IP Library Granted Patent US 11,165,851
Granted Patent B2
US 11,165,851 · App. 15/196,094 · Granted Nov 2, 2021

System and method for providing security to a communication network

Inventors: Yaron Galula (Kadima, IL); Ofer Ben-Noon (Rishon-LeZion, IL); Oron Lavi (Kfar Saba, IL); Ofer Kapota (Rishon LeZion, IL); Alexei Kovelman (Raanana, IL)
Assignee: Argus Cyber Security Ltd.
H04L67/10H04L63/14H04L63/1441H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,851
App. No.
15/196,094
Granted
Nov 2, 2021
Kind
B2
Abstract

A system and method for providing security to a network may include identifying a message sent over a network, the message related to a data transfer from an initiator to a target node, and transmitting, over the network, at least one disruptive message that causes the data transfer to fail.

Claims (32)

1. A system for providing cyber security to an in-vehicle communication network comprising:

a vehicle including:

a memory; and

a controller included in a security enforcement unit, the controller configured to:

determine that a message sent from an initiator to a target node, jeopardizes the security of the in-vehicle communication network, wherein the message is related to a data transfer which is related to a diagnostic session and wherein at least one of: the initiator and the target node is connected to the in-vehicle network;

generate a disruptive message designed to terminate or prevent transfer of data over the session; and

send, to at least one of the initiator and the target node, over the in-vehicle communication network, the disruptive message, wherein when sent, the disruptive message prevents the initiator from transferring data to the target node by at least one of:

causing at least one of the initiator and the target node to terminate the session, and

preventing at least one message sent from the initiator from reaching the target node.

2. The system of claim 1 , wherein the identified message is one of: a message sent by the initiator in order to prepare the target node to receive the data transfer and a message sent by the target node in reply to a message sent by the initiator.

3. The system of claim 1 , wherein the disruptive message modifies a state of a node.

4. The system of claim 1 , wherein the controller is further configured to select an operational mode and selectively send disruptive messages based on the selected operational mode.

5. The system of claim 1 , wherein the controller is further configured to select whether or not to send the disruptive message based on a context.

6. The system of claim 1 , wherein the controller is further configured to send a first disruptive message to the initiator and a second disruptive message to the target node.

7. The system of claim 1 , wherein the controller and memory are embedded in a node that is adapted to control at least one system in the vehicle.

8. The system of claim 1 , wherein the controller is further configured to select the disruptive message according to a predefined protocol.

9. The system of claim 1 , wherein the controller is further configured to select the disruptive message based on at least one of: a state of the vehicle, a context, a message received by the controller, the target node and a stage of a session.

10. The system of claim 1 , wherein the controller is further configured to send disruptive messages when in a protective operational mode and monitor traffic on the network when in a passive operational mode.

11. A method for providing cyber security to an in-vehicle network in a vehicle, the method comprising:

determining, by a controller, that a message sent from an initiator to a target node, jeopardizes the security of the in-vehicle network, wherein the message is related to a data transfer which is related to a diagnostic session and wherein at least one of: the initiator and the target node is connected to the in-vehicle network;

generating a disruptive message designed to terminate or prevent transfer of data over the session; and

sending, to at least one of the initiator and the target node, by the controller, over the in-vehicle network, the disruptive message, wherein when sent, the disruptive message prevents the initiator from transferring data to the target node by at least one of:

causing at least one of the initiator and the target node to terminate the session, and

preventing at least one message sent from the initiator from reaching the target node.

12. The method of claim 11 , wherein the identified message is one of: a message sent by the initiator in order to prepare the target node to receive the data transfer and a message sent by the target node in reply to a message sent by the initiator.

13. The method of claim 11 , wherein the disruptive message modifies a state of a node.

14. The method of claim 11 , comprising selecting whether or not to send the disruptive message based on a context.

15. The method of claim 11 , comprising sending a first disruptive message to the initiator and a second disruptive message to the target node.

16. The method of claim 11 , wherein the controller is embedded in a node that is adapted to control at least one system in the vehicle.

17. The method of claim 11 , comprising selecting the disruptive message according to a predefined protocol.

18. The method of claim 11 , comprising selecting the disruptive message based on at least one of: a state of the vehicle, a context, a message received by the controller, the target node and a stage of a session.

19. The method of claim 11 , comprising selecting the disruptive message based on one of: a context, a message received by the controller, the target node and a stage of a session.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069691/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2017
From: GALULA, YARON; BEN-NOON, OFER; LAVI, ORON; KOVELMAN, ALEXEI; KAPOTA, OFER
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 042035/0301 →
Continuity (2)
Provisional Application 62185943 · Jun 29, 2015
Related Publication 20160381055A1 · Dec 29, 2016
Cited By (4)
US 12,339,971 US 12,526,613 US 12,592,951 US 12,719,898