The Controller Area Network (CAN) bus serves as a standard protocol for facilitating communication among various electronic control units (ECUs) within contemporary vehicles. However, it has been demonstrated that the CAN bus is susceptible to remote attacks, which pose risks to the vehicle's safety and functionality. To tackle this concern, researchers have introduced intrusion detection systems (IDSs) to identify and thwart such attacks. In this paper, we present an innovative approach to intruder detection within the CAN bus, leveraging Graph Convolutional Network (GCN) techniques as introduced by Zhang, Tong, Xu, and Maciejewski in 2019. By harnessing the capabilities of deep learning, we aim to enhance attack detection accuracy while minimizing the requirement for manual feature engineering. Our experimental findings substantiate that the proposed GCN-based method surpasses existing IDSs in terms of accuracy, precision, and recall. Additionally, our approach demonstrates efficacy in detecting mixed attacks, which are more challenging to identify than single attacks. Furthermore, it reduces the necessity for extensive feature engineering and is particularly well-suited for real-time detection systems. To the best of our knowledge, this represents the pioneering application of GCN to CAN data for intrusion detection. Our proposed approach holds significant potential in fortifying the security and safety of modern vehicles, safeguarding against attacks and preventing them from undermining vehicle functionality.
翻译:控制器局域网(CAN)总线作为现代车辆中各类电子控制单元(ECU)间通信的标准协议。然而,研究表明CAN总线易受远程攻击,对车辆安全性和功能性构成威胁。为解决这一问题,研究人员引入了入侵检测系统(IDS)以识别和抵御此类攻击。本文提出一种创新的CAN总线入侵检测方法,利用张、童、徐及Maciejewski于2019年提出的图卷积网络(GCN)技术。通过发挥深度学习的能力,我们旨在提升攻击检测精度,同时最大限度减少对人工特征工程的依赖。实验结果证实,所提出的基于GCN的方法在准确率、精确率和召回率方面均优于现有IDS。此外,该方法在检测混合攻击(其难度高于单一攻击)方面展现出有效性,并减少了大量特征工程需求,特别适用于实时检测系统。据我们所知,这是首次将GCN应用于CAN数据进行入侵检测。本研究提出的方法在强化现代车辆安全防御、抵御攻击并防止其破坏车辆功能方面具有重要潜力。