Universal intrusion detection system on in-vehicle network

KR103022617B1Active Publication Date: 2026-09-21SOONCHUNYANG UNIV IND ACAD COOP FOUND
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
KR1020240012323
Authority / Receiving Office
KR · KR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-01-26
Publication Date
2026-09-21
Estimated Expiration
2044-01-26

Smart Images

  • Figure 112024010539323-PAT00001_ABST
    Figure 112024010539323-PAT00001_ABST
Patent Text Reader

Abstract

The present invention relates to universal intrusion detection for internal network security of a vehicle model. The universal intrusion detection method comprises the steps of normalizing received data through timestamp normalization and performing attack data labeling on the normalized data; extracting features based on the number of packets generated within a preset time interval on the normalized data; filtering data suspected of being abnormal data through initial verification based on the features; performing wavelet transform on the data suspected of being abnormal data and performing data preprocessing for input into a deep learning model; and verifying whether the data suspected of being abnormal data is normal or abnormal through the deep learning model.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The technical field to which the present invention belongs relates to intrusion detection for vehicle internal network security, and specifically to a universal intrusion detection method and device for vehicle internal network security of heterogeneous models. Background Technology

[0002] In-vehicle networks require an Intrusion Detection System (IDS) for several important reasons.

[0003] In-vehicle networks can be vulnerable to cyberattacks, and if an intrusion occurs, vehicle safety, privacy, and functionality can be jeopardized. An IDS acts as a guardian monitoring the in-vehicle network, continuously monitoring it to identify and block suspicious activity or intrusion attempts.

[0004] In terms of data protection, measures are also needed to protect sensitive information such as personal data, GPS location data, and vehicle diagnostic data.

[0005] IDS protects both user personal information and vehicle integrity by maintaining the confidentiality of this data and securely protecting it from unauthorized access.

[0006] In the context of developing a universal IDS for in-vehicle networks of the same manufacturer and model, the primary security challenge of these networks stems from the diversity of data generated by these vehicles. Since vehicles with identical manufacturer and model configurations can generate highly unique data profiles, existing IDS systems find it difficult to provide effective security without extensive customization.

[0007] The process of defining such an IDS is time-consuming, costly, and requires specialized expertise. Furthermore, the development of a general-purpose IDS is increasingly required due to the dynamic nature of in-vehicle networks, the need for real-time processing, and the constant evolution of security threats.

[0008] Balancing data heterogeneity with minimizing false positives remains a critical challenge in enhancing in-vehicle network security. Prior art literature

[0009] Korean Patent Publication No. 10-2021-0103972 (Title of Invention: System and Method for Intrusion Detection of In-vehicle Network) The problem to be solved

[0010] The problem to be solved by the present invention is to provide a general-purpose IDS that can prevent false positives while accommodating data heterogeneity, such as heterogeneous models, through the embodiments. means of solving the problem

[0011] A universal intrusion detection method for vehicle internal network security of a heterogeneous model according to one embodiment of the present invention comprises the steps of: receiving data from a plurality of CAN (Controller Area Network) sources; normalizing the received data through timestamp normalization and performing attack data labeling on the normalized data; extracting features based on the number of packets generated within a preset time interval for the normalized data; filtering data suspected of being abnormal data through initial verification based on the features; performing wavelet transform on the data suspected of being abnormal data and performing data preprocessing for input into a deep learning model; and verifying whether the data suspected of being abnormal data is normal or abnormal through the deep learning model.

[0012] The above deep learning model may be RseNet-50, which uses input data consisting of a 4D array of [32, 1, 10, 113] dimensions and is implemented using the PyTorch framework.

[0013] The step of filtering data suspected of being abnormal data through the above initial verification may include determining the data as suspected of being abnormal data if the value of the Pearson correlation coefficient for the normalized data falls outside a preset range.

[0014] A general-purpose intrusion detection device for internal network security of a heterogeneous model vehicle according to one embodiment of the present invention comprises: a data receiving unit that receives data from a plurality of CAN (Controller Area Network) sources; a data labeling unit that normalizes the received data through timestamp normalization and performs attack data labeling on the normalized data; a feature extraction unit that extracts features based on the number of packets generated within a preset time interval for the normalized data; an initial verification unit that filters data suspected of being abnormal data through initial verification based on the features, performs wavelet transform on the data suspected of being abnormal data, and performs data preprocessing for input into a deep learning model; and a verification unit that verifies whether the data suspected of being abnormal data is normal or abnormal through the deep learning model. Effects of the invention

[0015] According to embodiments of the present invention, a general-purpose IDS can be provided that can prevent false detection while accommodating data heterogeneity, such as heterogeneous models.

