Intrusion detection and defense method for vehicle-mounted CAN bus and message filtering device

By setting up a message filtering device on the CAN bus, analyzing and intercepting illegal messages, the problem of insufficient security of the CAN bus in intelligent connected vehicles is solved, and the safety and reliability of the vehicle are improved.

CN120602144APending Publication Date: 2025-09-05ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510732083.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The CAN bus of intelligent connected vehicles lacks a security authentication mechanism and is vulnerable to attacks, resulting in insufficient security and threatening the lives of passengers and drivers.

Method used

Set up a message filtering device on the CAN bus connected to the vehicle's functional domain controller. By analyzing the target field value of the message and comparing the filtering conditions, intercepting mismatched messages to prevent potential illegal attacks.

Benefits of technology

It improves the security of the CAN bus, reduces processing pressure, enhances personalized security control for different functional domains, reduces resource waste, and ensures the safety of key functional units.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602144A_ABST
    Figure CN120602144A_ABST
Patent Text Reader

Abstract

The invention provides an intrusion detection and defense method for a vehicle-mounted CAN bus and a message filtering device, the method is applied to the message filtering device, and the message filtering device is arranged on any CAN bus connected with a domain controller of any functional domain of a vehicle. The domain controller is connected with any CAN bus, and messages transmitted between the domain controller and each functional unit connected with the CAN bus pass through the message filtering device, and the method comprises the following steps: acquiring and analyzing the messages transmitted on the CAN bus, and comparing target field values of the messages with corresponding target filtering conditions; and if the target field value is not matched with the target filtering condition, intercepting the message.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of vehicle technology, and in particular to an intrusion detection and defense method and a message filtering device for a vehicle-mounted CAN bus. Background Art

[0002] With the development of intelligent connected vehicles (ICVs), the automotive industry is facing unprecedented multi-dimensional security challenges. ICVs not only feature complex IoV architectures but also expose a greater attack surface. Attackers can exploit a variety of attack methods to target vehicles, making automotive security defense even more challenging. Furthermore, the multitude of ICV protocols and the lack of unified security standards leave many connected cars inadequately protected. Attackers can exploit these vulnerabilities to easily compromise vehicle systems, causing serious security issues. Even more dangerous, the increasing profitability of attacking ICVs is driving hackers' growing interest in attacking vehicles. These hackers can exploit system vulnerabilities to gain control of the vehicle, even remotely operating it, posing a threat to the safety of passengers and drivers.

[0003] Therefore, the automotive industry must prioritize safety and implement effective measures to improve vehicle safety. This requires joint efforts by automakers and relevant organizations to establish more comprehensive safety standards and develop safer automotive systems. However, due to the lag in technological change, the CAN bus remains the primary bus protocol in vehicles. However, information security was not considered when the CAN bus was designed. The CAN bus lacks encryption and authentication mechanisms, allowing any device connected to the CAN bus to send and receive information. This allows attackers to exploit vehicles using the CAN bus protocol in a variety of ways. Summary of the Invention

[0004] To overcome the problems existing in the related art, this specification provides an intrusion detection and defense method and a message filtering device for a vehicle-mounted CAN bus.

[0005] According to a first aspect of an embodiment of this specification, a method for intrusion detection and defense against a vehicle-mounted CAN bus is provided. The method is applied to a message filtering device, which is provided on any CAN bus connected to a domain controller of any functional domain of a vehicle, and messages transmitted between the domain controller and each functional unit connected to any CAN bus pass through the message filtering device. The method includes:

[0006] Acquire and parse the message transmitted on the CAN bus, and compare the target field value of the message with the corresponding target filtering condition;

[0007] If the target field value does not match the target filtering condition, the message is intercepted.

[0008] According to the second aspect of the embodiments of this specification, a message filtering device is provided, which is arranged on any CAN bus connected to the domain controller of any functional domain of the vehicle, and the messages transmitted between the domain controller and each functional unit connected to any CAN bus pass through the message filtering device, and the message filtering device is used to implement the steps of the method described in the first aspect.

[0009] According to a third aspect of the embodiments of this specification, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method described in the first aspect are implemented.

[0010] According to a fourth aspect of the embodiments of this specification, a vehicle is provided, wherein the vehicle is equipped with a message filtering device, and the message filtering device is used to implement the steps of the method described in the first aspect.

[0011] The technical solutions provided by the embodiments of this specification may have the following beneficial effects:

[0012] In this embodiment, a message filtering device is installed on any CAN bus connected to a domain controller in any functional domain of the vehicle, and messages transmitted between the domain controller and each functional unit connected to any CAN bus pass through the message filtering device. Therefore, for functional units connected to different CAN buses in different functional domains, a message filtering device can be installed on the CAN bus where the functional unit with security requirements is located. The message filtering device is used to obtain and parse messages transmitted on the CAN bus, and compare the target field value of the message with the corresponding target filtering condition. If the target field value does not match the target filtering condition, the message is intercepted.

