Method and system for detecting intruders in heterogeneous vehicular networks by observing times between messages

The system addresses high computational costs and resource demands in automotive network intrusion detection by observing message times, offering efficient and reliable intruder detection with reduced complexity and minimal resource usage.

WO2025244522A1PCT designated stage Publication Date: 2025-11-27INST TECH Y DE ESTUDIOS SUPERIORES DE OCCIDENTE
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/MX2024/050064
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-24
Filing Date
2024-10-29
Publication Date
2025-11-27

AI Technical Summary

Technical Problem

Existing intruder detection systems in automotive networks face high computational costs and resource demands due to entropy calculations, and they may compromise data privacy and rely heavily on connectivity, leading to potential false positives and increased complexity.

Method used

A system that detects intruders by observing the times between messages in automotive networks, using a hardware-based approach with a microprocessor to calculate average message times and generate alerts when deviations occur, reducing computational resources and complexity.

Benefits of technology

This method efficiently detects intruders with minimal computational resources, providing fast and reliable alerts without the need for extensive entropy calculations, ensuring network security and reducing false positives.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure MX2024050064_27112025_PF_FP_ABST
    Figure MX2024050064_27112025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a system for detecting intruders in heterogeneous vehicular networks by observing the times between messages, characterised in that it comprises: an observation device for observing delivery times between data packets and comprising a transceiver as a connection interface for connecting to the bus of a communication network of a vehicle, and which adapts the logic signals of the observation device to the electrical levels of the bus; and a microprocessor configured with an averaging subsystem configured to calculate the time elapsed between consecutive data packets transported in the communication network of a vehicle and store them in a memory, establishing an average time threshold; said system also comprising an intruder alert generator which is in communication with the observation device for observing delivery times between data packets and which is configured to generate an intruder alert when a time less than the average time threshold is calculated, and transmission means for transmitting the intruder alerts inside or outside the vehicular system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND SYSTEM FOR INTRUDER DETECTION IN HETEROGENEOUS AUTOMOTIVE NETWORKS BY OBSERVING THE TIMES BETWEEN MESSAGES

[0002] FIELD OF INVENTION

[0003] The present invention relates to electronic systems in general, and in particular to electronic systems for transmitting an electrical alarm signal after detecting a signal to indicate presence, absence, or movement, which applies to motor vehicles, and more specifically to a method and system for detecting intruders in heterogeneous automotive networks by observing the times between messages.

[0004] BACKGROUND OF THE INVENTION

[0005] Automotive cybersecurity is defined by the following pillars: risk reduction, prevention, and mitigation. Although most technological development focuses on prevention, the patent application proposed in this document helps mitigate cyberattacks within a vehicle. Within the security activities defined in ISO / SAE 21434, this system falls under clause 8, cybersecurity monitoring.

[0006] An "internal automotive network" refers to the internal communication system that connects the various electronic components within a vehicle. This system allows the different devices and systems inside the car to exchange data and communicate with each other efficiently.

[0007] The Engine Control Unit (ECU) is the brain of the engine management system and controls various vehicle functions, such as fuel injection, ignition, and transmission. There may be several specialized ECUs for different systems within the vehicle.

[0008] Sensors are devices that collect data on various vehicle conditions, such as speed, engine temperature, throttle position, etc. The data collected by the sensors is sent to the ECU for processing and control.

[0009] Actuators, on the other hand, are electronically controlled devices that perform specific actions in response to instructions from the ECU. For example, actuators can control the opening and closing of intake and exhaust valves, adjust brake pressure, and so on. Meanwhile, the communication network is the infrastructure that connects all the electronic components of the vehicle. It can be based on different communication protocols, such as the Controller Area Network (CAN), Local Interconnect Network (LIN), the FlexRay communication protocol for automotive data buses, and others. These protocols allow for fast and reliable data transmission between the various devices.

[0010] The term “CAN” (Controller Area Network) bus is commonly used in Spanish, especially in technical and automotive contexts. The CAN bus is a serial communication protocol that allows microcontrollers and devices to communicate with each other without the need for a central computer. It is widely used in the automotive industry to interconnect various electronic systems within a vehicle.

[0011] The term "bus" is also commonly used in technical and engineering contexts to refer to communication systems between electronic components. An alternative in Spanish for the term "bus" could be "canal" or "red" in some contexts.

[0012] Although "bus" is an English word, its use has become so widespread that it has been integrated into the technical lexicon in Spanish without being translated.

[0013] The data bus is the physical medium through which data is transmitted in a communication network. It can be traditional cabling or even a wireless network in more modern systems.

[0014] Based on the above, the term “CAN bus” will be used from now on.

[0015] Engine control units (ECUs) exchange information through the vehicle's internal networks. Additionally, user support systems send details about the vehicle's surroundings. This information exchange is heterogeneous, depending on the origin, destination, and type of information. A network is considered heterogeneous if, at any point within the network, the information circulating uses different protocols.

