CAN bus intrusion detection method and system based on embedded platform

By using DMA double cache technology to acquire CAN bus voltage signals and determine the multi-dimensional feature vector of temperature robustness, the problem that CAN bus voltage fingerprint is susceptible to temperature changes is solved, and efficient intrusion detection on the embedded platform is achieved.

CN120165985AActive Publication Date: 2025-06-17NORTHWESTERN POLYTECHNICAL UNIV

Patent Information

Application Number
CN202510638933.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-06-17
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

In the prior art, the voltage fingerprint of the CAN bus is susceptible to temperature changes, resulting in a decrease in feature stability, and the hardware resource limitation of the embedded platform is difficult to support the real-time deployment of high-precision oscilloscopes, making it difficult to achieve intrusion detection.

Method used

The ADC interface and DMA double cache technology based on the embedded platform are used to collect the voltage signal of the CAN bus, and the voltage value data is obtained through voltage conversion, and a multi-dimensional feature vector with temperature robustness is determined, and a preset voltage fingerprint model is input for intrusion detection.

Benefits of technology

It improves IDS robustness in temperature change scenarios, reduces CPU utilization, solves the contradiction between hardware resource limitations and real-time sampling performance requirements, and realizes efficient intrusion detection on embedded platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165985A_ABST
    Figure CN120165985A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of industrial control network communication safety protection, and relates to a CAN bus intrusion detection method and system based on an embedded platform, through an ADC interface of the embedded platform, a DMA double-cache technology is adopted to collect a voltage signal of a CAN bus, the voltage signal is subjected to voltage conversion to obtain voltage value data, and the voltage value data is sent to the CAN bus. Determining a multi-dimensional feature vector with temperature robustness according to the voltage value data; voltage fingerprint offset caused by temperature change is overcome; and inputting the multi-dimensional feature vector into a preset voltage fingerprint model, predicting the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performing intrusion detection judgment according to the membership probability of the ECU to obtain an intrusion detection result. Through a DMA buffer mechanism, the sampled data is directly transmitted from the data register of the ADC to the memory buffer, so that the CPU utilization is greatly reduced, and the contradiction between the hardware resource limitation of the embedded ECU equipment and the real-time continuous sampling performance requirement is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control network communication security protection, and particularly relates to a method and system for CAN bus intrusion detection based on an embedded platform. Background Art

[0002] The Controller Area Network (CAN) bus has become the core communication protocol in the industrial control field, especially for industrial automation equipment and distributed control systems, due to its high real-time performance and strong anti-interference ability. In recent years, with the in-depth application of industrial Internet of Things and intelligent manufacturing technologies, the industrial CAN bus has integrated multiple heterogeneous communication interfaces through programmable logic controllers and intelligent sensor nodes to achieve device collaboration and remote monitoring functions. While these extended capabilities improve production efficiency, they also significantly expand the attack surface of the system - the proliferation of open protocol conversion interfaces and third-party device access provides a penetration path for cross-network attacks. More seriously, the inherent plaintext data transmission mechanism and stateless broadcast communication characteristics of the CAN bus pose risks such as replay attacks and instruction hijacking in industrial control scenarios, which may lead to production process interruptions or physical damage to critical equipment. Therefore, designing an active intrusion detection and protection mechanism for the industrial CAN bus is of urgent significance for ensuring the safe and stable operation of industrial control networks.

[0003] To address the increasingly severe security threats of the CAN bus, the academic community has proposed various protection mechanisms. The IDS (Intrusion Detection System) based on side-channel - hardware fingerprint recognition has the advantage of attack traceability. Among them, the IDS based on voltage fingerprint has received extensive attention from researchers due to the physical unclonability of voltage fingerprints and the anti-message frequency interference characteristics.

[0004] Mainstream voltage fingerprint-based IDSs, such as the papers [1] (Choi W, Joo K, Jo H J, et al. VoltageIDS: Low-level communication characteristics for automotive intrusion detection system[J]. IEEE Transactions on Information Forensics and Security, 2018, 13(8): 2114-2129.) and [2] (Kneib M, Huth C. Scission: Signal characteristic-based sender identification and intrusion detection in automotive networks[C]. Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. 2018: 787-800.) and the patent US11683323B2, are implemented through steps such as voltage feature extraction, classification model training, and intrusion detection algorithm identification based on the collected voltage signals. Although the existing voltage fingerprint-based IDSs provide effective protection for CAN bus security, their practical deployment still faces two key bottlenecks. First, the voltage characteristics of ECUs in the CAN bus, that is, the voltage signal characteristics, are vulnerable to environmental temperature fluctuations, resulting in a significant decline in feature stability. Whether there is a temperature-robust voltage feature set and the establishment of its screening and verification mechanism is still a core issue to be urgently solved. Second, the existing solutions mostly rely on high-precision oscilloscopes (such as PicoScope) to achieve signal acquisition, while the computing resources and storage capacity of ECUs deployed on embedded platforms are limited, making it difficult to support the real-time deployment of such devices. How to achieve efficient signal acquisition and multi-type attack detection based on the hardware of the embedded platform is another major challenge restricting the implementation of the technology. Summary of the Invention

