Centralized Cyber-Attack Detection for Connected Vehicles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected vehicles are vulnerable to cyber-attacks due to the collection and transmission of telemetric data, which can lead to vehicle misappropriation, failure, theft, and other malicious activities, posing risks to safety and financial security.

Innovation Solution

A method and system for detecting and mitigating cyber-attacks in connected vehicles by classifying data transmission behaviors as local or remote, identifying cyber-attack indicators, performing risk analysis by matching these indicators to known attack patterns, and implementing mitigation actions based on the analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If computerized control and management systems collect and transmit telemetric data from vehicles, then vehicle monitoring and control capabilities are improved, but vehicles become vulnerable to cyber-attacks and malicious activities

Engineering Contradiction:
Improvevehicle monitoring capabilityVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a centralized detection system that acts as an intermediary between vehicles and the external network. This system analyzes telemetry data and detects cyber-attacks centrally, protecting individual vehicles while maintaining monitoring capabilities. The intermediary filters malicious traffic before it reaches vehicles, resolving the contradiction between connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary risk analysis and attack detection by classifying behaviors and matching indicator combinations against known attack patterns before malicious actions can execute. By proactively identifying potential threats in telemetry data, the system prevents cyber-attacks while maintaining normal vehicle operations and monitoring functions.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If centralized detection systems analyze multiple cyber-attack indicators and perform risk analysis, then detection accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the detection process into distinct modules: behavior classification (local/remote), indicator determination, risk analysis with pattern matching, and mitigation actions. Each module handles specific aspects of detection independently, improving accuracy through comprehensive analysis while managing complexity through modular architecture. The segmented approach allows systematic processing of multiple indicators without overwhelming system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11539724B2Centralized detection techniques for cyber-attacks directed at connected vehicles
Publication Date: 2022.12.27 UPSTREAM SECURITY LTD
  • US11539724B2 patent drawing
  • US11539724B2 patent drawing
  • US11539724B2 patent drawing

AI summary

Systems and methods for detecting and mitigating cyber-attacks directed to connected vehicles. A method includes classifying a behavior of a connected vehicle into at least one classification with respect to a location of data transmission relative to the connected vehicle, wherein the at least one classification includes any of local and remote; determining a plurality of vehicle-related cyber-attack indicators related to the behavior of the connected vehicle; performing risk analysis based on a first combination of vehicle-related cyber-attack indicators and the classification, wherein performing the risk analysis further comprises matching the first combination to a plurality of second combinations of cyber-attack indicators of a plurality of known attack patterns, wherein each of the plurality of known attack patterns has at least one classification matching the at least one classification of the connected vehicle; and performing at least one mitigation action based on the risk analysis.