...
首页> 外文期刊>Pervasive and Mobile Computing >A holistic approach to power efficiency in a clock offset based Intrusion Detection Systems for Controller Area Networks
【24h】

A holistic approach to power efficiency in a clock offset based Intrusion Detection Systems for Controller Area Networks

机译:基于时钟偏移的基于控制器区域网络的入侵检测系统的电力效率的整体方法

获取原文
获取原文并翻译 | 示例
           

摘要

Controller Area Network (CAN) is an in-vehicle communication protocol, which provides an efficient and reliable communication link between Electronic Control Units (ECUs) in real time. Recent studies have shown that attackers can take remote control of the targeted vehicle by exploiting the vulnerabilities of the CAN protocol. Motivated by this fact, we propose an Intrusion Detection System (IDS), called Clock Offset-based IDS (COIDS), to monitor in-vehicle network activities to detect any intrusion. Precisely, COIDS measures and then exploits the clock offset of transmitter ECU's clock for fingerprinting ECU. COIDS next leverages the derived fingerprints to construct a baseline of ECU's normal clock behavior using an active learning technique. Based on the baseline of normal behavior, COIDS uses the Cumulative Sum method to detect any abnormal deviation in clock offset. Further, COIDS uses a sequential change-point detection technique to determine the exact time of intrusion. Generally, COIDS has to run on every ECU to monitor the network behavior. This can turn out to be a significant power overhead for a hardware-constrained ECU. Thus, we next develop a cooperative game model to optimize the active time duration of COIDS in an ECU. We performed exhaustive experiments on real world publicly available datasets primarily to assess the effectiveness of COIDS against a wide range of in-vehicle network attacks. Our results show that COIDS detects intrusions faster than the best performed IDS in the state-of-the-art. Further, the results show that our designed cooperative game model significantly reduces the power overhead of the ECU without compromising the performance. (C) 2021 Elsevier B.V. All rights reserved.
机译:控制器局域网(CAN)是一种车内通信协议,可在电子控制单元(ECU)之间实时提供高效可靠的通信链路。最近的研究表明,攻击者可以利用can协议的漏洞远程控制目标车辆。基于这一事实,我们提出了一种入侵检测系统(IDS),称为基于时钟偏移的入侵检测系统(COID),用于监控车内网络活动,以检测任何入侵。准确地说,COIDS测量并利用发射器ECU时钟的时钟偏移量对ECU进行指纹识别。COIDS接下来利用衍生指纹,使用主动学习技术构建ECU正常时钟行为的基线。基于正常行为的基线,COIDS使用累积和方法来检测时钟偏移中的任何异常偏差。此外,COIDS使用顺序变化点检测技术来确定入侵的确切时间。通常,COID必须在每个ECU上运行,以监控网络行为。对于硬件受限的ECU来说,这可能是一个巨大的电源开销。因此,我们接下来开发了一个合作博弈模型来优化ECU中COID的活动持续时间。我们在真实世界的公开数据集上进行了详尽的实验,主要是为了评估COID对各种车内网络攻击的有效性。我们的结果表明,COID比最先进的性能最好的ID检测入侵的速度更快。此外,结果表明,我们设计的合作博弈模型在不影响性能的情况下显著降低了ECU的功率开销。(c)2021爱思唯尔B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号