[0013] As can be seen, this embodiment can address the lack of a security authentication mechanism on the CAN bus by providing a separate message filtering device on the CAN bus to intercept messages suspected of being illegal attacks. Furthermore, because the message filtering device is provided on a single CAN bus, its monitored objects are also the functional units sharing that CAN bus. Therefore, the number of objects monitored by the device is limited to the functional units on the same CAN bus. This not only reduces the message processing workload of the message filtering device, thereby alleviating processing pressure, but also allows the message filtering device to be configured with only filtering conditions that meet the security requirements of the functional units on the CAN bus it is located on, thereby reducing the number of filtering conditions and improving the efficiency of matching filtering conditions.

[0014] It should be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the specification and, together with the description, serve to explain the principles of the specification.

[0016] Figure 1 This is an application scenario diagram of a message filtering device according to an exemplary embodiment of this specification.

[0017] Figure 2 This is a flowchart of an intrusion detection and defense method for a vehicle-mounted CAN bus according to an exemplary embodiment of this specification.

[0018] Figure 3 This is a flowchart of a cascaded detection and defense method for CAN bus intrusion according to an exemplary embodiment of this specification.

[0019] Figure 4 It is a structural diagram of an electronic device according to an exemplary embodiment of this specification.

[0020] Figure 5 This is a block diagram of a message filtering device according to an exemplary embodiment of the present specification. DETAILED DESCRIPTION

[0021] The complexity and functional diversity of modern vehicle electronic control systems continue to increase. To better manage these systems, vehicles are divided into different "domains." A vehicle domain refers to the functional division of the vehicle's electronic control system into multiple relatively independent parts, each responsible for a specific task. For example, the power domain is primarily responsible for controlling powertrain components such as the engine and transmission; the body domain primarily controls vehicle doors, lighting, and air conditioning; and the infotainment domain primarily controls infotainment components such as navigation, audio, video, and communications.

[0022] A domain controller is a centralized controller responsible for managing and coordinating the functional units (such as electronic control units, or ECUs) within a specific domain. For example, the domain controller for the power domain manages the functional units within the power domain; the domain controller for the body domain manages the functional units within the body domain, and so on. A domain controller is typically connected to at least one CAN bus, with each CAN bus connected to at least one functional unit. The CAN bus serves as a communication medium, and the domain controller communicates with each functional unit via the CAN bus, collecting fault data from each functional unit or sending control instructions to each functional unit.

[0023] like Figure 1As shown, for example, for a domain controller 12 of any functional domain of a vehicle, assuming that the domain controller 12 is connected to a CAN bus 10 and a CAN bus 13, in this example, a message filtering device 11 is set on the CAN bus 10 connected to the domain controller 12. The message filtering device 11 can be set as close to the domain controller 12 as possible so that messages transmitted between the domain controller 12 and the functional units a, b, and c connected to the CAN bus 10 can pass through the message filtering device 11. In addition, other message filtering devices (not shown in the figure) can also be set on the CAN bus 13 connected to the domain controller 12 to protect the various functional units connected to the CAN bus 13.

[0024] The hardware that forms the message filtering device 11 can be a programmable logic controller (PLC). Engineers can flexibly configure various filtering conditions within the PLC to intercept illegal messages with various attack characteristics. The message filtering devices installed on different CAN buses in different functional domains of the vehicle, or on different CAN buses in the same functional domain, can be configured with different filtering conditions. For example, the message filtering device on any CAN bus in any functional domain can be configured with corresponding personalized filtering conditions based on the personalized security requirements of each functional unit connected to that CAN bus, thereby meeting the personalized security requirements of functional units on different CAN buses in different functional domains at a more granular level.

[0025] For any CAN bus connected to the domain controller of any functional domain in the vehicle, users can choose whether to install or not install a message filter on a specific CAN bus within that domain, taking into account the security requirements of different CAN buses within different functional domains. For example, the power domain is primarily responsible for sensitive functional units such as the engine and brakes. These sensitive functional units are closely related to the safety of the vehicle and the personal safety of the driver. If these sensitive functional units in the power domain are attacked illegally, such as by an attacker sending illegal commands through the CAN bus, interfering with the normal control of the vehicle's electronic control system over sensitive functional units such as the engine or brakes, the driver's life will be seriously endangered. Therefore, message filters can be installed on any or all of the critical CAN buses connected to the power domain domain controller to prevent illegal attacks targeting specific functional units in the power domain. For the infotainment domain, it is primarily responsible for entertainment functional units such as navigation, audio, video, and communication. Since these functional units have lower security requirements and are generally not subject to illegal attacks, even if they are attacked, it is unlikely to endanger the life of the driver. Therefore, message filters can be installed on any CAN bus in the infotainment domain. By selectively setting up message filtering devices on key CAN buses according to the security requirements of different CAN buses in different functional domains, not only can more fine-grained security control be achieved specifically for functional units on a CAN bus, but message filtering devices can also be concentrated on the key CAN buses of key functional domains to maximize the security and reliability of these domains, while not over-protecting domains with low security requirements (such as the infotainment domain) and avoiding unnecessary waste of resources.

