Ieeexplore.Ieee Enhancing Intrusion Detection in Controller Area Networks
Article Content
- •TISIC improves detection of CAN attacks by redefining inter-message arrival times.
- •The CAN bus is vulnerable due to its design for reliability over security.
- •Public datasets validate the effectiveness of the new detection method.
Recent advancements in intrusion detection for Controller Area Networks (CAN) have been reported, focusing on time-based detection methods for timing transparent attacks. The conventional definition of inter-message arrival times has been shown to degrade detection performance due to attack messages influencing reference times. A new approach, TISIC, has been proposed to improve detection accuracy by preserving normal reference times even during attacks. This method was validated using publicly available datasets, including the Car-Hacking Dataset and X-CANIDS dataset, demonstrating enhanced detection metrics such as AUROC and AUPR. The CAN bus, widely used in modern vehicles, remains vulnerable due to its lack of built-in security features, exposing it to various attack vectors. The research emphasizes the growing need for robust intrusion detection systems as the attack surface for vehicles expands with new technologies. This development is timely, given the increasing regulatory focus on automotive cybersecurity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…