信息网络安全 ›› 2025, Vol. 25 ›› Issue (8): 1175-1195.doi: 10.3969/j.issn.1671-1122.2025.08.001

• 理论研究 • 上一篇    下一篇

车载以太网环境下CAN总线入侵检测系统兼容性评估与优化

曹越1, 方泊璎1(), 魏高达1, 李金宇1, 杨洋2, 彭涛3,4   

  1. 1.武汉大学国家网络安全学院,武汉 430040
    2.武汉云驰未来科技有限公司,武汉 430056
    3.大唐互联科技(武汉)有限公司,武汉 430056
    4.工业互联网集成技术湖北省工程研究中心,武汉 430056
  • 收稿日期:2025-03-19 出版日期:2025-08-10 发布日期:2025-09-09
  • 通讯作者: 方泊璎 E-mail:2022302181172@whu.edu.cn
  • 作者简介:曹越(1984—),男,湖北,教授,博士,CCF会员,主要研究方向为智能交通系统、车联网安全|方泊璎(2004—),女,湖北,本科,主要研究方向为车联网异常行为检测|魏高达(2002—),男,河南,硕士研究生,主要研究方向为车联网异常行为检测|李金宇(2003—),男,湖北,本科,主要研究方向为车联网异常行为检测|杨洋(1976—),女,湖北,高级工程师,硕士,主要研究方向为车联网安全|彭涛(1979—),男,湖北,高级工程师,博士,主要研究方向为智能制造、工业互联网
  • 基金资助:
    国家重点研发计划(2024YFB3108400);湖北省技术创新计划重大科技项目(2024BAA011);武汉市人工智能创新专项(2023010402040020)

Compatibility Evaluation and Optimization of CAN Bus Intrusion Detection Systems in In-Vehicle Ethernet Environment

CAO Yue1, FANG Boying1(), WEI Gaoda1, LI Jinyu1, YANG Yang2, PENG Tao3,4   

  1. 1. School of Cyber Science and Engineering, Wuhan University, Wuhan 430040, China
    2. Wuhan INCHTEK Technology Co., Ltd., Wuhan 430056, China
    3. Datang Interconnect Technology (Wuhan) Co., Ltd., Wuhan 430056, China
    4. Hubei Provincial Engineering Research Center for Industrial Internet Integration Technology, Wuhan 430056, China
  • Received:2025-03-19 Online:2025-08-10 Published:2025-09-09

摘要:

智能网联汽车的快速发展推动车载网络架构从传统CAN总线向高带宽、强拓展性的以太网转型。针对CAN总线入侵检测系统在车载以太网环境下的兼容性进行评估,既能有效利用现有安全资源、降低系统设计成本,又能为智能网联汽车安全架构顺利演进提供系统性解决方案。然而,由于CAN总线与车载以太网在通信特性、协议栈架构和数据传输机制等方面存在显著差异,如何实现安全资源的有效转化成为关键问题。为此,文章从跨协议适应性、检测方法兼容性、处理能力和扩展性4个维度,系统分析了现有CAN总线入侵检测系统的以太网兼容性,并提出多层级协议适配、检测方法改进、实时性与资源分配优化以及架构扩展性增强等优化策略。

关键词: 智能网联汽车, CAN总线, 以太网, 入侵检测系统, 兼容性

Abstract:

The rapid development of intelligent connected vehicles has driven the evolution of in-vehicle network architectures from traditional CAN bus to Ethernet with higher bandwidth and stronger scalability. By evaluating the compatibility of the CAN bus intrusion detection system in the in-vehicle Ethernet environment, it is possible to maximize the utilization of existing security resources, providing a systematic solution for the evolution of the security architecture of intelligent connected vehicles while reducing system design costs. However, there are significant differences between CAN bus and in-vehicle Ethernet in terms of communication characteristics, protocol stacks, and data transmission mechanisms. To address the issue of security resource transformation, this paper comprehensively analyzed the Ethernet compatibility of existing CAN intrusion detection systems from four dimensions, including protocol adaptability, detection method compatibility, processing capacity, and expandability. Moreover, optimization strategies such as multi-level protocol adaptation, detection method improvement, real-time performance and resource optimization, and enhanced architecture expandability were proposed.

Key words: intelligent connected vehicles, CAN bus, Ethernet, intrusion detection system, compatibility

中图分类号: