CAN message data flow anomaly detection method, system, device, medium and product

By adopting a two-stage collaborative detection method in intelligent connected vehicles, using lightweight information entropy detection on the vehicle side and deep long and short-term memory network detection on the cloud, the problems of large consumption of CAN network data flow abnormal detection resources and long detection delay in the existing technology are solved, and efficient and accurate abnormal detection is achieved, improving network security and data security.

CN120185867APending Publication Date: 2025-06-20PURPLE MOUNTAIN LAB
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510257908.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The CAN network data flow abnormal detection method of intelligent connected vehicles has problems such as large resource consumption and long detection delay, and it is difficult to effectively apply in an environment where on-board computing and storage resources are scarce.

Method used

Using a two-stage collaborative detection method, the vehicle terminal deploys a lightweight information entropy threshold interval detection model for preliminary detection. If no abnormality is detected, the reported CAN message data flows to the cloud. The cloud uses a pre-trained long and short-term memory network model to deeply detect the byte data flow, and performs final anomaly detection by fusing the output results of each cloud anomaly detection model.

Benefits of technology

It realizes accurate abnormal detection of CAN network data flow of intelligent connected vehicles, reduces the demand for on-board computing storage resources, improves the detection ability of concealed attacks, avoids missing alarms, and improves network security and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185867A_ABST
    Figure CN120185867A_ABST
Patent Text Reader

Abstract

The invention provides a CAN message data flow anomaly detection method, system, device, medium and product, and belongs to the technical field of automobile network and data security. An automobile end anomaly detection model of a to-be-detected automobile performs anomaly detection on ID information entropy of a CAN message data flow based on an information entropy threshold interval, and reports the CAN message data flow if no anomaly is detected; the cloud extracts byte data streams corresponding to each byte of the CAN message from the obtained CAN message data streams and sends the byte data streams to the cloud; and inputting the byte data stream into the corresponding cloud anomaly detection model, and fusing detection data output by each cloud anomaly detection model to obtain an anomaly detection result. Two-stage cooperative detection of the to-be-detected automobile is realized, abnormal conditions such as CAN message data flow violation reporting and information tampering simulated by network attacks such as DoS and injection of the intelligent networked automobile can be accurately detected, the capacity of coping with hidden attacks is improved, and the network security and the data security of the intelligent networked automobile are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of automotive network and data security, and in particular to a method, system, device, medium and product for detecting abnormal CAN message data streams. Background Art

[0002] With the rapid development of the intelligent vehicle industry and vehicle networking technology, intelligent connected vehicles (ICVs) achieve information interaction and sharing among vehicles, between vehicles and roadside units, between vehicles and cloud platforms, and between vehicles and people by carrying advanced on-vehicle sensors and intelligent control systems and combining them with modern mobile communication technology. The data processing ability of intelligent connected vehicles is increasing day by day, and it can not only collect facial expressions, actions, gazes, and voice data of passengers, but also collect vehicle geographical locations, in-vehicle and out-of-vehicle environment data, vehicle networking usage data, etc. While various on-vehicle sensors and intelligent control systems form a large amount of on-vehicle data, the number of vulnerabilities in the relevant software and hardware systems of intelligent connected vehicles is also increasing year by year. If the vulnerabilities are maliciously exploited, it is extremely easy to cause the leakage, abuse, and tampering of personal privacy data and important sensitive data, thus triggering on-vehicle data security problems.

[0003] In the relevant software and hardware systems of intelligent connected vehicles, the Controller Area Network (CAN) is the most widely used on-vehicle communication network in intelligent connected vehicles and is also the link for information interaction such as the operating status and control instructions between various in-vehicle electronic control units (ECUs). Due to the lack of information security mechanism design in the initial design of CAN, CAN, as an important medium of the on-vehicle network, is extremely vulnerable to attacks such as sniffing, forgery, modification, and replay. Even some attackers tamper with the whitelist of the on-vehicle data security gateway, resulting in a large amount of vehicle condition data, user privacy data, and sensitive data sensed by the external environment being reported to illegal nodes, thus causing the illegal reporting or leakage of important on-vehicle data.

