Connected Vehicle Security Incident Integration via Aggregate Event Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing threat detection systems for connected vehicles are limited in their ability to process large quantities of data from different sources, leading to potential failures in detecting threats, mis-prioritization of threats, and inefficient processing of threats.

Innovation Solution

A method and system for integrating connected vehicle security incident data with contextual cybersecurity data, allowing for correlation of security incidents across multiple vehicles, enrichment of data with external cybersecurity information, generation of risk assessments, and performance of mitigation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing threat detectors collect and process data from individual connected vehicles, then they can detect threats based on vehicle-specific data, but they fail to detect threats that require cross-vehicle analysis and cannot accurately determine root causes

Engineering Contradiction:
Improvethreat detection accuracyVSAvoiddata processing scope
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges data from multiple connected vehicles into a unified processing system. The threat detector collects and correlates security incident data across different vehicles, combining individual vehicle data with aggregate event information to enable comprehensive threat analysis that cannot be achieved by examining single vehicles in isolation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent adds a new dimension of analysis by introducing cross-vehicle correlation capabilities. Instead of processing data from a single vehicle, the system now operates across multiple vehicles simultaneously, enabling detection of patterns and threats that span across the vehicle fleet and providing additional context for root cause analysis.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Quantity of substance

If existing threat detectors focus on processing large quantities of data from multiple sources, then they can improve data comprehensiveness, but they mis-prioritize threats and inefficiently process security incidents

Engineering Contradiction:
Improvedata volume processedVSAvoidthreat processing efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent implements preliminary actions by pre-establishing correlation rules and aggregation thresholds before threat analysis begins. The system pre-processes and organizes data from multiple vehicles according to predefined categories and priority levels, enabling efficient threat processing without requiring complex real-time decisions when analyzing large volumes of data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the complex task of processing large quantities of multi-source data into manageable components. It divides security incident data into distinct categories and priority levels, processes each segment according to its characteristics, and correlates them systematically, thereby improving overall processing efficiency while maintaining comprehensive data analysis.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If connected vehicles collect and transmit telemetry data remotely, then they enable advanced control and monitoring capabilities, but they expose vehicles to cybersecurity threats and malicious control

Engineering Contradiction:
Improveremote control capabilityVSAvoidcybersecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the threat detector continuously monitors security incident data from connected vehicles and provides real-time alerts and recommendations. This feedback loop enables proactive identification of malicious activity and facilitates timely response to cybersecurity threats while maintaining the benefits of remote control capabilities.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a cybersecurity threat detector as an intermediary layer between the connected vehicles and external systems. This intermediary component analyzes telemetry data for malicious patterns, filters out false positives, and provides sanitized information for decision-making, thereby protecting vehicles from direct exposure to cyber threats while preserving remote control functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12289322B2System and method for connected vehicle security incident integration based on aggregate events
Publication Date: 2025.04.29 UPSTREAM SECURITY LTD
  • US12289322B2 patent drawing
  • US12289322B2 patent drawing
  • US12289322B2 patent drawing

AI summary

A system and method for connected vehicle security incident integration. The method includes correlating a security incident violation with a connected vehicle, wherein the security incident violation is indicated in security incident data collected by at least one connected vehicle security system of the connected vehicle, wherein the security incident violation indicates a deviation from normal operation of the connected vehicle; enriching security incident data of a connected vehicle with cybersecurity data related to at least one of: the connected vehicle, and communications between the connected vehicle and at least one external system; generating a risk assessment for the connected vehicle based on the enriched violation data; and performing at least one mitigation action with respect to the connected vehicle based on the risk assessment.