2023
DOI: 10.1109/jiot.2023.3303271
|View full text |Cite
|
Sign up to set email alerts
|

CANShield: Deep-Learning-Based Intrusion Detection Framework for Controller Area Networks at the Signal Level

Abstract: Modern vehicles rely on a fleet of electronic control units (ECUs) connected through controller area network (CAN) buses for critical vehicular control. With the expansion of advanced connectivity features in automobiles and the elevated risks of internal system exposure, the CAN bus is increasingly prone to intrusions and injection attacks. As ordinary injection attacks disrupt the typical timing properties of the CAN data stream, rule-based intrusion detection systems (IDS) can easily detect them. However, a… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2023
2023
2025
2025

Publication Types

Select...
4
1
1

Relationship

1
5

Authors

Journals

citations
Cited by 12 publications
(4 citation statements)
references
References 66 publications
0
4
0
Order By: Relevance
“…Frequency/Timing-Based: Regards the timing or sequencing of arbitration IDs [17,[19][20][21][22][23] Payload-Based: Considers the data frame (message contents) as a string of bits, without explicitly recovering the signals these bits represent [16,[24][25][26][27][28][29][30] Signal-Based: Requires first decoding raw data field bits into constituent signals, and uses time series' of signal values as inputs [5,17,[31][32][33][34][35][36][37] Physical Side-Channel: Uses physical layer attributes (e.g., voltage) [15,[38][39][40] Other: Includes works that do not fall into the above categories (e.g., using rules to guarantee specific characteristics of the CAN messages are followed [41,42]).…”
Section: The Growth and State Of Can Ids Researchmentioning
confidence: 99%
See 3 more Smart Citations
“…Frequency/Timing-Based: Regards the timing or sequencing of arbitration IDs [17,[19][20][21][22][23] Payload-Based: Considers the data frame (message contents) as a string of bits, without explicitly recovering the signals these bits represent [16,[24][25][26][27][28][29][30] Signal-Based: Requires first decoding raw data field bits into constituent signals, and uses time series' of signal values as inputs [5,17,[31][32][33][34][35][36][37] Physical Side-Channel: Uses physical layer attributes (e.g., voltage) [15,[38][39][40] Other: Includes works that do not fall into the above categories (e.g., using rules to guarantee specific characteristics of the CAN messages are followed [41,42]).…”
Section: The Growth and State Of Can Ids Researchmentioning
confidence: 99%
“…Another key aspect of introducing the research community to the ROAD dataset is that it provides a quality platform to test novel IDS architectures. In [37,[71][72][73][74][75][76][77][78], researchers use the ROAD dataset for evaluation purposes from a novel IDS method. Jin et al combine oversampling, outlier detection, and metric learning for intrusion detection and evaluate their model on ROAD (and other datasets) [71].…”
Section: Plos Onementioning
confidence: 99%
See 2 more Smart Citations