On-Board Network Anomaly Detection via Machine Learning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security technologies for on-board vehicle networks, such as those using CAN buses, are inadequate in detecting and counteracting a wide range of attack frames, as they primarily rely on registered anticipated periods and are ineffective against unknown or varied attack frames.
Innovation Solution
A security processing method and server system that assesses anomaly levels of frames transmitted on an on-board network using statistical processing, multivariate analysis, and machine learning, allowing for the detection and counteraction of various attack frames, including unknown threats, by continuously updating models based on received frame information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If rule-based security systems using registered anticipated periods are used to detect attack frames, then the system structure remains simple, but the detection capability is limited to known attack patterns only
Solution Approach 1:
The patent replaces rule-based mechanical detection systems with machine learning-based intelligent systems. The server uses trained models to automatically learn and detect attack patterns without requiring explicit rule programming, thereby improving adaptability while managing complexity through automated learning processes.
Solution Approach 2:
The system changes the detection parameters from fixed registered anticipated periods to dynamically learned time intervals and frame characteristics. By using machine learning models that adapt parameters based on training data, the system achieves broader detection capability without manually configuring each detection parameter.
2Adaptability or versatility
If machine learning-based anomaly assessment is implemented to detect various attack frames, then the detection versatility improves, but the processing complexity and computational requirements increase
Solution Approach 1:
The patent segments the security system into two parts: a training phase where the server learns attack patterns from labeled data, and an inference phase where the trained model assesses anomalies in real-time. This segmentation allows complex learning processes to occur offline while keeping online processing relatively simple.
Solution Approach 2:
The system performs preliminary training and model preparation before actual security monitoring begins. By pre-training the machine learning models with diverse attack patterns and normal traffic data, the system establishes detection capabilities in advance, reducing the complexity of real-time decision-making.
Data Source
AI summary
An anomaly detection server is provided. The anomaly detection server is a server for counteracting an anomalous frame transmitted on an on-board network of a single vehicle. The anomaly detection server acquires information about multiple frames received on one or multiple on-board networks of one or multiple vehicles, including the single vehicle. The anomaly detection server, acting as an assessment unit that, based on the information about the multiple frames and information about a frame received on the on-board network of the single vehicle after the acquisition of the information about the multiple frames, assesses an anomaly level of the frame received on the on-board network of the single vehicle.


