Unsupervised real-time anomaly detection system for vehicular network security
Chundong Wang, Zhentang Zhao, Likun Zhu, Zheli Liu, Xiaochun Cheng · Research Briefs on Information and Communication Technology Evolution · 2017
An unsupervised machine learning based anomaly detection system by hierarchical temporal memory(HTM) based learning algorithm is proposed to enhance the security of vehicular network. Firstly,the frequency distribution of Controller Area Network (CAN) packets is extracted as a meaningfulfeature to detect attacks in the CAN traffic. Then the features of CAN packets are learned byHTM-based module to predict what it expects to happen next. Furthermore, a novel anomaly scoreis calculated to analyze the probability of each class to discriminate normal and attack status. Thesystem protects vehicles by monitoring the CAN bus to detect threats in real time, including detectinganomalies that might indicate a sophisticated adversary hiding in the vehicle’s systems. Finally, it isdemonstrated with experimental results that the proposed method can provide a real-time anomalydetection to the attack in vehicular network.