IP Library Granted Patent US 12665914
Granted Patent B2
US 12665914 · App. 18/583,198 · Granted Jun 23, 2026

Vehicle security analysis apparatus, and method and program storage medium

Inventors: Satoshi Ueno (Tokyo, JP); Atsushi Wakasugi (Yokohama, JP); Kensuke Nakata (Tokyo, JP); Yasunobu Chiba (Tokyo, JP)
Assignees: NTT Docomo Business, Inc.; NTT Security (Japan) KK
H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12665914
App. No.
18/583,198
Granted
Jun 23, 2026
Kind
B2
Abstract

The vehicle security analysis apparatus generates, based on sensor log data items generated in in-vehicle devices, a combination of sensor log data items by associating a plurality of sensor log data items having a possibility of constituting the same individual attack, and identifies an individual attack pattern by comparing this combination of the sensor log data items with individual attack knowledge information. Next, a combination of a plurality of individual attack patterns that have occurred within a predetermined time period is compared with attack scenario knowledge information to identify an attack scenario. Then, the analysis result including the identified individual attack pattern and attack scenario is output.

Claims (32)

1 . A vehicle security analysis apparatus for acquiring and analyzing sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the apparatus comprising:

processing circuitry configured to

acquire and store the sensor log data;

generate multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack from among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) compare the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generate first analysis information that includes information indicating the identified individual attack pattern, such that the processing circuitry identifies multiple individual attack patterns corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;

compare the plurality of individual attack patterns obtained within a predetermined time period with attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generate second analysis information that includes information indicating the identified attack scenarios; and

output an analysis result including the generated first analysis information and the generated second analysis information.

2 . The vehicle security analysis apparatus according to claim 1 ,

wherein the processing circuitry is configured to select a sensor log data item as an analysis target for the individual attack to be analyzed from among the items of the stored sensor log data and provide the selected sensor log data item as the analysis target.

3 . The vehicle security analysis apparatus according to claim 1 , further comprising:

wherein the processing circuitry is configured to add extension information necessary for analysis of the individual attack pattern to the items of the stored sensor log data based on contents of the sensor log data and provide the sensor log data to which the extension information is added, as an analysis target.

4 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry generates the combination of the items of the sensor log data by associating a plurality of items of the sensor log data having identical identification information of a vehicle that serves as a generation source of the sensor log data and having generation times within a specific time period.

5 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry compares information included in the sensor log data with the plurality of individual attack patterns, the information indicating at least one of a sensor installation location and a sensor type, and the first analysis processing unit thereby identifies the corresponding individual attack pattern.

6 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry generates the first analysis information by describing contents of the items of the sensor log data that constitute an individual attack pattern, in a template predefined for each of the identified plurality of individual attack patterns.

7 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry determines whether or not an identified individual attack pattern is information to be provided for analysis of the attack scenario based on a determination condition predefined for an analysis target of the attack scenario, and does not provide the individual attack pattern to the second analysis processing unit if the individual attack pattern is not to be provided.

8 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry compares the plurality of individual attack patterns with the attack scenarios predefined as the attack scenario knowledge information, and identifies the attack scenario that includes the plurality of individual attack patterns and in which occurrence timings of the plurality of individual attack patterns are included within a predetermined time period.

9 . The vehicle security analysis apparatus according to claim 1 , wherein

wherein the processing circuitry generates the second analysis information by describing the plurality of individual attack patterns included in the attack scenario and contents of the items of the sensor log data that constitute the plurality of individual attack patterns, in a template predefined for each of the identified attack scenarios.

10 . A vehicle security analysis method executed by an apparatus that acquires and analyzes sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the vehicle security analysis method comprising:

acquiring and storing the sensor log data;

generating multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) comparing the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generating first analysis information including information indicating the identified individual attack pattern, such that multiple individual attack patterns are identified corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;

comparing a combination of the plurality of individual attack patterns obtained within a predetermined time period with a plurality of attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generating second analysis information including information indicating the identified attack scenarios; and

outputting an analysis result including the generated first analysis information and the generated second analysis information.

11 . A non-transitory computer-readable medium storing a program for causing a processor included in a vehicle security analysis apparatus to execute a method of acquiring and analyzing sensor log data relating to an operational state of an in-vehicle device mounted on a vehicle, the method comprising:

acquiring and storing the sensor log data;

generating multiple combinations, each combination including a plurality of items of the sensor log data constituting an identical individual attack among a plurality of items of the stored sensor log data, for each of the multiple combinations: (i) comparing the generated combination of the items of the sensor log data with a plurality of individual attack patterns predefined as individual attack knowledge information to identify a corresponding individual attack pattern, and (ii) generating first analysis information including information indicating the identified individual attack pattern, such that multiple individual attack patterns are identified corresponding to each of the multiple combinations, at least two of the attack patterns having an overlapping item of sensor log data;

comparing a combination of the individual attack patterns obtained within a predetermined time period with a plurality of attack scenarios predefined as attack scenario knowledge information to identify multiple different attack scenarios each constituted by the plurality of individual attack patterns, and generating second analysis information including information indicating the identified attack scenarios; and

outputting an analysis result including the generated first analysis information and the generated second analysis information.