Abnormality detection method and device for can bus, vehicle controller and medium

CN119945930BActive Publication Date: 2026-09-29CHERY NEW ENERGY AUTOMOBILE TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510014237.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2026-09-29
Estimated Expiration
2045-01-06

AI Technical Summary

Benefits of technology

[0028]本申请实施例提供了一种CAN总线的异常检测方法,通过基于待检测的CAN报文的报文类型,从检测规则库中确定该CAN报文对应的报文规则和信号规则,能够基于报文规则和信号规则,分别检测CAN报文的消息标识符、长度、发送周期以及CAN报文中包含的CAN信号是否符合CAN报文的在车辆的DBC文件中的定义,进而能够准确确定CAN报文的检测结果,并基于该检测结果,车辆的CAN总线的运行状态是否存在异常,从而能够有效提高CAN总线的安全性,确保车辆电子系统的稳定运行。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945930B_ABST
    Figure CN119945930B_ABST
Patent Text Reader

Abstract

The application provides an abnormality detection method and device of a CAN bus, a vehicle controller and a medium, and belongs to the technical field of automobiles. The method comprises the following steps: acquiring a CAN message to be detected; determining a message rule and a signal rule corresponding to the CAN message from a detection rule library of the vehicle based on the message type of the CAN message; detecting the CAN message based on the message rule and the signal rule to obtain a detection result of the CAN message; and determining that the operation state of the CAN bus is abnormal in the case that the detection result indicates that the CAN message is an abnormal message. The above method can accurately determine the detection result of the CAN message, and determine whether the operation state of the CAN bus of the vehicle is abnormal based on the detection result, thereby effectively improving the safety of the CAN bus and ensuring the stable operation of the electronic system of the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of automotive technology, and in particular to a method, device, vehicle controller, and medium for detecting anomalies in a CAN bus. Background Technology

[0002] CAN (Controller Area Network) bus, as a communication network used to connect various electronic control units in modern automobiles, boasts advantages such as strong anti-interference capabilities, reliable data transmission, fast data transmission, high flexibility, and low cost, and is widely used in the automotive field. However, with the emergence of automotive information security issues, malicious attacks can directly penetrate the vehicle's CAN bus network through external interfaces, posing a serious threat to vehicle performance, safety, and privacy. Currently, the CAN bus lacks basic information security mechanisms. To improve CAN bus security, implementing anomaly detection has become crucial; therefore, a method for CAN bus anomaly detection is urgently needed. Summary of the Invention

[0003] This application provides a method, apparatus, vehicle controller, and medium for detecting anomalies in a CAN bus. It can accurately determine the detection results of CAN messages and, based on these results, determine whether there are any anomalies in the operating state of the vehicle's CAN bus, thereby effectively improving the security of the CAN bus and ensuring the stable operation of the vehicle's electronic systems. The technical solution is as follows:

[0004] On the one hand, a method for detecting anomalies in a CAN bus is provided, the method comprising:

[0005] Acquire the CAN message to be detected, wherein the CAN message refers to the message transmitted on the vehicle's CAN bus;

[0006] Based on the message type of the CAN message, the message rules and signal rules corresponding to the CAN message are determined from the vehicle's detection rule base. The message rules are used to detect whether the message identifier, length, and transmission period of the CAN message conform to the definition in the vehicle's DBC file. The signal rules are used to indicate whether the CAN signals in the CAN message conform to the definition in the DBC file. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus.

[0007] Based on the message rules and the signal rules, the CAN message is detected to obtain the detection result of the CAN message;

[0008] If the detection result indicates that the CAN message is an abnormal message, it is determined that the operating state of the CAN bus is abnormal. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0009] On the other hand, an anomaly detection device for a CAN bus is provided, the device comprising:

[0010] The acquisition module is used to acquire the CAN message to be detected, wherein the CAN message refers to the message transmitted on the CAN bus of the vehicle;

[0011] The first determining module is used to determine the message rule and signal rule corresponding to the CAN message from the vehicle's detection rule base based on the message type of the CAN message. The message rule is used to indicate the definition of the message identifier, length, and transmission period of the CAN message in the vehicle's DBC file. The signal rule is used to indicate the definition of the CAN signal in the CAN message in the DBC file. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus.

[0012] The detection module is used to detect the CAN message based on the message rules and the signal rules, and obtain the detection result of the CAN message;

[0013] The second determining module is used to determine that the operating state of the CAN bus is abnormal when the detection result indicates that the CAN message is an abnormal message. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0014] In some embodiments, the detection module is configured to detect the CAN message based on the message rules and the signal rules; if at least one of the message identifier, length, transmission period, and CAN signals in the CAN message is found to be inconsistent with the definition in the DBC file, the CAN message is determined to be an abnormal message; if the message identifier, length, transmission period, and CAN signals in the CAN message are all found to be consistent with the definition in the DBC file, the CAN message is determined to be a normal message.

[0015] In some embodiments, the second determining module includes:

[0016] The first determining unit is used to analyze the inconsistent definition between the CAN message and the DBC file when the detection result indicates that the CAN message is an abnormal message, and to determine the abnormal event corresponding to the CAN message.

