Method, device and equipment for detecting attacks on a can bus

By mapping the CAN identifier and message type of CAN messages and calculating the information entropy, the problem of flooding attacks and small-scale replay attacks that cannot be identified in the existing technology is solved, and more accurate attack detection is achieved.

CN120896799BActive Publication Date: 2025-12-26CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511433813.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-09
Publication Date
2025-12-26
Estimated Expiration
2045-10-09

AI Technical Summary

Technical Problem

Existing CAN bus attack detection methods cannot effectively identify flood attacks that spoof high-priority CAN IDs and small-scale replay attacks.

Method used

By mapping the CAN identifier and message type of each CAN message, a symbolic representation is obtained, information entropy is calculated, and the attack detection result is determined based on the target information entropy, the reference entropy value, and the preset entropy threshold, thereby improving the statistical granularity of information entropy.

Benefits of technology

It can accurately detect flood attacks and small-scale replay attacks that spoof high-priority CAN IDs, thus improving detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120896799B_ABST
    Figure CN120896799B_ABST
Patent Text Reader

Abstract

The application discloses a CAN bus attack detection method, device and equipment, and relates to the technical field of computers. The method comprises the following steps: acquiring a plurality of CAN message messages on a CAN bus within a target time length, and determining the CAN identifier and message type of each CAN message message; mapping the CAN identifier and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message; determining the information entropy of each CAN message message within the target time length based on the symbolic representation corresponding to each CAN message message, and determining the target information entropy of the CAN bus based on the plurality of information entropies; and determining the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy value threshold. The method can detect flooding attacks and a small number of replay attacks disguised as high-priority CAN IDs.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a CAN bus attack detection method, device and equipment. BACKGROUND

[0002] In a Controller Area Network (CAN) network environment, the entropy of data traffic is an important indicator for detecting abnormal behavior. When a Distributed Denial-of-Service (DDoS) attack is encountered, a large number of malicious data streams flow into the network, causing the traffic distribution to become chaotic and the randomness to increase. At this time, the traffic entropy value will increase significantly. Therefore, by continuously monitoring the change of the entropy value, the traffic anomaly can be identified in time, thereby providing effective early warning support for the network security protection system.

[0003] At present, the CAN bus attack detection method based on information entropy mainly focuses on the distribution characteristics of CAN IDentity (ID) or the number of message statistics dimensions, and on this basis, the flooding attack and the replay attack are detected and studied. However, this method cannot effectively identify the flooding attack disguised as high priority CAN ID and the small number of replay attacks.

[0004] Therefore, how to detect the flooding attack disguised as high priority CAN ID and the small number of replay attacks has become a problem to be solved. SUMMARY

[0005] The embodiments of the present application provide a CAN bus attack detection method, device and equipment, which can detect the flooding attack disguised as high priority CAN ID and the small number of replay attacks.

[0006] In a first aspect, the embodiments of the present application provide a CAN bus attack detection method, which comprises:

[0007] Obtaining a plurality of CAN message messages on the CAN bus within a target time length, and determining the CAN IDentity and message type of each CAN message message;

[0008] Mapping the CAN IDentity and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message;

[0009] Determining the information entropy of each CAN message message within the target time length based on the symbolic representation corresponding to each CAN message message, and determining the target information entropy of the CAN bus based on a plurality of information entropies;

[0010] determine the attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus, and a first preset entropy value threshold; the first reference entropy value is determined based on a plurality of CAN bus information entropies corresponding to the CAN bus in a target time length under a normal working condition.

[0011] In one of the embodiments, the determining the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy value threshold comprises at least one of the following: determining the attack detection result for the CAN bus as the CAN bus being attacked in a case that a difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy value threshold; and determining the attack detection result for the CAN bus as the CAN bus not being attacked in a case that the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy value threshold.

[0012] In one of the embodiments, the method further comprises: obtaining a plurality of CAN bus information entropies respectively corresponding to the CAN bus in a plurality of time lengths under a normal working condition; for each time length, selecting a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to the time length, and determining a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy differences less than a preset difference value from the CAN bus information entropy differences respectively corresponding to the plurality of time lengths; and determining the first preset entropy value threshold based on a maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences.

[0013] In one of the embodiments, after the determining the attack detection result for the CAN bus, the method further comprises at least one of the following: determining that a CAN controller corresponding to each CAN message is attacked in a case that a difference between an information entropy of the CAN message in a target time length and a second reference entropy value is greater than a second preset entropy value threshold; the CAN controller is associated with a CAN identifier; and the second reference entropy value is determined based on a plurality of identifier information entropies corresponding to the CAN message in the target time length under a normal working condition; and determining that the CAN controller corresponding to each CAN message is not attacked in a case that the difference between the information entropy of the CAN message in the target time length and the second reference entropy value is less than or equal to the second preset entropy value threshold; the CAN controller is associated with the CAN identifier; and the second reference entropy value is determined based on the plurality of identifier information entropies corresponding to the CAN message in the target time length under the normal working condition.

[0014] In one of the embodiments, the method further comprises: obtaining, under normal working conditions, a plurality of identifier information entropies corresponding to each of the symbolic representations of the CAN message in the target time length; for each CAN message, selecting a maximum identifier information entropy and a minimum identifier information entropy from the plurality of identifier information entropies, and determining an identifier information entropy difference between the maximum identifier information entropy and the minimum identifier information entropy; determining the second preset entropy threshold based on a maximum identifier information entropy difference in the identifier information entropy differences corresponding to the plurality of CAN message.

[0015] In one of the embodiments, the method further comprises: obtaining, under normal working conditions, a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths; for each time length, selecting a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies, and determining a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy differences less than the preset difference from the CAN bus information entropy differences corresponding to the plurality of time lengths; and taking a time length corresponding to a minimum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences as the target time length.

[0016] In one of the embodiments, the information entropy of each CAN message in the target time length is determined based on the symbolic representation corresponding to each CAN message, comprising: determining the occurrence probability and the self-information of each CAN message in the target time length based on the symbolic representation corresponding to each CAN message; and determining the information entropy of each CAN message in the target time length according to the occurrence probability and the self-information corresponding to each CAN message.

[0017] In one of the embodiments, the occurrence probability and the self-information of each CAN message in the target time length are determined based on the symbolic representation corresponding to each CAN message, comprising: determining the transmission period of each CAN message corresponding to each symbolic representation in the target time length, and the total number of symbolic representations; determining the occurrence probability of each CAN message in the target time length based on the transmission period of each CAN message corresponding to each symbolic representation in the target time length, the target time length, and the total number of symbolic representations; and determining the self-information of each CAN message in the target time length based on the occurrence probability corresponding to each CAN message.

[0018] In a second aspect, the embodiments of the present application provide a CAN bus attack detection device, which comprises:

[0019] An acquisition and determination module is configured to acquire a plurality of CAN message in a target time length on a CAN bus, and determine a CAN identifier and a message type of each CAN message;

[0020] A processing module is configured to map the CAN identifier and the message type of each CAN message to obtain a symbolic representation of each CAN message;

[0021] A determination module is configured to determine an information entropy of each CAN message in the target time length based on the symbolic representation of each CAN message, and determine a target information entropy of the CAN bus based on the plurality of information entropies.

[0022] The determination module is further configured to determine an attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus, and a first preset entropy threshold value. The first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the target time length under a normal working condition.

