Multi-Layer In-Vehicle Network Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intrusion detection systems in vehicles are inadequate in detecting adversarial attacks in real-time and distinguishing between malicious and benign anomalies, particularly in complex, closed-loop control systems, leading to potential safety and security risks.

Innovation Solution

Implementing a combined layer intrusion detection system (IDS) that integrates information from multiple observation layers (physical, message, and context layers) to enhance detection confidence, accuracy, and reduce latency, using dynamic threshold adjustments and machine learning models to characterize attacks and distinguish between different types of intrusions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current intrusion detectors monitor for known voltage patterns and threshold behavior, then detection of specific attacks is achieved, but false positives occur when ECUs operate outside known thresholds due to temporary anomalous external factors

Engineering Contradiction:
Improveattack detection accuracyVSAvoidfalse positives
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The intrusion detection is segmented into multiple independent layers (physical layer, message layer, context layer), each monitoring different aspects of ECU behavior. This segmentation allows the system to detect attacks through multiple independent indicators rather than relying on a single threshold, reducing false positives while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from single-dimensional voltage threshold monitoring to multi-dimensional observation by incorporating physical layer signals, message layer content analysis, and context layer operational states. This dimensional expansion enables more accurate attack characterization and reduces false alarms from temporary anomalies.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If multiple observation layers are integrated for comprehensive attack detection, then detection confidence and accuracy are enhanced, but system complexity increases

Engineering Contradiction:
Improveattack detection accuracyVSAvoidIDS architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The complex multi-layer detection system is segmented into modular layers (physical, message, context) that can be independently implemented and configured. Each layer has specific detection functions, allowing the system to achieve high measurement precision while managing complexity through modular design and selective activation of detection layers.

Inventive Principle:
Principle #1Segmentation

3Reliability

If real-time attack detection is implemented in closed-loop control systems, then vehicle safety is improved, but detection latency may increase due to complex analysis requirements

Engineering Contradiction:
Improvevehicle safetyVSAvoiddetection latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The intrusion detection system operates with periodic sampling and analysis cycles at different layers, allowing real-time monitoring while managing computational load. Critical safety-related detections use shorter periods, while less critical analyses use longer periods, balancing vehicle safety requirements with detection latency constraints.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS12045348B2Methods and arrangements for multi-layer in-vehicle network intrusion detection and characterization
Publication Date: 2024.07.23 INTEL CORP
  • US12045348B2 patent drawing
  • US12045348B2 patent drawing
  • US12045348B2 patent drawing

AI summary

Logic may implement observation layer intrusion detection systems (IDSs) to combine observations by intrusion detectors and/or other intrusion detection systems. Logic may monitor one or more control units at one or more observation layers of an in-vehicle network, each of the one or more control units to perform a vehicle function. Logic may combine observations of the one or more control units at the one or more observation layers. Logic may determine, based on a combination of the observations, that one or more of the observations represent an intrusion. Logic may determine, based at least on the observations, characteristics of an attack, and to pass the characteristics of the attack information to a forensic logging system to log the attack or pass the characteristics of the attack to a recovery system for informed selection of recovery procedures. Logic may dynamically adjust a threshold for detection of suspicious activity.