Security support system
The security support system uses AI to generate detection rules and operations for intrusion detection systems in complex environments, addressing redundancy and manpower challenges by leveraging device and network information, enhancing efficiency and accuracy.
Patent Information
- Application Number
- PCT/JP2024/025951
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-19
- Publication Date
- 2026-01-22
AI Technical Summary
Existing systems struggle to generate detection rules for future anomalies or attacks in complex systems with multiple intrusion detection systems, leading to redundancy and requiring significant human effort to understand system configurations and device specifications.
A security support system that uses artificial intelligence to generate recommended settings for detection rules and basic operations of intrusion detection systems by inputting information about devices, network topology, communication data, past data, and intrusion detection system logs, allowing for minimal manpower configuration.
The system efficiently generates detection rules and operations tailored to the target system's specifications and past operations with reduced human intervention, improving efficiency and accuracy.
Smart Images

Figure JP2024025951_22012026_PF_FP_ABST
Abstract
Description
Security Support System
[0001] The present disclosure relates to a security assistance system.
[0002] The technology of Patent Document 1 acquires vehicle configuration information relating to the configuration of the in-vehicle network, information on the intrusion detection system installed in the vehicle, and information on attacks to be detected, and uses this information as input to generate detection rules for detecting attacks or abnormalities in the intrusion detection system according to a specific algorithm.
[0003] Specifically, among multiple devices installed in a vehicle, the installation location of each device is identified based on information about devices that can be the entry point (starting point) and attack point (ending point) of the attack, information about other devices, and information indicating the connection relationships between each device.The installation location of each device is then assigned to each device based on the identified installation location, and when an abnormality is detected in each device, the hop number or layer number assigned to the device is output, thereby making it possible to detect the progress of the attack.Here, the installation location of each device refers to, for example, the relative location of each device with the device that is the entry point as the base.
[0004] JP 2023-28510 A
[0005] The technology in Patent Document 1 can generate detection rules for existing anomalies or attacks according to a specific algorithm based on known information, but cannot generate detection rules for anomalies or attacks that may occur in the future. Furthermore, in a system equipped with multiple intrusion detection systems, applying the generated detection rules to all of the intrusion detection systems would result in redundancy, but the technology does not disclose how to set detection rules for each intrusion detection system.
[0006] On the other hand, in a system with multiple devices, if humans are to set the detection rules and / or basic operations of each intrusion detection system to deal with possible future abnormalities or attacks, they must understand the system configuration, the specifications of each device, and the normal and abnormal states of each device's communication data before setting the detection rules and / or basic operations of each intrusion detection system.As the system becomes more complex, this requires a great deal of manpower, and there are limits to human design.
[0007] Therefore, the object of the present disclosure is to provide a security support system that allows for the setting of detection rules or basic operations of each intrusion detection system installed in a target system having multiple devices with minimal manpower.
[0008] The security support system according to the present disclosure inputs the following information into a trained artificial intelligence: information on multiple devices that make up a target system; information on network topology that represents the connection relationships between the multiple devices and between each of the devices and the outside; specification information for each piece of communication data communicated between the multiple devices and between each of the devices and the outside; information on each piece of past communication data; information on the intrusion detection system installed in each of the devices; and log information on attacks or abnormalities detected by the intrusion detection system of each of the devices; and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each of the intrusion detection systems and / or recommended settings for the basic operation of each of the intrusion detection systems.
[0009] According to the security support system disclosed herein, by inputting information about multiple devices in a target system, information about the network topology of the target system, specification information for each piece of communication data, information about each piece of past communication data, information about the intrusion detection systems installed in each device, and log information about attacks or abnormalities detected by each intrusion detection system into an artificial intelligence, the artificial intelligence can generate recommended settings for the detection rules of each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system. Thus, the artificial intelligence can generate recommended settings suited to the specifications and past operation of the target system with little manpower.
[0010] 1 is a schematic configuration diagram of a security support system according to a first embodiment. FIG. 2 is a diagram illustrating an example of a target system according to the first embodiment. FIG. 3 is a diagram illustrating a schematic hardware configuration of a security support apparatus according to the first embodiment. FIG. 4 is a diagram illustrating network topology information according to the first embodiment. FIG. 5 is a diagram illustrating communication data specification information according to the first embodiment. FIG. 6 is a diagram illustrating past communication data information according to the first embodiment. FIG. 7 is a diagram illustrating intrusion detection system information according to the first embodiment. FIG. 8 is a diagram illustrating security function information according to the first embodiment. FIG. 9 is a diagram illustrating log information of attacks or abnormalities detected by the intrusion detection system according to the first embodiment. FIG. 10 is a diagram illustrating recommended settings for anomaly-type detection rules according to the first embodiment. FIG. 11 is a diagram illustrating recommended settings for signature-type detection rules according to the first embodiment. FIG. 12 is a diagram illustrating recommended settings for basic operations of the intrusion detection system according to the first embodiment. FIG. 13 is a flowchart illustrating processing of the security support system according to the first embodiment. FIG. 14 is a diagram illustrating a rule set for anomaly-type detection rules according to the second embodiment. FIG. 15 is a diagram illustrating a rule set for signature-type detection rules according to the second embodiment. FIG. 16 is a diagram illustrating information of the detection engines of each intrusion detection system according to the second embodiment. 1 is a flowchart illustrating processing of a security support system according to embodiment 2. FIG. 2 is a diagram illustrating information on attacks or abnormalities in related systems according to embodiment 3. FIG. 3 is a diagram illustrating information on attacks or abnormalities on the Internet according to embodiment 3. FIG. 4 is a diagram illustrating generation of a priority of recommended settings for each detection rule according to embodiment 3. FIG. 5 is a flowchart illustrating processing of a security support system according to embodiment 3.
[0011] 1. First Embodiment A security support system 1 according to a first embodiment will be described with reference to the drawings. FIG. 1 shows a schematic configuration diagram of the security support system 1.
[0012] In this embodiment, the security support system 1 includes a security support device 12. The security support device 12 is connected to a communication network such as the Internet. The security support device 12 is connected to a target system 10 via the communication network. Note that the security support device 12 may be provided within the target system 10.
