Patents Assigned to Upstream Security, Ltd.
  • Patent number: 11840244
    Abstract: A system and method for detecting behavioral anomalies among a fleet including a plurality of connected vehicles. The method includes generating at least one fleet behavioral profile for the fleet using a first set of data, wherein creating each fleet behavioral profile includes training a machine learning model using at least a portion of the first set of data, wherein the at least a portion of the first set of data relates to communications with and among the plurality of connected vehicles; applying the at least one fleet behavioral profile to detect at least one anomaly in a second set of data for the fleet wherein the second set of data includes data related to communications with and among the plurality of connected vehicles; and performing at least one mitigation action when the at least one anomaly is detected.
    Type: Grant
    Filed: December 21, 2018
    Date of Patent: December 12, 2023
    Assignee: UPSTREAM SECURITY, LTD.
    Inventors: Yoav Levy, Yonatan Appel, Amir Volfovich
  • Patent number: 11688212
    Abstract: A system and method for classifying driving behavior. The method includes training, via a supervised machine learning process, a classifier using a labeled training data set including at least one set of training features and corresponding training labels, wherein the classifier is trained to classify driving behavior, wherein the training features include training vehicle telemetries, wherein the training labels include at least one of driver labels and vehicle labels; and applying the classifier to an application data set including a plurality of application features to output a classification of driving behavior based on the application features, wherein the application features are extracted from application data including application vehicle telemetries for a vehicle.
    Type: Grant
    Filed: October 30, 2018
    Date of Patent: June 27, 2023
    Assignee: UPSTREAM SECURITY, LTD.
    Inventors: Yonatan Appel, Yoav Levy
  • Patent number: 11688207
    Abstract: A system and method for contextually monitoring vehicle states. The method includes enriching a plurality of messages based on at least one missing property value and a plurality of predictive properties in the plurality of messages, wherein at least one message of the plurality of messages is generated by a vehicle monitoring system, wherein each message of the plurality of messages is ingested at a vehicle state monitor, wherein each of the predictive properties is a property indicated in one of the plurality of messages of a predetermined type of property; and generating a contextual vehicle state for a vehicle based on the enriched plurality of messages, wherein the contextual vehicle state is a snapshot of a plurality of vehicle state properties at a given time.
    Type: Grant
    Filed: June 25, 2019
    Date of Patent: June 27, 2023
    Assignee: UPSTREAM SECURITY, LTD.
    Inventors: Yoav Levy, Yonatan Appel, Dekel Moshka
  • Patent number: 11539724
    Abstract: Systems and methods for detecting and mitigating cyber-attacks directed to connected vehicles. A method includes classifying a behavior of a connected vehicle into at least one classification with respect to a location of data transmission relative to the connected vehicle, wherein the at least one classification includes any of local and remote; determining a plurality of vehicle-related cyber-attack indicators related to the behavior of the connected vehicle; performing risk analysis based on a first combination of vehicle-related cyber-attack indicators and the classification, wherein performing the risk analysis further comprises matching the first combination to a plurality of second combinations of cyber-attack indicators of a plurality of known attack patterns, wherein each of the plurality of known attack patterns has at least one classification matching the at least one classification of the connected vehicle; and performing at least one mitigation action based on the risk analysis.
    Type: Grant
    Filed: December 9, 2020
    Date of Patent: December 27, 2022
    Assignee: Upstream Security, Ltd.
    Inventors: Yonatan Appel, Yoav Levy, Dor Attias
  • Patent number: 11477212
    Abstract: A system and method for connected vehicle cybersecurity. The method includes creating a normal behavior model based on a first set of data, the first set of data including at least one first event with respect to at least one connected vehicle, wherein the first set of data is collected from a plurality of data sources; detecting an anomaly based on the normal behavior model and a second set of data, the second set of data including a second event with respect to the at least one connected vehicle, wherein each of the first set of data and the second set of data includes vehicle data related to operation of the at least one connected vehicle, wherein each event represents a communication with the at least one connected vehicle; determining, based on the detected anomaly, at least one mitigation action; and causing implementation of the at least one mitigation action.
    Type: Grant
    Filed: July 27, 2018
    Date of Patent: October 18, 2022
    Assignee: Upstream Security, Ltd.
    Inventors: Yonatan Appel, Yoav Levy
  • Patent number: 11438345
    Abstract: A system and method for connected vehicle cybersecurity. The method includes creating a normal behavior model based on a first set of data, the first set of data including at least one first event with respect to at least one connected vehicle, wherein the first set of data is collected from a plurality of data sources; detecting an anomaly based on the normal behavior model and a second set of data, the second set of data including a second event with respect to the at least one connected vehicle, wherein each of the first set of data and the second set of data includes vehicle data related to operation of the at least one connected vehicle, wherein each event represents a communication with the at least one connected vehicle; determining, based on the detected anomaly, at least one mitigation action; and causing implementation of the at least one mitigation action.
    Type: Grant
    Filed: July 27, 2018
    Date of Patent: September 6, 2022
    Assignee: Upstream Security, Ltd.
    Inventors: Yonatan Appel, Yoav Levy
  • Publication number: 20220224700
    Abstract: A system and method for connected vehicle cybersecurity. A method includes creating, by a remote system, a normal behavior model based on a first set of data including at least one first event with respect to connected vehicles, wherein the first set of data is collected from data sources, wherein the remote system is remote from the fleet of connected vehicles; detecting, by the remote system, an anomaly based on the normal behavior model and a second set of data, the second set of data including a second event with respect to the connected vehicles, wherein each of the first set of data and the second set of data includes vehicle data related to operation of the connected vehicles, wherein each event represents a communication with the connected vehicles; determining, based on the detected anomaly, at least one mitigation action; and causing implementation of the at least one mitigation action.
    Type: Application
    Filed: March 30, 2022
    Publication date: July 14, 2022
    Applicant: Upstream Security, Ltd.
    Inventors: Yonatan APPEL, Yoav LEVY
  • Publication number: 20210258328
    Abstract: Systems and methods for detecting and mitigating cyber-attacks directed to connected vehicles. A method includes classifying a behavior of a connected vehicle into at least one classification with respect to a location of data transmission relative to the connected vehicle, wherein the at least one classification includes any of local and remote; determining a plurality of vehicle-related cyber-attack indicators related to the behavior of the connected vehicle; performing risk analysis based on a first combination of vehicle-related cyber-attack indicators and the classification, wherein performing the risk analysis further comprises matching the first combination to a plurality of second combinations of cyber-attack indicators of a plurality of known attack patterns, wherein each of the plurality of known attack patterns has at least one classification matching the at least one classification of the connected vehicle; and performing at least one mitigation action based on the risk analysis.
    Type: Application
    Filed: December 9, 2020
    Publication date: August 19, 2021
    Applicant: Upstream Security, Ltd.
    Inventors: Yonatan APPEL, Yoav LEVY, Dor ATTIAS
  • Publication number: 20210101618
    Abstract: A system and method for connected vehicle risk detection are presented. The includes computing risk scores for a plurality of behaviors detected with respect to a connected vehicle, wherein each of the detected plurality of behaviors is associated with the connected vehicle based on a contextual vehicle state of the connected vehicle; aggregating the computed risk scores to determine an aggregated risk score; determining a risk level for the connected vehicle based on the aggregated risk score; and causing execution of at least one mitigation action based on the determined risk level.
    Type: Application
    Filed: October 1, 2020
    Publication date: April 8, 2021
    Applicant: Upstream Security, Ltd.
    Inventors: Yoav LEVY, Yonatan APPEL, Dor ATTIAS, Dan SAHAR
  • Patent number: 10936461
    Abstract: A system and method for connected vehicle sequence anomaly detection. The method includes creating a normal sequence profile for a group of connected vehicles based on a plurality of first messages by training a normal behavior model using unsupervised machine learning with respect to potential sequences, the normal sequence profile defining normal sequences and triggers, wherein each of the plurality of normal sequences is associated with a timeframe, wherein each sequence is a series of condition combinations; preprocessing a second data set by generating a plurality of second messages in a unified format; identifying at least one instance of the plurality of triggers in the plurality of second messages; and detecting at least one abnormal sequence based on the identified at least one instance and the normal sequence profile, wherein an abnormal sequence is detected when none of the plurality of normal sequences is identified in the second data set.
    Type: Grant
    Filed: December 21, 2018
    Date of Patent: March 2, 2021
    Assignee: Upstream Security, Ltd.
    Inventors: Yoav Levy, Yonatan Appel, Nati Vazana, Yossi Asher
  • Publication number: 20200389474
    Abstract: A system and method for connected vehicle security incident integration. The method includes correlating a security incident violation with a connected vehicle, wherein the security incident violation is indicated in security incident data collected by at least one connected vehicle security system of the connected vehicle, wherein the security incident violation indicates a deviation from normal operation of the connected vehicle; enriching security incident data of a connected vehicle with cybersecurity data related to at least one of: the connected vehicle, and communications between the connected vehicle and at least one external system; generating a risk assessment for the connected vehicle based on the enriched violation data; and performing at least one mitigation action with respect to the connected vehicle based on the risk assessment.
