Vehicle ECU Security Log Packaging for Accurate Attack Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attack identification methods in vehicles lack clear specifications for grouping security logs, leading to inefficiencies in analysis and reduced detection accuracy of cyberattacks.
Innovation Solution
An attack analysis device that acquires security logs from multiple electronic control units, packages them into log packages based on specific rules, and estimates attacks using an attack abnormality relationship table to improve detection accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security logs from multiple electronic control units are analyzed individually without grouping, then the analysis process is simple, but the detection accuracy of cyberattacks is reduced
Solution Approach 1:
The patent segments security logs into grouped packages based on temporal proximity and source relationships. Instead of analyzing individual logs in isolation, the system clusters logs that occur within predetermined time windows and share common characteristics (same source ECU, related event types), creating structured packages that preserve contextual relationships while maintaining analytical tractability.
Solution Approach 2:
The patent introduces a new dimension of analysis by organizing logs into packages with multiple attributes (time stamps, source identifiers, event types, severity levels). This multi-dimensional packaging approach transforms flat individual log entries into structured composite objects that capture relationships across different dimensions, enabling more accurate attack detection without linearly increasing complexity.
2Measurement precision
If security logs are grouped into packages with detailed rules, then the detection accuracy is improved, but the processing time and complexity increase
Solution Approach 1:
The patent performs preliminary actions by pre-defining packaging rules and time window parameters before actual attack detection. The system establishes predetermined criteria for log grouping (time thresholds, source relationships, event type correlations) in advance, so that during runtime, logs can be quickly assigned to appropriate packages without complex real-time decision-making, reducing processing time while maintaining detection accuracy.
Solution Approach 2:
The patent utilizes parameter changes by adjusting packaging granularity and time window sizes based on different attack scenarios and system configurations. The system can dynamically modify parameters such as the time threshold for grouping, the number of logs per package, and the specificity of source matching, allowing optimization of the balance between detection accuracy and processing speed for different operational contexts.
Data Source
AI summary
An attack analysis device acquires a security log generated by a security sensor mounted on each of a plurality of electronic control units configuring an electronic control system, sets a log package in which a plurality of the security logs are packaged, estimates an attack received by the electronic control system based on the log package, and outputs attack information indicating the estimated attack.