[0016] It is worth noting that current automotive systems also exchange information via Bluetooth, 802.11 (standard designation originally developed for wireless communications) or 5G, which creates a diverse and vulnerable communication environment.

[0017] This patent application describes a new system for detecting intruders in vehicular networks by observing communication behavior. In packet-switched networks, entropy is commonly used to observe the number of packets, the source IP address, the destination IP address, and ports. This allows for the calculation of the entropy (amount of information) present in the communication exchange. In vehicular systems, profiles have been developed and experiments have been conducted that relate the functional states of the vehicle to entropy.

[0018] Using entropy (the amount of information) to detect intruders requires calculating the probability of a particular message originating from or destined for a specific message. Once the probability is obtained, the entropy of each message can be calculated. This requires a high computational cost (the resources needed to execute an algorithm or process in terms of time and space) for the detection system. When a significant change occurs within the messages on the automotive network, the system generates an alert associated with an intruder. One disadvantage is that an intruder with low data transfer generates a small change in entropy.

[0019] An intruder is defined as any system or user not initially considered in the vehicle's design. The intruder has the ability to collect information from the network and insert it into the vehicle's communication bus. The messages introduced by the intruder can modify the vehicle's operation and, therefore, jeopardize the safety of passengers and others outside the vehicle, or provide information for potential hacking.

[0020] When an intruder gains access to the communication channel and inserts messages into the bus, they can send commands or request information from each ECU in the vehicle. This is considered a security breach. Ensuring the security of information exchange is crucial, meaning that only the intended recipient can understand it. Furthermore, in addition to guaranteeing integrity, it is critical for a system to detect when an intruder is within its communication channel. The system proposed in this patent addresses intruder detection.

[0021] Entropy is related to the uncertainty of information. To calculate entropy, the set of all possible messages “m” to be sent is defined; the message characteristics must include the origin and destination of the information. Each possible message is assigned a probability “P”. mThis probability is associated with the number of times the message “m” passes through the car's internal communication channel. Some messages are more frequent (those common to the user and the engine's operation) and will have a higher probability than those that only occur under particular circumstances. Each message contains a certain amount of information. m = 1 / Pm. Entropy is defined as the average amount of information observed in the communication channel H = E{l m}, where “E” is the expectation or average operator.

[0022] However, calculating probability requires a high computational cost due to the following processes: collecting the information, sorting it by ascending values, calculating its density function, and finally its entropy. If this process is required for multiple variables (ports, packets, information, etc.), the computational resources (resources needed to execute an algorithm or process in terms of time and space) are compromised.

[0023] To calculate entropy, an observation with sufficient data is required to determine the density function P. m This implies that in addition to observing the messages on the communication channel, it is necessary to keep a record of the frequency of observation of each type of message “m”.

[0024] In vehicular systems, studies have been conducted and experiments have been carried out that relate functional states of the automobile to entropies.

[0025] There are software platforms currently on the market (https: / / www.snort.org / ) that compare known attacks with network behavior. This document describes a platform that requires minimal resources and low computational complexity (resources needed to execute an algorithm or process in terms of time and space) for intrusion detection, as well as minimal observation of message flow between ECUs.

[0026] A search was conducted to determine the closest prior art and the following documents were found:

[0027] Patent application US20210256854A1 by Alieiev Roman et al., filed on August 23, 2019, describes an apparatus in which one or more interfaces are configured to communicate in a mobile communication system, and a control module configured to control the one or more interfaces. The control module is further configured to receive one or more messages from one or more vehicles, to detect whether a potential intruder is present in a vehicle platoon based on one or more messages from one or more vehicles and based on a warning message activation condition, and to generate a warning message if a potential intruder is detected.

[0028] The fact that the control module is configured to receive messages from other vehicles, as well as to generate and transmit warning messages, raises concerns about data privacy and security. There is a risk that information about vehicle speed and location could be intercepted or misused by third parties, potentially compromising the safety and privacy of drivers and passengers. Furthermore, the proper functioning of the described system depends heavily on the availability and reliability of the mobile communication system's connectivity. If there are problems with the communication network, such as lack of coverage or service interruptions, the system might not function correctly or could even become useless in certain circumstances.

[0029] In summary, while the described device has the potential to improve safety and communication between vehicles, it also raises concerns about data privacy and security, the possibility of false positives, dependence on connectivity, and the increased cost and complexity of vehicles.

[0030] Patent document CN110445810B by He Zhanbo et al., dated September 12, 2019, was located. It describes a detection method based on a multi-level feedback queue, implemented using a detection system, a vehicle control network topology detection module, a vehicle control network protocol analysis module, a vehicle control network device vulnerability scanning module, a security event and vulnerability proof-of-concept library, a security event priority queue module, a security event backup queue registration module, and a security event injection detection module. This document was not identified in Mexico.

