Suricata-based SOME/IP intrusion detection system design and implementation
Shan Ding, yuwei cao, raotao deng · 2024
As the automotive industry continues to evolve towards electrification, interconnectivity, intellectualization, and sharing, the electronic and electrical architecture within vehicles is increasingly integrating with cloud-based systems. Despite its numerous advantages, SOME/IP, a protocol widely employed in vehicular network systems, is not without its security risks. This paper presents the design of an IDS for SOME/IP based on Suricata, capable of identifying and parsing SOME/IP traffic, scrutinizing various fields, and generating alerts in response to anomalous traffic patterns. Experimental testing was conducted to evaluate the system’s ability to detect replay attacks, header anomalies, and SOME/IP-SD feature anomalies. Results indicate that the proposed intrusion detection system can effectively identify these types of attacks, thereby enhancing the security of SOME/IP communications within vehicular environments.