Change Point Models for Real-Time Cyber Attack Detection in Connected Vehicle Environment

Change Point Models for Real-Time Cyber Attack Detection in Connected Vehicle Environment
复制标题

DOI:
10.1109/tits.2021.3113675
复制
发表时间:
2020-03
影响因子:
8.5
通讯作者:
G. Comert;Mizanur Rahman;Mhafuzul Islam;M. Chowdhury
G. Comert;Mizanur Rahman;Mhafuzul Islam;M. Chowdhury
中科院分区:
工程技术1区
文献类型:
--
作者:
G. Comert;Mizanur Rahman;Mhafuzul Islam;M. Chowdhury

文献摘要

相似文献

互联车辆(CV)系统受到潜在的网络攻击,因为其不同组件(如车辆、路边基础设施和交通管理中心)之间的连接性不断增加。然而,由于这种攻击的动态行为、高计算能力要求以及用于训练检测模型的历史数据要求,因此实时检测安全威胁并为CV系统开发适当或有效的对策是一个挑战。为了应对这些挑战,统计模型,特别是变点模型,具有实时异常检测的潜力。因此,本研究的目的是研究两种变点模型的有效性;期望最大化(EM)和两种形式的累积求和(Cumulative Summation,CUM)算法(即,典型且自适应),用于CV环境中的实时车辆到基础设施(V2 I)网络攻击检测。为了证明这些模型的有效性,我们评估了这两种模型的三种不同类型的网络攻击,拒绝服务(DOS),冒充,和虚假信息,通过模拟从CV生成的基本安全消息(BSM)。数值分析的结果表明,EM、ADMUM和自适应ADMUM(aDMUM)可以检测到这些网络攻击,如DOS、冒充和误报率较低的虚假信息。
Connected vehicle (CV) systems are subject to potential cyber attacks because of increasing connectivity between its different components, such as vehicles, roadside infrastructure, and traffic management centers. However, it is a challenge to detect security threats in real-time and develop appropriate or effective countermeasures for a CV system because of the dynamic behavior of such attacks, high computational power requirement, and a historical data requirement for training detection models. To address these challenges, statistical models, especially change point models, have potentials for real-time anomaly detection. Thus, the objective of this study is to investigate the efficacy of two change point models; Expectation Maximization (EM) and two forms of Cumulative Summation (CUSUM) algorithms (i.e., typical and adaptive), for real-time vehicle-to-infrastructure (V2I) cyber attack detection in a CV Environment. To prove the efficacy of these models, we evaluated these two models for three different types of cyber attack, denial of service (DOS), impersonation, and false information, using basic safety messages (BSMs) generated from CVs through simulation. Results from numerical analysis revealed that EM, CUSUM, and adaptive CUSUM (aCUSUM) could detect these cyberattacks, such as DOS, impersonation, and false information with low false positives.