IP Library Granted Patent US 12,309,593
Granted Patent B2
US 12,309,593 · App. 17/484,806 · Granted May 20, 2025

Techniques for misbehavior detection in wireless communications systems

Inventors: Jonathan Petit (Wenham, MA); Jean-Philippe Monteuuis (Shrewsbury, MA); Mohammad Raashid Ansari (Lowell, MA); Cong Chen (Shrewsbury, MA)
Assignee: QUALCOMM Incorporated
H04W12/121H04W4/40H04W12/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,593
App. No.
17/484,806
Granted
May 20, 2025
Kind
B2
Abstract

Methods, systems, and devices for wireless communications are described. A communication device may detect vehicle-to-everything (V 2 X) fuzzing attacks. The communication device may receive a set of packets. Each packet of the set of packets includes a set of information element (IE) fields. The communication device determine a change to one or more IE fields of the set of IE fields and associated with at least a subset of packets of the set of packets based on comparing a respective value associated with each of the one or more IE fields to a respective default value associated with each of the one or more IE fields. As a result, the communication device may transmit a report indicating a plurality of fuzzing attacks at the communication device.

Claims (44)

1. A method for wireless communication at a device, comprising:

receiving a set of vehicle-to-everything (V2X) messages during a time window for detection of fuzzing attacks, each V2X message of the set of V2X messages comprising a set of information element fields associated with V2X operations of a second device in accordance with the device operating within a V2X communications system;

determining a change to one or more information element fields of the set of information element fields in multiple V2X messages of the set of V2X messages received in the time window based at least in part on a comparison of a respective value associated with each of the one or more information element fields to a respective expected value associated with each of the one or more information element fields, each V2X message of the multiple V2X messages comprising a same identifier associated with the second device and comprising a respective basic safety message associated with the V2X operations of the second device;

detecting a fuzzing attack associated with the multiple V2X messages of the set of V2X messages received in the time window based at least in part on determining the change; and

transmitting, to a network entity, a single report indicating the fuzzing attack and including evidence of the fuzzing attack aggregated from the multiple V2X messages based at least in part on determining the change and based at least in part on the multiple V2X messages comprising the same identifier.

2. The method of claim 1 , wherein determining the change to the one or more information element fields of the set of information element fields comprises:

determining whether a value of each of the one or more information element fields of the multiple V2X messages satisfies a respective threshold value, wherein the respective threshold value comprises the respective expected value associated with each of the one or more information element fields.

3. The method of claim 1 , further comprising:

determining a pattern associated with the fuzzing attack for the multiple V2X messages, the pattern indicating an increase or a decrease in the respective value associated with each of the one or more information element fields, wherein the increase or the decrease in the respective value associated with each of the one or more information element fields is based at least in part on a randomness, the pattern identifying a data type associated with each of the one or more information element fields, wherein determining the change to the one or more information element fields of the set of information element fields is based at least in part on the pattern associated with the fuzzing attack for the multiple V2X messages.

4. The method of claim 1 , wherein determining the change to the one or more information element fields of the set of information element fields is based at least in part on a machine learning algorithm.

5. The method of claim 1 , further comprising:

aggregating evidence of a plurality of misbehaviors based at least in part on determining the change to the one or more information element fields of the set of information element fields, each misbehavior of the plurality of misbehaviors corresponding to an instance of the respective value associated with each of the one or more information element fields differing from the respective expected value associated with each of the one or more information element fields; and

storing the evidence of the plurality of misbehaviors, wherein detecting the fuzzing attack is based at least in part on storing the evidence, and wherein the single report includes the evidence of the plurality of misbehaviors.

6. The method of claim 1 , wherein transmitting the single report indicating the fuzzing attack and including the evidence aggregated from the multiple V2X messages comprises:

transmitting, to the network entity, information associated with the multiple V2X messages based at least in part on determining the change to the one or more information element fields of the set of information element fields, the information indicating a detected misbehavior for each of the multiple V2X messages and a time stamp associated with the detected misbehavior for each of the multiple V2X messages.

