SlideShare a Scribd company logo
1 of 18
Armin Wasicek
University of California, Berkeley
Technical University Vienna, Austria
MT-CPS Workshop
April 11, 2016
Context-aware Automotive Intrusion
Detection using Reference Models
2015 Automotive Security Incidents
Armin Wasicek 2
► 2015 has been a break-through year for automotive security
What is Intrusion Detection?
Gathers and analyzes
information
• Identifies potential
security breaches
– Intrusions
– Misuse/Fraud
► Reports to users
3
System
Perimeter
Users
Sensor
IDS
Armin Wasicek
Manipulation and Fault tolerance
4
• Partition system in safe
and unsafe state
• Manipulations are subtle
• Maximizing damage is not
always an attack goal
• Stay within safe states,
but modified behavior
• Gain manipulated service
Armin Wasicek
NTHSA: Misbehavior Detection [DOT HS 812 014]
Development of the processes, algorithms, reporting requirements, and
data requirements for both local and global detection functions;
Types of IDS
• Knowledge-based IDS
– Patterns/Signatures of malicious activities
– Low false positive rate, needs frequent updates
• Heuristic-based IDS
– Look for abnormal behavior, e.g., higher entropy
– Detect new attack patterns
• Context-aware IDS
– Compare to reference model, include semantics
– Check against specifications and regulations
5Armin Wasicek
IDS
S
Automotive System Architecture
Armin Wasicek 6
ECU
Switch
Backbone
Cloud
Eth
GW
• Host-based IDS monitors ECU
– CPU & memory usage, syscalls, # processes, …
• Network IDS monitors communication
– Message frequency, patterns, entropy, …
Over-the-air Updates
Environmental info.
Malicious
devices
Board
computer
External
communication
On-board
networks
Segregation
Traditional IDS
are not
designed to
detect cyber-
physical attacks
Chip tuning
Modify control algorithm parameters in ECU
• Parameters are stored in a table in flash memory
• Reprogram ECU with new values
– Debug interface, 3rd party device
► Messages emitted by ECU seem original!
7Armin Wasicek
Power boxing
Modify commands to ECU
• Replace the ECU in the communication system
• Insert device between the ECU and actuators
► Communication pattern does not change!
8
Improves low end
torque. Plug-in
installation in less
than 30 minutes.
Armin Wasicek
Cyber-Physical Attacks
Cyber-Physical attacks impact the physical domain
by manipulating the cyber domain and vice versa.
• Checking only cyber properties like CAN message
frequency might miss important attack vectors
• IDS needs to target attack on the physical part
► Compare actual behavior to reference model
enabling misbehavior detection
Armin Wasicek 9
ECU
Switch
Backbone
GW
Context-aware, automotive IDS
Armin Wasicek 10
Cloud
• Integrate firewall, authentication, and detection
• Fuse information from diverse sources
• Use semantics of control msg to reason about manipulation
Threat defense
Over-the-air Updates
Detect misbehavior
Chip
Tuning
Wheel speed
RPM, torque
Road conditions
IDS
Feature Extraction
Convert a time series to a feature vector
Processing pipeline works on a time slice
► Compute feature vector storing the relations
between process variables
11Armin Wasicek
Frame as a one-class classification problem
Bottleneck ANN:
• Hidden layer generalizes
ratio between features
• Stores the typical behavior of an engine
• Trained using same vector for input X, output Y
• Anomaly score is error between input and output
Artificial Neural Networks
12Armin Wasicek
Intrusion Detection Layer
Compares current to reference behavior
• Monitor converts data to potential manipulations
• Detector uses context and state info to reduce FP
► Deep Learning approach could extend to Detector
13Armin Wasicek
Evaluation: Simulation
• Racing car simulation TORCS (Peugeot 406)
14Armin Wasicek
Evaluation: Car data
Data points
0 5 10 15 20 25 30 35 40 45 50 55
Min/maxvalues
0
5
10
15
20
25
30
35
40
45
original
modified
Armin Wasicek 15
Vehicle speed Calculated load value
Engine RPM Absolute throttle position
Fuel rate O2 sensor lambda wide range
Fuel/Air commanded equivalence Absolute throttle position B
Accelerator pedal position D Catalyst temperature
Recognition result
Armin Wasicek 16
Size of subset (% of dataset)
0 10 20 30 40 50 60 70 80 90
Anomalyscore
10
6
10
7
108
109
10
10
10
11
ANN w. 16 hidden
ANN w. 32 hidden
ANN w. 43 hidden
Iterations
1 2 3 4 5 6 7 8 9 10 11 12
RatioanomalyscoreofXmod
/Xval
0
1
2
3
4
5
6
7
8
9
ANN w. 43 hidden
ANN w. 32 hidden
ANN w. 16 hidden
ANN with 43 hidden nodes has 6-8 times higher
anomaly score than validation set. 16 ~ factor
1.5
Conclusion and Outlook
• CPS integrate physical and cyber processes
• IDS need to target both sides of the coin
• Integrate with other security mechanisms
• Intelligently use the cloud to recognize attacks
• Faults, ageing, and repair effects are challenging
17Armin Wasicek
Thanks for your attention!
Contact me: arminw@berkeley.edu