[0005] The purpose of the present invention is to provide a CAN bus intrusion detection method and system based on an embedded platform, which solves the problems in the prior art of voltage fingerprint drift caused by sensitivity to temperature changes and the conflict between the sampling requirements of high-precision oscilloscopes and the limited hardware resources of the embedded platform. To achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present application discloses a method for CAN bus intrusion detection based on an embedded platform, including: Based on the ADC (Analog-to-Digital Converter) interface of the embedded platform, the DMA (Direct Memory Access) dual-buffer technology is adopted to collect the voltage signal of the CAN bus; The voltage signal is converted through voltage conversion to obtain voltage value data, and the multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness; The multi-dimensional feature vector is input into a preset voltage fingerprint model, and the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector. An intrusion detection judgment is made according to the membership probability of the ECU to obtain an intrusion detection result.

[0006] Preferably, the voltage signal of the CAN bus is a differential signal at -5°C to 40°C.

[0007] Preferably, converting the voltage signal through voltage conversion to obtain voltage value data, and determining the multi-dimensional feature vector according to the voltage value data specifically includes: S201: Convert the voltage signal into voltage value data through the ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the data rule of the CAN bus, identify the dominant bit of the voltage value data according to the SOF bit, and decode the ID corresponding to the dominant bit according to the dominant bit; S204: After the ID, identify the dominant bit according to the voltage value data, and use the random interleaved sampling method to divide the dominant bit into dominant bit units in turn according to the rising edge, falling edge, and dominant platform, and splice the dominant bit units in the order of the first size of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: Based on the heuristic algorithm and the preset evaluation index with temperature change robustness, extract the multi-dimensional feature vectors of the rising edge vector, the dominant platform vector, and the falling edge vector that are robust to temperature change respectively.

[0008] Preferably, the preset voltage fingerprint model is obtained through the following steps: Based on the ADC interface of the embedded platform, the DMA dual-buffer technology is adopted to collect the voltage signal of the CAN bus; The voltage signal is converted through voltage conversion to obtain voltage value data, and the multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness; According to the multi-dimensional feature vector, based on the heuristic algorithm, screen the voltage signal on at least two platforms, and extract the voltage feature set with temperature robustness; Train a multi-classification model based on the voltage feature set to obtain a voltage fingerprint model.

[0009] Preferably, after determining the intrusion detection result, a warning is issued according to the intrusion detection result and the attack source is located.

[0010] In a second aspect, the present application discloses a CAN bus intrusion detection system based on an embedded platform, including: A voltage sampling module for acquiring a voltage signal; wherein, the voltage signal is acquired from the CAN bus based on the ADC interface of the embedded platform and using the DMA double-buffer technology; A data preprocessing module for converting the voltage signal through voltage conversion to obtain voltage value data, and determining a multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; An intrusion detection module for inputting the multi-dimensional feature vector into a preset voltage fingerprint model, the voltage fingerprint model predicting the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performing intrusion detection judgment according to the membership probability of the ECU to obtain an intrusion detection result.

[0011] Preferably, it further includes a warning module for issuing a warning according to the intrusion detection result and locating the attack source.

[0012] Preferably, in the data preprocessing module, converting the voltage signal through voltage conversion to obtain voltage value data, and determining a multi-dimensional feature vector according to the voltage value data specifically includes: S201: Converting the voltage signal into voltage value data through the ADC conversion formula; S202: Identifying the SOF bit of the voltage value data; S203: Based on the CAN bus data rule, identifying the dominant bit of the voltage value data according to the SOF bit, and decoding the dominant bit to obtain the ID corresponding to the dominant bit; S204: After the ID, identifying the dominant bit according to the voltage value data, and using the random interleaved sampling method to divide the dominant bit into rising edges, falling edges, and dominant platforms, and splicing them in the order of the first digit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, extracting a multi-dimensional feature vector that is robust to temperature changes based on a heuristic algorithm and a preset evaluation index that is robust to temperature changes.

[0013] In a third aspect, the present application discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and when the processor executes the computer program, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0014] Fourthly, the present application discloses a computer-readable storage medium storing a computer program, which when executed by a processor, implements the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above.

