IP Library Granted Patent US 12,282,548
Granted Patent B2
US 12,282,548 · App. 17/725,774 · Granted Apr 22, 2025

Universally applicable signal-based controller area network (CAN) intrusion detection system

Inventors: Robert A. Bridges (Oak Ridge, TN); Kiren E. Verma (Oak Ridge, TN); Michael Iannacone (Oak Ridge, TN); Samuel C. Hollifield (Oak Ridge, TN); Pablo Moriano (Oak Ridge, TN); Jordan Sosnowski (Oak Ridge, TN)
Assignee: UT-Battelle, LLC
G06F21/556G06F21/552G06F21/554H04L12/40026H04L2012/40215
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,548
App. No.
17/725,774
Granted
Apr 22, 2025
Kind
B2
Abstract

A system and method for intrusion detection on automotive controller area networks. The system and method can detect various CAN attacks, such as attacks that cause unintended acceleration, deactivation of vehicle's brakes, or steering the vehicle. The system and method detects changes in nuanced correlations of CAN timeseries signals and how they cluster together. The system reverse engineers CAN signals and detect masquerade attacks by analyzing timeseries extracted from raw CAN frames. Specifically, anomalies in the CAN data can be detected by computing timeseries clustering similarity using hierarchical clustering on the vehicle's CAN signals and comparing the clustering similarity across CAN captures with and without attacks.

Claims (9)

1. An intrusion detection system for detecting masquerade attacks on CAN data communicated over a vehicle controller area network (CAN) of a vehicle, the intrusion detection system comprising: a CAN transceiver configured to receive CAN frames from the vehicle CAN, wherein each CAN frame includes an arbitration identifier (AID) and an up to 64-bit data payload; a CAN controller in communication with the CAN transceiver;

a processor in communication with the CAN controller, wherein the processor is configured to generate a signal definition for each AID mapping the up to 64-bit data payloads of CAN frames with that AID to a plurality of tokenized and translated signals defined by one or more sequences of bits of the up to 64-bit data payload, wherein the mapping accounts for start bit, length, endianness, and signedness of the signals; wherein the processor is configured to (1) learn inherent relationships between uninterpreted timeseries signals in decoded CAN training payload data without dependence upon CAN diagnostic inquiry; (2) learn inherent relationships between uninterpreted timeseries signals in decoded CAN test payload data without dependence upon CAN diagnostic inquiry; (3) detect masquerade attacks on CAN test payload data based on a contrast of the learned inherent relationships of timeseries signals in the decoded CAN training payload data and the learned inherent relationships of timeseries signals in the decoded CAN test payload data; and (4) upon detecting a masquerade attack on CAN test payload data, at least one of transmit an anomaly-notification message and log information relating to the detected masquerade attack.

2. The intrusion detection system of claim 1 wherein the processor is configured to store the signal definition for each AID together with the AID in a CAN database file (DBC) in memory.

3. The intrusion detection system of claim 1 , wherein the payload of the CAN frames from the vehicle CAN are encoded based on unknown signal definitions established by a third party, each signal definition including information to tokenize, translate, and interpret the CAN data, where the information to tokenize includes information to demarcate sequences of bits corresponding to signals in the CAN data and byte ordering, wherein the information to translate includes information about how the sequences of bits were converted to integers.

4. The intrusion detection system of claim 1 , wherein the processor is configured to monitor, during operation of the vehicle, the timeseries signals in the decoded CAN test payload data for anomalies to detect masquerade attacks in the CAN test payload data, wherein the processor is configured to: compute correlations between timeseries signals in the decoded CAN test payload data; and compute agglomerative hierarchical clusterings for the computed correlations between the timeseries signals for the CAN test payload data; compute similarity between hierarchical clusterings for the computed correlations between the timeseries signals for the CAN test payload data; generate a CAN test data distribution of similarities between hierarchical clusterings for the correlations between the timeseries signals for CAN test payload data; compare the CAN test data distribution of similarities between hierarchical clusterings for the correlations between the timeseries signals for the CAN test payload data and CAN training payload data distribution of similarities between hierarchical clusters based on the CAN training payload data stored in memory; and

identify one or more anomalies of the timeseries signals for the CAN test payload data based on the comparison of the CAN test payload data distribution of similarities and the CAN training payload data distribution of similarities.