[0013] 1-1. Target System 10 The target system 10 is a system in which multiple devices are connected for communication. The multiple devices are composed of various devices such as external communication devices that communicate with the outside of the system, internal communication devices and internal communication lines that communicate within the system, information processing devices, control devices, sensor devices, and actuators.
[0014] For example, as shown in Figure 2, the target system 10 is an in-vehicle system in which multiple devices mounted on a vehicle are communicatively connected. In this case, the external communication devices include wireless communication devices that perform wireless communication with external devices using various communication protocols (e.g., cellular communication, Wi-Fi, BLE (Bluetooth Low Energy)), and wired communication devices that perform wired communication with external devices using various communication protocols (e.g., USB, CAN (Controller Area Network)). The internal communication devices and internal communication lines include a network switch and gateway device that interconnect multiple communication lines, and multiple internal communication lines that communicate between multiple devices using communication protocols. CAN, Ethernet, FlexRay, LIN (Local Interconnect Network), etc. are used as communication protocols.
[0015] Furthermore, the information processing device may include a navigation device and a driving assistance device. The control device may include an electric steering control device that controls an electric steering device, an electric braking control device that controls an electric braking device, a drive control device that controls a drive power source for the wheels (e.g., a motor, an engine), a light control device that controls the drive of lights such as headlights, etc. The sensor device may include a surroundings monitoring device such as a camera and a radar, and a vehicle state detection device consisting of multiple sensors that detect the running state of the vehicle, etc. The actuators may include lights such as headlights, a motor for the electric steering device, a motor for the electric braking device, a motor for driving the wheels, and various actuators for the engine.
[0016] The target system 10 may be various systems other than an in-vehicle system. For example, the target system 10 may be a monitoring system configured with multiple roadside units installed outside a vehicle that monitor roads. Alternatively, the target system 10 does not need to be configured with multiple devices, but may be configured with multiple virtual machines or multiple container software programs running on a single information processing device. The single information processing device includes an external communication device (communication I / F) that communicates with the outside. In this case, each device described below is replaced with each virtual machine or each container software program, and communication between the devices is replaced with communication between each virtual machine or each container software program.
[0017] 1-2. Security Support Device 12 The security support device 12 includes functional units such as an information acquisition unit 35, a recommended setting unit 36, and a setting output unit 37. Each function of the security support device 12 is realized by a processing circuit included in the security support device 12. Specifically, as shown in FIG. 3, the security support device 12 includes an arithmetic processing unit 90 such as a CPU (Central Processing Unit), a storage device 91, a communication device 92, a human interface device 93, and the like.
[0018] The arithmetic processing device 90 may include an application-specific integrated circuit (ASIC), an integrated circuit (IC), a digital signal processor (DSP), a field programmable gate array (FPGA), a graphics processing unit (GPU), various artificial intelligence (AI) chips, various logic circuits, and various signal processing circuits. Furthermore, the arithmetic processing device 90 may include a plurality of the same or different types of devices, each performing a different process. The storage device 91 may include various storage devices such as a random access memory (RAM), a read-only memory (ROM), a hard disk, or a solid-state drive (SSD). The communication device 92 may be a wired communication device or a wireless communication device, and may be connected to a communication network such as the Internet. The human interface device 93 may include various devices such as a display device, a keyboard, a mouse, a touch panel, a speaker, and a microphone. Each function of the information processing unit is realized by cooperation of each piece of hardware such as the arithmetic processing unit 90, the storage device 91, the communication device 92, and the human interface device 93. When a CPU is used for the arithmetic processing unit 90, each function is realized by the CPU executing a program stored in the storage device 91.
[0019] 1-2-1 Information Acquisition Unit 35 The information acquisition unit 35 acquires various pieces of information described below, and transmits the acquired pieces of information to the recommendation setting unit 36.
[0020] For example, the information acquisition unit 35 may acquire various pieces of information from each device (e.g., gateway device, network switch) of the target system 10 that holds various pieces of information about the target system 10, or may acquire various pieces of information from the security support device 12 that holds various pieces of information about the target system 10 or a storage device of the target system 10. Furthermore, the source from which information is acquired may be changed depending on the type of information.
[0021] The information acquisition unit 35 converts the acquired information as necessary so that the acquired information can be used as input to the artificial intelligence of the recommendation setting unit 36, and transmits the converted information to the recommendation setting unit 36.
[0022] <Information on Multiple Devices> The information acquisition unit 35 acquires information on multiple devices that configure the target system 10 , and transmits the acquired information on the multiple devices to the recommended setting unit 36 .
[0023] The information on the multiple devices is information on the functions and specifications of each device that constitutes the target system 10. For example, if the device is an information processing device, the functions and specifications of the device include hardware information (amount of processing units such as CPUs, memory, and other hardware resources) and software information (software functions and specifications). If the device is a communication device, the functions and specifications of the device include the number of communication lines, and the communication protocol and communication specifications of each communication line.
[0024] <Network Topology Information> The information acquisition unit 35 acquires network topology information that indicates the connection relationships between a plurality of devices and between each device and the outside, and transmits the acquired network topology information to the recommended setting unit 36.
[0025] For example, network topology information includes information on the connection relationships between multiple devices and external entities via each communication line, as well as information on the communication protocols and communication specifications of each communication line. For example, the information shown in Figure 4 is used as the connection relationship information. Multiple devices and external entities are arranged on the vertical and horizontal axes, and a square with a value of 1 indicates that the device or external entity on the vertical axis is connected to the device or external entity on the horizontal axis, while a square with a value of 0 indicates that the device or external entity on the vertical axis is not connected to the device or external entity on the horizontal axis.
[0026] <Specification information of communication data> The information acquisition unit 35 acquires specification information of each communication data communicated between multiple devices and between each device and the outside, and transmits the acquired specification information of each communication data to the recommended setting unit 36.