[0016] According to embodiments of the present invention, an IDS that can be universally applied to all automobiles can be implemented by applying data generalization technology. In addition, by first identifying suspicious data, performing high-resolution feature extraction using wavelet technology, and then applying deep learning technology, the security process is simplified, resulting in more efficient and cost-effective benefits and the effect of ensuring the safety of all vehicles. Brief explanation of the drawing

[0017] FIG. 1 is a flowchart illustrating a universal intrusion detection method for vehicle internal network security of a model according to an embodiment of the present invention. FIG. 2 shows the configuration of a universal intrusion detection device for vehicle internal network security of a model according to an embodiment of the present invention. FIG. 3 is a diagram showing an example of Pearson correlation coefficient measurement according to one embodiment. FIG. 4 is a diagram illustrating, in its entirety, the concept of universal intrusion detection for vehicle internal network security of a model according to an embodiment of the present invention. Specific details for implementing the invention

[0018] Structural or functional descriptions are provided merely for the purpose of illustrating embodiments according to the concept of the present invention, and embodiments according to the concept of the present invention may be implemented in various forms and are not limited to the embodiments described herein.

[0019] Embodiments according to the concept of the present invention may be subject to various modifications and may take various forms; therefore, embodiments are illustrated in the drawings and described in detail in this specification. However, this is not intended to limit the embodiments according to the concept of the present invention to specific disclosed forms, and includes modifications, equivalents, or substitutions that fall within the spirit and scope of the present invention.

[0020] Terms such as "first" or "second" may be used to describe various components, but said components should not be limited by said terms. For the sole purpose of distinguishing one component from another, for example, without departing from the scope of rights according to the concept of the present invention, the first component may be named the second component, and similarly, the second component may be named the first component.

[0021] When it is stated that one component is "connected" or "connected" to another component, it should be understood that while it may be directly connected or connected to that other component, there may also be other components in between. Conversely, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between. Expressions describing the relationships between components, such as "between," "exactly between," or "directly adjacent to," should be interpreted in the same way.

[0022] The terms used herein are used merely to describe specific embodiments and are not intended to limit the invention. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this specification, terms such as “comprising” or “having” are intended to specify the existence of the described features, numbers, steps, actions, components, parts, or combinations thereof, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.

[0023] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which the present invention pertains. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this specification.

[0025] Hereinafter, embodiments will be described in detail with reference to the attached drawings. However, the scope of the patent application is not limited or restricted by these embodiments. Identical reference numerals provided in each drawing indicate identical components.

[0027] An embodiment of the present invention may be composed of two parts to solve the problems of conventional intrusion detection systems. The first part is a step of identifying suspicious data, and the second part is a step of performing high-resolution feature extraction using wavelet technology and then inputting it into a deep learning system.

[0028] The universal intrusion detection according to an embodiment of the present invention effectively processes various data generated from vehicles of various manufacturers and models. To this end, the process begins by accessing data relationships through linearity checks using Pearson correlation coefficients. Additionally, the data is converted into wavelet representations to enable extensive data generalization, ensuring that the IDS can accommodate a wide range of data variations. To account for such time-series data inputs, the IDS can adjust the time-series window based on the specific data generation rate of each vehicle. For example, Vehicle A may generate data at a rate of 2,500 data points per second, while Vehicle B may generate 3,500 data points per second. To maintain effective data generalization for all vehicles, the IDS can adjust the timing of the time-series window accordingly.

[0029] In one embodiment, once data preprocessing is completed, an enhanced dataset is generated and the enhanced dataset can be input into a deep learning model. Through the training of the deep learning model and the completed model, it becomes proficient in identifying common data patterns and anomalies, and labor-intensive manual customization is not required.

[0030] A general-purpose detection method according to one embodiment can maintain a robust, up-to-date state by continuously adapting to evolving threats and changing data patterns. Additionally, it can detect potential threats by operating in real-time without burdening the vehicle's computing resources.

