An Intrusion Detection Method and System for CAN Bus Based on Embedded Platform

By using ADC interface and DMA dual cache technology on the embedded platform to collect CAN bus voltage signals, determine multi-dimensional feature vectors and perform intrusion detection, the problems of voltage fingerprint drift caused by temperature changes and limited hardware resources are solved, and efficient and robust intrusion detection is achieved.

CN120165985BActive Publication Date: 2025-07-22NORTHWESTERN POLYTECHNICAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510638933.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-19
Publication Date
2025-07-22
Estimated Expiration
2045-05-19

AI Technical Summary

Technical Problem

The existing CAN bus intrusion detection system based on voltage fingerprints has problems such as temperature sensitivity on embedded platforms, resulting in voltage fingerprint drift and hardware resource limitation, making it difficult to achieve real-time deployment.

Method used

The ADC interface and DMA double buffering technology based on the embedded platform are used to collect the CAN bus voltage signal, determine the multi-dimensional feature vector through voltage conversion, and intrusion detection is performed using the voltage fingerprint model. Combined with random interleaved sampling and DMA buffering mechanism, it reduces CPU utilization and improves temperature robustness.

Benefits of technology

In the temperature change scenario, the robustness of the intrusion detection system is improved, the contradiction between hardware resource limitation and real-time sampling performance requirements is solved, and efficient intrusion detection of the embedded platform is realized.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165985B_ABST
    Figure CN120165985B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of industrial control network communication security protection, and relates to a method and system for CAN bus intrusion detection based on an embedded platform. By using the ADC interface of the embedded platform and adopting the DMA double-buffer technology to collect the voltage signal of the CAN bus, the voltage signal is converted into voltage value data through voltage conversion, and a multi-dimensional feature vector with temperature robustness is determined according to the voltage value data; the voltage fingerprint offset caused by temperature change is overcome; the multi-dimensional feature vector is input into a preset voltage fingerprint model to predict the membership probability of the ECU corresponding to the multi-dimensional feature vector, and intrusion detection judgment is carried out according to the membership probability of the ECU to obtain an intrusion detection result. Through the DMA buffer mechanism, the sampled data is directly transferred from the data register of the ADC to the memory buffer, greatly reducing the CPU utilization and solving the contradiction between the hardware resource limitation of the embedded ECU device and the performance requirement of real-time continuous sampling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control network communication security protection, and particularly relates to a method and system for CAN bus intrusion detection based on an embedded platform. Background Art

[0002] The Controller Area Network (CAN) bus has become the core communication protocol in the industrial control field, especially for industrial automation equipment and distributed control systems, due to its high real-time performance and strong anti-interference ability. In recent years, with the in-depth application of industrial Internet of Things and intelligent manufacturing technologies, the industrial CAN bus has integrated multiple heterogeneous communication interfaces through programmable logic controllers and intelligent sensor nodes to achieve device collaboration and remote monitoring functions. While these extended capabilities improve production efficiency, they also significantly expand the attack surface of the system - the proliferation of open protocol conversion interfaces and third-party device access provides a penetration path for cross-network attacks. More seriously, the inherent plaintext data transmission mechanism and stateless broadcast communication characteristics of the CAN bus pose risks such as replay attacks and instruction hijacking in industrial control scenarios, which may lead to production process interruption or physical damage to critical equipment. Therefore, designing an active intrusion detection and protection mechanism for the industrial CAN bus is of urgent significance for ensuring the safe and stable operation of industrial control networks.

[0003] To address the increasingly severe security threats of the CAN bus, the academic community has proposed various protection mechanisms. The IDS (Intrusion Detection System) based on side-channel - hardware fingerprint recognition has the advantage of attack traceability. Among them, the IDS based on voltage fingerprint has received extensive attention from researchers due to the physical unclonability of voltage fingerprints and the anti-message frequency interference characteristics.

[0004] Mainstream voltage fingerprint-based IDS, such as the paper [1] (Choi W, Joo K, Jo HJ, et al. Voltage IDS: Low-level communication characteristics for automotive intrusion detection system [J]. IEEE Transactions on Information Forensics and Security, 2018, 13 (8): 2114-2129.), the paper [2] (Kneib M, Huth C. Scission: Signal characteristic-based sender identification and intrusion detection in automotive networks [C]. Proceedings of the 2018 ACM SIGSAC conference on computer and communications security. 2018: 787-800.) and patent US11683323B2, are based on the collected voltage signals to perform voltage feature extraction and classification model training, intrusion detection algorithm identification and other steps. Although the existing voltage fingerprint-based IDS provides effective protection for CAN bus security, its practical deployment still faces two key bottlenecks. First, the voltage characteristics of the ECU in the CAN bus, that is, the voltage signal characteristics, are easily disturbed by ambient temperature fluctuations, resulting in a significant decrease in characteristic stability. Whether there is a set of temperature-robust voltage characteristics and establishing its screening and verification mechanism is still a core issue that needs to be solved. Second, existing solutions mostly rely on high-precision oscilloscopes (such as PicoScope) to achieve signal acquisition, while the computing resources and storage capacity of ECUs deployed on embedded platforms are limited, making it difficult to support real-time deployment of such devices. How to achieve efficient signal acquisition and multi-type attack detection based on embedded platform hardware is another major challenge that restricts the implementation of technology. Summary of the invention

