Vehicle Log Anomaly Scoring Using Fleet Statistics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing in-vehicle networks, such as those using encrypted communication and anomaly detection, face challenges in effectively preventing unauthorized control and detecting reverse engineering attempts, leading to potential security vulnerabilities.
Innovation Solution
An anomalous vehicle detection server that analyzes vehicle logs to identify suspicious behavior and calculates an anomaly score, determining whether a vehicle is anomalous based on its own score and statistical values from other vehicles, thereby enhancing network security by identifying and mitigating potential attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication is used to prevent unauthorized control, then security is improved, but communication overhead increases and key management complexity increases
Solution Approach 1:
The patent introduces a server as an intermediary that performs anomaly detection on vehicle logs externally. This mediator handles the complex analysis work, allowing the in-vehicle system to use simpler communication protocols without encryption while still achieving security through centralized monitoring and anomaly detection.
2Reliability
If anomaly detection is implemented in the in-vehicle network, then unauthorized frames can be blocked, but the system can only respond to anomalies rather than prevent attacks
Solution Approach 1:
The patent performs preliminary anomaly detection by analyzing vehicle logs before attacks can fully execute. The server detects suspicious patterns in advance and can notify vehicles to take preventive measures, shifting from reactive blocking to proactive prevention of unauthorized control.
3Measurement precision
If comprehensive monitoring of all vehicles is performed, then detection accuracy is improved, but data processing requirements and system complexity increase
Solution Approach 1:
The patent merges the anomaly detection functionality into a centralized server that collects and analyzes logs from multiple vehicles. This consolidation allows comprehensive monitoring of all vehicles to improve detection accuracy through statistical comparison, while the server handles the complex data processing externally rather than requiring complex processing in each vehicle.
Data Source
AI summary
An anomalous vehicle detection server includes an anomaly score calculator that detects a suspicious behavior different from a predetermined driving behavior based on pieces of vehicle information that are received from a plurality of vehicles, respectively, and are each based on a vehicle log including the content of an event that has occurred in a vehicle system provided in the vehicle, and acquires an anomaly score of each of the plurality of vehicles that indicates a likelihood that reverse engineering is performed on the vehicle; and an anomalous vehicle determiner that determines whether one vehicle of the plurality of vehicles is an anomalous vehicle based on the anomaly score of the one vehicle and a statistical value of the anomaly scores of two or more vehicles of the plurality of vehicles.


