System and method for providing secure in-vehicle network
View Patent ↗A system and a method of providing security to an in-vehicle network are provided. The method efficiently operates multiple detection techniques to reduce the required system resources while maintaining robustness against malicious message detection.
1. A method of providing security to an in-vehicle network, the method performed by an electronic apparatus connected to the in-vehicle network, the method comprising:
collecting a new network message from the in-vehicle network;
determining an application order of multiple detection techniques to apply to the new network message based on a history detection of the multiple detection techniques applied to at least one network message previously collected from the in-vehicle network; and
applying the multiple detection techniques to the new network message in a determined application order to determine whether the new network message is a security threat message;
wherein the application order of the multiple detection techniques is determined such that a detection technique of the multiple detection techniques, which has succeeded in detecting the security threat message from the at least one previously collected network message, is performed prior to other detection techniques of the multiple detection techniques.
2. The method of claim 1 , wherein the determining of the application order of the multiple detection techniques includes:
counting a cumulative number of times successful in detecting the security threat message for each of the multiple detection techniques; and
changing the application order of the multiple detection techniques in descending order of cumulative numbers of times for respective ones of the multiple detection techniques.
3. The method of claim 1 , wherein the multiple detection techniques include a static detection, a misuse detection, and an anomaly detection.
4. An electronic apparatus for providing security to an in-vehicle network, comprising:
one or more processors; and
a memory in which instructions are stored, wherein the instructions, when executed by the one or more processors, cause the electronic apparatus to perform the steps of:
collect a new network message from the in-vehicle network;
determine an application order of multiple detection techniques to apply to the new network message collected from the in-vehicle network based on a history of detection of the multiple detection techniques applied to at least one network message previously collected from the in-vehicle network; and
apply the multiple detection techniques to the new network message in a determined application order to determine whether the new network message is a security threat message,
wherein the application order of the multiple detection techniques is determined such that a detection technique, which has succeeded in detecting the security threat message from the at least one previously collected network message, is performed prior to other detection techniques.
5. The electronic apparatus of claim 4 , wherein the determining of the application order of the multiple detection techniques includes:
counting a cumulative number of times successful in detecting the security threat message for each of the multiple detection techniques; and
changing the application order of the multiple detection techniques in descending order of cumulative numbers of times for respective ones of the multiple detection techniques.
6. The electronic apparatus of claim 4 , wherein the multiple detection techniques include a static detection, a misuse detection, and an anomaly detection.