[0023] In a third aspect, an apparatus is provided, which includes a memory and a processor. The memory stores a computer program. The processor implements the steps of the method provided in the first aspect when executing the computer program.

[0024] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program. The computer program is executed by a processor to implement the steps of the method provided in the first aspect.

[0025] In a fifth aspect, a computer program product is provided, which includes a computer program. The computer program is executed by a processor to implement the steps of the method provided in the first aspect.

[0026] The CAN bus attack detection method, device and equipment described above obtain a plurality of CAN message packets on the CAN bus within a target time length, and determine the CAN identifier and message type of each CAN message packet; map the CAN identifier and message type corresponding to each CAN message packet to obtain the symbolic representation corresponding to each CAN message packet; determine the information entropy of each CAN message packet within the target time length based on the symbolic representation corresponding to each CAN message packet, and determine the target information entropy of the CAN bus based on the plurality of information entropies; determine the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy threshold value. The first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions. With this method, the symbolic representation corresponding to each CAN message packet is obtained by mapping the CAN identifier and message type corresponding to each CAN message packet before information entropy calculation. In this way, in the case where the same CAN identifier (corresponding to one CAN controller) corresponds to multiple message types, the CAN message packets can be divided in a finer granularity by introducing the message type of the CAN message packet, so that the information entropy of the plurality of CAN message packets on the CAN bus within the target time length can be statistically calculated in a finer granularity, and a more accurate target information entropy of the CAN bus can be determined. Then, based on the more accurate target information entropy of the CAN bus, the attack detection result for the CAN bus can be accurately determined. In this way, compared with the traditional CAN identifier and CAN message packet quantity statistical dimension, the method of detecting the flooding attack and the replay attack of the CAN bus based on information entropy can detect the flooding attack and the replay attack disguised as high-priority CAN ID because the statistical granularity of the information entropy of the plurality of CAN message packets on the CAN bus within the target time length is improved. BRIEF DESCRIPTION OF DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other related drawings can be obtained by those skilled in the art without creative labor.

[0028] Figure 1 is a flowchart of a CAN bus attack detection method provided by an embodiment of the present application;

[0029] Figure 2 is a process diagram of a symbolic representation provided by an embodiment of the present application;

[0030] Figure 3 is a schematic diagram of CAN bus information entropy corresponding to different time lengths provided by an embodiment of the present application;

[0031] Figure 4 is a flowchart of another CAN bus attack detection method provided by an embodiment of the present application;

[0032] Figure 5 is a calibration process schematic diagram of CAN bus attack detection provided by an embodiment of the present application;

[0033] Figure 6 is a structure schematic diagram of a CAN bus attack detection device provided by an embodiment of the present application;

[0034] Figure 7 is a structure schematic diagram of a computer device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solutions and advantages of the present application clearer, the present application is further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0036] In a CAN network environment, the entropy of data flow is an important indicator for detecting abnormal behavior. When encountering a DDoS attack, a large number of malicious data flows pour into the network, causing the flow distribution to tend to be chaotic and the randomness to increase. At this time, the flow entropy value will increase significantly. Therefore, by continuously monitoring the change of the entropy value, the flow anomaly can be identified in time, thereby providing effective early warning support for the network security protection system.

[0037] At present, the CAN bus attack detection method based on information entropy mainly focuses on the distribution characteristics of CAN ID (IDentity, ID) or the number of message statistics dimensions, and on this basis, the flooding attack and the replay attack are detected and studied. However, this method has the following defects:

[0038] (1) It is assumed that the CAN ID of the flooding attack message is 0x00, and the identification rate of information entropy is higher through CAN ID type statistics. Unlike Ethernet, the message sending of CAN bus is in broadcast mode. If the CAN ID of the flooding attack message is disguised as a highest priority CAN ID in the CAN bus, the information entropy value based on CAN ID statistics may not change much, thereby causing the flooding attack to be unable to be identified.

[0039] (2) For replay attacks, a certain number of replay attacks are required to be detected, however, replay attacks are generally of a deceptive nature and cannot be sent in large quantities, in which case the recognition rate of detecting replay attacks is not high.

[0040] Based on this, the embodiment of the application provides a CAN bus attack detection method, device and equipment. The method comprises the following steps: determining the CAN identifier and message type of each CAN message on the CAN bus in a target time period; mapping the CAN identifier and message type of each CAN message to obtain the symbolic representation of each CAN message; determining the target information entropy of the CAN bus based on the symbolic representation of each CAN message; determining the attack detection result of the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy threshold value. The first reference entropy value is obtained based on the plurality of CAN bus information entropies corresponding to the target time period of the CAN bus under normal working conditions. By mapping the CAN identifier and message type of each CAN message to obtain the symbolic representation of each CAN message before calculating the information entropy, the CAN message can be divided more finely by introducing the message type of the CAN message under the condition that the same CAN identifier (corresponding to one CAN controller) corresponds to multiple message types, so that the information entropy of the plurality of CAN messages on the CAN bus in the target time period can be more finely counted, and the target information entropy of the CAN bus can be more accurately determined. Furthermore, based on the more accurate target information entropy of the CAN bus, the attack detection result of the CAN bus can be accurately determined. Compared with the traditional CAN identifier and CAN message quantity statistical dimension, the method of detecting the flooding attack and replay attack of the CAN bus based on information entropy can detect the flooding attack of the disguised high priority CAN ID and the small amount of replay attack because the statistical granularity of the information entropy of the plurality of CAN messages on the CAN bus in the target time period is improved.

[0041] Optionally, the computer device mentioned above can be a terminal or a server. The terminal mentioned herein can include, but is not limited to, various personal computers, notebook computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things device can be a smart speaker, a smart television, a smart air conditioner, a smart vehicle-mounted device, a projection device, etc. The portable wearable device can be a smart watch, a smart bracelet, a head-mounted device, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, a cloud server providing cloud computing services, etc.

[0042] Optionally, the CAN bus attack detection method provided in the application can be applied to the vehicle CAN bus network in a vehicle.

[0043] The CAN bus attack detection method provided in the embodiment of the application is described below.

[0044] Please refer to Figure 1 , Figure 1 is a flowchart of a CAN bus attack detection method provided in the embodiment of the application. The method can be executed by a computer device. As shown in Figure 1 , the CAN bus attack detection method can include, but is not limited to, the following steps:

[0045] S101, acquiring a plurality of CAN message messages on the CAN bus within a target time length, and determining the CAN identifier and message type of each CAN message message.

[0046] The CAN bus is a serial communication bus used in real-time industrial control and automotive electronics, which uses twisted pair for communication and has the characteristics of high communication rate, strong reliability, and good real-time performance.

[0047] In the field of automotive electronics, the CAN bus is the underlying core infrastructure supporting all modern automotive electronics and intelligent functions. The CAN bus allows multiple electronic control units (ECU) to send and receive multiple message messages on the same network at the same time.

[0048] The CAN message is a data packet transmitted on the CAN bus, and contains all information to be transmitted. The CAN message can include a CAN identifier, a data length code (DLC) of the CAN message, and data (DATA). The CAN identifier corresponds to a CAN controller, and the DLC is used to indicate the number of bytes contained in the data field of a CAN message.

