Vehicle Cybersecurity Attack Path Analysis for Timed Countermeasures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In systems with multiple important devices, distinguishing the importance of each device during a cyber-security attack is difficult, leading to potential critical states before intrusion, and existing countermeasures may be excessive or delayed.

Innovation Solution

An analysis device that includes a communication unit to receive logs, an attack progress analysis unit to calculate intrusion locations, and an urgency degree determination unit to determine the urgency of countermeasures based on attack progress analysis, enabling appropriate countermeasures at the right time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection technology is implemented to detect cyber-security attacks, then security detection capability is improved, but false alarms and delayed detection occur without accurate danger assessment

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddanger degree determination accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system segments the attack detection process into multiple stages: initial attack detection, propagation path analysis, and urgency degree determination. Each stage handles specific aspects of threat assessment, allowing for more precise measurement of danger levels through structured analysis of attack progression through the network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring network traffic and updating propagation path analysis based on detected attacks. The urgency degree determination uses feedback from attack detection results to adjust countermeasure timing and intensity, improving both detection reliability and danger assessment precision.

Inventive Principle:
Principle #23Feedback

2Speed

If countermeasures are executed immediately upon detecting a cyber-security attack, then response speed is improved, but excessive countermeasures occur leading to system disruption

Engineering Contradiction:
Improvecountermeasure response speedVSAvoidexcessive countermeasure impact
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of propagation paths and urgency degrees before executing countermeasures. By pre-calculating potential attack routes and assessing danger levels in advance, the system can determine the appropriate timing and intensity of countermeasures, avoiding both premature and excessive responses while maintaining fast reaction speeds.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The countermeasure execution is made dynamic based on real-time urgency degree assessments. The system adjusts countermeasure intensity and timing according to the calculated danger levels and propagation paths, allowing flexible response that adapts to the specific threat situation rather than applying fixed immediate countermeasures.

Inventive Principle:
Principle #15Dynamics

3Measurement precision

If importance of each device is determined to select appropriate countermeasures, then countermeasure precision is improved, but device importance distinction becomes difficult in systems with multiple important devices

Engineering Contradiction:
Improvedevice importance determination accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies local quality assessment by determining importance and urgency degrees for each specific device and propagation path individually. Rather than treating all devices uniformly, the system analyzes local characteristics of each component's role in potential attack scenarios, enabling precise distinction of device importance even in complex multi-device systems.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system adds the dimension of propagation path analysis to device importance assessment. By evaluating devices not just based on their inherent importance but also on their position in attack propagation paths and calculated urgency degrees, the system creates a multi-dimensional assessment framework that simplifies device prioritization in complex systems.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12375504B2Analysis device and analysis method
Publication Date: 2025.07.29 ASTEMO LTD
  • US12375504B2 patent drawing
  • US12375504B2 patent drawing
  • US12375504B2 patent drawing

AI summary

An appropriate countermeasure is taken against a cyber-security attack at an appropriate timing. An analysis device, configured using a computer including a computation device that executes predetermined computation processing and a storage device accessible by the computation device, includes: a communication unit that receives, by the computation device, a log of an information processing device mounted on an instrument; an attack progress analysis unit that calculates, by the computation device, an intrusion location in a route from an intrusion point on the instrument to a protected asset from the received log; and an urgency degree determination unit that determines, by the computation device, an urgency degree of a countermeasure against an attack based on an analysis result of the attack progress analysis unit.