WO2023199552A1 - 検知装置および検知方法 - Google Patents

検知装置および検知方法 Download PDF

Info

Publication number
WO2023199552A1
WO2023199552A1 PCT/JP2022/046331 JP2022046331W WO2023199552A1 WO 2023199552 A1 WO2023199552 A1 WO 2023199552A1 JP 2022046331 W JP2022046331 W JP 2022046331W WO 2023199552 A1 WO2023199552 A1 WO 2023199552A1
Authority
WO
WIPO (PCT)
Prior art keywords
message
detection
reception interval
messages
burst
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2022/046331
Other languages
English (en)
French (fr)
Inventor
増川京佑
塚本博之
三好孝典
上田浩史
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Sumitomo Wiring Systems Ltd
AutoNetworks Technologies Ltd
Sumitomo Electric Industries Ltd
Original Assignee
Sumitomo Wiring Systems Ltd
AutoNetworks Technologies Ltd
Sumitomo Electric Industries Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Sumitomo Wiring Systems Ltd, AutoNetworks Technologies Ltd, Sumitomo Electric Industries Ltd filed Critical Sumitomo Wiring Systems Ltd
Priority to US18/855,390 priority Critical patent/US20250337673A1/en
Priority to JP2024514802A priority patent/JPWO2023199552A1/ja
Priority to CN202280090009.9A priority patent/CN118592018A/zh
Publication of WO2023199552A1 publication Critical patent/WO2023199552A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • H04L43/0852Delays
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0631Management of faults, events, alarms or notifications using root cause analysis; using analysis of correlation between notifications, alarms or events based on decision criteria, e.g. hierarchy, tree or time analysis
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/16Threshold monitoring