[0031] Although the invention promises to improve the security of the vehicle control network, it could also face challenges related to implementation, resource consumption, detection accuracy, reliance on security updates, and interoperability with existing systems. These aspects must be carefully considered when evaluating its feasibility and effectiveness in the real world.

[0032] Also located was document CN201910843169A by Wan Zhenhua and Zhang Haichun, dated September 6, 2019, which describes a method for obtaining vehicle data through a pre-established automotive network. The vehicle data is analyzed. The results of the analysis are displayed on an interface. The security level of the automotive network is characterized. A simulation of data transmission and a simulation of vehicle data replay are performed through the automotive network according to the security level. Vulnerability information in the automotive network is detected.

[0033] Although the method aims to characterize the security level of the automotive network and detect vulnerability information, it could also face challenges related to its reliance on a pre-established network, limitations in vulnerability detection, implementation cost and complexity, potential false positives / negatives, difficulties in updating and adapting, and possible impacts on vehicle performance. These aspects should be carefully considered when evaluating the feasibility and effectiveness of the method in practice.

[0034] Also located was document KR2347461 B1 by Oh Young Jin et al., dated August 4, 2021, which describes a device having an antenna unit installed on the exterior of the vehicle for remote control or autonomous movement by receiving a radio signal. A communication unit communicates with a vehicle control unit to control the moving object. A signal collection unit generates signal collection information by converting the radio signal into a frequency domain. A control unit, i.e., a user terminal, generates warning information to alert of a hacking risk and transmits the warning information through the communication unit. The control unit establishes a user of the moving object through the communication unit.

[0035] While the proposed device aims to facilitate remote control or autonomous movement of the vehicle, it also faces potential challenges related to safety, reliability, interference, vulnerability to physical damage, and the complexity of installation and maintenance.

[0036] Another document located is document KR1446525B1 by Kim Ki Woo and Kim Byung Hyun, dated September 27, 2013, which reveals a system with a decision criteria storage unit that stores the preset standard for determining vehicle hacking attempts based on the message transmitted to the vehicle gateway. A hacking attempt detection unit detects vehicle hacking attempts based on the preset standard stored in the decision criteria storage unit. A warning signal output unit emits the preset warning signal when a vehicle hacking attempt is detected.Although the system aims to detect vehicle hacking attempts, it also faces potential challenges related to its reliance on pre-established standards, limitations in detection capabilities, possible obsolescence, interference and false alarms, as well as the complexity of its adjustment and configuration. These aspects must be carefully considered when evaluating the system's effectiveness and practical viability.

[0037] Another document that was located is document KR1920833B1 KIM KYUNG OON, dated September 6, 2017, which describes a system with a main unit connected between a vehicle network and an external gateway to receive a packet from an external system. An Intrusion Detection and Blocking Device (IDPS) engine collects the packet received from a router and detects an abnormal packet corresponding to a signature on the attack packet types defined in pre-stored rule information. A connector transmits a normally determined packet to the external gateway and connects to the external system. The IDPS engine discards the packet on a communication port if an abnormal packet is received.This invention also faces challenges related to dependence on predefined rules, the potential generation of false positives, the impact on connectivity and vehicle performance, the complexity of configuration and maintenance, and the potential impact on interoperability.

[0038] Another document located is US20220161828A1 by Mikhailov Dmitry Mikhailovich et al., dated March 19, 2020, which describes a vehicle electronic control system protection system that includes at least one vehicle electronic module and a vehicle control system protection device connected via electrical conductors to the interface communication line. The vehicle control system protection device comprises a vehicle parameter monitoring and control unit, a passive scanning unit for the interface communication lines, a spectral analysis unit for the interface communication line, a malicious command detection and suppression unit, and a unit for detecting and adjusting interference from an unauthorized transceiver within a specified frequency range.The passive scanning unit for the interface communication lines, the unit for spectral analysis of the interface communication line, and the unit for detecting and suppressing malicious commands are all connected to the interface communication line. Although the system aims to protect the vehicle's electronic control systems against unauthorized intrusion, it also faces potential challenges related to implementation complexity and costs, interference with normal vehicle operation, possible false positives, dependence on security updates, impact on vehicle performance, and the complexity of integration with existing systems.

[0039] Also located was document WO2018146028A1 by Schoch Elmar and Corbett Christopher, dated February 5, 2018, which describes a method for receiving message data from a motor vehicle via a respective data network at a stationary central server device, using the motor vehicle's control units. A communication device receives the respective message data from the motor vehicles. The message data includes a predetermined minimum deviation from a predetermined normal behavior and a predetermined minimum match of the message data signal with a predetermined test pattern. A recognition device detects a matching portion of the message data from the motor vehicles as an attack signal.A defensive device checks whether attack data meets a predetermined criticality criterion and activates a predetermined defensive measure when the criticality criterion is met. The matching portion is detected based on a pattern recognition and machine learning method.