[0031] A method according to one embodiment can significantly reduce the possibility of false alarms or missing security issues, and by simplifying security measures, can protect the safety and integrity of all vehicles on the road more efficiently and cost-effectively, regardless of unique data characteristics.

[0033] FIG. 1 is a flowchart illustrating a universal intrusion detection method for vehicle internal network security of a model according to an embodiment of the present invention.

[0034] Referring to FIG. 1, a general-purpose detection method according to one embodiment normalizes received data through timestamp normalization in step 110 and performs attack data labeling on the normalized data.

[0035] Labeling attack data is an important process for training deep learning models and identifying attack data.

[0036] The initial process of labeling attack data may include identifying and marking data corresponding to the attack's start and end points. This allows for the filtering of all attack data related to Denial of Service (DoS), fuzzing, and replay attacks, thereby simplifying the classification and analysis of security incidents for vehicles from different manufacturers.

[0037] Accurate identification of attack data is an essential step in defining the scope and duration of the attack.

[0038] Once attack data is identified, the system can effectively filter attack-related data from normal operational data.

[0039] Timestamp normalization is a process that standardizes the time intervals of data points generated from different sources so that they can be compared and analyzed at a common scale. This can be accomplished by adding additional labels to previously labeled data using a time-series window approach. The time-series window can be set to, for example, 20 units, which may involve splitting Car-1 data into 0.01-second intervals and Car-2 data into 0.009-second intervals to achieve 20 functions for both different vehicles. This splitting process can be referred to as "timestamp normalization."

[0040] Various types of data can be classified and labeled through timestamp normalization. For example, one segment may be labeled as "no attack" indicated by 0, and another segment may be labeled as fuzzing (1), denial of service (DoS) (2), or replay (3).

[0041] Timestamp normalization can select a common interval that can appropriately represent the data of the two vehicles. For example, if a 0.01 second interval is selected as the standard, the data of Car-2 can be adjusted to fit this interval, which may include averaging the data points of Car-2 or interpolating to fit the 0.01 second interval.

[0042] A general-purpose detection method according to one embodiment extracts features based on the number of packets generated within a preset time interval for normalized data in step 120.

[0043] The goal of feature extraction, or the feature extraction process, is to identify the most common features of an Intrusion Detection System (IDS). Consequently, it is possible to extract features that quantify the number of packets generated within a specific time interval and calculate the average time interval between them. These capabilities can be utilized to identify suspicious data and train deep learning models. Feature extraction is an essential process because there is a significant correlation between data generation and time differences. As the data generation rate increases, the time interval between packets tends to decrease, and this trend helps to effectively identify abnormal data patterns.

[0044] For example, if 150 packets per second are detected in vehicle A, it is outside the normal range, and the IDS can identify this as abnormal activity.

[0045] Through steps 110 and 120, a hybrid approach consisting of two parts—an initial data verification phase and a detailed analysis phase—is possible.

[0046] Here, the initial verification or initial confirmation step examines the incoming data for signs of suspicious activity. The initial confirmation step is designed to be efficient and resource-friendly. The primary purpose of initial confirmation is to rapidly filter out data that does not cause immediate problems.

[0047] The detailed analysis step can be activated only for data identified as suspicious during the initial verification. In other words, deep learning technology is applied to thoroughly verify suspicious data. The detailed analysis step can be configured to be triggered only when necessary to investigate potentially harmful activities.

[0048] A general-purpose detection method according to one embodiment may identify data suspected of being abnormal data in step 130 and perform a wavelet transform on the data suspected of being abnormal data. For example, based on features extracted in step 120, data suspected of being abnormal data may be filtered through initial verification and a wavelet transform may be performed on the data suspected of being abnormal data.

[0049] In step 130, to identify data suspected of being abnormal, a linearity test can first be performed using Pearson Correlation.

[0050] Linearity testing evaluates interdependence by assessing the strength and characteristics of the relationship between variables. The Pearson correlation coefficient measures how closely variables are related and can express the relationship numerically from -1 to 1. A value of +1 indicates a perfect positive linear correlation, -1 indicates a perfect negative linear correlation, and 0 indicates no linear correlation.

