Vehicle security analysis apparatus, and method and program storage medium
The vehicle security analysis apparatus generates, based on sensor log data items generated in in-vehicle devices, a combination of sensor log data items by associating a plurality of sensor log data items having a possibility of constituting the same individual attack, and identifies an individual attack pattern by comparing this combination of the sensor log data items with individual attack knowledge information. Next, a combination of a plurality of individual attack patterns that have occurred within a predetermined time period is compared with attack scenario knowledge information to identify an attack scenario. Then, the analysis result including the identified individual attack pattern and attack scenario is output.
1 . A vehicle security analysis apparatus for acquiring and analyzing sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the apparatus comprising:
processing circuitry configured to
acquire and store the sensor log data;
generate multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack from among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) compare the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generate first analysis information that includes information indicating the identified individual attack pattern, such that the processing circuitry identifies multiple individual attack patterns corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;
compare the plurality of individual attack patterns obtained within a predetermined time period with attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generate second analysis information that includes information indicating the identified attack scenarios; and
output an analysis result including the generated first analysis information and the generated second analysis information.
2 . The vehicle security analysis apparatus according to claim 1 ,
wherein the processing circuitry is configured to select a sensor log data item as an analysis target for the individual attack to be analyzed from among the items of the stored sensor log data and provide the selected sensor log data item as the analysis target.
3 . The vehicle security analysis apparatus according to claim 1 , further comprising:
wherein the processing circuitry is configured to add extension information necessary for analysis of the individual attack pattern to the items of the stored sensor log data based on contents of the sensor log data and provide the sensor log data to which the extension information is added, as an analysis target.
4 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry generates the combination of the items of the sensor log data by associating a plurality of items of the sensor log data having identical identification information of a vehicle that serves as a generation source of the sensor log data and having generation times within a specific time period.
5 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry compares information included in the sensor log data with the plurality of individual attack patterns, the information indicating at least one of a sensor installation location and a sensor type, and the first analysis processing unit thereby identifies the corresponding individual attack pattern.
6 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry generates the first analysis information by describing contents of the items of the sensor log data that constitute an individual attack pattern, in a template predefined for each of the identified plurality of individual attack patterns.
7 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry determines whether or not an identified individual attack pattern is information to be provided for analysis of the attack scenario based on a determination condition predefined for an analysis target of the attack scenario, and does not provide the individual attack pattern to the second analysis processing unit if the individual attack pattern is not to be provided.
8 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry compares the plurality of individual attack patterns with the attack scenarios predefined as the attack scenario knowledge information, and identifies the attack scenario that includes the plurality of individual attack patterns and in which occurrence timings of the plurality of individual attack patterns are included within a predetermined time period.
9 . The vehicle security analysis apparatus according to claim 1 , wherein
wherein the processing circuitry generates the second analysis information by describing the plurality of individual attack patterns included in the attack scenario and contents of the items of the sensor log data that constitute the plurality of individual attack patterns, in a template predefined for each of the identified attack scenarios.
10 . A vehicle security analysis method executed by an apparatus that acquires and analyzes sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the vehicle security analysis method comprising:
acquiring and storing the sensor log data;
generating multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) comparing the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generating first analysis information including information indicating the identified individual attack pattern, such that multiple individual attack patterns are identified corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;
comparing a combination of the plurality of individual attack patterns obtained within a predetermined time period with a plurality of attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generating second analysis information including information indicating the identified attack scenarios; and
outputting an analysis result including the generated first analysis information and the generated second analysis information.
11 . A non-transitory computer-readable medium storing a program for causing a processor included in a vehicle security analysis apparatus to execute a method of acquiring and analyzing sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the method comprising:
acquiring and storing the sensor log data;
generating multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) comparing the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generating first analysis information including information indicating the identified individual attack pattern, such that multiple individual attack patterns are identified corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;
comparing a combination of the individual attack patterns obtained within a predetermined time period with a plurality of attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generating second analysis information including information indicating the identified attack scenarios; and
outputting an analysis result including the generated first analysis information and the generated second analysis information.