Method for Analyzing and Adapting a Network Model in a Signal Fingerprint System
By using signal parameters as fingerprints in the vehicle bus system to create and adapt the network model, the problem that the system is difficult to identify and prevent attacks when facing attacks is solved, and reliable sender identification and attack prevention are achieved.
Patent Information
- Application Number
- CN202010871124.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-27
- Filing Date
- 2020-08-26
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2040-08-26
AI Technical Summary
In the vehicle bus system, there is a lack of authentication of the sender and measures to prevent unauthorized signal changes, making it difficult for the system to identify and prevent attacks when facing an attack.
By using signal parameters as fingerprints in the network model, an adapted model is created and maintained to identify and classify signals, ensuring reliable sender identification and attack identification. The method involves detecting signal parameters, analyzing and adapting the model to cope with conceptual drift and aging effects.
Reliable identification and attack prevention of senders in the vehicle bus system are realized, which reduces system load and improves the recognition accuracy of signal fingerprints.
Smart Images

Figure CN112448943B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for adapting a network model, a computing unit for performing the method, and a computer program. Background Art
[0002] In order to achieve a certain level of security when transmitting messages and signals in a network, it is desirable that the sender can be authenticated separately and that the signals transmitted on the transmission path can be prevented from being changed without authorization.
[0003] For this purpose, different measures are generally known in the field of network technology, such as using signatures or MACs (Message Authentication Codes).
[0004] However, not all of these measures can be reasonably used in any network. For example, some systems are limited in terms of signal or message size, or there are only limited resources available for processing in real time, for instance.
[0005] An example of this is the bus system in a vehicle. The common standard for vehicle buses is the CAN (Controller Area Network) bus, which is set up to enable fast communication between microcontrollers and devices in a system without a host computer. The CAN bus protocol is a message-based protocol on a serial bus line, which was originally designed specifically to reduce connections in vehicles but is also used in many other fields.
[0006] Precisely in vehicles, with the progress in the fields of networking and autonomous vehicles, secure communication plays an increasingly important role. It has been shown that vehicle control can be attacked, especially when the system is connected to the outside, for example, through a mobile communication interface. Due to the lack of authentication measures on the bus, additional or forged messages can relatively easily sneak in undetected from the outside. Since these controls and the bus system also control safety-critical functions such as the braking function, the vulnerability from the outside is particularly problematic.
[0007] A simple possibility for attack recognition lies in checking the content and regularity of messages on the vehicle bus, since many messages are constant or can be easily predicted in this environment and are often sent periodically. There are still weaknesses in this case that such a system cannot recognize or prevent: since the messages in a CAN bus system do not contain information about the sender, it cannot be guaranteed whether the message actually comes from an allowed unit; and if an incorrect or recognized as an attack message sneaks in via one of the sending units in the network, it is almost impossible to identify the compromised unit.
[0008] Thus, in DE 10 2017 208 547 A1 it is proposed that: for protection, a physically determined "fingerprint" of the network or individual network components is used. Here, distinct characteristics of the network nodes in the network or the signals sent by these network nodes are used to identify the sender, such that the incoming messages can be recognized based on these signal characteristics. Once it is recognized with a high probability that none of the known components is considered as the sender of the message and an attack is necessarily suspected, corresponding countermeasures can be taken, such as outputting or sending an alarm signal, sending a fault report on the bus or blocking the relevant message.
[0009] For this purpose, for example, the clock offset can be used, which occurs in the clock frequency of the clock generator of the transmitter due to manufacturing tolerances and statistical variations. Thus, each sender in the bus system has a specific clock offset, i.e., a frequency deviation that is invariant with respect to the reference frequency.
[0010] Similarly, other signal parameters can also be used as fingerprint parameters. Examples of such fingerprint parameters include the stability of the signal, especially in the regions of the rising and falling signal edges, or the steepness of the signal edges. Small, sender-specific and reproducible deviations can also be found there, which enable identification.
[0011] These fingerprint parameters can initially be detected and specified by means of appropriate test messages or learned by means of appropriate machine learning methods, such that it is known in the system which parameter values belong to which sender. Subsequently, the measured bus signals can be classified on a statistical basis, such that when the probability exceeds a certain threshold, they are assigned to the appropriate sender.
