Log Determination Device for False Positive Filtering in Autonomous Vehicle Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In vehicles equipped with electronic control systems for autonomous driving, maintenance activities generate logs that can be misinterpreted as cyberattacks, leading to decreased analysis accuracy due to the mixing of maintenance-related and cyberattack-related logs.
Innovation Solution
A log determination device that acquires security logs, stores predicted maintenance patterns, and compares them to identify false positive logs generated during maintenance, thereby improving cyberattack analysis accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security logs are collected and analyzed to detect cyberattacks, then cyberattack detection capability is improved, but false positive logs from maintenance activities reduce analysis accuracy
Solution Approach 1:
The patent segments security logs into two categories: maintenance-related logs and cyberattack-related logs. By creating distinct log types with different identification flags, the system can process and analyze each category separately, preventing maintenance logs from interfering with cyberattack detection accuracy while maintaining comprehensive security monitoring
Solution Approach 2:
The patent introduces an intermediary component (the determination device) that acts as a mediator between log collection and cyberattack analysis. This intermediary identifies and filters maintenance-related logs before they reach the cyberattack analysis system, using prediction information about maintenance activities as an intermediate filtering criterion
2Reliability
If all security logs are processed through analysis, then comprehensive security monitoring is achieved, but communication and analysis resources are wasted on maintenance logs
Solution Approach 1:
The patent extracts maintenance-related logs from the overall security log stream by identifying them through comparison with prediction information. These extracted logs are then set aside with a specific identification flag, removing them from the cyberattack analysis pipeline and preventing unnecessary consumption of communication and computational resources
Solution Approach 2:
The patent applies partial action by selectively processing only those logs that are relevant to cyberattack detection. Instead of analyzing all logs equally, the system performs preliminary filtering to identify maintenance logs and excludes them from further analysis, applying analysis resources only where needed for security threats
Data Source
AI summary
A log determination device is configured to acquire a plurality of security logs each including an abnormality information and a position information, store an occurrence pattern of a security log which is predicted to occur due to a maintenance, and compare the plurality of security logs with the occurrence pattern to determine whether or not the plurality of security logs is a false positive log.