Definitions

  • the present disclosure relates to a sensing device and a sensing method.
  • This application claims priority based on Japanese Patent Application No. 2022-65792 filed on April 12, 2022, and the entire disclosure thereof is incorporated herein.
  • Patent Document 1 International Publication No. 2021/111685 discloses the following detection device. That is, the detection device is a detection device that detects fraudulent messages in an in-vehicle network, and includes an acquisition unit that acquires a target distribution that is a distribution of reception intervals of periodic messages transmitted in the in-vehicle network; an extraction unit that extracts a part of the target distribution according to a predetermined standard, and a detection unit that performs a detection process to detect the fraudulent message based on the part of the target distribution extracted by the extraction unit. Be prepared.
  • the detection device is a detection device that detects fraudulent messages in an in-vehicle network, and includes an acquisition unit that acquires a target distribution that is a distribution of reception intervals of periodic messages transmitted in the in-vehicle network; an extraction unit that extracts a part of the target distribution according to a predetermined standard, and a detection unit that performs a detection process to detect the fraudulent message based on the part of the target distribution extracted by the extraction unit. Be prepared.
  • a detection device of the present disclosure is a detection device that detects an abnormality in a network in which a plurality of target messages including periodic messages transmitted and received at a predetermined transmission cycle are transmitted and received, and the detection device calculates a reception interval of the target messages.
  • a detection unit that performs a detection process to detect an abnormality in the network based on the reception interval calculated by the calculation unit, and the target message whose reception interval is greater than the transmission cycle by a predetermined value or more.
  • a counting unit that counts a plurality of burst messages including a delayed message and one or more target messages received following the delayed message and whose reception interval is equal to or less than a predetermined value; , it is determined whether or not to perform the detection process based on the reception interval for at least one of the plurality of burst messages, based on the count value by the count unit.
  • the detection method of the present disclosure is a detection method for a detection device that detects an abnormality in a network in which a plurality of target messages including periodic messages transmitted and received at a predetermined transmission cycle are transmitted and received, a step of performing detection processing to detect an abnormality in the network based on the calculated reception interval; and a delayed message that is the target message in which the reception interval is larger than the transmission cycle by a predetermined value or more;
  • the step of performing the detection process includes the step of counting a plurality of burst messages including one or more of the target messages in which the reception interval is equal to or less than a predetermined value and which are received following the delayed message, and the step of performing the detection processing includes: Based on the count value of the plurality of burst messages, it is determined whether or not to perform the detection process based on the reception interval for at least one of the plurality of burst messages.
  • One aspect of the present disclosure can be realized not only as a detection device including such a characteristic processing unit, but also as a program for causing a computer to execute such characteristic processing steps, or as a detection device including such a characteristic processing unit. It can be realized as a semiconductor integrated circuit that realizes part or all of the above, or it can be realized as a system including a detection device.
  • FIG. 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure.
  • FIG. 2 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure.
  • FIG. 3 is a diagram illustrating an example of a distribution of target messages and reception times received by a relay device according to an embodiment of the present disclosure.
  • FIG. 4 is a diagram illustrating an example of statistical values used for detection processing in the relay device according to the embodiment of the present disclosure.
  • FIG. 5 is a diagram illustrating another example of the distribution of target messages and reception times received by the relay device according to the embodiment of the present disclosure.
  • FIG. 6 is a diagram illustrating an example of statistical values used for detection processing in a relay device according to a comparative example of the embodiment of the present disclosure.
  • FIG. 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure.
  • FIG. 2 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure.
  • FIG. 3
  • FIG. 7 is a diagram illustrating an example of a reception time of a target message received by a relay device according to an embodiment of the present disclosure.
  • FIG. 8 is a diagram illustrating another example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • FIG. 9 is a diagram illustrating an example of a reception time of a target message received by a relay device according to an embodiment of the present disclosure.
  • FIG. 10 is a diagram illustrating another example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • FIG. 11 is a diagram illustrating an example of a reception time of a target message received by a relay device according to an embodiment of the present disclosure.
  • FIG. 12 is a diagram illustrating an example of a correspondence table stored in a storage unit in a relay device according to an embodiment of the present disclosure.
  • FIG. 13 is a flowchart defining an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
  • FIG. 14 is a flowchart defining an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs a process of counting burst messages.
  • FIG. 15 is a diagram illustrating an example of a network connection topology according to an embodiment of the present disclosure.
  • FIG. 16 is a diagram illustrating another example of the correspondence table stored in the storage unit in the relay device according to the embodiment of the present disclosure.
  • the present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide a detection device and a detection method that can more accurately detect abnormalities in a network.
  • a detection device is a detection device that detects an abnormality in a network in which a plurality of target messages including periodic messages that are transmitted and received at a predetermined transmission cycle is transmitted and received.
  • a calculation unit that calculates a message reception interval; a detection unit that performs a detection process to detect an abnormality in the network based on the reception interval calculated by the calculation unit;
  • a counting unit that counts a plurality of burst messages including a delayed message that is the target message that is larger than a value, and one or more target messages that are received following the delayed message and whose reception interval is equal to or less than a predetermined value. and whether or not the detection unit performs the detection process based on the reception interval for at least one of the plurality of burst messages based on the count value by the count unit. Determine.
  • the configuration that determines whether or not to perform detection processing based on the reception interval of burst messages based on the count value of burst messages allows multiple It is possible to decide whether or not to target multiple burst messages for detection processing depending on the probability that the burst messages include fraudulent target messages, so for example, if a burst phenomenon occurs This makes it possible to prevent false positives caused by false positives and to prevent fraudulent messages included in multiple burst messages from being overlooked. Therefore, abnormalities in the network can be detected more accurately.
  • the detection unit when the count value is less than or equal to a threshold value, the detection unit performs the detection based on the reception interval of at least one of the burst messages among the plurality of burst messages. No processing is required.
  • the detection unit may perform the detection process based on the reception interval of the plurality of burst messages when the count value is larger than the threshold. good.
  • detection processing can be performed based on the reception interval of multiple burst messages, without excluding multiple burst messages that may include invalid target messages from detection processing targets. This makes it possible to prevent unauthorized messages from being overlooked.
  • the detection unit may determine the threshold according to the reception interval of the target message, which is the delayed message.
  • the detection unit calculates a detection index that increases or decreases depending on the relationship between the reception interval and reference information regarding the reception interval, and The detection processing is performed based on an index, and when the count value is less than or equal to the threshold, the detection unit detects the detection index for at least one of the burst messages among the plurality of burst messages.
  • a configuration in which no calculation is performed may also be used.
  • the counting unit ends counting if the next target message is not received within a predetermined time from the reception time of the target message that is the burst message.
  • the detection section may suspend the detection processing until the counting section finishes counting, and restart the detection processing after the counting section finishes counting.
  • counting of burst messages can be ended with the end of a burst phenomenon, and detection processing can be restarted at a more appropriate timing.
  • a detection method is a detection method in a detection device that detects an abnormality in a network where a plurality of target messages including periodic messages that are transmitted and received at a predetermined transmission cycle are transmitted and received. , a step of calculating a reception interval of the target message; a step of performing a detection process of detecting an abnormality in the network based on the calculated reception interval; counting a plurality of burst messages including a delayed message that is a target message, and one or more target messages received following the delayed message and whose reception interval is equal to or less than a predetermined value; In the step of performing the detection process, based on the count value of the plurality of burst messages, the detection process is performed on at least one of the plurality of burst messages based on the reception interval. Decide whether
  • FIG. 1 is a diagram showing the configuration of a communication system according to an embodiment of the present disclosure.
  • communication system 301 includes a relay device 101 and a plurality of communication devices 111.
  • Communication system 301 is mounted on a vehicle, for example.
  • the communication device 111 is, for example, an in-vehicle ECU (Electronic Control Unit).
  • the communication system 301 may include a relay device other than the relay device 101 (not shown).
  • the relay device 101 and the communication device 111 constitute a network 201. More specifically, relay device 101 and communication device 111 are connected to each other via transmission line 10.
  • the communication system 301 may have a configuration in which the relay device 101 is connected one-to-one to the communication device 111 via the line-type transmission line 10 as shown in FIG.
  • the device may be connected to a communication device 111 via a transmission line 10, or may be connected to a plurality of communication devices 111 in a one-to-many manner via a bus-type transmission line 10. It's okay.
  • the transmission line 10 is, for example, CAN (Controller Area Network) (registered trademark), FlexRay (registered trademark), MOST (Media Oriented Systems Transport) (registered trademark), Ethernet (registered trademark), and LIN (Lo cal Interconnect Network) etc.
  • CAN Controller Area Network
  • FlexRay registered trademark
  • MOST Media Oriented Systems Transport
  • Ethernet registered trademark
  • LIN Lu cal Interconnect Network
  • the relay device 101 can communicate with the communication device 111.
  • the relay device 101 performs a relay process of relaying information exchanged between a plurality of communication devices 111 connected to different transmission lines 10.
  • a plurality of messages including periodically transmitted messages are transmitted and received.
  • a message periodically transmitted in the network 201 will also be referred to as a periodic message.
  • periodic message is not limited to messages transmitted strictly periodically, but refers to messages of a type that should be transmitted periodically.
  • messages transmitted irregularly in the network 201 will also be referred to as event messages.
  • Message transmission by the communication device 111 may be performed by broadcast, unicast, or multicast.
  • the relay device 101 functions as a detection device and detects an abnormality in the network 201.
  • FIG. 2 is a diagram showing the configuration of a relay device according to an embodiment of the present disclosure.
  • relay device 101 includes a communication processing section 11, a calculation section 12, a processing section 14, a storage section 15, and a plurality of communication ports 16.
  • the processing section 14 is an example of a counting section and an example of a detecting section.
  • a part or all of the communication processing section 11, the calculation section 12, and the processing section 14 are realized, for example, by a processing circuit including one or more processors.
  • the storage unit 15 is, for example, a flash memory included in the processing circuit.
  • Communication port 16 is, for example, a connector or a terminal.
  • a transmission line 10 is connected to each communication port 16 .
  • the communication processing unit 11 performs relay processing to relay messages transmitted between the communication devices 111. For example, when the communication processing unit 11 receives a message from the communication device 111 via the corresponding transmission line 10 and the corresponding communication port 16, it generates a message CP that is a copy of the received message, and includes the received message in the generated message CP. Attach a timestamp indicating the time the message was received. The communication processing unit 11 then transmits the received message to the other communication device 111 via the corresponding communication port 16 and the corresponding transmission line 10, and outputs the message CP to which the time stamp has been added to the calculation unit 12.
  • the calculation unit 12 calculates the reception interval of a target message, which is a message to be subjected to detection processing in the relay device 101.
  • the relay device 101 may be configured to perform detection processing on one type of message sent from one communication device 111, or may perform detection processing on multiple types of messages sent from each of a plurality of communication devices 111. Alternatively, a configuration may be adopted in which detection processing is performed for each type of message. In the following, an example will be described in which the relay device 101 performs detection processing on a message transmitted from a certain communication device 111 as a "target message M."
  • the plurality of target messages M transmitted in the network 201 include periodic messages transmitted from the communication device 111 according to a predetermined transmission cycle Cm.
  • the calculation unit 12 obtains the reception time t of the target message M among the messages relayed by the communication processing unit 11.
  • the storage unit 15 stores an ID for each type of target message.
  • the ID of the target message will also be referred to as the target ID
  • the ID of the target message M will also be referred to as the target ID_M.
  • the calculation unit 12 receives the message CP from the communication processing unit 11 and checks the ID included in the received message CP and the target ID in the storage unit 15.
  • the calculation unit 12 recognizes that the message from which the message CP is copied is the target message M, and applies the message CP to the target message M. By referring to the given time stamp, the reception time t of the target message M is obtained.
  • the calculation unit 12 When the calculation unit 12 obtains the reception time t of the target message M, it calculates the difference between the reception time t and the reception time t of the immediately previous target message M as the reception interval x of the target message M. More specifically, the calculation unit 12 calculates the (m ⁇ 1)th target message M(m -1), the reception interval xm of the target message Mm is calculated by subtracting the reception time t(m-1). Here, m is a positive integer. The calculation unit 12 stores the calculated reception interval xm and reception time tm in the storage unit 15. When there are multiple target messages, the calculation unit 12 calculates the reception interval xm and reception time tm for each target message, and stores the calculated reception interval xm and reception time tm in the storage unit 15 for each target ID.
  • the processing unit 14 performs a detection process to detect an abnormality in the network 201 based on the reception interval x calculated by the calculation unit 12.
  • the processing unit 14 calculates the statistical value T of the receiving interval x using the standard deviation ⁇ of the receiving interval x calculated by the calculating unit 12, and performs the detection process based on the calculated statistical value T.
  • the statistical value T indicates the degree of deviation of the reception interval x from the normal state.
  • the statistical value T is an example of a detection index.
  • the processing unit 14 calculates the degree of abnormality Dm of the target message Mm according to the following equation (1).
  • is the average value of the reception interval x, and is an example of reference information regarding the target message M.
  • the standard deviation ⁇ and the average value ⁇ are stored in the storage unit 15.
  • the standard deviation ⁇ is calculated in advance by the manufacturer of the communication system 301 based on the reception interval x, and is stored in the storage unit 15.
  • the average value ⁇ is a value calculated in advance by the manufacturer of the communication system 301 based on the design value of the transmission cycle Cm of the target message M in the network 201, and is stored in the storage unit 15 in advance.
  • the processing unit 14 periodically or irregularly calculates the standard deviation ⁇ and the average value ⁇ based on the plurality of reception intervals x corresponding to the plurality of target messages M, and calculates the standard deviation ⁇ and the average value ⁇ in the storage unit 15.
  • the value ⁇ may be updated to the calculated standard deviation ⁇ and average value ⁇ .
  • the processing unit 14 calculates the statistical value Tm of the target message Mm according to the following equation (2).
  • k is a limiting parameter.
  • the limit parameter k is a preset constant.
  • the statistical value Tm of the target message Mm is the value obtained by subtracting the restriction parameter k from the sum of the statistical value T(m-1) of the target message M(m-1) and the abnormality degree Dm. , and zero, whichever is greater.
  • the statistical value Tm increases or decreases depending on the relationship between the reception interval xm of the target message Mm and the average value ⁇ . Specifically, when the reception interval xm becomes a value that deviates greatly from the average value ⁇ , and the abnormality degree Dm becomes a value larger than the limit parameter k, the statistical value Tm of the target message Mm is This value is larger than the statistical value T(m-1) of message M(m-1).
