Vulnerability Identification System for Digital Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack comprehensive methods for identifying and mitigating vulnerabilities in digital systems, particularly in transportation means, which are prone to various attacks and threats due to complex interactions among engine control units (ECUs), leading to potential safety and security risks.

Innovation Solution

A computer-implemented method for identifying and classifying vulnerabilities in digital systems and their components, storing this information in a database, and using it to configure systems for reduced vulnerability, monitor for attacks, and control responses to identified threats, employing machine learning and artificial intelligence for proactive measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive vulnerability identification and classification methods are implemented in digital systems, then security reliability is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability identification system is segmented into multiple independent modules: vulnerability data collection module, vulnerability classification module, attack pattern recognition module, and response configuration module. Each module handles specific tasks independently, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A centralized vulnerability database serves as an intermediary between various security components. The database stores classified vulnerability information and attack patterns, enabling different modules to access and share security data without direct complex interactions, thereby simplifying the system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proactive security measures and monitoring are implemented, then security reliability is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary vulnerability classification and attack pattern recognition in advance, storing results in the vulnerability database. This allows the monitoring module to quickly compare current system states against pre-analyzed patterns without performing full vulnerability assessments in real-time, reducing energy consumption during active monitoring.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The monitoring system applies partial action by focusing only on critical vulnerability areas identified through preliminary classification. Rather than continuously monitoring all system components equally, the system concentrates monitoring resources on high-risk areas, reducing overall energy consumption while maintaining effective security coverage.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3772838B1Computer-implemented method of security-related control or configuration of a digital system
Publication Date: 2024.05.22 CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
  • EP3772838B1 patent drawingFigure 1~2
  • EP3772838B1 patent drawingFigure 3~4
  • EP3772838B1 patent drawingFigure 5~6

AI summary

A computer-implemented method of identifying and classifying a plurality of digital systems' and/or their components' vulnerabilities to one or more of a plurality of threats classes and/or attack types includes receiving system information data representing configurations of a plurality of digital systems, and receiving attack and/or threat information data associated with attacks on and/or threats posed to individual ones of the plurality of digital systems. The received system information data and the associated attack and/or threat information data is analysed for identifying one or more attack types and/or threat classes associated with individual ones of the digital systems. For each of the identified attack types and/or treat classes, correlations and/or causalities between individual system constituents or combinations thereof in the digital systems associated with attacks and/or threats are identified. Based on the identified correlations and/or causalities, an attack and/or threat vulnerability value is determined and assigned, for each attack or threat, respectively, to each of the systems and/or systems' constituents and/or combinations thereof. The attack and/or threat vulnerability values associated with the systems, system constituents and/or combinations thereof are retrievably stored.