On-Board Network Anomaly Detection via Machine Learning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security technologies for on-board vehicle networks, such as those using CAN buses, are inadequate in detecting and counteracting a wide range of attack frames, as they primarily rely on registered anticipated periods and are ineffective against unknown or varied attack frames.

Innovation Solution

A security processing method and server system that assesses anomaly levels of frames transmitted on an on-board network using statistical processing, multivariate analysis, and machine learning, allowing for the detection and counteraction of various attack frames, including unknown threats, by continuously updating models based on received frame information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rule-based security systems using registered anticipated periods are used to detect attack frames, then the system structure remains simple, but the detection capability is limited to known attack patterns only

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent replaces rule-based mechanical detection systems with machine learning-based intelligent systems. The server uses trained models to automatically learn and detect attack patterns without requiring explicit rule programming, thereby improving adaptability while managing complexity through automated learning processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the detection parameters from fixed registered anticipated periods to dynamically learned time intervals and frame characteristics. By using machine learning models that adapt parameters based on training data, the system achieves broader detection capability without manually configuring each detection parameter.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If machine learning-based anomaly assessment is implemented to detect various attack frames, then the detection versatility improves, but the processing complexity and computational requirements increase

Engineering Contradiction:
Improvedetection versatilityVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the security system into two parts: a training phase where the server learns attack patterns from labeled data, and an inference phase where the trained model assesses anomalies in real-time. This segmentation allows complex learning processes to occur offline while keeping online processing relatively simple.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary training and model preparation before actual security monitoring begins. By pre-training the machine learning models with diverse attack patterns and normal traffic data, the system establishes detection capabilities in advance, reducing the complexity of real-time decision-making.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11575699B2Security processing method and server
Publication Date: 2023.02.07 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US11575699B2 patent drawing
  • US11575699B2 patent drawing
  • US11575699B2 patent drawing

AI summary

An anomaly detection server is provided. The anomaly detection server is a server for counteracting an anomalous frame transmitted on an on-board network of a single vehicle. The anomaly detection server acquires information about multiple frames received on one or multiple on-board networks of one or multiple vehicles, including the single vehicle. The anomaly detection server, acting as an assessment unit that, based on the information about the multiple frames and information about a frame received on the on-board network of the single vehicle after the acquisition of the information about the multiple frames, assesses an anomaly level of the frame received on the on-board network of the single vehicle.