[0004] There are mainly two existing methods for detecting abnormal CAN network data streams in intelligent connected vehicles. One is the anomaly detection method based on information statistical analysis, and the other is the anomaly detection method based on machine learning. The anomaly detection method based on information statistical analysis makes full use of the data resources of a large number of message transmissions in the CAN network in real time, and realizes the efficient detection of the CAN network state by statistically analyzing message transmission information entropy, periodic sequences, etc. The anomaly detection method based on information statistical analysis has small resource overhead and fast response speed, and is suitable for lightweight deployment under on-vehicle resource constraints. However, there are also false alarm situations caused by fuzzy network attacks. The detection method based on machine learning mainly uses various machine learning models to detect on-vehicle network anomalies. The detection accuracy is relatively high, but the complexity is high, the resource consumption is large, and the detection delay is long, making it difficult to be applied and deployed on on-vehicle terminals with scarce resources such as on-vehicle computing and storage.

[0005] Therefore, it is necessary to provide a technical solution that can accurately perceive the abnormal situation of the CAN network data stream of intelligent connected vehicles in all directions to ensure the network security and data security of intelligent connected vehicles. Summary of the Invention

[0006] The present invention provides a method, system, device, medium and product for detecting abnormal CAN message data streams, which can accurately detect the abnormal situation of intelligent connected vehicles and improve the network security and data security of intelligent connected vehicles.

[0007] The present invention provides a method for detecting abnormal CAN message data streams, which is applicable to the cloud and includes: Obtain the CAN message data stream uploaded by the vehicle to be tested. Among them, the vehicle to be tested is equipped with an on-vehicle anomaly detection model, and the on-vehicle anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval. If no anomaly is detected, report the CAN message data stream to the cloud; Extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; Input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain an anomaly detection result.

[0008] According to a method for detecting abnormal CAN message data streams provided by the present invention, the determination steps of the cloud anomaly detection model corresponding to each byte of the CAN message include: Obtain historical CAN message data streams; Determine the periodic characteristics of each historical byte data stream according to the historical CAN message data stream; Adjust the parameters of the long short-term memory network corresponding to each byte of the CAN message according to the periodic characteristics of each historical byte data stream; Train the adjusted long short-term memory network based on the historical byte data stream to obtain the cloud anomaly detection model corresponding to each byte of the CAN message.

[0009] According to a method for detecting abnormal CAN message data streams provided by the present invention, the adjusting the parameters of the long short-term memory network corresponding to each byte of the CAN message according to the periodic characteristics of each historical byte data stream includes: If the historical byte data stream does not have periodicity, increase the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and reduce the node inactivation rate; If the historical byte data stream has periodicity, reduce the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and increase the node inactivation rate.

[0010] According to a CAN message data stream anomaly detection method provided by the present invention, if the historical byte data stream does not have periodicity, an attention layer is added to the long short-term memory network corresponding to the historical byte data stream. The steps for determining the parameter weights of the attention layer include: Determine the matching degree between each of the historical byte data streams and the hidden layer state of the corresponding long short-term memory network; Normalize the matching degree based on the exponential function to obtain the parameter weights of the attention layer.

[0011] According to a CAN message data stream anomaly detection method provided by the present invention, the fusion of the detection data output by each of the cloud anomaly detection models includes: Perform weighted summation on the detection data output by each of the cloud anomaly detection models based on the weights determined by the historical confidence levels of each of the cloud anomaly detection models to complete the fusion; Wherein, the historical confidence levels of each of the cloud anomaly detection models are updated periodically.

[0012] The present invention also provides a CAN message data stream anomaly detection method applicable to a vehicle to be tested. The vehicle to be tested is provided with an in-vehicle anomaly detection model, including: Perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval; If no anomaly is detected, report the CAN message data stream to the cloud. The cloud is used to obtain the CAN message data stream, extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each of the cloud anomaly detection models to obtain an anomaly detection result.

[0013] According to a CAN message data stream anomaly detection method provided by the present invention, the steps for determining the information entropy threshold interval include: Obtain the historical CAN message data stream; Determine the information entropy of the historical CAN message data stream according to the probabilities of different ID messages appearing in the historical CAN message data stream; Determine the information entropy threshold interval according to the mean, variance, and variance sensitivity factor of the information entropy of the historical CAN message data stream.

