US 11,956,262 B2
Anomaly detection device and anomaly detection method
Ryo Hirano, Osaka (JP); Takeshi Kishikawa, Osaka (JP); Yoshihiro Ujiie, Osaka (JP); and Tomoyuki Haga, Nara (JP)
Assigned to PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA, Torrance, CA (US)
Filed by Panasonic Intellectual Property Corporation of America, Torrance, CA (US)
Filed on May 25, 2021, as Appl. No. 17/330,020.
Application 17/330,020 is a continuation of application No. PCT/JP2020/024841, filed on Jun. 24, 2020.
Prior Publication US 2021/0281595 A1, Sep. 9, 2021
Int. Cl. H04L 9/40 (2022.01); G06F 21/31 (2013.01); G06F 21/55 (2013.01); H04L 67/12 (2022.01); H04W 4/48 (2018.01)
CPC H04L 63/1425 (2013.01) [H04L 63/20 (2013.01); H04L 67/12 (2013.01)] 11 Claims
OG exemplary drawing
 
1. An anomaly detection device in an in-vehicle network system performing service-oriented communication via Ethernet (registered trade mark), the anomaly detection device comprising:
a detection rule generator circuit
that monitors a communication establishment frame flowing over the Ethernet in a communication establishment phase of the service-oriented communication, the communication establishment frame including a communication ID, and
that dynamically generates, for the communication ID, a detection rule including the communication ID written in the communication establishment frame, and a server address or a client address written in the communication establishment frame;
an anomaly detector circuit
that monitors a communication frame flowing over the Ethernet in a communication phase of the service-oriented communication,
that determines that the communication frame includes the communication ID corresponding to the dynamically generated detection rule,
that, by referring to the dynamically generated detection rule corresponding to the communication ID written in the communication frame, detects the communication frame as an anomalous frame when a server address or a client address written in the communication frame differs from the server address or the client address specified in the dynamically generated detection rule; and
an anomaly notifier circuit that provides a notification of an anomaly in response to the anomalous frame being detected, wherein
the detection rule generator circuit generates, for each of one or more communication IDs, a plurality of detection rules that include an identical communication ID and server addresses different from each other or client addresses different from each other.