  • the statistical value Tm of the target message Mm becomes zero or This value is smaller than the statistical value T(m-1) of the target message M(m-1).
  • the processing unit 14 performs a detection process to detect an abnormality in the network 201 based on the calculated statistical value T. For example, the processing unit 14 detects an abnormality in the network 201 based on the calculated statistical value T and a predetermined threshold Thx.
  • the processing unit 14 compares the calculated statistical value T and the threshold value Thx. If the statistical value T is less than or equal to the threshold value Thx, the processing unit 14 determines that no abnormality has occurred in the network 201. On the other hand, if the statistical value T is larger than the threshold value Thx, the processing unit 14 determines that an abnormality has occurred in the network 201.
  • FIG. 3 is a diagram illustrating an example of the distribution of target messages and reception times received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • the plurality of target messages M received by the communication processing unit 11 are legitimate periodic messages received at timings based on the transmission cycle Cm during the period from reception time t1 to reception time t12.
  • Target messages M1 to M4, M6, M8, M10, M12, and target messages M5, M7, M9 which are fraudulent messages BM received at timings based on the transmission cycle Cm during the period from reception time t5 to reception time t13.
  • M11, and M13 that is, during the period from reception time t5 to reception time t13, valid periodic messages and invalid periodic messages alternately arrive at relay device 101.
  • FIG. 4 is a diagram illustrating an example of statistical values used for detection processing in the relay device according to the embodiment of the present disclosure.
  • the horizontal axis shows time
  • the vertical axis shows statistical values.
  • FIG. 4 shows statistical values T1 to T13 calculated by the calculation unit 12 based on the reception times t1 to t13 of the target messages M1 to M13 shown in FIG. 3.
  • the processing unit 14 determines that no abnormality has occurred in the network 201 during the period from reception time t1 to reception time t4.
  • the processing unit 14 determines that an abnormality has occurred in the network 201 at the reception time t9.
  • the processing unit 14 transmits alarm information indicating that an abnormality has occurred in the network 201 to a higher-level device outside the communication system 301 via the communication processing unit 11.
  • the host device is, for example, a device such as a server that receives alarm information and performs predetermined processing.
  • the threshold Thx can be arbitrarily set by the manufacturer of the network 201. For example, by setting the threshold value Thx to a smaller value, it can be determined that an abnormality has occurred in the network 201 earlier after the transmission of an unauthorized message in the network 201 has started.
  • FIG. 5 is a diagram illustrating another example of the distribution of target messages and reception times received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • FIG. 5 shows the distribution of reception times of target messages M1 to M9, which are legitimate periodic messages.
  • target messages M1 and M2 arrive at relay device 101 with a transmission cycle Cm, processing load on communication device 111, which is the source of target message M, and increase or concentration of traffic in network 201, etc. Due to this influence, the target message M3, which would normally arrive at the relay device 101 after the transmission period Cm from the reception time t2 of the target message M2, may be delayed.
  • the target message M arriving at the relay device 101 is likely to be delayed due to waiting for access rights of the communication device 111 that is the sender. .
  • the target message M arriving at the relay device 101 is likely to be delayed due to congestion in the other relay device.
  • target message M3 is delayed, for example, target messages M4 to M7 following target message M3 arrive at relay device 101 at very short intervals due to the delay of target message M3.
  • the phenomenon in which a plurality of target messages M arrive at the relay device 101 at short intervals will also be referred to as a burst phenomenon.
  • FIG. 6 is a diagram illustrating an example of statistical values used for detection processing in a relay device according to a comparative example of the embodiment of the present disclosure.
  • the horizontal axis shows time
  • the vertical axis shows statistical values.
  • FIG. 6 shows the statistical values T1 to T9 calculated by the calculation unit 12 based on the reception times t1 to t9 of the target messages M1 to M9 shown in FIG.
  • the reception interval x3 becomes a value larger than the average value ⁇ , so the calculated statistical value T3 increases. Furthermore, since the target messages M4 to M7 arrive at the relay device at very short intervals, the reception intervals x4 to x7 become values smaller than the average value ⁇ , so the calculated statistical values T4 to T7 gradually increase. do.
  • the relay device determines that an abnormality has occurred in the network 201 when the receiving interval x of the target message M becomes shorter due to a burst phenomenon even though no fraudulent message has arrived. .
  • a method can be considered in which the reception interval x of the target message M that arrived during the period in which the burst phenomenon occurs is excluded from the detection process.
  • this method if a fraudulent message arrives during a period when a burst phenomenon is occurring, the fraudulent message cannot be detected.
  • the relay device 101 solves the above problem with the following configuration.
  • the processing unit 14 detects a delayed message DEM, which is a target message M whose reception interval x is larger than the transmission cycle Cm by a predetermined value or more.
  • the processing unit 14 compares the reception interval x with a predetermined threshold ThD. By doing so, it is determined whether the target message M is a delayed message DEM such as the above-described target message M3.
  • the threshold ThD is a threshold used to detect the delayed message DEM, and is, for example, twice the transmission period Cm of the periodic message.
  • FIG. 7 is a diagram illustrating an example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • the processing unit 14 determines that the target message Mm is not a delayed message DEM. In this case, the processing unit 14 calculates the statistical value Tm of the reception interval xm. The processing unit 14 then compares the calculated statistical value Tm with the threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result.
  • FIG. 8 is a diagram illustrating another example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • the processing unit 14 determines that the target message Mm is a delayed message DEM. In this case, the processing unit 14 suspends calculation of the statistical value T of the reception interval x of the delayed message DEM until calculation time tB, which is the time when the threshold ThB is added to the reception time t of the delayed message DEM. That is, the processing unit 14 suspends calculation of the statistical value Tm of the reception interval xm until calculation time tBm, which is the time when the threshold ThB is added to the reception time tm of the target message Mm, which is the delayed message DEM. Then, the processing unit 14 waits for the calculation unit 12 to save the reception interval x(m+1) of the target message M(m+1) next to the target message Mm in the storage unit 15.
  • the threshold ThB is set in advance based on the IFG (InterFrame Gap) of the frame in which the message is stored.
  • the threshold ThB is a value obtained by adding a predetermined margin set based on fluctuations in frame transmission timing to the frame transmission time according to the minimum IFG.
  • the threshold ThB may be a value obtained by subtracting a predetermined value from the transmission cycle Cm.
  • the processing unit 14 When the processing unit 14 detects the delayed message DEM, it determines whether a burst phenomenon has occurred.
  • the processing unit 14 determines whether a burst phenomenon has occurred depending on whether a new target message M arrives at the relay device 101 by the calculation time tB for the delayed message DEM. do. Note that, if a new message other than the target message M arrives at the relay device 101 by the calculation time tB, the processing unit 14 updates the calculation time tB to a time obtained by adding the threshold ThB to the reception time of the new message. You may.
  • FIG. 9 is a diagram illustrating an example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • FIG. 9 shows the reception time t(m+1) of the target message M(m+1) received by the communication processing unit 11 after the reception time tm shown in FIG.
  • the processing unit 14 calculates the calculation time tBm for the target message Mm before the communication processing unit 11 receives the next target message M(m+1) of the target message Mm, which is the delayed message DEM. If it has arrived, it is determined that a burst phenomenon has not occurred. That is, if the calculation time tBm arrives before the reception interval x(m+1) and reception time t(m+1) of the target message M(m+1) are stored in the storage unit 15 by the calculation unit 12, the processing unit 14 calculates It is determined that no burst phenomenon has occurred.
  • the processing unit 14 cancels the above-mentioned suspension and calculates the statistical value Tm of the reception interval xm according to the above-mentioned equations (1) and (2).
  • the processing unit 14 compares the calculated statistical value Tm with the threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result.
  • FIG. 10 is a diagram illustrating another example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • FIG. 10 shows the reception time t(m+1) of the target message M(m+1) received by the communication processing unit 11 after the reception time tm shown in FIG.
  • the processing unit 14 receives the target message M(m+1) next to the target message Mm, which is the delayed message DEM, by the calculation time tBm for the target message Mm, the communication processing unit 11 , it is determined that a burst phenomenon has occurred at the reception time tm of the target message Mm. That is, if the receiving interval x(m+1) and the receiving time t(m+1) of the target message M(m+1) are stored in the storage unit 15 by the calculating unit 12 before the calculation time tBm arrives, the processing unit 14 calculates the following: It is determined that a burst phenomenon has occurred at the reception time tm of the target message Mm.
  • the processing unit 14 determines that a burst phenomenon has occurred at the reception time tm of the target message Mm, it outputs burst occurrence information including the reception time t(m+1) of the target message M(m+1) to the calculation unit 12.
  • the calculation unit 12 determines whether the burst phenomenon has ended based on the end determination time tE, which is the time when the target message M is received by the threshold ThB. Determine.
  • the calculation unit 12 calculates the target message M(m+q+1) by the end determination time tE(m+q+1) for the target message M(m+q+1). If the next target message M(m+q+2) is received by the communication processing unit 11, it is determined that the burst phenomenon continues. That is, the calculation unit 12 determines that if the communication processing unit 11 outputs a message CP including a timestamp indicating the reception time t(m+q+2) before the end determination time tE(m+q+1) arrives, the burst phenomenon continues. It is determined that the Here, q is a positive integer.
  • the calculation unit 12 calculates, before the communication processing unit 11 receives the next target message M(m+q+2) after the target message M(m+q+1).
  • the end determination time tE(m+q+1) for the target message M(m+q+1) arrives, it is determined that the burst phenomenon has ended. That is, if the end determination time tE(m+q+1) arrives before the communication processing unit 11 outputs the message CP including the time stamp indicating the reception time t(m+q+2), the calculation unit 12 determines that the burst phenomenon has ended. It is determined that If the calculation unit 12 determines that the burst phenomenon has ended, it outputs burst end information to the processing unit 14.
  • the calculation unit 12 sets the end determination time tE to a time obtained by adding the threshold ThB to the reception time of the new message. You may update to That is, every time the calculation unit 12 receives a message CP from the communication processing unit 11 after the reception time t(m+1) indicated by the burst occurrence information, the calculation unit 12 calculates the ID included in the message CP regardless of the ID included in the received message CP.
  • the end determination time tE is updated based on the timestamp received, and if the communication processing unit 11 does not output the next message CP by the time the end determination time tE arrives, it is determined that the burst phenomenon has ended. Good too.
  • the processing unit 14 counts a plurality of burst messages Mbst including the detected delayed message DEM and one or more target messages M whose reception interval x is equal to or less than the threshold ThB, which are received following the delayed message DEM. do. That is, the processing unit 14 processes a plurality of target messages M that are successively received by the communication processing unit 11, and the target message M that is the delayed message DEM and the reception interval x following the target message M are set as a threshold value. One or more target messages M whose value is less than or equal to ThB are counted as burst messages Mbst.
  • the processing unit 14 counts the burst messages Mbst, which are the target messages M received by the communication processing unit 11 during the period in which the burst phenomenon occurs.
  • the processing unit 14 determines that a burst phenomenon has occurred at the reception time tm of the target message Mm based on the comparison result between the reception interval x(m+1) and the threshold value ThB, the processing unit 14 determines that the target message Mm is It is determined that the target message M(m+1) is the first burst message Mbst and the second burst message Mbst, and "2", which is the count value CNT of the burst message Mbst, is held.
  • FIG. 11 is a diagram illustrating an example of the reception time of the target message received by the relay device according to the embodiment of the present disclosure.
  • the horizontal axis indicates time.
  • FIG. 11 shows reception times t of a plurality of target messages M received by the communication processing unit 11 after the reception time tm shown in FIG.
  • the processing unit 14 uses the calculation unit 12 to calculate the reception interval x(m+n) and reception time t(m+n) of the target message M(m+n) in the storage unit 15. Each time the count value CNT is saved, the count value CNT is incremented and updated.
  • n is an integer of 2 or more.
  • the processing unit 14 sets the count value CNT to “3”. ”.
  • the processing unit 14 sets the count value CNT to “N+1”. Update to.
  • the processing unit 14 ends counting if the next target message M is not received by the communication processing unit 11 within a predetermined time from the reception time t of the target message M, which is the burst message Mbst. More specifically, when the processing unit 14 receives burst end information from the calculation unit 12, it ends counting the burst messages Mbst.
  • the processing unit 14 determines whether to perform detection processing based on the reception interval x of the plurality of burst messages Mbst.
  • the processing unit 14 when the count value CNT is less than or equal to the threshold value ThC, the processing unit 14 does not perform the detection process based on the reception interval x of at least one of the plurality of burst messages Mbst. Specifically, when the count value CNT is equal to or less than the threshold value ThC, the processing unit 14 limits the use of the reception interval x of at least one burst message Mbst among the plurality of burst messages Mbst in the detection process. do. More specifically, when the processing unit 14 finishes counting the burst messages Mbst, it compares the count value CNT and the threshold value ThC. When the count value CNT is less than or equal to the threshold value ThC, the processing unit 14 discards all the reception intervals x of the burst messages Mbst without using them for the detection process.
  • the processing unit 14 determines the threshold ThC used for comparison with the count value CNT, depending on the reception interval x of the target message M, which is the delayed message DEM.
  • FIG. 12 is a diagram illustrating an example of a correspondence table stored in the storage unit in the relay device according to the embodiment of the present disclosure.
  • the storage unit 15 stores a correspondence table Tb1 showing the correspondence between the reception interval x of the delayed message DEM and the threshold value ThC.
  • the threshold value ThC is calculated from the reception time t of the target message M immediately before the delayed message DEM, assuming that the target message M arrives at the relay device 101 at a timing according to the transmission cycle Cm. It is set to a value that is the sum of the number of target messages M received by the communication processing unit 11 during the period up to reception time t of the delayed message DEM and a predetermined margin.
  • the processing unit 14 acquires the threshold ThC corresponding to the reception interval xm of the target message Mm determined to be the delayed message DEM from the correspondence table Tb1 in the storage unit 15. As an example, if the reception interval xm of the target message Mm determined to be the delayed message DEM is four times or more the transmission cycle Cm and less than five times the transmission cycle Cm, the processing unit 14 uses the threshold value Obtain "5" as ThC.
  • the processing unit 14 compares the acquired threshold ThC and the count value CNT, and if the count value CNT is less than or equal to the threshold ThC, the processing unit 14 selects the target message Mm which is the burst message Mbst. , M(m+1)..., M(m+N), the reception intervals xm, x(m+1)..., x(m+N) are discarded without being used in the detection process.
  • the processing unit 14 calculates the receiving interval xm without calculating the statistical values Tm, T(m+1)..., T(m+N) of the receiving interval xm, x(m+1)..., x(m+N). , x(m+1) . . . , x(m+N) are deleted from the storage unit 15.
  • the process of detecting the reception interval x of the burst messages Mbst is performed. By discarding the data without using it, it is possible to suppress false detections due to the occurrence of a burst phenomenon.
  • the processing unit 14 determines that a burst phenomenon has occurred, it suspends the detection process until it finishes counting the burst messages Mbst, and restarts the detection process after it finishes counting the burst messages Mbst.
  • the processing unit 14 receives the target message M(m+N). At time t(m+N), the burst phenomenon ends, and it is determined that the target message M(m+N+1) is not a delayed message DEM, and the statistical value T(m+N+1) of the reception interval x(m+N+1) is calculated. More specifically, the processing unit 14 uses the statistical value T(m-1) of the target message M(m-1) immediately before the burst message Mbst, instead of the statistical value T(m+N) of the reception interval x(m+N). The statistical value T(m+N+1) is calculated using the above equation (1).
  • the processing unit 14 compares the calculated statistical value T(m+N+1) with the threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result.
