Automotive attack detection technology based on threat intelligence
Online published: 2024-07-08
Copyright
With the increasing complexity and connectivity of automobiles, ensuring automotive network security has become a critical issue. Traditional rule-based intrusion detection systems were found to struggle to comprehensively address the complex and evolving network threats of today.To address this issue, an automotive attack detection technology based on network security threat intelligence was proposed. Open-source threat intelligence was combined with real-time threat data collected from vehicles, utilizing threat intelligence to detect and analyze network security attacks on automobiles. Knowledge graph technology was employed to store and integrate public threat intelligence, enabling the analysis of network attacks on vehicles. Additionally, keyword extraction and text similarity analysis techniques were used to extract new automotive-related threat intelligence from open-source threat intelligence. Simultaneously, another knowledge graph was used to analyze real-time threat data obtained from actual vehicles, allowing the detection and identification of network attacks on vehicles. Through the utilization and analysis of threat intelligence, an intelligence-based automotive attack detection technology is developed.
GUO Biheng , PENG Yang , WANG Xiangyang , CHEN Lirong , LUO Lei , ZHAO Huanyu . Automotive attack detection technology based on threat intelligence[J]. Journal of Cybersecurity, 2024 , 2(2) : 86 -96 . DOI: 10.20172/j.issn.2097-3136.240208
表 1 网络安全实体的规模及属性字段Table 1 Scale and attributes of network security entities |
| 安全实 体类型 | 实体 数量/个 | 实体包含的属性字段 |
| CVE | 242347 | 发布日期、最后修改日期、描述、通用漏洞评分系统脆弱评分、关联的CWE脆弱点、关联的CPE资产、关键词 |
| CPE | 1016007 | 资产类型、厂商、产品名称、版本号、更新包、版本、语言项、软件版本、目标软件版本、目标硬件版本、其他信息 |
| CWE | 933 | 名称、脆弱性简介、状态、描述、扩展描述、相关CWE、脆弱点顺序、受影响平台、背景、替代条款、引入方法、利用因素、利用的可能性、常见后果、检测方法、潜在的缓解措施、已经观察到的例子、功能区、受影响的资源、分类映射、关联攻击特征、注释 |
| CAPEC | 559 | 名称、摘要、状态、描述、替代条款、攻击的可能性、典型严重性、关联的攻击模式、执行流、先决条件、所需技能、所需资源、指示物、影响、缓解措施、示例实例、关联的脆弱点、分类映射、注释 |
表 2 网络安全实体间关系的数量Table 2 Quantity of relationships between entities |
| 关系类型 | CVE-CPE | CVE-CWE | CWE-CAPEC |
| 关联数量/条 | 1449839 | 1725128 | 118796 |
表 3 层级关系的数量Table 3 Quantity of hierarchical relationships |
| 关系类型 | 数量/条 | |
| CWE-CWE | CAPEC-CAPEC | |
| 同级关系 | 93 | 19 |
| 父子关系 | 1141 | 533 |
| 同义关系 | 27 | 3 |
| 可推导 | 137 | 162 |
| 依赖关系 | 13 | 0 |
| 前驱后继 | 3 | - |
表 4 网联汽车软硬件环境配置要求(以OBD为例)Table 4 Requirements for software and hardware environment configuration of connected vehicles (using OBD as an example) |
| 包含项目 | 配置要求 |
| CPU | i.MX 6UltraLite 696 MHz Cortex-A7 core |
| 内存 | 512 MB LPDDR3L SDRAM, 400 MHz |
| 闪存 | 256 MB QSPI NOR Flash+1 TB SSD Disk |
| 通信接口 | 以太网、WLAN、Bluetooth、CAN bus |
| 操作系统 | Android 9 |
表 6 部分攻击行为关联到的威胁情报节点Table 6 Threat inteligence nodes associated with partial attack behavior |
| 关联漏洞 | 相关关键词 | 相似度 | 漏洞描述 |
| CVE-2015-0245 | Activation failure signals | 0.3742 | D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before systemd responds |
| CVE-2015-7513 | PIT counter, counter values,divide-by- zero error | 0.4857 | arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value |
| CVE-2019-5607 | reference counter, counter wrap | 0.5461 | rights transmitted over a domain socket did not properly release a reference on transmission error allowing a malicious user to cause the reference counter to wrap, forcing a free event. This could allow a malicious local user to gain root privileges or escape from a jail |
| CVE-2021-29504 | handshake error, handshake failure | 0.4469 | The vulnerability stems from the fact that the default behavior of `WP_CLI\Utils\http_request()` when encountering a TLS handshake error is to disable certificate validation and retry the same request. a TLS handshake failure is a hard error by default. This new default is a breaking change and ripples through to all consumers of `WP_CLI\Utils\http_request()` |
| CVE-2022-4696 | reference counter, use-after-free | 0.3627 | its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above |
| 1 |
CASCAVILLA G, TAMBURRI D A, VAN DEN HEUVEL W J. Cybercrime threat intelligence: a systematic multi-vocal literature review[J]. Computers & Security, 2021, 105, 102258.
|
| 2 |
ZHAO J, YAN Q, Li J, et al. TIMiner: automatically extracting and analyzing categorized cyber threat intelligence from social data[J]. