首页> 外文期刊>IEEE transactions on information forensics and security >Efficient Intrusion Detection With Bloom Filtering in Controller Area Networks
【24h】

Efficient Intrusion Detection With Bloom Filtering in Controller Area Networks

机译:控制器局域网中具有布隆过滤的高效入侵检测

获取原文
获取原文并翻译 | 示例

摘要

Due to its cost efficiency, the controller area network (CAN) is still the most wide-spread in-vehicle bus, and the numerous reported attacks demonstrate the urgency in designing new security solutions for CAN. In this paper, we propose an intrusion detection mechanism that takes advantage of Bloom filtering to test frame periodicity based on message identifiers and parts of the data-field which facilitates detection of potential replay or modification attacks. This proves to be an effective approach since most of the traffic from in-vehicle buses is cyclic in nature and the format of the data-field is fixed due to rigid signal allocation. Bloom filters provide an efficient time-memory tradeoff which is beneficial for the constrained resources of automotive grade controllers. We test the correctness of our approach and obtain good results on an industry-standard CANoe-based simulation for a J1939 commercial-vehicle bus and also on CAN with flexible data-rate traces obtained from a real-world high-end vehicle. The proposed filtering mechanism is straightforward to adapt for any other time-triggered in-vehicle bus, e.g., FlexRay, since it is built on time-driven characteristics.
机译:由于其成本效益,控制器局域网(CAN)仍然是最广泛的车载总线,据报道,大量攻击表明了为CAN设计新的安全解决方案的紧迫性。在本文中,我们提出了一种入侵检测机制,该机制利用布鲁姆过滤技术基于消息标识符和部分数据字段来测试帧周期性,从而有助于检测潜在的重放或修改攻击。事实证明,这是一种有效的方法,因为大多数车载总线的流量本质上都是循环的,并且由于信号分配严格,数据字段的格式是固定的。布隆过滤器提供了有效的时间记忆权衡,这对于汽车级控制器的资源有限很有帮助。我们测试了该方法的正确性,并在针对J1939商用车的基于行业标准CANoe的仿真上以及在从真实高端汽车获得的灵活数据速率轨迹的CAN上获得了良好的结果。所提出的滤波机制很容易适应任何其他时间触发的车载总线,例如FlexRay,因为它建立在时间驱动特性的基础上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号