Distributed Intrusion Detection System for Automotive Network Anomaly Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Centralized intrusion detection systems (IDS) in computer networks, particularly in automotive systems, are limited in detecting anomalies due to lack of knowledge about internal states of individual nodes and difficulties in determining message sources, leading to missed or costly detections.
Innovation Solution
A distributed IDS approach is implemented, where each node in the network shares physical connections, allowing access to message content, sender states, and internal states, enabling detection mechanisms that traditional centralized systems cannot perform or perform with high difficulty.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized IDS is used to monitor network traffic, then the system structure is simple and centralized, but the detection capability is limited due to lack of knowledge about internal states of individual nodes
Solution Approach 1:
The patent divides the centralized IDS into multiple distributed IDS components, each deployed at different network nodes. Each distributed IDS monitors local network traffic and has access to internal state information of its host node, enabling comprehensive anomaly detection that combines both network-wide perspective and node-specific internal state knowledge.
Solution Approach 2:
The patent adds a new dimension of information access by enabling IDS components to observe not only network traffic but also internal states of ECUs (electronic control units). This multi-dimensional observation capability allows the system to detect anomalies that would be invisible to traditional centralized IDS relying solely on network message content.
2Measurement precision
If a centralized IDS monitors all network traffic, then it has a comprehensive view of network messages, but it cannot determine the actual source of messages due to field bus specifications
Solution Approach 1:
The patent introduces distributed IDS components as intermediaries at each network node that can identify message sources locally. These intermediaries have direct access to internal state information and can correlate incoming network messages with the actual sending ECU, solving the source identification problem caused by field bus specifications.
3Reliability
If a distributed IDS is implemented to access internal states of nodes, then the anomaly detection rate improves, but the system complexity increases
Solution Approach 1:
The patent segments the IDS functionality across multiple distributed components, each handling local monitoring tasks. This segmentation enables the system to leverage internal state information at each node for improved detection while distributing the computational burden, thus managing complexity through modular architecture.
Data Source
AI summary
A method for detecting anomalies in a computer network, in which a message transmitted over the computer network is received or recorded by a node of the computer network; based on at least the message, it is checked by a detection mechanism of the node whether the anomalies have occurred, and an occurrence of the anomalies is either confirmed or refuted according to a predefined detection rule of the detection mechanism.


