Modern vehicles rely on a myriad of electronic control units (ECUs)
interconnected via controller area networks (CANs) for critical operations.
Despite their ubiquitous use and reliability, CANs are susceptible to
sophisticated cyberattacks, particularly masquerade attacks, which inject false
data that mimic legitimate messages at the expected frequency. These attacks
pose severe risks such as unintended acceleration, brake deactivation, and
rogue steering. Traditional intrusion detection systems (IDS) often struggle to
detect these subtle intrusions due to their seamless integration into normal
traffic. This paper introduces a novel framework for detecting masquerade
attacks in the CAN bus using graph machine learning (ML). We hypothesize that
the integration of shallow graph embeddings with time series features derived
from CAN frames enhances the detection of masquerade attacks. We show that by
representing CAN bus frames as message sequence graphs (MSGs) and enriching
each node with contextual statistical attributes from time series, we can
enhance detection capabilities across various attack patterns compared to using
only graph-based features. Our method ensures a comprehensive and dynamic
analysis of CAN frame interactions, improving robustness and efficiency.
Extensive experiments on the ROAD dataset validate the effectiveness of our
approach, demonstrating statistically significant improvements in the detection
rates of masquerade attacks compared to a baseline that uses only graph-based
features, as confirmed by Mann-Whitney U and Kolmogorov-Smirnov tests (p <
0.05).
外部データセット
ROAD
参考文献
Proc. 21st Int. Conf. Distrib. Comput. Netw.
Coids: A clock offset based intrusion detection system for controller area networks
S. Halder, M. Conti, S. K. Das
Published: 2020
IEEE Trans. Inf. Forensics Secur.
An efficient authentication scheme for intra-vehicular controller area network
B. Palaniswamy, S. A. Camtepe, E. Foo, J. Pieprzyk
Published: 2020
Proc. Symp. Veh. Secur. Privacy (VehicleSec)
Cantropy: Time series feature extraction-based intrusion detection systems for controller area networks
M. H. Shahriar, W. Lou, Y. T. Hou
Published: 2023
ACM Symposium on Applied Computing
CANTransfer: Transfer learning based intrusion detection on a controller area network using convolutional LSTM network
S. Tariq, S. Lee, S. S. Woo
Published: 2020
Sensors
Cansec: A practical in-vehicle controller area network security evaluation tool
H. Zhang, X. Meng, X. Zhang, Z. Liu
Published: 2020
IEEE Trans. Ind. Inf.
Tce-ids: Time interval conditional entropy-based intrusion detection system for automotive controller area networks
Z. Yu, Y. Liu, G. Xie, R. Li, S. Liu, L. T. Yang
Published: 2022
Black Hat USA
Remote exploitation of an unaltered passenger vehicle
C. Miller, C. Valasek
Published: 2015
Proc. 2023 12th Int. Conf. Softw. Comput. Appl.
Comparative evaluation of anomaly-based controller area network ids
S. Sharmin, H. Mansor, A. F. A. Kadir, N. A. Aziz
Published: 2023
Cybersecurity
Intrusion detection system for controller area network
V. Tanksale
Published: 2024
IEEE Trans. Transp. Electr.
Cy-phy ads: Cyber physical anomaly detection framework for ev charging systems
H. S. Mavikumbure, V. Cobilean, C. S. Wickramasinghe, B. J. Varghese, B. Carlson, C. Rieger, M. Manic
Published: 2024
Electronics
A review of anomaly detection strategies to detect threats to cyber-physical systems
Nicholas Jeffrey, Qing Tan, José R Villar
Published: 2023
Proc. 2022 17th Annu. Syst. Syst. Eng. Conf. (SOSE)
Condition monitoring and anomaly detection in cyber-physical systems
W. Marfo, D. K. Tosh, S. V. Moore
Published: 2022
IEEE Trans. Inf. Forensics Secur.
Intrusion device detection in fieldbus networks based on channel-state group fingerprint
X. Wang, Y. Liu, K. Jiao, P. Liu, X. Luo, T. Liu
Published: 2024
Appl. Intell.
Robust anomaly-based intrusion detection system for in-vehicle network by graph neural network framework
J. Xiao, L. Yang, F. Zhong, H. Chen, X. Li
Published: 2023
PLoS One
A comprehensive guide to can ids data and introduction of the road dataset
M. E. Verma, R. A. Bridges, M. D. Iannacone, S. C. Hollifield, P. Moriano, S. C. Hespeler
Published: 2024
Proc. IEEE Int. Conf. Fuzzy Syst. (FUZZ-IEEE)
Car hacking identification through fuzzy logic algorithms
F. Martinelli, F. Mercaldo, V. Nardone, A. Santone
Published: 2017
IEEE Trans. Veh. Technol.
Vadgan: An unsupervised gan framework for enhanced anomaly detection in connected and autonomous vehicles
S. Devika, R. R. Shrivastava, P. Narang, T. Alladi, F. R. Yu
Published: 2024
IEEE Trans. Veh. Technol.
Anomaly detection for in-vehicle network using cnn-lstm with attention mechanism
H. Sun, M. Chen, J. Weng, Z. Liu, G. Geng
Published: 2021
IEEE Trans. Ind. Appl.
Retracted: An evolutionary deep learning anomaly detection framework for in-vehicle networks-can bus
Y. Lin, C. Chen, F. Xiao, O. Avatefipour, K. Alsubhi, A. Yunianta
Published: 2020
IEEE Trans. Intell. Transp. Syst.
A survey of attacks on controller area networks and corresponding countermeasures
H. J. Jo, W. Choi
Published: 2021
IEEE Trans. Inf. Forensics Secur.
Detection of message injection attacks onto the can bus using similarities of successive messages-sequence graphs