[0040] Although the method aims to detect and respond to attacks on vehicle electronic control systems, it also faces potential challenges related to sensitivity to false positives and false negatives, dependence on predetermined criteria, complexity and resources required for machine learning, potential impacts on vehicle system performance, dependence on connectivity and network infrastructure, and potential challenges in implementation and configuration.

[0041] The method and system for detecting intruders in heterogeneous automotive networks by observing the timing between messages resolves the problems described in this section by detecting an intruder when they enter information attempting to control a specific ECU. The proposed system does not require storing statistics or information about the characteristics of the messages transmitted through the automotive network. By not requiring entropy calculations, the proposed system reduces the computational resources (resources needed to execute an algorithm or process in terms of time and space) required to detect an intruder.

[0042] OBJECTIVES OF THE INVENTION

[0043] The main objective of the present invention is to make available a method and system for intruder detection in heterogeneous automotive networks by observing the times between messages, allowing intruders to be detected through message variation in a fast and efficient manner by observing only the time between them.

[0044] Another objective of the invention is to make available a method and system for detecting intruders in heterogeneous automotive networks by observing the times between messages, which also allows constant observation of the average behavior between messages through a connection to the communication system between the ECUs of a vehicle.

[0045] Another objective of the invention is to make available a method and system for detecting intruders in heterogeneous automotive networks by observing the times between messages, which also allows for comparison of the behavior of using the car while it is on and previously in order to obtain a reference with the average message sending time.

[0046] Another objective of the invention is to make available a method and system for detecting intruders in heterogeneous automotive networks by observing the times between messages, which also allows generating an alert when there is a variation in the average; this alert can be transmitted to other devices within the car or to the cloud.

[0047] And all those qualities and objectives that will become apparent when making a general and detailed description of the present invention supported by the illustrated modalities.

[0048] BRIEF DESCRIPTION OF THE INVENTION

[0049] In general, this project designs a new system to detect intruders in vehicular networks by observing communication behavior. In packet-switched networks, entropy is commonly used to observe the number of packets, the source IP address, the destination IP address, and ports. This allows for the calculation of the entropy (amount of information) present in the communication exchange.

[0050] Within the vehicle system, a vehicle communications network is established as infrastructure that connects all the car's electronic components that support its operation, such as sensors, ECUs, and actuators. Sensors exchange information about physical variables and input it into the car's internal packet message network; actuators perform a specific operation when they receive certain commands; and ECUs are small systems with a microprocessor capable of decoding the information exchanged within the network. They typically have controllers that convert the electrical signal from the automotive network into a digital format that can be stored in the ECU's memory or processed by the microprocessor.

[0051] It is understood that the times between messages correspond to the times calculated between data packets measured within the vehicular communication bus.

[0052] The system for detecting intruders in heterogeneous automotive networks by observing the times between messages is characterized by comprising a device that observes the delivery times between data packets, comprising a transceiver as a connection interface to the bus of a vehicle's communications network, and which adapts the logical signals of the observing device to the electrical levels of the bus; a microprocessor configured with an averaging subsystem configured to calculate the time elapsed between consecutive data packets carried on the vehicle's communications network and store them in a memory, establishing an average time threshold;said system further comprising an intruder alert generator in communication with said data packet delivery time observer device, configured to generate an intruder alert when a time less than the average time threshold is calculated, and means of transmitting said intruder alerts internally or externally to the automotive system.

[0053] This microcontroller includes memory and communication ports; it also includes interfaces for adjusting voltages to different protocols.

[0054] This system is hardware-based and connects via wired or wireless connection to the car's communication network.

[0055] The means of transmitting these intruder alerts are selected from the group consisting of an automotive communication connection of a vehicle's own communication network and a wired or wireless interface for sending alerts to different receiving destinations, such as the cloud, a server, a smart device, or a central station.

[0056] This wired alert sending interface is selected from the group consisting of Ethernet, RS-232, RS-485, and USB communication standards.

[0057] This wireless alert sending interface is selected from the group consisting of WiFi, a mobile communications network such as GSM, LTE / 5G, LoraWAN, Bluetooth, and Zigbee.

[0058] The system can connect to the cloud and change some records in order to generate the alert; it can also notify the driver or send the alert via wired or wireless means that an intruder is inside the automotive network.

[0059] The messages are defined in the system and the system can be connected to a transmitter or can use the automotive communication connection to send them.

[0060] The manufacturer can adjust the average time depending on the automotive dynamics; the user can only receive the intruder alert.

[0061] This intruder alert generator, upon receiving a new consecutive time counter entry, performs two actions: a) it calculates the average time with the new data, and b) it compares whether the value of the new entry is significantly different from the average time threshold. If it is significantly lower, it generates a security alert.

