An intrusion detection system construction apparatus and method that utilize intrusion detection rules applied to CAN communication
The proposed intrusion detection system construction method and device enhance the detection and processing of CAN messages by setting detection policy rules, addressing the limitations of existing systems in accurately and efficiently identifying potential attacks on vehicle networks.
Patent Information
- Application Number
- JP2024108297
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2023-09-13
- Filing Date
- 2024-07-04
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-07-04
AI Technical Summary
Existing intrusion detection systems for CAN communication struggle to accurately and efficiently detect and respond to potential attacks on vehicle networks, particularly through non-periodic CAN messages.
An intrusion detection system construction method and device that parses input files associated with CAN communication to extract reference information, sets detection policy rules using fixed or custom rule sets, and generates a policy file to enhance detection and processing of CAN messages.
Enables the setting of detection policy rules to effectively detect and process CAN messages, improving the accuracy and efficiency of intrusion detection within vehicle networks.
Smart Images

Figure 0007690154000001 
Figure 0007690154000002 
Figure 0007690154000003
Abstract
Description
Technical Field
[0001] This application relates to an intrusion detection system construction device and method applied to CAN communication.
Background Art
[0002] Recently, not only automotive electronic control but also modules for supporting detailed driving assistance functions such as autonomous driving have been actively developed. In particular, for full self-driving automation technology, automotive IT integration technologies that support sensor technologies such as LiDAR (distance measurement / object recognition sensors) and external communication technologies (V2X: Vehicle to Everything) have been developed.
[0003] In order to effectively transfer various information by such various technologies, an electronic control unit (ECU) inside an automobile can share information through a Controller Area Network (CAN) inside the automobile via vehicle Ethernet (registered trademark) and control the automobile.
[0004] As a result, the need for security to protect messages transmitted inside and outside the automobile has also increased rapidly. As an example, an intrusion detection system (IDS) has been developed to detect attacks on the network inside the automobile. However, it can detect attacks using non-periodic CAN messages, and there is a growing demand for technologies that can more accurately and efficiently sense the risk of attacks and attacks through the network inside the vehicle.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] This application is for solving the above-described problems of the prior art, and an intrusion detection system construction apparatus and method applied to CAN communication capable of setting detection policy rules (Policy Rule) for detecting and processing CAN messages in cooperation with a vehicle in various ways are provided.
[0007] However, the technical problems to be achieved by the embodiments of this application are not limited to the above-described technical problems, and other technical problems may exist.
Means for Solving the Problems
[0008] As a technical means for achieving the above technical problems, an intrusion detection system construction method applied to CAN communication according to an embodiment of this application includes a step of parsing an input file associated with CAN communication to extract reference information, a step of setting detection policy rules by applying at least one of a fixed rule set and a custom rule set using the extracted reference information, and a step of packing the reference information and the detection policy rules to generate a policy file applied to the intrusion detection system.
[0009] Also, the reference information may include at least one of ECU information, PDU information, message information, signal information, and BUS information.
[0010] Also, the detection policy rules may include at least one of a first detection policy associated with the BUS information, a second detection policy associated with the message information, and a third detection policy associated with the signal information.
[0011] Also, in the step of setting the detection policy rules, at least a part of a plurality of parameters defined in advance as the fixed rule set can be set.
[0012] In addition, the step of setting the detection policy rule may include a step of defining custom parameters applicable as the custom rule set, and a step of determining at least one of combinations and set values of the custom parameters.
[0013] In addition, the policy file can include a binary file.
[0014] In addition, the binary file can be generated in a hierarchical structure including policy header information, lookup table information, and policy body information.
[0015] In addition, the policy file can be applied to at least one of the core layer and the detection layer of the intrusion detection system.
[0016] In addition, the input file can include a CAN DBC (registered trademark) file.
[0017] On the other hand, an intrusion detection system construction device applied to CAN communication according to an embodiment of the present application includes an input file analysis unit that parses an input file associated with CAN communication to extract reference information, a policy setting unit that applies at least one of a fixed rule set and a custom rule set using the extracted reference information to set a detection policy rule, and a policy file generation unit that packs the reference information and the detection policy rule to generate a policy file applied to the intrusion detection system.
[0018] In addition, the policy setting unit can set at least some of a plurality of parameters predefined as the fixed rule set.
[0019] In addition, the policy setting unit can define custom parameters applicable as the custom rule set and determine at least one of combinations and set values of the custom parameters.
[0020] The problem-solving means described above are merely exemplary and should not be construed as intending to limit the present application. In addition to the exemplary embodiments described above, additional embodiments can exist in the drawings and the detailed description of the invention.