[0005] The purpose of the present invention is to provide a CAN bus intrusion detection method and system based on an embedded platform, which solves the problems in the prior art of voltage fingerprint drift caused by sensitivity to temperature changes and the conflict between the reliance on high-precision oscilloscope sampling requirements and the embedded platform with limited hardware resources.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present application discloses a method for CAN bus intrusion detection based on an embedded platform, including:

[0008] Based on the ADC (Analog-to-Digital Converter) interface of the embedded platform, the voltage signal of the CAN bus is collected by using the DMA (Direct Memory Access) double-buffer technology;

[0009] The voltage signal is converted through voltage conversion to obtain voltage value data, and a multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0010] The multi-dimensional feature vector is input into a preset voltage fingerprint model, and the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector. Intrusion detection is judged according to the membership probability of the ECU to obtain an intrusion detection result.

[0011] Preferably, the voltage signal of the CAN bus is a differential signal at -5°C to 40°C.

[0012] Preferably, converting the voltage signal through voltage conversion to obtain voltage value data, and determining the multi-dimensional feature vector according to the voltage value data specifically includes:

[0013] S201: Convert the voltage signal into voltage value data through the ADC conversion formula;

[0014] S202: Identify the SOF bit of the voltage value data;

[0015] S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and decode the ID corresponding to the dominant bit according to the dominant bit;

[0016] S204: After the ID, identify the dominant bit according to the voltage value data, and use the random interleaved sampling method to divide the dominant bit into dominant bit units in turn according to the rising edge, falling edge, and dominant platform, and splice the dominant bit units in the order of the first size of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector;

[0017] S205: Based on the heuristic algorithm and the preset evaluation index with temperature change robustness, extract the multi-dimensional feature vectors of the rising edge vector, the dominant platform vector, and the falling edge vector that are robust to temperature change respectively.

[0018] Preferably, the preset voltage fingerprint model is obtained through the following steps:

[0019] Based on the ADC interface of the embedded platform, the voltage signal of the CAN bus is collected by using the DMA double-buffer technology;

[0020] Convert the voltage signal into voltage value data through voltage conversion, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0021] According to the multi-dimensional feature vector, based on the heuristic algorithm, screen the voltage signal on at least two platforms, and extract the voltage feature set with temperature robustness;

[0022] Train a multi-classification model based on the voltage feature set to obtain a voltage fingerprint model.

[0023] Preferably, after determining the intrusion detection result, issue a warning and locate the attack source according to the intrusion detection result.

[0024] In a second aspect, the present application discloses a CAN bus intrusion detection system based on an embedded platform, including:

[0025] A voltage sampling module for acquiring a voltage signal; wherein, the voltage signal is acquired from the CAN bus based on the ADC interface of the embedded platform using the DMA double-buffer technology;

[0026] A data preprocessing module for converting the voltage signal into voltage value data through voltage conversion, and determining the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0027] An intrusion detection module for inputting the multi-dimensional feature vector into a preset voltage fingerprint model, the voltage fingerprint model predicting the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performing intrusion detection judgment according to the membership probability of the ECU to obtain an intrusion detection result.

[0028] Preferably, it further includes a warning module for issuing a warning and locating the attack source according to the intrusion detection result.

[0029] Preferably, in the data preprocessing module, converting the voltage signal into voltage value data through voltage conversion, and determining the multi-dimensional feature vector according to the voltage value data specifically includes:

[0030] S201: Convert the voltage signal into voltage value data through the ADC conversion formula;

[0031] S202: Identify the SOF bit of the voltage value data;

[0032] S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and decode the dominant bit to obtain the ID corresponding to the dominant bit;

[0033] S204: After the ID, identify the dominant bits according to the voltage value data, and use the random interleaved sampling method to segment the dominant bits according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector;

[0034] S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index that is robust to temperature changes, extract the multi-dimensional feature vector that is robust to temperature changes.