    Type: Application
    Filed: June 2, 2020
    Publication date: December 10, 2020
    Applicant: Upstream Security, Ltd.
    Inventors: Yoav LEVY, Yonatan APPEL, Dan SAHAR
  • Publication number: 20200198651
    Abstract: A system and method for detecting behavioral anomalies among a fleet including a plurality of connected vehicles. The method includes generating at least one fleet behavioral profile for the fleet using a first set of data, wherein creating each fleet behavioral profile includes training a machine learning model using at least a portion of the first set of data, wherein the at least a portion of the first set of data relates to communications with and among the plurality of connected vehicles; applying the at least one fleet behavioral profile to detect at least one anomaly in a second set of data for the fleet wherein the second set of data includes data related to communications with and among the plurality of connected vehicles; and performing at least one mitigation action when the at least one anomaly is detected.
    Type: Application
    Filed: December 21, 2018
    Publication date: June 25, 2020
    Applicant: Upstream Security, Ltd.
    Inventors: Yoav LEVY, Yonatan APPEL, Amir VOLFOVICH
  • Publication number: 20200201731
    Abstract: A system and method for connected vehicle sequence anomaly detection. The method includes creating a normal sequence profile for a group of connected vehicles based on a plurality of first messages by training a normal behavior model using unsupervised machine learning with respect to potential sequences, the normal sequence profile defining normal sequences and triggers, wherein each of the plurality of normal sequences is associated with a timeframe, wherein each sequence is a series of condition combinations; preprocessing a second data set by generating a plurality of second messages in a unified format; identifying at least one instance of the plurality of triggers in the plurality of second messages; and detecting at least one abnormal sequence based on the identified at least one instance and the normal sequence profile, wherein an abnormal sequence is detected when none of the plurality of normal sequences is identified in the second data set.
    Type: Application
    Filed: December 21, 2018
    Publication date: June 25, 2020
    Applicant: Upstream Security, Ltd.
    Inventors: Yoav LEVY, Yonatan APPEL, Nati VAZANA, Yossi ASHER
  • Publication number: 20200035044
    Abstract: A system and method for contextually monitoring vehicle states. The method includes enriching a plurality of messages based on at least one missing property value and a plurality of predictive properties in the plurality of messages, wherein at least one message of the plurality of messages is generated by a vehicle monitoring system, wherein each message of the plurality of messages is ingested at a vehicle state monitor, wherein each of the predictive properties is a property indicated in one of the plurality of messages of a predetermined type of property; and generating a contextual vehicle state for a vehicle based on the enriched plurality of messages, wherein the contextual vehicle state is a snapshot of a plurality of vehicle state properties at a given time.
    Type: Application
    Filed: June 25, 2019
    Publication date: January 30, 2020
    Applicant: Upstream Security, Ltd.
    Inventors: Yoav LEVY, Yonatan APPEL, Dekel MOSHKA
  • Publication number: 20190130664
    Abstract: A system and method for classifying driving behavior. The method includes training, via a supervised machine learning process, a classifier using a labeled training data set including at least one set of training features and corresponding training labels, wherein the classifier is trained to classify driving behavior, wherein the training features include training vehicle telemetries, wherein the training labels include at least one of driver labels and vehicle labels; and applying the classifier to an application data set including a plurality of application features to output a classification of driving behavior based on the application features, wherein the application features are extracted from application data including application vehicle telemetries for a vehicle.
    Type: Application
    Filed: October 30, 2018
    Publication date: May 2, 2019
    Applicant: Upstream Security, Ltd.
    Inventors: Yonatan APPEL, Yoav LEVY
  • Publication number: 20190036948
    Abstract: A system and method for connected vehicle cybersecurity. The method includes creating a normal behavior model based on a first set of data, the first set of data including at least one first event with respect to at least one connected vehicle, wherein the first set of data is collected from a plurality of data sources; detecting an anomaly based on the normal behavior model and a second set of data, the second set of data including a second event with respect to the at least one connected vehicle, wherein each of the first set of data and the second set of data includes vehicle data related to operation of the at least one connected vehicle, wherein each event represents a communication with the at least one connected vehicle; determining, based on the detected anomaly, at least one mitigation action; and causing implementation of the at least one mitigation action.
    Type: Application
    Filed: July 27, 2018
    Publication date: January 31, 2019
    Applicant: Upstream Security, Ltd.
    Inventors: Yonatan APPEL, Yoav LEVY