  • the processing unit 14 stores the reception interval x(m+N+2) of the target message M(m+N+2) in the storage unit 15 by the calculation unit 12, and if the reception interval x(m+N+2) is less than the threshold ThD, It is determined that the target message M(m+N+2) is not a delayed message DEM, and the statistical value T(m+N+2) of the reception interval x(m+N+2) is calculated.
  • the processing unit 14 compares the calculated statistical value T(m+N+2) with the threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result.
  • the processing unit 14 calculates the statistical value T(m+N+1) of the reception interval x(m+N+1) when it is determined that the burst phenomenon has ended at the reception time t(m+N) of the target message M(m+N). Instead, the reception interval x(m+N+1) may be deleted from the storage unit 15. In this case, the processing unit 14 waits for the calculation unit 12 to save the reception interval x(m+N+2) in the storage unit 15, and instead of the statistical value T(m+N+1) of the reception interval x(m+N+1), Using the statistical value T(m-1) of the target message M(m-1), the statistical value T(m+N+2) is calculated according to the above equation (1).
  • the processing unit 14 performs a detection process based on the reception interval x of the burst message Mbst.
  • the processing unit 14 compares the threshold ThC and the count value CNT, and if the count value CNT is larger than the threshold ThC, the processing unit 14 selects the target message Mm,M(m+1) which is the burst message Mbst. ..., M(m+N), receive interval xm, x(m+1)..., x(m+N) statistical values Tm, T(m+1)..., T(m+N) are calculated.
  • the processing unit 14 compares the calculated statistical values Tm, T(m+1)..., T(m+N) with the threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result. Determine whether or not there is one.
  • the processing unit 14 is configured to calculate the statistical value T of the reception interval x and perform the detection process based on the calculated statistical value T, the present invention is not limited to this.
  • the processing unit 14 may be configured to perform the detection process without calculating the statistical value T.
  • the processing unit 14 calculates a moving average value A of the reception interval x of the most recent p target messages M received by the communication processing unit 11, and performs the detection process based on the calculated moving average value A.
  • . p is an integer of 2 or more.
  • the moving average value A is an example of a detection index.
  • the processing unit 14 calculates the movement of the reception interval xm, x(m-1), x(m-2)..., x(m-p+1). Calculate the average value Am.
  • the reception intervals x(m-1), x(m-2), . . . , x(m-p+1) are examples of reference information regarding the target message M.
  • the reception intervals x(m-1), x(m-2), . . . , x(m-p+1) are also referred to as reference intervals rm.
  • the moving average value Am increases or decreases depending on the relationship between the reception interval xm of the target message Mm and the reference interval rm.
  • the moving average value A calculated by the processing unit 14 is calculated from reception time t5 to reception time t13. gradually decreases over the period of .
  • the processing unit 14 detects an abnormality in the network 201 based on the calculated moving average value A and a predetermined threshold Thy. More specifically, the processing unit 14 compares the calculated moving average value A and the threshold value Thy. If the moving average value A is equal to or greater than the threshold value Thy, the processing unit 14 determines that no abnormality has occurred in the network 201. On the other hand, if the moving average value A is less than the threshold value Thy, the processing unit 14 determines that an abnormality has occurred in the network 201.
  • the processing unit 14 discards the reception interval x of the burst message Mbst without using it for calculating the moving average value A. Then, when the reception interval x of the target message M received next to the burst message Mbst is equal to or greater than a predetermined value, the processing unit 14 selects the most recent p messages received by the communication processing unit 11, excluding the burst message Mbst. A moving average value A of the reception interval x of the target message M is calculated, and a detection process is performed based on the calculated moving average value A.
  • FIG. 13 is a flowchart defining an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs detection processing.
  • relay device 101 waits for the arrival of target message M (NO in step S102), and upon receiving target message M (YES in step S102), the reception interval x of the received target message M is is calculated (step S104).
  • the relay device 101 determines that the received target message M is not a delayed message DEM, and Detection processing is performed based on the More specifically, the relay device 101 calculates a statistical value T of the reception interval x, compares the calculated statistical value T with a threshold value Thx, and determines whether an abnormality has occurred in the network 201 based on the comparison result. Determine whether or not the If the relay device 101 determines in the detection process that an abnormality has occurred in the network 201, it transmits, for example, alarm information to a higher-level device outside the communication system 301 (step S108).
  • the relay device 101 waits for the arrival of a new target message M (NO in step S102).
  • the relay device 101 determines that the received target message M is a delayed message DEM, and determines whether a burst phenomenon has occurred. Determine whether More specifically, the relay device 101 waits for the arrival of the next target message M of the delayed message DEM or the arrival of the calculation time tB for the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM or the arrival of the calculation time tB for the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM or the arrival of the calculation time tB for the delayed message DEM, and waits for the arrival of the next target message M of the delayed message DEM. If the message M is received, it is determined that a burst phenomenon has occurred, and
  • the relay device 101 determines that a burst phenomenon has not occurred (YES in step S112), it performs a detection process. More specifically, the relay device 101 calculates the statistical value T of the reception interval x of the delayed message DEM and the statistical value T of the reception interval x of the next target message M of the delayed message DEM, and calculates each of the calculated statistical values T. and a threshold value Thx, and based on the comparison result, it is determined whether an abnormality has occurred in the network 201 (step S108).
  • the relay device 101 waits for the arrival of a new target message M (NO in step S102).
  • the relay device 101 determines that a burst phenomenon is occurring (NO in step S112), it counts the burst messages Mbst. More specifically, the relay device 101 waits for the arrival of a new target message M, and counts burst messages Mbst, which are target messages M received during the period in which the burst phenomenon occurs (step S114).
  • the relay device 101 performs a detection process based on the reception interval x of the burst message Mbst. More specifically, the relay device 101 calculates each statistical value T of the reception interval x of a plurality of burst messages Mbst, compares each calculated statistical value T with a threshold value Thx, and based on the comparison result, , it is determined whether an abnormality has occurred in the network 201 (step S108).
  • the relay device 101 waits for the arrival of a new target message M (NO in step S102).
  • the relay device 101 discards the reception interval x of the burst message Mbst (step S118).
  • the relay device 101 waits for the arrival of a new target message M (NO in step S102).
  • FIG. 14 is a flowchart defining an example of an operation procedure when the relay device according to the embodiment of the present disclosure performs a process of counting burst messages.
  • FIG. 14 shows details of step S114 in FIG. 13.
  • relay device 101 waits for the elapse of threshold value ThB from reception time t of burst message Mbst and reception of a new target message M (NO in step S302 and NO in step S304). ), if a new target message M is received before the threshold ThB has elapsed from the reception time t of the burst message Mbst (NO in step S302 and YES in step S304), the received target message M is the burst message Mbst. It is determined that there is, and the count value CNT is incremented and updated (step S306).
  • the burst phenomenon has ended. It is determined that the burst message Mbst is counted, and the counting of the burst messages Mbst is ended (step S308).
  • the relay device 101 is configured to detect an abnormality in the network 201, but the present invention is not limited to this.
  • a device different from the relay device 101 may function as a detection device and detect an abnormality in the network 201.
  • the communication system 301 includes a detection device connected to the relay device 101 via the transmission line 10.
  • the relay device 101 receives a message from the communication device 111, it transmits a mirror message, which is a copy of the received message, to the detection device via the transmission line 10.
  • the detection device calculates the reception interval x and performs detection processing based on the reception time at the relay device 101 of the mirror message received from the relay device 101.
  • the communication system 301 has a configuration in which the relay device 101 functioning as a detection device is directly connected to the transmission line 10, the present disclosure is not limited to this.
  • FIG. 15 is a diagram illustrating an example of a network connection topology according to an embodiment of the present disclosure.
  • a detection device 151 may be connected to transmission line 10 via communication device 111.
  • the detection device 151 detects an abnormality in the network 201, for example, by monitoring messages received by the communication device 111. More specifically, the communication device 111 outputs the received message to the detection device 151.
  • the detection device 151 includes a calculation section 12, a processing section 14, and a storage section 15.
  • the calculation unit 12 in the detection device 151 obtains the reception time t of the target message M received by the communication device 111, and calculates the reception interval x based on the obtained reception time t.
  • the storage unit 15 is configured to store the correspondence table Tb1, but the present invention is not limited to this.
  • FIG. 16 is a diagram showing another example of the correspondence table stored in the storage unit in the relay device according to the embodiment of the present disclosure.
  • the storage unit 15 stores a correspondence table Tb2 indicating the correspondence between the reception interval x of the delayed message DEM and the threshold value ThC. It may be a stored configuration.
  • the threshold value ThC is calculated from the reception time t of the target message M immediately before the delayed message DEM, assuming that the target message M arrives at the relay device 101 at a timing according to the transmission cycle Cm.
  • the storage unit 15 may have a configuration in which the correspondence tables Tb1 and Tb2 are not stored.
  • the processing unit 14 uses a predetermined calculation formula to calculate the threshold ThC based on the reception interval x and transmission cycle Cm of the target message M determined to be the delayed message DEM.
  • the processing unit 14 uses the reception interval x of all burst messages Mbst without using it for the detection process.
  • the configuration is described as being discarded, the present invention is not limited to this.
  • the processing unit 14 may be configured to discard the reception interval x of some burst messages Mbst while using the reception interval x of some other burst messages Mbst in the detection process.
  • the processing unit 14 uses the reception interval x of the delayed message DEM among the plurality of burst messages Mbst in the detection process, while discarding the reception interval x of one or more burst messages Mbst other than the delayed message DEM.
  • the processing unit 14 is configured to perform a detection process based on the reception interval x of the burst message Mbst when the count value CNT is larger than the threshold value ThC.
  • the processing unit 14 may be configured not to perform the detection process based on the reception interval x of the burst message Mbst when the count value CNT is larger than the threshold value ThC. For example, if the count value CNT is larger than the threshold ThC, the processing unit 14 determines that an abnormality has occurred in the network 201 without performing any detection processing.
  • the processing unit 14 determines the threshold value ThC used for comparison with the count value CNT according to the reception interval x of the target message M, which is the delayed message DEM.
  • the present invention is not limited to this configuration.
  • the processing unit 14 may be configured to use a predetermined threshold ThC for comparison with the count value CNT, regardless of the reception interval x of the target message M, which is the delayed message DEM.
  • the processing unit 14 when it is determined that a burst phenomenon has occurred, the processing unit 14 suspends the detection process until the count of the burst messages Mbst is finished, and counts the burst messages Mbst.
  • the processing unit 14 may perform the detection process after the fact based on the predetermined number of reception intervals x stored in the storage unit 15 by the calculation unit 12.
  • the processing unit 14 may be configured not to suspend or restart the detection process.
  • the processing unit 14 discards the reception interval x of the burst message Mbst, which is a part of the reception interval x stored in the storage unit 15, based on the comparison result between the count value CNT and the threshold value ThC. , the detection process is performed based on the remaining reception interval x.
  • the processing unit 14 is configured to receive burst end information from the calculation unit 12 and end counting of the burst messages Mbst; however, the present disclosure is not limited to this. It's not a thing.
  • the processing unit 14 may be configured to determine the end of the burst phenomenon based on the comparison result between the reception interval x and the threshold value ThB, and end the counting. More specifically, if the reception interval x(m+N+1) of the target message M(m+N+1) is larger than the threshold ThB, the processing unit 14 determines that a burst phenomenon occurs at the reception time t(m+N) of the target message M(m+N). It is determined that the burst message DM has ended, and the count of burst messages DM is ended.
  • the calculation unit 12 calculates the reception interval x of the target message M.
  • the processing unit 14 performs a detection process to detect an abnormality in the network 201 based on the reception interval x calculated by the calculation unit 12.
  • the processing unit 14 processes a delayed message DEM which is a target message M whose reception interval x is larger than the transmission cycle Cm by a predetermined value or more, and one or more messages whose reception interval x is equal to or less than a predetermined value and which is received following the delayed message DEM.
  • a plurality of burst messages Mbst including the target message M are counted. Based on the count value CNT of the burst messages Mbst, the processing unit 14 determines whether to perform detection processing based on the reception interval x for at least one of the plurality of burst messages Mbst.
  • the use of the reception interval x of the burst message Mbst in the detection process is restricted based on the count value CNT of the burst message Mbst.
  • a plurality of burst messages Mbst that are unlikely to include a fraudulent target message M can be excluded from detection processing targets, and false detection due to the occurrence of a burst phenomenon can be suppressed. Therefore, abnormalities in the network 201 can be detected more accurately.
  • Each process (each function) of the above-described embodiment is realized by a processing circuit (Circuitry) including one or more processors.
  • the processing circuit may include an integrated circuit or the like in which one or more memories, various analog circuits, and various digital circuits are combined.
  • the one or more memories store programs (instructions) that cause the one or more processors to execute each of the above processes.
  • the one or more processors may execute each of the above processes according to the program read from the one or more memories, or may execute each of the above processes according to a logic circuit designed in advance to execute each of the above processes. May be executed.
  • the above processors include a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), and an FPGA (Field Programming Unit). rammable Gate Array) and ASIC (Application Specific Integrated Circuit), etc., which are compatible with computer control. processor.
  • the plurality of physically separated processors may cooperate with each other to execute each of the above processes.
  • the processors installed in each of a plurality of physically separated computers cooperate with each other via networks such as a LAN (Local Area Network), a WAN (Wide Area Network), and the Internet to perform each of the above processes. May be executed.
  • the above program may be installed in the above memory from an external server device etc.
  • CD-ROM Compact Disc Read Only Memory
  • DVD-ROM Digital Versatile Disk Read Only Memory
  • semiconductors It may be distributed in a state stored in a recording medium such as a memory, and installed into the memory from the recording medium.
  • a detection device that detects an abnormality in a network in which a plurality of target messages including periodic messages that are transmitted and received at a predetermined transmission cycle are transmitted and received, a calculation unit that calculates the reception interval of the target message; a detection unit that performs a detection process to detect an abnormality in the network based on the reception interval calculated by the calculation unit; detecting the delayed message, which is the target message, the reception interval of which is greater than the transmission cycle by a predetermined value; and a counting unit that counts a plurality of burst messages including the target message, The detection unit determines whether or not to perform the detection process based on the reception interval for at least one of the plurality of burst messages based on the count value by the count unit, The detection unit discards the reception interval of the plurality of burst messages when the count value by the counting unit is less than or equal to the threshold value, and discards the reception interval of the plurality of burst messages when the count value is larger than
  • a detection device that detects an abnormality in a network in which a plurality of target messages including periodic messages that are transmitted and received at a predetermined transmission cycle are transmitted and received, Equipped with a processing circuit,
  • the processing circuit includes: Calculate the reception interval of the target message, Performing a detection process to detect an abnormality in the network based on the calculated reception interval, detecting the delayed message, which is the target message, the reception interval of which is greater than the transmission cycle by a predetermined value; counting a plurality of burst messages including the target message; The detection device determines, based on the count value, whether or not to perform the detection process based on the reception interval for at least one of the plurality of burst messages.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Environmental & Geological Engineering (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

