Decoy Server for Anomalous Communication Detection in Vehicular Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service-oriented communication systems in vehicles face challenges in detecting reconnaissance attacks without causing a performance penalty, as existing intrusion detection approaches are computationally expensive and difficult to implement without altering existing middleware.
Innovation Solution
Implementing a decoy server that hosts decoy services within the service-oriented communication system, allowing for detection of anomalous communications by responding to requests from potential intruders without affecting the existing network's performance, and transmitting intrusion alerts to a detection server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing intrusion detection approaches are implemented in service-oriented communication systems, then security monitoring capability is improved, but computational cost and system performance penalty increase
Solution Approach 1:
The patent introduces a decoy service as an intermediary element within the service-oriented communication system. This decoy service acts as a mediator that attracts and detects intrusion attempts without requiring the main system components to perform computationally expensive security monitoring. The decoy service absorbs the computational burden of intrusion detection, allowing legitimate ECUs to maintain their primary functions without performance degradation.
Solution Approach 2:
The patent creates a copy or replica of a legitimate service (the decoy service) that mimics the behavior and interface of real services in the system. This copied service is specifically designed to be targeted by intruders, allowing the system to detect intrusion attempts by monitoring interactions with the decoy copy rather than analyzing all communications across the entire system, thereby reducing computational requirements.
2Reliability
If security monitoring is integrated into existing middleware components, then intrusion detection capability is improved, but system complexity and implementation difficulty increase
Solution Approach 1:
The patent segments the intrusion detection function from the existing middleware components and isolates it within a dedicated decoy service. This segmentation allows the security monitoring capability to be implemented independently without modifying or complicating the existing middleware architecture. The decoy service operates as a separate, self-contained module that can be added to the system without increasing the complexity of core communication infrastructure.
Solution Approach 2:
The decoy service is designed to be self-sufficient in performing intrusion detection tasks. It independently manages its own service registration, interaction monitoring, and anomaly detection without requiring existing middleware components to perform security monitoring tasks. This self-service approach eliminates the need for complex integration with existing security infrastructure and reduces implementation difficulty.
3Measurement precision
If decoy services are deployed to detect reconnaissance attacks, then intrusion detection accuracy is improved, but system resource usage increases
Solution Approach 1:
The patent applies local quality by concentrating intrusion detection resources specifically at the decoy service location rather than distributing monitoring across all system components. The decoy service is locally optimized to handle intrusion detection with high accuracy, while other parts of the system maintain their original resource usage patterns. This localized approach improves detection accuracy without proportionally increasing overall system resource consumption.
Data Source
AI summary
A computer-implemented method for detecting anomalous communications in a service oriented communication system. The method includes providing at least one decoy service, hosted by a decoy server communicably coupled to the service oriented communication system, wherein the at least one decoy service is addressable using a corresponding decoy service identifier; detecting, at the decoy server, a request to consume at least one instance of the at least one decoy service, wherein the request originates from a client communicably coupled to the decoy server via the service oriented communication system; and performing, at the decoy server, a response to the request to consume the at least one instance of the at least one decoy service.


