In-Vehicle Network Surveillance for Reverse Engineering Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing in-vehicle networks, such as those using encrypted communication and anomaly detection, are inadequate as they do not effectively prevent unauthorized control attempts and can be compromised if a legitimate key is used for unauthorized access, and they do not address the initial stages of reverse engineering by attackers.
Innovation Solution
A vehicle surveillance device and method that monitors in-vehicle networks for suspicious behaviors, calculates a score indicating the likelihood of reverse engineering, and adjusts surveillance levels based on this score to prevent unauthorized access by detecting passive, active, and refinement activities, thereby enhancing network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted communication is used to prevent unauthorized control, then security against unauthorized access is improved, but communication overhead increases and key management complexity increases
Solution Approach 1:
The patent introduces a surveillance device as an intermediary component that monitors communication frames between ECUs. This device calculates suspicion scores based on frame patterns and behaviors, acting as a mediator that enhances security without requiring complex encryption/decryption operations at each ECU, thereby reducing key management complexity while maintaining security
Solution Approach 2:
The surveillance device performs preliminary analysis of communication frames by calculating suspicion scores before unauthorized control can be executed. By detecting anomalous patterns in advance and blocking suspicious frames proactively, the system prevents unauthorized access without needing heavy encryption overhead at the point of control
2Reliability
If anomaly detection methods are used to block unauthorized frames, then security against transmitted attacks is improved, but the system cannot detect passive monitoring or reverse engineering activities
Solution Approach 1:
The surveillance device dynamically adjusts its monitoring approach by calculating suspicion scores that evolve over time based on accumulated frame data. The system adapts to different attack stages (passive monitoring, active monitoring, refinement) by continuously updating score calculations, enabling versatile detection across multiple attack vectors beyond static anomaly detection
Solution Approach 2:
The system implements feedback mechanisms where the surveillance device continuously monitors frame patterns, calculates suspicion scores, and uses this information to enhance detection capabilities. The score calculations incorporate historical frame data and behavioral patterns, creating a feedback loop that improves detection versatility against various attack types including reverse engineering activities
3Speed
If traditional anomaly detection is used, then processing speed is maintained, but the system cannot identify early stages of reverse engineering attempts
Solution Approach 1:
The surveillance device performs partial analysis by calculating suspicion scores based on selected frame attributes and patterns rather than exhaustive analysis of all frame data. This selective approach maintains processing speed while achieving sufficient detection precision for identifying early reverse engineering attempts, avoiding the overhead of complete frame decryption or detailed content analysis
Data Source
AI summary
A vehicle surveillance device for an in-vehicle network system that includes one or more electronic control units includes: a frame transmitter and receiver that receives a frame flowing over the in-vehicle network system; and a score calculator that detects a suspicious behavior different from a normal driving behavior based on the frame received by the frame transmitter and receiver and vehicle data including information on one or more frames received by the frame transmitter and receiver prior to receiving the frame, and calculates, based on a detection result, a score indicating a likelihood that reverse engineering has been performed on a vehicle provided with the in-vehicle network system.


