On-board Network Abnormality Detection via Message Frequency Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current techniques for detecting abnormal messages in on-board vehicle networks, such as those using the CAN protocol, are not sufficiently effective in identifying attack frames, which can lead to unauthorized control of vehicles.
Innovation Solution
A method involving determining a unit time for abnormality detection based on vehicle identification information, using a processor or circuit to assess message frequency and identify feature information, and comparing this information against a model to determine if a received message is abnormal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If statistical methods are used to detect attack frames, then detection capability is improved, but detection accuracy is insufficient
Solution Approach 1:
The patent changes the detection parameter from simple statistical presence/absence to message occurrence frequency within a specific unit time. By monitoring how many messages of each ID are received within a determined time window and comparing against pre-stored frequency thresholds, the system achieves more precise detection while maintaining statistical methodology
Solution Approach 2:
The patent introduces an intermediary detection device that sits between the CAN bus and the ECUs. This intermediary device intercepts and analyzes all messages on the bus, counting message frequencies and comparing them against stored thresholds before allowing messages to reach their destinations, thereby improving detection accuracy without disrupting normal ECU operations
2Measurement precision
If message frequency monitoring is implemented, then abnormality detection accuracy is improved, but processing complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-storing message frequency thresholds for normal operating conditions before the detection process begins. During operation, the system only needs to compare real-time message counts against these pre-established thresholds, avoiding the need for complex real-time analysis algorithms and reducing processing complexity
Solution Approach 2:
The patent segments the detection process into distinct functional modules: message interception, message ID extraction, frequency counting within unit time windows, threshold comparison, and abnormality determination. This segmentation allows each module to perform a simple, well-defined task, reducing overall system complexity while maintaining high detection accuracy
Data Source
AI summary
An abnormality detection method is provided. The abnormality detection method is for detecting an abnormality that may be transmitted to a bus in an on-board network system. The on-board network system includes a plurality of electronic controllers that transmit and receive messages via the bus in a mobility entity. In the abnormality detection method, for example, a gateway transmits identification information to a server and receives a response determining a unit time. An operation process is performed using feature information based on a number of messages received from the bus per the determined unit time and using a model indicating a criterion in terms of a message occurrence frequency. A judgment is made as to an abnormality according to a result of the operation process.