[0049] In some embodiments, the target time length can be determined in advance based on historical data. For example, the target time length is 12s.

[0050] In some embodiments, each CAN message can have one or more message types. For example, the message types include a message for raising a window, a message for lowering a window, a message for closing a door, a message for opening a door, and the like.

[0051] In some embodiments, the computer device determines the CAN identifier and the message type of each CAN message by parsing each CAN message to obtain a parsing result, and determining the CAN identifier and the message type of each CAN message from the respective parsing result of each CAN message.

[0052] S102, mapping the CAN identifier and the message type corresponding to each CAN message to obtain a symbolic representation corresponding to each CAN message.

[0053] The symbolic representation can also be referred to as an identifier.

[0054] For example, please refer to Figure 2 , Figure 2 is a process diagram of a symbolic representation provided by an embodiment of the present application. As shown in Figure 2 , for each CAN message, first, the computer device can parse the CAN message to obtain a CAN identifier, a data length code, a message type, and data; second, the computer device can select data with less variability and regularity from the CAN identifier, the data length code, the message type, and the data, i.e., the CAN identifier and the message type; and third, the computer device can map the CAN identifier and the message type to obtain a symbolic representation (or unique identifier) corresponding to the CAN message.

[0055] S103, determining the information entropy of each CAN message within the target time length based on the symbolic representation corresponding to each CAN message, and determining the target information entropy of the CAN bus based on the plurality of information entropies.

[0056] In some embodiments, the computer device determines the information entropy of each CAN message within the target time length based on the respective symbolized representation of each CAN message, which can be based on the respective symbolized representation of each CAN message and the transmission period of each CAN message within the target time length.

[0057] In some embodiments, the computer device determines the target information entropy of the CAN bus based on the plurality of information entropies, which can be the sum of the plurality of information entropies as the target information entropy of the CAN bus.

[0058] Optionally, when determining the target information entropy of the CAN bus based on the plurality of information entropies, the computer device can use the following formula (1).

[0059] (1)

[0060] In formula (1), E represents all CAN messages on the CAN bus obtained by the computer device within the target time length, i is an integer greater than or equal to 1 and less than n, and n represents the number of symbolized sequences, wherein, represents the CAN message corresponding to the i-th symbolized representation; H(E) represents the target information entropy of the CAN bus; represents the represents the self-information of the CAN message corresponding to the i-th symbolized representation within the target time length T; H i represents the information entropy of the CAN message corresponding to the i-th symbolized sequence within the target time length.

[0061] S104, based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy value threshold, determine the attack detection result for the CAN bus; the first reference entropy value is obtained based on the plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions.

[0062] In some embodiments, the first reference entropy value can be an average entropy value obtained by the computer device performing average processing on the plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions.

[0063] In some embodiments, the preset entropy value threshold can be determined based on the plurality of historical CAN messages corresponding to the CAN bus under normal working conditions, based on expert experience, based on multiple tests, etc., which is not limited here.

[0064] In the embodiments of the present application, the computer device can acquire a plurality of CAN message messages on the CAN bus within a target time length by using the CAN bus attack detection method, device and equipment, and determine the CAN identifier and message type of each CAN message message; map the CAN identifier and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message; determine the information entropy of each CAN message message within the target time length based on the symbolic representation corresponding to each CAN message message, and determine the target information entropy of the CAN bus based on the plurality of information entropies; and determine the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy value threshold. The first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions. By mapping the CAN identifier and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message before calculating the information entropy, the CAN message messages can be divided in a finer granularity by introducing the message type of the CAN message message in the case where the same CAN identifier (corresponding to one CAN controller) corresponds to a plurality of message types, so that the information entropy of the plurality of CAN message messages on the CAN bus within the target time length can be statistically calculated in a finer granularity, and a more accurate target information entropy of the CAN bus can be determined. Then, based on the more accurate target information entropy of the CAN bus, the attack detection result for the CAN bus can be accurately determined. Thus, compared with the traditional CAN identifier and CAN message message quantity statistical dimension, the method of detecting the flooding attack and the replay attack of the CAN bus based on the information entropy can detect the flooding attack and the replay attack disguised as high-priority CAN ID due to the improved statistical granularity of the information entropy of the plurality of CAN message messages on the CAN bus within the target time length.

[0065] In an alternative embodiment, Figure 1 The step S104 in the CAN bus attack detection method, i.e., the computer device determines the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus and the first preset entropy value threshold, can include at least one of the following: in the case where the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy value threshold, determining that the attack detection result for the CAN bus is that the CAN bus is attacked; and in the case where the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy value threshold, determining that the attack detection result is that the CAN bus is not attacked.

[0066] In some embodiments, the first reference entropy value can be an average entropy value obtained by averaging a plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions by the computer device.

[0067] The plurality of CAN bus information entropies can be obtained by the computer device based on a plurality of tests performed within the target time length.

[0068] That is, the computer device determines the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy threshold value, which can include the following three cases:

[0069] Case one: when the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy threshold value, the attack detection result for the CAN bus is determined to be that the CAN bus is attacked.

[0070] In this case, the computer device can be pre-configured with a trigger condition (denoted as trigger condition 1) for determining the attack detection result for the CAN bus to be that the CAN bus is attacked, i.e., the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy threshold value.

[0071] It can be understood that in this case, the computer device can only determine the attack detection result for the CAN bus to be that the CAN bus is attacked when it is determined that the trigger condition 1 is met. As for what the attack detection result for the CAN bus is when the trigger condition 1 is not met, the computer device does not care.

[0072] Case two: when the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy threshold value, the attack detection result is determined to be that the CAN bus is not attacked.

[0073] In this case, the computer device can be pre-configured with a trigger condition (denoted as trigger condition 2) for determining the attack detection result to be that the CAN bus is not attacked, i.e., the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy threshold value.

[0074] It can be understood that in this case, the computer device can only determine the attack detection result for the CAN bus to be that the CAN bus is not attacked when it is determined that the trigger condition 2 is met. As for what the attack detection result for the CAN bus is when the trigger condition 2 is not met, the computer device does not care.

[0075] In a third case, if the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy threshold, it is determined that the attack detection result for the CAN bus is that the CAN bus is attacked; if the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy threshold, it is determined that the attack detection result is that the CAN bus is not attacked.

[0076] In this case, the computer device can be preconfigured with a trigger condition 1 for determining that the attack detection result for the CAN bus is that the CAN bus is attacked, and a trigger condition 2 for determining that the attack detection result is that the CAN bus is not attacked.

[0077] It can be understood that in this case, the computer device can not only know under what circumstances the CAN bus is determined to be attacked, but also know under what circumstances the CAN bus is determined to be not attacked.

[0078] In some embodiments, the first preset entropy threshold can be determined by the computer device in the following manner: obtaining a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under normal working conditions; for each time length, selecting a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to the time length, and determining the CAN bus information entropy difference between the maximum CAN bus information entropy and the minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy differences that are less than a preset difference value from the CAN bus information entropy differences corresponding to the plurality of time lengths; and determining the first preset entropy threshold based on the maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences.

[0079] Optionally, the minimum time length in the plurality of time lengths can be 1s; and the plurality of time lengths can be obtained by gradually reducing a preconfigured reference time length by a preset step length. For example, assuming that the preconfigured reference time length is 15s and the preset step length is 3, in this case, the computer device can obtain the plurality of time lengths as follows: 15s, 12s, 9s, 6s, 3s, and 1s.

