Anomaly Log Analysis System for Mobile Bodies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies do not provide an efficient method for analyzing anomalies detected in mobile bodies, such as vehicles, especially when multiple attacks of the same new kind occur simultaneously, requiring significant computational and human resources.
Innovation Solution
An information processing method and system that analyze attack scenarios by obtaining anomaly logs from multiple mobile bodies, where if the detection details of an anomaly do not match any analyzed second attack scenario but match a third attack scenario that has not been analyzed, the system waits until the third attack scenario is analyzed before processing the anomaly log as a first anomalous event.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly analysis is performed on all detected anomalies without checking for duplicates, then analysis completeness is improved, but computational resources and time are wasted on redundant analyses
Solution Approach 1:
The system performs preliminary actions by checking whether an anomaly corresponds to an already-analyzed attack scenario before initiating full analysis. This pre-checking mechanism prevents redundant computational resources from being wasted on duplicate anomalies while ensuring that new attack scenarios are still analyzed thoroughly.
Solution Approach 2:
The system implements feedback by comparing detected anomaly detection details against previously analyzed attack scenarios. This feedback loop allows the system to identify and skip redundant analyses while maintaining completeness for novel attack patterns, thereby improving computational efficiency without sacrificing analysis thoroughness.
2Productivity
If the system waits to analyze attack scenarios until duplicates are identified, then computational resources are saved, but analysis time is delayed
Solution Approach 1:
The system performs preliminary identification of duplicate anomalies by comparing detection details against known attack scenarios before initiating full analysis. This allows the system to quickly identify and skip redundant analyses, reducing both computational resource consumption and analysis delay simultaneously.
Solution Approach 2:
The system applies partial action by performing only the necessary comparison check against known attack scenarios rather than conducting full analysis on all anomalies. This partial analysis approach efficiently identifies duplicates while minimizing time delay, as the system can quickly determine whether an anomaly requires full analysis or can be skipped.
3Speed
If the system analyzes all anomaly logs immediately, then response speed is improved, but redundant computational work increases
Solution Approach 1:
The system performs preliminary comparison of anomaly detection details against known attack scenarios before initiating full analysis. This pre-checking action enables the system to maintain fast response speed by quickly identifying duplicates while preventing computational energy from being wasted on redundant analyses of already-processed attack scenarios.
Solution Approach 2:
The system uses feedback mechanisms to compare detected anomalies against previously analyzed attack scenarios, enabling rapid identification of duplicates. This feedback loop allows the system to respond quickly to new anomalies while efficiently allocating computational energy only to truly novel attack scenarios, reducing overall energy consumption.
Data Source
AI summary
An information processing method is executed by an information processing system that analyzes an attack scenario by obtaining anomaly logs detected by mobile bodies. The method includes: obtaining, from a mobile body, an anomaly log indicating an anomaly of the mobile body; and when a detection detail of the anomaly included in the anomaly log and indicated by a first attack scenario does not match a detection detail of an anomaly indicated by any one of at least one second attack scenario that has been analyzed and matches a detection detail of an anomaly indicated by a third attack scenario among at least one third attack scenario that has not yet been analyzed, performing a process for the anomaly log as a first anomalous event occurring to the mobile body, after waiting until the third attack scenario has been analyzed.


