CAN IDS Policy Rules for Detecting Aperiodic Message Attacks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing intrusion detection systems for in-vehicle networks struggle to accurately and efficiently detect attacks using aperiodic CAN messages, necessitating a more sophisticated method to set policy rules for CAN message processing.
Innovation Solution
A method and apparatus for constructing an intrusion detection system that extracts standard information from CAN communication, applies a combination of static and custom rulesets to set policy rules, and creates a policy file for the IDS, including hierarchical structures for policy header, lookup table, and policy body information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing intrusion detection systems are used for in-vehicle networks, then basic CAN message monitoring is possible, but detection accuracy and efficiency for attacks using aperiodic CAN messages deteriorates
Solution Approach 1:
The policy rule is segmented into multiple hierarchical levels: bus-level policies (first detection policy), message-level policies (second detection policy), and signal-level policies (third detection policy). This segmentation allows the system to apply appropriate detection granularity without overwhelming complexity, improving detection accuracy for aperiodic messages while maintaining manageable system structure.
Solution Approach 2:
The system dynamically adjusts detection policies based on message characteristics. The policy setting unit applies different detection policies depending on whether messages are periodic or aperiodic, and selects appropriate parameters from static or custom rulesets based on the specific attack scenario, enabling adaptive detection without fixed complex structures.
2Reliability
If aperiodic CAN messages are used for attacks, then attack detection becomes more challenging, but the need for sophisticated detection methods increases
Solution Approach 1:
The system performs preliminary configuration by extracting standard information from input files and pre-setting detection policies in the policy file. The policy setting unit pre-defines detection rules for various message types and attack scenarios, so when aperiodic attack messages occur, the system can immediately apply appropriate pre-configured detection logic without real-time analysis complexity.
Solution Approach 2:
The system changes detection parameters based on message characteristics. The policy setting unit selects from multiple parameters defined in static ruleset or custom ruleset, adjusting detection thresholds, time windows, and analysis methods according to whether messages are periodic or aperiodic, thereby improving detection capability while managing complexity through parameter adaptation.
3Adaptability or versatility
If static ruleset and custom ruleset are combined to set policy rules, then detection flexibility improves, but system configuration complexity increases
Solution Approach 1:
The policy setting unit serves multiple functions: it extracts standard information from input files, applies both static ruleset and custom ruleset, selects appropriate detection policies, and generates the policy file. This multi-functionality consolidates what would otherwise be separate configuration steps into a unified process, improving flexibility while managing complexity through functional integration.
Solution Approach 2:
The system performs self-configuration by automatically extracting standard information from input files and applying the appropriate ruleset combination. The policy setting unit autonomously determines which parameters to set from the static or custom ruleset based on the detection requirements, reducing manual configuration complexity while maintaining high adaptability through automated rule application.
Data Source
AI summary
Disclosed are an apparatus and method for constructing an intrusion detection system applied to CAN communication. The method for constructing an intrusion detection system applied to CAN communication may include extracting standard information by parsing an input file associated with CAN communication, setting a policy rule by applying at least one of a static ruleset and a custom ruleset using the extracted standard information, and creating a policy file to be applied to the intrusion detection system by packing the standard information and the policy rule.