[0026] like Figure 2 As shown, Figure 2 This is a flowchart of an intrusion detection and defense method for a vehicle-mounted CAN bus according to an exemplary embodiment of the present specification. The method can be applied to Figure 1 The message filtering device 11 shown in FIG. 1 includes steps 201-202:

[0027] Step 201: Acquire and parse a message transmitted on the CAN bus, and compare the target field value of the message with a corresponding target filtering condition.

[0028] Step 202: If the target field value does not match the target filtering condition, intercept the message.

[0029] In one illustrated embodiment, the message filtering device can be configured with more than one filtering condition. The specific filtering conditions can be determined based on the specific security requirements of the functional units connected to the CAN bus where the message filtering device is located. Furthermore, the combined configuration of multiple different filtering conditions can also protect against a wider range of security threats through mutual cooperation, thereby improving the comprehensiveness of the defense.

[0030] The message filtering device can obtain the messages transmitted between the domain controller and each functional unit on the CAN bus. Since the messages sent by the functional unit to the domain controller are mainly status and feedback information, assuming that this information is safe and reliable, the message filtering device can only detect the messages sent by the domain controller to each functional unit, and directly release the messages sent by each functional unit to the domain controller, so as to save computing resources for detecting messages and improve detection efficiency. Of course, the message filtering device can detect both the messages sent by the domain controller to each functional unit and the messages sent by each functional unit to the domain controller. This specification does not impose any restrictions on this.

[0031] If a filtering condition is configured on the message filtering device, the filtering condition is used to detect whether the specific field value of the message is legal. For any message transmitted on the CAN bus, the message can be obtained and parsed, and the specific field value of the parsed message can be compared with the set filtering condition. If the specific field value does not match the filtering condition, the message is intercepted; if not, the message is allowed to pass.

[0032] If a plurality of filtering conditions are configured on the message filtering device, different filtering conditions can be used specifically to detect whether the field values ​​of different parts of the message are legal. For any message transmitted on the CAN bus, the message can be obtained and parsed, and the target field value of the parsed message can be compared with the corresponding target filtering condition. If the target field value does not match the target filtering condition, the message is intercepted; if not, the other target field values ​​of the message are continued to be compared with the corresponding other target filtering conditions until all the target field values ​​of the message match all the corresponding target filtering conditions, and the message is allowed to pass. Among them, the target filtering condition is any one of the multiple filtering conditions and the target filtering condition can be used for comparison with the target field value of the message.

[0033] In this embodiment, a message filtering device is separately provided on the CAN bus to intercept messages suspected of illegal attacks, thereby compensating for the problem that the CAN bus lacks a security authentication mechanism.

[0034] Next, we will introduce the various filtering conditions that can be configured in the message filtering device:

[0035] In one illustrated embodiment, the Figure 1For example, since the CAN bus 10 is connected to functional units a, b, and c, the domain controller 12 will not send messages whose node addresses are not functional units a, b, and c to the CAN bus 10 under normal operation. However, when the vehicle is attacked by an illegal attack such as a FUZZ attack, the attacker will send a large number of randomly generated illegal messages to the CAN bus 10, causing the domain controller 12 to send illegal messages whose node addresses are not functional units a, b, and c to the CAN bus 10 under the illegal attack. Therefore, this embodiment can be used in Figure 1 The filtering conditions set on the message filtering device 11 include the node identifiers of the functional units a, b and c. Whether the message is a legitimate message is determined by whether the message identifier in the message is the same as any node identifier. If the message identifier is different from any node identifier among a, b and c, the message is intercepted. It should be noted that the filtering conditions of this embodiment set by the message filtering devices on different CAN buses include the node identifiers of each functional unit connected to the CAN bus, and the node identifiers of the functional units connected to other CAN buses may not appear. Therefore, the number of functional units governed by the message filtering device 11 can be limited to the functional units of the same CAN bus, so that the number of node identifiers included in the filtering conditions can be the same as the number of functional units on the CAN bus, saving the workload of the message filtering device in matching node identifiers, thereby improving detection efficiency.

[0036] In another embodiment, the legal range of CAN IDs (i.e., node identifiers) provided to vehicles by the CAN bus protocol is generally 0x000 to 0x7FF. Unauthorized attackers typically exploit unused node identifiers outside this legal range. Therefore, the filtering condition may also include a preset legal range for node identifiers. If a message's message identifier is not within this range, the message is intercepted.

[0037] In some vehicle attack scenarios, attackers may forge control messages designed to attack sensitive functional units of the vehicle. However, these control messages may have legitimate message identifiers, making it impossible to identify forged control messages based on the message identifiers. For example, an attacker might forge a control message for opening a vehicle window and set an abnormal height value in the data field of the message, indicating that the window can be raised or lowered. Upon receiving this forged message, the window control unit would continuously raise or lower the window in response to the abnormal height value, until the window is damaged or the motor overloads. An attacker might also forge a control message for opening a rearview mirror and set an abnormal angle (e.g., 360 degrees) in the data field. A normal rearview mirror has a normal adjustment angle of [0, 90]. Upon receiving this message, the window control unit would continuously adjust the mirror's angle in response to the abnormal angle value in the control message, ultimately damaging the mirror's mechanical structure.

