Bus Network Malicious Node Detection via Autocorrelation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting malicious nodes in bus networks, such as those used in automobiles, are complex and time-consuming due to their reliance on frequency domain signal processing, making them inefficient for real-time attack detection.

Innovation Solution

A method that pre-stores autocorrelation characteristics and node identifiers for each signal in a bus network system, allowing for the identification of malicious nodes by comparing the autocorrelation characteristics of received signals in the time domain, using a node apparatus with an interface device, storage device, and processor to determine if the node identifiers match, thereby identifying and potentially blocking malicious nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If frequency domain signal processing is used to detect malicious nodes, then detection accuracy can be achieved, but signal processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidsignal processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent replaces frequency domain signal processing with time domain autocorrelation analysis. Instead of using complex frequency domain methods (FFT, spectral analysis), the invention uses autocorrelation coefficients calculated directly from time domain signals, substituting a simpler computational approach for the more complex one while maintaining detection capability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the domain of signal analysis from frequency domain to time domain. By calculating autocorrelation coefficients in the time domain and comparing them with pre-stored reference values, the system achieves malicious node detection without requiring frequency domain transformation, thus reducing processing complexity

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If frequency domain signal processing is used to detect malicious nodes, then detection accuracy can be achieved, but detection time increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddetection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces time-consuming frequency domain processing with faster time domain autocorrelation calculation. The autocorrelation coefficients can be computed directly from time domain signals without requiring FFT or other frequency domain transformations, significantly reducing computation time while maintaining detection accuracy

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent pre-calculates and stores autocorrelation coefficient characteristics for each normal node in advance. When detecting malicious nodes, the system only needs to calculate the autocorrelation of the current signal and compare it with pre-stored reference values, eliminating the need for time-consuming frequency domain analysis during actual detection

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If open communication channel is used in bus network, then communication simplicity is maintained, but security vulnerability increases

Engineering Contradiction:
Improvecommunication simplicityVSAvoidhacking vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent enables each node to autonomously detect malicious signals by comparing autocorrelation characteristics of received signals with pre-stored reference characteristics of legitimate nodes. The system self-protects by having nodes independently verify the authenticity of transmitted signals without requiring external security infrastructure, thus maintaining communication simplicity while adding security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where received signals are analyzed for autocorrelation characteristics and compared with stored reference data. This feedback loop allows the system to identify and reject signals from malicious nodes while maintaining normal communication with legitimate nodes, balancing security with communication simplicity

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11876810B2Method of detecting malicious node in bus network system and node apparatus
Publication Date: 2024.01.16 DAEGU GYEONGBUK INSTITUTE OF SCIENCE AND TECHNOLOGY
  • US11876810B2 patent drawing
  • US11876810B2 patent drawing
  • US11876810B2 patent drawing

AI summary

A method of detecting a malicious node in a bus network system includes pre-storing, by a receiving node, autocorrelation characteristics and node identifiers for each signal received from nodes excluding than the receiving node in a bus network system, receiving, by the receiving node, a target signal from any one of the nodes, generating, by the receiving node, an autocorrelation characteristic of the target signal, searching for an autocorrelation characteristic, which is identical to the autocorrelation characteristic of the target signal or similar to the autocorrelation characteristic of the target signal by a reference level or more, among the autocorrelation characteristics of each of the signals stored by the receiving node, determining, by the receiving node, whether a first node identifier matching the searched autocorrelation characteristic and a second node identifier extracted from a packet transmitted to the target signal are the same.