SAIDuCANT: Specification-Based Automotive Intrusion Detection Using Controller Area Network (CAN) Timing

SAIDuCANT: Specification-Based Automotive Intrusion Detection Using Controller Area Network (CAN) Timing
复制标题

DOI:
10.1109/tvt.2019.2961344
复制
发表时间:
2020-02-01
影响因子:
6.8
通讯作者:
Bloom, Gedare
Bloom, Gedare
中科院分区:
计算机科学2区
文献类型:
--
作者:
Olufowobi, Habeeb;Young, Clinton;Bloom, Gedare

文献摘要

被引文献

相似文献

现代车辆中嵌入式设备的激增,使得传统上封闭的车辆系统面临着网络安全攻击的风险,这些攻击通过物理和远程访问车载网络(如控制器局域网(CAN))进行。CAN总线没有实现可以保护车辆免受日益增加的网络和物理攻击的安全协议。为了解决这一风险,我们引入了一种新的算法来提取CAN总线的实时模型参数,并开发了SAIDuCANT,这是一种基于规范的入侵检测系统(IDS),使用基于异常的监督学习,将实时模型作为输入。我们使用从两辆乘用车收集的真实CAN日志和从真实场景收集的开源CAN数据集来评估SAIDuCANT的有效性。实验结果表明,SAIDuCANT能够有效检测数据注入攻击,且误报率低。在来自开源数据集的四个真实攻击场景中,SAIDuCANT在检测到攻击之前最多观察到一个误报,而其他使用CAN定时特征的检测方法在真正的攻击发生之前平均检测到100多个误报。
The proliferation of embedded devices in modern vehicles has opened the traditionally-closed vehicular system to the risk of cybersecurity attacks through physical and remote access to the in-vehicle network such as the controller area network (CAN). The CAN bus does not implement a security protocol that can protect the vehicle against the increasing cyber and physical attacks. To address this risk, we introduce a novel algorithm to extract the real-time model parameters of the CAN bus and develop SAIDuCANT, a specification-based intrusion detection system (IDS) using anomaly-based supervised learning with the real-time model as input. We evaluate the effectiveness of SAIDuCANT with real CAN logs collected from two passenger cars and on an open-source CAN dataset collected from real-world scenarios. Experimental results show that SAIDuCANT can effectively detect data injection attacks with low false positive rates. Over four real attack scenarios from the open-source dataset, SAIDuCANT observes at most one false positive before detecting an attack whereas other detection approaches using CAN timing features detect on average more than a hundred false positives before a real attack occurs.