TY - GEN
T1 - CAN-BERT do it? Controller Area Network Intrusion Detection System based on BERT Language Model
AU - Alkhatib, Natasha
AU - Mushtaq, Maria
AU - Ghauch, Hadi
AU - Danger, Jean Luc
N1 - Publisher Copyright:
© 2022 IEEE.
PY - 2022/1/1
Y1 - 2022/1/1
N2 - Due to the rising number of sophisticated customer functionalities, electronic control units (ECUs) are increasingly integrated into modern automotive systems. However, the high connectivity between the in-vehicle and the external networks paves the way for hackers who could exploit in-vehicle network protocols' vulnerabilities. Among these protocols, the Controller Area Network (CAN), known as the most widely used in-vehicle networking technology, lacks encryption and authentication mechanisms, making the communications delivered by distributed ECUs insecure. Inspired by the outstanding performance of bidirectional encoder representations from transformers (BERT) for improving many natural language processing tasks, we propose in this paper 'CAN-BERT', a deep learning based network intrusion detection system, to detect cyber attacks on CAN bus protocol. We show that the BERT model can learn the sequence of arbitration identifiers (IDs) in the CAN bus for anomaly detection using the 'masked language model' unsupervised training objective. The experimental results on the 'Car Hacking: Attack & Defense Challenge 2020' dataset show that 'CAN-BERT' outperforms state-of-the-art approaches. In addition to being able to identify in-vehicle intrusions in real-time within 0.8 ms to 3 ms w.r.t CAN ID sequence length, it can also detect a wide variety of cyberattacks with an F1-score of between 0.81 and 0.99.
AB - Due to the rising number of sophisticated customer functionalities, electronic control units (ECUs) are increasingly integrated into modern automotive systems. However, the high connectivity between the in-vehicle and the external networks paves the way for hackers who could exploit in-vehicle network protocols' vulnerabilities. Among these protocols, the Controller Area Network (CAN), known as the most widely used in-vehicle networking technology, lacks encryption and authentication mechanisms, making the communications delivered by distributed ECUs insecure. Inspired by the outstanding performance of bidirectional encoder representations from transformers (BERT) for improving many natural language processing tasks, we propose in this paper 'CAN-BERT', a deep learning based network intrusion detection system, to detect cyber attacks on CAN bus protocol. We show that the BERT model can learn the sequence of arbitration identifiers (IDs) in the CAN bus for anomaly detection using the 'masked language model' unsupervised training objective. The experimental results on the 'Car Hacking: Attack & Defense Challenge 2020' dataset show that 'CAN-BERT' outperforms state-of-the-art approaches. In addition to being able to identify in-vehicle intrusions in real-time within 0.8 ms to 3 ms w.r.t CAN ID sequence length, it can also detect a wide variety of cyberattacks with an F1-score of between 0.81 and 0.99.
KW - BERT
KW - CAN
KW - Intrusion Detection
KW - bidirectional encoder representations from transformers
KW - controller area network
KW - cyberattacks
KW - in-vehicle network
U2 - 10.1109/AICCSA56895.2022.10017800
DO - 10.1109/AICCSA56895.2022.10017800
M3 - Conference contribution
AN - SCOPUS:85147013019
T3 - Proceedings of IEEE/ACS International Conference on Computer Systems and Applications, AICCSA
BT - 2022 IEEE/ACS 19th International Conference on Computer Systems and Applications, AICCSA 2022 - Proceedings
PB - IEEE Computer Society
T2 - 19th IEEE/ACS International Conference on Computer Systems and Applications, AICCSA 2022
Y2 - 5 December 2022 through 7 December 2022
ER -