WO2024071120A1 - 情報処理装置、情報処理システム、情報処理プログラム、情報処理方法 - Google Patents
情報処理装置、情報処理システム、情報処理プログラム、情報処理方法 Download PDFInfo
- Publication number
- WO2024071120A1 WO2024071120A1 PCT/JP2023/034946 JP2023034946W WO2024071120A1 WO 2024071120 A1 WO2024071120 A1 WO 2024071120A1 JP 2023034946 W JP2023034946 W JP 2023034946W WO 2024071120 A1 WO2024071120 A1 WO 2024071120A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- unit
- vehicle
- verification
- integrity
- information processing
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/12—Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/84—Vehicles
Definitions
- This disclosure relates to a technology that estimates attacks against a vehicle based on security logs that indicate abnormalities that have occurred in the vehicle.
- Patent Document 1 describes a technology that uses a security log that indicates an abnormality that has occurred in a vehicle to estimate the attack against the vehicle that caused the abnormality.
- security logs may not only indicate abnormalities occurring in a vehicle due to the vehicle being attacked and compromised, but may also indicate abnormalities occurring in a vehicle due to causes other than the vehicle being attacked and compromised.
- One aspect of the present disclosure is to provide technology that can estimate attacks against vehicles with high accuracy.
- An information processing device includes a log acquisition unit, a log analysis unit, a verification instruction unit, an intrusion determination unit, and an attack estimation unit.
- the log acquisition unit acquires a security log indicating an abnormality that has occurred in the vehicle.
- the log analysis unit determines whether or not to instruct the vehicle's verification unit (18, S17-S19) to verify the integrity of the on-board unit based on the security log acquired by the log acquisition unit.
- the verification instruction unit instructs the verification unit to verify the integrity.
- the infringement determination unit determines whether or not the vehicle-mounted unit has been infringed based on the results of the integrity verification by the verification unit.
- the attack estimation unit makes an estimation regarding the attack that caused the infringement based on the infringement determination result by the infringement determination unit and the security log.
- An information processing program causes a computer to function as the information processing device described above.
- Another aspect of the present disclosure is an information processing method executed by the information processing device described above.
- An information processing system includes an in-vehicle information processing device and an external information processing device that communicates with the in-vehicle information processing device.
- the in-vehicle information processing device includes a monitoring unit and a verification unit (18, S17 to S19).
- the monitoring unit generates a security log that indicates an abnormality that occurs in the vehicle.
- the verification unit verifies the integrity of the in-vehicle unit.
- the information processing device outside the vehicle includes a log acquisition unit, a log analysis unit, a verification instruction unit, an intrusion determination unit, and an attack estimation unit.
- the log acquisition unit acquires a security log from the vehicle-mounted information processing device.
- the log analysis unit determines whether to instruct the vehicle's verification unit to verify the integrity of the vehicle-mounted unit based on the security log acquired by the log acquisition unit.
- the verification instruction unit instructs the verification unit to verify the integrity.
- the infringement determination unit determines whether or not the vehicle-mounted unit has been infringed based on the results of the integrity verification by the verification unit.
- the attack estimation unit makes an estimation regarding the attack that caused the infringement based on the infringement determination result by the infringement determination unit and the security log.
- Another aspect of the present disclosure is an information processing method executed by the information processing system described above.
- FIG. 1 is a block diagram showing a configuration of an information processing system.
- FIG. 1 is a block diagram showing a multi-layered defense configuration for a vehicle.
- FIG. 2 is a block diagram showing the configuration of an in-vehicle information processing device.
- FIG. 2 is a block diagram showing the configuration of an information processing device outside the vehicle.
- FIG. 4 is an explanatory diagram showing the configuration of a security log.
- FIG. 4 is a block diagram showing the configuration of an analysis unit of an information processing device outside the vehicle.
- FIG. 13 is an explanatory diagram showing the configuration of the abnormal attack table before modification.
- FIG. FIG. 13 is an explanatory diagram showing the configuration of the abnormal attack table after the change.
- an information processing system 2 of the present embodiment includes ECUs 10, 20, 30, 40, 50, and 60 that are information processing devices mounted on a vehicle 4, and a server 100 that is an information processing device outside the vehicle.
- ECU stands for Electronic Control Unit. At least one of the ECUs 10, 20, 30, 40, 50, and 60, the vehicle 4, and the server 100 communicate with each other via, for example, a wireless communication network 6.
- Vehicle 4 employs a multi-layer defense system with different security levels to enhance security against external malicious attacks such as cyber attacks.
- vehicle 4 has three defense layers: a first layer, a second layer, and a third layer.
- ECU#1, ECU#2, and DLC belong to the first layer
- ECU#3 belongs to the second layer
- ECU#4 and ECU#5 belong to the third layer.
- DLC stands for Data Link Connector.
- ECUs can communicate with each other via a CAN or Ethernet network.
- CAN stands for Controller Area Network.
- CAN and Ethernet are registered trademarks.
- ECU#1 and ECU#2 belonging to the first layer function as, for example, a TCU and IVI that have communication functions with the outside of the vehicle 4.
- TCU stands for Telematics Control Unit
- IVI stands for In Vehicle Infotainment.
- ECU#1 and ECU#2 are equipped with a security function that monitors data entering the vehicle from outside the vehicle.
- OBD is an abbreviation for On Board Diagnostics.
- ECU#3 belonging to the second layer is, for example, a gateway ECU equipped with a security function that monitors data communicated between the network of ECU#1 and ECU#2 in the first layer and the network of ECU#4 and ECU#5 in the third layer.
- ECU#3 implements security measures different from those of ECU#1 and ECU#2 described above.
- the area monitored by ECU#3 has a different security level from the first layer, which is the area protected by ECU#1 and ECU#2.
- ECU#4 and ECU#5 belonging to the third layer are, for example, vehicle control ECUs that control the movement of vehicle 4. Only data that has passed the security function of ECU#3 belonging to the second layer is communicated to ECU#4 and ECU#5.
- the third layer is an area that has a different security level from the second layer.
- FIG. 3 shows an example of the configuration of ECUs 10, 20, 30, 40, 50, and 60 mounted on vehicle 4.
- the configuration of the security functions may differ depending on ECUs 10, 20, 30, 40, 50, and 60.
- ECUs 10, 20, 30, 40, 50, and 60 are equipped with microcomputers having, for example, a CPU, ROM, RAM, flash memory, and the like (not shown).
- the CPU of ECUs 10, 20, 30, 40, 50, and 60 executes a program stored in the ROM or flash memory, thereby performing information processing by the monitoring unit 12 and the verification unit 18 (described later).
