IP Library › Granted Patent US 11,943,243
Granted Patent B2
US 11,943,243 · App. 17/322,371 · Granted Mar 26, 2024

Anomaly detection method and anomaly detection device

Inventors: Takamitsu Sasaki (Osaka, JP); Tomoyuki Haga (Nara, JP); Daiki Tanaka (Hiroshima, JP); Makoto Yamada (Kyoto, JP); Hisashi Kashima (Kyoto, JP); Takeshi Kishikawa (Osaka, JP)
Assignee: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
H04L63/1425H04L12/40H04L63/1466H04L2012/40215H04L2463/142
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,943,243
App. No.
17/322,371
Granted
Mar 26, 2024
Kind
B2
Abstract

In an anomaly detection method that determines whether each frame in observation data constituted by a collection of frames sent and received over a communication network system is anomalous, a difference between a data distribution of a feature amount extracted from the frame in the observation data and a data distribution for a collection of frames sent and received over the communication network system, obtained at a different timing from the observation data, is calculated. A frame having a feature amount for which the difference is predetermined value or higher is determined to be an anomalous frame. An anomaly contribution level of feature amounts extracted from the frame determined to be an anomalous frame is calculated, and an anomalous payload part, which is at least one part of the payload corresponding to the feature amount for which the anomaly contribution level is at least the predetermined value, is output.

Claims (50)

1. An anomaly detection method that, in a communication network system, determines whether each of frames, which are contained in observation data constituted by a collection of frames transmitted and received over the communication network system and observed in a predetermined period, is anomalous, and outputs an anomalous part of a payload in a frame determined to be anomalous, the anomaly detection method comprising:

obtaining a data distribution of a plurality of feature amounts pertaining to a part of the payload included in the frame, the part being at least one bit;

detecting whether or not the frame contained in the observation data is anomalous; and

outputting the anomalous part; and

determining an anomaly type,

wherein in the obtaining, the data distribution is obtained for a collection of frames that are transmitted and received over the communication network system, the collection being obtained at a different timing from a timing at which the observation data is obtained,

in the detecting, a difference between the data distribution obtained in the obtaining and a data distribution of a feature amount extracted from the frame contained in the observation data is calculated, and the frame is determined to be an anomalous frame when the frame has a feature amount for which the difference is at least a predetermined value,

in the outputting, when a frame determined to be an anomalous frame in the detecting is present, an anomaly contribution level is calculated for the plurality of feature amounts that have been extracted from the anomalous frame, and an anomalous payload part is output, the anomalous payload part being at least one part in the payload that corresponds to a feature amount for which the anomaly contribution level is at least a predetermined value, and

in the determining of the anomaly type, an anomalous payload part length is specified based on the anomalous payload part, and the anomaly type is determined according to the anomalous payload part length.

2. The anomaly detection method according to claim 1 ,

wherein in the determining of the anomaly type, the anomaly type is determined to be a state value anomaly when the anomalous payload part length is within a first range, a sensor value anomaly when the anomalous payload part length is within a second range greater than the first range, and a trial attack anomaly when the anomalous payload part length is within a third range longer than the second range.

3. The anomaly detection method according to claim 2 ,

wherein the first range is a range having an upper limit of no greater than 4 bits,

the second range is a range having a lower limit of at least 8 bits and an upper limit of no greater than 16 bits, and

the third range is a range having a lower limit of 32 bits.

4. The anomaly detection method according to claim 1 , further comprising:

determining an anomaly level,

wherein in the determining of the anomaly level, the anomaly level is determined to be higher when a plurality of types of frames have been determined to be anomalous in the detecting and the anomalous payload part output in the outputting differs among the plurality of types of frames than when the anomalous payload part is the same among the plurality of types of frames.

5. The anomaly detection method according to claim 1 , further comprising:

determining an anomaly level,

wherein in the determining of the anomaly level, the anomaly level is determined to be higher than when a plurality of types of frames have been determined to be anomalous in the detecting and the anomaly type determined in the determining of the anomaly type is the same among the plurality of types of frames.

6. The anomaly detection method according to claim 1 , further comprising:

determining an anomaly level,

wherein in the determining of the anomaly level, the anomaly level is determined to be lower when at least one type of frame has been determined to be anomalous in the detecting and the anomaly type determined in the determining of the anomaly type is only a trial attack anomaly than when the anomaly type determined does not include the trial attack anomaly.

