COIDS: A Clock Offset Based Intrusion Detection System for Controller Area Networks

被引:23
|
作者
Halder, Subir [1 ]
Conti, Mauro [1 ]
Das, Sajal K. [2 ]
机构
[1] Univ Padua, Dept Math, Padua, Italy
[2] Missouri Univ Sci & Technol, Dept Comp Sci, Rolla, MO 65409 USA
关键词
Clock Offset; Clock Skew; Controller Area Network; Cumulative Sum method; Intrusion Detection Systems;
D O I
10.1145/3369740.3369787
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Controller Area Network (CAN) is an in-vehicle communication protocol which provides an efficient and reliable communication link between Electronic Control Units (ECUs) in real-time. Recent studies have shown that attackers can take remote control of the targeted car by exploiting the vulnerabilities of the CAN protocol. Motivated by this fact, we propose Clock Offset-based Intrusion Detection System (COIDS) to monitor in-vehicle network and detect any intrusion. Precisely, we first measure and then exploit the clock offset of transmitter ECU's clock for fingerprinting ECU. We next leverage the derived fingerprints to construct a baseline of ECU's normal clock behaviour using an active learning technique. Based on the baseline of normal behaviour, we use Cumulative Sum method to detect any abnormal deviation in clock offset. Particularly, if the deviation in clock offset exceeds an unexpected positive or negative value, COIDS declares this change as an intrusion. Further, we use sequential change-point detection technique to determine the exact time of intrusion. We perform exhaustive experiments on real-world publicly available datasets primarily to assess the effectiveness of COIDS against three most potential attacks on CAN, i.e., DoS, impersonation and fuzzy attacks. The results show that COIDS is highly effective in defending all these three attacks. Further, the results show that COIDS considerably faster in detecting intrusion compared to a state-of-the-art solution.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] TTIDS: Transmission-Resuming Time-Based Intrusion Detection System for Controller Area Network (CAN)
    Lee, Seyoung
    Jo, Hyo Jin
    Cho, Aram
    Lee, Dong Hoon
    Choi, Wonsuk
    IEEE ACCESS, 2022, 10 : 52139 - 52153
  • [32] PE-Detector: Intrusion Detection of Periodic and Event Message Attacks on Controller Area Networks
    Kim, Hyunghoon
    Choi, Wonsuk
    Jo, Hyo Jin
    IEEE TRANSACTIONS ON VEHICULAR TECHNOLOGY, 2024, 73 (12) : 19374 - 19388
  • [33] A Statefull Firewall and Intrusion Detection System Enforced with Secure Logging for Controller Area Network
    Lenard, Teri
    Bolboaca, Roland
    PROCEEDINGS OF THE 2021 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2021, 2021, : 39 - 45
  • [34] Storage-based intrusion detection for storage area networks (SANs)
    Banikazemi, M
    Poff, D
    Abali, B
    TWENTY-SECOND IEEE/THIRTEENTH NASA GODDARD CONFERENCE ON MASS STORAGE SYSTEMS AND TECHNOLOGIES, PROCEEDINGS: INFORMATION RETRIEVAL FROM VERY LARGE STORAGE SYSTEMS, 2005, : 118 - 127
  • [35] Collective Intrusion Detection in Wide Area Networks
    Nafir, Abdenacer
    Mazouzi, Smaine
    Chikhi, Salim
    2014 IEEE INTERNATIONAL SYMPOSIUM ON INNOVATIONS IN INTELLIGENT SYSTEMS AND APPLICATIONS (INISTA 2014), 2014, : 46 - 51
  • [36] Survey of Automotive Controller Area Network Intrusion Detection Systems
    Young, Clinton
    Zambreno, Joseph
    Olufowobi, Habeeb
    Bloom, Gedare
    IEEE DESIGN & TEST, 2019, 36 (06) : 48 - 55
  • [37] A Survey of Network Intrusion Detection Systems for Controller Area Network
    Dupont, Guillaume
    den Hartog, Jerry
    Etalle, Sandro
    Lekidis, Alexios
    2019 IEEE INTERNATIONAL CONFERENCE OF VEHICULAR ELECTRONICS AND SAFETY (ICVES 19), 2019,
  • [38] Advanced Temperature-Varied ECU Fingerprints for Source Identification and Intrusion Detection in Controller Area Networks
    Tian, Miaoqing
    Jiang, Ruobing
    Qu, Haipeng
    Lu, Qian
    Zhou, Xiaoyun
    SECURITY AND COMMUNICATION NETWORKS, 2020, 2020
  • [39] Intrusion Detection Method Using Bi-Directional GPT for in-Vehicle Controller Area Networks
    Nam, Minki
    Park, Seungyoung
    Kim, Duk Soo
    IEEE ACCESS, 2021, 9 : 124931 - 124944
  • [40] Message Source Identification in Controller Area Network by Utilizing Diagnostic Communications and an Intrusion Detection System
    Matsubayashi, Masaru
    Koyama, Takuma
    Tanaka, Masashi
    Okano, Yasushi
    Miyajima, Asami
    2022 IEEE 96TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2022-FALL), 2022,