can-sleuth: Investigating and Evaluating Automotive Intrusion Detection Datasets

被引:0
|
作者
Kidmose, Brooke [1 ]
Meng, Weizhi [1 ]
机构
[1] Tech Univ Denmark, Kongens Lyngby, Denmark
关键词
automotive; vehicle; controller area network; in-vehicle network; intrusion detection system; can-train-and-test dataset; HCRL Car Hacking dataset; HCRL Survival Analysis dataset; machine learning; DETECTION SYSTEM;
D O I
10.1145/3655693.3655696
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The modern automobile is a network-specifically, a controller area network (CAN)-of computers. Automotive computers manage the engine (e.g., fuel injection), the transmission (e.g., automatic shifting), the vehicle speed (e.g., cruise control), and many, many more systems. Therefore, a vehicle's CAN bus is safety critical; by design, it is robust, reliable, and error tolerant. Unfortunately, it is not secure; it was developed in the 1980s, and, at that time, it was a closed system-no Internet access. The modern automobile is not a closed system, yet the CAN bus remains insecure. Automotive researchers are gravitating toward intrusion detection as one possible solution to the problem of automotive [in]security. To build and evaluate an intrusion detection system (IDS), however, researchers need adequate training and testing data. In this paper, we investigate and evaluate the following automotive intrusion detection datasets: (1) the HCRL Car Hacking dataset, (2) the HCRL Survival Analysis dataset, and (3) the can-train-and-test dataset. The HCRL Car Hacking dataset (hcrl-ch) and the HCRL Survival Analysis dataset (hcrl-sa) are well-established in the literature, whereas the can-train-and-test dataset is a promising new dataset. First, we investigate the can-train-and-test dataset-in particular, we evaluate the impacts of various features on the performance of sixteen machine learning IDSs. Second, we compare can-train-and-test to hcrl-ch and hcrl-sa. We find that, compared to the two established datasets, can-train-and-test provides new and greater insights to researchers interested in automotive intrusion detection, automotive firewalls & filtering, and more. With an order of magnitude more training and testing data, can-train-and-test enables the data-intensive machine learning models to demonstrate their full potential, with eight of the sixteen models achieving an average F1-score above 0.9. Moreover, can-train-and-test maintains ample differentiation power; the standard deviation of the models' average F1-scores was 0.2247, which exceeds the standard deviations of hcrl-ch (0.2202) and hcrl-sa (0.2243).
引用
收藏
页码:19 / 28
页数:10
相关论文
共 50 条
  • [1] Systematic Evaluation of Automotive Intrusion Detection Datasets
    Vahidi, Arash
    Rosenstatter, Thomas
    Mowla, Nishat I.
    PROCEEDINGS OF 6TH ACM COMPUTER SCIENCE IN CARS SYMPOSIUM, CSCS 2022, 2022,
  • [2] A Comprehensive Analysis of Datasets for Automotive Intrusion Detection Systems
    Lee, Seyoung
    Choi, Wonsuk
    Kim, Insup
    Lee, Ganggyu
    Lee, Dong Hoon
    CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 76 (03): : 3413 - 3442
  • [3] Investigating Network Intrusion Detection Datasets Using Machine Learning
    Amaizu, Gabriel Chukwunonso
    Nwakanma, Cosmas Ifeanyi
    Lee, Jae-Min
    Kim, Dong-Seong
    11TH INTERNATIONAL CONFERENCE ON ICT CONVERGENCE: DATA, NETWORK, AND AI IN THE AGE OF UNTACT (ICTC 2020), 2020, : 1325 - 1328
  • [4] MELODY: SYNTHESIZED DATASETS FOR EVALUATING INTRUSION DETECTION SYSTEMS FOR THE SMART GRID
    Babu, Vignesh
    Kumar, Rakesh
    Hoang Hai Nguyen
    Nicol, David M.
    Palani, Kartik
    Reed, Elizabeth
    2017 WINTER SIMULATION CONFERENCE (WSC), 2017, : 1061 - 1072
  • [5] Evading Voltage-Based Intrusion Detection on Automotive CAN
    Bhatia, Rohit
    Kumar, Vireshwar
    Serag, Khaled
    Celik, Z. Berkay
    Payer, Mathias
    Xu, Dongyan
    28TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2021), 2021,
  • [6] can-train-and-test: A curated CAN dataset for automotive intrusion detection
    Lampe, Brooke
    Meng, Weizhi
    COMPUTERS & SECURITY, 2024, 140
  • [7] Cryptographic and Intrusion Detection System for automotive CAN bus: Survey and contributions
    Gmiden, Mabrouka
    Gmiden, Mohamed Hedi
    Trabelsi, Hafedh
    2019 16TH INTERNATIONAL MULTI-CONFERENCE ON SYSTEMS, SIGNALS & DEVICES (SSD), 2019, : 158 - 163
  • [8] Exploring Highly Quantised Neural Networks for Intrusion Detection in Automotive CAN
    Khandelwal, Shashwat
    Shreejith, Shanker
    2023 33RD INTERNATIONAL CONFERENCE ON FIELD-PROGRAMMABLE LOGIC AND APPLICATIONS, FPL, 2023, : 235 - 241
  • [9] Investigating and evaluating behavioural profiling and intrusion detection using data mining
    Singh, H
    Furnell, S
    Lines, B
    Dowland, P
    INFORMATION ASSURANCE IN COMPUTER NETWORKS: METHODS, MODELS AND ARCHITECTURES FOR NETWORK SECURITY, PROCEEDINGS, 2001, 2052 : 153 - 158
  • [10] Can evolutionary computation handle large datasets? A study into network intrusion detection
    Dam, HH
    Shafi, K
    Abbass, HA
    AI 2005: ADVANCES IN ARTIFICIAL INTELLIGENCE, 2005, 3809 : 1092 - 1095