Bus Network Malicious Node Detection via Autocorrelation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting malicious nodes in bus networks, such as those used in automobiles, are complex and time-consuming due to their reliance on frequency domain signal processing, making them inefficient for real-time attack detection.
Innovation Solution
A method that pre-stores autocorrelation characteristics and node identifiers for each signal in a bus network system, allowing for the identification of malicious nodes by comparing the autocorrelation characteristics of received signals in the time domain, using a node apparatus with an interface device, storage device, and processor to determine if the node identifiers match, thereby identifying and potentially blocking malicious nodes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If frequency domain signal processing is used to detect malicious nodes, then detection accuracy can be achieved, but signal processing complexity increases
Solution Approach 1:
The patent replaces frequency domain signal processing with time domain autocorrelation analysis. Instead of using complex frequency domain methods (FFT, spectral analysis), the invention uses autocorrelation coefficients calculated directly from time domain signals, substituting a simpler computational approach for the more complex one while maintaining detection capability
Solution Approach 2:
The patent changes the domain of signal analysis from frequency domain to time domain. By calculating autocorrelation coefficients in the time domain and comparing them with pre-stored reference values, the system achieves malicious node detection without requiring frequency domain transformation, thus reducing processing complexity
2Measurement precision
If frequency domain signal processing is used to detect malicious nodes, then detection accuracy can be achieved, but detection time increases
Solution Approach 1:
The patent replaces time-consuming frequency domain processing with faster time domain autocorrelation calculation. The autocorrelation coefficients can be computed directly from time domain signals without requiring FFT or other frequency domain transformations, significantly reducing computation time while maintaining detection accuracy
Solution Approach 2:
The patent pre-calculates and stores autocorrelation coefficient characteristics for each normal node in advance. When detecting malicious nodes, the system only needs to calculate the autocorrelation of the current signal and compare it with pre-stored reference values, eliminating the need for time-consuming frequency domain analysis during actual detection
3Ease of operation
If open communication channel is used in bus network, then communication simplicity is maintained, but security vulnerability increases
Solution Approach 1:
The patent enables each node to autonomously detect malicious signals by comparing autocorrelation characteristics of received signals with pre-stored reference characteristics of legitimate nodes. The system self-protects by having nodes independently verify the authenticity of transmitted signals without requiring external security infrastructure, thus maintaining communication simplicity while adding security
Solution Approach 2:
The patent implements a feedback mechanism where received signals are analyzed for autocorrelation characteristics and compared with stored reference data. This feedback loop allows the system to identify and reject signals from malicious nodes while maintaining normal communication with legitimate nodes, balancing security with communication simplicity
Data Source
AI summary
A method of detecting a malicious node in a bus network system includes pre-storing, by a receiving node, autocorrelation characteristics and node identifiers for each signal received from nodes excluding than the receiving node in a bus network system, receiving, by the receiving node, a target signal from any one of the nodes, generating, by the receiving node, an autocorrelation characteristic of the target signal, searching for an autocorrelation characteristic, which is identical to the autocorrelation characteristic of the target signal or similar to the autocorrelation characteristic of the target signal by a reference level or more, among the autocorrelation characteristics of each of the signals stored by the receiving node, determining, by the receiving node, whether a first node identifier matching the searched autocorrelation characteristic and a second node identifier extracted from a packet transmitted to the target signal are the same.


