Field classification, modeling and anomaly detection in unknown CAN bus networks

被引:82
作者
Markovitz, Moti [1 ]
Wool, Avishai [1 ]
机构
[1] Tel Aviv Univ, Sch Elect Engn, Tel Aviv, Israel
关键词
CAN bus; Anomaly detection; Network layer issues; Security and privacy; Communication architecture;
D O I
10.1016/j.vehcom.2017.02.005
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
This paper describes a novel domain-aware anomaly detection system for in-car CAN bus traffic. Through inspection of real CAN bus communication, we discovered the presence of semantically-meaningful Constantfields, Multi-Value fields and Counter or Sensor fields. For CAN networks in which the specifications of the electronic control units (ECUs) are unknown, and hence, the borders between the bit-fields are unknown, we developed a greedy algorithm to split the messages into fields and classify the fields into the types we observed. Next, we designed a semantically-aware anomaly detection system for CAN bus traffic. In its learning phase, our system uses the classifier to characterize the fields and build a model for the messages, based on their field types. The model is based on Ternary Content-Addressable Memory (TCAM), that can run efficiently in either software or hardware. During the enforcement phase our system detects deviations from the model. We evaluated our system on simulated CAN bus traffic, and achieved very encouraging results: a median false positive rate of 1% with a median of only 89.5 TCAMs. Finally we evaluated our system on the real CAN bus traffic. With a sufficiently long period of recording, we achieved a median false positive rate of 0% with an average of 252 TCAMs. (C) 2017 Elsevier Inc. All rights reserved.
引用
收藏
页码:43 / 52
页数:10
相关论文
共 50 条
  • [41] ResGCN: attention-based deep residual modeling for anomaly detection on attributed networks
    Pei, Yulong
    Huang, Tianjin
    van Ipenburg, Werner
    Pechenizkiy, Mykola
    MACHINE LEARNING, 2022, 111 (02) : 519 - 541
  • [42] Deep Anomaly Detection with Deviation Networks
    Pang, Guansong
    Shen, Chunhua
    van den Hengel, Anton
    KDD'19: PROCEEDINGS OF THE 25TH ACM SIGKDD INTERNATIONAL CONFERENCCE ON KNOWLEDGE DISCOVERY AND DATA MINING, 2019, : 353 - 362
  • [43] ResGCN: Attention-based Deep Residual Modeling for Anomaly Detection on Attributed Networks
    Pei, Yulong
    Huang, Tianjin
    van Ipenburg, Werner
    Pechenizkiy, Mykola
    2021 IEEE 8TH INTERNATIONAL CONFERENCE ON DATA SCIENCE AND ADVANCED ANALYTICS (DSAA), 2021,
  • [44] Statistical Anomaly Detection with Sensor Networks
    Paschalidis, Ioannis Ch.
    Chen, Yin
    ACM TRANSACTIONS ON SENSOR NETWORKS, 2010, 7 (02)
  • [45] Anomaly detection in dynamic networks: a survey
    Ranshous, Stephen
    Shen, Shitian
    Koutra, Danai
    Harenberg, Steve
    Faloutsos, Christos
    Samatova, Nagiza F.
    WILEY INTERDISCIPLINARY REVIEWS-COMPUTATIONAL STATISTICS, 2015, 7 (03): : 223 - 247
  • [46] A Review of Neural Networks for Anomaly Detection
    de Albuquerque Filho, Jose Edson
    Brandao, Laislla C. P.
    Torres Fernandes, Bruno Jose
    Maciel, Alexandre M. A.
    IEEE ACCESS, 2022, 10 : 112342 - 112367
  • [47] PulseAnomaly: Unsupervised Anomaly Detection on Avionic Platforms With Seasonality and Trend Modeling in Transformer Networks
    Yu, Hanbo
    Acharya, Sudipta
    Ding, Steven H. H.
    Zulkernine, Mohammad
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2025, 22 (02) : 1567 - 1581
  • [48] Anomaly Detection and Modeling of Surveillance Video
    Yang F.
    Xiao B.
    Yu Z.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2021, 58 (12): : 2708 - 2723
  • [49] Anomaly detection in online social networks
    Savage, David
    Zhang, Xiuzhen
    Yu, Xinghuo
    Chou, Pauline
    Wang, Qingmai
    SOCIAL NETWORKS, 2014, 39 : 62 - 70
  • [50] A Survey of Anomaly Detection Methods in Networks
    Zhang, Weiyu
    Yang, Qingbo
    Geng, Yushui
    2009 INTERNATIONAL SYMPOSIUM ON COMPUTER NETWORK AND MULTIMEDIA TECHNOLOGY (CNMT 2009), VOLUMES 1 AND 2, 2009, : 619 - 621