[0027] A plurality of pieces of communication data to be communicated within the target system 10 are designed in advance, and specification information for the plurality of pieces of communication data designed in advance is acquired. For example, as shown in Fig. 5 , the specification information for each piece of communication data includes a communication data ID, a source device ID, a destination device ID, a communication protocol, a communication cycle, etc. Note that since the specifications of the communication data differ depending on the system, the items of information for the communication data may differ from the items in Fig. 5 , and it is preferable that specification information that is effective for recommended settings of detection rules, which will be described later, is included.
[0028] <Operational Status of Target System> The information acquisition unit 35 acquires the operational status of the target system 10 and transmits the acquired operational status of the target system 10 to the recommended setting unit 36 .
[0029] Various operating states of the target system 10 are acquired. For example, the overall operating state of the target system 10 (e.g., operating, stopped, undergoing diagnosis, software update) is acquired. The operating states of each function of each device in the target system 10 are also acquired. The operating state of a driving assistance device (e.g., automatic driving, speed control assistance, steering control assistance, driving assistance stopped) is acquired. The operating state of a navigation device (e.g., route guidance, route guidance stopped) is acquired. The operating states of each device in the target system 10 are also acquired. The resource usage status of the hardware of each device (e.g., a processing unit such as a CPU, memory, and other hardware), the operating status of the software of each device, etc. are acquired. The communication status of each communication line (e.g., data communication volume, and information on the source and destination of each communication line) is acquired. The acquired operating states may differ depending on the system, and may include predefined operating states that are effective for, for example, recommended settings for detection rules, which will be described later.
[0030] <Information on Past Communication Data> The information acquisition unit 35 acquires information on each piece of past communication data of the target system 10 and transmits the acquired information on each piece of past communication data to the recommended setting unit 36. The information acquisition unit 35 may acquire information on each piece of past communication data stored in a storage device of each device in the target system 10, or may acquire information on each piece of past communication data collected and stored by the security support device 12 from each device in the target system 10.
[0031] For example, as shown in Fig. 6, the information on each piece of past communication data includes a timestamp at the time of communication, a communication data ID, a source device ID, a destination device ID, a communication protocol, a data size, a data value, etc. If not only normal communication data but also abnormal communication data is included, the normality or abnormality of each piece of communication data is also included. Note that since the specifications of communication data differ depending on the system, the items of communication data information may be different from the items in Fig. 6, and it is preferable that information on communication data that is effective for recommended settings of detection rules, which will be described later, is included.
[0032] <Intrusion Detection System Information> The information acquisition unit 35 acquires information about an intrusion detection system (IDS) provided in each device, and transmits the acquired intrusion detection system information to the recommended settings unit 36 .
[0033] For example, as shown in Fig. 7, the information about the intrusion detection system provided in each device includes the ID of the intrusion detection system (IDS), the ID of the device in which the intrusion detection system is provided, the operating state (ON / OFF), the operating cycle, the detection content, the operation when an attack or abnormality is detected, etc. Note that since the information about the intrusion detection system differs depending on the type of intrusion detection system, the items of the information about the intrusion detection system may be different from the items in Fig. 7, and it is preferable that information about the intrusion detection system that is effective for recommended settings of detection rules, which will be described later, etc., is included.
[0034] <Security Function Information> The information acquisition unit 35 acquires information about security functions provided in each device and transmits the acquired security function information to the recommended settings unit 36. For example, the security functions include the security function of a network switch and a security module installed in an OS (Operating System), etc. For example, the security function of a network switch is a filtering function that blocks communication from destinations and sources not registered in an allow list, and blocks communication from destinations and sources registered in a reject list.
[0035] For example, as shown in Fig. 8, the information on the security function provided in each device includes the ID of the security function, the ID of the device in which the security function is provided, the operating state (ON / OFF), the operating cycle, the detection content, the action when an attack or an abnormality is detected, etc. Note that since the information on the security function differs depending on the detection content, the items of the information on the security function may be different from the items in Fig. 8, and it is preferable that information on effective security functions be included in recommended settings of the security functions, which will be described later.
[0036] <Log Information of Attacks or Abnormalities> The information acquisition unit 35 acquires log information of attacks or abnormalities detected by the intrusion detection system of each device, and transmits the acquired log information of attacks or abnormalities to the recommended settings unit 36 .
[0037] For example, as shown in Figure 9, the log information of an attack or anomaly includes a timestamp when the attack or anomaly was detected, the ID of the intrusion detection system that detected the attack or anomaly, the type of the detected attack or anomaly, the detection rule that detected the attack or anomaly, and information about the communication data when the attack or anomaly was detected. The type of attack or anomaly includes types of attacks or anomalies that can be detected by each intrusion detection system, such as unauthorized access and DoS attacks. The information about the communication data when the attack or anomaly was detected includes the communication data ID, the source device ID, the destination device ID, the communication protocol, the data size, the data value, the communication cycle, and the like. Note that, because the log information of an attack or anomaly differs depending on the type of intrusion detection system, the items in the log information of an attack or anomaly may differ from those shown in Figure 9, and it is preferable that the log information include items that are effective for recommended settings of detection rules, which will be described later.
[0038] The information acquisition unit 35 also acquires log information about attacks or abnormalities detected by the security functions of each device, and transmits the acquired log information about attacks or abnormalities to the recommended settings unit 36 .
[0039] For example, as shown in FIG. 10 , log information of an attack or anomaly detected by a security function of a network switch includes a timestamp at the time of the attack or anomaly detection, the ID of the security function that detected the attack or anomaly, the ID of the device in which the security function is installed, the type of the detected attack or anomaly, and information about the communication data at the time of the attack or anomaly detection. The type of attack or anomaly includes types of attacks or anomalies that can be detected by each security function, such as anomaly detection using an allow list method or anomaly detection using a deny list method. Information about the communication data at the time of the attack or anomaly detection includes the device ID of the sender, the device ID of the destination, the communication protocol, the communication data ID, the data size, the data value, the communication cycle, etc. Note that, because the log information of an attack or anomaly varies depending on the detection content, the items in the log information of the attack or anomaly may be different from those shown in FIG. 10 , and it is preferable to include items that are effective for the recommended settings of the detection rules, which will be described later.