Effect of the Invention
[0021] According to the problem-solving means of the present application described above, it is possible to provide an intrusion detection system construction apparatus and method applied to CAN communication that can set detection policy rules (Policy Rule) for detecting and processing CAN messages in cooperation with a vehicle in various ways.
[0022] However, the effects obtained in the present application are not limited to the effects as described above, and other effects can exist.
Brief Description of the Drawings
[0023]
Figure 1
Figure 2
Figure 3
Figure 4a
Figure 4b
Figure 5a
Figure 5b
Figure 5c
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Mode for Carrying Out the Invention
[0024] Hereinafter, embodiments of the present application will be described in detail with reference to the accompanying drawings so that those having ordinary knowledge in the technical field to which the present application belongs can easily implement it. However, the present application can be embodied in various different forms and is not limited to the embodiments described here. And, in order to clearly explain the present application in the drawings, parts not related to the explanation are omitted, and similar parts are denoted by similar reference numerals throughout the specification.
[0025] Throughout the present specification, if a part is "connected" to another part, this includes not only the case where they are "directly connected", but also the case where they are "electrically connected" or "indirectly connected" with other elements interposed therebetween.
[0026] Throughout the present specification, if a member is located "above", "on the upper part of", "at the upper end of", "below", "on the lower part of", or "at the lower end of" another member, this includes not only the case where a member is in contact with another member, but also the case where there are other members between the two members.
[0027] Throughout the present specification, if a part "includes" a certain component, this means that, unless otherwise stated to the contrary, it does not exclude other components, but can further include other components.
[0028] The present application relates to an intrusion detection system construction device and method applicable to CAN communication.
[0029] FIG. 1 and FIG. 2 are schematic configuration diagrams of an intrusion detection system according to an embodiment of the present application. Specifically, FIG. 1 is a drawing showing a structure in which CAN IDS is applied in the case of a general ECU system.
[0030] Referring to FIG. 1, an intrusion detection system 10 according to an embodiment of the present application can have a hierarchical structure including a first layer 11, a second layer 12, and a third layer 13. Also, referring to FIG. 2, an intrusion detection system 10 according to an embodiment of the present application can include a controller 14.
[0031] Specifically, according to an embodiment of the present application, the first layer 11 of the intrusion detection system 10 can include a detection layer (IDS Detect Layer). Also, the second layer 12 of the intrusion detection system 10 can include a core layer (IDS Core Layer).
[0032] In this connection, an intrusion detection system construction device 100 (hereinafter referred to as "intrusion detection system construction device 100") applied to CAN communication according to an embodiment of the present application can define a detection policy rule 1000 applied to at least one of a detection layer (IDS Detect Layer) and a core layer (IDS Core Layer) of the intrusion detection system 10, and operate to generate a policy file 2 including the defined detection policy rule.
[0033] In other words, the detection layer (IDS Detect Layer) and the core layer (IDS Core Layer) of the intrusion detection system 10 can be layers that perform a function of detecting and processing CAN messages based on a detection policy rule 1000 described in detail below.
[0034] On the other hand, referring to FIG. 2, when the intrusion detection system 10 exemplarily adopts a system configuration based on a Classic AUTOSAR flat form, the intrusion detection system 10 can include a CAN packet mirroring system included in PduR of a communication services layer of basic software (Basic Software; BSW) or included in complex drivers.
[0035] For reference, in the description of the embodiment of the present application, the intrusion detection system construction device 100 can be mounted on a vehicle (not shown) equipped with the intrusion detection system 10 in the form of a policy management program for defining a detection policy rule applied to the intrusion detection system 10 and generating a policy file 2 in which the detection policy rule is reflected, but is not limited thereto.
[0036] FIG. 3 is a conceptual diagram for explaining the operation process of an intrusion detection system construction device applied to CAN communication according to an embodiment of the present application.
[0037] Referring to FIG. 3, the intrusion detection system construction device 100 can parse the input file 1 associated with CAN communication to extract reference information. Specifically, the input file 1 provided to the intrusion detection system construction device 100 can be a CAN DBC (registered trademark) file, but is not limited thereto.
[0038] Specifically, the intrusion detection system construction device 100 can obtain reference information (see "a" in FIG. 3) including at least one of ECU information, PDU information, message information, signal information, and BUS information from the input file 1. On the other hand, the message information can also be referred to as frame information.
[0039] In addition, the intrusion detection system construction device 100 can set the detection policy rule 1000 by applying at least one of a fixed rule set (see "b" in FIG. 3) and a custom rule set (see "c" in FIG. 3) using the extracted reference information.
