×

Data security inspection mechanism for serial networks

  • US 10,666,671 B2
  • Filed: 04/26/2017
  • Issued: 05/26/2020
  • Est. Priority Date: 04/26/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method, comprising:

  • tracking, by a device in a serial network that is a controller area network (CAN) bus network, timing information associated with an inter-arrival time and a number of frames from each device in the serial network in a database;

    determining, by the device in the serial network, that a suspicious event has occurred in the serial network, wherein the suspicious event is identified based on whether the inter-arrival time of one or more frames from a particular device in the serial network is within an expected range;

    assessing, by the device, whether the suspicious event is malicious by evaluating a sequence of events in the serial network that precede the suspicious event, wherein the sequence of events a) specify an order of events that are expected to precede an event for the particular device and b) is determined based on a first-order analysis of data in the CAN bus network; and

    causing, by the device, a mitigation action to be performed in the serial network when the suspicious event is deemed malicious.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×