[0040] 1-2-2. Recommended Settings Unit 36 <Recommended Settings for Detection Rules and Recommended Settings for Basic Operation of Each Intrusion Detection System> The recommended settings unit 36 inputs each piece of information acquired from the information acquisition unit 35 to the trained artificial intelligence. The recommended settings unit 36 inputs information about the multiple devices that make up the target system 10, information about the network topology of the target system 10, specification information for each piece of communication data, information about each piece of past communication data, information about the intrusion detection system installed in each device, and log information about attacks or abnormalities detected by the intrusion detection system of each device to the trained artificial intelligence, and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system.
[0041] With this configuration, by inputting information about multiple devices in the target system, information about the network topology of the target system, specification information for each piece of communication data, information about each piece of past communication data, information about the intrusion detection systems installed in each device, and log information about attacks or abnormalities detected by each intrusion detection system into the artificial intelligence, the artificial intelligence can generate recommended settings for the detection rules of each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system. Thus, the artificial intelligence can generate recommended settings that are suitable for the specifications and past operation of the target system with little manpower.
[0042] Artificial intelligence is a broad concept that includes generative AI. Artificial intelligence and generative AI are composed of neural networks, etc. AI learning methods use various well-known learning methods, such as machine learning.
[0043] The artificial intelligence is trained in advance to generate one or both of recommended settings for detection rules and recommended settings for basic operations of each intrusion detection system in response to each piece of input information. For example, multiple data sets are prepared, including information corresponding to each piece of input information for sample systems such as the target system 10, previous models of the target system 10, systems similar to the target system 10, and various other systems, as well as example detection rule settings and example basic operation settings for the sample systems, and the artificial intelligence is trained to learn from these data sets. The example detection rule settings and example basic operation settings may be past setting examples collected, or may be settings configured for learning using rule-based processing. In addition, artificial intelligence may be made to learn information on a large number of past communication data, including whether the communication data is normal or abnormal, specification information on the corresponding communication data, and information on the system corresponding to each communication data, for sample systems such as the target system 10, previous models of the target system 10, systems similar to the target system 10, and various other systems, and then generate recommended settings for detection rules to detect abnormal communication data and recommended settings for the basic operation of the intrusion detection system based on the communication data and information on the target system input to the artificial intelligence.
[0044] The artificial intelligence (e.g., a generation AI) is capable of natural language processing and generates answers to natural language input. For example, when the generation AI is input with the command, "In a system having conditions of input information A, input information B, input information C, input information D, input information E, etc., please generate recommended settings for detection rules for detecting attacks or anomalies in each intrusion detection system for input information E, and recommended settings for basic operations of each intrusion detection system for input information E," the generation AI outputs recommended settings for detection rules of each intrusion detection system for input information E and recommended settings for basic operations of each intrusion detection system for input information E that apply to the multiple input information input. Input information A, input information B, etc. correspond to each piece of input information input to the artificial intelligence. Note that various input formats that the artificial intelligence can discern, such as semi-formal languages or formal languages, may be used as input to the artificial intelligence.
[0045] Alternatively, the artificial intelligence (e.g., a neural network) may be configured to automatically output pre-set information such as recommended settings for the detection rules of each intrusion detection system and recommended settings for the basic operation of each intrusion detection system when each piece of input information is input.
[0046] For example, recommended settings for an anomaly-type detection rule that apply to the multiple pieces of input information are generated, as shown in Figure 11. The recommended settings for each detection rule include the intrusion detection system ID of the target of the setting, the communication data ID to which the detection rule applies, the normal source device ID and destination device ID, the communication protocol, the normal data size, the normal data value range, the normal communication cycle, etc. When the communication data deviates from the normal state defined in the detection rule, the intrusion detection system to which the detection rule is applied determines that an attack or an abnormality has occurred in the communication data.
[0047] Alternatively, recommended settings for signature-type detection rules that apply to multiple pieces of input information may be generated, as shown in Figure 12. The recommended settings for each detection rule include the intrusion detection system ID of the target, the communication data ID to which the detection rule applies, the device IDs of the unauthorized sender and destination, the communication protocol, the data size, the unauthorized payload data, the unauthorized communication cycle, etc. The intrusion detection system to which the detection rule is applied determines that an attack or an abnormality has occurred in the communication data when the communication data matches the unauthorized state specified in the detection rule. Note that the items of the detection rule differ depending on the type of detection rule, and therefore the items of the detection rule may differ from those shown in Figure 12.
[0048] For example, recommended settings for the basic operation of each intrusion detection system that apply to the multiple pieces of input information are set, as shown in Figure 13. The recommended settings for the basic operation of each intrusion detection system include the intrusion detection system ID, device ID, operating state (ON / OFF), operating cycle, detection content, and action to take when an attack or abnormality is detected, etc. Note that since the setting content differs depending on the type of intrusion detection system, the setting content items may differ from the items in Figure 13.
[0049] The format of each generated recommended setting does not have to be a table format like the figures, but may be any of various data formats that can be determined by a computer, or may be a natural language format.
[0050] <Recommended settings for each security function> In this embodiment, the recommended settings unit 36 further inputs information about the security functions provided in each device of the target system 10 and log information about attacks or abnormalities detected by the security functions of each device of the target system 10 into the artificial intelligence, and causes the artificial intelligence to generate recommended settings for each security function.
[0051] According to this configuration, by inputting information about the security functions provided in each device and log information about attacks or abnormalities detected by the security functions of each device into the artificial intelligence, the artificial intelligence can generate recommended settings for each security function. Therefore, recommended settings for each security function that are suitable for the specifications and past operations of the target system related to the security functions can be generated by the artificial intelligence with little manpower.
[0052] In training the artificial intelligence, for example, multiple data sets are prepared, each containing information corresponding to each input information about the sample system described above and example security function settings for the sample system, and the artificial intelligence is trained on the data. The example security function settings may be past setting examples collected or may be set for training purposes using rule-based processing. Furthermore, the artificial intelligence may be trained on a large amount of past communication data information for the sample system, including whether the communication data is normal or abnormal, specification information for the corresponding communication data, and system information corresponding to each communication data, and generate recommended security function settings for the communication data and target system information input to the artificial intelligence.