- the monitoring unit 12 has security sensors that detect abnormalities in the on-board units such as the ECUs 10, 20, 30, 40, 50, and 60 and the network, and monitors whether an abnormality has occurred in the on-board units. When the monitoring unit 12 detects an abnormality in the on-board units, it generates a security log.
- the monitoring unit 12 has security sensors such as a firewall, HIDS, an IDS for detecting anomalies in networks such as CAN and Ethernet, and an Auth function.
- security sensors such as a firewall, HIDS, an IDS for detecting anomalies in networks such as CAN and Ethernet, and an Auth function.
- HIDS stands for Host Based Intrusion Detection System
- IDS stands for Intrusion Detection System
- Auth stands for Authentication.
- the analysis unit 14 analyzes whether or not the security log generated by the monitoring unit 12 may have been generated as a result of an attack on the vehicle 4.
- the analysis unit 14 determines that this may be due to an attack on the vehicle 4. In this case, the analysis unit 14 transmits the security log from the communication unit 16 to the server 100.
- the analysis unit 14 determines that there is no possibility that an attack on the vehicle 4 has been the cause. In this case, the analysis unit 14 does not transmit the security log from the communication unit 16 to the server 100.
- the communication unit 16 communicates with the server 100 via the wireless communication network 6.
- the verification unit 18 is instructed by the server 100 to verify the integrity of its own ECU or other ECUs or in-vehicle units such as VMs or software running on the ECUs, it verifies the in-vehicle units.
- VM is an abbreviation for Virtual Machine.
- the verification unit 18 is protected from being compromised by attacks by security functions such as hardware.
- the server 100 includes a communication unit 110, a log acquisition unit 112, a security log DB 114, an analysis unit 120, a verification instruction unit 140, and a reference value DB 142.
- the analysis unit 120 of the server 100 includes a log analysis unit 122, an infringement determination unit 124, an attack estimation unit 126, an output unit 128, and an abnormal attack DB 130.
- the server 100 is equipped with a computer having, for example, a CPU, ROM, RAM, flash memory, etc. (not shown).
- the CPU of the server 100 executes a program stored in the storage device, and information processing is performed by the log acquisition unit 112, the log analysis unit 122, the intrusion determination unit 124, the attack estimation unit 126, and the verification instruction unit 140.
- the communication unit 110 communicates with the vehicle 4 via the wireless communication network 6.
- the log acquisition unit 112 acquires the security log that the communication unit 110 receives from the vehicle 4 and stores it in the security log DB 114.
- the security log acquired by the log acquisition unit 112 is composed of information such as the ID of the vehicle 4, the time when the abnormality was detected, the location in the vehicle 4 where the abnormality was detected, and the sensor ID that detected the abnormality. Note that the security log may also include information other than these.
- the log analysis unit 122 determines whether to instruct the verification unit 18 of the vehicle 4 to verify the integrity of the vehicle-mounted unit based on the security log acquired by the log acquisition unit 112 and stored in the security log DB 114.
- the log analysis unit 122 determines to instruct the verification unit 18 of the vehicle 4 to verify the integrity of the on-board unit.
- the security log was generated by the detection function of a security sensor to detect a breach of vehicle 4 due to a cyber attack.
- the infringement determination unit 124 determines whether the on-board unit has been infringed based on the result of the determination made by the verification instruction unit 140 in response to the result of the integrity verification made by the verification unit 18 and obtained from the vehicle 4. The determination made by the verification instruction unit 140 in response to the result of the integrity verification will be described later.
- the attack estimation unit 126 estimates the attack that caused the intrusion based on the intrusion determination result by the intrusion determination unit 124, the security log, and the abnormal attack table of the abnormal attack DB 130.
- the output unit 128 outputs the estimation result by the attack estimation unit 126 to a DB or the like (not shown).
- the abnormal attack DB 130 has, for example, the structure of the abnormal attack table shown in FIG. 7.
- the abnormal attack DB 130 represents the relationship between the ECUs belonging to each layer of the defense in depth, the type of abnormality that occurs in each ECU, the attack that causes the abnormality that occurs in each ECU, the location of the attack's starting point, the location of the target that is attacked from the attack's starting point, and the evaluation value.
- the location of the attack's starting point and the location of the target of the attack show the path of the attack.
- the evaluation values "1" and “0” are preset values based on the system configuration of vehicle 4, the attacks that are expected to be made against vehicle 4, and the abnormalities that are expected to occur as a result of the attacks.
- An evaluation value of "1” indicates that there is a possibility that the corresponding abnormality will occur if attacked.
- An evaluation value of "0” indicates that the corresponding abnormality will not occur in the expected attacks.
- the abnormalities are classified according to the type of abnormality that occurs in the ECU.
- the abnormalities may be classified according to the type of abnormality that occurs in each VM.
- the abnormalities may be classified according to the type of abnormality that occurs in each software program.
- the verification instruction unit 140 like the verification unit 18 of the vehicle 4, is protected by security features such as hardware to prevent the verification instruction unit 140 itself from being compromised by attacks.
- the verification instruction unit 140 instructs the vehicle 4 to verify the integrity of the target on-board unit.
- the verification instruction unit 140 instructs the vehicle 4 to verify the integrity of the on-board unit in one of the following patterns (1) to (4).
- An on-board unit that is physically or logically related to the on-board unit in which the abnormality was detected refers to, for example, an on-board unit that is connected to the on-board unit in which the abnormality was detected via a network, or that performs processing based on the processing results of the on-board unit in which the abnormality was detected.
- Vehicle units other than the vehicle unit in which the abnormality was detected For example, if an abnormality is detected in a security sensor that is reliable for detecting abnormalities, the integrity of vehicle units other than the vehicle unit in which the relevant security sensor detected the abnormality is verified.
- the verification instruction unit 140 also instructs the vehicle 4 to verify the integrity of the on-board unit, for example, for items (1) and (2) described below.
- the specified location of the vehicle-mounted unit is one of the following (1a) to (1d).
- verification of program code may be performed starting from program code that is likely to be taken control of if attacked.
- the verification instruction unit 140 also determines the order of the on-board units for which the verification unit 18 of the vehicle 4 is to be instructed to verify the integrity, for example, using one of the following patterns (1) to (3).
- the system first instructs the verification of the integrity of on-board units that belong to shallower layers. For example, if an abnormality is detected in an on-board unit in the second layer, the system first instructs the verification of the integrity of on-board units that belong to the first layer, which is shallower than the second layer.
- the system first instructs to verify the integrity of on-board units that belong to deeper layers. For example, if an abnormality is detected in an on-board unit in the first layer, the system first instructs to verify the integrity of on-board units that belong to the second layer, which is deeper than the first layer.
- the verification instruction unit 140 also compares the value of the integrity verification result performed by the verification unit 18 with the normal value of the integrity verification result stored in the reference value DB 142 to determine whether the integrity of the vehicle-mounted unit is maintained.