[0014] The present invention also provides a CAN message data stream anomaly detection system, including a vehicle to be tested and a cloud; The vehicle to be tested is equipped with a vehicle - end anomaly detection model, which is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre - determined information entropy threshold interval; if no anomaly is detected, the CAN message data stream is reported to the cloud; The cloud is used to obtain the CAN message data stream uploaded by the vehicle to be tested; extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud - end anomaly detection model corresponding to each byte of the pre - determined CAN message, and fuse the detection data output by each cloud - end anomaly detection model to obtain an anomaly detection result.

[0015] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the CAN message data stream anomaly detection method as described in any one of the above.

[0016] The present invention also provides a non - transitory computer - readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the CAN message data stream anomaly detection method as described in any one of the above.

[0017] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the CAN message data stream anomaly detection method as described in any one of the above.

[0018] The CAN message data stream anomaly detection method, system, device, medium, and product provided by the present invention set up a vehicle - end anomaly detection model and a cloud - end anomaly detection model corresponding to each byte of the CAN message, realizing two - stage collaborative detection of the vehicle to be tested. The lightweight vehicle - end anomaly detection model is deployed on the in - vehicle terminal to perform preliminary anomaly detection on the ID information entropy of the CAN message data stream, which can effectively reduce the demand for in - vehicle computing and storage resources. Then, the cloud - end anomaly detection model performs secondary detection on the byte data stream that has passed the vehicle - end anomaly detection model, and can accurately detect abnormal situations such as illegal reporting and information tampering of the CAN message data stream simulated by network attacks such as DoS and injection on intelligent connected vehicles, improving the ability to cope with hidden attacks with low tampering frequency and little injected data, avoiding missed alarm situations, and thus improving the network security and data security of intelligent connected vehicles. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0020] Figure 1 It is one of the schematic flowcharts of the CAN message data stream anomaly detection method provided by the present invention.

[0021] Figure 2 It is the schematic structural diagram of the heterogeneous cloud anomaly detection model provided by the present invention.

[0022] Figure 3 It is the schematic structural diagram of the attention layer provided by the present invention.

[0023] Figure 4 It is the second schematic flowchart of the CAN message data stream anomaly detection method provided by the present invention.

[0024] Figure 5 It is the first schematic structural diagram of the CAN message data stream anomaly detection system provided by the present invention.

[0025] Figure 6 It is the second schematic structural diagram of the CAN message data stream anomaly detection system provided by the present invention.

[0026] Figure 7 It is the anomaly detection logic diagram of the vehicle - end anomaly detection model provided by the present invention.

[0027] Figure 8 It is the schematic structural diagram of the cloud provided by the present invention.

[0028] Figure 9 It is the schematic structural diagram of the electronic device provided by the present invention. Detailed implementation manners

[0029] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention with reference to the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0030] Figure 1 It is one of the schematic flowcharts of the CAN message data stream anomaly detection method provided by the present invention. As Figure 1 shown, the present invention provides a CAN message data stream anomaly detection method, including the following steps.

[0031] Step S110: Obtain the CAN message data stream uploaded by the vehicle to be tested. Among them, the vehicle to be tested is equipped with an on-vehicle anomaly detection model, which is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval. If no anomaly is detected, report the CAN message data stream to the cloud. Optionally, if the on-vehicle anomaly detection model detects an anomaly, an alarm is issued and the CAN message data stream is not reported.

[0032] Step S120: Extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream. The number of byte data streams is determined based on the number of bytes of the CAN message.

[0033] Step S130: Input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain an anomaly detection result. The number of cloud anomaly detection models is determined based on the number of bytes of the CAN message, and each cloud anomaly detection model constitutes a heterogeneous anomaly detection network.

