网络与信息安全学报 ›› 2020, Vol. 6 ›› Issue (1): 27-37.doi: 10.11959/j.issn.2096-109x.2020005

• 学术论文 • 上一篇    下一篇

基于通信特征的CAN总线泛洪攻击检测方法

季一木1,2,3,4,焦志鹏1,3(),刘尚东1,2,3,4,吴飞3,5,孙静1,3,王娜1,3,陈治宇1,3,毕强1,3,田鹏浩1,3   

  1. 1 南京邮电大学计算机学院,江苏 南京 210023
    2 南京邮电大学江苏省无线传感网高技术研究重点实验室,江苏 南京 210023
    3 南京邮电大学高性能计算与大数据处理研究所,江苏 南京 210023
    4 南京邮电大学高性能计算与智能处理工程研究中心,江苏 南京 210023;5.南京邮电大学自动化学院,江苏 南京 210023
    5 南京邮电大学自动化学院,江苏 南京 210023
  • 修回日期:2019-07-29 出版日期:2020-02-15 发布日期:2020-03-23
  • 作者简介:季一木(1978– ),男,江苏南京人,南京邮电大学教授、博士生导师,主要研究方向为 P2P 网络、云计算和大数据安全等|焦志鹏(1994– ),男,江苏淮安人,南京邮电大学硕士生,主要研究方向为总线安全|刘尚东(1979– ),男,甘肃永靖人,南京邮电大学讲师,主要研究方向为网络行为分析,大数据处理等|吴飞(1989– ),男,江苏常州人,博士,南京邮电大学讲师,主要研究方向为人工智能、模式识别|孙静(1993– ),女,江苏南京人,南京邮电大学博士生,主要研究方向为机器学习|王娜(1995– ),女,安徽芜湖人,南京邮电大学硕士生,主要研究方向为计算机视觉|陈治宇(1994– ),男,江苏徐州人,南京邮电大学硕士生,主要研究方向为视觉与激光雷达的传感器融合|毕强(1995– ),男,江苏宿迁人,南京邮电大学硕士生,主要研究方向为计算机视觉|田鹏浩(1996– ),男,江苏连云港人,南京邮电大学硕士生,主要研究方向为路径规划
  • 基金资助:
    国家重点研发计划基金资助项目(2017YFB1401302);国家重点研发计划基金资助项目(2017YFB0202200);国家自然科学基金资助项目(61572260);国家自然科学基金资助项目(61872196);江苏省自然科学基金优秀青年基金资助项目(BK20170100);江苏省重点研发计划基金资助项目(BE2017166)

CAN bus flood attack detection based on communication characteristics

Yimu JI1,2,3,4,Zhipeng JIAO1,3(),Shangdong LIU1,2,3,4,Fei WU3,5,Jing SUN1,3,Na WANG1,3,Zhiyu CHEN1,3,Qiang BI1,3,Penghao TIAN1,3   

  1. 1 School of Computer Science,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    2 Jiangsu Key Laboratory of High-Tech Research on Wireless Sensor Networks,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    3 Institute of High Performance Computing and Big Data Processing,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    4 Research Center for High Performance Computing and Intelligent Processing Engineering,Nanjing University of Posts and Telecommunications,Nanjing 210023,China;5.School of Automation,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    5 School of Automation,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
  • Revised:2019-07-29 Online:2020-02-15 Published:2020-03-23
  • Supported by:
    The National Key R&D Program of China(2017YFB1401302);The National Key R&D Program of China(2017YFB0202200);The National Natural Science Foundation of China(61572260);The National Natural Science Foundation of China(61872196);The Jiangsu Natural Science Foundation Excellent Youth Fund Project(BK20170100);The Jiangsu Provincial Key R&D Program(BE2017166)

摘要:

CAN由于其突出的可靠性和灵活性,已成为当代汽车应用最广泛的现场总线。但是标准CAN协议没有提供足够的安全措施,易遭受窃听、重放、泛洪、拒绝服务攻击。为了有效检测 CAN 总线是否遭受到攻击,并在遭受泛洪攻击时将恶意报文滤除。对车载 CAN 总线报文通信特征进行了分析,提出一种入侵检测方法,该方法可以有效进行入侵检测、恶意报文滤除。通过实验验证,该方法可以100%检测出CAN总线是否遭受攻击,恶意报文过滤的准确率可达99%以上。

关键词: CAN总线, 通信特征, 入侵检测, 恶意报文过滤

Abstract:

CAN has become the most extensive fieldbus for contemporary automotive applications due to its outstanding reliability and flexibility.However,the standard CAN protocol does not provide sufficient security measures and is vulnerable to eavesdropping,replay,flooding,and denial of service attacks.In order to effectively detect whether the CAN bus is attacked,and to filter malicious messages when subjected to flooding attacks.The characteristics of vehicle CAN bus message communication were analyzed,and an intrusion detection method was proposed,which could effectively perform intrusion detection and malicious message filtering.Through experimental verification,the method can detect whether the CAN bus is attacked by 100%,and the accuracy of malicious packet filtering can reach over 99%.

Key words: CAN bus, communication characteristics, intrusion detection, malicious message filtering

中图分类号: 

No Suggested Reading articles found!