[0017] The second determining unit is used to determine that the operating state of the CAN bus is abnormal when the danger level of the abnormal event is higher than a preset value, wherein the danger level is used to indicate the degree of danger of the CAN message.

[0018] In some embodiments, the first determining unit is configured to, when the detection result indicates that the CAN message is an abnormal message, analyze the inconsistent definition between the CAN message and the DBC file to determine the abnormal type of the CAN message; and, based on the abnormal type of the CAN message, query the abnormal event corresponding to the CAN message from the abnormal event mapping information, wherein the abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event.

[0019] In some embodiments, the second determining unit is further configured to, when the danger level of the abnormal event corresponding to the CAN message is higher than the preset value, analyze the inconsistent definition between the CAN message and the DBC file, determine the attack type of the CAN message, the attack type including at least one of injection attack, replay attack and obfuscation attack; issue an alarm and execute the defense measures corresponding to the attack type.

[0020] In some embodiments, the apparatus further includes:

[0021] The rule update module is used to adjust the detection rules in the detection rule base based on the updated DBC file when a definition update is detected in the DBC file.

[0022] The first determining module is used to determine the message rule and signal rule corresponding to the CAN message from the adjusted detection rule base based on the message type of the CAN message.

[0023] In some embodiments, the apparatus further includes:

[0024] The parameter calculation module is used to calculate the CAN bus load rate and CAN bus information entropy of the vehicle during operation. The CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of the messages transmitted on the CAN bus.

[0025] The second determining module is further configured to determine that the operating state of the CAN bus is abnormal when the CAN bus load rate or the CAN bus information entropy exceeds the threshold defined in the detection rule base.

[0026] In another direction, a vehicle controller is provided, which includes a main control module. The main control module includes a processor and a memory. The memory is used to store at least one computer program, which is loaded and executed by the processor to implement the CAN bus anomaly detection method in the embodiments of this application.

[0027] On the other hand, a computer-readable storage medium is provided for storing at least one computer program, which is loaded and executed by a processor to implement the CAN bus anomaly detection method in the embodiments of this application.

[0028] This application provides a method for anomaly detection of a CAN bus. By determining the message rules and signal rules corresponding to the CAN message from a detection rule base based on the message type of the CAN message to be detected, the method can detect whether the message identifier, length, transmission period, and CAN signals contained in the CAN message conform to the definition of the CAN message in the vehicle's DBC file. This allows for accurate determination of the CAN message detection result, and based on the detection result, it can determine whether there are any abnormalities in the operating state of the vehicle's CAN bus. This effectively improves the security of the CAN bus and ensures the stable operation of the vehicle's electronic systems. Attached Figure Description

[0029] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0030] Figure 1 This is a schematic diagram of the implementation environment of a CAN bus anomaly detection method provided in the embodiments of this application;

[0031] Figure 2 This is a flowchart of a CAN bus anomaly detection method according to an embodiment of this application;

[0032] Figure 3 This is a schematic diagram of a CAN bus anomaly detection process provided according to an embodiment of this application;

[0033] Figure 4 This is a flowchart of another CAN bus anomaly detection method provided according to an embodiment of this application;

[0034] Figure 5 This is a block diagram of a CAN bus anomaly detection device according to an embodiment of this application;

[0035] Figure 6 This is a block diagram of another CAN bus anomaly detection device according to an embodiment of this application;

[0036] Figure 7 This is a schematic diagram of the structure of a vehicle controller according to an embodiment of this application. Detailed Implementation

[0037] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0038] In this application, the terms "first," "second," etc., are used to distinguish identical or similar items with essentially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor are there any restrictions on quantity or execution order.

[0039] In this application, the term "at least one" means one or more, and "multiple" means two or more.

[0040] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, data stored, data displayed, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0041] Figure 1 This is a schematic diagram illustrating the implementation environment of a CAN bus anomaly detection method according to an embodiment of this application. See also... Figure 1 The implementation environment includes vehicle 101 and server 102, which are connected via a wireless network.

[0042] In some embodiments, the vehicle 101 is equipped with multiple electronic control units (ECUs), such as engine control units, wheel speed control units, vehicle stability control units, airbag control units, and anti-lock braking units. These multiple ECUs communicate via a CAN bus within the vehicle 101.

[0043] In some embodiments, the CAN bus includes a powertrain CAN bus, a chassis control CAN bus, a body control CAN bus, and an entertainment system CAN bus, etc. Different CAN buses connect to different electronic control units. Accordingly, a gateway is also installed in vehicle 101. The gateway receives data from different CAN buses and can forward data from one CAN bus to another to enable communication between two electronic control units not connected to the same CAN bus. For example, when the engine of vehicle 101 fails, the engine control unit sends a fault signal to the powertrain CAN bus. After receiving the fault signal from the powertrain CAN bus, the gateway forwards it to the body control CAN bus, allowing the body control unit to obtain the fault signal from the body control CAN bus. Based on the fault signal, the body control unit then illuminates the dashboard warning light to alert the driver of a powertrain system failure.

[0044] In some embodiments, server 102 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0045] In this embodiment, the gateway, acting as the vehicle controller with the highest network traffic in vehicle 101, is equipped with a CAN bus anomaly detection system. During the operation of vehicle 101, the gateway can obtain CAN messages from different CAN buses and the detection rule base sent to vehicle 101 by server 102 via wireless network connection. Based on the detection rule base, the gateway can detect CAN messages and determine whether there are any anomalies in the operating status of the vehicle's CAN bus according to the detection results of the CAN messages.