7. The anomaly detection method according to claim 1 , further comprising:

determining an anomaly level,

wherein in the determining of the anomaly level, when at least one type of frame has been determined to be anomalous in the detecting, the anomaly level is determined based on a predetermined formula that takes, as a parameter, at least one of the type of the frame determined to be anomalous, a number of types of frames determined to be anomalous, the anomalous payload part output in the outputting, and the anomaly type determined in the determining of the anomaly type.

8. The anomaly detection method according to claim 1 ,

wherein in the determining of the anomaly type, when a plurality of the anomalous payload parts are included in a single frame and a number of intermediate bits between the plurality of the anomalous payload parts is no greater than a predetermined standard, the anomalous payload part and the intermediate bits are collectively treated as a single anomalous payload part.

9. The anomaly detection method according to claim 1 ,

wherein the communication network system is an in-vehicle network system.

10. An anomaly detection device that, in a communication network system, determines whether a frame, which is contained in observation data constituted by a collection of frames transmitted and received over the communication network system and observed in a predetermined period, is anomalous, and outputs an anomalous part of a payload in a frame determined to be anomalous, the anomaly detection device comprising:

a reference model holder that holds a data distribution of a plurality of feature amounts pertaining to a part of the payload included in the frame, the part being at least one bit;

an anomaly detector that determines whether or not the frame contained in the observation data is anomalous;

an anomalous part outputter that, when the anomaly detector has detected an anomalous frame, calculates an anomaly contribution level for the plurality of feature amounts that have been extracted from the anomalous frame, and outputs an anomalous payload part, the anomalous payload part being at least one part contained in the frame and corresponding to a feature amount for which the anomaly contribution level is at least a predetermined value; and

a controller that determines an anomaly type,

wherein the reference model holder holds the data distribution for a collection of frames that are transmitted and received over the communication network system, the collection being obtained at a different timing from a timing at which the observation data is obtained,

the anomaly detector calculates a difference between the data distribution held by the reference model holder and a data distribution of a feature amount extracted from the frame contained in the observation data, and determines that the frame is an anomalous frame when the frame has a feature amount for which the difference is at least a predetermined value, and

the controller specifies an anomalous payload part length based on the anomalous payload part, and determines the anomaly type according to the anomalous payload part length.

11. An anomaly detection device that, in a communication network system, determines whether a frame, which is contained in observation data constituted by a collection of frames transmitted and received over the communication network system and observed in a predetermined period, is anomalous, and outputs an anomalous part of a payload in a frame determined to be anomalous, the anomaly detection device comprising:

a processor; and

a memory including a control program that, when executed by the processor, causes the processor to perform functions, the functions including:

obtaining a data distribution of a plurality of feature amounts pertaining to a part of the payload included in the frame, the part being at least one bit;

detecting whether or not the frame contained in the observation data is anomalous;

outputting the anomalous part; and

determining an anomaly type,

wherein in the obtaining, the data distribution is obtained for a collection of frames that are transmitted and received over the communication network system, the collection being obtained at a different timing from a timing at which the observation data is obtained,

in the detecting, a difference between the data distribution obtained in the obtaining and a data distribution of a feature amount extracted from the frame contained in the observation data is calculated, and the frame is determined to be an anomalous frame when the frame has a feature amount for which the difference is at least a predetermined value,

in the outputting, when a frame determined to be an anomalous frame in the detecting is present, an anomaly contribution level is calculated for the plurality of feature amounts that have been extracted from the anomalous frame, and an anomalous payload part is output, the anomalous payload part being at least one part in the payload that corresponds to a feature amount for which the anomaly contribution level is at least a predetermined value, and

in the determining of the anomaly type, an anomalous payload part length is specified based on the anomalous payload part, and the anomaly type is determined according to the anomalous payload part length.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: SASAKI, TAKAMITSU; HAGA, TOMOYUKI; TANAKA, DAIKI; YAMADA, MAKOTO; KASHIMA, HISASHI; KISHIKAWA, TAKESHI
To: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
Reel/Frame 058341/0684 →
Priority Claims (1)
JP 2019-067627 · Mar 29, 2019 · national
Continuity (2)
Continuation PCTJP2020012301 · Mar 19, 2020
Related Publication 20210273966A1 · Sep 2, 2021