[0062] The system connects to the vehicle's communication bus and monitors the time gaps between data packets. When an intruder reaches the communication bus, the transmission rate within the channel increases. The system records data on both normal and abnormal operation. It continuously calculates the average frequency of data messages and compares them over time; when this average decreases, the system generates an alert.

[0063] The system includes an averaging subsystem that calculates average times across different time windows. This granularity facilitates detection because once an alert is generated, the time window can be narrowed to observe the intruder's activity within the communication channel. The system can send an alert internally within the automotive system or externally. This alert can contain information about the observed abnormal activity. The alert can also be communicated to other ECUs for forensic analysis.The system is feasible for implementation in automotive systems because it uses a moving average structure to calculate the average. This structure allows for the calculation of previous averages with reduced memory and a small number of arithmetic operations. The system is compatible with automotive communication systems, which facilitates sending an alert when an intruder is detected.

[0064] The system is scalable and can monitor one or more communication systems. It can be used to analyze multimedia communications, communications within the automotive train, for a specific system, or to protect communication between systems. Its compact size and ease of connection within the automotive bus allow for scalability and reuse.

[0065] This system detects intruders in vehicular networks based on the observation of behaviors; the observation variable is the time between information packets.

[0066] This system detects intruders in heterogeneous vehicular networks based on behavioral observation; the observed variable is the time between information packets. Since entropy observation has proven effective for intruder detection and profiling, Sanov's theorem relates the entropy of the variable to the probabilistic survival function. Therefore, observing the times between packets is computationally less demanding (resources required to execute an algorithm or process in terms of time and space) and provides information about anomalous network behavior.

[0067] It differs in the following main aspects:

[0068] • The characteristics of the messages are observed, not extracted.

[0069] • The time between sent messages is observed, which computationally (resources needed to run an algorithm or process in terms of time and space) is more economical and also allows flexibility for heterogeneous networks (CAN, LIN, FlexRay, MOST, Ethernet automotive, among others).

[0070] • Alerts are generated from the analysis of the times between packets to indicate that there is anomalous behavior in the vehicular network.

[0071] As proof of the implementation of the intruder detection system of the present invention, the following examples are included, without limiting the scope of said intruder detection system:

[0072] A proof of concept was performed for intruder detection in automotive networks with various parameters in the attack start and end ranges in different milliseconds (ms):

[0073] • Attack start and end at 1000 ms • Attack start and end at 100 ms

[0074] • Start and end of attack at 5000 ms

[0075] • Start and end of attack at 10000 ms

[0076] • Start and end of attack at 10 ms

[0077] • Start and end of attack at 1 ms

[0078] The invention also provides a method for detecting intruders in heterogeneous automotive networks by observing the times between messages, characterized by comprising: a) Connecting an intruder detection system via a wired or wireless interface to the bus of a vehicle's communications network; b) Calculating the time elapsed between consecutive data packets carried on the vehicle's communications network and storing it in memory, establishing an average time threshold; c) Generating an intruder alert when the calculated time between consecutive data packets carried on the vehicle's communications network is less than the preset average time threshold;d) Transmit the detected intruder alert, through selected transmission means of the group consisting of an automotive communication connection of the vehicle's own communication network and a wired or wireless interface for sending alerts to different receiving destinations, such as the cloud, a server, a smart device or a central station.;

[0079] To better understand the characteristics of the invention, the following drawings, which are illustrative but not limiting, are included as an integral part of this description.

[0080] BRIEF DESCRIPTION OF THE FIGURES

[0081] Figure 1 shows a general schematic diagram of the system for intruder detection in heterogeneous automotive networks by observing the times between messages, in accordance with the present invention.

[0082] Figure 2 shows a schematic diagram of the data packet delivery time observer device of the system for intruder detection in heterogeneous automotive networks by observing the times between messages, in accordance with the present invention.

[0083] Figure 3 shows a flowchart of the system operation for intruder detection in heterogeneous automotive networks by observing the inter-message timings. Figure 4 shows a block diagram illustrating the detection of an intruder on the vehicle bus by observing the communication behavior through the system for intruder detection in heterogeneous automotive networks by observing the inter-message timings, according to the present invention.

[0084] Figure 5 shows a block diagram of the averaging subsystem of the data packet delivery time observer device of the system for intruder detection in heterogeneous automotive networks by observing the times between messages, in accordance with the present invention.

[0085] Figure 6 shows a schematic diagram of the system for intruder detection in heterogeneous automotive networks by observing the times between messages, illustrating a communication interface that transmits alerts to the cloud, in accordance with the present invention.

[0086] Figure 7 shows a schematic diagram of a system test setup for intruder detection in heterogeneous automotive networks by observing the times between messages, showing an attacker.

[0087] Figure 8 shows an illustration of a vehicle showing the interconnection of different engine control units (ECUs) interconnected with each other and with the intruder detection system of the present invention.

[0088] Figure 9 shows an observation graph of an intruder attack, showing the average times measured within a vehicle communications network bus by the intruder detection system of the present invention and the execution times of the packet transmission times calculation in a period, showing the beginning and end of an intruder attack.

[0089] For a better understanding of the invention, a detailed description of some of its modalities will be given, shown in the drawings that are attached to this description for illustrative but not limiting purposes.

[0090] DETAILED DESCRIPTION OF THE INVENTION

[0091] The characteristic details of the system for intruder detection in heterogeneous automotive networks by observing the times between messages are clearly shown in the following description and in the accompanying illustrative drawings, with the same reference symbols serving to indicate the same parts. According to Figures 1 and 2, the system for intruder detection in heterogeneous automotive networks by observing the times between messages comprises a device for observing the delivery times (t) between data packets (1), which includes a transceiver as a connection interface (2) to the bus (3) of a vehicle communication network (4), and which adapts the logic signals of the observing device to the electrical levels of the bus (3);a microprocessor (5, see figure 2) configured with an averaging subsystem configured to calculate the time elapsed between consecutive data packets carried on the communications network of a vehicle and store them in a memory (6, see figure 2), establishing an average time threshold; said system further comprising an intruder alert generator (7, see figure 1) in communication with said time observer device (t) of delivery between data packets (1), configured to generate an intruder alert when a time less than the average time threshold is calculated and means of transmitting intruder alerts (8) (9) internally or externally to the automotive system, for the illustration of figure 2 the alerts are sent to the cloud (12);But as described in the brief description, alerts can be transmitted via an automotive communication connection of a vehicle's own communications network and a wired or wireless alert sending interface to different receiving destinations, such as the cloud (12), a server, a smart device or a central station.

[0092] A transceiver, acting as a connection interface (2) to the bus (3) of a vehicle's communications network (4), is a system that adapts the signal generated by the microprocessor (5, see Figure 2) to the voltage levels or wireless signals of the automotive system. The microprocessor (5, see Figure 2) is a system element that manages information and calculates the average of the automotive messages. The means of transmitting intruder alerts (8) (9) can be an interface to the cloud (12), which adapts the alert generated by the microprocessor for wired or wireless transmission. Information is stored in memory (6, see Figure 2) to average the time between messages and thus provide a reference for normal behavior (without intruders).

[0093] Figure 3 shows a flowchart where the system continuously monitors (measures) the delivery time between data packets using the data packet delivery time monitor (1, see Figures 1 and 2) on the automotive system's communication bus (3, see Figures 1 and 2). The granularity of the observations depends on the memory and processing resources of the safety-related ECU. The system in Figure 3 shows a startup, and the data packet delivery time monitor (1, see Figures 1 and 2) calculates the average time (tp) between packet deliveries using a regression system that requires minimal storage. The comparator block stores the average time (tp) between packet deliveries between the ECUs of a vehicle's communication network (4, see Figure 1). This stored average time (tp) between packet deliveries has been observed to be generally constant.If the measured time (tm) decreases relative to the average time (tp) between packet deliveries, then an intruder is considered to be present and an attack is configured, generating an alert in the intruder alert generator (7, see Figure 1). If the average time (tp) drops significantly, different types of alerts can be generated, some preventive and others indicating a greater vulnerability.

[0094] Once an intruder is detected (9), the system generates an alert via the intruder alert generator (7, see Figure 1). This alert can be a plain text message, a message with different tones, or identifiers depending on the severity. The detection system passes the information to the intruder alert transmission media (8) (9), which is responsible for sending the information to the vehicle's own communication network or a wired or wireless alert transmission interface to different receiving destinations, such as the cloud (12), a server, a smart device, or a central station.

[0095] Figure 4 shows the average time (tp) calculated by the time-observing device (t) for data packet delivery (1) between the ECUs. This average time (tp) is established when an intruder device attempts to communicate with the ECUs already in operation. It can be observed that the average time (tp) measured between packets decreases due to the presence of malicious packets from the intruder (9), establishing an attack time (ta) (tp>ta). The intruder (9) will attempt to send messages constantly in order to control the vehicle's devices. The detection system bases its operation on observing this packet delivery time to detect when there is a decrease in the attack times (ta).

[0096] According to Figure 5, the averaging subsystem (10) of the time (t) observer device between packets (1, see Figures 1 and 2) of the data system for intruder detection in heterogeneous automotive networks by observing the times between messages, in accordance with the present invention, where it is shown that said averaging subsystem (10) measures the packet delivery time (t) and calculates the average time (tp) between packet deliveries using a regression system which requires little storage.

