Attack Analysis Device Using Context Data for Cybersecurity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies for analyzing attacks on electronic control systems in vehicles often include low-probability attack types in estimates, leading to inappropriate countermeasures being selected.
Innovation Solution
An attack analysis device that acquires security logs and uses attack abnormality relationship information to estimate attacks, while also analyzing the estimation accuracy based on context data, to provide accurate attack information and estimation accuracy information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If attack estimation is performed using only security logs and attack abnormality relationship information, then the attack estimation process is simple, but the estimation accuracy is low due to inclusion of low-probability attack types
Solution Approach 1:
The patent introduces context data as an intermediary element that mediates between the security log and the attack estimation result. The context data contains information about the vehicle state, environment, and operational conditions that help filter and refine attack probability assessments. This intermediary layer enables more accurate attack estimation without requiring complete system redesign.
Solution Approach 2:
The patent implements a feedback mechanism where the attack estimation result is compared against context data to validate and refine the estimation. The system uses the context information to provide feedback on the likelihood of estimated attacks, allowing the system to adjust and improve estimation accuracy iteratively while maintaining a manageable analysis framework.
2Adaptability or versatility
If comprehensive attack types are included in attack estimation, then the coverage of potential attacks is improved, but inappropriate countermeasures are selected due to low-probability attack types
Solution Approach 1:
The patent applies local quality by differentiating the treatment of different attack types based on their probability and context relevance. High-probability attack types receive detailed analysis and corresponding countermeasures, while low-probability types are filtered out using context data. This selective approach ensures comprehensive coverage where needed while maintaining reliability by excluding spurious low-probability matches.
Solution Approach 2:
The patent changes the probability threshold parameter dynamically based on context data. When context indicators suggest a high-risk situation, the system lowers the threshold to capture more attack types. When context indicates normal operation, the threshold increases to filter out low-probability false positives. This parameter adjustment mechanism balances coverage and reliability adaptively.
Data Source
AI summary
An attack analysis device stores attack abnormality relationship information indicating a relationship among (i) predicted attack information indicating an attack predicted to be received by an electronic control system, (ii) predicted abnormality information indicating an abnormality predicted to occur in response to the predicted attack, and (iii) predicted abnormality location information indicating a location within the electronic control system where the predicted abnormality occurs. The attack analysis device is configured to: acquire a security log indicating an abnormality detected in the electronic control system and a detection location of the abnormality in the electronic control system; estimate the attack based on the security log and the attack abnormality relationship information; analyze an estimation accuracy of the attack based on context data included in the security log; and output attack information, which indicates the estimated attack, and estimation accuracy information, which indicates the estimation accuracy of the attack.


