SYSTEM AND METHOD FOR DETECTION AND PREVENTION OF ATTACKS ON IN-VEHICLE NETWORKS

    公开(公告)号:US20200067958A1

    公开(公告)日:2020-02-27

    申请号:US16666445

    申请日:2019-10-29

    Abstract: Systems and methods for detection of attacks on a communication authentication layer of an in-vehicle network, including determining, by at least one network node, at least one attack attempt on the communication authentication layer of the in-vehicle network, wherein the determination is carried out by identifying anomalies in at least one of messages, data and metadata directed to the communication authentication layer, and selecting, by the at least one network node, a response corresponding to the determined attack attempt from at least one of modification of parameter values corresponding to a security protocol, a failsafe response, and rejection of messages identified as anomalies.

    GLOBAL AUTOMOTIVE SAFETY SYSTEM
    4.
    发明申请
    GLOBAL AUTOMOTIVE SAFETY SYSTEM 有权
    全球汽车安全系统

    公开(公告)号:US20150195297A1

    公开(公告)日:2015-07-09

    申请号:US14590022

    申请日:2015-01-06

    Abstract: A system for providing security to an in-vehicle communication network, the system comprising: a data monitoring and processing hub; and at least one module configured to monitor messages in communication traffic propagating in a vehicle's in-vehicle network, the network having a bus and at least one node connected to the bus, the module comprising: a communication interface configured to support communication with the hub; a memory having software comprising data characterizing messages that the at least one node transmits and receives during normal operation of the node; at least one communication port via which the module receives and transmits messages configured to be connected to a portion of the in-vehicle network; a processor that processes messages received via the port from the portion of the in-vehicle network responsive to the software in the memory to: identify an anomalous message in the received messages indicative of exposure of the in-vehicle network to damage from a cyber attack; determine an action to be taken by the module that affects the anomalous message; and transmit data responsive to the anomalous message to the hub for processing by the hub via the communication interface.

    Abstract translation: 一种用于向车载通信网络提供安全性的系统,所述系统包括:数据监控和处理集线器; 以及至少一个模块,被配置为监视在车辆车载网络中传播的通信业务中的消息,所述网络具有总线和连接到所述总线的至少一个节点,所述模块包括:通信接口,被配置为支持与所述集线器的通信 ; 具有软件的存储器,所述软件包括表征所述至少一个节点在所述节点的正常操作期间发送和接收的消息的数据; 至少一个通信端口,所述模块经由所述至少一个通信端口接收并发送被配置为连接到所述车载网络的一部分的消息; 响应于存储器中的软件,处理经由端口从车载网络的部分接收的消息的处理器,以识别接收到的消息中的异常消息,指示车载网络暴露于网络攻击造成的损坏 ; 确定模块将采取的影响异常消息的动作; 并且响应于所述异常消息将数据发送到所述集线器,以经由所述通信接口由所述集线器进行处理。

    BUS WATCHMAN
    7.
    发明申请

    公开(公告)号:US20150191135A1

    公开(公告)日:2015-07-09

    申请号:US14590027

    申请日:2015-01-06

    Abstract: A module for providing security to an in-vehicle communication network having a bus and at least one node connected to the bus, the module comprising: a memory having software comprising data characterizing messages that the at least one node transmits and receives via the bus during normal operation of the node; a communication port via which the module receives and transmits messages configured to be connected to a portion of the in-vehicle network; and a processor that processes messages received via the port from the portion of the in-vehicle network responsive to the software in the memory to: identify an anomalous message in the received messages indicative of exposure of the in-vehicle network to damage from a cyber attack; and cause the module to transmit at least one signal via the port to the portion of the in-vehicle network that alters the anomalous message so that the at least one node will discard it.

    Abstract translation: 一种用于向具有总线和连接到总线的至少一个节点的车载通信网络提供安全性的模块,所述模块包括:具有软件的存储器,所述软件包括表征所述至少一个节点经由所述总线在所述总线期间发送和接收的消息的数据 节点正常运行; 通信端口,所述模块经由所述通信端口接收并发送被配置为连接到所述车载网络的一部分的消息; 以及处理器,其响应于所述存储器中的软件来处理经由所述端口从所述端口接收的消息,以便:识别所接收的消息中的异常消息,其指示所述车载网络暴露于来自网络的损坏 攻击; 并且使得所述模块经由所述端口将至少一个信号发送到所述车载网络中改变所述异常消息的部分,使得所述至少一个节点将其丢弃。

    OBD PORT ACCESS CONTROL
    8.
    发明申请

    公开(公告)号:US20180015888A1

    公开(公告)日:2018-01-18

    申请号:US15717980

    申请日:2017-09-28

    Abstract: A module for providing security to an in-vehicle communication network having a bus and at least one node connected to the bus, the module comprising: a memory having software comprising data characterizing messages that the at least one node transmits to and/or receives via the bus; a communication port via which the module receives and transmits messages configured to be connected to a portion of the in-vehicle network; and a processor that is operable to: processes messages received via the port responsive to the software in the memory to control passage of messages through an on-board diagnostics (OBD) port between the in-vehicle network and an entity external to the vehicle.

    BUS WATCHMAN
    10.
    发明申请
    BUS WATCHMAN 审中-公开

    公开(公告)号:US20170259761A1

    公开(公告)日:2017-09-14

    申请号:US15607760

    申请日:2017-05-30

    Abstract: A cyber security module for providing security to an in-vehicle communication network having a bus, at least one node connected to the bus, and at least one communications device coupled to the in-vehicle communication network configured to interface the in-vehicle network with an external communication network, the cyber security module comprising: a communication port configured to receive a message from the communication device that the communication device generates based on a message that the communication device receives from the external communication network; at least one communication port coupled to the bus; an authentication module configured to authenticate whether or not the message originated from an authorized source; and a processor configured to operate to prevent content of the message from being operated on if the authentication module determines that the source of the message received by the communication device is not from an authorized source.

Patent Agency Ranking