IP Library › Granted Patent US 11,509,675
Granted Patent B2
US 11,509,675 · App. 17/097,558 · Granted Nov 22, 2022

Systems and methods for cyber monitoring and alerting for connected aircraft

Inventors: Amit Srivastav (Hyderabad, IN); Rajesh Chenchu (Tirupati, IN); Nayyar Azam Khan Rao (Bangalore, IN); Phani Ammi Raju Pothula (Peravali, IN); Vijayshankaran Iyer (Phoenix, AZ)
Assignee: Honeywell International Inc.
H04L63/1425G06N20/00H04L41/16H04L43/045H04L63/0236H04L63/1433H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,675
App. No.
17/097,558
Granted
Nov 22, 2022
Kind
B2
Abstract

A method of monitoring network traffic of a connected vehicle. The method includes receiving network traffic information from a vehicle gateway, the network traffic information including malicious and/or benign information. The method also includes storing the network traffic information on a data server and periodically updating the network traffic information stored on the data server. The method further includes: pre-processing the network traffic information, the pre-processing the network traffic information including filtering and normalizing the network traffic information; generating a learning model based on the pre-processed network traffic information, the learning model being generated by an artificial intelligence learning; updating the learning model based on additional network traffic information, the additional network traffic information including real-time network data; in accordance with the updated learning model, detecting an anomaly event in the incoming network data; and generating a notification and/or blocking one or more packets associated with the incoming network data.

Claims (66)

1. A computer-implemented method of monitoring network traffic of a connected vehicle, the method comprising:

receiving network traffic information from a vehicle gateway, the network traffic information including malicious and/or benign information;

storing the network traffic information on a data server and periodically updating the network traffic information stored on the data server;

pre-processing the network traffic information stored on the data server, the pre-processing the network traffic information including filtering and normalizing the network traffic information;

generating a learning model based on the pre-processed network traffic information, the learning model being generated by an artificial intelligence learning;

updating the learning model based on additional network traffic information, the additional network traffic information including real-time network data;

in accordance with the updated learning model, detecting an anomaly event in incoming network data; and

in accordance with detecting the anomaly event in the incoming network data, generating a notification and/or blocking one or more packets associated with the incoming network data.

2. The method of claim 1 , further comprising:

classifying the anomaly event based on a predetermined level of threat severity.

3. The method of claim 1 , further comprising:

deploying the learning model on a user device, wherein the learning model is deployed by manually or automatically loading the learning model onto the user device.

4. The method of claim 1 , further comprising:

generating the learning model on a cloud network; and

updating the learning model based on a predetermined time interval.

5. The method of claim 1 , further comprising:

in accordance with the learning model, analyzing encrypted metadata of the network traffic information without performing decryption; and

in accordance with the analyzed encrypted metadata, identifying at least one anomaly pattern.

6. The method of claim 1 , further comprising:

in accordance with detecting the anomaly event, displaying the anomaly event on a display.

7. The method of claim 1 , further comprising:

in accordance with detecting the anomaly event, identifying an origin of the anomaly event.

8. A computer system for monitoring network traffic of a connected vehicle, the system comprising:

a memory storing instructions; and

one or more processors configured to execute the instructions to perform operations including:

receiving network traffic information from a vehicle gateway, the network traffic information including malicious and/or benign information;

storing the network traffic information on a data server and periodically updating the network traffic information stored on the data server;

pre-processing the network traffic information stored on the data server, the pre-processing the network traffic information including filtering and normalizing the network traffic information;

generating a learning model based on the pre-processed network traffic information, the learning model being generated by an artificial intelligence learning;

updating the learning model based on additional network traffic information, the additional network traffic information including real-time network data;

in accordance with the updated learning model, detecting an anomaly event in incoming network data; and

in accordance with detecting the anomaly event in the incoming network data, generating a notification and/or blocking one or more packets associated with the incoming network data.

9. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

classifying the anomaly event based on a predetermined level of threat severity.

10. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

deploying the learning model on a user device, wherein the learning model is deployed by manually or automatically loading the learning model onto the user device.

11. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

generating the learning model on a cloud network; and

updating the learning model based on a predetermined time interval.

12. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

in accordance with the learning model, analyzing encrypted metadata of the network traffic information without performing decryption; and

in accordance with the analyzed encrypted metadata, identifying at least one anomaly pattern.

13. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

in accordance with detecting the anomaly event, displaying the anomaly event on a display.

14. The system of claim 8 , wherein the one or more processor configured to execute the instructions to perform operations further including:

in accordance with detecting the anomaly event, identifying an origin of the anomaly event.

15. A non-transitory computer-readable medium storing instructions that, when executed by one or more processors of a computer system, cause the computer system to perform a method of monitoring network traffic of a connected vehicle, the method comprising:

receiving network traffic information from a vehicle gateway, the network traffic information including malicious and/or benign information;

storing the network traffic information on a data server and periodically updating the network traffic information stored on the data server;

pre-processing the network traffic information stored on the data server, the pre-processing the network traffic information including filtering and normalizing the network traffic information;

generating a learning model based on the pre-processed network traffic information, the learning model being generated by an artificial intelligence learning;

updating the learning model based on additional network traffic information, the additional network traffic information including real-time network data;

in accordance with the updated learning model, detecting an anomaly event in incoming network data; and

in accordance with detecting the anomaly event in the incoming network data, generating a notification and/or blocking one or more packets associated with the incoming network data.

16. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises:

deploying the learning model on a user device, wherein the learning model is deployed by manually or automatically loading the learning model onto the user device.

17. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises:

generating the learning model on a cloud network; and

updating the learning model based on a predetermined time interval.

18. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises:

in accordance with the learning model, analyzing encrypted metadata of the network traffic information without performing decryption; and

in accordance with the analyzed encrypted metadata, identifying at least one anomaly pattern.

19. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises:

in accordance with detecting the anomaly event, displaying the anomaly event on a display.

20. The non-transitory computer-readable medium of claim 15 , wherein the method further comprises:

in accordance with detecting the anomaly event, identifying an origin of the anomaly event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2020
From: SRIVASTAV, AMIT; CHENCHU, RAJESH; RAO, NAYYAR AZAM KHAN; POTHULA, PHANI AMMI RAJU; IYER, VIJAYSHANKARAN
To: HONEYWELL INTERNATIONAL INC.
Reel/Frame 054362/0890 →
Priority Claims (1)
IN 202011041660 · Sep 25, 2020 · national
Continuity (1)
Related Publication 20220103578A1 · Mar 31, 2022
Cited By (4)
US 12,634,321 US 12,689,579 US 12,712,808 US 12,719,914