USENIX Security2023Top-tier venue
RIDAS: Real-time identification of attack sources on controller area networks
Jiwoo Shin, Hyunghoon Kim, Seyoung Lee, Wonsuk Choi, Dong Hoon Lee, Hyo Jin Jo
Abstract
Researchers have responded to various cyber attacks on controller area network (CAN) by studying technologies for identifying the source of an attack. However, existing attack source identification technologies have shown significantly lower accuracy depending on changes in the vehicle environment (temperature, humidity, battery level, etc.), or have proven to be circumvented by identification-aware attackers, or do not provide real-time identification. A real-time attack node identification technology that cannot be bypassed by an attacker while not being affected by changes in the vehicle environment is essential for cyber attack response technologies such as node isolation, security patch, digital forensics, etc. To meet this need, we propose a novel real-time attack node identification method, called RIDAS, which can identify the attack source by using the error handling rule of CAN. RIDAS injects bit errors into the abnormal messages that have been detected by an existing intrusion detection system (IDS). The source that sent the abnormal message become the error passive state defined in CAN in which it cannot send consecutive messages. RIDAS then sequentially inspects all electronic control units (ECU) and identifies the node in the error passive state by checking the priority reduction phenomenon that occurs in that state. Moreover, RIDAS address two challenging issues, identification robustness and identification errors. Our experimental results, conducted on both a CAN bus prototype and one real vehicle, have demonstrated that RIDAS can accurately identify an attack source while remaining unaffected by changes in the vehicle's environment. Additionally, RIDAS is able to deal with RIDAS-aware attackers.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dc293688-af4f-4a34-a339-d460d0fe00d2Builds on9
- Fingerprinting Electronic Control Units for Vehicle Intrusion DetectionKyong-Tak Cho, Kang G. ShinUSENIX Security 2016 · 524 citations
- Viden: Attacker Identification on In-Vehicle NetworksKyong-Tak Cho, Kang G. ShinCCS 2017 · 218 citations
- Scission: Signal Characteristic-Based Sender Identification and Intrusion Detection in Automotive NetworksMarcel Kneib, Christopher HuthCCS 2018 · 162 citations
- CANvas: Fast and Inexpensive Automotive Network MappingSekar Kulandaivel, Tushar Goyal, Arnav Kumar Agrawal, Vyas SekarUSENIX Security 2019 · 49 citations
- Exposing New Vulnerabilities of Error Handling Mechanism in CANKhaled Serag, Rohit Bhatia, Vireshwar Kumar, Z. Berkay Celik et al.USENIX Security 2021 · 30 citations
Related papers
- Evading Voltage-Based Intrusion Detection on Automotive CANRohit Bhatia, Vireshwar Kumar, Khaled Serag, Z. Berkay Celik et al.NDSS 2021
- EdgeTDC: On the Security of Time Difference of Arrival Measurements in CAN Bus SystemsMarc Roeschlin, Giovanni Camurati, Pascal Brunner, Mridula Singh et al.NDSS 2023
- Error Handling of In-vehicle Networks Makes Them VulnerableKyong-Tak Cho, Kang G. ShinCCS 2016 · 238 citations
- Models on the Move: Towards Feasible Embedded AI for Intrusion Detection on Vehicular CAN BusHe Xu, Di Wu, Yufeng Lu, Jiwu Lu et al.USENIX ATC 2024 · 4 citations
- Vulnerability of Controller Area Network to Schedule-Based AttacksSena Hounsinou, Mark Stidd, Uchenna Ezeobi, Habeeb Olufowobi et al.RTSS 2021 · 16 citations
