Unauthorized communication detection method, program, and unauthorized communication detection device
The unauthorized communication detection method addresses the challenge of accurately identifying spoofed device IDs by analyzing communication overlaps, thereby reducing false detections in dynamic IP and VPN environments.
Patent Information
- Application Number
- PCT/JP2024/044394
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-19
- Filing Date
- 2024-12-16
- Publication Date
- 2025-06-26
AI Technical Summary
Existing methods struggle to accurately detect unauthorized access that spoofs a device ID without causing false detections, especially in scenarios where IP addresses change frequently due to dynamic IP assignment or VPN usage.
An unauthorized communication detection method that determines the presence of temporal overlaps in communications from different source IP addresses with the same device ID, using a communication overlap determination process to identify potential unauthorized communications.
This method effectively detects unauthorized access that spoofs a device ID while minimizing false detections, even in environments with dynamic IP changes or VPN usage.
Smart Images

Figure JP2024044394_26062025_PF_FP_ABST
Abstract
Description
Unauthorized communication detection method, program, and unauthorized communication detection device
[0001] The present disclosure relates to an unauthorized communication detection method, a program, and an unauthorized communication detection device for detecting spoofing attacks against web servers on the Internet.
[0002] Patent Document 1 discloses a method for detecting unauthorized access that uses spoofed Layer 2 addresses such as MAC (Media Access Control) addresses with as few false positives as possible, in which the method detects combinations of IP (Internet Protocol) addresses and MAC addresses in packets flowing through a network, counts the number of times the same IP address is combined with different MAC addresses, and compares the count with a predetermined threshold value to detect unauthorized access.
[0003] Japanese Patent Application Laid-Open No. 2007-150778
[0004] The present disclosure aims to provide an unauthorized communication detection method and the like that can detect unauthorized access that uses a false device ID with as little false detection as possible.
[0005] To achieve the above object, one aspect of the present disclosure provides an unauthorized communication detection method executed by one or more processors. In the unauthorized communication detection method, when two or more communications from two or more different source IP addresses containing the same device identifier, which is a device identifier for uniquely identifying a device, are detected within a predetermined period of time in communications between the Internet and a server, a communication overlap determination process is performed to determine whether or not there is one or more temporal overlaps between the two or more communications. In the unauthorized communication detection method, when the communication overlap determination process detects one or more overlaps, it is determined that at least one of the two or more communications is an unauthorized communication that falsely represents the device identifier.
[0006] According to the present disclosure, it is possible to detect unauthorized access using a false device ID with as little false detection as possible.
[0007] FIG. 1A is a diagram showing an example of access for anonymous communication and non-anonymous communication. FIG. 1B is a diagram showing another example of access for anonymous communication and non-anonymous communication. FIG. 2 is a diagram showing the overall configuration of an unauthorized communication detection system according to the first embodiment. FIG. 3 is a diagram showing the configuration of an unauthorized communication detection device according to the first embodiment. FIG. 4 is a diagram showing an example of a communication log according to the first embodiment. FIG. 5 is a diagram showing an example of a block list according to the first embodiment. FIG. 6 is a diagram showing an example of a spoofing grey list according to the first embodiment. FIG. 7 is a diagram showing an example of an access history according to the first embodiment. FIG. 8 is a diagram showing an example of an access history according to the first embodiment. FIG. 9 is a diagram showing an example of the operation of the unauthorized communication detection system according to the first embodiment. FIG. 10 is a diagram showing an example of a communication log collection process according to the first embodiment. FIG. 11 is a diagram showing an example of a spoofing grey list creation process according to the first embodiment. FIG. 12 is a diagram showing an example of an unauthorized communication determination process according to the first embodiment. FIG. 13 is a diagram showing an example of a communication overlap determination process according to the first embodiment. FIG. 14 is a diagram showing an example of a spoofing determination process (first operation) according to the first embodiment. FIG. 15 is a diagram showing an example of an access history extraction process according to the first embodiment. FIG. 16 is a diagram showing communication of grey list No. 1 in embodiment 1. FIG. 17 is a diagram showing communication of grey list No. 2 in embodiment 1. FIG. 18 is a diagram showing communication of grey list No. 3 in embodiment 1. FIG. 19 is a diagram showing communication of grey list No. 4 in embodiment 1. FIG. 20 is a diagram showing communication of grey list No. 5 in embodiment 1. FIG. 21 is a diagram showing communication of grey list No. 6 in embodiment 1. FIG. 22 is a diagram showing a spoofing grey list in a second operation of embodiment 1. FIG. 23 is a diagram showing an example of spoofing determination processing (second operation) in embodiment 1. FIG. 24 is a diagram showing a spoofing grey list in a third operation of embodiment 1. FIG. 25 is a diagram showing an example of spoofing determination processing (third operation) in embodiment 1. FIG. 26 is a diagram showing an example of communication log collection processing in a fourth operation of embodiment 1.FIG. 27 is a diagram showing a spoofing grey list in the fourth operation of the first embodiment. FIG. 28 is a diagram showing an example (fourth operation) of the spoofing determination process in the first embodiment. FIG. 29 is a diagram showing the overall configuration of the unauthorized communication detection system in the second embodiment. FIG. 30 is a diagram showing the configuration of the unauthorized communication detection device in the second embodiment. FIG. 31 is a diagram showing an example of a communication log in the second embodiment. FIG. 32 is a diagram showing a first example of the spoofing grey list in the second embodiment. FIG. 33 is a diagram showing a first example of the house identification list in the second embodiment. FIG. 34 is a diagram showing an example of the operation of the unauthorized communication detection system in the second embodiment. FIG. 35 is a diagram showing an example of the operation of the house identification list creation process in the second embodiment. FIG. 36 is a diagram showing an example of the unauthorized communication determination process in the second embodiment. FIG. 37 is a diagram showing an example of the spoofing determination process in the second embodiment. FIG. 38 is a diagram showing a second example of the spoofing grey list in the second embodiment. FIG. 39 is a diagram showing a second example of the house identification list in the second embodiment. FIG. 40 is a diagram showing a third example of the spoofing grey list in the second embodiment. FIG. 41 is a diagram showing a third example of a house identification list in Embodiment 2. FIG. 42 is a diagram showing a fourth example of a spoofing grey list in Embodiment 2. FIG. 43 is a diagram showing a fourth example of a house identification list in Embodiment 2. FIG. 44 is a diagram showing a fifth example of a spoofing grey list in Embodiment 2. FIG. 45 is a diagram showing a fifth example of a house identification list in Embodiment 2. FIG. 46 is a diagram showing an example of a device type list in Embodiment 1. FIG. 47 is a diagram showing an example of a device type list in a third operation of Embodiment 1. FIG. 48 is a diagram showing an example of a device type list in a fourth operation of Embodiment 1. FIG. 49 is a configuration diagram of an unauthorized communication detection device in Modification 2. FIG. 50 is a diagram showing an example of communication log collection processing in Modification 2. FIG. 51 is a diagram showing an example of unauthorized communication determination processing in Modification 2. FIG. 52 is a diagram showing an example of spoofing determination processing in Modification 3. FIG. 53 is a diagram showing the overall configuration of an unauthorized communication detection system in Modification 5. FIG. 54 is a diagram showing the overall configuration of an unauthorized communication detection system in Modification 6.Fig. 55 is a diagram showing the overall configuration of an unauthorized communication detection system in Modification 7. Fig. 56 is a diagram showing the configuration of an unauthorized communication detection device in Modification 9. Fig. 57 is a diagram showing an example of spoofing determination processing in Modification 9. Fig. 58 is a diagram showing an example of notification when spoofing is detected when two or more communications overlap in time. Fig. 59 is a diagram showing an example of notification when spoofing is detected when two or more communications do not overlap in time. Fig. 60 is a diagram showing an example of notification of a block list.
[0008] [Findings that led to the present disclosure] The following describes the points of view of the inventors of the present application.
[0009] In recent years, with the advent of IoT (Internet of Things) in home appliances, not only PCs (Personal Computers) and TVs (Televisions) but also home appliances such as air conditioners, refrigerators, and washing machines can now be connected to the Internet via routers, making life more convenient by enabling remote control via home appliance servers and linking home appliances together.
[0010] On the other hand, there is an increasing risk of cyber attacks, such as spoofing the device IDs used by home appliance servers to uniquely identify home appliances, disguising them as legitimate home appliances, and gaining unauthorized access to the home appliance server, operating the server illegally, or stealing information. Therefore, home appliance servers need to take measures to defend against cyber attacks, such as blocking unauthorized access using spoofed device IDs.
[0011] A typical method for this is to register a combination of a device ID and a source IP address in a database, and if an access is made using a device ID and IP address that is different from that combination, it is detected as spoofing.
[0012] However, if the ISP (Internet Service Provider) that assigns IP addresses on the Internet uses a dynamic IP allocation method, the IP address will change periodically, and the IP address assigned by the ISP may also change when, for example, the home router is restarted.
[0013] In other words, even if access is made from different IP addresses using the same device ID, if those IP addresses are assigned by the same ISP, there is a high possibility that the access is from the same user. As a result, false positives occur frequently, where access is recognized as spoofing even when it is not unauthorized access.
[0014] As already mentioned, Patent Document 1 discloses a method for detecting unauthorized access that uses spoofed Layer 2 addresses such as MAC addresses with as few false positives as possible, by detecting combinations of IP (Internet Protocol) addresses and MAC addresses in packets flowing through a network, counting the number of times the same IP address is combined with different MAC addresses, and comparing the count with a predetermined threshold value to detect unauthorized access.
[0015] When the method disclosed in Patent Document 1 is applied to a home appliance server on the Internet, the number of times different IP addresses are combined with the same device ID is compared with a predetermined threshold to determine whether or not it is spoofing.
[0016] In this case, false detection can be prevented by not counting up different IP addresses if they are within the address range of the same ISP, and by setting a threshold value based on how often the ISP reassigns IP addresses.
[0017] However, there are users of home appliances in countries all over the world, and it is extremely difficult to set a threshold value for each device ID that is appropriate for the operation of the ISP in each country or region.
[0018] In addition, modern televisions are equipped with video streaming service functions, and an increasing number of users are using anonymous communication services to circumvent national or regional viewing restrictions in order to watch videos being streamed in other countries.
[0019] When accessed from a TV, a video distribution server identifies the country of origin from the source IP address. For example, by using a service such as "Whois," which allows any Internet user to access information about IP addresses and domain name registrants, it is possible to easily identify the country name from the IP address. As shown in Figure 1A, when a TV directly accesses a video distribution server from country A (in the case of non-anonymous communication), the video distribution server restricts viewing because the access is not from country B, the target of distribution.
[0020] Therefore, if you connect the TV to a VPN server installed in country B, which is the target country of distribution, and access the video distribution server via the VPN server (in the case of non-anonymous communication), the video distribution server will recognize the access as coming from country B, which is the target country of distribution, and you will actually be able to watch videos while being outside the target country of distribution.
[0021] As shown in Figure 1B, a TV in such an environment normally accesses the home appliance server using an IP address assigned by the ISP with which the user has a contract, and when connected to a VPN for the purpose of watching videos, it accesses the home appliance server using the IP address of the VPN server.
[0022] From the perspective of the home appliance server, it appears as if the same device ID is being used to access the device from a different IP address, so there is a possibility that one of the communications will be mistakenly detected as an unauthorized access attempting to spoof the TV's device ID.
[0023] VPN servers are installed in countries around the world, and users can freely choose a country to communicate in anonymously and can connect / disconnect to the VPN server at any time, so the frequency with which the IP address changes for the same device ID is irregular.
[0024] In other words, it is extremely difficult to set a threshold appropriate for each device ID, and the method of Patent Document 1 cannot prevent false spoofing detection in such cases. Normally, communications determined to be spoofing pose a significant security risk, so the response is often to block the communications for a certain period of time. Therefore, if a false spoofing detection is made, communications of normal home appliances will be blocked, causing great inconvenience to users.
[0025] Furthermore, from the perspective of security monitoring operations, if false positive alerts occur frequently, there is a risk that truly high-risk alerts will be overlooked, so it is desirable to prevent false positives as much as possible.
[0026] The purpose of the present disclosure is to increase detection accuracy by minimizing false positives of spoofing, even in cases where the IP address is changed periodically by the ISP or where the user sets up a VPN and the IP address changes irregularly, by taking into consideration information such as overlapping communications and whether the IP address is for anonymous communications, rather than simply detecting a change in IP address and determining that it is spoofing.
[0027] The following describes, with reference to the drawings, the configuration of an unauthorized communication detection system according to an embodiment of the present disclosure, the configuration of an unauthorized communication detection device that is a component of the system, and the flow of the unauthorized communication detection process. Note that each of the embodiments described below represents a preferred specific example of the present disclosure. In other words, the numerical values, shapes, materials, components, component arrangements and connection forms, steps, and step order shown in the following embodiments are examples of the present disclosure and are not intended to limit the present disclosure. The present disclosure is defined by the claims. Therefore, among the components in the following embodiments, components that are not recited in the independent claims that represent the superordinate concept of the present disclosure are not necessarily required to achieve the objectives of the present disclosure, but are described as components that constitute more preferred embodiments.
[0028] (Embodiment 1) In an embodiment of the present disclosure, a configuration is described in which an unauthorized communication detection device that relays communication between the Internet and the home appliance server determines whether unauthorized access is due to impersonation when multiple different IP communications access the home appliance server using the TV's device ID.
[0029] [1. Details of First Embodiment] Here, as a first embodiment of the present disclosure, an unauthorized communication detection system 1 according to the present disclosure will be described with reference to the drawings. Note that this embodiment describes a case in which a TV is connected to the Internet and directly connects to a home appliance server on the Internet, and a case in which the TV is connected to the home appliance server via a VPN server.
[0030] 2 is a diagram showing the network configuration of the fraudulent communication detection system 1 according to the present disclosure. The fraudulent communication detection system 1 includes the Internet 10, a fraudulent communication detection device 20, a VPN server 30, a home appliance server 31, a communication information providing server 32, and a TV 40.
[0031] The Internet 10 is a general Internet, and the VPN server 30 is a general VPN server connected to the Internet 10. The home appliance server 31 is a server that can be reached via the Internet 10, and manages home appliances accessed via the Internet 10 and links the home appliances with each other.
[0032] The communication information providing server 32 is a server that, when inquired about an IP address, returns various pieces of information linked to the IP address.
[0033] The various information includes, for example, a network group name (ASN: Autonomous System Number), the name of the provider that manages the IP address (ISP: Internet Service Provider), or location information that can be determined from the IP address (e.g., country name, city name, latitude, longitude, etc.). In addition, information on whether communication from the IP address is anonymous communication via a VPN server, a proxy server, TOR (The Onion Router), or the like may be returned. Hereinafter, this information will be collectively referred to as communication information.