5. The intrusion detection system of claim 4 wherein the processor is configured to compute the agglomerative hierarchical clusterings based on at least one of a single linkage function, complete linkage function, average linkage function, and a Ward's linkage function.

6. The intrusion detection system of claim 4 wherein the processor is configured to interpolate the timeseries signals in the decoded CAN test payload data according to a selected base-line frequency to an equivalent length.

7. The intrusion detection system of claim 4 , wherein at least one of the respective timeseries for each of the CAN test payload data signals includes a correlated attack, speedometer attack, engine coolant attack, reverse light on attack, and reverse light off attack.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2022
From: BRIDGES, ROBERT A.; VERMA, KIREN E.; IANNACONE, MICHAEL; HOLLIFIELD, SAMUEL C.
To: UT-BATTELLE, LLC
Reel/Frame 060827/0831 →
CONFIRMATORY LICENSE Recorded Jun 13, 2022
From: UT-BATTELLE, LLC
To: U. S. DEPARTMENT OF ENERGY
Reel/Frame 060176/0854 →
Continuity (2)
Provisional Application 63178586 · Apr 23, 2021
Related Publication 20220374515A1 · Nov 24, 2022
References Cited (64)
US 8923607B1 · Kwatra · 2014 [cited by examiner]
US 10892911B2 · Wojciechowski · 2021 [cited by examiner]
US 11423145B2 · Gutierrez · 2022 [cited by examiner]
US 11423162B2 · Juliato · 2022 [cited by examiner]
US 11789886B2 · Muth · 2023 [cited by examiner]
US 11985150B2 · Bajpai · 2024 [cited by examiner]
US 12013935B2 · Davidovich · 2024 [cited by examiner]
US 20190312892A1 · Chung · 2019 [cited by examiner]
US 20210044600A1 · Elend · 2021 [cited by examiner]
US 20210178996A1 · Verma et al. · 2021 [cited by applicant]
WO WO2022040360A1 · 2022 [cited by examiner]
WO WO2022110444A1 · 2022 [cited by examiner]
Miki Verma, ACTT: Automotive CAN Tokenization and Translation, 2018, IEEE (Year: 2018). [cited by examiner]
Gedare Bloom, Reverse Engineering Controller Area Network Messages Using Unsupervised Machine Learning, 2020, IEEE (Year: 2020). [cited by examiner]
Miro Marchetti, READ: Reverse Engineering of Automotive Data Frames, IEEE, 2018 (Year: 2018). [cited by examiner]
Cho, Kyong-Tak et al., “Fingerprinting Electronic Control Units for Vehicle Intrusion Detection”, Proceedings of the 25th USENIX Security Symposium, Aug. 2016, pp. 1-18. [cited by applicant]
Flach, Tobias et al., “CARMA: Towards Personalized Automotive Tuning”, SenSys'11, Nov. 2011, pp. 135-148. [cited by applicant]
Gmiden, Mabrouka et al., “An Intrusion Detection Method for Security In-Vehicle CAN bus”, 17th International Conference on Sciences and Techniques of Automatic Control & Computer Engineering, Dec. 2016, pp. 176-180. [cited by applicant]
Li, Huaxin et al., “POSTER: Intrusion Detection System for In-vehicle Networks using Sensor Correlation and Integration”, CCS'17, Nov. 2017, pp. 2531-2533. [cited by applicant]
Tyree, Zachariah et al., “Exploiting the Shape of CAN Data for In-Vehicle Intrusion Detection”, downloaded at arXiv:1808.10840v1, Aug. 28, 2018, pp. 106. [cited by applicant]
Narayanan, Sandeep Nair et al., “Using Data Analytics to Detect Anomalous States in Vehicles”, downloaded at arXiv:1512.08048v1; Dec. 25, 2015, pp. 1-10. [cited by applicant]
Wasicek, Armin R. et al., “Context-aware Intrusion Detection in Automotive Control Systems”, available at least as of Dec. 13, 2019, pp. 1-14. [cited by applicant]
