Traffic anomaly detection algorithm for CAN bus using similarity analysis

被引:2
|
作者
Wang, Chao [1 ]
Xu, Xueqiao [1 ]
Xiao, Ke [1 ]
He, Yunhua [1 ]
Yang, Guangcan [1 ]
机构
[1] North China Univ Technol, Sch Informat Sci & Technol, Beijing 100144, Peoples R China
来源
HIGH-CONFIDENCE COMPUTING | 2024年 / 4卷 / 03期
关键词
Automotive safety; CAN bus; Anomaly detection; INTRUSION DETECTION;
D O I
10.1016/j.hcc.2024.100207
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, vehicles have experienced a rise in networking and informatization, leading to increased security concerns. As the most widely used automotive bus network, the Controller Area Network (CAN) bus is vulnerable to attacks, as security was not considered in its original design. This paper proposes SIDuBzip2, a traffic anomaly detection method for the CAN bus based on the bzip2 compression algorithm. The proposed method utilizes the pseudo-periodic characteristics of CAN bus traffic, constructing time series of CAN IDs and calculating the similarity between adjacent time series to identify abnormal traffic. The method consists of three parts: the conversion of CAN ID values to characters, the calculation of similarity based on bzip2 compression, and the optimal solution of model parameters. The experimental results demonstrate that the proposed SIDuBzip2 method effectively detects various attacks, including Denial of Service , replay, basic injection, mixed injection, and suppression attacks. In addition, existing CAN bus traffic anomaly detection methods are compared with the proposed method in terms of performance and delay, demonstrating the feasibility of the proposed method. (c) 2024 The Author(s). Published by Elsevier B.V. on behalf of Shandong University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:11
相关论文
共 50 条
  • [1] Cosine similarity based anomaly detection methodology for the CAN bus
    Kwak, Byung Il
    Han, Mee Lan
    Kim, Huy Kang
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 166
  • [2] Network Traffic Anomaly Detection in CAN Bus Based on Ensemble Learning
    Wu, Yuxi
    Tao, Xiaodong
    2024 4TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND INTELLIGENT SYSTEMS ENGINEERING, MLISE 2024, 2024, : 240 - 245
  • [3] Analysis of ID Sequences Similarity Using DTW in Intrusion Detection for CAN Bus
    Sun, Heng
    Sun, Mengsi
    Weng, Jian
    Liu, Zhiquan
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2022, 71 (10) : 10426 - 10441
  • [4] Anomaly Detection in Vehicular CAN Bus Using Message Identifier Sequences
    Donmez, Tahsin C. M.
    IEEE ACCESS, 2021, 9 : 136243 - 136252
  • [5] Anomaly detection of CAN bus messages through analysis of ID sequences
    Marchetti, Mirco
    Stabili, Dario
    2017 28TH IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV 2017), 2017, : 1577 - 1583
  • [6] Network traffic anomaly detection algorithm using mahout classifier
    Peng, Hua
    Liu, Liang
    Liu, Jiayong
    Lewis, Johnwb R.
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2019, 37 (01) : 137 - 144
  • [7] Network Traffic Anomaly Detection Based on Self-similarity Using FRFT
    Ye, Xiaolong
    Lan, Julong
    Huang, Wanwei
    PROCEEDINGS OF 2013 IEEE 4TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING AND SERVICE SCIENCE (ICSESS), 2012, : 837 - 840
  • [8] Bus Headways Analysis for Anomaly Detection
    Jarabo-Penas, Alejandro
    Zufiria, Pedro J.
    Garcia-Maurino, Carlos
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2022, 23 (10) : 18975 - 18988
  • [9] Network Traffic Anomaly Detection Using Weighted Self-similarity Based on EMD
    Han, Jieying
    Zhang, James Z.
    2013 PROCEEDINGS OF IEEE SOUTHEASTCON, 2013,
  • [10] Research on network traffic anomaly detection algorithm
    Lv, Jun
    Li, Tong
    Li, Xing
    2007 IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS, VOLS 1-3, 2007, : 1097 - 1102