Attributing Bus-Off Attacks via ECU Error State Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles face challenges in detecting and attributing bus-off attacks on Controller Area Network (CAN) buses, where external devices impersonate legitimate network devices, leading to unauthorized access and potential interference with critical vehicle functions, as existing systems struggle to differentiate between legitimate and malicious error frames.

Innovation Solution

A system that maintains an estimated transmit error counter (TEC) value for each electronic control unit (ECU) connected to the network bus, monitors error frames, and informs an anomaly detection system when an ECU changes error state, allowing for the identification of attacks by impersonating ECUs through the tracking of TEC values and network identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If error frames are monitored to detect bus-off attacks, then attack detection capability is improved, but difficulty in differentiating legitimate and malicious error frames increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddifferentiation difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system maintains estimated TEC values for each ECU and uses them as feedback to determine whether an ECU is in error active or error passive state. This feedback mechanism enables the system to differentiate between legitimate error frames (from ECUs in error passive state) and malicious error frames (from impersonating devices), thereby resolving the contradiction between detection capability and differentiation difficulty

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the parameter of TEC value estimation based on the error state of each ECU. By maintaining separate estimated TEC values and comparing them against threshold values, the system can dynamically adjust its detection behavior to distinguish between legitimate and malicious sources, improving both detection reliability and differentiation accuracy

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If TEC values are tracked for each ECU, then attribution accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveattribution accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments the monitoring task by maintaining separate estimated TEC values for each ECU on the bus. This segmentation allows precise attribution of error frames to specific ECUs while managing complexity through structured organization of tracking data per device

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The estimated TEC value acts as an intermediary parameter that simplifies the attribution process. Instead of directly analyzing complex error frame patterns, the system uses the intermediate TEC metric to infer ECU state and identify malicious actors, reducing overall system complexity while maintaining attribution accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If anomaly detection is triggered on ECU state changes, then attack response time is improved, but false alarm rate increases

Engineering Contradiction:
Improveattack response timeVSAvoidfalse alarm rate
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system performs preliminary action by maintaining estimated TEC values and determining ECU error states in advance. This preparation allows the system to quickly and accurately detect genuine attacks without false alarms, as the baseline state of each ECU is already established before monitoring for anomalies

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10958470B2Attributing bus-off attacks based on error frames
Publication Date: 2021.03.23 LEAR CORP
  • US10958470B2 patent drawing
  • US10958470B2 patent drawing
  • US10958470B2 patent drawing

AI summary

An error detector is configured to identify transmission errors and maintain a transmit error counter (TEC) value and corresponding network identifier for each of a plurality of electronic control units (ECUs) connected to a network bus. The error detector is configured to adjust the TEC values for the ECUs based on error frames and inform an intrusion detection system when an ECU changes error state. In this manner, the error detector is configured to help identify and attribute attacks by an impersonating node when a message is received containing the network identifier of a legitimate ECU that is in a Bus Off state.