[0040] Specifically, the intrusion detection system construction device 100 can set the detection policy rule 1000 including at least one of a first detection policy associated with BUS information, a second detection policy associated with message information, and a third detection policy associated with signal information among the reference information.
[0041] In this regard, the detection policy rule 1000 disclosed in the present application operates like a detection engine base of the intrusion detection system 10. The detection policy rule 1000 can include a BUS detection rule, a message detection rule, a signal detection rule, a periodic detection rule, etc. Each detection rule is independent, and it can be determined whether to operate according to the setting of the detection policy.
[0042] In addition, the intrusion detection system construction device 100 can store the content for the defined detection policy rule 1000 as a policy file 2 in the form of a binary file (Policy Binary), which is an IDS Policy Rule file. Also, the detection policy rule 1000 can have a buffering table and a policy rule for each message according to the policy rule of the binary file (Policy Binary).
[0043] Also, according to an embodiment of the present application, the intrusion detection system construction device 100 can set at least a part of a plurality of parameters defined in advance as a fixed rule set. In this regard, the fixed rule set (Static Ruleset) can mean a set of preset (already defined) detection rules.
[0044] FIGS. 4a and 4b are charts exemplarily showing the parameter types of the fixed rule set (Static Ruleset).
[0045] Referring to FIGS. 4a and 4b, the intrusion detection system construction device 100 can separately generate a first detection policy associated with BUS information, a second detection policy associated with message information, and a third detection policy associated with signal information by using the DBC (registered trademark) information extracted as reference information.
[0046] FIGS. 5a to 5c are charts exemplarily showing the parameters that can be adopted for each of the first detection policy to the third detection policy. Specifically, FIG. 5a is a chart showing nine preset parameters that can be set for the first detection policy associated with BUS information, FIG. 5b is a chart showing four preset parameters that can be set for the second detection policy associated with message information, and FIG. 5c is a chart showing seven preset parameters that can be set for the third detection policy associated with signal information.
[0047] Referring to FIGS. 5a to 5c, each parameter applied to the detection policy rule 1000 can be mutually distinguished through the policy name (Rule Name) and the policy identifier (Rule ID; Detection ID).
[0048] Exemplarily, referring to FIG. 5a, the parameters that can be set for the first detection policy include "Bus Load Too High (ID: 1)" for detecting when the bus traffic (mps) is equal to or higher than the reference value (upper limit value), "Bus Load Too Low (ID: 2)" for detecting when the bus traffic is equal to or lower than the reference value (lower limit value), "Unknown Arb ID (Arbitration) (ID: 3)" for detecting messages not defined in DBC (registered trademark), "Signal Correlation Error (ID: 4)" for detecting abnormal gateway relay messages, "Recv Unknown ECU Message (ID: 5)" for detecting message reception from an undetectable (unknown) ECU, "Detected Dos Attack (ID: 6)" for detecting a denial-of-service attack, "Unknown DIAG ID (ID: 7)" for detecting undefined diagnostic messages, "DIAG Message Flooding (ID: 8)" for detecting a control service denial-of-service attack using diagnostic messages, "DIAG Scanning Detected (ID: 9)" for detecting a control scanning attack using diagnostic messages, etc.
[0049] Similarly, the policy name (Rule Name), the policy identifier (Rule ID; Detection ID), and the purpose / description of the parameters that can be set for each of the second detection policy and the third detection policy are also shown in FIGS. 5b and 5c.
[0050] Also, according to an embodiment of the present application, in relation to the first detection policy, the intrusion detection system construction device 100 can set a BUS detection rule (first detection policy) in the detection rule plug (Detection Rule flag) of the policy header information of the policy file 2. In the IDS Engine, it operates based on the setting of the detection rule plug in the policy header. When an anomaly detection message is generated, the value of the policy identifier (Rule ID; Detection ID) corresponding to each parameter of the BUS detection policy is stored in the detection log buffer of the logging system.
[0051] Also, according to an embodiment of the present application, in relation to the second detection policy, the intrusion detection system construction device 100 can set a message detection rule (second detection policy) in the detection rule plug (Detection rule flag) of the message header. In the IDS Engine, it operates based on the setting of the detection rule plug in the message header. When an anomaly detection message is generated, the policy identifier (Rule ID; Detection ID) value corresponding to each parameter of the message detection policy is stored in the detection log buffer of the logging system.
[0052] Also, according to an embodiment of the present application, in relation to the third detection policy, the intrusion detection system construction device 100 can set a signal detection rule (third detection policy) to the signal type of the signal header (Signal Header). In the IDS Engine, it operates based on the signal type setting of the signal header. When an anomaly detection message occurs, the policy identifier (Rule ID; Detection ID) value corresponding to each parameter of the signal detection policy is stored in the detection log buffer of the logging system (Logging System).