[0012] If these sender-specific fingerprint features are now observed over a longer period of time, increasingly long-term small deviations can be derived from models based on different effects (so-called Concept Drift, a change in the distribution of the measured data, which results in the predictions of the learned model no longer being valid). On the one hand, aging effects, for example, can change physical characteristics. In particular, it is also well known that, in the case of the statistical characteristics of the observed variables, the prediction becomes less accurate over time, such that the deviation of the prediction model is inevitable over a longer observation period.
[0013] These changes can thus lead to the fact that the assignment of fingerprints to their respective senders can no longer be carried out with sufficient reliability. However, the recognition of long-term drift effects is not without significance, since fluctuations in environmental conditions can also lead to temporary deviations. To ensure reliable recognition, it is desirable to first identify the deviations caused by concept drift and, if necessary, adapt the model used, which is responsible for the assignment and classification of the fingerprints for attack recognition. However, the control units usually integrated into vehicle buses and similar networks mostly do not have sufficient computing power or storage capacity for the required amount of data to dynamically take such deviations into account by means of a continuously learning model. Summary of the Invention
[0014] According to the invention, a method for analyzing and adapting a prediction model for a network, a computing unit, and a computer program for carrying out the method are proposed.
[0015] In particular, a method for adapting a network model is described, in which current signal parameter values for at least one signal parameter are first received in an analysis unit, these signal parameter values describing signals transmitted on the network. At the analysis unit, an adapted model of the electronic architecture of the network is created based on the at least one signal parameter. The adapted model can be compared with the model stored in the analysis unit for the network, and based on this comparison, it can be determined whether the model has to be updated. If the model finally has to be updated, the correspondingly adapted model can be sent back to the network. This enables the recognition of possible changes in the fingerprint system and thus also enables the system to be adapted in a timely manner before the sending units in the network can no longer be reliably distinguished.
[0016] The signal parameter values received in the analysis unit are detected or determined in advance by a suitable unit and transmitted to the analysis unit. This is preferably also carried out within the framework of the present invention, but can also be independent of the present invention.
[0017] Here, according to one embodiment, determining whether the model needs to be updated may include: predicting the expected parameter values for the at least one signal parameter; and comparing the expected parameter values with the received signal parameter values.
[0018] Here, the following signal parameters can be used for analysis, and these signal parameters are at least partially specific to the network member that has sent the signal in the network. Such a signal can be used as a signal fingerprint for identifying the sender in the network, and should be clearly and reliably identified even in the case of deviations. Thus, the analysis of the model can analyze whether reliable identification can still be performed with sufficient security using the existing model data.
[0019] For this purpose, for example, the probability that the transmitted signal can be assigned to a specific network member using the current model can be checked.
[0020] Different analog and digital parameters that can be obtained from the detected signal can be considered as signal parameters, such as the clock offset of the signal, signal jitter, the edge steepness of the rising or falling signal edge, the fluctuation of the signal voltage, the frequency components of the signal, the bit length of the signal, and so on.
[0021] Models of electronic and electrical network architectures can include, for example, machine learning algorithms, neural networks, stochastic models, data-based models. Then, based on the received signal parameters, the stored or specified model can be appropriately adapted.
[0022] In addition, the signal parameters from at least two different networks can be statistically analyzed, where these networks have at least partially the same network characteristics. Thus, for example, more accurate predictions can be obtained based on the data of multiple vehicles with the same network architecture, and thus possible deviations and concept drift changes can be predicted more reliably.
[0023] In addition, such data from multiple networks, that is, for example, centrally collected data of multiple vehicles of one type, can be used to form network models or adapt these network models based on network characteristics and statistical analysis of signal parameters.
[0024] The above embodiments can be applied to networks that include a controller area network bus (CAN bus) in a vehicle, wherein the evaluation unit includes a remote central computing unit. This provides the possibility of analyzing, creating, and sending a fingerprint model adapted for the vehicle bus to the vehicle in a suitably equipped backend. In this way, the computationally intensive process of model adaptation is transferred to the so-called backend, which reduces the load on the fingerprint system in the vehicle.
[0025] In this way, the signal fingerprint can be validated more reliably and more accurately even if the physical properties change due to aging and similar conditions.
