[论文解读] A Comprehensive Guide to CAN IDS Data & Introduction of the ROAD Dataset
本文介绍了ROAD数据集,这是一个全面的现实世界CAN总线数据集,包含超过3.5小时的车辆数据,涵盖多样化的、经过物理验证的攻击——包括真实模糊测试、伪造攻击以及高级隐蔽攻击——并附带现有公开CAN入侵检测系统(IDS)数据集的系统性指南。ROAD数据集使入侵检测系统的评估更加真实、可比且可复现,解决了先前研究中在保真度和攻击多样性方面的关键缺陷。
Although ubiquitous in modern vehicles, Controller Area Networks (CANs) lack basic security properties and are easily exploitable. A rapidly growing field of CAN security research has emerged that seeks to detect intrusions on CANs. Producing vehicular CAN data with a variety of intrusions is out of reach for most researchers as it requires expensive assets and expertise. To assist researchers, we present the first comprehensive guide to the existing open CAN intrusion datasets, including a quality analysis of each dataset and an enumeration of each's benefits, drawbacks, and suggested use case. Current public CAN IDS datasets are limited to real fabrication (simple message injection) attacks and simulated attacks often in synthetic data, which lack fidelity. In general, the physical effects of attacks on the vehicle are not verified in the available datasets. Only one dataset provides signal-translated data but not a corresponding raw binary version. Overall, the available data pigeon-holes CAN IDS works into testing on limited, often inappropriate data (usually with attacks that are too easily detectable to truly test the method), and this lack data has stymied comparability and reproducibility of results. As our primary contribution, we present the ROAD (Real ORNL Automotive Dynamometer) CAN Intrusion Dataset, consisting of over 3.5 hours of one vehicle's CAN data. ROAD contains ambient data recorded during a diverse set of activities, and attacks of increasing stealth with multiple variants and instances of real fuzzing, fabrication, and unique advanced attacks, as well as simulated masquerade attacks. To facilitate benchmarking CAN IDS methods that require signal-translated inputs, we also provide the signal time series format for many of the CAN captures. Our contributions aim to facilitate appropriate benchmarking and needed comparability in the CAN IDS field.
研究动机与目标
- 解决缺乏标准化、高保真度的CAN入侵检测系统(IDS)数据集的问题,这些问题阻碍了研究的可复现性和可比性。
- 提供一份全面、精心整理的公开CAN IDS数据集指南,涵盖攻击类型、数据质量及使用场景。
- 引入ROAD数据集作为新基准,涵盖多种攻击类别中真实且经过物理验证的攻击,包括隐蔽和高级变体。
- 通过提供原始CAN数据和信号转换的时间序列格式,支持现代IDS方法的测试。
- 通过提供具有真实物理效应和攻击复杂度的数据,促进下一代CAN IDS的开发与评估。
提出的方法
- 将CAN攻击分为三类主要类型:伪造(例如,消息注入)、暂停(合法帧的移除)和伪装(伪造帧替代被暂停的帧)。
- 对5个公开的CAN IDS数据集进行详细的质量分析,评估数据类型(真实/模拟)、攻击类型(真实/模拟)、数据格式(原始CAN或信号转换)、车辆数量和总时长。
- 使用车载测功机从单辆汽车收集真实CAN总线数据,记录环境驾驶行为,并注入广泛的真实和模拟攻击。
- 以逐步提升隐蔽性的攻击级别记录攻击,包括多种模糊测试、伪造攻击的变体以及独特的高级攻击模式,所有攻击均经过物理验证。
- 同时提供原始二进制CAN数据和信号转换的时间序列数据,以支持多样化的IDS评估方法。
- 设计数据集以支持启发式、统计和基于机器学习的IDS模型的基准测试,并提供用于训练和测试的标记攻击实例。
实验结果
研究问题
- RQ1现有公开CAN IDS数据集在攻击真实性、数据保真度和可复现性方面存在哪些关键局限?
- RQ2研究人员如何根据攻击类型、数据格式和车辆特性,为其特定的IDS评估需求选择最合适的数据集?
- RQ3当前数据集在多大程度上支持对高级隐蔽攻击(如伪装攻击或低速伪造攻击)的测试?
- RQ4与合成或模拟数据相比,包含物理验证攻击的真实世界CAN数据是否能更有效地提升现代IDS模型的基准测试与验证效果?
- RQ5同时包含原始CAN和信号转换数据格式在多大程度上提升了基准数据集的通用性和适用性?
主要发现
- ROAD数据集包含来自单辆汽车的超过3.5小时真实CAN总线数据,涵盖多样化的物理验证攻击,包括真实模糊测试、伪造攻击以及高级隐蔽攻击。
- 在所有先前公开的数据集中,仅有一个提供了信号转换数据,但缺乏对应的原始二进制版本,限制了其在完整栈IDS评估中的实用性。
- 大多数现有公开数据集仅限于简单、易检测的伪造攻击或合成模拟,未能体现真实世界中低速、渐进式攻击模式。
- ROAD数据集使IDS方法的基准测试更加真实,其攻击难以通过简单的基于时间的启发式方法检测,从而更真实地反映现实威胁场景。
- 该数据集已被多个研究团队采纳,用于评估新型IDS架构,包括基于度量学习、深度聚类和上下文感知检测的模型。
- ROAD数据集正日益被引用为CAN IDS研究中最全面、最真实的开放基准,其在该领域中被广泛认可为事实上的标准。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。