首页> 外文会议>SAE Intelligent and Connected Vehicles Symposium >Research on CAN Network Security Aspects and Intrusion Detection Design
【24h】

Research on CAN Network Security Aspects and Intrusion Detection Design

机译:CAN网络安全方面和入侵检测设计研究

获取原文

摘要

With the rapid development of vehicle intelligent and networking technology, the IT security of automotive systems becomes an important area of research. In addition to the basic vehicle control, intelligent advanced driver assistance systems, infotainment systems will all exchange data with in-vehicle network. Unfortunately, current communication network protocols, including Controller Area Network (CAN), FlexRay, MOST, and LIN have no security services, such as authentication or encryption, etc. Therefore, the vehicle are unprotected against malicious attacks. Since CAN bus is actually the most widely used field bus for in-vehicle communications in current automobiles, the security aspects of CAN bus is focused on. Based on the analysis of the current research status of CAN bus network security, this paper summarizes the CAN bus potential security vulnerabilities and the attack means. Aiming at flood, spoof, drop, replay and modify attacks of CAN bus, an in-vehicle intrusion detection system is designed consisting of a network interface & analysis module, an intrusion detection module based on Adaptive-Network-based Fuzzy Inference System (ANFIS) and a feature database. In order to validate the efficiency of the proposed intrusion detection system, the experiment is setup in the real environment of electric vehicle, in which the attack model and the intrusion detection system are mainly implemented in an emulated gateway, and the attacks are mounting through OBD-II port to the network of the electric vehicle. Through several experiment of attacks, the results show that the designed system for network intrusion detection can effectively detect the abnormal behavior of CAN bus network.
机译:随着汽车智能和网络技术的快速发展,汽车系统的IT安全成为一个重要的研究领域。除了基本的车辆控制,智能高级驾驶员辅助系统外,信息娱乐系统将所有与车载网络交换数据。不幸的是,当前通信网络协议,包括控制器区域网络(CAN),FlexRay,大多数和LIN都没有安全服务,例如认证或加密等,因此,车辆无法反对恶意攻击。由于CAN总线实际上是最广泛使用的现场总线用于当前汽车的车载通信,CAN总线的安全方面集中在上面。根据分析CAN总线网络安全的当前研究现状,总结了CAN总线潜在安全漏洞和攻击手段。针对CAN总线的洪水,欺骗,滴,重放和修改攻击,车载入侵检测系统是由网络接口​​和分析模块的基于自适应网络的模糊推理系统(ANFIS)的入侵检测模块组成)和一个特征数据库。为了验证所提出的入侵检测系统的效率,实验是在电动车辆的真实环境中设置的,其中攻击模型和入侵检测系统主要在模拟网关中实现,并且攻击通过OBD安装-ii端口到电动车辆的网络。通过几个攻击实验,结果表明,网络入侵检测设计系统可以有效地检测CAN总线网络的异常行为。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号