[0026] A computing unit according to the invention, for example an electronic control unit in a motor vehicle, is configured in particular in a program-technical manner to carry out the method according to the invention. In this case, a plurality of computing units can be used to carry out the method, wherein a first unit detects or determines and optionally analyzes signal parameters and transmits these signal parameters to other units, while a computing unit used as an evaluation unit can be configured to carry out the remaining steps.
[0027] In particular, when the implementing control device is also used for other tasks and is therefore always present, the implementation of the method according to the invention in the form of a computer program or computer program product with program code for executing all method steps is also advantageous, because this results in particularly low costs. In particular, suitable data carriers for providing the computer program are magnetic, optical and electrical memories, such as hard disks, flash memories, EEPROMs, DVDs and others. It is also possible to download the program via a computer network (Internet, intranet, etc.).
[0028] Further advantages and embodiments of the invention are apparent from the description and the accompanying drawings.
[0029] The invention is schematically illustrated in the drawings with the aid of exemplary embodiments and is described below with reference to the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 exemplarily shows a bus system in which embodiments of the present invention can be applied; and
[0031] Figure 2 An exemplary method flow according to an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0032] Figure 1An exemplary system in which embodiments of the present invention can be applied is shown. The system includes a network 1 having a bus line 10 equipped with terminal resistors 20, 22 at its ends. A plurality of members 30, 32, 34, also referred to as nodes, can be connected to the bus. In the case of a vehicle bus, in particular, a plurality of electronic control units (ECUs, electronic control unit) can be connected. The plurality of electronic control units can control different associated modules such as actuators and sensors in the vehicle and can thus support various different tasks ranging from the braking system via the positioning system to the engine control function.
[0033] Here, a plurality of members can be connected to the bus line. In a vehicle, often there are 5 to 10 elements on each bus line 10. Each network member 30, 32, 34 includes at least one corresponding control unit and a transceiver or transmitter-receiver that can send and receive signals on the bus.
[0034] As an example, a CAN bus system (Controller Area Network) with a corresponding protocol is discussed in the current case, but the method steps used can also be transferred to other networks and protocols.
[0035] The bus line 10 includes two signal conductors 12, 14, and differential binary signals with non-return-to-zero coding are transmitted on these two signal conductors. According to the CAN bus protocol, all bus members are basically equal in rights, that is, messages can be sent to the bus at any time, and conflicts are avoided through bit-by-bit arbitration. The bus members 30, 32, 34 are connected to these two signal conductors 12, 14 (CAN high / CAN low) via their respective transceivers on branch lines 50, 52, 54.
[0036] Here, one of the members 30, 32, 34 connected to the bus can include a hardware- and / or software-based module that can detect and analyze the physical characteristics or parameters of the signals transmitted on the bus system analogically and / or digitally. Such a unit can be specifically set only for parameter measurement, or it can also undertake other control tasks or be connected to other components. In particular, such a module can be established for an attack recognition system based on signal fingerprints as described above.
[0037] This physical signal parameter can be periodically detected or determined based on measurement data and transmitted to an analysis unit, for example, transmitted to a computing unit in the network, in other areas of the vehicle, or also transmitted to a central computing unit or system backend 62, which can analyze the data and models for multiple bus systems 1. For this purpose, a gateway element 34 can be provided as a bus member or network node, which can implement connections to one or more other networks 60 through corresponding interfaces. Here, other parallel vehicle buses may be involved, such as separated according to functions; or external networks like WLAN networks may also be involved, or access to the Internet via a mobile radio connection or other interfaces.
[0038] These parameters can also optionally be used there to keep the model of the bus architecture at the electrical / electronic level up to date.
[0039] As already described, it is desirable that if deviations occur due to concept drift, identification is performed in the signal fingerprint system for identifying network members or the sender of signals on the bus; and the used model is adapted in a timely manner to enable reliable identification of fingerprints.
[0040] For this purpose, in principle, simple identification methods for concept drift can be used. These identification methods monitor the function of the classifier by using common methods for evaluating accuracy and hit rate. If the threshold is exceeded here, a new model is generated or the old model is appropriately adapted. Such methods are described, for example, in the chapter "An Overview of Concept Drift Applications" (pages 91 - 114) of "Big data analysis: new algorithms for a new society" by I Žliobaitė, M Pechenizkiy, and J Gama.
