DOE OSTI ยท code-134139
Using Signal Clustering Similarity for Detecting CAN Masquerade Attacks
Abstract
The computer code assumes that time series representing the physical signals of the vehicle have been extracted from the CAN bus. The main input of the computer code is the multivariate time series representation of the signals in the CAN bus. The computer code cluster these time series using agglomerative hierarchical clustering from benign and attack datasets. Based on this, it generates probability distributions from the similarity of the obtained clusters based in each scenario---benign and attack---using the CluSim method (https://github.com/Hoosier-Clusters/clusim). Finally, it compares how a new data collection compares with the previous distribution to provide and probability score for an intrusion.
Keep this discovery
Explore connections, maps & timelines
Moriano, Pablo. 2024-07-10. Using Signal Clustering Similarity for Detecting CAN Masquerade Attacks. https://doi.org/10.11578/dc.20240710.1
Cite the original work for its findings. Save a collection to share your selection of sources.