CAN bus intrusion detection method and system based on temperature sensor equipment

By employing temperature-sensitive voltage fingerprint models and anomaly detection, the method addresses temperature-induced voltage drift issues, ensuring robust CAN bus intrusion detection across diverse temperature ranges.

CN120321031AActive Publication Date: 2025-07-15NORTHWESTERN POLYTECHNICAL UNIV
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510770706.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-15
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In the dynamic temperature scenarios of the prior art, the supply voltage characteristics of the ECU node will cause nonlinear drift with the change of ambient temperature, resulting in a deviation between the voltage fingerprint model and the real-time signal matching, affecting the accuracy and generalization ability of CAN bus intrusion detection.

Method used

The CAN bus intrusion detection method based on temperature sensor equipment is adopted, and the CAN bus voltage and temperature data are collected in real time, and the voltage fingerprint model corresponding to the temperature interval in the voltage fingerprint model cluster is dynamically loaded, and the support vector machine (SVM) is used for training, and the model hyperparameters are optimized by minimizing cross entropy, and anomaly warning is performed in combination with the question counter and trusted threshold.

Benefits of technology

Maintaining high detection performance under different temperature environments improves the accuracy and adaptability of intrusion detection, reduces storage space usage, realizes rapid model search and call, and promptly identify internal or external attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321031A_ABST
    Figure CN120321031A_ABST
Patent Text Reader

Abstract

The invention discloses a CAN bus intrusion detection method and system based on temperature sensor equipment, and belongs to the technical field of industrial control network communication safety protection, and the method comprises the steps: firstly, collecting the voltage data and temperature data of a CAN bus in real time, and carrying out the preprocessing of the voltage data, so as to extract voltage features and corresponding ECU nodes; then, dynamically loading a pre-trained voltage fingerprint model of a corresponding temperature interval according to the real-time temperature data, and inputting the voltage characteristics into the model to obtain the membership probability of each ECU node; and finally, performing abnormal early warning based on the membership probabilities. The training process of the voltage fingerprint model comprises temperature interval division, training data set selection and SVM model training, so that a plurality of voltage fingerprint models for different temperature intervals are obtained. According to the method, efficient and accurate CAN bus intrusion detection is realized by comprehensively using temperature and voltage data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of industrial control network communication security protection, and relates to a CAN bus intrusion detection method and system based on temperature sensor devices. Background Art

[0002] With the rapid development of technology, industrial control networks are gradually evolving towards intelligence and interconnection. In this process, the Controller Area Network (CAN) protocol, as the core communication bus for industrial automation devices, plays a crucial role. With its excellent real-time performance and anti-interference ability, the CAN bus continues to undertake the transmission tasks of key control instructions and sensor data in industrial fields such as intelligent manufacturing, process control, and robot collaboration.

[0003] However, with the rise of the industrial Internet of Things and the cloud-edge collaborative architecture, the network security boundary of traditional industrial CAN buses is facing unprecedented challenges. On the one hand, the remote monitoring interfaces, wireless communication modules, and third-party device access points integrated by industrial gateways expose the originally closed CAN bus system to a more complex cross-protocol attack chain. Attackers can use these access points to penetrate and damage the CAN bus, seriously threatening the security and stability of industrial control systems.

[0004] On the other hand, the CAN bus protocol itself also has some inherent security flaws. For example, the lack of message integrity verification mechanisms and node identity binding functions makes the broadcast communication architecture vulnerable to different types of security threats such as replay attacks and instruction injection. Once these threats succeed, they may cause the production system to stop or physical damage to the equipment, bringing significant economic losses and reputation damage to enterprises.

[0005] In response to the above security challenges, both academia and industry are actively seeking effective solutions. Among them, intrusion detection technology based on physical layer feature analysis has gradually become a research hotspot. This technology realizes the precise positioning ability of the attack source by extracting the inherent physical features of ECU (Electronic Control Unit) nodes, providing a new idea for the security protection of the CAN bus.

[0006] In the technology based on physical layer feature analysis, the voltage domain fingerprint recognition technology has attracted much attention due to its unique advantages. First, the physical unclonability of signal voltage characteristics makes it difficult for attackers to forge or copy the characteristics of real ECU nodes, thus effectively countering security threats such as message replay attacks. Second, the waveform characteristics have natural robustness to bus load changes, which can avoid false alarms caused by traffic mutations and improve the accuracy and reliability of detection.

[0007] However, despite the significant theoretical advantages of voltage domain fingerprint recognition technology, it still faces some challenges in practical engineering applications. In particular, in dynamic temperature scenarios, the supply voltage characteristics of the ECU node will produce nonlinear drift with changes in ambient temperature, resulting in a matching deviation between the voltage fingerprint model and the real-time signal. This matching deviation will seriously affect the accuracy and generalization ability of detection, causing the existing technology to reduce the recognition accuracy by more than 30% within the temperature range of -10°C to 40°C.

