Cyber Watchman Network Attack Period Determination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle safety systems face challenges in efficiently extracting the period of a network attack from massive communication traffic data, leading to increased processing loads for cyber hubs.
Innovation Solution
An information processing device that includes an obtainer for detecting anomalies, an occurrence time determiner, an end time determiner, and a condition determiner to record and manage detection logs, allowing for the automatic determination of attack occurrence and expected end times, thereby reducing processing loads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If the cyber hub collects and processes all communication traffic data from vehicles to identify attack periods, then the accuracy of attack period identification is improved, but the processing load on the cyber hub increases significantly
Solution Approach 1:
The system divides the attack period identification task into two segments: (1) The in-vehicle cyber watchman performs preliminary analysis of communication traffic data to generate detection logs with anomaly information and timestamps; (2) The cyber hub receives these pre-processed logs and determines attack periods by comparing occurrence times and end conditions. This segmentation reduces the cyber hub's processing load while maintaining identification accuracy.
Solution Approach 2:
The cyber watchman performs preliminary processing of communication traffic data by continuously monitoring anomalies and generating detection logs that include occurrence times, end conditions, and attack type information. This preliminary action prepares the data in advance, so when the cyber hub receives the logs, the attack period can be determined directly without requiring the hub to process raw communication traffic data, thereby reducing processing load.
2Speed
If the system monitors all communication traffic data in real-time to detect anomalies, then the detection speed of attacks is improved, but the complexity of the monitoring system increases
Solution Approach 1:
The cyber watchman acts as an intermediary device installed in each vehicle that continuously monitors communication traffic data and detects anomalies. It generates detection logs containing occurrence times, end conditions, and attack type information. This intermediary approach enables real-time detection without requiring the cyber hub to directly process all raw data, thus maintaining detection speed while reducing overall system complexity.
Solution Approach 2:
The cyber watchman autonomously performs anomaly detection, log generation, and preliminary analysis of communication traffic data without requiring constant intervention from the cyber hub. It independently identifies attacks, determines their characteristics, and transmits only essential information to the hub, enabling self-service operation that maintains fast detection while simplifying the centralized system's complexity.
3Measurement precision
If the cyber hub processes raw communication traffic data to determine attack occurrence and end times, then the precision of attack period determination is improved, but the time required for analysis increases
Solution Approach 1:
The cyber watchman performs preliminary analysis by continuously monitoring communication traffic and pre-calculating key parameters including occurrence time, end condition, and attack type. These pre-computed values are stored in detection logs and transmitted to the cyber hub. This preliminary action eliminates the need for the hub to re-analyze raw data, achieving precise attack period determination without time-consuming processing.
Solution Approach 2:
The system extracts only the essential information needed for attack period determination (occurrence time, end condition, attack type) from the communication traffic data at the cyber watchman level. These extracted key parameters are transmitted to the cyber hub, which then determines attack periods by comparing these pre-extracted values rather than processing entire data sets, thereby achieving precision without time loss.
Data Source
AI summary
An information processing device includes: an obtainer that obtains, from an anomaly detection sensor that detects an anomaly in a network, a detection log related to the anomaly in the network and the detection time of the anomaly indicated in the detection log; an occurrence time determiner that determines the occurrence time of an attack on the network based on the obtained detection time, and records the determined occurrence time; and an end time determiner that determines the expected end time of the attack on the network based on the obtained detection log, and records the determined expected end time.


