Submitted:
03 July 2023
Posted:
04 July 2023
You are already at the latest version
Abstract
Keywords:
1. Introduction
2. Preliminaries
2.1. CAN protocol basics
2.2. Threats on CAN protocol
- Spoofing Attack: Unauthorized attackers can disguise malicious nodes as legitimate nodes and transmit malicious frames.
- Fuzzing Attack: Unauthorized malicious nodes can randomly insert invalid data into the vehicle network, causing confusion in the functionality of legitimate Electronic Control Units (ECUs).
- Sniffing Attack: When a legitimate node transmits frames on the CAN bus without encryption, malicious attackers can eavesdrop on the frames.
- Replay Attack: Malicious attackers can capture frames transmitted in plaintext from an ECU responsible for specific critical functions (e.g., engine shutdown, brake operation) and resend the same frame to a node with a higher priority CAN ID during vehicle operation.
3. Related work
4. LSTM-Autoencoder based CAN IDS
4.1. Time Interval Sequence Extractor
4.2. Hamming Distance Sequence Extractor
4.3. LSTM-Autoencoder
4.4. Anomaly Detector
5. Evaluation
5.1. Dataset description and experimental environment
5.2. Performance metrics
5.3. Anomaly detection accuracy
6. Discussion
Author Contributions
Funding
Acknowledgments
Conflicts of Interest
References
- Leen, G.; Heffernan, D. Expanding automotive electronic systems. Computer 2002, 35, 88-93. [CrossRef]
- Huang, S. C.; Chen, B. H.; Chou, S. K.; Hwang, J. N.; Lee, K. H. Smart car [application notes], IEEE Computational Intelligence Magazine 2016, 11, 46-58. [CrossRef]
- HPL, S. C. Introduction to the controller area network (CAN). Application Report SLOA101 2002, 1-17.
- Carsten, P.; Andel, T. R.; Yampolskiy, M.; McDonald, J. T. In-vehicle networks: Attacks, vulnerabilities, and proposed solutions. In Proceedings of the 10th Annual Cyber and Information Security Research Conference, pp. 1-8.
- Koscher, K.; Czeskis, A.; Roesner, F.; Patel, S.; Kohno, T.; Checkoway, S.; Savage, S. Experimental security analysis of a modern automobile, In Proceedings of the 2010 IEEE symposium on security and privacy, pp. 447-462. IEEE.
- Hoppe, T.; Dittman, J. Sniffing/Replay Attacks on CAN Buses: A simulated attack on the electric window lift classified using an adapted CERT taxonomy. In Proceedings of the 2nd workshop on embedded systems security (WESS), pp. 1-6.
- Checkoway, S.; McCoy, D.; Kantor, B.; Anderson, D.; Shacham, H.; Savage, S.; Kohno, T. Comprehensive experimental analyses of automotive attack surfaces. In Proceedings of the 2011 USENIX security symposium pp. 2021, pp. 447-462.
- Miller, C.; Valasek, C. (2015). Remote exploitation of an unaltered passenger vehicle. In Proceedings of the 2015 Black Hat, USA, 2015, pp. 1-91.
- Sun, H.; Chen, M.; Weng, J.; Liu, Z.; Geng, G. Anomaly detection for in-vehicle network using CNN-LSTM with attention mechanism. IEEE Transactions on Vehicular Technology 2021, 70, pp. 10880-10893. [CrossRef]
- Song, H. M.; Kim, H. R.; Kim, H. K. Intrusion detection system based on the analysis of time intervals of CAN messages for in-vehicle network. In Proceedings of the 2016 international conference on information networking (ICOIN), pp. 63-68.
- Wang, Q.; Lu, Z.; Qu, G. (2018, September). An entropy analysis based intrusion detection system for controller area network in vehicles. In Proceedings of the 31st IEEE International System-on-Chip Conference (SOCC), pp. 90-95.
- Olufowobi, H.; Young, C.; Zambreno, J.; Bloom, G. SAIDuCANT: Specification-based automotive intrusion detection using controller area network (CAN) timing. IEEE Transactions on Vehicular Technology 2019, 2, pp. 1484-1494. [CrossRef]
- Sunny, J.; Sankaran, S.; Saraswat, V. A hybrid approach for fast anomaly detection in controller area networks. In Proceedings of the 2020 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS), pp. 1-6.
- Stabili, D.; Marchetti, M.; Colajanni, M. Detecting attacks to internal vehicle networks through Hamming distance. In Proceedings of the 2017 AEIT International Annual Conference, pp. 1-6.
- Murvay, P. S.; Groza, B. Source identification using signal characteristics in controller area networks. IEEE Signal Processing Letters 2014, 4, pp. 395-399. [CrossRef]
- Cho, K. T.; Shin, K. G. Fingerprinting electronic control units for vehicle intrusion detection. In Proceedings of the 2016 USENIX Security Symposium, 40, pp. 911-927.