[0038] In one illustrated embodiment, corresponding filtering conditions can be set for sensitive functional units, such as window functional units or rearview mirror functional units, to identify attacks specifically targeting sensitive functional units. Specifically, the filtering conditions can include the sensitive node identifier of the sensitive functional unit and the corresponding safe numerical range. If the message identifier of a message is the same as the sensitive node identifier and the value of the data field of the message is within the safe numerical range corresponding to the sensitive node identifier, the message is determined to match the filtering conditions. If not, the message is intercepted. Of course, in another case, if the message is not sent to the sensitive functional unit, that is, the message identifier of the message is different from the sensitive node identifier, the message can also be considered to match the filtering conditions, and the legitimacy of the message can be further tested using other filtering conditions, such as the legal node identifier range of the aforementioned embodiment. For example, if the sensitive functional unit is a window functional unit, the filtering conditions can include the node identifier of the window functional unit and the normal operating numerical range of the window functional unit. When it is detected that the message identifier of a certain message is the same as the node identifier of the vehicle window functional unit, it means that the message is a message sent to the vehicle window functional unit. It is possible to continue to detect whether the value of the data field of the message is within the normal operating value range. If the value of the data field is not within the normal operating value range, it means that the message is suspected to be a control message forged by an attacker. It is intercepted by a message filtering device to avoid damage to the vehicle window.

[0039] In this embodiment, the message filtering device verifies the legal value range of the data field of the message based on the filtering conditions of this embodiment to compensate for the defect that the functional unit of the electronic control system lacks a mechanism for detecting the legal value range of the control instruction.

[0040] It should be noted that the filtering conditions for sensitive functional units can be limited to the sensitive functional units connected to the CAN bus where the message filtering device is located. If no sensitive functional units exist on the CAN bus where the message filtering device is located, the filtering conditions of the above embodiment can be omitted for the message filtering device. The sensitive functional units such as the window functional unit and the rearview mirror functional unit mentioned in the above embodiment are merely examples; other sensitive functional units may also exist, and this specification does not impose any limitations on this.

[0041] In some vehicle attack scenarios, while the vehicle is in motion, attackers send forged diagnostic messages containing sensitive diagnostic instructions to the vehicle's key functional units via the CAN bus, inducing the key functional units to perform diagnostic operations that should not be performed at this time while the vehicle is in motion, resulting in a temporary loss of control over key components and ultimately causing the vehicle to lose control. For example, if the engine control unit receives a forged diagnostic instruction while the vehicle is in motion, it may actively shut down the engine when executing the diagnostic instruction. For another example, if the brake control unit in the brake domain receives a forged diagnostic instruction, it may prevent the user from controlling the vehicle's brake system when executing the diagnostic instruction.

[0042] In one illustrated embodiment, corresponding filtering conditions can be configured on a message filtering device for sensitive diagnostic instructions. Any diagnostic instruction that could cause a normally operating functional unit to experience operational disruptions upon receiving the instruction, such as causing an operational anomaly or temporary cessation of operation, is considered a sensitive diagnostic instruction. Such sensitive diagnostic instructions include, but are not limited to, reset instructions and programming session instructions. A reset instruction is used to restart a vehicle's electronic control unit (ECU). Upon receiving the reset instruction, the ECU suspends operation, temporarily disabling all vehicle functions controlled by the ECU. For example, resetting the engine control unit (ECU) causes the engine to stall, while resetting the brake control unit (BCU) disables the braking system. Programming session instructions are used to enter the ECU's programming mode, allowing for firmware updates or parameter programming. This process is typically performed during vehicle repair and maintenance. If the ECU receives a programming session instruction while the vehicle is in motion, it may cease normal control functions due to the need to receive new programming or configuration parameters. Therefore, in this embodiment, the message filtering device can intercept sensitive diagnostic messages containing such sensitive diagnostic instructions when the vehicle is determined to be in motion. However, the actual situation is that not all sensitive diagnostic messages sent to all ECUs need to be intercepted while the vehicle is driving. When some ECUs fail, more serious consequences may occur if an emergency reset is not performed. For example, an error occurs in a sensor in the automatic driving system, which makes the system unable to judge the vehicle's surroundings normally. At this time, it may be necessary to immediately reset the sensor's ECU. In response to this situation, this embodiment divides the functional units into critical functional units and non-critical functional units. When the vehicle is in driving state, sensitive diagnostic messages containing sensitive diagnostic instructions sent to critical functional units can be intercepted, but sensitive diagnostic messages sent to non-critical functional units can be allowed to pass. As for the division of critical functional units and non-critical functional units, users can make their own divisions based on security requirements and actual conditions, and this manual does not impose any restrictions on this.

[0043] The filtering conditions may include a non-critical node identifier of a non-critical functional unit and an instruction code of a sensitive diagnostic instruction. If the message filtering device determines that the vehicle is in a driving state and that the message identifier of the message is the same as the non-critical node identifier and the instruction field of the message contains the instruction code, it means that the message is a sensitive diagnostic message sent to a non-critical functional unit, and the message is allowed to pass. If the message filtering device determines that the vehicle is in a driving state and that the message identifier of the message is different from the non-critical node identifier and the instruction field of the message contains the instruction code, it means that the message is a sensitive diagnostic message sent to a critical functional unit, and the message can be intercepted.

