Decoy Server for Anomalous Communication Detection in Vehicular Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service-oriented communication systems in vehicles face challenges in detecting reconnaissance attacks without causing a performance penalty, as existing intrusion detection approaches are computationally expensive and difficult to implement without altering existing middleware.

Innovation Solution

Implementing a decoy server that hosts decoy services within the service-oriented communication system, allowing for detection of anomalous communications by responding to requests from potential intruders without affecting the existing network's performance, and transmitting intrusion alerts to a detection server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing intrusion detection approaches are implemented in service-oriented communication systems, then security monitoring capability is improved, but computational cost and system performance penalty increase

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidcomputational cost
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a decoy service as an intermediary element within the service-oriented communication system. This decoy service acts as a mediator that attracts and detects intrusion attempts without requiring the main system components to perform computationally expensive security monitoring. The decoy service absorbs the computational burden of intrusion detection, allowing legitimate ECUs to maintain their primary functions without performance degradation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy or replica of a legitimate service (the decoy service) that mimics the behavior and interface of real services in the system. This copied service is specifically designed to be targeted by intruders, allowing the system to detect intrusion attempts by monitoring interactions with the decoy copy rather than analyzing all communications across the entire system, thereby reducing computational requirements.

Inventive Principle:
Principle #26Copying

2Reliability

If security monitoring is integrated into existing middleware components, then intrusion detection capability is improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the intrusion detection function from the existing middleware components and isolates it within a dedicated decoy service. This segmentation allows the security monitoring capability to be implemented independently without modifying or complicating the existing middleware architecture. The decoy service operates as a separate, self-contained module that can be added to the system without increasing the complexity of core communication infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The decoy service is designed to be self-sufficient in performing intrusion detection tasks. It independently manages its own service registration, interaction monitoring, and anomaly detection without requiring existing middleware components to perform security monitoring tasks. This self-service approach eliminates the need for complex integration with existing security infrastructure and reduces implementation difficulty.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If decoy services are deployed to detect reconnaissance attacks, then intrusion detection accuracy is improved, but system resource usage increases

Engineering Contradiction:
Improveintrusion detection accuracyVSAvoidsystem resource usage
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies local quality by concentrating intrusion detection resources specifically at the decoy service location rather than distributing monitoring across all system components. The decoy service is locally optimized to handle intrusion detection with high accuracy, while other parts of the system maintain their original resource usage patterns. This localized approach improves detection accuracy without proportionally increasing overall system resource consumption.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11979269B2Detecting anomalous communications
Publication Date: 2024.05.07 ROBERT BOSCH GMBH
  • US11979269B2 patent drawing
  • US11979269B2 patent drawing
  • US11979269B2 patent drawing

AI summary

A computer-implemented method for detecting anomalous communications in a service oriented communication system. The method includes providing at least one decoy service, hosted by a decoy server communicably coupled to the service oriented communication system, wherein the at least one decoy service is addressable using a corresponding decoy service identifier; detecting, at the decoy server, a request to consume at least one instance of the at least one decoy service, wherein the request originates from a client communicably coupled to the decoy server via the service oriented communication system; and performing, at the decoy server, a response to the request to consume the at least one instance of the at least one decoy service.