An Efficient Hidden Markov Model For Anomaly Detection In CAN Bus Networks

被引:1
作者
Boumiza, Safa [1 ]
Braham, Rafik [1 ]
机构
[1] Univ Sousse, PRINCE Res Lab, ISITCOM, Hammam Sousse, Tunisia
来源
2019 27TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS (SOFTCOM) | 2019年
关键词
in-vehicle networks; self-driven cars; HMM; anomaly detection; CAN packets;
D O I
10.23919/softcom.2019.8903789
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
CAN Bus is currently the most used bus network in vehicles. It was designed however to be used for internal communications with no external access. On the other hand, nowadays in-vehicle networks allow communication with external devices through wireless interfaces such as Bluetooth, Wi-Fi, cellular, etc. For this reason, the network became vulnerable to many external threats which may cause high danger for both drivers and passengers. Much research is being done on securing this bus. Most proposed solutions are based on cryptographic approaches. There are only few works which employ anomaly-detection techniques despite their efficiencies in systems that need real-time detection. Therefore, we propose an intrusion detection system (IDS) based on Hidden Markov Models for the Controller Area Network (CAN) bus. Our system extracts suitable features from CAN packets and uses them to train and construct system model parameters. The system operates by comparing test transition sequences obtained in the detection phase and normal sequences built in the training phase. HMM is a powerful tool to process no linear and time variant systems. For this reason, the proposed IDS shows a good performance namely substantial decrease of false positive errors and increase of detection rate.
引用
收藏
页码:482 / 487
页数:6
相关论文
共 17 条
  • [1] [Anonymous], 2011, P 20 USENIX SEC S SA
  • [2] [Anonymous], 2016, P KOR ADV I SCI TECH
  • [3] [Anonymous], ELECT LETT
  • [4] [Anonymous], INT J EMBEDDED SYSTE
  • [5] HMMPayl: An intrusion detection system based on Hidden Markov Models
    Ariu, Davide
    Tronci, Roberto
    Giacinto, Giorgio
    [J]. COMPUTERS & SECURITY, 2011, 30 (04) : 221 - 241
  • [6] Intrusion Threats And Security Solutions For Autonomous Vehicle Networks
    Boumiza, Safa
    Braham, Rafik
    [J]. 2017 IEEE/ACS 14TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2017, : 120 - 127
  • [7] Efficient anomaly detection by modeling privilege flows using hidden Markov model
    Cho, SB
    Park, HJ
    [J]. COMPUTERS & SECURITY, 2003, 22 (01) : 45 - 55
  • [8] Etschberger K., 2001, IXXAT AUTOMATION
  • [9] Experimental Security Analysis of a Modern Automobile
    Koscher, Karl
    Czeskis, Alexei
    Roesner, Franziska
    Patel, Shwetak
    Kohno, Tadayoshi
    Checkoway, Stephen
    Mccoy, Damon
    Kantor, Brian
    Anderson, Danny
    Shacham, Hovav
    Savage, Stefan
    [J]. 2010 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2010, : 447 - 462
  • [10] Field classification, modeling and anomaly detection in unknown CAN bus networks
    Markovitz, Moti
    Wool, Avishai
    [J]. VEHICULAR COMMUNICATIONS, 2017, 9 : 43 - 52