- Hossain, M. D.; Inoue, H.; Ochiai, H.; Fall, D.; Kadobayashi, Y. (2020, July). Long short-term memory-based intrusion detection system for in-vehicle controller area network bus. In 2020 IEEE 44th Annual Computers, Software, and Applications Conference (COMPSAC) (pp. 10-17). IEEE.
- Derhab, A.; Belaoued, M.; Mohiuddin, I.; Kurniawan, F.; Khan, M. K. Histogram-based intrusion detection and filtering framework for secure and safe in-vehicle networks. IEEE Transactions on Intelligent Transportation Systems 2021, 3, pp. 2366-2379. [CrossRef]
- Sagong, S. U.; Ying, X.; Poovendran, R.; Bushnell, L. Exploring attack surfaces of voltage-based intrusion detection systems in controller area networks. In Proceedings of the 2018 ESCAR Conference, pp. 1-13.
- Müter, M.; Asaj, N. Entropy-based anomaly detection for in-vehicle networks. In Proceedings of the 2011 IEEE Intelligent Vehicles Symposium, pp. 1110-1115.
- Han, M. L.; Kwak, B. I.; Kim, H. K. Anomaly intrusion detection method for vehicular networks based on survival analysis. Vehicular communications 2018, 14, 52-63. [CrossRef]




| ID | DLC | Data Payload | |||||||
|---|---|---|---|---|---|---|---|---|---|
| 316 | 8 | 5 | 1F | 84 | 9 | 1F | 1D | 0 | 7B |
| 316 | 8 | 5 | 1E | 84 | 9 | 1E | 1D | 0 | 7B |
| 316 | 8 | 5 | 1E | 88 | 9 | 1E | 1D | 0 | 7B |
| 316 | 8 | 5 | 1F | 88 | 9 | 1F | 1D | 0 | 7B |
| 316 | 8 | 5 | 1E | 7C | 9 | 1E | 1D | 0 | 7B |
| 316 | 8 | 5 | 1F | 7C | 9 | 1F | 1D | 0 | 7B |
| 316 | 8 | 5 | 1F | 70 | 9 | 1F | 1D | 0 | 7B |
| 316 | 8 | 5 | 1F | 70 | 9 | 1F | 1D | 0 | 7B |
| 316 | 8 | 5 | 1F | 70 | 9 | 1F | 1D | 0 | 7B |
| ID | DLC | Data Payload | |||||||
|---|---|---|---|---|---|---|---|---|---|
| 316 | 8 | 8 | 5 | 1E | 7C | 9 | 1E | 1D | 0 |
| 316 | 8 | 8 | 5 | 1F | 7C | 9 | 1F | 1D | 0 |
| 316 | 8 | 8 | 5 | 1F | 70 | 9 | 1F | 1D | 0 |
| 316 | 8 | 8 | 45 | 29 | 24 | FF | 29 | 24 | 0 |
| 316 | 8 | 8 | 45 | 29 | 24 | FF | 29 | 24 | 0 |
| 316 | 8 | 8 | 5 | 1F | 84 | 9 | 1F | 1D | 0 |
| 316 | 8 | 8 | 45 | 29 | 24 | FF | 29 | 24 | 0 |
| 316 | 8 | 8 | 5 | 1E | 84 | 9 | 1E | 1D | 0 |
| 316 | 8 | 8 | 45 | 29 | 24 | FF | 29 | 24 | 0 |
| Layer | Activation | Dropout rate | Output | Others | |
|---|---|---|---|---|---|
| Encoder | LSTM | Tanh/Sigmoid | - | (Timestep, 128) | Optimizer: Adaptive Moment Estimation |
| LSTM | Tanh/Sigmoid | 0.25 | (1,64) | ||
| Repeat vector | - | - | (Timestep, 64) | ||
| Decoder | LSTM | Tanh/Sigmoid | - | (Timestep,64) | Loss: Mean Squared Error |
| LSTM | Tanh/Sigmoid | - | (Timestep,128) | ||
| Fully-connected | Identity | 0.25 | (Timestep, # of IDs) | ||
| Data Type | # of Normal Frames | # of Abnormal Frames |
|---|---|---|
| Normal set | 117,173 | 0 |
| Abnormal set | 116,677 | 15,974 |
| Feature | ID | TN | FP | FN | TP | Precision | Recall | F1 score | Accuracy |
|---|---|---|---|---|---|---|---|---|---|
| Time interval | 0x316 | 5,941 | 2 | 0 | 13,876 | 0.99 | 1 | 0.99 | 0.99 |
| 0x43F | 5,939 | 14 | 3 | 13,873 | 0.99 | 0.99 | 0.99 | 0.99 | |
| Hamming distance | 0x316 | 5,925 | 18 | 4563 | 9,313 | 0.99 | 0.67 | 0.80 | 0.70 |
| 0x43F | 5,694 | 249 | 3212 | 10,664 | 0.98 | 0.77 | 0.86 | 0.78 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2023 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).