A Vehicle Network Intrusion Detection Method Based on State Awareness
Through the in-vehicle network intrusion detection method based on state perception, the information entropy detection model is dynamically selected, which solves the problems of low detection accuracy and high false alarm rate in the existing technology, and achieves efficient intrusion detection performance and low false alarm rate.
Patent Information
- Application Number
- CN202310232617.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-13
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2043-03-13
AI Technical Summary
The existing technology lacks an effective security protection mechanism and intrusion detection system in the on-board network, making it difficult to cope with changes in message transmission caused by changes in the driving state of the car and the problem of the inability of a single intrusion detection model to accurately model the message information entropy in the on-board network, resulting in low detection accuracy and high false alarm rate.
The in-vehicle network intrusion detection method based on state perception is adopted. By monitoring CAN bus messages in real time, the corresponding information entropy detection model is selected according to the message type, the variance value of the message ID entropy value and the information entropy value are calculated, and the detection model is dynamically selected to improve the detection accuracy.
It realizes intrusion detection with low computational complexity, high detection performance and low false alarm rate, and can effectively deal with Dos attacks, injection attacks and fuzzy attacks. It is compatible with CAN2.0A and CAN2.0B protocols and does not require changes to hardware or existing protocols.
Smart Images

Figure CN116318955B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of automotive network communication and automotive safety, and particularly to an in-vehicle network intrusion detection method based on state awareness. Background Art
[0002] Currently, there have been a large number of reports on attacks against in-vehicle networks, especially CAN buses. However, automotive electronic systems, especially CAN buses, lack effective security protection mechanisms and the design of intrusion detection systems. An in-vehicle intrusion detection system (IDS) is a reactive security component that can monitor abnormal behaviors of in-vehicle networks in real time and react immediately. In traditional computer networks, most traditional intrusion detection systems are signature-based. Signature-based intrusion detection systems have high detection accuracy and low false alarm rates, but the cost is that the signature library needs to be updated frequently. However, due to reasons such as attack methods, limited attack possibilities, and vehicle lifespan, anomaly-based intrusion detection methods are more suitable for in-vehicle networks. However, anomaly-based intrusion detection methods require defining the behavior of the system in the normal state, and any state deviating from this normal behavior is regarded as an attack.
[0003] Currently, there have been some systematic studies on in-vehicle network intrusion detection based on information entropy. However, the existing studies have not solved problems such as the change in the transmission situation of in-vehicle network messages caused by the change in the driving state of the vehicle and the inability of a single intrusion detection model to accurately model the information entropy of messages in the in-vehicle network, resulting in changes in information entropy and not achieving good detection accuracy either.
[0004] In summary, the problems existing in the prior art are:
[0005] (1) In the existing CAN bus protocol, the security of in-vehicle network information is not considered. There are no measures to encrypt the data on the CAN bus, and the CAN bus also has no identity authentication mechanism. For any device connected to the CAN bus, if the message format sent conforms to the network protocol, it can be received by other ECUs. Therefore, the CAN bus is easily attacked and monitored by hackers.
[0006] (2) In the existing technology, the messages in the CAN bus are not classified, which is likely to interfere with the information entropy in the case of different driving states of the vehicle and non-periodic CAN messages.
[0007] (3) In the existing technology, the intrusion detection model is single, and it is unable to accurately model the information entropy of messages in the in-vehicle network, resulting in difficulty in determining the information entropy threshold and generating a large number of false alarms and missed alarms.
[0008] (4) The existing technology has low detection accuracy, requires too high computing power for the ECU, occupies too much bandwidth resource, and cannot adapt to complex driving environments. Summary of the Invention
[0009] Aiming at the problems existing in the prior art, the purpose of the present invention is to provide a vehicle network intrusion detection method based on state awareness, which provides a method for the vehicle CAN bus with low computational complexity, high detection performance, low false alarm rate, and can dynamically select a detection model according to the message category in the vehicle network to improve the detection accuracy of the IDS when facing injection attacks and fuzzing attacks.
