AI Cybersecurity for Connected Vehicles Using Normal Pattern Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber threat defense systems are limited in their ability to monitor and analyze the unique data types and protocols used in connected vehicle ecosystems, leading to security blind spots and inadequate protection against cyber threats.

Innovation Solution

A cyber threat defense system utilizing machine-learning and AI algorithms to compare data from connected vehicles to established normal patterns of life, detecting anomalies that may indicate cyber threats, and employing autonomous response modules to counter detected threats without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional commercial cyber threat defense systems are used, then protection is provided for logical enterprise zones, but they cannot analyze uncommon protocol and data types from IoT devices and connected vehicles without significant development work

Engineering Contradiction:
Improveability to analyze different protocol and data typesVSAvoiddevelopment work required
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal cybersecurity platform that can analyze multiple protocol types (CAN, LIN, Ethernet, WiFi, Bluetooth, 5G) and data formats from diverse sources including vehicles, IoT devices, and enterprise systems. The system uses a unified data normalization layer that converts various protocols into a common analysis format, eliminating the need for separate specialized systems for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary normalization layer between data collection and analysis components. This layer standardizes incoming data from various protocols and devices into a unified format, allowing the core security engine to process all data types through a single analysis pipeline without requiring protocol-specific processing logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If specialized machine learning approaches are used for specific zones, then accurate detection is achieved for that zone, but the system lacks versatility to accommodate unseen data types and structures

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to accommodate unseen data types
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic machine learning models that automatically adapt to new data types and protocols encountered in the environment. The system continuously learns from incoming data streams, adjusting its detection parameters and patterns without requiring manual reconfiguration. This allows the system to maintain high detection accuracy while accommodating unseen data types from emerging devices and protocols.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs preliminary training phases where the machine learning models are exposed to diverse protocol and data type samples before deployment. This pre-training establishes a broad foundation of recognition patterns that enables the system to accurately detect threats across multiple device types and protocols from the outset, rather than requiring zone-specific customization.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If lower level protocols in the protocol stack are analyzed, then comprehensive coverage is achieved, but the data types differ significantly from those typically analyzed by commercial security systems

Engineering Contradiction:
Improvecomprehensive security coverageVSAvoiddifficulty of analyzing varying data types
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary normalization layer between data collection and analysis components. This layer standardizes incoming data from various protocols and devices into a unified format, allowing the core security engine to process all data types through a single analysis pipeline without requiring protocol-specific processing logic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual protocol-specific analysis configurations with automated machine learning-based analysis. The system automatically identifies and adapts to different protocol characteristics, substituting the need for complex manual setup and maintenance of protocol-specific analysis rules with self-adapting intelligent algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250119446A1Artificial intelligence based cybersecurity system for monitoring automotive ecosystems
Publication Date: 2025.04.10 DARKTRACE HLDG LTD
  • US20250119446A1 patent drawing
  • US20250119446A1 patent drawing
  • US20250119446A1 patent drawing

AI summary

A cyber threat defense system is provided comprising: a processing component; and a non-transitory computer readable medium including one or more software modules accessible by the processing component, the one or more software modules comprising: a vehicle module configured to receive data from a first vehicle and a second vehicle and reference one or more machine-learning models using machine-learning and artificial intelligence (AI) algorithms, the one or more machine-learning models including a first machine-learning model trained on a normal pattern of life associated with the first vehicle and the second vehicle, and a comparator module configured to cooperate with the vehicle module to compare data received from the first vehicle and the second vehicle to the normal pattern of life associated with the first vehicle and the second vehicle to detect anomalies representing a cyber threat within the first vehicle or the second vehicle. A corresponding method and non-transitory computer readable medium are also provided.