[0034] The TV 40 is a TV with a network function, and is connected to the VPN server 30 and the home appliance server 31 via the Internet 10. The TV 40 stores the device ID "TV1" in a memory unit within the TV 40, and when communicating with the home appliance server 31, includes its own device ID in the communication data.
[0035] The unauthorized communication detection device 20 is connected to a communication line (e.g., Ethernet (registered trademark)) that connects the Internet 10 and the home appliance server 31. In other words, the unauthorized communication detection device 20 acts as an intermediary for communication between home appliances on the Internet 10 and the home appliance server 31.
[0036] Specifically, the unauthorized communication detection device 20 receives all communication packets addressed to the home appliance server 31 from the Internet 10 and forwards them to the home appliance server 31, and also receives communication packets from the home appliance server 31 and forwards them to the Internet 10. In the process of mediating communication in this way, the unauthorized communication detection device 20 monitors whether there is any unauthorized communication from the Internet 10 side, and blocks unauthorized communication as necessary.
[0037] In this embodiment, a TV 40 is used as a component of the fraudulent communication detection system 1 as the home appliance that accesses the home appliance server 31, but it does not necessarily have to be a TV; it can be any other home appliance, and there can be more than one.
[0038] Although the fraudulent communication detection device 20 is said to be connected between the Internet 10 and the home appliance server 31, this is not limited to this and the device may be incorporated inside the home appliance server 31, or may be connected to the same network as the home appliance server 31 and monitor fraudulent communications by obtaining communication logs from the home appliance server 31.
[0039] 3 is a block diagram showing the configuration of the unauthorized communication detection device 20. The unauthorized communication detection device 20 includes a communication unit 201, a communication log collection unit 202, a spoofing grey list creation unit 203, an unauthorized communication determination unit 204, a communication log storage unit 205, a block list storage unit 206, a grey list storage unit 207, and an access history storage unit 208.
[0040] The unauthorized communication detection device 20 can be realized by a computer including a processor (such as a CPU (Central Processing Unit)), a memory, etc., executing a program.
[0041] The communication unit 201 is a collection of general communication interface devices, and communicates with home appliances and the home appliance server 31 connected to the Internet 10. If the address systems of the Internet 10 and the home appliance server 31 differ, a different communication interface device is assigned for each of these address systems. The communication standard used by the communication unit 201 is, for example, wired communication typified by IEEE 802.3 (Ethernet), but is not limited to this. Other wired communication such as PLC (Power Line Communication) may also be used, or wireless LAN communication of the IEEE 802.11 series (IEEE 802.11a, b, g, n, ac, ax, etc.) may also be used.
[0042] The communication log collection unit 202 receives all communication packets addressed to the home appliance server 31 from the Internet 10 via the communication unit 201 and forwards them to the home appliance server 31, and also receives communication packets from the home appliance server 31 and forwards them to the Internet 10. However, before forwarding, it checks the block list stored in the block list holding unit 206, and does not forward the packet if the combination of the source IP address and destination address of the communication packet is registered in the block list. In addition, a communication log is generated from all received packets and saved in the communication log holding unit 205.
[0043] The communication log storage unit 205 stores all communication packets relayed by the communication unit 201 as a communication log. Fig. 4 is a diagram showing an example of the communication log. The communication log in Fig. 4 stores a timestamp when the communication packet was received, the source IP address of the communication packet, the destination IP address of the communication packet, the communication state, and the device ID of the home appliance that sent the communication packet.
[0044] The communication state is information indicating the establishment status of the communication. For example, the communication state may be described as a TCP (Transmission Control Protocol) packet type such as "SYN," "SYN / ACK," or "ACK," or may be stored by expressing a "SYN" packet as "communication start," a "SYN / ACK" packet as "communication permission," an "ACK" packet as "communication establishment," a "PSH" packet as "message transmission," or a "FIN" packet as "communication end."
[0045] Alternatively, the communication state may store a communication state between the server and the client that is used in communication data at a layer other than the TCP layer, for example, an application layer.
[0046] 4 is an example, and may include TCP / IP header information such as MAC addresses and port numbers, application layer data, and other information. Furthermore, the communication status may be indicated by a flag instead of a character string.
[0047] The device ID is an ID that uniquely identifies the home appliance that is the source of the transmission, and is stored as application layer data of the packet from the home appliance to the home appliance server 31. Although it is written as a character string in Fig. 4, it may be stored in binary.
[0048] The block list holding unit 206 holds a block list for blocking unauthorized access from the Internet 10. Fig. 5 shows an example of the block list. The block list in Fig. 5 stores combinations of source IP addresses and destination IP addresses to be blocked.
[0049] The block list in FIG. 5 is an example, and may include only source IP addresses, only IP addresses of home appliances, device IDs, or other formats.
[0050] The spoofing grey list creation unit 203 reads communication logs for a certain period from the communication log storage unit 205, and checks whether the read communication logs contain multiple communications from different source IP addresses for one device ID.
[0051] Here, the certain period depends on the implementation of the unauthorized communication detection device 20, but may be set to a time that is considered short enough for the IP address of the home appliance to change naturally, such as one hour or one day, or may simply be set by a memory capacity limit for storing the read log.
[0052] If the read communication log contains multiple communications from different source IP addresses for one device ID, the spoofing grey list creation unit 203 determines that the device ID may be spoofed, and acquires communication information by querying the communication information providing server 32 for each source IP address via the communication unit 201. The spoofing grey list creation unit 203 then creates a list of the device IDs and communication information relating to communications from the multiple source IP addresses, and stores the list in the grey list holding unit 207 as a spoofing grey list.
[0053] The grey list holding unit 207 holds a spoofing grey list that lists device IDs and communication information related to communications from a plurality of source IP addresses. Fig. 6 is a diagram showing an example of the spoofing grey list.
[0054] 6 stores a device ID, multiple different source IP addresses that have accessed using that device ID within a certain period of time, the start and end times of communication from that IP address, the name of the ISP that manages that IP address, and the name of the anonymous communication service if the communication from that IP address is anonymous communication, or "-" if it is not anonymous communication. Regarding the communication start time and communication end time, if the communication did not start or end within a certain period of time, the character string "-" is stored instead of the time.
[0055] 6 is an example, and may be written in other formats. For example, the character string "-" is stored in the case of non-anonymous communication, but other character strings such as "none" may be stored, or "NULL" may be stored.
[0056] The unauthorized communication determination unit 204 reads the spoofing gray list from the gray list holding unit 207 and checks whether there is overlap in multiple communications from different source IP addresses for one device ID. Specifically, the unauthorized communication determination unit 204 determines the period from the start time of communication to the end time of communication as the access period, and if there is overlap in the access periods, it determines that the unauthorized access is due to spoofing.
[0057] Even if there is no overlap in the access periods, the unauthorized communication determination unit 204 considers that access from different IP addresses with the same device ID within a short period of time is highly likely to be unauthorized access due to spoofing, and therefore determines whether the unauthorized access is due to spoofing by taking into account information such as the ISP name and anonymous communication service name, as well as past access history.
[0058] Here, the past access history is created by extracting only the logs with a "specific device ID" and a "communication status of 'message sending'" from the past communication logs stored in the communication log storage unit 205, and adding the communication information of the sender IP address.
[0059] Here, the communication state of the access history extraction condition may be a state other than "message sent" as long as it can extract at least one of the multiple logs generated by one access. After the access history is created, it is stored in the access history holding unit 208. Furthermore, as necessary, the device type list holding unit 209 is referenced to associate the device ID with the device type.
[0060] In this embodiment, the device type is acquired from the device ID format, but is not limited to this. For example, if the device type is transmitted from the home appliance to the home appliance server when communication between the home appliance server and the home appliance is started or when exchanging data after communication has started, the information may be acquired from the communication packet. Alternatively, if there is a home appliance server for each device type, the device type of the home appliance may be determined based on the IP address of the home appliance server with which the home appliance communicates.
[0061] In this way, by considering whether or not there is overlap in communication and the communication information and access history together, it is possible to improve the accuracy of detecting unauthorized access that falsely uses a device ID, even in cases where the IP address is changed periodically by the ISP or where the IP address is changed irregularly when a user sets up a VPN.
[0062] If the result of the determination is that the unauthorized access was due to spoofing, the source IP address of the access is recorded in the block list of the block list holding unit 206 .
[0063] The access history storage unit 208 stores, as an access history, a message transmission log of a specific device ID from past communication logs to which communication information has been added. Fig. 7 is a diagram showing an example of the access history.
[0064] The access history in Fig. 7 stores the device ID, the source IP address, the time of communication establishment, the name of the ISP that manages the IP address, the anonymous communication service name if the communication from the IP address is anonymous communication, and "-" if the communication is not anonymous communication. Note that the access history in Fig. 7 is an example, and may be recorded in other formats. For example, the character string "-" is stored if the communication is not anonymous, but another character string such as "none" may be stored, or "NULL" may be stored.
[0065] The device type list storage unit 209 stores a device type list that associates device types with device ID formats. The device type list of Fig. 46 stores combinations of device types and device ID formats.
[0066] The device type list in Fig. 46 is an example, and the device may be listed in other formats. The device ID format is a string of two alphabetic characters representing the home appliance plus a wildcard, but is not limited to this. The device ID may be represented by numbers only, or may be stored in binary.
[0067] The following describes the operations of the unauthorized communication detection device 20 and the unauthorized communication detection system 1 configured as described above. The following describes the first operation, which is the basic processing operation according to this embodiment, and the second to fourth operations, which can further improve the detection accuracy of the first operation by adding types of information used in the first operation.
[0068] 9 is a flowchart showing the first operation of the unauthorized communication detection system 1 according to this embodiment. The operation of the unauthorized communication detection system 1 includes three processes: a communication log collection process, a spoofing grey list creation process, and an unauthorized communication determination process.
[0069] First, the communication log collection process starts when the unauthorized communication detection device 20 is started (step S001). This process is executed asynchronously with subsequent processes and continues until the unauthorized communication detection device 20 is stopped (shut down).
[0070] Next, the spoofing gray list creation process is executed (step S002), and then the unauthorized communication determination process is executed (step S003). After waiting for a certain period of time (step S004), the process returns to step S002. In other words, the processes of steps S002 and S003 are repeated at regular intervals until the unauthorized communication detection device 20 is stopped (shut down).
[0071] Each process will be explained below with reference to the drawings.
[0072] [1.3.1 Operation During Communication Log Collection Processing] FIG. 10 is a flowchart showing an example of communication log collection processing of the unauthorized communication detection system 1.
[0073] In step S101, the communication log collection unit 202 waits to receive a communication packet from a home appliance or home appliance server 31 connected to the Internet 10 via the communication unit 201. When a communication packet is received (Yes in S101), in step S102, the communication log collection unit 202 analyzes the header information and data of the packet and extracts the timestamp at which the packet was received, the source IP address of the packet, the destination IP address of the packet, the communication state, and the device ID of the source home appliance. Then, in step S103, these are stored as a communication log in the communication log storage unit 205.
[0074] Next, in step S104, it is confirmed whether the combination of the source IP address and destination IP address included in the header information is included in the block list of the block list holding unit 206.
[0075] If the packet is not included in the block list (No in S104), in step S105, the packet is transferred to the destination IP address in the header via the communication unit 201, and the process returns to the packet reception waiting state (return to step S101).
[0076] If the destination IP address is included in the block list (Yes in S104), in step S106 the packet is discarded without being forwarded to the destination IP address, and the process returns to the packet reception waiting state (return to step S101).
[0077] [1.3.2 Operations During Spoofing Grey List Creation Process] FIG. 11 is a flowchart showing an example of the spoofing grey list creation process of the unauthorized communication detection system 1.
[0078] In step S201, the spoofing grey list creation unit 203 reads communication logs for a certain period of time at regular intervals from the communication log storage unit 205. In step S202, a communication log for one device ID is extracted, and in step S203, it is confirmed whether or not multiple source IP addresses exist in the extracted log.
[0079] If there are no multiple devices (No in S203), it is determined that there is no possibility of spoofing the device ID, and the process proceeds to step S206.
[0080] If there are multiple devices (Yes in S203), it is determined that the device ID may be a spoofed device, and in step S204, the communication information providing server 32 is queried for each sender IP address to obtain communication information.
[0081] Then, in step S205, the device ID, the multiple source IP addresses, the start and end times of communications from each source IP address, and the communication information related to each source IP address are added as one record to the spoofing gray list in the gray list holding unit 207. At this time, the records are added in order of earliest communication start time.
[0082] Regarding the communication start time and communication end time, if the communication does not start or end within a certain period, there is no communication log containing that information, so the string "-" is stored instead of the time.
[0083] The communication information includes the name of the ISP to which the source IP address belongs, the name of the anonymous communication service if the communication from the IP address is anonymous communication, and "-" if the communication is not anonymous communication.
[0084] In step S206, it is checked whether there is a communication log of another device ID among the communication logs for the fixed time period extracted in step S201, and if there is a communication log of another device ID (Yes in S206), the process returns to step S202. If there is no communication log of another device ID (No in S206), the process ends.
[0085] [1.3.3 Operation During Unauthorized Communication Determination Processing] FIG. 12 is a flowchart showing an example of the unauthorized communication determination processing of the unauthorized communication detection system 1.
[0086] In step S301, one record of the spoofing grey list is read from the grey list holding unit 207.
[0087] In step S302, a communication overlap determination process is performed to check whether there is an overlap among the multiple communications included in one read record. This process will be described in detail later with reference to FIG.
[0088] If there is an overlap in the communications (Yes in S303), it is determined that there has been unauthorized access by spoofing (step S304), and the process proceeds to step S307, where the combination of the source IP address and destination IP address of the communications is added to the block list stored in the block list holding unit 206.
[0089] Thereafter, in step S308, it is confirmed whether the spoofing grey list has been read to the end, and if it has not been read to the end (No in S308), the process returns to step S301. If it has been read to the end (Yes in S308), the process ends.
[0090] If there is no overlap in the communications (No in S303), spoofing determination processing is performed in step S305, which will be described in detail later with reference to FIG.
[0091] Next, in step S306, the result of the spoofing determination in step S305 is checked, and if it is not spoofing, the process proceeds to step S308, where it is confirmed whether the spoofing grey list has been read to the end.
[0092] If the data has not been read to the end (No in S308), the process returns to step S301. If the data has been read to the end (Yes in S308), the process ends.
[0093] If the determination result in step S306 is spoofing, the process proceeds to step S307, where the combination of the source IP address and destination IP address of the communication is added to the block list stored in the block list holding unit 206.