[0034] It can be understood that the on-vehicle anomaly detection model performs anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval, which is convenient to be deployed on in-vehicle terminals with scarce resources such as in-vehicle computing and storage, and performs preliminary anomaly detection on the ID information entropy of the CAN message data stream. If no anomaly is detected, the CAN message data stream is reported to the cloud, which can effectively reduce the demand for in-vehicle computing and storage resources and solve the defects of high complexity, large resource consumption, and long detection delay of machine learning models. On the basis of realizing the preliminary on-vehicle detection of the vehicle to be tested by means of information statistical analysis, each cloud anomaly detection model independently detects the byte data stream corresponding to each byte of the CAN message, and fuses the independent detection data to obtain the final anomaly detection result, realizing the deep secondary detection of the cloud for the vehicle to be tested. The heterogeneous cloud anomaly detection model can accurately detect anomalies such as illegal reporting and information tampering of the CAN message data stream simulated by the intelligent connected vehicle suffering from network attacks such as DoS and injection, improve the ability to cope with covert attacks with low tampering frequency and little injected data, avoid missed alarm situations, and thus improve the network security and data security of the intelligent connected vehicle.

[0035] Based on the above embodiments, as an optional embodiment, the steps for determining the cloud anomaly detection model corresponding to each byte of the CAN message include the following steps.

[0036] Step S101: Obtain the historical CAN message data stream. Specifically, it is necessary to obtain a sufficient number of historical CAN message data streams and the detection results indicating whether the historical CAN message data stream is abnormal. The detection results include the vehicle-end detection results output by the vehicle-end anomaly detection model and the anomaly detection results of the cloud.

[0037] Step S102: Determine the periodic characteristics of each historical byte data stream according to the historical CAN message data stream. Extract the historical byte data stream corresponding to the number of CAN message bytes from the historical CAN message data stream, and determine the periodic characteristics of each historical byte data stream by judging whether the sequence period of the historical byte data stream is stable and clear or ambiguous.

[0038] Step S103: Adjust the parameters of the long short-term memory network corresponding to each byte of the CAN message according to the periodic characteristics of each historical byte data stream.

[0039] Step S104: Train the adjusted long short-term memory network based on the historical byte data stream to obtain the cloud anomaly detection model corresponding to each byte of the CAN message.

[0040] In the embodiment of the present invention, taking the CAN message with 8 bytes as an example, 8 historical byte data streams are extracted from the historical CAN message data stream. The hyperparameters of each long short-term memory network are adjusted in combination with the transmission cycle characteristics of the 8 historical byte data streams to form a heterogeneous machine learning network model. The historical byte data stream is used as a training sample, and the detection result is used as a label to train the adjusted long short-term memory network. After training, the byte data stream uploaded by the vehicle to be tested can be independently detected.

[0041] It can be understood that the present invention adjusts the parameters of the long short-term memory network through the periodic characteristics of the historical byte data stream, which can prevent the phenomenon of underfitting or overfitting and improve the efficiency and accuracy of model training.

[0042] Based on the above embodiment, as an optional embodiment, the adjusting the parameters of the long short-term memory network corresponding to each byte of the CAN message according to the periodic characteristics of each historical byte data stream includes the following steps.

[0043] Step S1031: If the historical byte data stream does not have periodicity, increase the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and reduce the node inactivation rate. For the historical byte data stream with a relatively fuzzy transmission cycle, use a multi-layer stacked LSTM, and set a lower node inactivation rate and a higher learning rate for key feature learning to prevent underfitting.

[0044] Step S1032: If the historical byte data stream has periodicity, reduce the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and increase the node inactivation rate. When the transmission period of the historical byte data stream is relatively stable and clear, a standard single-layer LSTM can be used, and a relatively high node inactivation rate and a relatively low learning rate can be set for key feature learning to prevent overfitting, thereby improving the efficiency of model training.

[0045] As Figure 2 shown, the parameters of the long short-term memory network (LSTM network) are mainly reflected in the forget gate , input gate and output gate . The calculations of the three gates and the output state are shown in the following equations: Among them, , , are the weight matrices of the forget gate, input gate, and output gate respectively, is the input sequence at time t , which refers to the historical byte data stream at time , , are the output sequences of the forget gate, input gate, and output gate respectively, , , are the bias terms of the forget gate, input gate, and output gate respectively, is the cell state at time is the candidate cell state at time is the hidden layer state of the LSTM network at time, represents function, represents the multiplication of two elements.