[0015] Compared with the prior art, the present invention has the following beneficial effects: Based on the ADC interface of the embedded platform, the present application introduces a DMA buffer mechanism to collect the voltage signals of the CAN bus, enabling the data transmission between the ADC and the memory without the participation of the CPU (Central Processing Unit). Through the interface with the ADC, the DMA directly transfers the sampled data from the data register of the ADC to the memory buffer, which can significantly reduce the CPU utilization and solve the contradiction between the hardware resource limitation of the embedded ECU device and the real-time continuous sampling performance requirement. By determining a multi-dimensional feature vector with temperature robustness from the voltage signals, the offset of the voltage fingerprint caused by temperature changes is overcome. The influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS recognition, is weakened, and the robustness of the IDS to temperature changes in the temperature change scenario is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 is a schematic flowchart of the method of the embodiment of the present invention; Figure 2 is a system block diagram of the embodiment of the present invention; Figure 3 is a hardware design for the deployment of a CAN bus intrusion detection system based on an embedded platform according to an embodiment of the present invention; Figure 4 is a flowchart of feature extraction and selection in the CAN bus intrusion detection system of the comparative example of the present invention; Figure 5 is a flowchart of the feature selection framework in the CAN bus intrusion detection system of the comparative example of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] The following will refer to the drawings and combine with the embodiments to detail the present invention. It should be noted that, without conflict, the embodiments and features in the present application can be combined with each other.

[0019] The following detailed descriptions are all exemplary descriptions, aiming to provide further detailed explanations for the present invention. Unless otherwise specified, all technical terms adopted in the present invention have the same meanings as those commonly understood by those of ordinary skill in the art to which this application belongs. The terms used in the present invention are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention.

[0020] See Figure 1 , this application discloses a method for CAN bus intrusion detection based on an embedded platform, including: S1: Based on the ADC interface of the embedded platform, the DMA dual-buffer technology is used to collect the voltage signal of the CAN bus; based on the ADC interface of the embedded platform, this application introduces a DMA buffer mechanism to collect the voltage signal of the CAN bus, enabling the data transmission between the ADC and the memory without the participation of the CPU. DMA directly transfers the sampled data from the data register of the ADC to the memory buffer through the interface with the ADC, which can significantly reduce CPU utilization and solve the contradiction between the hardware resource limitations of the embedded ECU device and the performance requirements of real-time continuous sampling.

[0021] S2: The voltage signal is converted into voltage value data through voltage conversion, and a multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness; by determining a multi-dimensional feature vector with temperature robustness from the voltage signal, the voltage fingerprint offset caused by temperature changes is overcome. The influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS recognition, is weakened, and the robustness of the IDS to temperature changes in a temperature change scenario is improved.

[0022] S3: The multi-dimensional feature vector is input into a preset voltage fingerprint model, and the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector. An intrusion detection judgment is made according to the membership probability of the ECU to obtain an intrusion detection result.

[0023] In the traditional ADC sampling method, the CPU needs to continuously poll the status of the ADC to read the conversion result. In this system, the system needs to monitor the ADC status at all times. Therefore, the traditional ADC sampling method not only increases the burden on the CPU, but also reduces the real-time performance of the system due to polling delay. To solve this problem, this application introduces a DMA buffer mechanism, enabling data transmission between the ADC and memory without the participation of the CPU. Since the data sending frequency of the CAN bus is usually high, while the sampling rate of the ADC may not be able to match it, resulting in the inability to accurately restore all the information of the CAN frame. The ADC and DMA are connected through hardware logic and do not rely on the CPU to transfer data. Therefore, DMA directly transfers the sampled data from the data register of the ADC to the memory buffer through its interface with the ADC, which can significantly reduce CPU utilization. Random interleaved sampling restores the CAN bus signal collected at a high sampling rate by splicing multiple dominant bits, thereby reducing the sampling rate requirement for the platform and solving the conflict between it and the platform hardware. Since voltage acquisition is a linear time sequence, by sorting and splicing the messages according to the magnitude of the first bit in each message, the original signal characteristics can be restored. This method can maximize the retention of the characteristics of the CAN signal even at a low sampling rate, avoiding information loss in periodic sampling.

[0024] In some embodiments, the voltage signal of the CAN bus is a differential signal at -5°C to 40°C. The prior art can only meet the temperature range of 0°C to 15°C. The voltage signal adopted in this application expands the available temperature range and improves the adaptability of the application system to temperature changes.

