CAN bus attack detection method based on Mahalanobis distance OOD score

The invention belongs to the technical field of vehicle-mounted network security, and discloses a CAN bus attack detection method based on Mahalanobis distance OOD score. A CAN bus attack detection architecture based on reconstruction loss and OOD score is provided, and an intrusion detection proble...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: HU BING, WANG MEIQUAN, HUANG ZIXUAN, BI YUANGUO, BAI ZEKAI, SHI YIMING
Format: Patent
Sprache:chi ; eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:The invention belongs to the technical field of vehicle-mounted network security, and discloses a CAN bus attack detection method based on Mahalanobis distance OOD score. A CAN bus attack detection architecture based on reconstruction loss and OOD score is provided, and an intrusion detection problem is converted into two-stage detection problems in close connection, namely, a distinguishing problem of normal traffic and abnormal traffic, and a problem of carrying out known attack classification and unknown attack identification on the abnormal traffic. In order to solve the influence caused by data imbalance, an improved random sampling algorithm based on ensemble learning is provided. In order to reduce the false alarm rate of detection, a threshold selection algorithm based on a confidence interval # imgabs0 # principle is provided; according to the method and the system, the detection precision, the recall rate and the F1 score of known attacks and unknown attacks of the CAN bus are improved, finally, var