Vehicle Cyber Attack Detection via IT-Vehicle Data Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting unauthorized access in vehicles are inadequate due to a lack of specific attack behavior data for automobiles and difficulties in distinguishing between normal and malicious activities, particularly in communication systems like Ethernet frames, leading to low detection accuracy.

Innovation Solution

A vehicle unauthorized access countermeasure system that generates vehicle-specific characteristic information by comparing vehicle access data with general IT system data, creating detection rules to accurately identify unauthorized access, utilizing a system comprising an attack detection rule generation server and a monitoring server to analyze logs and alert for potential cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If general IT system unauthorized access information is used for vehicle security detection, then the detection coverage is improved, but the detection accuracy deteriorates due to lack of vehicle-specific characteristics

Engineering Contradiction:
Improvedetection coverageVSAvoiddetection accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The detection system is segmented into two distinct modules: one for acquiring general IT system unauthorized access information and another for acquiring vehicle-specific unauthorized access information. These segmented modules work together to combine broad coverage with precise vehicle-specific detection, resolving the contradiction between detection coverage and accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent merges general IT system security detection capabilities with vehicle-specific security characteristics by combining information from both sources. The generation unit integrates these diverse information sources to create comprehensive detection rules that achieve both wide coverage and high accuracy for vehicle unauthorized access detection.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If vehicle-specific unauthorized access information is collected from limited sources, then the detection accuracy is improved, but the detection coverage deteriorates due to insufficient data

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system merges multiple information sources by combining general IT system unauthorized access information with vehicle-specific unauthorized access information. This merging approach allows the system to maintain high detection accuracy through vehicle-specific data while achieving broad detection coverage through general IT security patterns.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The detection system achieves universality by applying both general IT security detection principles and vehicle-specific detection methods. The unified detection rules generated can handle diverse unauthorized access scenarios, making the system multi-functional and broadly applicable while maintaining vehicle-specific precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If detection rules are generated using only general IT system data, then the system complexity is reduced, but the detection precision deteriorates due to lack of vehicle-specific characteristics

Engineering Contradiction:
Improvesystem complexityVSAvoiddetection precision
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The rule generation process is segmented into distinct acquisition units: one for general IT system information and another for vehicle-specific information. This segmentation allows the system to manage complexity by organizing data collection into manageable modules while ensuring both general and specific characteristics are captured for precise detection.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If comprehensive vehicle unauthorized access information is collected from multiple sources, then the detection accuracy is improved, but the information processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The generation unit acts as an intermediary that processes and integrates information from multiple sources (general IT system data and vehicle-specific data). This intermediary component simplifies the overall processing complexity by centralizing the integration logic and transforming multiple input streams into unified detection rules, thereby maintaining detection accuracy while managing information processing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11436322B2Vehicle unauthorized access countermeasure taking apparatus and vehicle unauthorized access countermeasure taking method
Publication Date: 2022.09.06 HITACHI LTD
  • US11436322B2 patent drawing
  • US11436322B2 patent drawing
  • US11436322B2 patent drawing

AI summary

An unauthorized access to a vehicle is accurately detected. An attack detection rule generation server includes: a general unauthorized access information receiving section receiving, from an external information processing apparatus, general unauthorized access information about an unauthorized access made to an information processing apparatus; a vehicle unauthorized access characteristic information generation section generating vehicle unauthorized access characteristic information about characteristics of an unauthorized access to a vehicle in a case of comparing the unauthorized access to the vehicle with the unauthorized access to the information processing apparatus; a vehicle unauthorized access information generation section generating vehicle unauthorized access information indicating a configuration of the unauthorized access to the vehicle, on the basis of the general unauthorized access information and the vehicle unauthorized access characteristic information; and a vehicle unauthorized access detection rule generation section generating a vehicle unauthorized access detection rule detecting the unauthorized access to the vehicle, on the basis of the vehicle unauthorized access information.