[0044] In this embodiment, attack behaviors created by attackers using sensitive diagnostic instructions can be accurately detected and intercepted, thereby enhancing the defense capability of the message filtering device against such attack behaviors.

[0045] The various filtering conditions shown in the above embodiments can be partially or completely set in the message filtering device. For example, only the filtering conditions introduced in some embodiments can be set in the message filtering device. Of course, all the filtering conditions introduced in the above embodiments can also be set in the message filtering device. In view of the location where the message filtering device is set, some functional units connected to the CAN bus may not need to use some of the filtering conditions introduced in the above embodiments. For example, the filtering conditions including the sensitive node identifiers of sensitive functional units and the corresponding safety value ranges may not be applied to the infotainment domain. Therefore, it is not necessary to set such filtering conditions on the message filtering device on the CAN bus in the infotainment domain to reduce unnecessary detection.

[0046] The above embodiment sets filtering conditions for various field values ​​of the message, and identifies attack messages by detecting the legitimacy of the field values ​​of the message. In addition, this specification also sets other ways for the message filtering device to identify illegal attacks on the CAN bus. For details, please refer to the following embodiments:

[0047] In one illustrated embodiment, in some vehicle attack scenarios, such as flooding attacks, attackers continuously send a large number of forged messages to the CAN bus, occupying bus bandwidth and preventing legitimate messages from being transmitted to functional units connected to the CAN bus in a timely manner. These forged messages may be randomly generated or duplicated legitimate messages. In the latter case, it is difficult to identify a flooding attack based on the field values ​​of a single message.

[0048] In response to the attack principle of, for example, a flood attack, this embodiment uses a message filtering device to determine the load rate of the CAN bus within a preset time period. If the load rate is greater than the load rate threshold, it means that the CAN bus is suspected of being illegally attacked. The preset time period can be selected from 30s, 1 minute, or 2 minutes, etc. The message filtering device can determine the load rate of the CAN bus within a preset time period every 5 minutes, 10 minutes, or 15 minutes to save computing resources. The message filtering device can collect the CAN bus load data of normal communication within a certain period of time each time the vehicle is started normally, and calculate the normal load rate, and use a value slightly greater than the normal load rate as the load rate threshold. Of course, the average load rate of the vehicle's CAN bus under various working conditions can also be tested before the vehicle is sold, and a value slightly greater than the average load rate can be used as the load rate threshold.

[0049] In this embodiment, the message filtering device can be configured with an emergency filtering condition, which includes a specific node identifier of a specific functional unit. Furthermore, the emergency filtering condition can be activated upon detecting that the load rate is greater than a load rate threshold. When the emergency filtering condition is activated, if the identifier of a message transmitted on the CAN bus is different from the specific node identifier, the message is intercepted; otherwise, the message is allowed to pass. The so-called specific functional unit can be a functional unit used to control the basic driving functions of the vehicle, so as to ensure that during vehicle driving, after detecting an illegal attack on the CAN bus, the vehicle can use its basic driving functions to drive normally to the roadside and await rescue.

[0050] In this embodiment, after an illegal attack is detected based on abnormal changes in the load rate on the CAN bus, an emergency filtering condition is activated. The emergency filtering condition can only allow messages that maintain the normal operation of the basic functional units of the vehicle to pass through, while intercepting messages sent to other functional units of the vehicle. In the event that the vehicle is suspected of being under an illegal attack, more functional units of the vehicle can be protected from further attacks as much as possible.

[0051] In one illustrated embodiment, if an illegal attack is characterized by repeated transmission of illegal messages to the same node, then during the attack, the ratio of the number of messages from that node to the total number of nodes on the CAN bus will exceed a normal ratio. Therefore, whether the CAN bus is under an illegal attack can be identified based on the change in the ratio of the number of messages from each node to the total number of nodes within a preset duration. If the message ratio of any node exceeds a normal ratio threshold, the CAN bus is determined to be under an illegal attack. The message filtering device is provided on the CAN bus and is primarily responsible for the communication security of each functional unit connected to the CAN bus. In a vehicle network, the node in this embodiment refers to the control unit connected to the vehicle CAN bus. Therefore, the total number of nodes can be the number of functional units connected to the CAN bus. The preset duration can be selected from various lengths, such as 1 minute, 3 minutes, or 5 minutes. The message identifier in the message can be used to determine which functional unit the message is sent to. The message filtering device can detect the ratio of the number of messages from each node to the total number of nodes on the CAN bus within the preset duration every 3 minutes, 5 minutes, or 10 minutes. The message filtering device can collect messages transmitted on the CAN bus within a certain period of time each time the vehicle is started, and calculate the normal ratio of the number of messages transmitted on each node to the total number of nodes. Of course, before the vehicle is sold, the normal ratio of the number of messages transmitted on each node to the total number of nodes can also be tested under various operating conditions. A value slightly higher than the normal ratio of any node can be used as the normal ratio threshold for that node.

