A hybrid deep learning based intrusion detection system using spatial-temporal representation of in-vehicle network traffic

被引:98
作者
Lo, Wei [1 ]
Alqahtani, Hamed [2 ]
Thakur, Kutub [3 ]
Almadhor, Ahmad [4 ]
Chander, Subhash [5 ]
Kumar, Gulshan [6 ]
机构
[1] Guangxi Univ Finance & Econ, Guangxi 530003, Guangxi, Peoples R China
[2] King Khalid Univ, Abha, Saudi Arabia
[3] New Jersey City Univ, Jersey City, NJ USA
[4] Jouf Univ, Jouf, Saudi Arabia
[5] Malout Inst Management & Informat Technol, Malout, Punjab, India
[6] Shaheed Bhagat Singh State Univ, Ferozepur, Punjab, India
关键词
Controller area network; Deep neural networks; Intrusion detection; In-vehicle network; Representation learning; Security and privacy; NEURAL-NETWORKS;
D O I
10.1016/j.vehcom.2022.100471
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
A significant increase in the use of electronics control units (ECUs) in modern vehicles has made controller area network (CAN) a de facto standard in the automotive industry. CAN standard has been designed as a reliable and straightforward broadcast-based protocol for providing serial communication between ECUs without considering security aspects like authentication and encryption. Cyber attackers have exploited these vulnerabilities to mount a variety of attacks against CAN-based in-vehicle network. In this work, we proposed a hybrid deep learning-based intrusion detection system (HyDL-IDS) based upon spatial-temporal representation for characterizing in-vehicle network traffic accurately. For this purpose, we use convolutional neural network (CNN) and long short term memory (LSTM) in sequence for extracting spatial and temporal features automatically from in-vehicle network traffic. The proposed HyDL-IDS have been validated using a benchmark car-hacking data set. The reported results demonstrate approximately 100% detection accuracy with a low false alarm rate for different cyber-attacks, including denial-of-service (DoS) attacks, fuzzy attacks and spoofing (Gear and revolutions per minute (RPM)) attacks based on the identified dataset. The HyDL-IDS have significantly improved detection accuracy and false alarm rate for detecting intrusions in-vehicle network compared to other methods, namely Naive Bayes, Decision tree, Multi-layer perceptron, CNN, and LSTM based on spatial-temporal representation of in-vehicle network traffic.(c) 2022 Elsevier Inc. All rights reserved.
引用
收藏
页数:17
相关论文
共 41 条
[1]  
Aliwa Emad., ACM Computing Surveys, V54, P1
[2]  
Angelo G.D., J NETW COMPUT APPL, V173
[3]  
[Anonymous], 2000, ACM SIGKDD EXPLORATI, DOI DOI 10.1145/846183.846199
[4]  
Avatefipour O., ARXIV PREPRINT ARXIV
[5]   Representation Learning: A Review and New Perspectives [J].
Bengio, Yoshua ;
Courville, Aaron ;
Vincent, Pascal .
IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2013, 35 (08) :1798-1828
[6]   FINDING STRUCTURE IN TIME [J].
ELMAN, JL .
COGNITIVE SCIENCE, 1990, 14 (02) :179-211
[7]  
Erdem H, FEATURE SELECTION MU
[8]   An overview of Controller Area Network [J].
Farsi, M ;
Ratcliff, K ;
Barbosa, M .
COMPUTING & CONTROL ENGINEERING JOURNAL, 1999, 10 (03) :113-120
[9]  
Fengli Zhang, 2013, 2013 IEEE Eighth International Conference on Networking, Architecture and Storage (NAS), P307, DOI 10.1109/NAS.2013.49
[10]   A Primer on Neural Network Models for Natural Language Processing [J].
Goldberg, Yoav .
JOURNAL OF ARTIFICIAL INTELLIGENCE RESEARCH, 2016, 57 :345-420