首页> 外国专利> ANOMALY DETECTION FOR VEHICULAR NETWORKS FOR INTRUSION AND MALFUNCTION DETECTION

ANOMALY DETECTION FOR VEHICULAR NETWORKS FOR INTRUSION AND MALFUNCTION DETECTION

机译:入侵和故障检测的车辆网络异常检测

摘要

A security monitoring system for a Controller Area Network (CAN) comprises an Electronic Control Unit (ECU) operatively connected to the CAN bus. The ECU is programmed to classify a message read from the CAN bus as either normal or anomalous using an SVM-based classifier with a Radial Basis Function (RBF) kernel. The classifying includes computing a hyperplane curvature parameter γ of the RBF kernel as γ=f(D) where f( ) denotes a function and D denotes CAN bus message density as a function of time. In some such embodiments γ=f(Var(D)) where Var(D) denotes the variance of the CAN bus message density as a function of time. The security monitoring system may be installed in a vehicle (e.g. automobile, truck, watercraft, aircraft) including a vehicle CAN bus, with the ECU operatively connected to the vehicle CAN bus to read messages communicated on the CAN bus. By not relying on any proprietary knowledge of arbitration IDs from manufacturers through their dbc files, this anomaly detector truly functions as a zero knowledge detector.
机译:控制器局域网(CAN)的安全监视系统包括可操作地连接到CAN总线的电子控制单元(ECU)。 ECU被编程为使用带有径向基函数(RBF)内核的基于SVM的分类器,将从CAN总线读取的消息分类为正常还是异常。分类包括将RBF内核的超平面曲率参数γ计算为γ= f(D),其中f()表示函数,D表示CAN总线消息密度随时间的变化。在一些这样的实施例中,γ= f(Var(D)),其中Var(D)表示CAN总线消息密度随时间的变化。安全监视系统可以安装在包括车辆CAN总线的车辆(例如,汽车,卡车,船只,飞机)中,并且ECU可操作地连接到车辆CAN总线以读取在CAN总线上传送的消息。通过不依赖制造商通过其dbc文件提供的仲裁ID的专有知识,该异常检测器真正可以充当零知识检测器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号