[0094] Thereafter, in step S308, it is confirmed whether the spoofing grey list has been read to the end, and if it has not been read to the end (No in S308), the process returns to step S301. If it has been read to the end (Yes in S308), the process ends.
[0095] As described above, since IP addresses are changed by the ISP, there is a possibility that an IP address that was once blocked as a source of spoofed access may be assigned to a legitimate home appliance, in which case the legitimate home appliance will be unable to properly communicate with the home appliance server 31. To avoid this, a blocking period may be set and the block may be released after the period has expired.
[0096] The details of the communication overlap determination process in step S302 will now be described with reference to Fig. 13. Specifically, the communications of the multiple source IP addresses contained in one record read in step S301 are compared two by two from the top to check whether there is any overlap. The record stores source IP addresses and communication information in order of earliest communication start time.
[0097] In step S401, an initial value of 1 is assigned to a counter N. In step S402, the communication end time (Te) of the Nth source IP address is compared with the communication start time (Ts) of the N+1th source IP address.
[0098] If the communication start time (Ts) of the N+1th source IP address is less than the communication end time (Te) of the Nth source IP address (Yes in S403), it is determined that there is an overlap in the communications (step S404), and the process is terminated.
[0099] If the communication start time (Ts) of the N+1th source IP address is equal to or greater than the communication end time (Te) of the Nth source IP address (No in S403), step S405 checks whether the N+1th source IP address is the last in the record, and if it is not the last (Yes in S405), N+1 is assigned to counter N for comparison of the next two sets of communications (step S406), and processing returns to step S402.
[0100] If it is the last source IP address in the record (No in S405), the process ends.
[0101] Next, the spoofing determination process in step S305 will be described in detail.
[0102] In step S501 of Fig. 14, the number of anonymous communication services contained in the read record is counted. Specifically, the number of types of anonymous communication service names stored in the anonymous communication service name column in the record is counted. At this time, if the anonymous communication service name is the same, it is counted as one.
[0103] If the number of anonymous communication services is 0, proceed to step S502 and count the number of non-anonymous communication ISPs included in the read record. Specifically, count the types of ISP names stored in the ISP name column in the record. At this time, if the ISP name is the same, it is counted as one.
[0104] If the number of ISPs is one, the process proceeds to step S503, where it is determined that the ISP is not spoofing and the process ends. If the number of ISPs is two or more, the process proceeds to step S504, where it is determined that the ISP is spoofing and the process ends.
[0105] Even when there are two or more ISPs, if the source IP address has an ISP that is an MVNO (Mobile Virtual Network Operator), the communication information providing server 32 may return the ISP name of the MNO (Mobile Network Operator) depending on the timing of the inquiry. Therefore, even if there are two or more ISPs, a more detailed determination may be made, such as determining that it is not spoofing if the ISP is a combination of an MVO and an MVNO.
[0106] If the number of anonymous communication services is one or more in step S501, the process proceeds to step S505, where the number of non-anonymous communication ISPs included in the read record is counted. Specifically, the number of types of ISP names stored in the ISP name column in the record is counted. At this time, if the ISP name is the same, it is counted as one.
[0107] If the number of ISPs is two or more, the process proceeds to step S506, where it is determined that the request is an impersonation and the process ends.
[0108] In step S505, if the number of ISPs is one, the process proceeds to step S507, where the access history of the device ID is extracted and stored in the access history storage unit 208. This will be described in detail later with reference to FIG.
[0109] In step S508, it is confirmed whether the anonymous communication service included in the record read from the spoofing grey list appears frequently in the access history extracted in step S507, that is, whether it is an anonymous communication service that is used on a daily basis based on the device ID.
[0110] For example, if the access interval is short, such as once every few days, and the access occurs over a fairly long period of time, such as at least several weeks, it is determined that the anonymous communication service is used on a daily basis, and the process proceeds to step S509, where it is determined that the service is not spoofing and the process ends. The frequency of access determined as daily here is just an example, and other frequencies may be used.
[0111] If it is not a commonly used anonymous communication service, the process proceeds to step S510, where it is determined that the service is an impersonation and the process ends.
[0112] In step S505, if the number of ISPs is 0, the process proceeds to step S511, where the access history of the device ID is extracted and stored in the access history storage unit 208. This will be described in detail later with reference to FIG.
[0113] In step S512, the number of ISPs for non-anonymous communication is counted by referring to the access history. Specifically, the types of ISP names stored in the ISP name column in the record are counted.
[0114] If the number of ISPs is 0, that is, if there is no history of non-anonymous communication in the past, the process proceeds to step S513, where it is determined that the device ID is not spoofed because the anonymous communication service is used on a daily basis, and the process ends.
[0115] If the number of ISPs in the past communication log is two or more, the process proceeds to step S506, where it is determined that the communication is spoofing, and the process ends.
[0116] If the number of ISPs in the access history is one, the process proceeds to step S508, where it is confirmed whether the anonymous communication service included in the read record is an anonymous communication service that is regularly used based on the device ID.
[0117] If the anonymous communication service is one that is used daily, the process proceeds to step S509, where it is determined that the service is not a spoofing service and the process ends. If the anonymous communication service is not one that is used daily, the process proceeds to step S510, where it is determined that the service is a spoofing service and the process ends.
[0118] Next, the access history extraction process executed in steps S507 and S511 will be described in detail with reference to FIG.
[0119] In step S601, the unauthorized communication determination unit 204 reads communication logs for a certain period from the communication log storage unit 205.
[0120] In step S602, only communication logs with the device ID and communication status of "message transmission" are extracted.
[0121] In step S603, the communication information providing server 32 is inquired about all source IP addresses included in the extracted communication log, and communication information is acquired.
[0122] Then, in step S604, the device ID, source IP address, timestamp, and communication information related to each source IP address are stored as a single record in the access history storage unit 208 as an access history, and the process ends. At this time, the records are stored in order of earliest timestamp. Note that the communication information stored includes the name of the ISP to which the source IP address belongs, the name of the anonymous communication service if the communication from that IP address is anonymous communication, and "-" if the communication is not anonymous communication.
[0123] 16 to 21 are diagrams that visualize the communications of records No. 1 to No. 6 in the spoofing grey list of FIG. 6, respectively.
[0124] The processing of the unauthorized communication determination unit 204 will be specifically described below for each of records No. 1 to No. 6 in the spoofing grey list in Fig. 6, with reference to Figs. 12 to 21.
[0125] In the unauthorized communication determination process step S301 in Fig. 12, after reading out record No. 1, a communication overlap determination is performed (S302). Specifically, referring to Fig. 13, first, in step S401, an initial value of 1 is assigned to counter N, and the communication end time of the first C_IP1 in record No. 1 is compared with the communication start time of the second C_IP2 (S402).
[0126] As shown in Figure 16, the communication start time of C_IP2, "13:10:29", is earlier than the communication end time of C_IP1, "13:15:43" (Yes in S403), so it is determined that there is an overlap in communication between "13:10:29" and "13:15:43" (S404), and the processing is terminated.
[0127] 12 , the communication overlap determination result is checked in step S303, and since there is communication overlap (Yes in S303), it is determined that the device ID "TV1" in record No. 1 has been spoofed (S304), and the combination of source IP address C_IP1 and destination IP addresses S_I and P (hereinafter referred to as C_IP / S_IP), and C_IP2 / S_IP are added to the block list (S307). Since record No. 1 is not the last record in the spoofing grey list (No in S308), the process returns to step S301.
[0128] After reading record No. 2 in step S301, communication overlap determination is performed (S302). Specifically, referring to Fig. 13, an initial value of 1 is assigned to counter N in step S401, and the communication end time of the first C_IP3 in record No. 2 is compared with the communication start time of the second C_IP4 (S402).
[0129] 17, since the communication start time of C_IP4, "13:11:31", is later than the communication end time of C_IP3, "13:10:42" (No in S403), it is determined that there is no overlap in communication (S404). Furthermore, since C_IP4 is the last source IP address in record No. 2 (Yes in S405), the process ends.
[0130] Returning to FIG. 12, in step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0131] In step S501 of Figure 14, the number of anonymous communication services included in record No. 2 is counted. Since both C_IP3 and C_IP4 have "-" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 2 is zero, the process proceeds to step S502, where the number of ISPs included in record No. 2 is checked. Both C_IP3 and C_IP4 are the same ISP 3, and the number of ISPs is one. This situation could be, for example, a case in which TV2, which originally communicated using C_IP3 assigned by ISP3, communicated after its IP address changed to C_IP4 due to a restart of the home appliance or the home router or some other reason on the ISP side. Therefore, it is determined that this is not spoofing (step S503), and the process ends.
[0132] In step S306 of FIG. 12, since the determination result is not spoofing, it is checked whether it is the last record in the spoofing grey list (S308), and since it is not the last record (No in S308), the process returns to step S301.
[0133] After reading record No. 3 in step S301, communication overlap determination is performed (S302). Specifically, referring to Fig. 13, first, in step S401, an initial value of 1 is substituted into counter N, and the communication end time of the first C_IP5 in record No. 3 is compared with the communication start time of the second C_IP6 (S402).
[0134] 18, since the communication start time of C_IP6, "13:15:51", is later than the communication end time of C_IP5, "13:14:42" (No in S403), it is determined that there is no overlap in communication (S404). Since C_IP6 is the last source IP address in record No. 3 (Yes in S405), the process ends.
[0135] Returning to FIG. 12, in step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0136] In step S501 of Figure 14, the number of anonymous communication services included in record No. 3 is counted. Since both C_IP5 and C_IP6 have "-" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 3 is zero, the process proceeds to step S502, where the number of ISPs included in record No. 3 is checked. Since C_IP5 is ISP4 and C_IP6 is ISP5, the number of ISPs is two. Since an average household typically has a contract with one ISP, if there are two or more ISPs, even if one of the ISPs is accessing from a legitimate home appliance, it is highly likely that the others are communications spoofing TV3. Therefore, it is determined to be spoofing (step S504), and the process ends.
[0137] 12, since the determination result is spoofing, the combinations of source IP address and destination IP address, C_IP5 / S_IP and C_IP6 / S_IP, are added to the block list (S307). After that, it is confirmed whether or not it is the last record on the spoofing grey list (S308), and since it is not the last record (No in S308), the process returns to step S301.
[0138] After record No. 4 is read in step S301, a communication overlap determination is performed (S302). Since record No. 4 contains three source IP addresses, the overlap determination is performed twice. Specifically, referring to Figure 13, in step S401, an initial value of 1 is assigned to counter N, and the communication end time of the first C_IP7 in record No. 4 is compared with the communication start time of the second C_IP8 (S402).
[0139] 19, since the communication start time of C_IP6, "13:26:18", is later than the communication end time of C_IP7, "13:25:41" (No in S403), it is determined that there is no overlap in communication (S404). Since C_IP8 is not the last source IP address in record No. 4 (No in S405), N is assigned N+1 (S406), and the process returns to step S402.
[0140] The communication end time of the second C_IP8 in record No. 4 is compared with the communication start time of the third C_IP9 (S402).
[0141] 18, since the communication start time of C_IP9, "13:31:51", is later than the communication end time of C_IP8, "13:29:26" (No in S403), it is determined that there is no overlap in communication (S404). Since C_IP9 is the last source IP address in record No. 4 (Yes in S405), the process ends.
[0142] Returning to FIG. 12, in step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0143] In step S501 of Figure 14, the number of anonymous communication services included in record No. 4 is counted. Both C_IP7 and C_IP8 have "-" stored in the anonymous communication service name, and C_IP9 has "VPN2" stored. In other words, the number of anonymous communication services included in record No. 4 is one, so proceed to step S505 and check the number of ISPs for non-anonymous communication included in record No. 4. Since C_IP9 is for anonymous communication, ISP6 for C_IP7 and ISP7 for C_IP8 are targeted, resulting in a total of two ISPs. Since a typical household typically has a contract with one ISP, if there are two or more ISPs, even if one of them is access from a legitimate home appliance, the others are very likely communications spoofing TV4. Therefore, it is determined to be spoofing (step S506), and processing ends.
[0144] In step S306 of FIG. 12, since the determination result is spoofing, the combinations of source IP address and destination IP address C_IP7 / S_IP, C_IP8 / S_IP, and C_IP9 / S_IP are added to the block list (S307).
[0145] Thereafter, it is confirmed whether or not the record is the last record on the spoofing grey list (S308), and since it is not the last record (No in S308), the process returns to step S301.
[0146] After record No. 5 is read in step S301, communication overlap determination is performed (S302). Specifically, referring to Fig. 13, first, in step S401, an initial value of 1 is assigned to counter N, and the communication end time of the first C_IP 10 in record No. 5 is compared with the communication start time of the second C_IP 11 (S402).
[0147] 20, since the communication start time of C_IP11, "13:35:47", is later than the communication end time of C_IP10, "13:19:21" (No in S403), it is determined that there is no overlap in communication (S404), and since C_IP11 is the last source IP address in record No. 5 (Yes in S405), the process ends.
[0148] Returning to FIG. 12, in step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0149] In step S501 of Figure 14, the number of anonymous communication services included in record No. 5 is counted. C_IP10 has "-" stored in the anonymous communication service name, and C_IP11 has "VPN3" stored. In other words, the number of anonymous communication services included in record No. 5 is one, so the process proceeds to step S505, where the number of ISPs for non-anonymous communication included in record No. 5 is checked. Since C_IP11 is anonymous communication, ISP9 for C_IP10 is the target, and the number of ISPs is one. In the case of this combination of one anonymous communication and one non-anonymous communication, it is possible that a legitimate home appliance (TV5) normally accesses home appliance server 31 using an IP address assigned by ISP9, but connects to VPN3 when using services such as watching videos. Therefore, the process proceeds to step S507, where the access history of TV5 is first extracted.
[0150] 7 shows an example of the results of performing the procedures of steps S601 to S604 in Fig. 15 and extracting the access history from TV 5 for the past year. From this access history, it is checked whether VPN 3 is an anonymous communication service that is used on a daily basis (step S508).
[0151] Based on the access history in Figure 7, since the IP address of ISP9 and VPN3 has been used continuously for the past year, it is determined that VPN3 is an anonymous communication service that is used on a daily basis (Yes in S508), and in step S509 it is determined that this is not spoofing, and the process is terminated.
[0152] Here, if the anonymous communication service appearing in the access history of Figure 7 is something other than VPN3, for example VPN5, then even though VPN5 is the anonymous communication service that is used on a daily basis, it will be determined that the one-off access from VPN3 this time is highly likely to be spoofing.
[0153] After the spoofing determination process is completed, in step S306 of FIG. 12, since the determination result is not spoofing, it is checked whether it is the last record in the spoofing grey list (S308), and since it is not the last record (No in S308), the process returns to step S301.