[0053] Also, according to another embodiment of the present application, the setting unit 120 can define custom parameters applicable as a custom rule set. Further, the intrusion detection system construction device 100 can determine at least one of the combination of custom parameters and the set values. In this regard, a custom rule set (Custom Ruleset) means a set of detection rules whose content is determined by the user.
[0054] In particular, in the case of a custom rule set, the detection policy can be set based on the sensor information of the signal of the CAN message received by the intrusion detection system 10.
[0055] FIG. 6 is a conceptual diagram for explaining the types of combinations of detection rules that can be set by the user.
[0056] Referring to FIG. 6, the detection combinations that can be set by the user using the custom rule set can be determined through a plurality of methods shown in FIG. 6. Specifically, (a) in FIG. 6 is a detection rule combination that omits the argument value and performs detection only based on signal types such as counters and CRCs. (b) in FIG. 6 is a detection rule combination based on a fixed rule set that requires detection arguments for sensing, such as Enum and Range Detection. (c) in FIG. 6 is a detection rule combination to which a single user's defined conditional expression based on the custom rule set is applied. (d) in FIG. 6 is a detection rule combination to which a multi-user defined conditional expression based on the custom rule set is applied. (e) in FIG. 6 shows a composite detection rule combination to which both the fixed rule set and the custom rule set are applied.
[0057] On the other hand, in relation to the multi-user defined conditional expression shown in (d) of FIG. 6, various logical combinations such as a setting where sensing is performed when all of the exemplary first condition (expression 1), second condition (expression 2), and third condition (expression 3) are satisfied (Expression 1 AND Expression 2 AND Expression 3) can be applied to the defined conditions of multiple users.
[0058] FIG. 7 is a diagram exemplarily showing parameters that can be adopted for the custom rule set.
[0059] Referring to FIG. 7, the custom parameters can be variously defined by user settings so as to reflect various situations or scenarios that can be controlled using various sensing information and measurement information obtained from a vehicle (not shown) to which the intrusion detection system 10 is applied, such as parameters for detecting the case where the wheels rotate with the shift lever in the P position by way of example, parameters for detecting the case where the speeds of the respective wheels have an abnormally large difference, parameters for detecting the situation where the vehicle is in operation or the battery voltage becomes extremely low, and parameters for detecting an abnormal situation where the heated wire and the ventilation seat are turned on simultaneously.
[0060] In addition, the intrusion detection system construction device 100 can generate a policy file to be applied to the intrusion detection system 10 by packing reference information and detection policy rules.
[0061] In other words, the intrusion detection system construction device 100 sets a detection policy rule 1000 based on at least one of a fixed rule set and a custom rule set using the parsed DBC (registered trademark) information, and can generate a policy file 2 in binary file form through packing that combines the information (DBC (registered trademark) information and Policy Rule information) thus generated.
[0062] Hereinafter, with reference to FIGS. 8 to 11, the data structure of the policy file 2 generated by the intrusion detection system construction device 100 will be specifically described.
[0063] FIG. 8 is a drawing exemplarily showing the hierarchical structure of a policy file generated by an intrusion detection system construction device applied to CAN communication according to an embodiment of the present application.
[0064] Referring to FIG. 8, the intrusion detection system construction device 100 can generate a binary file having a hierarchical structure including Policy Header information 21, lookup table information 22, and Policy Body information 23 as a policy file 2. In particular, the Policy Body information 23 can include information on the detection policy rules 1000 applied for each CAN message.
[0065] FIG. 9 is a drawing showing the data structure of the Policy Header information of the binary file.
[0066] Referring to FIG. 9, the Policy Header information 21 is located at the beginning of the policy file 2 and can consist of a policy version, generation date and time, detection settings applied to the CAN BUS, etc. According to an embodiment of the present application, a policy for a plurality of (for example, 6) pre-set bus information can be integrally set in the Policy Header information 21, and the detection policy rules generated based on the BUS information extracted by DBC (registered trademark) can be reflected. Exemplarily, the Policy Header information 21 has a size of 48 bytes and can include the following data fields.
[0067] First, Policy version (8 bytes) is a data field indicating the version information of the binary file, and can exemplarily include vehicle type information (2 bytes), major version information (2 bytes), minor version information (2 bytes), detail version information (2 bytes), etc.
[0068] Also, created timestamp (4 bytes) is a data field indicating information on the generation date (time) of the binary file, and an exemplary notation such as 1900-01-01.00:00:00~2037-12-31.23:59:59 can be applied.