7. The method of claim 1 , further comprising:

tracking the same identifier associated with the second device that transmits at the multiple V2X messages based at least in part on determining the change to the one or more information element fields.

8. The method of claim 1 , further comprising:

receiving, from the network entity, feedback information based at least in part on the single report indicating the fuzzing attack; and

monitoring a second set of V2X messages for a second change to a second one or more information element fields of a second set of information element fields in multiple V2X messages of the second set of V2X messages based at least in part on the feedback information.

9. The method of claim 8 , wherein the feedback information comprises an acknowledgement of the single report indicating the fuzzing attack.

10. The method of claim 8 , wherein the feedback information comprises a negative acknowledgement of the single report indicating the fuzzing attack, and wherein the feedback information indicates that the change to the one or more information element fields is associated with a plurality of separate attacks, the method further comprising:

adjusting a detection criteria for fuzzing attacks based at least in part on the feedback information comprising the negative acknowledgement, wherein monitoring the second set of V2X messages for the change to the second one or more information element fields of the second set of information element fields is based at least in part on the adjusting of the detection criteria for fuzzing attacks.

11. The method of claim 1 , wherein the time window for detection of fuzzing attacks comprises a pre-configured time window or a dynamically configured time window.

12. A device for wireless communication, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus device to:

receive a set of vehicle-to-everything (V2X) messages during a time window for detection of fuzzing attacks, each V2X message of the set of V2X messages comprising a set of information element fields associated with V2X operations of a second device in accordance with the device operating within a V2X communications system;

determine a change to one or more information element fields of the set of information element fields in multiple V2X messages of the set of V2X messages received in the time window based at least in part on a comparison of a respective value associated with each of the one or more information element fields to a respective expected value associated with each of the one or more information element fields, each V2X message of the multiple V2X messages comprising a same identifier associated with the second device and comprising a respective basic safety message associated with the V2X operations of the second device;

detect a fuzzing attack associated with the multiple V2X messages of the set of V2X messages received in the time window based at least in part on determining the change; and

transmit, to a network entity, a single report indicating the fuzzing attack and including evidence of the fuzzing attack aggregated from the multiple V2X messages based at least in part on determining the change and based at least in part on the multiple V2X messages comprising the same identifier.

13. The device of claim 12 , wherein, to determine the change to the one or more information element fields of the set of information element fields, the one or more processors are individually or collectively operable to cause the device to:

determine whether a value of each of the one or more information element fields of the multiple V2X messages satisfies a respective threshold value, wherein the respective threshold value comprises the respective expected value associated with each of the one or more information element fields.

14. The device of claim 12 , wherein the one or more processors are individually or collectively further operable to cause the device to:

determine a pattern associated with the fuzzing attack for of the multiple V2X messages, the pattern indicating an increase or a decrease in the respective value associated with each of the one or more information element fields, wherein the increase or the decrease in the respective value associated with each of the one or more information element fields is based at least in part on a randomness, the pattern identifying a data type associated with each of the one or more information element fields, wherein the one or more processors are individually or collectively operable to determine the change to the one or more information element fields of the set of information element fields based at least in part on the pattern associated with the fuzzing attack for the multiple V2X messages.

15. The device of claim 12 , wherein the one or more processors are individually or collectively operable to determine the change to the one or more information element fields of the set of information element fields based at least in part on a machine learning algorithm.

16. The device of claim 12 , wherein the one or more processors are individually or collectively further operable to cause the device to:

aggregate evidence of a plurality of misbehaviors based at least in part on determining the change to the one or more information element fields of the set of information element fields, each misbehavior of the plurality of misbehaviors corresponding to an instance of the respective value associated with each of the one or more information element fields differing from the respective expected value associated with each of the one or more information element fields; and

store the evidence of the plurality of misbehaviors, wherein detecting the fuzzing attack is based at least in part on storing the evidence and wherein the single report includes the evidence of the plurality of misbehaviors.