- the verification instruction unit 140 determines that the integrity of the on-board unit is maintained. In contrast, if the value of the result of the integrity verification performed by the verification unit 18 does not match the normal value stored in the reference value DB 142, the verification instruction unit 140 determines that the integrity of the on-board unit is impaired.
- the monitoring unit 12 of the vehicle 4 monitors whether any abnormalities have occurred in the ECU itself and the network to which the ECU is connected.
- the monitoring unit 12 detects an abnormality in the on-board unit, it transmits a security log to the analysis unit 14 of the vehicle 4, the security log being composed of the vehicle ID for identifying the vehicle 4 itself, the time when the abnormality was detected, the location where the abnormality was detected, and the sensor ID of the security sensor that detected the abnormality.
- the analysis unit 14 analyzes the security log received from the monitoring unit 12 in S5 and S6 as described above, and determines whether the log should be sent to the server 100 or not. If the log should be sent to the server 100, the analysis unit 14 transmits the security log from the communication unit 16 to the server 100.
- the log acquisition unit 112 of the server 100 receives the security log sent from the vehicle 4 from the communication unit 110 and stores it in the security log DB 114 in the data structure shown in FIG. 5.
- the log analysis unit 122 of the analysis unit 120 analyzes the security log obtained from the security log DB 114 in S9, and determines whether to instruct the vehicle 4 to verify the integrity of the on-board unit of the corresponding vehicle 4.
- the log analysis unit 122 determines in S10 that the vehicle 4 should be instructed to verify the integrity of the vehicle's on-board unit, in S11, the log analysis unit 122 requests the verification instruction unit 140 to instruct the vehicle 4 to verify the integrity of the vehicle's on-board unit.
- the verification instruction unit 140 when the verification instruction unit 140 receives a request from the log analysis unit 122 in S12 to instruct the corresponding vehicle 4 to verify the integrity of the on-board unit, the verification instruction unit 140 instructs the corresponding vehicle 4 to verify the integrity of the on-board unit.
- the verification unit 18 of the ECU 50 having the communication unit 16 instructs the relevant ECUs, including the own ECU 50, to verify the integrity.
- the verification unit 18 of the ECU 50 having the communication unit 16 verifies the integrity of the ECU 50 if the ECU 50 is the target of the integrity verification.
- the verification unit 18 of the other ECU that has been instructed by the verification unit 18 of the ECU 50 to verify the integrity of the ECU itself performs the integrity verification.
- the verification unit 18 which has performed the integrity verification, adds the most recent start time when the ECU itself was started to the result of the integrity verification in S20 and S21, and transmits the result to the ECU 50 having the communication unit 16.
- the verification unit 18 of the ECU 50 having the communication unit 16 transmits the integrity verification result received from the other ECU in S22 and the integrity verification result of the own ECU 50, which includes the most recent startup time of the own ECU 50, from the communication unit 16 to the server 100.
- the verification instruction unit 140 of the server 100 obtains the integrity verification result including the start time received by the communication unit 110 from the vehicle 4.
- the verification instruction unit 140 executes a determination process to determine whether the integrity of the vehicle-mounted unit to be verified is maintained, whether the integrity is not maintained and is impaired, or whether it is impossible to determine whether the integrity is maintained or not.
- the in-vehicle unit may be started after the abnormality is detected, and the abnormality may be resolved by the time integrity verification is performed.
- the verification instruction unit 140 cannot determine whether the integrity of the vehicle unit is maintained.
- the vehicle-mounted unit will not restart from when the abnormality is detected until the integrity verification is performed, so it is possible to determine whether the integrity of the vehicle-mounted unit is maintained based on the results of the integrity verification.
- the verification instruction unit 140 reads the verification result when the integrity verification result is normal from the reference value DB 142, and determines whether the normal verification result matches the verification result obtained from the vehicle 4.
- the verification instruction unit 140 determines that the integrity of the vehicle-mounted unit is maintained, and if the normal verification result does not match the acquired verification result, it determines that the integrity of the vehicle-mounted unit is not maintained and is impaired.
- the verification instruction unit 140 transmits the results of the judgment process for the aforementioned verification results to the infringement judgment unit 124.
- the infringement determination unit 124 determines whether the vehicle-mounted unit has been infringed based on the determination result of the verification result obtained from the verification instruction unit 140.
- the infringement determination unit 124 determines that the vehicle-mounted unit has not been infringed.
- the intrusion determination unit 124 determines that the vehicle-mounted unit has been intruded.
- the infringement determination unit 124 cannot determine whether the integrity of the vehicle-mounted unit is maintained, it cannot determine whether the vehicle-mounted unit has been infringed.
- the attack estimation unit 126 sets an evaluation value of the attack that caused the intrusion into the vehicle-mounted unit based on the judgment result of the intrusion judgment unit 124, and then estimates what kind of attack was made against the vehicle-mounted unit.
- the attack estimation unit 126 increases the evaluation value of the abnormality that is expected to occur in the on-board unit that is determined to have been infringed by the infringement determination unit 124 by a predetermined amount.
- the attack estimation unit 126 increases the evaluation value of the abnormality that is expected to occur in ECU #1 from “1" to "2" as shown in FIG. 9.
- the attack estimation unit 126 reduces, by a predetermined amount, the evaluation value of the abnormality that is expected to occur in the on-board unit that is determined by the intrusion determination unit 124 to have not been intruded.
- the attack estimation unit 126 reduces the evaluation value of the abnormality assumed to occur in ECU #2 from "1" to "0" as shown in FIG. 9.
- ECU #1 is a TCU and ECU #2 is an IVI, it is determined that only the TCU has been attacked.
- the attack estimation unit 126 performs the following process (1) or (2) on the evaluation value of an abnormality that is expected to occur in the in-vehicle unit.
- the evaluation value of the abnormality that is expected to occur in the on-board unit that is the target of the attack is increased by a value lower than the increase in the evaluation value of the on-board unit that is the source of the attack.
- the on-board unit from which the attack originates and the on-board unit that is the target of the attack are physically or logically related via a network, etc., so if the on-board unit from which the attack originates is compromised, the on-board unit that is the target of the attack may also be compromised.
- ECU #3 is the target of attack C, which starts from ECU #1. This time, it was determined that ECU #1 was compromised, but it was not possible to determine whether ECU #3 was compromised. In this case, since ECU #1 has been compromised, the evaluation value of the abnormality that is expected to occur in ECU #3 in attack C is increased by a smaller amount than from "1" to "2", for example to "1.1".
