Method for detecting, blocking and reporting cyber-attacks against automotive electronic control units
The disclosed apparatus, systems and methods relate to protecting automotive electronic control units from cyber-attacks.
1. A protection system for a vehicle comprising at least one vehicle bus in electronic communication with a critical electronic control unit and a non-critical electronic control unit, the protection system comprising:
(a) a firewall configured to communicate with the critical electronic control unit, the non-critical electronic control unit, and the at least one vehicle bus; and
(b) a memory in communication with the firewall, the memory storing a set of filtering rules,
wherein the firewall is configured to:
(i) periodically send vehicle bus messages to the critical and non-critical electronic control units to determine a state of the vehicle;
(ii) receive response messages from the critical and non-critical electronic control units in response to the vehicle bus messages;
(iii) monitor the received response messages to determine the state of the vehicle; and
(iv) receive and filter data packets sent by the critical and non-critical electronic control units using the set of filtering rules and the state of the vehicle.
2. The protection system of claim 1 , wherein the firewall is configured to send vehicle bus messages to the critical and non-critical electronic control units between 1 and 10 times per second.
3. The protection system of claim 2 , wherein the state of the vehicle is based on at least one of current vehicle speed, vehicle gear status, and braking status.
4. The protection system of claim 3 , wherein the set of filtering rules comprises rules for at least BLOCK, ALLOW, and LOG.
5. The protection system of claim 4 , wherein the firewall is configured to prevent a data packet from being sent to the critical or non-critical electronic control units if the firewall applies the rule for BLOCK.
6. The protection system of claim 5 , wherein the firewall is configured to send a data packet to the critical or non-critical electronic control units if the firewall applies the rule for ALLOW.
7. The protection system of claim 6 , wherein the firewall is configured to send a data packet to the critical or non-critical electronic control units and log the sending if the firewall applies the rule for LOG.
8. A protection system for a vehicle with a vehicle bus and at least one electronic control unit, the protection system comprising:
(a) a vehicle bus bridge configured to communicate with the vehicle bus and the at least one electronic control unit;
(b) a firewall in communication with the vehicle bus bridge; and
(c) memory in communication with the firewall, the memory storing a first set of filtering rules and a second set of filtering rules,
wherein,
(1) the firewall is configured to send messages to the at least one electronic control unit to determine a state of the vehicle,
(2) the vehicle bus bridge is configured to perform bi-directional filtering based upon the first and second set of filtering rules and the state of the vehicle, and
(3) the first set of filtering rules is used for vehicle bus messages being sent from a critical vehicle bus to a non-critical vehicle bus and the second set of filtering rules is used for vehicle bus messages being sent from a non-critical vehicle bus to a critical vehicle bus.
9. The protection system of claim 8 , wherein the firewall is configured to send messages to the at least one electronic control unit to determine the state of the vehicle at least about every second.
10. The protection system of claim 8 , wherein the state of the vehicle is based on at least one of gear status, braking status, and vehicle speed.
11. The protection system of claim 8 , wherein the firewall comprises at least three filtering actions including BLOCK, ALLOW, and LOG.
12. The protection system of claim 8 , wherein the firewall and the memory are part of the vehicle bus bridge.
13. The protection system of claim 12 , wherein the firewall is a first firewall and the bus bridge further comprises a second firewall, wherein the first firewall is configured to filter the vehicle bus messages sent from the critical vehicle bus to the non-critical vehicle bus using the first set of filtering rules, and wherein the second firewall is configured to filter the vehicle bus messages sent from the non-critical vehicle bus to the critical vehicle bus using the second set of filtering rules.
14. The protection system of claim 1 , wherein the data packets comprise message IDs, and wherein the set of filtering rules defines an action for each combination of vehicle state and message ID.
15. The protection system of claim 14 , wherein the set of filtering rules defines different actions for different vehicle states for at least one message ID.
16. The protection system of claim 14 , wherein the state of the vehicle is one of a group of vehicle states comprising PARKED, STOPPED, and MOVING.
17. The protection system of claim 8 , wherein the vehicle bus messages comprise message IDs, and wherein the set of filtering rules defines an action for each combination of vehicle state and message ID.
18. The protection system of claim 17 , wherein the first set of filtering rules defines different actions for different vehicle states for at least one message ID and wherein the second set of filtering rules defines different actions for different vehicle states for at least one message ID.
19. The protection system of claim 17 , wherein the state of the vehicle is one of a group of vehicle states comprising PARKED, STOPPED, and MOVING.
20. A method for securing a vehicle on a first firewall, comprising:
sending vehicle bus messages from the first firewall to at least one electronic control unit;
receiving, from the at least one electronic control unit, response messages comprising vehicle state information;
filtering messages on the first firewall using at least a first set of filtering rules, a second set of filtering rules, and the vehicle state information where the first set of filtering rules is used for vehicle bus messages being sent from a critical vehicle bus to a non-critical vehicle bus and the second set of filtering rules is used for vehicle bus messages being sent from a non-critical vehicle bus to a critical vehicle bus; and
sending approved vehicle bus response messages to a vehicle bus.