A Hybrid Intrusion Detection System for for In-Vehicle CAN Bus.

Shuhan Wu,Zikai Wang,Yuhua Xu,Wei Sun
DOI: https://doi.org/10.1109/iccc55456.2022.9880746
2022-01-01
Abstract:Intrusion detection on the Controller Area Network (CAN) is aimed for detecting attacks from external interfaces of smart cars. Conventional detection methods judge the frames with fixed time thresholds determined by the range of a single interval. Due to the differences between statistical properties of training datasets and real vehicle data, the result may not attain a good balance in terms of precision and recall. To address the problem, we propose the adjacent interval-based detection (AID) method. The key insight of this method is determining the legitimate range based on two adjacent intervals that meet specific fluctuation amplitude. Furthermore, to improve the low recall under some specific forms of attack, a hybrid intrusion detection system (IDS) consists of the AID method, information entropy detection, and relative distance detection is proposed. Experiments on real vehicle datasets demonstrate that our system outperforms the conventional method.
What problem does this paper attempt to address?