検知装置は、対象メッセージの受信間隔を算出する算出部と、前記受信間隔に基づいて検知処理を行う検知部と、前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするカウント部とを備え、前記検知部は、前記カウント部によるカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する。

Description

検知装置および検知方法
 本開示は、検知装置および検知方法に関する。
 この出願は、2022年4月12日に出願された日本出願特願2022-65792号を基礎とする優先権を主張し、その開示のすべてをここに取り込む。
 特許文献1(国際公開第2021/111685号)には、以下のような検知装置が開示されている。すなわち、検知装置は、車載ネットワークにおける不正メッセージを検知する検知装置であって、前記車載ネットワークにおいて送信される周期メッセージの受信間隔の分布である対象分布を取得する取得部と、前記取得部によって取得された前記対象分布の一部を所定の基準に従って抽出する抽出部と、前記抽出部によって抽出された前記対象分布の一部に基づいて、前記不正メッセージを検知する検知処理を行う検知部とを備える。
国際公開第2021/111685号
 本開示の検知装置は、所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置であって、前記対象メッセージの受信間隔を算出する算出部と、前記算出部により算出された前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行う検知部と、前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするカウント部とを備え、前記検知部は、前記カウント部によるカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する。
 本開示の検知方法は、所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置における検知方法であって、前記対象メッセージの受信間隔を算出するステップと、算出した前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行うステップと、前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするステップとを含み、前記検知処理を行うステップにおいては、前記複数のバーストメッセージのカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する。
 本開示の一態様は、このような特徴的な処理部を備える検知装置として実現され得るだけでなく、かかる特徴的な処理のステップをコンピュータに実行させるためのプログラムとして実現され得たり、検知装置の一部または全部を実現する半導体集積回路として実現され得たり、検知装置を含むシステムとして実現され得る。
図1は、本開示の実施の形態に係る通信システムの構成を示す図である。 図2は、本開示の実施の形態に係る中継装置の構成を示す図である。 図3は、本開示の実施の形態に係る中継装置により受信される対象メッセージおよび受信時刻の分布の一例を示す図である。 図4は、本開示の実施の形態に係る中継装置において検知処理に用いられる統計値の一例を示す図である。 図5は、本開示の実施の形態に係る中継装置により受信される対象メッセージおよび受信時刻の分布の他の例を示す図である。 図6は、本開示の実施の形態の比較例に係る中継装置において検知処理に用いられる統計値の一例を示す図である。 図7は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。 図8は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の他の例を示す図である。 図9は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。 図10は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の他の例を示す図である。 図11は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。 図12は、本開示の実施の形態に係る中継装置における記憶部が記憶している対応テーブルの一例を示す図である。 図13は、本開示の実施の形態に係る中継装置が検知処理を行う際の動作手順の一例を定めたフローチャートである。 図14は、本開示の実施の形態に係る中継装置がバーストメッセージをカウントする処理を行う際の動作手順の一例を定めたフローチャートである。 図15は、本開示の実施の形態に係るネットワークの接続トポロジの一例を示す図である。 図16は、本開示の実施の形態に係る中継装置における記憶部が記憶している対応テーブルの他の例を示す図である。
 従来、ネットワークにおけるセキュリティを向上させるための技術が提案されている。
 [本開示が解決しようとする課題]
 特許文献1に記載の技術を超えて、ネットワークにおける異常をより正しく検知することが可能な技術が望まれる。
 本開示は、上述の課題を解決するためになされたもので、その目的は、ネットワークにおける異常をより正しく検知することが可能な検知装置および検知方法を提供することである。
 [本開示の効果]
 本開示によれば、ネットワークにおける異常をより正しく検知することができる。
 [本開示の実施形態の説明]
 最初に、本開示の実施形態の内容を列記して説明する。
 (1)本開示の実施の形態に係る検知装置は、所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置であって、前記対象メッセージの受信間隔を算出する算出部と、前記算出部により算出された前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行う検知部と、前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするカウント部とを備え、前記検知部は、前記カウント部によるカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する。
 このように、対象メッセージの受信間隔に基づいて検知処理を行う検知装置において、バーストメッセージのカウント値に基づいて、バーストメッセージの受信間隔に基づく検知処理を行うか否かを決定する構成により、複数のバーストメッセージに不正な対象メッセージが含まれている可能性の高さに応じて、複数のバーストメッセージを検知処理の対象とするか否かを決定することができるので、たとえば、バースト現象が発生したことによる誤検知を抑制しながら、複数のバーストメッセージに含まれる不正メッセージの見逃しを抑制することができる。したがって、ネットワークにおける異常をより正しく検知することができる。
 (2)上記(1)において、前記検知部は、前記カウント値がしきい値以下である場合、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージの前記受信間隔に基づく前記検知処理を行わなくてもよい。
 このような構成により、不正な対象メッセージが含まれている可能性が低い複数のバーストメッセージを検知処理の対象から除外し、バースト現象が発生したことによる誤検知を抑制することができる。
 (3)上記(1)または(2)において、前記検知部は、前記カウント値が前記しきい値よりも大きい場合、前記複数のバーストメッセージの前記受信間隔に基づいて前記検知処理を行ってもよい。
 このような構成により、不正な対象メッセージが含まれている可能性がある複数のバーストメッセージを検知処理の対象から除外することなく、当該複数のバーストメッセージの受信間隔に基づいて検知処理を行うことができるので、不正メッセージの見逃しを抑制することができる。
 (4)上記(1)から(3)のいずれかにおいて、前記検知部は、前記遅延メッセージである前記対象メッセージの前記受信間隔に応じて、前記しきい値を決定してもよい。
 このような構成により、遅延メッセージの遅延の程度に応じて決定したしきい値を用いて、バーストメッセージの受信間隔に基づく検知処理を行うか否かをより適切に判断することができる。
 (5)上記(1)から(4)のいずれかにおいて、前記検知部は、前記受信間隔と、前記受信間隔に関する参照情報との関係に応じて増減する検知指標を算出し、算出した前記検知指標に基づいて前記検知処理を行い、前記検知部は、前記カウント値が前記しきい値以下である場合、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについての前記検知指標の算出を行わない構成であってもよい。
 このような構成により、バースト現象が発生したことによる誤検知を抑制しながら、メッセージの受信間隔の、正常値からの逸脱度合いを示す検知指標に基づいて、ネットワークにおける異常をより正確に検知することができる。
 (6)上記(1)から(5)のいずれかにおいて、前記カウント部は、前記バーストメッセージである前記対象メッセージの受信時刻から所定時間以内に次の前記対象メッセージが受信されない場合、カウントを終了し、前記検知部は、前記カウント部によるカウントが終了するまで前記検知処理を保留し、前記カウント部によるカウントの終了後において前記検知処理を再開してもよい。
 このような構成により、バースト現象の終了に伴ってバーストメッセージのカウントを終了し、検知処理をより適切なタイミングで再開することができる。
 (7)本開示の実施の形態に係る検知方法は、所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置における検知方法であって、前記対象メッセージの受信間隔を算出するステップと、算出した前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行うステップと、前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするステップとを含み、前記検知処理を行うステップにおいては、前記複数のバーストメッセージのカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する。
 このように、対象メッセージの受信間隔に基づいて検知処理を行う検知装置において、バーストメッセージのカウント値に基づいて、バーストメッセージの受信間隔に基づく検知処理を行うか否かを決定する方法により、複数のバーストメッセージに不正な対象メッセージが含まれている可能性の高さに応じて、複数のバーストメッセージを検知処理の対象とするか否かを決定することができるので、たとえば、バースト現象が発生したことによる誤検知を抑制しながら、複数のバーストメッセージに含まれる不正メッセージの見逃しを抑制することができる。したがって、ネットワークにおける異常をより正しく検知することができる。
 以下、本開示の実施の形態について図面を用いて説明する。なお、図中同一または相当部分には同一符号を付してその説明は繰り返さない。また、以下に記載する実施の形態の少なくとも一部を任意に組み合わせてもよい。
 [構成および基本動作]
 図1は、本開示の実施の形態に係る通信システムの構成を示す図である。図1を参照して、通信システム301は、中継装置101と、複数の通信装置111とを備える。通信システム301は、たとえば車両に搭載される。この場合、通信装置111は、たとえば車載ECU(Electronic Control Unit)である。なお、通信システム301は、中継装置101以外の図示しない他の中継装置を備える構成であってもよい。
 中継装置101および通信装置111は、ネットワーク201を構成する。より詳細には、中継装置101および通信装置111は、伝送線10を介して互いに接続される。通信システム301は、中継装置101が、図1に示すようにライン型の伝送線10を介して通信装置111と1対1で接続されている構成であってもよいし、図示しない他の中継装置および伝送線10を介して通信装置111と接続されている構成であってもよいし、バス型の伝送線10を介して複数の通信装置111と1対多で接続されている構成であってもよい。伝送線10は、たとえば、CAN(Controller Area Network)(登録商標)、FlexRay(登録商標)、MOST(Media Oriented Systems Transport)(登録商標)、イーサネット(登録商標)、およびLIN(Local Interconnect Network)等の規格に従うケーブルである。
 中継装置101は、通信装置111と通信を行うことが可能である。中継装置101は、たとえば、異なる伝送線10に接続された複数の通信装置111間でやり取りされる情報を中継する中継処理を行う。
 ネットワーク201では、周期的に送信されるメッセージを含む複数のメッセージが送受信される。
 より詳細には、ネットワーク201では、たとえば、所定の取り決めに従って、通信装置111から他の通信装置111へ中継装置101経由で周期的にメッセージが送信される。以下、ネットワーク201において周期的に送信されるメッセージを、周期メッセージとも称する。なお、「周期メッセージ」とは、厳密に周期的に送信されたメッセージに限らず、周期的に送信されるべき種類のメッセージを意味するものとする。
 また、ネットワーク201では、周期メッセージの他に、通信装置111から他の通信装置111へ中継装置101経由で不定期に送信されるメッセージが存在する。以下、ネットワーク201において不定期に送信されるメッセージを、イベントメッセージとも称する。
 通信装置111によるメッセージの送信は、ブロードキャストによって行われてもよいし、ユニキャストによって行われてもよいし、マルチキャストによって行われてもよい。
 中継装置101は、検知装置として機能し、ネットワーク201における異常を検知する。
 〔中継装置〕
 図2は、本開示の実施の形態に係る中継装置の構成を示す図である。図2を参照して、中継装置101は、通信処理部11と、算出部12と、処理部14と、記憶部15と、複数の通信ポート16とを備える。処理部14は、カウント部の一例であり、かつ検知部の一例である。通信処理部11、算出部12および処理部14の一部または全部は、たとえば、1または複数のプロセッサを含む処理回路(Circuitry)により実現される。記憶部15は、たとえば上記処理回路に含まれるフラッシュメモリである。通信ポート16は、たとえばコネクタまたは端子である。各通信ポート16には、伝送線10が接続される。
 通信処理部11は、通信装置111間で伝送されるメッセージを中継する中継処理を行う。たとえば、通信処理部11は、通信装置111から対応の伝送線10および対応の通信ポート16経由でメッセージを受信すると、受信したメッセージの複製であるメッセージCPを生成し、生成したメッセージCPに、受信したメッセージの受信時刻を示すタイムスタンプを付与する。そして、通信処理部11は、受信したメッセージを他の通信装置111へ対応の通信ポート16および対応の伝送線10経由で送信し、タイムスタンプが付与されたメッセージCPを算出部12へ出力する。
 (受信間隔の算出)
 算出部12は、中継装置101における検知処理の対象となるメッセージである対象メッセージの受信間隔を算出する。中継装置101は、1つの通信装置111から送信される1種類のメッセージを対象として検知処理を行う構成であってもよいし、複数の通信装置111の各々から送信される複数種類のメッセージを対象として、メッセージの種類ごとに検知処理を行う構成であってもよい。以下では、中継装置101が、ある通信装置111から送信されるメッセージを「対象メッセージM」として検知処理を行う例について説明する。ネットワーク201において送信される複数の対象メッセージMには、所定の送信周期Cmに従って当該通信装置111から送信される周期メッセージが含まれる。
 より詳細には、算出部12は、通信処理部11によって中継されるメッセージのうちの対象メッセージMの受信時刻tを取得する。
 たとえば、記憶部15は、対象メッセージの種類ごとのIDを記憶している。以下、対象メッセージのIDを対象IDとも称し、対象メッセージMのIDを対象ID_Mとも称する。
 算出部12は、通信処理部11からメッセージCPを受けて、受けたメッセージCPに含まれるID、および記憶部15における対象IDを確認する。
 そして、算出部12は、通信処理部11から受けたメッセージCPに含まれるIDが対象ID_Mと一致する場合、当該メッセージCPの複製元のメッセージが対象メッセージMであると認識し、当該メッセージCPに付与されたタイムスタンプを参照することにより、対象メッセージMの受信時刻tを取得する。
 算出部12は、対象メッセージMの受信時刻tを取得すると、当該受信時刻tと、直前の対象メッセージMの受信時刻tとの差分を対象メッセージMの受信間隔xとして算出する。より詳細には、算出部12は、通信処理部11によって受信されたm番目の対象メッセージMmの受信時刻tmから、通信処理部11によって受信された(m-1)番目の対象メッセージM(m-1)の受信時刻t(m-1)を差し引くことにより、対象メッセージMmの受信間隔xmを算出する。ここで、mは正の整数である。算出部12は、算出した受信間隔xmおよび受信時刻tmを記憶部15に保存する。算出部12は、対象メッセージが複数存在する場合、対象メッセージごとに受信間隔xmおよび受信時刻tmを算出し、算出した受信間隔xmおよび受信時刻tmを対象IDごとに記憶部15に保存する。
 (検知処理)
 処理部14は、算出部12により算出された受信間隔xに基づいて、ネットワーク201における異常を検知する検知処理を行う。
 たとえば、処理部14は、算出部12により算出された受信間隔xの標準偏差σを用いて、受信間隔xの統計値Tを算出し、算出した統計値Tに基づいて検知処理を行う。統計値Tは、受信間隔xの、正常状態からの逸脱度合いを示す。統計値Tは、検知指標の一例である。
 より詳細には、処理部14は、算出部12により対象メッセージMmの受信間隔xmが記憶部15に保存されると、以下の式(1)に従って、対象メッセージMmの異常度Dmを算出する。
Figure JPOXMLDOC01-appb-M000001
 ここで、μは、受信間隔xの平均値であり、対象メッセージMに関する参照情報の一例である。標準偏差σおよび平均値μは、記憶部15に保存されている。たとえば、標準偏差σは、予め通信システム301の製造者により受信間隔xに基づいて算出され、記憶部15に保存される。また、たとえば、平均値μは、予め通信システム301の製造者により、ネットワーク201における対象メッセージMの送信周期Cmの設計値に基づいて算出される値であり、予め記憶部15に保存される。なお、処理部14は、定期的または不定期に、複数の対象メッセージMに対応する複数の受信間隔xに基づいて標準偏差σおよび平均値μを算出し、記憶部15における標準偏差σおよび平均値μを、算出した標準偏差σおよび平均値μに更新してもよい。
 処理部14は、対象メッセージMmの異常度Dmを算出すると、以下の式(2)に従って、対象メッセージMmの統計値Tmを算出する。
Figure JPOXMLDOC01-appb-M000002
 ここで、kは、制限パラメータである。制限パラメータkは、予め設定された定数である。式(2)に示すように、対象メッセージMmの統計値Tmは、対象メッセージM(m-1)の統計値T(m-1)と異常度Dmとの和から制限パラメータkを差し引いた値、およびゼロのうちの大きい方の値となる。
 式(1)および式(2)に示されるように、統計値Tmは、対象メッセージMmの受信間隔xmと、平均値μとの関係に応じて増減する。具体的には、受信間隔xmが平均値μから大きく乖離した値となることにより、異常度Dmが制限パラメータkよりも大きな値となった場合、対象メッセージMmの統計値Tmは、直前の対象メッセージM(m-1)の統計値T(m-1)よりも大きな値となる。一方、受信間隔xmが平均値μに近い値となることにより、異常度Dmが制限パラメータkよりも小さな値となった場合、対象メッセージMmの統計値Tmは、ゼロとなるか、または直前の対象メッセージM(m-1)の統計値T(m-1)よりも小さな値となる。
 処理部14は、算出した統計値Tに基づいて、ネットワーク201における異常を検知する検知処理を行う。たとえば、処理部14は、算出した統計値Tと、所定のしきい値Thxとに基づいて、ネットワーク201における異常を検知する。
 より詳細には、処理部14は、算出した統計値Tとしきい値Thxとを比較する。処理部14は、統計値Tがしきい値Thx以下である場合、ネットワーク201における異常は発生していないと判定する。一方、処理部14は、統計値Tがしきい値Thxよりも大きい場合、ネットワーク201における異常が発生していると判定する。
 図3は、本開示の実施の形態に係る中継装置により受信される対象メッセージおよび受信時刻の分布の一例を示す図である。図3において、横軸は時刻を示している。