[0053] For example, when the generation AI is input with the command "In a system having the conditions of input information A, input information B, input information C, input information D, input information E, input information F, ... please generate recommended settings for each security function of input information F," the generation AI outputs recommended settings for each security function of input information F that apply to the multiple pieces of input information that have been input. Input information A, input information B, ... correspond to each piece of input information input to the artificial intelligence. Note that various input formats that the artificial intelligence can discern, such as semi-formal languages or formal languages, may be used as input to the artificial intelligence.
[0054] For example, as shown in FIG. 14 , recommended settings for each security function that match the multiple pieces of input information are generated. The recommended settings for each security function include the ID of the security function to be configured, the ID of the device in which the security function to be configured is installed, the operating state (ON / OFF), operating cycle, detection content, and action when an attack or abnormality is detected. If the security function is a filtering function of a network switch, the detection content may include allow list-type destination and source settings, deny list-type destination and source settings, etc. Note that since the setting content differs depending on the detection content, the setting content items may differ from the items in FIG. 14 . If the security function is an OS security module, the detection content may include the setting and type of the security module, etc.
[0055] <Input of the Operating State of the Target System> In this embodiment, the recommended setting unit 36 further inputs the operating state of the target system 10 to the artificial intelligence. Then, the recommended setting unit 36 causes the artificial intelligence to generate one or both of recommended settings for the detection rules of each intrusion detection system and recommended settings for the basic operations of each intrusion detection system that further apply to the operating state of the target system 10. The recommended setting unit 36 also causes the artificial intelligence to generate recommended settings for each security function that further apply to the operating state of the target system 10.
[0056] According to this configuration, the artificial intelligence can generate recommended settings suitable for the current operating state of the target system 10. Based on the overall operating state of the target system 10 and the operating state of each function of each device in the target system 10, recommended settings related to functions that are operating are generated, and recommended settings related to functions that are not operating are not generated. For example, recommended settings for detection rules of an intrusion detection system and recommended settings for security functions for communication data used in functions that are operating are generated, and recommended settings for communication data used in functions that are not operating are not generated.
[0057] The recommended setting unit 36 does not need to input the operating state of the target system 10 into the artificial intelligence. Recommended settings that can deal with any operating state are generated.
[0058] <Generation of Basis> The recommendation setting unit 36 further causes the artificial intelligence to generate the basis used in determining the recommended setting of the detection rule.
[0059] For example, if the user further inputs to the generation AI, "Please generate the basis used to determine the recommended settings for the generated detection rule," the generation AI outputs the basis. Note that various input formats that can be discriminated by the AI, such as semi-formal languages or formal languages, may be used as input to the AI.
[0060] The recommended setting unit 36 outputs the information source used to generate the recommended setting as the basis. For example, the basis may be log information of past attacks or abnormalities of the input target system, information on each past communication data of the input target system, past setting examples of a sample system used for learning, or information on a large amount of past communication data used for learning. The basis may also be multiple information sources. The recommended setting unit 36 may also cause an artificial intelligence to output detailed data that served as the basis.
[0061] According to this configuration, the user can determine the validity of the recommended settings for the detection rules based on evidence.
[0062] 1-2-3. Settings Output Unit 37 The settings output unit 37 presents the user with either or both of the recommended settings for the detection rules of each intrusion detection system and the recommended settings for the basic operations of each intrusion detection system, and allows the user to approve or change each recommended setting. In this embodiment, the settings output unit 37 also presents the user with the basis used to determine the recommended settings for the detection rules. The settings output unit 37 also presents the user with the recommended settings for each security function, and allows the user to approve or change the recommended settings for each security function.
[0063] This configuration allows the user to efficiently confirm each recommended setting. At this time, the user can make a decision based on the basis used to determine the recommended setting for the detection rule. For example, each recommended setting and the basis are displayed on a display device, and the user can approve or change each recommended setting using a keyboard, mouse, touch panel, or the like.
[0064] Furthermore, the setting output unit 37 changes one or both of the detection rule settings and the basic operation settings of each intrusion detection system based on one or both of the recommended detection rule settings and the recommended basic operation settings of each intrusion detection system.The setting output unit 37 also changes the settings of each security function based on the recommended settings of each security function.When the user approves or changes each recommended setting, the approved or changed recommended setting is used for each setting.
[0065] This configuration makes it possible to efficiently change the settings of each intrusion detection system and each security function of the target system 10. For example, the setting output unit 37 transmits the settings of each intrusion detection system and each security function to the corresponding device of the target system 10, causing each setting to be changed.
[0066] 1-2-4 Flowchart The outline of the processing of the security support system 1 will be explained with reference to the flowchart in FIG.
[0067] In step S01 , as described above, the information acquisition unit 35 acquires information on the plurality of devices that make up the target system 10 , and transmits the acquired information on the plurality of devices to the recommended setting unit 36 .
[0068] In step S02, as described above, the information acquisition unit 35 acquires network topology information representing the connection relationships between multiple devices and between each device and the outside, and transmits the acquired network topology information to the recommended setting unit 36.
[0069] In step S03, as described above, the information acquisition unit 35 acquires specification information of each communication data communicated between multiple devices and between each device and the outside, and transmits the acquired specification information of each communication data to the recommended setting unit 36.
[0070] In step S04, as described above, the information acquisition unit 35 acquires the operating status of the target system 10 and transmits the acquired operating status of the target system 10 to the recommended setting unit 36.
[0071] In step S05, as described above, the information acquisition unit 35 acquires information about the intrusion detection system provided in each device, and transmits the acquired information about the intrusion detection system to the recommended settings unit 36.
[0072] In step S06 , as described above, the information acquisition unit 35 acquires information about the security functions provided in each device, and transmits the acquired information about the security functions to the recommended settings unit 36 .
[0073] In step S07, as described above, the information acquisition unit 35 acquires log information of attacks or abnormalities detected by the intrusion detection system of each device, and transmits the acquired log information of the attacks or abnormalities to the recommendation setting unit 36. The information acquisition unit 35 also acquires log information of attacks or abnormalities detected by the security function of each device, and transmits the acquired log information of the attacks or abnormalities to the recommendation setting unit 36.
