IP Library › Granted Patent US 12,483,566
Granted Patent B2
US 12,483,566 · App. 18/141,614 · Granted Nov 25, 2025

Vehicle attack event continuity determination method, vehicle attack event continuity determination device, and non-transitory computer-readable recording medium

Inventors: Takashi Ushio (Osaka, JP); Takamitsu Sasaki (Osaka, JP)
Assignee: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
H04L63/1416H04L63/1425H04L67/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,483,566
App. No.
18/141,614
Granted
Nov 25, 2025
Kind
B2
Abstract

A vehicle attack continuity determination method includes: obtaining first vehicle attack event information pertaining to a first vehicle attack event which has occurred in an in-vehicle network, second vehicle attack event information pertaining to a second vehicle attack event which has occurred in the in-vehicle network before the first vehicle attack event, and in-vehicle network information indicating a configuration of the in-vehicle network; determining whether there is continuity between the first vehicle attack event and the second vehicle attack event based on the first vehicle attack event information, the second vehicle attack event information, and the in-vehicle network information; and outputting a result of the determining.

Claims (63)

1 . A vehicle attack event continuity determination method comprising:

obtaining first vehicle attack event information pertaining to a first vehicle attack event which has occurred in an in-vehicle network, second vehicle attack event information pertaining to a second vehicle attack event which has occurred in the in-vehicle network before the first vehicle attack event, and in-vehicle network information indicating a configuration of the in-vehicle network;

determining whether there is continuity between the first vehicle attack event and the second vehicle attack event based on the first vehicle attack event information, the second vehicle attack event information, and the in-vehicle network information; and

outputting a result of the determining,

wherein the in-vehicle network includes a plurality of anomaly detectors,

the first vehicle attack event information includes information indicating one or more first anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the first vehicle attack event,

the second vehicle attack event information includes information indicating one or more second anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the second vehicle attack event,

the determining includes calculating an attack path in the first vehicle attack event, calculating a non-detecting anomaly detector which has not detected an anomaly in the first attack event and which is located upstream from the one or more first anomaly detectors in the attack path, and determining that there is continuity between the first vehicle attack event and the second vehicle attack event when the non-detecting anomaly detector is an endpoint anomaly detector, among the one or more second anomaly detectors, that has most recently detected an anomaly,

the determining includes determining the continuity for the second vehicle attack event that has occurred within a first predetermined period from an occurrence time of the first vehicle attack event,

the obtaining further includes obtaining vehicle function event information pertaining to a vehicle function event that has occurred in a vehicle in which the in-vehicle network is installed,

the determining further includes determining the continuity also based on the vehicle function event information,

the vehicle function event information further includes a vehicle function usage rate pertaining to a total number of times or a duration for which a first vehicle function event has occurred within a third predetermined period into the past from a first time that is an earliest time at which the one or more first anomaly detectors have detected an anomaly, the first vehicle function event being identical to a vehicle function event that has occurred within a second predetermined period into the past from the first time, and the third predetermined period being longer than the second predetermined period,

the vehicle attack event continuity determination method further comprises updating the first predetermined period based on the vehicle function usage rate, and

the determining includes determining the continuity using the first predetermined period updated in the updating.

2 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the obtaining further includes obtaining third vehicle attack event information pertaining to a third vehicle attack event which has occurred in the in-vehicle network before the second vehicle attack event, and

the determining further includes, when it has been determined that there is no continuity between the first vehicle attack event and the second vehicle attack event, determining whether there is continuity between the first vehicle attack event and the third vehicle attack event based on the first vehicle attack event information, the third vehicle attack event information, and the in-vehicle network information.

3 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the updating includes updating the first predetermined period such that (1) the first predetermined period is not changed when the first vehicle function event has not occurred within the third predetermined period into the past from the first time, (2) the first predetermined period is shortened when the first vehicle function event has occurred within the third predetermined period into the past from the first time and for a total number of times or a duration that is at least a predetermined threshold, or (3) the first predetermined period is lengthened when the first vehicle function event has occurred within the third predetermined period into the past from the first time and for a total number of times or a duration that is less than the predetermined threshold.

4 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the first vehicle function event is an engine running event in which an engine of the vehicle is running.

5 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the first vehicle function event is an automatic driving activation event in which automatic driving of the vehicle is active.

6 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the first vehicle function event is a high-speed travel event in which the vehicle travels at a high speed.

7 . The vehicle attack event continuity determination method according to claim 1 ,

wherein the first vehicle function event is a software update event of updating software of the vehicle.

8 . The vehicle attack event continuity determination method according to claim 1 , further comprising:

merging the first vehicle attack event and the second vehicle attack event when it is determined in the determining that there is continuity.

9 . The vehicle attack event continuity determination method according to claim 8 , further comprising:

when the first vehicle attack event and the second vehicle attack event have been merged into a post-merger vehicle attack event in the merging, calculating a reliability level of the post-merger vehicle attack event based on the first vehicle attack event information and the second vehicle attack event information,

wherein the outputting further includes outputting the reliability level.

