In-Vehicle Network Anomaly Detection via Flow Ratio Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods struggle to detect anomalies in in-vehicle networks using protocols like FlexRay and CAN, as they are not effective when anomalies occur without disrupting frame reception intervals, and specialized anomaly detecting devices for each protocol are costly and complex to implement.
Innovation Solution
An anomaly detecting device that collects and compares flow communication traffic across multiple networks using a flow collector and anomaly determiner, calculating observed and normal ratios to identify anomalies based on header information, allowing for detection across different protocols with a simple configuration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If specialized anomaly detecting devices are equipped for each protocol (CAN, FlexRay, Ethernet), then anomaly detection accuracy is improved, but device complexity and cost increase
Solution Approach 1:
The patent implements a universal anomaly detection device that can detect anomalies across multiple protocols (CAN, FlexRay, Ethernet) using a single integrated system. The flow collector gathers traffic data from different networks, the flow classifier categorizes frames by protocol type, and the anomaly detector analyzes patterns across all protocols uniformly, eliminating the need for separate specialized devices for each protocol while maintaining detection accuracy
Solution Approach 2:
The patent merges multiple protocol-specific detection functions into a single integrated anomaly detection device. By combining the flow collector, flow classifier, and anomaly detector into one system that processes multiple protocols simultaneously, the patent reduces the number of separate devices needed while preserving the ability to detect protocol-specific anomalies through unified analysis
2Reliability
If multiple specialized anomaly detecting devices are deployed for different protocols, then comprehensive anomaly detection is achieved, but system cost increases
Solution Approach 1:
The patent creates a cost-effective solution by implementing a single anomaly detection device that handles multiple protocols (CAN, FlexRay, Ethernet) through unified flow collection, classification, and analysis. This universal approach achieves comprehensive anomaly detection across all protocols while significantly reducing system cost compared to deploying separate specialized devices for each protocol
Solution Approach 2:
The patent uses flow classification to create virtual copies of protocol-specific detection logic within a single device. The flow classifier categorizes incoming frames by protocol type, allowing the anomaly detector to apply protocol-appropriate analysis rules to each category, effectively replicating specialized detection capabilities without requiring separate physical devices
3Measurement precision
If protocol-specific detection methods are used (e.g., reception interval disruption for CAN), then detection effectiveness is improved for that protocol, but adaptability to other protocols deteriorates
Solution Approach 1:
The patent adapts detection parameters based on protocol type by classifying flows according to their protocol characteristics. For CAN protocols, the system monitors reception intervals and looks for disruptions; for FlexRay, it examines communication patterns within cyclic and slot structures; for Ethernet, it analyzes TCP/IP header information. This parameter adaptation allows protocol-specific detection effectiveness while maintaining a unified detection framework
Solution Approach 2:
The patent applies different detection strategies to different protocol types within the same system. The flow classifier identifies the protocol type of each flow, then the anomaly detector applies protocol-appropriate analysis methods: reception interval monitoring for CAN, communication pattern analysis for FlexRay, and header information examination for Ethernet, achieving local optimization for each protocol while maintaining overall system unity
Data Source
AI summary
An anomaly detecting device includes a flow collector that collects an amount of flow communication traffic in each of two or more networks in an in-vehicle network system that including the two or more networks, the amount of flow communication traffic being information obtained by tallying an amount of communication traffic of one or more frames classified according to a predetermined rule that is based on header information of a network protocol; and an anomaly detector that calculates, based on the amount of flow communication traffic, an observed ratio indicating a ratio of respective amounts of communication traffic in the two or more networks and determines whether the two or more networks are anomalous based on the observed ratio calculated and a normal ratio indicating a ratio of respective amounts of communication traffic in the two or more networks in a normal state.