[0080] Optionally, the plurality of CAN bus information entropies corresponding to the CAN bus in each time length under normal working conditions can be obtained by the computer device based on multiple tests, wherein each test corresponds to one CAN bus information entropy; or the plurality of CAN bus information entropies can be obtained after the computer device time-slices each time length to obtain a plurality of time slices, and then obtains the plurality of CAN bus information entropies based on the CAN bus information entropy corresponding to each time slice.

[0081] Optionally, the computer device selects, for each time length, a plurality of candidate CAN bus information entropies from the corresponding plurality of CAN bus information entropies, which can be selecting, for each time length, a plurality of CAN bus information entropies satisfying a corresponding selection condition from the corresponding plurality of CAN bus information entropies as the plurality of candidate CAN bus information entropies.

[0082] The corresponding selection condition can be selecting CAN bus information entropies in a preset CAN bus information entropy range, or selecting a plurality of CAN bus information entropies with stable fluctuations in a continuous period of time, and the like, which is not limited here.

[0083] Optionally, the computer device determines a first preset entropy value threshold based on the maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences, which can be taking a value greater than the maximum candidate CAN bus information difference in the plurality of candidate CAN bus information entropy differences and less than or equal to a preset difference value as the first preset entropy value threshold.

[0084] For example, assuming that each time length includes 15s, 12s, 9s, 6s, 3s, and 1s, and the number of trials corresponding to each time length is 30, each time length can correspond to 30 CAN bus information entropies. Assuming that the schematic diagram of the 30 CAN bus information entropies corresponding to each time length is as shown in FIG. 7, Figure 3 Figure 3 which is a schematic diagram of CAN bus information entropies corresponding to different time lengths provided by an embodiment of the present application. In this case, first, for each time length, the computer device can select the 7th CAN bus information entropy to the 30th CAN bus information entropy from the corresponding 30 CAN bus information entropies as a plurality of candidate CAN bus information entropies.

[0085] Second, the computer device can determine, based on the plurality of candidate CAN bus information entropies corresponding to each time length, the maximum CAN bus information entropy, the minimum CAN bus information entropy, the average entropy value, and the difference between the maximum CAN bus information entropy and the minimum CAN bus information entropy corresponding to each time length. For example, the maximum CAN bus information entropy, the minimum CAN bus information entropy, the average entropy value, and the difference between the maximum CAN bus information entropy and the minimum CAN bus information entropy corresponding to each time length can be as shown in Table 1.

[0086] Table 1: CAN bus information entropy statistical data table corresponding to each time length

[0087]

[0088] ​Afterwards, assuming that the preset difference value is 0.01, the computer device can determine, from the 6 difference values in Table 1, the difference values less than 0.01, i.e. 15s, 12s, 9s and 6s correspond to 4 difference values (i.e. 0.009, 0.002, 0.007, 0.008) respectively; finally, the computer device can determine the first preset entropy value threshold based on the maximum value of 0.009, 0.002, 0.007 and 0.008. The first preset entropy value threshold can be a value greater than the maximum value of 0.009, 0.002, 0.007 and 0.008 and less than or equal to the preset difference value 0.01. For example, the first preset entropy value threshold is 0.01.

[0089] For example, assuming that the target time length is 12s, the first reference entropy value mentioned above can be the average entropy value corresponding to 12s in Table 1, i.e. 2.4154.

[0090] With this embodiment, the computer device can quickly and accurately determine the attack detection result for the CAN bus based on the target information entropy and the first preset entropy value threshold corresponding to the target information entropy.

[0091] In an alternative embodiment, Figure 1 In the CAN bus attack detection method shown, after step S104, i.e. after the computer device determines the attack detection result for the CAN bus, the method can further include at least one of the following: in the case that the difference between the information entropy of each CAN message in the target time length and the second reference entropy value is greater than the second preset entropy value threshold, determining that the CAN controller corresponding to the CAN message is attacked; the CAN controller is associated with the CAN identifier; the second reference entropy value is determined based on the plurality of identifier information entropies corresponding to the CAN message in the target time length under normal working conditions; in the case that the difference between the information entropy of each CAN message in the target time length and the second reference entropy value is less than or equal to the second preset entropy value threshold, determining that the CAN controller corresponding to the CAN message is not attacked; the CAN controller is associated with the CAN identifier; the second reference entropy value is determined based on the plurality of identifier information entropies corresponding to the CAN message in the target time length under normal working conditions.

[0092] In some embodiments, the second reference entropy value can be determined by the computer device based on the plurality of identifier information entropies corresponding to the CAN message in the target time length under normal working conditions.

[0093] The plurality of identifier information entropies can be obtained by the computer device based on multiple tests of the target time length.

[0094] That is, after the computer device determines the attack detection result for the CAN bus, the computer device can perform the operation corresponding to any of the following situations:

[0095] In a case where the difference between the information entropy of each CAN message and the second reference entropy value is greater than the second preset entropy threshold value, it is determined that the CAN controller corresponding to the CAN message is attacked.

[0096] In this case, the computer device can be pre-provided with a trigger condition (denoted as trigger condition A) for determining that the CAN controller corresponding to the CAN message is attacked, i.e., the difference between the information entropy of the CAN message and the second reference entropy value is greater than the second preset entropy threshold value.

[0097] It can be understood that in this case, the computer device can only determine that the CAN controller corresponding to the CAN message is attacked in a case where it is determined that the trigger condition A is met. As for whether the CAN controller corresponding to the CAN message is attacked in a case where the trigger condition A is not met, the computer device does not concern.

[0098] In a case where the difference between the information entropy of each CAN message and the second reference entropy value is less than or equal to the second preset entropy threshold value, it is determined that the CAN controller corresponding to the CAN message is not attacked.

[0099] In this case, the computer device can be pre-provided with a trigger condition (denoted as trigger condition B) for determining that the CAN controller corresponding to the CAN message is not attacked, i.e., the difference between the information entropy of the CAN message and the second reference entropy value is less than or equal to the second preset entropy threshold value.

[0100] It can be understood that in this case, the computer device can only determine that the CAN controller corresponding to the CAN message is not attacked in a case where it is determined that the trigger condition B is met. As for whether the CAN controller corresponding to the CAN message is attacked in a case where the trigger condition B is not met, the computer device does not concern.

[0101] In a case where the difference between the information entropy of each CAN message and the second reference entropy value is greater than the second preset entropy threshold value, it is determined that the CAN controller corresponding to the CAN message is attacked; and in a case where the difference between the information entropy of each CAN message and the second reference entropy value is less than or equal to the second preset entropy threshold value, it is determined that the CAN controller corresponding to the CAN message is not attacked.

[0102] In this case, the computer device can be pre-configured with a trigger condition A for determining that the CAN controller corresponding to the CAN message is attacked, and a trigger condition B for determining that the CAN controller corresponding to the CAN message is not attacked.

[0103] It can be understood that in this case, the computer device can not only know under what circumstances the CAN controller corresponding to the CAN message is attacked, but also know under what circumstances the CAN controller corresponding to the CAN message is not attacked.

