Cross-Device Event Detection via Log Correlation Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies struggle to detect events occurring across multiple devices, such as large-scale cyber-attacks, as individual analysis of device logs is insufficient to identify such cross-device events.
Innovation Solution
An analysis apparatus and system that collect and correlate log data from multiple devices, using a monitoring server to execute correlation analysis and detect events occurring across multiple vehicles or devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If individual device log analysis is performed, then device-specific security events can be detected, but cross-device events such as large-scale cyber-attacks cannot be detected
Solution Approach 1:
The patent merges log data from multiple devices by collecting logs from plurality of devices and storing them in a unified log database, enabling correlation analysis across devices to detect cross-device security events that individual analysis cannot identify
Solution Approach 2:
The patent introduces a server as an intermediary that collects logs from multiple devices, performs correlation analysis, and generates detection results. This intermediary enables cross-device event detection without requiring direct peer-to-peer analysis between devices
2Reliability
If correlation analysis across multiple devices is implemented, then cross-device events can be detected, but system complexity increases
Solution Approach 1:
The patent segments the security analysis system into distinct functional modules: log collection module, log storage module, correlation analysis module, and result generation module. This segmentation manages system complexity by organizing functions into separate, manageable components while enabling comprehensive cross-device analysis
3Quantity of substance
If logs from multiple devices are collected and analyzed, then large-scale cyber-attacks can be detected, but data processing volume increases
Solution Approach 1:
The patent performs preliminary actions by collecting and storing logs from multiple devices in advance in a centralized log database before correlation analysis is needed. This preliminary log aggregation enables efficient correlation analysis when security events need to be detected, as the data is already prepared and organized
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An analysis apparatus includes a receiver unit configured to receive log data transmitted from each device among a plurality of devices connected to a network, via the network; a determination unit configured to determine, for said each device, which one of a plurality of types of events corresponds to an event occurring in said each device, based on the log data transmitted from said each device; and a detection unit configured to detect an occurrence of events across the plurality of devices, based on a comparison of the log data of the plurality of devices related to a plurality of events of a same type of determination results as determined by the determination unit, to be capable of detecting events occurring across the plurality of devices.