[0035] In a third aspect, the present application discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0036] In a fourth aspect, the present application discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0037] Compared with the prior art, the present invention has the following beneficial effects:

[0038] Based on the ADC interface of the embedded platform, the present application introduces a DMA buffer mechanism to collect the voltage signal of the CAN bus, so that the data transmission between the ADC and the memory does not require the participation of the CPU (Central Processing Unit). Through the interface with the ADC, DMA directly transfers the sampled data from the data register of the ADC to the memory buffer, which can greatly reduce the CPU utilization and solve the contradiction between the hardware resource limitation of the embedded ECU device and the performance requirement of real-time continuous sampling. By determining the multi-dimensional feature vector with temperature robustness from the voltage signal, the offset of the voltage fingerprint caused by temperature changes is overcome. The influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS recognition, is weakened, and the robustness of the IDS to temperature changes in a temperature change scenario is improved. Description of the Drawings

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0040] Figure 1It is a schematic flow chart of the method according to an embodiment of the present invention;

[0041] Figure 2 It is a system block diagram of an embodiment of the present invention;

[0042] Figure 3 It is a hardware design for the deployment of a CAN bus intrusion detection system based on an embedded platform according to an embodiment of the present invention;

[0043] Figure 4 It is a flow chart of feature extraction and selection in the CAN bus intrusion detection system of the comparative example of the present invention;

[0044] Figure 5 It is a flow chart of the feature selection framework in the CAN bus intrusion detection system of the comparative example of the present invention. Specific embodiments

[0045] The present invention will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other.

[0046] The following detailed descriptions are all exemplary descriptions, aiming to provide further detailed descriptions of the present invention. Unless otherwise specified, all technical terms adopted by the present invention have the same meaning as commonly understood by those of ordinary skill in the art to which the present application belongs. The terms used in the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the exemplary embodiments according to the present invention.

[0047] See Figure 1 , the present application discloses a method for CAN bus intrusion detection based on an embedded platform, including:

[0048] S1: Based on the ADC interface of the embedded platform, the voltage signal of the CAN bus is collected by using the DMA double-buffer technology; the present application introduces a DMA buffer mechanism based on the ADC interface of the embedded platform to collect the voltage signal of the CAN bus, so that the data transmission between the ADC and the memory does not require the participation of the CPU. The DMA directly transfers the sampled data from the data register of the ADC to the memory buffer through the interface with the ADC, which can greatly reduce the CPU utilization and solve the contradiction between the hardware resource limitation of the embedded ECU device and the real-time continuous sampling performance requirement.

[0049] S2: Convert the voltage signal into voltage value data through voltage conversion, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; by determining the multi-dimensional feature vector with temperature robustness from the voltage signal, the voltage fingerprint offset caused by temperature changes is overcome. The influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS identification, is weakened, and the robustness of the IDS to temperature changes in a temperature change scenario is improved.

[0050] S3: Input the multi-dimensional feature vector into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performs intrusion detection judgment according to the membership probability of the ECU to obtain the intrusion detection result.

[0051] In the traditional ADC sampling method, the CPU needs to continuously poll the status of the ADC to read the conversion result. In this system, the system needs to monitor the ADC status at all times. Therefore, the traditional ADC sampling method not only increases the burden on the CPU, but also reduces the real-time performance of the system due to polling delay. To solve this problem, this application introduces a DMA buffer mechanism, enabling data transfer between the ADC and memory without the participation of the CPU. Since the data sending frequency of the CAN bus is usually high, and the sampling rate of the ADC may not be able to match it, resulting in the inability to accurately restore all the information of the CAN frame. The ADC and DMA are connected through hardware logic and do not rely on the CPU to transfer data. Therefore, DMA directly transfers the sampled data from the data register of the ADC to the memory buffer through the interface with the ADC, which can significantly reduce CPU utilization. Random interleaved sampling restores the CAN bus signal collected at a high sampling rate by splicing multiple dominant bits, thereby reducing the requirement for the platform sampling rate and solving the conflict with the platform hardware. Since voltage acquisition is linear in time sequence, sorting and splicing the messages according to the size of the first bit in each message can restore its original signal characteristics. This method can maximize the retention of the characteristics of the CAN signal even at a low sampling rate, avoiding information loss in periodic sampling.

[0052] In some embodiments, the voltage signal of the CAN bus is a differential signal at -5°C to 40°C. The prior art can only meet the temperature range of 0°C to 15°C. The voltage signal adopted in this application expands the available temperature range and improves the adaptability of the application system to temperature changes.

[0053] In some embodiments, converting the voltage signal into voltage value data through voltage conversion and determining the multi-dimensional feature vector according to the voltage value data specifically includes:

[0054] S201: Convert the voltage signal into voltage value data through the ADC conversion formula;

[0055] S202: Identify the SOF bit of the voltage value data;

[0056] S203: Based on the CAN bus data pattern, identify the dominant bits of the voltage value data according to the SOF bit, decode the ID corresponding to the dominant bit based on the dominant bit, and based on the known mapping relationship between the ECU and the ID, determine the ECU corresponding to each ID;

[0057] S204: After the ID, identify the dominant bits according to the voltage value data, use the random interleaved sampling method to divide the dominant bits according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector;

[0058] S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index that is robust to temperature changes, extract the multi-dimensional feature vector that is robust to temperature changes.