[0025] In some embodiments, the voltage signal is converted into voltage value data through voltage conversion, and a multi-dimensional feature vector is determined according to the voltage value data, specifically including: S201: Convert the voltage signal into voltage value data through the ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the data law of the CAN bus, identify the dominant bits of the voltage value data according to the SOF bit, decode the ID corresponding to the dominant bit according to the dominant bit, and based on the known mapping relationship between the ECU and the ID, determine the ECU corresponding to each ID; S204: After the ID, identify the dominant bits according to the voltage value data, and use the random interleaved sampling method to divide the dominant bits into rising edges, falling edges, and dominant platforms, and splice them in the order of the magnitude of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, extract a multi-dimensional feature vector that is robust to temperature changes based on a heuristic algorithm and a preset evaluation index that is robust to temperature changes.

[0026] Further preferably, the S205 specifically includes: S2051: According to the calculation formula of voltage characteristics, taking voltage value data as the unit, calculate the rising edge vector, dominant platform vector, and falling edge vector to obtain voltage characteristics; S2052: For the voltage characteristics, select single voltage characteristics that meet the conditions through indicators; determine the selection range of voltage characteristics according to the single voltage characteristics; S2053: Based on the selection range of voltage characteristics, perform basic feature combination on single voltage characteristics to obtain a basic voltage feature combination; the basic voltage feature combination refers to the common feature set of existing voltage-based intrusion detection systems; S2054: For the basic voltage feature combination, based on a heuristic algorithm, with the preset robustness to temperature change as the evaluation index, screen the basic voltage feature combination to obtain the first optimal voltage feature set, and based on the rising edge vector, dominant platform vector, and falling edge vector, extract the corresponding second optimal voltage feature set. The first optimal voltage feature set and the second optimal voltage feature set constitute a multi-dimensional feature vector.

[0027] The heuristic algorithm is proposed relative to the optimization algorithm. It is defined as: an algorithm constructed based on intuition or experience that gives a feasible solution for each instance of the combinatorial optimization problem to be solved at an acceptable cost (referring to computing time and space), and the deviation degree of the feasible solution from the optimal solution generally cannot be predicted. The heuristic algorithm in this application is based on the existing genetic algorithm, sets its evaluation index as the robustness to temperature change, and optimizes and screens to obtain a multi-dimensional feature vector that is robust to temperature change.

[0028] In some embodiments, the multi-dimensional feature vector is input into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performs intrusion detection judgment based on the membership probability of the ECU to obtain an intrusion detection result. Among them, in data preprocessing, based on the known mapping relationship between the ECU and the ID, the corresponding ECU is judged; then: S301: The multi-dimensional feature vector is input into a preset voltage fingerprint model to calculate the membership probability that the current multi-dimensional feature vector belongs to the corresponding ECU; S302: Combine the membership probabilities of other IDs with the calculated ECU membership probability, and judge whether an attack is encountered and locate the ECU of the attack source through a preset intrusion detection algorithm.

[0029] Specifically, the preset intrusion detection algorithm identifies the multi-dimensional feature vector of the current message based on the voltage fingerprint model and predicts the membership probability P of the message belonging to each known ECUECU If the membership probability P of the current message corresponding to the ECU ECU is higher than the trust threshold T min = 0.8, it indicates that the source ECU of the message is consistent with its message content. Then, the message is considered legal, and the degree of suspicion of the model for this ECU message is further reduced by decreasing the value of the questioned message counter. When P ECU is lower than the trust threshold T min , it means that the source ECU of the current message is inconsistent with its message content. Then, the current message is considered possibly abnormal, and the system enters the next step of judgment. When the credibility of the message is questioned, the system will further compare the membership probability values of other IDs. If the membership probability P of other IDs other is higher than the warning threshold T doubt = 0.6, it indicates that the source of the message is identified as another ECU. At this time, the system determines an internal attack and marks the current message as illegal.

[0030] Further preferably, the preset intrusion detection algorithm is an intrusion detection algorithm designed for possible attacks (for example: Scission, EASI).

[0031] In some embodiments, it further includes, after determining the intrusion detection result, issuing a warning and locating the attack source according to the intrusion detection result. If the intrusion detection result is an encounter with an attack, the embedded platform controls the buzzer to emit a sound to give a warning.

[0032] If the intrusion detection result determines the attack source and type, the embedded platform controls the display screen to output the attack source and the attack result.

[0033] In some embodiments, the preset voltage fingerprint model is obtained through the following steps: Based on the ADC interface of the embedded platform, the voltage signals of the CAN bus are collected by using the DMA double-buffer technology; The voltage signals are converted into voltage value data through voltage conversion, and the multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness; According to the multi-dimensional feature vector, based on the heuristic algorithm, the voltage signals are screened on no less than two platforms to extract the voltage feature set with temperature robustness; Based on the voltage feature set, a multi-classification model is trained to obtain the voltage fingerprint model.

[0034] In some embodiments, in the host computer, voltage signals obtained from no less than two platforms are screened according to multi-dimensional feature vectors, and a set of voltage features with temperature robustness is extracted as input features. The ECU corresponding to the input features is used as a label. Among them, the input features and the corresponding labels constitute a mapping data set. For this mapping data set, a machine learning multi-classification algorithm is used to train a voltage fingerprint model. During the training process, this method uses the minimization of cross-entropy as the loss function and adopts k-fold cross-validation to optimize the parameters of the voltage fingerprint model. The parameters of the trained voltage fingerprint model are exported to the embedded platform in the form of text or static variables, and on the embedded platform, by reading the parameters, the deployed voltage fingerprint model is loaded.

[0035] Further preferably, the preset evaluation index for temperature change robustness is a numerical evaluation index for customizing voltage signals that are robust to temperature changes.

[0036] This application also discloses a CAN bus intrusion detection system based on an embedded platform, including: A voltage sampling module for acquiring voltage signals; among them, the voltage signals are collected from the CAN bus based on the ADC interface of the embedded platform using the DMA double-buffer technology; A data preprocessing module for converting the voltage signals into voltage value data through voltage conversion and determining the multi-dimensional feature vectors of the voltage according to the voltage value data; the multi-dimensional feature vectors have temperature robustness; An intrusion detection module for inputting the multi-dimensional feature vectors into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vectors, and performs intrusion detection judgment according to the membership probability of the ECU to obtain an intrusion detection result.

[0037] In some embodiments, see Figure 2 , and further includes a warning module for issuing a warning according to the intrusion detection result and locating the attack source.

[0038] In some embodiments, in the data preprocessing module, converting the voltage signals into voltage value data through voltage conversion and determining the multi-dimensional feature vectors according to the voltage value data specifically includes: S201: Converting the voltage signals into voltage value data through the ADC conversion formula; S202: Identifying the SOF bit of the voltage value data; S203: Based on the SOF bit and the CAN bus data rule, identifying the dominant bit of the voltage value data, decoding the ID according to the dominant bit, and judging the corresponding ECU according to the ID in combination with the known mapping relationship between the ECU and the ID; S204: After the ID, identify the dominant bits according to the voltage value data, and use the random interleaved sampling method to segment the dominant bits according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index that is robust to temperature changes, extract the multi-dimensional feature vector that is robust to temperature changes.

[0039] Embodiment: This embodiment provides a CAN bus intrusion detection method based on STM32 for internal attacks.

[0040] Hardware configuration: Master control chip: STM32H743ZIT6 (built-in 3 12-bit ADCs, supporting an input range of 0 - 3.3V); ADC sampling configuration: Sampling rate: 5 MS / s (ADC clock configured to 30 MHz, 12-bit resolution); DMA channel: DMA2 Stream0, circular buffer size 2048 samples; This method includes the following steps: S1: Based on the ADC interface of the embedded platform, use the DMA double-buffer technology to collect the voltage signal of the CAN bus; within the environmental temperature range of [-5, 20) °C, set 6 temperature gradients at intervals of 5 °C (-5 °C, 0 °C, 5 °C, 10 °C, 15 °C, 20 °C). At each temperature point, collect: 8 ECUs × 700 frames = 5600 frames (actually collect 113200 frames) S2: Convert the voltage signal through voltage conversion to obtain voltage value data, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; S201: Convert the voltage signal into voltage value data through the ADC conversion formula; the reference voltage is 3.3V; S202: Identify the SOF bit of the voltage value data; determine the threshold, the threshold for the dominant bit is: differential voltage > 1.5V (duration ≥ 4 sampling points), and the threshold for the recessive bit is: differential voltage < 0.5V. Judge the CAN bus data according to the threshold.

[0041] S203: Based on the CAN bus data rule, compile the data with 11 bits per bit, identify the dominant bits of the voltage value data according to the SOF bit, and decode the dominant bits to obtain the ID corresponding to the dominant bit. According to the ID, based on the known mapping relationship between the ECU and the ID, judge the corresponding ECU; S204: After the ID, identify the dominant bits based on the voltage value data. Use the random interleaved sampling method (random interleaved sampling adopts 5-fold oversampling) to segment the dominant bits according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index that is robust to temperature changes, extract the multi-dimensional feature vector that is robust to temperature changes.

[0042] S3: Input the multi-dimensional feature vector into the preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and perform intrusion detection judgment according to the membership probability of the ECU to obtain the intrusion detection result.

[0043] Comparative example: Select a car as the actual application scenario; to verify the effectiveness of the solution and eliminate the influence of the environmental factors of the real vehicle, it is proved by experiments on two platforms of the real vehicle and the prototype system respectively. See Figure 3 、 Figure 4 and Figure 5 .

[0044] Real vehicle platform: The experiment uses a Buick Regal as the real vehicle platform. The ECUs on the real vehicle are provided by multiple manufacturers, so it is more in line with the heterogeneity characteristics of the ECUs in real-scenario vehicles. However, the environmental temperature of the ECUs on the real vehicle system is more complex. The environmental temperature of the ECUs on the real vehicle is affected by the heat generated by the engine operation. Therefore, the real vehicle is divided into a cold start state and a hot start state in the experiment. Among them, the cold start state is defined as the engine starting in a low-temperature state, which refers to the start state after the engine has been shut down for a period of time. The hot start state refers to the process of the engine being shut down and restarted after running for a period of time.

[0045] Prototype System: Considering that ECUs in real vehicles usually come from different manufacturers, the prototype system uses ECUs from different manufacturers as much as possible to simulate the actual application environment. The prototype system consists of 7 ECUs. The system architecture is designed to maximize the simulation of hardware platforms from different manufacturers to improve the broad applicability of experimental results. The specific components include: 3 STM32F103 development boards equipped with CAN modules, 2 Arduino Nanos, each Arduino Nano is connected to an MCP2515 CAN controller and a TJA1050 CAN transceiver, 1 USBCAN-II Pro device that can be used as a CAN bus communication device, and 1 CANalyst-II device that can be used as a CAN bus communication device. To restore the CAN bus channel, one of the STM32F103 development boards and one USBCAN-II Pro device in the prototype system carry resistors respectively to ensure the normal voltage of the CAN bus. The prototype system includes two CAN High and CAN Low lines with a rate of 500 kbit / s.

[0046] Experimental Parameters To verify the temperature changes in the validation and feature selection phases, it is necessary to collect voltage data at different temperatures on each platform. During the experiment, to ensure the accuracy of the ambient temperature, two thermometers, a mercury thermometer and an electronic thermometer, are used as references for temperature data. Since the ambient temperature will fluctuate slightly in a short period of time, each data set is collected and divided with a temperature change step of 5°C. That is, the temperature difference of each data collection does not exceed 5°C, and the temperature step interval is left-closed and right-open. For example, the temperature step [-5,0)°C means that the lowest temperature of this data collection is -5°C and the highest does not exceed 0°C. The specific parameter settings of the experiment are shown in Table 1.

[0047] Table 1

[0048] The ambient temperature change step refers to the size of the temperature interval divided by the ambient temperature during each data collection.

[0049] On the real vehicle platform, the ambient temperature changes according to the natural outdoor temperature. The data collection of the real vehicle's hot start state is carried out after driving the real vehicle for half an hour before data collection. The data collection of the real vehicle's cold start state is that when the engine is ignited at the start of data collection, the engine has not been started within one hour. The ambient temperature of the real vehicle is measured by placing a thermometer in front of the vehicle outside the car and one at the back of the car. Due to the need to wait for the natural temperature change in the data collection of the real vehicle platform, the natural ambient temperature change range is [-5, 20) °C during the experimental stage. The temperatures of the real vehicle cold start data set and the real vehicle hot start data set are in the range of [-5, 20) °C, with a temperature step of 5 °C. Each temperature step data set contains the voltage signals of 8 ECUs in the vehicle, and the voltage signal of each ECU is at least 700 frames. Finally, a real vehicle cold start data set containing 113,187 CAN messages and a real vehicle hot start data set containing 116,777 CAN message segments are formed.

[0050] In the prototype system, temperature measurement is carried out by placing a mercury thermometer and an electronic thermometer on the same plane as the prototype system. The temperature of the prototype system data set is in the range of [-10, 40) °C, with a temperature step of 5 °C. Each temperature step data set contains 7 ECU voltage data, and the voltage signal of each ECU has at least 2,000 frames. Since the CAN bus message sending of the prototype system can be controlled by a program, the number of messages of each ECU varies less.

[0051] Experimental results To verify the influence of temperature on the voltage fingerprint model and compare the effects of this solution, the experiments select the representative works Scission and EASI that establish voltage fingerprints based on voltage characteristics for comparative experiments. This experiment extracts the features that are robust to temperature changes selected in this application, the feature set of the comparative work Scission, and the feature set of the comparative work EASI from the voltage signal data of the training stage temperature, and trains classification models as the voltage fingerprint model of this solution, the Scission model, and the EASI model respectively. During the process of training the classification model, through parameter search, a model with the highest accuracy when using the current data set as the test set is established to measure the influence of temperature change on its accuracy. For example: at a temperature of [0, 5) °C, during the process of training the model, the voltage signal data set at a temperature of [0, 5) °C is used as the test data set for parameter tuning to make its accuracy reach the highest.

