arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

汽车CAN网络无监督入侵检测的行为残差化方法

Behavioral Residualization for Unsupervised Intrusion Detection in Automotive CAN Networks

Chandan Hegde, Mukundh R Reddy

arXiv 2608.05548首次发表:更新:

AI 中文总结

针对汽车CAN网络现有入侵检测方法在攻击者复用合法仲裁ID时失效的问题,提出每ID行为残差化表示,经多检测器和数据集验证,可有效提升无监督入侵检测性能,但存在新颖ID泛洪和跨ID模糊测试的局限性。

AI 中文摘要

现代车辆依赖控制器局域网(CAN)总线,其设计优先考虑低成本和实时性,但未提供消息认证或加密。因此,具有物理或远程访问权限的攻击者可以注入任意帧,使得入侵检测成为重要的纵深防御机制。已发表的大多数CAN入侵检测系统依赖基于存在的特征,例如新颖的仲裁ID、固定的有效载荷字节或异常的DLC值。这些特征在包含易区分攻击的公共数据集上表现良好,但当攻击者复用合法仲裁ID时会失效。我们提出了针对CAN的每ID行为残差化方法,该方法从滑动窗口中提取14个时间、协议和有效载荷特征,并将其相对于每个仲裁ID的正常基线进行残差化。我们的核心主张是,该表示而非任何单个检测器驱动了性能提升。在6种无监督检测器和2个数据集上,残差化在大多数评估中提升了平均F1值(在HCRL数据集的5个随机种子下为21/24,在ROAD数据集下为30/36)。在攻击复用合法ID的更贴近实际的ROAD数据集上,该表示针对定向信号操纵攻击实现了召回率≥0.99和高ROC-AUC。我们明确量化了两个局限性:新颖ID泛洪(HCRL拒绝服务攻击,F1=0.02)和跨ID模糊测试(ROAD,F1=0.27),定义了所提表示的实测覆盖边界。

英文摘要

Modern vehicles rely on the Controller Area Network (CAN) bus, whose design prioritizes low cost and real-time performance but provides no message authentication or encryption. An attacker with physical or remote access can therefore inject arbitrary frames, making intrusion detection an important defense-in-depth mechanism. Most published CAN intrusion detection systems rely on presence-based features, such as novel arbitration IDs, frozen payload bytes, or anomalous DLC values. These features perform well on public datasets containing easily separable attacks but fail when attackers reuse legitimate arbitration IDs. We present per-ID behavioral residualization, a CAN-specific representation that extracts fourteen temporal, protocol, and payload features from sliding windows and residualizes them against each arbitration ID's normal baseline. Our central claim is that this representation, rather than any individual detector, drives the performance gains. Across six unsupervised detectors and two datasets, residualization improves mean F1 in the majority of evaluations (21/24 on HCRL and 30/36 on ROAD across five seeds). On the more realistic ROAD dataset, where attacks reuse legitimate IDs, the representation achieves recall >= 0.99 with high ROC-AUC on targeted signal-manipulation attacks. Two limitations are explicitly quantified: novel-ID flooding (HCRL DoS, F1 = 0.02) and cross-ID fuzzing (ROAD, F1 = 0.27), defining the measured coverage boundary of the proposed representation.

Comments9 pages, 5 figures, 8 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