IP Library Granted Patent US 12,476,988
Granted Patent B2
US 12,476,988 · App. 17/516,101 · Granted Nov 18, 2025

In-vehicle network intrusion detection using unsupervised learning

Inventor: Nandi O. Leslie (Silver Spring, MD)
Assignee: NIGHTWING GROUP, LLC
H04L63/1425G06F18/231H04L12/40071H04L2012/40215H04L2012/40273
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,988
App. No.
17/516,101
Granted
Nov 18, 2025
Kind
B2
Abstract

Discussed herein are devices, systems, and methods for detecting anomalous or malicious processes based on in-vehicle network traffic data. A method includes receiving, at a monitor device, a controller access network (CAN) bus packet from an electronic control unit (ECU), implementing an ensemble hierarchical agglomerative clustering (E-HAC) algorithm to identify respective clusters to which the CAN bus data maps, and determining, based on the identified respective clusters, whether the CAN bus packet is associated with in-vehicle network intrusion.

Claims (41)

1 . A device of an in-vehicle network, the device comprising:

at least one memory including instructions stored thereon; and

processing circuitry configured to execute the instructions, the instructions, when executed, cause the processing circuitry to perform operations comprising:

receiving a controller access network (CAN) bus packet from an electronic control unit (ECU);

implementing an ensemble hierarchical agglomerative clustering (E-HAC) algorithm, the E-HAC algorithm implementing multiple HAC algorithms on the CAN bus packet to identity respective clusters to which the CAN bus packet maps in relationship to other CAN bus packets, wherein each CAN bus packet is treated as a separate observation for each HAC evaluation in the clustering analysis, with at least two different distance measures and at least two different linkage functions used by said HAC the E-HAC, wherein each of said HAC algorithms of the E-HAC algorithm operates using a distinct combination of a linkage function and a distance measure pair within said E-HAC, and wherein each of the respective clusters is associated with a designation of either malicious behavior or benign behavior;

identifying a mode of the designation of the respective clusters; and

determining the CAN bus packet that is associated with a network intrusion responsive to identifying the mode of the designation is malicious behavior and the results of the identification of respective clusters using the E-HAC algorithm.

2 . The device of claim 1 , wherein the E-HAC algorithm determines the CAN bus packet is benign responsive to identifying the mode of the designation is benign behavior.

3 . The device of claim 1 , wherein the linkage functions include two or more of Ward, average, simple, or complete linkage.

4 . The device of claim 1 , wherein the distances include two or more of L 1 , L 2 , or cosine.

5 . The device of claim 1 , wherein data of the CAN bus packets conforms to 11939 Standards.

6 . The device of claim 5 , wherein the operations further comprise: extracting features of the CAN bus packet and

wherein the HAC algorithms of the E-HAC algorithm operate on the extracted features to cluster the CAN bus packet.

7 . The device of claim 6 , wherein the features include two or more of engine rotations per minute (RPM), vehicle speed, coolant temperature, engine oil level, oil pressure, fuel level, handbrake applied, distance to service, fuel consumption per unit distance or time, or coolant level.

8 . A non-transitory machine-readable medium including instructions that, when executed by a machine, cause the machine to perform operations for in-vehicle network intrusion detection, the operations comprising:

receiving a controller access network (CAN) bus packet from an electronic control unit (ECU);

implementing an ensemble hierarchical agglomerative clustering (E-HAC) algorithm, the E-HAC algorithm implementing multiple HAC algorithms on the CAN bus packet to identify respective clusters to which the CAN bus packet maps in relationship to other CAN bus packets, wherein each CAN bus packet is treated as a separate observation for each HAC evaluation in the clustering analysis, with at least two different distance measures and at least two different linkage functions used by said HAC algorithms of the E-HAC, wherein each of said HAC algorithms of the E-HAC algorithm operates using a distinct combination of a linkage function and a distance measure pair within said E-HAC, and wherein each of the respective clusters is associated with a designation of either malicious behavior or benign behavior;

identifying a mode of the designation of the respective clusters: and

determining the CAN bus packet that is associated with in-vehicle network intrusion responsive to identifying the mode of the designation is malicious behavior and the results of the identification of respective clusters using the E-HAC algorithm.

9 . The non-transitory machine-readable medium of claim 8 , wherein the E-HAC algorithm determines the CAN bus packet is benign if responsive to identifying the mode of designation is benign behavior.

10 . The non-transitory machine-readable medium of claim 8 , wherein the linkage functions include two or more of Ward, average, simple, or complete linkage.

11 . The non-transitory machine-readable medium of claim 8 , wherein the distances include two or more of L1, L2, or cosine.

