Intrusion detection system
The intrusion detection system addresses the high processing load and log recording challenges by using a switch unit to analyze frames and add option information, and information processing units for storage and processing, resulting in improved security and reduced costs.
Patent Information
- Application Number
- PCT/JP2023/045246
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-18
- Publication Date
- 2025-06-26
AI Technical Summary
Existing intrusion detection systems face challenges in reducing the processing load for abnormal frame determination in switches and lack efficient log recording mechanisms, leading to increased costs and complexity.
The proposed intrusion detection system incorporates a switch unit that analyzes frames based on headers, determines abnormality, and adds option information for further processing, while also including information processing units for storage and intrusion detection processing.
This solution reduces the processing load for abnormality determination in switches and enables efficient storage and processing of abnormal frames, thereby enhancing security and reducing the risk of Denial of Service attacks.
Smart Images

Figure JP2023045246_26062025_PF_FP_ABST
Abstract
Description
Intrusion Detection System
[0001] TECHNICAL FIELD This disclosure relates to intrusion detection systems.
[0002] In the technology of Patent Document 1, a terminal device includes a switch that serves as a gateway for communication and controls the communication path, and a microcomputer that communicates with the switch and transmits control information for the switch. The switch analyzes not only the Layer 2 header that defines the source and destination of the communication frame, but also the Layer 3 and Layer 4 headers, and transmits the analysis results to the microcomputer. Based on the received analysis results, the microcomputer generates control information for the switch and transmits it to the switch. Based on the received control information, the switch determines whether to forward the communication frame to the terminal device or to hold it.
[0003] International Publication No. 2018 / 105197
[0004] However, the technology in Patent Document 1 expands the functionality of the switch, making it more sophisticated. However, increasing the functionality of the switch requires high-performance hardware that can realize the functionality, which increases costs. Furthermore, the technology in Patent Document 1 does not disclose how to record logs.
[0005] Therefore, an object of the present disclosure is to provide an intrusion detection system that can reduce the processing load of determining frame anomalies in a switch and store the sending and receiving status of frames containing anomalies on the information processing device side.
[0006] a frame receiving unit that receives the frame; a filtering unit that determines whether or not the received frame has an abnormality based on the header included in the received frame; an option adding unit that adds optional information to the frame when it is determined that there is an abnormality, including the abnormality determination result, whether or not information storage is required, and whether or not intrusion detection processing is required; and a frame transmitting unit that transmits the frame after processing by the filtering unit and the option adding unit to the destination of the header included in the frame; and at least one specific information processing unit comprises: a frame receiving unit that receives the frame transmitted from the switch unit; and an information storage unit that, when the received frame includes the optional information and the information storage is required, stores the abnormality determination result and information about the received frame included in the optional information in a storage device of the specific information processing unit; and an intrusion detection processing unit that, when the received frame includes the option information and the intrusion detection processing is necessary, performs the intrusion detection processing on the received frame.
[0007] a frame receiving unit that receives the frames; a filtering unit that determines whether or not the received frames have an abnormality based on the headers included in the received frames; a counting unit that counts the number of abnormality determinations per determination period for abnormal frames having the same headers as the source and destination; an abnormality storage unit that stores the number of abnormality determinations per determination period and information on abnormal headers, which are the headers corresponding to the number of abnormality determinations per determination period, in a storage device of the switch unit; and a frame sending unit that discards the abnormal frames and does not send them to the destination of the headers included in the abnormal frames, sends the frames that are determined to be normal to the destination of the headers included in the normal frames, and sends the number of abnormality determinations per determination period and the information on the abnormal headers stored in the storage device of the switch unit to the destination of the abnormal header, At least one of the specific information processing units includes a frame receiving unit that receives the frame transmitted from the switch unit, as well as information on the number of abnormality determinations per determination period and the abnormal header, and an information storage unit that stores the number of abnormality determinations per determination period and the abnormal header information in a storage device of the specific information processing unit.
[0008] According to the first intrusion detection system of the present disclosure, the switch unit determines whether a frame has an abnormality based on information with a small header, thereby reducing the processing load of the abnormality determination process on the switch unit. Furthermore, when the switch unit determines that an abnormality exists, optional information including the abnormality determination result, whether information storage is required, and whether intrusion detection processing is required is added to the frame and transmitted. Therefore, a specific information processing unit can appropriately store the transmission and reception status of the abnormal frame according to need, and can appropriately perform intrusion detection processing on the abnormal frame according to need.
[0009] According to the second intrusion detection system of the present disclosure, the switch unit determines whether a frame has an anomaly based on information with little header information, thereby reducing the processing load of the anomaly determination process on the switch unit. Furthermore, the switch unit discards anomaly-containing frames and does not transmit them to the destination of the header contained in the anomaly-containing frame, thereby preventing a large number of anomaly-containing frames from being transmitted to the destination's information processing unit due to a denial of service (DoS) attack, and preventing the destination's information processing unit from being infiltrated by anomaly-containing frames. Therefore, the security of the destination's information processing unit can be prevented from being compromised by anomaly-containing frames. Meanwhile, for anomaly-containing frames, the number of anomaly determinations per determination period and information on the anomaly header are transmitted to the destination of the anomaly header, allowing a specific destination's information processing unit to store the transmission and reception status of the anomaly-containing frame.
[0010] 1 is a schematic configuration diagram of an intrusion detection system according to a first embodiment. FIG. 2 is a schematic block diagram of a main part of the intrusion detection system according to the first embodiment. FIG. 3 is a schematic hardware configuration diagram of a switch unit according to the first embodiment. FIG. 4 is a diagram for explaining the addition of option information to a frame according to the first embodiment. FIG. 5 is a diagram for explaining necessity determination using a deny list method according to the first embodiment. FIG. 6 is a diagram for explaining necessity determination using a permit list method according to the first embodiment. FIG. 7 is a diagram for explaining necessity determination when there is no abnormality according to the first embodiment. FIG. 8 is a schematic hardware configuration diagram of a specific information processing unit according to the first embodiment. FIG. 9 is a flowchart for explaining the processing of the switch unit according to the first embodiment. FIG. 10 is a flowchart for explaining the processing of the specific information processing unit according to the first embodiment. FIG. 11 is a schematic block diagram of a main part of an intrusion detection system according to a second embodiment. FIG. 12 is a flowchart for explaining the processing of the switch unit according to the second embodiment. FIG. 13 is a flowchart for explaining the processing of the specific information processing unit according to the second embodiment. FIG. 14 is a schematic block diagram of a main part of an intrusion detection system according to a third embodiment. FIG. 15 is a flowchart for explaining the processing of the specific information processing unit according to the third embodiment.
[0011] 1. First Embodiment An intrusion detection system 1 according to a first embodiment will be described with reference to the drawings. 1 and 2 show a schematic configuration diagram of the intrusion detection system 1.
[0012] The intrusion detection system 1 includes a plurality of information processing units 10 and a switch unit 30. At least one information processing unit 10 (in this example, one information processing unit 10) is designated as a specific information processing unit 20. For example, the specific information processing unit 20 may be set as an information processing unit that requires security management among the plurality of information processing units 10.
[0013] In this embodiment, each information processing unit 10 is an information processing device, and the switch unit 30 is a switch device. For example, the information processing devices may include a communication device that performs wireless or wired communication with an external device, a control device that controls various control targets, and an information processing device that performs various information processing.