[0046] Figure 2 This is a flowchart of a CAN bus anomaly detection method according to an embodiment of this application. The method is executed by the vehicle's gateway. Figure 2 As shown, the anomaly detection method for this CAN bus includes the following steps:

[0047] 201. The gateway obtains the CAN message to be detected. The CAN message refers to the message transmitted on the vehicle's CAN bus.

[0048] In this embodiment, the gateway in the vehicle is equipped with a CAN bus anomaly detection system. This system detects messages transmitted on the vehicle's CAN bus to determine if there are any anomalies in the CAN bus's operating status. Accordingly, when the anomaly detection system is activated, the gateway can acquire the CAN message to be detected. This CAN message can be a message sent by any electronic control unit in the vehicle.

[0049] 202. The gateway determines the corresponding message rules and signal rules for the CAN message from the vehicle's detection rule base based on the message type of the CAN message.

[0050] In this embodiment, when the vehicle's anomaly detection system is activated, the gateway can also retrieve a detection rule base generated from the vehicle's DBC (Database CAN) file from the server. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate via the CAN bus. The CAN message definition includes message definitions (message identifier, length, period, etc.) and signal definitions (value range, start bit, length, maximum value, reserved bits, etc. of signals in the message). This detection rule base includes multiple detection rules, which are standards used to determine whether data meets specific conditions. Based on these detection rules, the gateway can detect whether a CAN message is an abnormal message.

[0051] CAN message types include data frames, remote frames, and overload frames. Data frames are the most common message type on the CAN bus, used to transmit actual data between electronic control units (ECUs). Remote frames are used to request data from other ECUs; for example, if an ECU needs to obtain engine speed data, it will send a remote frame requesting this data. Overload frames are used to request a temporary halt to message transmission when the receiver or sender cannot process the current message flow, to avoid data loss or errors.

[0052] Because the content of CAN messages of different message types differs, the corresponding detection rules also differ. Accordingly, the gateway can determine the corresponding message rules and signal rules for the CAN message from the vehicle's detection rule base based on the message type. The message rules are used to detect whether the message identifier, length, and transmission period of the CAN message conform to the definitions in the DBC file; that is, the message rules specify the definitions of the message identifier, length, and transmission period of the CAN message in the vehicle's DBC file. The signal rules are used to detect whether the CAN signals in the CAN message conform to the definitions in the DBC file; that is, the signal rules specify the definitions of the CAN signals in the CAN message in the DBC file.

[0053] 203. The gateway detects CAN messages based on message rules and signal rules, and obtains the detection results of CAN messages.

[0054] In this embodiment, the gateway can detect whether the actual message identifier, actual length, and actual transmission period of the CAN message conform to the definition in the vehicle's DBC file, based on the message identifier, length, and transmission period of the CAN message indicated in the message rules. Similarly, the gateway can also detect whether the value range, start bit, length, maximum value, reserved bits, etc. of the CAN signal in the CAN message conform to the definition in the DBC file, based on the definition of the CAN signal in the CAN message indicated in the signal rules. If any item does not conform to the definition, the gateway determines that the CAN message is an abnormal message; if all items conform to the definition, the gateway determines that the CAN message is a normal message.

[0055] For example, Figure 3 This is a schematic diagram of a CAN bus anomaly detection process according to an embodiment of this application. Figure 3 As shown, the anomaly detection system first loads the vehicle's detection rule base, then collects CAN messages transmitted on the CAN bus through the gateway, and preprocesses the CAN messages to obtain the CAN message ID (message identifier), length, transmission period, CAN signal value range, start bit, length, maximum value, reserved bits, etc. Finally, it detects the CAN messages according to the detection rules in the detection rule base and obtains the detection results.

[0056] 204. If the detection result indicates that the CAN message is an abnormal message, the gateway determines that there is an abnormality in the operation of the CAN bus. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0057] In this embodiment of the application, if the detection result indicates that the CAN message is an abnormal message, it means that the CAN message obtained by the gateway does not conform to the definition of the CAN message in the DBC file. Therefore, the gateway can determine that the operating state of the CAN bus is abnormal, that is, the CAN bus is under attack.

[0058] This application provides a method for anomaly detection of a CAN bus. By determining the message rules and signal rules corresponding to the CAN message from a detection rule base based on the message type of the CAN message to be detected, the method can detect whether the message identifier, length, transmission period, and CAN signals contained in the CAN message conform to the definition of the CAN message in the vehicle's DBC file. This allows for accurate determination of the CAN message detection result, and based on the detection result, it can determine whether there are any abnormalities in the operating state of the vehicle's CAN bus. This effectively improves the security of the CAN bus and ensures the stable operation of the vehicle's electronic systems.

[0059] Figure 4 This is a flowchart of another CAN bus anomaly detection method provided according to an embodiment of this application. This method is executed by the vehicle's gateway, such as... Figure 4 As shown, the anomaly detection method for this CAN bus includes the following steps:

[0060] 401. The gateway obtains the CAN message to be detected. The CAN message refers to the message transmitted on the vehicle's CAN bus.