[0008] Therefore, how to overcome the voltage fingerprint offset problem caused by temperature changes has become a core problem that needs to be solved urgently. Summary of the invention

[0009] The purpose of the present invention is to solve the technical problem of voltage fingerprint deviation caused by temperature change in the prior art, and to provide a CAN bus intrusion detection method and system based on a temperature sensor device.

[0010] In order to achieve the above object, the present invention adopts the following technical solutions: A first aspect of the present invention provides a CAN bus intrusion detection method based on a temperature sensor device, comprising the following steps: Real-time collection of CAN bus voltage data and temperature data; Preprocess the collected CAN bus voltage data to obtain CAN bus voltage characteristics and corresponding ECU nodes; According to the real-time collected temperature data, the voltage fingerprint model of the corresponding temperature range in the voltage fingerprint model cluster is dynamically loaded; the CAN bus voltage characteristics are input into the voltage fingerprint model of the corresponding temperature range to obtain the membership probability of the CAN bus voltage characteristics to all ECU nodes; the membership probability of the corresponding ECU node and the membership probability of other ECU nodes; Based on the corresponding ECU nodes and CAN bus voltage characteristics, the membership probability of all ECU nodes is checked to provide abnormal warning; The training method of the voltage fingerprint model is specifically as follows: The temperature is divided into intervals, and based on the divided temperature intervals, the voltage data of the CAN bus and the corresponding ECU nodes in the corresponding temperature intervals are selected as training data sets; The training data sets in different temperature ranges are respectively input into the SVM model for training to obtain the voltage fingerprint models in different temperature ranges to form a voltage fingerprint model cluster.

[0011] Furthermore, the loss function of the voltage fingerprint model is to minimize the cross entropy.

[0012] Furthermore, the hyperparameters of the voltage fingerprint model are optimized using k-fold cross validation.

[0013] Further, the voltage fingerprint models in different temperature ranges are mapped one-to-one with the corresponding temperature ranges and stored in a temperature-model index table.

[0014] Further, the voltage fingerprint models in different temperature ranges are stored using parametric differential compression technology.

[0015] Further, based on the membership probabilities of all ECU nodes with respect to the voltage characteristics of the corresponding ECU nodes and the CAN bus, an anomaly warning is performed; specifically: A suspicion counter is set to measure the legitimacy of the CAN bus voltage characteristics; If the membership probability of the ECU node corresponding to the CAN bus voltage characteristic is greater than or equal to the trust threshold, the CAN bus voltage data is legal, and the suspicion counter is updated and decreased by 1; If the membership probability of the ECU node corresponding to the CAN bus voltage characteristic is less than the trust threshold, an anomaly detection mechanism is triggered, and the anomaly detection mechanism includes: When the membership probability of other ECU nodes is greater than the warning threshold, the CAN bus voltage data is an internal attack; When the value of the suspicion counter is greater than the suspicion threshold, the CAN bus voltage data is an external attack; When the CAN bus voltage data is neither an internal attack nor an external attack, the suspicion counter is incremented by 3.

[0016] In a second aspect of the present invention, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned CAN bus intrusion detection method based on a temperature sensor device is implemented.

[0017] In a third aspect of the present invention, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned CAN bus intrusion detection method based on a temperature sensor device is implemented.

[0018] In a fourth aspect of the present invention, a computer program product is provided. The computer program product includes computer instructions, and the computer instructions instruct a computer to execute the above-mentioned CAN bus intrusion detection method based on a temperature sensor device.

[0019] In a fifth aspect of the present invention, a CAN bus intrusion detection system based on a temperature sensor device is provided, including: A data acquisition module that real-time collects the voltage data of the CAN bus and the corresponding temperature data; A data preprocessing module preprocesses the voltage data of the CAN bus collected to obtain the CAN bus voltage characteristics; An intrusion detection module dynamically loads the voltage fingerprint models in the corresponding temperature range in the voltage fingerprint model cluster according to the temperature data collected in real time; inputs the CAN bus voltage characteristics into the voltage fingerprint models in the corresponding temperature range to obtain the membership probabilities of the CAN bus voltage characteristics for all ECU nodes; the membership probabilities of the corresponding ECU nodes and the membership probabilities of other ECU nodes; An early warning module performs abnormal early warning based on the corresponding ECU nodes and the membership probabilities of the CAN bus voltage characteristics for all ECU nodes.

