IP Library › Granted Patent US 12,341,798
Granted Patent B2
US 12,341,798 · App. 18/151,680 · Granted Jun 24, 2025

Log management device, log management method, computer program product, and security attack detection and analyzing system

Inventors: Takeshi Sugashima (Kariya, JP); Masumi Egawa (Kariya, JP)
Assignee: DENSO CORPORATION
H04L63/1425H04L41/5067H04L63/1416H04W12/122
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,798
App. No.
18/151,680
Granted
Jun 24, 2025
Kind
B2
Abstract

A log management device includes a log collection unit configured to receive a log generated by a security sensor, a storage unit configured to store the log, a statistical analysis unit configured to obtain a statistical calculation result by performing statistical analysis on a plurality of the logs, a control unit configured to determine which of the log and the statistical calculation result is to be sent according to a predetermined condition, and a transmission unit configured to transmit at least one of the log or the statistical calculation result according to the predetermined condition.

Claims (62)

1. A log management device comprising:

a receiver receiving a log generated by a security sensor;

a processor and memory configured to:

store the received log in the memory;

obtain a statistical calculation result by performing statistical analysis on a plurality of the logs in the log management device;

determine which of the log and the statistical calculation result is to be sent, from the log management device to a center device, according to a predetermined condition; and

a transmitter transmitting, from the log management device to the center device, at least one of the log or the statistical calculation result according to the predetermined condition.

2. The log management device according to claim 1 , wherein the processor and memory are further configured to:

detect an attack based on the log, and

obtain the statistical calculation result by performing the statistical analysis when the attack is detected a predetermined times or more.

3. The log management device according to claim 1 , wherein the processor and memory are further configured to:

detect an attack based on the log, wherein

the predetermined condition is a number of detected attacks.

4. The log management device according to claim 3 , wherein

the transmitter is further configured to

transmit the log when the number of detected attacks is equal to or less than a predetermined number, and

transmit the statistical calculation result after receiving an upload request from the center device when the number of detected attacks is greater than the predetermined number.

5. The log management device according to claim 3 , wherein

the predetermined condition that is the number of detected attacks is set depending on a location where the security sensor is installed or an importance of a communication bus to which the security sensor is connected.

6. The log management device according to claim 1 , wherein the processor and memory are further configured to:

receive an upload request from the center device for uploading at least one of the log or the statistical calculation result, wherein

the predetermined condition is the upload request.

7. The log management device according to claim 6 , wherein

the predetermined condition is an amount of the log in addition to the upload request.

8. The log management device according to claim 7 , wherein

the transmitter is further configured to

transmit the log when the amount of the log is equal to or less than a predetermined amount, and

transmit the statistical calculation result when the amount of the log is greater than the predetermined amount.

9. The log management device according to claim 6 , wherein

the transmitter is further configured to transmit at least one of the log or the statistical calculation result based on latest one of the upload request when the at least one of the log or the statistical calculation result becomes transmittable after a situation where the at least one of the log or the statistical calculation result is untransmittable.

10. The log management device according to claim 1 , wherein

the log management device is mounted in a moving body.

11. A log management method implemented by a processor and memory, the processor executing instructions of a program stored in the memory of the log management device, the instructions comprising:

receiving a log generated by a security sensor;

storing the received log in the memory;

obtaining a statistical calculation result by performing statistical analysis on a plurality of the logs in the log management device;

determining which of the log and the statistical calculation result is to be sent, from the log management device to a center device, according to a predetermined condition; and

transmitting, from the log management device to the center device, at least one of the log or the statistical calculation result according to the predetermined condition.

12. A computer program product stored on at least one non-transitory computer readable medium and comprising instructions configured to, when executed by at least one processor of a log management device, cause the at least one processor to:

receive a log generated by a security sensor;

store the received log in the computer-readable non-transitory storage medium;

obtain a statistical calculation result by performing statistical analysis on a plurality of the logs in the log management device;

determine which of the log and the statistical calculation result is to be sent, from the log management device to a center device, according to a predetermined condition; and

transmit, from the log management device to the center device, at least one of the log or the statistical calculation result according to the predetermined condition.

13. A security attack detection and analyzing system comprising:

a log management device; and

a center device, wherein

the log management device includes:

a processor and first memory configured to:

receive a log generated by a security sensor,

store the received log in the first memory,

obtain a statistical calculation result by performing statistical analysis on a plurality of the logs in the management device,

determine which of the log and the statistical calculation result is to be sent, from the log management device to a center device, according to a predetermined condition, and

transmit, from the log management device to the center device, at least one of the log or the statistical calculation result according to the predetermined condition, and

the center device includes

a receiver receiving the at least one of the log or the statistical calculation result,

a second memory,

a controller, by executing a program stored in the second memory, analyzing the at least one of the log or the statistical calculation result, and generating an upload request for at least one of an additional log or an additional statistical calculation result based on a result of the analysis, and

a transmitter transmitting transmission unit configured to transmit the upload request to the log management device.

14. The security attack detection and analyzing system according to claim 13 , wherein

the log management device is mounted in a moving body, and

the transmitter of the center device is configured to transmit the upload request to at least one of the log management device of the moving body or the log management device mounted in another moving body of a same type.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2023
From: SUGASHIMA, TAKESHI; EGAWA, MASUMI
To: DENSO CORPORATION
Reel/Frame 062315/0148 →
Priority Claims (1)
JP 2020-120721 · Jul 14, 2020 · national
Continuity (2)
Continuation PCTJP2021021285 · Jun 3, 2021
Related Publication 20230156027A1 · May 18, 2023
References Cited (15)
US 8839435B1 · King · 2014 [cited by examiner]
US 20060217116A1 · Cassett · 2006 [cited by examiner]
US 20190141072A1 · Sasaki · 2019 [cited by applicant]
US 20190156593A1 · Sasaki · 2019 [cited by applicant]
US 20190182275A1 · Ando et al. · 2019 [cited by applicant]
US 20190379683A1 · Overby · 2019 [cited by examiner]
US 20200336504A1 · Maeda et al. · 2020 [cited by applicant]
US 20210056776A1 · Sasaki · 2021 [cited by applicant]
US 20210112085A1 · Sasaki · 2021 [cited by applicant]
US 20210320937A1 · Aso et al. · 2021 [cited by applicant]
CN 107547740A · 2018 [cited by examiner]
JP 2018032254A · 2018 [cited by applicant]
JP 2019087277A · 2019 [cited by applicant]
JP 2020038439A · 2020 [cited by applicant]
WO WO2019193786A1 · 2019 [cited by applicant]