Intrusion Path Analysis for In-Vehicle Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for enhancing in-vehicle network security, such as those using cryptographic communication and domain separation, are inadequate for identifying the intrusion path of attacks, making it difficult to effectively countermeasure and protect against unauthorized control of vehicles.
Innovation Solution
An intrusion path analysis device and method that connect to a control network system via a network, utilizing security sensors to detect breaches, and analyze intrusion paths based on security alerts, event histories, and intrusion depth to output detailed analysis results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security methods (cryptographic communication, domain separation) are used to protect the in-vehicle network, then security protection is improved, but the ability to identify intrusion paths deteriorates
Solution Approach 1:
The patent introduces a security information management system as an intermediary component that collects, manages, and analyzes security information from multiple sources without interfering with the normal security protection mechanisms. This intermediary system enables intrusion path identification by aggregating security events, alerts, and logs while maintaining the effectiveness of cryptographic communication and domain separation.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring security events, analyzing intrusion patterns, and providing actionable intelligence back to the security protection systems. This feedback loop enables dynamic adjustment of security measures and improves the ability to identify and respond to intrusion paths while maintaining security protection.
2Difficulty of detecting and measuring
If security monitoring is enhanced to detect attacks, then detection capability is improved, but system complexity increases
Solution Approach 1:
The security information management system is designed with multi-functionality, serving as a centralized platform that performs multiple security tasks including data collection, analysis, storage, and response coordination. This universal approach consolidates multiple security functions into a single system, improving detection capability while managing complexity through integration rather than proliferation of separate components.
Solution Approach 2:
The patent merges multiple security information sources, analysis functions, and response mechanisms into a unified security information management system. By combining data collection from various sensors, event log analysis, alert management, and intrusion path identification into a single integrated system, the patent enhances detection capability while avoiding the complexity increase that would result from multiple separate systems.
Data Source
AI summary
The control network system is connected to electronic control unit(s) and a communication device, and includes security sensor(s) that transmits a security alert indicating that an indication of a security breach is detected to the network, if the indication is detected in at least one of the network, the electronic control unit(s), or the communication device. The intrusion path analysis device includes: an alert obtainer that obtains the security alert from the security sensor(s); an event obtainer that obtains an event history of an event that occurs in the control network system; and an intrusion path analyzer that performs an analysis on an intrusion path of an attack on the basis of the security alert, the event history, and an intrusion depth indicating an intrusion level to be assumed in a case the security alert occurs, and that outputs a result of the analysis.