[0104] In some embodiments, the second preset entropy threshold value can be determined by the computer device in the following manner: obtaining, under normal working conditions, a plurality of identifier information entropies corresponding to each CAN message within a target time length; for each CAN message, selecting a maximum identifier information entropy and a minimum identifier information entropy from the plurality of identifier information entropies, and determining an identifier information entropy difference between the maximum identifier information entropy and the minimum identifier information entropy; and determining the second preset entropy threshold value based on a maximum identifier information entropy difference among the identifier information entropy differences corresponding to the plurality of CAN messages.

[0105] The plurality of identifier information entropies can be obtained by the computer device through multiple tests based on the target time length. For example, assuming that the target time length is 12s and the number of tests is 30, the identifier information entropy statistical data corresponding to the target time length can be shown in Table 2.

[0106] Table 2 Identifier information entropy statistical data corresponding to a time length of 12s

[0107]

[0108] Based on Table 2, the computer device can determine that the identifier information entropy difference 0.0041 corresponding to the CAN message of the symbolic representation 74 within the time length of 12s is the maximum among the identifier information entropy differences corresponding to the CAN messages of the plurality of symbolic representations in Table 2. Then, the computer device can determine the second preset entropy threshold value based on 0.0041. The second preset entropy threshold value can be a value greater than 0.0041. For example, the second preset entropy threshold value can be 0.005.

[0109] In this embodiment, for the information entropy of each CAN message within the target time length, the computer device can quickly and accurately determine whether the CAN controller corresponding to each CAN message is attacked based on the information entropy and the second preset entropy threshold value corresponding to the plurality of information entropies.

[0110] In an alternative embodiment, Figure 1In the shown CAN bus attack detection method, the target time length can be determined by the computer device in the following manner: obtaining a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under normal working conditions; for each time length, selecting a plurality of candidate CAN bus information entropies from the corresponding plurality of CAN bus information entropies, and determining the CAN bus information entropy difference between the maximum CAN bus information entropy and the minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy differences less than a preset difference value from the CAN bus information entropy differences corresponding to the plurality of time lengths; and taking the time length corresponding to the minimum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences as the target time length.

[0111] In some embodiments, the computer device can select, for each time length, a plurality of candidate CAN bus information entropies from the corresponding plurality of CAN bus information entropies, which can be selecting, for each time length, a plurality of CAN bus information entropies satisfying a corresponding selection condition from the corresponding plurality of CAN bus information entropies as the plurality of candidate CAN bus information entropies.

[0112] The corresponding selection condition can be selecting CAN bus information entropies within a preset CAN bus information entropy range, or selecting a plurality of CAN bus information entropies stably fluctuating within a continuous period of time, etc., which is not limited here.

[0113] For example, assuming that the plurality of time lengths are 15s, 12s, 9s, 6s, 3s, and 1s, the CAN bus information entropy statistics corresponding to each time length can be as shown in Table 1, and the preset difference value is 0.01, the computer device can first determine the difference values less than 0.01 from the 6 difference values in Table 1, i.e., the 4 difference values (i.e., 0.009, 0.002, 0.007, and 0.008) corresponding to 15s, 12s, 9s, and 6s; then, the computer device can determine the time length corresponding to the minimum difference value (i.e., 0.02) in the selected 4 difference values, i.e., 12s, as the target time length.

[0114] With this embodiment, the computer device can quickly and accurately determine the target time length required for CAN bus attack detection.

[0115] In an alternative embodiment, Figure 1In step S103 of the CAN bus attack detection method shown, the computer device determines the information entropy of each CAN message within the target time length based on the respective symbolic representation of each CAN message, which can include: determining the occurrence probability and self-information of each CAN message within the target time length based on the respective symbolic representation of each CAN message; and determining the information entropy of each CAN message within the target time length according to the respective occurrence probability and self-information of each CAN message.

[0116] In some embodiments, the computer device determines the occurrence probability and self-information of each CAN message within the target time length based on the respective symbolic representation of each CAN message, which can be: determining the transmission period of each CAN message corresponding to each symbolic representation within the target time length, and the total number of symbolic representations; determining the occurrence probability of each CAN message within the target time length based on the transmission period of each CAN message corresponding to each symbolic representation within the target time length, the target time length, and the total number of symbolic representations; and determining the self-information of each CAN message within the target time length based on the respective occurrence probability of each CAN message.

[0117] Optionally, when the computer device determines the occurrence probability of each CAN message within the target time length based on the transmission period of each CAN message corresponding to each symbolic representation within the target time length, the target time length, and the total number of symbolic representations, the following formula (2) can be used.

[0118] (2)

[0119] In formula (2), T represents the target time length; represents the CAN message corresponding to the i-th symbolic representation; represents the represents the occurrence probability of the CAN message corresponding to the i-th symbolic representation within the target time length T; c i represents the transmission period of the CAN message corresponding to the i-th symbolic representation within the target time length T.

[0120] Optionally, when the computer device determines the self-information of each CAN message within the target time length based on the respective occurrence probability of each CAN message, the following formula (3) can be used.

[0121] (3)

[0122] In formula (3), represents the This represents the probability of the CAN message corresponding to the i-th symbolic representation appearing within the target duration T; It means This represents the self-information of the CAN message corresponding to the i-th symbolic representation within the target duration T.

[0123] Because of formula (3) It can be determined by the aforementioned formula (2). Therefore, formula (3) is equivalent to the following formula (4).

[0124] (4)

[0125] For the physical meaning of each parameter in formula (4), please refer to the explanation of the physical meaning of each parameter in formula (2) and formula (3) above, and it will not be repeated here.

[0126] In some embodiments, when a computer device determines the information entropy of each CAN message within a target duration based on the occurrence probability and self-information of each CAN message, the following formula (5) may be used.

[0127] (5)

[0128] In formula (5), H i The information entropy of the CAN message corresponding to the i-th symbolized sequence within the target duration is represented. It means The probability of the CAN message corresponding to the i-th symbolic representation appearing within the target duration T can be determined by the aforementioned formula (2); It means The self-information of the CAN message corresponding to the i-th symbolic representation within the target duration T can be determined by the aforementioned formula (4).

[0129] Using this implementation method, the information entropy of each CAN message on the CAN bus within a target duration can be accurately calculated based on the statistical analysis of CAN message messages on the CAN bus.

[0130] The following is combined Figure 4 This paper describes the overall process of the CAN bus attack detection method provided in the embodiments of this application. Please refer to [link / reference]. Figure 4 , Figure 4 This is a flowchart illustrating another CAN bus attack detection method provided in an embodiment of this application, which can be executed by a computer device. Figure 4 As shown, the CAN bus attack detection method may include, but is not limited to, the following steps.

[0131] S401, determine the target time length, the first reference entropy value, the first preset entropy value threshold, the second reference entropy value, and the second preset entropy value threshold.

[0132] In an optional embodiment, the process of determining the target time length, the first reference entropy value, the first preset entropy value threshold, the second reference entropy value, and the second preset entropy value threshold by the computer device can be regarded as a calibration process of CAN bus attack detection. In the calibration process, the computer device can collect message data from the CAN bus network simulating a real environment, then perform feature extraction and symbolization into unique identifiers, and in the time length T, the data set of information entropy is statistically obtained, and then the entropy value is calculated and the conclusion data is recorded. After multiple rounds of experiments, the experimental results are compared, analyzed and evaluated, and finally the target time length, the first reference entropy value, the first preset entropy value threshold (denoted as D e ), the second reference entropy value, and the second preset entropy value threshold (denoted as D i ) are determined.