[0059] Further preferably, the S205 specifically includes:

[0060] S2051: According to the calculation formula of the voltage characteristics, calculate the rising edge vector, the dominant platform vector, and the falling edge vector in units of voltage value data to obtain the voltage characteristics;

[0061] S2052: For the voltage characteristics, screen out the single voltage characteristics that meet the conditions through the index; determine the selection range of the voltage characteristics according to the single voltage characteristics;

[0062] S2053: Based on the selection range of the voltage characteristics, perform basic feature combination on the single voltage characteristics to obtain a basic voltage feature combination; the basic voltage feature combination refers to the common feature set of the existing voltage-based intrusion detection system;

[0063] S2054: For the basic voltage feature combination, based on the heuristic algorithm, with the preset robustness to temperature changes as the evaluation index, screen the basic voltage feature combination to obtain the first optimal voltage feature set, and based on the rising edge vector, the dominant platform vector, and the falling edge vector, extract the corresponding second optimal voltage feature set. The first optimal voltage feature set and the second optimal voltage feature set constitute the multi-dimensional feature vector.

[0064] The described heuristic algorithm is proposed relative to the optimization algorithm. Its definition is: an algorithm constructed based on intuition or experience that gives a feasible solution for each instance of the combinatorial optimization problem to be solved at an acceptable cost (referring to computational time and space), and the degree of deviation of this feasible solution from the optimal solution generally cannot be predicted. The heuristic algorithm in this application is based on the existing genetic algorithm, sets its evaluation index as the robustness to temperature changes, and optimizes and screens out multi-dimensional feature vectors that are robust to temperature changes.

[0065] In some embodiments, the multi-dimensional feature vector is input into a preset voltage fingerprint model, and the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector. An intrusion detection determination is made based on the membership probability of the ECU to obtain an intrusion detection result. Among them, in data preprocessing, the corresponding ECU is determined based on the known mapping relationship between the ECU and the ID; then:

[0066] S301: The multi-dimensional feature vector is input into the preset voltage fingerprint model, and the membership probability that the current multi-dimensional feature vector belongs to the corresponding ECU is calculated;

[0067] S302: Combining the membership probabilities of other IDs with the calculated ECU membership probability, it is determined whether an attack has occurred through a preset intrusion detection algorithm, and the ECU of the attack source is located.

[0068] Specifically, the preset intrusion detection algorithm identifies the multi-dimensional feature vector of the current message based on the voltage fingerprint model and predicts the membership probability P of this message belonging to each known ECU ECU . If the membership probability P of the current message corresponding to the ECU ECU is higher than the trust threshold T min =0.8, that is, it indicates that the source ECU of this message is consistent with its message content, then this message is considered legal, and the suspicion degree of the model for the messages of this ECU is further reduced by reducing the value of the suspicious message counter. When P ECU is lower than the trust threshold T min , it indicates that the source ECU of the current message is inconsistent with its message content, then the current message is considered possibly abnormal, and the system enters the next judgment. In the case where the credibility of the message is questioned, the system will further compare the membership probability values of other IDs. If the membership probability P of other IDs other is higher than the warning threshold T doubt =0.6, it indicates that the source of this message is identified as other ECUs, and at this time the system determines an internal attack and marks the current message as illegal.

[0069] Further preferably, the preset intrusion detection algorithm is an intrusion detection algorithm designed for possible attacks (for example: Scission, EASI).

[0070] In some embodiments, it further includes, after determining the intrusion detection result, issuing a warning according to the intrusion detection result and locating the attack source. If the intrusion detection result is an encounter with an attack, the embedded platform controls the buzzer to emit a sound to give a warning.

[0071] If the intrusion detection result determines the attack source and type, the embedded platform controls the display screen to output the attack source and the attack result.

[0072] In some embodiments, the preset voltage fingerprint model is obtained through the following steps:

[0073] Based on the ADC interface of the embedded platform, the DMA double-buffer technology is used to collect the voltage signals of the CAN bus;

[0074] The voltage signals are converted into voltage value data through voltage conversion, and the multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0075] According to the multi-dimensional feature vector, based on the heuristic algorithm, the voltage signals are screened on no less than two platforms to extract the voltage feature set with temperature robustness;

[0076] Based on the voltage feature set, a multi-classification model is trained to obtain the voltage fingerprint model.