12 . The non-transitory machine-readable medium of claim 8 , wherein data of the CAN bus packet conforms to Jl939 Standards.

13 . The non-transitory machine-readable medium of claim 12 , wherein the operations further comprise:

extracting features of the CAN bus packet; and

wherein the HAC algorithms operate on the extracted features to duster the CAN bus packet.

14 . The non-transitory machine-readable medium of claim 13 , wherein the features include two or more of engine rotations per minute (RPM), vehicle speed, coolant temperature, engine oil level, oil pressure, fuel level, handbrake applied, distance to service, fuel consumption per unit distance or time, or coolant level.

15 . A method for in-vehicle network intrusion detection, the method comprising

receiving, at a monitor device, a controller access network (CAN) bus packet from an electronic control unit (ECU);

implementing an ensemble hierarchical agglomerative clustering (E-HAC) algorithm, the E-HAC algorithm implementing multiple HAC algorithms on the CAN bus packet to identify respective clusters to which the CAN bus packet maps in relationship to other CAN bus packets, wherein each CAN bus packet is treated as a separate observation for each HAC evaluation in the clustering analysis,

with at least two different distance measures and at least two different linkage functions used by said HAC algorithms of the E-HAC, wherein each of said HAC algorithms of the E-HAC algorithm operates using a distinct combination of a linkage function and a distance measure pair within said E-HAC, and wherein each of the respective clusters is associated with a designation of either malicious behavior or benign behavior;

identifying a mode of the designation of the respective clusters; and

determining the CAN bus packet that is associated with in-vehicle network intrusion responsive to identifying the mode of the designation is malicious behavior and the results of the identification of respective clusters using the E-HAC algorithm.

16 . The method of claim 15 , wherein determining whether the E-HAC algorithm determines the CAN bus packet is benign responsive to identifying the mode of the designation is benign behavior.

17 . The method of claim 15 , wherein the linkage functions include two or more of Ward, average, simple, or complete.

18 . The method of claim 15 , wherein the distances include two or more of L1, L 2, or cosine.

19 . The method of claim 15 , wherein data of the CAN bus packet conforms to J1939 Standards.

20 . The method of claim 19 , further comprising: extracting features of the CAN bus packet; and

wherein the E-HAC algorithm operates on the extracted features to cluster the CAN bus packet.

21 . The device of claim 1 , wherein the processing circuitry is configured to execute the instructions that cause the processing circuitry to perform converting multiple vehicle characteristics and conditions to a corresponding normalized and dimensionally reduced set of numerical feature values, wherein determining the CAN bus packet is associated with network intrusion includes determining the CAN bus packet is associated with a network intrusion or is not associated with a network intrusion as a function of the number of respective clusters to which the CAN bus packet maps associated with malicious behavior and the number of respective clusters associated with benign behavior, and wherein the CAN bus packet is determined to be associated with an intrusion if a majority of identified respective clusters to which the CAN bus maps is associated with malicious behavior, and the CAN bus packet is determined to be associated with a benign behavior if a majority of identified respective clusters to which the CAN bus maps is associated with benign behavior.

22 . The method of claim 15 , further comprising converting multiple vehicle characteristics and conditions to a corresponding normalized and dimensionally reduced set of numerical feature values, wherein the determining step includes determining the CAN bus packet is associated with a network intrusion or is not associated with a network intrusion as a function of the number of respective clusters to which the CAN bus packet maps associated with malicious behavior and the number of respective clusters associated with benign behavior, and wherein the CAN bus packet is determined to be an intrusion if a majority of identified respective clusters to which the CAN bus maps is associated with malicious behavior, and the CAN bus packet is determined to be benign if a majority of identified respective clusters to which the CAN bus maps is associated with benign behavior.