[0046] The design focus of the LSTM network lies in the network structure design of the three gates to train and obtain appropriate , , , as well as , , Parameters such as these. Combining the periodic characteristics of each historical byte data stream, in the network structure design of the LSTM forget gate, input gate, and output gate, the following principles are followed: 1) For historical byte data streams with relatively ambiguous sequence periods, use a hidden layer with a larger network width, such as 256 nodes; and set a lower node inactivation rate and a higher learning rate for key feature learning to prevent underfitting. 2) For historical byte data streams with relatively stable and clear sequence periods, a hidden layer with a smaller network width can be used, such as 128 or 64; at the same time, set a higher node inactivation rate and a lower learning rate for key feature learning, thereby improving the efficiency of model training and preventing overfitting.

[0047] Through statistical analysis of a large number of historical CAN message data streams, it can be known that the approximate change periods of the CAN message byte 1 data stream to byte 8 data stream are 25, 50, 25, 25, 25, 30, 50, and 50 messages respectively. Among them, the data stream changes of byte 1, byte 4, byte 5, and byte 6 are relatively regular, while the data stream changes of byte 2, byte 3, byte 7, and byte 8 are relatively ambiguous. For the LSTM networks of the byte 2, byte 3, byte 7, and byte 8 data streams of the CAN message data stream, the first design idea can be adopted, and the network width can be set to 256, the node inactivation rate to 0.2, and the learning rate to 0.99. For the LSTM networks of the byte 1, byte 4, byte 5, and byte 6 data streams, the second design idea can be adopted, and the network width can be set to 128, the node inactivation rate to 0.3, and the learning rate to 0.97.

[0048] It can be understood that the present invention adjusts the parameters of the long short-term memory network through the periodic characteristics of the historical byte data stream, which can prevent underfitting or overfitting, and improve the efficiency and accuracy of model training.

[0049] As Figure 3 shown, on the basis of the above embodiments, as an optional embodiment, if the historical byte data stream does not have periodicity, an attention layer is added to the long short-term memory network corresponding to the historical byte data stream. The steps for determining the parameter weights of the attention layer include: Determine the matching degree between each historical byte data stream and the hidden layer state of the corresponding long short-term memory network.

[0050] Normalize the matching degree based on the exponential function to obtain the parameter weights of the attention layer.

[0051] The calculation formula for the matching degree is as follows: ; where represents t at time kThe historical byte data stream of bytes, indicating t the k matching degree between the historical byte data stream of the th byte and the hidden layer state of the long short-term memory network. In the embodiments of the present invention, the attention mechanism implemented by the alignment model is used, and the improved alignment model is used to calculate the matching degree. are all model parameters of the alignment model, used to quantify and the relationship between them, forming a correlation matrix to compare and the matching degree between them.

[0052] The normalization formula is as follows: is the weight normalized by the exponential function.

[0053] Based on the above embodiments, as an alternative embodiment, the fusion of the detection data output by each of the cloud anomaly detection models includes: Performing weighted summation on the detection data output by each of the cloud anomaly detection models based on the weights determined by the historical confidence levels of each of the cloud anomaly detection models to complete the fusion; wherein, the historical confidence levels of each of the cloud anomaly detection models are updated periodically.

[0054] It can be understood that the weights of the detection data output by each model are calculated by combining the historical detection confidence levels of each cloud anomaly detection model, and the final CAN message data stream detection result of the second stage of the cloud is formed through weighted summation. At the same time, the historical confidence levels of the heterogeneous cloud anomaly detection models are statistically counted periodically, and the weight distribution of the output results of the heterogeneous cloud anomaly detection models can be dynamically adjusted according to the latest confidence information, improving the real-time accuracy of the detection data fusion.

[0055] Next, the CAN message data stream anomaly detection method provided by the present invention will be described. The CAN message data stream anomaly detection method described below can be mutually corresponding and referred to the CAN message data stream anomaly detection method described above.

[0056] Figure 4 is the second flowchart of the CAN message data stream anomaly detection method provided by the present invention. As Figure 4 shown, the present invention also provides a CAN message data stream anomaly detection method, which is applicable to a vehicle to be tested. The vehicle to be tested is provided with a vehicle-end anomaly detection model, and includes the following steps.

[0057] Step S210, perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold range. Optionally, if the vehicle-side anomaly detection model detects an anomaly, an alarm is issued and the CAN message data stream is not reported.