[0069] Furthermore, it can further include a bus count (2 Byte) data field indicating the total number of BUSES, a message count data field indicating the total number of messages, a buf-5-rec-num (2 Byte) data field indicating the number of messages with 5 buffering counts for CAN Standard messages, a buf-10-rec-num (2 Byte) data field indicating the number of messages with 10 buffering counts for CAN Standard messages, an fd-buf-5-rec-num (2 Byte) data field indicating the number of messages with 5 buffering counts for CAN FD messages, an fd-buf-10-rec-num (2 Byte) data field indicating the number of messages with 10 buffering counts for CAN FD messages, etc.
[0070] Also, when setting detection policy rules (Policy Rule) for a plurality of preset CAN BUS information, a bus number (1 Byte) data field indicating the CAN BUS number, a detection rule flag (1 Byte) data field indicating the detection rule setting plug applied to the BUS, etc. can be applied.
[0071] In this regard, FIG. 10 is a drawing showing the data structure of the BUS detection rule plug.
[0072] Referring to FIG. 10, the BUS detection rule plug can include a "Bus detect ON / OFF" field for determining whether all detection rules for the BUS itself are applied. When the field is 0, it is excluded from all detection targets, and when it is 1, the detection rules can be applied only.
[0073] In addition, the BUS detection rule plug includes a "Unknown Arbitration ID detect" field for detecting the case where a message with an Arbitration ID not present in the detection policy flows into the BUS, a "Bus load detect" field for detecting the case where the BUS load deviates from the appropriate range, an "Invalid DIAG detect" field for detecting an invalid diagnostic message flowing into the BUS, a "DoS attack detect" field for detecting a denial-of-service (DoS) attack on the BUS, an "Unknown DIAG ID detect" field for detecting a diagnostic message not present in the DBC (registered trademark), a "DIAG Flooding detect" field for detecting a control machine service attack using a diagnostic message, a "DIAG Scanning detect" field for detecting a control machine scanning attack using a diagnostic message, and the like.
[0074] For reference, in the case of the "Bus load detect" field, additional settings for the minimum / maximum load values may be required. In this regard, a maximum load mps (1Byte) field, which is the value for setting the maximum load on the BUS, and a minimum load mps (1Byte) field, which is the value for setting the minimum load on the BUS, can be defined. The maximum load setting value and the minimum load setting value can be set within the range of 0 to 25500 mps in the form of mps (messages for second) values on a 1 / 100 scale, but are not limited thereto.
[0075] Also, such BUS detection rules can be set by the intrusion detection system construction device 100, the operation in the IDS Engine of the intrusion detection system 10 can be changed according to the value of the detection rule setting plug, and when an anomaly detection occurs, the Detection ID value of the BUS detection Parameter can be stored in the Log Buffer.
[0076] Figure 11 is a drawing showing the data structure of the lookup table information of a binary file.
[0077] Referring to Figure 11, the lookup table information 22 can include information for storing and retrieving the data of the set detection policy rule 1000 and the received message in a buffer.
[0078] Specifically, the lookup table information 22 stores matters (contents) for the CAN information extracted by DBC (registered trademark). At this time, a lookup key is generated by the combination of CAN BUS + Arbitration ID (CAN message ID), and the policy body information 23 storing the detection policy of the CAN message and the information of the buffering table can be stored. Therefore, illustratively, the lookup table information 22 can be designed with a 6-byte data structure and can be generated for the total number of DBC (registered trademark) messages.
[0079] On the other hand, regarding each data field of the lookup table information 22, the "lookup key (2 bytes)" field, which is the key for searching the Policy Body, which is the detection policy rule, and the Buffering Table, can consist of the CAN BUS ID, the "BUS ID (5 bits)" field indicating the BUS ID stored in the Policy Header, and the "Arbitration ID (11 bits)" indicating the CAN message ID, and can include the "policy index (2 bytes)" field indicating the index information of the detection policy rule of the policy body information 23, the "entry index (2 bytes)" field indicating the index information for the buffering table, and the like.
[0080] Also, the entry index field can consist of a "buffer type (2-bit)" field indicating information for storing a CAN message in the buffering table and a "buffer index (14-bit)" field indicating the address information of the buffering table.
[0081] In summary, the operation of storing the received CAN message in the Buffering Table can be performed through the policy index and entry index information of the policy text information 23.
[0082] More specifically, when a CAN message is received, the CAN message is stored in the Buffering Table based on the Buffer type and index information of the Lookup Table through the Lookup Key (BUS + Arbitration ID). The CAN message is classified into Standard and FD, and the Buffering Table has storage space for all CAN messages in the Lookup Table, and the storage location varies depending on the form of the message. The Buffering Table is allocated to a RAM area (fixed address area) determined in the initialization process. When a CAN message is received, it is determined whether to put it into a table set with 5 buffers or a table set with 10 buffers through the Buffer type corresponding to the CAN message in the Lookup Table. If the received message is a CAN Standard message and the Buffer type is 00, it will be stored at the address corresponding to the Buffer index number in the buf-5-rec-num table. And the first item in the Lookup Table is the item used when detecting a message not registered in DBC (registered trademark). This item is specified as an item requiring buffering and allocated to the Buffering Table.
[0083] Also, when a CAN message is stored in the Buffering Table, the detection policy rule of the CAN message in the Policy Body is retrieved through the information of the Policy index. It is possible to determine whether the CAN message is valid data through the retrieved information.
[0084] The policy body information 23 can include a detection policy rule (Policy Rule) for each CAN message, and can consist of a "Message Header" field and a "Signal Policy Rule" field for setting the detection policy rule for each CAN message.
[0085] Specifically, in the policy body information 23, the message header field is used in common for CAN Standard and CAN FD. Based on the information obtained from DBC (registered trademark), quick values (normal period, upper / lower limit range, detection rule usage plug) related to the detection policy rule are added, and the data structure of the message header field can be 5 bytes and configured as follows.
[0086] Specifically, the message header field includes a CAN FD (1Bit) field determined by 0 for CAN Standard Message and 1 for CAN FD, a Periodic (1Bit) field determined by 1 when the CAN Message is periodic, an Event (1Bit) field determined by 1 when the CAN Message is an event, a Reverse (1Bit) field indicating the case where the message inflow direction is incorrect, a DLC (4Bit) field indicating the data length of the CAN Message, an Average period (1Byte) field indicating the average period of the message (settable in 10ms units from 0 to 2550ms at 1 / 10 scale), a Signal count (6Bit) field indicating the number of signals included in the message, an Upper period margin (5Bit) field indicating the upper limit correction value for judgment by the average period (settable up to 32ms in 1ms units), a Lower Period margin (5Bit) field indicating the lower limit correction value for judgment by the average period (settable up to 32ms in 1ms units), a Detection rule flag (4Bit) field indicating activation of DLC abnormality detection, activation of period detection, etc., and a Message body size (12 Bit) field indicating the size of the Signal Policy Rule after the message header (maximum 4095Byte), etc.
[0087] In addition, the signal policy rule field can include a signal header that stores basic signal information such as the bit position, length, sign, and byte order of the signal, and the signal type. At this time, in the case of the signal type, it can be determined by inference from DBC (registered trademark) or the type found by analyzing the Dump data.
[0088] On one hand, the signal header is used in common for CAN Standard and CAN FD, with a maximum of 64 bytes. The starting position of the signal is from 0 to 511, and the maximum size of the signal shall not exceed 128 bits (16 bytes). The data structure of the Signal Header can specifically include a bit index (9 bits) field with a size of 0 to 512, a length (7 bits) field with a size of 0 to 127, an order (1 bit) field, a sign (1 bit) field, a signal type (6 bits) field with a size of 0 to 63, a signal body size (1 byte) field with a size of 0 to 255, etc.
[0089] Also, in relation to the types of signals, "enum(0x00)" is an enumerated signal with limited characteristics with several values (e.g., 0:inactive, 1:on, 2:off, 3:invalid, etc.), "counter(0x01)" is a signal with a counter pattern where the value changes sequentially in an increasing manner, "CRC(0x02)" is a signal that requires CRC calculation and the bit range used for CRC calculation is necessary, "const(0x03)" is a signal used to represent unused bit areas and has characteristics without separate information in the actual DBC (registered trademark), "sensor(0x04)" is a signal with general irregular sensor values and has a value range, and "binary(0x05)" is a signal represented by 0 or 1 as a 1-bit length signal.
[0090] Also, the Detection Argument is located next to the signal header and contains the factor value information used in the detection rule. Since there can be various factor values depending on the type of detection rule, it is designed to be flexibly implemented using the factor code. The Detection Argument is composed of a Detect Header and a Detect Body. The Detect Header has its value type and type of the argument predetermined by the combination of the Argument Code and the Sub Code.
[0091] Each data field of the detection factor may specifically include an "argument code (5Bit)" field, a "sub code (3Bit)" field, an "argument body size (1Byte)" field, an "argument body (2Byte)" field, and the like.
[0092] FIG. 12 is a schematic configuration diagram of an intrusion detection system construction device applied to CAN communication according to an embodiment of the present application.
[0093] Referring to FIG. 12, the construction device 100 may include an input file analysis unit 110, a policy setting unit 120, and a policy file generation unit 130.
