Vehicle Network Intrusion Detection via Correlation Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved systems and methods to detect and identify unauthorized data intrusions on vehicle networks, particularly those caused by passenger-owned devices, as passenger connectivity increases and the risk of malicious activity grows.

Innovation Solution

A vehicle network system comprising a network processor, storage device, and wireless network-access devices distributed in passenger areas, which uses a correlation engine to detect unauthorized intrusions by analyzing communications information and identifying passenger-owned devices based on unique data communications, network use, and passenger-cabin configuration data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If passenger connectivity is increased to meet growing demand for network access, then passenger convenience and network utilization are improved, but the risk of unauthorized intrusions and malicious activities increases

Engineering Contradiction:
Improvepassenger connectivityVSAvoidunauthorized intrusion risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by continuously monitoring and storing communications information from passenger devices before intrusions occur. The correlation engine maintains a database of device identifiers, communication patterns, and passenger information in advance, enabling rapid identification and response when unauthorized activities are detected, thus preventing potential harm while maintaining connectivity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network monitoring and security detection capabilities are enhanced to identify intrusions, then network security is improved, but system complexity and processing requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The correlation engine serves as an intermediary component that bridges network monitoring and passenger identification. It collects communications information from multiple sources, correlates it with passenger data, and presents integrated results to security systems. This intermediary approach simplifies the overall system architecture by centralizing complex correlation tasks rather than distributing them across multiple systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of communications information and stores them in the correlation-engine storage area for later analysis. By maintaining copies of device identifiers, communication patterns, and passenger information, the system enables rapid security investigations without requiring real-time processing of all network traffic, thus reducing immediate processing demands while enhancing security capabilities.

Inventive Principle:
Principle #26Copying

3Measurement precision

If communications information is stored and analyzed to identify intruding devices, then intrusion identification accuracy is improved, but data storage requirements and processing time increase

Engineering Contradiction:
Improveintrusion identification accuracyVSAvoiddata storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The correlation engine extracts only the essential and relevant communications information needed for intrusion identification, such as device identifiers, communication patterns, and passenger information. By selectively extracting and storing only critical data elements rather than all possible network communications, the system achieves high identification accuracy while minimizing data storage requirements and processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10992689B2Systems and methods for relating network intrusions to passenger-owned devices
Publication Date: 2021.04.27 THE BOEING CO
  • US10992689B2 patent drawing
  • US10992689B2 patent drawing
  • US10992689B2 patent drawing

AI summary

A vehicle network system is configured to detect unauthorized intrusions by a passenger-owned device, and to identify the passenger-owned device based at least in part on stored information representative of network communications. The vehicle network system can be further configured to determine a position of the intruding passenger-owned device within a passenger area of the vehicle and to obtain a name and/or camera image of a passenger associated with the device. The position of the intruding device can be identified based at least in part on communications between the intruding device and one or more network-access devices distributed throughout the passenger area.