In-Vehicle Attack Response Control by Penetration Depth
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vehicle systems face challenges in adapting control responses effectively to various attack scenarios due to obsolete defense functions and evolving attack methods, particularly in connected cars that remain online for extended periods.
Innovation Solution
A vehicle system that includes a controller capable of dynamically changing communication methods, defense strategies, and log storage approaches based on the depth of penetration of malicious attacks, allowing for adaptive control by switching between different in-vehicle apparatuses and communication channels to mitigate attack effects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the vehicle system uses fixed defense functions and control responses, then the system structure is simple and easy to implement, but the system cannot adapt to evolving attack methods and obsolete defense functions
Solution Approach 1:
The patent implements dynamic control responses that change based on the detected attack scenario. The controller selects from multiple predefined control responses (first through fifth) depending on the type and severity of attack detected, transforming a static defense system into a dynamic one that adapts to different threat levels and attack vectors.
Solution Approach 2:
The system changes operational parameters such as communication methods, log storage locations, and control responses based on the detected attack scenario. For example, it may switch between different communication channels, move log storage to secure locations, or implement specific control actions like disabling certain functions or isolating affected systems.
2Reliability
If the vehicle system implements adaptive control with multiple defense strategies, then the system can respond effectively to various attack scenarios, but the control logic becomes complex
Solution Approach 1:
The patent pre-defines multiple control responses (first through fifth control responses) for different attack scenarios before deployment. The anomaly detector identifies attack patterns and matches them to predefined responses, eliminating the need for complex real-time decision algorithms and simplifying the control logic while maintaining adaptability.
Solution Approach 2:
The system continuously monitors for anomalies and attacks, detects the type and severity of the threat, and adjusts control responses accordingly. This closed-loop feedback mechanism allows the system to adapt to evolving attacks while using structured, predefined response protocols that manage complexity.
3Reliability
If the system continuously monitors and adapts to attacks, then the security response is effective, but the processing time and computational resources increase
Solution Approach 1:
The system pre-identifies potential attack scenarios and prepares corresponding control responses in advance. When an anomaly is detected, the system matches it against predefined patterns and executes the corresponding pre-prepared response, significantly reducing processing time compared to generating responses in real-time.
Solution Approach 2:
The system implements monitoring and adaptive control at strategic points in the architecture rather than continuously analyzing all data streams. The anomaly detector focuses on specific indicators of compromise and attack patterns, enabling effective security response with reduced computational overhead and processing time.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A vehicle system (100) is a vehicle system used for a vehicle, and includes: a plurality of in-vehicle apparatuses (110) installed in the vehicle; and a controller (120) that, in accordance with a depth of penetration of a malicious attack carried out on the plurality of in-vehicle apparatuses (110), changes at least one of a communication method with an outside of the vehicle, a defense method against the malicious attack, or a storage method for logs pertaining to the plurality of in-vehicle apparatuses (110).