[0058] Step S220, if no anomaly is detected, report the CAN message data stream to the cloud. The cloud is used to obtain the CAN message data stream, extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain an anomaly detection result.

[0059] Optionally, the vehicle-side anomaly detection model is set in the OBU of the vehicle to be tested.

[0060] In the process of calculating the ID information entropy of the CAN message data stream, first extract the ID messages in the collected CAN message data stream, perform information statistical analysis on a certain number of ID messages, determine the types of ID messages, and calculate the ID information entropy of the CAN message data stream by statistically analyzing the probabilities of different types of ID messages appearing within a certain number of messages. The calculation formula is as follows: Among them, is the information entropy of the th type of ID message within the sliding window, is the number of times the th type of ID message appears within the sliding window, is the type of different ID messages that appear within the sliding window, is the information entropy of all types of ID messages within the sliding window.

[0061] It can be understood that the vehicle-side anomaly detection model provided by the present invention performs preliminary detection by means of information statistical analysis, which is fast, efficient, and occupies less on-vehicle computing and storage resources. It can quickly detect whether the CAN message data stream is abnormal. If no anomaly is detected, the CAN message data stream is uploaded to the cloud for in-depth detection by the cloud, thereby improving the network security and data security of intelligent connected vehicles.

[0062] On the basis of the above embodiments, as an optional embodiment, the steps for determining the information entropy threshold range include the following steps.

[0063] Step S201, obtain historical CAN message data streams.

[0064] Step S202: Determine the information entropy of the historical CAN message data stream according to the probabilities of different ID messages in the historical CAN message data stream. The calculation method of the information entropy of the historical CAN message data stream is similar to that of the ID information entropy of the CAN message data stream and will not be elaborated here.

[0065] Step S203: Determine the information entropy threshold interval according to the mean value, variance and variance sensitivity factor of the information entropy of the historical CAN message data stream.

[0066] Specifically, calculate the mean value of the information entropy of the historical CAN message data stream and the variance , and combine with the variance sensitivity factor to establish the information entropy threshold interval of the normal CAN message data stream. The expression of the information entropy threshold interval is as follows: The vehicle under test calculates the ID information entropy of the real-time collected CAN message data stream. If the ID information entropy is within the information entropy threshold interval , it is determined that the CAN message data stream is normal, and the CAN message data stream is uploaded to the cloud. Otherwise, it is regarded as an anomaly detected and an alarm is issued.

[0067] It can be understood that the present invention determines the information entropy threshold interval through the mean value, variance and variance sensitivity factor of the information entropy of the historical CAN message data stream, which can improve the accuracy of the information entropy threshold interval.

[0068] Next, the CAN message data stream anomaly detection system provided by the present invention will be described. The CAN message data stream anomaly detection system described below can be mutually referred to with the CAN message data stream anomaly detection method described above.

[0069] Figure 5 is a schematic structural diagram of the CAN message data stream anomaly detection system provided by the present invention. As Figure 5 shown, the present invention also provides a CAN message data stream anomaly detection system, including a vehicle under test 510 and a cloud 520.

[0070] The vehicle under test 510 is equipped with a vehicle-side anomaly detection model, which is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval; if no anomaly is detected, the CAN message data stream is reported to the cloud.

[0071] The cloud 520 is used to obtain the CAN message data stream uploaded by the vehicle to be tested; extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the CAN message determined in advance, and fuse the detection data output by each cloud anomaly detection model to obtain the anomaly detection result.

[0072] Based on the above embodiments, as an optional embodiment, the present invention provides a two-stage collaborative detection system architecture covering vehicle-end preliminary detection and cloud-end deep detection, as Figure 6 shown. In vehicle-mounted terminals with limited resources such as computing and storage, a vehicle-end anomaly detection model based on information entropy is established to achieve lightweight real-time detection of the first stage of the CAN message data stream; in the cloud with abundant resource configuration, a heterogeneous cloud anomaly detection model is established to independently detect each byte data stream, realizing the deep detection of the second stage of the data stream in the cloud. During the detection process, the CAN message data stream first undergoes the first-stage detection at the vehicle end. When an abnormal situation is detected in the first stage, an alarm will be issued; when no abnormality is detected in the first stage, it will enter the second-stage deep detection.

