Vehicle Bus Attack Detection via Communication Rule Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting hacker attacks on vehicle bus systems, such as the CAN bus, are not optimal in terms of accuracy and often result in false positives, requiring substantial hardware and software investments, and can lead to the shutdown of critical vehicle functions.

Innovation Solution

An attack detection method that analyzes messages received via the bus system against predefined communication rules, allowing for efficient detection of deviations and potential attacks without the need for a learning phase or complex encryption, thereby reducing false positives and enabling robust detection of malicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If complex encryption and learning phases are used for attack detection, then detection accuracy improves, but device complexity and implementation cost increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidhardware and software investment
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The attack detection function is segmented into a separate dedicated device that monitors bus traffic independently from the main control units. This segmentation allows complex detection logic to be isolated without increasing the complexity of individual control units, while maintaining high detection accuracy through specialized analysis of communication patterns against predefined rules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention uses simple, lightweight detection mechanisms based on predefined communication rules rather than complex encryption protocols. The detection approach uses basic message format verification and pattern matching that can be implemented with minimal computational resources, making the solution cost-effective and easy to deploy in embedded systems.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If complex attack detection methods are used, then detection capability improves, but false positives increase leading to shutdown of critical functions

Engineering Contradiction:
Improveattack detection capabilityVSAvoidfalse positives and function shutdowns
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The detection device continuously monitors bus traffic and provides feedback by comparing observed communication patterns against predefined rules. When deviations are detected, the system generates alerts without immediately shutting down functions, allowing for verification and reducing false positives while maintaining reliable attack detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The detection system operates autonomously by automatically analyzing messages against predefined communication rules without requiring manual intervention or learning phases. This self-service approach reduces the risk of false positives by consistently applying established rules rather than adaptive algorithms that may incorrectly identify normal variations as attacks.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption and complex protocols are implemented, then security improves, but ease of manufacture and implementation deteriorates

Engineering Contradiction:
Improvesecurity levelVSAvoidimplementation ease in embedded systems
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The invention implements security using simple, lightweight detection mechanisms based on predefined communication rules rather than complex encryption protocols. The detection approach uses basic message format verification and pattern matching that can be implemented with minimal computational resources, making the solution cost-effective and easy to deploy in embedded systems while maintaining adequate security levels.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The detection device is designed as a universal monitoring component that can be integrated into various bus systems without requiring system-specific customization. By using generic communication rule validation rather than proprietary encryption schemes, the solution achieves broad applicability and ease of manufacture across different vehicle platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11063970B2Attack detection method, attack detection device and bus system for a motor vehicle
Publication Date: 2021.07.13 VOLKSWAGEN AG
  • US11063970B2 patent drawing
  • US11063970B2 patent drawing
  • US11063970B2 patent drawing

AI summary

An attack detection method for a bus system of a motor vehicle, wherein communication rules for transmitting messages are determined for the bus system. The detection method includes receiving messages, which are sent via the bus system, and analyzing whether the received messages are received according to the communication rules.