In-Vehicle Entropy Analysis for CAN Intrusion Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected vehicles equipped with network communication functions are vulnerable to external data intrusion, which can disrupt their control systems and pose a risk to safety, as existing technologies lack effective methods to detect such intrusions.
Innovation Solution
An apparatus and method that utilize information entropy analysis to detect external data intrusion by comparing reference entropy values with criteria entropy values generated from packet overlapping events in the vehicle's CAN communication network, determining if the vehicle is under attack by checking if the entropy values fall within predetermined limits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the vehicle is equipped with network communication functions to enable connected car capabilities, then the vehicle can transceive data with other vehicles and external traffic facilities, but the vehicle becomes vulnerable to external data intrusion that can disrupt control systems and pose safety risks
Solution Approach 1:
The patent introduces an entropy analysis mechanism as an intermediary layer between the CAN communication network and the control systems. This mechanism monitors packet ID sequences and calculates entropy values to detect abnormal patterns indicating external intrusion, thereby protecting the control systems without restricting legitimate network communication functions.
Solution Approach 2:
The patent implements a feedback mechanism where the entropy analysis results are continuously monitored and used to detect intrusion attempts. The system calculates entropy values from packet ID sequences, compares them against threshold values, and triggers intrusion detection when abnormal patterns are identified, creating a closed-loop security monitoring system.
2Reliability
If traditional intrusion detection methods are used, then the system can identify some security threats, but the methods lack effectiveness in detecting subtle entropy changes caused by external data intrusion
Solution Approach 1:
The patent changes the detection parameter from traditional security metrics to information entropy of packet ID sequences. By calculating entropy values and comparing them against threshold values, the system can precisely detect subtle changes in communication patterns that indicate external intrusion, significantly improving detection accuracy over traditional methods.
Data Source
AI summary
Disclosed are an apparatus for detecting in-vehicle external data intrusion by comparing multiple information entropy and a method of operating the same. The present invention may prevent a danger due to in-vehicle external data intrusion by providing a technology that may determine whether in-vehicle external data intrusion occurs by checking information entropy representing the amount of information for a package ID generable through an in-vehicle Controller Area Network (CAN) communication network.

