Remote Mobility Anomaly Monitoring via Operation-Control Log Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing remote operation systems for mobility entities struggle to differentiate between anomalies caused by cyber attacks and those caused by operator errors, making it difficult to identify the root cause of accidents.
Innovation Solution
An anomaly monitoring apparatus and method that collect and compare operation logs from an operator apparatus and control logs from a mobility entity to identify the attack origin, utilizing anomaly detection and attack origin identification based on log comparisons.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is performed using network frame monitoring in a remote operation system, then anomalies can be detected, but the cause of the anomaly (cyber attack vs. operator error) cannot be identified
Solution Approach 1:
The patent segments the monitoring system into two distinct log collection paths: one for operation logs (from the operation apparatus) and another for control logs (from the mobility entity). This segmentation allows independent tracking of commands issued by the operator versus commands actually executed by the mobility entity, enabling subsequent comparison to identify discrepancies that indicate cyber attacks versus operator errors.
Solution Approach 2:
The patent introduces a centralized log collection apparatus as an intermediary that receives and stores both operation logs and control logs. This intermediary component facilitates the comparison process by making both log types available in a centralized location, allowing the system to identify anomalies by comparing what the operator intended to do versus what the mobility entity actually did.
2Device complexity
If only network frame monitoring is used for anomaly detection, then the system remains simple, but it cannot differentiate between cyber attacks and operator errors
Solution Approach 1:
The patent implements preliminary action by collecting and storing operation logs and control logs in advance before anomalies occur. The log collection apparatus continuously accumulates historical data from both the operation apparatus and the mobility entity, so when an anomaly is detected through frame monitoring, the system can immediately compare against stored logs to identify the cause without requiring additional real-time monitoring complexity.
3Loss of information
If the system collects and compares operation logs and control logs to identify attack origins, then accurate cause identification is achieved, but system complexity increases
Solution Approach 1:
The patent uses copying by creating duplicate records of operation commands in operation logs and control commands in control logs. These copied log entries serve as historical references that can be compared when anomalies are detected. The copying approach allows the system to maintain simple real-time monitoring while using historical copies of data for detailed analysis when needed.
Data Source
AI summary
An anomaly monitoring apparatus in a remote operation system for remotely operating a mobility entity includes: a log collector that collects an operation log from an operation apparatus which remotely operates the mobility entity and a control log from a control apparatus installed in the mobility entity; an anomaly detector that detects whether an anomaly is present in the mobility entity based on at least one of the operation log or the control log; an attack origin identifier that, when the anomaly detector detects an anomaly, identifies an attack origin that caused the anomaly in the mobility entity from among a plurality of attack origins based on a result of comparing the operation log with the control log; and an anomaly notifier that makes a notification for taking a countermeasure for the attack origin identified by the attack origin identifier.


