Vehicle Network Attack Detection via ECU State Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle communication network security systems face challenges in accurately distinguishing between attacks and ECU failures, leading to unnecessary log data storage and communication traffic.
Innovation Solution
The system employs an ECU with a signal determination unit, transmission source determination unit, and attack determination unit to analyze signals on the CAN network, identifying abnormal signals and determining the state of the transmission source ECU to differentiate between attacks and failures, thereby reducing unnecessary log collection and transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the system logs all abnormal signals detected on the communication network, then the security monitoring coverage is improved, but the storage resources are wasted due to false attack data from failing ECUs
Solution Approach 1:
The patent introduces a transmission source determination unit as an intermediary between the signal determination unit and the log collection unit. This intermediary verifies whether the abnormal signal originates from an attack or an ECU failure by checking the transmission source's state, thereby preventing false attack data from being logged and wasting storage resources.
Solution Approach 2:
The system implements a feedback mechanism where the transmission source determination unit continuously monitors the state of signal transmission sources and provides feedback to the log collection unit. When a transmission source is determined to be in a failure state, the feedback prevents logging of its abnormal signals, thus avoiding storage resource waste while maintaining security monitoring for genuine attacks.
2Reliability
If the system transmits log data for all abnormal signals to external servers, then the security analysis capability is improved, but the communication traffic is increased due to unnecessary data transmission from ECU failures
Solution Approach 1:
The transmission source determination unit serves as an intermediary that filters log data before external transmission. By verifying the transmission source state, it prevents unnecessary log data from ECU failures from being transmitted to external servers, thereby reducing communication traffic while maintaining security analysis capability for genuine attacks.
Solution Approach 2:
The system extracts and removes unnecessary log data corresponding to ECU failures from the set of all abnormal signal logs before external transmission. This extraction process separates genuine attack data from false alarm data, reducing communication traffic while preserving security analysis capability.
3Measurement precision
If the system monitors and analyzes every signal on the CAN network, then the attack detection accuracy is improved, but the device complexity increases
Solution Approach 1:
The patent segments the signal analysis process into distinct functional units: signal determination unit for detecting abnormal signals, transmission source determination unit for identifying attack sources, and log collection unit for data management. This segmentation improves attack detection accuracy by assigning specialized functions to each unit while managing complexity through modular architecture.
Solution Approach 2:
The system applies local quality by making each functional unit specialize in a specific aspect of signal analysis. The signal determination unit focuses on detecting abnormal signals, the transmission source determination unit focuses on identifying attack sources, and the log collection unit focuses on data management. This specialization improves overall detection accuracy while keeping each unit's complexity manageable.
Data Source
AI summary
A determination device includes: a signal determination unit configured to determine whether a signal flowing on a communication network in a moving object is abnormal; a transmission source determination unit configured to determine, when the signal determination unit determines that the signal flowing on the communication network is abnormal, whether a communication device which is a transmission source of the abnormal signal is normal; and an attack determination unit configured to determine that an attack on the communication network has occurred, when the signal determination unit determines that the signal flowing on the communication network is abnormal, and the transmission source determination unit determines that the communication device which is the transmission source of the abnormal signal is normal.


