Intrusion Response System for In-Vehicle Networks: Uncertainty-Aware Deep Reinforcement Learning-based Approach

Han Jun Yoon, David Soon, Terrence J. Moore, Seunghyun Yoon, Hyuk Lim, Dong Seong Kim, Frederica F. Nelson, Jin-Hee Cho · 2024

Modern vehicles use the Controller Area Network (CAN) bus system to manage communication between electronic control units (ECUs). The CAN bus lacks authentication and authorization mechanisms, and cryptographic protections are rarely used. This creates vulnerabilities to attacks such as Denial of Service, spoofing, and fuzzing, which can disrupt ECU functionality. Injection attacks through external connections (e.g., telematic unit, head unit, OBD-II port) can cause ECU malfunctions, leading to abnormal vehicle behavior or catastrophic events like car crashes. To address these issues, we propose a deep reinforcement learning (DRL)-based intrusion response system (IRS). Upon detecting an attack with an intrusion detection system (IDS), our IRS responds with the optimal defense strategy, maximizing defense utility. Our goal is to minimize the attack's success while ensuring mission completion within deadlines. We define an action space representing defense strategies for detected intrusions. Our extensive experiments prove that our IRS significantly outperforms state-of-the-art and baseline counterparts in minimizing the attack's success by up to 60% and maximizing the mission performance by up to 70%. This work is the first to propose a DRL-based IRS for managing multiple attacks in in-vehicle networks under ML-based IDS alerts.

Read the paper · More papers on PaperTik