More Related Content

What's hot

City wide rf tracking 2013
City wide rf tracking 2013City wide rf tracking 2013
City wide rf tracking 2013Chris Kameir
 
RFID based Highway Toll Fee Process System
RFID based Highway Toll Fee Process SystemRFID based Highway Toll Fee Process System
RFID based Highway Toll Fee Process SystemAmar Reddy
 
Balancing micro networks in dynamic production and demand environments
Balancing micro networks in dynamic production and demand environmentsBalancing micro networks in dynamic production and demand environments
Balancing micro networks in dynamic production and demand environmentsLandis+Gyr
 
Senet - LPWANs for smart building, campus, and city applications
Senet - LPWANs for smart building, campus, and city applicationsSenet - LPWANs for smart building, campus, and city applications
Senet - LPWANs for smart building, campus, and city applicationsKen Lynch
 
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...KajalDubey13
 
Ensuring solution performance in large-scale smart installations”, Showcase t...
Ensuring solution performance in large-scale smart installations”, Showcase t...Ensuring solution performance in large-scale smart installations”, Showcase t...
Ensuring solution performance in large-scale smart installations”, Showcase t...Landis+Gyr
 
A Novel Wireless Sensor Network Frame for Urban Transportation
A Novel Wireless Sensor Network Frame for Urban TransportationA Novel Wireless Sensor Network Frame for Urban Transportation
A Novel Wireless Sensor Network Frame for Urban Transportationsaddamhusain hadimani
 
Smart Traffic Control System
Smart Traffic Control SystemSmart Traffic Control System
Smart Traffic Control SystemAtul Gupta
 
Traffic control system
Traffic control systemTraffic control system
Traffic control systemzahid6
 
Connecting vehicles, highways and telecommunications
Connecting vehicles, highways and telecommunicationsConnecting vehicles, highways and telecommunications
Connecting vehicles, highways and telecommunicationsinnovITS
 
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT Network
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT NetworkRIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT Network
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT NetworkRIPE NCC
 
A low cost and noninvasive system for the measurement and detection of faulty...
A low cost and noninvasive system for the measurement and detection of faulty...A low cost and noninvasive system for the measurement and detection of faulty...
A low cost and noninvasive system for the measurement and detection of faulty...ieeeprojectsbangalore
 
Automated toll tax collection using rfid
Automated toll tax collection using rfidAutomated toll tax collection using rfid
Automated toll tax collection using rfidjeet patalia
 
Ac pwm based power control by igbt mosfet 12000
Ac pwm based power control by igbt  mosfet  12000Ac pwm based power control by igbt  mosfet  12000
Ac pwm based power control by igbt mosfet 12000Vivek Bhakta
 
Automated Network Management Solution
Automated Network Management SolutionAutomated Network Management Solution
Automated Network Management SolutionLandis+Gyr
 

What's hot (20)

City wide rf tracking 2013
City wide rf tracking 2013City wide rf tracking 2013
City wide rf tracking 2013
 