[0051] In a Pearson correlation coefficient analysis according to one embodiment, a consistent negative correlation can be utilized between the amount of generated data and the average time difference between data points. Specifically, when an attack begins, the speed of data generation tends to increase, and the average time interval between data points can be significantly reduced.

[0052] As shown in Figure 3, experimental results showed that in a scenario without attacks, this negative correlation is distributed in a coefficient range of -0.50 to 0.75, as indicated by reference numeral 310, for all vehicles of this type. However, when an attack occurs, this coefficient tends to decrease further to -0.80 to -1.

[0053] Therefore, suspicious data can be identified through the measurement of the Pearson correlation coefficient.

[0054] In step 130, the wavelet transform can be performed to prepare data to be input into the deep neural network by activating the high-resolution feature extraction step when suspicious data is detected.

[0055] Through wavelet transform, not only can detailed and useful features be obtained, but data generalization can also be aided. Furthermore, it can improve the effective feeding of data into deep neural networks for additional analysis and anomaly detection.

[0056] Wavelet Transform is a mathematical method for analyzing images and signals. It can perform functions similar to waves by using wavelets, which have limited amplitude and short durations. Wavelets analyze signals across various time-spaces using window scaling and translation. The advantage of Wavelet Transform is that it helps emphasize general or detailed signal analysis by analyzing signals of various dimensions. Compared to traditional Fourier analysis, Wavelet Transform offers advantages such as the identification of frequency and temporal location.

[0057] In a wavelet transform according to one embodiment, data is transformed into fixed-length segments. At this time, each segment may contain 100 data points corresponding to a period of 1 second. Additionally, a wavelet transform can be applied using a 'db8' wavelet with a 'symmetric' mode and 11 levels. Through this, a series of coefficients is generated, and 113 coefficients can be obtained as features for a 100-point input segment. However, since it is not easy to use the wavelet transform results directly as input to deep learning, data preprocessing may be required to construct a consistent input data set for the deep learning model.

[0058] A general-purpose detection method according to one embodiment performs data preprocessing for input into a deep learning model in step 140.

[0059] When processing data for deep learning models based on wavelet transform results, the data can be divided into fixed-length intervals for consistent analysis. In this case, if some intervals are shorter than the standard length (in this case, 100 data points corresponding to a 1-second period) due to the division, it is necessary to standardize the length of all intervals. Therefore, the dimensions can be standardized by filling the empty spaces in short intervals with small replacement values, such as -0.0001. In other words, by standardizing the dimensions of each interval, the data becomes compatible with deep learning models, enabling the model to effectively process and analyze the data.

[0060] In summary, in the 130-step wavelet transform and 140-step preprocessing, the data is divided into 1-second intervals, and the 'db8' wavelet transform is applied with 11 levels and 'symmetric' mode to generate 113 coefficients as features. At this time, to ensure compatibility with deep learning models, the coefficients can be filled with a constant dimension and the blanks can be filled with -0.0001.

[0061] Through preprocessing, the data input to the deep learning model can be composed of a 4D array of [32, 1, 10, 113] dimensions.

[0062] The first dimension

[32] represents the deep learning input batch size. A batch size of 32 means that the network processes 32 samples at a time.

[0063] The second dimension [1] indicates that one data instance or sample is being processed at a time. That is, it represents a single data segment.

[0064] The third dimension

[10] represents the result of a wavelet transform applied to 100 data points. On average, this transform generates about 10 coefficients. Therefore, to accommodate this feature, the data can be organized into segments of 10 coefficients.

[0065] The fourth dimension

[0113] indicates that each of the 10 coefficients obtained from the wavelet transform is enhanced by additional features of the data generation process, and as a result, a total of 113 features are generated for each coefficient, creating a rich dataset for deep learning.

[0066] A general-purpose detection method according to one embodiment may train a deep learning model at step 150 or perform detailed verification through the trained model. Through step 150, the normality or abnormality of the data suspected of being abnormal data can be verified through the deep learning model.

[0067] The deep learning architecture could be ResNet-50 implemented using the PyTorch framework. ResNet-50 is a well-established CNN (Convolutional Neural Network) model known for its deep and efficient architecture.

[0068] The learning rate selected for the model optimization program is set to 0.0001, which is an important hyperparameter affecting training speed and stability.