10 . A vehicle attack event continuity determination device comprising:

a processor;

and memory storing a program,

wherein, when the program is executed by the processor, the program causes the processor to perform processing of:

obtaining first vehicle attack event information pertaining to a first vehicle attack event which has occurred in an in-vehicle network, second vehicle attack event information pertaining to a second vehicle attack event which has occurred in the in-vehicle network before the first vehicle attack event, and in-vehicle network information indicating a configuration of the in-vehicle network;

determining whether there is continuity between the first vehicle attack event and the second vehicle attack event based on the first vehicle attack event information, the second vehicle attack event information, and the in-vehicle network information; and

outputting a result of the determining,

the in-vehicle network includes a plurality of anomaly detectors,

the first vehicle attack event information includes information indicating one or more first anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the first vehicle attack event,

the second vehicle attack event information includes information indicating one or more second anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the second vehicle attack event,

the determining includes calculating an attack path in the first vehicle attack event, calculating a non-detecting anomaly detector which has not detected an anomaly in the first attack event and which is located upstream from the one or more first anomaly detectors in the attack path, and determining that there is continuity between the first vehicle attack event and the second vehicle attack event when the non-detecting anomaly detector is an endpoint anomaly detector, among the one or more second anomaly detectors, that has most recently detected an anomaly,

the determining includes determining the continuity for the second vehicle attack event that has occurred within a first predetermined period from an occurrence time of the first vehicle attack event,

the obtaining further includes obtaining vehicle function event information pertaining to a vehicle function event that has occurred in a vehicle in which the in-vehicle network is installed,

the determining further includes determining the continuity also based on the vehicle function event information,

the vehicle function event information further includes a vehicle function usage rate pertaining to a total number of times or a duration for which a first vehicle function event has occurred within a third predetermined period into the past from a first time that is an earliest time at which the one or more first anomaly detectors have detected an anomaly, the first vehicle function event being identical to a vehicle function event that has occurred within a second predetermined period into the past from the first time, and the third predetermined period being longer than the second predetermined period,

when the program is executed by the processor, the program further causes the processor to perform processing of updating the first predetermined period based on the vehicle function usage rate, and

the determining includes determining the continuity using the first predetermined period updated.

11 . A non-transitory computer-readable recording medium having recorded thereon a program for causing a computer to execute vehicle attack event continuity determination processing, the vehicle attack event continuity determination processing comprising:

obtaining first vehicle attack event information pertaining to a first vehicle attack event which has occurred in an in-vehicle network, second vehicle attack event information pertaining to a second vehicle attack event which has occurred in the in-vehicle network before the first vehicle attack event, and in-vehicle network information indicating a configuration of the in-vehicle network;

determining whether there is continuity between the first vehicle attack event and the second vehicle attack event based on the first vehicle attack event information, the second vehicle attack event information, and the in-vehicle network information; and

outputting a result of the determining,

wherein the in-vehicle network includes a plurality of anomaly detectors,

the first vehicle attack event information includes information indicating one or more first anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the first vehicle attack event,

the second vehicle attack event information includes information indicating one or more second anomaly detectors, among the plurality of anomaly detectors, that have detected an anomaly in the second vehicle attack event,

the determining includes calculating an attack path in the first vehicle attack event, calculating a non-detecting anomaly detector which has not detected an anomaly in the first attack event and which is located upstream from the one or more first anomaly detectors in the attack path, and determining that there is continuity between the first vehicle attack event and the second vehicle attack event when the non-detecting anomaly detector is an endpoint anomaly detector, among the one or more second anomaly detectors, that has most recently detected an anomaly,

the determining includes determining the continuity for the second vehicle attack event that has occurred within a first predetermined period from an occurrence time of the first vehicle attack event,

the obtaining further includes obtaining vehicle function event information pertaining to a vehicle function event that has occurred in a vehicle in which the in-vehicle network is installed,

the determining further includes determining the continuity also based on the vehicle function event information,

the vehicle function event information further includes a vehicle function usage rate pertaining to a total number of times or a duration for which a first vehicle function event has occurred within a third predetermined period into the past from a first time that is an earliest time at which the one or more first anomaly detectors have detected an anomaly, the first vehicle function event being identical to a vehicle function event that has occurred within a second predetermined period into the past from the first time, and the third predetermined period being longer than the second predetermined period,

the vehicle attack event continuity determination processing further comprises updating the first predetermined period based on the vehicle function usage rate, and

the determining includes determining the continuity using the first predetermined period updated in the updating.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2023
From: USHIO, TAKASHI; SASAKI, TAKAMITSU
To: PANASONIC INTELLECTUAL PROPERTY CORPORATION OF AMERICA
Reel/Frame 064822/0410 →
Continuity (3)
Continuation PCTJP2021025103 · Jul 2, 2021
Provisional Application 63116479 · Nov 20, 2020
Related Publication 20230269258A1 · Aug 24, 2023
References Cited (11)
US 20170302691A1 · Singh · 2017 [cited by examiner]
US 20200143053A1 · Gutierrez · 2020 [cited by examiner]
US 20210056206A1 · Hirano · 2021 [cited by examiner]
US 20210258334A1 · Sayag · 2021 [cited by examiner]
CN 111581643 · 2020 [cited by applicant]
JP 201526252 · 2015 [cited by applicant]
WO 2019227076 · 2019 [cited by applicant]
International Search Report (ISR) issued on Aug. 24, 2021 in International (PCT) Application No. PCT/JP2021/025103. [cited by applicant]
Extended European Search Report issued Mar. 28, 2024 in corresponding European Patent Application No. 21894256.3. [cited by applicant]
“Methodologies for intrusion detection system on in-vehicle networks”, ITU-T Draft; Study Period 2017-2020; Study Group 17, International Telecommunication Union, Geneva; CH, vol. ties/17, Aug. 2020, pp. 1-38. [cited by applicant]
Ankang Ju et al., “MCKC: a modified cyber kill chain model for cognitive APTs analysis within Enterprise multimedia network”, Multimedia Tools and Applications, Kluwer Academic Publishers, Boston, US, vol. 79, No. 39-40… [cited by applicant]