[0014] The network (communication path) connecting the multiple information processing units 10 and the switch unit 30 is a network using a communication protocol such as Ethernet, CAN (Controller Area Network), or IP (Internet Protocol). The network connected to the switch unit 30 may be different for each information processing unit 10, and the communication protocol may be different for each information processing unit 10. For example, Ethernet is used for the first network connecting the first information processing unit 10 and the switch unit 30, CAN is used for the second network connecting the second and third information processing units 10 and the switch unit 30, and CAN is used for the third network connecting the fourth information processing unit 10 and the switch unit 30.
[0015] In this disclosure, a frame refers to a communication unit of data communicated over a network. Generally, it is called a frame or a packet depending on the communication protocol, but in this disclosure, they refer to the same thing.
[0016] In this embodiment, the intrusion detection system 1 is mounted on a vehicle, and the information processing units 10 and the switch unit 30 are connected by a local network (on-board network) within the vehicle.
[0017] 1-1. Switch Unit 30 The switch unit 30 switches communication paths and transmits and receives frames between a plurality of information processing units 10 based on headers included in the frames that identify the source and destination information processing units 10. In this embodiment, the switch unit 30 is a gateway device that relays communications between a plurality of information processing units 10.
[0018] The switch unit 30 includes a frame receiving unit 31, a filtering unit 32, an option adding unit 33, and a frame transmitting unit .
[0019] As shown in FIG. 3 , the switch unit 30 includes an arithmetic processing unit 90, a storage device 91, and a communication device 92. The arithmetic processing unit 90 may be a central processing unit (CPU), an integrated circuit (IC), a field programmable gate array (FPGA), or other such arithmetic processing unit. The storage device 91 may be a volatile memory or a nonvolatile memory. The storage device 91 may be provided inside the arithmetic processing unit 90. The communication device 92 is connected to a network and communicates with each information processing unit 10. When multiple networks are connected, multiple communication devices 92 are provided. The functions of the frame receiving unit 31, filtering unit 32, option assigning unit 33, frame transmitting unit 34, and other components of the switch unit 30 are realized by the cooperation of the hardware components of the arithmetic processing unit 90, storage device 91, and communication device 92. When the arithmetic processing unit 90 includes a CPU, the CPU executes programs stored in the storage device 91 to realize the functions.
[0020] 1-1-1 Frame Receiving Unit 31 The frame receiving unit 31 receives frames from each information processing unit 10.
[0021] The frame is a communication frame, which is the smallest unit of data communicated over the network connecting each information processing unit 10 and the switch unit 30, as described above.
[0022] 4, a frame has a payload of the data body and a header that identifies the information processing units of the sender and destination (MAC addresses in the case of Ethernet), etc. In this embodiment, option information is added to the frame by the option adding unit 33, as will be described later.
[0023] 1-1-2. Filtering Unit 32 The filtering unit 32 determines whether or not there is an abnormality in the received frame based on the header included in the received frame.
[0024] According to this configuration, the presence or absence of an abnormality in a frame is determined based on a small amount of information in the header, thereby reducing the processing load of the abnormality determination process.
[0025] For example, the filtering unit 32 determines whether or not there is an abnormality in the received frame based on the source and destination of the header included in the received frame. Note that the filtering unit 32 may also determine whether or not there is an abnormality in the received frame based on various communication information included in the header, such as a virtual local area network (VLAN) or a priority code point (PCP).
[0026] In this embodiment, the filtering unit 32 determines whether or not there is an abnormality using one or both of a reject list method and a permit list method.
[0027] The reject list method uses a reject list in which combinations of senders (sender MAC addresses) and destinations (destination MAC addresses) that should not be sent or received are registered in advance. When the reject list method is used, the filtering unit 32 determines that there is an abnormality in the received frame if the combination of sender and destination in the header included in the received frame corresponds to a combination of sender and destination registered in the reject list, and otherwise determines that there is no abnormality in the received frame.
[0028] It is conceivable that a sender not registered on the reject list may be subject to infringement such as "spoofing" or "tampering" and send an abnormal frame to a destination not registered on the reject list. Even if the filtering unit 32 determines that a received frame is normal using the reject list method, it may ultimately determine that the received frame is abnormal if the number of times frames with the same source and destination headers that were determined to be normal per determination period is equal to or exceeds a threshold. Note that the number of times the frame is received may be counted as the number of times frames with the same source and destination headers that were determined to be normal per determination period, regardless of whether or not there is an abnormality. The same applies hereinafter.
[0029] The permission list method uses a pre-registered permission list of combinations of senders (sender MAC addresses) and destinations (destination MAC addresses) that are permitted to send and receive. When the permission list method is used, the filtering unit 32 determines that there is no abnormality in the received frame if the combination of sender and destination in the header included in the received frame corresponds to a combination of sender and destination registered in the permission list, and otherwise determines that there is an abnormality in the received frame.
[0030] It is conceivable that a sender registered on the allow list may be compromised by "spoofing," "tampering," or the like, and send an abnormal frame to a destination registered on the allow list. Even if the filtering unit 32 determines that a received frame is not abnormal using the allow list method, it may ultimately determine that the received frame is abnormal if the number of times per determination period that a frame having the same sender and destination header as the one determined to be normal is equal to or exceeds a threshold.
[0031] When both the reject list method and the allow list method are used, the filtering unit 32 finally determines that the received frame contains an abnormality if the reject list method determines that the received frame contains an abnormality, and finally determines that the received frame contains no abnormality if the allow list method determines that the received frame does not contain an abnormality. When the filtering unit 32 determines that the received frame does not contain an abnormality using the reject list method and also determines that the received frame contains an abnormality using the allow list method, the filtering unit 32 may finally determine that the received frame contains an abnormality, or may finally determine that the received frame does not contain an abnormality.
[0032] Even if the filtering unit 32 determines that there is no abnormality in the received frame, it may determine that there is an abnormality in the received frame if the number of times a frame having the same source and destination header as those determined to be normal is received per determination period is greater than or equal to a threshold value.
[0033] Alternatively, without using the reject list method or the allow list method, the filtering unit 32 may determine that there is an abnormality in the received frame if the number of times a frame with the same source and destination header is received per determination period is equal to or greater than a threshold, and may determine that there is no abnormality in the received frame if the number of times it is received is less than the threshold.
[0034] 1-1-3 Option Adding Unit 33 When the option adding unit 33 determines that a received frame has an abnormality, it adds option information to the frame, including the abnormality determination result, whether or not information storage is required, and whether or not intrusion detection processing is required.
[0035] As shown in Fig. 4, optional information is added to a frame. That is, the optional information is added to the frame in addition to the header and payload. The optional information may be added to the frame additionally, like the header, or may be overwritten in a free or unused area of an existing header. In the latter case, the optional information may be overwritten in the layer where the source and destination are stored (layer 2 in this example), or in the header of any other layer.
[0036] In this embodiment, the option adding unit 33 adds optional information to the frame even when it is determined that there is no abnormality. With this configuration, even when it is determined that there is no abnormality, the specific information processing unit 20 can grasp each piece of information related to the abnormality determination result from the optional information and can perform appropriate processing. Note that when it is determined that there is no abnormality, the optional information does not need to be added to the frame.
[0037] The option adding unit 33 adds option information to the frame, including whether or not log information related to the transmission and reception of the frame needs to be stored, and whether or not the frame needs to be stored, as information storage necessity.
[0038] Here, the log information stored in the specific information processing unit 20 includes history information such as the date and time of transmission and reception of a frame, the source and destination, and the transmission and reception path, as well as the abnormality determination result.