Miller, Charlie Dr. et al., “Adventures in Automotive Networks and Control Units”, available at least as of Dec. 13, 2019, pp. 1-101. [cited by applicant]
Checkoway, Stephen, et al., “Comprehensive Experimental Analyses of Automotive Attack Surfaces”, available at least as of Dec. 13, 2019, pp. 1-16. [cited by applicant]
Choi, Wonsuk, et al., “Identifying ECUs Using Inimitable Characteristics of Signals in Controller Area Networks”, downloaded at arXiv:1607.00497v1; Jul. 2, 2016, pp. 1-12. [cited by applicant]
Enev, Miro, et al., “Automobile Driver Fingerprinting”, De Gruyter Open, Proceedings on Privacy Enhancing Technologies; 2016 (1):34-51. [cited by applicant]
Hanselmann, Markus, et al., “CANet: An Unsupervised Intrusion Detection System for High Dimensional CAN Bus Data”, downloaded at arXiv:1906.02492v1; Jun. 6, 2019, pp. 1-9. [cited by applicant]
Huybrechts, Thomas, et al., “Automatic Reverse Engineering of CAN Bus Data Using Machine Learning Techniques”, Copyright Springer International Publishing AG 2018, pp. 751-761. [cited by applicant]
Jaynes, Michael, et al., “Automating ECU Identification for Vehicle Security”, 2016 15th IEEE International Conference on Machine Learning and Applications, pp. 632-635. [cited by applicant]
Koscher, Karl, et al., “Experimental Security Analysis of a Modern Automobile”, 2010 IEEE Symposium on Security and Privacy, pp. 447-462. [cited by applicant]
Lee, Hyunsung, et al., “OTIDS: A Novel Intrusion Detection System for In-vehicle Network by using Remote Frame”, 2017 15th Annual Conference on Privacy, Security and Trust, pp. 57-66. [cited by applicant]
Lestyan, Szilvia, et al., “Extracting vehicle sensor signals from CAN logs for driver re-identification”, downloaded at arXiv:1902.08956v1; Feb. 24, 2019, pp. 1-11. [cited by applicant]
Lokman, Siti-Farhana, et al., Intrusion detection system for automotive Controller Area Network (CAN) bus system: a review, EURASIP Journal on Wireless Communications and Networking (2019) 2019:184, 17 pp. [cited by applicant]
Marchetti, Micro, et al., “READ: Reverse engineering of automotive data frames”, 1556-6013(c) 2018 IEEE, 15 pp. [cited by applicant]
Markovitz, Moti, et al., “Vehicular Communications”, Vehicular Communication 9 (2017) 43-52. [cited by applicant]
Moore, Michael R., et al., “Modeling inter-signal arrival times for accurate detection of CAN bus signal injection attacks* A data-driven approach to in-vehicle intrusion detection”, Proceedings of Cyber & Information S… [cited by applicant]
Narayanan, Sandeep Nair, et al., “OBD_SecureAlert: An Anomaly Detection System for Vehicles”, Conference Paper May 2016, publication at https://www.researchgate.net/publication/305674115, 7 pp. [cited by applicant]
Nolan, Brent C., et al., “Unsupervised Time Series Extraction from Controller Area Network Payloads”, available at least as of Dec. 13, 2019, 5 pp. [cited by applicant]
Pawelec, Krzysztof, et al., “Towards a CAN IDS Based on a neural Network Data Field Predictor*”, Session: Anaomaly Detection for Controller Area Network, AutoSec '19, Mar. 27, 2019, Richardson, TX, USA, pp. 31-34. [cited by applicant]
Pese, Mert D., et al., “LibreCAN: Automated CAN Message Translator”, 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS ' 19), Nov. 11-15, 2019, London, United Kingdom. ACM, New York, NY, USA, 18 pp. [cited by applicant]
Bosch, Robert GmbH, “CAN Specification Version 2.0”, 1991, 72 pp. [cited by applicant]