RFID based Highway Toll Fee Process System
RFID based Highway Toll Fee Process SystemRFID based Highway Toll Fee Process System
RFID based Highway Toll Fee Process System
 
EENA2019: Track2 session6 AML in Norway_Sven Bruun
EENA2019: Track2 session6 AML in Norway_Sven BruunEENA2019: Track2 session6 AML in Norway_Sven Bruun
EENA2019: Track2 session6 AML in Norway_Sven Bruun
 
Balancing micro networks in dynamic production and demand environments
Balancing micro networks in dynamic production and demand environmentsBalancing micro networks in dynamic production and demand environments
Balancing micro networks in dynamic production and demand environments
 
Senet - LPWANs for smart building, campus, and city applications
Senet - LPWANs for smart building, campus, and city applicationsSenet - LPWANs for smart building, campus, and city applications
Senet - LPWANs for smart building, campus, and city applications
 
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...
Adaptive Traffic Control System : The Smart and Imperative Traffic Monitoring...
 
EENA 2018 - GRALLE, a EU initiative for a Galileo-based Emergency Warning Sys...
EENA 2018 - GRALLE, a EU initiative for a Galileo-based Emergency Warning Sys...EENA 2018 - GRALLE, a EU initiative for a Galileo-based Emergency Warning Sys...
EENA 2018 - GRALLE, a EU initiative for a Galileo-based Emergency Warning Sys...
 
Ensuring solution performance in large-scale smart installations”, Showcase t...
Ensuring solution performance in large-scale smart installations”, Showcase t...Ensuring solution performance in large-scale smart installations”, Showcase t...
Ensuring solution performance in large-scale smart installations”, Showcase t...
 
A Novel Wireless Sensor Network Frame for Urban Transportation
A Novel Wireless Sensor Network Frame for Urban TransportationA Novel Wireless Sensor Network Frame for Urban Transportation
A Novel Wireless Sensor Network Frame for Urban Transportation
 
Smart Traffic Control System
Smart Traffic Control SystemSmart Traffic Control System
Smart Traffic Control System
 
Traffic control system
Traffic control systemTraffic control system
Traffic control system
 
Connecting vehicles, highways and telecommunications
Connecting vehicles, highways and telecommunicationsConnecting vehicles, highways and telecommunications
Connecting vehicles, highways and telecommunications
 
EENA2019: Track1 session3 Deploying Next Generation 112 in Europe_Cristina Lu...
EENA2019: Track1 session3 Deploying Next Generation 112 in Europe_Cristina Lu...EENA2019: Track1 session3 Deploying Next Generation 112 in Europe_Cristina Lu...
EENA2019: Track1 session3 Deploying Next Generation 112 in Europe_Cristina Lu...
 
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT Network
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT NetworkRIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT Network
RIPE Atlas: Ethical, Security and Legal Considerations of Running an IoT Network
 
EENA 2021: Industry session - Emergency apps (3/3)
EENA 2021: Industry session - Emergency apps (3/3)EENA 2021: Industry session - Emergency apps (3/3)
EENA 2021: Industry session - Emergency apps (3/3)
 
A low cost and noninvasive system for the measurement and detection of faulty...
A low cost and noninvasive system for the measurement and detection of faulty...A low cost and noninvasive system for the measurement and detection of faulty...
A low cost and noninvasive system for the measurement and detection of faulty...
 
Automated toll tax collection using rfid
Automated toll tax collection using rfidAutomated toll tax collection using rfid
Automated toll tax collection using rfid
 
EENA 2018 - Next Generation 112 made simple
EENA 2018 - Next Generation 112 made simpleEENA 2018 - Next Generation 112 made simple
EENA 2018 - Next Generation 112 made simple
 
Ac pwm based power control by igbt mosfet 12000
Ac pwm based power control by igbt  mosfet  12000Ac pwm based power control by igbt  mosfet  12000
Ac pwm based power control by igbt mosfet 12000
 
Automated Network Management Solution
Automated Network Management SolutionAutomated Network Management Solution
Automated Network Management Solution
 

