Anomaly Detection Approach Using Adaptive Cumulative Sum Algorithm for Controller Area Network

Anomaly Detection Approach Using Adaptive Cumulative Sum Algorithm for Controller Area Network
复制标题

DOI:
10.1145/3309171.3309178
复制
发表时间:
2019-03
期刊:
Proceedings of the ACM Workshop on Automotive Cybersecurity
影响因子:
--
通讯作者:
Habeeb Olufowobi;Uchenna Ezeobi;Eric Muhati;Gaylon Robinson;C. Young;Joseph Zambreno;Gedare Bloom
Habeeb Olufowobi;Uchenna Ezeobi;Eric Muhati;Gaylon Robinson;C. Young;Joseph Zambreno;Gedare Bloom
中科院分区:
其他
文献类型:
--
作者:
Habeeb Olufowobi;Uchenna Ezeobi;Eric Muhati;Gaylon Robinson;C. Young;Joseph Zambreno;Gedare Bloom

文献摘要

被引文献

相似文献

现代汽车已经从一个纯粹的机械系统转变为一个嵌入了几个电子设备的系统。这些设备通过车载网络进行通信,以增强安全性和舒适性,但容易受到网络物理风险和攻击。检测这些攻击和异常事件的一种众所周知的技术是使用入侵检测系统。网络中的异常发生在未知点,并导致消息流的统计特征发生突变。提出了一种基于异常的入侵检测方法,该方法使用累积和(CUSUM)变点检测算法来检测控制器局域网(CAN)总线上的数据注入攻击。我们利用变点算法所需的参数来降低虚警率和检测延迟。使用汽车在正常运行时产生的真实数据集,对我们的检测方法在三种不同类型的攻击场景中进行了评估。
The modern vehicle has transformed from a purely mechanical system to a system that embeds several electronic devices. These devices communicate through the in-vehicle network for enhanced safety and comfort but are vulnerable to cyber-physical risks and attacks. A well-known technique of detecting these attacks and unusual events is by using intrusion detection systems. Anomalies in the network occur at unknown points and produce abrupt changes in the statistical features of the message stream. In this paper, we propose an anomaly-based intrusion detection approach using the cumulative sum (CUSUM) change-point detection algorithm to detect data injection attacks on the controller area network (CAN) bus. We leverage the parameters required for the change-point algorithm to reduce false alarm rate and detection delay. Using real dataset generated from a car in normal operation, we evaluate our detection approach on three different kinds of attack scenarios.