[0020] Compared with the prior art, the present invention has the following beneficial effects: The present invention discloses a CAN bus intrusion detection method based on a temperature sensor device, and proposes a dynamic voltage fingerprint model loading mechanism based on temperature ranges. By pre-training multiple voltage fingerprint models corresponding to different temperature ranges and dynamically loading the most suitable model according to the temperature data collected in real time, the effectiveness and adaptability of the detection model in different temperature environments are ensured. This mechanism effectively solves the problem of the decline in the detection performance of traditional static models under complex environmental changes. The support vector machine (Support Vector Machine, SVM) is used as the basic algorithm of the voltage fingerprint model, and the cross entropy is minimized as the loss function to ensure the optimization direction of the model during training. At the same time, the k-fold cross-validation method is introduced to optimize the model hyperparameters, further improving the generalization ability and detection accuracy of the model. Under the combined action of these measures, the voltage fingerprint model can still maintain a high detection performance in the complex and changeable CAN bus environment. By mapping and storing multiple trained voltage fingerprint models to the corresponding temperature ranges in an index table one by one, the rapid search and call of the models are realized. At the same time, the parameter differential compression technology is used to store the model parameters, effectively reducing the storage space occupancy and improving the system operation efficiency. An abnormal early warning mechanism based on membership probabilities is constructed. By setting parameters such as a doubt counter, a trust threshold, and an early warning threshold, the legitimacy of the CAN bus voltage characteristics is dynamically evaluated. When abnormal voltage characteristics are detected, the source (internal attack or external attack) can be quickly judged, and the corresponding early warning mechanism is triggered. This mechanism not only improves the real-time performance of intrusion detection, but also provides strong support for subsequent security responses. Description of the Drawings

[0021] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0022] Figure 1 Flowchart of the CAN bus intrusion detection method based on temperature sensor devices of the present invention; Figure 2 Structural diagram of the CAN bus intrusion detection system based on temperature sensor devices of the present invention; Figure 3 Block diagram of the CAN bus intrusion detection system based on temperature sensor devices of the present invention; Figure 4 Working principle diagram of the data preprocessing module in the embodiment of the present invention. Specific implementation manner

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations.

[0024] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0025] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

[0026] The present invention will be further described in detail below in conjunction with the drawings: This embodiment discloses a CAN bus intrusion detection method based on temperature sensor devices. The implementation process of the overall method is as Figure 1 shown and includes the following steps: S1. Multimodal data collaborative acquisition: 1) Differential voltage signal acquisition: The differential signal waveform of the CAN bus is captured in real time through the Analog-to-Digital Converter (ADC) interface integrated in the deployment platform to achieve the acquisition of the CAN bus voltage data. The voltage signal of the CAN bus is a differential signal at -5°C to 40°C.

[0027] 2) Dynamic temperature perception acquisition: The deployment platform is connected to a high-precision digital temperature sensor to establish a temperature-voltage timestamp synchronization mechanism. A temperature-related sampling strategy is set during the acquisition process. When the temperature sensor receives a control acquisition signal, a set of temperature data is sampled. The temperature data is synchronously acquired by receiving the temperature acquisition signal.

[0028] S2. Preprocess the acquired CAN bus voltage data to obtain the CAN bus voltage characteristics and the corresponding ECU nodes; Preferably, the original signal is converted into voltage value data through voltage conversion, and the voltage value data is successively subjected to SOF bit recognition, ID decoding, random interleaved sampling, and feature calculation to obtain voltage characteristics; specifically including: S201: Convert the acquired CAN bus voltage data into voltage value data through the ADC conversion formula; S202: Identify the SOF bit of the voltage value data; on the CAN bus, the start of a CAN message is identified by the Start of Frame (SOF) bit. Therefore, it is necessary to identify the SOF bit in the continuously acquired voltage data. During the acquisition process, every time an SOF bit is identified, a temperature acquisition signal is sent to acquire temperature data in real time.

[0029] S203: According to the SOF bit, combined with the CAN bus data rule, identify the dominant bit of the voltage value data, and decode the ID (Identity) according to the dominant bit. According to the ID, combined with the known mapping relationship between the in-vehicle control unit (ECU) and the ID, judge the corresponding ECU; S204: Concatenate the voltage value data in units of the identified dominant bits to form rising edges, dominant platforms, and falling edges; S205: According to the calculation formula of the selected voltage characteristics, calculate the rising edges, dominant platforms, and falling edges formed in S204 in units of voltage value data to obtain the CAN bus voltage characteristics.

[0030] S3. Voltage fingerprint model training and deployment: The voltage fingerprint model training is carried out on a host computer, such as a Personal Computer (PC).

[0031] S301. Temperature-step training model: Based on the typical working-condition temperature range in the industrial control field (such as -10°C to 40°C), divide the temperature range into temperature intervals according to a preset fixed temperature step (such as 5°C). Calculate the CAN bus voltage characteristics obtained in S1 and S2 for each temperature interval. Using the CAN bus voltage characteristics as input and the corresponding ECU node as the label, a mapping data set is constructed; train the SVM model with the mapping data set of the CAN bus voltage characteristics and the corresponding ECU node. During the training process, use the minimization of cross-entropy as the loss function and adopt k-fold cross-validation to optimize the hyperparameters of the SVM model. The SVM model trained by the data set of each temperature interval is the voltage fingerprint model for that temperature interval. The voltage fingerprint models of all temperature intervals form a voltage fingerprint model cluster.

[0032] S302. Use the parameter differential compression technology to store the obtained voltage fingerprint model cluster, and store the temperature-model index table according to the corresponding relationship between the temperature interval and the voltage fingerprint model. Specifically, save the complete parameter set for the reference model (such as the voltage fingerprint model in the 25°C interval), and only store the parameter difference amount for the voltage fingerprint models in other temperature intervals.

