Side-Channel Cyber-Attack Detection via Signal Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for detecting cyber-attacks in multi-module systems, such as vehicles with CAN bus communication, require prior examples of normal and anomalous behavior, making them ineffective against novel attacks and potentially dangerous as they cannot detect spoofing or altering of messages in real-time.

Innovation Solution

A side-channel based detection system that converts data bus signals and analog side-channel signals into time series of system states, comparing them to identify violations of predetermined constraints, allowing for the detection of cyber-attacks without prior examples, and initiates actions like deactivating internet connections or switching to a safe mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional intrusion detection systems are used that require prior examples of normal and abnormal behavior, then they can detect known attacks, but they cannot detect novel attacks and require extensive training data

Engineering Contradiction:
Improvedetection accuracyVSAvoidability to detect novel attacks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of trying to detect anomalies by comparing against known normal behavior patterns, the system inverts the approach by establishing predetermined constraints that normal behavior must satisfy. Any violation of these constraints is immediately flagged as anomalous, eliminating the need for training data and enabling detection of novel attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system performs preliminary action by pre-defining the constraints that normal system behavior must satisfy before any attack occurs. These constraints are established based on the expected relationship between data bus states and side-channel states, allowing the system to immediately detect any deviations without requiring prior exposure to attack patterns.

Inventive Principle:
Principle #10Preliminary action

2Speed

If side-channel analysis is used to detect attacks, then real-time detection is possible, but the system complexity increases due to multiple signal processing requirements

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidsignal processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The system extracts only the essential features needed for attack detection by converting both data bus signals and side-channel signals into simplified time series of system states. This extraction process removes unnecessary complexity while retaining the critical information needed to detect constraint violations in real-time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces an intermediary representation layer that converts raw data bus and side-channel signals into a common time series format of system states. This intermediary representation simplifies the comparison process and reduces the complexity of analyzing the relationship between different signal types.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If multiple pre-existing examples of normal and abnormal behavior are collected for training, then detection accuracy improves, but the system cannot adapt to new attack types and requires extensive data storage

Engineering Contradiction:
Improvedetection precisionVSAvoiddata storage requirements
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

Instead of collecting and storing large quantities of training data to improve detection precision, the system inverts the approach by defining precise constraints that normal behavior must satisfy. This constraint-based approach achieves high detection precision without requiring extensive data storage, as the constraints themselves serve as the reference for detecting anomalies.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP3752943B1System and method for side-channel based detection of cyber-attack
Publication Date: 2024.01.31 HRL LAB
  • EP3752943B1 patent drawingFigure 1
  • EP3752943B1 patent drawingFigure 2
  • EP3752943B1 patent drawingFigure 3A

AI summary

Described is a system for side-channel based detection of cyber-attack. In operation, the system converts data bus signals from a platform (e.g., vehicular platform) into a first time series of system states. The system further converts analog side-channel signals from the platform into a second time-series of system states. Anomalous behavior of the platform is detected by comparing the first time series of system states with the second time series of system states to identify violations of predetermined constraints. Upon detection, the anomalous behavior is designated as a cyber-attack of the platform, which causes the platform to initiate an action based on the detected cyber-attack. Such actions include implementing a safe made, etc.