Vehicle Network Attack Logging and Alarm Timing Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing attack detection technologies for vehicle networks, particularly those using Ethernet, are inadequate as they do not account for the unique characteristics of vehicles and are difficult to apply to networks with mixed legacy and Ethernet-based domains, leading to increased hacking risks and inefficiencies in alarm and log management.
Innovation Solution
A method and device that detect attacks on vehicle networks, provide alarms, and store logs by adjusting settings based on attack duration and type, using a first to fifth period of time framework to manage alarms and logs efficiently, and prioritize memory storage based on attack information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing attack detection technologies are applied to vehicle networks, then attack detection capability is improved, but device complexity increases and adaptability to mixed Ethernet and legacy domains deteriorates
Solution Approach 1:
The attack detection system is segmented into domain-specific modules: Ethernet domain detection module and legacy domain detection module. Each module is optimized for its specific domain characteristics, allowing the system to detect attacks in both Ethernet and legacy networks without requiring a single complex unified solution. This segmentation reduces overall device complexity while maintaining comprehensive detection capability.
Solution Approach 2:
Different detection strategies and parameters are applied locally to different domains. The Ethernet domain uses detection methods optimized for Ethernet characteristics (e.g., MAC address analysis, Ethernet frame inspection), while legacy domains use appropriate traditional methods. This local optimization improves detection effectiveness without imposing unnecessary complexity across the entire system.
2Reliability
If attack detection is continuously monitored, then detection reliability is improved, but energy consumption increases
Solution Approach 1:
The system implements periodic monitoring with variable intervals based on threat levels and domain activity. During normal operation, monitoring occurs at standard intervals. When suspicious activity is detected, the monitoring frequency increases automatically. This periodic action maintains detection reliability while avoiding continuous monitoring energy overhead.
Solution Approach 2:
The monitoring intensity and resource allocation are dynamically adjusted based on real-time conditions. The system transitions between low-power standby mode and high-alert detection mode according to detected traffic patterns and threat indicators, optimizing the balance between detection reliability and energy consumption.
3Loss of information
If all attacks are logged immediately, then information completeness is improved, but memory usage increases
Solution Approach 1:
Different logging policies are applied to different attack types and domains. Critical attacks (e.g., those targeting safety-critical systems) are logged with high priority and retained indefinitely. Less severe attacks are logged with lower priority and subject to rotation or deletion policies. This differentiated approach preserves essential information while managing memory resources efficiently.
Solution Approach 2:
The system implements log rotation and prioritization mechanisms where older or less critical logs are discarded or archived when memory capacity is reached. High-priority logs are preserved while lower-priority logs are removed, ensuring that memory is always available for critical security information while maintaining reasonable information completeness.
Data Source
AI summary
A includes: detecting an attack on a vehicle network; when the attack is detected, determining whether the attack continues for a first period of time; when the attack continues for the first period of time, storing a log just before a second period of time; when the attack continues for the first period of time, providing an alarm; after the alarm, determining whether the attack continues for a third period of time; when the attack continues for the third period of time, providing the alarm again; when the attack does not continue for the third period of time, determining that the attack is ended; determining whether the end of the attack continues for a fourth period of time; and when it is determined that the attack is ended, storing a log from a time point, at which the attack is ended, to a fifth period of time.