 図3を参照して、通信処理部11により受信される複数の対象メッセージMは、受信時刻t1から受信時刻t12までの期間において、送信周期Cmに基づくタイミングで受信される正当な周期メッセージである対象メッセージM1~M4,M6,M8,M10,M12と、受信時刻t5から受信時刻t13までの期間において、たとえば送信周期Cmに基づくタイミングで受信される不正メッセージBMである対象メッセージM5,M7,M9,M11,M13とを含む。すなわち、受信時刻t5から受信時刻t13までの期間において、正当な周期メッセージと不正な周期メッセージとが、中継装置101へ交互に到来する。
 図4は、本開示の実施の形態に係る中継装置において検知処理に用いられる統計値の一例を示す図である。図4において、横軸は時刻を示しており、縦軸は統計値を示している。図4は、図3に示す対象メッセージM1~M13の受信時刻t1~t13に基づいて算出部12により算出される統計値T1~T13を示している。
 図4を参照して、受信時刻t1から受信時刻t4までの期間では、一定の送信周期Cmで送信される正当な対象メッセージM1~M4のみが通信処理部11により受信され、受信間隔x1~x4が平均値μとほぼ等しい値となるので、処理部14により算出される統計値T1~T4はゼロである。
 処理部14は、算出した統計値T1~T4がしきい値Thx以下であるので、受信時刻t1から受信時刻t4までの期間においてネットワーク201における異常は発生していないと判定する。
 一方、受信時刻t5から受信時刻t13までの期間では、送信周期Cmで送信される対象メッセージM6,M8,M10,M12に加えて、不正メッセージBMが通信処理部11により受信され、受信間隔x5~x13が平均値μから乖離した値となるので、処理部14により算出される統計値T5~T13は徐々に増加する。
 処理部14は、算出した統計値T9がしきい値Thxを超えるので、受信時刻t9においてネットワーク201における異常が発生したと判定する。処理部14は、ネットワーク201における異常が発生したと判定した場合、ネットワーク201における異常が発生したことを示す警報情報を通信処理部11経由で通信システム301外における上位装置へ送信する。上位装置は、たとえば、警報情報を受けて所定の処理を行うサーバ等の装置である。
 ここで、しきい値Thxは、ネットワーク201の製造者により任意に設定可能である。たとえば、しきい値Thxをより小さい値に設定することにより、ネットワーク201における不正メッセージの送信が開始された後、より早期に、ネットワーク201における異常が発生していると判定することができる。
 図5は、本開示の実施の形態に係る中継装置により受信される対象メッセージおよび受信時刻の分布の他の例を示す図である。図5において、横軸は時刻を示している。図5は、正当な周期メッセージである対象メッセージM1~M9の受信時刻の分布を示している。
 図5を参照して、対象メッセージM1,M2が送信周期Cmで中継装置101へ到来する一方で、対象メッセージMの送信元の通信装置111における処理負荷およびネットワーク201におけるトラフィックの増大または集中等の影響により、本来であれば対象メッセージM2の受信時刻t2から送信周期Cm後に中継装置101へ到来する対象メッセージM3が遅延する場合がある。特に、中継装置101が複数の通信装置111と1対多で接続されているネットワーク201では、送信元の通信装置111のアクセス権待ちにより、中継装置101へ到来する対象メッセージMの遅延が生じやすい。また、中継装置101が他の中継装置を介して通信装置111と接続されているネットワーク201では、当該他の中継装置における輻輳により、中継装置101へ到来する対象メッセージMの遅延が生じやすい。図5に示すように、対象メッセージM3が遅延した場合、たとえば、対象メッセージM3に続く対象メッセージM4~M7が、対象メッセージM3の遅延に伴って非常に短い間隔で中継装置101へ到来する。以下、複数の対象メッセージMが短い間隔で中継装置101へ到来する現象を、バースト現象とも称する。
 [課題]
 図6は、本開示の実施の形態の比較例に係る中継装置において検知処理に用いられる統計値の一例を示す図である。図6において、横軸は時刻を示しており、縦軸は統計値を示している。図6は、図5に示す対象メッセージM1~M9の受信時刻t1~t9に基づいて算出部12により算出される統計値T1~T9を示している。
 図6を参照して、対象メッセージM3が遅延することにより、受信間隔x3が平均値μよりも大きな値となるので、算出される統計値T3は増大する。また、対象メッセージM4~M7が非常に短い間隔で中継装置へ到来することにより、受信間隔x4~x7が平均値μよりも小さな値となるので、算出される統計値T4~7は徐々に増大する。
 比較例に係る中継装置では、たとえば統計値T5がしきい値Thxを超えるので、ネットワーク201における異常が発生したと判定する。すなわち、比較例に係る中継装置は、不正メッセージが到来していないにもかかわらず、バースト現象により対象メッセージMの受信間隔xが短くなった場合、ネットワーク201における異常が発生したと判定してしまう。
 このような誤検知を抑制するために、バースト現象が発生している期間中に到来した対象メッセージMの受信間隔xを検知処理の対象から除外する方法が考えられる。しかしながら、この方法では、バースト現象が発生している期間中に不正メッセージが到来した場合、当該不正メッセージを検知することができない。
 そこで、本開示の実施の形態に係る中継装置101は、以下のような構成により、上記の課題を解決する。
 (遅延メッセージDEMの検知)
 処理部14は、受信間隔xが送信周期Cmよりも所定値以上大きい対象メッセージMである遅延メッセージDEMを検知する。
 より詳細には、処理部14は、算出部12により対象メッセージMの受信間隔xおよび受信時刻tが記憶部15に保存されると、当該受信間隔xと、所定のしきい値ThDとを比較することにより、当該対象メッセージMがたとえば上述の対象メッセージM3のような遅延メッセージDEMであるか否かを判定する。しきい値ThDは、遅延メッセージDEMの検知に用いられるしきい値であり、たとえば周期メッセージの送信周期Cmの2倍である。
 図7は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。図7において、横軸は時刻を示している。
 図7を参照して、処理部14は、対象メッセージMmの受信間隔xmがしきい値ThD未満である場合、当該対象メッセージMmは遅延メッセージDEMではないと判定する。この場合、処理部14は、当該受信間隔xmの統計値Tmを算出する。そして、処理部14は、算出した統計値Tmと、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。
 図8は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の他の例を示す図である。図8において、横軸は時刻を示している。
 図8を参照して、処理部14は、対象メッセージMmの受信間隔xmがしきい値ThD以上である場合、当該対象メッセージMmは遅延メッセージDEMであると判定する。この場合、処理部14は、遅延メッセージDEMの受信時刻tにしきい値ThBを加えた時刻である算出時刻tBまで、遅延メッセージDEMの受信間隔xの統計値Tの算出を保留する。すなわち、処理部14は、遅延メッセージDEMである対象メッセージMmの受信時刻tmにしきい値ThBを加えた時刻である算出時刻tBmまで、受信間隔xmの統計値Tmの算出を保留する。そして、処理部14は、算出部12による、対象メッセージMmの次の対象メッセージM(m+1)の受信間隔x(m+1)の記憶部15への保存を待ち受ける。
 たとえば、しきい値ThBは、メッセージが格納されるフレームのIFG(InterFrame Gap)に基づいて予め設定される。好ましくは、しきい値ThBは、最小のIFGに応じたフレームの伝送時間に、フレームの送信タイミングのゆらぎに基づいて設定される所定のマージンを加えた値である。なお、しきい値ThBは、送信周期Cmから所定値を差し引いた値であってもよい。
 (バースト現象の判定)
 処理部14は、遅延メッセージDEMを検知した場合、バースト現象が発生したか否かを判定する。
 より詳細には、処理部14は、遅延メッセージDEMについての算出時刻tBまでに、新たな対象メッセージMが中継装置101へ到来するか否かに応じて、バースト現象が発生したか否かを判定する。なお、処理部14は、算出時刻tBまでに対象メッセージM以外の新たなメッセージが中継装置101へ到来した場合、算出時刻tBを当該新たなメッセージの受信時刻にしきい値ThBを加えた時刻に更新してもよい。
 図9は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。図9において、横軸は時刻を示している。図9は、図8に示す受信時刻tm以降において、通信処理部11により受信される対象メッセージM(m+1)の受信時刻t(m+1)を示している。
 図9を参照して、処理部14は、遅延メッセージDEMである対象メッセージMmの次の対象メッセージM(m+1)が通信処理部11により受信される前に、対象メッセージMmについての算出時刻tBmが到来した場合、バースト現象は発生していないと判定する。すなわち、処理部14は、対象メッセージM(m+1)の受信間隔x(m+1)および受信時刻t(m+1)が算出部12により記憶部15に保存される前に、算出時刻tBmが到来した場合、バースト現象は発生していないと判定する。この場合、処理部14は、上述の保留を解除し、上述の式(1)および式(2)に従って受信間隔xmの統計値Tmを算出する。そして、処理部14は、算出した統計値Tmと、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。
 図10は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の他の例を示す図である。図10において、横軸は時刻を示している。図10は、図8に示す受信時刻tm以降において、通信処理部11により受信される対象メッセージM(m+1)の受信時刻t(m+1)を示している。
 図10を参照して、処理部14は、対象メッセージMmについての算出時刻tBmまでに、遅延メッセージDEMである対象メッセージMmの次の対象メッセージM(m+1)が通信処理部11により受信された場合、対象メッセージMmの受信時刻tmにおいてバースト現象が発生したと判定する。すなわち、処理部14は、算出時刻tBmが到来する前に、対象メッセージM(m+1)の受信間隔x(m+1)および受信時刻t(m+1)が算出部12により記憶部15に保存された場合、対象メッセージMmの受信時刻tmにおいてバースト現象が発生したと判定する。
 処理部14は、対象メッセージMmの受信時刻tmにおいてバースト現象が発生したと判定すると、対象メッセージM(m+1)の受信時刻t(m+1)を含むバースト発生情報を算出部12へ出力する。
 算出部12は、処理部14からバースト発生情報を受けた場合、対象メッセージMの受信時刻tにしきい値ThBを加えた時刻である終了判定時刻tEに基づいて、バースト現象が終了したか否かを判定する。
 より詳細には、算出部12は、受けたバースト発生情報が示す受信時刻t(m+1)以降において、対象メッセージM(m+q+1)についての終了判定時刻tE(m+q+1)までに、対象メッセージM(m+q+1)の次の対象メッセージM(m+q+2)が通信処理部11により受信された場合、バースト現象が継続していると判定する。すなわち、算出部12は、終了判定時刻tE(m+q+1)が到来する前に、受信時刻t(m+q+2)を示すタイムスタンプを含むメッセージCPが通信処理部11により出力された場合、バースト現象が継続していると判定する。ここで、qは正の整数である。
 一方、算出部12は、受けたバースト発生情報が示す受信時刻t(m+1)以降において、対象メッセージM(m+q+1)の次の対象メッセージM(m+q+2)が通信処理部11により受信される前に、対象メッセージM(m+q+1)についての終了判定時刻tE(m+q+1)が到来した場合、バースト現象が終了したと判定する。すなわち、算出部12は、受信時刻t(m+q+2)を示すタイムスタンプを含むメッセージCPが通信処理部11により出力される前に、終了判定時刻tE(m+q+1)が到来した場合、バースト現象が終了したと判定する。算出部12は、バースト現象が終了したと判定した場合、バースト終了情報を処理部14へ出力する。
 なお、算出部12は、終了判定時刻tEまでに対象メッセージM以外の新たなメッセージが中継装置101へ到来した場合、終了判定時刻tEを当該新たなメッセージの受信時刻にしきい値ThBを加えた時刻に更新してもよい。すなわち、算出部12は、バースト発生情報が示す受信時刻t(m+1)以降において、通信処理部11からメッセージCPを受けるたびに、受けたメッセージCPに含まれるIDに関わらず、当該メッセージCPに含まれるタイムスタンプに基づいて終了判定時刻tEを更新し、終了判定時刻tEが到来するまでに、通信処理部11が次のメッセージCPを出力しない場合、バースト現象が終了したと判定する構成であってもよい。
 (バーストメッセージのカウント)
 処理部14は、検知した遅延メッセージDEMと、当該遅延メッセージDEMに続いて受信される受信間隔xがしきい値ThB以下の1または複数の対象メッセージMと、を含む複数のバーストメッセージMbstをカウントする。すなわち、処理部14は、通信処理部11により連続して受信される複数の対象メッセージMであって、遅延メッセージDEMである対象メッセージMと、当該対象メッセージMに続く受信間隔xがしきい値ThB以下である1または複数の対象メッセージMと、をバーストメッセージMbstとしてカウントする。
 たとえば、処理部14は、バースト現象が発生している期間において通信処理部11により受信された対象メッセージMであるバーストメッセージMbstをカウントする。
 より詳細には、処理部14は、受信間隔x(m+1)としきい値ThBとの比較結果に基づいて、対象メッセージMmの受信時刻tmにおいてバースト現象が発生したと判定した場合、対象メッセージMmが1つ目のバーストメッセージMbstであり、対象メッセージM(m+1)が2つ目のバーストメッセージMbstであると判断し、バーストメッセージMbstのカウント値CNTである「2」を保持する。
 図11は、本開示の実施の形態に係る中継装置により受信される対象メッセージの受信時刻の一例を示す図である。図11において、横軸は時刻を示している。図11は、図10に示す受信時刻tm以降において、通信処理部11により受信される複数の対象メッセージMの受信時刻tを示している。
 図11を参照して、処理部14は、バースト現象が発生したと判定した後、算出部12により対象メッセージM(m+n)の受信間隔x(m+n)および受信時刻t(m+n)が記憶部15に保存されるたびに、カウント値CNTをインクリメントして更新する。ここで、nは、2以上の整数である。
 より詳細には、処理部14は、算出部12により対象メッセージM(m+2)の受信間隔x(m+2)および受信時刻t(m+2)が記憶部15に保存されると、カウント値CNTを「3」に更新する。
 同様にして、処理部14は、算出部12により対象メッセージM(m+N)の受信間隔x(m+N)および受信時刻t(m+N)が記憶部15に保存されると、カウント値CNTを「N+1」に更新する。
 たとえば、処理部14は、バーストメッセージMbstである対象メッセージMの受信時刻tから所定時間以内に通信処理部11により次の対象メッセージMが受信されない場合、カウントを終了する。より詳細には、処理部14は、算出部12からバースト終了情報を受けた場合、バーストメッセージMbstのカウントを終了する。
 (バーストメッセージの受信間隔の使用制限)
 処理部14は、カウント値CNTに基づいて、複数のバーストメッセージMbstの受信間隔xに基づく検知処理を行うか否かを決定する。
 たとえば、処理部14は、カウント値CNTがしきい値ThC以下である場合、複数のバーストメッセージMbstのうちの少なくともいずれか1つのバーストメッセージMbstの受信間隔xに基づく検知処理を行わない。詳細には、処理部14は、カウント値CNTがしきい値ThC以下である場合、複数のバーストメッセージMbstのうちの少なくともいずれか1つのバーストメッセージMbstの受信間隔xの、検知処理における使用を制限する。より詳細には、処理部14は、バーストメッセージMbstのカウントを終了すると、カウント値CNTとしきい値ThCとを比較する。処理部14は、カウント値CNTがしきい値ThC以下である場合、すべてのバーストメッセージMbstの受信間隔xを、検知処理に用いることなく破棄する。
 たとえば、処理部14は、遅延メッセージDEMである対象メッセージMの受信間隔xに応じて、カウント値CNTとの比較に用いるしきい値ThCを決定する。
 図12は、本開示の実施の形態に係る中継装置における記憶部が記憶している対応テーブルの一例を示す図である。図12を参照して、記憶部15は、遅延メッセージDEMの受信間隔xと、しきい値ThCとの対応関係を示す対応テーブルTb1を記憶している。たとえば、対応テーブルTb1において、しきい値ThCは、対象メッセージMが送信周期Cmに従うタイミングで中継装置101へ到来したと仮定した場合において、遅延メッセージDEMの直前の対象メッセージMの受信時刻tから当該遅延メッセージDEMの受信時刻tまでの期間に通信処理部11により受信される対象メッセージMの数と、所定のマージンとを加算した値に設定される。
 たとえば、処理部14は、記憶部15における対応テーブルTb1から、遅延メッセージDEMであると判定した対象メッセージMmの受信間隔xmに対応するしきい値ThCを取得する。一例として、処理部14は、遅延メッセージDEMであると判定した対象メッセージMmの受信間隔xmが、送信周期Cmの4倍以上であり、かつ送信周期Cmの5倍未満である場合、しきい値ThCとして「5」を取得する。
 再び図11を参照して、処理部14は、取得したしきい値ThCと、カウント値CNTとを比較し、カウント値CNTがしきい値ThC以下である場合、バーストメッセージMbstである対象メッセージMm,M(m+1)・・・,M(m+N)の受信間隔xm,x(m+1)・・・,x(m+N)を、検知処理に用いることなく破棄する。
 より詳細には、カウント値CNTがしきい値ThC以下である場合、バーストメッセージMbstについての統計値Tの算出を行わない。すなわち、処理部14は、受信間隔xm,x(m+1)・・・,x(m+N)の統計値Tm,T(m+1)・・・,T(m+N)の算出を行うことなく、受信間隔xm,x(m+1)・・・,x(m+N)を記憶部15から消去する。
 カウント値CNTがしきい値ThC以下である場合、通信処理部11により受信された複数のバーストメッセージMbstに不正メッセージが含まれている可能性は低いので、バーストメッセージMbstの受信間隔xを検知処理に用いることなく破棄することにより、バースト現象が発生したことによる誤検知を抑制することができる。
 たとえば、処理部14は、バースト現象が発生したと判定した場合、バーストメッセージMbstのカウントを終了するまで検知処理を保留し、バーストメッセージMbstのカウントの終了後において検知処理を再開する。
 より詳細には、処理部14は、対象メッセージM(m+N+1)の受信間隔x(m+N+1)がしきい値ThBよりも大きく、かつしきい値ThD未満である場合、対象メッセージM(m+N)の受信時刻t(m+N)においてバースト現象が終了し、かつ当該対象メッセージM(m+N+1)は遅延メッセージDEMではないと判定し、受信間隔x(m+N+1)の統計値T(m+N+1)を算出する。より詳細には、処理部14は、受信間隔x(m+N)の統計値T(m+N)の代わりに、バーストメッセージMbstの直前の対象メッセージM(m-1)の統計値T(m-1)を用いて、上述した式(1)に従って統計値T(m+N+1)を算出する。
 そして、処理部14は、算出した統計値T(m+N+1)と、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。
 次に、処理部14は、算出部12により対象メッセージM(m+N+2)の受信間隔x(m+N+2)が記憶部15に保存され、受信間隔x(m+N+2)がしきい値ThD未満である場合、当該対象メッセージM(m+N+2)は遅延メッセージDEMではないと判定し、受信間隔x(m+N+2)の統計値T(m+N+2)を算出する。
 そして、処理部14は、算出した統計値T(m+N+2)と、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。