[0010] To achieve the above purpose, the present invention provides the following technical solutions: A vehicle network intrusion detection method based on state awareness, including the following content:
[0011] An intrusion detection system with state awareness function monitors the messages in the CAN bus in real time, judges the current working state of the CAN bus according to the message type transmitted in the CAN bus, and selects a corresponding information entropy detection model according to the state to detect whether there is an intrusion behavior in the CAN bus.
[0012] The CAN bus message ID entropy calculation method is as follows:
[0013] (1) Use id i to represent the ID of a certain message in the detection window, and calculate the probability i of id appearing as follows:
[0014]
[0015] where C i is the number of message id i in the detection window, n represents the total number of message IDs in the detection window, and
[0016] (2) Calculate the entropy value H(W) of the message ID in each detection window as follows:
[0017]
[0018] where is the probability of id i appearing in the set of message IDs in the detection window;
[0019] (3) Calculate the self-information amount i of message id as follows:
[0020]
[0021] (4) Calculate the mean value of the self-information of the message to obtain its entropy value as follows:
[0022]
[0023] The detection window selection strategy is as follows:
[0024] (1) Calculate the average value of the information entropy in the CAN bus as follows:
[0025]
[0026] where H i (W) represents the entropy value of the messages in each window;
[0027] (2) Calculate the variance σ of the message ID entropy value in the CAN bus as follows:
[0028]
[0029] (3) Take the variance value calculation formula in step (2) as the objective function, and obtain the window value when the function takes the minimum value through the simulated annealing algorithm. Take this window value as the optimal detection window, and judge whether to receive a deteriorated solution through the following formula:
[0030]
[0031] Use the above Metropolis criterion to judge whether it is the optimal solution. Among them, E(x) is the objective function, and T represents the initial temperature. If E(x new ) < E(x old ), it means that a better solution is found. Therefore, in this case, the probability of accepting the new solution is 1. If E(x new ) ≥ E(x old ), it means that a deteriorated solution is obtained, and the solution is accepted with probability p.
[0032] (4) The information entropy detection model can be expressed as where is the average value of the information entropy, σ is the variance value of the information entropy, and the k value determines the legal range of the information entropy value in the CAN bus. If the k value is too large, the detection performance will deteriorate, resulting in a very high false negative rate. If the k value is too small, the false positive rate will increase. Therefore, the range of the intrusion detection model should satisfy where H min is the minimum value of the information entropy in the CAN bus, and H max is the maximum value of the information entropy in the CAN bus.
[0033] The intrusion detection system includes a training stage and a detection stage. The training stage is used to obtain a suitable detection window and the variance value of the information entropy under this window. In the real-time detection stage, an intrusion detection system is constructed based on the training results to detect anomalies. The specific steps are as follows:
[0034] Step 1: Classify the messages in the CAN bus according to the message definition, and obtain the CAN bus message status, which can be further mapped to the vehicle running status.
[0035] Step 2: Randomly generate a detection window and add messages to the window.
[0036] Step 3: Extract the message IDs in the window, calculate the information entropy of the data set under the given window, and the variance value of the information entropy.
[0037] Step 4: Compare the obtained variance value with the previous calculation result, and judge whether to accept the current solution through the Metropolis criterion.
[0038] Step 5: Execute the cooling function. If the temperature is lower than Eps (the lowest temperature value that can be reached), end the training. If the temperature is higher than Eps, repeat the above steps 1 to 4 for iteration to obtain the best detection window size with the most stable entropy value.
[0039] Furthermore, in the real-time detection stage, an intrusion detection system is constructed based on the training results to detect anomalies. The steps are as follows:
[0040] Step 1: In the real-time detection stage, the CAN bus messages are first stored in the memory of the ECU. After the number reaches the detection window size, calculate the information entropy to obtain the information entropy value within the detection window.
[0041] Step 2: Select the corresponding detection model according to the message definition in the window and compare it with the information entropy value obtained in Step 1 to obtain the intrusion detection result.