[0039] The abnormality determination result indicates whether or not there is an abnormality, and may include information that determines the determination result (for example, whether or not it falls under the permission list, whether or not it falls under the rejection list, or the number of times it is received is above a threshold).
[0040] The option adding unit 33 determines whether or not information needs to be stored (in this example, whether or not log information needs to be stored and whether or not frames need to be stored) and whether or not intrusion detection processing is required based on the abnormality determination result and the header.
[0041] For example, as shown in FIG. 5, when the option granting unit 33 determines that there is an abnormality because the information falls under the rejection list, it may determine that intrusion detection processing is unnecessary, determine that storage of log information is necessary, determine that storage of frames is unnecessary, or determine that storage of frames is necessary.
[0042] This configuration prevents the specific information processing unit 20 from performing intrusion detection processing on obviously dangerous frames that fall under the reject list, thereby reducing the risk of intrusion into the specific information processing unit 20. Furthermore, for example, if a specific information processing unit 20 stores frames and an external management system is to analyze frames that fall under the reject list, it is sufficient to determine that storing the frames is necessary. However, if analysis is not to be performed by the external management system or if the risk of intrusion due to storage is to be avoided, it is sufficient to determine that storing the frames is unnecessary. In either case, since log information is stored in the specific information processing unit 20, the external management system can check the status of transmission and reception of frames that fall under the reject list, and the status of intrusion.
[0043] As shown in Figure 6, if the option granting unit 33 determines that there is an abnormality because the information does not match the permission list, it may determine that intrusion detection processing is necessary, determine that storage of log information is necessary, determine that storage of frames is not necessary, or determine that storage of frames is necessary.
[0044] According to this configuration, a specific information processing unit 20 can perform intrusion detection processing on gray frames that do not fall under the allowance list, thereby determining whether they are the result of a malfunction or an attack. Since there is also the possibility of an unknown attack, it is better to perform intrusion detection processing and analyze the frames. Furthermore, for example, if a specific information processing unit 20 stores frames and an external management system is to analyze the frames, it is sufficient to determine that storing the frames is necessary. However, if analysis is not to be performed by the external management system or if the risk of intrusion due to storage is to be avoided, it is sufficient to determine that storing the frames is unnecessary. In either case, since log information is stored in the specific information processing unit 20, the external management system can check the status of transmission and reception of gray frames that do not fall under the allowance list and determine the status of intrusions.
[0045] If option information is added to a frame even when it is determined that there is no abnormality, as shown in Figure 7, the option adding unit 33 may determine that intrusion detection processing is unnecessary and that storage of log information is necessary, or may determine that storage of log information is unnecessary and that storage of a frame is unnecessary.
[0046] According to this configuration, it is possible to prevent the specific information processing unit 20 from performing intrusion detection processing on frames that are free of abnormalities, thereby reducing the processing load on the specific information processing unit 20. Furthermore, if an error in the judgment result indicates an abnormality and it is desired to have an external management system perform a minimal analysis later, it is sufficient to determine that storing log information is necessary, and if it is desired to suppress an increase in the storage capacity and processing load of the specific information processing unit 20 due to the storage of log information, it is sufficient to determine that storing a log is unnecessary. Since frames that are free of abnormalities are not stored in the specific information processing unit 20, it is possible to suppress an increase in the storage capacity of the specific information processing unit 20.
[0047] 1-1-4. Frame Transmitting Unit 34 The frame transmitting unit 34 transmits the frame processed by the filtering unit 32 and the option adding unit 33 to the destination of the header included in the frame.
[0048] According to this configuration, a frame with optional information added is sent to the destination, and a specific information processing unit 20 can appropriately process the received frame based on the optional information contained in the received frame.
[0049] It should be noted that the filtering unit 32 and the option adding unit 33 do not need to perform processing when the destination of the header included in the received frame is not a specific information processing unit 20. With this configuration, processing for adding option information that is not used at the destination can be avoided, and the processing load on the switch unit 30 can be reduced.
[0050] 1-2. Specific Information Processing Unit 20 The specific information processing unit 20 includes a frame receiving unit 21, an information storage unit 22, an intrusion detection processing unit 23, and a frame forwarding unit 24. In addition to these, the specific information processing unit 20 also includes an application execution unit that executes an application (software) for performing the original information processing.
[0051] As shown in FIG. 8 , the specific information processing unit 20 includes an arithmetic processing device 80, a storage device 81, a communication device 82, and the like. The arithmetic processing device 80 may be a central processing unit (CPU), various integrated circuits (ICs), field programmable gate arrays (FPGAs), graphics processing units (GPUs), or various artificial intelligence (AI) chips. The storage device 81 may be a variety of volatile and non-volatile memories. The storage device 81 may be provided inside the arithmetic processing device 80. The communication device 82 is connected to a network and communicates with the switch unit 30 and the like. The functions of the frame receiving unit 21, information storage unit 22, intrusion detection processing unit 23, frame forwarding unit 24, and the like provided in the specific information processing unit 20 are realized by the cooperation of the hardware components of the arithmetic processing device 80, storage device 81, communication device 82, and the like provided in the specific information processing unit 20. When a CPU is used as the arithmetic processing device 80, the functions are realized by the CPU executing a program stored in the storage device 81.
[0052] 1-2-1. Frame Receiving Unit 21 The frame receiving unit 21 receives frames transmitted from the switch unit 30.
[0053] 1-2-2. Information Storage Unit 22 When the received frame includes optional information and information storage is necessary, the information storage unit 22 stores the abnormality determination result included in the optional information and information related to the received frame in the storage device 81 (non-volatile storage device) of a specific information processing unit 20.
[0054] In this embodiment, as described above, the necessity of storing information includes whether or not log information relating to the transmission and reception of frames needs to be stored, and whether or not frames need to be stored.
[0055] When it is necessary to store log information, the information storage unit 22 stores, as log information of the received frame, history information such as the transmission and reception date and time, the source and destination, and the transmission and reception route of the received frame, as well as the abnormality determination result included in the option information of the received frame, in the storage device 81. The source, destination, transmission and reception route, etc. may be acquired from the header of each layer included in the received frame.
[0056] When storage of a frame is necessary, the information storage unit 22 stores the received frame in the storage device 81. To ensure safety, the received frame may be stored in a storage device provided outside a specific information processing unit 20. In this case, the frame may be stored in association with the abnormality determination result, log information, etc.
[0057] 1-2-3 Intrusion Detection Processor 23 When a received frame contains optional information and intrusion detection processing is required, the intrusion detection processor 23 performs intrusion detection processing on the received frame.
[0058] In this embodiment, the intrusion detection process is a Network-based Intrusion Detection System (NIDS) process, and various known intrusion detection processes are performed. The intrusion detection process includes more advanced determination processes than the frame anomaly determination process performed by the filtering unit 32. For example, based on more detailed transmission and reception paths of the frame included in the header, it is determined whether the frame has been spoofed, tampered with, or is an unauthorized transmission and reception path. The transmission and reception paths include transmission and reception paths such as IP addresses in external networks included in headers from layer 3 onwards. In addition, log information of multiple abnormal frames is analyzed to determine whether they match an attack pattern. The payload of the received frame is analyzed to determine whether the payload is abnormal. These determinations may be made using information obtained via the communication device 82 from an external database that stores information on unauthorized frames.
