Field classification, modeling and anomaly detection in unknown CAN bus networks

被引:82
|
作者
Markovitz, Moti [1 ]
Wool, Avishai [1 ]
机构
[1] Tel Aviv Univ, Sch Elect Engn, Tel Aviv, Israel
关键词
CAN bus; Anomaly detection; Network layer issues; Security and privacy; Communication architecture;
D O I
10.1016/j.vehcom.2017.02.005
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper describes a novel domain-aware anomaly detection system for in-car CAN bus traffic. Through inspection of real CAN bus communication, we discovered the presence of semantically-meaningful Constantfields, Multi-Value fields and Counter or Sensor fields. For CAN networks in which the specifications of the electronic control units (ECUs) are unknown, and hence, the borders between the bit-fields are unknown, we developed a greedy algorithm to split the messages into fields and classify the fields into the types we observed. Next, we designed a semantically-aware anomaly detection system for CAN bus traffic. In its learning phase, our system uses the classifier to characterize the fields and build a model for the messages, based on their field types. The model is based on Ternary Content-Addressable Memory (TCAM), that can run efficiently in either software or hardware. During the enforcement phase our system detects deviations from the model. We evaluated our system on simulated CAN bus traffic, and achieved very encouraging results: a median false positive rate of 1% with a median of only 89.5 TCAMs. Finally we evaluated our system on the real CAN bus traffic. With a sufficiently long period of recording, we achieved a median false positive rate of 0% with an average of 252 TCAMs. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:43 / 52
页数:10
相关论文
共 50 条
  • [1] An Efficient Hidden Markov Model For Anomaly Detection In CAN Bus Networks
    Boumiza, Safa
    Braham, Rafik
    2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM), 2019, : 482 - 487
  • [2] ML-based Anomaly Detection for Intra-Vehicular CAN-bus Networks
    Purohit, Shaurya
    Govindarasu, Manimaran
    2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 227 - 232
  • [3] An Anomaly Detector for CAN Bus Networks in Autonomous Cars based on Neural Networks
    Boumiza, Safa
    Braham, Rafik
    2019 INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMPUTING, NETWORKING AND COMMUNICATIONS (WIMOB), 2019,
  • [4] Frequency-Based Anomaly Detection for the Automotive CAN bus
    Taylor, Adrian
    Japkowicz, Nathalie
    Leblanc, Sylvain
    2015 WORLD CONGRESS ON INDUSTRIAL CONTROL SYSTEMS SECURITY (WCICSS), 2015, : 45 - 49
  • [5] Research on Anomaly Detection of In⁃Vehicle CAN Bus Based on Entropy
    Zhang H.
    Jiang R.
    Wang J.
    Lu Z.
    Liu Z.
    Qiche Gongcheng/Automotive Engineering, 2021, 43 (10): : 1543 - 1548
  • [6] Cosine similarity based anomaly detection methodology for the CAN bus
    Kwak, Byung Il
    Han, Mee Lan
    Kim, Huy Kang
    EXPERT SYSTEMS WITH APPLICATIONS, 2021, 166
  • [7] Modeling Unknown Web Attacks in Network Anomaly Detection
    Liang Guangmin
    THIRD 2008 INTERNATIONAL CONFERENCE ON CONVERGENCE AND HYBRID INFORMATION TECHNOLOGY, VOL 2, PROCEEDINGS, 2008, : 112 - 116
  • [8] Network Traffic Anomaly Detection in CAN Bus Based on Ensemble Learning
    Wu, Yuxi
    Tao, Xiaodong
    2024 4TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND INTELLIGENT SYSTEMS ENGINEERING, MLISE 2024, 2024, : 240 - 245
  • [9] Anomaly detection of CAN bus messages through analysis of ID sequences
    Marchetti, Mirco
    Stabili, Dario
    2017 28TH IEEE INTELLIGENT VEHICLES SYMPOSIUM (IV 2017), 2017, : 1577 - 1583
  • [10] Anomaly Detection in Vehicular CAN Bus Using Message Identifier Sequences
    Donmez, Tahsin C. M.
    IEEE ACCESS, 2021, 9 : 136243 - 136252