TY - GEN
T1 - Anomaly detection for SOME/IP using complex event processing
AU - Herold, Nadine
AU - Posselt, Stephan A.
AU - Hanka, Oliver
AU - Carle, Georg
N1 - Publisher Copyright:
© 2016 IEEE.
PY - 2016/6/30
Y1 - 2016/6/30
N2 - Recent developments favor the adoption of IP-based protocols in automotive and aerospace domains. The increased connectivity between components helps to cut costs and enables better re-use of standardized components. However, increased connectivity also increases the attack surface of the overall system and necessitates dedicated security solutions. This paper presents an anomaly detection system for SOME/IP, a standardized automotive middleware protocol. Within the system, Esper, a complex event processing engine, applies a domain-specific rule set to a stream of SOME/IP packets. Possible attacks and protocol violations on the SOME/IP protocol are identified, suitable rules for detection are presented, and finally, the performance of the system is evaluated.
AB - Recent developments favor the adoption of IP-based protocols in automotive and aerospace domains. The increased connectivity between components helps to cut costs and enables better re-use of standardized components. However, increased connectivity also increases the attack surface of the overall system and necessitates dedicated security solutions. This paper presents an anomaly detection system for SOME/IP, a standardized automotive middleware protocol. Within the system, Esper, a complex event processing engine, applies a domain-specific rule set to a stream of SOME/IP packets. Possible attacks and protocol violations on the SOME/IP protocol are identified, suitable rules for detection are presented, and finally, the performance of the system is evaluated.
UR - http://www.scopus.com/inward/record.url?scp=84979777182&partnerID=8YFLogxK
U2 - 10.1109/NOMS.2016.7502991
DO - 10.1109/NOMS.2016.7502991
M3 - Conference contribution
AN - SCOPUS:84979777182
T3 - Proceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
SP - 1221
EP - 1226
BT - Proceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
A2 - Badonnel, Sema Oktug
A2 - Ulema, Mehmet
A2 - Cavdar, Cicek
A2 - Granville, Lisandro Zambenedetti
A2 - dos Santos, Carlos Raniery P.
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016
Y2 - 25 April 2016 through 29 April 2016
ER -