[0074] In step S08, as described above, the recommended settings unit 36 inputs information about the multiple devices that make up the target system 10, information about the network topology of the target system 10, specification information about each piece of communication data, information about each piece of past communication data, information about the intrusion detection systems installed in each piece of device, and log information about attacks or abnormalities detected by the intrusion detection systems of each piece of device into the trained artificial intelligence, and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system, and recommended settings for the basic operation of each intrusion detection system, or both.
[0075] In this embodiment, the recommended setting unit 36 further inputs information about the security functions provided in each device of the target system 10 and log information about attacks or abnormalities detected by the security functions of each device of the target system 10 to the artificial intelligence, and causes the artificial intelligence to generate recommended settings for each security function. The recommended setting unit 36 also inputs the operating status of the target system 10 to the artificial intelligence. The recommended setting unit 36 also causes the artificial intelligence to generate the basis used to determine the recommended settings for the detection rules.
[0076] In step S09, as described above, the setting output unit 37 presents the user with either or both of the recommended settings for the detection rules of each intrusion detection system and the recommended settings for the basic operations of each intrusion detection system, and allows the user to approve or change each recommended setting. In this embodiment, the setting output unit 37 also presents the user with the basis used to determine the recommended settings for the detection rules. The setting output unit 37 also presents the user with the recommended settings for each security function, and allows the user to approve or change the recommended settings for each security function.
[0077] In step S10, as described above, the setting output unit 37 changes one or both of the settings of the detection rules of each intrusion detection system and the settings of the basic operation of each intrusion detection system based on one or both of the recommended settings of the detection rules of each intrusion detection system and the recommended settings of the basic operation of each intrusion detection system.
[0078] 2. Second Embodiment Next, a security support system 1 according to a second embodiment will be described. Explanation of the same components as those in the first embodiment will be omitted. The basic configuration of the security support system 1 according to this embodiment is the same as that of the first embodiment, but differs in that the amount of information input to the artificial intelligence is increased compared to that of the first embodiment.
[0079] <Acquiring information on currently set detection rules> In this embodiment, the information acquisition unit 35 acquires information on the detection rules currently set in each intrusion detection system of the target system 10, and transmits the acquired information on the detection rules to the recommended setting unit 36.
[0080] For example, the acquired detection rule information is the same as the recommended settings of the detection rules described in embodiment 1. When an anomaly-type detection rule is set, the settings for each detection rule include, as in FIG. 11 , the intrusion detection system ID for the target, the communication data ID to which the detection rule is applied, the device IDs of normal source and destination data, the communication protocol, the normal data size, the range of normal data values, the normal communication cycle, etc. When a signature-type detection rule is set, the settings for each detection rule include, as in FIG. 12 , the intrusion detection system ID for the target, the communication data ID to which the detection rule is applied, the device IDs of abnormal source and destination data, the communication protocol, the data size, the abnormal payload data, the abnormal communication cycle, etc. Note that, because the detection rules differ depending on the type of intrusion detection system, the items of the detection rule may differ from those in FIGS. 11 and 12 .
[0081] <Acquisition of Rule Set of Detection Rule> The information acquisition unit 35 acquires a rule set of known detection rules from a database or the like, and transmits the acquired rule set of the detection rules to the recommendation setting unit 36 .
[0082] The rule set includes registered example settings for general-purpose detection rules that are common to multiple systems. For example, the rule set includes example settings for anomaly-type detection rules that define various types of normal communication data, as shown in FIG. 16 , and example settings for signature-type detection rules that identify various types of unauthorized communication data, as shown in FIG. 17 . The rule set of detection rules to be acquired may be limited to those related to the target system 10. Since the items of the detection rules differ depending on the type of detection rule, the items of the detection rules may differ from the items in FIGS. 16 and 17 .
[0083] <Acquisition of detection engine information> The information acquisition unit 35 acquires information about the detection engines for detecting attacks or abnormalities that are installed in each intrusion detection system of the target system 10, and transmits the acquired detection engine information to the recommended setting unit 36.
[0084] A detection engine is an algorithmic process that compares characteristic information (signatures) of communication data with detection rules to detect attacks or anomalies. As shown in FIG. 18 , there are different types of detection engines, and the types and formats (items and data formats) of supported detection rules differ. Therefore, the type of detection engine acquired can determine the types and formats of detection rules that can be set. Note that the items of detection engine information may differ from those shown in FIG. 18 as long as the detection engine used in each intrusion detection system and the format of the detection rules that can be used with each detection engine can be identified.
[0085] <Recommendation setting unit 36> The recommendation setting unit 36 inputs information about the multiple devices that make up the target system 10, information about the network topology of the target system 10, specification information about each piece of communication data, information about each piece of past communication data, information about the intrusion detection system provided in each device, log information about attacks or abnormalities detected by the intrusion detection system of each device, information about the detection rules currently set in each intrusion detection system, rule sets for the detection rules, and information about the detection engine of each intrusion detection system into the trained artificial intelligence, and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system.
[0086] The method of embodiment 1 also generates recommended settings suited to the specifications and past operations of the target system 10. In this embodiment, the artificial intelligence can be further made to generate recommended detection rule settings suited to the detection engine of each intrusion detection system based on the currently set detection rules and rule sets of the detection rules. Therefore, it is possible to generate recommended detection rule settings that are closer to the currently set detection rules and rule sets of the detection rules than when the artificial intelligence is made to generate recommended detection rule settings from scratch, as in embodiment 1, thereby improving the accuracy of generation.
[0087] As in the first embodiment, the artificial intelligence is pre-trained to generate recommended settings for detection rules for each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system in response to each piece of input information. In addition to the training of the first embodiment, the artificial intelligence is further trained to generate recommended settings for detection rules that are close to the input currently set information for detection rules and the rule set of detection rules and are compatible with the input detection engine of each intrusion detection system. The training data may be collected past setting examples or may be data set for learning by rule-based processing. The artificial intelligence also pre-trains the type of detection engine of each intrusion detection system and the types and formats of detection rules that can be set for each type of detection engine. The artificial intelligence may also be trained to learn the input rule set of detection rules before generating each recommended setting.