[0033] S4. Intrusion detection: S401. Real-time temperature matching detection: Based on the temperature-model index table, dynamically load the voltage fingerprint model of the corresponding temperature interval according to the current sensor reading, perform fingerprint recognition on the voltage data, and obtain the membership probabilities of the ECU nodes corresponding to the CAN bus voltage characteristics and the membership probabilities of other ECU nodes, that is, the membership probabilities of the CAN bus voltage characteristics for all ECU nodes.

[0034] S402. Perform anomaly warning according to the membership probabilities of the ECU nodes corresponding to the CAN bus message and the membership probabilities of other ECU nodes; If the judgment result is an attack, the embedded platform controls the buzzer to sound an alarm. At the same time, the embedded platform controls the display screen to output the temperature, the source of the attack, and the attack result.

[0035] An embodiment of the present invention provides a CAN bus intrusion detection method based on a temperature sensor device. This example is based on the STM32H743ZIT6 microcontroller and the temperature sensor DS18B20 to realize CAN bus intrusion detection. The specific implementation process is as follows: S1. Multi-modal data collaborative acquisition 1) Differential voltage signal acquisition The 12-bit ADC module built into the STM32H743ZIT6 microcontroller is configured with a sampling rate of 5 MHz to collect the CAN high and CAN low signals, ensuring coverage of the CAN bus voltage fluctuations. The ADC captures the voltage waveform in continuous sampling mode, and thus the voltage data of the CAN bus can be collected.

[0036] 2) Dynamic temperature sensing and acquisition The DS18B20 temperature sensor (±0.5℃ accuracy) is connected to the STM32H743ZIT6 microcontroller through the single-wire protocol. After detecting the SOF bit of the CAN message, a sampling signal is sent to trigger the sensor to perform temperature sampling, ensuring that the temperature data is aligned with the message timestamp. Each frame of the message triggers one temperature acquisition, and the temperature value (temperature data) and the corresponding message data (CAN bus voltage data) are synchronously recorded.

[0037] S2. Voltage data preprocessing, see Figure 4 Preprocess the collected CAN bus voltage data to obtain the CAN bus voltage characteristics and the corresponding ECU nodes.

[0038] 1) Voltage conversion and calibration Based on the 3.3V reference voltage of the STM32H743ZIT6, the ADC raw sampling value is converted to the true voltage value through the two-point calibration method.

[0039] 2) SOF bit identification and ID decoding Set the dominant bit threshold to 1.6V and the recessive bit threshold to 0.6V. Locate the falling edge of the SOF bit through the edge detection algorithm; when the distance between the detected rising edge and falling edge is greater than 6 bit positions, the falling edge is considered the SOF bit; starting from the SOF bit, calculate that each bit corresponds to 20 sampling points (5MHz sampling rate) according to the 500kbit / s rate. When decoding the ID, determine the ID according to the standard CAN ID field length, and complete the ECU matching in combination with the pre-set ECU-ID mapping table (such as ID 0x101 corresponding to the engine ECU) to obtain the corresponding ECU node.

[0040] 3) Random interleaved sampling For the message data in the same temperature range (±2.5℃), adopt the random interleaved sampling strategy. Taking the message as a unit, splice the dominant bits, rising edges, and dominant bits within the same message to increase the equivalent sampling rate to 25MHz.

[0041] 4) Feature extraction Based on the sampling results, according to the voltage characteristic formula, calculate the following CAN bus voltage characteristics: maximum value of the rising edge, roll-off rate of the complete bit, average deviation of the rising edge, roll-off rate of the falling edge, flatness of the dominant bit, kurtosis of the rising edge, skewness of the falling edge, kurtosis of the complete bit spectrum, irregularity of the complete bit, falling edge platform, and flatness of the falling edge.

[0042] S3. Voltage fingerprint model training and deployment 1) Modeling by temperature gradient The voltage fingerprint model is trained on the host computer, such as a personal computer (PC). The temperature range from -10°C to 40°C is divided with a step of 5°C, and an SVM model is independently trained for each interval. Requirements for training data screening: Each ECU contains at least 2000 samples at each temperature gradient. The input is the CAN bus voltage characteristics preprocessed by S2, and the output is the ECU node label. Store the temperature-model index table in STM32.

[0043] 2) Model deployment Adopt the parameter differential compression technology to store the voltage fingerprint model cluster. Save the complete parameter set for the reference model (such as the voltage fingerprint model in the 25°C interval), and only store the parameter difference for the voltage fingerprint models in other temperature intervals.

[0044] 3) Dynamic model loading Store the temperature-model index table in STM32 (such as 0x00 corresponding to the model address in the -10°C to -5°C interval). During detection, according to the temperature reading of the current temperature sensor, find the voltage fingerprint model in the corresponding temperature interval through binary search. During the loading process, the parameters of the reference model and the difference are synthesized in real time to obtain the parameters of the voltage fingerprint model in the corresponding temperature interval, reducing the storage space occupation.

