Vehicle Log Management Device for Cyber Attack Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vehicles equipped with advanced communication systems are increasingly vulnerable to cyber attacks, which can lead to loss of control, especially at high speeds, necessitating robust defense mechanisms.

Innovation Solution

A security attack detection and analyzing system comprising a log management device mounted on a vehicle and a center device outside the vehicle, where the log management device collects and analyzes security logs, performs statistical analysis, and transmits relevant data to the center device for further analysis and anomaly detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If all security logs are transmitted to the center device for analysis, then the anomaly detection accuracy is improved, but the communication volume and processing load increase significantly

Engineering Contradiction:
Improveanomaly detection accuracyVSAvoidcommunication volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts and transmits only specific log items that are determined to be necessary for anomaly detection, rather than transmitting all security logs. The log management device performs statistical analysis locally to identify which log items contain meaningful information for detecting anomalies, and only these selected items are transmitted to the center device, thereby reducing communication volume while maintaining detection accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs statistical analysis on security logs locally at the log management device before transmission to the center device. This preliminary processing identifies patterns and anomalies in advance, allowing the system to transmit only the most relevant log items rather than all raw logs, thus reducing the communication burden while preserving detection capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all security logs are transmitted to the center device, then comprehensive analysis is improved, but the processing load at the center device increases

Engineering Contradiction:
Improvecomprehensive analysisVSAvoidprocessing load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts only the essential log items that contribute to anomaly detection after performing local statistical analysis. By filtering out redundant information before transmission, the center device receives a reduced set of logs that still enable comprehensive security analysis, thereby reducing its processing load while maintaining analytical completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The log management device acts as an intermediary that performs preliminary statistical analysis and filtering of security logs before forwarding them to the center device. This intermediate processing step reduces the volume of data requiring comprehensive analysis at the center device, distributing the processing load appropriately while ensuring thorough security monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If statistical analysis is performed on all logs at the log management device, then transmission data quality is improved, but the processing load at the log management device increases

Engineering Contradiction:
Improvetransmission data qualityVSAvoidprocessing load at log management device
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent applies partial statistical analysis to security logs at the log management device, focusing only on the aspects necessary for identifying which log items to transmit. Rather than performing exhaustive analysis on all logs, the system performs targeted statistical evaluation to determine transmission priorities, reducing the processing load while maintaining sufficient data quality for effective anomaly detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12341798B2Log management device, log management method, computer program product, and security attack detection and analyzing system
Publication Date: 2025.06.24 DENSO CORP
  • US12341798B2 patent drawing
  • US12341798B2 patent drawing
  • US12341798B2 patent drawing

AI summary

A log management device includes a log collection unit configured to receive a log generated by a security sensor, a storage unit configured to store the log, a statistical analysis unit configured to obtain a statistical calculation result by performing statistical analysis on a plurality of the logs, a control unit configured to determine which of the log and the statistical calculation result is to be sent according to a predetermined condition, and a transmission unit configured to transmit at least one of the log or the statistical calculation result according to the predetermined condition.