arrow
返回

Detecting Masquerade Attacks in Controller Area Networks Using Graph Machine Learning

delete2025-01-01
delete0
PRE
AI
W
William Marfo
P
Pablo Moriano *
D
Deepak K. Tosh
S
Shirley Moore
DOI:10.1109/TIFS.2025.3636019delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Modern vehicles rely on a myriad of electronic control units (ECUs) interconnected via controller area networks (CANs) for critical operations. Despite their ubiquitous use and reliability, CANs are susceptible to sophisticated cyberattacks, particularly masquerade attacks, which inject false data that mimic legitimate messages at the expected frequency. These attacks pose severe risks such as unintended acceleration, brake deactivation, and rogue steering. Traditional intrusion detection systems (IDS) often struggle to detect these subtle intrusions due to their seamless integration into normal traffic. This paper introduces a novel framework for detecting masquerade attacks in the CAN bus using graph machine learning (ML). We hypothesize that the integration of shallow graph embeddings with time series features derived from CAN frames enhances the detection of masquerade attacks. We show that by representing CAN bus frames as message sequence graphs (MSGs) and enriching each node with contextual statistical attributes from time series, we can enhance detection capabilities across various attack patterns compared to using graph-based features only. Our method ensures a comprehensive and dynamic analysis of CAN frame interactions, improving robustness and efficiency. Extensive experiments on the ROAD dataset validate the effectiveness of our approach, demonstrating statistically significant improvements in the detection rates of masquerade attacks compared to a baseline that uses graph-based features only as confirmed by Mann-Whitney U and Kolmogorov-Smirnov tests (p < 0.05).
Keyword:
Accuracy
Controller area networks
Time series analysis
Roads
Training
Protocols
Fabrication
Computer crime
Suspensions (mechanical systems)
Payloads
intrusion detection systems
graph ML
masquerade attacks

期刊

IEEE Transactions on Information Forensics and Security 封面图
IEEE Transactions on Information Forensics and Security
IF:
8
论文数:
5.3K
被引数:
2.3W

机构

U
university of texas at el paso
学者数:
2.4K
论文数: 2.0K
被引数: 0
U
university of texas system
学者数:
18.5W
论文数: 15.6W
被引数: 210
引用论文

引用论文

Understanding and Using the Controller Area Network Communication Protocol
err
IF0
err2012-01-01
err0
PREAI
errMarco Di Natale; Haibo Zeng; Paolo Giusto; Arkadeb Ghosal
err分享
err收藏
unFlowS: An Unsupervised Construction Scheme of Flow Spectrum for Network Traffic Detection
err
IF0
err2025-01-01
err0
PREAI
errLuming Yang; Yongjun Wang; Lin Liu; Jun-Jie Huang; Jiangyong Shi; Shaojing Fu; Shize Guo
err分享
err收藏
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
CrySyS dataset of CAN traffic logs containing fabrication and masquerade attacks
err2023-12-15
err0
errOAAI
errAndrás Gazdag; Rudolf Ferenc; Levente Buttyán
err分享
err收藏
学者 查看更多内容