CAN IDS Policy Rules for Detecting Aperiodic Message Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing intrusion detection systems for in-vehicle networks struggle to accurately and efficiently detect attacks using aperiodic CAN messages, necessitating a more sophisticated method to set policy rules for CAN message processing.

Innovation Solution

A method and apparatus for constructing an intrusion detection system that extracts standard information from CAN communication, applies a combination of static and custom rulesets to set policy rules, and creates a policy file for the IDS, including hierarchical structures for policy header, lookup table, and policy body information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing intrusion detection systems are used for in-vehicle networks, then basic CAN message monitoring is possible, but detection accuracy and efficiency for attacks using aperiodic CAN messages deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidpolicy rule complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The policy rule is segmented into multiple hierarchical levels: bus-level policies (first detection policy), message-level policies (second detection policy), and signal-level policies (third detection policy). This segmentation allows the system to apply appropriate detection granularity without overwhelming complexity, improving detection accuracy for aperiodic messages while maintaining manageable system structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts detection policies based on message characteristics. The policy setting unit applies different detection policies depending on whether messages are periodic or aperiodic, and selects appropriate parameters from static or custom rulesets based on the specific attack scenario, enabling adaptive detection without fixed complex structures.

Inventive Principle:
Principle #15Dynamics

2Reliability

If aperiodic CAN messages are used for attacks, then attack detection becomes more challenging, but the need for sophisticated detection methods increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoiddetection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary configuration by extracting standard information from input files and pre-setting detection policies in the policy file. The policy setting unit pre-defines detection rules for various message types and attack scenarios, so when aperiodic attack messages occur, the system can immediately apply appropriate pre-configured detection logic without real-time analysis complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes detection parameters based on message characteristics. The policy setting unit selects from multiple parameters defined in static ruleset or custom ruleset, adjusting detection thresholds, time windows, and analysis methods according to whether messages are periodic or aperiodic, thereby improving detection capability while managing complexity through parameter adaptation.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If static ruleset and custom ruleset are combined to set policy rules, then detection flexibility improves, but system configuration complexity increases

Engineering Contradiction:
Improvedetection policy flexibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The policy setting unit serves multiple functions: it extracts standard information from input files, applies both static ruleset and custom ruleset, selects appropriate detection policies, and generates the policy file. This multi-functionality consolidates what would otherwise be separate configuration steps into a unified process, improving flexibility while managing complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs self-configuration by automatically extracting standard information from input files and applying the appropriate ruleset combination. The policy setting unit autonomously determines which parameters to set from the static or custom ruleset based on the detection requirements, reducing manual configuration complexity while maintaining high adaptability through automated rule application.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12603902B2Apparatus and method for constructing intrusion detection system applied to CAN communication using detection policy rule
Publication Date: 2026.04.14 AUTOCRYPT CO LTD
  • US12603902B2 patent drawing
  • US12603902B2 patent drawing
  • US12603902B2 patent drawing

AI summary

Disclosed are an apparatus and method for constructing an intrusion detection system applied to CAN communication. The method for constructing an intrusion detection system applied to CAN communication may include extracting standard information by parsing an input file associated with CAN communication, setting a policy rule by applying at least one of a static ruleset and a custom ruleset using the extracted standard information, and creating a policy file to be applied to the intrusion detection system by packing the standard information and the policy rule.