Traffic anomaly detection algorithm for CAN bus using similarity analysis

被引:2
|
作者
Wang, Chao [1 ]
Xu, Xueqiao [1 ]
Xiao, Ke [1 ]
He, Yunhua [1 ]
Yang, Guangcan [1 ]
机构
[1] North China Univ Technol, Sch Informat Sci & Technol, Beijing 100144, Peoples R China
来源
HIGH-CONFIDENCE COMPUTING | 2024年 / 4卷 / 03期
关键词
Automotive safety; CAN bus; Anomaly detection; INTRUSION DETECTION;
D O I
10.1016/j.hcc.2024.100207
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, vehicles have experienced a rise in networking and informatization, leading to increased security concerns. As the most widely used automotive bus network, the Controller Area Network (CAN) bus is vulnerable to attacks, as security was not considered in its original design. This paper proposes SIDuBzip2, a traffic anomaly detection method for the CAN bus based on the bzip2 compression algorithm. The proposed method utilizes the pseudo-periodic characteristics of CAN bus traffic, constructing time series of CAN IDs and calculating the similarity between adjacent time series to identify abnormal traffic. The method consists of three parts: the conversion of CAN ID values to characters, the calculation of similarity based on bzip2 compression, and the optimal solution of model parameters. The experimental results demonstrate that the proposed SIDuBzip2 method effectively detects various attacks, including Denial of Service , replay, basic injection, mixed injection, and suppression attacks. In addition, existing CAN bus traffic anomaly detection methods are compared with the proposed method in terms of performance and delay, demonstrating the feasibility of the proposed method. (c) 2024 The Author(s). Published by Elsevier B.V. on behalf of Shandong University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Traffic Anomaly Detection Based on Robust Principal Component Analysis Using Periodic Traffic Behavior
    Matsuda, Takahiro
    Morita, Tatsuya
    Kudo, Takanori
    Takine, Tetsuya
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2017, E100B (05) : 749 - 761
  • [32] Traffic Pattern Analysis for Distributed Anomaly Detection
    Kolaczek, Grzegorz
    Juszczyszyn, Krzysztof
    PARALLEL PROCESSING AND APPLIED MATHEMATICS, PT II, 2012, 7204 : 648 - 657
  • [33] Analysis of network traffic features for anomaly detection
    Félix Iglesias
    Tanja Zseby
    Machine Learning, 2015, 101 : 59 - 84
  • [34] Network Traffic Monitoring, Analysis and Anomaly Detection
    Wang, Wei
    Zhang, Xiangliang
    Shi, Wenchang
    Lian, Shiguo
    Feng, Dengguo
    IEEE NETWORK, 2011, 25 (03): : 6 - 7
  • [35] Driving Anomaly Detection with Conditional Generative Adversarial Network using Physiological and CAN-Bus Data
    Qiu, Yuning
    Misu, Teruhisa
    Busso, Carlos
    ICMI'19: PROCEEDINGS OF THE 2019 INTERNATIONAL CONFERENCE ON MULTIMODAL INTERACTION, 2019, : 164 - 173
  • [36] Hyperspectral Anomaly Detection Using Combined Similarity Criteria
    Vafadar, Maryam
    Ghassemian, Hassan
    IEEE JOURNAL OF SELECTED TOPICS IN APPLIED EARTH OBSERVATIONS AND REMOTE SENSING, 2018, 11 (11) : 4076 - 4085
  • [37] Volume Based Anomaly Detection using LRD Analysis of Decomposed Network Traffic
    Zeb, Khan
    AsSadhan, Basil
    Al-Muhtadi, Jalal
    Alshebeili, Saleh
    Bashaiwth, Abdulmuneem
    2014 FOURTH INTERNATIONAL CONFERENCE ON INNOVATIVE COMPUTING TECHNOLOGY (INTECH), 2014, : 52 - 57
  • [38] Traffic Similarity Observation Using a Genetic Algorithm and Clustering
    Oujezsky, Vaclav
    Horvath, Tomas
    TECHNOLOGIES, 2018, 6 (04):
  • [39] Anomaly Intrusion Detection for CAN-FD Bus by Support Vector Machine
    Luo F.
    Hu Q.
    Hou S.
    Zhang X.
    Hu, Qiang (404huqiang@tongji.edu.cn), 1790, Science Press (48): : 1790 - 1796
  • [40] Network traffic anomaly detection using PCA and BiGAN
    Patil, Rajlaxmi
    Biradar, Rajshekhar
    Ravi, Vinayakumar
    Biradar, Poornima
    Ghosh, Uttam
    INTERNET TECHNOLOGY LETTERS, 2022, 5 (01)