Vehicle ECU Attack Analysis Using State Indicators and Anomaly Logs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies for analyzing cyberattacks on electronic control systems in vehicles lack accuracy in estimating attacks and are computationally inefficient.

Innovation Solution

An attack analysis device that utilizes a log acquisition unit, indicator acquisition unit, attack anomaly relation information storage, and attack estimation unit to estimate attacks based on security logs, indicators, and attack anomaly relation information, improving estimation accuracy and reducing computational load.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing technologies are used to analyze cyberattacks on electronic control systems, then attack analysis can be performed, but estimation accuracy is insufficient and computational load is high

Engineering Contradiction:
Improveattack estimation accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The attack analysis process is segmented into distinct functional units: log acquisition unit for collecting security logs, indicator acquisition unit for gathering vehicle state indicators, attack anomaly relation information storage for pre-stored attack patterns, and attack estimation unit for performing the actual estimation. This segmentation allows each unit to specialize in specific tasks, improving overall estimation accuracy while distributing computational load efficiently across the system architecture

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Attack anomaly relation information is pre-stored in the system, containing relationships between various attacks and their corresponding anomaly patterns. By preparing this reference data in advance, the attack estimation unit can perform rapid pattern matching during actual attack analysis without needing to compute complex relationships in real-time, thereby improving estimation accuracy while reducing computational complexity during operation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250220035A1Attack analysis device, attack analysis method, and storage medium thereof
Publication Date: 2025.07.03 DENSO CORP
  • US20250220035A1 patent drawing
  • US20250220035A1 patent drawing
  • US20250220035A1 patent drawing

AI summary

An attack analysis device includes a storage device storing attack anomaly relation information indicating a relation among (i) predicted attack information indicating an attack predicted to be received by an electronic control system, (ii) predicted anomaly information indicating an anomaly predicted to occur when the electronic control system receives the predicted attack, and (iii) predicted anomaly location information indicating a location within the electronic control system where the predicted anomaly occurs. The attack analysis device is configured to: acquire a security log indicating (i) an anomaly detected in the electronic control system and (ii) a location where the anomaly is detected; acquire an indicator indicating an internal state and/or external state of the mobile object when the anomaly occurs; estimate the received attack based on (i) the security log, (ii) the attack anomaly relation information, and (iii) the indicator; and output the attack information indicating the estimated attack.