[0061] In this embodiment, step 401 is the same as step 201 described above, and will not be repeated here.

[0062] 402. The gateway determines the corresponding message rules and signal rules for the CAN message from the vehicle's detection rule base based on the message type of the CAN message.

[0063] In this embodiment, the CAN bus carries various types of messages originating from different electronic control units and carrying diverse information, including vehicle status information (such as vehicle speed and engine speed) and control commands (such as braking commands and throttle control commands). Different messages normally follow different communication rules. Therefore, to accurately detect message anomalies, the gateway can determine the corresponding message and signal rules from the vehicle's detection rule library based on the message type of the CAN message. The message rules are used to detect whether the message identifier, length, and transmission period of the CAN message conform to the definitions in the DBC file; that is, the message rules clarify the definitions of the message identifier, length, and transmission period of the CAN message in the vehicle's DBC file. The signal rules are used to detect whether the CAN signals in the CAN message conform to the definitions in the DBC file; that is, the signal rules clarify the definitions of the CAN signals in the CAN message in the DBC file.

[0064] It should be noted that the detection rule base includes detection rules corresponding to CAN messages sent by multiple electronic control units (ECUs) of the vehicle. For CAN messages of the same type but originating from different ECUs, the corresponding message rules and signal rules will also be different.

[0065] For example, regarding the definition of message identifiers in the message rules, for CAN messages sent by the engine control unit, the range of message identifiers defined in the corresponding message rules can be 0x100-0x1FF, and for CAN messages sent by the body control unit, the range of message identifiers defined in the corresponding message rules can be 0x200-0x2FF.

[0066] In some embodiments, when an update to the definition contained in the DBC file is detected, the detection rules in the detection rule base are adjusted based on the updated DBC file. Accordingly, step 402 can be replaced by: determining the message rules and signal rules corresponding to the CAN message from the adjusted detection rule base based on the message type of the CAN message. The DBC file is a database file format used to describe CAN bus network communication. It contains detailed definitions of messages on the CAN bus, such as the message identifier, message length, and the meaning of each byte of data in the message. With vehicle function upgrades, electronic control units may be added or upgraded. Accordingly, the definitions of CAN messages in the DBC file will also change. The gateway can read the updated DBC file from the server and parse it to obtain the network node definitions, message definitions, and signal definitions. Then, it can extract key parameters from the definitions, such as the updated message identifier and various attributes of the updated signals, and adjust the corresponding detection rules based on the updated parameters in the definitions. By adjusting the detection rules in the detection rule base, it is possible to perform packet detection based on the new detection rules, ensuring accurate detection of intrusion behavior.

[0067] 403. The gateway detects CAN messages based on message rules and signal rules.

[0068] In this embodiment, a CAN message consists of a frame start, arbitration field, control field, data field, CRC (Cyclic Redundancy Check) field, acknowledgment field, and frame end. The frame start marks the beginning of a CAN message, notifying all nodes on the CAN bus that a new message is being transmitted. The arbitration field defines the message identifier of the CAN message, which determines its priority. When multiple electronic control units (ECUs) transmit CAN messages simultaneously, the gateway can arbitrate based on the size of the message identifier. The smaller the message identifier value, the higher the priority. The control field defines information such as the length of the data field. The data field is the core of the CAN message and contains the CAN signal. Different ECUs transmit CAN signals of varying lengths based on their functions and current communication requirements. For example, a simple door status message might have a 1-byte CAN signal indicating whether the door is open or closed. A complex engine condition message might have an 8-byte CAN signal containing multiple parameters such as engine speed, coolant temperature, and intake pressure. When sending a CAN message, the sender calculates a CRC value based on the preceding data field and stores it in the CRC field. Upon receiving the message, the receiver calculates its own CRC value using the same algorithm and compares it to the received CRC value. If they match, the message transmission was error-free; otherwise, a potential error has occurred, and the receiver requests a retransmission to ensure data accuracy. After successfully receiving and verifying the message, the receiver sends an acknowledgment signal in the acknowledgment field to confirm successful reception. The end of a frame marks the end of a CAN message.

[0069] In the process of detecting CAN messages based on message rules, the gateway can parse the CAN message to obtain the actual message identifier, actual length, and actual transmission period of the CAN message. Then, it matches these values ​​one by one with the message identifier, length, and transmission period defined in the message rules to obtain the matching result. Similarly, in the process of detecting CAN messages based on signal rules, the gateway can parse the CAN message to obtain the actual value range, actual start bit, actual length, actual maximum value, and actual reserved bits of the CAN signal in the CAN message. Then, it matches these values ​​one by one with the parameters defined in the signal rules to obtain the matching result.

[0070] 404. If the gateway detects that at least one of the following in the CAN message—message identifier, length, transmission period, or CAN signal in the CAN message—is inconsistent with the definition in the DBC file, the CAN message will be identified as an abnormal message.

[0071] In this embodiment of the application, if the matching result indicates that at least one of the following—the message identifier, length, transmission period, and CAN signal in the CAN message—is inconsistent with the definition in the DBC file, it indicates that the current CAN message is abnormal, and therefore the CAN message is determined to be an abnormal message.

