Connected Vehicle Security Incident Integration via Aggregate Event Correlation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing threat detection systems for connected vehicles are limited in their ability to process large quantities of data from different sources, leading to potential failures in detecting threats, mis-prioritization of threats, and inefficient processing of threats.
Innovation Solution
A method and system for integrating connected vehicle security incident data with contextual cybersecurity data, allowing for correlation of security incidents across multiple vehicles, enrichment of data with external cybersecurity information, generation of risk assessments, and performance of mitigation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing threat detectors collect and process data from individual connected vehicles, then they can detect threats based on vehicle-specific data, but they fail to detect threats that require cross-vehicle analysis and cannot accurately determine root causes
Solution Approach 1:
The patent merges data from multiple connected vehicles into a unified processing system. The threat detector collects and correlates security incident data across different vehicles, combining individual vehicle data with aggregate event information to enable comprehensive threat analysis that cannot be achieved by examining single vehicles in isolation.
Solution Approach 2:
The patent adds a new dimension of analysis by introducing cross-vehicle correlation capabilities. Instead of processing data from a single vehicle, the system now operates across multiple vehicles simultaneously, enabling detection of patterns and threats that span across the vehicle fleet and providing additional context for root cause analysis.
2Quantity of substance
If existing threat detectors focus on processing large quantities of data from multiple sources, then they can improve data comprehensiveness, but they mis-prioritize threats and inefficiently process security incidents
Solution Approach 1:
The patent implements preliminary actions by pre-establishing correlation rules and aggregation thresholds before threat analysis begins. The system pre-processes and organizes data from multiple vehicles according to predefined categories and priority levels, enabling efficient threat processing without requiring complex real-time decisions when analyzing large volumes of data.
Solution Approach 2:
The patent segments the complex task of processing large quantities of multi-source data into manageable components. It divides security incident data into distinct categories and priority levels, processes each segment according to its characteristics, and correlates them systematically, thereby improving overall processing efficiency while maintaining comprehensive data analysis.
3Adaptability or versatility
If connected vehicles collect and transmit telemetry data remotely, then they enable advanced control and monitoring capabilities, but they expose vehicles to cybersecurity threats and malicious control
Solution Approach 1:
The patent implements feedback mechanisms where the threat detector continuously monitors security incident data from connected vehicles and provides real-time alerts and recommendations. This feedback loop enables proactive identification of malicious activity and facilitates timely response to cybersecurity threats while maintaining the benefits of remote control capabilities.
Solution Approach 2:
The patent introduces a cybersecurity threat detector as an intermediary layer between the connected vehicles and external systems. This intermediary component analyzes telemetry data for malicious patterns, filters out false positives, and provides sanitized information for decision-making, thereby protecting vehicles from direct exposure to cyber threats while preserving remote control functionality.
Data Source
AI summary
A system and method for connected vehicle security incident integration. The method includes correlating a security incident violation with a connected vehicle, wherein the security incident violation is indicated in security incident data collected by at least one connected vehicle security system of the connected vehicle, wherein the security incident violation indicates a deviation from normal operation of the connected vehicle; enriching security incident data of a connected vehicle with cybersecurity data related to at least one of: the connected vehicle, and communications between the connected vehicle and at least one external system; generating a risk assessment for the connected vehicle based on the enriched violation data; and performing at least one mitigation action with respect to the connected vehicle based on the risk assessment.