[0133] The calibration process of CAN bus attack detection can be as shown in Figure 5 , and Figure 5 is a schematic diagram of the calibration process of CAN bus attack detection provided by an embodiment of the present application. As shown in Figure 5 , the computer device can first obtain, under normal working conditions, a plurality of CAN message information corresponding to the CAN bus in a plurality of time lengths under multiple tests (corresponding to the CAN bus data acquisition in Figure 5 ); then determine the CAN identifier and message type of each CAN message (corresponding to the CAN feature extraction in Figure 5 ); map the CAN identifier and message type corresponding to each CAN message to obtain the identifier corresponding to each CAN message (corresponding to the symbolization in Figure 5 ); then, based on the identifiers corresponding to the plurality of CAN message corresponding to the CAN bus in each time length under each test, determine the CAN bus entropy value corresponding to the CAN bus in a plurality of time lengths under each test, and based on the transmission period of the CAN message corresponding to each identifier in each time length under each test, determine the identifier information entropy of the CAN message corresponding to each identifier in each time length (corresponding to the data collection and entropy value calculation in Figure 5 ), so that a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under multiple tests, and a plurality of identifier information entropies corresponding to the CAN message corresponding to each identifier in each time length under multiple tests can be obtained.

[0134] Then, the computer device can perform result analysis on the result of the entropy value calculation to determine the target time length, the first reference entropy value, the first preset entropy threshold, the second reference entropy value, and the second preset entropy threshold.

[0135] In some embodiments, the computer device can determine the first reference entropy value, the first preset entropy threshold, and the target time length in the following manner: for each time length, select a plurality of candidate CAN bus information entropies from the corresponding plurality of CAN bus information entropies; take the average of the plurality of candidate CAN bus information entropies as the first reference entropy value; determine the maximum CAN bus information entropy and the minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies, and determine a plurality of candidate CAN bus information entropy differences that are less than a preset difference value from the CAN bus information entropy differences corresponding to the plurality of time lengths; determine the first preset entropy threshold based on the maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences, and take the time length corresponding to the minimum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences as the target time length.

[0136] In some embodiments, the computer device can determine the second reference entropy value in the following manner: take the average of the identifier information entropies of the CAN message corresponding to each identifier under the same time length (for example, 12s) as the second reference entropy value corresponding to the CAN message corresponding to each identifier under 12s.

[0137] In some embodiments, the computer device can determine the second preset entropy threshold in the following manner: obtain the plurality of identifier information entropies corresponding to each symbolized representation under each time length under normal working conditions; for each CAN message, select the maximum identifier information entropy and the minimum identifier information entropy from the plurality of identifier information entropies corresponding to the same time length (for example, 12s), and determine the identifier information entropy difference between the maximum identifier information entropy and the minimum identifier information entropy; determine the second preset entropy threshold corresponding to the CAN message corresponding to each identifier under the time length (12s) based on the maximum identifier information entropy difference in the plurality of identifier information entropy differences corresponding to the plurality of CAN messages under the time length (12s).

[0138] S402, obtain a plurality of CAN message on the CAN bus within a target time length, and determine the CAN identifier and the message type of each CAN message.

[0139] S403, map the CAN identifier and the message type corresponding to each CAN message to obtain the identifier corresponding to each CAN message.

[0140] In an optional implementation, the specific descriptions of steps S402 and S403 can refer to the descriptions of steps S101 and S102 respectively, and will not be repeated here.

[0141] S404, determining the occurrence probability and the self-information of each CAN message in the target time length based on the identifier corresponding to each CAN message.

[0142] In an optional implementation, the computer device can determine the occurrence probability of each CAN message in the target time length by using the foregoing formula (2).

[0143] In an optional implementation, the computer device can determine the self-information of each CAN message in the target time length by using the foregoing formula (4).

[0144] S405, determining the information entropy of each CAN message in the target time length according to the occurrence probability and the self-information corresponding to each CAN message.

[0145] In an optional implementation, the computer device can determine the information entropy of each CAN message in the target time length by using the foregoing formula (5).

[0146] S406, determining the target information entropy of the CAN bus based on the information entropy of each CAN message in the target time length.

[0147] In an optional implementation, the computer device can determine the target information entropy of the CAN bus by using the foregoing formula (1).

[0148] S407, determining whether the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than a first preset entropy threshold value, if yes, performing step S408, and if no, performing steps S409 to S411.

[0149] S408, determining that the attack detection result of the CAN bus is that the CAN bus is attacked, and recording first information, the first information being used to indicate that the CAN bus is attacked.

[0150] In some embodiments, after performing step S408, the computer device can further determine that the CAN controller corresponding to each CAN message in the target time length of the CAN bus is attacked, if the difference between the information entropy of the CAN message and the second reference entropy value is greater than a second preset entropy threshold value. That is, the computer device can further determine which CAN controller of the plurality of CAN controllers connected by the CAN bus is attacked, when determining that the CAN bus is attacked. In this way, the attacked CAN controller can be accurately determined.

[0151] It can be understood that, since the CAN controllers corresponding to the plurality of CAN message packets are communicated through the CAN bus, in the case that the CAN bus is attacked, there is no case that the CAN controller corresponding to each CAN message packet on the CAN bus is attacked.

[0152] S409, for each CAN message packet, determine whether the difference between the information entropy in the target time length and the second reference entropy value is greater than the second preset entropy threshold value, if yes, execute step S410; if not, execute step S413.

[0153] S410, determine that the CAN controller corresponding to the CAN message packet corresponding to the information entropy is attacked, and record the second information, the second information is used to indicate that the CAN controller corresponding to the CAN message packet corresponding to the information entropy is attacked.

[0154] S411, determine that the CAN bus and the CAN controller corresponding to each CAN message packet on the CAN bus are not attacked.

[0155] In the embodiments of the present application, the computer device can pre-calibrate a plurality of reference data for performing CAN bus attack detection, i.e., a target time length, a first reference entropy value, a first preset entropy threshold, a second reference entropy value, and a second preset entropy threshold. Then, in the process of performing CAN bus attack detection, the CAN identifier corresponding to each CAN message is obtained by mapping the CAN identifier and the message type of each CAN message before performing information entropy calculation. In this way, in the case where the same CAN identifier (corresponding to one CAN controller) corresponds to multiple message types, the CAN message can be divided in a finer granularity by introducing the message type of the CAN message. Thus, the information entropy of the plurality of CAN messages on the CAN bus within the target time length can be statistically calculated in a finer granularity, and a more accurate target information entropy of the CAN bus can be determined. Then, based on the more accurate target information entropy of the CAN bus and the pre-calibrated first preset entropy threshold, the attack detection result for the CAN bus can be accurately determined. In this way, compared with the traditional CAN identifier and the number of CAN messages, the method of performing flooding attack detection and replay attack detection on the CAN bus based on information entropy can detect the flooding attack and the replay attack disguised as high-priority CAN ID, because the statistical granularity of the information entropy of the plurality of CAN messages on the CAN bus within the target time length is improved. In addition, the computer device can also determine the difference between the information entropy of each CAN message within the target time length and the pre-calibrated second reference entropy value, and accurately determine the attacked CAN controller based on the difference and the pre-calibrated second preset entropy threshold.