17. An device for wireless communication, comprising:

means for receiving a set of vehicle-to-everything (V2X) messages during a time window for detection of fuzzing attacks, each V2X message of the set of V2X messages comprising a set of information element fields associated with V2X operations of a second device in accordance with the device operating within a V2X communications system;

means for determining a change to one or more information element fields of the set of information element fields in multiple V2X messages of the set of V2X messages received in the time window based at least in part on a comparison of a respective value associated with each of the one or more information element fields to a respective expected value associated with each of the one or more information element fields, each V2X message of the multiple V2X messages comprising a same identifier associated with the second device and comprising a respective basic safety message associated with the V2X operations of the second device;

means for detecting a fuzzing attack associated with the multiple V2X messages of the set of V2X messages received in the time window based at least in part on determining the change; and

means for transmitting, to a network entity, a single report indicating the fuzzing attack and including evidence of the fuzzing attack aggregated from the multiple V2X messages based at least in part on determining the change and based at least in part on the multiple V2X messages comprising the same identifier.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: PETIT, JONATHAN; MONTEUUIS, JEAN-PHILIPPE; ANSARI, MOHAMMAD RAASHID; CHEN, CONG
To: QUALCOMM INCORPORATED
Reel/Frame 057825/0189 →
Continuity (1)
Related Publication 20230100792A1 · Mar 30, 2023
References Cited (23)
US 8726382B2 · Knapp · 2014 [cited by examiner]
US 10454968B1 · Bortz · 2019 [cited by examiner]
US 11349869B1 · Moeck · 2022 [cited by examiner]
US 11349963B1 · Chattopadhyay · 2022 [cited by examiner]
US 20080016562A1 · Keeni · 2008 [cited by examiner]
US 20090254970A1 · Agarwal · 2009 [cited by examiner]
US 20130058276A1 · Somasundaram · 2013 [cited by examiner]
US 20190052674A1 · Wada · 2019 [cited by examiner]
US 20190109872A1 · Dhakshinamoorthy · 2019 [cited by examiner]
US 20200106797A1 · Christian · 2020 [cited by examiner]
US 20200274887A1 · Zaw · 2020 [cited by examiner]
US 20200314491A1 · Rodgers · 2020 [cited by examiner]
US 20210203641A1 · Mantin · 2021 [cited by examiner]
US 20220021689A1 · Aoki · 2022 [cited by examiner]
US 20220028903A1 · Lee et al. · 2022 [cited by applicant]
US 20220038903A1 · Fu · 2022 [cited by examiner]
CN 110505134A · 2019 [cited by applicant]
Koscher, “Experimental security analysis of a modern automobile”, 2010, IEEE, pp. 1-15 (Year: 2010). [cited by examiner]
Al-Jarrah, “Intrusion Detection Systems for Intra-Vehicle Networks: A Review”, Feb. 27, 2019, IEEE, vol. 7, pp. 21266-21286 (Year: 2019). [cited by examiner]
International Search Report and Written Opinion—PCT/US2022/040730—ISA/EPO—Dec. 7, 2022 (2106678WO). [cited by applicant]
Koscher K., et al., “Experimental Security Analysis of a Modern Automobile”, Security and Privacy (SP), 2010 IEEE Symposium On, IEEE, Piscataway, NJ, USA, May 16, 2010, pp. 447-462, XP031705100, ISBN: 978-1-4244-6894-2,… [cited by applicant]
Nazakat I., et al., “Intrusion Detection System for In-Vehicular Communication”, 2019 15Th International Conference on Emerging Technologies, IEEE, Dec. 2, 2019, 6 Pages, XP033714024, DOI: 10.1109/ICET48972.2019.8994327… [cited by applicant]
Song H. M., et al., “Self-Supervised Anomaly Detection for In-Vehicle Network Using Noised Pseudo Normal Data”, IEEE Transactions on Vehicular Technology, IEEE, USA, vol. 70, No. 2, Jan. 12, 2021, pp. 1098-1108, XP01184… [cited by applicant]