Received Message Anomaly Detection With Adaptive Timing and Field Checks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anomaly detection methods for in-vehicle networks, such as those using the CAN standard, face challenges in performing effective anomaly detection within limited processing time due to resource constraints and high data volumes.
Innovation Solution
Anomaly detection methods that select appropriate combinations of determination functions based on available execution time, load amount, data amount, and total number of messages, utilizing fields with fixed and variable values, and considering periodicity and message timing, to optimize detection performance within limited processing time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive anomaly detection processes are performed on all received messages, then detection precision is improved, but processing time increases and productivity decreases
Solution Approach 1:
The anomaly detection process is segmented into multiple determination functions (first determination function for message timing, second determination function for message content, etc.), each handling specific aspects of anomaly detection. This segmentation allows the system to perform comprehensive detection while maintaining processing efficiency by executing only relevant determination functions for each message type.
Solution Approach 2:
The system dynamically selects and executes determination functions based on message characteristics and available processing time. The ECU determines which determination functions to execute by considering the type of received message and current processing time constraints, allowing flexible adaptation between detection thoroughness and processing speed.
2Reliability
If multiple determination functions are executed for each received message, then anomaly detection reliability is improved, but device complexity increases
Solution Approach 1:
The detection system is divided into multiple independent determination functions, each responsible for specific detection tasks. This modular structure improves reliability through comprehensive checking while managing complexity by organizing functions into distinct, manageable units that can be selectively executed.
Solution Approach 2:
The ECU is designed to execute multiple determination functions that can handle various message types and anomaly scenarios. This multi-functional approach allows a single system to perform diverse detection tasks, improving reliability across different communication scenarios without requiring separate specialized systems for each case.
3Quantity of substance
If anomaly detection is performed on high-volume message traffic, then detection coverage is improved, but processing time requirements increase
Solution Approach 1:
The system dynamically adjusts the execution of determination functions based on processing time availability and message characteristics. When processing time is limited, the ECU selectively executes only the most critical determination functions, allowing it to maintain detection coverage across high-volume traffic while adapting to real-time processing constraints.
Solution Approach 2:
The system can skip less critical determination functions when processing time is insufficient, focusing computational resources on essential anomaly detection tasks. This selective execution allows the system to process high volumes of messages efficiently by rushing through critical checks while deferring or omitting less urgent analyses.
Data Source
AI summary
In an anomaly determination method for determining an anomaly in a received message, a plurality of messages which include messages that are periodic and each of which includes a first field having a fixed value and a second field having a variable value are each received as the received message, and one of a plurality of combinations to be used for determination each of which includes at least one of a plurality of anomaly determinations including an anomaly determination utilizing a reception timing based on the periodicity or the number of received messages, an anomaly determination utilizing the first field, and an anomaly determination utilizing the second field, is selected according to one or more criteria among available execution time of the anomaly determination method, a load amount, a data amount, and the number of messages.