[0069] Additionally, an early stopping mechanism known as "persistence" or "endurance" can be incorporated into the training process, where training is halted if model performance does not improve during a specific sequence of epochs. In this case, training may be stopped without improvement after 10 generations. These hyperparameter selections and the use of ResNet-50 enable robust and well-tailored deep learning for a given task, focusing on both the model architecture and training strategy to achieve optimal results while avoiding overfitting.

[0071] FIG. 2 shows the configuration of a universal intrusion detection device for vehicle internal network security of a model according to an embodiment of the present invention.

[0072] Referring to FIG. 2, a general-purpose intrusion detection device according to an embodiment includes a data receiving unit (210), a feature extraction unit (220), an initial verification unit (230), and a verification unit (240). At this time, the device may further include a data labeling unit (not shown) that normalizes the received data through timestamp normalization and performs attack data labeling on the normalized data.

[0073] The data receiving unit (210) can receive data from a plurality of CAN (Controller Area Network) sources. At this time, the plurality of CAN data may be data from a different type of vehicle and may include at least one of C-CAN, B-CAN, M-CAN, and P-CAN.

[0074] The feature extraction unit (220) extracts features based on the number of packets generated within a preset time interval for the normalized data.

[0075] The initial verification unit (230) filters data suspected of being abnormal data through initial verification based on features, performs wavelet transform on the data suspected of being abnormal data, and performs data preprocessing for input into a deep learning model.

[0076] At this time, the initial verification unit (230) can determine that the data is suspected of being abnormal data if the value of the Pearson correlation coefficient for the normalized data falls outside a preset range.

[0077] The verification unit (240) verifies whether the data suspected of being abnormal data is normal or abnormal through a deep learning model.

[0079] FIG. 3 is a diagram showing an example of Pearson correlation coefficient measurement according to one embodiment.

[0080] Pearson correlation coefficients can be used to gain a deeper understanding of the relationships between variables and to draw conclusions based on statistical data.

[0081] Referring to FIG. 3, the distribution of correlation coefficient values ​​(311, 313) of data obtained from two different vehicles is distributed in the coefficient range of -0.50 to 0.75 as shown in reference numeral 310, and when an attack occurs, the coefficient decreases to -0.60 or lower as shown in reference numeral 320, which may appear as a sign of a suspicious attack. Through this, a simple and effective means of detecting potential security breaches can be provided.

[0083] FIG. 4 is a diagram illustrating, in its entirety, the concept of universal intrusion detection for vehicle internal network security of a model according to an embodiment of the present invention.

[0084] Referring to FIG. 4, the Gateway (410) receives data from various CAN sources. Data received from various channels can be routed to an intrusion detection device through the Gateway (410).

[0085] Subsequently, the device performs timestamp normalization (420) and proceeds to adjust the time interval of the data for each vehicle based on the time when the data was generated. Through timestamp normalization (420), it is ensured that the time interval is synchronized with the actual data generation process of each vehicle.

[0086] Through feature extraction (430), the number of packets generated within a specific time interval after alignment is quantified and the average time interval between packets is calculated.

[0087] Safe and suspicious data can be identified through the measurement of the Pearson correlation coefficient (440). At this time, the linearity between the number of packets and the average time interval can be checked to find suspicious data.

[0088] Wavelet features (450) are extracted from suspicious data through wavelet transformation. That is, for messages detected as abnormal, a procedure for detailed verification is performed using wavelets.

[0089] Data preprocessing (460) performs the same process as step 140 of FIG. 1.

[0090] The deep learning model (470) verifies whether the input data or message is abnormal. If there are signs of an abnormality, it outputs an abnormality and can send a notification for a warning.

[0092] The device described above may be implemented as a hardware component, a software component, and / or a combination of a hardware component and a software component. For example, the device and components described in the embodiments may be implemented using one or more general-purpose or special-purpose computers, such as, for example, a processor, a controller, an arithmetic logic unit (ALU), a digital signal processor, a microcomputer, a field programmable array (FPA), a programmable logic unit (PLU), a microprocessor, or any other device capable of executing and responding to instructions. The processing unit may execute an operating system (OS) and one or more software applications executed on said operating system. Additionally, the processing unit may access, store, manipulate, process, and generate data in response to the execution of the software. For ease of understanding, the processing unit may be described as being used as a single unit, but those skilled in the art will understand that the processing unit may include multiple processing elements and / or multiple types of processing elements. For example, the processing unit may include multiple processors or one processor and one controller. In addition, other processing configurations, such as parallel processors, are also possible.

