基于CAN网络的防火墙能否防范内网攻击?其防护范围如何?
Great question—this is a common point of confusion because CAN bus firewalls work a bit differently than the IP firewalls most folks are used to. Let’s break it down based on how these firewalls are designed and deployed:
1. Basic CAN Firewalls: Focused on Segment Isolation
Most entry-level CAN firewalls are built to isolate distinct CAN segments (e.g., powertrain CAN vs. infotainment CAN). Their core job is to filter traffic that crosses between these segments, not monitor traffic within a single segment.
- If an attacker compromises an ECU within a segment and sends malicious broadcast packets to other nodes in the same segment, this traffic never passes through the firewall—so the firewall can’t block it.
- These firewalls only stop attacks that originate from a different segment (e.g., an infotainment ECU trying to send unauthorized commands to the powertrain CAN).
2. Advanced CAN Firewalls: Internal Attack Mitigation
Higher-end CAN firewalls (often called "intelligent CAN firewalls") are designed with features that let them monitor and enforce rules within a single segment, acting more like a host-based firewall for the entire bus:
- Node Whitelisting: They can restrict which ECUs are allowed to send specific message IDs. If a compromised ECU starts sending messages it’s not authorized to transmit, the firewall drops those packets immediately.
- Message Validation: They check message content, frequency, and timing against predefined rules. For example, if an ECU suddenly sends brake command messages 10x faster than normal, the firewall flags and blocks that traffic.
- Signature-Based Detection: Some even support verifying message signatures to ensure only legitimate, unmodified messages are allowed on the bus—stopping tampered or forged messages from internal nodes.
Key Takeaway
It all depends on the firewall’s capabilities:
- Basic models only block cross-segment attacks, leaving internal segment traffic unfiltered.
- Advanced models can actively monitor and block malicious behavior from within the same CAN network, similar to how a host firewall protects individual devices.
内容的提问来源于stack exchange,提问作者ThatCrazyCow