[0052] In this embodiment, the message filtering device can be configured with an emergency filtering condition, which includes a specific node identifier of a specific functional unit. In addition, the emergency filtering condition can be activated when it is detected that the message ratio of any node exceeds the normal ratio threshold. When the emergency filtering condition is activated, if the identifier of the message transmitted on the CAN bus is different from the specific node identifier, the message is intercepted; otherwise, the message is allowed to pass. The so-called specific functional unit can be a functional unit for controlling the basic driving functions of the vehicle to ensure that during the driving process of the vehicle, after an illegal attack on the CAN bus is detected, the vehicle can use the basic driving functions of the vehicle to drive normally to the roadside and wait for rescue.

[0053] In one illustrated embodiment, in some vehicle attack scenarios, such as fuzzing attacks, attackers may send large amounts of random data or malformed data to the CAN bus in an attempt to trigger functional units receiving the messages to erroneously behave. For example, assuming a vehicle is under a fuzzing attack, the attacker may forge attack messages in the following format: the data field value of the message is a random value, such as "FF FF FF FF FF FF FF," or the data field of the message is in an unexpected format, such as "12 34 56 78 90AB CD EF." In contrast, research has found that during normal CAN bus communication, the data change rate between adjacent messages belonging to the same node is generally stable and does not change significantly. For example, the data field value of the adjacent messages "018F 11 34 77 87F8 E7" and "01 8F11 34 77 87F8 D7" belonging to the same node changes from "E7" to "D7."

[0054] When calculating the data change rate between adjacent messages belonging to the same node, the 8-byte hexadecimal message frame can be decomposed into a 64-bit message format. For example, the message "01 8F 1134 77 87F8 E7" can be converted to "00000001 10001111 00010001 0011010001110111 10000111 1111100011100111". For the message "01 8F 11 34 77 87F8 D7", it can be converted to "00000001 1000111100010001 00110100 01110111 1000011111111000 11010111". It can be seen that the data changed in the latter message compared to the previous message is the "01" in the 8th byte "11010111". The data change rate can be calculated as 2 / 64=3.125%.

[0055] For example, the attack principle of fuzzing attack. The message filtering device can detect the data change rate between messages that are adjacent and belong to the same node on the CAN bus. If the data change rate exceeds the change rate threshold, it is determined that the CAN bus is suspected of being attacked illegally. For example, the message filtering device can continuously detect the data change rate between any two adjacent messages that belong to the same node on the CAN bus within a preset time period. If the data change rate of any node exceeds the change rate threshold corresponding to the node, it is determined that the CAN bus is suspected of being attacked illegally. The message filtering device can collect messages transmitted on the CAN bus within a certain time period each time the vehicle is started, and calculate the average data change rate of all adjacent messages belonging to the same node. In this way, the average data change rate of all nodes on the CAN bus can be obtained, and a value slightly larger than the data change rate average is taken as the data change rate threshold of the node. Of course, the data change rate threshold corresponding to each node can also be determined before the vehicle is sold. For example, the message filtering device can collect messages transmitted on the CAN bus within a preset time period and calculate the average value of the data change rate between each adjacent message belonging to the same node. If the average value of the data change rate exceeds the change rate threshold, it is determined that the CAN bus is suspected of being illegally attacked. The message filtering device can collect messages transmitted on the CAN bus within a certain time period each time the vehicle is started, and calculate the average value of the data change rate of all adjacent messages belonging to the same node, and take the comprehensive average value of the average data change rate of all nodes, and use a value slightly greater than the comprehensive average value as the data change rate threshold. Of course, the data change rate threshold corresponding to each node can also be determined before the vehicle is sold.

[0056] In this embodiment, the message filtering device can be configured with an emergency filtering condition, which includes a specific node identifier of a specific functional unit. Furthermore, the emergency filtering condition can be activated upon detecting that the data change rate exceeds a change rate threshold. When the emergency filtering condition is activated, if the identifier of the message transmitted on the CAN bus is different from the specific node identifier, the message is intercepted; otherwise, the message is allowed to pass. The so-called specific functional unit can be a functional unit for controlling the basic driving functions of the vehicle, so as to ensure that during the vehicle's driving process, after detecting an illegal attack on the CAN bus, the vehicle can use the vehicle's basic driving functions to drive normally to the roadside and wait for rescue.

[0057] In one illustrated embodiment, the message filtering device can simultaneously detect changes in the CAN bus load rate, message volume ratio, and data changes in adjacent messages belonging to the same node. If any of these changes are abnormal, emergency filtering conditions are activated. By having multiple detection mechanisms working simultaneously, more comprehensive anomaly detection capabilities can be provided.

[0058] In another illustrated embodiment, as Figure 3 As shown, various types of changes can be detected in sequence. If an illegal attack cannot be detected based on the previous type of change, the detection based on the next type of change can be carried out. For details, see Figure 3 Steps:

[0059] Step 301: Determine the load rate of the CAN bus within a preset time period.

