Traffic anomaly detection algorithm for CAN bus using similarity analysis

被引:2
|
作者
Wang, Chao [1 ]
Xu, Xueqiao [1 ]
Xiao, Ke [1 ]
He, Yunhua [1 ]
Yang, Guangcan [1 ]
机构
[1] North China Univ Technol, Sch Informat Sci & Technol, Beijing 100144, Peoples R China
来源
HIGH-CONFIDENCE COMPUTING | 2024年 / 4卷 / 03期
关键词
Automotive safety; CAN bus; Anomaly detection; INTRUSION DETECTION;
D O I
10.1016/j.hcc.2024.100207
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, vehicles have experienced a rise in networking and informatization, leading to increased security concerns. As the most widely used automotive bus network, the Controller Area Network (CAN) bus is vulnerable to attacks, as security was not considered in its original design. This paper proposes SIDuBzip2, a traffic anomaly detection method for the CAN bus based on the bzip2 compression algorithm. The proposed method utilizes the pseudo-periodic characteristics of CAN bus traffic, constructing time series of CAN IDs and calculating the similarity between adjacent time series to identify abnormal traffic. The method consists of three parts: the conversion of CAN ID values to characters, the calculation of similarity based on bzip2 compression, and the optimal solution of model parameters. The experimental results demonstrate that the proposed SIDuBzip2 method effectively detects various attacks, including Denial of Service , replay, basic injection, mixed injection, and suppression attacks. In addition, existing CAN bus traffic anomaly detection methods are compared with the proposed method in terms of performance and delay, demonstrating the feasibility of the proposed method. (c) 2024 The Author(s). Published by Elsevier B.V. on behalf of Shandong University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Bit scanner: Anomaly detection for in-vehicle CAN bus using binary sequence whitelisting
    Zhang, Guiqi
    Liu, Qi
    Cao, Chenhong
    Li, Jiangtao
    Li, Yufeng
    COMPUTERS & SECURITY, 2023, 134
  • [22] Detecting Anomaly in Traffic Flow from Road Similarity Analysis
    Liu, Xinran
    Liu, Xingwu
    Wang, Yuanhong
    Pu, Juhua
    Zhang, Xiangliang
    WEB-AGE INFORMATION MANAGEMENT, PT II, 2016, 9659 : 92 - 104
  • [23] Video Analysis for Traffic Anomaly Detection Using Support Vector Machines
    Batapati, Praveen
    Duy Tran
    Sheng, Weihua
    Liu, Meiqin
    Zeng, Ruili
    2014 11TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION (WCICA), 2014, : 5500 - 5505
  • [24] Field classification, modeling and anomaly detection in unknown CAN bus networks
    Markovitz, Moti
    Wool, Avishai
    VEHICULAR COMMUNICATIONS, 2017, 9 : 43 - 52
  • [25] An Efficient Hidden Markov Model For Anomaly Detection In CAN Bus Networks
    Boumiza, Safa
    Braham, Rafik
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 482 - 487
  • [26] Network Traffic Anomaly Detection based on Viterbi Algorithm Using SNMP MIB Data
    Alhaidari, Sulaiman
    Alharbi, Ali
    Alshaikhsaleh, Mansour
    Zohdy, Mohamed
    Debnath, Debatosh
    PROCEEDINGS OF 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEM AND DATA MINING (ICISDM 2019), 2019, : 92 - 97
  • [27] Improving anomaly detection event analysis using the EventRank algorithm
    Begnum, Kyrre
    Burgess, Mark
    INTER-DOMAIN MANAGEMENT, PROCEEDINGS, 2007, 4543 : 145 - +
  • [28] Multicriteria Similarity-Based Anomaly Detection Using Pareto Depth Analysis
    Hsiao, Ko-Jen
    Xu, Kevin S.
    Calder, Jeff
    Hero, Alfred O., III
    IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS, 2016, 27 (06) : 1307 - 1321
  • [29] USING R FOR ANOMALY DETECTION IN NETWORK TRAFFIC
    Hock, Denis
    Kappes, Martin
    PROCEEDINGS OF THE FIFTH INTERNATIONAL CONFERENCE ON INTERNET TECHNOLOGIES AND APPLICATIONS (ITA 13), 2013, : 98 - 105
  • [30] Analysis of network traffic features for anomaly detection
    Iglesias, Felix
    Zseby, Tanja
    MACHINE LEARNING, 2015, 101 (1-3) : 59 - 84