Chinese Journal of Network and Information Security ›› 2020, Vol. 6 ›› Issue (1): 27-37.doi: 10.11959/j.issn.2096-109x.2020005

• Papers • Previous Articles     Next Articles

CAN bus flood attack detection based on communication characteristics

Yimu JI1,2,3,4,Zhipeng JIAO1,3(),Shangdong LIU1,2,3,4,Fei WU3,5,Jing SUN1,3,Na WANG1,3,Zhiyu CHEN1,3,Qiang BI1,3,Penghao TIAN1,3   

  1. 1 School of Computer Science,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    2 Jiangsu Key Laboratory of High-Tech Research on Wireless Sensor Networks,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    3 Institute of High Performance Computing and Big Data Processing,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    4 Research Center for High Performance Computing and Intelligent Processing Engineering,Nanjing University of Posts and Telecommunications,Nanjing 210023,China;5.School of Automation,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
    5 School of Automation,Nanjing University of Posts and Telecommunications,Nanjing 210023,China
  • Revised:2019-07-29 Online:2020-02-15 Published:2020-03-23
  • Supported by:
    The National Key R&D Program of China(2017YFB1401302);The National Key R&D Program of China(2017YFB0202200);The National Natural Science Foundation of China(61572260);The National Natural Science Foundation of China(61872196);The Jiangsu Natural Science Foundation Excellent Youth Fund Project(BK20170100);The Jiangsu Provincial Key R&D Program(BE2017166)

Abstract:

CAN has become the most extensive fieldbus for contemporary automotive applications due to its outstanding reliability and flexibility.However,the standard CAN protocol does not provide sufficient security measures and is vulnerable to eavesdropping,replay,flooding,and denial of service attacks.In order to effectively detect whether the CAN bus is attacked,and to filter malicious messages when subjected to flooding attacks.The characteristics of vehicle CAN bus message communication were analyzed,and an intrusion detection method was proposed,which could effectively perform intrusion detection and malicious message filtering.Through experimental verification,the method can detect whether the CAN bus is attacked by 100%,and the accuracy of malicious packet filtering can reach over 99%.

Key words: CAN bus, communication characteristics, intrusion detection, malicious message filtering

CLC Number: 

No Suggested Reading articles found!