[0154] After record No. 6 is read in step S301, communication overlap determination is performed (S302). Specifically, referring to Fig. 13, an initial value of 1 is assigned to counter N in step S401, and the communication end time of the first C_IP 12 in record No. 6 is compared with the communication start time of the second C_IP 13 (S402).
[0155] 21, since the communication start time of C_IP13, "13:51:37", is later than the communication end time of C_IP12, "13:45:11" (No in S403), it is determined that there is no overlap in communication (S404), and since C_IP13 is the last source IP address in record No. 6 (Yes in S405), the process ends.
[0156] Returning to FIG. 12, in step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0157] In step S501 of Fig. 14, the number of anonymous communication services included in record No. 6 is counted. Both C_IP12 and C_IP13 store "VPN4" as the anonymous communication service name. In other words, the number of anonymous communication services included in record No. 6 is 1, so the process proceeds to step S505, where the number of ISPs for non-anonymous communication included in record No. 6 is checked. As described above, both C_IP12 and C_IP13 are for anonymous communication, so the number of ISPs for non-anonymous communication is 0.
[0158] In this case where there is only one anonymous communication, similar to record No. 5, it is highly likely that the legitimate home appliance (TV 6) normally accesses home appliance server 31 using an IP address assigned by the ISP with which it has a contract, but connects to VPN 4 when watching videos or the like and the IP address has changed for some reason (Case 1), or that the legitimate home appliance (TV 5) mainly uses VPN 4 on a daily basis and the IP address has changed (Case 2). Therefore, in order to distinguish between these cases, the process proceeds to step S507, where the access history of TV 6 is first extracted.
[0159] 8 shows an example of the results of performing the above-described steps S601 to S604 in Fig. 15 and extracting the access history for the past year from the TV 6. From this access history, the number of past non-anonymous communication services is checked to determine whether it is Case 1 or Case 2 (Step S512).
[0160] 8, it has been determined that only VPN4 has been used continuously for the past year, which corresponds to the above-mentioned Case 2. In other words, it is determined that there is no spoofing (step S513), and the process ends.
[0161] Here, if the anonymous communication service appearing in the access history of Figure 8 is something other than VPN4, for example VPN5, then even though VPN5 is the anonymous communication service that is used on a daily basis, it will be determined that the one-off access from VPN4 this time is highly likely to be spoofing.
[0162] After the spoofing determination process is completed, in step S306 of Figure 12, the determination result is not spoofing, so it is checked whether it is the last record in the spoofing gray list (S308), and since it is the last record (Yes in S308), the fraudulent communication determination process is terminated.
[0163] [1.4 Second Operation of the Unauthorized Communication Detection System 1] In the first operation, which is the basic processing operation according to this embodiment, when the same device ID is accessed from different IP addresses during a certain period of time, it is determined whether each of these communications is anonymous or non-anonymous, and the number and combination of these communications is also taken into consideration to determine whether or not the communication is spoofing. In the second operation, by adding the country name and city name associated with the IP address to the determination conditions, it is possible to improve the accuracy of spoofing determination when there is only one ISP, such as in steps S503, S509, and S510 in the spoofing determination process of FIG. 14.
[0164] 22 is a diagram showing the spoofing grey list in the second operation of this embodiment. Compared to the spoofing grey list in FIG. 6 used in the first operation, information on country names, city names, latitudes, and longitudes has been added.
[0165] 23 is a diagram showing an example of spoofing determination processing in the second operation of this embodiment. A more detailed determination procedure (steps S701 to S705) using country names and city names is added to step S503 in FIG. 14 used in the first operation.
[0166] The processing that differs from the first operation will be described using FIG. 22 and FIG. 23, and the description of other equivalent processing will be omitted.
[0167] The unauthorized communication determination unit 204 reads out record No. 1 of the spoofing gray list in Fig. 22 and, since there is no overlap in communication, proceeds to the spoofing determination process in Fig. 23.
[0168] 23, the number of anonymous communication services included in record No. 1 is counted. Since both C_IP14 and C_IP15 have "-" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 1 is 0, the process proceeds to step S502, where the number of ISPs included in record No. 1 is checked.
[0169] Since both C_IP14 and C_IP15 are ISP13 and the number of ISPs is one, the process proceeds to step S701 to count the number of countries. C_IP14 is the United Kingdom and C_IP15 is Israel, so the number of countries is two.
[0170] In this situation, a home appliance with a device ID of TV7 is being accessed from the UK and Israel at almost the same time, and since it is clear that one of the accesses is likely to be an unauthorized access through spoofing, it is determined to be spoofing (step S704), and the process is terminated.
[0171] In this case, it is not possible to determine which is the unauthorized access due to spoofing, so in step S307 of FIG. 12, the combinations of source IP address and destination IP address, C_IP14 / S_IP and C_IP15 / S_IP, are added to the block list (S307).
[0172] Here, record No. 1 is a record that is determined not to be spoofed in the first operation, but it can be determined to be spoofed in the second operation, which adds a determination based on the number of countries and improves the determination accuracy.
[0173] Next, the unauthorized communication determination unit 204 reads record No. 2, and since there is no overlap in the communications, the unauthorized communication determination unit 204 proceeds to the spoofing determination process of Fig. 23. In step S501 of Fig. 23, the number of anonymous communication services included in record No. 2 is counted.
[0174] Since both C_IP16 and C_IP17 have "-" stored in the anonymous communication service name and the number of anonymous communication services included in record No. 2 is 0, the process proceeds to step S502, where the number of ISPs included in record No. 2 is checked.
[0175] Since both C_IP16 and C_IP17 are ISP14 and the number of ISPs is one, the process proceeds to step S701, where the number of countries is counted.
[0176] C_IP16 is France, and C_IP17 is also France, so the number of countries is 1. Therefore, the process proceeds to step S702, where the number of cities is counted.
[0177] C_IP16 is Paris, C_IP17 is also Paris, and the number of cities is one.
[0178] In this situation, it is highly likely that these two source IP addresses belong to the same user, so it is determined that this is not spoofing (step S705), and the process ends.
[0179] Next, the unauthorized communication determination unit 204 reads record No. 3, and since there is no overlap in communications, proceeds to the spoofing determination process of Fig. 23. In step S501 of Fig. 23, the number of anonymous communication services included in record No. 3 is counted. Since both C_IP18 and C_IP19 have "-" stored in the anonymous communication service name and the number of anonymous communication services included in record No. 3 is 0, proceeds to step S502, and the number of ISPs included in record No. 3 is checked.
[0180] Since both C_IP18 and C_IP19 are ISP15, and the number of ISPs is one, the process proceeds to step S701, where the number of countries is counted.
[0181] C_IP18 is Japan, and C_IP19 is also Japan, so the number of countries is 1. Therefore, the process proceeds to step S702, where the number of cities is counted.
[0182] C_IP18 is Fukuoka and C_IP19 is Aomori, making the number of cities two.
[0183] In step S703, it is confirmed whether the distance between the cities is long or short. Specifically, using the latitude and longitude information in the record, the straight-line distance is calculated using the cosine theorem of spherical trigonometry to obtain 1,218.7285 km, and if this straight-line distance exceeds a threshold, it is determined that the cities are long.
[0184] Here, the threshold value may be determined assuming that home appliances are transported by car, for example, 240 km, which is the distance that a car traveling at 80 km / h can travel in three hours, or may be determined assuming other situations. This threshold value is merely an example and is not limited to this.
[0185] Furthermore, the distance between cities is calculated using the cosine law of spherical trigonometry, but it may also be calculated by mapping latitude and longitude onto a vector space, or other methods may be used.
[0186] In this situation, home appliances with a device ID of TV9 are accessing the network from Fukuoka City and Aomori City, which are approximately 1,219 km apart in a straight line, at almost the same time. Since the distance is over 240 km, it is determined that the distance is far. Since it is clear that one of the accesses is likely to be an unauthorized access by spoofing, it is determined that the access is spoofing (step S704), and the process ends.
[0187] In this case, it is not possible to determine which is the unauthorized access due to spoofing, so in step S307 of FIG. 12, the combinations of source IP address and destination IP address, C_IP18 / S_IP and C_IP19 / S_IP, are added to the block list (S307).
[0188] Here, record No. 3 is a record that is determined not to be spoofed in the first operation, and is an access from the same country, but in the second operation, which adds a determination based on the number of cities and distance, these two records are determined in more detail and are determined to be spoofed.
[0189] Next, the unauthorized communication determination unit 204 reads record No. 4 and, since there is no overlap in the communications, proceeds to the spoofing determination process of FIG.
[0190] 23, the number of anonymous communication services included in record No. 4 is counted. Since both C_IP20 and C_IP21 have "-" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 4 is 0, the process proceeds to step S502, where the number of ISPs included in record No. 4 is checked.
[0191] Since both C_IP20 and C_IP21 are ISP16 and the number of ISPs is one, the process proceeds to step S701, where the number of countries is counted.
[0192] C_IP20 is Japan, and C_IP21 is also Japan, so the number of countries is 1. Therefore, the process proceeds to step S702, where the number of cities is counted.
[0193] C_IP20 is Osaka, and C_IP21 is Amagasaki, resulting in two cities. In step S703, it is confirmed whether the distance between the cities is long or short. Specifically, using the latitude and longitude information in the record, the straight-line distance is calculated using the cosine theorem of spherical trigonometry to obtain a straight-line distance of 7.562 km. Because this straight-line distance is below the threshold value of 240 km, it is determined that the cities are close.
[0194] In this situation, a home appliance with a device ID of TV10 was accessed from Osaka City and Amagasaki City at almost the same time, and it is possible that one of them was accessed through unauthorized spoofing, but it cannot be ruled out that the TV10 used in Osaka City was transported to Amagasaki City by car.
[0195] In this case, the second operation places importance on preventing false positives and determines that this is not spoofing (step S705), and ends the process.
[0196] In the case of a system or service specification that places emphasis on detecting unauthorized access caused by spoofing, it may be determined that the access is spoofing.
[0197] In order to further improve the detection accuracy, the start time / end time of communication may also be included in the judgment criteria, and whether or not it is spoofing may also be determined based on whether or not it is within the time frame for transportation between the two cities.
[0198] Furthermore, the accuracy of detection can be improved by including in the judgment criteria whether the device ID is for an appliance that is relatively easy to transport, such as a small TV or mobile terminal, or a large appliance that is relatively difficult to transport, such as a refrigerator, washing machine, or air conditioner.
[0199] In the explanation of the second operation of this embodiment, an example was given in which a more detailed determination procedure using country names and city names was added after step S502, but this is not limiting. For example, a similar determination procedure may be inserted after the branch in step S505 where the number of ISPs is one. Specifically, the procedures of steps S701 to S703 may be inserted immediately before step S509 to improve detection accuracy.
[0200] [1.5 Third operation of the fraudulent communication detection system 1] In the first operation, which is the basic processing operation of this embodiment, when the same device ID is accessed from different IP addresses within a certain period of time, it is determined whether each of these communications is anonymous or non-anonymous, and the number and combination of these communications is also taken into consideration to determine whether they are spoofing.
[0201] In the third operation, the accuracy of the spoofing determination process of FIG. 14 can be improved by adding the type of home appliance that can be determined from the device ID to the determination conditions.
[0202] 24 is a diagram showing a spoofing grey list in the third operation of this embodiment. Compared to the spoofing grey list in FIG. 6 used in the first operation, information on device types has been added.
[0203] 47 shows a device type list for the third operation of this embodiment. In addition to the device type and device ID, the list stores whether or not the device type is likely to use anonymous communication.
[0204] 25 is a diagram showing an example of spoofing determination processing in the third operation of this embodiment. In the case where the number of anonymous communication services is one or more in step S501 of FIG. 14 used in the first operation, a more detailed determination procedure (steps S801 to S802) using the home appliance type is added.
[0205] The processing that differs from the first operation will be described using FIG. 24 and FIG. 25, and the description of other equivalent processing will be omitted.
[0206] The unauthorized communication determination unit 204 reads out record No. 1 of the spoofing gray list in Fig. 24 and, since there is no overlap in communication, proceeds to the spoofing determination process in Fig. 25.
[0207] 25, the number of anonymous communication services included in record No. 1 is counted. Since C_IP22 has "-" stored in the anonymous communication service name and C_IP23 has "VPN5" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 1 is 1, the process proceeds to step S801, where the device ID included in record No. 1 is checked and the home appliance type is determined by referring to the device type list in FIG.
[0208] The device ID "TV11" indicates a television, and since it is possible that an anonymous communication service such as a VPN may be used, the process proceeds to the detailed determination procedure from step S505 onwards (description thereof will be omitted).
[0209] Next, the unauthorized communication determination unit 204 reads record No. 2, and since there is no overlap in the communications, the unauthorized communication determination unit 204 proceeds to the spoofing determination process of Fig. 23. In step S501 of Fig. 23, the number of anonymous communication services included in record No. 2 is counted.
[0210] C_IP24 stores "-" as the anonymous communication service name, and C_IP25 stores "VPN6" as the anonymous communication service name, and the number of anonymous communication services included in record No. 2 is one. Therefore, the process proceeds to step S801, where the device ID included in record No. 2 is checked, and the type of home appliance is determined by referring to the device type list in FIG. 47 .
[0211] The device ID "AC1" indicates an air conditioner, and it is unlikely that an anonymous communication service such as a VPN would be used. Therefore, it is determined to be spoofing (step S802), and the process ends.
[0212] In the description of the third operation, an air conditioner, which is not shown in the overall configuration diagram of Fig. 2, is used as an example of a home appliance, but the present invention is not limited to this. Other home appliances such as a refrigerator and a washing machine may also be used.
[0213] [1.6 Fourth operation of unauthorized communication detection system 1] In the fourth operation of this embodiment, the detection accuracy can be further improved by adding the state of the home appliance to the judgment conditions related to the type of home appliance in the third operation.
[0214] For example, if the TV status is "streaming playback," "tuner playback," or "recorded program playback," it would not be strange to use a VPN when "streaming playback," but it would be unnatural to use a VPN while watching a program on terrestrial, BS, or CS broadcasts. This procedure incorporates this idea into the criteria for judgment.
[0215] These home appliance states are included in communication data received from the home appliances and are stored in the communication log storage unit 205 as a communication log as shown in FIG.
[0216] 27 is a diagram showing a spoofing grey list in the fourth operation of the present embodiment. Compared to the spoofing grey list in FIG. 6 used in the first operation, information on the status of the home appliance is added.
[0217] 48 shows a device type list for the third operation of this embodiment. In addition to the device type and device ID, the device status and whether or not anonymous communication is possible in the device status are stored.
