CAN Bus Threat Detection Using Baseline Pattern Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern vehicles' CAN bus systems are vulnerable to malicious attacks due to limited bandwidth, requiring a low-resource-intensive security mechanism to detect and notify users or service providers of such threats.

Innovation Solution

A threat forensics platform with a processor and memory that stores a baseline model of CAN data, compares real-time data with the baseline, determines a threat score, and notifies drivers or service providers of malicious activity, utilizing machine learning algorithms and edge versions of baseline models for efficient detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security mechanism is implemented to detect malicious attacks on CAN bus, then security reliability is improved, but resource consumption increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent replaces complex mechanical security systems with a software-based machine learning model that runs on the existing CAN bus infrastructure. The neural network processes CAN messages using algorithmic patterns rather than physical security mechanisms, significantly reducing resource consumption while maintaining detection effectiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the parameters of security detection by using threat scores and probabilistic thresholds instead of deterministic security rules. The machine learning model dynamically adjusts detection sensitivity based on learned patterns, optimizing the balance between security reliability and resource usage by processing only relevant features from CAN messages.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If machine learning algorithms are used for threat detection, then detection accuracy is improved, but computational complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the CAN bus communication into distinct message types and categories, allowing the machine learning model to process specific message patterns separately. This segmentation enables the system to focus computational resources on detecting threats in critical message types while using simpler validation for routine messages, reducing overall computational complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial machine learning processing to all CAN messages but reserves full computational power for messages that exhibit suspicious patterns or belong to critical systems. The threat scoring mechanism allows the model to perform lightweight analysis on most messages and intensive analysis only when necessary, balancing accuracy and complexity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11546353B2Detection of malicious activity on CAN bus
Publication Date: 2023.01.03 TOYOTA MOTOR NORTH AMERICA INC
  • US11546353B2 patent drawing
  • US11546353B2 patent drawing
  • US11546353B2 patent drawing

AI summary

Methods, systems, and apparatus for a threat detection system. The threat detection system includes a threat forensics platform. The threat forensics platform includes a memory. The memory is configured to store a baseline model of controller area network (CAN) data. The threat forensics platform includes a processor coupled to the memory. The processor is configured to obtain CAN data including multiple messages. The processor is configured to compare the CAN data including the multiple messages with the baseline model. The processor is configured to determine a threat score for the CAN data based on the comparison and determine that there is a threat within the CAN data based on the threat score. The processor is configured to provide an indication that there is the threat to a driver of a vehicle or to a service provider.