IP Library Granted Patent US 10,298,612
Granted Patent B2
US 10,298,612 · App. 15/196,301 · Granted May 21, 2019

System and method for time based anomaly detection in an in-vehicle communication network

Inventors: Yaron Galula (Kadima, IL); Ofer Ben-Noon (Rishon-LeZion, IL); Oron Lavi (Kfar Saba, IL)
Assignee: Argus Cyber Security Ltd.
H04L63/1441B60R16/0231B60R16/0232B60R21/01B60R25/10B60R25/30G07C5/0816G07C5/0841H04L63/02H04L63/123H04L63/1416H04L63/1425H04L63/20H04L67/12H04W12/10H04W12/12B60R2021/01197
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,298,612
App. No.
15/196,301
Granted
May 21, 2019
Kind
B2
Abstract

A system and method for providing security to a network may include maintaining, by a processor, a model of an expected behavior of data communications over the in-vehicle communication network; receiving, by the processor, a message sent over the network; determining, by the processor, based on the model and based on a timing attribute of the message, whether or not the message complies with the model; and if the message does not comply with the model then performing, by the processor, at least one action related to the message.

Claims (51)

1. A system including a non-transitory computer readable medium including instructions that, when executed by at least one hardware processor, cause the at least one hardware processor to perform timing-based cyber-security operations, the operations including:

maintaining a model of an expected timing behavior of data communications over an in-vehicle communication network, the model including a counter threshold value and a time laps threshold value;

receiving first and second messages communicated over the in-vehicle communication network, wherein the first and second messages include the same message ID value;

if the time lapse between receptions of the first and second messages is greater than the time laps threshold value then increasing a value in a counter;

if the value in the counter is greater than the counter threshold value then determining at least one of the messages is anomalous; and

if at least one of the first and second messages is anomalous then performing, by the processor, at least one action related to the anomalous message.

2. The system of claim 1 , wherein

if the time lapse between receptions of the first and second messages is less than a time lapse threshold included in the model then determining that at least one of the first and second messages is related to an anomaly.

3. The system of claim 1 , wherein

if the time lapse between receptions of the first and second messages is greater than the time lapse threshold then determining that at least one of the first and second messages is related to an anomaly.

4. The system of claim 1 , wherein the processor is further configured to reset the counter to a predefined value if a predefined number of consecutive valid messages are identified.

5. The system of claim 1 , wherein the processor is further configured to dynamically modify the time lapse threshold value.

6. The system of 1 claim, wherein the processor is further configured to:

determine a context related to at least one of: the vehicle, the network, and a node connected to the network; and

determine whether or not a message is related to an anomaly based on the context.

7. The system of claim 1 , wherein the processor is further configured to:

identify an event related to at least one of: the vehicle, the network, and a node connected to the network; and

determine a message is related to an anomaly based on the event.

8. The system of claim 1 , wherein the at least one action related to the message includes isolating a portion of the network from the rest of the in-vehicle communication network in order to isolate a source of a message related to an anomaly.

9. The system of claim 1 , wherein the processor is further configured to:

determine a component connected to an in-vehicle communication network is malfunctioning based on one or more messages; and

generate an indication related to the malfunctioning component.

10. The system of claim 1 , wherein if at least one message does not comply with the model then performing, by the processor, at least one action related to the message comprises:

calculating a confidence level of a message being related to an anomaly; and

performing an action based on the confidence level.

11. The system of claim 1 , wherein an action related to the message is at least one of: disabling a component connected to the network, activating a component connected to the network, blocking a message, delaying a message, limiting a frequency of a message type, logging a message and alerting.

12. The system of claim 1 , wherein the hardware processor is further configured to:

determine whether or not at least one of the messages complies with the model by:

comparing a time lapse between receptions of first and second messages to at least two time lapse thresholds; and

determining at least one of the messages does not comply with the model if at least one of the time lapse thresholds is breached.

13. A method comprising:

maintaining, by a hardware processor, a model of an expected behavior of data communications over an in-vehicle communication network, the model including a counter threshold value and a time laps threshold value;

receiving, by the processor, first and second messages sent over the in-vehicle communication network, wherein the first and second messages include the same message ID value;

if the time lapse between receptions of the first and second messages is greater than the time laps threshold value then increasing a value in a counter;

if the value in the counter is greater than the counter threshold value then determining, by the processor, least one of the messages is anomalous; and

if at least one of the messages is anomalous then performing, by the processor, at least one action related to the message.

14. The method of claim 13 , comprising:

if the time lapse between receptions of the first and second messages is less than a time lapse threshold included in the model then determining that at least one of the first and second messages is related to an anomaly.

15. The method of claim 13 , comprising:

if the time lapse between receptions the first and second messages greater than the time lapse threshold then determining that at least one of the first and second messages is related to an anomaly.

16. The method of claim 13 , comprising:

if a time lapse between receptions of the first and second messages is less than a threshold value included in the model then increasing a counter, and

if the counter is greater than a counter threshold value included in the model then determining that at least one of the first and second messages is related to an anomaly.

17. The method of claim 16 , comprising resetting the counter to a predefined value if a predefined number of consecutive valid messages are identified.

18. The method of claim 13 , comprising dynamically modifying the counter threshold value.

19. A method for enforcing security in a communication network, the method comprising:

maintaining, by a hardware processor, a model related to messages communicated on an in-vehicle data communication network, the model including a counter threshold value and a time laps threshold value;

receiving first message and second message communicated on the in-vehicle data communication network, wherein the first and second messages include the same message ID value;

if the time interval between receptions of the first and second messages is greater than the time laps threshold value then increasing a value in a counter;

if the value in the counter is greater than the counter threshold value then determining, whether or not at least one of the first and second messages is related to an anomaly; and

if at least one of the first and second messages is related to an anomaly then performing at least one action related to the messages.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069691/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2017
From: GALULA, YARON; BEN-NOON, OFER; LAVI, ORON
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 042820/0515 →
Continuity (2)
Provisional Application 62185929 · Jun 29, 2015
Related Publication 20160381068A1 · Dec 29, 2016
Cited By (2)
US 12,190,653 US 12,531,887