[0218] 28 is a diagram showing an example of spoofing determination processing in the fourth operation of this embodiment. In the case where the number of anonymous communication services is one or more in step S501 of FIG. 14 used in the first operation, a more detailed determination procedure (steps S901 to S903) using the home appliance type and the home appliance state is added.
[0219] The processing that differs from the first operation will be described using FIG. 27 and FIG. 28, and the description of other equivalent processing will be omitted.
[0220] The unauthorized communication determination unit 204 reads out record No. 1 of the spoofing grey list in Fig. 27 and, since there is no overlap in communication, proceeds to the spoofing determination process in Fig. 28.
[0221] 28, the number of anonymous communication services included in record No. 1 is counted. Since C_IP26 has "-" stored in the anonymous communication service name and C_IP27 has "VPN7" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 1 is 1, the process proceeds to step S901, where the device ID included in record No. 1 is checked and the home appliance type is determined by referring to the device type list in FIG.
[0222] Since the device ID "TV12" indicates a television and may be using an anonymous communication service such as a VPN, the process proceeds to step S903, where the home appliance status included in record No. 1 is checked. The home appliance status of both C_IP26 and C_IP27 is "streaming playback," which indicates that a video distribution service is being used via the Internet.
[0223] A possible case is that C_IP 26 was watching a video, but VPN settings were made to watch a video from another country, and C_IP 27 continued watching the operation. If "streaming playback" is selected from the device type list, there is a possibility that anonymous communication is being used, so the process proceeds to the determination procedure from step S505 onwards (description omitted).
[0224] Next, the unauthorized communication determination unit 204 reads record No. 2 and, since there is no overlap in the communications, proceeds to the spoofing determination process of FIG.
[0225] 28, the number of anonymous communication services included in record No. 2 is counted. Since C_IP28 has "-" stored in the anonymous communication service name and C_IP29 has "VPN8" stored in the anonymous communication service name, and the number of anonymous communication services included in record No. 2 is 1, the process proceeds to step S901, where the device ID included in record No. 2 is checked and the home appliance type is determined by referring to the device type list in FIG.
[0226] Since the device ID "TV13" indicates a television and may be using an anonymous communication service such as a VPN, the process proceeds to step S903, where the home appliance status included in record No. 2 is checked.
[0227] The home appliance status of both C_IP28 and C_IP29 is "tuner playing", which indicates that a program such as terrestrial broadcasting or BS / CS broadcasting is being viewed.
[0228] Since "tuner playing" from the device type list cannot be a case where anonymous communication is used, C_IP 29 determines that it is spoofing (step S902) and ends the process.
[0229] In this case, by adding only C_IP 29 of the source IP addresses to the block list, the risk of C_IP 28, which is highly likely to be a legitimate user, being blocked from the home appliance server 31 can be reduced.
[0230] Next, the unauthorized communication determination unit 204 reads record No. 3 and, since there is no overlap in the communications, proceeds to the spoofing determination process of FIG.
[0231] 28, the number of anonymous communication services included in record No. 3 is counted. Since C_IP30 stores "VPN9" as the anonymous communication service name and C_IP31 stores "VPN10" as the anonymous communication service name, and the number of anonymous communication services included in record No. 3 is two, the process proceeds to step S901, where the device ID included in record No. 3 is checked and the home appliance type is determined by referring to the device type list in FIG.
[0232] Since the device ID "TV14" indicates a television and may be using an anonymous communication service such as a VPN, the process proceeds to step S903, where the home appliance status included in record No. 3 is checked.
[0233] The home appliance status of C_IP30 is "tuner playing" and a program such as terrestrial broadcasting or BS / CS is being viewed, and "tuner playing" from the device type list means that anonymous communication is not possible.
[0234] On the other hand, the home appliance status of C_IP31 is "streaming playback", and "streaming playback" in the device type list means that anonymous communication may be used.
[0235] Taking all of these factors into consideration, C_IP 30 determines that the request is an impersonation (step S902) and ends the process.
[0236] In this case, by adding only C_IP30 of the source IP addresses to the block list, the risk of C_IP31, which is highly likely to be a legitimate user, being blocked from the home appliance server 31 can be reduced.
[0237] In the description of the fourth operation, the two states of the home appliance, "streaming playback" and "tuner playback," are given as examples, but the home appliance state is not limited to these. The home appliance state may be other states such as "power off," "recording," "watching a recorded program," or "standby."
[0238] Furthermore, although a television is used as an example of the type of home appliance, the present invention is not limited to this and may be any other type of home appliance that is considered to use an anonymous communication service.
[0239] Here, in the first operation, which is a basic processing operation, if the spoofing determination process of Figure 14 determines that spoofing has occurred (steps S504, S506, S510), even if communications from a legitimate user are included, they cannot be identified, and all multiple source IP addresses are added to the block list, thereby blocking access from legitimate users as well.
[0240] In contrast, the fourth operation adds the type of home appliance and the state of the appliance to the judgment conditions, which has the effect of increasing the possibility of identifying a spoofed source IP address among multiple source IP addresses.
[0241] [1.7 Effects of First Embodiment] In the present embodiment, when the same device ID is accessed from different IP addresses during a certain period of time, it is confirmed whether each of these multiple communications is anonymous or non-anonymous, and by taking into consideration the number and combination of these communications, the country name and city name linked to the source IP address, and the type and status of the home appliance, it is possible to determine that the IP address has changed in a normal use case of a legitimate home appliance, even in cases where a device ID would normally be erroneously detected as being spoofed, and it is possible to prevent erroneous detection as much as possible.
[0242] Second Embodiment In the first embodiment of the present disclosure, all home appliances accessed via the Internet 10 are treated as individual appliances.
[0243] Here, as a second embodiment of the present disclosure, we will describe a configuration that can further improve the accuracy of detecting impersonation by grouping home appliances that access via the Internet 10 by household and making a judgment by comparing their status with that of other home appliances in the same household.
[0244] [2. Details of the Second Embodiment] Here, as the second embodiment of the present disclosure, an unauthorized communication detection system 2 according to the present disclosure will be described with reference to the drawings. Note that components having the same functions as those in the first embodiment of the present disclosure are designated by the same reference numerals, and detailed descriptions thereof will be omitted.
[0245] 2.1 Overall Configuration of the Unauthorized Communication Detection System 2 Figure 29 is a diagram showing the network configuration of the unauthorized communication detection system 2 according to the present disclosure. The unauthorized communication detection system 2 includes the Internet 10, a home network 11, an unauthorized communication detection device 21, a VPN server 30, a home appliance server 31, a communication information providing server 32, a TV 40, an air conditioner 41, a refrigerator 42, and a router 50. The difference from the first embodiment of the present disclosure is that the home network 11 in which the home appliances reside is illustrated in detail.
[0246] A router 50 is installed at the boundary between the home network 11 and the Internet 10. The TV 40, the air conditioner 41, and the refrigerator 42 are home appliances with network functions, and are connected to the home appliance server 31 via the home network 11 and the Internet 10, respectively.
[0247] The TV 40 stores the device ID "TV1", the air conditioner 41 stores the device ID "AC1", and the refrigerator 42 stores the device ID "FR1" in a memory unit within the device, and when communicating with the home appliance server 31, the device ID is included in the communication data.
[0248] It is also assumed that the TV 40, the air conditioner 41, and the refrigerator 42 are all located in the same house, and that the coordinate information acquired by each of them using a GPS (Global Positioning System) function or the like is the same value.
[0249] In this embodiment, the TV 40, the air conditioner 41, and the refrigerator 42 are used as components of the unauthorized communication detection system 2 as home appliances connected to the home network 11, but other home appliances may also be used.
[0250] 30 is a block diagram showing the configuration of the unauthorized communication detection device 21. Components having the same functions as those in the first embodiment are given the same reference numerals, and detailed description thereof will be omitted.
[0251] The unauthorized communication detection device 21 includes a communication unit 201, a communication log collection unit 202, an impersonation gray list creation unit 203, an unauthorized communication determination unit 204, a communication log holding unit 205, a block list holding unit 206, a gray list holding unit 207, an access history holding unit 208, an equipment type list holding unit 209, a house identification list creation unit 210, and a house identification list holding unit 211.
[0252] The communication log storage unit 205 stores a log of all packets received by the communication unit 201. Fig. 31 is a diagram showing an example of the communication log. The communication log is basically the same as the communication log of the first embodiment shown in Fig. 4, but additionally stores coordinate information acquired by the transmitting home appliance using GPS or the like as house identification information.
[0253] 31 is an example, and the home identification information may include information other than the coordinate information. For example, the home identification information may be information input or set by a user to the home appliance, or the home appliance itself may acquire information indicating the characteristics of the home from another facility device connected to the same home network using a protocol such as ECHONET Lite (registered trademark), and store the information as the home identification information.
[0254] Specific examples of obtaining information indicating the characteristics of a house include obtaining the cumulative amount of power generated from a fuel cell (not shown), obtaining the cumulative amount of power from a watt-hour meter (not shown), obtaining the cumulative water flow rate from a water flow meter (not shown), or obtaining the cumulative amount of gas consumed from a gas meter (not shown), etc. Appliances with the same usage amount in the same time period can be determined to be in the same house.
[0255] The grey list holding unit 207 holds a spoofing grey list that lists device IDs and communication information related to communications from multiple source IP addresses. Fig. 32 shows an example of a spoofing grey list. This is basically the same as the grey list of the first embodiment shown in Fig. 6, but house identification information is additionally stored.
[0256] The house identification list creation unit 210 reads the spoofing grey list from the grey list holding unit 207, reads the communication log from the communication log holding unit 205 using the house identification information of each record as a key, extracts communication logs from home appliances having the same house identification information during the same time period, creates a house identification list, and stores it in the house identification list holding unit 211.
[0257] The house identification list holding unit 211 holds a house identification list that allows home appliances to be identified on a house-by-house basis. Fig. 33 is a diagram showing an example of the house identification list. The house identification list in Fig. 31 stores a list of grey list numbers linked to grey list record numbers, house identification information, device IDs, source IP addresses, ISP names, and anonymous communication service names.
[0258] The operation of the unauthorized communication detection device 21 and the unauthorized communication detection system 2 configured as above will be described below.
[0259] 34 is a flowchart showing the operation of the unauthorized communication detection system 2 according to this embodiment. The operation of the unauthorized communication detection system 2 includes four processes: a communication log collection process, a spoofing gray list creation process, a house identification list creation process, and an unauthorized communication determination process.
[0260] First, the communication log collection process starts when the unauthorized communication detection device 21 is started (step S001). This process is executed asynchronously with subsequent processes and continues until the unauthorized communication detection device 21 is stopped (shut down).
[0261] Next, the spoofing gray list creation process is executed (step S002), followed by the house identification list creation process (step S1001), and then the unauthorized communication determination process is executed (step S003). After waiting for a certain period of time (step S004), the process returns to step S002. In other words, the processes of steps S002 to S004 are repeated at regular intervals until the unauthorized communication detection device 21 is stopped (shut down).
[0262] [2.3.1 Operation During House Identification List Creation Process] FIG. 35 is a flowchart showing an example of the house identification list creation process of the unauthorized communication detection system 2.
[0263] In step S1101, the house identification list creation unit 210 reads out a communication log for a certain period of time from the communication log holding unit 205 at regular intervals.
[0264] In step S1102, the spoofing grey list is read from the grey list holding unit 207.
[0265] In step S1103, a communication log is extracted from the communication log read in step S1101 using the house identification information of one record in the grey list as a key.
[0266] In step S1104, the record number of the currently read impersonation gray list, the house identification information extracted from the extracted communication log, the device ID, the source IP address, the ISP name, and the anonymous communication service name are added to the house identification list of the house identification list holding unit 211.
[0267] Thereafter, in step S1105, it is confirmed whether the read record in the spoofing grey list is the last record, and if it is not the last record (No in S1105), the process returns to step S1103. If it is the last record (Yes in S1105), the process ends.
[0268] [2.3.2 Operation During Unauthorized Communication Determination Processing] Fig. 36 is a flowchart showing an example of the unauthorized communication determination processing (step S003) in embodiment 2. This is almost the same as the processing in Fig. 12 in embodiment 1, but in embodiment 2, the operation of the spoofing determination processing in step S305 is different.
[0269] Details will be explained later, but the difference is that this spoofing determination process also involves adding the source IP address to the block list, so checking the spoofing determination results in step S306 in Figure 12 is no longer necessary and has been deleted.
[0270] FIG. 37 is a flowchart showing an example of the spoofing determination process (S305) of the unauthorized communication detection system 2.
[0271] 37, a house identification list including the record number of the spoofing grey list read in S301 is read from the house identification list holding unit 211. Next, one piece of sender information is picked up from the multiple pieces of sender information included in the record of the spoofing grey list read in step S301. In step S1203, it is confirmed whether the ISP included in the picked up sender information is the same as the ISP of another home appliance in the house identification list read in step S1201.
[0272] If the ISP is the same as that of the other home appliances (Yes in S1203), it is determined that the source IP address of the picked-up source information is not spoofed (step S1206), and it is confirmed whether it is the last source information in the record (step S1208).
[0273] If it is the last piece of source information (Yes in S1208), the process ends, and if it is not the last piece of source information (No in S1208), the process returns to step S1202.
[0274] If the ISP is not the same as that of the other home appliances (No in S1203), it is checked in step S1204 whether the anonymous communication service is being used by the other home appliances. If the same anonymous communication service is being used by the other home appliances (Yes in S1204), it is determined that the source IP address of the picked-up source information is not spoofed (step S1206), and it is checked whether it is the last source information in the record (step S1208). If it is the last source information (Yes in S1208), the process ends, and if it is not the last source information (No in S1208), the process returns to step S1202.
[0275] If the same anonymous communication service as other home appliances is not being used (No in S1204), in step S1205, it is determined that the information is being impersonated, and the combination of the source IP address and destination IP address of the source information is added to the block list (step S1207).
[0276] Then, it is confirmed whether or not it is the last sender information in the record (step S1208). If it is the last sender information (Yes in S1208), the process ends, and if it is not the last sender information (No in S1208), the process returns to step S1202.
[0277] 32, 38, 40, 42, and 44 are diagrams showing first to fifth examples of the spoofing grey list in embodiment 2. Also, FIGS. 33, 39, 41, 43, and 45 are diagrams showing first to fifth examples of the house identification list in embodiment 2.
[0278] The processing of the unauthorized communication determination unit 204 will be specifically described below with reference to FIGS.
[0279] First, a first specific example will be described with reference to FIGS. 32, 33, 36, and 37.
[0280] In unauthorized communication determination processing step S301 in Fig. 36, after reading out the record of spoofing grey list No. 1 in Fig. 32, communication overlap determination is performed (S302). This determination processing is the same as in embodiment 1, and therefore detailed procedures will be omitted.