[0093] Software may include computer programs, code, instructions, or a combination of one or more of these, and may configure a processing unit to operate as desired or command the processing unit independently or collectively. Software and / or data may be permanently or temporarily embodied in any type of machine, component, physical device, virtual equipment, computer storage medium or device, or transmitted signal wave so as to be interpreted by the processing unit or to provide instructions or data to the processing unit. Software may be distributed over networked computer systems and may be stored or executed in a distributed manner. Software and data may be stored on one or more computer-readable recording media.

[0094] The method according to the embodiment may be implemented in the form of program instructions that can be executed through various computer means and recorded on a computer-readable medium. The computer-readable medium may include program instructions, data files, data structures, etc., either alone or in combination. The program instructions recorded on the medium may be those specifically designed and configured for the embodiment, or they may be those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc. The hardware devices described above may be configured to operate as one or more software modules to perform the operation of the embodiment, and vice versa.

[0095] Although the embodiments have been described above with reference to the limited drawings, those skilled in the art can make various modifications and variations from the description above. For example, suitable results can be achieved even if the described techniques are performed in a different order than described, and / or the components of the described system, structure, device, circuit, etc. are combined or assembled in a form different from described, or replaced or substituted by other components or equivalents.

[0096] Therefore, other implementations, other embodiments, and equivalents to the claims also fall within the scope of the claims set forth below.

Claims

Claim 1 A step of receiving data from different CAN (Controller Area Network) sources of heterogeneous models; a step of normalizing the received data through timestamp normalization and performing attack data labeling on the normalized data to determine whether it is normal or an attack, wherein the timestamp normalization includes standardizing the time intervals of data points generated at different rates from different sources of heterogeneous models based on a common time interval; a step of quantifying the number of packets generated within a preset time interval for the normalized data and extracting features including the quantified number of packets and the average time interval between packets; a step of filtering data suspected of being abnormal data through initial verification based on the features for resource efficiency; a step of performing a wavelet transform on the data suspected of being abnormal data to extract a plurality of wavelet coefficients and performing data preprocessing to input the plurality of wavelet coefficients into a deep learning model; A universal intrusion detection method for internal network security of a heterogeneous model of a vehicle, comprising the step of verifying whether the data suspected of being abnormal data is normal or abnormal through the deep learning model, and the step of filtering the data suspected of being abnormal data through the initial verification, wherein the data is determined to be suspected of being abnormal data if the value of the Pearson correlation coefficient for features including the number of packets and the average time interval between packets is -0.80 or less. Claim 2 In claim 1, the deep learning model is RseNet-50 implemented using the PyTorch framework, which uses input data consisting of a [32, 1, 10, 113] dimension 4D array, and is a general-purpose intrusion detection method for vehicle in-vehicle network security of a model. Claim 3 delete Claim 4 A data receiving unit that receives data from different CAN (Controller Area Network) sources of different machine models; a data labeling unit that normalizes the received data through timestamp normalization and performs attack data labeling on the normalized data to determine whether it is normal or an attack; a feature extraction unit that quantifies the number of packets generated within a preset time interval for the normalized data and extracts features including the quantified number of packets and the average time interval between packets; and an initial verification unit that, for resource efficiency, filters data suspected of being abnormal data through initial verification based on the features, performs a wavelet transform on the data suspected of being abnormal data to extract a plurality of wavelet coefficients, and performs data preprocessing to input the plurality of wavelet coefficients into a deep learning model. A universal intrusion detection device for in-vehicle network security of a heterogeneous model, comprising a verification unit that verifies whether the data suspected of being abnormal data is normal or abnormal through the deep learning model, wherein the initial verification unit determines the data as suspected of being abnormal data if the value of the Pearson correlation coefficient for features including the number of packets and the average time interval between packets is -0.80 or less.

Citation Information

Patent Citations

  • Network traffic anomaly detection method and detection system

    CN114244594A

  • CAN bus intrusion detection method and device based on neural network, and medium

    CN117278296A

  • Universally applicable signal-based controller area network (CAN) intrusion detection system

    US20220374515A1