Vehicle-mounted CAN bus network abnormity detection method and system

A CAN bus, network abnormal technology, applied in the field of vehicle network, can solve problems such as inapplicability, real-time communication impact, and inability to send abnormal messages.

Active Publication Date: 2019-09-24
XIDIAN UNIV
View PDF14 Cites 40 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0009] (1) The CAN bus anomaly detection scheme based on the statistical method does not take into account the impact of non-periodic messages on the message interval value, and cannot detect the abnormality of non-periodic messages; there are certain false positives and false positives; there is no use of messages The connection between them, the ID of the abnormal message cannot be given; if the attacker injects the message at the natural frequency of the bus, the anomaly detection scheme based on information entropy will fail
[0010] (2) The CAN bus anomaly detection scheme based on machine learning can only detect the anomaly after the attacker has changed the state of the vehicle, which is less practical; generally, the amount of calculation is large, but the essence of the vehicle ECU is a single-chip microcomputer, and its computing power and The storage cap

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Vehicle-mounted CAN bus network abnormity detection method and system
  • Vehicle-mounted CAN bus network abnormity detection method and system
  • Vehicle-mounted CAN bus network abnormity detection method and system

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0105] In order to make the object, technical solution and advantages of the present invention more clear, the present invention will be further described in detail below in conjunction with the examples. It should be understood that the specific embodiments described here are only used to explain the present invention, not to limit the present invention.

[0106] Aiming at the existing technology, it can only solve part of the attacks faced by the vehicle CAN bus network, but cannot provide comprehensive protection for the CAN bus. The invention adopts a CAN bus abnormality detection scheme, and detects both the identifier and the abnormality of the data field of the CAN bus message. Aiming at the anomalies of the message identifier and data domain, the relative entropy and data domain characteristics are used respectively to establish an abnormal detection system for the CAN bus to comprehensively protect the safety of the vehicle CAN bus. Experiments were carried out on th...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention, which belongs to the technical field of vehicle-mounted network, discloses a vehicle-mounted CAN bus network abnormity detection method and system. CAN bus abnormity detection based on a relative entropy is performed on an identifier ID; a sliding window with a fixed message number is employed; messages are paired based on a relationship between a message sensing sequence and a sending number, relative entropies of the paired messages and relative entropies of all IDs and normal distribution are calculated, and whether abnormity occurs is determined based on the two kinds of relative entropies; a replay attack and a denial of service attack are detected; CAN bus network abnormity detection based on a message data domain is performed on a data domain; features, including a constant value feature, a cyclic value feature, and a multi-value feature, of the message data domain are extracted; and a normal message model is established based on the extracted features and the message abnormity is detected. Therefore, the replay attack, the denial of service attack, the tampering attack and the forgery attack can be detected effectively and efficiently; more abnormal information is provided; and thus subsequent protection can be performed well.

Description

technical field [0001] The invention belongs to the technical field of vehicle-mounted networks, and in particular relates to a method and system for detecting abnormality of a vehicle-mounted CAN bus network. Background technique [0002] At present, the closest existing technology: With the rapid development of technologies such as the Internet of Things and mobile communications, the degree of informatization and networking of automobiles continues to increase, and gradually enters the era of Internet of Vehicles (IoV). It is estimated that by 2020, the sales volume of passenger cars in my country will reach 27.733 million units, and the market size of intelligent networked vehicles will reach more than 100 billion yuan. However, existing research and frequent automotive information security incidents in recent years show that connected vehicles are facing serious information security issues. Attackers can obtain private information and location information of cars and c...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
IPC IPC(8): G05B23/02
CPCG05B23/0213G05B2219/24065
Inventor 李兴华张会林张恒友陈颖钟成马建峰
Owner XIDIAN UNIV
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products