SOME/IP Intrusion Detection using Sequential Models in Automotive Ethernet-based Networks

Natasha Alkhatib, Hadi Ghauch, Jean‐Luc Danger · HAL (Le Centre pour la Communication Scientifique Directe) · 2021

Intrusion Detection Systems are widely used to detect cyberattacks, especially a prone-to-attacks protocol such as SOME/IP, a standard protocol for service oriented communication in vehicles. However, few works have been developed to address this significant problem. In this paper, we have generated a dataset with normal and abnormal SOME/IP-based network traffic behavior, modeled a Deep Learning Based sequential Model to detect intrusions on SOME/IP and tuned the model's hyperparameters to get an optimum classifier in order to prove the efficiency of Deep Learning technology. Finally, our numerical results show that RNN and LSTM excel at predicting invehicle intrusions by achieving an accuracy of 99.31% and 92% respectively and low False Positive and Negative Rates.

Read the paper · More papers on PaperTik