- ECU #3 is the target of attack D, which starts from ECU #2. If it cannot be determined whether ECU #3 has been compromised and it is determined that ECU #2, which is the starting point of attack D, has not been compromised, the attack estimation unit 126 leaves the evaluation value of abnormality A, which is assumed to occur in ECU #3 in attack D, at "1" and does not change it.
- ECU #5 is the starting point and target of attack X. If it cannot be determined whether ECU #5 has been compromised this time, the starting point of attack X against ECU #5 is ECU #5 itself, so the attack estimation unit 126 does not change the evaluation values of abnormalities B and C that are assumed to occur in ECU #5 in attack X from "1.”
- the attack estimation unit 126 adjusts the evaluation value of the anomaly corresponding to the attack shown in FIG. 7, which is stored as an abnormal attack table in the abnormal attack DB 130, based on the result of the integrity verification, as shown in FIG. 9. Then, after adjusting the evaluation value, the attack estimation unit 126 estimates which type of attack shown in FIG. 9 has been performed.
- the estimation is calculated by measuring the similarity between the measured anomaly information and the predicted anomaly information.
- the measured anomaly information indicates a combination of anomalies that have actually been observed in the vehicle 4.
- the predicted anomaly information indicates a combination of anomalies that are predicted to occur in the electronic control system when attacked by each attack type, and an abnormality evaluation value, which are stored as an abnormality attack table in the abnormal attack DB 130.
- the inner product of the data string of the actual anomaly information expressed as a vector and the data string of the predicted anomaly information expressed as a vector is calculated. Then, the inner product is divided by the number of elements in the vector of the predicted anomaly information that have a value greater than 0, and the row of the anomaly attack table with the highest result is extracted. Then, if the result of this calculation is equal to or greater than a predetermined value, it is presumed that the corresponding attack has been carried out on the ECU, which is an on-board unit.
- abnormalities A, B, and C are observed in ECU #1 as actual anomaly information, referring to Figure 9, in the case of attack A, the evaluation values of abnormalities A and C in ECU #1 are each 2, while the evaluation value of abnormality B in ECU #1 is 0, so the calculation result of the inner product is 4. And since there are two abnormalities with evaluation values greater than 0, abnormalities A and C, the result of dividing 4 by 2, 2, is the similarity between attack A and the actual anomaly information.
- the output unit 128 outputs the estimation result to a database (not shown) or the like.
- an attack on the vehicle 4 can be estimated with high accuracy based on the intrusion determination result indicating whether the on-board unit has been invaded by an attack on the vehicle 4 and the security log indicating an abnormality caused by this intrusion.
- the evaluation value is increased by a value lower than the increase in the evaluation value of the compromised on-board unit, for an on-board unit that is the target of an attack and for which it was not possible to determine whether it has been compromised.
- the analysis unit 14 of the vehicle 4 analyzes in advance whether the security log should be transmitted to the server 100, i.e., whether to transmit to the server 100. This makes it possible to minimize the amount of communication between the vehicle 4 and the server 100.
- security logs are generated for ECU#1 and ECU#2, but the integrity verification results can determine that only ECU#1 has been attacked, and ECU#2 has not been attacked. This makes it possible to determine with high accuracy which ECU has been attacked, even for ECUs that belong to the same entry point, based on the integrity verification results.
- the processing load can be reduced compared to when the integrity of the vehicle-mounted unit is periodically verified.
- ECUs 10, 20, 30, 40, 50, and 60 correspond to the in-vehicle information processing device and the in-vehicle unit
- server 100 corresponds to the information processing device outside the vehicle.
- S8 in FIG. 8 corresponds to the processing of the log acquisition unit 112
- S10 corresponds to the processing of the log analysis unit 122
- S13 corresponds to the processing of the verification instruction unit 140
- S17 to S19 correspond to the processing of the verification unit 18
- S26 corresponds to the processing of the infringement determination unit 124
- S27 corresponds to the processing of the attack estimation unit 126.
- abnormal attack table shown in the structure of the abnormal attack DB130 corresponds to a correspondence table between types of abnormalities, attacks, and evaluation values.
- the server 100 outside the vehicle has the functions of the log analysis unit 122, the intrusion determination unit 124, the attack estimation unit 126, and the verification instruction unit 140, but is not limited to this.
- the vehicle 4 may have some of the functions of the log analysis unit 122, the intrusion determination unit 124, the attack estimation unit 126, and the verification instruction unit 140 in addition to the functions of the verification unit 18.
- the vehicle 4 may not communicate with the server 100, and may have all the functions of the verification unit 18, the log analysis unit 122, the intrusion determination unit 124, the attack estimation unit 126, and the verification instruction unit 140.
- the server 100 is an information processing device outside the vehicle, and performs attack estimation processing on multiple vehicles 4, but this is not limited to this.
- a service tool or a personal computer may be connected to the vehicle 4 wirelessly or via a wire as an external information processing device, and attacks against the vehicle 4 may be estimated using one external information processing device for each vehicle 4.
- the above-mentioned in-vehicle unit may be an information processing device configured by software, such as a VM, rather than a physical information processing device.
- an attack on the vehicle 4 is estimated using an abnormality attack table, but this is not limited to this.
- an attack on the vehicle 4 may be estimated without using an abnormality attack table, based on the security log and the integrity verification result.
- the ECUs 10, 20, 30, 40, 50, 60 and server 100 and the methods described herein may be implemented by a special purpose computer provided by configuring a processor and memory programmed to perform one or more functions embodied in a computer program.
- the ECUs 10, 20, 30, 40, 50, 60 and server 100 and the methods described herein may be implemented by a dedicated computer provided by configuring a processor with one or more dedicated hardware logic circuits.
- the ECUs 10, 20, 30, 40, 50, 60 and server 100 and the methods described in this disclosure may be implemented by one or more dedicated computers configured with a processor and memory programmed to perform one or more functions and a processor configured with one or more hardware logic circuits.
- the computer program may also be stored in a computer-readable non-transitory tangible recording medium as instructions executed by a computer.
- the method for realizing the functions of each part included in ECUs 10, 20, 30, 40, 50, 60 and server 100 does not necessarily have to include software, and all of the functions may be realized using one or more pieces of hardware.
- Multiple functions possessed by one component in the above-mentioned embodiments may be realized by multiple components, or one function possessed by one component may be realized by multiple components. Also, multiple functions possessed by multiple components may be realized by one component, or one function realized by multiple components may be realized by one component. Also, part of the configuration of the above-mentioned embodiments may be omitted. Also, at least part of the configuration of the above-mentioned embodiments may be added to or substituted for the configuration of another of the above-mentioned embodiments.
- the present disclosure can also be realized in various forms, such as an information processing system 2 having the ECUs 10, 20, 30, 40, 50, 60 and the server 100 as components, an information processing program for causing a computer to function as the ECUs 10, 20, 30, 40, 50, 60 and the server 100, a non-transient physical recording medium such as a semiconductor memory on which this program is recorded, and an information processing method.
