IVHM-Cyber Anomaly Detection for Vehicle False Alarm Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vehicle electronics intrusion detection systems (IDS) suffer from high rates of false positives due to equipment failures, which overwhelm security operations centers and divert resources from identifying real cyber threats, as they often incorrectly flag legitimate traffic as malicious.

Innovation Solution

An integrated vehicle health management (IVHM) system is combined with cyber intrusion detection to differentiate between equipment failures and cyber attacks using a symptom pattern recognition matrix initialized from vehicle design data, updated through a learning loop, and enhanced by neural networks to classify anomalies and reduce false alarms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly-based detection is used to identify cyber attacks, then cyber threat detection capability is improved, but false positive rate increases due to equipment failures being misclassified as cyber attacks

Engineering Contradiction:
Improvecyber threat detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system segments anomaly analysis into two distinct pathways: one for equipment failure patterns and one for cyber attack patterns. The IVHM system handles equipment failure anomalies while the cyber security system handles potential cyber threats, preventing misclassification and reducing false positives.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the IVHM system) that acts as a filter between the anomaly detection system and the cyber security response system. This intermediary classifies anomalies before they reach the cyber security team, preventing equipment failure anomalies from being misinterpreted as cyber attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If all detected anomalies are investigated by security analysts, then cyber attack identification thoroughness is improved, but resource efficiency deteriorates due to the large volume of equipment failure anomalies requiring review

Engineering Contradiction:
Improveanomaly investigation thoroughnessVSAvoidanalyst efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system extracts and removes equipment failure anomalies from the cyber security analysts' workload by routing them to the IVHM system for specialized handling. Only anomalies that the IVHM system cannot classify or that are suspected to be cyber threats are presented to security analysts, dramatically reducing their burden.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The IVHM system provides self-service capability by automatically classifying and handling equipment failure anomalies without requiring security analyst intervention. This allows the system to manage its own routine anomaly processing, freeing up analyst resources for more complex cyber threat investigations.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If a learning loop is implemented to improve anomaly classification, then diagnostic accuracy is improved, but system complexity increases due to the need for continuous model updates and training

Engineering Contradiction:
Improveanomaly classification accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges the IVHM learning loop with the cyber security anomaly detection system, creating a unified platform that leverages data from both domains to improve classification accuracy. This integration allows the system to learn from both equipment failure patterns and cyber attack patterns, enhancing overall diagnostic capability while sharing computational resources.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11444959B2Integrated equipment fault and cyber attack detection arrangement
Publication Date: 2022.09.13 GARRETT TRANSPORTATION I INC
  • US11444959B2 patent drawing
  • US11444959B2 patent drawing
  • US11444959B2 patent drawing

AI summary

An integrated vehicle health management (IVHM) system to resolve equipment-fault related anomalies detected by cyber intrusion detection system (IDS). A benefit of the present system is that it can result in fewer alerts that need manual analysis. A combination of cyber and monitoring with integrated vehicle health management (IVHM) may be a high value differentiator. As a solution gets more mature through a learning loop, it may be customized for different customers in a cost effective manner, something that might be expensive to develop on their own for most original equipment manufacturers (OEMs). An IVHM symptom pattern recognition matrix may link a pattern of reported symptoms to known equipment failures. This matrix may be initialized from the vehicle design data but its entries may get updated by a learning loop that improves a correlation by incorporating results of investigations.