Side-Channel Security Analysis of Connected Vehicle Communications Using Hidden Markov Models

Side-Channel Security Analysis of Connected Vehicle Communications Using Hidden Markov Models
复制标题

DOI:
10.1109/tits.2022.3164779
复制
发表时间:
2022-10
影响因子:
8.5
通讯作者:
Fei Sun;R. Brooks;G. Comert;Nathan Tusing
Fei Sun;R. Brooks;G. Comert;Nathan Tusing
中科院分区:
工程技术1区
文献类型:
--
作者:
Fei Sun;R. Brooks;G. Comert;Nathan Tusing

文献摘要

相似文献

本文研究了一个交通路口应用程序的车载无线通信应用程序(DSRC/WAVE)协议实现的侧信道漏洞。利用实际的动态随机序列控制装置实现了一个路侧单元的原型。WAVE短消息(WSM)信道的功能被扩展以包括用于在车辆通信中广播GPS数据和RSU指令的WAVE短消息协议(WSMP)的实现。在所用的示例中,使用了DSRC来替换十字路口的红绿灯。拒绝服务攻击是利用DSRC RSU计时和数据包大小旁通道选择性地禁用信号灯来执行的。通过模拟来确定我们是否有能力偷偷地丢弃数据包,从而迫使两辆车相撞。利用嗅探到的侧信道信息构造隐马尔可夫模型(HMM)和支持向量机(SVM)。我们使用分组间延迟时间和分组大小侧信道信息来设计我们的攻击。在运行中的网络中,应对数据包进行加密以隐藏数据包有效负载的内容,但数据包大小和计时不受加密的影响。仅使用侧通道信息来推断HMM。推断的HMM随时间跟踪协议状态。使用侧信道数据和分组有效载荷来推断支持向量机分类器。然而,在运行时,支持向量机只能访问旁路信息。进行了仿真实验,测试了HMM和支持向量机识别用于信号车辆停车和让路的报文的能力。定时隐马尔可夫模型边信道攻击导致冲突,误检率为2.5%,而分组大小攻击导致的误检率为9.5%。
This paper investigates side-channel vulnerabilities of a wireless communication application in vehicular environments (DSRC/WAVE) protocol implementation of a traffic intersection application. A prototype roadside unit (RSU) was implemented using real DSRC devices. The functionality of the WAVE short message (Wsm)-channel is extended to include an implementation of WAVE short message protocol (WSMP) for broadcasting GPS data and RSU instructions in vehicular communications. In the example used, DSRC is used to replace an intersection stoplight. Denial of service attacks are executed that leverage DSRC RSU timing and packet size side-channels to selectively disable the stoplight. Simulations are implemented to determine our ability to stealthily drop packets so as to force two vehicles to collide. Hidden Markov models (HMM) and Support Vector Machines (SVM) are constructed from sniffed side-channel information. We use inter-packet delay time and packet size side-channel information to design our attackes. In operational networks, packets should be encrypted in order to hide the contents of the packet payloads, but packet sizes and timing are not affected by encryption. HMMs were inferred using only side-channel information. The inferred HMMs track the protocol status over time. The SVM classifier was inferred using both side-channel data and packet payloads. At run-time, though, the SVM only had access to side-channel information. Simulation experiments were implemented to test HMM and SVM ability to identify packets used to signal vehicles to stop and yield right-of-way. Timing HMM side-channel attack caused collision with 2.5% false positive rate (FPR), while the packet size one resulted 9.5% FPR.