[0042] Step 3: If there is an intrusion, record the abnormal entropy value.
[0043] The present invention provides an evaluation method, which uses the method of calculating the accuracy rate and false alarm rate in machine learning for evaluation.
[0044] Compared with the prior art, the beneficial effects of the present invention are:
[0045] 1. It has advantages such as high accuracy, low false alarm rate, low computational complexity, and short detection response time, and can effectively cope with Dos attacks, injection attacks, and fuzzing attacks. In the case of no attack, the information entropy value of CAN messages tends to be in a stable state. This method models the information entropy value of the CAN bus in the normal state, and when the entropy value deviates from the normal range, it is determined that there is an intrusion. It has good real-time performance and can be compatible with both CAN2.0A and CAN2.0B protocols, with good compatibility and no need to modify the hardware or existing protocols, so it can effectively detect intrusions.
[0046] 2. It is easy to maintain. The existing signature-based intrusion detection technology applied to CAN networks requires frequent update of the signature library, which is not easy to maintain and occupies too much storage resources. The present invention does not require maintaining a feature library and only needs to store a small amount of data, that is, the information entropy of CAN bus messages. Brief Description of the Drawings
[0047] Figure 1 is the flowchart of the training stage of the present invention;
[0048] Figure 2 is the flowchart of the detection stage of the present invention;
[0049] Figure 3 is the dataset in the state of no attack;
[0050] Figure 4 is the DOS attack dataset. Detailed Embodiments
[0051] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the following further details the present invention in conjunction with the accompanying drawings and embodiments. The specific embodiments described herein are only used to explain the technical solutions of the present invention and are not limited to the present invention. This embodiment does not show how to divide the working state of the CAN bus, but only introduces how to model the information entropy of the CAN bus and determine whether there is an intrusion behavior.
[0052] The embodiment of the present invention provides a vehicle network intrusion detection method based on state awareness, which uses a fixed number of messages as a window for monitoring the information entropy of the CAN bus. The intrusion detection system collects the messages in the CAN bus in real time and detects the anomalies in the CAN bus by calculating the entropy value when the number of messages reaches the window size; the intrusion detection system monitors the messages in the CAN bus in real time, classifies the messages according to the message definition, and for different types of messages, the intrusion detection system uses different models to judge the entropy value in the window to achieve classification detection. It includes a training stage (as shown in Figure 1 ) and a real-time detection stage (as shown in Figure 2 ), and specifically includes the following steps:
[0053] Step 1: Classify the messages in the CAN bus and store them in the memory of the ECU;
[0054] Step 2: Randomly generate a detection window and add messages to the window;
[0055] Step 3: Extract the message IDs in the window, calculate the information entropy of the data set under the given window, and the variance value of the information entropy;
[0056] Step 4: Use the simulated annealing algorithm to obtain the optimal detection window of the CAN bus in different states;
[0057] Step 5: After the number of CAN bus messages stored in the ECU reaches the size of the detection window, calculate the information entropy value within the detection window;
[0058] Step 6: Select the corresponding detection model according to the message definition in the window for entropy value comparison to obtain the intrusion detection result.
[0059] The following is an example to illustrate the process of calculating the information entropy of the CAN bus and obtaining the intrusion detection result.
[0060] In this example, a data set in a non - attacked state (part of the data set is as shown in Figure 3 ) and a data set in a DOS - attacked state (part of the data set is as shown in Figure 4 ) are selected. Each data set contains 50 messages. (Since the number of messages is small, the messages are not classified in the example)
[0061] Given that the size of the detection window is 10, messages are added to the window. To model the information entropy of the message IDs in the CAN bus, the CAN bus can be represented as N=(I, 10), where 10 represents the size of the detection window and I represents the set of message IDs that appear in the detection window.
