LSTM-Based Intrusion Detection System for VANETs: A Time Series Classification Approach to False Message Detection

LSTM-Based Intrusion Detection System for VANETs: A Time Series Classification Approach to False Message Detection
复制标题

基于 LSTM 的 VANET 入侵检测系统:错误消息检测的时间序列分类方法

DOI:
10.1109/tits.2022.3190432
复制
发表时间:
2022
影响因子:
8.5
通讯作者:
Jingxiao Ma
Jingxiao Ma
中科院分区:
工程技术1区
文献类型:
--
作者:
Yantao Yu;Xin Zeng;Xiaoping Xue;Jingxiao Ma

文献摘要

相似文献

在车载自组织网络(VANET)中,车辆广播紧急消息和信标消息,使驾驶员能够感知超出其视线范围的交通状况,从而提高驾驶安全。然而,内部攻击者可以通过在紧急消息中报告不存在的交通事件来出于私利目的发起虚假消息攻击。此外,一些串通攻击者可能会合作传播虚假信标消息,使虚假交通事件更具欺骗性。为了提高虚假紧急消息检测的准确率,提出了一种基于时间序列分类和深度学习的入侵检测系统。考虑到交通参数与时间高度相关,我们从交通事件报告附近的车辆消息中收集与交通事件密切相关的交通参数时间序列作为时间序列特征向量。为了更准确地识别交通参数随时间变化的模式,设计了一种基于长短期记忆(LSTM)的交通事件分类器,并使用来自正常攻击场景和合谋攻击场景的时间序列特征向量进行训练。基于分类结果,可以确定紧急消息的真实性。最后,通过大量的仿真对所提出的基于LSTM的入侵检测系统的性能进行了评估。仿真结果表明,与一些基于机器学习的入侵检测方法相比,本文提出的入侵检测系统具有更高的误报检测准确率。
In vehicular ad hoc networks (VANETs), vehicles broadcast emergency messages and beacon messages, which enable drivers to perceive traffic conditions beyond their visual range thus improve driving safety. However, internal attackers can launch a false message attack for selfish purposes by reporting a non-existent traffic incident in emergency messages. Moreover, some collusion attackers may spread bogus beacon messages cooperatively to make the bogus traffic incident more deceptive. To improve the accuracy of false emergency message detection, we propose a novel intrusion detection system (IDS) based on time series classification and deep learning. Considering that traffic parameters are highly correlated with time, we collect time series of traffic parameters closely related to traffic incidents from messages of vehicles near reported traffic incidents as time series feature vectors. To recognize the pattern of traffic parameters changing over time more accurately, a traffic incident classifier based on long short-term memory (LSTM) is designed and trained using time series feature vectors from both normal and collusion attack scenarios. Based on the classification result, the authenticity of the emergency message can be determined. Finally, we evaluate the performance of the proposed LSTM-based IDS through extensive simulation. Simulation results validate that our IDS is more accurate in false message detection compared with some well-known machine learning-based schemes.