CAN Bus Intrusion Detection via Rule-Based Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Intrusion Detection Systems (IDS) for CAN bus communication struggle to efficiently detect attacks due to limitations in processing power, real-time detection capabilities, and the failure to utilize actual attack patterns in CAN bus traffic.

Innovation Solution

A CAN communication security method that involves reanalyzing intrusion detection results using a rule-based filter, specifically analyzing CAN data frames through a pre-learned IDS model to classify attack types and filter them based on established rules for DOS, spoofing, and fuzzy attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep learning techniques are implemented on edge computing devices in the vehicle, then intrusion detection capability is improved, but power consumption increases and real-time detection becomes difficult to achieve

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments the intrusion detection process into two parts: a pre-training phase using deep learning techniques to create detection rules, and a runtime phase using lightweight rule-based filtering. This segmentation allows the computationally intensive deep learning model to be trained offline, while the actual real-time detection uses minimal resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-training the deep learning model offline to generate detection rules and patterns before deployment. The pre-processed detection rules are then used during runtime, eliminating the need for real-time deep learning computation and significantly reducing power consumption while maintaining detection effectiveness.

Inventive Principle:
Principle #10Preliminary action

2Use of energy by moving object

If machine learning techniques are used, then efficiency and power consumption are improved, but intrusion detection accuracy decreases compared to deep learning

Engineering Contradiction:
Improvepower consumptionVSAvoidintrusion detection accuracy
Core Design Contradiction:
Use of energy by moving objectVSMeasurement precision

Solution Approach 1:

The patent merges the strengths of both deep learning and machine learning approaches by using deep learning for offline pattern recognition and rule generation, then combining these rules with traditional machine learning-based filtering algorithms. This hybrid approach achieves high detection accuracy while maintaining low power consumption and computational requirements for real-time operation.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of manufacture

If existing IDS methods are used, then basic detection functionality is provided, but actual attack patterns in CAN bus traffic are not effectively detected

Engineering Contradiction:
Improvedetection functionalityVSAvoidattack pattern detection efficiency
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an intermediary layer between existing IDS methods and the actual detection task. The deep learning model serves as an intermediary that processes raw CAN bus traffic and generates refined detection rules, which then feed into the rule-based filtering system. This intermediary transformation enables effective detection of actual attack patterns while maintaining the simplicity of rule-based systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250168177A1Can communication security method for detecting can bus attacks, recording medium and can communication device for performing the same
Publication Date: 2025.05.22 AY INNOVATIVE CO LTD
  • US20250168177A1 patent drawing
  • US20250168177A1 patent drawing
  • US20250168177A1 patent drawing

AI summary

A Controller Area Network (CAN) communication security method in a CAN communication security apparatus for detecting a CAN bus attack by monitoring a CAN data frame through a CAN bus, which includes receiving a CAN data frame; analyzing the CAN data frame through a pre-learned intrusion detection systems (IDS) model to classify an attack type of the CAN bus; and filtering the classified attack type based on a pre-established rule. The efficiency of intrusion detection in IDS can be improved by reanalyzing the intrusion detection results in IDS based on rule-based filters that utilize actual attack patterns that can be observed in CAN bus traffic.