Similar to Context-aware Automotive Intrusion Detection using Reference Models

Automated Fault Analysis - IVPower for Transmission System Operators and Dist...
Automated Fault Analysis - IVPower for Transmission System Operators and Dist...Automated Fault Analysis - IVPower for Transmission System Operators and Dist...
Automated Fault Analysis - IVPower for Transmission System Operators and Dist...AFAS - Automated Fault Analysis NetCeler
 
Octavis Vibration Monitor Brochure
Octavis Vibration Monitor BrochureOctavis Vibration Monitor Brochure
Octavis Vibration Monitor Brochureifm electronic gmbh
 
How to Plan for Line Controls and Integration
How to Plan for Line Controls and IntegrationHow to Plan for Line Controls and Integration
How to Plan for Line Controls and IntegrationNercon
 
Asset Insight Manager Introduction 2014 (2)
Asset Insight Manager Introduction 2014 (2)Asset Insight Manager Introduction 2014 (2)
Asset Insight Manager Introduction 2014 (2)Dean Bishop
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSDeepak Shankar
 
PlantConnect Presentation
PlantConnect PresentationPlantConnect Presentation
PlantConnect PresentationAkshay Tilak
 
Overview of IoT/M2M Capability
Overview of IoT/M2M CapabilityOverview of IoT/M2M Capability
Overview of IoT/M2M CapabilityALTEN Calsoft Labs
 
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...Intelligent Production: Deploying IoT and cloud-based machine learning to opt...
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...Amazon Web Services
 
VIBRATION AND POWER ANALYZER By Zreyas Technology Private Limited
VIBRATION AND POWER ANALYZER By Zreyas Technology Private LimitedVIBRATION AND POWER ANALYZER By Zreyas Technology Private Limited
VIBRATION AND POWER ANALYZER By Zreyas Technology Private LimitedIndiaMART InterMESH Limited
 
,Article reprint from_erneuerbareenergien
,Article reprint from_erneuerbareenergien,Article reprint from_erneuerbareenergien
,Article reprint from_erneuerbareenergienManel Montesinos
 
The Road Ahead of IoT
The Road Ahead of IoTThe Road Ahead of IoT
The Road Ahead of IoTTiE Bangalore
 
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...IES VE
 

Similar to Context-aware Automotive Intrusion Detection using Reference Models (20)

Automated Fault Analysis - IVPower for Transmission System Operators and Dist...
Automated Fault Analysis - IVPower for Transmission System Operators and Dist...Automated Fault Analysis - IVPower for Transmission System Operators and Dist...
Automated Fault Analysis - IVPower for Transmission System Operators and Dist...
 
Octavis Vibration Monitor Brochure
Octavis Vibration Monitor BrochureOctavis Vibration Monitor Brochure
Octavis Vibration Monitor Brochure
 
Wfcs2019
Wfcs2019Wfcs2019
Wfcs2019
 
How to Plan for Line Controls and Integration
How to Plan for Line Controls and IntegrationHow to Plan for Line Controls and Integration
How to Plan for Line Controls and Integration
 
Asset Insight Manager Introduction 2014 (2)
Asset Insight Manager Introduction 2014 (2)Asset Insight Manager Introduction 2014 (2)
Asset Insight Manager Introduction 2014 (2)
 
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERSROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
ROLE OF DIGITAL SIMULATION IN CONFIGURING NETWORK PARAMETERS
 
A2IoT OBDII Case Study
A2IoT OBDII Case StudyA2IoT OBDII Case Study
A2IoT OBDII Case Study
 
OPAL-RT ePHASORsim Webinar
OPAL-RT ePHASORsim WebinarOPAL-RT ePHASORsim Webinar
OPAL-RT ePHASORsim Webinar
 
PlantConnect Presentation
PlantConnect PresentationPlantConnect Presentation
PlantConnect Presentation
 
Overview of IoT/M2M Capability
Overview of IoT/M2M CapabilityOverview of IoT/M2M Capability
Overview of IoT/M2M Capability
 
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...Intelligent Production: Deploying IoT and cloud-based machine learning to opt...
Intelligent Production: Deploying IoT and cloud-based machine learning to opt...
 