[0073] The vehicle-end anomaly detection model in the first stage is deployed in the OBU. The detection in this stage is fast and efficient and occupies less vehicle-mounted computing and storage resources, and can quickly detect whether the CAN message data stream is abnormal; the deep detection in the second stage can be deployed in the roadside unit or the vehicle monitoring center. With the guarantee of cloud resources in this stage, the high accuracy of the anomaly detection method based on machine learning can be reflected.

[0074] The vehicle-end anomaly detection model based on information entropy designed at the vehicle end consists of a CAN message acquisition module, an information entropy normal range calculation module, an information entropy real-time calculation module, and an anomaly judgment module. The information entropy normal range calculation module statistically analyzes the historical CAN message data stream and calculates the information entropy threshold range. The CAN message acquisition module acquires and caches the CAN message data stream of the vehicle to be tested, and the information entropy real-time calculation module calculates the ID information entropy of the CAN message data stream; the anomaly judgment module compares the ID information entropy with the information entropy threshold range to judge whether the real-time acquired CAN message data stream is abnormal. The anomaly detection logic of the vehicle-end anomaly detection model is as Figure 7 shown.

[0075] The cloud includes a CAN message byte data stream extraction module, a heterogeneous LSTM network module, and a detection result fusion module. The CAN message byte data stream extraction module extracts an 8-byte data stream from the CAN message data stream. The heterogeneous LSTM network module includes 8 independent LSTM networks. The 8 independent LSTM networks respectively perform anomaly detection on the 8-byte data streams and output 8 detection data. The detection result fusion module fuses the 8 detection data to obtain the final detection result, that is, the anomaly detection result.

[0076] The CAN message data stream anomaly detection system provided by the present invention is used to execute the CAN message data stream anomaly detection method described in any of the above embodiments, and has technical effects corresponding to the CAN message data stream anomaly detection method, which will not be elaborated here.

[0077] Figure 9 An example of the physical structure diagram of an electronic device is as Figure 9 shown. The electronic device may include: a processor 910, a communication interface 920, a memory 930, and a communication bus 940. Among them, the processor 910, the communication interface 920, and the memory 930 complete mutual communication through the communication bus 940. The processor 910 can call the logical instructions in the memory 930 to execute the CAN message data stream anomaly detection method. The method includes: obtaining the CAN message data stream uploaded by the vehicle to be tested. Among them, the vehicle to be tested is equipped with a vehicle-side anomaly detection model, and the vehicle-side anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval. If no anomaly is detected, report the CAN message data stream to the cloud; extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain the anomaly detection result.

[0078] In addition, when the logical instructions in the above-mentioned memory 930 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0079] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the CAN message data stream anomaly detection method provided by the above-mentioned various methods. The method includes: obtaining the CAN message data stream uploaded by the vehicle to be tested. Among them, the vehicle to be tested is provided with a vehicle-side anomaly detection model, and the vehicle-side anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval. If no anomaly is detected, report the CAN message data stream to the cloud; extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain an anomaly detection result.

[0080] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the CAN message data stream anomaly detection method provided by the above-mentioned various methods. The method includes: obtaining the CAN message data stream uploaded by the vehicle to be tested. Among them, the vehicle to be tested is provided with a vehicle-side anomaly detection model, and the vehicle-side anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a pre-determined information entropy threshold interval. If no anomaly is detected, report the CAN message data stream to the cloud; extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; input the byte data stream into the cloud anomaly detection model corresponding to each byte of the pre-determined CAN message, and fuse the detection data output by each cloud anomaly detection model to obtain an anomaly detection result.

[0081] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative work.

[0082] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course also by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0083] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of the present invention.

Claims

1. A method for detecting abnormality in CAN message data flow, characterized in that: Available in the cloud, including: Acquire a CAN message data stream uploaded by the vehicle to be tested, wherein the vehicle to be tested is provided with a vehicle-side anomaly detection model, and the vehicle-side anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a predetermined information entropy threshold interval, and if no anomaly is detected, report the CAN message data stream to the cloud; Extracting from the CAN message data stream to obtain a byte data stream corresponding to each byte of the CAN message; The byte data stream is input into a cloud-based anomaly detection model corresponding to each byte of a predetermined CAN message, and the detection data output by each cloud-based anomaly detection model is fused to obtain an anomaly detection result.