[0094] The input file analysis unit 110 can parse the input file 1 associated with CAN communication and extract reference information.
[0095] Specifically, the input file analysis unit 110 can obtain reference information including at least one of ECU information, PDU information, message information, signal information, and BUS information from the input file 1.
[0096] The policy setting unit 120 can set detection policy rules by applying at least one of a fixed rule set and a custom rule set using the extracted reference information.
[0097] Specifically, the policy setting unit 120 can set detection policy rules including at least one of a first detection policy associated with BUS information, a second detection policy associated with message information, and a third detection policy associated with signal information among the reference information.
[0098] In connection with this, according to an embodiment of the present application, the policy setting unit 120 can set at least a part of a plurality of parameters predefined as a fixed rule set.
[0099] Also, according to another embodiment of the present application, the setting unit 120 can define custom parameters applicable as a custom rule set. Further, the policy setting unit 120 can determine at least one of a combination of custom parameters and a set value.
[0100] The policy file generation unit 130 can generate a policy file for application to the intrusion detection system 10 by packing the reference information and the detection policy rules.
[0101] Specifically, the policy file generation unit 130 can generate a binary file having a hierarchical structure including policy header information, lookup table information, and policy body information as a policy file.
[0102] Hereinafter, based on the content described in detail above, the operation flow of the present application will be briefly described.
[0103] FIG. 13 is an operation flowchart for a method of constructing an intrusion detection system applied to CAN communication according to an embodiment of the present application.
[0104] The method of constructing an intrusion detection system applied to CAN communication shown in FIG. 13 can be performed by the above-described construction device 100. Therefore, even if the content omitted below, the content described for the construction device 100 can also be equally applied to the description of the method of constructing an intrusion detection system applied to CAN communication.
[0105] Referring to FIG. 13, in step S11, the input file analysis unit 110 can parse the input file 1 associated with CAN communication and extract reference information.
[0106] Specifically, in step S11, the input file analysis unit 110 can obtain reference information including at least one of ECU information, PDU information, message information, signal information, and BUS information from the input file 1.
[0107] Next, in step S12, the policy setting unit 120 can set a detection policy rule by applying at least one of a fixed rule set and a custom rule set using the extracted reference information.
[0108] Specifically, in step S12, the policy setting unit 120 can set a detection policy rule including at least one of a first detection policy associated with BUS information, a second detection policy associated with message information, and a third detection policy associated with signal information among the reference information.
[0109] According to an embodiment of the present application, in step S12, the policy setting unit 120 can set at least a part of a plurality of parameters predefined as a fixed rule set.
[0110] According to another embodiment of the present application, in step S12, the policy setting unit 120 can define custom parameters applicable as a custom rule set. Also, in step S12, the policy setting unit 120 can determine at least one of a combination of custom parameters and set values.
[0111] Next, in step S13, the policy file generation unit 130 can generate a policy file to be applied to the intrusion detection system 10 by packing the reference information and the detection policy rule.
[0112] Specifically, in step S13, the policy file generation unit 130 can generate a binary file having a hierarchical structure including policy header information, lookup table information, and policy body information as the policy file.
[0113] In the above description, steps S11 to S13 can be further divided into additional steps or combined into fewer steps according to the embodiments of the present application. Also, some steps may be omitted as necessary, and the order between steps may be changed.
[0114] The method for constructing an intrusion detection system applied to CAN communication according to an embodiment of the present application can be implemented in the form of program instructions that can be performed through various computer means and recorded on a computer-readable medium. The computer-readable medium can include program instructions, data files, data structures, etc. alone or in combination. The program instructions recorded on the above medium may be those specially designed and configured for the present invention or those known to those skilled in computer software and available for use. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specially configured to store and execute program instructions such as ROMs, RAMs, and flash memories (registered trademarks). Examples of program instructions include not only machine language codes such as those generated by compilers but also high-level language codes that can be executed by a computer using an interpreter or the like. The above hardware device can be configured to operate as one or more software modules for performing the operations of the present invention, and vice versa.
[0115] Also, the method for constructing an intrusion detection system applied to CAN communication described above can also be implemented in the form of a computer program or application executed by a computer stored in a recording medium.
[0116] The foregoing description of the present application is for illustrative purposes, and those with ordinary knowledge in the technical field to which the present application pertains will be able to understand that it can be easily transformed into other specific forms without changing the technical idea and essential features of the present application. Therefore, it should be understood that the embodiments described above are illustrative in all aspects and not restrictive. For example, each component described as a single type may be implemented dispersedly, and similarly, components described as dispersed may also be implemented in a combined form.
