Attack Analyzer for In-Vehicle Electronic Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The varying configurations of in-vehicle electronic control systems across different vehicles pose a challenge in identifying cyber attacks, as each system requires unique abnormality detection patterns and analysis rules, leading to increased processing loads and development complexities.
Innovation Solution
An attack analyzer that includes a common log acquisition unit, an attack/abnormality relationship table storage unit, an estimation unit, and an output unit, which converts abnormality positions into common positions across electronic control systems, enabling the estimation of attack types regardless of system configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If abnormality detection patterns and analysis rules are set for each in-vehicle system configuration, then cyber attack identification accuracy is improved, but device complexity and processing load increase
Solution Approach 1:
The patent creates a universal attack analysis system that can handle multiple in-vehicle system configurations through a single standardized interface. By defining common abnormality positions that map to specific ECUs and functions, the system achieves multi-functionality across different vehicle types, manufacturers, and model years without requiring separate analysis rules for each configuration.
Solution Approach 2:
The system changes the parameter representation from configuration-specific ECU identifiers to standardized common abnormality position codes. This parameter transformation allows the same attack analysis logic to be applied universally while adapting to different physical configurations through the mapping relationship between common positions and actual ECUs.
2Measurement precision
If abnormality detection patterns are customized for each electronic control device, then detection precision is improved, but ease of manufacture and maintenance deteriorate
Solution Approach 1:
The patent segments the attack analysis system into two independent parts: a configuration-independent attack analysis engine with standardized logic, and a configuration-specific mapping layer that translates between common abnormality positions and actual ECU identifiers. This segmentation allows the core analysis logic to be manufactured and deployed once, while adapting to different configurations through the mapping layer.
3Reliability
If comprehensive attack analysis coverage is achieved for all ECU configurations, then reliability is improved, but processing load increases
Solution Approach 1:
The patent performs preliminary action by pre-defining the mapping relationships between common abnormality positions and ECU identifiers, and pre-establishing the attack analysis rules based on standardized position codes. When a cyber attack occurs, the system only needs to perform the mapping lookup and apply the predetermined analysis logic, significantly reducing the processing load during actual attack detection while maintaining comprehensive coverage.
Data Source
Figure 1
Figure 2A~2B
Figure 3~4
AI summary
An attack analyzer includes: a common log acquisition unit (201) acquiring a common security log including abnormality information indicating abnormality detected by an electronic control system, and a common abnormality position indicating an abnormality position of the abnormality converted to be common among the electronic control system and other electronic control systems; an attack / abnormality relationship table storage unit (202) storing an attack / abnormality relationship table; an estimation unit (203); and an output unit (205) outputting attack information including the attack type.