VIBRATION AND POWER ANALYZER By Zreyas Technology Private Limited
VIBRATION AND POWER ANALYZER By Zreyas Technology Private LimitedVIBRATION AND POWER ANALYZER By Zreyas Technology Private Limited
VIBRATION AND POWER ANALYZER By Zreyas Technology Private Limited
 
,Article reprint from_erneuerbareenergien
,Article reprint from_erneuerbareenergien,Article reprint from_erneuerbareenergien
,Article reprint from_erneuerbareenergien
 
Valarie Hines: 2013 Sandia National Laboratoies Wind Plant Reliability Workshop
Valarie Hines: 2013 Sandia National Laboratoies Wind Plant Reliability WorkshopValarie Hines: 2013 Sandia National Laboratoies Wind Plant Reliability Workshop
Valarie Hines: 2013 Sandia National Laboratoies Wind Plant Reliability Workshop
 
HUMS-Final-PPT.pptx
HUMS-Final-PPT.pptxHUMS-Final-PPT.pptx
HUMS-Final-PPT.pptx
 
EnviroConnect
EnviroConnectEnviroConnect
EnviroConnect
 
The Road Ahead of IoT
The Road Ahead of IoTThe Road Ahead of IoT
The Road Ahead of IoT
 
Advance Traffic management system
Advance Traffic management systemAdvance Traffic management system
Advance Traffic management system
 
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...
Synthesis and Refinement of Artificial HVAC Sensor Data Intended for Supervis...
 
Multilin™ Intelligent Line Monitoring System
Multilin™ Intelligent Line Monitoring SystemMultilin™ Intelligent Line Monitoring System
Multilin™ Intelligent Line Monitoring System
 

Recently uploaded

How To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative ErrorHow To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative ErrorAndres Auto Service
 
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...shivangimorya083
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxzohiiimughal286
 
How To Fix Mercedes Benz Anti-Theft Protection Activation Issue
How To Fix Mercedes Benz Anti-Theft Protection Activation IssueHow To Fix Mercedes Benz Anti-Theft Protection Activation Issue
How To Fix Mercedes Benz Anti-Theft Protection Activation IssueTerry Sayther Automotive
 
Innovating Manufacturing with CNC Technology
Innovating Manufacturing with CNC TechnologyInnovating Manufacturing with CNC Technology
Innovating Manufacturing with CNC Technologyquickpartslimitlessm
 
What Causes BMW Chassis Stabilization Malfunction Warning To Appear
What Causes BMW Chassis Stabilization Malfunction Warning To AppearWhat Causes BMW Chassis Stabilization Malfunction Warning To Appear
What Causes BMW Chassis Stabilization Malfunction Warning To AppearJCL Automotive
 
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...Hot Call Girls In Sector 58 (Noida)
 
John deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance ManualJohn deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance ManualExcavator
 
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一meq5nzfnk
 
Russian Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...
Russian  Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...Russian  Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...
Russian Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...shivangimorya083
 
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂Hot Call Girls In Sector 58 (Noida)
 
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls Services
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls ServicesBandra Escorts, (*Pooja 09892124323), Bandra Call Girls Services
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls ServicesPooja Nehwal
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagardollysharma2066
 
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...Hot Call Girls In Sector 58 (Noida)
 
Chapter-1.3-Four-Basic-Computer-periods.pptx
Chapter-1.3-Four-Basic-Computer-periods.pptxChapter-1.3-Four-Basic-Computer-periods.pptx
Chapter-1.3-Four-Basic-Computer-periods.pptxAnjieVillarba1
 
What Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingWhat Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingBruce Cox Imports
 

Recently uploaded (20)

How To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative ErrorHow To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
How To Troubleshoot Mercedes Blind Spot Assist Inoperative Error
 
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...
Hot And Sexy 🥵 Call Girls Delhi Daryaganj {9711199171} Ira Malik High class G...
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptx
 