[0059] When the intrusion detection processing unit 23 determines that the received frame has an abnormality through the intrusion detection processing, it stores the intrusion detection result of the intrusion detection processing and information about the frame in the storage device 81 (non-volatile storage device) of the specific information processing unit 20. Furthermore, the intrusion detection processing unit 23 may transmit the intrusion detection result of the intrusion detection processing, etc. to an external management system via the communication device 82.
[0060] 1-2-4. Frame forwarding unit 24 If the abnormality determination result included in the optional information indicates that an abnormality exists, or if intrusion detection processing is required and the intrusion detection result of the intrusion detection processing indicates that an abnormality exists, the frame forwarding unit 24 discards the received frame without forwarding it to another application so that the frame cannot be used by another application (another processing unit) of the specific information processing unit 20.
[0061] On the other hand, if the abnormality determination result included in the optional information is no abnormality, and intrusion detection processing is not required and no intrusion detection processing is performed, or intrusion detection processing is required and the intrusion detection result by the intrusion detection processing is no abnormality, the frame forwarding unit 24 forwards the received frame to another application (another processing unit) of the specific information processing unit 20 so that it can be used in another application (another processing unit).
[0062] 1-3 Flowchart of Switch Section 30 Next, the outline of the processing procedure of the switch section 30 according to this embodiment will be described with reference to the flowchart shown in FIG.
[0063] In step S01, the frame receiving section 31 determines whether or not a new frame has been received, and if so, the process proceeds to step S02.
[0064] In step S02, as described above, the filtering unit 32 determines whether or not there is an abnormality in the received frame based on the header contained in the received frame, and if it determines that there is an abnormality, it proceeds to step S03, and if it determines that there is no abnormality, it proceeds to step S04.
[0065] In step S03, as described above, if it is determined that an abnormality exists, the option adding unit 33 adds option information to the frame, including the abnormality determination result, whether information storage is required, and whether intrusion detection processing is required. In this embodiment, whether information storage is required includes whether log information related to the transmission and reception of the frame is required, and whether the frame itself is required. Furthermore, the option adding unit 33 determines whether information storage is required and whether intrusion detection processing is required based on the abnormality determination result and the header.
[0066] In step S04, as described above, even if it is determined that no abnormality exists, the option adding unit 33 adds optional information to the frame, including the abnormality determination result, whether information storage is required, and whether intrusion detection processing is required. In this embodiment, the necessity of information storage similarly includes whether log information related to the transmission and reception of the frame is required to be stored, and whether the frame is required to be stored. Furthermore, the option adding unit 33 determines whether information storage is required and whether intrusion detection processing is required based on the abnormality determination result and the header. Alternatively, the option adding unit 33 may not add optional information to the frame if it is determined that no abnormality exists.
[0067] In step S05, as described above, the frame transmitting unit 34 transmits the frame processed by the filtering unit 32 and the option adding unit 33 to the destination of the header included in the frame.
[0068] 1-4 Flowchart of the Specific Information Processing Unit 20 Next, the outline of the processing procedure of the specific information processing unit 20 according to this embodiment will be described with reference to the flowchart shown in FIG.
[0069] In step S21, the frame receiving section 21 determines whether or not a new frame has been received, and if so, the process proceeds to step S22.
[0070] In step S22, as described above, the information storage unit 22 determines whether the received frame contains optional information, and if optional information is included, proceeds to step S23, and if optional information is not included, proceeds to step S32.
[0071] In step S23, the information storage unit 22 determines whether or not it is necessary to store the log information, and if it is necessary to store the log information, the process proceeds to step S24, and if it is not necessary to store the log information, the process proceeds to step S25. In step S24, as described above, the information storage unit 22 stores the log information of the frame in the storage device 81.
[0072] In step S25, the information storage unit 22 determines whether or not it is necessary to store the frame, and if it is necessary to store the frame, the process proceeds to step S26, and if it is not necessary to store the frame, the process proceeds to step S27. In step S26, as described above, the information storage unit 22 stores the frame in the storage device 81.
[0073] In step S27, the intrusion detection processing unit 23 determines whether or not the intrusion detection process is necessary, and if the intrusion detection process is necessary, the process proceeds to step S28, and if the intrusion detection process is not necessary, the process proceeds to step S29. In step S28, as described above, the intrusion detection processing unit 23 performs the intrusion detection process on the received frame.
[0074] In step S29, the frame forwarding unit 24 determines whether or not the abnormality determination result included in the option information indicates an abnormality, and if so, proceeds to step S31, and if not, proceeds to step S30. In step S30, the frame forwarding unit 24 determines whether or not the intrusion detection result from the intrusion detection process indicates an abnormality, and if so, proceeds to step S31, and if the intrusion detection result indicates no abnormality or the intrusion detection process has not been performed, proceeds to step S32.
[0075] In step S31, the frame transfer unit 24 discards the received frame without transferring it to another application of the specific information processing unit 20 so that the frame cannot be used by another application (another processing unit).
[0076] In step S32, the frame transfer unit 24 transfers the received frame to another application (another processing unit) of the specific information processing unit 20 so that the frame can be used in that other application (another processing unit).
[0077] 2. Second Embodiment An intrusion detection system 1 according to a second embodiment will be described with reference to the drawings. Fig. 11 shows a schematic configuration diagram of the main parts of the intrusion detection system 1 according to this embodiment.
[0078] As in the first embodiment, the intrusion detection system 1 includes a plurality of information processing units 10 and a switch unit 30. At least one information processing unit 10 (in this example, one information processing unit 10) is designated as a specific information processing unit 20.
[0079] As in the first embodiment, each information processing unit 10 is an information processing device, and the switch unit 30 is a switch device. For example, the information processing devices may include a communication device that performs wireless or wired communication with an external device, a control device that controls various control targets, and an information processing device that performs various information processing.
[0080] As in the first embodiment, the network connecting the information processing units 10 and the switch unit 30 is a network using a communication protocol such as Ethernet, CAN (Controller Area Network), or IP (Internet Protocol).
[0081] As in the first embodiment, the intrusion detection system 1 is mounted on a vehicle, and the information processing units 10 and the switch unit 30 are connected by a local network (on-board network) within the vehicle.
[0082] 2-1. Switch Unit 30 As in the first embodiment, the switch unit 30 switches communication paths and transmits and receives frames between a plurality of information processing units 10 based on headers included in the frames that identify the source and destination information processing units. In this embodiment, the switch unit 30 is a gateway device that relays communications between a plurality of information processing units 10.
[0083] The switch unit 30 includes a frame receiving unit 35 , a filtering unit 36 , an option adding unit 37 , a counting unit 38 , an abnormality storage unit 39 , and a frame transmitting unit 40 .
[0084] 3, the switch unit 30 includes a processor 90, a storage device 91, and a communication device 92. The hardware configuration is the same as that of the switch unit 30 in the first embodiment, so a description thereof will be omitted.
[0085] 2-1-1 Frame Receiving Unit 35 The frame receiving unit 35 receives frames from each information processing unit 10.
[0086] The frame is a communication frame, which is the smallest unit of data communicated over the network connecting each information processing unit 10 and the switch unit 30, as described above.
[0087] 2-1-2. Filtering Unit 36 The filtering unit 36 determines whether or not there is an abnormality in the received frame based on the header contained in the received frame.
[0088] According to this configuration, the presence or absence of an abnormality in a frame is determined based on a small amount of information in the header, thereby reducing the processing load of the abnormality determination process.