[0156] It should be understood that, although each step in the flowchart involved in each embodiment as described above is shown in sequence according to the arrow, these steps are not necessarily executed in sequence according to the arrow. Unless otherwise specified herein, the execution of these steps is not strictly limited in sequence, and these steps can be executed in other sequences. Moreover, at least part of the steps in the flowchart involved in each embodiment as described above can include multiple steps or stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence of these steps or stages is not necessarily sequential, but can be executed in rotation or alternation with at least part of other steps or stages in other steps.

[0157] Based on the same inventive concept, the embodiments of the present application also provide a CAN bus attack detection device for implementing the CAN bus attack detection method described above. The implementation scheme of the device for solving the problem is similar to the implementation scheme described in the above method, so the specific limitations in one or more CAN bus attack detection device embodiments provided below can refer to the limitations of the CAN bus attack detection method described above, which will not be repeated here.

[0158] Please refer to Figure 6 , Figure 6 is a structure diagram of a CAN bus attack detection device provided by the embodiments of the present application. As Figure 6 indicated, the CAN bus attack detection device can include but is not limited to:

[0159] The acquisition and determination module 601 is configured to acquire a plurality of CAN message messages on the CAN bus within a target time length, and determine the CAN identifier and message type of each CAN message message.

[0160] The processing module 602 is configured to map the CAN identifier and message type corresponding to each CAN message message to obtain the symbolic representation corresponding to each CAN message message.

[0161] The determination module 603 is configured to determine the information entropy of each CAN message message within the target time length based on the symbolic representation corresponding to each CAN message message, and determine the target information entropy of the CAN bus based on the plurality of information entropies.

[0162] The determination module 603 is further configured to determine the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy value threshold. The first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the target time length of the CAN bus under normal working conditions.

[0163] In some embodiments, when the determination module 603 is configured to determine the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy value threshold, it is specifically configured to perform at least one of the following: in the case that the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy value threshold, determining that the attack detection result for the CAN bus is that the CAN bus is attacked; in the case that the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy value threshold, determining that the attack detection result is that the CAN bus is not attacked.

[0164] In some embodiments, the obtaining and determining module 601 is further configured to: obtain a plurality of CAN bus information entropies respectively corresponding to the CAN bus in a plurality of time lengths under a normal working condition; for each time length, select a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to the time length, and determine a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determine a plurality of candidate CAN bus information entropy differences less than a preset difference value from the CAN bus information entropy differences respectively corresponding to the plurality of time lengths; and determine a first preset entropy threshold value based on a maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences.

[0165] In some embodiments, after determining the attack detection result for the CAN bus, the determining module 603 is further configured to perform at least one of the following: determining that a CAN controller corresponding to each CAN message is attacked when a difference between an information entropy of the CAN message in a target time length and a second reference entropy value is greater than a second preset entropy threshold value, the CAN controller being associated with a CAN identifier, the second reference entropy value being determined based on a plurality of identifier information entropies corresponding to the CAN message in the target time length under a normal working condition; determining that the CAN controller corresponding to each CAN message is not attacked when the difference between the information entropy of the CAN message in the target time length and the second reference entropy value is less than or equal to the second preset entropy threshold value, the CAN controller being associated with the CAN identifier, the second reference entropy value being determined based on the plurality of identifier information entropies corresponding to the CAN message in the target time length under the normal working condition.

[0166] In some embodiments, the obtaining and determining module 601 is further configured to: obtain a plurality of identifier information entropies respectively corresponding to a CAN message corresponding to each symbolization in a target time length under a normal working condition; for each CAN message, select a maximum identifier information entropy and a minimum identifier information entropy from the plurality of identifier information entropies corresponding to the CAN message, and determine an identifier information entropy difference between the maximum identifier information entropy and the minimum identifier information entropy; and determine a second preset entropy threshold value based on a maximum identifier information entropy difference in the identifier information entropy differences respectively corresponding to the plurality of CAN messages.

[0167] In some embodiments, the acquisition and determination module 601 acquires a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under normal working conditions; for each time length, selects a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to the time length, and determines a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determines a plurality of candidate CAN bus information entropy differences less than a preset difference from the CAN bus information entropy differences corresponding to the plurality of time lengths; and takes a time length corresponding to a minimum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences as a target time length.

[0168] In some embodiments, the determination module 603, when determining the information entropy of each CAN message in the target time length based on the respective symbolized representation of each CAN message, is specifically configured to: determine the occurrence probability and the self-information of each CAN message in the target time length based on the respective symbolized representation of each CAN message; and determine the information entropy of each CAN message in the target time length according to the occurrence probability and the self-information of each CAN message.

[0169] In some embodiments, the determination module 603, when determining the occurrence probability and the self-information of each CAN message in the target time length based on the respective symbolized representation of each CAN message, is specifically configured to: determine the transmission period of each CAN message corresponding to each symbolized representation in the target time length, and the total number of symbolized representations; determine the occurrence probability of each CAN message in the target time length based on the transmission period of each CAN message corresponding to each symbolized representation in the target time length, the target time length, and the total number of symbolized representations; and determine the self-information of each CAN message in the target time length based on the occurrence probability of each CAN message.

[0170] It can be understood that the specific implementation of each module in the CAN bus attack detection device provided by the embodiments of the present application and the beneficial effects that can be achieved can refer to the description of the foregoing CAN bus attack detection method embodiments, which will not be described here.

[0171] Each module in the CAN bus attack detection device described above can be implemented in whole or in part by software, hardware, and combinations thereof. Each module described above can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the vehicle control device in software form, so as to be called and executed by the processor to perform the operations corresponding to each module.

[0172] In an exemplary embodiment, a computer device is provided, and an internal structure diagram of the computer device can be as follows:Figure 7 The computer device 700 shown in the figure includes a processor 701, a memory 702, an input / output interface 703, a communication interface 704, a display unit 705, and an input device 706. Among them, the processor 701, the memory 702, and the input / output interface 703 are connected through a system bus 707, and the communication interface 704, the display unit 705, and the input device 706 are connected to the system bus 707 through the input / output interface 703. Among them, the processor 701 of the new energy vehicle 700 is used to provide computing and control capabilities. The memory 702 of the new energy vehicle includes a non-volatile storage medium 7021 and an internal memory 7022. The non-volatile storage medium 7021 stores an operating system 7021a and a computer program 7021b. The internal memory 7022 provides an environment for the operating system 7021a and the computer program 7021b in the non-volatile storage medium 7021 to run. The input / output interface 703 of the new energy vehicle 700 is used to exchange information between the processor 701 and external devices. The communication interface 704 of the new energy vehicle 700 is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be achieved through WIFI, mobile cellular network, NFC (Near Field Communication) or other technologies. The computer program is executed by the processor to implement a CAN bus attack detection method. The display unit 7051 of the new energy vehicle is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the new energy vehicle can be a touch layer overlaid on the display screen, or a key, trackball or touchpad provided in the new energy vehicle.

[0173] Those skilled in the art can understand that Figure 7 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.

[0174] In one exemplary embodiment, the present application provides a computer device including a memory and a processor, the memory storing a computer program; the processor implements the steps of each of the CAN bus attack detection methods described above when executing the computer program.

