Detecting Message Modification Attacks on the CAN Bus with Temporal Convolutional Networks

Irina Chiscop, András Gazdag, Joost Bosman, Gergely Biczók

Abstract

Multiple attacks have shown that in-vehicle networks have vulnerabilities which can be exploited. Securing the Controller Area Network (CAN) for modern vehicles has become a necessary task for car manufacturers. Some attacks inject potentially large amount of fake messages into the CAN network; however, such attacks are relatively easy to detect. In more sophisticated attacks, the original messages are modified, making the detection a more complex problem. In this paper, we present a novel machine learning based intrusion detection method for CAN networks. We focus on detecting message modification attacks, which do not change the timing patterns of communications. Our proposed temporal convolutional network-based solution can learn the normal behavior of CAN signals and differentiate them from malicious ones. The method is evaluated on multiple CAN-bus message IDs from two public datasets including different types of attacks. Performance results show that our lightweight approach compares favorably to the state-of-the-art unsupervised learning approach, achieving similar or better accuracy for a wide range of scenarios with a significantly lower false positive rate.

Download


Paper Citation


in Harvard Style

Chiscop I., Gazdag A., Bosman J. and Biczók G. (2021). Detecting Message Modification Attacks on the CAN Bus with Temporal Convolutional Networks. In Proceedings of the 7th International Conference on Vehicle Technology and Intelligent Transport Systems - Volume 1: VEHITS, ISBN 978-989-758-513-5, pages 488-496. DOI: 10.5220/0010445504880496


in Bibtex Style

@conference{vehits21,
author={Irina Chiscop and András Gazdag and Joost Bosman and Gergely Biczók},
title={Detecting Message Modification Attacks on the CAN Bus with Temporal Convolutional Networks},
booktitle={Proceedings of the 7th International Conference on Vehicle Technology and Intelligent Transport Systems - Volume 1: VEHITS,},
year={2021},
pages={488-496},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010445504880496},
isbn={978-989-758-513-5},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 7th International Conference on Vehicle Technology and Intelligent Transport Systems - Volume 1: VEHITS,
TI - Detecting Message Modification Attacks on the CAN Bus with Temporal Convolutional Networks
SN - 978-989-758-513-5
AU - Chiscop I.
AU - Gazdag A.
AU - Bosman J.
AU - Biczók G.
PY - 2021
SP - 488
EP - 496
DO - 10.5220/0010445504880496