[0089] For example, the filtering unit 32 determines whether or not there is an abnormality in the received frame based on the source and destination of the header included in the received frame. Note that the filtering unit 32 may also determine whether or not there is an abnormality in the received frame based on various communication information included in the header, such as a virtual local area network (VLAN) or a priority code point (PCP).
[0090] In this embodiment, the filtering unit 36 determines whether or not there is an abnormality using one or both of a reject list method and a permit list method.
[0091] The reject list method uses a reject list in which combinations of senders (sender MAC addresses) and destinations (destination MAC addresses) that should not be sent or received are registered in advance. When the reject list method is used, the filtering unit 36 determines that there is an abnormality in the received frame if the combination of sender and destination in the header included in the received frame corresponds to a combination of sender and destination registered in the reject list, and otherwise determines that there is no abnormality in the received frame.
[0092] The permission list method uses a pre-registered permission list of combinations of senders (sender MAC addresses) and destinations (destination MAC addresses) that are permitted to send and receive. When the permission list method is used, the filtering unit 36 determines that there is no abnormality in the received frame if the combination of sender and destination in the header included in the received frame corresponds to a combination of sender and destination registered in the permission list, and otherwise determines that there is an abnormality in the received frame.
[0093] When both the reject list method and the allow list method are used, the filtering unit 36 finally determines that the received frame contains an abnormality if the reject list method determines that the received frame contains an abnormality, and finally determines that the received frame contains no abnormality if the allow list method determines that the received frame does not contain an abnormality. When the filtering unit 36 determines that the received frame does not contain an abnormality using the reject list method and also determines that the received frame contains an abnormality using the allow list method, the filtering unit 36 may finally determine that the received frame contains an abnormality, or may finally determine that the received frame does not contain an abnormality.
[0094] 2-1-3. Counting Unit 38 The counting unit 38 counts the number of times an abnormality is determined per determination period for frames with an abnormality that have the same source and destination headers.
[0095] For example, when a frame having a source and destination header for which counting of the number of abnormality determinations has not currently started (the number of abnormality determinations is 0) is determined to be abnormal by the filtering unit 36, the counting unit 38 starts counting the number of abnormality determinations and sets the number of abnormality determinations to 1, and counts up the number of abnormality determinations by 1 each time a frame having the same source and destination header is determined to be abnormal by the filtering unit 36. Then, when the determination period has elapsed after starting counting, the counting unit 38 ends counting, outputs the current number of abnormality determinations as the number of abnormality determinations per determination period for abnormal frames having the same source and destination headers that have been counted, and then resets the number of abnormality determinations to 0 so that it can start counting again.
[0096] The number of times that an abnormality is determined is counted in parallel for frames with an abnormality that have headers with different sender and destinations.
[0097] In this embodiment, the counting unit 38 counts the number of times that an abnormality-free frame having the same source and destination header is received per judgment period, and if the number of times that it is received is equal to or greater than a threshold value, it determines that there is an abnormality in the received abnormality-free frame, and sets the number of times that it is received as the number of times that it judges an abnormality per judgment period.
[0098] Even if a frame is determined to be normal by the filtering unit 36 based on the source and destination of the header, it is possible that the frame may be subject to intrusions such as "spoofing" or "tampering" and result in the frame being sent frequently to the destination. In such cases, it is possible to determine whether an abnormality exists based on the number of times the frame is received per determination period.
[0099] 2-1-4. Abnormality Storage Unit 39 The abnormality storage unit 39 stores, in the storage device 91 of the switch unit 30, the number of abnormality determinations per determination period and information on the abnormality header, which is a header corresponding to the number of abnormality determinations.
[0100] Each time the counting unit 38 finishes counting a determination period and outputs the number of abnormality determinations per determination period, the abnormality storage unit 39 stores the output number of abnormality determinations per determination period and the corresponding abnormality header information in the storage device 91 of the switch unit 30. The stored abnormality header information may include not only the source and destination included in the header of layer 2, but also the transmission and reception path, such as an IP address in an external network, included in the header of layer 3 or later. In other words, header information for all layers may be stored, or header information for necessary layers including layer 2 may be stored.
[0101] In this embodiment, the abnormality storage unit 39 further stores, in the storage device 91 of the switch unit 30, a representative frame that represents the frames corresponding to the number of abnormality determinations per determination period.
[0102] The representative frame is set to any frame (for example, the first or last frame) among the frames corresponding to the number of abnormality determinations per determination period.
[0103] Furthermore, even if the counting unit 38 determines that a frame without an abnormality is a frame with an abnormality based on the number of times it is received per judgment period, the abnormality memory unit 39 stores the number of abnormality judgments per judgment period and information about the abnormality header, which is a header corresponding to the number of abnormality judgments, in the memory device 91 of the switch unit 30, and stores the representative frame in the memory device 91 of the switch unit 30.
[0104] 2-1-5. Option Adding Unit 37 The option adding unit 37 adds option information, including the number of abnormality determinations per determination period and abnormal header information stored in the storage device 91 of the switch unit 30, to an abnormality-free frame having a header with the same destination as the destination of the abnormal header.
[0105] According to this configuration, the number of abnormality determinations per determination period and information on the abnormal header can be included in an abnormality-free frame sent to the same destination as the destination of the abnormal header.
[0106] In this embodiment, the option adding unit 37 adds option information including the representative frame to an abnormality-free frame having a header with the same destination as the destination of the abnormal header, in addition to the number of abnormality determinations per determination period and information on the abnormal header.
[0107] After the number of abnormality determinations per determination period and the abnormal header are stored in the storage device 91, the option adding unit 37 adds option information to the next abnormal-free frame with the same destination as the destination of the abnormal header.
[0108] 2-1-6. Frame Transmitting Unit 40 The frame transmitting unit 40 discards frames with anomalies and does not transmit them to the destination of the header included in the frames with anomalies, and transmits frames determined to be normal to the destination of the header included in the frames with no anomalies. The frame transmitting unit 40 also transmits the number of anomaly detections per detection period and information about the abnormal header stored in the storage device 91 of the switch unit 30 to the destination of the abnormal header.
[0109] According to this configuration, anomaly-containing frames are discarded and not transmitted to the destination of the header contained in the anomaly-containing frame, thereby preventing a large number of anomaly-containing frames from being transmitted to the destination information processing unit 10 due to a DoS (Denial of Service) attack, and preventing the destination information processing unit 10 from being infiltrated by anomaly-containing frames. This prevents the security of the destination information processing unit 10 from being compromised by anomaly-containing frames. Meanwhile, the number of anomaly detections per detection period and information on the anomaly header for anomaly-containing frames are transmitted to the destination of the anomaly header, allowing the destination information processing unit 10 to grasp the transmission status of the anomaly-containing frame, and for example, the destination information processing unit 10 can analyze the information, or transmit the transmission status of the anomaly-containing frame to an external management system for analysis.
[0110] In this embodiment, the frame transmitting unit 40 further transmits the representative frame stored in the storage device 91 of the switch unit 30 to the destination of the abnormal header.
[0111] The abnormal frame with the abnormality determination count per determination period is not transmitted to the information processing unit 10, which is the destination of the abnormal header, and only the representative frame is transmitted to the information processing unit 10, which is the destination of the abnormal header. Therefore, by transmitting the representative frame in addition to the information on the abnormality determination count and the abnormal header, attacks using abnormal frames can be analyzed in more detail while preventing the destination information processing unit 10 from being attacked by a DoS (Denial of Service) attack.