[0175] In one exemplary embodiment, the present application provides a computer readable storage medium having a computer program stored thereon. The computer program is executed by the processor to implement the steps of each of the CAN bus attack detection methods described above.

[0176] In one example embodiment, the present application provides a computer program product comprising a computer program. The computer program is executed by a processor to implement the steps of the above CAN bus attack detection methods.

[0177] It can be understood by those skilled in the art that all or part of the processes in the above-mentioned embodiment methods can be completed by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. In the embodiments of the present application, any reference to memory, database or other medium can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments of the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments of the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.

[0178] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist, they should be considered as the scope of the present application.

[0179] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.

Claims

1. A method of CAN bus attack detection, characterized in that, The method comprises: acquiring a plurality of CAN message messages on a CAN bus within a target time length, and determining a CAN identifier and a message type of each of the CAN message messages; mapping the CAN identifier and the message type corresponding to each of the CAN message messages to obtain a symbolic representation corresponding to each of the CAN message messages; determining a transmission period of the CAN message message corresponding to each of the symbolic representations within the target time length, and a total number of the symbolic representations; determining an occurrence probability of each of the CAN message messages within the target time length based on the transmission period of the CAN message message corresponding to each of the symbolic representations within the target time length, the target time length, and the total number of the symbolic representations, and determining self-information of each of the CAN message messages within the target time length based on the occurrence probability corresponding to each of the CAN message messages; determining an information entropy of each of the CAN message messages within the target time length according to the occurrence probability and the self-information corresponding to each of the CAN message messages, and determining a target information entropy of the CAN bus based on a plurality of the information entropies; determining an attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus, and a first preset entropy value threshold; the first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the CAN bus within the target time length under a normal working condition.

2. The method of claim 1, wherein, Determining an attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus, and a first preset entropy value threshold comprises at least one of the following: in a case where a difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy value threshold, determining that the attack detection result for the CAN bus is that the CAN bus is attacked; in a case where the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy value threshold, determining that the attack detection result is that the CAN bus is not attacked.

3. The method of claim 2, wherein, The method further comprises: acquiring a plurality of CAN bus information entropies respectively corresponding to the CAN bus under a plurality of time lengths under a normal working condition; for each of the time lengths, selecting a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding thereto, and determining a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy differences less than a preset difference from the CAN bus information entropy differences respectively corresponding to the plurality of time lengths; determining the first preset entropy value threshold based on a maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences.

4. The method of claim 2, wherein, After determining the attack detection result for the CAN bus, the method further comprises at least one of the following: determining that the CAN controller corresponding to the CAN message is attacked in a case that a difference between the information entropy of each CAN message in the target time length and a second reference entropy value is greater than a second preset entropy threshold value; the CAN controller is associated with the CAN identifier; the second reference entropy value is determined based on a plurality of identifier information entropies corresponding to the CAN message in the target time length under a normal working condition; determining that the CAN controller corresponding to the CAN message is not attacked in a case that the difference between the information entropy of each CAN message in the target time length and the second reference entropy value is less than or equal to the second preset entropy threshold value; the CAN controller is associated with the CAN identifier; the second reference entropy value is determined based on a plurality of identifier information entropies corresponding to the CAN message in the target time length under a normal working condition.

5. The method of claim 4, wherein, The method further comprises: obtaining a plurality of identifier information entropies corresponding to each of the symbolic representations in the target time length under a normal working condition; selecting a maximum identifier information entropy and a minimum identifier information entropy from the plurality of identifier information entropies corresponding to each CAN message, and determining an identifier information entropy difference value of the maximum identifier information entropy and the minimum identifier information entropy; determining the second preset entropy threshold value based on a maximum identifier information entropy difference value in the identifier information entropy difference values corresponding to the plurality of CAN messages respectively.

6. The method according to any one of claims 1 to 5, characterized in that, The method further comprises: obtaining a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under a normal working condition; selecting a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to each time length, and determining a CAN bus information entropy difference value of a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determining a plurality of candidate CAN bus information entropy difference values less than a preset difference value from the CAN bus information entropy difference values corresponding to the plurality of time lengths respectively; taking a time length corresponding to a minimum candidate CAN bus information entropy difference value in the plurality of candidate CAN bus information entropy difference values as the target time length.

7. A CAN bus attack detection apparatus characterized by comprising: The device comprises: an acquisition and determination module configured to acquire a plurality of CAN messages on a CAN bus in a target time length, and determine a CAN identifier and a message type of each CAN message; a processing module configured to map the CAN identifier and the message type corresponding to each CAN message to obtain a symbolic representation corresponding to each CAN message; and a determination module configured to determine that the CAN controller corresponding to the CAN message is attacked in a case that a difference between the information entropy of each CAN message in the target time length and a second reference entropy value is greater than a second preset entropy threshold value; the CAN controller is associated with the CAN identifier; the second reference entropy value is determined based on a plurality of identifier information entropies corresponding to the CAN message in the target time length under a normal working condition. determining, by the determining module, a transmission period of each of the symbolic representations in the target time length, and a total number of the symbolic representations; determining, based on the transmission period of each of the symbolic representations in the target time length, the target time length, and the total number of the symbolic representations, an occurrence probability of each of the CAN message in the target time length, and determining, based on the occurrence probability of each of the CAN message, a self-information of each of the CAN message in the target time length; determining, according to the occurrence probability and the self-information of each of the CAN message, an information entropy of each of the CAN message in the target time length, and determining, based on the information entropy, a target information entropy of the CAN bus; The determining module is further configured to determine an attack detection result for the CAN bus based on the target information entropy, a first reference entropy value corresponding to the CAN bus, and a first preset entropy threshold value. The first reference entropy value is obtained based on a plurality of CAN bus information entropies corresponding to the target time length under a normal working condition.

8. The apparatus of claim 7, wherein, When the determining module is used to determine the attack detection result for the CAN bus based on the target information entropy, the first reference entropy value corresponding to the CAN bus, and the first preset entropy threshold value, the determining module is specifically configured to perform at least one of the following: In a case where a difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is greater than the first preset entropy threshold value, the attack detection result for the CAN bus is determined as the CAN bus being attacked. In a case where the difference between the target information entropy and the first reference entropy value corresponding to the CAN bus is less than or equal to the first preset entropy threshold value, the attack detection result is determined as the CAN bus not being attacked.

9. The apparatus of claim 7, wherein, The obtaining and determining module is further configured to: obtain a plurality of CAN bus information entropies corresponding to the CAN bus in a plurality of time lengths under a normal working condition; for each of the time lengths, select a plurality of candidate CAN bus information entropies from the plurality of CAN bus information entropies corresponding to the time length, and determine a CAN bus information entropy difference between a maximum CAN bus information entropy and a minimum CAN bus information entropy in the plurality of candidate CAN bus information entropies; determine a plurality of candidate CAN bus information entropy differences that are less than a preset difference value from the CAN bus information entropy differences corresponding to the plurality of time lengths; determine the first preset entropy threshold value based on a maximum candidate CAN bus information entropy difference in the plurality of candidate CAN bus information entropy differences.

10. A device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor, when executing the computer program, implements the steps of the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Vehicle-mounted CAN bus network abnormity detection method and system

    CN110275508A

  • CAN message data flow anomaly detection method, system, device, medium and product

    CN120185867A