[0088] The recommendation setting unit 36 may output information indicating changes (additions, deletions, changes) to the recommended settings of the detection rules from the currently set detection rules. The output of these changes may be performed by artificial intelligence or an algorithm.
[0089] <Flowchart> The outline of the processing of the security support system 1 according to this embodiment will be described with reference to the flowchart of FIG.
[0090] Steps S21 to S27, step S32, and step S33 are similar to steps S01 to S07, step S09, and step S10 in the first embodiment, respectively, and therefore will not be described here.
[0091] In step S28, as described above, the information acquisition unit 35 acquires information on the detection rules currently set in each intrusion detection system of the target system 10, and transmits the acquired information on the detection rules to the recommended setting unit 36.
[0092] In step S29, as described above, the information acquisition unit 35 acquires a rule set of detection rules from a known database or the like, and transmits the acquired rule set of detection rules to the recommendation setting unit 36.
[0093] In step S30, as described above, the information acquisition unit 35 acquires information about the detection engines for detecting attacks or abnormalities that are installed in each intrusion detection system of the target system 10, and transmits the acquired information about the detection engines to the recommended setting unit 36.
[0094] In step S31, as described above, the recommended settings unit 36 inputs information about the multiple devices that make up the target system 10, information about the network topology of the target system 10, specification information about each communication data, information about each past communication data, information about the intrusion detection system installed in each device, log information about attacks or abnormalities detected by the intrusion detection system of each device, information about the detection rules currently set in each intrusion detection system, the rule set of the detection rules, and information about the detection engine of each intrusion detection system into the trained artificial intelligence, and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system.
[0095] As in the first embodiment, the recommended setting unit 36 further inputs information about the security functions provided in each device of the target system 10 and log information about attacks or abnormalities detected by the security functions of each device of the target system 10 to the artificial intelligence, and causes the artificial intelligence to generate recommended settings for each security function. The recommended setting unit 36 also inputs the operating status of the target system 10 to the artificial intelligence. The recommended setting unit 36 also causes the artificial intelligence to generate the basis used in determining the recommended settings for the detection rules.
[0096] 3. Embodiment 3 Next, a security support system 1 according to embodiment 3 will be described. Description of the same components as those in embodiment 1 or 2 above will be omitted. The basic configuration of the security support system 1 according to this embodiment is the same as that of embodiment 1 or 2, but differs in that the amount of information input to the artificial intelligence is increased compared to embodiment 1 or 2.
[0097] <Acquisition of information on attacks or abnormalities in related systems> In this embodiment, the information acquisition unit 35 acquires information on attacks or abnormalities that have occurred in systems related to the target system 10, and transmits the acquired information on attacks or abnormalities to the recommended settings unit 36.
[0098] When there are multiple devices equipped with the target system 10, such as an in-vehicle system, information on attacks or abnormalities made on other devices equipped with the target system 10 is collected. Alternatively, information on attacks or abnormalities made on similar systems installed in similar devices (e.g., vehicles) as the device equipped with the target system 10 is collected. For example, when the security support device 12 provides security support for multiple devices, information on attacks or abnormalities can be obtained from the other devices. Alternatively, information on attacks or abnormalities made on other devices may be obtained from an external database.
[0099] For example, as shown in Fig. 20 , the acquired attack or anomaly information includes the type of attack, the device ID of the target of the attack, the impact of the attack, security measures taken against the attack, etc. The security measures may include detailed information such as detection rule settings, basic operation settings for the intrusion detection system, and security function settings. Note that the items of attack or anomaly information may be different from the items shown in Fig. 20 , as long as the information is useful as a reference when generating recommended settings for detection rules.
[0100] <Acquisition of information on Internet attacks or anomalies> In this embodiment, the information acquisition unit 35 acquires information on attacks or anomalies collected from the Internet and transmits the acquired information on Internet attacks or anomalies to the recommended settings unit 36.
[0101] The collected internet information refers to all information that can be collected from the internet and is not limited to specific information. For example, words related to security attacks or anomalies (DoS attacks, unauthorized access) are searched for from social networking services (SNS) and community sites, and the number of times the search words appear is tallied. For example, as shown in FIG. 21 , the collected attack or anomaly information includes the search words, the number of times the search words appear, and the most recent date of appearance. Note that the items of attack or anomaly information may be different from those shown in FIG. 21 , as long as the information is useful as a reference when generating recommended settings for detection rules.
[0102] <Recommendation setting unit 36> The recommendation setting unit 36 inputs information about the multiple devices that make up the target system 10, information about the network topology of the target system 10, specification information for each piece of communication data, information about each piece of past communication data, information about the intrusion detection system provided in each device, log information about attacks or abnormalities detected by the intrusion detection system of each device, information about attacks or abnormalities made to systems related to the target system 10, and information about attacks or abnormalities collected from the Internet into the trained artificial intelligence, and causes the artificial intelligence to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system.
[0103] The method of embodiment 1 also generates recommended settings suited to the specifications and past operation of the target system 10. In this embodiment, the artificial intelligence can further refer to information on attacks or anomalies committed on related systems and information on attacks or anomalies on the Internet to generate recommended settings for detection rules and recommended settings for basic operation of the intrusion detection system. Therefore, it is possible to preferentially generate recommended settings for detection rules and recommended settings for basic operation of the intrusion detection system that can deal with attacks or anomalies that are expected in the future and attacks or anomalies that are trending in the real world.
[0104] Therefore, by using not only information related to the target system 10 but also attack information on related systems and information on the Internet as input, it is possible to generate detection rules that will act as countermeasures in advance against attacks that may be carried out on the target system in the future, and to generate detection rules that correspond to trends in the real world.In addition, because information from an unspecified number of systems is used as input, it is easy to collect attack information and detection results, and it is possible to take countermeasures in advance before damage from a specific attack spreads to multiple target systems, and it is possible to generate highly accurate detection rules.