- a log acquisition unit (112, S8) configured to acquire a security log indicating an abnormality occurring in the vehicle (4); a log analysis unit (122, S10) configured to determine whether or not to instruct a verification unit (18, S17 to S19) of the vehicle to verify the integrity of the in-vehicle unit (10, 20, 30, 40, 50, 60) based on the security log acquired by the log acquisition unit; a verification instruction unit (140, S13) configured to instruct the verification unit to verify the integrity of the vehicle-mounted unit when the log analysis unit determines that the verification unit should be instructed to verify the integrity of the vehicle-mounted unit; an intrusion determination unit (124, S26) configured to determine whether the vehicle-mounted unit has been intruded based on a verification result of the integrity verification by the verification unit; an attack estimation unit (126, S27) configured to estimate an attack that causes an intrusion based on a result of the intrusion determination unit and the security log;
- An information processing device comprising:
- Item 1 is an information processing device according to the present invention
- the attack estimation unit is configured to increase an evaluation value of the attack that causes an intrusion by a predetermined increase amount for the on-board unit that the intrusion determination unit has determined to be intruded, and to decrease an evaluation value of the on-board unit that the intrusion determination unit has determined to be not intruded by a predetermined decrease amount, and to make an estimation regarding the attack based on the evaluation value.
- Information processing device is configured to increase an evaluation value of the attack that causes an intrusion by a predetermined increase amount for the on-board unit that the intrusion determination unit has determined to be intruded, and to decrease an evaluation value of the on-board unit that the intrusion determination unit has determined to be not intruded by a predetermined decrease amount, and to make an estimation regarding the attack based on the evaluation value.
- the attack estimation unit is configured to increase the evaluation value by a value lower than the increase amount, when the intrusion determination unit is unable to determine whether the intrusion determination unit has been intruded into the in-vehicle unit and the intrusion determination unit has determined that the intrusion has been intruded into the in-vehicle unit, and the intrusion determination unit has determined that the intrusion has been intruded into the in-vehicle unit .... Information processing device.
- [Item 4] 4. The information processing device according to claim 2, a correspondence table for the on-board unit, the type of abnormality indicated by the security log, the attack, and the evaluation value; the attack estimation unit is configured to make an estimation regarding the attack based on a sum of the evaluation values in the correspondence table corresponding to the attack. Information processing device.
- the verification instruction unit is configured, when it determines that the log analysis unit should instruct the verification unit to verify the integrity based on the security log, to instruct the verification unit to verify the integrity of all the in-vehicle units, or the in-vehicle units whose security logs indicate the abnormality, or the in-vehicle units other than the in-vehicle units whose security logs indicate the abnormality, or the in-vehicle units whose security logs indicate the abnormality and the in-vehicle units whose security logs indicate the abnormality have a physical or logical relationship with the in-vehicle units whose security logs indicate the abnormality.
- Information processing device is configured, when it determines that the log analysis unit should instruct the verification unit to verify the integrity based on the security log, to instruct the verification unit to verify the integrity of all the in-vehicle units, or the in-vehicle units whose security logs indicate the abnormality, or the in-vehicle units other than the in-vehicle units
- the verification instruction unit is configured to, when the log analysis unit determines based on the security log that the log analysis unit should instruct the verification unit to verify the integrity, instruct the verification unit to verify at least one of a program code, data, a hardware configuration, and a software configuration, as the integrity verification.
- Information processing device is configured to, when the log analysis unit determines based on the security log that the log analysis unit should instruct the verification unit to verify the integrity, instruct the verification unit to verify at least one of a program code, data, a hardware configuration, and a software configuration, as the integrity verification.
- the intrusion determination unit is configured to instruct the verification unit to verify the integrity when one or more of the following conditions are met: the security log was generated because a detection function of the vehicle detected the abnormality, or the security log was generated because a defense function of a second or subsequent layer of a defense in depth of the vehicle defended against the attack, and not to instruct the verification unit to verify the integrity when none of the conditions are met.
- Information processing device is configured to instruct the verification unit to verify the integrity when one or more of the following conditions are met: the security log was generated because a detection function of the vehicle detected the abnormality, or the security log was generated because a defense function of a second or subsequent layer of a defense in depth of the vehicle defended against the attack, and not to instruct the verification unit to verify the integrity when none of the conditions are met.
- the verification instruction unit is configured not to instruct the verification unit to verify the integrity during the period from when the verification instruction unit instructs the verification unit to verify the integrity until the verification of the integrity is completed. Information processing device.
- the information processing device according to any one of items 1 to 8,
- the infringement determination unit is configured to determine that the in-vehicle unit is compromised if the integrity is impaired, to determine that the in-vehicle unit is not compromised if the integrity of the in-vehicle unit is maintained, and to determine that it is not possible to determine whether the in-vehicle unit is compromised or not if the integrity cannot be verified.
- Information processing device is configured to determine that the in-vehicle unit is compromised if the integrity is impaired, to determine that the in-vehicle unit is not compromised if the integrity of the in-vehicle unit is maintained, and to determine that it is not possible to determine whether the in-vehicle unit is compromised or not if the integrity cannot be verified.