[0077] In some embodiments, in the host computer, the voltage signals obtained by screening no less than two platforms according to the multi-dimensional feature vector are used to extract the voltage feature set with temperature robustness as the input features, and the ECU corresponding to the input features is used as the label; wherein, the input features and the corresponding labels constitute a mapping data set; for this mapping data set, a machine learning multi-classification algorithm is used to train the voltage fingerprint model. During the training process, this method uses the minimum cross-entropy as the loss function and adopts k-fold cross-validation to optimize the parameters of the voltage fingerprint model. The parameters of the trained voltage fingerprint model are exported to the embedded platform in the form of text or static variables, and on the embedded platform, by reading the parameters, the deployed voltage fingerprint model is loaded.

[0078] Further preferably, the preset evaluation index for temperature change robustness is a numerical evaluation index for customizing the voltage signals that are robust to temperature change.

[0079] This application also discloses a CAN bus intrusion detection system based on an embedded platform, including:

[0080] A voltage sampling module for obtaining voltage signals; wherein, the voltage signals are collected from the CAN bus based on the ADC interface of the embedded platform by using the DMA double-buffer technology;

[0081] A data preprocessing module, which is used to convert a voltage signal into voltage value data through voltage conversion, and determine a multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0082] An intrusion detection module, which is used to input the multi-dimensional feature vector into a preset voltage fingerprint model. The voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and performs intrusion detection and judgment according to the membership probability of the ECU to obtain an intrusion detection result.

[0083] In some embodiments, see Figure 2 , and further includes an early warning module, which is used to issue an early warning according to the intrusion detection result and locate the attack source.

[0084] In some embodiments, in the data preprocessing module, converting the voltage signal into voltage value data through voltage conversion and determining the multi-dimensional feature vector according to the voltage value data specifically includes:

[0085] S201: Convert the voltage signal into voltage value data through the ADC conversion formula;

[0086] S202: Identify the SOF bit of the voltage value data;

[0087] S203: Based on the CAN bus data rule according to the SOF bit, identify the dominant bit of the voltage value data, decode the ID according to the dominant bit, and judge the corresponding ECU according to the ID in combination with the known mapping relationship between the ECU and the ID;

[0088] S204: After the ID, identify the dominant bit according to the voltage value data, and use the random interleaved sampling method to divide the dominant bit into rising edges, falling edges, and dominant platforms, and splice them in the order of the first size of the rising edges to form a rising edge vector, a dominant platform vector, and a falling edge vector;

[0089] S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, extract a multi-dimensional feature vector that is robust to temperature changes based on a heuristic algorithm and a preset evaluation index for temperature change robustness.

[0090] Embodiment: This embodiment provides a CAN bus intrusion detection method based on STM32 for internal attacks.

[0091] Hardware configuration:

[0092] Main control chip: STM32H743ZIT6 (built-in 3 12-bit ADCs, supporting an input range of 0 - 3.3V);

[0093] ADC sampling configuration: Sampling rate: 5 MS / s (ADC clock configured to 30MHz, 12-bit resolution);

[0094] DMA Channel: DMA2 Stream0, Ring buffer size 2048 samples;

[0095] The method comprises the following steps:

[0096] S1: Based on the ADC interface of the embedded platform, the voltage signal of the CAN bus is collected by using the DMA double-buffer technology; within the ambient temperature range of [-5, 20) °C, 6 temperature gradients (-5 °C, 0 °C, 5 °C, 10 °C, 15 °C, 20 °C) are set at intervals of 5 °C. At each temperature point, 8 ECUs × 700 frames = 5600 frames (113200 frames are actually collected)

[0097] S2: The voltage signal is converted to voltage value data through voltage conversion, and the multi-dimensional feature vector of the voltage is determined according to the voltage value data; the multi-dimensional feature vector has temperature robustness;

[0098] S201: The voltage signal is converted to voltage value data through the ADC conversion formula; the reference voltage is 3.3V;

[0099] S202: Identify the SOF bit of the voltage value data; determine the threshold values, the dominant bit threshold is: differential voltage > 1.5V (duration ≥ 4 sampling points), and the recessive bit threshold is: differential voltage < 0.5V. Judge the CAN bus data according to the threshold values.

[0100] S203: Based on the CAN bus data rule, compile the data with 11 bits per bit, identify the dominant bit of the voltage value data according to the SOF bit, decode the dominant bit to obtain the ID corresponding to the dominant bit, and judge the corresponding ECU based on the mapping relationship between the known ECU and ID according to the ID;

[0101] S204: After the ID, identify the dominant bit according to the voltage value data, and use the random interleaved sampling method (random interleaved sampling uses 5-fold oversampling) to divide the dominant bit according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first digit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector;

[0102] S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index of temperature change robustness, extract the multi-dimensional feature vector that is robust to temperature change.

[0103] S3: Input the multi-dimensional feature vector into the preset voltage fingerprint model, the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and perform intrusion detection judgment according to the membership probability of the ECU to obtain the intrusion detection result.

[0104] Proportion for comparison:

[0105] Select a car as the actual application scenario; to verify the effectiveness of the solution and eliminate the influence of environmental factors of the real vehicle, experiments are conducted on two platforms, the real vehicle and the prototype system, as shown in Figure 3 , Figure 4 and Figure 5 .

