Monitoring ECU Unauthorized Activity Detection in Onboard Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for detecting unauthorized frames in onboard CAN networks fail to detect frames transmitted by ECUs that have been compromised through firmware rewriting or malware execution, especially when the transmission timing appears legitimate, and they increase bus traffic due to the need for continuous communication with each ECU.
Innovation Solution
A monitoring ECU connected to the onboard network system uses unauthorized activity detection rules to identify abnormal patterns in frame relations between ECUs, allowing for the detection of unauthorized states without continuous communication, by determining if frames from compromised ECUs disrupt the normal relations between frames with different IDs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If communication with each ECU is performed constantly to detect unauthorized rewriting, then detection capability is improved, but bus traffic increases
Solution Approach 1:
The patent extracts the detection function from direct ECU communication and implements it through passive monitoring of frame transmissions on the bus. The monitoring ECU observes and analyzes frame content without requiring active communication cycles with each ECU, thereby reducing bus traffic while maintaining detection capability.
Solution Approach 2:
The patent introduces a monitoring ECU as an intermediary that indirectly detects unauthorized rewriting by analyzing frame content from multiple ECUs. Instead of direct communication with each ECU, the monitoring ECU acts as a mediator that observes the network traffic and identifies anomalies, reducing the need for frequent direct communications.
2Measurement precision
If firmware rewriting detection is implemented by communicating with each ECU, then detection accuracy is improved, but system complexity increases
Solution Approach 1:
The patent merges the detection function into a single monitoring ECU that consolidates the analysis of frames from multiple ECUs. This eliminates the need for each ECU to independently perform detection and coordinate with others, reducing system complexity while maintaining detection accuracy through centralized frame content analysis.
3Ease of operation
If traditional reception interval monitoring is used, then implementation simplicity is improved, but detection capability against firmware rewriting is lost
Solution Approach 1:
The patent transitions from monitoring only the temporal dimension (reception intervals) to analyzing the content dimension of frames. By examining the actual data content, identifiers, and relationships between frames, the system detects firmware rewriting attacks that maintain legitimate transmission timing, adding a new dimension of detection capability.
Data Source
AI summary
An unauthorized activity detection method is provided in an onboard network system having multiple electronic units (ECU) that perform communication via a bus, such that an occurrence of an unauthorized state can be detected by monitoring frames transmitted over the bus. The unauthorized activity detection method determines, by a monitoring electronic control unit using unauthorized activity detection rule information indicating a first condition, whether or not a set of frames received from the bus satisfies the first condition. The first condition being a condition regarding a relation in content between a first frame having a first identifier and a second frame having a second identifier that differs from the first identifier. And the method further detects the occurrence of the unauthorized state in a case where the first condition is not satisfied.


