Microcontroller Message Interval Monitoring for Spoofed Signal Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern automobiles' electronic control units (ECUs) lack inherent security features, making them vulnerable to malicious attacks that can compromise critical vehicle systems, such as brakes and engine control, due to the absence of intrinsic security in controller area network (CAN) communications.

Innovation Solution

A system and method for detecting suspicious microcontroller messages by monitoring typical message intervals and flagging deviations, using modules to observe, identify, determine, and categorize messages as suspicious based on variations from the typical interval, thereby enabling security actions to prevent malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ECUs are extensively tested for automotive safety, then reliability is improved, but security against malicious electronic attacks is not addressed

Engineering Contradiction:
Improveautomotive safetyVSAvoidvulnerability to malicious attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by observing and establishing the typical message interval pattern of ECUs before security evaluation. This baseline timing information is stored and used to proactively detect suspicious messages that deviate from the established pattern, enabling preventive security measures rather than reactive responses

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring message intervals from ECUs and comparing them against the established typical interval. When deviations are detected, the system generates security alerts and can trigger security actions, creating a closed-loop feedback mechanism that continuously adapts to and responds to potential security threats

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If CAN networks include intrinsic security features, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system uses an intermediary approach by introducing a separate security evaluation system that monitors CAN network traffic without modifying the existing CAN protocol or ECU hardware. This external security layer analyzes message timing patterns and identifies suspicious activity, providing security protection while maintaining the simplicity of the original CAN network architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies parameter changes by focusing on the timing parameter of ECU messages rather than modifying the message content or protocol structure. By analyzing temporal patterns and detecting deviations from typical message intervals, the system provides security through parameter monitoring rather than structural complexity

Inventive Principle:
Principle #35Parameter changes

3Difficulty of detecting and measuring

If the system monitors message intervals to detect suspicious messages, then security detection capability is improved, but processing time increases

Engineering Contradiction:
Improvesuspicious message detectionVSAvoidmessage processing time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system applies partial action by focusing monitoring efforts only on the timing parameter of messages rather than analyzing complete message content. This selective approach to security evaluation reduces processing overhead while maintaining effective detection capability for timing-based anomalies and spoofed messages

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10193903B1Systems and methods for detecting suspicious microcontroller messages
Publication Date: 2019.01.29 CA TECH INC
  • US10193903B1 patent drawing
  • US10193903B1 patent drawing
  • US10193903B1 patent drawing

AI summary

The disclosed computer-implemented method for detecting suspicious microcontroller messages may include (1) observing a typical interval at which messages are sent over a network by a microcontroller, (2) identifying a message sent over the network by the microcontroller, (3) determining that the interval between the message and the previous message sent by the microcontroller does not comprise the typical interval, and (4) categorizing the message as a suspicious message in response to determining that the interval does not comprise the typical interval. Various other methods, systems, and computer-readable media are also disclosed.