Switch Anomaly Detection in Automotive Ethernet
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Network-based Intrusion Detection and Prevention Systems (NIDS/NIDPS) require dedicated hardware and additional communication infrastructure, which is not feasible for all communication networks, especially in resource-constrained environments like automotive Ethernet networks.
Innovation Solution
A method and device that utilize rule-based anomaly recognition and reaction components within the existing communication network, allowing detectors to analyze data streams, recognize anomalies, and send information via the network, while actuators initiate countermeasures without the need for dedicated hardware, enabling a distributed and hierarchical monitoring and response system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional NIDS/NIDPS are realized by dedicated hardware with separate components, then anomaly recognition and response capabilities are improved, but device complexity and hardware requirements increase
Solution Approach 1:
The patent merges the NIDS/NIDPS functionality with existing switch hardware by integrating detectors and actuators directly into the switch components. This allows anomaly recognition and response capabilities to be achieved without adding separate dedicated hardware systems, thereby reducing overall device complexity while maintaining security functions.
Solution Approach 2:
The switch hardware is designed to perform multiple functions: both its original data forwarding tasks and the additional anomaly detection/prevention functions. The detectors and actuators integrated into the switch enable it to serve as both a communication device and a security system, eliminating the need for separate dedicated hardware.
2Extent of automation
If separate NIDS/NIDPS components are added to the communication network, then anomaly detection and response functions are improved, but the number of components and system complexity increase
Solution Approach 1:
The patent combines the anomaly detection and response functions directly into the existing switch components. The detectors are integrated as part of the switch architecture, and actuators are incorporated to enable automated responses, thereby achieving automation without adding separate component systems.
Solution Approach 2:
The switch components are designed to perform anomaly detection and response functions autonomously as part of their own operation. The integrated detectors and actuators enable the switch to monitor and respond to anomalies without requiring external dedicated systems, making the system self-sufficient.
3Speed
If fast switch ports are used to forward data traffic to NIDS/NIDPS, then anomaly recognition speed is improved, but network bandwidth consumption and infrastructure requirements increase
Solution Approach 1:
The patent merges the anomaly detection function with the data forwarding function in the same switch ports. This eliminates the need for separate dedicated ports or infrastructure to forward traffic to a separate NIDS, as the switch can perform both functions simultaneously using its existing hardware resources.
Solution Approach 2:
The switch ports and internal architecture are designed to handle multiple functions: data forwarding and anomaly detection. This multi-functionality allows the system to achieve fast anomaly recognition without requiring additional network infrastructure or dedicated hardware resources.
4Loss of time
If NIDS/NIDPS functionality is integrated directly at the switch, then response time to anomalies is improved, but the computing resource requirements and hardware complexity at the switch increase
Solution Approach 1:
The patent merges the NIDS/NIDPS functionality with the switch hardware architecture. The detectors and actuators are integrated directly into the switch components, enabling immediate anomaly response at the point of detection without requiring complex external systems or additional hardware layers.
Solution Approach 2:
The switch hardware is designed with built-in anomaly detection and response capabilities that operate autonomously. The integrated detectors and actuators enable the switch to respond to anomalies immediately as part of its own operational logic, minimizing response time without relying on external processing systems.
Data Source
AI summary
A device and method for handling an anomaly in a communication network of a motor vehicle includes at least one detector analyzing a data stream in the communication network, recognizing at least one anomaly using a rule-based anomaly recognition method if at least one parameter for a data packet of the data stream deviates from a target value, and sending information about the at least one recognized anomaly via the communication network.