- An information processing system including an in-vehicle information processing device (10, 20, 30, 40, 50, 60) and an external information processing device (100) that communicates with the in-vehicle information processing device
- the in-vehicle information processing device includes: a monitoring unit (12, S1, S2) configured to generate a security log indicative of anomalies occurring in the vehicle (4); a verification unit (18, S17-S19) configured to verify the integrity of the vehicle-mounted unit (10, 20, 30, 40, 50, 60); Equipped with The information processing device outside the vehicle includes: A log acquisition unit (112, S8) configured to acquire the security log from the on-board information processing device; a log analysis unit (122, S10) configured to determine whether to instruct the verification unit to verify the integrity of the vehicle-mounted unit based on the security log acquired by the log acquisition unit; a verification instruction unit (140, S13) configured to instruct the verification unit to verify the integrity when the log analysis unit determines that the verification unit should verify the integrity; an intrusion determination unit (124, S26) configured to
- [Item 13] generating a security log indicating anomalies occurring in the vehicle (4); Acquire the generated security log; determining whether or not to instruct to verify the integrity of the vehicle-mounted unit (10, 20, 30, 40, 50, 60) based on the acquired security log; when it is determined that the verification of the integrity of the in-vehicle unit is to be instructed, the verification of the integrity is instructed; When instructed to perform the integrity verification, the integrity verification is performed; determining whether the vehicle-mounted unit has been compromised based on a result of the integrity verification; making an inference regarding an attack that caused the intrusion based on a result of the intrusion determination as to whether the intrusion has occurred or not and the security log; Information processing methods.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- Health & Medical Sciences (AREA)
- Medical Informatics (AREA)
- Bioethics (AREA)
- Small-Scale Networks (AREA)
Abstract
Description
図1に示すように、本実施形態の情報処理システム2は、車両4に搭載された情報処理装置であるECU10、20、30、40、50、60と、車外の情報処理装置であるサーバ100と、を備える。ECUは、Electronic Control Unitの略である。ECU10、20、30、40、50、60の少なくともいずれかと車両4とサーバ100とは、例えば、無線通信ネットワーク6を介して互いに通信を行う。
図8に基づいて、ECU10、20、30、40、50、60とサーバ100とを備える情報処理システム2が実行する情報処理について説明する。
以上説明した実施形態によれば、以下の効果を得ることができる。
以上、本開示の実施形態について説明したが、本開示は前述の実施形態に限定されることなく、種々変形して実施することができる。
[項目1]
車両(4)で発生した異常を示すセキュリティログを取得するように構成されたログ取得部(112、S8)と、
前記ログ取得部が取得する前記セキュリティログに基づいて、前記車両の検証部(18、S17~S19)に車載ユニット(10、20、30、40、50、60)の完全性の検証を指示するか否かを判定するように構成されたログ分析部(122、S10)と、
前記検証部に前記車載ユニットの前記完全性の検証を指示すると前記ログ分析部が判定すると、前記完全性の検証を前記検証部に指示するように構成された検証指示部(140、S13)と、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定するように構成された侵害判定部(124、S26)と、
前記侵害判定部による侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行うように構成された攻撃推定部(126、S27)と、
を備える情報処理装置。
項目1に記載の情報処理装置であって、
前記攻撃推定部は、侵害されたと前記侵害判定部が判定した前記車載ユニットについて侵害の起因となる前記攻撃の評価値を所定の上昇分高くし、侵害されていないと前記侵害判定部が判定した前記車載ユニットについて前記評価値を所定の低下分低くし、前記評価値に基づいて前記攻撃に関する推定を行うように構成されている、
情報処理装置。
項目2に記載の情報処理装置であって、
前記攻撃推定部は、侵害されたか否かを前記侵害判定部が判定できなかった前記車載ユニットについて、侵害されたと前記侵害判定部が判定した前記車載ユニットと物理的または論理的に関連性がある場合、前記上昇分よりも低い値で前記評価値を高くするように構成されている、
情報処理装置。
項目2または3に記載の情報処理装置であって、
前記車載ユニットと前記セキュリティログが示す前記異常の種類と前記攻撃と前記評価値との対応テーブルをさらに備え、
前記攻撃推定部は、前記攻撃に対応する前記対応テーブルの前記評価値の合計に基づいて、前記攻撃に関する推定を行うように構成されている、
情報処理装置。
項目1から4のいずれか1項に記載の情報処理装置であって、
前記検証指示部は、前記ログ分析部が前記セキュリティログに基づいて前記検証部に前記完全性の検証を指示すると判定すると、すべての前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニット以外の前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニットと前記セキュリティログが前記異常を示す前記車載ユニットに物理的または論理的な関連性を有する前記車載ユニット、に対する前記完全性の検証を前記検証部に指示するように構成されている、
情報処理装置。
項目1から5のいずれか1項に記載の情報処理装置であって、
前記検証指示部は、前記ログ分析部が前記セキュリティログに基づいて前記検証部に前記完全性の検証を指示すると判定すると、前記完全性の検証として、プログラムコードと、データと、ハードウェア構成と、ソフトウェア構成とのうち、少なくとも一つを検証するように前記検証部に指示するように構成されている、
情報処理装置。
項目1から6のいずれか1項に記載の情報処理装置であって、
前記侵害判定部は、前記セキュリティログが、前記車両の検出機能が前記異常を検出したことにより生成された場合、あるいは、前記車両の多層防御の第2層以降の防御機能が前記攻撃を防御したことにより生成された場合、のいずれか1個以上の条件が成立すると、前記完全性の検証を前記検証部に指示し、前記条件がいずれも成立しない場合、前記完全性の検証を前記検証部に指示しないように構成されている、
情報処理装置。
項目1から7のいずれか1項に記載の情報処理装置であって、
前記検証指示部は、前記検証部に前記完全性の検証を指示してから前記完全性の検証が終了するまでの間、前記検証部に対して前記完全性の検証を指示しないように構成されている、
情報処理装置。
項目1から8のいずれか1項に記載の情報処理装置であって、
前記侵害判定部は、前記完全性が損なわれている場合、前記車載ユニットは侵害されていると判定し、前記車載ユニットの前記完全性が保たれている場合、前記車載ユニットは侵害されていないと判定し、前記完全性を検証できなかった場合、前記車載ユニットが侵害されているか否かを判定できないと判定する、ように構成されている、
情報処理装置。
項目1から項目9のいずれか1項に記載の情報処理装置としてコンピュータを機能させる情報処理プログラム。
車両(4)で発生した異常を示すセキュリティログを取得し、
取得した前記セキュリティログに基づいて、前記車両の検証部に車載ユニットの完全性の検証を指示するか否かを判定し、
前記検証部に前記完全性の検証を指示すると判定すると、前記検証部に前記車載ユニットの前記完全性の検証を指示し、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定し、
前記車載ユニットが侵害されたか否かの侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行う、
情報処理方法。
