Search NASAโŒ• Search

DOE OSTI ยท code-134139

Using Signal Clustering Similarity for Detecting CAN Masquerade Attacks

Abstract

The computer code assumes that time series representing the physical signals of the vehicle have been extracted from the CAN bus. The main input of the computer code is the multivariate time series representation of the signals in the CAN bus. The computer code cluster these time series using agglomerative hierarchical clustering from benign and attack datasets. Based on this, it generates probability distributions from the similarity of the obtained clusters based in each scenario---benign and attack---using the CluSim method (https://github.com/Hoosier-Clusters/clusim). Finally, it compares how a new data collection compares with the previous distribution to provide and probability score for an intrusion.

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Moriano, Pablo. 2024-07-10. Using Signal Clustering Similarity for Detecting CAN Masquerade Attacks. https://doi.org/10.11578/dc.20240710.1

Cite the original work for its findings. Save a collection to share your selection of sources.