Cargando…

A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles

In this paper, we propose an intrusion detection system based on the estimation of the Rényi entropy with multiple orders. The Rényi entropy is a generalized notion of entropy that includes the Shannon entropy and the min-entropy as special cases. In 2018, Kim proposed an efficient estimation method...

Descripción completa

Detalles Bibliográficos
Autores principales: Yu, Ki-Soon, Kim, Sung-Hyun, Lim, Dae-Woon, Kim, Young-Sik
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2020
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7516617/
https://www.ncbi.nlm.nih.gov/pubmed/33285960
http://dx.doi.org/10.3390/e22020186
_version_ 1783587042532261888
author Yu, Ki-Soon
Kim, Sung-Hyun
Lim, Dae-Woon
Kim, Young-Sik
author_facet Yu, Ki-Soon
Kim, Sung-Hyun
Lim, Dae-Woon
Kim, Young-Sik
author_sort Yu, Ki-Soon
collection PubMed
description In this paper, we propose an intrusion detection system based on the estimation of the Rényi entropy with multiple orders. The Rényi entropy is a generalized notion of entropy that includes the Shannon entropy and the min-entropy as special cases. In 2018, Kim proposed an efficient estimation method for the Rényi entropy with an arbitrary real order [Formula: see text]. In this work, we utilize this method to construct a multiple order, Rényi entropy based intrusion detection system (IDS) for vehicular systems with various network connections. The proposed method estimates the Rényi entropies simultaneously with three distinct orders, two, three, and four, based on the controller area network (CAN)-IDs of consecutively generated frames. The collected frames are split into blocks with a fixed number of frames, and the entropies are evaluated based on these blocks. For a more accurate estimation against each type of attack, we also propose a retrospective sliding window method for decision of attacks based on the estimated entropies. For fair comparison, we utilized the CAN-ID attack data set generated by a research team from Korea University. Our results show that the proposed method can show the false negative and positive errors of less than 1% simultaneously.
format Online
Article
Text
id pubmed-7516617
institution National Center for Biotechnology Information
language English
publishDate 2020
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-75166172020-11-09 A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles Yu, Ki-Soon Kim, Sung-Hyun Lim, Dae-Woon Kim, Young-Sik Entropy (Basel) Article In this paper, we propose an intrusion detection system based on the estimation of the Rényi entropy with multiple orders. The Rényi entropy is a generalized notion of entropy that includes the Shannon entropy and the min-entropy as special cases. In 2018, Kim proposed an efficient estimation method for the Rényi entropy with an arbitrary real order [Formula: see text]. In this work, we utilize this method to construct a multiple order, Rényi entropy based intrusion detection system (IDS) for vehicular systems with various network connections. The proposed method estimates the Rényi entropies simultaneously with three distinct orders, two, three, and four, based on the controller area network (CAN)-IDs of consecutively generated frames. The collected frames are split into blocks with a fixed number of frames, and the entropies are evaluated based on these blocks. For a more accurate estimation against each type of attack, we also propose a retrospective sliding window method for decision of attacks based on the estimated entropies. For fair comparison, we utilized the CAN-ID attack data set generated by a research team from Korea University. Our results show that the proposed method can show the false negative and positive errors of less than 1% simultaneously. MDPI 2020-02-06 /pmc/articles/PMC7516617/ /pubmed/33285960 http://dx.doi.org/10.3390/e22020186 Text en © 2020 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Yu, Ki-Soon
Kim, Sung-Hyun
Lim, Dae-Woon
Kim, Young-Sik
A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title_full A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title_fullStr A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title_full_unstemmed A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title_short A Multiple Rényi Entropy Based Intrusion Detection System for Connected Vehicles
title_sort multiple rényi entropy based intrusion detection system for connected vehicles
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC7516617/
https://www.ncbi.nlm.nih.gov/pubmed/33285960
http://dx.doi.org/10.3390/e22020186
work_keys_str_mv AT yukisoon amultiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT kimsunghyun amultiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT limdaewoon amultiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT kimyoungsik amultiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT yukisoon multiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT kimsunghyun multiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT limdaewoon multiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles
AT kimyoungsik multiplerenyientropybasedintrusiondetectionsystemforconnectedvehicles