Towards Resiliency of Heavy Vehicles through Compromised Sensor Data Reconstruction

Towards Resiliency of Heavy Vehicles through Compromised Sensor Data Reconstruction
复制标题

DOI:
10.1145/3508398.3511523
复制
发表时间:
2022-04
期刊:
Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
H. Shirazi;W. Pickard;I. Ray;Haonan Wang
H. Shirazi;W. Pickard;I. Ray;Haonan Wang
中科院分区:
其他
文献类型:
--
作者:
H. Shirazi;W. Pickard;I. Ray;Haonan Wang

文献摘要

相似文献

现代汽车的几乎所有方面都由嵌入式计算机控制,称为电子控制单元(ECU)。ECU通过控制器局域网(CAN)网络相互连接。ECU相互通信并使用消息控制汽车的行为。与乘用汽车不同,重型车辆使用由不同原始设备制造商(OEM)制造的ECU构造。出于互操作性的原因,汽车工程师协会(SAE)要求所有ECU都应使用标准化的SAE-J1939协议进行通信,该协议为CAN网络上传输的信号提供了语义。在协议和标准中,安全问题历来被忽视。因此,具有恶意代码的ECU可以欺骗其他ECU,例如,消息可以通过OBD-II端口或远程信息处理单元注入内部网络以干扰车辆的行为。入侵检测系统(IDS)已被提出并用于检测各种类型的安全攻击。然而,这样的系统只能检测攻击,而不能减轻攻击。受损的ECU可能会生成无效数据值;即使检测到此类无效值,仍需要消除其影响。几乎所有先前的工作都集中在检测攻击上。我们展示了如何使车辆对攻击具有弹性。我们分析了真实的驾驶场景的日志文件,并显示ECU在很大程度上依赖于其他ECU来运行。我们证明了受损ECU的参数可以从其他未受损ECU的参数中重建,以允许车辆继续运行并使其能够抵御攻击。我们通过使用多变量长短期记忆(LSTM)神经网络对ECU的行为进行建模来实现这一点。然后,我们使用从可信ECU获得的信息重建受损ECU值。尽管存在一定程度的错误,但我们的模型可以重建可信赖的数据值,这些值可以替代受损ECU生成的值。重建值与正确值之间的误差小于受损ECU的工作范围的6%,这是非常低的,可以替代。我们提出的方法使车辆具有弹性,而不需要改变内部架构。
Almost all aspects of modern automobiles are controlled by embedded computers, known as Electronic Control Units (ECUs). ECUs are connected with each other over a Controller Area Network (CAN) network. ECUs communicate with each other and control the automobile's behavior using messages. Heavy vehicles, unlike passenger cars, are constructed using ECUs manufactured by different Original Equipment Manufacturers (OEMs). For reasons of interoperability, the Society of Automotive Engineers (SAE) mandates that all ECUs should communicate using the standardized SAE-J1939 protocol that gives semantics to the signals transmitted on the CAN network. Security concerns have been historically ignored in protocols and standards. Consequently, an ECU having malicious code can spoof other ECUs, e.g., a message can be injected through the OBD-II port or the telematics unit into the internal network to interfere with the behavior of the vehicle. Intrusion Detection Systems (IDS) have been proposed and utilized to detect various types of security attacks. However, such systems are only capable of detecting attacks and cannot mitigate them. A compromised ECU may generate invalid data values; even if such invalid values are detected, there is still a need to counter their effects. Almost all prior works focus on detecting attacks. We demonstrate how to make the vehicle resilient to attacks. We analyze the log files of real driving scenarios and show ECUs are significantly dependent on other ECUs to operate. We demonstrate that parameters of a compromised ECU can be reconstructed from those of other non-compromised ECUs to allow the vehicle to continue operation and make it resilient to attacks. We achieve this by modeling the behavior of an ECU using the multivariate Long Short-Term Memory (LSTM) neural network. We then reconstruct compromised ECU values using information obtained from trustworthy ECUs. Despite some levels of errors, our model can reconstruct trustworthy data values that can be substituted for values generated by compromised ECUs. The error between the reconstructed values and the correct ones is less than 6% of the operating range for the compromised ECU, which is significantly low and can be substituted. Our proposed approach makes the vehicle resilient without requiring changes to the internal architecture.