2. The CAN message data flow anomaly detection method according to claim 1, characterized in that: The step of determining the cloud anomaly detection model corresponding to each byte of the CAN message includes: Get historical CAN message data stream; Determine the periodic characteristics of each historical byte data stream according to the historical CAN message data stream; According to the periodic characteristics of each historical byte data stream, adjust the parameters of the long short-term memory network corresponding to each byte of the CAN message; The adjusted long short-term memory network is trained based on the historical byte data stream to obtain a cloud-based anomaly detection model corresponding to each byte of the CAN message.

3. The CAN message data flow anomaly detection method according to claim 2, characterized in that: The method of adjusting the parameters of the long short-term memory network corresponding to each byte of the CAN message according to the periodic characteristics of each historical byte data stream includes: If the historical byte data stream does not have periodicity, increase the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and reduce the node deactivation rate; If the historical byte data stream has periodicity, reduce the network width and learning rate of the hidden layer of the long short-term memory network corresponding to the historical byte data stream, and increase the node deactivation rate.

4. The CAN message data flow anomaly detection method according to claim 3 is characterized in that: If the historical byte data stream does not have periodicity, an attention layer is added to the long short-term memory network corresponding to the historical byte data stream, and the step of determining the parameter weight of the attention layer includes: Determining the degree of matching between each of the historical byte data streams and the hidden layer state of the corresponding long short-term memory network; The matching degree is normalized based on the exponential function to obtain the parameter weights of the attention layer.

5. The CAN message data flow anomaly detection method according to claim 4, characterized in that: The fusing of the detection data output by each of the cloud-based anomaly detection models includes: Performing weighted summation on the detection data output by each of the cloud anomaly detection models based on the weights determined by the historical confidence of each of the cloud anomaly detection models to complete the fusion; The historical confidence of each of the cloud-based anomaly detection models is updated periodically.

6. A method for detecting abnormality in CAN message data flow, characterized in that: Applicable to a vehicle to be tested, the vehicle to be tested is provided with a vehicle-side anomaly detection model, including: Perform abnormal detection on the ID information entropy of the CAN message data stream based on a predetermined information entropy threshold interval; If no abnormality is detected, the CAN message data stream is reported to the cloud, and the cloud is used to obtain the CAN message data stream, and extract the byte data stream corresponding to each byte of the CAN message from the CAN message data stream; the byte data stream is input into a predetermined cloud-based anomaly detection model corresponding to each byte of the CAN message, and the detection data output by each of the cloud-based anomaly detection models is fused to obtain an anomaly detection result.

7. The CAN message data flow anomaly detection method according to claim 6, characterized in that: The step of determining the information entropy threshold interval includes: Get historical CAN message data stream; Determine the information entropy of the historical CAN message data stream according to the probability of occurrence of different ID messages in the historical CAN message data stream; The information entropy threshold interval is determined according to the mean, variance and variance sensitivity factor of the information entropy of the historical CAN message data stream.

8. A CAN message data flow anomaly detection system, characterized in that: Including the car under test and the cloud; The vehicle to be tested is provided with a vehicle-side anomaly detection model, and the vehicle-side anomaly detection model is used to perform anomaly detection on the ID information entropy of the CAN message data stream based on a predetermined information entropy threshold interval; if no anomaly is detected, the CAN message data stream is reported to the cloud; The cloud is used to obtain the CAN message data stream uploaded by the vehicle to be tested; Extracting from the CAN message data stream to obtain a byte data stream corresponding to each byte of the CAN message; The byte data stream is input into a cloud-based anomaly detection model corresponding to each byte of a predetermined CAN message, and the detection data output by each cloud-based anomaly detection model is fused to obtain an anomaly detection result.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the CAN message data flow anomaly detection method as described in any one of claims 1 to 7 is implemented.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the CAN message data flow anomaly detection method as described in any one of claims 1 to 7 is implemented.

Citation Information

Cited By

  • CAN bus attack detection method, device and equipment

    CN120896799A

  • Method, device and equipment for detecting attacks on a can bus

    CN120896799B