Ethernet Frame Statistical Generator for Mobility Network Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current on-board network architectures using CAN and Ethernet combinations struggle to monitor overall traffic and detect anomalies in detail, as existing methods classify communication packets based solely on 5-tuples, failing to distinguish between different CAN messages within Ethernet frames, leading to incomplete traffic monitoring and anomaly analysis.
Innovation Solution
A statistical information generation device that collects and classifies Ethernet frames based on destination IP address, source IP address, destination port number, source port number, and protocol, along with mobility control-related identification information, to generate detailed statistical information for accurate anomaly detection and analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If Ethernet frames are classified based solely on 5-tuples (destination IP address, source IP address, destination port number, source port number, and protocol), then the classification process is simple and fast, but the traffic monitoring is incomplete and cannot distinguish between different CAN messages within Ethernet frames
Solution Approach 1:
The patent segments the classification process into two stages: first classification by 5-tuples for fast grouping, then secondary classification by CAN message identifiers within each group. This segmentation allows the system to maintain high processing speed while achieving complete traffic monitoring by examining CAN message details only when necessary.
Solution Approach 2:
The patent adds another dimension to the classification by incorporating CAN message identifier fields (such as extension identifier, identifier, and standard identifier) beyond the traditional 5-tuple classification. This multi-dimensional classification enables detailed traffic monitoring while maintaining efficiency through hierarchical processing.
2Loss of information
If detailed classification of Ethernet frames including CAN message identifiers is performed, then traffic monitoring completeness is improved, but the classification complexity and processing time increase
Solution Approach 1:
The classification process is segmented into hierarchical levels: Level 1 uses 5-tuple classification for broad grouping, Level 2 uses CAN message identifiers for detailed classification. This segmentation reduces overall complexity by processing frames in stages rather than examining all details simultaneously.
Solution Approach 2:
The system performs partial classification on all frames (5-tuple level) and excessive/detailed classification only when needed (CAN message identifier level). This approach balances complexity by applying detailed processing only to the extent necessary for complete traffic monitoring.
3Measurement precision
If statistical information is generated for each detailed group of Ethernet frames with same CAN message identifiers, then anomaly detection precision is improved, but the information processing load increases
Solution Approach 1:
The statistical information generation is segmented by classification level: aggregate statistics are generated at the 5-tuple level for all frames, while detailed statistics are generated at the CAN message identifier level only for grouped frames. This segmentation reduces processing load while maintaining high anomaly detection precision through multi-level statistical analysis.
Solution Approach 2:
The system performs partial statistical generation at the aggregate level and excessive/detailed statistical generation only where needed for anomaly detection. This approach optimizes energy usage by applying detailed processing only to the extent necessary for precise anomaly detection.
Data Source
AI summary
A statistical information generation device that generates statistical information from Ethernet frames on a mobility network includes: a transceiver that transmits and receives the Ethernet frames; and a statistical information generator that collects a plurality of Ethernet frames transmitted or received by the transceiver within a predetermined time period, and classifies, out of the plurality of Ethernet frames collected, Ethernet frames containing the same destination IP address, source IP address, destination port number, source port number, and protocol, and containing, in payloads, same identification information related to mobility control, into the same group, generates the statistical information for each group from the Ethernet frames classified into groups, and transmits the generated statistical information from the transceiver.


