4.7 Article

Automatic whitelist generation system for ethernet based in-vehicle network

Journal

COMPUTERS IN INDUSTRY
Volume 142, Issue -, Pages -

Publisher

ELSEVIER
DOI: 10.1016/j.compind.2022.103735

Keywords

In -vehicle network; IIoT; Smart city; Network security; Abnormal detection; Whitelist

Funding

  1. Basic Science Research Program through the National Research Foundation of Korea (NRF) - Ministry of Science, ICT & Future Planning [NRF- 2018R1D1A1B07043349]

Ask authors/readers for more resources

With the advancement of industrial Internet of Things technology, the introduction of Ethernet to in-vehicle networks has become an irreversible industrial trend. This study establishes an IVN simulation environment based on Ethernet protocols and proposes an automatic whitelist generation system to enhance IVN security.
Owing to the development of industrial internet of things (IIoT) technology, the connectivity and complexity of vehicles have also increased, and new communication technologies have been introduced to invehicle networks (IVN). In order to achieve a sufficient level of IIoT cybersecurity, strict ground rules must exist in the critical infrastructures (CI). Traditionally, many legacy communication techniques such as controller area networks (CAN), and FlexRay have been proposed and used for IVN and CI. However, these legacy protocols cannot accommodate advanced IIoT technologies that require high connectivity; hence, Ethernet for vehicles has been introduced in recent years. The phenomenon of introducing Ethernet to IVN is an irreversible industrial trend, such as Ethernet-based Smart Factory, Smart City, and industrial control system based on IIoT. Some automotive Ethernet protocols such as MOST150 and BroadR-Reach have been commercialized primarily for infotainment and are being expanded for providing IIoT services. However, security studies pertaining to automotive Ethernet are incomplete. Even though the amount of data that must be processed by security solutions in the Ethernet environment is increasing, vehicles must be guaranteed 'hard real-time'. In this study, to reflect the characteristics of IVN security such as real-time, extensibility, and certainty, we establish an IVN simulation environment based on several Ethernet protocols and propose an automatic whitelist generation system. The whitelist performs filtering based on certain criteria, and after it is defined, the time consumed for packet preprocessing is extremely small. The proposed system is designed to create a whitelist through learning to ensure extensibility in an IVN environment composed of heterogeneous networks. The proposed system operates in two stages: the first step automatically generates three types of whitelists, i.e., global, local, and connection, by learning the network; the second step performs filtering by applying the generated rule. The whitelists generated through the proposed system filter out abnormal packets or sections based on the alert levels. The proposed system is expected to cope flexibly with various potential cyber threats on IVNs in the future.(c) 2022 Published by Elsevier B.V.

Authors

I am an author on this paper
Click your name to claim this paper and add it to your profile.

Reviews

Primary Rating

4.7
Not enough ratings

Secondary Ratings

Novelty
-
Significance
-
Scientific rigor
-
Rate this paper

Recommended

No Data Available
No Data Available