ANOMALY DETECTION DEVICE AND ANOMALY DETECTION METHOD

    公开(公告)号:US20210281595A1

    公开(公告)日:2021-09-09

    申请号:US17330020

    申请日:2021-05-25

    Abstract: An anomaly detection device (IDS ECU) includes a detection rule generator that monitors a communication establishment frame flowing over Ethernet in a communication establishment phase of service-oriented communication and that generates, for each communication ID, a detection rule including the communication ID written in the communication establishment frame and a server (or client) address written in the communication establishment frame; an anomaly detector that monitors a communication frame flowing over the Ethernet in a communication phase of the service-oriented communication and that, by referring to a detection rule that includes a communication ID written in the communication frame, detects the communication frame as an anomalous frame when a server (or client) address written in the communication frame differs from a server (or client) address included in the detection rule; and an anomaly notifier that provides a notification of an anomaly in response to the anomalous frame being detected.

    ANOMALY DETECTION METHOD AND ANOMALY DETECTION DEVICE

    公开(公告)号:US20210044610A1

    公开(公告)日:2021-02-11

    申请号:US17082431

    申请日:2020-10-28

    Abstract: An anomaly detection device included in a communication network adopting a time-triggered protocol based on a time slot includes: a frame transceiver that receives frames; and an anomaly detector that detects an occurrence of an anomalous frame in accordance with a time slot among a plurality of time slots included in a cycle and the number of repeated cycles of the cycle for each frame. The anomaly detector detects an occurrence of an anomalous frame by verifying a statistic on the frames received while the cycle is repeated a predetermined number of times, which is at least once, against a rule indicating a reference range of the statistic.

    INTEGRITY VERIFICATION DEVICE AND INTEGRITY VERIFICATION METHOD

    公开(公告)号:US20240086541A1

    公开(公告)日:2024-03-14

    申请号:US18515925

    申请日:2023-11-21

    CPC classification number: G06F21/57 G06F21/64 G06F2221/033

    Abstract: An integrity verification device, in which software is executed by one of one or more electronic control units connected to an in-vehicle network system, includes: a verification schedule determiner that determines a verification timing at which to verify the integrity of the software; an integrity verifier that, for the software, determines, at the verification timing determined for the software, whether first integrity information, that is information for verifying the integrity of the software and that corresponds to at least part of the software corresponding to a verification scope, matches second integrity information, that is information calculated from at least part of the software at the verification timing, and determines that the integrity of the software is ensured when the first integrity information and the second integrity information match; and a verification priority determiner that determines a verification priority that affects determining of the verification timing or the verification scope.

    VEHICLE LOG TRANSMISSION DEVICE, VEHICLE LOG ANALYSIS SYSTEM, AND VEHICLE LOG TRANSMISSION/RECEPTION METHOD

    公开(公告)号:US20210226973A1

    公开(公告)日:2021-07-22

    申请号:US17222325

    申请日:2021-04-05

    Abstract: A vehicle log transmission device includes: a vehicle log obtainer that obtains the vehicle log; a vehicle state extractor that extracts a vehicle state from the obtained vehicle log; difference generation log storage that stores a list of difference generation logs, each being a vehicle log for each of vehicle states shared between the vehicle log transmission device and a vehicle log analysis server; a difference generation log selector that selects a difference generation log from the list in accordance with the extracted vehicle state; a difference log generator that generates a difference log based on the obtained vehicle log and the selected difference generation log; and a difference log transmitter that transmits, to the vehicle log analysis server, the generated difference log and a difference generation log identifier corresponding to the selected difference generation log.

    ANTI-FRAUD CONTROL SYSTEM, MONITORING DEVICE, AND ANTI-FRAUD CONTROL METHOD

    公开(公告)号:US20210226966A1

    公开(公告)日:2021-07-22

    申请号:US17224883

    申请日:2021-04-07

    Abstract: In an anti-fraud control system, a first error monitoring device includes a first frame transmitting and receiving unit that receives a frame flowing on the on-board network; and a first error detector that causes transmission of an error notification frame for notifying of an occurrence of an error in the frame when detecting the occurrence of the error in the frame received by the first frame transmitting and receiving unit. Each of second error monitoring devices includes: a second frame transmitting and receiving unit that receives the error notification frame; and a second error detector that regards, as a frame to be invalidated, the frame subjected to the error and included in the received error notification frame, and shifts the second error monitoring device to an invalidation mode for invalidating reception of subsequent frames, if no error is detected in an own branch with respect to the frame.

    ANOMALY MONITORING APPARATUS AND ANOMALY MONITORING METHOD

    公开(公告)号:US20230208859A1

    公开(公告)日:2023-06-29

    申请号:US18112246

    申请日:2023-02-21

    CPC classification number: H04L63/1416 H04L67/12

    Abstract: An anomaly monitoring apparatus in a remote operation system for remotely operating a mobility entity includes: a log collector that collects an operation log from an operation apparatus which remotely operates the mobility entity and a control log from a control apparatus installed in the mobility entity; an anomaly detector that detects whether an anomaly is present in the mobility entity based on at least one of the operation log or the control log; an attack origin identifier that, when the anomaly detector detects an anomaly, identifies an attack origin that caused the anomaly in the mobility entity from among a plurality of attack origins based on a result of comparing the operation log with the control log; and an anomaly notifier that makes a notification for taking a countermeasure for the attack origin identified by the attack origin identifier.

    ANOMALY DETECTING DEVICE, ANOMALY DETECTING SYSTEM, AND ANOMALY DETECTING METHOD

    公开(公告)号:US20220263709A1

    公开(公告)日:2022-08-18

    申请号:US17738837

    申请日:2022-05-06

    Abstract: An anomaly detecting device includes a flow collector that collects an amount of flow communication traffic in each of two or more networks in an in-vehicle network system that including the two or more networks, the amount of flow communication traffic being information obtained by tallying an amount of communication traffic of one or more frames classified according to a predetermined rule that is based on header information of a network protocol; and an anomaly detector that calculates, based on the amount of flow communication traffic, an observed ratio indicating a ratio of respective amounts of communication traffic in the two or more networks and determines whether the two or more networks are anomalous based on the observed ratio calculated and a normal ratio indicating a ratio of respective amounts of communication traffic in the two or more networks in a normal state.

    UNAUTHORIZED FRAME DETECTION DEVICE AND UNAUTHORIZED FRAME DETECTION METHOD

    公开(公告)号:US20210314336A1

    公开(公告)日:2021-10-07

    申请号:US17354213

    申请日:2021-06-22

    Abstract: An unauthorized frame detection device that can keep an unauthorized ECU from spoofing as a legitimate server or client while suppressing an overhead during communication is provided. The unauthorized frame detection device includes a plurality of communication ports corresponding to the respective of networks, a communication controller, and an unauthorized frame detector. The plurality of communication ports are each connected to a corresponding predetermined network among the plurality of networks and each transmit or receive a frame via the predetermined network. The unauthorized frame detector determines whether an identifier of a service, a type of the service, and port information that are each included in the frame match a permission rule set in advance and outputs a result of the determination.

Patent Agency Ranking