車載の情報処理装置(10、20、30、40、50、60)と前記車載の情報処理装置と通信する車外の情報処理装置(100)とを備える情報処理システムであって、
前記車載の情報処理装置は、
車両(4)で発生した異常を示すセキュリティログを生成するように構成された監視部(12、S1、S2)と、
車載ユニット(10、20、30、40、50、60)の完全性の検証を行うように構成された検証部(18、S17~S19)と、
を備え、
前記車外の情報処理装置は、
前記車載の情報処理装置から前記セキュリティログを取得するように構成されたログ取得部(112、S8)と、
前記ログ取得部が取得する前記セキュリティログに基づいて、前記検証部に前記車載ユニットの前記完全性の検証を指示するか否かを判定するように構成されたログ分析部(122、S10)と、
前記検証部に前記完全性の検証を指示すると前記ログ分析部が判定すると、前記完全性の検証を前記検証部に指示するように構成された検証指示部(140、S13)と、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定するように構成された侵害判定部(124、S26)と、
前記侵害判定部による侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行うように構成された攻撃推定部(126、S27)と、
を備える、
情報処理システム。
車両(4)で発生した異常を示すセキュリティログを生成し、
生成した前記セキュリティログを取得し、
取得した前記セキュリティログに基づいて、車載ユニット(10、20、30、40、50、60)の完全性の検証を行うことを指示するか否かを判定し、
前記車載ユニットの前記完全性の検証を行うことを指示すると判定すると、前記完全性の検証を行うことを指示し、
前記完全性の検証を行うことを指示されると前記完全性の検証を行い、
前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定し、
前記車載ユニットが侵害されたか否かの侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行う、
情報処理方法。
Claims (13)
- 車両(4)で発生した異常を示すセキュリティログを取得するように構成されたログ取得部(112、S8)と、
前記ログ取得部が取得する前記セキュリティログに基づいて、前記車両の検証部(18、S17~S19)に車載ユニット(10、20、30、40、50、60)の完全性の検証を指示するか否かを判定するように構成されたログ分析部(122、S10)と、
前記検証部に前記車載ユニットの前記完全性の検証を指示すると前記ログ分析部が判定すると、前記完全性の検証を前記検証部に指示するように構成された検証指示部(140、S13)と、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定するように構成された侵害判定部(124、S26)と、
前記侵害判定部による侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行うように構成された攻撃推定部(126、S27)と、
を備える情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記攻撃推定部は、侵害されたと前記侵害判定部が判定した前記車載ユニットについて侵害の起因となる前記攻撃の評価値を所定の上昇分高くし、侵害されていないと前記侵害判定部が判定した前記車載ユニットについて前記評価値を所定の低下分低くし、前記評価値に基づいて前記攻撃に関する推定を行うように構成されている、
情報処理装置。 - 請求項2に記載の情報処理装置であって、
前記攻撃推定部は、侵害されたか否かを前記侵害判定部が判定できなかった前記車載ユニットについて、侵害されたと前記侵害判定部が判定した前記車載ユニットと物理的または論理的に関連性がある場合、前記上昇分よりも低い値で前記評価値を高くするように構成されている、
情報処理装置。 - 請求項2に記載の情報処理装置であって、
前記車載ユニットと前記セキュリティログが示す前記異常の種類と前記攻撃と前記評価値との対応テーブルをさらに備え、
前記攻撃推定部は、前記攻撃に対応する前記対応テーブルの前記評価値の合計に基づいて、前記攻撃に関する推定を行うように構成されている、
情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記検証指示部は、前記ログ分析部が前記セキュリティログに基づいて前記検証部に前記完全性の検証を指示すると判定すると、すべての前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニット以外の前記車載ユニットか、あるいは、前記セキュリティログが前記異常を示す前記車載ユニットと前記セキュリティログが前記異常を示す前記車載ユニットに物理的または論理的な関連性を有する前記車載ユニット、に対する前記完全性の検証を前記検証部に指示するように構成されている、
情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記検証指示部は、前記ログ分析部が前記セキュリティログに基づいて前記検証部に前記完全性の検証を指示すると判定すると、前記完全性の検証として、プログラムコードと、データと、ハードウェア構成と、ソフトウェア構成とのうち、少なくとも一つを検証するように前記検証部に指示するように構成されている、
情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記侵害判定部は、前記セキュリティログが、前記車両の検出機能が前記異常を検出したことにより生成された場合、あるいは、前記車両の多層防御の第2層以降の防御機能が前記攻撃を防御したことにより生成された場合、のいずれか1個以上の条件が成立すると、前記完全性の検証を前記検証部に指示し、前記条件がいずれも成立しない場合、前記完全性の検証を前記検証部に指示しないように構成されている、
情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記検証指示部は、前記検証部に前記完全性の検証を指示してから前記完全性の検証が終了するまでの間、前記検証部に対して前記完全性の検証を指示しないように構成されている、
情報処理装置。 - 請求項1に記載の情報処理装置であって、
前記侵害判定部は、前記完全性が損なわれている場合、前記車載ユニットは侵害されていると判定し、前記車載ユニットの前記完全性が保たれている場合、前記車載ユニットは侵害されていないと判定し、前記完全性を検証できなかった場合、前記車載ユニットが侵害されているか否かを判定できないと判定する、ように構成されている、
情報処理装置。 - 請求項1から請求項9のいずれか1項に記載の情報処理装置としてコンピュータを機能させる情報処理プログラム。
- 車両(4)で発生した異常を示すセキュリティログを取得し、
取得した前記セキュリティログに基づいて、前記車両の検証部に車載ユニットの完全性の検証を指示するか否かを判定し、
前記検証部に前記完全性の検証を指示すると判定すると、前記検証部に前記車載ユニットの前記完全性の検証を指示し、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定し、
前記車載ユニットが侵害されたか否かの侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行う、
情報処理方法。 - 車載の情報処理装置(10、20、30、40、50、60)と前記車載の情報処理装置と通信する車外の情報処理装置(100)とを備える情報処理システムであって、
前記車載の情報処理装置は、
車両(4)で発生した異常を示すセキュリティログを生成するように構成された監視部(12、S1、S2)と、
車載ユニット(10、20、30、40、50、60)の完全性の検証を行うように構成された検証部(18、S17~S19)と、
を備え、
前記車外の情報処理装置は、
前記車載の情報処理装置から前記セキュリティログを取得するように構成されたログ取得部(112、S8)と、
前記ログ取得部が取得する前記セキュリティログに基づいて、前記検証部に前記車載ユニットの前記完全性の検証を指示するか否かを判定するように構成されたログ分析部(122、S10)と、
前記検証部に前記完全性の検証を指示すると前記ログ分析部が判定すると、前記完全性の検証を前記検証部に指示するように構成された検証指示部(140、S13)と、
前記検証部による前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定するように構成された侵害判定部(124、S26)と、
前記侵害判定部による侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行うように構成された攻撃推定部(126、S27)と、
を備える、
情報処理システム。 - 車両(4)で発生した異常を示すセキュリティログを生成し、
生成した前記セキュリティログを取得し、
取得した前記セキュリティログに基づいて、車載ユニット(10、20、30、40、50、60)の完全性の検証を行うことを指示するか否かを判定し、
前記車載ユニットの前記完全性の検証を行うことを指示すると判定すると、前記完全性の検証を行うことを指示し、
前記完全性の検証を行うことを指示されると前記完全性の検証を行い、
前記完全性の検証の検証結果に基づいて、前記車載ユニットが侵害されたか否かを判定し、
前記車載ユニットが侵害されたか否かの侵害判定結果と前記セキュリティログとに基づいて、侵害の起因となる攻撃に関する推定を行う、
情報処理方法。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP23872343.1A EP4597345A4 (en) | 2022-09-30 | 2023-09-26 | INFORMATION PROCESSING DEVICE, INFORMATION PROCESSING SYSTEM, INFORMATION PROCESSING PROGRAM AND INFORMATION PROCESSING METHOD |
| CN202380069358.7A CN119968631A (zh) | 2022-09-30 | 2023-09-26 | 信息处理装置、信息处理系统、信息处理程序、信息处理方法 |
| US19/088,590 US20250225237A1 (en) | 2022-09-30 | 2025-03-24 | Information processing device, information processing system, method and storage medium thereof |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2022158053A JP7835142B2 (ja) | 2022-09-30 | 2022-09-30 | 情報処理装置、情報処理システム、情報処理プログラム、情報処理方法 |
