<p>Securing in-vehicle communication networks, particularly the Controller Area Network (CAN) bus, is increasingly critical due to the growing threat of cyberattacks in connected vehicles. While recent Intrusion Detection Systems (IDS) have shown promising results, they often suffer from two key limitations: an overemphasis on CAN IDs while overlooking payload data, and limited validation using only publicly available datasets. To overcome these challenges, we propose a novel IDS framework that combines n-gram analysis and Word2Vec embeddings with a 1D Convolutional Neural Network (CNN) for robust anomaly detection. Unlike prior approaches, our method extracts sequential patterns from both the CAN ID and payload fields and converts them into dense vector representations using the Continuous Bag of Words model. These enriched features are then used to train a 1D CNN classifier capable of distinguishing between normal and malicious traffic. The framework is evaluated on three public datasets–Car Hacking, OTIDS, and Survival Analysis–as well as a real-world dataset&#xa0;(AutoCAN) that we collected from three OEM vehicles. The proposed IDS shows high effectiveness across public and real-world datasets, achieving up to 99.66% F1-score on the Car Hacking dataset, over 99.5% precision and recall on OTIDS, and 99.9% accuracy on most attacks in the Survival Analysis dataset. On the AutoCAN dataset, it reaches 99.16% accuracy in binary classification and over 99.3% in multiclass detection, accurately identifying DoS, fuzzy, spoofing, and replay attacks. These results highlight the IDS’s robustness, generalizability, and superior performance over existing state-of-the-art methods.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Detecting cyberattacks in CAN bus: a hybrid IDS with sequential feature learning and deep learning

  • Ritu Rai,
  • Jyoti Grover

摘要

Securing in-vehicle communication networks, particularly the Controller Area Network (CAN) bus, is increasingly critical due to the growing threat of cyberattacks in connected vehicles. While recent Intrusion Detection Systems (IDS) have shown promising results, they often suffer from two key limitations: an overemphasis on CAN IDs while overlooking payload data, and limited validation using only publicly available datasets. To overcome these challenges, we propose a novel IDS framework that combines n-gram analysis and Word2Vec embeddings with a 1D Convolutional Neural Network (CNN) for robust anomaly detection. Unlike prior approaches, our method extracts sequential patterns from both the CAN ID and payload fields and converts them into dense vector representations using the Continuous Bag of Words model. These enriched features are then used to train a 1D CNN classifier capable of distinguishing between normal and malicious traffic. The framework is evaluated on three public datasets–Car Hacking, OTIDS, and Survival Analysis–as well as a real-world dataset (AutoCAN) that we collected from three OEM vehicles. The proposed IDS shows high effectiveness across public and real-world datasets, achieving up to 99.66% F1-score on the Car Hacking dataset, over 99.5% precision and recall on OTIDS, and 99.9% accuracy on most attacks in the Survival Analysis dataset. On the AutoCAN dataset, it reaches 99.16% accuracy in binary classification and over 99.3% in multiclass detection, accurately identifying DoS, fuzzy, spoofing, and replay attacks. These results highlight the IDS’s robustness, generalizability, and superior performance over existing state-of-the-art methods.