[0045] S4. Intrusion detection and response 1) Real-time detection of internal attacks Real-time collect the voltage data and temperature data of the CAN bus; Preprocess the collected voltage data of the CAN bus to obtain the CAN bus voltage characteristics and the corresponding ECU nodes; According to the real-time collected temperature data, dynamically load the pre-trained voltage fingerprint model in the corresponding temperature interval; input the CAN bus voltage characteristics into the pre-trained voltage fingerprint model in the corresponding temperature interval to obtain the membership probability of the ECU node corresponding to the CAN bus voltage characteristics and the membership probability of other ECU nodes; Perform anomaly warning according to the membership probability of the ECU node corresponding to the CAN bus message and the membership probability of other ECU nodes; If the membership probability P of the ECU corresponding to the collected voltage data of the CAN busECU Greater than or equal to the trust threshold T min = 0.8, which means that the ECU node corresponding to the voltage data collected from the CAN bus matches the content of the voltage data. Then, the voltage data is considered legal, and the degree of suspicion of the voltage fingerprint model for this voltage data is reduced by decreasing the value of the challenge counter. When P ECU Less than the trust threshold T min it indicates that the ECU node corresponding to the voltage data collected from the current message of the CAN bus does not match the content of the voltage data. Then, the voltage data collected from the CAN bus is considered possibly abnormal and needs to enter the next step of judgment: When the credibility of the voltage data is challenged, the possibility values of other ECU nodes will be further compared. If the membership probability P other of other ECU nodes is higher than the warning threshold T doubt = 0.6, it means that the source of the voltage data is identified as other ECU nodes. At this time, it is determined that the voltage data is an internal attack, and the voltage data is marked as illegal.

[0046] 2) Attack warning mechanism When an anomaly is detected, the buzzer is triggered through the GPIO (frequency 2 kHz, duration 200 ms), and the attack type (such as "ECU attack: ID 0x201") and the current temperature value (such as "Ambient temperature: 23.5 °C") are output on the TFT display screen.

[0047] Another embodiment of the present invention provides a CAN bus intrusion detection system based on STM32 and temperature sensors for internal and external attacks. This example is based on the STM32H743ZIT6 microcontroller and the DS18B20 temperature sensor to implement a CAN bus intrusion detection system for internal and external attacks. The system consists of a data acquisition module, a data preprocessing module, an intrusion detection module, and a warning module. According to Figure 2As shown in the figure, connect the physical circuit; connect the ADC pin of the STM32H743ZIT6 microcontroller to the high level of the CAN bus, and connect the low level of the CAN bus to the ground wire of the STM32H743ZIT6 microcontroller; collect data through the voltage acquisition module. The voltage data acquisition module transmits the data to the data preprocessing module through DMA (Direct Memory Access, direct memory access). Before the data preprocessing module, the temperature data is transmitted to the data preprocessing module through the temperature sensor. The data preprocessing module stores the data through the SD card (Secure Digital Memory Card, secure digital memory card), and performs data processing. The feature data obtained after preprocessing is transmitted to the intrusion detection module for detection. The detection result of the intrusion detection module enters the warning module for warning. The warning module is equipped with a buzzer and a liquid crystal display; the USB interface of the STM32H743ZIT6 microcontroller is used to communicate with the computer to realize code burning.

[0048] As Figure 3 shown, the specific modules are as follows: 1. Data acquisition module: Real-time collect the voltage data of the CAN bus and the corresponding temperature data.

[0049] Collect the CAN bus differential voltage signal through the built-in 12-bit ADC module (reference voltage 3.3V) of the STM32H743ZIT6 embedded platform, support the input range of 0~3.3V, and adapt to the voltage characteristics of the dominant bit (>1.6V) and the recessive bit (<0.6V). The ADC is configured with a sampling rate of 5 MS / s, and clock synchronous sampling is achieved through timer triggering. In the environmental temperature range of [-5, 20) °C, divide 6 temperature ladders with a step of 5 °C, and collect the voltage data of 8 ECUs in each ladder (700 frames for each ECU, a total of 5600 frames). The DS18B20 temperature sensor (±0.5 °C accuracy) communicates with the STM32 through the single-wire protocol, and triggers temperature sampling after detecting the SOF bit of the CAN message.

[0050] 2. Data preprocessing module: Preprocess the collected voltage data of the CAN bus to obtain the CAN bus voltage characteristics.

[0051] Improve the equivalent sampling rate to 25 MS / s through the random interleaved sampling algorithm to capture the detailed features of the signal. When reconstructing the voltage waveform, calibrate based on the original ADC sampling value and the 3.3V reference voltage. Extract the ID field after identifying the SOF bit, and complete the label matching by combining the preset ECU-ID mapping table. And calculate the CAN bus voltage characteristics.

