Looking for breakthrough ideas for innovation challenges? Try Patsnap Eureka!

Abnormal communication detection device, abnormal communication detection method, and program

A technology of abnormal communication and detection device, which is applied to computer security devices, data exchange, transportation and packaging through path configuration to achieve the effect of reducing over-detection

Active Publication Date: 2020-06-30
NIPPON TELEGRAPH & TELEPHONE CORP
View PDF8 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

It is known that by means of network connection to an illegal ECU or illegal action rewriting of a known ECU, an attack transmission that inserts an ID associated with an attack target function may induce illegal actions of the target function

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Abnormal communication detection device, abnormal communication detection method, and program
  • Abnormal communication detection device, abnormal communication detection method, and program
  • Abnormal communication detection device, abnormal communication detection method, and program

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0046] Below, refer to figure 1 , figure 2 Next, the configuration of the abnormal communication detecting device of the first embodiment for detecting abnormal communication from the communication of each electronic control device in the communication network will be described. Such as figure 1 As shown, the abnormal communication detection device 1 of this embodiment includes: a stage switching unit 11, a receiving unit 12, a temporary holding unit 13, a knowledge information acquisition unit 14, a knowledge information storage unit 14a, a distribution rule generation unit 15, a distribution rule storage unit 15 a , distribution unit 16 , first detectors 17 - 1 , .

[0047] Such as figure 2 As shown, the nth detector 17 - n (n=1, . Furthermore, the n-th probe 17 - n may have components other than those shown in the figure, or may not have a part of the components shown in the figure. For example, the receiving unit 171 of the nth probe 17 - n may directly transmit the...

Embodiment 2

[0071] Depending on the state of the machine, eg parking, driving, autonomous driving, etc. in the vehicle, the communication to which sensor is assigned changes. For example, in communication data from a vehicle, there are IDs that appear in a cycle+event type when the ignition of the vehicle is ON, but appear in an event type when the ignition is OFF.

[0072] Below, refer to Figure 4 , Figure 5 Next, the structure of the abnormality communication detection apparatus of Example 2 which processes the communication data sent from the electronic control apparatus which has several mechanical states is demonstrated. Such as Figure 4 As shown, the abnormal communication detection device 2 of this embodiment includes: a stage switching unit 11, a receiving unit 12, a temporary holding unit 13, a knowledge information acquisition unit 24, a knowledge information storage unit 14a, a distribution rule generation unit 25, a distribution rule storage unit 15a, distribution unit 1...

Embodiment 3

[0081] Depending on the structure of the machine or the combination of installed probes, most of the communication data may belong to one group and may be allocated only to specific probes. The abnormal communication detection device can process multiple tasks in parallel, but when the detector can be configured as an independent device, by preparing multiple identical learners and detectors, the processing time required for learning and detection can be reduced and distributed , Processing load.

[0082] Below, refer to Figure 7 , the configuration of the abnormal communication detecting device of the third embodiment in which a plurality of the same detectors are prepared will be described. Such as Figure 7 As shown, the abnormal communication detection device 3 of this embodiment includes: a stage switching unit 11, a receiving unit 12, a temporary holding unit 13, a knowledge information acquisition unit 14, a knowledge information storage unit 14a, a distribution rule...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The present invention provides an abnormal communication detection device capable of reducing overdetection. This abnormal communication detection device comprises: a reception unit which receives learning communication data containing an identifier, and detection communication data containing an identifier; a knowledge information acquisition unit which acquires knowledge information that is information relating to a temporal property and / or a property of a payload of the learning communication data; a sorting rule generation unit which generates a sorting rule that is a rule defining, on thebasis of the knowledge information, which identifier-containing communication data is to be sorted into which detector among a plurality of detectors; a sorting unit which sorts the communication data into any one of the detectors on the basis of the sorting rule; and the plurality of detectors which each, if the learning communication data has been sorted thereinto, learn a model for detecting whether the communication data sorted into the detector is normal or abnormal, and if the detection communication data has been sorted thereinto, detect whether the detection communication data is normal or abnormal on the basis of the learned model.

Description

technical field [0001] The present invention relates to the detection of abnormalities caused by attack communication, etc., in a network installed in vehicles, machine tools, construction machinery, agricultural machinery, etc., a communication device connected to the network, and a communication system constituted by them A communication abnormality detection device, an abnormal communication detection method, and a program. Background technique [0002] Vehicles (cars, special vehicles, motorcycles, bicycles, etc.), machine tools, construction machinery, agricultural machinery and other machinery are equipped with multiple electronic control units (ECU: Electronic Control Unit). A typical network used in the communication network is a controller area network (CAN: Controller Area Network). The CAN network structure adopts a so-called bus type structure that shares the communication lines of each ECU. In the communication process on the bus of the ECU, CSMA / CR (Carrier S...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): H04L12/28B60R16/023H04L12/70
CPCB60R16/023H04L63/1408H04L63/1433H04L2012/40215G06F21/577H04L2012/40273G06N20/20B60R16/0232G06F18/217
Inventor 小山卓麻冈野靖田中政志
Owner NIPPON TELEGRAPH & TELEPHONE CORP
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Patsnap Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Patsnap Eureka Blog
Learn More
PatSnap group products