[0072] For example, if the message identifier of a CAN message is detected to be outside the range that its corresponding electronic control unit should use, it may mean that an unauthorized device has accessed the device or the message has been tampered with, thus the CAN message can be determined as an abnormal message. Alternatively, for CAN messages known to be periodically transmitted, the difference between the timestamp of the current CAN message and the previous CAN message of the same type can be compared to determine if it falls within the normal period range specified in the rule base. When it deviates from the normal range, the CAN message can be determined as an abnormal message. Alternatively, the values ​​of the CAN signals in the CAN message can be determined to be within the value range set in the rule base. For example, the normal range for engine speed is 0 to 8000 revolutions per minute. If the engine speed field value in the CAN signal is detected to be 10000 revolutions per minute, it can be determined that it clearly exceeds the normal range, thus the engine speed message is considered abnormal.

[0073] 405. If the message identifier, length, transmission period, and CAN signals in the CAN message are all consistent with the definitions in the DBC file, the gateway will determine the CAN message as a normal message.

[0074] In this embodiment of the application, if the matching result indicates that the message identifier, length, transmission period, and CAN signal in the CAN message are all consistent with the definition in the DBC file, it indicates that there is no abnormality in the current CAN message, and therefore the CAN message is determined to be a normal message.

[0075] 406. If the detection result indicates that the CAN message is an abnormal message, the gateway analyzes the inconsistent definitions between the CAN message and the DBC file to determine the abnormal event corresponding to the CAN message.

[0076] In this embodiment of the application, since some abnormal events with low degree of danger will not affect vehicle safety, when the CAN message is an abnormal message, the gateway can also determine the abnormal event corresponding to the abnormal situation of the CAN message by analyzing the inconsistent definitions between the CAN message and the DBC file.

[0077] In some embodiments, when the detection result indicates that the CAN message is an abnormal message, the inconsistency between the CAN message definition and the DBC file is analyzed to determine the abnormal type of the CAN message. Based on the abnormal type of the CAN message, the corresponding abnormal event is queried from the abnormal event mapping information. The abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event. The abnormal type may include length abnormality, signal value abnormality, message period abnormality, etc. Optionally, the mapping relationship between the abnormal type and the abnormal event is shown in Table 1. The abnormal events corresponding to length abnormality and signal value abnormality are message health abnormalities.

[0078] Table 1

[0079]

[0080]

[0081] 407. When the danger level of an abnormal event is higher than the preset value, the gateway determines that there is an abnormality in the operation of the CAN bus. The danger level is used to indicate the degree of danger of the CAN message.

[0082] In this embodiment of the application, since different abnormal events correspond to different levels of danger, when the level of danger of the abnormal event corresponding to the CAN message is higher than the preset value, that is, when the level of danger of the CAN message is high, the gateway cannot ignore the abnormality. Therefore, the gateway can determine that the CAN message is an attack message, that is, the CAN message will cause abnormality to the operating state of the CAN bus.

[0083] In some embodiments, if the danger level of the abnormal event corresponding to the CAN message is higher than a preset value, the inconsistent definition between the CAN message and the DBC file is analyzed to determine the attack type of the CAN message. The attack type includes at least one of injection attack, replay attack and obfuscation attack; an alarm is issued and the defense measures corresponding to the attack type are executed.

[0084] Injection attacks refer to attackers inserting malicious data into normal CAN bus communication. Attackers attempt to tamper with vehicle control system commands or interfere with normal communication data to influence vehicle behavior. For example, sending a forged engine speed control message on the CAN bus sets the engine speed to an abnormally high value, causing the engine to overspeed. This attack can seriously damage the vehicle's powertrain and even endanger driving safety. Accordingly, when CAN signal values ​​in a CAN message are detected to deviate from the normal range, the attack type can be identified as an injection attack. Defenses against injection attacks include encrypting critical messages transmitted on the CAN bus, ensuring that even if an attacker intercepts the message, they cannot tamper with its contents without the decryption key.

[0085] A replay attack refers to an attacker intercepting and recording legitimate CAN messages, then retransmitting them at an appropriate time to deceive the vehicle's electronic control unit (ECU) into performing the same operation or disrupting normal communication. For example, suppose an attacker intercepts a legitimate door unlock message. After the owner has locked the doors and left the vehicle, the attacker retransmits this message, causing the doors to unlock again. This not only compromises vehicle security but could also lead to theft from inside the vehicle. Accordingly, when the transmission interval of CAN messages is detected to be outside the normal range, the attack type can be identified as a replay attack. Defense measures against replay attacks could include adding a timestamp to each CAN message to record its transmission time. Upon receiving a CAN message, the timestamp is compared to the current time to determine its freshness. For example, if the received message's timestamp differs from the current time by more than a reasonable range (e.g., a few seconds), it is considered a possible replay attack, and the message is rejected. Alternatively, a unique sequence number can be assigned to each message. The receiver records the sequence numbers that have already been received. When it receives a CAN message with a sequence number that has already appeared, it determines that it may be a replay attack.

