On-Vehicle Device Log Management for Anomaly Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle log management systems fail to collect appropriate log information effectively, especially when cyber-attack patterns change, leading to inefficient log data collection.
Innovation Solution
An on-vehicle device capable of communicating with a server, which receives and stores log acquisition requirements, detects anomalies, acquires relevant logs based on designated anomaly points, and transmits them to the server, allowing for targeted and efficient log collection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the same type of log information is simply and uniformly collected, then the log collection process is simple, but appropriate log information cannot be collected when cyber-attack patterns change
Solution Approach 1:
The system performs preliminary actions by pre-defining multiple log acquisition patterns (first through fourth patterns) that correspond to different anomaly types and attack scenarios. When an anomaly is detected, the system selects and executes the appropriate pre-configured pattern, enabling rapid adaptation to changing attack patterns without requiring complex real-time analysis or system reconfiguration.
2Productivity
If log information is collected uniformly from all sources, then comprehensive log data is obtained, but the efficiency and relevance of log collection decreases
Solution Approach 1:
The system applies local quality by defining different log acquisition patterns tailored to specific anomaly types and system components. Each pattern (first through fourth) targets specific log sources and parameters relevant to particular attack scenarios, ensuring that log collection is both efficient and highly relevant to the detected anomaly without unnecessary data gathering.
3Measurement precision
If detailed and specific log information is collected for each anomaly type, then appropriate log information is obtained, but the log collection system becomes complex
Solution Approach 1:
The system resolves the complexity issue by performing preliminary configuration of multiple detailed log acquisition patterns. Each pattern is pre-defined with specific log sources, parameters, and filtering criteria tailored to different anomaly types. This allows the system to maintain high measurement precision for log information while avoiding complex real-time decision-making, as the appropriate detailed collection strategy is already predetermined.
Data Source
AI summary
An on-vehicle device according to the present disclosure is capable of communicating with a server and mounted on a vehicle. The on-vehicle device includes a memory, and a hardware processor coupled to the memory. The hardware processor is configured to: receive, from the server, a log acquisition requirement including an anomaly detected point portion that designates one or more anomaly detected points and a log acquisition target portion that indicates one or more logs to be acquired when an anomaly is detected at the one or more anomaly detected points designated by the anomaly detected point portion; store the log acquisition requirement; detect an anomaly of the vehicle; acquire, when detecting an anomaly, a log based on a part where an anomaly is detected and the log acquisition requirement; and transmit the acquired log to the server.


