Zhaozhou Tang, Georgia Institute of Technology; Khaled Serag, Qatar Computing Research Institute; Saman Zonouz, Georgia Institute of Technology; Z. Berkay Celik and Dongyan Xu, Purdue University; Raheem Beyah, Georgia Institute of Technology
The Controller Area Network (CAN bus) is a critical communication protocol used in vehicles. Its lack of built-in security allows an attacker with bus access to launch various impersonation attacks, such as spoofing and replay. Researchers proposed defense approaches to counter these attacks using various features, such as message frequencies, voltages, signal asymmetries, and more recently, timing. In this paper, we propose a new timing feature which we call "transmit signatures" (TS). TS strongly depends on the physical distances and propagation delays between ECUs, allowing us to detect and localize impersonation attacks. Unlike prior approaches, we extract TS from the natural time intervals between messages, without installing additional wiring or modifying ECUs' software and traffic. We formulate a hypothesis about TS' distance dependency. We then conduct experiments to validate and refine our hypothesis. Using the refined theory, we introduce and evaluate a TS modeling approach and propose attack detection and localization methods.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Zhaozhou Tang and Khaled Serag and Saman Zonouz and Z. Berkay Celik and Dongyan Xu and Raheem Beyah},
title = {{WIP}: Intrusion Detection and Localization for {CAN} by Extracting Propagation Delay Features from Message Intervals},
booktitle = {3rd USENIX Symposium on Vehicle Security and Privacy (VehicleSec 25)},
year = {2025},
isbn = {978-1-939133-49-6},
address = {Seattle, WA},
pages = {19--26},
url = {https://www.usenix.org/conference/vehiclesec25/presentation/tang},
publisher = {USENIX Association},
month = aug
}