[0052] 3. Intrusion Detection Module: Select the pre-trained voltage fingerprint model corresponding to the temperature step according to the corresponding temperature data; input the CAN bus voltage feature into the pre-trained voltage fingerprint model corresponding to the temperature step to obtain the membership probability of the ECU node corresponding to the CAN bus voltage feature and the membership probability of other ECU nodes. The intrusion detection module constructs a voltage fingerprint model based on the Support Vector Machine (SVM) algorithm, including the following sub-modules: Voltage Fingerprint Sub-module: Divide the training data set in the host computer at a temperature step of 5°C (such as [-5°C, 0°C), [0°C, 5°C), etc.), and independently train the SVM models for each temperature interval. The model cluster is stored using the parameter differential compression technology. The reference model (25°C) saves the complete support vector weights and bias parameters, and only the difference from the reference model is stored for the models in adjacent temperature intervals. During deployment, import the model parameter set into the STM32 storage unit and establish a temperature-model index table.

[0053] Real-time Detection Sub-module: 1) Temperature Matching and Model Loading: According to the temperature value collected in real time by the DS18B20 temperature sensor, look up the table to determine the current temperature interval and dynamically load the corresponding SVM model parameters; 2) Feature Input and Classification Inference: Receive the CAN bus voltage feature output by the preprocessing module, and calculate the membership probability P of the ECU corresponding to the current message through the voltage fingerprint sub-module ECU and the membership probability of other ECU nodes.

[0054] 4. Warning Module Credibility Judgment: If P ECU ≥0.6 (credible threshold T min ), determine that the message is legal and subtract 1 from the suspicion counter value; if P ECU <0.6, trigger the anomaly detection mechanism; Anomaly Type Identification: Internal Attack: When the second-highest P other ≥0.85 (warning threshold T other ), determine it as a camouflage attack of the internal ECU and trigger the warning module; External Attack: If P ECU <0.6 and the cumulative value of the suspicion counter ≥ 100, determine it as an external injection attack; Pending Confirmation Status: When the above thresholds are not reached, the value of the suspicion counter is increased by 3, and subsequent legal messages are required to offset the cumulative value.

[0055] When an attack is detected, the buzzer is triggered to alarm (frequency 2KHz, duration 0.5 seconds) and an alarm message (ID: 0x7FF) is broadcast through the CAN bus. The attack type (such as "Internal attack: ECU3" or "External attack: unknown source") is synchronously output on the LCD display.

[0056] An embodiment of the present invention demonstrates the superiority of the present invention through the following experiments, specifically: Since the in-vehicle network of automobiles is an important field of CAN bus application, automobiles are selected as the actual application scenario for this experiment. To verify the effectiveness of the solution and eliminate the influence of real environment factors, the experiment is carried out on two platforms: a real vehicle platform and a prototype system. The Buick Regal is selected as the test vehicle for the real vehicle platform, and its ECUs come from multiple suppliers, which can fully reflect the heterogeneity characteristics of ECUs in actual vehicles. The data collection of the hot start state of the real vehicle is carried out after driving the real vehicle for half an hour before data collection. The data collection of the cold start state of the real vehicle is when the engine is ignited at the start of data collection and the engine has not been started within one hour. To ensure the accuracy of temperature data, a dual-redundancy scheme of a mercury thermometer and an electronic thermometer is adopted for real-time monitoring.

[0057] To eliminate the uncontrollable factors in the real vehicle environment, a prototype system is also constructed as a supplementary verification platform. The prototype system consists of 7 heterogeneous ECUs, including STM32F103 development boards, Arduino Nanos, and USBCAN-II Pro and CANalyst-II devices, to simulate the heterogeneity of multi-supplier ECUs in actual vehicles. The prototype system includes two CAN High and CAN Low lines with a rate of 500 kbit / s. The prototype system manually simulates temperature changes and is equipped with a precision temperature control module to ensure that the temperature is accurately controllable within the range of -10°C to 40°C. The bus characteristics are simulated through variable resistors and the same network structure to ensure that the experimental environment is consistent with the characteristics of the real CAN bus.

[0058] The experiment adopts a temperature-stepped data collection strategy, dividing the temperature range into intervals with a step size of 5°C (such as [-5,0)°C, [0,5)°C,...) to ensure the consistency of data distribution within each temperature interval. In the cold start and hot start modes of the real vehicle platform, the temperature range is -5°C to 20°C, divided into 5 temperature steps, and each ECU collects no less than 1000 frames of data within each step. The temperature range of the prototype system is -10°C to 40°C, divided into 10 temperature steps, and each ECU collects no less than 2000 frames of data within each step. Through the above parameters, the sufficiency and representativeness of the experimental data in different temperature intervals are ensured, providing a high-quality data basis for subsequent model training and verification.

[0059] Table 1

[0060] Note: (1) Definition of cold start experiment: When the engine is ignited during data collection, the engine has not been started within one hour. (2) Definition of hot start experiment: When the engine is ignited during data collection, the engine has been working for more than half an hour. (3) The environmental temperature change step refers to the size of the temperature interval divided by the environmental temperature during each data collection.

