Intrusion Detection Models for Time Sensitive Network Desynchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Time-sensitive networking (TSN) systems are vulnerable to desynchronization attacks, which can disrupt critical timing and safety in applications like autonomous vehicles and industrial systems, necessitating effective intrusion detection and isolation mechanisms to prevent the spread of such attacks.

Innovation Solution

Implementing intrusion detection systems (IDS) throughout TSN networks to rapidly detect and localize attackers, isolate compromised devices, and update network configurations to prevent desynchronization attacks, using techniques like dropping malicious messages and reconfiguring network paths based on knowledge of network topology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems are implemented throughout TSN networks to detect and isolate attackers, then the reliability and safety of TSN systems is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvesafety of TSN systemsVSAvoidcomplexity of IDS implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into multiple TSN domains with hierarchical IDS deployment. Each domain has its own IDS that operates independently, detecting attacks locally before they can spread network-wide. This segmentation reduces the complexity burden on individual devices while maintaining overall network reliability through distributed detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The IDS is configured with pre-established inference models and attack detection rules before deployment. These models contain predetermined patterns for identifying desynchronization attacks, allowing the system to rapidly classify incoming messages as benign or malicious without requiring complex real-time analysis, thereby reducing processing overhead.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If IDS rapidly detects and isolates attackers by dropping malicious messages, then the detection time is reduced, but the loss of legitimate time-sensitive data increases

Engineering Contradiction:
Improvedetection time of attacksVSAvoidloss of legitimate data
Core Design Contradiction:
Loss of timeVSLoss of information

Solution Approach 1:

The IDS implements continuous feedback loops where detection results from one message are used to refine the inference model for subsequent messages. The system learns from patterns in legitimate traffic versus attack traffic, improving its ability to distinguish between the two over time. This feedback mechanism reduces false positives that would otherwise cause legitimate data loss while maintaining rapid detection capability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The IDS dynamically adjusts its detection parameters and inference thresholds based on network conditions and traffic patterns. By changing parameters such as detection sensitivity and message timing tolerances, the system can adapt to legitimate variations in traffic while maintaining rapid detection of actual attacks, thereby reducing both detection time and false rejection of legitimate data.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12095782B2Inference models for intrusion detection systems in time sensitive networks
Publication Date: 2024.09.17 INTEL CORP
  • US12095782B2 patent drawing
  • US12095782B2 patent drawing
  • US12095782B2 patent drawing

AI summary

Techniques to secure a time sensitive network are described. An apparatus may establish a data stream between a first device and a second device in a network domain, the network domain includes a plurality of switching nodes, receive messages from the first device by the second device in the network domain, the messages to comprise time information to synchronize a first clock for the first device and a second clock for the second device to a network time for the network domain, update a correction field for a received message with a residence time and time delay value by the second device, determine whether the updated message is benign or malicious, update the correction field for the updated message with an inference time when the updated message is benign, and prevent relay of the updated message to other devices in the network domain when the updated message is malicious.