基于流的CAN帧压缩聚合

D. Grimm, Simon Leiner, Martin Sommer, Felix Pistorius, E. Sax
{"title":"基于流的CAN帧压缩聚合","authors":"D. Grimm, Simon Leiner, Martin Sommer, Felix Pistorius, E. Sax","doi":"10.1109/SMARTCOMP50058.2020.00046","DOIUrl":null,"url":null,"abstract":"Modern cars are equipped with a wide variety of sensors generating continually growing amounts of data. This data is transmitted via bus systems such as Controller Area Network (CAN) inside of the vehicle to the microcontroller-based Electronic Control Units. By connecting the vehicle to its surroundings using wireless interfaces, this data becomes accessible to the vehicle manufacturer from a distance. Through the opening to the outside, cyber attacks can exploit these interfaces and introduce major risks to the privacy and safety of vehicle users. Hence, suitable methods for vehicle security monitoring such as intrusion detection and logging are needed. In this work, we focus on the logging of network data, since this data is useful for the development of security updates, countermeasures and incident signatures. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames.","PeriodicalId":346827,"journal":{"name":"2020 IEEE International Conference on Smart Computing (SMARTCOMP)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"Flow-based Aggregation of CAN Frames with Compressed Payload\",\"authors\":\"D. Grimm, Simon Leiner, Martin Sommer, Felix Pistorius, E. Sax\",\"doi\":\"10.1109/SMARTCOMP50058.2020.00046\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Modern cars are equipped with a wide variety of sensors generating continually growing amounts of data. This data is transmitted via bus systems such as Controller Area Network (CAN) inside of the vehicle to the microcontroller-based Electronic Control Units. By connecting the vehicle to its surroundings using wireless interfaces, this data becomes accessible to the vehicle manufacturer from a distance. Through the opening to the outside, cyber attacks can exploit these interfaces and introduce major risks to the privacy and safety of vehicle users. Hence, suitable methods for vehicle security monitoring such as intrusion detection and logging are needed. In this work, we focus on the logging of network data, since this data is useful for the development of security updates, countermeasures and incident signatures. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames.\",\"PeriodicalId\":346827,\"journal\":{\"name\":\"2020 IEEE International Conference on Smart Computing (SMARTCOMP)\",\"volume\":\"8 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE International Conference on Smart Computing (SMARTCOMP)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/SMARTCOMP50058.2020.00046\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Conference on Smart Computing (SMARTCOMP)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/SMARTCOMP50058.2020.00046","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

摘要

现代汽车配备了各种各样的传感器,产生不断增长的数据量。这些数据通过总线系统,如车辆内部的控制器局域网(CAN)传输到基于微控制器的电子控制单元。通过使用无线接口将车辆与周围环境连接起来,车辆制造商可以从远处访问这些数据。通过对外开放,网络攻击可以利用这些接口,给车辆用户的隐私和安全带来重大风险。因此,需要入侵检测和日志记录等合适的车辆安全监控方法。在这项工作中,我们将重点关注网络数据的日志记录,因为这些数据对于开发安全更新、对策和事件签名非常有用。为此,我们提出了一种新的CAN总线数据聚合方法。该方法将CAN帧组合成所谓的流。每个流包含一组共享某种公共属性(例如:帧类型和标识符)的数据包。为了将车队的安全监控无缝集成到后端服务器系统中,收集到的CAN流数据以行业标准数据格式存储。此外,使用压缩算法将有效负载数据包含在流格式中,以利用深度包检查。对真实车辆数据的评估结果表明,与存储CAN帧的行业标准格式相比,我们的方法可以将总体数据大小减少40%。为此,我们提出了一种新的CAN总线数据聚合方法。该方法将CAN帧组合成所谓的流。每个流包含一组共享某种公共属性(例如:帧类型和标识符)的数据包。为了将车队的安全监控无缝集成到后端服务器系统中,收集到的CAN流数据以行业标准数据格式存储。此外,使用压缩算法将有效负载数据包含在流格式中,以利用深度包检查。对真实车辆数据的评估结果表明,与存储CAN帧的行业标准格式相比,我们的方法可以将总体数据大小减少40%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Flow-based Aggregation of CAN Frames with Compressed Payload
Modern cars are equipped with a wide variety of sensors generating continually growing amounts of data. This data is transmitted via bus systems such as Controller Area Network (CAN) inside of the vehicle to the microcontroller-based Electronic Control Units. By connecting the vehicle to its surroundings using wireless interfaces, this data becomes accessible to the vehicle manufacturer from a distance. Through the opening to the outside, cyber attacks can exploit these interfaces and introduce major risks to the privacy and safety of vehicle users. Hence, suitable methods for vehicle security monitoring such as intrusion detection and logging are needed. In this work, we focus on the logging of network data, since this data is useful for the development of security updates, countermeasures and incident signatures. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames. On this account, we propose a new method to aggregate the data of the CAN bus. The method combines CAN frames into so-called flows. Each flow contains a set of packets that share a certain common attribute (e.g.: frame type and identifier). To integrate security monitoring of vehicle fleets seamlessly into backend server systems, the gathered CAN flow data is stored in an industry standard data format. Additionally, the payload data is included in the flow format using a compression algorithm to leverage deep-packet inspection. The evaluation results with realworld vehicle data indicate that in our case about 40 % reduction of the overall data size is possible with our method compared to industry-standard formats for storing CAN frames.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信