| JP2022-158053 | 2022-09-30 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/088,590 Continuation US20250225237A1 (en) | 2022-09-30 | 2025-03-24 | Information processing device, information processing system, method and storage medium thereof |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024071120A1 true WO2024071120A1 (ja) | 2024-04-04 |
Family
ID=90478059
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2023/034946 Ceased WO2024071120A1 (ja) | 2022-09-30 | 2023-09-26 | 情報処理装置、情報処理システム、情報処理プログラム、情報処理方法 |
Country Status (5)
| Country | Link |
|---|---|
| US (1) | US20250225237A1 (ja) |
| EP (1) | EP4597345A4 (ja) |
| JP (1) | JP7835142B2 (ja) |
| CN (1) | CN119968631A (ja) |
| WO (1) | WO2024071120A1 (ja) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN119996048A (zh) * | 2025-03-12 | 2025-05-13 | 北京天融信网络安全技术有限公司 | 机框式设备攻击报文的收集方法、查询方法、计算机装置 |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016149655A (ja) * | 2015-02-12 | 2016-08-18 | 富士通株式会社 | 管理方法、管理プログラム、管理装置、管理システムおよび情報処理方法 |
| WO2020153122A1 (ja) * | 2019-01-21 | 2020-07-30 | エヌ・ティ・ティ・コミュニケーションズ株式会社 | 車両セキュリティ監視装置、方法及びプログラム |
| JP2020123307A (ja) | 2019-01-29 | 2020-08-13 | オムロン株式会社 | セキュリティ装置、攻撃特定方法、及びプログラム |
| WO2022014193A1 (ja) * | 2020-07-14 | 2022-01-20 | 株式会社デンソー | ログ管理装置及びセキュリティ攻撃検知・分析システム |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP7380473B2 (ja) * | 2020-07-29 | 2023-11-15 | 株式会社デンソー | セキュリティ監視システム |
| JP7517223B2 (ja) * | 2021-03-29 | 2024-07-17 | 株式会社デンソー | 攻撃分析装置、攻撃分析方法、及び攻撃分析プログラム |
-
2022
- 2022-09-30 JP JP2022158053A patent/JP7835142B2/ja active Active
-
2023
- 2023-09-26 CN CN202380069358.7A patent/CN119968631A/zh active Pending
- 2023-09-26 EP EP23872343.1A patent/EP4597345A4/en active Pending
- 2023-09-26 WO PCT/JP2023/034946 patent/WO2024071120A1/ja not_active Ceased
-
2025
- 2025-03-24 US US19/088,590 patent/US20250225237A1/en active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2016149655A (ja) * | 2015-02-12 | 2016-08-18 | 富士通株式会社 | 管理方法、管理プログラム、管理装置、管理システムおよび情報処理方法 |
| WO2020153122A1 (ja) * | 2019-01-21 | 2020-07-30 | エヌ・ティ・ティ・コミュニケーションズ株式会社 | 車両セキュリティ監視装置、方法及びプログラム |
| JP2020123307A (ja) | 2019-01-29 | 2020-08-13 | オムロン株式会社 | セキュリティ装置、攻撃特定方法、及びプログラム |
| WO2022014193A1 (ja) * | 2020-07-14 | 2022-01-20 | 株式会社デンソー | ログ管理装置及びセキュリティ攻撃検知・分析システム |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP4597345A4 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN119996048A (zh) * | 2025-03-12 | 2025-05-13 | 北京天融信网络安全技术有限公司 | 机框式设备攻击报文的收集方法、查询方法、计算机装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4597345A1 (en) | 2025-08-06 |
| EP4597345A4 (en) | 2025-12-31 |
| JP2024051738A (ja) | 2024-04-11 |
| JP7835142B2 (ja) | 2026-03-25 |
| CN119968631A (zh) | 2025-05-09 |
| US20250225237A1 (en) | 2025-07-10 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN107431709B (zh) | 攻击识别方法、攻击识别装置和用于汽车的总线系统 | |
| US11971982B2 (en) | Log analysis device | |
| US20190303567A1 (en) | Detecting data anomalies on a data interface using machine learning | |
| JP7176569B2 (ja) | 情報処理装置、ログ分析方法及びプログラム | |
| US12039050B2 (en) | Information processing device | |
| WO2021260984A1 (ja) | 情報処理装置、情報処理方法及びプログラム | |
| CN115134109A (zh) | 攻击分析器、攻击分析方法和存储介质 | |
| CN111066303A (zh) | 与机动车辆驾驶员辅助系统相关的方法 | |
| US12341750B2 (en) | Arrangement of cyber security and prognostics, coexisting on a single platform | |
| WO2021084961A1 (ja) | 分析装置及び分析方法 | |
| US12511377B2 (en) | Information processing device and method for controlling information processing device | |
| CN115270128A (zh) | 安全系统和安全方法 | |
| JP7537382B2 (ja) | 攻撃分析装置、攻撃分析方法、及び攻撃分析プログラム | |
| US20250225237A1 (en) | Information processing device, information processing system, method and storage medium thereof | |
| JP7523855B2 (ja) | 検知ルール出力方法、及び、セキュリティシステム | |
| WO2019207764A1 (ja) | 抽出装置、抽出方法および記録媒体、並びに、検知装置 | |
| JP7509091B2 (ja) | 攻撃分析装置、攻撃分析方法、及び攻撃分析プログラム | |
| JP2020096320A (ja) | 不正信号処理装置 | |
| JP2024051327A (ja) | 更新装置、更新方法、及び更新プログラム | |
| CN107608339B (zh) | 汽车车机的接口防护方法及装置 | |
| CN106789932A (zh) | 一种基于组件跳变的网络系统安全防护方法及装置 | |
| EP3661149A1 (en) | Test system and method for data analytics | |
| US20250156549A1 (en) | Verification system, verification method, and recording medium | |
| US20250247411A1 (en) | Attack analysis device, attack analysis method, and attack analysis program | |
| US12621318B2 (en) | System for intrusion detection using a vehicle electrical system |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23872343 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202380069358.7 Country of ref document: CN |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023872343 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2023872343 Country of ref document: EP Effective date: 20250430 |
|
| WWP | Wipo information: published in national office |
Ref document number: 202380069358.7 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 2023872343 Country of ref document: EP |