Assignments (4)
CHANGE OF NAME Recorded Jul 3, 2024
From: COLUMBUS BUYER LLC
To: NIGHTWING GROUP, LLC
Reel/Frame 068106/0251 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2024
From: RAYTHEON COMPANY
To: COLUMBUS BUYER LLC
Reel/Frame 068233/0420 →
SECURITY INTEREST Recorded Apr 1, 2024
From: COLUMBUS BUYER LLC; RAYTHEON BLACKBIRD TECHNOLOGIES, INC.; RAYTHEON FOREGROUND SECURITY, INC.
To: WELLS FARGO BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066960/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2021
From: LESLIE, NANDI O.
To: RAYTHEON COMPANY
Reel/Frame 058099/0944 →
Continuity (2)
Provisional Application 63122277 · Dec 7, 2020
Related Publication 20220182402A1 · Jun 9, 2022
References Cited (21)
US 20160234167A1 · Engel · 2016 [cited by examiner]
US 20180198812A1 · Christodorescu · 2018 [cited by examiner]
US 20200314117A1 · Nguyen · 2020 [cited by examiner]
CN 108809946A · 2018 [cited by examiner]
CN 108881277A · 2018 [cited by examiner]
CN 109344913A · 2019 [cited by examiner]
L. Su et al, “Hierarchical Clustering Based Network Traffic Data Reduction for Improving Suspicious Flow Detection,” 2018 17th IEEE International Conference On Trust, Security And Privacy In Computing And Communications… [cited by examiner]
U. Ezeobi, H. Olufowobi, C. Young, J. Zambreno and G. Bloom, “Reverse Engineering Controller Area Network Messages Using Unsupervised Machine Learning,” in IEEE Consumer Electronics Magazine, vol. 11, No. 1, pp. 50-56, … [cited by examiner]
E. Hooper, “An Intelligent Intrusion Detection and Response System Using Hybrid Ward Hierarchical Clustering Analysis,” 2007 International Conference on Multimedia and Ubiquitous Engineering (MUE'07), Seoul, Korea (Sout… [cited by examiner]
G. D'Angelo, A. Castiglione and F. Palmieri, “A Cluster-Based Multidimensional Approach for Detecting Attacks on Connected Vehicles,” in IEEE Internet of Things Journal, vol. 8, No. 16, pp. 12518-12527, 15 Aug. 15, 2021… [cited by examiner]
Akbari, E., Dahlan, H., Ibrahim, R., Alizadeh, H. “Hierarchical Cluster Ensemble Selection”, Elsevier, Engineering Applications of Artificial Intelligence, vol. 39, pp. 146-156, 2015. (Year: 2015). [cited by examiner]
Xue, M., Bian R., Liu, W., Wang, J. “Defeating Untrustworthy Testing Parties: A Novel Hybrid Clustering Ensemble Based Golden Models-Free Hardware Trojan Detection Method,” in IEEE Access, vol. 7, pp. 5124-5140, 2019 (Y… [cited by examiner]
Chiu, C. H., Chen, J. J., Yu, F. “An Effective Distributed GHSOM Algorithm for Unsupervised Clustering on Big Data”. 2017 IEEE 6th International Congress on Big Data. 2017. (Year: 2017). [cited by examiner]
Makrehchi, M. “Hierarchical Agglomerative Clustering Using Common Neighbors Similarity”. 2016 IEEE/WIC/ACM International Conference on Web Intelligence. 2016. (Year: 2016). [cited by examiner]
D'Angelo, G., Castiglione, A., Palmieri, F. “A Cluster-Based Multidimensional Approach for Detecting Attacks on Connected Vehicles”. Oct. 22, 2020. IEEE. doi: 10.1109/JIOT.2020.3032935 (Year: 2020). [cited by examiner]
Emmendorfer, L. R. “An Empirical Evaluation of Two Novel Linkage Criteria for Hierarchical Agglomerative Clustering”. Oct. 15-18, 2019. IEEE. doi: 10.1109/BRACIS.2019.00114 (Year: 2019). [cited by examiner]
Park, S., Choi, J. Y. “Hierarchical Anomaly Detection Model for In-Vehicle Networks Using Machine Learning Algorithms”. Jul. 15, 2020. PubMed. doi: 10.3390/s20143934. (Year: 2020). [cited by examiner]
Avatefipour, O., Al-Sumaiti, A. S., El-Sherbeeny, A. M., Awwad, E. M., Elmeligy, M. A., Mohamed, M. A. “An Intelligent Secured Framework for Cyberattack Detection in Electric Vehicles' CAN Bus Using Machine Learning”. A… [cited by examiner]
Faridi, H., Srinivasagopalan, S., Verma, R. “Performance Evaluation of Features and Clustering Algorithms for Malware”. Nov. 17-20, 2018. IEEE. doi: 10.1109/ICDMW.2018.00010 (Year: 2018). [cited by examiner]
Levi, M., Allouche, Y., Kontorovich, A. “Advanced Analytics for Connected Car Cybersecurity”. Jun. 3-6, 2018. IEEE. doi: 10.1109/VTCSpring.2018.8417690 (Year: 2018). [cited by examiner]
Hassan, S. Z., Verma, B. “Decisions Fusion Strategy: Towards Hybrid Cluster Ensemble”. Dec. 3-6, 2007. IEEE. doi: 10.1109/ISSNIP.2007.4496873 (Year: 2007). [cited by examiner]