[0097] Figure 6 illustrates the attack alert detection system, item (11), which is defined by the data packet delivery time observer device (1, see Figures 1 and 2) and the intruder alert generator (7, see Figure 1) in communication with said data packet delivery time observer device (1, see Figures 1 and 2). This system is configured to generate an intruder alert when the calculated time is less than the average time threshold and means of intruder alert transmission (8), either internally or externally to the automotive system. Intruder alerts are sent to the cloud (12); however, as described in the brief description, alerts can also be transmitted via an automotive communication connection on the vehicle's own communication network and a wired or wireless alert sending interface to various receiving destinations, such as the cloud, a server, a smart device, or a central station.

[0098] According to Figure 7, a schematic diagram of a system test setup for intruder detection in heterogeneous automotive networks is shown by observing the timings between messages, revealing an attacker. In this figure, the vehicle communication bus (3) (CAN bus) of a vehicle communication network (4, see Figure 1) “heterogeneous automotive networks of the vehicle system” can be illustrated, comprising at least one or a plurality of engine control units (ECUs), a plurality of sensor elements (13) for sensing various vehicle conditions, and electronically controlled actuators (14) that perform specific actions in response to instructions from the ECUs, which adapt the logic signals of the board to the electrical levels of the bus (3) “CAN bus”;a time observer device (1) comprising a transceiver as a connection interface (2, see figure 2) to the “CAN bus” (3) of a vehicle communications network (4, see figure 1), and adapting the logical signals of the observer device to the electrical levels of the bus (3), and comprising a microprocessor (5, see figure 2) configured with an averaging subsystem (10, see figure 5) configured to calculate the time elapsed between consecutive data packets carried on the vehicle communications network (4, see figure 1) and store them in a memory (6, see figure 2), establishing an average time threshold;said system further comprising an intruder alert generator (7, see figure 1) in communication with said data packet delivery time observer device (t) (1), configured to generate an intruder alert (9) when a time less than the average time threshold is calculated and means of intruder alert transmission (8, see figure 2) (9) internally or externally to the automotive system, the alerts are sent to the cloud (12);However, as described in the brief description, alerts can be transmitted via an automotive communication connection from a vehicle's own communication network and a wired or wireless alert sending interface to different receiving destinations, such as the cloud (12), a server, a smart device, or a central station. The test system, as shown in Figure 7, illustrates a terminal connected remotely via Ethernet to establish an SSH connection for data visualization and calculations through a visualization module (15). Any computer with the necessary software can be used to establish a connection with the terminal to observe all the traffic circulating on the bus (3), "the CAN network," to measure the times between each of the packets, as well as the implementation of a calculation algorithm.

[0099] The system connects to the vehicle's communication bus (3) and monitors the time gaps between packets. When an intruder (9) or attacker (16) reaches the communication bus (3), the rate at which information packets are sent within the channel increases. The system records data on both normal and abnormal operation. It continuously calculates the average frequency of information messages and compares them over time. When the average frequency decreases, the system generates an alert.

[0100] The system contains an averaging subsystem (10, see Figure 5) that allows it to calculate average times across different time windows. This granularity facilitates detection because once an alert is generated, the time window can be reduced, allowing observation of the intruder's activity (9) within the communication channel. The system can send an alert internally within the automotive system or externally via an intruder alert generator (7, see Figure 1) in communication with the aforementioned device that monitors the delivery times (t) between data packets (1) and with the vehicle's CAN bus (3). This alert can contain information about the observed abnormal activity. The alert can also be communicated to other ECUs for forensic recording purposes.

[0101] The system includes a timer. This timer is activated when a message is present on the communication bus and stops when the next consecutive message is transmitted. The time recorded by the timer is averaged within this block to generate an average time.

[0102] Test example 1.

[0103] For the attacker (16) shown in Figure 7, an embedded system running the operating system, preferably “Linux®”, is used; but it can be another operating system and already has the necessary drivers to connect to a CAN network of the vehicle system. It is not necessary to develop any specific program or code to inject data packets into the network; only the necessary parameters for the use of the hardware on the card are configured and activated. The attacker (16) sends data packets regardless of content and recipient, only with a specific period and duration.

[0104] For the device that observes the delivery times (t) between data packets (1), as mentioned previously, implementing a program is not necessary for using the CAN port. However, it is necessary to observe all the traffic circulating through the CAN network in order to measure the times between each packet, as well as to implement the algorithm that is the subject of these tests. The obtained and calculated data are printed on the console where the developed program is running.

[0105] For the purpose of conducting the test and based on the requirements described above, it was decided to use as an embedded system, a board called “Beagle Bone Black”, based on a Texas Instruments™ Sitara™ processor and which houses the Linux operating system.

[0106] Figure 8 illustrates a vehicle showing the interconnection of different engine control units (ECUs) interconnected with each other and with the intruder detection system (SDI) of the present invention. The intruder detection system (SDI) can be connected to the communication channel where increased security is desired. The system can detect different types of wired or wireless media. The system is compatible with the communication protocol used by the rest of the vehicle.