[0041] According to an embodiment of the present invention, the model of the network can be processed in a separate computing unit, preferably in the so - called backend of the system. There, a separate and as specific as possible mathematical model of the electronic and electrical architecture can be stored for each affiliated network (for example, each vehicle bus) and the mathematical model can be kept up to date in an appropriate manner. Such models can be generated using common methods, as detailed in "Simulation of CAN bus physical layer using SPICE", IEEE International Conference on Applied Electronics, 2013.
[0042] Here, the background can be a computing unit, such as a processor with sufficient computing power within a vehicle, which is connected to a bus system via a communication channel, or the background can also be a remote central computing unit, such as a computing center or a server. Other components, such as volatile and non-volatile storage elements, interfaces for data transmission, etc., can be present in a suitable implementation and are not further described here.
[0043] Here, the required data, such as parameters and model data, can be transmitted via a suitable interface of the network, depending on the location of the computing unit where the implementation takes place, i.e., for example, it can be transmitted via a wired interface in the vehicle and / or via a wireless interface, which can enable a direct connection to the corresponding background or to an external network such as the Internet.
[0044] The system parameters that reproduce the characteristics of the bus system can be fixedly pre-given or can change. For example, the background can request specific parameters, or all the measured parameters can always be transmitted. Depending on what computing power is available in or on the bus system, the measurement data detected for these parameters can be transmitted as raw data or as data that has been further processed.
[0045] Figure 2 An exemplary method flow according to an embodiment of the present invention is shown. Here, first, in step 100, one or more signal parameters of the signals transmitted in a network, such as in a vehicle bus, are detected.
[0046] For example, different analog or digital signal characteristics are considered as the measured signal parameters, such as the edge steepness at the rising and / or falling edges, the signal-to-noise ratio of the signal, the bit length of the digital signal, and other quality-related characteristics. In particular, it is also possible to measure such a parameter that is used as a signal fingerprint and is specific enough to exactly one corresponding sender in the network.
[0047] Then, these detected signal parameters can be transmitted via an interface and received in the background 62 (computing unit) responsible for analysis in step 110. In the case of a remote background, one computing unit can be responsible for multiple networks or vehicles and store, process, and analyze the parameters and / or models of these networks or vehicles. Here, it can be stipulated that: the vehicle system or generally the interface device that transmits parameters to the background is equipped with an identifier that enables an unambiguous assignment to the model 200 stored at this background. Therefore, preferably, the current network model currently in use can be stored in the background for each fingerprint system.
[0048] Subsequently, the current model can be adapted based on the received signal parameters, if this is deemed necessary. To this end, common methods for analyzing deviations can be applied (see above), as there is sufficient computing power available in the background. Here, thresholds can be defined which determine whether an adaptation of the model in the vehicle bus is currently required or whether the deviations are determined such that an adaptation should not be performed currently. These thresholds can also be specified based on the data connection and the design of the fingerprint system in the bus. It is also known and other analysis methods can be used here to detect concept drift.
[0049] Here, in particular, it can be determined what deviations are to be expected with respect to the monitored fingerprint parameters due to changes in the signal parameters. To this end, in step 120, a modified architecture model can be created in the background based on the received signal parameters of the network. Subsequently, in step 130, the two models can be compared with each other, for example, with respect to the distinguishability of the signal fingerprint parameters derived from the respective models.
[0050] If the analysis of the models reveals that the model currently used in the vehicle bus must be adapted or recreated, then in step 140 such an adaptation can be carried out and then in step 150 the modified model can be transmitted back to the fingerprint system or to other model units in the network that locally manage the model of the network architecture, where the modified model can then overwrite the currently used model at the fingerprint system or at the other model unit. If the model is defined by specific predefined model parameters, it may be sufficient to transmit only these model parameters or only the modified model parameters of these model parameters back to the fingerprint system, where the received data is then used to form the complete model. If the existing model provides sufficient accuracy, then in step 100 a new measurement and analysis cycle can be started without an update.
[0051] It can also be checked, for example, whether a model can be selected from a plurality of previously stored modified models that can now achieve a better assignment of the fingerprint parameters than the model currently applied in the bus system. Here, for example, information from other vehicles with the same bus architecture can also have an impact. Such data can enable an early prediction of changes.
