to any one of paragraphs 1 to 3, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit if the vehicle has a known vulnerability. (8) The vehicle security analysis system according to any one of paragraphs 1 to 3, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit if an attack has occurred against the same vehicle model as the vehicle.(Item 9) A vehicle security analysis method in which a computer executes the following: an acquisition process to acquire sensor log data related to an on-board device mounted on a vehicle, an analysis process to selectively analyze sensor log data that needs to be analyzed from the sensor log data acquired in the acquisition process based on analysis determination information corresponding to the vehicle, and an output process to output the analysis results from the analysis process. (Item 10) A program that causes a computer to execute the following: an acquisition process to acquire sensor log data related to an on-board device mounted on a vehicle, an analysis process to selectively analyze sensor log data that needs to be analyzed from the sensor log data acquired in the acquisition process based on analysis determination information corresponding to the vehicle, and an output process to output the analysis results from the analysis process.
[0131] Although one embodiment of the present invention has been described in detail above, the present invention can be modified and applied in various ways within the scope of the gist described in the claims.
[0132] This application claims priority from basic application No. 2023-186501, filed with the Japan Patent Office on October 31, 2023, the entire contents of which are incorporated herein by reference.
[0133] REFERENCE SIGNS LIST 1 Vehicle security analysis system 10 SOC server (vehicle security analysis device) 20 Vehicle 21, 21a, 21b In-vehicle device 31 Log data (sensor log data) 300 Computer 401 Acquisition unit 402 Management unit 403 Determination unit 404 Analysis unit 405 Output unit 411 Analysis determination information DB 412 Analysis logic DB 701, 702, 1201 Analysis determination information
Claims
1. A vehicle security analysis system comprising: an acquisition unit that acquires sensor log data relating to an on-board device installed in a vehicle; an analysis unit that selectively analyzes sensor log data that requires analysis from the sensor log data acquired by the acquisition unit based on analysis determination information corresponding to the vehicle; and an output unit that outputs the analysis results by the analysis unit.
2. A vehicle security analysis system as described in claim 1, further comprising a judgment unit that, when the acquisition unit acquires the sensor log data, judges whether or not to analyze the sensor log data acquired by the acquisition unit based on the analysis judgment information and the sensor log data.
3. A vehicle security analysis system as described in claim 1, wherein the analysis and judgment information includes information indicating the state of the vehicle, and the system has a judgment unit that judges whether or not to analyze the sensor log data acquired by the acquisition unit based on the state of the vehicle.
4. A vehicle security analysis system as described in claim 1, wherein the analysis determination information includes information on the number of times the sensor log data occurred in the vehicle, and the analysis unit does not analyze the sensor log data acquired by the acquisition unit if the number of times the sensor log data occurred does not reach a threshold value.
5. A vehicle security analysis system as described in any one of claims 1 to 4, wherein the analysis unit does not analyze the sensor log data acquired by the acquisition unit when the vehicle is not in motion.
6. A vehicle security analysis system as described in any one of claims 1 to 4, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit when the vehicle is connected to an external network or external device.
7. A vehicle security analysis system as described in any one of claims 1 to 4, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit if the vehicle has a known vulnerability.
8. A vehicle security analysis system as described in any one of claims 1 to 4, wherein the analysis unit analyzes the sensor log data acquired by the acquisition unit when an attack has occurred against the same vehicle model as the vehicle.
9. A vehicle security analysis method in which a computer executes the following steps: an acquisition process for acquiring sensor log data relating to an on-board device installed in a vehicle; an analysis process for selectively analyzing sensor log data that requires analysis from the sensor log data acquired in the acquisition process based on analysis determination information corresponding to the vehicle; and an output process for outputting the analysis results obtained by the analysis process.
10. A program that causes a computer to execute the following: an acquisition process for acquiring sensor log data related to an on-board device installed in a vehicle; an analysis process for selectively analyzing sensor log data that requires analysis from the sensor log data acquired in the acquisition process based on analysis determination information corresponding to the vehicle; and an output process for outputting the analysis results obtained by the analysis process.
Citation Information
Patent Citations
On-vehicle security device, vehicle security system, and vehicle management method
JP2022089097A
Vehicle security analysis system, vehicle security analysis method, and program
JP2025075386A
Object detection during vehicle parking
US20150266509A1
Vehicle security analysis device, method, and program thereof
WO2023048185A1
Vehicle security analysis device and method, and program therefor
WO2023048187A1