[0106] Real vehicle platform: The experiment uses a Buick Regal as the real vehicle platform. The ECUs on the real vehicle are provided by multiple manufacturers, so it is more in line with the heterogeneity characteristics of ECUs in real-world vehicles. However, the environmental temperature of the ECUs on the real vehicle system is more complex. The environmental temperature of the ECUs on the real vehicle is affected by the heat generated by the engine operation. Therefore, the real vehicle is divided into a cold start state and a hot start state in the experiment. Among them, the cold start state is defined as the engine starting in a low-temperature state, which refers to the start state after the engine has been shut down for some time. The hot start state refers to the process of the engine being shut down and then restarted after running for some time.

[0107] Prototype system: Considering that the ECUs in real vehicles usually come from different manufacturers, the prototype system uses ECUs from different manufacturers as much as possible to simulate the actual application environment. The prototype system consists of 7 ECUs. The design purpose of the system architecture is to maximize the simulation of hardware platforms from different manufacturers to improve the wide applicability of the experimental results. The specific components include: 3 STM32F103 development boards equipped with CAN modules, 2 Arduino Nanos, each Arduino Nano is connected to an MCP2515 CAN controller and a TJA1050 CAN transceiver, 1 USBCAN-II Pro device that can be used as a CAN bus communication device, and 1 CANalyst-II device that can be used as a CAN bus communication device. In order to restore the CAN bus channel, one of the STM32F103 development boards and one USBCAN-II Pro device in the prototype system carry resistors respectively to ensure the normal voltage of the CAN bus. The prototype system includes two CAN High and CAN Low lines with a rate of 500 kbit / s.

[0108] Experimental parameters

[0109] To verify the temperature changes in the verification and feature selection phases, it is necessary to collect voltage data at different temperatures on each platform. During the experiment, in order to ensure the accuracy of the environmental temperature, two thermometers, a mercury thermometer and an electronic thermometer, are used as the reference for temperature data. Since the environmental temperature will fluctuate slightly in a short period of time, each data set is collected and divided with a temperature change step of 5°C. That is, the temperature difference of each data collection does not exceed 5°C, and the temperature step interval is left-closed and right-open. For example, the temperature step [-5,0)°C means that the lowest temperature of this data collection is -5°C and the highest does not exceed 0°C. The specific parameter settings of the experiment are shown in Table 1.

[0110] Table 1

[0111]

[0112] The environmental temperature change step refers to the size of the temperature range divided by the environmental temperature during each data collection.

[0113] On the real vehicle platform, the environmental temperature changes according to the change of the natural outdoor temperature. The data collection of the hot start state of the real vehicle is carried out after driving the real vehicle for half an hour. The data collection of the cold start state of the real vehicle is that the engine has not been started within one hour when the engine is ignited at the beginning of data collection. The environmental temperature of the real vehicle is measured by placing a thermometer in front of the vehicle hood and at the rear of the vehicle respectively. Since the data collection of the real vehicle platform needs to wait for the change of the natural temperature, the range of the natural environmental temperature change is [-5, 20) °C during the experimental stage. The temperatures of the real vehicle cold start data set and the real vehicle hot start data set are in the range of [-5, 20) °C, with a temperature step of 5 °C. Each temperature step data set contains the voltage signals of 8 ECUs in the vehicle, and the voltage signal of each ECU is at least 700 frames. Finally, a real vehicle cold start data set containing 113187 CAN messages and a real vehicle hot start data set containing 116777 CAN message segments are formed.

[0114] In the prototype system, the temperature is measured by placing a mercury thermometer and an electronic thermometer on the same plane as the prototype system. The temperature of the prototype system data set is in the range of [-10, 40) °C, with a temperature step of 5 °C. Each temperature step data set contains 7 ECU voltage data, and the voltage signal of each ECU has at least 2000 frames. Since the CAN bus message sending of the prototype system can be controlled by a program, the difference in the number of messages of each ECU is relatively small.

[0115] Experimental Results

[0116] In order to verify the influence of temperature on the voltage fingerprint model and compare the effect of this scheme, the experiments select the representative works Scission and EASI based on voltage characteristics to establish voltage fingerprints for comparative experiments. In this experiment, the features robust to temperature changes selected in this application, the feature set of the comparative work Scission, and the feature set of the comparative work EASI are extracted from the voltage signal data of the training stage temperature, and the classification models are trained respectively as the voltage fingerprint model of this scheme, the Scission model, and the EASI model. During the process of training the classification model, through parameter search, a model with the highest accuracy when using the current data set as the test set is established to measure the influence of temperature change on its accuracy. For example: at a temperature of [0, 5) °C, during the process of training the model, the voltage signal data set at a temperature of [0, 5) °C is used as the test data set for parameter tuning to make its accuracy reach the highest.