[0281] In step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0282] 37, the house identification list linked to the read grey list No. 1 is read from the house identification list holding unit 211.
[0283] Specifically, as shown in Fig. 33, a list in which 1 is stored in the grey list No. is extracted. The house identification list in Fig. 33 is obtained by extracting communication logs having "coordinate information A" as house identification information from among communication logs accessed during the same time period, and therefore also includes communication logs of the two source home appliances listed in the spoofing grey list in Fig. 32. In other words, one or both of the device IDs "TV1" in Fig. 33 are spoofed fraudulent home appliances, and "AC1" and "FR1" are information on other home appliances other than the two "TV1"s that exist in the same house.
[0284] In step S1202, the first source information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances present in the same house in FIG.
[0285] The greylist side is "ISP3" and the other home appliance is "ISP1", and since these are different (No in S1203), the process proceeds to step S1204 to check whether the same anonymous communication service is being used as the other home appliances. Specifically, the anonymous communication service name "-" included in the first sender information item of record No. 1 in the greylist is compared with the anonymous communication service name "-" of the other home appliances in the same house in FIG. 33. In this case, since it indicates that neither is using an anonymous communication service, it is determined that the same anonymous communication service is not being used (No in S1204).
[0286] This situation indicates that the ISP is different when no anonymous communication service is being used, i.e., the IP address of the home router is different, so it is determined that the first sender in greylist record No. 1 is in a different home from the other home appliances, i.e., spoofing (step S1205), and C_IP3 / S_IP, which is the combination of the source IP address and destination IP address, is added to the block list (step S1207).Since this is not the last sender information in greylist record No. 1 (No in S1208), the process returns to step S1202.
[0287] In step S1202, the second sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 33. The grey list side is "ISP3" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0288] Specifically, the anonymous communication service name "-" included in the second sender information of record No. 1 on the grey list is compared with the anonymous communication service name "-" of another home appliance in the same house in Fig. 33. In this case, since it indicates that neither appliance uses an anonymous communication service, it is determined that the appliances do not use the same anonymous communication service (No in S1204).
[0289] This situation indicates that the ISP is different and no anonymous communication service is being used, i.e., the IP address of the home router is different, so the second sender in greylist record No. 1 is determined to be spoofed (step S1205), and C_IP4 / S_IP, which is the combination of the source IP address and destination IP address, is added to the block list (step S1207). Because this is the last sender information in greylist record No. 1 (Yes in S1208), the process ends.
[0290] This first specific example is a record that would be determined not to be spoofing in embodiment 1, but in embodiment 2, which improves the accuracy of spoofing detection by comparing the state with other home appliances in the same house, it was possible to determine that it was spoofing.
[0291] Next, a second specific example will be described with reference to FIGS. 36, 37, 38, and 39.
[0292] In unauthorized communication determination processing step S301 in Fig. 36, after reading out the record of spoofing grey list No. 1 in Fig. 38, communication overlap determination is performed (S302). This determination processing is the same as in embodiment 1, and therefore detailed procedures will be omitted.
[0293] In step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0294] In step S1201 of Fig. 37, the house identification list associated with the read grey list No. 1 is read from the house identification list holding unit 211. Specifically, as shown in Fig. 39, a list in which 1 is stored as the grey list No. is extracted. The house identification list of Fig. 39 is obtained by extracting communication logs having "coordinate information A" as house identification information from among communication logs accessed during the same time period, and therefore also includes communication logs of the two source home appliances listed in the spoofing grey list of Fig. 38. In other words, one or both of the device IDs "TV1" in Fig. 39 are spoofed unauthorized home appliances, and "AC1" and "FR1" are information on other home appliances other than the two "TV1"s that exist in the same house.
[0295] In step S1202, the first sender information in greylist record No. 1 is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances present in the same house in Fig. 39. Since the greylist side is "ISP1" and the other home appliances are "ISP1," which are the same (No in S1203), it is determined that the first sender in greylist record No. 1 is present in the same house as the other home appliances, that is, it is not spoofing (step S1206), and the process proceeds to step S1208. Since this is not the last sender information in greylist record No. 1 (No in S1208), the process returns to step S1202.
[0296] In step S1202, the second sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 39. The grey list side is "ISP2" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0297] Specifically, the anonymous communication service name "-" included in the second sender information of record No. 1 on the grey list is compared with the anonymous communication service name "-" of other home appliances in the same house in Fig. 39. In this case, since it indicates that neither appliance is using an anonymous communication service, it is determined that the appliances are not using the same anonymous communication service (No in S1204).
[0298] This situation indicates that the ISP is different and no anonymous communication service is being used, i.e., the IP address of the home router is different, so the second sender in greylist record No. 1 is determined to be spoofed (step S1205), and C_IP6 / S_IP, which is the combination of the source IP address and destination IP address, is added to the block list (step S1207). Because this is the last sender information in greylist record No. 1 (Yes in S1208), the process ends.
[0299] This second specific example is a record that is determined to be spoofed in the first embodiment, and both the source IP addresses of C_IP5 and C_IP6 are added to the block list. In the second embodiment, which improves the accuracy of spoofing detection by making a determination based on a comparison of the status with other home appliances in the same house, only C_IP6 can be determined to be spoofed, and the risk of C_IP5 being blocked can be reduced.
[0300] Next, a third specific example will be described with reference to FIGS. 36, 37, 40, and 41.
[0301] In unauthorized communication determination processing step S301 in Fig. 36, after reading out the record of spoofing grey list No. 1 in Fig. 40, communication overlap determination is performed (S302). This determination processing is the same as in embodiment 1, and therefore detailed procedures will be omitted.
[0302] In step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0303] In step S1201 of Fig. 37, a house identification list linked to the read grey list No. 1 is read from the house identification list holding unit 211. Specifically, as shown in Fig. 41, a list in which 1 is stored as the grey list No. is extracted. The house identification list of Fig. 41 is obtained by extracting communication logs having "coordinate information A" as house identification information from among communication logs accessed during the same time period, and therefore also includes communication logs of the three source home appliances listed in the spoofing grey list of Fig. 40. In other words, any or all of the device IDs "TV1" in Fig. 41 are spoofed unauthorized home appliances, and "AC1" and "FR1" are information on other home appliances other than the three "TV1"s that exist in the same house.
[0304] In step S1202, the first sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 41. The grey list side is "ISP6" and the other home appliances are "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0305] Specifically, the anonymous communication service name "-" included in the first sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance in the same house in Fig. 41. In this case, it is determined that the same anonymous communication service is not being used (No in S1204).
[0306] This situation indicates that the other home appliances are using the anonymous communication service "VPN1," meaning that the home router is configured with "VPN1." The first sender in greylist record No. 1 is determined to be in a different home from the other home appliances, meaning it is spoofed (step S1205), and C_IP7 / S_IP, which is the combination of source IP address and destination IP address, is added to the block list (step S1207). Because this is not the last sender information in greylist record No. 1 (No in S1208), the process returns to step S1202.
[0307] In step S1202, the second sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 41. The grey list side is "ISP7" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0308] Specifically, the anonymous communication service name "-" included in the second sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance in the same house in Fig. 41. In this case, it is determined that the same anonymous communication service is not being used (No in S1204).
[0309] This situation indicates that other home appliances are using the anonymous communication service "VPN1," meaning that the home router is configured for "VPN1." Therefore, it is determined that the second sender in greylist record No. 1 is in a different home, meaning that it is a spoofed sender (step S1205), and C_IP8 / S_IP, which is the combination of the source IP address and destination IP address, is added to the block list (step S1207).
[0310] Since this is not the last sender information in record No. 1 of the grey list (No in S1208), the process returns to step S1202.
[0311] In step S1202, the third sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 41. The grey list side is "ISP8" and the other home appliances are "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0312] Specifically, the anonymous communication service name "VPN1" included in the third sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance in the same house in Fig. 41. In this case, it is determined that the same anonymous communication service is being used (Yes in S1204).
[0313] This situation indicates that the other home appliances are using the anonymous communication service "VPN1," meaning that the home router is configured with "VPN1." Although the third source IP address and ISP in greylist record No. 1 are different, it is possible that the user changed the VPN server before this appliance communicated, and it is highly likely that this appliance also exists in the same home. In other words, it is determined that this is not spoofing (step S1206), and the process proceeds to step S1208. Because this is the last source information in greylist record No. 1 (Yes in S1208), the process ends.
[0314] This third specific example is a record that is determined to be spoofed in the first embodiment, and the source IP addresses of C_IP7, C_IP8, and C_IP9 are all added to the block list. In the second embodiment, which improves the accuracy of spoofing detection by making a determination based on a comparison of the status with other home appliances in the same house, only C_IP7 and C_IP8 can be determined to be spoofed, and the risk of C_IP9 being blocked can be reduced.
[0315] Next, a fourth specific example will be described with reference to FIGS. 36, 37, 42 and 43.
[0316] In unauthorized communication determination processing step S301 in Fig. 36, after reading out the record of spoofing grey list No. 1 in Fig. 42, communication overlap determination is performed (S302). This determination processing is the same as in embodiment 1, and therefore detailed procedures will be omitted.
[0317] In step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0318] 37, the house identification list linked to the read grey list No. 1 is read from the house identification list holding unit 211.
[0319] Specifically, as shown in Fig. 43, a list in which 1 is stored in the grey list No. is extracted. The house identification list in Fig. 43 is obtained by extracting communication logs having "coordinate information A" as house identification information from among communication logs accessed during the same time period, and therefore also includes communication logs of the two source home appliances listed in the spoofing grey list in Fig. 42. In other words, either one of the device IDs "TV1" in Fig. 43 is a spoofed fraudulent home appliance, and "AC1" and "FR1" are information on other home appliances other than the two "TV1s" that exist in the same house.
[0320] In step S1202, the first sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 43. The grey list side is "ISP9" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0321] Specifically, the anonymous communication service name "-" included in the first sender information of record No. 1 on the grey list is compared with the anonymous communication service names "-" of other home appliances in the same house in Fig. 43. In this case, since it indicates that neither appliance uses an anonymous communication service, it is determined that the appliances do not use the same anonymous communication service (No in S1204).
[0322] This situation indicates that the ISP is different when no anonymous communication service is being used, i.e., the IP address of the home router is different, so it is determined that the first sender in record No. 1 on the grey list is in a different home from the other home appliances, i.e., it is spoofed (step S1205), and C_IP10 / S_IP, which is the combination of the source IP address and destination IP address, is added to the block list (step S1207).
[0323] Since this is not the last sender information in record No. 1 of the grey list (No in S1208), the process returns to step S1202.
[0324] In step S1202, the second sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 43. The grey list side is "ISP10" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0325] Specifically, the anonymous communication service name "VPN1" included in the second sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance present in the same house in FIG. 43 .
[0326] In this case, it is determined that the same anonymous communication service is being used (Yes in S1204). This situation indicates that the other home appliances are using the anonymous communication service "VPN1," meaning that "VPN1" is configured on the home router. Although the second source IP address and ISP in greylist record No. 1 are different, it is possible that the user changed the VPN server before this home appliance communicated, and it is highly likely that this home appliance also exists in the same house. In other words, it is determined that there is no spoofing (step S1206), and the process proceeds to step S1208. Because this is the last source information in greylist record No. 1 (Yes in S1208), the process ends.
[0327] This fourth specific example is a record that would be determined not to be spoofed in embodiment 1, but in embodiment 2, which improves the accuracy of spoofing detection by comparing the state with other home appliances in the same house, it was possible to determine that only C_IP10 was spoofed.
[0328] Finally, a fifth specific example will be described with reference to FIGS. 36, 37, 44, and 45.
[0329] In unauthorized communication determination processing step S301 in Fig. 36, after reading out the record of spoofing grey list No. 1 in Fig. 44, communication overlap determination is performed (S302). This determination processing is the same as in embodiment 1, and therefore detailed procedures will be omitted.
[0330] In step S303, the communication overlap determination result is checked, and since there is no communication overlap (No in S303), the process proceeds to spoofing determination processing (S305).
[0331] 37, in step S1201, the house identification list linked to the read grey list No. 1 is read from the house identification list holding unit 211. Specifically, as shown in FIG. 45, a list in which 1 is stored in the grey list No. is extracted.
[0332] The house identification list in Fig. 45 is an extraction of communication logs having "coordinate information A" as house identification information from among communication logs accessed during the same time period, and therefore also includes communication logs of the two source home appliances listed in the spoofing grey list in Fig. 44. In other words, one or both of the device IDs "TV1" in Fig. 45 is a spoofed fraudulent home appliance, and "AC1" and "FR1" are information on other home appliances other than the two "TV1s" that exist in the same house.
[0333] In step S1202, the first sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 45. The grey list side is "ISP11" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0334] Specifically, the anonymous communication service name "VPN2" included in the first sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance in the same house in Fig. 45. In this case, it is determined that the same anonymous communication service is not being used (No in S1204).
[0335] This situation indicates that the other home appliances are using the anonymous communication service "VPN1," meaning that the home router is configured for "VPN1." The first sender in greylist record No. 1 is determined to be in a different home from the other home appliances, meaning it is spoofed (step S1205), and C_IP12 / S_IP, which is the combination of source IP address and destination IP address, is added to the block list (step S1207). Because this is not the last sender information in greylist record No. 1 (No in S1208), the process returns to step S1202.
[0336] In step S1202, the second sender information in record No. 1 of the grey list is picked up, and the ISP information contained therein is compared with the ISP information of other home appliances in the same house in Fig. 45. The grey list side is "ISP12" and the other home appliance is "ISP1," and since these are different (No in S1203), the process proceeds to step S1204, where it is confirmed whether the same anonymous communication service as the other home appliances is being used.
[0337] Specifically, the anonymous communication service name "VPN2" included in the second sender information of record No. 1 on the grey list is compared with the anonymous communication service name "VPN1" of another home appliance in the same house in Fig. 45. In this case, it is determined that the same anonymous communication service is not being used (No in S1204).
[0338] This situation indicates that the other home appliances are using the anonymous communication service "VPN1," meaning that the home router is configured with "VPN1." The first sender in greylist record No. 1 is determined to be in a different home from the other home appliances, meaning it is spoofed (step S1205), and C_IP13 / S_IP, which is the combination of source IP address and destination IP address, is added to the block list (step S1207). Because this is the last sender information in greylist record No. 1 (Yes in S1208), the process ends.
[0339] This fifth specific example is a record that would be determined not to be spoofed in embodiment 1, but in embodiment 2, which improves the accuracy of spoofing detection by making a judgment based on a comparison of the state with other home appliances in the same house, it was possible to determine that both C_IP12 and C_IP13 were spoofed.
