Robust In-Vehicle Diagnostic-Based Intrusion Detection System
Ahmed Shafee, Tasneem A. Awaad, Ahmed Moro · 2024
Cybersecurity has become a significant concern for automotive manufacturers as modern cars increasingly incorporate electronic components. Electronic Control Units (ECUs) have evolved to become the central control units for critical car functions such as engines and brakes, experiencing rapid technological advancements. However, this swift progression in ECU technology has also made them prime targets for cyber attacks. This vulnerability has spurred researchers to focus on securing ECUs. Numerous studies have proposed intrusion detection systems (IDS) to protect against attacks on ECUs in vehicles. Yet, these IDSs are not impenetrable; attackers can exploit them by launching evasion attacks, which can trigger numerous false positive alarms. Such false alarms can be disruptive and potentially hazardous for drivers. Additionally, attackers can evade IDSs from detecting malicious data that can cause harm to the vehicle. Accordingly, in this paper, we propose a novel training framework to train a robust in-vehicle IDS that can encounter evasion attacks. Our methodology is based on implementing two rounds of mimic learning technique for training Random Forest (RF) based IDS. RF has been chosen to incorporate the randomness of the RF architecture to enhance the robustness of the model. Additionally, in each round of the two rounds of the mimic learning technique, an RF model with a different architecture is chosen to improve the resilience of the model against evasion attacks without affecting its accuracy. Our Experimental results have shown the effectiveness of our framework against evasion attacks.