Vehicle Cybersecurity Priority Assignment via Threat Resolution State

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for evaluating attack priority levels on vehicles assign high priority to numerous similar attacks, leading to analysts having to manually reassess and prioritize detection results, causing inefficiencies in analysis services.

Innovation Solution

An information processing apparatus connected to vehicles and a threat information server, which determines attack priority levels based on whether the attack is recorded, its resolution state, and countermeasure application, allowing for automated and differentiated priority assignment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If priority evaluation is based on matching rates of maintenance target system and threat information, then analysts can process detection results preferentially, but when large number of same attacks are detected with high risk, all detection results are assigned high priority levels causing manual reassessment burden

Engineering Contradiction:
Improveattack processing efficiencyVSAvoidanalyst workload
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments the priority evaluation process by introducing multiple evaluation dimensions: whether the attack type is recorded in the threat information server, the resolution state of the attack, and the number of detected attacks. This segmentation allows differentiated priority assignment rather than uniform high priority for all similar attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different priority levels to different detection results based on their specific characteristics. Detection results are classified into first priority (unrecorded attack types), second priority (recorded but unresolved), and third priority (recorded and resolved), ensuring each detection result receives appropriate priority treatment based on its local context

Inventive Principle:
Principle #3Local quality

2Reliability

If all detection results of same attacks are assigned high priority levels, then important attacks are not missed, but analysts have to manually reassign priority levels reducing analysis service efficiency

Engineering Contradiction:
Improveattack detection completenessVSAvoidmanual reassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary automatic priority assignment based on pre-established evaluation criteria before analyst review. By automatically classifying detection results into priority levels using recorded attack types and resolution states, the system prepares the work in advance, reducing the time analysts need to spend on manual reassessment while maintaining reliable detection coverage

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual reassessment of priority levels is required, then accurate priority assignment can be achieved, but analysis service efficiency is reduced

Engineering Contradiction:
Improvepriority level accuracyVSAvoidanalysis service throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system implements self-service by automatically evaluating and assigning priority levels to detection results using predefined criteria. The threat information server automatically determines whether attack types are recorded, checks resolution states, and assigns appropriate priority levels without requiring analyst intervention, thereby maintaining accurate priority assignment while significantly improving analysis service throughput

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4135261B1Information processing device, information processing method, and program
Publication Date: 2024.04.17 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • EP4135261B1 patent drawingFigure 1~2
  • EP4135261B1 patent drawingFigure 3~4
  • EP4135261B1 patent drawingFigure 5~6

AI summary

An information processing apparatus (100) includes: an obtaining unit (1001) which obtains a detection result of an attack on one of vehicles connected to the information processing apparatus (100); a first determining unit (1002) which determines whether the attack is included in any one of the pieces of threat information stored in a threat information server; a second determining unit (1003) which determines, when the attack is included therein, whether the resolution state to the attack included in the one of the pieces of threat information indicates that the attack has not been resolved or has been resolved; a deciding unit (1007) which decides a processing priority level of the attack, based on the result of determination made by the first determining unit (1002) and the result of determination made by the second determining unit (1003); and an output unit (1009) which outputs the processing priority level decided by the deciding unit (1007).