In-Vehicle Attack Path Estimation from ECU Anomaly Signals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods struggle to accurately estimate the attack path, including the entry point and attack target, in cyber attacks on in-vehicle networks due to issues like undetected anomalies and false detections.
Innovation Solution
An attack analysis device that utilizes in-vehicle network configuration information and anomaly detection information to estimate the attack path, incorporating external communication interfaces and control ECUs, with additional considerations for external communication and vehicle control event histories to enhance accuracy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anomaly detection is performed in in-vehicle networks, then attack detection capability is improved, but false detections and undetected anomalies occur reducing reliability
Solution Approach 1:
The patent introduces an attack path estimator as an intermediary component that bridges anomaly detection and attack identification. This estimator uses graph theory to model the in-vehicle network and calculate probability distributions of attack paths, serving as a mediator that processes anomaly detection results and transforms them into reliable attack path predictions, thereby resolving the contradiction between detection capability and accuracy
Solution Approach 2:
The system implements feedback mechanisms where anomaly detection results are fed into the attack path estimator, which then refines the detection by providing probability-based attack path information. This feedback loop allows the system to continuously improve detection accuracy by comparing estimated attack paths with actual anomaly patterns, reducing both false detections and missed detections
2Measurement precision
If comprehensive attack path estimation is performed including entry points and attack targets, then analysis accuracy is improved, but computational complexity and analysis costs increase
Solution Approach 1:
The patent segments the attack path estimation problem into distinct components: entry point identification, intermediate node identification, and attack target identification. Each component is handled by specific algorithms working on divided aspects of the network graph, making the overall complex problem manageable and reducing system complexity while maintaining comprehensive estimation accuracy
Solution Approach 2:
The system performs partial action by focusing computational resources on estimating only the most probable attack paths rather than exhaustively analyzing all possible paths. By using probability thresholds and stopping criteria, the system achieves sufficient estimation accuracy without the excessive computational complexity of complete path enumeration
Data Source
AI summary
An attack analysis device includes: an obtainer that obtains in-vehicle network information indicating a configuration of an in-vehicle network including a plurality of external communication interfaces and a plurality of control Electronic Control Units (ECUs), and anomaly detection information indicating a result of detecting an anomaly in at least one node in the in-vehicle network; an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point indicating an external communication interface that is a point of intrusion into the in-vehicle network in the attack and an attack target indicating a control ECU that is a target of the attack; and an outputter that outputs the attack path.