[0117] Table 2

[0118]

[0119] Table 3

[0120]

[0121] The experimental results under the cold start state of the actual vehicle are shown in Table 2. The experimental results under the hot start state of the actual vehicle are shown in Table 3. From the analysis of the experimental results of the cold start state and the hot start state of the actual vehicle platform, the conclusion can be drawn that under the cold start state and the hot start state of the actual vehicle platform, the present application can provide higher temperature adaptability and maintain relatively stable recognition ability in multiple temperature ranges. When the training stage temperature is 0 - 5°C and 15 - 20°C, the voltage fingerprint model of the present application maintains a high recognition accuracy in multiple temperature ranges. Especially in the [10, 15)°C and [15, 20)°C ranges, the accuracy of the models in different training stages is close to 100%. In contrast, the accuracy of the comparison schemes Scission and EASI models decreases in the higher temperature ranges (such as [10, 15)°C and [15, 20)°C). When the training stage temperature of the present application is 15 - 20°C, there is also a small decrease in the [-5, 0)°C range. However, compared with the comparison schemes Scission and EASI, its accuracy is not lower than 90%, which is within an acceptable range. Temperature change has a greater impact on the recognition accuracy of the voltage fingerprint model without feature engineering. The comparison schemes Scission and EASI models maintain a high recognition accuracy after parameter tuning in the training stage at the same temperature as their training stage. However, as the temperature changes, their accuracy will decrease to varying degrees.

[0122] The experimental results of the prototype system platform The test results of the prototype system platform are shown in Table 4. On the prototype system platform of the present application, in the temperature range of [-10, 40)°C, compared with the Scission and EASI models, it has stronger robustness to temperature change and the ability to identify the ECU. When the training stage temperature is [10, 15)°C and [15, 20)°C, the voltage fingerprint model of the present scheme maintains a high recognition accuracy in multiple temperature ranges, and the average value is above 90%. In contrast, the accuracy of the comparison schemes Scission and EASI models decreases with the temperature change, and the decrease of the EASI model is the most significant.

[0123] Table 4

[0124]

[0125] The time overhead of the system for detecting samples affects the time when an attack is recognized. Therefore, this experiment conducted a detailed evaluation of the time overhead of the intrusion detection system on the STM32 platform, and the results are shown in Table 5. The experiment recorded the time overhead of each stage by detecting the legality of 1000 samples. Among them, the feature extraction stage accounted for the main time cost of intrusion detection. The average time per sample was 276.43 μs, and the standard deviation was 22.83 μs, which was the main part of the system time overhead. The time cost of the classification stage was relatively low, with an average time of 10.21 μs per sample. This stage mainly involved calculating the probability of each sample belonging to the ECU. For the detection of legal signals, the average time cost was 2.33 μs, mainly including the matching operation of the message ID and the predicted ECU. In contrast, the detection of abnormal signals required additional time to trigger the buzzer alarm, with an average time of 2.46 μs.

[0126] Table 5

[0127]

[0128] In summary, this application systematically sorted out 80 candidate voltage characteristics, and used a heuristic algorithm and a multi-scenario optimization strategy (covering the temperature change scenarios of -5°C to 20°C for the real vehicle platform and -10°C to 40°C for the prototype system) to screen out a core voltage characteristic set with temperature robustness to overcome the voltage fingerprint offset caused by temperature changes. The present invention improves the robustness of the IDS to temperature changes in the temperature change scenario by weakening the influence of temperature changes on the voltage fingerprint model, which is an important basis for IDS recognition. Experiments show that the voltage characteristic set selected by the feature selection framework proposed by the present invention maintains the ECU recognition accuracy within an acceptable range at different temperature gradients (5°C intervals), which is significantly better than other IDS schemes based on voltage fingerprints.

[0129] This application proposes to design a low-resource signal acquisition architecture based on the random interleaved sampling and direct memory access double-buffer mechanism to solve the contradiction between the hardware resource limitations of embedded ECU devices and the real-time continuous sampling performance requirements. This application reduces the high-precision sampling requirements of the IDS for sampling devices through random interleaved sampling, and improves the sampling rate of the IDS based on the DMA double-buffer mechanism. This application designs the deployment architecture of the IDS on the resource-limited platform to replace the high-precision oscilloscope in the traditional scheme, reduce the deployment cost of the IDS, and improve its engineering feasibility. This application realizes all processes of intrusion detection (including signal acquisition, data processing, detection, etc.) on resource-constrained embedded devices, and completes the end-to-end deployment of the IDS.

[0130] The present application also discloses an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0131] The present application also discloses a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the steps of the method for CAN bus intrusion detection based on an embedded platform described in any one of the above are implemented.

