Dynamic Cyber Attack Detection Criteria for Vehicle ECU

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber attack detection systems for vehicles lack the ability to dynamically adjust detection criteria based on the vehicle's situation, leading to potential overlooking of attacks with high impact, especially when the vehicle is in a high-risk environment.

Innovation Solution

A log determination device and support device that dynamically set and adjust detection criteria based on the vehicle's risk situation, using a risk determination unit to assess the risk degree and a determination criterion setting unit to adjust the detection process accordingly, incorporating a prediction table and abnormality logs to determine attack reception.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fixed detection criteria are used for cyber attack detection, then the detection system is simple to implement, but it may overlook attacks with high impact when the vehicle is in high-risk environments

Engineering Contradiction:
Improveattack detection reliabilityVSAvoiddetection system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic detection criteria that automatically adjust based on the vehicle's current situation and risk level. The system transitions from static, fixed thresholds to dynamic thresholds that are modified in real-time according to contextual factors such as vehicle state, environment, and threat level, thereby improving detection reliability without requiring completely separate detection systems for different scenarios

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes detection parameters (thresholds, sensitivity levels, criterion weights) based on the assessed risk degree. When the vehicle is in a high-risk environment, the system adjusts detection parameters to become more sensitive and stringent, whereas in low-risk environments, parameters are relaxed. This allows a single detection system to adapt its behavior to match the current threat landscape

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If detection criteria are adjusted dynamically based on vehicle situation, then the sensitivity of attack detection is improved, but the complexity of the detection system increases

Engineering Contradiction:
Improveattack detection sensitivityVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary assessment of the vehicle's situation and risk level before executing the actual attack detection. By pre-evaluating contextual factors and determining the appropriate risk degree in advance, the system can then apply pre-configured detection criteria corresponding to that risk level, reducing the computational complexity during the actual detection process while maintaining high sensitivity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system modifies detection parameters such as sensitivity thresholds, criterion weights, and evaluation metrics based on the assessed risk degree. This allows the same detection infrastructure to achieve different levels of sensitivity by simply changing parameters rather than restructuring the entire detection algorithm, thereby improving measurement precision with controlled increases in complexity

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive risk assessment and dynamic criterion adjustment are implemented, then the likelihood of overlooking attacks is reduced, but the processing time and computational resources increase

Engineering Contradiction:
Improveattack detection reliabilityVSAvoiddetection processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs risk assessment and determines appropriate detection criteria in advance, before actual attack detection is needed. By pre-evaluating the vehicle's operational context, historical data, and threat landscape, and by pre-configuring the corresponding detection criteria, the system minimizes the computational burden during real-time detection, thus reducing processing time while maintaining comprehensive assessment capabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection process is segmented into distinct phases: risk assessment phase, criterion selection phase, and actual detection phase. Each phase operates with specific, optimized algorithms appropriate to its function. This segmentation allows the system to perform comprehensive risk assessment without burdening the real-time detection process, thereby maintaining high reliability while controlling processing time

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240422546A1Log determination device, log determination method, log determination program, log determination support device, log determination support method, and log determination support program
Publication Date: 2024.12.19 DENSO CORP
  • US20240422546A1 patent drawing
  • US20240422546A1 patent drawing
  • US20240422546A1 patent drawing

AI summary

By a log determination device, a log determination method, a non-transitory computer-readable storage medium storing a log determination program, a log determination support device, a log determination support method, or a non-transitory computer-readable storage medium storing a log determination support program, a risk degree of attack reception by an electronic control system mounted on a mobile object is determined, whether the electronic control system has received the attack is determined.