An Unsupervised Learning Approach for In-Vehicle Network Intrusion Detection

被引:10
作者
Leslie, Nandi [1 ]
机构
[1] Raytheon Technol, Arlington, VA 22209 USA
来源
2021 55TH ANNUAL CONFERENCE ON INFORMATION SCIENCES AND SYSTEMS (CISS) | 2021年
关键词
Unsupervised learning; hierarchical clustering; in-vehicle networks; cybersecurity;
D O I
10.1109/CISS50987.2021.9400233
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In-vehicle networks remain largely unprotected from a myriad of vulnerabilities to failures caused by adversarial activities. Remote attacks on the SAE J1939 protocol based on controller access network (CAN) bus for heavy-duty ground vehicles can lead to detectable changes in the physical characteristics of the vehicle. In this paper, I develop an unsupervised learning approach to monitor the normal behavior within the CAN bus data and detect malicious traffic. The J1939 data packets have some text-based features that I convert to numerical values. In addition, I propose an algorithm based on hierarchical agglomerative clustering that considers multiple approaches for linkages and pairwise distances between observations. I present prediction performance results to show the effectiveness of this ensemble algorithm. In addition to in-vehicle network security, this algorithm is also transferrable to other cybersecurity datasets, including botnet attacks in traditional enterprise IP networks.
引用
收藏
页数:4
相关论文
共 15 条
[1]   Intrusion Detection Systems for Intra-Vehicle Networks: A Review [J].
Al-Jarrah, Omar Y. ;
Maple, Carsten ;
Dianati, Mehrdad ;
Oxtoby, David ;
Mouzakitis, Alex .
IEEE ACCESS, 2019, 7 :21266-21289
[2]  
[Anonymous], 2011, P 20 USENIX SEC S SA
[3]  
[Anonymous], 2003, ADV NEURAL INFORM PR
[4]  
Cho KT, 2016, PROCEEDINGS OF THE 25TH USENIX SECURITY SYMPOSIUM, P911
[5]  
Jain A. K., 1988, Algorithms for Clustering Data, P446
[6]   Intrusion Detection System Using Deep Neural Network for In-Vehicle Network Security [J].
Kang, Min-Joo ;
Kang, Je-Won .
PLOS ONE, 2016, 11 (06)
[7]   Experimental Security Analysis of a Modern Automobile [J].
Koscher, Karl ;
Czeskis, Alexei ;
Roesner, Franziska ;
Patel, Shwetak ;
Kohno, Tadayoshi ;
Checkoway, Stephen ;
Mccoy, Damon ;
Kantor, Brian ;
Anderson, Danny ;
Shacham, Hovav ;
Savage, Stefan .
2010 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2010, :447-462
[8]  
Kwon M, 2020, CONF LASER ELECTR
[9]   Intrusion detection system for automotive Controller Area Network (CAN) bus system: a review [J].
Lokman, Siti-Farhana ;
Othman, Abu Talib ;
Abu-Bakar, Muhammad-Husaini .
EURASIP JOURNAL ON WIRELESS COMMUNICATIONS AND NETWORKING, 2019, 2019 (1)
[10]  
Moore M. R., 2017, P 12 ANN C CYB INF S, P1, DOI DOI 10.1145/3064814.3064816