[0086] A fuzzy attack refers to an attacker sending malformed, non-compliant, or abnormally formatted messages to the CAN bus. The aim is to cause errors in the vehicle's electronic control unit (ECU) during message processing, such as system crashes, abnormal states, or the leakage of sensitive information. For example, an attacker might send a CAN message with a data field length that does not meet the specifications. When the ECU receives such a non-compliant message, it may malfunction due to its inability to process it correctly, resulting in issues such as program loops or memory overflows, thus affecting the normal operation of the vehicle. Accordingly, when a CAN message's format is detected to be non-compliant with the protocol standard, checking the correctness of the CAN message's frame start and end points, and whether the data field length is within the specified range, can determine the attack type as a fuzzy attack. The corresponding defense against fuzzy attacks is to rigorously check whether the received CAN message format conforms to the CAN bus protocol. This includes verifying the correctness of the format of each part, including the frame start, arbitration field, control field, data field, CRC field, acknowledgment field, and frame end.

[0087] Optionally, if a CAN message on the CAN bus that does not conform to the normal message identifier range of the electronic control unit is detected, it is likely a spoofing attack. For example, under normal circumstances, the message identifier range sent by the engine control unit is 0x100-0x1FF. If a CAN message with a message identifier of 0x300 claims to come from the engine control unit, it is possible that an external device is spoofing the message sent by the engine control unit. If the period of a critical message that is periodically sent (such as the vehicle speed message) becomes extremely short or extremely long, exceeding the normal range, it may also be a denial-of-service attack. For example, if the normal vehicle speed message is sent once every 100ms, and suddenly it becomes sent once every 10ms, it will consume a large amount of bus resources, preventing other electronic control units from communicating normally.

[0088] In some embodiments, flood attacks, injection attacks, etc., on the vehicle network can cause the CAN bus load rate and information entropy to exceed normal values. Therefore, in addition to detecting messages, the gateway can also calculate the load rate and information entropy on the CAN bus, and then determine whether there is an anomaly based on the calculation results. Accordingly, the CAN bus load rate and CAN bus information entropy are calculated during vehicle operation. The CAN bus load rate describes the current workload of the CAN bus, and the CAN bus information entropy describes the complexity and uncertainty of the messages transmitted on the CAN bus. If the CAN bus load rate or CAN bus information entropy exceeds the threshold defined in the detection rule base, it is determined that the CAN bus operating state is abnormal. The CAN bus load rate refers to the ratio of the number of bits actually transmitted per unit time to the number of bits that can be transmitted on the CAN bus. Load rate detection can monitor network traffic. Information entropy is used to measure the complexity and uncertainty of the messages transmitted on the CAN bus. Since the CAN bus load rate and information entropy are relatively stable under normal circumstances, when the CAN bus load rate exceeds the threshold defined in the detection rule base (a sudden and significant increase), it may indicate a flood attack. Attackers attempt to overwhelm normal communication messages by sending a large number of packets, preventing the vehicle's electronic control unit from processing information properly. When a vehicle is running stably, the CAN bus entropy remains within a relatively stable range. If the CAN bus entropy exceeds a threshold defined in the detection rule base (a sudden and significant increase), it may indicate an anomaly in the CAN bus. For example, during an attack, if a large number of new, irregular messages are injected, the entropy will increase.

[0089] This application provides a method for anomaly detection of a CAN bus. By determining the message rules and signal rules corresponding to the CAN message from a detection rule base based on the message type of the CAN message to be detected, the method can detect whether the message identifier, length, transmission period, and CAN signals contained in the CAN message conform to the definition of the CAN message in the vehicle's DBC file. This allows for accurate determination of the CAN message detection result, and based on the detection result, it can determine whether there are any abnormalities in the operating state of the vehicle's CAN bus. This effectively improves the security of the CAN bus and ensures the stable operation of the vehicle's electronic systems.

[0090] Figure 5 This is a block diagram of a CAN bus anomaly detection device according to an embodiment of this application. This device is used to execute the steps of the above-described CAN bus anomaly detection method, see [link to relevant documentation]. Figure 5 The device includes:

[0091] The acquisition module 501 is used to acquire the CAN message to be detected. The CAN message refers to the message transmitted on the CAN bus of the vehicle.

[0092] The first determining module 502 is used to determine the message rules and signal rules corresponding to the CAN message from the vehicle's detection rule library based on the message type of the CAN message. The message rules are used to detect whether the message identifier, length, and transmission period of the CAN message conform to the definition in the vehicle's DBC file. The signal rules are used to detect whether the CAN signals in the CAN message conform to the definition in the DBC file. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus.

[0093] The detection module 503 is used to detect CAN messages based on message rules and signal rules, and obtain the detection results of CAN messages;

[0094] The second determining module 504 is used to determine that there is an abnormality in the operating state of the CAN bus when the detection result indicates that the CAN message is an abnormal message. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file.

[0095] In some embodiments, the detection module 503 is used to detect CAN messages based on message rules and signal rules; if at least one of the message identifier, length, transmission period, and CAN signals in the CAN message is inconsistent with the definition in the DBC file, the CAN message is determined to be an abnormal message; if the message identifier, length, transmission period, and CAN signals in the CAN message are all consistent with the definition in the DBC file, the CAN message is determined to be a normal message.

