Vehicle Log Analysis Using Context-Based Attack Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Analyzing cyber-attacks on connected vehicles is resource-intensive due to the need to examine a large number of logs, making it costly and time-consuming to determine if an anomaly is caused by an attack.
Innovation Solution
An information processing apparatus and method that utilize a monitoring server to analyze logs from vehicles, where anomaly scores are calculated and context information is generated to determine the likelihood of an attack, allowing for the comparison with known events and contexts to reduce the need for extensive analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If anomaly detection techniques are applied to analyze all logs to identify cyber-attacks, then detection accuracy is improved, but calculation load and analysis cost increase significantly
Solution Approach 1:
The patent segments the log analysis process into two distinct stages: (1) anomaly detection stage that identifies suspicious events using lightweight rules, and (2) detailed analysis stage that performs comprehensive investigation only on segmented suspect events. This segmentation allows the system to process all logs for basic anomaly detection while reserving heavy calculation resources for only the minority of events that require deep analysis, thereby resolving the contradiction between detection accuracy and calculation load.
Solution Approach 2:
The patent applies local quality by differentiating the analysis depth based on event characteristics. Normal events receive minimal processing, while events identified as anomalies receive focused, intensive analysis. This localized approach ensures that high calculation resources are concentrated only where needed (on suspect events) rather than uniformly applied to all logs, reducing overall calculation load while maintaining detection accuracy for critical events.
2Reliability
If comprehensive log analysis is performed on all detected anomaly events to determine if they are cyber-attacks, then detection reliability is improved, but time and effort required increase
Solution Approach 1:
The patent implements preliminary action by performing anomaly detection and event segmentation before detailed analysis. The system pre-identifies suspect events using lightweight anomaly detection rules, preparing a filtered list of events that require comprehensive analysis. This preliminary filtering action ensures that time-consuming detailed analysis is performed only on events with high probability of being cyber-attacks, thereby improving reliability for critical events while reducing overall analysis time.
Solution Approach 2:
The patent applies partial action by performing comprehensive detailed analysis only on the portion of events that are identified as anomalies, rather than applying full analysis to all logs. The system performs excessive analysis (detailed investigation) only where necessary (on suspect events), and minimal analysis elsewhere, optimizing the balance between reliability and time consumption.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A storage processing unit configured to store, in a storage unit, first data output by a device or any one of multiple devices in association with first context information related to the first data, and a determining unit configured to obtain second context information related to second data in a case where the second data is received from the device or any one of the multiple devices, and determine whether an analysis of the received second data is necessary based on the received second data and the obtained second context information and based on the first data and the first context information stored in the storage unit, are provided.