[0061] To verify the temperature adaptability of the present invention, multi-dimensional tests are carried out through the prototype system and the real vehicle platform. The Scission and EASI are selected as the comparison methods, and the models are trained in fixed temperature intervals ([0, 5) °C and [15, 20) °C) respectively for comparison with the invention. The Scission method comes from Kneib M, Huth C. Scission: A Method for Identifying Senders and Detecting Intrusions in In-Vehicle Networks Based on Signal Features [C]. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. The EASI method comes from US Patent US11683323B2.

[0062] The test results on the prototype system platform are shown in Table 2. In the full temperature range of -10 °C to 40 °C, the proposed scheme maintains a stable accuracy rate of 99.7% - 100%, which is significantly better than the traditional methods. For example, in the extreme low temperature interval [-10, -5) °C, the accuracy rate of the proposed scheme reaches 99.7%, while the Scission and EASI models trained in [0, 5) °C drop to 83.2% and 75.6% respectively; in the high temperature interval [35, 40) °C, it still maintains an accuracy rate of 100%, while the comparison methods drop below 87.8%. This phenomenon is due to the fact that the temperature-model dynamic matching mechanism effectively suppresses the feature drift, while the traditional methods are difficult to cover the wide temperature range feature distribution with a single model. Especially in the temperature mutation scenario (such as from [15, 20) °C to [25, 30) °C), the comparison methods drop by an average of 21.6% (Scission drops from 97.4% to 90.2%), and the proposed scheme only fluctuates by 0.1%, verifying the decoupling ability of hierarchical modeling.

[0063] Table 2

[0064] The experimental results on the real vehicle cold start platform, as shown in Table 3, further reveal the advantages of this solution. In the [5,10)℃ range where the temperature fluctuates violently, the accuracy of this solution is 99%, while the comparison method drops drastically (Scission's accuracy is 66% and EASI's accuracy is 54.8%). It is worth noting that when the Scission model trained at [15,20)℃ is tested in the adjacent [10,15)℃ range, the accuracy drops sharply by 22%, while this solution still maintains 99.8%, indicating that the traditional method is extremely sensitive to temperature boundaries.

[0065] Table 3

[0066] The experimental results under the hot start state, as shown in Table 4, further confirm the advantages of this solution. In the temperature change scenario (such as [5,10)℃), the method of the present invention maintains 100% accuracy, while the comparison method drops by 14%~19%. More importantly, when the EASI model trained at [15,20)℃ is tested at [-5,0)℃, the hot start accuracy drops by 19.2% (68.3%→49.1%) compared with the cold start, while this solution only fluctuates by 0.8%, proving that the dynamic adaptation mechanism can effectively cope with the complex environment of the real vehicle and adapt to the impact of the heat generated by the engine start-up.

[0067] Table 4

[0068] Combining the results of the three experiments, it can be seen that the present invention presents two core advantages: 1) Full temperature range stability: 8 of the 10 temperature steps of the prototype system reach 100% accuracy, and the average accuracy of cold / hot start of the actual vehicle exceeds 99.8%, which is more than 23.5 percentage points higher than the traditional method; 2) Boundary robustness: When switching between adjacent temperature zones (such as [15,20)℃→[20,25)℃), the comparison method produces more than 10% performance degradation due to model solidification, while this solution always keeps the error rate below 0.3% through dynamic model switching triggered by the temperature sensor. The experimental results confirm that this method breaks through the traditional method's dependence on a fixed temperature range, solves the problem of voltage fingerprint drift caused by temperature changes during the test phase, and provides a more comprehensive protection solution for network security in the field of industrial control.

[0069] In another embodiment of the present invention, an electronic device is provided, which includes a processor and a memory. The memory is used to store a computer program, and the computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions to implement the corresponding method flow or corresponding function. The processor described in the embodiments of the present invention can be used for the operation of the CAN bus intrusion detection method based on the temperature sensor device.

[0070] In another embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium. The computer-readable storage medium is a memory device in the terminal device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the terminal device and, of course, the extended storage medium supported by the terminal device. It can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. The computer-readable storage medium provides a storage space that stores the operating system of the terminal. And in this storage space, one or more instructions suitable for being loaded and executed by the processor are also stored. These instructions can be one or more computer programs (including program codes). It should be noted that more specific examples (non-exhaustive list) of the computer-readable storage medium here include: electrical connections with one or more wires, portable disks, hard disks, random access memories, read-only memories, erasable programmable read-only memories, optical fibers, portable compact disk read-only memories, optical storage devices, magnetic storage devices, or any suitable combination of the above.

[0071] The computer-readable storage medium also includes a data signal propagated in a baseband or as part of a carrier wave, which carries the readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable storage medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium can be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber, etc., or any suitable combination of the above.

[0072] The program code for performing the operations of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network or a wide area network, or can be connected to an external computing device (for example, by using an Internet service provider to connect through the Internet).

[0073] One or more instructions stored in the computer-readable storage medium can be loaded and executed by a processor to implement the corresponding steps of the CAN bus intrusion detection method based on a temperature sensor device in the above embodiments.

