Dynamic Cyber Attack Detection Criteria for Vehicle ECU
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cyber attack detection systems for vehicles lack the ability to dynamically adjust detection criteria based on the vehicle's situation, leading to potential overlooking of attacks with high impact, especially when the vehicle is in a high-risk environment.
Innovation Solution
A log determination device and support device that dynamically set and adjust detection criteria based on the vehicle's risk situation, using a risk determination unit to assess the risk degree and a determination criterion setting unit to adjust the detection process accordingly, incorporating a prediction table and abnormality logs to determine attack reception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fixed detection criteria are used for cyber attack detection, then the detection system is simple to implement, but it may overlook attacks with high impact when the vehicle is in high-risk environments
Solution Approach 1:
The patent implements dynamic detection criteria that automatically adjust based on the vehicle's current situation and risk level. The system transitions from static, fixed thresholds to dynamic thresholds that are modified in real-time according to contextual factors such as vehicle state, environment, and threat level, thereby improving detection reliability without requiring completely separate detection systems for different scenarios
Solution Approach 2:
The system changes detection parameters (thresholds, sensitivity levels, criterion weights) based on the assessed risk degree. When the vehicle is in a high-risk environment, the system adjusts detection parameters to become more sensitive and stringent, whereas in low-risk environments, parameters are relaxed. This allows a single detection system to adapt its behavior to match the current threat landscape
2Measurement precision
If detection criteria are adjusted dynamically based on vehicle situation, then the sensitivity of attack detection is improved, but the complexity of the detection system increases
Solution Approach 1:
The system performs preliminary assessment of the vehicle's situation and risk level before executing the actual attack detection. By pre-evaluating contextual factors and determining the appropriate risk degree in advance, the system can then apply pre-configured detection criteria corresponding to that risk level, reducing the computational complexity during the actual detection process while maintaining high sensitivity
Solution Approach 2:
The system modifies detection parameters such as sensitivity thresholds, criterion weights, and evaluation metrics based on the assessed risk degree. This allows the same detection infrastructure to achieve different levels of sensitivity by simply changing parameters rather than restructuring the entire detection algorithm, thereby improving measurement precision with controlled increases in complexity
3Reliability
If comprehensive risk assessment and dynamic criterion adjustment are implemented, then the likelihood of overlooking attacks is reduced, but the processing time and computational resources increase
Solution Approach 1:
The system performs risk assessment and determines appropriate detection criteria in advance, before actual attack detection is needed. By pre-evaluating the vehicle's operational context, historical data, and threat landscape, and by pre-configuring the corresponding detection criteria, the system minimizes the computational burden during real-time detection, thus reducing processing time while maintaining comprehensive assessment capabilities
Solution Approach 2:
The detection process is segmented into distinct phases: risk assessment phase, criterion selection phase, and actual detection phase. Each phase operates with specific, optimized algorithms appropriate to its function. This segmentation allows the system to perform comprehensive risk assessment without burdening the real-time detection process, thereby maintaining high reliability while controlling processing time
Data Source
AI summary
By a log determination device, a log determination method, a non-transitory computer-readable storage medium storing a log determination program, a log determination support device, a log determination support method, or a non-transitory computer-readable storage medium storing a log determination support program, a risk degree of attack reception by an electronic control system mounted on a mobile object is determined, whether the electronic control system has received the attack is determined.


