Vehicle Network Intrusion Detection via Correlation Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for improved systems and methods to detect and identify unauthorized data intrusions on vehicle networks, particularly those caused by passenger-owned devices, as passenger connectivity increases and the risk of malicious activity grows.
Innovation Solution
A vehicle network system comprising a network processor, storage device, and wireless network-access devices distributed in passenger areas, which uses a correlation engine to detect unauthorized intrusions by analyzing communications information and identifying passenger-owned devices based on unique data communications, network use, and passenger-cabin configuration data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If passenger connectivity is increased to meet growing demand for network access, then passenger convenience and network utilization are improved, but the risk of unauthorized intrusions and malicious activities increases
Solution Approach 1:
The system performs preliminary actions by continuously monitoring and storing communications information from passenger devices before intrusions occur. The correlation engine maintains a database of device identifiers, communication patterns, and passenger information in advance, enabling rapid identification and response when unauthorized activities are detected, thus preventing potential harm while maintaining connectivity.
2Reliability
If network monitoring and security detection capabilities are enhanced to identify intrusions, then network security is improved, but system complexity and processing requirements increase
Solution Approach 1:
The correlation engine serves as an intermediary component that bridges network monitoring and passenger identification. It collects communications information from multiple sources, correlates it with passenger data, and presents integrated results to security systems. This intermediary approach simplifies the overall system architecture by centralizing complex correlation tasks rather than distributing them across multiple systems.
Solution Approach 2:
The system creates copies of communications information and stores them in the correlation-engine storage area for later analysis. By maintaining copies of device identifiers, communication patterns, and passenger information, the system enables rapid security investigations without requiring real-time processing of all network traffic, thus reducing immediate processing demands while enhancing security capabilities.
3Measurement precision
If communications information is stored and analyzed to identify intruding devices, then intrusion identification accuracy is improved, but data storage requirements and processing time increase
Solution Approach 1:
The correlation engine extracts only the essential and relevant communications information needed for intrusion identification, such as device identifiers, communication patterns, and passenger information. By selectively extracting and storing only critical data elements rather than all possible network communications, the system achieves high identification accuracy while minimizing data storage requirements and processing overhead.
Data Source
AI summary
A vehicle network system is configured to detect unauthorized intrusions by a passenger-owned device, and to identify the passenger-owned device based at least in part on stored information representative of network communications. The vehicle network system can be further configured to determine a position of the intruding passenger-owned device within a passenger area of the vehicle and to obtain a name and/or camera image of a passenger associated with the device. The position of the intruding device can be identified based at least in part on communications between the intruding device and one or more network-access devices distributed throughout the passenger area.


