IP Library Granted Patent US 11,628,784
Granted Patent B2
US 11,628,784 · App. 15/706,715 · Granted Apr 18, 2023

Fleet monitoring

Inventors: Ofer Ben Noon (Rishon LeZion, IL); Yaron Galula (Kadima, IL); Oron Lavi (Kfar Saba, IL)
Assignee: ARGUS CYBER SECURITY LTD.
B60R16/023B60R25/00G06F11/30G06F21/55G06F21/554G06F21/606G06F21/6281H04L12/4625H04L63/0227H04L63/14H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L67/12H04L63/123H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,628,784
App. No.
15/706,715
Granted
Apr 18, 2023
Kind
B2
Abstract

A system for providing security to a fleet of vehicles, the system comprising: a plurality of modules, each module configured to monitor messages propagating in an in-vehicle network of a vehicle comprised in the fleet; a memory having data characterizing messages, and software executable to: identify an anomaly in communications over the in-vehicle communication network; and instruct a communication interface, configured to support communication with an entity external to the vehicle, to transmit monitoring data responsive to the messages; and a processor configured to execute the software in the memory; and a data monitoring and processing hub external to the vehicles comprised in the fleet and operable to receive transmission of monitoring data from the plurality of modules.

Claims (41)

1. A system for providing security to a fleet of vehicles, the vehicles being real vehicles, the system comprising:

a plurality of modules, each module configured to monitor messages propagating in an in-vehicle network of a vehicle, which is the vehicle the modlule is present on, comprised in the fleet, the in-vehicle network having a bus and at least one node connected to the bus, each module comprising:

at least one communication port connectable to a portion of the in-vehicle network, via which the module receives and transmits messages;

a memory having data characterizing messages that the at least one node transmits and receives during normal operation of the node, and software executable to:

identify, responsive to the data characterizing messages and messages received from the in-vehicle network, an anomaly in communications over the in-vehicle communication network; and

instruct a communication interface, configured to support communication with an entity external to the vehicle, to transmit monitoring data responsive to the received messages; and

a processor configured to execute the software in the memory; and

a data monitoring and processing hub external to the vehicles comprised in the fleet and operable to receive transmission of monitoring data from the plurality of modules and process data in the monitoring data to identify whether within a same specified timeframe a plurality of vehicles having messages monitored by the modules is subject to a same cyber attack and wherein none of the processed data is generated from a message in a communication that the hub instructed a vehicle in the fleet to initiate with a suspected source of malware that the hub identified.

2. The system according to claim 1 , wherein the communication interface is comprised in a module of the plurality of modules.

3. The system according to claim 1 , wherein the communication interface is comprised in a node connected to the bus of an in-vehicle network.

4. The system according to claim 1 , wherein the hub is operable to provide a user interface that displays information regarding health of the fleet with respect to cyber attacks.

5. The system according to claim 4 , wherein the user interface of the hub is operable to display a distribution of anomalous messages detected by at least a portion of the plurality of modules in a specified timeframe.

6. The system according to claim 4 , wherein the user interface of the hub is operable to display a distribution of anomalous messages detected by at least a portion of the plurality of modules in a specified geographical area.

7. The system according to claim 6 , wherein the distribution is displayed as a heat map.

8. The system according to claim 1 , wherein the data comprises a state feature vector representing a state of the vehicle.

9. The system according to claim 8 , wherein the software is executable to change the state feature vector responsive to identifying an anomaly in communications over the in-vehicle communication network.

10. The system according to claim 1 , wherein the software is executable to raise an alert responsive to identifying an anomaly in communications over the in-vehicle communication network.

11. The system according to claim 1 , wherein the software is executable to identify if at least one of the messages received via the at least one communication port is anomalous.

12. The system according to 11 , wherein the monitoring data comprises data relevant to tracking performance of the module, responsive to identifying at least one anomalous message.

13. The system according to claim 12 , wherein the monitoring data comprises information regarding one or more anomalous messages identified by the module.

14. The system according to claim 12 , wherein the hub is operable to track the performance of one or more of the plurality of modules.

15. The system according to claim 14 , wherein the tracking of performance comprises determining how frequently one or more the plurality of modules generates false positives or false negatives in identifying messages as anomalous messages.

16. The system according to claim 1 wherein the module is configured to transmit the monitoring data or a portion thereof based on a request that the module receives from the hub.

17. The system according to claim 16 wherein the transmission of the monitoring data or portion thereof is subject to authenticating the request.

18. The system according to claim 17 wherein the module is configured to stop transmitting the monitoring data or portion thereof in response to a communication from the hub.

19. A system for providing security to a fleet of vehicles, the vehicles being real vehicles, the system comprising:

a plurality of modules, each module configured to monitor messages propagating in an in-vehicle network of one vehicle, which is the vehicle the module is present on, comprised in the fleet, the in-vehicle network having a bus and at least one node connected to the bus, each module comprising:

at least one communication port connectable to a portion of the in-vehicle network, via which the module receives and transmits messages;

a memory having data characterizing messages that the at least one node transmits and receives during normal operation of the node, and software executable to:

identify, responsive to the data characterizing messages and messages received from the in-vehicle network, an anomaly in communications over the in-vehicle communication network; and

instruct a communication interface, configured to support communication with an entity eternal to the vehicle, to transmit monitoring data reponsive to the received messages; and

a procesor configured to execute the software in the memory; and

a data monitoring and processing hub eternal to the vehicles comprised in the fleet and operable to receive transmission of monitoring data from the plurality of modules and process data in the monitoring data to identify whether within a same specified timeframe a plurality of vehicles having messages monitored by the modules is subject to a same probability of failure of a vehicle control system or component and wherein none of the processed data is generated from a message in a communication that the hub instructed a vehicle in the fleet to initiate with a suspected source of malware that the hub identified.

20. A system for providing security to a fleet of vehicles, the vehicles being real vehicles, the system comprising:

a plurality of modules, each module configured to monitor messages propagating in an in-vehicle network of one vehicle, which is the vehicle the module is present on, comprised in the fleet, the in-vehicle network having a bus and at least one node connected to the bus, each module comprising:

at least one communication port connectable to a portion of the in-vehicle network, via which the module receives and transmits messages;

a memory having data characterizing messages that the at least one node transmits and receives during normal operation of the node, and software executable to:

identify an anomaly in communications over the in-vehicle communication network responsive to the data characterizing messages, messages received from the in-vehicle network, and an operation context of the vehicle during transmission of the received messages over the in-vehicle communications network; and

instruct a communication interface, configured to support communiation with an entity external to the vehicle, to transmit monitoring data responsive to the received messages; and

a processor configured to execute the software in the memory; and

a data monitoring and processing hub external to the vehicles comprised in the fleet and operable to receive transmission of monitoring data from the plurality of modules and process data in the monitoring data to identify whether within a same specified timeframe a plurality of vehicles having messages monitored by the modules is subject to a same cyber attack and wherein none of the processed data is generated from a message in a communication that the hub instructed a vehicle in the fleet to initiate with a suspected source of malware that the hub identified.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069691/0310 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2017
From: BEN NOON, OFER; GALULA, YARON; LAVI, ORON
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 043609/0793 →
Continuity (6)
Continuation 14590038 · Jan 6, 2015
Provisional Application 62038856 · Aug 19, 2014
Provisional Application 62038859 · Aug 19, 2014
Provisional Application 61927515 · Jan 15, 2014
Provisional Application 61923790 · Jan 6, 2014
Related Publication 20180029539A1 · Feb 1, 2018
Cited By (1)
US 12,483,577