[0060] Step 302: If the load rate is greater than the load rate threshold, go to step 307 to start the emergency filtering condition; if not, go to step 303.

[0061] Step 303: Determine the ratio of the number of messages of each node to the total number of nodes on the CAN bus within a preset time period.

[0062] Step 304: If the message ratio of any node exceeds the normal ratio threshold, go to step 307 and start the emergency filtering condition; if not, go to step 305.

[0063] Step 305: Determine the data change rate between adjacent messages belonging to the same node on the CAN bus.

[0064] Step 306: If the data change rate is greater than the change rate threshold, go to step 307 to activate the emergency filtering condition.

[0065] In this embodiment, through this step-by-step detection method, the system can sequentially refine the detection with lower resource consumption, gradually detect illegal attack behaviors, and thus improve the accuracy of detection.

[0066] Corresponding to the aforementioned method embodiments, this specification also provides embodiments of an apparatus and a terminal to which it is applied.

[0067] like Figure 4 As shown, Figure 4 This is a structural diagram of an electronic device 400 shown in this specification according to an exemplary embodiment. At the hardware level, the device includes a processor 402, an internal bus 404, a network interface 406, a memory 408, and a non-volatile memory 410, and of course may also include hardware required for other services. One or more embodiments of this specification can be implemented based on software, such as the processor 402 reading the corresponding computer program from the non-volatile memory 410 into the memory 408 and then running it. Of course, in addition to software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic module, but can also be hardware or logic devices.

[0068] like Figure 5 As shown, Figure 5 This specification shows a message filtering device according to an exemplary embodiment. The message filtering device is set on any CAN bus connected to the domain controller of any functional domain of the vehicle, and the messages transmitted between the domain controller and each functional unit connected to any CAN bus pass through the message filtering device. The device can be used for Figure 4 The electronic device 400 shown in the figure implements the technical solution of this specification. The device includes:

[0069] The comparison module 502 is configured to obtain and parse the message transmitted on the CAN bus, and compare the target field value of the message with the corresponding target filtering condition.

[0070] The interception module 504 is configured to intercept the message if the target field value does not match the target filtering condition.

[0071] Optionally, the target filtering condition includes a node identifier of each functional unit, and the target field value matches the target filtering condition, including: the message identifier of the message is the same as any node identifier.

[0072] Optionally, the target filtering condition includes a sensitive node identifier of a sensitive functional unit and a corresponding safe numerical range, and the target field value matches the target filtering condition, including: the message identifier of the message is the same as the sensitive node identifier and the value of the data field of the message is within the safe numerical range; or, the message identifier of the message is different from the sensitive node identifier.

[0073] Optionally, the target filtering condition includes a non-critical node identifier of a non-critical functional unit and an instruction code of a sensitive diagnostic instruction, and the target field value matches the target filtering condition, including: when it is determined that the vehicle is in a driving state, the message identifier of the message is the same as the non-critical node identifier and the instruction field of the message contains the instruction code.

[0074] Optionally, the sensitive diagnostic instruction includes a reset instruction and / or a programming session instruction.

[0075] Optionally, the target filtering condition includes an emergency filtering condition, the emergency filtering condition including a specific node identifier of a specific functional unit. The apparatus further includes a load rate detection module 506 configured to determine a load rate of the CAN bus within a preset time period and activate the emergency filtering condition when the load rate exceeds a load rate threshold. The target field value matching the emergency filtering condition includes: the message identifier of the message being the same as the specific node identifier.

[0076] Optionally, the target filtering condition includes an emergency filtering condition, wherein the emergency filtering condition includes a specific node identifier of a specific functional unit. The apparatus further includes a node ratio detection module 508 for determining the ratio of the number of messages of each node to the total number of nodes on the CAN bus within a preset time period, and activating the emergency filtering condition when the message ratio of any node exceeds a normal ratio threshold. The target field value matches the emergency filtering condition when: the message identifier of the message is the same as the specific node identifier.

[0077] Optionally, the target filtering condition includes an emergency filtering condition, the emergency filtering condition including a specific node identifier of a specific functional unit. The apparatus further includes a node data change rate detection module 510 configured to determine a data change rate between adjacent messages belonging to the same node on the CAN bus, and to initiate the emergency filtering condition when the data change rate exceeds a change rate threshold. The target field value matching the emergency filtering condition includes: the message identifier of the message being the same as the specific node identifier.

[0078] Optionally, the target filtering condition includes an emergency filtering condition, the emergency filtering condition includes a specific node identifier of a specific functional unit, and the device further includes a multi-level detection module 512 for determining the load rate of the CAN bus within a preset time period, and activating the emergency filtering condition when the load rate is greater than a load rate threshold; and, if the load rate is less than the load rate threshold, determining the ratio of the number of messages of each node of the CAN bus to the total number of nodes within the preset time period, and activating the emergency filtering condition when the message ratio of any node exceeds a normal ratio threshold; and, if the message ratio of any node is less than the normal ratio threshold, determining the data change rate between adjacent messages belonging to the same node on the CAN bus, and activating the emergency filtering condition when the data change rate exceeds the change rate threshold. The target field value matches the emergency filtering condition, including: the message identifier of the message is the same as the specific node identifier.

