Vehicle Cybersecurity Priority Assignment via Threat Resolution State
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for evaluating attack priority levels on vehicles assign high priority to numerous similar attacks, leading to analysts having to manually reassess and prioritize detection results, causing inefficiencies in analysis services.
Innovation Solution
An information processing apparatus connected to vehicles and a threat information server, which determines attack priority levels based on whether the attack is recorded, its resolution state, and countermeasure application, allowing for automated and differentiated priority assignment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If priority evaluation is based on matching rates of maintenance target system and threat information, then analysts can process detection results preferentially, but when large number of same attacks are detected with high risk, all detection results are assigned high priority levels causing manual reassessment burden
Solution Approach 1:
The patent segments the priority evaluation process by introducing multiple evaluation dimensions: whether the attack type is recorded in the threat information server, the resolution state of the attack, and the number of detected attacks. This segmentation allows differentiated priority assignment rather than uniform high priority for all similar attacks
Solution Approach 2:
The patent applies local quality by assigning different priority levels to different detection results based on their specific characteristics. Detection results are classified into first priority (unrecorded attack types), second priority (recorded but unresolved), and third priority (recorded and resolved), ensuring each detection result receives appropriate priority treatment based on its local context
2Reliability
If all detection results of same attacks are assigned high priority levels, then important attacks are not missed, but analysts have to manually reassign priority levels reducing analysis service efficiency
Solution Approach 1:
The system performs preliminary automatic priority assignment based on pre-established evaluation criteria before analyst review. By automatically classifying detection results into priority levels using recorded attack types and resolution states, the system prepares the work in advance, reducing the time analysts need to spend on manual reassessment while maintaining reliable detection coverage
3Measurement precision
If manual reassessment of priority levels is required, then accurate priority assignment can be achieved, but analysis service efficiency is reduced
Solution Approach 1:
The system implements self-service by automatically evaluating and assigning priority levels to detection results using predefined criteria. The threat information server automatically determines whether attack types are recorded, checks resolution states, and assigns appropriate priority levels without requiring analyst intervention, thereby maintaining accurate priority assignment while significantly improving analysis service throughput
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
An information processing apparatus (100) includes: an obtaining unit (1001) which obtains a detection result of an attack on one of vehicles connected to the information processing apparatus (100); a first determining unit (1002) which determines whether the attack is included in any one of the pieces of threat information stored in a threat information server; a second determining unit (1003) which determines, when the attack is included therein, whether the resolution state to the attack included in the one of the pieces of threat information indicates that the attack has not been resolved or has been resolved; a deciding unit (1007) which decides a processing priority level of the attack, based on the result of determination made by the first determining unit (1002) and the result of determination made by the second determining unit (1003); and an output unit (1009) which outputs the processing priority level decided by the deciding unit (1007).