Distributed Intrusion Detection System for Automotive Network Anomaly Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized intrusion detection systems (IDS) in computer networks, particularly in automotive systems, are limited in detecting anomalies due to lack of knowledge about internal states of individual nodes and difficulties in determining message sources, leading to missed or costly detections.

Innovation Solution

A distributed IDS approach is implemented, where each node in the network shares physical connections, allowing access to message content, sender states, and internal states, enabling detection mechanisms that traditional centralized systems cannot perform or perform with high difficulty.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized IDS is used to monitor network traffic, then the system structure is simple and centralized, but the detection capability is limited due to lack of knowledge about internal states of individual nodes

Engineering Contradiction:
Improveanomaly detection capabilityVSAvoidinternal state information of nodes
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent divides the centralized IDS into multiple distributed IDS components, each deployed at different network nodes. Each distributed IDS monitors local network traffic and has access to internal state information of its host node, enabling comprehensive anomaly detection that combines both network-wide perspective and node-specific internal state knowledge.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of information access by enabling IDS components to observe not only network traffic but also internal states of ECUs (electronic control units). This multi-dimensional observation capability allows the system to detect anomalies that would be invisible to traditional centralized IDS relying solely on network message content.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If a centralized IDS monitors all network traffic, then it has a comprehensive view of network messages, but it cannot determine the actual source of messages due to field bus specifications

Engineering Contradiction:
Improvemessage source identificationVSAvoiddistributed system architecture
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces distributed IDS components as intermediaries at each network node that can identify message sources locally. These intermediaries have direct access to internal state information and can correlate incoming network messages with the actual sending ECU, solving the source identification problem caused by field bus specifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a distributed IDS is implemented to access internal states of nodes, then the anomaly detection rate improves, but the system complexity increases

Engineering Contradiction:
Improveanomaly detection rateVSAvoiddistributed IDS architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the IDS functionality across multiple distributed components, each handling local monitoring tasks. This segmentation enables the system to leverage internal state information at each node for improved detection while distributing the computational burden, thus managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11178162B2Method and device for detecting anomalies in a computer network
Publication Date: 2021.11.16 ROBERT BOSCH GMBH
  • US11178162B2 patent drawing
  • US11178162B2 patent drawing
  • US11178162B2 patent drawing

AI summary

A method for detecting anomalies in a computer network, in which a message transmitted over the computer network is received or recorded by a node of the computer network; based on at least the message, it is checked by a detection mechanism of the node whether the anomalies have occurred, and an occurrence of the anomalies is either confirmed or refuted according to a predefined detection rule of the detection mechanism.