Vehicle Network Intrusion Detection via Cyclic Message Anomalies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected vehicles are vulnerable to cyber intrusions through wireless networks, posing a significant risk to their electronic systems and potentially allowing hackers to control vehicles without the driver's knowledge.
Innovation Solution
A method and system for improving vehicle electronics security by using timers and counters to detect anomalies in cyclic messages, request signals, and response signals, thereby identifying potential intrusions in real-time.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If wireless network access is provided in connected vehicles, then access to information and services is improved, but vulnerability to cyber intrusions increases
Solution Approach 1:
The system performs preliminary actions by establishing baseline communication patterns and setting threshold values before intrusions occur. The processor continuously monitors message counts, response times, and communication patterns, comparing them against pre-established thresholds to detect anomalies that indicate potential cyber intrusions.
Solution Approach 2:
The system implements feedback mechanisms by continuously monitoring vehicle electronic communication and providing real-time detection of abnormal patterns. When the message count exceeds thresholds or response times deviate from expected ranges, the system generates alerts and can trigger safety responses, creating a closed-loop security system.
2Measurement precision
If real-time intrusion detection is implemented, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The detection system is segmented into distinct functional modules: a monitoring module that counts messages and measures response times, a comparison module that evaluates counts against thresholds, and a response module that triggers alerts. This segmentation allows the complex detection task to be divided into manageable, independent functions.
Solution Approach 2:
The system uses parameter changes by establishing threshold values for message counts and response times that define normal versus abnormal operation. These parameters can be adjusted based on specific vehicle systems and communication patterns, allowing the detection system to adapt to different operational contexts without increasing structural complexity.
Data Source
AI summary
Methods and systems of improving security of a computing system having a network of embedded devices are disclosed. The method includes starting a timer of a predetermined length of time, obtaining an expected number of cyclic messages to be received within the predetermined length of time, incrementing a message counter each time a cyclic message is received within the predetermined length of time, incrementing a set counter in response to an actual number of cyclic messages received by the end of the predetermined length of time exceeding the expected number of cyclic messages to be received by a first threshold value, and detecting an intrusion in the system in response to the set counter exceeding a second threshold value by the end of the predetermined length of time.