[0096] In some embodiments, Figure 6 This is a block diagram of another CAN bus anomaly detection device according to an embodiment of this application. See also Figure 6 The second determining module 504 includes:

[0097] The first determining unit 601 is used to analyze the inconsistent definitions between the CAN message and the DBC file and determine the abnormal event corresponding to the CAN message when the detection result indicates that the CAN message is an abnormal message.

[0098] The second determining unit 602 is used to determine that the operating state of the CAN bus is abnormal when the danger level of the abnormal event is higher than a preset value. The danger level is used to indicate the degree of danger of the CAN message.

[0099] In some embodiments, the first determining unit 601 is configured to analyze the inconsistent definitions between the CAN message and the DBC file and determine the abnormal type of the CAN message when the detection result indicates that the CAN message is an abnormal message; based on the abnormal type of the CAN message, query the abnormal event corresponding to the CAN message from the abnormal event mapping information, wherein the abnormal event mapping information is used to indicate the mapping relationship between the abnormal type and the abnormal event.

[0100] In some embodiments, the second determining unit 602 is further configured to analyze the inconsistent definitions between the CAN message and the DBC file when the danger level of the abnormal event corresponding to the CAN message is higher than a preset value, determine the attack type of the CAN message, the attack type including at least one of injection attack, replay attack and obfuscation attack; issue an alarm and execute the defense measures corresponding to the attack type.

[0101] In some embodiments, see continue to see Figure 6 The device also includes:

[0102] The rule update module 505 is used to adjust the detection rules in the detection rule base based on the updated DBC file when a definition update is detected in the DBC file.

[0103] The first determining module 502 is used to determine the message rules and signal rules corresponding to the CAN message from the adjusted detection rule base based on the message type of the CAN message.

[0104] In some embodiments, see continue to see Figure 6 The device also includes:

[0105] The parameter calculation module 506 is used to calculate the CAN bus load rate and CAN bus information entropy during vehicle operation. The CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of the messages transmitted on the CAN bus.

[0106] The second determining module 504 is also used to determine that there is an abnormality in the operating state of the CAN bus when the CAN bus load rate or CAN bus information entropy exceeds the threshold defined in the detection rule base.

[0107] This application provides an anomaly detection device for a CAN bus. By determining the message rules and signal rules corresponding to the CAN message from a detection rule base based on the message type of the CAN message to be detected, the device can detect whether the message identifier, length, transmission period, and CAN signals contained in the CAN message conform to the definition of the CAN message in the vehicle's DBC file. This allows for accurate determination of the CAN message detection result, and based on the detection result, it can determine whether there are any anomalies in the operating state of the vehicle's CAN bus. This effectively improves the security of the CAN bus and ensures the stable operation of the vehicle's electronic systems.

[0108] It should be noted that the CAN bus anomaly detection device provided in the above embodiments is only illustrated by the division of the above functional modules when running the application program. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the CAN bus anomaly detection device and the CAN bus anomaly detection method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0109] Figure 7 This is a schematic diagram of the structure of a vehicle controller according to an embodiment of this application.

[0110] Typically, the vehicle controller 700 includes: a main control module 701, a CAN interface 702, a hard-wired input interface 703, and a hard-wired output interface 704. The main control module 701 is connected to the CAN interface 702, the hard-wired input interface 703, and the hard-wired output interface 704, respectively.

[0111] The main control module 701 typically includes a processor and memory. The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor can be implemented using at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor may also include a main processor and a coprocessor. The main processor, also known as a CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content required to be displayed on the vehicle's screen. In some embodiments, the processor may also include an AI (Artificial Intelligence) processor, which is used to handle computational operations related to machine learning. The memory may include one or more computer-readable storage media, which may be non-transitory. The memory may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In some embodiments, a non-transitory computer-readable storage medium in the memory is used to store at least one computer program, which is executed by a processor to implement the CAN bus anomaly detection method provided in the method embodiments of this application.

[0112] The CAN interface 702 may include a powertrain CAN interface, a body CAN interface, a brake CAN interface, and a diagnostic CAN interface. The powertrain CAN interface is used to communicate with the vehicle's powertrain system, the body CAN interface is used to communicate with the vehicle's body control system, the brake CAN interface is used to communicate with the vehicle's braking system, and the diagnostic CAN interface is used to communicate with the diagnostic system.

[0113] The hard-wired input interface 703 is used to receive hard-wired control signals. The hard-wired output interface 704 is used to send control commands to the vehicle's electronic control components, causing the vehicle's electronic control components to perform corresponding actions. The vehicle's electronic control components include a power management system, a motor controller, an on-board charger, and a body control system.

[0114] The main control module 701 can communicate with the vehicle's power system, body control system, braking system and diagnostic system through the CAN interface 702, and generate control commands based on the hard-wired control signals received by the hard-wired input interface 703, so as to send the control commands to the vehicle's electronic control components through the hard-wired output interface 704.

[0115] Those skilled in the art will understand that Figure 7 The structure shown does not constitute a limitation on the vehicle controller 700, and may include more or fewer components than shown, or combine certain components, or use different component arrangements.

[0116] This application also provides a computer-readable storage medium storing at least one computer program. This computer program is loaded and executed by the processor of a vehicle controller to implement the operations performed by the vehicle controller in the CAN bus anomaly detection method of the above embodiments. For example, the computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, or optical data storage device, etc.

