US 12,335,307 B2
Edge-based decentralized intrusion and anomaly detection
Marc Sebastian Patric Stöttinger, Oestrich-Winkel (DE); Andreas Andrae, Frankfurt am Main (DE); David Gonzalez Gonzalez, Egelsbach (DE); and Osvaldo Gonsa, Frankfurt am Main (DE)
Assigned to Continental Automotive Technologies GmbH, Hannover (DE)
Appl. No. 17/798,741
Filed by Continental Automotive Technologies GmbH, Hannover (DE)
PCT Filed Jan. 21, 2021, PCT No. PCT/EP2021/051260
§ 371(c)(1), (2) Date Aug. 10, 2022,
PCT Pub. No. WO2021/160395, PCT Pub. Date Aug. 19, 2021.
Claims priority of application No. 20156634 (EP), filed on Feb. 11, 2020.
Prior Publication US 2023/0344870 A1, Oct. 26, 2023
Int. Cl. H04L 29/06 (2006.01); G06F 21/00 (2013.01); H04L 9/40 (2022.01); H04W 12/12 (2021.01)
CPC H04L 63/1491 (2013.01) [H04W 12/12 (2013.01)] 15 Claims
OG exemplary drawing
 
1. A method for detecting intrusions and anomalies by an intrusion and anomaly detecting edge computing unit, being coupled together with at least one further intrusion and anomaly detecting edge computing unit to form a plurality of coupled distributed intrusion and anomaly detecting edge computing units, the plurality of coupled distributed intrusion and anomaly detecting edge computing units being part of an edge cloud,
the method comprising:
transmitting and receiving data to and from other entities being temporarily or permanently coupled to said edge cloud,
pretending to be at least one entity of a plurality of other entities being temporarily or permanently coupled to the edge cloud to receive data transmitted in the edge cloud that is intended for being transmitted to the said at least one entity of the plurality of other entities being temporarily or permanently coupled to the edge cloud,
analyzing received data for detecting anomalies and intrusions in the received data by comparing data received from at least two other entities being temporarily or permanently coupled to the edge cloud, and
if at least one of an anomaly and an intrusion is detected in the received data:
storing information about the at least one of a detected anomaly and a detected intrusion and
transmitting information about the at least one of a detected anomaly and a detected intrusion to at least one other anomaly and intrusion detecting edge-computing unit of said edge cloud.