[0105] As in the first embodiment, the artificial intelligence is trained in advance to generate recommended settings for detection rules of each intrusion detection system and / or recommended settings for basic operation of each intrusion detection system in response to each piece of input information. In addition to the training of the first embodiment, the artificial intelligence is further trained to preferentially generate recommended settings for detection rules and recommended settings for basic operation of the intrusion detection system to deal with input information on attacks or anomalies committed on related systems and information on attacks or anomalies on the Internet. The data used for training may be past setting examples collected, or may be data set for training based on a rule base.
[0106] As shown in Figure 22, the recommendation setting unit 36 may use artificial intelligence to generate a priority for the recommended settings of each detection rule, and may increase the priority of the recommended settings of detection rules that deal with information about attacks or abnormalities committed on related systems and information about attacks or abnormalities on the Internet.
[0107] <Flowchart> The outline of the processing of the security support system 1 according to this embodiment will be described with reference to the flowchart of FIG.
[0108] Steps S41 to S47, step S51, and step S52 are similar to steps S01 to S07, step S09, and step S10 in the first embodiment, respectively, and therefore will not be described here.
[0109] In step S48, as described above, the information acquisition unit 35 acquires information about attacks or abnormalities that have occurred on systems related to the target system 10, and transmits the acquired information about the attacks or abnormalities to the recommended settings unit 36.
[0110] In step S49, as described above, the information acquisition unit 35 acquires information about attacks or abnormalities collected from the Internet, and transmits the acquired information about attacks or abnormalities on the Internet to the recommended settings unit 36.
[0111] In step S50, as described above, information on the multiple devices that make up the target system 10, information on the network topology of the target system 10, specification information on each communication data, information on each past communication data, information on the intrusion detection systems installed in each device, log information on attacks or abnormalities detected by the intrusion detection systems of each device, information on attacks or abnormalities made on systems related to the target system 10, and information on attacks or abnormalities collected from the Internet are input into the trained artificial intelligence, and the artificial intelligence is caused to generate recommended settings for detection rules for detecting attacks or abnormalities in each intrusion detection system and / or recommended settings for the basic operation of each intrusion detection system.
[0112] As in the first embodiment, the recommended setting unit 36 further inputs information about the security functions provided in each device of the target system 10 and log information about attacks or abnormalities detected by the security functions of each device of the target system 10 to the artificial intelligence, and causes the artificial intelligence to generate recommended settings for each security function. The recommended setting unit 36 also inputs the operating status of the target system 10 to the artificial intelligence. The recommended setting unit 36 also causes the artificial intelligence to generate the basis used in determining the recommended settings for the detection rules.
[0113] As in embodiment 2, the information acquisition unit 35 may acquire information on the detection rules currently set in each intrusion detection system, the rule set of the detection rules, and information on the detection engine of each intrusion detection system. Furthermore, the recommendation setting unit 36 may further input the information on the detection rules currently set in each intrusion detection system, the rule set of the detection rules, and information on the detection engine of each intrusion detection system to the artificial intelligence.
[0114] Although various exemplary embodiments and examples are described in this disclosure, the various features, aspects, and functions described in one or more embodiments are not limited to the application of a particular embodiment, but may be applied to the embodiments alone or in various combinations. Therefore, countless variations not illustrated are anticipated within the scope of the technology disclosed herein. For example, this includes cases where at least one component is modified, added, or omitted, or where at least one component is extracted and combined with components of another embodiment.
[0115] 1: security support system, 10: target system, 12: security support device, 35: information acquisition unit, 36: recommended setting unit, 37: setting output unit
Claims
1. A security support system that inputs into trained artificial intelligence the following information: information on multiple devices that make up a target system; information on network topology that represents the connection relationships between the multiple devices and between each of the devices and the outside; specification information for each piece of communication data exchanged between the multiple devices and between each of the devices and the outside; information on each piece of past communication data; information on the intrusion detection systems installed in each of the devices; and log information on attacks or abnormalities detected by the intrusion detection systems of each of the devices; and causes the artificial intelligence to generate recommended settings for detection rules to detect attacks or abnormalities in each of the intrusion detection systems, and / or recommended settings for the basic operations of each of the intrusion detection systems.
2. The security support system according to claim 1, wherein the operating status of the target system is further input to the artificial intelligence.
3. The security support system of claim 1, further inputting into the artificial intelligence: information on the detection rules currently set in each of the intrusion detection systems; a rule set of the detection rules; and information on the detection engine for detecting attacks or anomalies provided in each of the intrusion detection systems.
4. A security support system as described in any one of claims 1 to 3, further inputting into the artificial intelligence information on attacks or anomalies carried out on systems related to the target system and information on attacks or anomalies collected from the Internet.
5. A security support system as described in any one of claims 1 to 3, which presents to the user one or both of recommended settings for the detection rules of each of the intrusion detection systems and recommended settings for the basic operation of each of the intrusion detection systems, and allows the user to approve and change each recommended setting.
6. A security support system as described in any one of claims 1 to 3, which changes one or both of the settings of the detection rules of each of the intrusion detection systems and the settings of the basic operations of each of the intrusion detection systems based on one or both of the recommended settings of the detection rules of each of the intrusion detection systems and the recommended settings of the basic operations of each of the intrusion detection systems.
7. A security support system according to any one of claims 1 to 3, wherein the artificial intelligence is further made to generate the basis used in determining the recommended settings for the detection rules.
8. A security support system as described in any one of claims 1 to 3, further inputting information about security functions provided in each of the devices and log information of attacks or abnormalities detected by the security functions of each of the devices into the artificial intelligence, and causing the artificial intelligence to generate recommended settings for each of the security functions.
9. A security support system according to any one of claims 1 to 3, wherein the target system is an in-vehicle system installed in a vehicle.
Citation Information
Patent Citations
Artificial intelligence-assisted rule generation
JP2022502732A
Attack analysis apparatus for vehicle, attack analysis system, attack analysis method, and attack analysis program
JP2024051325A
Iintrusion detection system enrichment based on system lifecycle
US20190042736A1