Spoofing Attack Detection Method by Estimating Transmitting Device on 10BASE-T1S

Kazuki Iehira, Hiroyuki Inoue · 2024

In recent years, the introduction of advanced driver assistance systems in automobiles has significantly increased the communication volume of in-vehicle networks. Automotive Ethernet has been introduced to solve this problem, which enabling the application of security protocols and providing substantial high communication capacity. In particular, the 10BASE-T1S protocol, which is compatible with Ethernet at the MAC layer, has been specified for bus networks designed for use at the end point of in-vehicle networks. However, like Ethernet, 10BASE-T1S, lacks a mechanism to authenticate the transmitting device as a standard feature, making it vulnerable to spoofing attacks. Currently, threat analysis and countermeasures against 10BASE-T1S have not been reported. Therefore, studying threats and countermeasures for 10BASE-T1S is a critical task. In this study, we propose a method for detecting spoofing attacks on busbased networks using 10BASE-T1S. The proposed method detects spoofing attacks by monitoring the transmission timing, focusing on the characteristics of physical-layer collision avoidance (PLCA), which is a collision avoidance mechanism of 10BASE-T1S. Evaluations were conducted using reception records obtained in a minimally configured actual environment using 10BASE-T1S. The results show that the proposed method can estimate the transmitting device and detect spoofing attacks.

Read the paper · More papers on PaperTik