Attributing Bus-Off Attacks via ECU Error State Tracking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern vehicles face challenges in detecting and attributing bus-off attacks on Controller Area Network (CAN) buses, where external devices impersonate legitimate network devices, leading to unauthorized access and potential interference with critical vehicle functions, as existing systems struggle to differentiate between legitimate and malicious error frames.
Innovation Solution
A system that maintains an estimated transmit error counter (TEC) value for each electronic control unit (ECU) connected to the network bus, monitors error frames, and informs an anomaly detection system when an ECU changes error state, allowing for the identification of attacks by impersonating ECUs through the tracking of TEC values and network identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If error frames are monitored to detect bus-off attacks, then attack detection capability is improved, but difficulty in differentiating legitimate and malicious error frames increases
Solution Approach 1:
The system maintains estimated TEC values for each ECU and uses them as feedback to determine whether an ECU is in error active or error passive state. This feedback mechanism enables the system to differentiate between legitimate error frames (from ECUs in error passive state) and malicious error frames (from impersonating devices), thereby resolving the contradiction between detection capability and differentiation difficulty
Solution Approach 2:
The system changes the parameter of TEC value estimation based on the error state of each ECU. By maintaining separate estimated TEC values and comparing them against threshold values, the system can dynamically adjust its detection behavior to distinguish between legitimate and malicious sources, improving both detection reliability and differentiation accuracy
2Measurement precision
If TEC values are tracked for each ECU, then attribution accuracy is improved, but system complexity increases
Solution Approach 1:
The system segments the monitoring task by maintaining separate estimated TEC values for each ECU on the bus. This segmentation allows precise attribution of error frames to specific ECUs while managing complexity through structured organization of tracking data per device
Solution Approach 2:
The estimated TEC value acts as an intermediary parameter that simplifies the attribution process. Instead of directly analyzing complex error frame patterns, the system uses the intermediate TEC metric to infer ECU state and identify malicious actors, reducing overall system complexity while maintaining attribution accuracy
3Speed
If anomaly detection is triggered on ECU state changes, then attack response time is improved, but false alarm rate increases
Solution Approach 1:
The system performs preliminary action by maintaining estimated TEC values and determining ECU error states in advance. This preparation allows the system to quickly and accurately detect genuine attacks without false alarms, as the baseline state of each ECU is already established before monitoring for anomalies
Data Source
AI summary
An error detector is configured to identify transmission errors and maintain a transmit error counter (TEC) value and corresponding network identifier for each of a plurality of electronic control units (ECUs) connected to a network bus. The error detector is configured to adjust the TEC values for the ECUs based on error frames and inform an intrusion detection system when an ECU changes error state. In this manner, the error detector is configured to help identify and attribute attacks by an impersonating node when a message is received containing the network identifier of a legitimate ECU that is in a Bus Off state.


