Vehicle Cyber Attack Detection via Multi-Source Data Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles are vulnerable to cyber and communication attacks due to their pervasive computerization and complex network systems, with existing security solutions failing to adequately address the unique attack vectors and functional logic of these systems.

Innovation Solution

A device comprising an input-unit for data collection, a database for storage, a detection-unit for monitoring data content, meta-data, and physical-data, and an action-unit for alerting and preventing attacks by manipulating communication channels, utilizing machine-learning to recognize irregularities and employing a remote-server for additional parameter sharing and attack detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewall and antivirus software are used to protect vehicle networks, then basic security is provided, but they fail to detect sophisticated cyber attacks that exploit unique vehicle attack vectors

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into multiple specialized modules: detection unit for monitoring communication channels, analysis unit for evaluating data against vehicle functional logic, identification unit for recognizing attack patterns, and action unit for responding to threats. Each module performs a specific function in the security detection chain, allowing sophisticated attack detection without requiring a single overly complex security component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary detection and analysis layer between the vehicle's communication networks and control systems. This intermediary monitors communication channels, analyzes data packets against known vehicle functioning logic, and intercepts malicious commands before they reach critical vehicle systems, providing deep inspection without disrupting normal vehicle operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive monitoring of all vehicle communication channels is implemented, then attack detection capability is improved, but system resource consumption and processing time increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining databases of known attack patterns, vehicle functional logic, and normal communication protocols before attacks occur. The detection unit continuously compares incoming data against these pre-established criteria, enabling rapid identification of anomalies without requiring complex real-time analysis of every data packet from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes monitoring parameters dynamically based on vehicle operating conditions and threat levels. The detection unit adjusts the intensity and focus of monitoring across different communication channels according to the vehicle's current state, allocating processing resources to high-risk channels while reducing monitoring on stable channels, thus maintaining detection accuracy while optimizing processing time.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3751818A1A device for detection and prevention of an attack on a vehicle
Publication Date: 2020.12.16 TOWER SEC
  • EP3751818A1 patent drawingFigure 1
  • EP3751818A1 patent drawingFigure 2
  • EP3751818A1 patent drawing

AI summary

A new device for detection and prevention of an attack on a vehicle via its communication channels, having: an input-unit configured to collect real-time and/or offline data from various sources such as sensors, network based services, navigation applications, the vehicles electronic control units, the vehicle's bus-networks, the vehicle's subsystems, and on board diagnostics; a database, for storing the data; a detection-unit in communication with the input-unit; and an action-unit, in communication with the detection unit, configured for sending an alert via the communication channels and/or prevent the attack, by breaking or changing the attacked communication channels. The detection-unit is configured to simultaneously monitor the content, the meta-data and the physical-data of the data and detect the attack.