In-Vehicle Network Log Generation for Anomaly Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for detecting anomalous messages in in-vehicle networks, such as those using the CAN standard, face challenges in identifying and investigating messages transmitted externally, particularly when a malicious third party gains control of an ECU, leading to difficulties in determining message anomalies post-transmission.

Innovation Solution

A log generation method that performs multiple determination processes using different methods to assess whether messages sent to the in-vehicle network are anomalous, generating a log based on these processes, and transmitting only the necessary information, which includes distinct items based on the combined results of these processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple determination processes are performed using different methods to detect anomalous messages, then the detection accuracy and reliability are improved, but the device complexity and processing time increase

Engineering Contradiction:
Improveanomaly detection reliabilityVSAvoiddetermination process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The anomaly detection system is divided into multiple independent determination processes (first determination process using transmission cycle, second determination process using message ID frequency, third determination process using data field analysis). Each process independently analyzes different aspects of message anomalies and generates separate determination results, which are then combined to achieve comprehensive detection with high reliability without requiring a single complex detection mechanism

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The log generation device performs multiple determination processes that can detect various types of anomalies (transmission cycle anomalies, message ID frequency anomalies, data field anomalies) using a single integrated system. The device universally handles different anomaly detection methods and combines their results to provide comprehensive anomaly detection capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If comprehensive log information is generated including all determination process results, then the investigation capability is improved, but the data volume and storage requirements increase

Engineering Contradiction:
Improveanomaly investigation informationVSAvoidlog data volume
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The log generation device extracts only the necessary determination results from multiple determination processes based on anomaly presence. When anomalies are detected, only the relevant determination results corresponding to the detected anomalies are included in the log, rather than including all possible determination results. This extracts essential information while minimizing unnecessary data volume

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The log information is customized based on the specific anomaly detection needs. Different determination results are selectively included in the log depending on which anomalies are actually detected, making the log content locally optimized for each specific anomaly case rather than using a fixed comprehensive format for all cases

Inventive Principle:
Principle #3Local quality

3Loss of information

If all determination results are transmitted to external devices, then the analysis capability is improved, but the communication cost and time increase

Engineering Contradiction:
Improveanomaly analysis informationVSAvoidlog transmission time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

Before transmitting logs to external devices, the system extracts and includes only the determination results that are actually needed for anomaly analysis. By filtering out unnecessary determination results that do not correspond to detected anomalies, the transmission data volume is reduced, thereby decreasing communication time and cost while preserving essential anomaly analysis information

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11838303B2Log generation method, log generation device, and recording medium
Publication Date: 2023.12.05 PANASONIC INTELLECTUAL PROPERTY CORP OF AMERICA
  • US11838303B2 patent drawing
  • US11838303B2 patent drawing
  • US11838303B2 patent drawing

AI summary

A log generation method for generating a log of communication on an in-vehicle network includes: performing a plurality of determination processes for determining, by using different methods, whether or not a message sent to the in-vehicle network is anomalous; generating a log in accordance with results of the plurality of determination processes; and transmitting the generated log. In the generating, information items to be included in the log are determined in accordance with a combination of the results of the plurality of determination processes so that the log does not include identical information items.