[0112] In this embodiment, the frame transmitter 40 transmits the anomaly-free frame with the option information added to it to the destination of the header included in the anomaly-free frame. With this configuration, it is possible to include information about an anomaly-free frame in the anomaly-free frame and transmit it without increasing the number of frames to be transmitted.
[0113] The frame transmitting unit 40 may generate a new frame including the number of abnormality determinations per determination period, information on the abnormal header, and information on the representative frame, and transmit the new frame to the destination of the abnormal header.
[0114] Furthermore, the frame transmitting unit 40 erases the transmitted number of abnormality determinations per determination period, the abnormal header information, and the representative frame information from the storage device 91. With this configuration, it is not necessary to provide the switch unit 30 with a large-capacity storage device, and the information can be stored in a relatively large-capacity storage device of the specific information processing unit 20.
[0115] 2-2. Specific Information Processing Unit 20 The specific information processing unit 20 includes a frame receiving unit 25, an information storage unit 26, and a frame forwarding unit 27. The specific information processing unit 20 also includes an application execution unit that executes an application (software) for performing the original information processing.
[0116] 8, the specific information processing unit 20 includes a processor 80, a storage device 81, and a communication device 82. The hardware configuration is the same as that of the specific information processing unit 20 in the first embodiment, so a description thereof will be omitted.
[0117] 2-2-1. Frame Receiving Unit 25 The frame receiving unit 25 receives frames transmitted from the switch unit 30, as well as the number of abnormality determinations per determination period and information on the abnormal header. In this embodiment, the frame receiving unit 25 also receives representative frames.
[0118] In this embodiment, the frame receiving unit 25 acquires the number of abnormality determinations per determination period, abnormal header information, and representative frame information included in the option information of the received abnormal-free frame. Note that the frame receiving unit 25 may also receive a new frame including the number of abnormality determinations per determination period, abnormal header information, and representative frame information.
[0119] 2-2-2. Information Storage Unit 26 The information storage unit 26 stores the number of abnormality determinations per determination period and information on the abnormal header in the storage device 81 (non-volatile storage device) of the specific information processing unit 20. In this embodiment, the information storage unit 26 further stores representative frames in the storage device 81 of the specific information processing unit 20.
[0120] 2-2-3 Frame Transfer Unit 27 The frame transfer unit 27 transfers the received normal frame to another application (another processing unit) of the specific information processing unit 20 so that the frame can be used in that other application (another processing unit).
[0121] The frame forwarding unit 27 may transmit the number of abnormality judgments per judgment period, abnormal header information, representative frames, etc. stored in the memory device 81 to an external management system via the communication device 82 and have the external management system analyze them.
[0122] 2-3 Flowchart of Switch Section 30 Next, the outline of the processing procedure of the switch section 30 according to this embodiment will be described with reference to the flowchart shown in FIG.
[0123] In step S41, the frame receiving section 35 determines whether or not a new frame has been received, and if so, the process proceeds to step S42.
[0124] In step S42, as described above, the filtering unit 36 determines whether or not there is an abnormality in the received frame based on the header contained in the received frame, and if it determines that there is an abnormality, it proceeds to step S43, and if it determines that there is no abnormality, it proceeds to step S46.
[0125] In step S43, as described above, the counting unit 38 counts the number of times an anomaly is determined per determination period for an anomaly-containing frame having the same source and destination header. In this embodiment, even if an anomaly-free frame having the same source and destination header is determined to be absent in step S42, the counting unit 38 counts the number of times an anomaly-free frame having the same source and destination header is received per determination period, and if the number of times is equal to or greater than a threshold, the counting unit 38 determines that an anomaly-free frame is present in the number of times it is received and sets the number of times an anomaly is determined per determination period.
[0126] In step S44, as described above, after starting to count the number of abnormality determinations, when the determination period has elapsed, the abnormality storage unit 39 stores the number of abnormality determinations per determination period and information on the abnormality header, which is a header corresponding to the number of abnormality determinations, in the storage device 91 of the switch unit 30. In this embodiment, the abnormality storage unit 39 further stores, in the storage device 91 of the switch unit 30, a representative frame that represents the frames of the number of abnormality determinations per determination period.
[0127] In step S45, as described above, the option adding unit 37 adds option information including the number of abnormality determinations per determination period and information about the abnormal header stored in the storage device 91 of the switch unit 30 to an abnormality-free frame having a header with the same destination as the destination of the abnormal header. In this embodiment, the option adding unit 37 adds option information including a representative frame in addition to the information about the number of abnormality determinations per determination period and the abnormal header to an abnormality-free frame having a header with the same destination as the destination of the abnormal header.
[0128] In step S46, as described above, the frame transmitting unit 40 discards the abnormal frame and does not send it to the destination of the header included in the abnormal frame, and sends the abnormal-free frame, with or without optional information attached, to the destination of the header included in the abnormal-free frame.
[0129] 1-4 Flowchart of Specific Information Processing Unit 20 Next, the outline of the processing procedure of the specific information processing unit 20 according to this embodiment will be described with reference to the flowchart shown in FIG.
[0130] In step S51, the frame receiving section 21 determines whether or not a new frame has been received, and if so, the process proceeds to step S52.
[0131] In step S52, the frame receiving unit 25 determines whether the received frame (in this example, optional information) includes information such as the number of abnormality determinations per determination period and abnormal header information, and if so, proceeds to step S53; if not, proceeds to step S55.
[0132] In step S53, as described above, the information storage unit 26 stores the number of abnormality determinations per determination period and information on the abnormal header in the storage device 81 of the specific information processing unit 20. In this embodiment, the information storage unit 26 further stores the representative frame in the storage device 81 of the specific information processing unit 20.
[0133] In step S54, as described above, the frame forwarding unit 27 transmits the number of abnormality judgments per judgment period, abnormal header information, representative frames, etc. stored in the memory device 81 to an external management system via the communication device 82.
[0134] On the other hand, in step S55, as described above, the frame forwarding unit 27 forwards the received normal frame (excluding optional information in this example) to another application so that it can be used in another application (another processing unit) of the specific information processing unit 20.
[0135] 3. Third Embodiment Next, an intrusion detection system 1 according to a third embodiment will be described. Description of components similar to those of the first embodiment will be omitted. The basic configuration of the intrusion detection system 1 according to this embodiment is similar to that of the first embodiment, but differs from the first embodiment in that the specific information processing unit 20 further includes a state determination unit 28. Figure 14 shows a schematic configuration diagram of the main components of the intrusion detection system 1 according to this embodiment.
[0136] The state determination unit 28 changes the content of the process to be executed based on the option-related state, which is the state of a specific information processing unit 20 related to the process to be executed based on the option information.
[0137] If the specific information processing unit 20 is attacked by an abnormal frame, the state of the specific information processing unit 20 changes from the normal state, and if processing based on the option information is continued, the state of the specific information processing unit 20 may deteriorate. Furthermore, not limited to attacks using abnormal frames, if the processing load of the specific information processing unit 20 increases or the free space of the storage device 81 of the specific information processing unit 20 decreases due to some other factor, continuing processing based on the option information may have an adverse effect on other functions of the specific information processing unit 20. According to the above configuration, the content of the processing executed based on the option information is changed based on the option-related state, so that it is possible to prevent the state of the specific information processing unit 20 from worsening and to prevent adverse effects on other functions of the specific information processing unit 20.
[0138] In this embodiment, the option-related status includes the free space of the storage device 81 of the specific information processing unit 20. Even if the option information requires information storage, the status determination unit 28 restricts storage of the abnormality determination result and information related to the frame in the storage device 81 when the free space of the storage device 81 is less than the determination value.
