Control Device Security Malfunction Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for gathering attack information from onboard LANs fail to accurately distinguish between genuine security attacks and false alarms caused by circuit malfunctions in message authentication and firewalls, leading to increased communication costs and resource wastage.
Innovation Solution
A determination device that communicates with a control device using both non-conforming and conforming information to the firewall rules to determine the device's state, excluding false detections by ascertaining the control device's normal or malfunctioning state through specific notifications, thereby reducing unnecessary information acquisition and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If attack information is gathered from control device using firewall and message authentication, then security attack detection capability is improved, but false detections increase due to circuit malfunctions
Solution Approach 1:
The determination device performs preliminary actions by sending first information (non-conforming to firewall rules) and second information (conforming to firewall rules) before gathering attack information, to pre-determine whether the control device is in a normal state or malfunction state. This preliminary determination prevents false detections by identifying circuit malfunctions before they contaminate the attack information gathering process.
Solution Approach 2:
The determination device acts as an intermediary between the information gathering device and the control device. It sends test information to the control device and determines the device state based on responses, thereby mediating the information flow and preventing malformed data from reaching the information gathering device. This intermediary function filters out false detections caused by control device malfunctions.
2Reliability
If attack information is gathered from all control devices, then comprehensive security monitoring is improved, but communication costs and resource expenditure increase due to processing false detections
Solution Approach 1:
The determination device extracts and identifies the essential characteristic that distinguishes genuine security attacks from false detections by analyzing the control device's response to test information. It separates valid attack information from false detections caused by circuit malfunctions, extracting only the necessary information for accurate security monitoring while discarding false data that would waste communication and analysis resources.
Solution Approach 2:
Before comprehensive attack information gathering is performed, the determination device executes preliminary determination actions by sending test information and evaluating control device responses. This preliminary action identifies which control devices are functioning normally and can provide valid attack information, thereby preventing unnecessary communication and resource expenditure on malfunctioning devices that would generate false detections.
3Ease of operation
If determination is made based on single type of information, then processing simplicity is improved, but detection accuracy decreases due to inability to distinguish malfunction states
Solution Approach 1:
The determination process is segmented into distinct stages: sending first information (non-conforming to firewall rules) to detect obvious malfunctions, and sending second information (conforming to firewall rules) to verify normal operation. Each segment targets specific aspects of control device functionality, and the combination of results from both segments provides accurate determination of the control device state while maintaining clear, manageable processing steps.
Data Source
AI summary
A determination device includes a processor. The processor being configured to: send first information that is not conforming to a rule of a firewall to a control device, execute first determination processing in which the control device is determined to be in a malfunction state in a case in which a first notification acquired from the control device is a normal notification, and the control device is determined to be in a normal state in a case in which the first notification is an abnormal notification, additionally send second information conforming to the rule to the control device in a case in which the control device has been determined to be in a normal state, and execute second determination processing in which the control device is determined to be in a normal state in a case in which a second notification acquired from the control device is the normal notification.


