In-Vehicle Network Anomaly Detection via Session Model Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern in-vehicle communication networks are vulnerable to cyber-attacks and faults due to their complexity, making it difficult to detect and identify malicious activities or anomalies during diagnostic sessions, which can compromise vehicle safety and performance.

Innovation Solution

Implementing a system that tracks and compares transfer session messages against a session model to detect anomalous sessions by monitoring communications over the network and performing actions such as logging, blocking, or alerting when deviations from expected behavior are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the in-vehicle communication network supports a large number of electronic control systems and sensors, then the functionality and versatility of the vehicle is improved, but the vulnerability to cyber-attacks and faults increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidvulnerability to cyber-attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary anomaly detection system that sits between the electronic control systems and the communication network. This intermediary monitors and analyzes diagnostic messages (UDS protocols) to detect anomalies without disrupting the normal communication between control systems and sensors, thus maintaining functionality while reducing vulnerability to cyber-attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the complexity of the in-vehicle network increases to support more control systems, then the versatility is improved, but the difficulty of detecting and measuring anomalies increases

Engineering Contradiction:
ImproveversatilityVSAvoiddifficulty of detecting anomalies
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extracts the anomaly detection function from the complex network of electronic control systems by implementing a separate, dedicated anomaly detection system. This extracted component specifically monitors diagnostic messages and session states, making anomaly detection easier without adding complexity to the existing control systems

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The anomaly detection system implements feedback mechanisms by continuously monitoring diagnostic messages and comparing them against expected session states. When anomalies are detected, the system provides feedback through alerts and logs, enabling timely detection and response to security threats in the complex network

Inventive Principle:
Principle #23Feedback

3Reliability

If real-time monitoring and anomaly detection is implemented, then the security is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the anomaly detection functionality into distinct components: session state tracking, message analysis, anomaly detection logic, and alert generation. This segmentation allows the security monitoring to be implemented in a modular way, improving security while managing complexity through organized, separate functional blocks

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10440120B2System and method for anomaly detection in diagnostic sessions in an in-vehicle communication network
Publication Date: 2019.10.08 PLAXIDITYX LTD
  • US10440120B2 patent drawing
  • US10440120B2 patent drawing
  • US10440120B2 patent drawing

AI summary

A method of monitoring communications propagating in an in-vehicle communications network of a vehicle, the method comprising: monitoring messages transmitted over at least a portion of the in-vehicle network; determining if the transmitted messages are indicative of a current data transfer session conducted over the in-vehicle network; comparing at least one feature of a message of the transmitted messages to at least one expected feature of a message comprised in a model of the data transfer session to determine whether or not the at least one feature of the transmitted message is expected; determining that the transmitted message is an anomalous message if the feature of the transmitted message is determined to be unexpected.