Hardware Switch Intrusion Detection for Automotive Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Network Intrusion Detection and Prevention Systems (NIDPS) designed for enterprise networks are inefficient for automotive networks due to differences in network structure, dynamics, and nodes, requiring a tailored approach for automotive networks that accounts for static network conditions and limited resources.
Innovation Solution
A method and device for intrusion detection in automotive networks utilizing a hardware switch unit with a Ternary Content Addressable Memory and multiple filters to analyze data packets at the data link and network layers, allowing for efficient detection of anomalies without analyzing the entire network traffic, suitable for automotive Ethernet networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprise network NIDPS systems are used for automotive networks, then intrusion detection capability is provided, but resource efficiency deteriorates due to analyzing entire network traffic
Solution Approach 1:
The system segments intrusion detection into two stages: hardware-based filtering (Layer 2/3) and software-based analysis (Layer 7). The hardware filter handles basic packet filtering and forwarding decisions, while the processing unit only analyzes packets marked as suspicious, dividing the detection task to reduce overall computational load.
Solution Approach 2:
The patent extracts only suspicious packets from the entire network traffic flow using hardware filters that identify and mark anomalous packets. This extraction approach allows the system to focus processing resources only on potentially malicious traffic rather than analyzing all packets.
2Measurement precision
If comprehensive packet analysis is performed to improve intrusion detection accuracy, then detection precision is improved, but processing speed deteriorates
Solution Approach 1:
The hardware filter performs preliminary actions by pre-marking suspicious packets before they reach the processing unit. This preliminary identification allows the main processing unit to focus only on marked packets, maintaining high detection accuracy while improving overall processing speed through selective analysis.
3Device complexity
If static network configuration is assumed to simplify detection, then device complexity is reduced, but adaptability deteriorates when network changes occur
Solution Approach 1:
The system implements dynamic adaptation through learning algorithms that automatically adjust detection parameters based on observed network traffic patterns. The processing unit learns normal traffic behavior and adapts to network changes without requiring manual reconfiguration, maintaining simplicity while improving adaptability.
Data Source
AI summary
Device and method for intrusion detection in a computer network. A data packet is received at an input of a hardware switch unit, an output of the hardware switch unit being selected for sending the data packet or a copy as a function of data link layer information from the data packet and of a hardware address from a memory of the hardware switch unit. An actual value from a field of the data packet is compared by a hardware filter with a setpoint value for values from this field, the field including data link layer data or network layer data, and the data packet or a copy of the data packet being provided to a computing device as a function of a result of the comparison. The analysis for detecting an intrusion pattern in a network traffic in the computer network id carried out by the computing device.


