CPC G06F 21/552 (2013.01) [G06F 2221/034 (2013.01)] | 18 Claims |
1. An attack analyzer comprising a processor coupled to a memory configured to execute:
a common log acquisition unit acquiring a common security log from a common security log generation unit, the common security log including:
(a) abnormality information indicating an abnormality detected by an electronic control system, and
(b) a common abnormality position indicating an abnormality position of the abnormality converted to be common among the electronic control system and other electronic control systems;
an attack/abnormality relationship table storage unit storing an attack/abnormality relationship table indicating a relationship among:
(c) an attack type of an attack on the electronic control system,
(d) predicted abnormality information indicating a predicted abnormality predicted to occur when the electronic control system is attacked, and
(e) a common predicted abnormality position indicating a predicted abnormality position of the predicted abnormality converted to be common among the electronic control system and the other electronic control systems;
an estimation unit estimating the attack type of the attack received by the electronic control system from a combination of (A) the predicted abnormality information corresponding to a combination of (a) the abnormality information and (b) the common abnormality position, and (B) the common predicted abnormality position; and
an output unit outputting attack information including the attack type, wherein
the common security log generation unit includes
an individual log acquisition unit acquiring an individual security log including the abnormality information and the abnormality position,
a positional relationship table storage unit storing a positional relationship table, which shows a relationship between (a) an individual position, which is a position in the electronic control system, and (b) a common position, which is a position of the individual position converted to be common between the electronic control system and the other electronic control systems, and
a commonality converter unit converting the abnormality position to the common abnormality position using the positional relationship table.
|