仅靠交通流数据就能识别红绿灯被恶意操控的网络攻击。
Machine Learning for Cyber-Attack Identification from Traffic Flows
- 用真实交通数据模拟攻击,通过流量统计检测异常
- 模型准确率达85%,关键指标为占用率、拥堵长度和停车时长
- 适合交通安防与智能网联汽车安全研究者参考
本文通过在佛罗里达州代托纳比奇的交通控制系统中使用Raspberry Pi虚拟机、OPNSense防火墙、SUMO交通仿真及Metasploit框架进行网络攻击模拟,研究仅通过分析交通流模式能否识别攻击。重点关注攻击者随机使繁忙路口红绿灯全绿或全红的情形。尽管面临数据不平衡和交通模式重叠的挑战,最佳模型在仅依赖交通流统计信息的情况下仍实现85%的入侵检测准确率。成功检测的关键指标包括占有率、拥堵长度和停驶时长。
原文摘要 · Abstract (English)
This paper presents our simulation of cyber-attacks and detection strategies on the traffic control system in Daytona Beach, FL. using Raspberry Pi virtual machines and the OPNSense firewall, along with traffic dynamics from SUMO and exploitation via the Metasploit framework. We try to answer the research questions: are we able to identify cyber attacks by only analyzing traffic flow patterns. In this research, the cyber attacks are focused particularly when lights are randomly turned all green or red at busy intersections by adversarial attackers. Despite challenges stemming from imbalanced data and overlapping traffic patterns, our best model shows 85\% accuracy when detecting intrusions purely using traffic flow statistics. Key indicators for successful detection included occupancy, jam length, and halting durations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。