Cross-Device Event Detection via Log Correlation Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies struggle to detect events occurring across multiple devices, such as large-scale cyber-attacks, as individual analysis of device logs is insufficient to identify such cross-device events.

Innovation Solution

An analysis apparatus and system that collect and correlate log data from multiple devices, using a monitoring server to execute correlation analysis and detect events occurring across multiple vehicles or devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individual device log analysis is performed, then device-specific security events can be detected, but cross-device events such as large-scale cyber-attacks cannot be detected

Engineering Contradiction:
Improvedetection capabilityVSAvoidanalysis scope
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent merges log data from multiple devices by collecting logs from plurality of devices and storing them in a unified log database, enabling correlation analysis across devices to detect cross-device security events that individual analysis cannot identify

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a server as an intermediary that collects logs from multiple devices, performs correlation analysis, and generates detection results. This intermediary enables cross-device event detection without requiring direct peer-to-peer analysis between devices

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If correlation analysis across multiple devices is implemented, then cross-device events can be detected, but system complexity increases

Engineering Contradiction:
Improveevent detection accuracyVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security analysis system into distinct functional modules: log collection module, log storage module, correlation analysis module, and result generation module. This segmentation manages system complexity by organizing functions into separate, manageable components while enabling comprehensive cross-device analysis

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If logs from multiple devices are collected and analyzed, then large-scale cyber-attacks can be detected, but data processing volume increases

Engineering Contradiction:
Improvelog data volumeVSAvoidanalysis efficiency
Core Design Contradiction:
Quantity of substanceVSProductivity

Solution Approach 1:

The patent performs preliminary actions by collecting and storing logs from multiple devices in advance in a centralized log database before correlation analysis is needed. This preliminary log aggregation enables efficient correlation analysis when security events need to be detected, as the data is already prepared and organized

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3805928B1Analyzing device, analysis system, analysis method, and program
Publication Date: 2025.01.22 NT T INC
  • EP3805928B1 patent drawingFigure 1
  • EP3805928B1 patent drawingFigure 2
  • EP3805928B1 patent drawingFigure 3

AI summary

An analysis apparatus includes a receiver unit configured to receive log data transmitted from each device among a plurality of devices connected to a network, via the network; a determination unit configured to determine, for said each device, which one of a plurality of types of events corresponds to an event occurring in said each device, based on the log data transmitted from said each device; and a detection unit configured to detect an occurrence of events across the plurality of devices, based on a comparison of the log data of the plurality of devices related to a plurality of events of a same type of determination results as determined by the determination unit, to be capable of detecting events occurring across the plurality of devices.