ATTACK SOURCE IDENTIFYING SYSTEM, ATTACK SOURCE IDENTIFYING APPARATUS, ATTACK SOURCE IDENTIFYING METHOD AND PROGRAM
An attack source identifying system according to an aspect of the present disclosure is an attack source identifying system including: a plurality of electronic control devices; a gateway device communicably connected to the plurality of electronic control devices; and an analysis device communicably connected to the plurality of electronic control devices, wherein each of the electronic control devices includes: a creation unit configured to create history information of messages transmitted from a process executed by the electronic control device; and a transmission unit configured to transmit at least a part of the history information to the analysis device, the gateway device includes a detection unit configured to detect an attack message from messages transmitted and received by the plurality of electronic control devices, and the analysis device includes an identification unit configured to identify a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.
1 . An attack source identifying system comprising:
a plurality of electronic control devices;
a gateway device communicably connected to the plurality of electronic control devices;
an analysis device communicably connected to the plurality of electronic control devices;
a processor; and
a memory that includes instructions, which when executed, cause the processor to execute:
creating, by each of the plurality of electronic control devices, history information of messages transmitted from a process executed by the electronic control device;
transmitting, by each of the plurality of electronic control devices, at least a part of the history information to the analysis device;
detecting, by the gateway device, an attack message from messages transmitted and received by the plurality of electronic control devices; and
identifying, by the analysis device, a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.
2 . The attack source identifying system according to claim 1 , wherein the instructions, which when executed, cause the processor to execute:
creating, by each of the plurality of electronic control devices, history information including a message ID indicating identification information of a message transmitted from a process executed by the electronic control device and a process name indicating a name of the process;
transmitting, by each of the plurality of electronic control devices, information including at least the message ID and the process name to the analysis device; and
comparing, by the analysis device, a message ID of the attack message included in the detection information with message IDs included in pieces of the information received from the plurality of electronic control devices, and to identify, as transmission sources of the attack message, a process with a process name corresponding to a matching message ID and an electronic control device as a transmission source of information including the message ID.
3 . The attack source identifying system according to claim 2 , wherein the instructions, which when executed, cause the processor to execute:
transmitting, by each of the plurality of electronic control devices to the analysis device, information further including a time at which the message is transmitted; and
comparing, by the analysis device, a time that is included in the detection information and at which the attack message is detected with times included in the pieces of the information received from the plurality of electronic control devices, and identifying, as transmission sources of the attack message, a process with a process name corresponding to a matching message ID and a matching time and an electronic control device as a transmission source of information including the message ID and the time.
4 . The attack source identifying system according to claim 2 , wherein the instructions, which when executed, cause the processor to execute:
acquiring, by each of the plurality of electronic control devices, a message ID of a message and a process name of a process executed by the electronic control device each time the message is transmitted from the process; and
creating, by each of the plurality of electronic control devices, the history information by using the message ID and the process name acquired at the acquiring.
5 . The attack source identifying system according to claim 4 , wherein
the message is a CAN message, and
the instructions, which when executed, cause the processor to execute:
acquiring a CAN-ID of a CAN message and a process name of a process executed by the electronic control device each time the CAN message is transmitted from the process.
6 . An attack source identifying apparatus comprising:
a plurality of electronic control devices;
a gateway device communicably connected to the plurality of electronic control devices;
an analysis device communicably connected to the plurality of electronic control devices;
a processor; and
a memory that includes instructions, which when executed, cause the processor to execute:
creating, by each of the plurality of electronic control devices, history information of messages transmitted from a process executed by the electronic control device;
transmitting, by each of the plurality of electronic control devices, at least a part of the history information to the analysis device;
detecting, by the gateway device, an attack message from messages transmitted and received by the plurality of electronic control devices; and
identifying, by the analysis device, a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.
7 . An attack source identifying method used in an attack source identifying system including: a plurality of electronic control devices; a gateway device communicably connected to the plurality of electronic control devices; and an analysis device communicably connected to the plurality of electronic control devices, wherein
each of the electronic control devices executes:
creating history information of messages transmitted from a process executed by the electronic control device; and
transmitting at least a part of the history information to the analysis device,
the gateway device executes
detecting an attack message from messages transmitted and received by the plurality of electronic control devices, and
the analysis device executes
identifying a transmission source of the attack message by using detection information related to the attack message and information received from the plurality of electronic control devices in a case where the attack message is detected.
8 . (canceled)
9 . A non-transitory computer-readable recording medium having computer-readable instructions stored thereon, which when executed, cause a computer including a memory and a processor, to execute the attack source identifying method according to claim 7 .