A hybrid deep learning based intrusion detection system using spatial-temporal representation of in-vehicle network traffic

被引:81
作者
Lo, Wei [1 ]
Alqahtani, Hamed [2 ]
Thakur, Kutub [3 ]
Almadhor, Ahmad [4 ]
Chander, Subhash [5 ]
Kumar, Gulshan [6 ]
机构
[1] Guangxi Univ Finance & Econ, Guangxi 530003, Guangxi, Peoples R China
[2] King Khalid Univ, Abha, Saudi Arabia
[3] New Jersey City Univ, Jersey City, NJ USA
[4] Jouf Univ, Jouf, Saudi Arabia
[5] Malout Inst Management & Informat Technol, Malout, Punjab, India
[6] Shaheed Bhagat Singh State Univ, Ferozepur, Punjab, India
关键词
Controller area network; Deep neural networks; Intrusion detection; In-vehicle network; Representation learning; Security and privacy; NEURAL-NETWORKS;
D O I
10.1016/j.vehcom.2022.100471
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
A significant increase in the use of electronics control units (ECUs) in modern vehicles has made controller area network (CAN) a de facto standard in the automotive industry. CAN standard has been designed as a reliable and straightforward broadcast-based protocol for providing serial communication between ECUs without considering security aspects like authentication and encryption. Cyber attackers have exploited these vulnerabilities to mount a variety of attacks against CAN-based in-vehicle network. In this work, we proposed a hybrid deep learning-based intrusion detection system (HyDL-IDS) based upon spatial-temporal representation for characterizing in-vehicle network traffic accurately. For this purpose, we use convolutional neural network (CNN) and long short term memory (LSTM) in sequence for extracting spatial and temporal features automatically from in-vehicle network traffic. The proposed HyDL-IDS have been validated using a benchmark car-hacking data set. The reported results demonstrate approximately 100% detection accuracy with a low false alarm rate for different cyber-attacks, including denial-of-service (DoS) attacks, fuzzy attacks and spoofing (Gear and revolutions per minute (RPM)) attacks based on the identified dataset. The HyDL-IDS have significantly improved detection accuracy and false alarm rate for detecting intrusions in-vehicle network compared to other methods, namely Naive Bayes, Decision tree, Multi-layer perceptron, CNN, and LSTM based on spatial-temporal representation of in-vehicle network traffic.(c) 2022 Elsevier Inc. All rights reserved.
引用
收藏
页数:17
相关论文
共 41 条
  • [1] Aliwa Emad., ACM Computing Surveys, V54, P1
  • [2] Angelo G.D., J NETW COMPUT APPL, V173
  • [3] Avatefipour O., ARXIV PREPRINT ARXIV
  • [4] Representation Learning: A Review and New Perspectives
    Bengio, Yoshua
    Courville, Aaron
    Vincent, Pascal
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2013, 35 (08) : 1798 - 1828
  • [5] ELKAN C, 2000, ACM SIGKDD EXPLORATI, V1, P63, DOI DOI 10.1145/846183.846199
  • [6] FINDING STRUCTURE IN TIME
    ELMAN, JL
    [J]. COGNITIVE SCIENCE, 1990, 14 (02) : 179 - 211
  • [7] Erdem H, FEATURE SELECTION MU
  • [8] An overview of Controller Area Network
    Farsi, M
    Ratcliff, K
    Barbosa, M
    [J]. COMPUTING & CONTROL ENGINEERING JOURNAL, 1999, 10 (03): : 113 - 120
  • [9] Fengli Zhang, 2013, 2013 IEEE Eighth International Conference on Networking, Architecture and Storage (NAS), P307, DOI 10.1109/NAS.2013.49
  • [10] A Primer on Neural Network Models for Natural Language Processing
    Goldberg, Yoav
    [J]. JOURNAL OF ARTIFICIAL INTELLIGENCE RESEARCH, 2016, 57 : 345 - 420