IP Library Granted Patent US 12,438,894
Granted Patent B2
US 12,438,894 · App. 15/992,257 · Granted Oct 7, 2025

System and method for providing fleet cyber-security

Inventors: Yaron Galula (Kadima, IL); Ofer Ben-Noon (Rishon-LeZion, IL)
Assignee: PlaxidityX Ltd
H04L63/1425G06F21/552H04L63/1416H04W4/44H04W12/12H04L43/062H04L63/1433H04L67/12H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,894
App. No.
15/992,257
Granted
Oct 7, 2025
Kind
B2
Abstract

A system and method for providing fleet cyber-security comprising may include collecting, by a plurality of data collection units installed in a respective plurality of vehicles in the fleet, information related to cyber security and including the information in reports to a server. Data in reports may be aggregated, by the server. A cyber-attack may be identified based on aggregated data.

Claims (74)

1. A system for providing cyber-security to a fleet of vehicles, the system comprising:

a server included in a security operations center (SOC) managing cyber-security of the fleet, the server comprising:

a memory; and

a processor adapted to:

receive from a plurality of data collection units (DCUs) installed in a respective plurality of vehicles in the fleet, a plurality of reports, the reports including information collected by the DCUs and related to cyber security;

correlate information received from a first DCU installed in a first vehicle with information received from a second DCU installed in a second vehicle that is separate from the first vehicle,

based on the correlation, identify at least one of:

a common time of an occurrence of a common event,

a common geographic place,

a common component included in the vehicles,

a common service facility,

a common manufacturer of a common element,

a common source of network messages, and

an attribute which is common to a plurality of vehicles in the fleet; and

based on the identification, determine that at least one of the fleet and a vehicle in the fleet is under a cyber-attack.

2. The system of claim 1 , wherein determining that at least one of the fleet and a vehicle in the fleet is under a cyber-attack is based on at least one of:

correlating information in the reports with data stored on the server; and

correlating information in the reports with server logs related to a communication of DCUs with the server.

3. The system of claim 1 , wherein the server is adapted to identify the cyber-attack based on reports from at least one of: a dealership, a service facility and a component in at least one of the vehicles.

4. The system of claim 1 , wherein:

the DCUs are adapted to include, in the reports, codes identifying service entities; and

the server is adapted to use the received codes to associate a service entity with a cyber threat.

5. The system of claim 1 , wherein the server is adapted to:

classify an event based on relating the event to one or more recorded events; and

identify a cyber-attack based on the classification.

6. The system of claim 5 , wherein the server is adapted to identify a false positive detection based on the classification.

7. The system of claim 1 , wherein the server is adapted to identify previously undetected threats by correlating historical data with newly identified hacks.

8. The system of claim 1 , wherein the server is adapted to identify a cyber-threat based on correlating data received from a plurality of DCUs in a vehicle.

9. A method of providing cyber-security to a fleet of vehicles, the method comprising:

examining, by a server included in a security operations center (SOC) managing cyber-security of the fleet, data in reports received from a plurality of data collection units (DCUs), the DCUs installed in a respective plurality of vehicles in the fleet, the reports including information related to cyber security; and

determining that at least one of the fleet and a vehicle in the fleet is under a cyber-attack based on:

correlating data received from a first DCU installed in a first vehicle with data received from a second DCU installed in a second vehicle that is separate from the first vehicle, and

based on the correlation, identifying at least one of:

a common time of an occurrence of a common event,

a common geographic place,

a common component included in the respective vehicles,

a common service facility,

a common manufacturer of a common element,

a common source of network messages, and

an attribute which is common to a plurality of vehicles in the fleet; and

based on the identification, determining that at least one of the fleet and a vehicle in the fleet is under a cyber-attack.

10. The method of claim 9 , wherein determining that at least one of the fleet and a vehicle in the fleet is under a cyber-attack is based on at least one of:

correlating information in the reports with data stored on the server; and

correlating information in the reports with server logs related to a communication of DCUs with the server.

11. The method of claim 9 , comprising identify the cyber-attack based on aggregating reports from at least one of: a dealership, a service facility and a component in at least one of the vehicles.

12. The method of claim 9 , comprising:

including, in the reports, codes identifying service entities; and

using the received codes to associate a service entity with a cyber threat.

13. The method of claim 9 , comprising:

classifying, by the server, an event based on relating the event to one or more recorded events; and

identifying a cyber-attack based on the classification.

14. The method of claim 13 , comprising identifying a false positive detection based on the classification.

15. The method of claim 9 , comprising identifying previously undetected threats by correlating historical data with newly identified hacks.

16. The method of claim 9 , comprising identifying a cyber-threat based on correlating data received from a plurality of DCUs in a vehicle.

17. The method of claim 9 , comprising:

including, in the reports, geolocation information; and

using the geolocation information to associate a cyber threat with a location.

18. The method of claim 9 , comprising:

including, in the reports, connectivity information; and

using the connectivity information to associate a cyber threat with a communication entity.

19. The method of claim 9 , comprising:

including, in the reports, weather conditions; and

using the weather conditions to identify false positive detection.

20. A method of providing cyber-security to a fleet of vehicles, the method comprising:

obtaining, by a set of sensors units installed in a respective set of vehicles in the fleet, data related to cyber security and sending the data to a server included in a security operations center (SOC) managing cyber-security of the fleet; and

correlating data received from a first set of sensor units installed in a first vehicle with data received from a second set of sensor units installed in a second vehicle that is separate from the first vehicle, and

based on the correlation, identifying at least one of:

a common time of an occurrence of a common event,

a common geographic place,

a common component included in the vehicles,

a common service facility,

a common manufacturer of a common element, a specific source of network messages, and

an attribute which is common to a plurality of vehicles in the fleet; and

based on the identification, determining that at least one of the fleet and a vehicle in the fleet is under a cyber-attack.

Assignments (2)
CHANGE OF NAME Recorded Dec 13, 2024
From: ARGUS CYBER SECURITY LTD
To: PLAXIDITYX LTD
Reel/Frame 069690/0650 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2021
From: GALULA, YARON; BEN-NOON, OFER
To: ARGUS CYBER SECURITY LTD.
Reel/Frame 057709/0676 →
Continuity (2)
Provisional Application 62512187 · May 30, 2017
Related Publication 20180351980A1 · Dec 6, 2018
References Cited (10)
US 20140358839A1 · Dhurandhar · 2014 [cited by examiner]
US 20150113638A1 · Valasek · 2015 [cited by examiner]
US 20150195297A1 · Ben Noon · 2015 [cited by examiner]
US 20170200323A1 · Allouche et al. · 2017 [cited by applicant]
US 20170230385A1 · Ruvio et al. · 2017 [cited by applicant]
US 20180275648A1 · Ramalingam · 2018 [cited by examiner]
US 20180316701A1 · Holzhauer · 2018 [cited by examiner]
US 20190036946A1 · Ruvio · 2019 [cited by examiner]
US 20190141070A1 · Tsurumi · 2019 [cited by examiner]
Non-Final Office Action mailed Mar. 12, 2025 from related U.S. Appl. No. 18/754,170. [cited by applicant]