Framework for Efficient Automated Alarm Analysis in Intelligent Connected Vehicles
摘要
As the degree of connectivity of intelligent connected vehicles continues to increase, the corresponding network attack surface continues to increase. Traditional Intrusion Detection Systems (IDS) generates massive alerts every day, which increases the workload of security analysts. Rule-based attack detection systems rely on expert knowledge and cannot detect new types of attacks. This paper proposes an automated rule mining architecture for massive alerts. Alerts are aggregated through data preprocessing, and then massive alerts are mined in parallel through a new parallel mining algorithm. The mined rules are organized and stored in the rule base, and then the rules are visualized to restore the attack path, which greatly improves the efficiency of rule generation. Although this work is aimed at smart connected cars, the proposed method is also applicable to traditional networks.