Illegal Intrusion Detection for In-Vehicle CAN Bus Based on Immunology Principle

被引:1
|
作者
Li, Xiaowei [1 ]
Liu, Feng [1 ]
Li, Defei [1 ]
Hu, Tianchi [1 ]
Han, Mu [1 ]
机构
[1] Jiangsu Univ, Sch Comp Sci & Commun Engn, Zhenjiang 212013, Jiangsu, Peoples R China
来源
SYMMETRY-BASEL | 2022年 / 14卷 / 08期
关键词
anomaly detection; enhanced DCA; CAN bus; in-vehicle network; DETECTION SYSTEM; NETWORKS;
D O I
10.3390/sym14081532
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
The controller area network (CAN) bus has become one of the most commonly used protocols in automotive networks. Some potential attackers inject malicious data packets into the CAN bus through external interfaces for implementing illegal operations (intrusion). Anomaly detection is a technique for network intrusion detection which can detect malicious data packs by comparing the normal data packets with incoming data packets obtained from the network traffic. The data of a normal network is in a symmetric and stable state, which will become asymmetric when compromised. Considering the in-vehicle network, the CAN bus is symmetrically similar to the immune system in terms of internal network structure and external invasion threats. In this work, we use an intrusion detection method based on the dendritic cell algorithm (DCA). However, existing studies suggest the use of optimization methods to improve the accuracy of classification algorithms, and the current optimization of the parameters of the detection method mostly relies on the manual tuning of the parameters, which is a large workload. In view of the above challenges, this paper proposes a new detection algorithm based on the particle swarm optimization algorithm (PSO) and gravitational search algorithm (GSA) to improve the dendritic cell algorithm (PSO-GSA-DCA). PSO-GSA-DCA achieves adaptive parameter tuning and improves detection accuracy by mixing optimization algorithms and using them to optimize the dendritic cell algorithm classifier. Additionally, DCA-based CAN message attribute matching rules (measured by information gain and standard deviation of CAN data) are proposed for matching the three input signals (PAMP, DS, SS) of the DCA. The experimental results show that our proposed scheme has a significant improvement in accuracy, which can reach 91.64%, and lower time loss compared with other correlation anomaly detection schemes. Our proposed method also enables adaptive tuning, which solves the problem that most models now rely on manual tuning.
引用
收藏
页数:19
相关论文
共 50 条
  • [41] Topology Verification Enabled Intrusion Detection for In-Vehicle CAN-FD Networks
    Yu, Tianqi
    Wang, Xianbin
    IEEE COMMUNICATIONS LETTERS, 2020, 24 (01) : 227 - 230
  • [42] Multi-Attack Intrusion Detection for In-Vehicle CAN-FD Messages
    Gao, Fei
    Liu, Jinshuo
    Liu, Yingqi
    Gao, Zhenhai
    Zhao, Rui
    SENSORS, 2024, 24 (11)
  • [43] Exploiting Temperature-Varied Voltage Fingerprints for In-vehicle CAN Intrusion Detection
    Li, Dong
    Tian, Miaoqing
    Jiang, Ruobing
    Yang, Ke
    PROCEEDINGS OF ACM TURING AWARD CELEBRATION CONFERENCE, ACM TURC 2021, 2021, : 116 - 120
  • [44] VNGuard: Intrusion Detection System for In-Vehicle Networks
    Aung, Yan Lin
    Wang, Shanshan
    Cheng, Wang
    Chattopadhyay, Sudipta
    Zhou, Jianying
    Cheng, Anyu
    INFORMATION SECURITY, ISC 2023, 2023, 14411 : 79 - 98
  • [45] MGA-IDS: Optimal feature subset selection for anomaly detection framework on in-vehicle networks-CAN bus based on genetic algorithm and intrusion detection approach
    Aksu, Dogukan
    Aydin, Muhammed Ali
    COMPUTERS & SECURITY, 2022, 118
  • [46] Universal Intrusion Detection System on In-Vehicle Network
    Islam, Md Rezanur
    Oh, Insu
    Yim, Kangbin
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2023, 2023, 177 : 78 - 85
  • [47] Attacker Identification and Intrusion Detection for In-Vehicle Networks
    Ning, Jing
    Wang, Jiadai
    Liu, Jiajia
    Kato, Nei
    IEEE COMMUNICATIONS LETTERS, 2019, 23 (11) : 1927 - 1930
  • [48] Detecting CAN overlapped voltage attacks with an improved voltage-based in-vehicle intrusion detection system
    Yin, Long
    Xu, Jian
    Wang, Chen
    Wang, Qiang
    Zhou, Fucai
    JOURNAL OF SYSTEMS ARCHITECTURE, 2023, 143
  • [49] Long Short-Term Memory-based Intrusion Detection System for In-Vehicle Controller Area Network Bus
    Hossain, Md Delwar
    Inoue, Hiroyuki
    Ochiai, Hideya
    Fall, Doudou
    Kadobayashi, Youki
    2020 IEEE 44TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2020), 2020, : 10 - 17
  • [50] Dynamic Voting based Explainable Intrusion Detection System for In-vehicle Network
    Mowla, Nishat, I
    Rosell, Joakim
    Vahidi, Arash
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 406 - +