TTIDS: Transmission-Resuming Time-Based Intrusion Detection System for Controller Area Network (CAN)

被引:10
|
作者
Lee, Seyoung [1 ]
Jo, Hyo Jin [2 ]
Cho, Aram [3 ]
Lee, Dong Hoon [1 ]
Choi, Wonsuk [4 ]
机构
[1] Korea Univ, Grad Sch Informat Secur, Seoul 02841, South Korea
[2] Soongsil Univ, Sch Software, Seoul 06978, South Korea
[3] Hyundai Motors, Hwaseong Si 18280, South Korea
[4] Hansung Univ, Div IT Convergence Engn, Seoul 02876, South Korea
关键词
Payloads; Automotive engineering; Processor scheduling; Intrusion detection; Standards; Software; Hardware; Automotive security; controller area network (CAN); electronic control unit (ECU); intrusion detection system (IDS); AUTHENTICATION;
D O I
10.1109/ACCESS.2022.3174356
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern vehicles are becoming complex cyber-physical systems equipped with numerous electronic control units (ECUs). Over the controller area network (CAN), these ECUs communicate with each other to share information related to vehicle status as well as commands to efficiently control the vehicle. However, the increasing complexity of modern vehicles has inadvertently expanded potential attack surfaces, making them vulnerable to cyber attacks. In light of this, researchers are currently working to demonstrate remote vehicle maneuvering by compromising ECUs, and as a countermeasure to such malicious manipulation, to study automotive intrusion detection systems (IDSs) as potential remedies. In general, CAN messages are transmitted periodically, and as such, many researchers have relied on frequency-based IDSs in their solutions proposals. However, an attacker can bypass this defense by suspending the communication of the target ECU from the network and injecting malicious messages with the same frequency as the suspended messages. As a result, an attacker is able to masquerade as the original transmission frequency. In this paper, we propose a Transmission-resuming Time-based IDS (TTIDS), which is designed to detect such attacks. TTIDS detects when an ECU periodically transmitting messages is suspended, and then it estimates when the suspended ECU resumes periodic transmission. With this projection, TTIDS detects malicious messages transmitted while the ECU is suspended. We conduct the evaluation of TTIDS on two real vehicles and present the results, which show the TTIDS is able to effectively detect an enhanced attack that bypasses existing frequency-based IDSs with a false positive rate of 0.213% and a false negative rate of 0.027%.
引用
下载
收藏
页码:52139 / 52153
页数:15
相关论文
共 50 条
  • [1] Autocorrelation-based intrusion detection system for controller area network (CAN)
    Jeong W.
    Choi E.
    Choi J.-W.
    Journal of Institute of Control, Robotics and Systems, 2021, 27 (02) : 92 - 97
  • [2] WINDS: A Wavelet-Based Intrusion Detection System for Controller Area Network (CAN)
    Bozdal, Mehmet
    Samie, Mohammad
    Jennions, Ian K.
    IEEE ACCESS, 2021, 9 : 58621 - 58633
  • [3] Intrusion detection system for controller area network
    Vinayak Tanksale
    Cybersecurity, 7
  • [4] Intrusion detection system for controller area network
    Tanksale, Vinayak
    CYBERSECURITY, 2024, 7 (01)
  • [5] Intrusion detection system for automotive Controller Area Network (CAN) bus system: a review
    Siti-Farhana Lokman
    Abu Talib Othman
    Muhammad-Husaini Abu-Bakar
    EURASIP Journal on Wireless Communications and Networking, 2019
  • [6] Intrusion detection system for automotive Controller Area Network (CAN) bus system: a review
    Lokman, Siti-Farhana
    Othman, Abu Talib
    Abu-Bakar, Muhammad-Husaini
    EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2019, 2019 (1)
  • [7] An Entropy Analysis based Intrusion Detection System for Controller Area Network in Vehicles
    Wang, Qian
    Lu, Zhaojun
    Qu, Gang
    2018 31ST IEEE INTERNATIONAL SYSTEM-ON-CHIP CONFERENCE (SOCC), 2018, : 90 - 95
  • [8] Transfer Learning-Based Intrusion Detection System for a Controller Area Network
    Khatri, Narayan
    Lee, Sihyung
    Nam, Seung Yeob
    IEEE ACCESS, 2023, 11 : 120963 - 120982
  • [9] CAN-BERT do it? Controller Area Network Intrusion Detection System based on BERT Language Model
    Alkhatib, Natasha
    Mushtaq, Maria
    Ghauch, Hadi
    Danger, Jean-Luc
    2022 IEEE/ACS 19TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2022,
  • [10] TTIDS : A Time-Driven Trust Based Intrusion Detection System for IoT Networks
    Choukhairi, Mouad
    Fakhri, Youssef
    Amnai, Mohamed
    Proceedings - 2022 9th International Conference on Wireless Networks and Mobile Communications, WINCOM 2022, 2022,