[0139] According to this configuration, when there is little free space, by restricting storage to the storage device 81, it is possible to prevent the free space of the storage device 81 from running out and causing a malfunction in the function of a specific information processing unit 20.
[0140] As explained in the first embodiment, in this embodiment, the necessity of storing information includes the necessity of storing log information related to the transmission and reception of frames, and the necessity of storing frames.
[0141] For example, even if storage of a frame is necessary, if the available capacity of the storage device 81 is smaller than a first determination value, the status determination unit 28 restricts storage of the received frame in the storage device 81. Even if storage of log information is necessary, if the available capacity is smaller than a second determination value, the status determination unit 28 restricts storage of the log information of the received frame in the storage device 81. Here, the second determination value is set to a value smaller than the first determination value.
[0142] According to this configuration, when the available capacity becomes smaller than the first judgment value, by limiting the storage of frames with a relatively large storage capacity, it is possible to prevent the reduction in available capacity due to the storage of frames, even in the event of, for example, a DoS attack in which a large number of abnormal frames are transmitted. Meanwhile, in a state in which the reduction in available capacity due to the storage of frames is prevented, it is possible to continue storing log information until the available capacity becomes smaller than the second judgment value, which is smaller than the first judgment value, thereby enabling the analysis of attacks using log information.
[0143] Here, limiting storage includes stopping storage or reducing the frequency of storage, and changing (rewriting) the necessity of storing optional information to the necessity of not storing. Furthermore, the frequency of storage may be reduced as available capacity decreases. The frequency of storage is the ratio of the number of times storage is actually performed to the number of times storage is required. The available capacity of the storage device 81 may be the capacity allocated for storing frames and log information.
[0144] In this embodiment, the option-related state includes the processing load of a specific information processing unit 20 (in this example, an arithmetic processing device 80 such as a CPU). Even if the option information indicates that intrusion detection processing is required, the state determination unit 28 restricts the execution of the intrusion detection processing if the processing load is higher than a determination value.
[0145] According to this configuration, when the processing load is high, the execution of the intrusion detection process is limited, thereby preventing the processing load from becoming too high and causing a malfunction in the function of a specific information processing unit 20. For example, even when there is a DoS attack and a large number of abnormality frames are transmitted, the execution of the intrusion detection process can be stopped, thereby preventing an increase in the processing load.
[0146] Here, limiting the execution of the intrusion detection process includes stopping the execution of the intrusion detection process or reducing the frequency of the intrusion detection process, and changing (rewriting) the optional information from "intrusion detection process required" to "intrusion detection process not required." Furthermore, the frequency of the intrusion detection process may be reduced as the processing load increases. The frequency of the intrusion detection process is the ratio of the number of times the intrusion detection process is actually executed to the number of times it would be required. The processing load of the specific information processing unit 20 may be the processing load allocated for the execution of the intrusion detection process.
[0147] Even after processing by the state determination unit 28, if information storage is necessary, the information storage unit 22 stores the abnormality determination result included in the option information and information related to the received frame in the storage device 81.
[0148] In this embodiment, if it is necessary to store the log information even after processing by the state determination unit 28, the information storage unit 22 stores the log information of the received frame in the storage device 81. Furthermore, if it is necessary to store the frame even after processing by the state determination unit 28, the information storage unit 22 stores the received frame in the storage device 81.
[0149] Even after the processing by the state determination unit 28, if the intrusion detection processing is necessary, the intrusion detection processing unit 23 performs the intrusion detection processing on the received frame.
[0150] Next, a schematic process procedure of the specific information processing unit 20 according to this embodiment will be described with reference to the flowchart shown in FIG.
[0151] In step S61, the frame receiving section 21 determines whether or not a new frame has been received, and if so, the process proceeds to step S62.
[0152] In step S62, as described above, the status determination unit 28 determines whether or not the received frame contains optional information, and if optional information is included, proceeds to step S63, and if optional information is not included, proceeds to step S78.
[0153] In step S63, the status determination unit 28 determines whether or not it is necessary to store log information. If it is necessary to store log information, the process proceeds to step S64. If it is not necessary to store log information, the process proceeds to step S67.
[0154] In step S64, as described above, the status determination unit 28 determines whether the free space of the storage device 81 is smaller than the second determination value, and if it is smaller, the process proceeds to step S65, and if it is not smaller, the process proceeds to step S66. In step S65, the status determination unit 28 rewrites the requirement to store log information to the requirement not to store log information, and then proceeds to step S67.
[0155] In step S66, as described in the first embodiment, the information storage unit 22 stores the log information of the frame in the storage device 81.
[0156] In step S67, the state determination unit 28 determines whether or not it is necessary to store the frame. If it is necessary to store the frame, the process proceeds to step S68; if it is not necessary to store the frame, the process proceeds to step S71.
[0157] In step S68, as described above, the state determination unit 28 determines whether the free space of the storage device 81 is smaller than the first determination value, and if it is smaller, the process proceeds to step S69, and if it is not smaller, the process proceeds to step S70. In step S69, the state determination unit 28 rewrites the frame storage requirement to the frame storage unnecessary, and then proceeds to step S71.
[0158] In step S70, the information storage unit 22 stores the frame in the storage device 81, as described in the first embodiment.
[0159] In step S71, the state determination unit 28 determines whether or not intrusion detection processing is required. If intrusion detection processing is required, the process proceeds to step S72; if intrusion detection processing is not required, the process proceeds to step S75.
[0160] In step S72, as described above, the state determination unit 28 determines whether the processing load of the specific information processing unit 20 is higher than the determination value, and if it is higher, proceeds to step S73, and if it is not higher, proceeds to step S74. In step S73, the state determination unit 28 rewrites the intrusion detection processing requirement to the intrusion detection processing unnecessary, and then proceeds to step S75.
[0161] In step S74, as explained in the first embodiment, the intrusion detection processing unit 23 performs the intrusion detection process on the received frame.
[0162] In step S75, the frame forwarding unit 24 determines whether or not the abnormality determination result included in the option information indicates an abnormality, and if so, proceeds to step S77, and if not, proceeds to step S76. In step S76, the frame forwarding unit 24 determines whether or not the intrusion detection result from the intrusion detection process indicates an abnormality, and if so, proceeds to step S77, and if the intrusion detection result indicates no abnormality or the intrusion detection process has not been performed, proceeds to step S78.
[0163] In step S77, the frame transfer unit 24 discards the received frame without transferring it to another application of the specific information processing unit 20 so that the frame cannot be used by another application (another processing unit).
[0164] In step S78, the frame transfer unit 24 transfers the received frame to another application (another processing unit) of the specific information processing unit 20 so that the frame can be used in that other application (another processing unit).
[0165] Other Embodiments (1) In the above embodiments, the multiple information processing units 10 are information processing devices, and the switch unit 30 is a switch device. However, the multiple information processing units 10 may include multiple virtual machines running on one physical processor of the information processing device using virtualization technology such as Hyper Visor. As shown in FIG. 16 , the switch unit 30 may be a switch device that switches communication paths between multiple virtual machines and one or more physical machines (information processing devices) to transmit and receive frames. Alternatively, the switch unit 30 may be an application having the functionality of the switch unit 30 that runs on one physical processor of the information processing device and switches communication paths between multiple virtual machines to transmit and receive frames.
