Vehicle Correlation System for Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems fail to effectively detect and prevent cyber-attacks on connected vehicles communicating through on-board communication agent modules, which poses a significant security risk due to the lack of vehicle correlation systems for identifying and mitigating threats across multiple vehicles.

Innovation Solution

A vehicle correlation system comprising first and second on-board communication agent modules that collect and transmit metadata to a remote cloud-based detection server, where a correlation engine calculates the probability of cyber-attacks and detects threats based on data parameters such as suspect threats, attack spread, location, and communication parameters, enabling alert and prevention measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If connected vehicles share data through communication networks to improve road safety and reduce congestion, then the benefits of data sharing increase, but the vulnerability to cyber-attacks and security threats increases

Engineering Contradiction:
Improveroad safety improvementVSAvoidcyber-attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by continuously monitoring communication metadata and calculating correlation values before attacks can spread. The correlation engine proactively identifies suspicious patterns by comparing metadata from multiple vehicles against established baselines, enabling early detection and prevention of cyber-attacks before they compromise vehicle systems

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary correlation engine that acts as a mediator between connected vehicles and potential threats. This engine processes communication metadata, calculates correlation values, and identifies attack patterns without directly interfering with vehicle operations. The intermediary system filters and analyzes communication data to distinguish legitimate data sharing from malicious activities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real-time monitoring of communication metadata is implemented across multiple vehicles to detect attacks, then attack detection capability improves, but system complexity and computational requirements increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the attack detection function into distributed correlation engines in each vehicle and a centralized server. Each vehicle's correlation engine locally processes its own communication metadata and shares results with the network, while the centralized server aggregates data from multiple vehicles. This segmentation distributes computational complexity across many simple nodes rather than requiring one complex centralized system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each vehicle's correlation engine performs self-service by autonomously calculating correlation values for its own communication metadata and comparing it against network-wide patterns. The system enables vehicles to independently contribute to and benefit from collective security intelligence without requiring constant centralized control, reducing overall system complexity while maintaining high detection accuracy

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3197730B1Vehicle correlation system for cyber attacks detection and method thereof
Publication Date: 2020.02.19 TOWER SEC
  • EP3197730B1 patent drawingFigure 1
  • EP3197730B1 patent drawingFigure 2

AI summary

A system and method for detection of at least one cyber-attack on one or more vehicles comprising steps of transmitting and/or receiving by a first on-board agent module installed within one or more vehicles and/or a second on-board agent module installed within road infrastructure and in a range of communication with said first on-board agent module metadata to and/or from an on-site and/or remote cloud-based detection server comprising a correlation engine; detecting cyberattacks based on correlation calculation between said metadata received from one or more first agent module installed within vehicles and/or from one or more second agent modules installed within road infrastructure; indicating a probability of a cyber-attack against one or more vehicles based on correlation calculation; initiating blocking of vehicle-to- vehicle communication to prevent and/or stop a spread of an identified threat.