IP Library › Patent Application 18862256
Patent Application
App. No. 18/862,256

ATTACK SOURCE IDENTIFYING SYSTEM, ATTACK SOURCE IDENTIFYING APPARATUS, ATTACK SOURCE IDENTIFYING METHOD AND PROGRAM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/862,256
Abstract

An attack source identifying system according to an aspect of the present disclosure is an attack source identifying system including: a plurality of electronic control devices; a gateway device communicably connected to the plurality of electronic control devices; and an analysis device communicably connected to the plurality of electronic control devices, wherein each of the electronic control devices includes: a creation unit configured to create history information of messages transmitted from a process executed by the electronic control device; and a transmission unit configured to transmit at least a part of the history information to the analysis device, the gateway device includes a detection unit configured to detect an attack message from messages transmitted and received by the plurality of electronic control devices, and the analysis device includes an identification unit configured to identify a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.

Claims (44)

1 . An attack source identifying system comprising:

a plurality of electronic control devices;

a gateway device communicably connected to the plurality of electronic control devices;

an analysis device communicably connected to the plurality of electronic control devices;

a processor; and

a memory that includes instructions, which when executed, cause the processor to execute:

creating, by each of the plurality of electronic control devices, history information of messages transmitted from a process executed by the electronic control device;

transmitting, by each of the plurality of electronic control devices, at least a part of the history information to the analysis device;

detecting, by the gateway device, an attack message from messages transmitted and received by the plurality of electronic control devices; and

identifying, by the analysis device, a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.

2 . The attack source identifying system according to claim 1 , wherein the instructions, which when executed, cause the processor to execute:

creating, by each of the plurality of electronic control devices, history information including a message ID indicating identification information of a message transmitted from a process executed by the electronic control device and a process name indicating a name of the process;

transmitting, by each of the plurality of electronic control devices, information including at least the message ID and the process name to the analysis device; and

comparing, by the analysis device, a message ID of the attack message included in the detection information with message IDs included in pieces of the information received from the plurality of electronic control devices, and to identify, as transmission sources of the attack message, a process with a process name corresponding to a matching message ID and an electronic control device as a transmission source of information including the message ID.

3 . The attack source identifying system according to claim 2 , wherein the instructions, which when executed, cause the processor to execute:

transmitting, by each of the plurality of electronic control devices to the analysis device, information further including a time at which the message is transmitted; and

comparing, by the analysis device, a time that is included in the detection information and at which the attack message is detected with times included in the pieces of the information received from the plurality of electronic control devices, and identifying, as transmission sources of the attack message, a process with a process name corresponding to a matching message ID and a matching time and an electronic control device as a transmission source of information including the message ID and the time.

4 . The attack source identifying system according to claim 2 , wherein the instructions, which when executed, cause the processor to execute:

acquiring, by each of the plurality of electronic control devices, a message ID of a message and a process name of a process executed by the electronic control device each time the message is transmitted from the process; and

creating, by each of the plurality of electronic control devices, the history information by using the message ID and the process name acquired at the acquiring.

5 . The attack source identifying system according to claim 4 , wherein

the message is a CAN message, and

the instructions, which when executed, cause the processor to execute:

acquiring a CAN-ID of a CAN message and a process name of a process executed by the electronic control device each time the CAN message is transmitted from the process.

6 . An attack source identifying apparatus comprising:

a plurality of electronic control devices;

a gateway device communicably connected to the plurality of electronic control devices;

an analysis device communicably connected to the plurality of electronic control devices;

a processor; and

a memory that includes instructions, which when executed, cause the processor to execute:

creating, by each of the plurality of electronic control devices, history information of messages transmitted from a process executed by the electronic control device;

transmitting, by each of the plurality of electronic control devices, at least a part of the history information to the analysis device;

detecting, by the gateway device, an attack message from messages transmitted and received by the plurality of electronic control devices; and

identifying, by the analysis device, a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.

7 . An attack source identifying method used in an attack source identifying system including: a plurality of electronic control devices; a gateway device communicably connected to the plurality of electronic control devices; and an analysis device communicably connected to the plurality of electronic control devices, wherein

each of the electronic control devices executes:

creating history information of messages transmitted from a process executed by the electronic control device; and

transmitting at least a part of the history information to the analysis device,

the gateway device executes

detecting an attack message from messages transmitted and received by the plurality of electronic control devices, and

the analysis device executes

identifying a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.

8 . (canceled)

9 . A non-transitory computer-readable recording medium having computer-readable instructions stored thereon, which when executed, cause a computer including a memory and a processor, to execute the attack source identifying method according to claim 7 .

Assignments (2)
CHANGE OF NAME Recorded Aug 15, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072491/0021 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2024
From: OKANO, YASUSHI; MATSUBAYASHI, MASARU; TANAKA, MASASHI; KOYAMA, TAKUMA
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 069102/0206 →