Provencher, Hugo, “Controller Area Networks for Vehicles”, Directed Studies, ENGR 5004G, Faculty of Engineering and Applied Science, University of Ontario Institute of Technology, Apr. 2012, 67 pp. [cited by applicant]
Miller, Charlie, Dr., et al., “Remote Exploitation of an Unaltered Passenger Vehicle”, Aug. 10, 2015, 91 pp. [cited by applicant]
Taylor, Adrian, et al., “Anomaly Detection in Automobile Control Network Data with Long Short-Term Memory Networks”, 2016 IEEE International Conference on Data Science and Advanced Analytics, pp. 130-139. [cited by applicant]
Smith, Craig, et al., “Car Hacker's Handbook, A Guide for the Penetration Tester”, no starch press, San Francisco, Copyright 2016, 306 pp. [cited by applicant]
Tyree, Zachariah, et al., “Exploiting the Shape of CAN Data for In-Vehicle Intrusion Detection”, downloaded at arXiv:1808.10840v1; Aug. 28, 2018, pp. 1-6. [cited by applicant]
Wakita, Toshihiro, et al., “Driver Identification Using Driving Behavior Signals”, IEICE Trans. Inf. & Syst., vol. E89-D, No. 3 Mar. 2006, pp. 1188-1194. [cited by applicant]
Wu, Wufei, et al., “A Survey of Intrusion Detection for In-Vehicle Networks”, IEEE Transaction on Intelligent Transportation Systems, 1624-9050 Copyright 2019 IEEE, pp. 1-15. [cited by applicant]
Young, Clinton, et al., “Towards Reverse Engineering Controller Area Network Messages Using Machine Learning”, available at least as of Dec. 13, 2019, 6 pp. [cited by applicant]
Verma, Miki E., et al., “ACTT: Automative CAN Tokenization and Translation”, downloaded at arXiv:1811.07897v1; Nov. 19, 2018, 6 pp. [cited by applicant]
Website https://github.com/commaai/opendbc, available at least as of Nov. 30, 2018. [cited by applicant]
Website https://github.com/linux-can/can-utils, available at least as of Oct. 26, 2019. [cited by applicant]
Website https://en.wikipedia.org/wiki/Unified_Diagnostic_Services, available at least as of Jul. 18, 2017. [cited by applicant]
Website https://en.wikipedia.org/wiki/OBD-II_PIDs, available at least as of Aug. 27, 2019. [cited by applicant]
Website https://en.wikipedia.org/wiki/Endianness, available at least as of Dec. 11, 2019. [cited by applicant]
Website https://en.wikipedia.org/wiki/Two%27s_complement, available at least as of Dec. 10, 2019. [cited by applicant]
Website http://www.industrialberry.com/canberrydual-v2-1/, available at least as of Dec. 13, 2019. [cited by applicant]
Website https://www.sae.org/standards/content/j1939_201308/, Abstract available at least as of Jun. 12, 2018. [cited by applicant]
Website https://training.dewesoft.com/online/course/automotive-buses-can-measurement, available at least as of Dec. 13, 2019. [cited by applicant]
Website https://hackaday.com/2013/10/22/can-hacking-the-in-vehicle-network/, available at least as of Jul. 12, 2019. [cited by applicant]
Website http://hooovahh.blogspot.com/2017/05/can-part-5-signal-api.html, available at least as of Apr. 15, 2019. [cited by applicant]
Website https://courses.cs.washington.edu/courses/cse521/13wi/slides/06dp-sched.pdf, available at least as of Dec. 13, 2019. [cited by applicant]
Gates, A.J., “CluSim: a python package for calculating clustering similarity”, The Journal of Open Source Software, published Mar. 21, 2019, 4(35), 1264, pp. 1-5. [cited by applicant]
Blevins, D.H., “Time-Based CAN Intrusion Detection Benchmark”, Workshop on Automotive and Autonomous Vehicle Security (AutoSec), Feb. 21, 2021, pp. 1-7. [cited by applicant]