IDS-DEC: A novel intrusion detection for CAN bus traffic based on deep embedded clustering

被引:2
|
作者
Shi, Jiahao [1 ]
Xie, Zhijun [1 ]
Dong, Li [1 ]
Jiang, Xianliang [1 ]
Jin, Xing [1 ]
机构
[1] Ningbo Univ, Fac Elect Engn & Comp Sci, Ningbo, Zhejiang, Peoples R China
关键词
Controller area network; In-vehicle network; Unsupervised learning; Deep embedded clustering; Intrusion detection; IN-VEHICLE; ANOMALY DETECTION; DETECTION SYSTEM; ATTACKS;
D O I
10.1016/j.vehcom.2024.100830
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
As the automotive industry advances towards greater automation, the proliferation of electronic control units (ECUs) has led to a substantial increase in the connectivity of in-vehicle networks with the external environment. However, the widely used Controller Area Network (CAN), which serves as the standard for in-vehicle networks, lacks robust security features, such as authentication or encrypted information transmission. This poses a significant challenge to the security of these networks. Despite the availability of powerful intrusion detection methods based on machine learning and deep learning, there are notable limitations in terms of stability and accuracy in the absence of a supervised learning process with labeled data. To address this issue, this paper introduces a novel in-vehicle intrusion detection system, termed IDS-DEC. This system combines a spatiotemporal self-coder employing LSTM and CNN (LCAE) with an entropy-based deep embedding clustering. Specifically, our approach involves encoding in-vehicle network traffic into windowed messages using a stream builder, designed to adapt to high-frequency traffic. These messages are then fed into the LCAE to extract a low-dimensional nonlinear spatiotemporal mapping from the initially high-dimensional data. The resulting low-dimensional mapping is subjected to a dual constraint in conjunction with our entropy-based pure deep embedding clustering module. This creates a bidirectional learning objective, addressing the optimization problem and facilitating an end-to-end training pattern for our model to adapt to diverse attack environments. The effectiveness of IDS-DEC is validated using both the benchmark Car Hacking dataset and the Car Hacking-Attack & Defense Challenge dataset. Experimental results demonstrate the model's high detection accuracy across various attacks, stabilizing at approximately 99% accuracy with a 0.5% false alarm rate. The F1 score also stabilizes at around 99%. In comparison with unsupervised methods based on deep stream clustering, LSTM-based self-encoder, and classification-based methods, IDS-DEC exhibits significant improvements across all performance metrics.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Deep IDS : A deep learning approach for Intrusion detection based on IDS 2018
    Dey, Arunavo
    2020 2ND INTERNATIONAL CONFERENCE ON SUSTAINABLE TECHNOLOGIES FOR INDUSTRY 4.0 (STI), 2020,
  • [2] IDS for CAN: A Practical Intrusion Detection System for CAN Bus Security
    Lampe, Brooke
    Meng, Weizhi
    2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 1782 - 1787
  • [3] CANSat-IDS: An adaptive distributed Intrusion Detection System for satellites, based on combined classification of CAN traffic
    Driouch, Otman
    Bah, Slimane
    Guennoun, Zouhair
    COMPUTERS & SECURITY, 2024, 146
  • [4] DESC-IDS: Towards an efficient real-time automotive intrusion detection system based on deep evolving stream clustering
    Cheng, Pengzhou
    Han, Mu
    Liu, Gongshen
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2023, 140 : 266 - 281
  • [5] CAN Bus Intrusion Detection Based on Auxiliary Classifier GAN and Out-of-distribution Detection
    Zhao, Qingling
    Chen, Mingqiang
    Gu, Zonghua
    Luan, Siyu
    Zeng, Haibo
    Chakrabory, Samarjit
    ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2022, 21 (04)
  • [6] Illegal Intrusion Detection for In-Vehicle CAN Bus Based on Immunology Principle
    Li, Xiaowei
    Liu, Feng
    Li, Defei
    Hu, Tianchi
    Han, Mu
    SYMMETRY-BASEL, 2022, 14 (08):
  • [7] Adversarial Attacks for Intrusion Detection Based on Bus Traffic
    He, Daojing
    Dai, Jiayu
    Liu, Xiaoxia
    Zhu, Shanshan
    Chan, Sammy
    Guizani, Mohsen
    IEEE NETWORK, 2022, 36 (04): : 203 - 209
  • [8] Network Traffic Anomaly Detection in CAN Bus Based on Ensemble Learning
    Wu, Yuxi
    Tao, Xiaodong
    2024 4TH INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND INTELLIGENT SYSTEMS ENGINEERING, MLISE 2024, 2024, : 240 - 245
  • [9] A Deep Learning-Based IDS for Automotive Theft Detection for In-Vehicle CAN Bus
    Khan, Junaid Ahmad
    Lim, Dae-Woon
    Kim, Young-Sik
    IEEE ACCESS, 2023, 11 : 112814 - 112829
  • [10] Deep Learning-based Embedded Intrusion Detection System for Automotive CAN
    Khandelwal, Shashwat
    Wadhwa, Eashan
    Shreejith, Shanker
    2022 IEEE 33RD INTERNATIONAL CONFERENCE ON APPLICATION-SPECIFIC SYSTEMS, ARCHITECTURES AND PROCESSORS (ASAP), 2022, : 88 - 92