Software Intrusion Detection via Activity Threshold Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting hacking in electronic devices, such as those in vehicles, are inadequate as they rely solely on monitoring communications and cannot detect unauthorized modifications or software installations that do not cause detectable changes in communication patterns.

Innovation Solution

An intrusion detection module that determines an expected activity value for software applications and monitors current activity to initiate security actions when the current value exceeds a threshold, including halting execution, disconnecting communications, or deleting the software, thereby addressing undetectable hacking attempts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If communication monitoring is used to detect hacking, then detection capability for communication-based attacks is improved, but detection capability for non-communication-based hacking is lost

Engineering Contradiction:
Improvedetection capabilityVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent transitions from monitoring only communication dimensions (network traffic, messages) to adding internal system activity dimensions (CPU usage, memory usage, power consumption). This multi-dimensional approach allows detection of hacking attempts that do not manifest in communication patterns but do affect system resource consumption.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The intrusion detection system is designed to monitor multiple types of activities simultaneously - communication activities and internal system activities. This universal monitoring capability enables the system to detect various hacking methods regardless of whether they involve communication changes, making the detection mechanism versatile across different attack vectors.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional communication monitoring is implemented, then system complexity is reduced, but detection reliability is insufficient

Engineering Contradiction:
Improvedetection reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into distinct components: communication monitoring modules and internal activity monitoring modules. Each module independently monitors specific aspects (network traffic vs. CPU/memory usage), and their results are combined for comprehensive intrusion detection. This segmentation improves reliability without creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces activity value thresholds as intermediary reference points. Instead of directly comparing complex monitoring data, the system compares activity values against pre-established thresholds to determine intrusions. This intermediary approach simplifies the detection logic while maintaining high reliability through objective criterion-based detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11341238B2Electronic device intrusion detection
Publication Date: 2022.05.24 APTIV TECHNOLOGIES AG
  • US11341238B2 patent drawing
  • US11341238B2 patent drawing
  • US11341238B2 patent drawing

AI summary

A method for detecting an intrusion (i.e. hacking) of an electronic device includes determining an expected activity value associated with one or more software applications executing on a processor, monitoring the one or more software applications executing on the processor to determine a current activity value associated with the one or more software applications, determining whether the current activity value exceeds a threshold associated with the expected activity value, and in response to determining that the current activity value exceeds the threshold, initiating one or more security actions associated with the one or more software applications. A system for detecting an intrusion of an electronic device includes an intrusion detection module configured to perform the steps of the method.