[0117] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0118] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for detecting anomalies in a CAN bus, characterized in that, The method includes: Acquire the CAN message to be detected, wherein the CAN message refers to the message transmitted on the vehicle's CAN bus; Based on the message type of the CAN message, the message rules and signal rules corresponding to the CAN message are determined from the vehicle's detection rule base. The message rules are used to detect whether the message identifier, length, and transmission period of the CAN message conform to the definition in the vehicle's DBC file. The signal rules are used to indicate whether the CAN signals in the CAN message conform to the definition in the DBC file. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus. Based on the message rules and the signal rules, the CAN message is detected to obtain the detection result of the CAN message; If the detection result indicates that the CAN message is an abnormal message, the inconsistent definition between the CAN message and the DBC file is analyzed to determine the abnormal event corresponding to the CAN message. Different abnormal events correspond to different levels of danger. If the danger level of the abnormal event is higher than a preset value, it is determined that the operating state of the CAN bus is abnormal. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file, and the danger level is used to indicate the degree of danger of the CAN message.

2. The method according to claim 1, characterized in that, The step of detecting the CAN message based on the message rules and the signal rules to obtain the detection result of the CAN message includes: The CAN message is detected based on the message rules and the signal rules. If at least one of the following is found to be inconsistent with the definition in the DBC file: message identifier, length, transmission period, and CAN signal in the CAN message; the CAN message will be identified as an abnormal message. If the message identifier, length, transmission period, and CAN signals in the CAN message are all consistent with the definitions in the DBC file, the CAN message is determined to be a normal message.

3. The method according to claim 1, characterized in that, When the detection result indicates that the CAN message is an abnormal message, the inconsistency between the CAN message definition and the definition in the DBC file is analyzed to determine the abnormal event corresponding to the CAN message, including: If the detection result indicates that the CAN message is an abnormal message, analyze the inconsistency between the CAN message and the definition in the DBC file to determine the abnormal type of the CAN message; Based on the exception type of the CAN message, the exception event corresponding to the CAN message is queried from the exception event mapping information. The exception event mapping information is used to indicate the mapping relationship between the exception type and the exception event.

4. The method according to claim 1, characterized in that, The method further includes: If the danger level of the abnormal event corresponding to the CAN message is higher than the preset value, the inconsistent definition between the CAN message and the DBC file is analyzed to determine the attack type of the CAN message. The attack type includes at least one of injection attack, replay attack and obfuscation attack. Issue an alert and execute the defense measures corresponding to the attack type.

5. The method according to claim 1, characterized in that, The method further includes: If an update to a definition is detected in a DBC file, the detection rules in the detection rule base are adjusted based on the updated DBC file. Based on the message type of the CAN message, the process of determining the corresponding message rules and signal rules for the CAN message from the vehicle's detection rule base includes: Based on the message type of the CAN message, the message rules and signal rules corresponding to the CAN message are determined from the adjusted detection rule base.

6. The method according to claim 1, characterized in that, The method further includes: Calculate the CAN bus load rate and CAN bus information entropy of the vehicle during operation. The CAN bus load rate is used to describe the current workload of the CAN bus, and the CAN bus information entropy is used to describe the complexity and uncertainty of the messages transmitted on the CAN bus. If the CAN bus load rate or the CAN bus information entropy exceeds the threshold defined in the detection rule base, it is determined that the CAN bus operating state is abnormal.

7. A CAN bus anomaly detection device, characterized in that, The device includes: The acquisition module is used to acquire the CAN message to be detected, wherein the CAN message refers to the message transmitted on the CAN bus of the vehicle; The first determining module is used to determine the message rule and signal rule corresponding to the CAN message from the vehicle's detection rule base based on the message type of the CAN message. The message rule is used to indicate the definition of the message identifier, length, and transmission period of the CAN message in the vehicle's DBC file. The signal rule is used to indicate the definition of the CAN signal in the CAN message in the DBC file. The DBC file contains the definitions of all CAN messages generated when multiple electronic control units of the vehicle communicate through the CAN bus. The detection module is used to detect the CAN message based on the message rules and the signal rules, and obtain the detection result of the CAN message; The second determining module is used to analyze the inconsistent definitions between the CAN message and the DBC file when the detection result indicates that the CAN message is an abnormal message, and to determine the abnormal event corresponding to the CAN message. Different abnormal events correspond to different levels of danger. If the danger level of the abnormal event is higher than a preset value, it is determined that the operating state of the CAN bus is abnormal. The abnormal message is used to indicate that the CAN message is inconsistent with the definition in the DBC file, and the danger level is used to indicate the degree of danger of the CAN message.

8. A vehicle controller, characterized in that, The vehicle controller includes a main control module, which includes a processor and a memory. The memory is used to store at least one computer program, which is loaded and executed by the processor. The abnormal detection method for the CAN bus according to any one of claims 1 to 6 is described in the claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store at least one computer program for executing the CAN bus anomaly detection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Abnormity detection method and device

    CN112514351A

  • Vehicle CAN network intrusion detection method and device, electronic equipment and medium

    CN114374565A

  • CAN bus attack type determination method, processor and computer equipment

    CN117544410A