 なお、処理部14は、対象メッセージM(m+N)の受信時刻t(m+N)においてバースト現象が終了したと判定した場合において、受信間隔x(m+N+1)の統計値T(m+N+1)の算出を行うことなく、受信間隔x(m+N+1)を記憶部15から消去してもよい。この場合、処理部14は、算出部12による受信間隔x(m+N+2)の記憶部15への保存を待ち受け、受信間隔x(m+N+1)の統計値T(m+N+1)の代わりに、バーストメッセージMbstの直前の対象メッセージM(m-1)の統計値T(m-1)を用いて、上述した式(1)に従って統計値T(m+N+2)を算出する。
 (バーストメッセージの受信間隔を用いた検知処理)
 処理部14は、カウント値CNTがしきい値ThCよりも大きい場合、バーストメッセージMbstの受信間隔xに基づいて検知処理を行う。
 より詳細には、処理部14は、しきい値ThCと、カウント値CNTとを比較し、カウント値CNTがしきい値ThCよりも大きい場合、バーストメッセージMbstである対象メッセージMm,M(m+1)・・・,M(m+N)の受信間隔xm,x(m+1)・・・,x(m+N)の統計値Tm,T(m+1)・・・,T(m+N)を算出する。
 そして、処理部14は、算出した統計値Tm,T(m+1)・・・,T(m+N)と、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。
 カウント値CNTがしきい値ThCよりも大きい場合、通信処理部11により受信された複数のバーストメッセージMbstに不正メッセージが含まれている可能性があるので、バーストメッセージMbstの受信間隔xに基づいて通常通り検知処理を行うことにより、不正メッセージの見逃しを抑制することができる。
 <変形例>
 処理部14は、受信間隔xの統計値Tを算出し、算出した統計値Tに基づいて検知処理を行う構成であるとしたが、これに限定するものではない。処理部14は、統計値Tを算出することなく検知処理を行う構成であってもよい。一例として、処理部14は、通信処理部11により受信された直近のp個の対象メッセージMの受信間隔xの移動平均値Aを算出し、算出した移動平均値Aに基づいて検知処理を行う。pは、2以上の整数である。移動平均値Aは、検知指標の一例である。
 より詳細には、処理部14は、対象メッセージMmの受信間隔xmを算出すると、受信間隔xm,x(m-1),x(m-2)・・・,x(m-p+1)の移動平均値Amを算出する。ここで、受信間隔x(m-1),x(m-2)・・・,x(m-p+1)は、対象メッセージMに関する参照情報の一例である。以下、受信間隔x(m-1),x(m-2)・・・,x(m-p+1)を、参照間隔rmとも称する。移動平均値Amは、対象メッセージMmの受信間隔xmと、参照間隔rmとの関係に応じて増減する。
 たとえば、処理部14により算出される移動平均値Aは、図3に示すように通信処理部11により受信される複数の対象メッセージMが不正メッセージBMを含む場合、受信時刻t5から受信時刻t13までの期間において徐々に減少する。
 処理部14は、算出した移動平均値Aと、所定のしきい値Thyとに基づいて、ネットワーク201における異常を検知する。より詳細には、処理部14は、算出した移動平均値Aとしきい値Thyとを比較する。処理部14は、移動平均値Aがしきい値Thy以上である場合、ネットワーク201における異常は発生していないと判定する。一方、処理部14は、移動平均値Aがしきい値Thy未満である場合、ネットワーク201における異常が発生していると判定する。
 処理部14は、バーストメッセージMbstのカウント値CNTがしきい値ThC以下である場合、バーストメッセージMbstの受信間隔xを、移動平均値Aの算出に用いることなく破棄する。そして、処理部14は、バーストメッセージMbstの次に受信された対象メッセージMの受信間隔xが所定値以上である場合、バーストメッセージMbstを除く、通信処理部11により受信された直近のp個の対象メッセージMの受信間隔xの移動平均値Aを算出し、算出した移動平均値Aに基づいて検知処理を行う。
 [動作の流れ]
 図13は、本開示の実施の形態に係る中継装置が検知処理を行う際の動作手順の一例を定めたフローチャートである。
 図13を参照して、まず、中継装置101は、対象メッセージMの到来を待ち受け(ステップS102でNO)、対象メッセージMを受信すると(ステップS102でYES)、受信した対象メッセージMの受信間隔xを算出する(ステップS104)。
 次に、中継装置101は、算出した受信間隔xがしきい値ThD未満である場合(ステップS106でYES)、受信した対象メッセージMは遅延メッセージDEMではないと判定し、算出した受信間隔xに基づいて検知処理を行う。より詳細には、中継装置101は、受信間隔xの統計値Tを算出し、算出した統計値Tと、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する。中継装置101は、検知処理において、ネットワーク201における異常が発生したと判定した場合、たとえば、警報情報を通信システム301外における上位装置へ送信する(ステップS108)。
 次に、中継装置101は、新たな対象メッセージMの到来を待ち受ける(ステップS102でNO)。
 一方、中継装置101は、算出した受信間隔xがしきい値ThD以上である場合(ステップS106でNO)、受信した対象メッセージMは遅延メッセージDEMであると判定し、バースト現象が発生したか否かを判定する。より詳細には、中継装置101は、遅延メッセージDEMの次の対象メッセージMの到来または遅延メッセージDEMについての算出時刻tBの到来を待ち受け、算出時刻tBが到来する前に遅延メッセージDEMの次の対象メッセージMを受信した場合、バースト現象が発生したと判定し、遅延メッセージDEMの次の対象メッセージMが到来する前に算出時刻tBが到来した場合、バースト現象が発生していないと判定する(ステップS110)。
 次に、中継装置101は、バースト現象が発生していないと判定した場合(ステップS112でYES)、検知処理を行う。より詳細には、中継装置101は、遅延メッセージDEMの受信間隔xの統計値T、および遅延メッセージDEMの次の対象メッセージMの受信間隔xの統計値Tを算出し、算出した各統計値Tと、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する(ステップS108)。
 次に、中継装置101は、新たな対象メッセージMの到来を待ち受ける(ステップS102でNO)。
 一方、中継装置101は、バースト現象が発生していると判定した場合(ステップS112でNO)、バーストメッセージMbstをカウントする。より詳細には、中継装置101は、新たな対象メッセージMの到来を待ち受け、バースト現象が発生している期間において受信した対象メッセージMであるバーストメッセージMbstをカウントする(ステップS114)。
 次に、中継装置101は、バーストメッセージMbstのカウント値CNTがしきい値ThCよりも大きい場合(ステップS116でYES)、バーストメッセージMbstの受信間隔xに基づいて検知処理を行う。より詳細には、中継装置101は、複数のバーストメッセージMbstの受信間隔xの統計値Tをそれぞれ算出し、算出した各統計値Tと、しきい値Thxとを比較し、比較結果に基づいて、ネットワーク201における異常が発生しているか否を判定する(ステップS108)。
 次に、中継装置101は、新たな対象メッセージMの到来を待ち受ける(ステップS102でNO)。
 一方、中継装置101は、バーストメッセージMbstのカウント値CNTがしきい値ThC以下である場合(ステップS116でNO)、バーストメッセージMbstの受信間隔xを破棄する(ステップS118)。
 次に、中継装置101は、新たな対象メッセージMの到来を待ち受ける(ステップS102でNO)。
 図14は、本開示の実施の形態に係る中継装置がバーストメッセージをカウントする処理を行う際の動作手順の一例を定めたフローチャートである。図14は、図13におけるステップS114の詳細を示している。
 図14を参照して、まず、中継装置101は、バーストメッセージMbstの受信時刻tからのしきい値ThBの経過、および新たな対象メッセージMの受信を待ち受け(ステップS302でNOかつステップS304でNO)、バーストメッセージMbstの受信時刻tからしきい値ThBが経過するまでに新たな対象メッセージMを受信した場合(ステップS302でNOかつステップS304でYES)、受信した対象メッセージMはバーストメッセージMbstであると判断し、カウント値CNTをインクリメントして更新する(ステップS306)。
 一方、中継装置101は、新たな対象メッセージMを受信するまでにバーストメッセージMbstの受信時刻tからしきい値ThBが経過した場合(ステップS302でYESかつステップS304でNO)、バースト現象が終了したと判定し、バーストメッセージMbstのカウントを終了する(ステップS308)。
 なお、本開示の実施の形態に係る通信システム301では、中継装置101が、ネットワーク201における異常を検知する構成であるとしたが、これに限定するものではない。通信システム301では、中継装置101とは別の装置が、検知装置として機能し、ネットワーク201における異常を検知する構成であってもよい。たとえば、通信システム301は、伝送線10を介して中継装置101に接続された検知装置を備える。中継装置101は、通信装置111からメッセージを受信すると、受信したメッセージの複製であるミラーメッセージを伝送線10経由で当該検知装置へ送信する。当該検知装置は、中継装置101から受信したミラーメッセージの中継装置101における受信時刻に基づいて、受信間隔xの算出および検知処理を行う。
 また、本開示の実施の形態に係る通信システム301では、検知装置として機能する中継装置101が伝送線10に直接接続される構成であるとしたが、これに限定するものではない。
 図15は、本開示の実施の形態に係るネットワークの接続トポロジの一例を示す図である。図15を参照して、検知装置151が、通信装置111を介して伝送線10に接続される構成であってもよい。この場合、検知装置151は、たとえば、当該通信装置111が受信するメッセージを監視することにより、ネットワーク201における異常を検知する。より詳細には、当該通信装置111は、受信したメッセージを検知装置151へ出力する。検知装置151は、算出部12、処理部14および記憶部15を備える。検知装置151における算出部12は、通信装置111により受信された対象メッセージMの受信時刻tを取得し、取得した受信時刻tに基づいて受信間隔xを算出する。
 また、本開示の実施の形態に係る中継装置101では、記憶部15は、対応テーブルTb1を記憶している構成であるとしたが、これに限定するものではない。
 図16は、本開示の実施の形態に係る中継装置における記憶部が記憶している対応テーブルの他の例を示す図である。図16を参照して、記憶部15は、対応テーブルTb1の代わりに、または対応テーブルTb1に加えて、遅延メッセージDEMの受信間隔xと、しきい値ThCとの対応関係を示す対応テーブルTb2を記憶している構成であってもよい。たとえば、対応テーブルTb2において、しきい値ThCは、対象メッセージMが送信周期Cmに従うタイミングで中継装置101へ到来したと仮定した場合において、遅延メッセージDEMの直前の対象メッセージMの受信時刻tから当該遅延メッセージDEMの受信時刻tまでの期間に通信処理部11により受信される対象メッセージMの数と、当該期間におけるイベントの発生頻度に基づいて通信処理部11により受信されると推測されるイベントメッセージの数と、所定のマージンとを加算した値に設定される。
 記憶部15は、対応テーブルTb1,Tb2を記憶していない構成であってもよい。この場合、たとえば、処理部14は、所定の計算式を用いて、遅延メッセージDEMであると判定した対象メッセージMの受信間隔xおよび送信周期Cmに基づくしきい値ThCを算出する。
 また、本開示の実施の形態に係る中継装置101では、処理部14は、カウント値CNTがしきい値ThC以下である場合、すべてのバーストメッセージMbstの受信間隔xを、検知処理に用いることなく破棄する構成であるとしたが、これに限定するものではない。処理部14は、一部のバーストメッセージMbstの受信間隔xを破棄する一方で、他の一部のバーストメッセージMbstの受信間隔xを検知処理に用いる構成であってもよい。たとえば、処理部14は、複数のバーストメッセージMbstのうちの遅延メッセージDEMの受信間隔xを検知処理に用いる一方で、遅延メッセージDEMを除く1または複数のバーストメッセージMbstの受信間隔xを破棄する。
 また、本開示の実施の形態に係る中継装置101では、処理部14は、カウント値CNTがしきい値ThCよりも大きい場合、バーストメッセージMbstの受信間隔xに基づいて検知処理を行う構成であるとしたが、これに限定するものではない。処理部14は、カウント値CNTがしきい値ThCよりも大きい場合、バーストメッセージMbstの受信間隔xに基づく検知処理を行わない構成であってもよい。たとえば、処理部14は、カウント値CNTがしきい値ThCよりも大きい場合、検知処理を行うことなく、ネットワーク201における異常が発生していると判定する。
 また、本開示の実施の形態に係る中継装置101では、処理部14は、遅延メッセージDEMである対象メッセージMの受信間隔xに応じて、カウント値CNTとの比較に用いるしきい値ThCを決定する構成であるとしたが、これに限定するものではない。処理部14は、遅延メッセージDEMである対象メッセージMの受信間隔xに関わらず、予め定められたしきい値ThCをカウント値CNTとの比較に用いる構成であってもよい。
 また、本開示の実施の形態に係る中継装置101では、処理部14は、バースト現象が発生したと判定した場合、バーストメッセージMbstのカウントを終了するまで検知処理を保留し、バーストメッセージMbstのカウントの終了後において検知処理を再開する構成であるとしたが、これに限定するものではない。処理部14は、算出部12により記憶部15に蓄積された所定数の受信間隔xに基づいて、事後的に検知処理を行ってもよい。処理部14は、事後的に検知処理を行う場合、検知処理の保留および再開を行わない構成であってもよい。より詳細には、処理部14は、カウント値CNTとしきい値ThCとの比較結果に基づいて、記憶部15に蓄積された受信間隔xの一部であるバーストメッセージMbstの受信間隔xを破棄し、残りの受信間隔xに基づいて検知処理を行う。
 また、本開示の実施の形態に係る中継装置101では、処理部14は、算出部12からバースト終了情報を受けて、バーストメッセージMbstのカウントを終了する構成であるとしたが、これに限定するものではない。処理部14は、受信間隔xとしきい値ThBとの比較結果に基づいて、バースト現象の終了を判定し、カウントを終了する構成であってもよい。より詳細には、処理部14は、対象メッセージM(m+N+1)の受信間隔x(m+N+1)がしきい値ThBよりも大きい場合、対象メッセージM(m+N)の受信時刻t(m+N)においてバースト現象が終了したと判定し、バーストメッセージDMのカウントを終了する。
 ところで、ネットワークにおける異常をより正しく検知することが可能な技術が望まれる。
 これに対して、本開示の実施の形態に係る中継装置101では、算出部12は、対象メッセージMの受信間隔xを算出する。処理部14は、算出部12により算出された受信間隔xに基づいて、ネットワーク201における異常を検知する検知処理を行う。処理部14は、受信間隔xが送信周期Cmよりも所定値以上大きい対象メッセージMである遅延メッセージDEMと、遅延メッセージDEMに続いて受信される、受信間隔xが所定値以下の1または複数の対象メッセージMと、を含む複数のバーストメッセージMbstをカウントする。処理部14は、バーストメッセージMbstのカウント値CNTに基づいて、複数のバーストメッセージMbstのうちの少なくともいずれか1つのバーストメッセージMbstについて、受信間隔xに基づく検知処理を行うか否かを決定する。
 このように、対象メッセージMの受信間隔xに基づいて検知処理を行う中継装置101において、バーストメッセージMbstのカウント値CNTに基づいて、バーストメッセージMbstの受信間隔xの、検知処理における使用を制限する構成により、たとえば不正な対象メッセージMが含まれている可能性が低い複数のバーストメッセージMbstを検知処理の対象から除外し、バースト現象が発生したことによる誤検知を抑制することができる。したがって、ネットワーク201における異常をより正しく検知することができる。
 上記実施の形態は、すべての点で例示であって制限的なものではないと考えられるべきである。本発明の範囲は、上記説明ではなく請求の範囲によって示され、請求の範囲と均等の意味および範囲内でのすべての変更が含まれることが意図される。
 上述の実施形態の各処理(各機能)は、1または複数のプロセッサを含む処理回路(Circuitry)により実現される。上記処理回路は、上記1または複数のプロセッサに加え、1または複数のメモリ、各種アナログ回路、各種デジタル回路が組み合わされた集積回路等で構成されてもよい。上記1または複数のメモリは、上記各処理を上記1または複数のプロセッサに実行させるプログラム(命令)を格納する。上記1または複数のプロセッサは、上記1または複数のメモリから読み出した上記プログラムに従い上記各処理を実行してもよいし、予め上記各処理を実行するように設計された論理回路に従って上記各処理を実行してもよい。上記プロセッサは、CPU(Central Processing Unit)、GPU(Graphics Processing Unit)、DSP(Digital Signal Processor)、FPGA(Field Programmable Gate Array)、およびASIC(Application Specific Integrated Circuit)等、コンピュータの制御に適合する種々のプロセッサであってよい。なお、物理的に分離した上記複数のプロセッサが互いに協働して上記各処理を実行してもよい。たとえば、物理的に分離した複数のコンピュータのそれぞれに搭載された上記プロセッサがLAN(Local Area Network)、WAN (Wide Area Network)、およびインターネット等のネットワークを介して互いに協働して上記各処理を実行してもよい。上記プログラムは、外部のサーバ装置等から上記ネットワークを介して上記メモリにインストールされても構わないし、CD-ROM(Compact Disc Read Only Memory)、DVD-ROM(Digital Versatile Disk Read Only Memory)、および半導体メモリ等の記録媒体に格納された状態で流通し、上記記録媒体から上記メモリにインストールされても構わない。
 以上の説明は、以下に付記する特徴を含む。
 [付記1]
 所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置であって、
 前記対象メッセージの受信間隔を算出する算出部と、
 前記算出部により算出された前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行う検知部と、
 前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージを検知し、前記遅延メッセージと、前記遅延メッセージに続いて受信される前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするカウント部とを備え、
 前記検知部は、前記カウント部によるカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定し、
 前記検知部は、前記カウント部によるカウント値がしきい値以下である場合、前記複数のバーストメッセージの前記受信間隔を破棄し、前記カウント値が前記しきい値よりも大きい場合、前記複数のバーストメッセージの前記受信間隔に基づいて前記検知処理を行う、検知装置。
 [付記2]
 所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置であって、
 処理回路を備え、
 前記処理回路は、
 前記対象メッセージの受信間隔を算出し、
 算出した前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行い、
 前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージを検知し、前記遅延メッセージと、前記遅延メッセージに続いて受信される前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントし、
 前記カウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する、検知装置。
 10 伝送線
 11 通信処理部
 12 算出部
 14 処理部(カウント部、検知部)
 15 記憶部
 16 通信ポート
 101 中継装置
 111 通信装置
 151 検知装置
 201 ネットワーク
 301 通信システム
 Tb1,Tb2 対応テーブル

