Detecting CAN Bus Intrusion by Applying Machine Learning Method to Graph Based Features

Detecting CAN Bus Intrusion by Applying Machine Learning Method to Graph Based Features
复制标题

将机器学习方法应用于基于图的特征检测 CAN 总线入侵

DOI:
10.1007/978-3-030-82199-9_49
复制
发表时间:
2021
期刊:
Proceedings of SAI Intelligent Systems Conference
影响因子:
--
通讯作者:
Malik, H.
Malik, H.
中科院分区:
--
文献类型:
--
作者:
Refat, R.U.D.;Elkhail, A.A.;Hafeez, A.;Malik, H.

文献摘要

参考文献

被引文献

相似文献

现代车辆通过无线接口与外界相连,因此被认为是易受攻击的系统。虽然互联互通为乘客提供了更多的便利和功能,但它也成为攻击者攻击车载网络的途径。随着现代车辆与外界的联系日益紧密,车内攻击对人类生命安全的影响越来越大,对车辆安全的研究日益受到重视。控制器局域网(Controller area network, CAN)是一种传统的车载通信协议,但由于缺乏身份验证,CAN报文中缺少发送方信息,存在漏洞。本文提出了一种新的CAN入侵检测系统(IDS),该系统将CAN消息转换为时间图,并使用机器学习算法检测CAN入侵。利用支持向量机(SVM)和k近邻(KNN)两种机器学习算法,提取了七个基于图的属性,并将其用作检测入侵的特征。通过对真实车辆CAN总线数据集的拒绝服务攻击、模糊攻击和欺骗攻击三种CAN总线攻击对IDS的性能进行了评估。实验结果表明,使用基于图的特征,使用SVM和KNN算法分别达到97.92%和97.99%的准确率,优于使用传统的机器学习CAN总线特征。
Modern vehicle is considered as a system vulnerable to attacks because it is connected to the outside world via a wireless interface. Although, connectivity provides more convenience and features to the passengers, however, it also becomes a pathway for the attackers targeting in-vehicle networks. Research in vehicle security is getting attention as in-vehicle attacks can impact human life safety as modern vehicle is connected to the outside world. Controller area network (CAN) is used as a legacy protocol for in-vehicle communication, However, CAN suffers from vulnerabilities due to lack of authentication, as the information about sender is missing in CAN message. In this paper, a new CAN intrusion detection system (IDS) is proposed, the CAN messages are converted to temporal graphs and CAN intrusion is detected using machine learning algorithms. Seven graph-based properties are extracted and used as features for detecting intrusions utilizing two machine learning algorithms which are support vector machine (SVM) & k-nearest neighbors (KNN). The performance of the IDS was evaluated over three CAN bus attacks are denial of service (DoS), fuzzy & spoofing attacks on real vehicular CAN bus dataset. The experimental results showed that using graph-based features, an accuracy of 97.92% & 97.99% was achieved using SVM & KNN algorithms respectively, which is better than using traditional machine learning CAN bus features.
基于机器学习的控制器局域网入侵检测系统
DOI: --
发表时间: 2020
期刊: Design and Analysis of Intelligent Vehicular Networks and Applications
影响因子: --
作者:
Omar Minawi;Jason Whelan;Abdulaziz Almehmadi;K. El
通讯作者: K. El
使用 CAN 协议实现基于网络的分布式系统
DOI: 10.1007/11552413_157
发表时间: 2005
影响因子: 2.4
作者:
Joonhong Jung;Kiheon Park;J. Cha
通讯作者: J. Cha
DOI: 10.4271/2020-01-0721
发表时间: 2020
期刊: ArXiv
影响因子: --
作者:
Azeem Hafeez;K. Rehman;Hafiz Malik
通讯作者: Hafiz Malik
利用通道失真进行发射机识别以实现车载网络安全
DOI: 10.4271/11-02-02-0005
发表时间: 2020
期刊: Future Internet
影响因子: 3.4
作者:
Azeem Hafeez;Sai Charan Ponnapali;Hafiz Malik
通讯作者: Hafiz Malik
直径、半径和(几乎)Helly 属性的故事
DOI: 10.1002/net.21998
发表时间: 2020
期刊: Networks
影响因子: 2.1
作者:
G. Ducoffe;F. Dragan
通讯作者: F. Dragan