[0052] Table 2

[0053] Table 3

[0054] The experimental results under the cold start state of the actual vehicle are shown in Table 2. The experimental results under the hot start state of the actual vehicle are shown in Table 3. Analyzing from the experimental results of the cold start state and the hot start state of the actual vehicle platform, the conclusion can be drawn that under the cold start state and the hot start state of the actual vehicle platform, the present application can provide higher temperature adaptability and maintain relatively stable recognition ability in multiple temperature ranges. When the training stage temperature is 0 - 5 °C and 15 - 20 °C, the voltage fingerprint model of the present application maintains a high recognition accuracy in multiple temperature ranges. Especially in the [10, 15) °C and [15, 20) °C ranges, the accuracy of the models in different training stages is close to 100%. In contrast, the accuracy of the comparison schemes Scission and EASI models decreases in the higher temperature ranges (such as [10, 15) °C and [15, 20) °C). When the training stage temperature of the present application is 15 - 20 °C, there is also a small decrease in the [-5, 0) °C range. However, compared with the comparison schemes Scission and EASI, its accuracy is not lower than 90%, which is within an acceptable range. Temperature change has a greater impact on the recognition accuracy of the voltage fingerprint model without feature engineering. The comparison schemes Scission and EASI models maintain a high recognition accuracy after parameter tuning in the training stage at the same temperature as their training stage. However, with the change of temperature, their accuracy will decrease to varying degrees.

[0055] The experimental results of the prototype system platform The test results of the prototype system platform are shown in Table 4. On the prototype system platform of the present application, in the temperature range of [-10, 40) °C, compared with the Scission and EASI models, it has stronger robustness to temperature change and the ability to recognize the ECU. When the training stage temperature is [10, 15) °C and [15, 20) °C, the voltage fingerprint model of the present scheme maintains a high recognition accuracy in multiple temperature ranges, and the average value is above 90%. In contrast, the accuracy of the comparison schemes Scission and EASI models decreases with the change of temperature, and the decrease of the EASI model is the most significant.

[0056] Table 4

[0057] The time overhead of the system for detecting samples affects the time when an attack is recognized. Therefore, this experiment conducted a detailed evaluation of the time overhead of the intrusion detection system on the STM32 platform, and the results are shown in Table 5. The experiment recorded the time overhead of each stage by detecting the legality of 1000 samples. Among them, the feature extraction stage accounted for the main time cost of intrusion detection. The average time per sample was 276.43 μs, and the standard deviation was 22.83 μs, which was the main part of the system time overhead. The time cost of the classification stage was relatively low, with an average time of 10.21 μs per sample. This stage mainly involved calculating the probability of each sample belonging to the ECU. For the detection of legal signals, the average time cost was 2.33 μs, mainly including the matching operation of the message ID and the predicted ECU. In contrast, the detection of abnormal signals required additional time to trigger the buzzer alarm, with an average time of 2.46 μs.

[0058] Table 5

[0059] In summary, this application systematically sorted out 80 candidate voltage features, and used a heuristic algorithm and a multi-scenario optimization strategy (covering the temperature change scenarios of -5°C to 20°C for the real vehicle platform and -10°C to 40°C for the prototype system) to screen out a core voltage feature set with temperature robustness to overcome the voltage fingerprint offset caused by temperature changes. The present invention improves the robustness of the IDS to temperature changes in the temperature change scenario by weakening the influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS recognition. Experiments show that the voltage feature set selected by the feature selection framework proposed by the present invention maintains the ECU recognition accuracy within an acceptable range at different temperature gradients (with a 5°C interval), which is significantly better than other IDS schemes based on voltage fingerprints.

[0060] This application proposes to design a low-resource signal acquisition architecture based on the random interleaved sampling and direct memory access double-buffer mechanism to solve the contradiction between the hardware resource limitations of embedded ECU devices and the requirements for real-time continuous sampling performance. This application reduces the high-precision sampling requirements of the IDS for sampling devices through random interleaved sampling, and improves the sampling rate of the IDS based on the DMA double-buffer mechanism. This application designs a deployment architecture of the IDS on a resource-limited platform to replace the high-precision oscilloscope in the traditional scheme, reduce the deployment cost of the IDS, and improve its engineering feasibility. This application has implemented all processes of intrusion detection (including signal acquisition, data processing, detection, etc.) on resource-constrained embedded devices, and completed the end-to-end deployment of the IDS.

[0061] The present application also discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0062] The present application also discloses a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0063] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0064] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0065] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0066] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable devices provide means for realizing the functions in the process Figure 1One process or multiple processes and / or boxes Figure 1 Steps of the functions specified in one box or multiple boxes.