How To Fix Mercedes Benz Anti-Theft Protection Activation Issue
How To Fix Mercedes Benz Anti-Theft Protection Activation IssueHow To Fix Mercedes Benz Anti-Theft Protection Activation Issue
How To Fix Mercedes Benz Anti-Theft Protection Activation Issue
 
Innovating Manufacturing with CNC Technology
Innovating Manufacturing with CNC TechnologyInnovating Manufacturing with CNC Technology
Innovating Manufacturing with CNC Technology
 
What Causes BMW Chassis Stabilization Malfunction Warning To Appear
What Causes BMW Chassis Stabilization Malfunction Warning To AppearWhat Causes BMW Chassis Stabilization Malfunction Warning To Appear
What Causes BMW Chassis Stabilization Malfunction Warning To Appear
 
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...
Alina 7042364481 Call Girls Service Pochanpur Colony - independent Pochanpur ...
 
Call Girls In Kirti Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Kirti Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In Kirti Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Kirti Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
John deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance ManualJohn deere 425 445 455 Maitenance Manual
John deere 425 445 455 Maitenance Manual
 
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
定制多伦多大学毕业证(UofT毕业证)成绩单(学位证)原版一比一
 
Russian Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...
Russian  Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...Russian  Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...
Russian Call Girls Delhi Indirapuram {9711199171} Aarvi Gupta ✌️Independent ...
 
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
 
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls Services
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls ServicesBandra Escorts, (*Pooja 09892124323), Bandra Call Girls Services
Bandra Escorts, (*Pooja 09892124323), Bandra Call Girls Services
 
Stay Cool and Compliant: Know Your Window Tint Laws Before You Tint
Stay Cool and Compliant: Know Your Window Tint Laws Before You TintStay Cool and Compliant: Know Your Window Tint Laws Before You Tint
Stay Cool and Compliant: Know Your Window Tint Laws Before You Tint
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
 
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...
꧁ ୨ Call Girls In Radisson Blu Plaza Delhi Airport, New Delhi ❀7042364481❀ Es...
 
Call Girls In Kirti Nagar 7042364481 Escort Service 24x7 Delhi
Call Girls In Kirti Nagar 7042364481 Escort Service 24x7 DelhiCall Girls In Kirti Nagar 7042364481 Escort Service 24x7 Delhi
Call Girls In Kirti Nagar 7042364481 Escort Service 24x7 Delhi
 
Chapter-1.3-Four-Basic-Computer-periods.pptx
Chapter-1.3-Four-Basic-Computer-periods.pptxChapter-1.3-Four-Basic-Computer-periods.pptx
Chapter-1.3-Four-Basic-Computer-periods.pptx
 
Call Girls In Greater Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Greater Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In Greater Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Greater Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
What Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingWhat Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop Working
 