Claims (7)

  1.  所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置であって、
     前記対象メッセージの受信間隔を算出する算出部と、
     前記算出部により算出された前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行う検知部と、
     前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするカウント部とを備え、
     前記検知部は、前記カウント部によるカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する、検知装置。
  2.  前記検知部は、前記カウント値がしきい値以下である場合、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージの前記受信間隔に基づく前記検知処理を行わない、請求項1に記載の検知装置。
  3.  前記検知部は、前記カウント値が前記しきい値よりも大きい場合、前記複数のバーストメッセージの前記受信間隔に基づいて前記検知処理を行う、請求項1または請求項2に記載の検知装置。
  4.  前記検知部は、前記遅延メッセージである前記対象メッセージの前記受信間隔に応じて、前記しきい値を決定する、請求項1から請求項3のいずれか1項に記載の検知装置。
  5.  前記検知部は、前記受信間隔と、前記受信間隔に関する参照情報との関係に応じて増減する検知指標を算出し、算出した前記検知指標に基づいて前記検知処理を行い、
     前記検知部は、前記カウント値が前記しきい値以下である場合、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについての前記検知指標の算出を行わない、請求項1から請求項4のいずれか1項に記載の検知装置。
  6.  前記カウント部は、前記バーストメッセージである前記対象メッセージの受信時刻から所定時間以内に次の前記対象メッセージが受信されない場合、カウントを終了し、
     前記検知部は、前記カウント部によるカウントが終了するまで前記検知処理を保留し、前記カウント部によるカウントの終了後において前記検知処理を再開する、請求項1から請求項5のいずれか1項に記載の検知装置。
  7.  所定の送信周期で送受信される周期メッセージを含む複数の対象メッセージが送受信されるネットワーク、における異常を検知する検知装置における検知方法であって、
     前記対象メッセージの受信間隔を算出するステップと、
     算出した前記受信間隔に基づいて、前記ネットワークにおける異常を検知する検知処理を行うステップと、
     前記受信間隔が前記送信周期よりも所定値以上大きい前記対象メッセージである遅延メッセージと、前記遅延メッセージに続いて受信される、前記受信間隔が所定値以下の1または複数の前記対象メッセージと、を含む複数のバーストメッセージをカウントするステップとを含み、
     前記検知処理を行うステップにおいては、前記複数のバーストメッセージのカウント値に基づいて、前記複数のバーストメッセージのうちの少なくともいずれか1つの前記バーストメッセージについて、前記受信間隔に基づく前記検知処理を行うか否かを決定する、検知方法。
PCT/JP2022/046331 2022-04-12 2022-12-16 検知装置および検知方法 Ceased WO2023199552A1 (ja)

Priority Applications (3)

Application Number Priority Date Filing Date Title
US18/855,390 US20250337673A1 (en) 2022-04-12 2022-12-16 Detection device and detection method
JP2024514802A JPWO2023199552A1 (ja) 2022-04-12 2022-12-16
CN202280090009.9A CN118592018A (zh) 2022-04-12 2022-12-16 检测装置及检测方法

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2022065792 2022-04-12
JP2022-065792 2022-04-12

Publications (1)

Publication Number Publication Date
WO2023199552A1 true WO2023199552A1 (ja) 2023-10-19

Family

ID=88329547

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2022/046331 Ceased WO2023199552A1 (ja) 2022-04-12 2022-12-16 検知装置および検知方法

Country Status (4)

Country Link
US (1) US20250337673A1 (ja)
JP (1) JPWO2023199552A1 (ja)
CN (1) CN118592018A (ja)
WO (1) WO2023199552A1 (ja)

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014187445A (ja) * 2013-03-22 2014-10-02 Toyota Motor Corp ネットワーク監視装置及びネットワーク監視方法
WO2017104112A1 (ja) * 2015-12-16 2017-06-22 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ セキュリティ処理方法及びサーバ
WO2021065068A1 (ja) * 2019-09-30 2021-04-08 株式会社オートネットワーク技術研究所 検知装置、車両、検知方法および検知プログラム

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014187445A (ja) * 2013-03-22 2014-10-02 Toyota Motor Corp ネットワーク監視装置及びネットワーク監視方法
WO2017104112A1 (ja) * 2015-12-16 2017-06-22 パナソニック インテレクチュアル プロパティ コーポレーション オブ アメリカ セキュリティ処理方法及びサーバ
WO2021065068A1 (ja) * 2019-09-30 2021-04-08 株式会社オートネットワーク技術研究所 検知装置、車両、検知方法および検知プログラム

Also Published As

Publication number Publication date
JPWO2023199552A1 (ja) 2023-10-19
CN118592018A (zh) 2024-09-03
US20250337673A1 (en) 2025-10-30

Similar Documents

Publication Publication Date Title
US11863569B2 (en) Bus-off attack prevention circuit
CN111344192B (zh) 禁用恶意电子控制单元的系统、方法和计算机程序产品
US10911182B2 (en) In-vehicle information processing for unauthorized data
US20210226872A1 (en) Abnormality detection method, abnormality detection apparatus, and abnormality detection system
JP6566400B2 (ja) 電子制御装置、ゲートウェイ装置、及び検知プログラム
US20200021611A1 (en) Fraud detection method, fraud detection device, and recording medium
JP6828632B2 (ja) 検知装置、検知方法および検知プログラム
WO2014115455A1 (ja) ネットワーク装置およびデータ送受信システム
CN108605004B (zh) 通信系统
US11700271B2 (en) Device and method for anomaly detection in a communications network
JP2019126003A (ja) 攻撃検知装置および攻撃検知方法
WO2023199552A1 (ja) 検知装置および検知方法
JP3971353B2 (ja) ウィルス隔離システム
US12028184B2 (en) Controller area network module and method for the module
JP7175858B2 (ja) 情報処理装置および正規通信判定方法
WO2023127460A1 (ja) 検知装置および検知方法
CN105554041B (zh) 一种检测基于流表超时机制的分布式拒绝服务攻击的方法
US12353544B2 (en) Method for detecting and responding for attack on can network
WO2024051193A1 (zh) 接入用户的在线检测方法、电子设备、计算机可读介质
CN121619612A (zh) 报文传输方法、装置、设备及存储介质
CN118104217A (zh) 检测装置、检测方法和检测程序
KR20230077596A (ko) Can 네트워크에서 공격을 탐지 및 대응하기 위한 방법
Yin et al. Medium access control with packet length priority towards a real time Ethernet
CN119051965A (zh) Cpu攻击检测方法、装置、网络设备和可读存储介质
CN121077888A (zh) 一种故障处理方法、设备以及存储介质

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22937527

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 202280090009.9

Country of ref document: CN

ENP Entry into the national phase

Ref document number: 2024514802

Country of ref document: JP

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: 18855390

Country of ref document: US

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22937527

Country of ref document: EP

Kind code of ref document: A1

WWP Wipo information: published in national office

Ref document number: 18855390

Country of ref document: US