[0107] Test results

[0108] According to Figure 9, it shows a graph of the observation of an intruder attack (9), where the average times measured within the communication network bus of a vehicle (4) by the intruder detection system of the present invention are shown, and the execution times of the calculation of packet transmission times in a period, showing the beginning and end of an intruder attack (9).

[0109] During the different tests, large amounts of numbers were obtained, which are difficult to interpret at first glance, so they are presented graphically for a better and faster interpretation of the results obtained in all the tests performed.

[0110] The intruder detection system was tested on an Audi vehicle within an experimental panel. This panel houses the entire electrical system, including all the ECUs. The system was started, simulating that the car was running, and the average time between messages was observed to be 7500 microseconds. The first intruder (9) sent messages to the system at a rate of 1 second, and the average time within the system was observed to be 7400 microseconds. In the second experiment, messages were sent to the system every 0.1 seconds, and the average decreased to 7000 microseconds. Finally, a test was conducted with messages sent to the system every 5 seconds, and no change in the average time was observed.

[0111] To calculate the average, two observation windows are used. A shorter window requires fewer resources, but the resulting value is more volatile. One window is 100 microseconds, and the second is 200 microseconds. Based on observations, the 200-microsecond window is recommended due to its stability and lower probability of triggering a negative alert.

[0112] All connection methods between the detection system, all its components, and the ECU systems can be wired or wireless. Likewise, the system that generates the alert can do so via wired or wireless means.

[0113] The invention has been described sufficiently so that a person with average knowledge in the subject can reproduce and obtain the results mentioned in the present invention.

Claims

CLAIMS Having sufficiently described the invention, the following claims are claimed as property.

1. A system for detecting intruders in heterogeneous automotive networks by observing the times between messages, characterized by comprising a device for observing delivery times between data packets, comprising a transceiver as a connection interface to the bus of a vehicle's communications network, and adapting the logical signals of the observing device to the electrical levels of the bus; a microprocessor configured with an averaging subsystem configured to calculate the time elapsed between consecutive data packets carried on the vehicle's communications network and store them in a memory, establishing an average time threshold;said system further comprising an intruder alert generator in communication with said data packet delivery time observer device, configured to generate an intruder alert when a time less than the average time threshold is calculated, and means of transmitting said intruder alerts internally or externally to the automotive system.

2. The system for detecting intruders in automotive networks heterogeneous by observing the times between messages, according to claim 1, characterized in that said microcontroller comprises a memory, communication ports and interfaces for adjusting the voltages to the different protocols.

3. The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 1, characterized in that it comprises wired or wireless connection means for connecting to the automotive communication network.

4. The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 1, characterized in that said means of transmitting said intruder alerts are selected from the group consisting of an automotive communication connection of the vehicle's own communication network and a wired or wireless interface for sending alerts to different receiving destinations, such as the cloud, a server, a smart device or a central station.

5. The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 4, characterized in that This wired alert sending interface is selected from the group consisting of Ethernet, RS-232, RS-485, and USB communication standards.

6. The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 4, characterized in that said wireless alert sending interface is selected from the group consisting of WiFi, a mobile communications network such as GSM, LTE / 5G, LoraWAN, Bluetooth and Zigbee.

7. The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 1, characterized in that it is configured to operate one or more communication systems, analyze multimedia communications, communications within the automotive train, and to protect communication between systems. 8.- The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 1, characterized in that the generated alerts are selected from the group consisting of a plain text message, a message with different tones or identifiers, depending on the severity. 9.- The system for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 1, characterized in that said heterogeneous automotive networks are selected from CAN, LIN, FlexRay, MOST, Ethernet automotive, among others.

10. A method for detecting intruders in heterogeneous automotive networks by observing the times between messages, characterized by comprising: a) Connecting an intruder detection system via a wired or wireless interface to the bus of a vehicle's communications network; b) Calculating the time elapsed between consecutive data packets transmitted on the vehicle's communications network and storing them in memory, establishing an average time threshold; c) Generating an intruder alert when the calculated time between consecutive data packets transmitted on the vehicle's communications network is less than the pre-established average time threshold;d) Transmit the detected intruder alert, through selected transmission means of the group consisting of an automotive communication connection of the vehicle's own communication network and a wired or wireless interface for sending alerts to different destinations; receivers, such as the cloud, a server, a smart device, or a central station.

11. The method for detecting intruders in heterogeneous automotive networks by observing the times between messages, according to claim 10, characterized in that said intruder alerts are sent to the other ECUs for forensic recording.

Citation Information

Patent Citations

  • System and method for anomaly detection in diagnostic sessions in an in-vehicle communication network

    US10440120B2

  • Automotive cybersecurity

    US10630699B2

  • System and method for time based anomaly detection in an in-vehicle communication network

    US20160381068A1

  • End-to-end controller protection and message authentication

    US20190207950A1