MALWARE DETECTION METHOD, MALWARE DETECTION DEVICE, AND RECORDING MEDIUM

    公开(公告)号:US20240134983A1

    公开(公告)日:2024-04-25

    申请号:US18402429

    申请日:2024-01-02

    IPC分类号: G06F21/56 G06F11/30

    CPC分类号: G06F21/566 G06F11/3062

    摘要: A malware detection method for a home network system including one or more home appliances that are connected to a home network includes: obtaining a plurality of setting values including at least information indicating a device type and an operating state of a target device subject to malware detection; selecting one detection model out of a plurality of detection models according to the plurality of setting values obtained; obtaining power consumption or current consumption of the target device; and detecting whether the target device is infected with malware, based on stable power or stable current obtained in the obtaining of the power consumption or the current consumption using the one detection model selected in the selecting, when the power consumption indicates stable power that varies within a predetermined range or the current consumption indicates stable current that varies within a predetermined range.

    ANOMALY DETECTION METHOD, RECORDING MEDIUM, AND ANOMALY DETECTION SYSTEM

    公开(公告)号:US20220263849A1

    公开(公告)日:2022-08-18

    申请号:US17739935

    申请日:2022-05-09

    IPC分类号: H04L9/40 H04L67/12

    摘要: An anomaly detection method in an in-vehicle network system in which a plurality of ECUs are connected. Among the plurality of ECUs, at least one ECU includes a detector which determines whether a received message satisfies a predetermined rule, and the at least one ECU transmits the detection result determined to a network. The anomaly detection method includes (i) receiving the detection result from the network, and storing the detection result received in a memory, (ii) determining whether the detection result is received within a predetermined time, and storing a determination result in the memory in association with the detection result, and (iii) outputting a message to the outside, the message including the detection result in association with the determination result.

    INTRUSION PATH ANALYSIS DEVICE AND INTRUSION PATH ANALYSIS METHOD

    公开(公告)号:US20220182404A1

    公开(公告)日:2022-06-09

    申请号:US17665218

    申请日:2022-02-04

    IPC分类号: H04L9/40

    摘要: The control network system is connected to electronic control unit(s) and a communication device, and includes security sensor(s) that transmits a security alert indicating that an indication of a security breach is detected to the network, if the indication is detected in at least one of the network, the electronic control unit(s), or the communication device. The intrusion path analysis device includes: an alert obtainer that obtains the security alert from the security sensor(s); an event obtainer that obtains an event history of an event that occurs in the control network system; and an intrusion path analyzer that performs an analysis on an intrusion path of an attack on the basis of the security alert, the event history, and an intrusion depth indicating an intrusion level to be assumed in a case the security alert occurs, and that outputs a result of the analysis.

    ANOMALOUS VEHICLE DETECTION SERVER AND ANOMALOUS VEHICLE DETECTION METHOD

    公开(公告)号:US20210349997A1

    公开(公告)日:2021-11-11

    申请号:US17380228

    申请日:2021-07-20

    IPC分类号: G06F21/56

    摘要: An anomalous vehicle detection server includes an anomaly score calculator that detects a suspicious behavior different from a predetermined driving behavior based on pieces of vehicle information that are received from a plurality of vehicles, respectively, and are each based on a vehicle log including the content of an event that has occurred in a vehicle system provided in the vehicle, and acquires an anomaly score of each of the plurality of vehicles that indicates a likelihood that reverse engineering is performed on the vehicle; and an anomalous vehicle determiner that determines whether one vehicle of the plurality of vehicles is an anomalous vehicle based on the anomaly score of the one vehicle and a statistical value of the anomaly scores of two or more vehicles of the plurality of vehicles.

    In-vehicle information processing for unauthorized data

    公开(公告)号:US20210184886A1

    公开(公告)日:2021-06-17

    申请号:US17169958

    申请日:2021-02-08

    摘要: A network hub is provided for an onboard network system. The onboard network system includes first and second networks for transmission of first-type and second-type frames following first and second communication protocols. The network hub includes a receiver that receives a first-type frame. A processor determines whether or not the first-type frame received by the receiver includes first information that is a base for a second-type frame to be transmitted to the second network, to obtain a determination result, and selects a port to send a frame based on the first-type frame based on the determination result. A transmitter sends the frame based on the first-type frame to a wired transmission path connected to the port selected by the processor based on the first-type frame received by the receiver.