UNIVERSAL INTRUSION DETECTION AND PREVENTION FOR VEHICLE NETWORKS
A device may include a vehicle comprising a plurality of network zones, each network zone comprising a plurality of end points. A device may include a controller, comprising: a log monitoring component configured to interpret a log corpus associated with at least one of the plurality of end points, a log analysis component configured to detect a risk event in response to the log corpus, and a risk response component configured to perform a risk response operation in response to the detected risk event.
1 . A system, comprising:
a vehicle comprising a plurality of network zones, each network zone comprising a plurality of end points;
a controller, comprising:
a network monitoring component configured to interpret network communications associated with at least one of the network zones;
a network intrusion detection component configured to detect an intrusion attempt in response to the network communications; and
an intrusion response component configured to perform an intrusion prevention operation in response to the detected intrusion attempt.
2 . The system of claim 1 , wherein the intrusion prevention operation comprises adjusting a blocked/allowed source list.
3 . The system of claim 1 , wherein the intrusion prevention operation comprises adjusting a blocked/allowed target list.
4 . The system of claim 1 , wherein the network intrusion detection component is further configured to interpret an automated intrusion response in response to the detected intrusion attempt, and to update the operations to detect the intrusion attempt in response to the automated intrusion response.
5 . The system of claim 1 , wherein the network intrusion response component is further configured to interpret an automated intrusion response in response to the detected intrusion attempt, and wherein the intrusion response component is further configured to update the intrusion prevention operation in response to the automated intrusion response.
6 . The system of claim 1 , wherein the intrusion response component is further configured to interpret an automated intrusion response in response to the detected intrusion attempt, and to update the operations to respond to the detected intrusion attempt in response to the automated intrusion response.
7 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle;
wherein the vehicle cloud communication controller is further configured to interpret an automated intrusion response; and
the system further comprising at least one of:
wherein the network intrusion detection component is further configured to update the operations to detect the intrusion attempt in response to the automated intrusion response; or
wherein the intrusion response component is further configured to update the operations to respond to the detected intrusion attempt in response to the automated intrusion response.
8 . The system of claim 7 , wherein the automated intrusion response comprises a workflow to be performed on the controller.
9 . The system of claim 8 , wherein the workflow comprises a workflow to perform at least one operation selected from:
detecting an intrusion attempt;
confirming an intrusion attempt;
adjusting an intrusion notification scheme;
blocking an intrusion attempt; or
characterizing an intrusion attempt.
10 . The system of claim 7 , wherein the automated intrusion response is received from an external device.
11 . The system of claim 7 , wherein the automated intrusion response is at least one of received from the intrusion response component or activated by the intrusion response component.