[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for CAN bus intrusion detection based on an embedded platform, characterized in that: include: Based on the ADC interface of the embedded platform, DMA double buffer technology is used to collect the voltage signal of the CAN bus; The voltage signal is converted into voltage value data, and a multi-dimensional characteristic vector of the voltage is determined according to the voltage value data; The multidimensional feature vector has temperature robustness; The multidimensional feature vector is input into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multidimensional feature vector. Intrusion detection judgment is performed according to the membership probability of the ECU to obtain the intrusion detection result.

2. The method for CAN bus intrusion detection based on an embedded platform according to claim 1 is characterized in that: The voltage signal of the CAN bus is a differential signal at -5°C to 40°C.

3. The method for CAN bus intrusion detection based on an embedded platform according to claim 1 is characterized in that: The voltage signal is converted into voltage value data, and a multi-dimensional feature vector is determined according to the voltage value data, specifically including: S201: converting the voltage signal into voltage value data through an ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and obtain the ID corresponding to the dominant bit according to the dominant bit decoding; S204: After the ID, the dominant bit is identified according to the voltage value data, and the dominant bit is divided into the rising edge, the falling edge, and the dominant platform in sequence by random interleaved sampling to obtain dominant bit units, and the dominant bit units are spliced ​​in the order of the first position of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: Based on the heuristic algorithm and the preset temperature change robustness evaluation index, multi-dimensional feature vectors of the rising edge vector, the explicit platform vector and the falling edge vector that are robust to temperature changes are extracted respectively.

4. The method for CAN bus intrusion detection based on an embedded platform according to claim 1 is characterized in that: The preset voltage fingerprint model is obtained by the following steps: Based on the ADC interface of the embedded platform, DMA double buffer technology is used to collect the voltage signal of the CAN bus; The voltage signal is converted into voltage value data, and a multi-dimensional characteristic vector of the voltage is determined according to the voltage value data; The multidimensional feature vector has temperature robustness; According to the multi-dimensional feature vector, based on the heuristic algorithm, the voltage signal is screened on no less than two platforms to extract a voltage feature set with temperature robustness; A multi-classification model is trained based on the voltage feature set to obtain a voltage fingerprint model.

5. The method for CAN bus intrusion detection based on an embedded platform according to claim 1 is characterized in that: It also includes, after determining the intrusion detection result, issuing an early warning and locating the attack source according to the intrusion detection result.

6. A CAN bus intrusion detection system based on an embedded platform, characterized in that: include: A voltage sampling module is used to obtain a voltage signal; wherein the voltage signal is acquired from the CAN bus using a DMA double buffering technology based on an ADC interface of an embedded platform; A data preprocessing module, used to obtain voltage value data by converting the voltage signal, and determine a multidimensional characteristic vector of the voltage according to the voltage value data; the multidimensional characteristic vector has temperature robustness; The intrusion detection module is used to input the multidimensional feature vector into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multidimensional feature vector, performs intrusion detection judgment based on the membership probability of the ECU, and obtains the intrusion detection result.

7. The system for CAN bus intrusion detection based on an embedded platform according to claim 6 is characterized in that: It also includes an early warning module, which is used to issue early warnings and locate the attack source based on the intrusion detection results.

8. The CAN bus intrusion detection system based on an embedded platform according to claim 6 is characterized in that: In the data preprocessing module, the voltage signal is converted into voltage value data through voltage conversion, and a multi-dimensional feature vector is determined according to the voltage value data, which specifically includes: S201: converting the voltage signal into voltage value data through an ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and obtain the ID corresponding to the dominant bit according to the dominant bit decoding; S204: After the ID, the dominant bit is identified according to the voltage value data, and the dominant bit is divided into rising edge, falling edge, and dominant platform by random interleaved sampling, and spliced ​​in the order of the first rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: extracting a multi-dimensional feature vector that is robust to temperature changes from a rising edge vector, an explicit platform vector, and a falling edge vector based on a heuristic algorithm and a preset temperature change robustness evaluation index.

9. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method for CAN bus intrusion detection based on an embedded platform as described in any one of claims 1 to 5 when executing the computer program.

10. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the steps of the method for CAN bus intrusion detection based on an embedded platform according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Device for safely isolating and exchanging industrial control networks

    CN104486336A

  • Vehicle intrusion detection method for establishing fingerprint for each identifier and related device

    CN115801396A

  • CAN bus intrusion detection method and system based on deep belief network

    CN116545700A

  • Method and apparatus for detecting attack in can bus

    US20220407874A1

  • Data processing method and apparatus, and storage medium and program product

    WO2024178581A1

Cited By

  • CAN bus intrusion detection method and system suitable for wide temperature range

    CN121441647A

  • A can bus intrusion detection method and system suitable for a wide temperature range

    CN121441647B