Vehicle IDS Rule Generation for Model-Specific Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face challenges in generating and outputting detection rules for each vehicle model to detect abnormalities in in-vehicle networks, requiring significant effort and specialized knowledge, as the configuration of in-vehicle networks varies.

Innovation Solution

A detection rule output method that acquires vehicle configuration information, IDS information, and attack information to generate detection rules for identifying abnormality locations and details, including attack paths and scenarios, which can be easily output to a storage device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If detection rules are generated manually for each vehicle model, then detection accuracy can be improved, but the time and expertise required increase significantly

Engineering Contradiction:
Improvedetection accuracyVSAvoidtime required for rule generation
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables self-service by allowing the detection rule generation to be performed automatically based on vehicle configuration information and attack scenarios, without requiring manual intervention or expert knowledge. The detection rule output device autonomously generates rules by processing input data about the in-vehicle network and desired detection targets.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of creating detection rules through expert knowledge with an automated information processing system. The detection rule output device uses computational methods to generate rules by processing vehicle configuration data, IDS information, and attack scenario definitions, substituting human expertise with an automated system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If detection rules are customized for each vehicle model, then detection specificity improves, but device complexity increases

Engineering Contradiction:
Improvedetection specificityVSAvoidcomplexity of rule generation system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the detection rule generation process into distinct functional components: acquiring vehicle configuration information, acquiring IDS information, acquiring attack scenario definitions, generating detection rules, and outputting them. This segmentation allows each component to handle specific tasks independently, reducing overall system complexity while maintaining customization capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The detection rule output device is designed as a universal system that can generate detection rules for multiple vehicle models by processing their respective configuration information through the same automated process. This multi-functionality eliminates the need for separate manual rule creation processes for each model, reducing complexity while maintaining specificity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If manual detection rule creation is used, then rule accuracy can be maintained, but ease of operation decreases

Engineering Contradiction:
Improverule accuracyVSAvoidease of rule generation
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system implements self-service by automatically generating detection rules based on input data about the vehicle network and attack scenarios. Users simply provide the necessary configuration information and desired detection targets, and the system autonomously creates accurate rules without requiring operational expertise or manual rule crafting.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The detection rule output device acts as an intermediary between the raw vehicle configuration data and the final detection rules. It processes and transforms the input information through automated logic, mediating between the simple input data and the complex detection rules, thereby maintaining accuracy while improving ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12615269B2Detection rule output method, security system, and detection rule output device
Publication Date: 2026.04.28 PANASONIC AUTOMOTIVE SYST CO LTD
  • US12615269B2 patent drawing
  • US12615269B2 patent drawing
  • US12615269B2 patent drawing

AI summary

A detection rule output method is a detection rule output method for outputting a detection rule used in a security system that determines attack details based on log information of a vehicle, the detection rule output method including: acquiring vehicle configuration information regarding a configuration of an in-vehicle network provided in the vehicle, intrusion detection system (IDS) information regarding one or more intrusion detection systems (IDSes) mounted in the vehicle, and attack information to be detected regarding an attack on the vehicle to be detected; and outputting, to a storage device included in the security system, the detection rule that is a detection rule for detecting a location in the vehicle where an abnormality has occurred and the abnormality that has occurred in the location, and is generated based on the vehicle configuration information, the IDS information, and the attack information to be detected.