Field classification, modeling and anomaly detection in unknown CAN bus networks

被引:82
|
作者
Markovitz, Moti [1 ]
Wool, Avishai [1 ]
机构
[1] Tel Aviv Univ, Sch Elect Engn, Tel Aviv, Israel
关键词
CAN bus; Anomaly detection; Network layer issues; Security and privacy; Communication architecture;
D O I
10.1016/j.vehcom.2017.02.005
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper describes a novel domain-aware anomaly detection system for in-car CAN bus traffic. Through inspection of real CAN bus communication, we discovered the presence of semantically-meaningful Constantfields, Multi-Value fields and Counter or Sensor fields. For CAN networks in which the specifications of the electronic control units (ECUs) are unknown, and hence, the borders between the bit-fields are unknown, we developed a greedy algorithm to split the messages into fields and classify the fields into the types we observed. Next, we designed a semantically-aware anomaly detection system for CAN bus traffic. In its learning phase, our system uses the classifier to characterize the fields and build a model for the messages, based on their field types. The model is based on Ternary Content-Addressable Memory (TCAM), that can run efficiently in either software or hardware. During the enforcement phase our system detects deviations from the model. We evaluated our system on simulated CAN bus traffic, and achieved very encouraging results: a median false positive rate of 1% with a median of only 89.5 TCAMs. Finally we evaluated our system on the real CAN bus traffic. With a sufficiently long period of recording, we achieved a median false positive rate of 0% with an average of 252 TCAMs. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:43 / 52
页数:10
相关论文
共 50 条
  • [21] Anomaly Detection in Industrial Networks: Current State, Classification, and Key Challenges
    Kuchar, Karel
    Fujdiak, Radek
    IEEE SENSORS JOURNAL, 2025, 25 (03) : 5031 - 5043
  • [22] Application of Controller Area Network (CAN) bus anomaly detection based on time series prediction
    Qin, Hongmao
    Yan, Mengru
    Ji, Haojie
    VEHICULAR COMMUNICATIONS, 2021, 27
  • [23] Explainable machine learning for performance anomaly detection and classification in mobile networks
    Ramirez, Juan M.
    Diez, Fernando
    Rojo, Pablo
    Mancuso, Vincenzo
    Fernandez-Anta, Antonio
    COMPUTER COMMUNICATIONS, 2023, 200 : 113 - 131
  • [24] Radio Frequency Classification and Anomaly Detection using Convolutional Neural Networks
    Conn, Marvin A.
    Josyula, Darsana
    2019 IEEE RADAR CONFERENCE (RADARCONF), 2019,
  • [25] A survey and classification of the security anomaly detection mechanisms in software defined networks
    Jafarian, Tohid
    Masdari, Mohammad
    Ghaffari, Ali
    Majidzadeh, Kambiz
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2021, 24 (02): : 1235 - 1253
  • [26] Anomaly Detection System of Controller Area Network (CAN) Bus Based on Time Series Prediction
    Tan, Xiangtian
    Zhang, Chen
    Li, Bo
    Ge, Binbin
    Liu, Chen
    SMART COMPUTING AND COMMUNICATION, 2022, 13202 : 318 - 328
  • [27] Anomaly information detection and fault tolerance control method for CAN-FD bus network
    Wang, Aoran
    Fang, Jie
    Xu, Yinan
    Xu, Yihu
    Wang, Yubing
    Wu, Yujing
    Chung, Jin-Gyun
    2022 19TH INTERNATIONAL SOC DESIGN CONFERENCE (ISOCC), 2022, : 308 - 309
  • [28] Applying Transformers for Anomaly Detection in Bus Trajectories
    Cruz, Michael
    Barbosa, Luciano
    INTELLIGENT SYSTEMS, BRACIS 2024, PT I, 2025, 15412 : 169 - 184
  • [29] Bit scanner: Anomaly detection for in-vehicle CAN bus using binary sequence whitelisting
    Zhang, Guiqi
    Liu, Qi
    Cao, Chenhong
    Li, Jiangtao
    Li, Yufeng
    COMPUTERS & SECURITY, 2023, 134
  • [30] A survey and classification of the security anomaly detection mechanisms in software defined networks
    Tohid Jafarian
    Mohammad Masdari
    Ali Ghaffari
    Kambiz Majidzadeh
    Cluster Computing, 2021, 24 : 1235 - 1253