[0052] In particular, in the context of the described analysis and adaptation of model accuracy, parameters from multiple networks or bus systems can also be used, in particular, for example, signal parameters obtained from multiple vehicle buses. The data obtained from different sources can be appropriately analyzed, for example, also classified according to the same or equivalent characteristics, such as the same bus system in a vehicle type or equivalent components on the bus. Here, different statistical analysis methods can be used, where the data can be appropriately stored and also collected, analyzed, and combined within a pre-given time period, for example, to form an average over time or to observe long-term changes. Subsequently, based on the data thus obtained, an improved adaptation of the network model can be performed and the analysis of the changed signal parameters can be carried out more reliably in order to reliably identify long-term changes relative to the model used.
[0053] If it is stipulated that the model in the vehicle bus must be changed or updated and the corresponding updated model data has been sent to the fingerprint unit, then the signal fingerprints of existing components can be guaranteed to be reliably identified even if the physical characteristics change due to aging and similar preconditions. The use of the model also allows, for example, predictions to be made about the fingerprints to be expected after a long parking period, after which the bus characteristics may have suddenly changed, which may be accelerated, for example, due to weather conditions.
[0054] It is understandable that all common methods and algorithms for identifying and taking into account concept drift effects can be applied. The selection of the appropriate method can in particular also depend on the way of modeling, the data structure, and the learning algorithm used.
[0055] The methods mentioned can equally be applied to all networks in which distinct signal characteristics are used together with a corresponding model as fingerprints for sender identification.
Claims
1. A method for adapting a network model (200), the method comprising: In an analysis unit (62), signal parameter values of at least one signal parameter of a signal transmitted on a network (1) are received; An adapted model of the electronic architecture of the network (1) is created based on the at least one signal parameter; The adapted model is compared with a model (200) stored in the analysis unit for the network; Based on the comparison, it is determined whether the model must be updated; and If the model must be updated, the adapted model is sent to a model unit in the network (1), where the determination of whether the model must be updated includes: Predicting an expected parameter value of the at least one signal parameter based on the stored model (200); And Comparing the predicted parameter value with the received signal parameter value, and where at least a part of the received signal parameter is dedicated to a network member that has transmitted the signal to which it belongs in the network, and where the probability that the transmitted signal can be assigned to the network member using the current model is checked.
2. The method according to claim 1, wherein at least one of the received signal parameters (100) comprises at least one of the following parameters: clock offset of the signal, signal jitter, edge steepness of the rising or falling signal edge, fluctuation of the signal voltage, frequency components of the signal, bit length of the signal.
3. The method according to any one of claims 1 to 2 above, wherein the model (200) comprises at least one of the following models: machine learning algorithm, neural network, stochastic model, data-based model.
4. The method according to any one of claims 1 to 2 above, the method further comprising: The stored model (200) is adapted based on the received signal parameter values.
5. The method according to any one of claims 1 to 2 above, the method further comprising: A statistical analysis of signal parameters in at least two different networks is performed, where the networks have at least partially the same network characteristics.
6. The method according to claim 5, the method further comprising: Based on the network characteristics and the statistical analysis of signal parameters from multiple networks, the model (200) for signals in the network is formed or the model (200) is adapted.
7. The method according to any one of claims 1 to 2 above, the method further comprising: Determining a current signal parameter value of at least one signal parameter, the signal parameter value describing a signal transmitted on the network (1); And Sending at least one signal parameter value to the analysis unit (62).
8. The method according to any one of claims 1 to 2 above, wherein the network comprises a controller area network bus in a vehicle, and wherein the analysis unit (62) comprises a computing unit remote from the vehicle.
9. A computing unit configured to perform all method steps of the method according to any one of claims 1 to 8 above.
10. A machine-readable storage medium having a computer program stored thereon, which, when implemented on a computing unit, causes the computing unit to perform all method steps of the method according to one of claims 1 to 8.
Citation Information
Patent Citations
Procedure for protecting a network from a cyber attack
DE102017208547A1
System and method for designing, tracking, measuring, predicting and optimizing data communication network
CN101819609A
Method and control unit for detecting manipulations of a vehicle network
CN103547975A
Self-learning-based machine learning model updating method and system
CN108921301A