[0117] The scope of the present application is represented by the claims described below rather than the above detailed description, and all changes or modified forms derived from the meaning and scope of the claims and their equivalent concepts should be construed as being included within the scope of the present application.
Explanation of Reference Numerals
[0118] 10: Intrusion Detection System 11: First Layer 12: Second Layer 13: Third Layer 14: Controller 100: Intrusion Detection System Construction Device Applied to CAN Communication 110: Input File Analysis Unit 120: Policy Setting Unit 130: Policy File Generation Unit 1: Input File 2: Policy File
Claims
1. A method for constructing an intrusion detection system applied to CAN communication, comprising: parsing an input file associated with the CAN communication by a computer to extract reference information; setting, by the computer, a detection policy rule by applying at least one of a fixed rule set and a custom rule set using the extracted criteria information; generating, by the computer, a policy file that is applied to the intrusion detection system by packing the criteria information and the detection policy rules; Including, The reference information is At least one of ECU information, PDU information, message information, signal information, and BUS information is included; The detection policy rule is: indicating whether a first detection policy associated with the BUS information, a second detection policy associated with the message information, and a third detection policy associated with the signal information are each independently applied.
2. The method of claim 1, wherein the first detection policy includes at least one of the following: traffic on a bus used for the CAN communication is above an upper limit value, traffic on the bus is below a lower limit value, the CAN communication on the bus includes a message not defined in DBC, a gateway relay message anomaly has occurred on the bus, reception of a message from an unidentified ECU has occurred on the bus, a denial of service attack has occurred on the bus, an undefined diagnostic message is being communicated on the bus, a controller denial of service attack using the diagnostic message has occurred on the bus, and a controller scanning attack using the diagnostic message has occurred on the bus.
3. The method of claim 1, wherein the second detection policy includes at least one of: a length of a message of the CAN communication is smaller than a set value; a length of the message is greater than a set value; and a period of the message is within a normal period; and the message includes an invalid diagnostic message.
4. The method of claim 1, wherein the third detection policy includes at least one of the following: whether an unacceptable bit area is used in the signal communication of the CAN communication, whether a CRC error occurs in the signal communication, whether a counter sequence error occurs in the signal communication, whether the signal communication includes communication that is not an enumerated value permitted by the detection policy rules, whether the signal communication is below a signal lower limit value, whether the signal communication exceeds an upper signal value, and whether the rate of change of the signal value is equal to or greater than a set value.
5. The step of setting the detection policy rule by the computer comprises: The method of claim 1 , further comprising: setting, by the computer, at least a portion of a plurality of predefined parameters as the fixed rule set.
6. The step of setting the detection policy rule by the computer comprises: defining, by the computer, custom parameters applicable as the custom rule set; determining, by the computer, at least one of the combinations and settings of the custom parameters; The method of claim 1 , comprising:
7. The method of claim 1 , wherein the policy file is a binary file.
8. The binary file is The method according to claim 7, wherein the policy information is generated in a hierarchical structure including policy header information, lookup table information and policy body information.
9. The method of claim 1 , wherein the policy file is applied to at least one of a core layer and a detection layer of the intrusion detection system.
10. The method of claim 1 , wherein the input file comprises a CAN DBC® file.
11. In a construction device for an intrusion detection system applied to CAN communication, an input file analyzer that parses an input file in conjunction with CAN communication to extract reference information; a policy setting unit that sets a detection policy rule by applying at least one of a fixed rule set and a custom rule set using the extracted reference information; a policy file generating unit that generates a policy file to be applied to the intrusion detection system by packing the reference information and the detection policy rule; Including, The reference information is At least one of ECU information, PDU information, message information, signal information, and BUS information is included; The detection policy rule is: An apparatus for indicating whether each of a first detection policy associated with the BUS information, a second detection policy associated with the message information, and a third detection policy associated with the signal information is independently applied.
12. The policy setting unit The apparatus according to claim 11 , further comprising: setting at least a portion of a plurality of predefined parameters as the fixed rule set.
13. The policy setting unit The apparatus of claim 11 , further comprising: defining custom parameters applicable as the custom rule set; and determining at least one of combinations and setting values of the custom parameters.
14. The policy file is The apparatus according to claim 11 , wherein the policy information is a binary file generated in a hierarchical structure including policy header information, lookup table information, and policy body information.
Citation Information
Patent Citations
Internet of Vehicles monitoring system, method and device and readable storage medium
CN111431864A
In-vehicle safety rule file generation method and device
CN112363984A
Vehicle CAN network intrusion detection method and device, electronic equipment and medium
CN114374565A
Vehicle CAN network IDS safety detection system and method
CN115102707A
Can bus attack detection method using IFS, gateway and attach detection device implemneting it
KR1020230094513A