Information processing device, anomaly detection method, and computer-readable recording medium
In an ECU, virtualization software operates a first virtual machine (VM) and a second VM. A transfer unit of the second VM acknowledges communication data transmitted from the first VM and destined to the second VM. A transfer unit generates a parameter related to communication between the VMs, based on the communication data acknowledged. A detection unit of the second VM detects abnormal communication, based on the parameter generated by the transfer unit.
1 . An information processing device in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, the information processing device comprising:
an acknowledgment unit that acknowledges communication data transmitted from the first VM and destined to the second VM;
a generation unit that generates a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged by the acknowledgment unit;
a data transfer unit that transfers the communication data acknowledged by the acknowledgment unit to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;
a detection unit that detects abnormal communication, based on the parameter generated by the generation unit; and
a responding unit that executes a measure to counter the abnormal communication in accordance with a result of detection by the detection unit, and that updates the predetermined security policy of the data transfer unit in accordance with the result of detection by the detection unit, wherein
the generation unit generates the parameter based on two or more pieces of information out of a source identifier of a source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.
2 . The information processing device according to claim 1 , wherein
the detection unit detects the abnormal communication when the detection unit determines that the communication signal between the first VM and the second VM meets a predetermined condition, based on the parameter generated by the generation unit.
3 . The information processing device according to claim 1 , wherein
the generation unit is implemented in an execution environment more reliable than the first VM.
4 . The information processing device according to claim 1 , wherein
the detection unit is implemented in an execution environment more reliable than the first VM.
5 . The information processing device according to claim 1 , further comprising:
an analysis unit that analyzes the communication data destined to the second VM when the detection unit detects the abnormal communication.
6 . The information processing device according to claim 1 , wherein
the parameter, which is generated by the generation unit, includes an ID of the first VM and an ID of the second VM.
7 . The information processing device according to claim 1 , further comprising:
a protection processing unit implemented in an execution environment more reliable than the virtualization software and adapted to execute a predetermined protection process, wherein
when the detection unit detects an anomaly, the responding unit prevents execution of the predetermined protection process in the protection processing unit in response to a request from the first VM.
8 . The information processing device according to claim 1 , further comprising:
a Hyper Visor (HV) for operating the first VM and the second VM; and
a shared memory accessible to the first VM and the second VM,
wherein the acknowledgment unit, the generation unit, and the detection unit are included in the second VM,
the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and
the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.
9 . An anomaly detection method for a device, in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, the anomaly detection method comprising:
acknowledging communication data transmitted from the first VM and destined to the second VM;
generating a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged; and
transferring the communication data acknowledged by the acknowledging to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;
detecting abnormal communication, based on the parameter generated;
executing a measure to counter the abnormal communication in accordance with a result of detection by the detecting; and
updating the predetermined security policy in accordance with the result of detection by the detecting, wherein
the parameter is generated based on two or more pieces of information out of a source identifier of a source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.
10 . The anomaly detection method according to claim 9 , wherein
the device further includes a Hyper Visor (HV) for operating the first VM and the second VM, and a shared memory accessible to the first VM and the second VM,
the acknowledging, the generating, and the detecting are performed in the second VM,
the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and
the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.
11 . A non-transitory computer-readable recording medium encoded with a computer program that causes a device, in which virtualization software operates a first virtual machine (VM) and a second VM in a vehicle, to perform:
acknowledging communication data transmitted from the first VM and destined to the second VM;
generating a parameter related to a communication signal between the first VM and the second VM, based on the communication data acknowledged;
transferring the communication data acknowledged by the acknowledging to an application on the second VM in accordance with a predetermined security policy, which includes a policy related to the parameter;
detecting abnormal communication, based on the parameter generated;
executing a measure to counter the abnormal communication in accordance with a result of detection by the detecting; and
updating the predetermined security policy in accordance with the result of detection by the detecting, wherein
the parameter is generated based on two or more pieces of information out of a source identifier of the source VM and a destination identifier of a destination VM of the communication signal, a request number of the communication signal, an interrupt number of the communication signal, or a protocol number of the communication signal.
12 . The non-transitory computer-readable recording medium according to claim 11 , wherein
the device further includes a Hyper Visor (HV) for operating the first VM and the second VM, and a shared memory accessible to the first VM and the second VM,
the communication data is acknowledged by, the parameter is generated by, and the abnormal communication is detected by the second VM,
the first VM transmits to the second VM the communication data including a communication payload as contents to be delivered to the second VM and the communication signal as control information for controlling communication between the first VM and the second VM, and
the second VM reads the communication payload stored in the shared memory by the first VM, and the first VM transmits the communication signal to the second VM via the HV, thereby transmitting the communication data from the first VM to the second VM.