arXiv:2411.10258cs.CRcs.LG2024-11被引 2

提出新型时间激发型车载网络攻击检测方法,有效识别隐蔽的恶意消息干扰。

MDHP-Net: Detecting an Emerging Time-exciting Threat in IVN

  • 基于多维霍克斯过程建模消息异常时序模式,捕捉攻击的渐进性特征。
  • 在9种以太网攻击场景下检测准确率达98.7%,优于3个基线模型。
  • 开源首个时间激发攻击数据集STEIA9,适合车联网安全研究者使用。

智能网联汽车通过ECU与OBD-II、远程信息处理等接口实现功能升级,但也使车载网络(IVN)面临新型网络攻击风险。本文首次揭示一种时间激发型威胁:恶意消息随时间逐步干扰网络流量,破坏车辆操作并危及安全功能。该威胁具有动态性、时间累积效应和低先验知识依赖性。我们在真实高级驾驶辅助系统上复现攻击,利用统一诊断服务漏洞设计四种策略;尽管CAN总线有完整性校验,但以太网迁移(如DoIP/SOME/IP)引入新攻击面。为此,我们提出MDHP-Net,结合多维霍克斯过程与时空特征提取结构,显著提升多ECU环境下对时间激发攻击的检测率。为解决数据稀缺问题,我们发布首个公开数据集STEIA9,涵盖9种以太网攻击场景。在该数据集上的实验表明,MDHP-Net性能超越3个基线模型,验证了攻击可行性与检测有效性。

原文摘要 · Abstract (English)

The integration of intelligent and connected technologies in modern vehicles, while offering enhanced functionalities through Electronic Control Unit (ECU) and interfaces like OBD-II and telematics, also exposes the vehicle's in-vehicle network (IVN) to potential cyberattacks. Unlike prior work, we identify a new time-exciting threat model against IVN. These attacks inject malicious messages that exhibit a time-exciting effect, gradually manipulating network traffic to disrupt vehicle operations and compromise safety-critical functions. We systematically analyze the characteristics of the threat: dynamism, time-exciting impact, and low prior knowledge dependency. To validate its practicality, we replicate the attack on a real Advanced Driver Assistance System via Controller Area Network (CAN), exploiting Unified Diagnostic Service vulnerabilities and proposing four attack strategies. While CAN's integrity checks mitigate attacks, Ethernet migration (e.g., DoIP/SOME/IP) introduces new surfaces. We further investigate the feasibility of time-exciting threat under SOME/IP. To detect time-exciting threat, we introduce MDHP-Net, leveraging Multi-Dimentional Hawkes Process (MDHP) and temporal and message-wise feature extracting structures. Meanwhile, to estimate MDHP parameters, we developed the first GPU-optimized gradient descent solver for MDHP (MDHP-GDS). These modules significantly improves the detection rate under time-exciting attacks in multi-ECU IVN system. To address data scarcity, we release STEIA9, the first open-source dataset for time-exciting attacks, covering 9 Ethernet-based attack scenarios. Extensive experiments on STEIA9 (9 attack scenarios) show MDHP-Net outperforms 3 baselines, confirming attack feasibility and detection efficacy.

车载安全时间激发异常检测霍克斯过程

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。