[0340] [3. Other Modifications] The present disclosure is not limited to the embodiments described above, and various modifications conceivable by those skilled in the art and forms constructed by combining components of different embodiments are also included within the scope of the present disclosure, as long as they do not deviate from the spirit of the present disclosure. For example, the following modifications are also included in the present disclosure.
[0341] (Variation 1) In the first and second embodiments, whether an access to the home appliance server 31 is a spoofed or not spoofed access is determined, but the severity of the spoofing may be expressed as a graded numerical value (score), and the response, such as blocking or not, may be changed depending on the score. This makes it possible to respond by not blocking access with a low severity, thereby reducing the risk of erroneous blocking due to false detection of legitimate users.
[0342] (Variant 2) In the first and second embodiments, when an access to the home appliance server 31 is determined to be spoofed, the combination of the source IP address and destination IP address of the access is added to a block list, and subsequent access is blocked. However, this is not limited to this, and it is also possible to simply notify the risk to the home appliance server 31 or a security operation center (SOC) or the like that remotely monitors the home appliance server 31.
[0343] In this case, as shown in Fig. 49, the configuration of the unauthorized communication detection device 22 is different from the configuration of the unauthorized communication detection device 20 according to the first embodiment of the present disclosure (Fig. 3) in that it does not include the block list holding unit 206, and the communication log collection process and the unauthorized communication determination process are performed as shown in the flowcharts of Fig. 50 and Fig. 51. Similar configuration and process changes can also be made in other embodiments and modifications.
[0344] (Variation 3) In the second operation of the spoofing determination process of the first embodiment, as shown in Fig. 23, when the number of anonymous communication services included in a greylist record is 0 and the number of ISPs is 1, whether or not it is spoofing is determined based on the number of countries, the number of cities, the distance between cities, etc., as criteria for determination. However, the present invention is not limited to this flow. For example, a flow chart such as that shown in Fig. 52 may also be used.
[0345] 52, the number of anonymous communication services included in the read record is counted. If the number of anonymous communication services is 0, the process proceeds to step S706, where it is checked whether the read record includes non-anonymous communication.
[0346] If there is no non-anonymous communication, it is determined in step S705 that there is no spoofing and the process ends. If there is non-anonymous communication, the process proceeds to step S701 and the number of countries is counted.
[0347] If the number of countries is two or more, it is determined in step S704 that the information is a spoofed address, and the process ends. If the number of countries is one, the process proceeds to step S702, where the number of cities is counted.
[0348] If there is one city, it is determined in step S705 that there is no spoofing and the process ends. If there are two or more cities, it is checked in step S703 whether the distance between the cities is far or close.
[0349] Specifically, the latitude and longitude information in the record is used to derive the cosine law of spherical trigonometry, and compared with a threshold to determine whether the distance is close or far. If the distance is close, it is determined in step S705 that there is no spoofing and the process ends. If the distance is far, it is determined in step S704 that there is spoofing and the process ends.
[0350] In step S501, the number of anonymous communication services included in the read record is counted, and if there is one or more anonymous communication services, the process proceeds to step S507, where the access history of the device ID is extracted.
[0351] In step S508, it is confirmed whether the anonymous communication service included in the record read from the spoofing grey list appears frequently in the access history extracted in step S507, that is, whether it is an anonymous communication service that is used on a daily basis based on the device ID.
[0352] If the service is not used on a daily basis, it is determined in step S510 that the service is spoofing, and the process ends. If the service is an anonymous communication service that is used on a daily basis, the process proceeds to step S706, and a check is made to see if there is any non-anonymous communication in the read record. If there is no non-anonymous communication, it is determined in step S705 that the service is not spoofing, and the process ends.
[0353] If there is non-anonymous communication, the process proceeds to step S701, where the number of countries in non-anonymous communication is counted. If the number of countries in non-anonymous communication is two or more, the process determines in step S704 that the communication is spoofing, and the process ends.
[0354] If the number of countries for non-anonymous communication is one, the process proceeds to step S702, where the number of cities for non-anonymous communication is counted.
[0355] If the number of cities in non-anonymous communication is one, it is determined in step S705 that there is no spoofing, and the process ends.
[0356] If the number of cities in non-anonymous communication is two or more, in step S703, it is confirmed whether the distance between the cities is long or short. Specifically, using the latitude and longitude information in the record, the cosine law of spherical trigonometry is used to derive the distance, and the result is compared with a threshold value to determine whether the cities are long or short.
[0357] If the distance is short, it is determined in step S705 that there is no spoofing and the process ends.
[0358] If the distance is far, it is determined in step S704 that the information is an impersonation, and the process ends.
[0359] Similar configuration changes and processing changes can be made in other embodiments and modifications.
[0360] (Variation 4) In the second embodiment, the home identification information stored may be coordinate information acquired by the transmitting home appliance using GPS or the like, information indicating the characteristics of the home acquired using the ECHONET Lite (registered trademark) protocol, or information input or set by the user to the home appliance, but this is not limited to this.
[0361] For example, each home appliance can be given the function of returning a device ID, and each home appliance can acquire the device IDs of surrounding home appliances via broadcast or multicast and send them to the home appliance server, and the home identification list creation unit 210 of the unauthorized communication detection device 21 can determine which home appliances exist on the same network and store them in the home identification list.Since the IP addresses of home appliances belonging to the same house are the IP address of the router 50, home appliances with the same IP address when not using an anonymous communication service can be determined to be in the same house and stored in the home identification list.The home appliance server can also have the user input the home appliances used in the same house and acquire this to create the home identification list, or a combination of these can be used to make the determination.
[0362] (Variant 5) In the first and second embodiments, when there are multiple communications from different source IPs, the unauthorized communication detection device 20 or 21 determines that the device ID may be spoofed, and queries the communication information providing server 32 for each source IP address via the communication unit 201 to obtain the communication information, but the obtaining means is not limited to this.
[0363] The unauthorized communication detection device may originally have a database of communication information, or the information may be acquired by other means. In this case, as shown in Figure 53, the unauthorized communication detection system 3 has the same configuration as the unauthorized communication detection system 1 of the first embodiment (Figure 2) but does not have the communication information providing server 32. Similar configuration and processing changes can be made in other embodiments and modifications.
[0364] (Variant 6) In the above-described first and second embodiments, the unauthorized communication detection device 20 or 21 is connected to a communication line (e.g., Ethernet) connecting the Internet 10 and the home appliance server 31, and serves to mediate communication between home appliances on the Internet 10 and the home appliance server 31, as well as monitor unauthorized communications to the home appliance server 31. However, this is not limited to this, and the unauthorized communication detection device 20 or 21 may also be incorporated inside the home appliance server 31.
[0365] In this case, the unauthorized communication detection system 4 has a configuration as shown in Fig. 54. In other embodiments and modifications, similar configuration changes and processing changes can be made.
[0366] (Variant 7) In the above-described first and second embodiments, the unauthorized communication detection device 20 or 21 is connected to a communication line (e.g., Ethernet) connecting the Internet 10 and the home appliance server 31, and serves to mediate communication between home appliances on the Internet 10 and the home appliance server 31, as well as monitor unauthorized communication to the home appliance server 31. However, this is not limited to this, and the unauthorized communication detection device 20 or 21 may be connected to the same network as the home appliance server 31 and monitor unauthorized communication by obtaining communication logs from the home appliance server 31.
[0367] In this case, the unauthorized communication detection system 5 has a configuration as shown in Fig. 55. In other embodiments and modifications, similar configuration changes and processing changes can be made.
[0368] (Modification 8) In the first and second embodiments, the communication log collection unit 202 stores communication packets as a communication log in the communication log storage unit 205, but this is not limitative.
[0369] The communication log may be a communication log stored by the home appliance server 31 within the home appliance server, a communication log stored by the home appliance server 31 in an external log storage server, a communication log obtained from the home appliance server by an external log server at regular intervals, or something else.
[0370] (Variant 9) In embodiment 1, the unauthorized communication detection device 20 is equipped with a device type list holding unit 209, but when executing the first and second operations of the impersonation determination process, the unauthorized communication detection device 23 does not need to be equipped with a device type list holding unit 209, as shown in Figure 56.
[0371] An example of the spoofing determination process when the unauthorized communication detection device 23 does not include the device type list holding unit 209 will be described below with reference to FIG.
[0372] In step S801 of Fig. 57, the number of anonymous communication services contained in the read record is counted. Specifically, the number of types of anonymous communication service names stored in the anonymous communication service name column in the record is counted. At this time, if the anonymous communication service name is the same, it is counted as one.
[0373] If the number of anonymous communication services is 0, the process proceeds to step S802, where the number of non-anonymous communication ISPs included in the read record is counted. Specifically, the number of types of ISP names stored in the ISP name column in the record is counted. At this time, if the ISP name is the same, it is counted as one.
[0374] If the number of ISPs is one or less, the process proceeds to step S803, where it is determined that there is no spoofing and the process ends. If the number of ISPs is two or more, the process proceeds to step S804, where it is determined that there is spoofing and the process ends.
[0375] Even if there are two or more ISPs, if the source IP address has an ISP that is an MVNO, the communication information providing server 32 may return the ISP name of the MNO depending on the timing of the inquiry. Therefore, even if there are two or more ISPs, if the ISP is a combination of an MVO and an MVNO, a more detailed judgment may be made, such as determining that it is not spoofing.
[0376] If the number of anonymous communication services is one or more in step S801, the process proceeds to step S805, where the access history of the device ID is extracted and stored in the access history storage unit 208.
[0377] In step S806, it is confirmed whether the anonymous communication service included in the record read from the impersonation grey list appears frequently in the access history extracted in step S507, that is, whether it is an anonymous communication service that is used on a daily basis based on the device ID.
[0378] For example, if the access interval is short, such as once every few days, and if the access occurs over a fairly long period of time, such as at least several weeks, it is determined that the anonymous communication service is used on a daily basis, and the process proceeds to step S802. If the anonymous communication service is not used on a daily basis, the process proceeds to step S807, where it is determined that the service is an spoofed service, and the process ends.
[0379] Similar configuration changes and processing changes can be made in other embodiments and modifications.
[0380] [4. Example of Notification] Incidentally, as described in Modification 2, the unauthorized communication detection devices 20, 21, 22, and 23 may simply notify the home appliance server 31 or a security operation center (SOC) or the like that remotely monitors the home appliance server 31 of the risk. Below, an example in which the unauthorized communication detection devices 20, 21, 22, and 23 notify an operator of the security operation center of the risk will be described with reference to Figures 58, 59, and 60.
[0381] 58 shows an example of a notification when the communication overlap determination process determines that two or more communications overlap in time and detects spoofing. As shown in FIG. 58, when spoofing is detected, the detection result (risk) is displayed on a display 60 used by, for example, an operator at a security operation center. In the example shown in FIG. 58, the operator is notified that the communication corresponding to C_IP1 / S_IP (hereinafter also referred to as the "first communication") is spoofed, and that the communication corresponding to C_IP2 / S_IP (hereinafter also referred to as the "second communication") is spoofed.
[0382] The operator can add C_IP1 / S_IP of the first communication to the block list by selecting, for example, icon I1 in the area where the detection results of the first communication are displayed. Similarly, the operator can add C_IP2 / S_IP of the second communication to the block list by selecting, for example, icon I1 in the area where the detection results of the second communication are displayed.
[0383] 59 shows an example of a notification when the communication overlap determination process determines that there is no temporal overlap between two or more communications, but the spoofing determination process detects spoofing. As shown in FIG. 59, when spoofing is detected, the detection result (risk) is displayed on a display 60 used by, for example, an operator at a security operation center. In the example shown in FIG. 59, the operator is notified that the communication corresponding to C_IP1 / S_IP (hereinafter also referred to as "third communication") is not spoofed, and that the C_IP2 / S_IP communication (hereinafter also referred to as "fourth communication") is spoofed.
[0384] The operator can add C_IP2 / S_IP of the fourth communication to the block list, for example, by selecting icon I1 in the area where the detection result of the fourth communication is displayed.
[0385] Figure 60 shows an example of a block list displayed on a display 60 used by an operator of a security operations center. In the example shown in Figure 60, the block list includes a communication corresponding to C_IP2 / S_IP (hereinafter also referred to as the "fifth communication"), a communication corresponding to C_IP15 / S_IP (hereinafter also referred to as the "sixth communication"), and a communication corresponding to C_IP30 / S_IP (hereinafter also referred to as the "seventh communication").
[0386] For example, by selecting icon I2 in the display area of any of the fifth, sixth, and seventh communications, the operator can remove the selected communication from the block list, i.e., unblock the unauthorized communication.
[0387] [5. Summary] As described above, the fraudulent communication detection method according to the first aspect is a fraudulent communication detection method executed by one or more processors. In the fraudulent communication detection method, when two or more communications from two or more different source IP addresses containing the same device identifier, which is a device identifier for uniquely identifying a device, are detected within a predetermined period of time in communications between the Internet and a server, a communication overlap determination process is performed to determine whether or not there is one or more temporal overlaps between the two or more communications. In the fraudulent communication detection method, when one or more overlaps are found by the communication overlap determination process, it is determined that at least one of the two or more communications is a fraudulent communication that uses a false device identifier.
[0388] Furthermore, in the unauthorized communication detection method according to the second aspect, when the communication overlap determination process in the first aspect does not find one or more overlaps, a communication information confirmation process is performed to confirm whether the communication type of each of two or more communications is anonymous or non-anonymous from two or more different source IP addresses. The unauthorized communication detection method determines whether at least one of the two or more communications is unauthorized, depending on the number and combination of anonymous and non-anonymous communications.
[0389] In addition, in the unauthorized communication detection method according to the third aspect, in the second aspect, whether anonymous communication among two or more communications is unauthorized communication is determined further depending on the communication history of the device identifier. For example, in the unauthorized communication detection method, the communication history of the device identifier is checked, and a process is performed to determine whether communication determined to be anonymous communication is used on a daily basis as communication of the device identifier, and if it is determined that the communication is used on a daily basis, the communication determined to be anonymous communication is not unauthorized communication.
[0390] Furthermore, in the fraudulent communication detection method according to the fourth aspect, when two or more communications are all non-anonymous in the second or third aspect, a process is performed to confirm the country and city of the source from the source IP address of each communication. The fraudulent communication detection method determines whether at least one of the two or more communications is fraudulent depending on whether the countries are different and the distance between the cities.
[0391] Here, the fraudulent communication detection method according to the fourth aspect further performs a process in which, when the source cities of two or more communications are different, the difference in time between the end time of the communication that started earlier and the start time of the communication that started later is calculated, and a determination is made as to whether the communications occurred during a time when travel between the cities is possible. If it is determined that the communications occurred during a time when travel between the cities is impossible, the fraudulent communication detection method determines that the communications determined to have occurred during a time when travel between the cities is impossible is fraudulent.
