IP Library › Granted Patent US 11,423,145
Granted Patent B2
US 11,423,145 · App. 16/727,565 · Granted Aug 23, 2022

Methods and arrangements for multi-layer in-vehicle network intrusion detection and characterization

Inventors: Christopher N. Gutierrez (Hillsboro, OR); Marcio Juliato (Portland, OR); Shabbir Ahmed (Beaverton, OR); Qian Wang (Santa Clara, CA); Manoj Sastry (Portland, OR); Liuyang L. Yang (Portland, OR); Xiruo Liu (Portland, OR)
Assignee: INTEL CORPORATION
G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,423,145
App. No.
16/727,565
Granted
Aug 23, 2022
Kind
B2
Abstract

Logic may implement observation layer intrusion detection systems (IDSs) to combine observations by intrusion detectors and/or other intrusion detection systems. Logic may monitor one or more control units at one or more observation layers of an in-vehicle network, each of the one or more control units to perform a vehicle function. Logic may combine observations of the one or more control units at the one or more observation layers. Logic may determine, based on a combination of the observations, that one or more of the observations represent an intrusion. Logic may determine, based at least on the observations, characteristics of an attack, and to pass the characteristics of the attack information to a forensic logging system to log the attack or pass the characteristics of the attack to a recovery system for informed selection of recovery procedures. Logic may dynamically adjust a threshold for detection of suspicious activity.

Claims (33)

1. An apparatus to detect intrusion, the apparatus comprising:

memory; and

a detection logic circuitry arranged to:

dynamically adjust a threshold for detection of suspicious activity by an intrusion detection system (IDS) at a first observation layer of a plurality of observation layers of an in-vehicle network based on either a single output or a combination of outputs from at least one other IDS;

monitor one or more control units at one or more of the plurality of observation layers of the in-vehicle network, each of the one or more control units to perform a vehicle function;

combine observations of the one or more control units at the one or more of the plurality of observation layers; and

determine, based on a combination of the observations and the threshold for detection of suspicious activity, that one or more of the observations represent an intrusion.

2. The apparatus of claim 1 , further comprising attack characterization logic circuitry to determine, based at least on the observations, characteristics of an attack, and to pass the characteristics of the attack information to a forensic logging system to log the attack or pass the characteristics of the attack to a recovery system for informed selection of recovery procedures.

3. The apparatus of claim 2 , the characteristics to comprise an indication of the one or more of the observations that represent the attack.

4. The apparatus of claim 3 , the characteristics to comprise an indication of compromised signals.

5. The apparatus of claim 2 , the characteristics to comprise an indication of one or more of the control units that represent a source of the attack.

6. The apparatus of claim 2 , the characteristics to comprise an indication of one or more of the control units that represent a target for the attack.

7. The apparatus of claim 1 , wherein the detection logic circuitry comprises a processor coupled with the memory to execute code of the detection logic circuitry.

8. The apparatus of claim 1 , wherein the observation layers to include any one or more layers of a physical layer, a message layer, a context layer, and an other layer, wherein the physical layer comprises voltage levels at pins of a control unit, the message layer comprises message ordering/timing and content contained within the messages observed on channels of an in-vehicle bus, the context layer comprises vehicle specific messages, and the other layer comprises other vehicle data.

9. The apparatus of claim 1 , wherein combination of the observations of the one or more control units at the one or more observation layers comprises any one or combination of intra-layer observation combinations, inter-layer combinations, and global layer combinations.

10. The apparatus of claim 1 , wherein combination of the observations of the one or more control units at the one or more observation layers comprises any one or combination of majority voting, machine learning, weighted voting, and historical pattern comparison.

11. A method to detect intrusion, the method comprising:

dynamically adjusting, by detection logic circuitry, a threshold for detection of suspicious activity by an intrusion detection system (IDS) at a first layer of a plurality of observation layers of an in-vehicle network based on a single output or a combination of outputs from at least one other IDS;

monitoring, by the detection logic circuitry, one or more control units at one or more observation layers of the plurality of observation layers of the in-vehicle network, each of the one or more control units to perform a vehicle function;

combining observations of the one or more control units at the one or more observation layers; and

determining, based on a combination of the observations and the threshold for detection of suspicious activity, that one or more of the observations represent an intrusion.

12. The method of claim 11 , further comprising determining, based at least on the observations, characteristics of an attack, and to pass the characteristics of the attack information to a forensic logging system to log the attack or pass the characteristics of the attack to a recovery system for informed selection of recovery procedures.

13. The method of claim 12 , the characteristics to comprise an indication of the one or more of the observations that represent the attack.

14. The method of claim 12 , the characteristics to comprise an indication of compromised signals and an indication of one or more of the control units that represent a source of the attack.

15. A computer program product comprising a non-transitory computer-readable medium, comprising instructions, which when executed by a processor cause the processor to perform operations, the operations to:

dynamically adjust a threshold for detection of suspicious activity by an intrusion detection system (IDS) at a first layer of a plurality of observation layers of an in-vehicle network based on a single output or a combination of outputs from at least one other IDS;

monitor one or more control units at one or more observation layers of the plurality of observation layers of the in-vehicle network, each of the one or more control units to perform a vehicle function;

combine observations of the one or more control units at the one or more observation layers; and

determine, based on a combination of the observations and the threshold for detection of suspicious activity, that one or more of the observations represent an intrusion.

16. The computer program product of claim 15 , wherein the operations further comprise operations to determine based at least on the observations, characteristics of an attack, and to pass the characteristics of the attack information to a forensic logging system to log the attack or pass the characteristics of the attack to a recovery system for informed selection of recovery procedures.

17. The computer program product of claim 16 , the characteristics to comprise an indication of the one or more of the observations that represent the attack and an indication of compromised signals.

18. The computer program product of claim 16 , the characteristics to comprise an indication of one or more of the control units that represent a source of the attack.

19. The computer program product of claim 15 , wherein combination of the observations of the one or more control units at the one or more observation layers comprises any one or combination of intra-layer observation combinations, inter-layer combinations, and global layer combinations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 15, 2020
From: GUTIERREZ, CHRISTOPHER N.; JULIATO, MARCIO; AHMED, SHABBIR; WANG, QIAN; SASTRY, MANOJ; YANG, LIUYANG L.; LIU, XIRUO
To: INTEL CORPORATION
Reel/Frame 051597/0144 →
Continuity (1)
Related Publication 20200143053A1 · May 7, 2020
Cited By (1)
US 12,282,548