[0079] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0080] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to the partial description of the method embodiments. The device embodiments described above are only schematic, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the scheme of this specification. Those of ordinary skill in the art can understand and implement it without paying any creative work.

[0081] This specification provides a vehicle equipped with a message filtering device, which is used to implement the steps of the intrusion detection and defense method for the vehicle-mounted CAN bus of any of the aforementioned embodiments.

[0082] This specification also provides a computer-readable storage medium having a computer program stored thereon. When the program is executed by a processor, the steps of any of the aforementioned intrusion detection and defense methods for the vehicle-mounted CAN bus provided in this application are implemented.

[0083] Specifically, computer-readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including, for example, semiconductor memory devices (such as EPROM, EEPROM and flash memory devices), magnetic disks (such as internal hard disks or removable disks), magneto-optical disks, and CD ROM and DVD-ROM disks.

Claims

1. A method for intrusion detection and defense against vehicle-mounted CAN bus, characterized in that: The method is applied to a message filtering device, which is provided on any CAN bus connected to a domain controller of any functional domain of a vehicle, and messages transmitted between the domain controller and each functional unit connected to the any CAN bus pass through the message filtering device. The method includes: Acquire and parse the message transmitted on the CAN bus, and compare the target field value of the message with the corresponding target filtering condition; If the target field value does not match the target filtering condition, the message is intercepted.

2. The method according to claim 1, characterized in that The target filtering condition includes the node identifier of each functional unit, and the target field value matches the target filtering condition, including: The message identifier of the message is the same as any node identifier.

3. The method according to claim 1, characterized in that The target filtering condition includes a sensitive node identifier of a sensitive functional unit and a corresponding safe numerical range, and the target field value matches the target filtering condition, including: The message identifier of the message is the same as the sensitive node identifier and the value of the data field of the message is within the safe numerical range; or, The message identifier of the message is different from the sensitive node identifier.

4. The method according to any one of claims 1 to 3, characterized in that The target filtering condition includes a non-critical node identifier of a non-critical functional unit and an instruction code of a sensitive diagnostic instruction, and the target field value matches the target filtering condition, including: When it is determined that the vehicle is in a driving state, the message identifier of the message is the same as the non-critical node identifier and the instruction field of the message includes the instruction code.

5. The method according to claim 4, characterized in that The sensitive diagnostic instructions include reset instructions and / or programming session instructions.

6. The method according to claim 1, characterized in that The target filtering condition includes an emergency filtering condition, and the emergency filtering condition includes a specific node identifier of a specific functional unit. The method further includes: determining a load rate of the CAN bus within a preset time period, and initiating the emergency filtering condition when the load rate is greater than a load rate threshold; The target field value matches the emergency filtering condition, including: the message identifier of the message is the same as the specific node identifier.

7. The method according to claim 1, characterized in that The target filtering condition includes an emergency filtering condition, and the emergency filtering condition includes a specific node identifier of a specific functional unit. The method further includes: determining a ratio of the number of messages of each node to the total number of nodes of the CAN bus within a preset time period, and activating the emergency filtering condition when the message ratio of any node exceeds a normal ratio threshold; The target field value matches the emergency filtering condition, including: the message identifier of the message is the same as the specific node identifier.

8. The method according to claim 1, characterized in that The target filtering condition includes an emergency filtering condition, and the emergency filtering condition includes a specific node identifier of a specific functional unit. The method further includes: determining a data change rate between adjacent messages belonging to the same node on the CAN bus, and initiating the emergency filtering condition when the data change rate exceeds a change rate threshold; The target field value matches the emergency filtering condition, including: the message identifier of the message is the same as the specific node identifier.

9. The method according to claim 1, characterized in that The target filtering condition includes an emergency filtering condition, and the emergency filtering condition includes a specific node identifier of a specific functional unit. The method further includes: determining a load rate of the CAN bus within a preset time period, and activating the emergency filtering condition when the load rate is greater than a load rate threshold; and If the load rate is less than the load rate threshold, determining the ratio of the number of messages of each node to the total number of nodes of the CAN bus within a preset time period, and activating the emergency filtering condition when the message ratio of any node exceeds the normal ratio threshold; and If the message ratio of any node is less than a normal ratio threshold, determining a data change rate between adjacent messages belonging to the same node on the CAN bus, and activating the emergency filtering condition if the data change rate exceeds the change rate threshold; The target field value matches the emergency filtering condition, including: the message identifier of the message is the same as the specific node identifier.

10. A message filtering device, characterized in that: The message filtering device is arranged on any CAN bus connected to the domain controller of any functional domain of the vehicle, and the messages transmitted between the domain controller and each functional unit connected to any CAN bus pass through the message filtering device. The message filtering device is used to implement the steps of the method as described in any one of claims 1 to 9.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method according to any one of claims 1 to 9 are implemented.

12. A vehicle, characterized in that: The vehicle is equipped with a message filtering device, which is used to implement the steps of the method according to any one of claims 1 to 9.