[0166] Although various exemplary embodiments and examples are described in this disclosure, the various features, aspects, and functions described in one or more embodiments are not limited to the application of a particular embodiment, but may be applied to the embodiments alone or in various combinations. Therefore, countless variations not illustrated are contemplated within the scope of the technology disclosed in this disclosure specification. For example, this includes cases where at least one component is modified, added, or omitted, or where at least one component is extracted and combined with components of another embodiment.
[0167] 1: Intrusion detection system, 10: Information processing unit, 20: Specific information processing unit, 21: Frame receiving unit, 22: Information storage unit, 23: Intrusion detection processing unit, 24: Frame forwarding unit, 25: Frame receiving unit, 26: Information storage unit, 27: Frame forwarding unit, 28: Status determination unit, 30: Switch unit, 31: Frame receiving unit, 32: Filtering unit, 33: Option setting unit, 34: Frame transmitting unit, 35: Frame receiving unit, 36: Filtering unit, 37: Option setting unit, 38: Counting unit, 39: Abnormality storage unit, 40: Frame transmitting unit
Claims
1. A plurality of information processing units, and a switch unit that switches a communication path and transmits and receives the frame based on a header included in the frame and identifying the information processing units of the source and destination among the plurality of information processing units. The switch unit includes a frame receiving unit that receives the frame, a filtering unit that determines whether there is an abnormality in the received frame based on the header included in the received frame, an option adding unit that adds option information including an abnormality determination result, a necessity of information storage, and a necessity of intrusion detection processing to the frame when it is determined that there is an abnormality, and a frame transmitting unit that transmits the frame after the processing of the filtering unit and the option adding unit to the destination of the header included in the frame. At least one specific information processing unit includes a frame receiving unit that receives the frame transmitted from the switch unit, an information storage unit that stores the abnormality determination result included in the option information and information about the received frame in a storage device of the specific information processing unit when the option information is included in the received frame and information storage is necessary, and an intrusion detection processing unit that performs the intrusion detection processing on the received frame when the option information is included in the received frame and intrusion detection processing is necessary. An intrusion detection system.
2. The intrusion detection system according to claim 1, wherein the option adding unit determines the necessity of information storage and the necessity of intrusion detection processing based on the abnormality determination result and the header.
3. The option adding unit adds the option information including the necessity of storing log information related to transmission and reception of the frame and the necessity of storing the frame as the necessity of information storage to the frame. The information storage unit stores the log information of the received frame in a storage device of the specific information processing unit when it is necessary to store the log information, and stores the received frame in the storage device of the specific information processing unit when it is necessary to store the frame. The intrusion detection system according to claim 1 or 2.
4. The intrusion detection system according to claim 1 or 2, wherein the option adding unit adds the option information to the frame even when it is determined that there is no abnormality.
5. The intrusion detection system according to claim 1 or 2, wherein the filtering unit determines that there is an abnormality in the received frame when the number of receptions per determination period of the frame having the same header of the same transmission source and the same transmission destination is equal to or greater than a threshold value.
6. The specific information processing unit further includes a frame transfer unit. When the abnormality determination result included in the option information indicates that there is an abnormality, or when the intrusion detection process is required and the intrusion detection result by the intrusion detection process indicates that there is an abnormality, the frame transfer unit discards the received frame without transferring it to another processing unit of the specific information processing unit. When the abnormality determination result included in the option information indicates that there is no abnormality, and the intrusion detection process is not required and the intrusion detection process is not performed, or when the intrusion detection process is required and the intrusion detection result by the intrusion detection process indicates that there is no abnormality, the frame transfer unit transfers the received frame to the other processing unit of the specific information processing unit. The intrusion detection system according to claim 1 or 2.
7. The specific information processing unit further includes a state determination unit. The state determination unit changes the processing content executed based on the option information based on the option-related state, which is the state of the specific information processing unit related to the processing executed based on the option information, based on the option information. The intrusion detection system according to claim 1 or 2.
8. The option-related state includes the free capacity of the storage device of the specific information processing unit. The state determination unit restricts the storage of the abnormality determination result and the information related to the frame in the storage device of the specific information processing unit when the free capacity is smaller than a determination value even when the information storage is required. The intrusion detection system according to claim 7.
9. As for the necessity of the information storage, it includes the necessity of storing log information related to the transmission and reception of the frame and the necessity of storing the frame. Even when it is necessary to store the frame, if the free capacity is smaller than the first determination value, the state determination unit restricts the storage of the received frame in the storage device of the specific information processing unit. Even when it is necessary to store the log information, if the free capacity is smaller than the second determination value which is smaller than the first determination value, the state determination unit restricts the storage of the log information of the received frame in the storage device of the specific information processing unit. The intrusion detection system according to claim 8.
10. The option-related state includes the processing load of the specific information processing unit. Even when the intrusion detection process is necessary, if the processing load is higher than the determination value, the state determination unit restricts the execution of the intrusion detection process. The intrusion detection system according to claim 7.
11. A plurality of information processing units, and a switch unit that switches a communication path and transmits and receives the frame based on a header included in the frame and specifying the information processing units of the source and destination among the plurality of information processing units. The switch unit includes a frame reception unit that receives the frame, a filtering unit that determines the presence or absence of an abnormality in the received frame based on the header included in the received frame, a counting unit that counts the number of abnormality determinations per determination period for the frame with an abnormality having the same header of the source and destination, an abnormality storage unit that stores information on the number of abnormality determinations per determination period and the abnormal header that is the header corresponding to the number of abnormality determinations per determination period in a storage device of the switch unit, and a frame transmission unit that discards the frame with an abnormality, does not transmit it to the destination of the header included in the frame with an abnormality, transmits the frame determined to have no abnormality to the destination of the header included in the frame with no abnormality, and transmits the number of abnormality determinations per determination period and the information on the abnormal header stored in the storage device of the switch unit to the destination of the abnormal header. At least one specific information processing unit includes a frame reception unit that receives the frame transmitted from the switch unit, and the number of abnormality determinations per determination period and the information on the abnormal header, and an information storage unit that stores the number of abnormality determinations per determination period and the information on the abnormal header in a storage device of the specific information processing unit. An intrusion detection system.
12. The intrusion detection system according to claim 11, wherein the counting unit counts the number of receptions per determination period for the frame with no abnormality having the same header of the source and destination, and when the number of receptions is equal to or greater than a threshold value, determines that there is an abnormality in the frame with no abnormality of the number of receptions, and sets the number of receptions as the number of abnormality determinations per determination period.
13. The abnormal memory unit further stores a representative frame representing the frame of the number of abnormal determinations per said determination period in the storage device of the switch unit. The frame transmission unit of the switch unit further transmits the representative frame stored in the storage device of the switch unit to the destination of the abnormal header. The frame reception unit of the specific information processing unit further receives the representative frame. The information storage unit further stores the representative frame in the storage device of the specific information processing unit. The intrusion detection system according to claim 11 or 12.
14. The intrusion detection system according to claim 11 or 12, further comprising an option adding unit that adds option information including the number of abnormal determinations per said determination period and information of the abnormal header stored in the storage device of the switch unit to the frame without abnormality having the same header as the destination of the abnormal header. The frame transmission unit transmits the frame without abnormality with the option information added thereto to the destination of the header included in the frame without abnormality. The frame reception unit of the specific information processing unit acquires the number of abnormal determinations per said determination period and the information of the abnormal header included in the option information of the received frame without abnormality.
Citation Information
Patent Citations
Communication device
JP2016515316A