[0392] Furthermore, in the unauthorized communication detection method, when it is determined that two or more communications occurred within a time that would allow inter-city travel, a process is further performed to determine whether the device identifier is a transportable home appliance type. In the unauthorized communication detection method, when it is determined that the device identifier is not a transportable home appliance type, it is determined that the communications determined to have occurred within a time that would allow inter-city travel are unauthorized communications.
[0393] In addition, in the fraudulent communication detection method according to the fifth aspect, when two or more communications are all non-anonymous and there is only one ISP, a process is performed to confirm the country and city of the source from the source IP address of each communication. The fraudulent communication detection method determines whether at least one of the two or more communications is fraudulent depending on whether the countries are different and the distance between the cities.
[0394] In addition, in the unauthorized communication detection method according to a sixth aspect, in any one of the second to fifth aspects, when anonymous communication is included in two or more communications, a process is performed to determine whether the device identifier is a home appliance type that can use anonymous communication. In the unauthorized communication detection method, if it is determined that the device identifier is not a home appliance type that can use anonymous communication, it is determined that the anonymous communication is unauthorized communication.
[0395] In addition, in the unauthorized communication detection method according to the seventh aspect, when it is determined in the sixth aspect that the device identifier is a home appliance type that can use anonymous communication, a process is further performed to check the state of the device identifier and determine whether or not it is in a state where anonymous communication can be used. In the unauthorized communication detection method, when it is determined that the device identifier is not in a state where anonymous communication can be used, it is determined that the anonymous communication is unauthorized communication.
[0396] In addition, in the fraudulent communication detection method relating to the eighth aspect, in any one of the first to seventh aspects, if at least one of two or more communications is determined to be fraudulent, the two or more communications are blocked.
[0397] In addition, in the fraudulent communication detection method of the ninth aspect, in the eighth aspect, a process is performed to check whether a predetermined period has passed since the blocking of two or more communications, and if the period has passed, the blocking of two or more communications is lifted.
[0398] In addition, in the fraudulent communication detection method relating to the 10th aspect, in any one of the first to ninth aspects, if at least one of two or more communications is determined to be fraudulent, a server or other device is notified that the fraudulent communication has been detected.
[0399] In addition, in the fraudulent communication detection method relating to the 11th aspect, in the second aspect, when at least one of two or more communications is determined to be fraudulent, the level of risk is determined based on the circumstances of the fraudulent communication, and a numerical score indicating the level of risk is determined.
[0400] Here, the fraudulent communication detection method according to the eleventh aspect further checks the communication history of the device identifier and determines whether the communication determined to be anonymous communication is routinely used as communication of the device identifier. If it is determined that the communication is not routinely used, the fraudulent communication detection method determines that there is a high risk that the communication determined to be anonymous communication is fraudulent communication and sets a high score.
[0401] Furthermore, in the fraudulent communication detection method according to the eleventh aspect, when two or more communications are all non-anonymous and there is only one ISP, a process is performed to confirm the country and city of the source from the source IP address of each communication. The fraudulent communication detection method determines whether at least one of the two or more communications is fraudulent depending on whether the countries are different and the distance between the cities, and determines the risk level depending on the circumstances of the fraudulent communication and determines a numerical score.
[0402] Furthermore, in the fraudulent communication detection method according to the eleventh aspect, when the senders of two or more communications are from different cities, the difference in time between the end time of the communication that started earlier and the start time of the communication that started later is calculated, and a process is performed to determine whether the communications occurred during a time when travel between the cities is possible. If the fraudulent communication detection method determines that the communications occurred during a time when travel between the cities is impossible, it determines that there is a high risk that the communications determined to have occurred during a time when travel between the cities is impossible is fraudulent, and sets a high score.
[0403] Furthermore, in the unauthorized communication detection method, when it is determined that two or more communications occurred within a time that would allow inter-city travel, a process is further performed to determine whether the device identifier is a portable home appliance type. In the unauthorized communication detection method, when it is determined that the device identifier is not a portable home appliance type, it is determined that there is a high risk that the communications determined to have occurred within a time that would allow inter-city travel are unauthorized communications, and a high score is set.
[0404] Furthermore, in the unauthorized communication detection method according to the eleventh aspect, when two or more communications include one or more anonymous communications, a process is performed to determine whether the device identifier is for a home appliance type that can use anonymous communication. If the unauthorized communication detection method determines that the device identifier is not for a home appliance type that can use anonymous communication, it determines that there is a high risk that at least one of the two or more communications is unauthorized communication, and sets a high score value.
[0405] In addition, in the unauthorized communication detection method according to the eleventh aspect, when it is determined that the device identifier is a home appliance type that can use anonymous communication, the state of the device identifier is further checked to determine whether it is in a state where anonymous communication can be used. In the unauthorized communication detection method, when it is determined that the device identifier is not in a state where anonymous communication can be used, it is determined that there is a high risk that at least one of the two or more communications is unauthorized communication, and a high score is set.
[0406] In addition, in the unauthorized communication detection method according to the twelfth aspect, in the eleventh aspect, when the score value exceeds a threshold value, two or more communications are blocked.
[0407] In addition, in the unauthorized communication detection method relating to the 13th aspect, in the 12th aspect, a process is performed to check whether a predetermined period has passed since the blocking of two or more communications, and if so, the blocking of two or more communications is lifted.
[0408] In addition, in the fraudulent communication detection method of the 14th aspect, in any one of the 11th to 13th aspects, if the score exceeds a threshold, a server or other device is notified that at least one of the two or more communications has been detected as fraudulent.
[0409] In addition, in the fraudulent communication detection method relating to the 15th aspect, in the first aspect, if the communication overlap determination process does not find one or more overlaps, a first communication type obtained by a communication information acquisition process that confirms whether the communication type of each of the two or more communications is anonymous or non-anonymous from the source IP addresses of each of the two or more communications is compared with a second communication type obtained by a communication information acquisition process that confirms whether the communication type is anonymous or non-anonymous from the source IP addresses of other devices that have the same house identification information as the house identification information included in the two or more communications, and if they do not match, it is determined that at least one of the two or more communications is fraudulent.
[0410] In addition, in the fraudulent communication detection method according to the sixteenth aspect, in the fifteenth aspect, the home identification information is any one of information input by a user into the home appliance, physical location information acquired by the device, and information indicating the characteristics of the home acquired by the device from another device using the ECHONET Lite (registered trademark) protocol.
[0411] In addition, in the fraudulent communication detection method of the 17th aspect, in the 15th or 16th aspect, if at least one of two or more communications is determined to be fraudulent, the two or more communications are blocked.
[0412] In addition, in the fraudulent communication detection method relating to the 18th aspect, in the 17th aspect, a process is performed to check whether a predetermined period has passed since the blocking of two or more communications, and if so, the blocking of two or more communications is lifted.
[0413] In addition, in the fraudulent communication detection method relating to the 19th aspect, in any one of the 15th to 18th aspects, if at least one of two or more communications is determined to be fraudulent communication, a server or other device is notified that the fraudulent communication has been detected.
[0414] In addition, in the fraudulent communication detection method relating to the 20th aspect, in any one of the 15th to 19th aspects, if it is determined that at least one of two or more communications is fraudulent, the level of risk is determined based on the circumstances of the fraudulent communication, and a numerical score indicating the level of risk is determined.
[0415] Furthermore, a program according to a twenty-first aspect causes one or more processors to execute the unauthorized communication detection method according to any one of the first to twentieth aspects.
[0416] Furthermore, an unauthorized communication detection device according to a twenty-second aspect includes one or more processors and a memory. When the one or more processors detect two or more communications from two or more different source IP addresses containing the same device identifier within a predetermined period in communications between the Internet and a server, the one or more processors perform a communication overlap determination process to determine whether or not there is one or more temporal overlaps between the two or more communications. When the communication overlap determination process detects one or more overlaps, the one or more processors determine that at least one of the two or more communications is an unauthorized communication that uses a false device identifier.
[0417] The present disclosure can be used in services and systems that are configured with servers on the Internet and devices connected to the servers.
[0418] 1, 2, 3, 4, 5 Unauthorized communication detection system 10 Internet 11 Home network 20, 21, 22, 23 Unauthorized communication detection device 30 VPN server 31 Home appliance server 32 Communication information providing server 40 TV 41 Air conditioner 42 Refrigerator 50 Router 201 Communication unit 202 Communication log collection unit 203 Spoofing grey list creation unit 204 Unauthorized communication determination unit 205 Communication log storage unit 206 Block list storage unit 207 Grey list storage unit 208 Access history storage unit 209 Device type list storage unit 210 House identification list creation unit 211 House identification list storage unit
Claims
1. A fraudulent communication detection method executed by one or more processors, which, when two or more communications from two or more different source IP addresses containing the same device identifier are detected within a specified period in communications between the Internet and a server, performs a communication overlap determination process to determine whether or not there is one or more temporal overlaps between the two or more communications, and, when one or more overlaps are confirmed by the communication overlap determination process, determines that at least one of the two or more communications is a fraudulent communication that falsely represents the device identifier.
2. The unauthorized communication detection method of claim 1, further comprising the steps of: if the communication overlap determination process does not find one or more overlaps, performing a communication information confirmation process to confirm whether the communication type of each of the two or more communications is anonymous or non-anonymous from the two or more different source IP addresses; and determining whether at least one of the two or more communications is the unauthorized communication depending on the number and combination of the anonymous communications and the non-anonymous communications.
3. The unauthorized communication detection method according to claim 2, further comprising determining whether the anonymous communication among the two or more communications is the unauthorized communication based on the communication history of the device identifier.
4. The method for detecting fraudulent communications described in claim 2, further comprising: if the two or more communications are all non-anonymous communications, a process of confirming the country and city of the source from the source IP address of each communication is performed; and depending on whether the countries are different and the distance between the cities, it is determined whether at least one of the two or more communications is the fraudulent communication.
5. The fraudulent communication detection method of claim 4, further comprising the steps of: when the two or more communications are all non-anonymous communications and there is only one type of ISP; performing a process of confirming the country and city of the source from the source IP address of each communication; and determining whether or not at least one of the two or more communications is the fraudulent communication depending on whether the countries are different and the distance between the cities.
6. The method for detecting unauthorized communication as described in claim 2, further comprising the steps of: when the anonymous communication is included in the two or more communications, performing a process for determining whether the device identifier is a type of home appliance that can use the anonymous communication; and when it is determined that the device identifier is not a type of home appliance that can use the anonymous communication, determining that the anonymous communication is the unauthorized communication.
7. The method for detecting unauthorized communication as described in claim 6, further comprising, when it is determined that the device identifier is a type of home appliance capable of using the anonymous communication, performing a process of checking the state of the device identifier and determining whether it is in a state in which the anonymous communication can be used, and when it is determined that the device identifier is not in a state in which the anonymous communication can be used, determining that the anonymous communication is the unauthorized communication.
8. A method for detecting unauthorized communications according to any one of claims 1 to 7, further comprising blocking said two or more communications if at least one of said two or more communications is determined to be an unauthorized communication.
9. The unauthorized communication detection method according to claim 8, further comprising the step of: performing a process to check whether a predetermined period of time has elapsed since the blocking of said two or more communications; and, if the predetermined period of time has elapsed, lifting the blocking of said two or more communications.
10. A method for detecting unauthorized communications as described in any one of claims 1 to 7, further comprising, when at least one of the two or more communications is determined to be an unauthorized communication, notifying the server or other device that the unauthorized communication has been detected.
11. The fraudulent communication detection method described in claim 2, further comprising the steps of: when at least one of the two or more communications is determined to be the fraudulent communication, judging the degree of danger according to the circumstances of the fraudulent communication, and determining a numerical score indicating the degree of danger.
12. The method for detecting fraudulent communications described in claim 11, further comprising blocking the two or more communications when the score exceeds a threshold value.
13. The unauthorized communication detection method according to claim 12, further comprising the step of: performing a process to check whether a predetermined period of time has elapsed since the blocking of said two or more communications; and, if the predetermined period of time has elapsed, lifting the blocking of said two or more communications.
14. A method for detecting fraudulent communications described in any one of claims 11 to 13, further comprising, when the score exceeds a threshold, notifying the server or other device that at least one of the two or more communications has been detected to be the fraudulent communication.
15. The method for detecting unauthorized communication as described in claim 1, wherein, when one or more overlaps are not found by the communication overlap determination process, a first communication type obtained by a communication information acquisition process that confirms whether the communication type of each of the two or more communications is anonymous communication or non-anonymous communication from the source IP addresses of each of the two or more communications is compared with a second communication type obtained by the communication information acquisition process that confirms whether the communication type is the anonymous communication or the non-anonymous communication from the source IP address of another device having the same home identification information as the home identification information included in the two or more communications, and, when they do not match, it is determined that at least one of the two or more communications is the unauthorized communication.
16. The method for detecting unauthorized communications according to claim 15, wherein the home identification information is any one of information input by a user to a home appliance, physical location information acquired by the appliance, and information indicating home characteristics acquired by the appliance from the other appliance using the ECHONET Lite (registered trademark) protocol.
17. The method for detecting unauthorized communications as described in claim 15, further comprising blocking said two or more communications when at least one of said two or more communications is determined to be an unauthorized communication.
18. The unauthorized communication detection method according to claim 17, further comprising the step of: performing a process to check whether a predetermined period of time has passed since the blocking of said two or more communications; and, if the predetermined period of time has passed, lifting the blocking of said two or more communications.
19. A method for detecting unauthorized communication as described in any one of claims 15 to 18, further comprising, when at least one of the two or more communications is determined to be the unauthorized communication, notifying the server or other device that the unauthorized communication has been detected.
20. A method for detecting fraudulent communications described in any one of claims 15 to 18, wherein when at least one of the two or more communications is determined to be a fraudulent communication, a degree of danger is judged according to the circumstances of the fraudulent communication, and a numerical score indicating the degree of danger is determined.
21. A program causing one or more processors to execute the method for detecting unauthorized communications according to claim 1.
22. An unauthorized communication detection device comprising one or more processors and memory, wherein the one or more processors are a device identifier for uniquely identifying a device within a specified period of time in communications between the Internet and a server, and when two or more communications from two or more different source IP addresses containing the same device identifier are detected, perform a communication overlap determination process to determine whether or not there is one or more temporal overlaps between the two or more communications, and when the one or more overlaps are recognized by the communication overlap determination process, determine that at least one of the two or more communications is an unauthorized communication that falsely represents the device identifier.
Citation Information
Patent Citations
Electronic device of correspondent type to network
JP2006246109A
Authentication system, authentication method, authentication device, and program
JP2016009469A
Information processing system and program
JP2022080520A
Privacy-preserving location attestation
WO2023113819A1