Context-aware Automotive Intrusion Detection using Reference Models

  • 1. Armin Wasicek University of California, Berkeley Technical University Vienna, Austria MT-CPS Workshop April 11, 2016 Context-aware Automotive Intrusion Detection using Reference Models
  • 2. 2015 Automotive Security Incidents Armin Wasicek 2 ► 2015 has been a break-through year for automotive security
  • 3. What is Intrusion Detection? Gathers and analyzes information • Identifies potential security breaches – Intrusions – Misuse/Fraud ► Reports to users 3 System Perimeter Users Sensor IDS Armin Wasicek
  • 4. Manipulation and Fault tolerance 4 • Partition system in safe and unsafe state • Manipulations are subtle • Maximizing damage is not always an attack goal • Stay within safe states, but modified behavior • Gain manipulated service Armin Wasicek NTHSA: Misbehavior Detection [DOT HS 812 014] Development of the processes, algorithms, reporting requirements, and data requirements for both local and global detection functions;
  • 5. Types of IDS • Knowledge-based IDS – Patterns/Signatures of malicious activities – Low false positive rate, needs frequent updates • Heuristic-based IDS – Look for abnormal behavior, e.g., higher entropy – Detect new attack patterns • Context-aware IDS – Compare to reference model, include semantics – Check against specifications and regulations 5Armin Wasicek IDS S
  • 6. Automotive System Architecture Armin Wasicek 6 ECU Switch Backbone Cloud Eth GW • Host-based IDS monitors ECU – CPU & memory usage, syscalls, # processes, … • Network IDS monitors communication – Message frequency, patterns, entropy, … Over-the-air Updates Environmental info. Malicious devices Board computer External communication On-board networks Segregation Traditional IDS are not designed to detect cyber- physical attacks
  • 7. Chip tuning Modify control algorithm parameters in ECU • Parameters are stored in a table in flash memory • Reprogram ECU with new values – Debug interface, 3rd party device ► Messages emitted by ECU seem original! 7Armin Wasicek
  • 8. Power boxing Modify commands to ECU • Replace the ECU in the communication system • Insert device between the ECU and actuators ► Communication pattern does not change! 8 Improves low end torque. Plug-in installation in less than 30 minutes. Armin Wasicek
  • 9. Cyber-Physical Attacks Cyber-Physical attacks impact the physical domain by manipulating the cyber domain and vice versa. • Checking only cyber properties like CAN message frequency might miss important attack vectors • IDS needs to target attack on the physical part ► Compare actual behavior to reference model enabling misbehavior detection Armin Wasicek 9
  • 10. ECU Switch Backbone GW Context-aware, automotive IDS Armin Wasicek 10 Cloud • Integrate firewall, authentication, and detection • Fuse information from diverse sources • Use semantics of control msg to reason about manipulation Threat defense Over-the-air Updates Detect misbehavior Chip Tuning Wheel speed RPM, torque Road conditions IDS
  • 11. Feature Extraction Convert a time series to a feature vector Processing pipeline works on a time slice ► Compute feature vector storing the relations between process variables 11Armin Wasicek
  • 12. Frame as a one-class classification problem Bottleneck ANN: • Hidden layer generalizes ratio between features • Stores the typical behavior of an engine • Trained using same vector for input X, output Y • Anomaly score is error between input and output Artificial Neural Networks 12Armin Wasicek
  • 13. Intrusion Detection Layer Compares current to reference behavior • Monitor converts data to potential manipulations • Detector uses context and state info to reduce FP ► Deep Learning approach could extend to Detector 13Armin Wasicek
  • 14. Evaluation: Simulation • Racing car simulation TORCS (Peugeot 406) 14Armin Wasicek
  • 15. Evaluation: Car data Data points 0 5 10 15 20 25 30 35 40 45 50 55 Min/maxvalues 0 5 10 15 20 25 30 35 40 45 original modified Armin Wasicek 15 Vehicle speed Calculated load value Engine RPM Absolute throttle position Fuel rate O2 sensor lambda wide range Fuel/Air commanded equivalence Absolute throttle position B Accelerator pedal position D Catalyst temperature
  • 16. Recognition result Armin Wasicek 16 Size of subset (% of dataset) 0 10 20 30 40 50 60 70 80 90 Anomalyscore 10 6 10 7 108 109 10 10 10 11 ANN w. 16 hidden ANN w. 32 hidden ANN w. 43 hidden Iterations 1 2 3 4 5 6 7 8 9 10 11 12 RatioanomalyscoreofXmod /Xval 0 1 2 3 4 5 6 7 8 9 ANN w. 43 hidden ANN w. 32 hidden ANN w. 16 hidden ANN with 43 hidden nodes has 6-8 times higher anomaly score than validation set. 16 ~ factor 1.5
  • 17. Conclusion and Outlook • CPS integrate physical and cyber processes • IDS need to target both sides of the coin • Integrate with other security mechanisms • Intelligently use the cloud to recognize attacks • Faults, ageing, and repair effects are challenging 17Armin Wasicek
  • 18. Thanks for your attention! Contact me: arminw@berkeley.edu

Editor's Notes

  1. From an intrusion detection perspective, vehicular network CAN communica'ons are considered fairly predictable and well-­‐suited for real-­‐'me monitoring to detect anomalous ac'vity with respect to nominal expected message flows.
  2. Replace software in the ECU