IP Library Granted Patent US 10,708,293
Granted Patent B2
US 10,708,293 · App. 15/196,338 · Granted Jul 7, 2020

System and method for time based anomaly detection in an in-vehicle communication network

Inventors: Yaron Galula (Kadima, IL); Ofer Ben-Noon (Rishon-LeZion, IL); Oron Lavi (Kfar Saba, IL); Ofer Kapota (Rishon LeZion, IL); Alexei Kovelman (Raanana, IL)
Assignee: Argus Cyber Security Ltd.
H04L63/1441B60R16/0231B60R16/0232B60R21/01B60R25/10B60R25/30G07C5/0816G07C5/0841H04L63/02H04L63/123H04L63/1416H04L63/1425H04L63/20H04L67/12H04W12/10H04W12/12B60R2021/01197H04W12/00502H04W12/00505H04W12/00508
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,708,293
App. No.
15/196,338
Granted
Jul 7, 2020
Kind
B2
Abstract

A system and method for providing security to a network may include maintaining, by a processor, a model of an expected behavior of data communications over the in-vehicle communication network; receiving, by the processor, a message sent over the network; determining, by the controller, based on the model and based on a timing attribute of the message, whether or not the message complies with the model; and if the message does not comply with the model then performing, by the processor, at least one action related to the message.

Claims (60)

1. A system including a non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform timing-based cyber-security operations, the operations including:

maintaining a timing model of an expected behavior of data communications over an in-vehicle communication network;

receiving a plurality of messages communicated over the network;

determining, based on:

monitoring time lapses related to the plurality of messages having a message ID value,

calculating an average time lapse for a message ID value, and

relating the average time lapse to a threshold included in the timing model

whether or not at least one of the messages is related to an anomaly; and

if at least one message is related to an anomaly then performing, by the processor, at least one action related to the message;

wherein the action is at least one of: disabling a component connected to the network, activating a component connected to the network, blocking a message, delaying a message, limiting a frequency of a message type, logging a message, and alerting.

2. The system of claim 1 , wherein the threshold is dynamically modified.

3. The system of claim 1 , wherein the processor is configured to:

determine a context related to at least one of: the vehicle, the network, and a node connected to the network; and

determine a message is related to an anomaly based on the context.

4. The system of claim 1 , wherein the processor is configured to:

identify an event related to at least one of: the vehicle, the network, and a node connected to the network; and

determine a message is related to an anomaly based on the event.

5. The system of claim 1 , wherein the at least one action related to the message includes isolating a portion of the network from the rest of the in-vehicle communication network in order to isolate a source of a message related to an anomaly.

6. The system of claim 1 , wherein the processor is configured to:

determine a whether or not a component connected to in-vehicle communication network is malfunctioning based on one or more messages; and

generate an indication related to the malfunctioning component.

7. The system of claim 1 , wherein performing, by the processor, at least one action related to the message includes:

calculating a confidence level of a message being related to an anomaly; and

performing an action based on the confidence level.

8. The system of claim 1 , wherein maintaining the timing model and performing the at least one action is performed in real-time.

9. The system of claim 1 , wherein if the message does not comply with the timing model then excluding the message from subsequent calculation of an average time lapse.

10. A method comprising:

maintaining, by a processor, a timing model of an expected behavior of data communications over the in-vehicle communication network;

receiving, by the processor, a plurality of messages sent over the network;

determining, by the controller, based on:

monitoring time lapses related to the plurality of messages having a message ID value;

calculating an average time lapse for a message ID value; and

based on relating the average time lapse to a threshold included in the timing model,

whether or not at least one of the messages related to an anomaly; and

if the message does not comply with the timing model then performing, by the processor, at least one action related to the message;

wherein the action is at least one of: disabling a component connected to the network, activating a component connected to the network, blocking a message, delaying a message, limiting a frequency of a message type, logging a message, and alerting.

11. The method of claim 10 , wherein the threshold is dynamically modified.

12. The method of 10 , comprising:

determining a context related to at least one of: the vehicle, the network, and a node connected to the network; and

determining whether or not a message complies with the timing model based on the context.

13. The method of 10 , comprising:

identifying an event related to at least one of: the vehicle, the network, and a node connected to the network; and

determining whether or not a message complies with the timing model based on the event.

14. The method of 10 , wherein the at least one action related to the message includes isolating a portion of the network from the rest of the in-vehicle communication network in order to isolate a source of a message related to an anomaly.

15. The method of 10 , comprising:

determining whether or not a component connected to in-vehicle communication network is malfunctioning based on one or more messages; and

generating an indication related to the malfunctioning component.

16. The method of 10 , comprising:

calculating a confidence level of a message being related to an anomaly; and

wherein performing the action is based on the confidence level.

17. A method for enforcing security in a communication network, the method comprising:

maintaining, by a processor, a timing model related to messages communicated on the network;

receiving a first message and a second message communicated on the network;

determining, based on:

monitoring time lapses related to the plurality of messages having a message ID value,

calculating an average time lapse for a message ID value, and

relating the average time lapse to a threshold included in the timing model,

whether or not at least one of the first and second messages is related to an anomaly; and

if at least one of the first and second messages is related to an anomaly then performing at least one action related to the messages;

wherein the action is at least one of: disabling a component connected to the network, activating a component connected to the network, blocking a message, delaying a message, limiting a frequency of a message type, logging a message, and alerting.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069691/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2017
From: GALULA, YARON; BEN-NOON, OFER; LAVI, ORON; KAPOTA, OFER; KOVELMAN, ALEXEI
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 041835/0839 →
Continuity (2)
Provisional Application 62185929 · Jun 29, 2015
Related Publication 20160381059A1 · Dec 29, 2016