Vehicle Control Monitoring for Unknown Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional control systems fail to detect abnormalities caused by unknown cyber-security attacks during vehicle operation, as they do not monitor input-output values between calculation steps effectively, leading to undetected changes in control values and processing sequences.
Innovation Solution
A control system comprising a control unit, calculation unit, storage units, acquisition unit, comparison unit, and determination unit that monitors and compares execution-time information with pre-defined normal time information to detect abnormalities in control processing, even when unknown attacks occur during operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional process order monitoring is used to detect abnormalities, then known attack scenarios can be detected, but unknown cyber-security attacks cannot be detected when control values remain within normal ranges
Solution Approach 1:
The patent introduces a new monitoring dimension by tracking input-output value relationships between calculation steps, in addition to the conventional process order monitoring. This dimensional expansion allows detection of unknown attacks that maintain normal process sequences but produce abnormal value transformations, thereby resolving the contradiction between detecting known attacks and adapting to unknown threats
Solution Approach 2:
The system establishes feedback loops where output values from one calculation step become input values for the next step, and these values are continuously monitored for abnormal transformations. The abnormality determination unit uses this feedback information to detect when control values deviate from expected relationships, enabling detection of unknown attacks while maintaining reliability for known attack detection
2Reliability
If memory checking is performed at all times during vehicle operation to detect unknown attacks, then security is improved, but process workload becomes excessively large
Solution Approach 1:
The patent extracts only the essential monitoring elements (input-output value relationships between calculation steps) from the comprehensive memory checking process. By monitoring specifically the transformation relationships of control values rather than checking all memory contents, the system maintains security against unknown attacks while significantly reducing the process workload and preserving control processing efficiency
Solution Approach 2:
Instead of performing complete memory checking at all times, the system applies partial monitoring focused on critical input-output value relationships in the calculation process. This selective approach provides sufficient security coverage for unknown attack detection while avoiding the excessive workload of comprehensive continuous memory checking
3Measurement precision
If comprehensive monitoring of all calculation values is performed to detect abnormalities, then detection accuracy is improved, but processing time and system complexity increase
Solution Approach 1:
The patent segments the monitoring task into discrete units corresponding to individual calculation steps and their input-output value relationships. By dividing the comprehensive monitoring into step-specific monitoring units, the system achieves high detection accuracy for each segment while keeping the overall system complexity manageable through modular organization of monitoring functions
Data Source
AI summary
A control system for preventing abnormal operation including the storage of execution time input and output values, the storage of normal time read and write information of an address contained in a pre-defined address range, and the determination of abnormality based on comparison between execution time and normal time information.