[0074] An embodiment of the present invention provides a computer program product, which includes computer instructions, and is characterized in that the computer instructions direct the computer to execute the above CAN bus intrusion detection method based on a temperature sensor device.

[0075] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A CAN bus intrusion detection method based on a temperature sensor device, characterized in that, It includes the following steps: Collect the voltage data and temperature data of the CAN bus in real time; Preprocess the collected voltage data of the CAN bus to obtain the CAN bus voltage characteristics and the corresponding ECU nodes; According to the temperature data collected in real time, dynamically load the voltage fingerprint model corresponding to the temperature range in the voltage fingerprint model cluster; input the CAN bus voltage characteristics into the voltage fingerprint model corresponding to the temperature range to obtain the membership probabilities of the CAN bus voltage characteristics for all ECU nodes; the membership probabilities of the corresponding ECU nodes and the membership probabilities of other ECU nodes; Based on the corresponding ECU nodes and the membership probabilities of the CAN bus voltage characteristics for all ECU nodes, conduct anomaly warnings; Among them, the training method of the voltage fingerprint model is specifically as follows: Divide the temperature into intervals, and based on the divided temperature intervals, select the voltage data of the CAN bus and the corresponding ECU nodes in the corresponding temperature intervals as the training data set; Input the training data sets in different temperature intervals into the SVM model for training respectively to obtain the voltage fingerprint models in different temperature intervals, which form a voltage fingerprint model cluster.

2. The CAN bus intrusion detection method based on a temperature sensor device according to claim 1, wherein The loss function of the voltage fingerprint model is the minimization of cross entropy.

3. The CAN bus intrusion detection method based on a temperature sensor device according to claim 1, characterized in that, The hyperparameters of the voltage fingerprint model are optimized by k-fold cross-validation.

4. The CAN bus intrusion detection method based on a temperature sensor device according to claim 1, characterized in that, The voltage fingerprint models in different temperature intervals are mapped one-to-one with the corresponding temperature intervals and stored in a temperature-model index table.

5. The CAN bus intrusion detection method based on a temperature sensor device according to claim 1 or 4, characterized in that, The voltage fingerprint models in different temperature intervals are stored using parameter differential compression technology.

6. The CAN bus intrusion detection method based on a temperature sensor device according to claim 1, characterized in that, Based on the corresponding ECU nodes and the membership probabilities of the CAN bus voltage characteristics for all ECU nodes, conduct anomaly warnings; specifically: Set a doubt counter to measure the legitimacy of the CAN bus voltage characteristics; If the membership probability of the ECU node corresponding to the CAN bus voltage characteristics is greater than or equal to the credibility threshold, the CAN bus voltage data is legal, and the doubt counter is updated and decreased by 1; If the membership probability of the ECU node corresponding to the CAN bus voltage characteristics is less than the credibility threshold, trigger an anomaly detection mechanism, and the anomaly detection mechanism includes: When the membership probability of other ECU nodes is greater than the warning threshold, the CAN bus voltage data is an internal attack; When the value of the doubt counter is greater than the doubt threshold, the CAN bus voltage data is an external attack; When the CAN bus voltage data is neither an internal attack nor an external attack, the doubt counter is incremented by 3.

7. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the CAN bus intrusion detection method based on a temperature sensor device according to any one of claims 1-6.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the CAN bus intrusion detection method based on a temperature sensor device according to any one of claims 1-6.

9. A computer program product, the computer program product comprising computer instructions, characterized in that, The computer instructions instruct the computer to execute the CAN bus intrusion detection method based on a temperature sensor device according to any one of claims 1-6.

10. A CAN bus intrusion detection system based on a temperature sensor device, based on the CAN bus intrusion detection method based on a temperature sensor device according to claim 1, characterized in that, It includes: A data acquisition module that collects the voltage data of the CAN bus and the corresponding temperature data in real time; Data preprocessing module, which preprocesses the voltage data of the CAN bus collected to obtain the CAN bus voltage characteristics; Intrusion detection module, which dynamically loads the voltage fingerprint model corresponding to the temperature range in the voltage fingerprint model cluster according to the real-time collected temperature data; inputs the CAN bus voltage characteristics into the voltage fingerprint model corresponding to the temperature range to obtain the membership probability of the CAN bus voltage characteristics for all ECU nodes; the membership probability of the corresponding ECU node and the membership probability of other ECU nodes; Early warning module, which conducts abnormal early warning based on the corresponding ECU node and the membership probability of the CAN bus voltage characteristics for all ECU nodes.

Citation Information

Patent Citations

  • Abnormal intrusion detection method and device for Internet of Vehicles CAN bus

    CN110752977A

  • Vehicle intrusion detection method for establishing fingerprint for each identifier and related device

    CN115801396A

  • Vehicle data acquisition and analysis system based on CAN bus

    CN117155737A

  • Temperature abnormity alarm method and system, electronic equipment and medium

    CN118833149A

  • Identifying compromised electronic control units via voltage fingerprinting

    US20190245872A1