[0132] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0133] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0134] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the specified functions in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0135] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the specified functions in Figure 1One process or multiple processes and / or boxes Figure 1 Steps of the functions specified in one box or multiple boxes.

[0136] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present invention, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.

Claims

1. A method for CAN bus intrusion detection based on an embedded platform, characterized in that Including: An ADC interface based on an embedded platform, which uses DMA dual-buffer technology to collect the voltage signal of the CAN bus; Convert the voltage signal through voltage conversion to obtain voltage value data, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; The multi-dimensional feature vector has temperature robustness; specifically including: S201: Convert the voltage signal into voltage value data through the ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and decode the ID corresponding to the dominant bit according to the dominant bit; S204: After the ID, identify the dominant bit according to the voltage value data, and use the random interleaved sampling method to divide the dominant bit into dominant bit units in turn according to the rising edge, falling edge, and dominant platform, and splice the dominant bit units in the order of the first size of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: Based on the heuristic algorithm and the preset evaluation index of temperature change robustness, extract the multi-dimensional feature vectors of the rising edge vector, the dominant platform vector, and the falling edge vector that are robust to temperature change respectively; Input the multi-dimensional feature vector into the preset voltage fingerprint model, the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and perform intrusion detection judgment according to the membership probability of the ECU to obtain the intrusion detection result; The preset voltage fingerprint model is obtained through the following steps: An ADC interface based on an embedded platform, which uses DMA dual-buffer technology to collect the voltage signal of the CAN bus; Convert the voltage signal through voltage conversion to obtain voltage value data, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; According to the multi-dimensional feature vector, based on the heuristic algorithm, screen the voltage signals on no less than two platforms, and extract the voltage feature set with temperature robustness; Train a multi-classification model based on the voltage feature set to obtain a voltage fingerprint model.

2. The method for CAN bus intrusion detection based on an embedded platform according to claim 1, characterized in that, The voltage signal of the CAN bus is a differential signal at -5°C to 40°C.

3. A method for CAN bus intrusion detection based on an embedded platform according to claim 1, characterized in that, It also includes, after determining the intrusion detection result, issuing a warning and locating the attack source according to the intrusion detection result.

4. A CAN bus intrusion detection system based on an embedded platform, characterized in that, Including: A voltage sampling module for obtaining a voltage signal; wherein, the voltage signal is collected from the CAN bus based on the ADC interface of the embedded platform using DMA dual-buffer technology; A data preprocessing module for converting the voltage signal through voltage conversion to obtain voltage value data, and determining the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; specifically including: S201: Convert the voltage signal into voltage value data through the ADC conversion formula; S202: Identify the SOF bit of the voltage value data; S203: Based on the CAN bus data rule, identify the dominant bit of the voltage value data according to the SOF bit, and decode the ID corresponding to the dominant bit according to the dominant bit; S204: After the ID, identify the dominant bits according to the voltage value data, and use the random interleaved sampling method to segment the dominant bits according to the rising edge, falling edge, and dominant platform, and splice them in the order of the first bit of the rising edge to form a rising edge vector, a dominant platform vector, and a falling edge vector; S205: For the rising edge vector, the dominant platform vector, and the falling edge vector, based on the heuristic algorithm and the preset evaluation index that is robust to temperature changes, extract the multi-dimensional feature vector that is robust to temperature changes; An intrusion detection module, configured to input the multi-dimensional feature vector into a preset voltage fingerprint model, the voltage fingerprint model predicts the membership probability of the ECU corresponding to the multi-dimensional feature vector, and perform intrusion detection and judgment according to the membership probability of the ECU to obtain an intrusion detection result; The preset voltage fingerprint model is obtained through the following steps: Based on the ADC interface of the embedded platform, use the DMA double-buffer technology to collect the voltage signal of the CAN bus; Convert the voltage signal to obtain voltage value data, and determine the multi-dimensional feature vector of the voltage according to the voltage value data; the multi-dimensional feature vector has temperature robustness; According to the multi-dimensional feature vector, based on the heuristic algorithm, screen the voltage signal on no less than two platforms, and extract the voltage feature set with temperature robustness; Train a multi-classification model based on the voltage feature set to obtain a voltage fingerprint model.

5. The system for CAN bus intrusion detection based on an embedded platform according to claim 4, characterized in that, It further includes a warning module, configured to issue a warning according to the intrusion detection result and locate the attack source.

6. An electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, the steps of the method for CAN bus intrusion detection based on an embedded platform according to any one of claims 1-3 are implemented.

7. A computer-readable storage medium, where the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for CAN bus intrusion detection based on an embedded platform according to any one of claims 1-3 are implemented.

Citation Information

Patent Citations

  • Device for safely isolating and exchanging industrial control networks

    CN104486336A

  • Vehicle intrusion detection method for establishing fingerprint for each identifier and related device

    CN115801396A