Ethernet Frame Statistical Generator for Mobility Network Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current on-board network architectures using CAN and Ethernet combinations struggle to monitor overall traffic and detect anomalies in detail, as existing methods classify communication packets based solely on 5-tuples, failing to distinguish between different CAN messages within Ethernet frames, leading to incomplete traffic monitoring and anomaly analysis.

Innovation Solution

A statistical information generation device that collects and classifies Ethernet frames based on destination IP address, source IP address, destination port number, source port number, and protocol, along with mobility control-related identification information, to generate detailed statistical information for accurate anomaly detection and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If Ethernet frames are classified based solely on 5-tuples (destination IP address, source IP address, destination port number, source port number, and protocol), then the classification process is simple and fast, but the traffic monitoring is incomplete and cannot distinguish between different CAN messages within Ethernet frames

Engineering Contradiction:
Improveclassification speedVSAvoidtraffic monitoring completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments the classification process into two stages: first classification by 5-tuples for fast grouping, then secondary classification by CAN message identifiers within each group. This segmentation allows the system to maintain high processing speed while achieving complete traffic monitoring by examining CAN message details only when necessary.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds another dimension to the classification by incorporating CAN message identifier fields (such as extension identifier, identifier, and standard identifier) beyond the traditional 5-tuple classification. This multi-dimensional classification enables detailed traffic monitoring while maintaining efficiency through hierarchical processing.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Loss of information

If detailed classification of Ethernet frames including CAN message identifiers is performed, then traffic monitoring completeness is improved, but the classification complexity and processing time increase

Engineering Contradiction:
Improvetraffic monitoring completenessVSAvoidclassification process complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The classification process is segmented into hierarchical levels: Level 1 uses 5-tuple classification for broad grouping, Level 2 uses CAN message identifiers for detailed classification. This segmentation reduces overall complexity by processing frames in stages rather than examining all details simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial classification on all frames (5-tuple level) and excessive/detailed classification only when needed (CAN message identifier level). This approach balances complexity by applying detailed processing only to the extent necessary for complete traffic monitoring.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If statistical information is generated for each detailed group of Ethernet frames with same CAN message identifiers, then anomaly detection precision is improved, but the information processing load increases

Engineering Contradiction:
Improveanomaly detection precisionVSAvoidinformation processing load
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The statistical information generation is segmented by classification level: aggregate statistics are generated at the 5-tuple level for all frames, while detailed statistics are generated at the CAN message identifier level only for grouped frames. This segmentation reduces processing load while maintaining high anomaly detection precision through multi-level statistical analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial statistical generation at the aggregate level and excessive/detailed statistical generation only where needed for anomaly detection. This approach optimizes energy usage by applying detailed processing only to the extent necessary for precise anomaly detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11818024B2Statistical information generation device, statistical information generation method, and recording medium
Publication Date: 2023.11.14 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US11818024B2 patent drawing
  • US11818024B2 patent drawing
  • US11818024B2 patent drawing

AI summary

A statistical information generation device that generates statistical information from Ethernet frames on a mobility network includes: a transceiver that transmits and receives the Ethernet frames; and a statistical information generator that collects a plurality of Ethernet frames transmitted or received by the transceiver within a predetermined time period, and classifies, out of the plurality of Ethernet frames collected, Ethernet frames containing the same destination IP address, source IP address, destination port number, source port number, and protocol, and containing, in payloads, same identification information related to mobility control, into the same group, generates the statistical information for each group from the Ethernet frames classified into groups, and transmits the generated statistical information from the transceiver.