[0062] In the normal state without attack, the set of message IDs in the first detection window is I = {0316, 0329, 0080, 0081, 0120, 0153, 018f, 0220, 0153, 01f1}. Using the information entropy calculation formula, the entropy value of the message IDs in this window is H 1 (W)=3.12193. Similarly, the entropy values of the message IDs in each window of this data set can be calculated in turn as H 1 (W)=3.12193, H 2 (W)=3.32193, H 3 (W)=3.32193, H 4 (W)=3.12193, H 5(W) = 3.32193. Then the change range of the information entropy value of the message during transmission is 3.12193 - 3.32193. Modeling the above information entropy value, the information entropy model can be obtained as
[0063]
[0064] Under normal conditions, the entropy value of the message in the CAN bus is relatively stable and fluctuates regularly within a small range.
[0065] Since the DoS attack dataset is generated by injecting the highest-priority message with ID = 0x000 into the CAN bus that is normally transmitting messages. In the DOS attack state, the detection window size is the same as that in the normal state, which is also 10. The message ID set in the first detection window is I = {0000, 0080, 0000, 0081, 0000, 0165, 0000, 018f, 0000, 02a0}. Using the information entropy calculation formula, the entropy value of the message IDs in this window can be obtained as H 1 (W) = 2.16096. Similarly, the entropy values of the message IDs in each window of this dataset can be calculated in turn as H 1 (W) = 2.16096, H 2 (W) = 1.77095, H 3 (W) = 2.52193, H 4 (W) = 1.96096, H 5 (W) = 1.98974. The above information entropy values are calculated by the information entropy calculation formula. In the DOS attack state, the information entropy value of the message fluctuates irregularly within the range of [1.77095, 2.52193].
[0066] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. All technical solutions falling within the scope of the inventive concept of the present invention are within the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as within the protection scope of the present invention.
Claims
1. A vehicle network intrusion detection method based on state awareness, characterized in that, it includes: Taking a fixed number of messages as a window for monitoring the information entropy of the CAN bus. The intrusion detection system collects the messages in the CAN bus in real time, and detects the anomalies in the CAN bus by calculating the entropy value when the number of messages reaches the window size; The intrusion detection system monitors the messages in the CAN bus in real time, classifies the messages according to the message definition, and for different types of messages, the intrusion detection system uses different information entropy detection models to judge the entropy value in the window, achieving classification detection, and the message definition is obtained from the CAN network application layer protocol; The intrusion detection method includes the following steps: Step 1, classify the messages in the CAN bus according to the application layer protocol and store them in the memory of the ECU; Step 2, the intrusion detection system judges the working state of the current CAN bus according to the message definition, and the working state can be further mapped to the vehicle running state; Step 3, use the simulated annealing algorithm to obtain the optimal detection window of the CAN bus in different working states; Step 4, use the optimal detection window obtained in Step 3 to calculate the average value and variance value of the information entropy of the CAN bus in each working state, and obtain the corresponding information entropy detection model; Step 5, select the corresponding information entropy detection model according to the message definition in the window to compare the entropy values, and judge whether there is an intrusion behavior in the CAN bus.
2. The vehicle network intrusion detection method based on state awareness according to claim 1, characterized in that, the judgment of the working state of the CAN bus is based on the message definition.
3. The vehicle network intrusion detection method based on state awareness according to claim 1, characterized in that, The information entropy value is calculated as where id i represents the ID of a certain message in the detection window, is the self-information amount of the message id i , C i is the number of the message id i within the detection window, and n represents the total number of message IDs in the detection window; the information entropy detection model is expressed as where is the average value of the information entropy, σ is the variance value of the information entropy, and the k value determines the legal range of the information entropy value in the CAN bus.
4. The vehicle network intrusion detection method based on state awareness according to claim 1, characterized in that, the selection of the optimal detection window adopts the simulated annealing algorithm, and its rule is the Metropolis criterion Among them, E(x) is the objective function, and T represents the initial temperature; if E(x new ) < E(x old ), the probability of accepting the new solution is 1. If E(x new ) ≥ E(x old ), the solution is accepted with probability p.