Anomaly detection for SOME/IP using complex event processing

Nadine Herold, Stephan A. Posselt, Oliver Hanka, Georg Carle

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

16 Scopus citations

Abstract

Recent developments favor the adoption of IP-based protocols in automotive and aerospace domains. The increased connectivity between components helps to cut costs and enables better re-use of standardized components. However, increased connectivity also increases the attack surface of the overall system and necessitates dedicated security solutions. This paper presents an anomaly detection system for SOME/IP, a standardized automotive middleware protocol. Within the system, Esper, a complex event processing engine, applies a domain-specific rule set to a stream of SOME/IP packets. Possible attacks and protocol violations on the SOME/IP protocol are identified, suitable rules for detection are presented, and finally, the performance of the system is evaluated.

Original languageEnglish
Title of host publicationProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium
EditorsSema Oktug Badonnel, Mehmet Ulema, Cicek Cavdar, Lisandro Zambenedetti Granville, Carlos Raniery P. dos Santos
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1221-1226
Number of pages6
ISBN (Electronic)9781509002238
DOIs
StatePublished - 30 Jun 2016
Event2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016 - Istanbul, Turkey
Duration: 25 Apr 201629 Apr 2016

Publication series

NameProceedings of the NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium

Conference

Conference2016 IEEE/IFIP Network Operations and Management Symposium, NOMS 2016
Country/TerritoryTurkey
CityIstanbul
Period25/04/1629/04/16

Fingerprint

Dive into the research topics of 'Anomaly detection for SOME/IP using complex event processing'. Together they form a unique fingerprint.

Cite this