UNIVERSAL INTRUSION DETECTION AND PREVENTION FOR VEHICLE NETWORKS
A device may include a vehicle comprising a plurality of network zones, each network zone comprising a plurality of end points. A device may include a controller, comprising: a log monitoring component configured to interpret a log corpus associated with at least one of the plurality of end points, a log analysis component configured to detect a risk event in response to the log corpus, and a risk response component configured to perform a risk response operation in response to the detected risk event.
1 . A system, comprising:
a vehicle comprising a plurality of network zones, each network zone comprising a plurality of end points;
a controller, comprising:
a network monitoring component configured to interpret network communications associated with at least one of the network zones;
a network intrusion detection component configured to detect an intrusion event in response to the network communications; and
an intrusion response component configured to perform an intrusion response operation in response to the detected intrusion event.
2 . The system of claim 1 , wherein the plurality of network zones comprise a plurality of ethernet based network zones.
3 . The system of claim 1 , wherein a first one of the plurality of network zones comprises an ethernet based network zone, and wherein a second one of the plurality of network zones comprises a controller area network (CAN) based network zone.
4 . The system of claim 1 , wherein the network intrusion detection component is further configured to detect the intrusion event in response to a communication source value.
5 . The system of claim 1 , wherein the network intrusion detection component is further configured to detect the intrusion event in response to a communication frequency description.
6 . The system of claim 1 , wherein the network intrusion detection component is further configured to detect the intrusion event in response to a communication destination value.
7 . The system of claim 1 , wherein the network intrusion detection component is further configured to detect the intrusion event in response to a communication payload value.
8 . The system of claim 1 , wherein the intrusion response operation comprises providing a notification in response to the detected intrusion event.
9 . The system of claim 8 , wherein the intrusion response component is further configured to provide the notification in response to a severity of the detected intrusion event.
10 . The system of claim 8 , wherein the notification is provided to at least one of: an end point on at least one of the network zones; a cloud server; or an external device.
11 . The system of claim 8 , wherein the notification comprises at least one of: a severity description, an intrusion type, an intrusion confidence value, an intrusion destination value, or an intrusion source value.
12 . The system of claim 1 , wherein the intrusion response operation comprises blocking a communication source in response to the detected intrusion event.
13 . The system of claim 12 , further comprising:
wherein blocking the communication source comprises communicating an intrusion source value to a vehicle cloud communication controller; and
wherein the controller further comprises the vehicle cloud communication controller, the vehicle cloud communication controller configured to manage external communications comprising communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle.
14 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage external communications comprising communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle; and
wherein the intrusion response operation comprises providing a notification to the vehicle cloud communication controller.
15 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle;
wherein the vehicle cloud communication controller is further configured to interpret a communication policy; and
wherein the network monitoring component is further configured to interpret network communications associated with at least one of the network zones in response to the communication policy.
16 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle;
wherein the vehicle cloud communication controller is further configured to interpret a communication policy; and
wherein the network intrusion detection component is further configured to detect an intrusion event in response to the communication policy.
17 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle;
wherein the vehicle cloud communication controller is further configured to interpret a communication policy; and
wherein the intrusion response component is further configured to perform the intrusion response operation in response to the communication policy.
18 . The system of claim 1 , further comprising:
wherein the controller further comprises a vehicle cloud communication controller, the vehicle cloud communication controller configured to manage communications between: 1) each one of the plurality of end points on the plurality of network zones, and 2) external devices at least selectively communicatively coupled to the vehicle;
wherein the vehicle cloud communication controller is further configured to interpret a communication policy; and
the system further comprising at least one of:
wherein the network monitoring component is further configured to interpret network communications associated with at least one of the network zones in response to the communication policy;
wherein the network intrusion detection component is further configured to detect an intrusion event in response to the communication policy; or
wherein the intrusion response component is further configured to perform the intrusion response operation in response to the communication policy.
19 . The system of claim 18 , wherein the vehicle cloud communication controller is further configured to interpret at least one of a new communication policy or an updated communication policy, and to update the communication policy in response to the at least one of the new communication policy or the updated communication policy.
20 . The system of claim 18 , wherein the intrusion response operation comprises an update to the communication policy.