In-Vehicle Attack Path Estimation from ECU Anomaly Signals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods struggle to accurately estimate the attack path, including the entry point and attack target, in cyber attacks on in-vehicle networks due to issues like undetected anomalies and false detections.

Innovation Solution

An attack analysis device that utilizes in-vehicle network configuration information and anomaly detection information to estimate the attack path, incorporating external communication interfaces and control ECUs, with additional considerations for external communication and vehicle control event histories to enhance accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If anomaly detection is performed in in-vehicle networks, then attack detection capability is improved, but false detections and undetected anomalies occur reducing reliability

Engineering Contradiction:
Improveattack detection capabilityVSAvoidanomaly detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an attack path estimator as an intermediary component that bridges anomaly detection and attack identification. This estimator uses graph theory to model the in-vehicle network and calculate probability distributions of attack paths, serving as a mediator that processes anomaly detection results and transforms them into reliable attack path predictions, thereby resolving the contradiction between detection capability and accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where anomaly detection results are fed into the attack path estimator, which then refines the detection by providing probability-based attack path information. This feedback loop allows the system to continuously improve detection accuracy by comparing estimated attack paths with actual anomaly patterns, reducing both false detections and missed detections

Inventive Principle:
Principle #23Feedback

2Measurement precision

If comprehensive attack path estimation is performed including entry points and attack targets, then analysis accuracy is improved, but computational complexity and analysis costs increase

Engineering Contradiction:
Improveattack path estimation accuracyVSAvoidanalysis system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the attack path estimation problem into distinct components: entry point identification, intermediate node identification, and attack target identification. Each component is handled by specific algorithms working on divided aspects of the network graph, making the overall complex problem manageable and reducing system complexity while maintaining comprehensive estimation accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs partial action by focusing computational resources on estimating only the most probable attack paths rather than exhaustively analyzing all possible paths. By using probability thresholds and stopping criteria, the system achieves sufficient estimation accuracy without the excessive computational complexity of complete path enumeration

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12432226B2Attack analysis device, attack analysis method, and non-transitory computer-readable recording medium
Publication Date: 2025.09.30 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US12432226B2 patent drawing
  • US12432226B2 patent drawing
  • US12432226B2 patent drawing

AI summary

An attack analysis device includes: an obtainer that obtains in-vehicle network information indicating a configuration of an in-vehicle network including a plurality of external communication interfaces and a plurality of control Electronic Control Units (ECUs), and anomaly detection information indicating a result of detecting an anomaly in at least one node in the in-vehicle network; an attack path estimator that, based on the in-vehicle network information and the anomaly detection information, estimates an attack path in an attack on the in-vehicle network, the attack path including an entry point indicating an external communication interface that is a point of intrusion into the in-vehicle network in the attack and an attack target indicating a control ECU that is a target of the attack; and an outputter that outputs the attack path.