Monitoring Log Transmission Control for Intrusion-Depth Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information processing devices lack integrity verification for monitoring log transmission, making them vulnerable to attacks that compromise the integrity of anomaly detectors and monitors, leading to delayed detection of anomalies.
Innovation Solution
An information processing device with a storage, transmitter, anomaly detector, integrity monitors, and a transmission controller that adjusts the timing and frequency of monitoring log transmission based on intrusion depth to ensure early detection of anomalies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monitoring logs are transmitted at regular intervals (first timing), then the system maintains normal operation, but when an anomaly occurs in the anomaly detector or first monitor, the transmission is delayed and the anomaly detection is late
Solution Approach 1:
The transmission timing is made dynamic rather than fixed. The transmission controller adjusts the log transmission timing based on the operational state of the anomaly detector and first monitor. When these components are operating normally, logs are transmitted at regular intervals (first timing). When an anomaly is detected, the timing is immediately changed to transmit at a second timing that is earlier than the regular interval, allowing timely anomaly reporting while maintaining normal operation under standard conditions.
Solution Approach 2:
A feedback mechanism is implemented where the transmission controller continuously monitors the operational status of the anomaly detector and first monitor. Based on this feedback information, the controller dynamically adjusts the log transmission timing. The second monitor provides feedback about the integrity of the first monitor, creating a layered feedback system that enables timely detection and response to anomalies in the monitoring chain.
2Reliability
If integrity verification is performed on the transmitter and anomaly detector, then security is improved, but the system complexity increases due to multiple monitors and verification layers
Solution Approach 1:
The integrity verification function is segmented into multiple independent components: the first monitor verifies the transmitter and anomaly detector, while the second monitor verifies the first monitor. This segmentation allows each monitor to focus on specific verification tasks, improving overall reliability through distributed verification while maintaining clear functional boundaries that prevent the complexity from becoming unmanageable.
Solution Approach 2:
The verification structure is organized in a nested manner where the second monitor verifies the integrity of the first monitor, which in turn verifies the transmitter and anomaly detector. This nested verification structure creates layers of security where each layer protects the previous one, ensuring that even if one verification layer is compromised, other layers remain intact to detect and report the anomaly.
3Loss of time
If the transmission timing is changed to transmit earlier (second timing), then anomaly detection speed is improved, but the regular monitoring schedule is disrupted
Solution Approach 1:
The system uses periodic action by establishing a regular first timing for log transmission during normal operation. This periodic schedule ensures consistent monitoring efficiency and predictable system behavior under normal conditions. When an anomaly is detected, the system temporarily deviates from this periodic schedule to transmit at the second timing, allowing urgent anomaly reporting while maintaining the efficiency benefits of regular periodic transmission during normal operation.
Data Source
AI summary
An information processing device includes: a log storage that stores a monitoring log; a log transmitter that transmits a monitoring log stored in the log storage to an SOC at a first timing; a first anomaly detector that detects a presence or absence of an anomaly in the information processing device; an integrated monitor that verifies an integrity of each of the log transmitter and the first anomaly detector; a root monitor that verifies an integrity of the integrated monitor; a determiner that determines an intrusion depth based on a monitoring log stored in the log storage when an anomaly due to an attack occurs; and a transmission controller that changes, based on the intrusion depth, a timing of transmission of a monitoring log by the log transmitter from the first timing to a second timing that is earlier than the first timing.


