CAN Bus Intrusion Detection for Motor Vehicle Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Controller Area Network (CAN) in motor vehicles lacks security measures to protect against attacks such as intrusion, denial of service, or impersonation, making it vulnerable to anomalies in data traffic.

Innovation Solution

A monitoring method is implemented on each node of the CAN bus network, comprising an intrusion-detection module that analyzes CAN messages for anomalies and generates alerts, and a vehicle-recovery module that performs recovery actions based on detected anomalies, using software modules in control units to identify and respond to suspicious behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protection is added to the CAN bus, then security against attacks is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An intrusion detection module is introduced as an intermediary component that monitors CAN bus traffic without disrupting the existing communication protocol. This module analyzes message integrity, detects anomalies, and generates alerts while maintaining the original CAN bus architecture and operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-diagnosis by having each node monitor its own incoming and outgoing traffic for anomalies. Nodes independently detect intrusion attempts, message integrity violations, and abnormal communication patterns, enabling security without external intervention

Inventive Principle:
Principle #25Self-service

2Measurement precision

If intrusion detection is implemented on each node, then detection precision is improved, but use of energy increases

Engineering Contradiction:
Improvedetection precisionVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The intrusion detection module performs selective monitoring rather than analyzing every single CAN message in detail. It uses filtering mechanisms to identify only suspicious traffic patterns and performs deep analysis only on potentially anomalous messages, reducing overall computational energy consumption while maintaining detection precision

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system implements periodic sampling and monitoring of CAN bus traffic rather than continuous full-analysis monitoring. Detection operations are performed at strategic intervals and triggered by specific events, reducing energy consumption while maintaining effective intrusion detection capability

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3319275B1Method for monitoring data traffic in a motor-vehicle network
Publication Date: 2019.06.26 FAB ITAL MAGNETI MARELLI SPA
  • EP3319275B1 patent drawingFigure 1
  • EP3319275B1 patent drawingFigure 2
  • EP3319275B1 patent drawingFigure 3~4

AI summary

Described herein is a method for monitoring the data traffic (CBT, CF, G) over a CAN bus (11) of a CAN-type communication network (10) of a motor vehicle, said network comprising a plurality of nodes (12) associated to said CAN bus (11) in a signal-exchange relationship in order to detect data traffic (CBT, CF) with anomalies (AT) and generate an alert (AL). According to the invention, it is envisaged to carry out at each node (12) an intrusion-detection operation (300, 400) on messages (CF, G) received at said node (12) and a corresponding vehicle-recovery operation (200); said intrusion-detection operation (300, 400) comprising receiving (205, 310) CAN messages (CF) or groups of CAN messages (G) transmitted to the node (12) on the CAN bus (11), analysing (310, 410) said CAN messages (CF) or groups of CAN messages (G), and issuing an alert (AL) comprising a type of anomaly (AT) that has caused the alert (AL), said vehicle-recovery operation (200) comprising implementing, on the basis of said type of anomaly (AT), a corresponding intrusion-recovery action (VR).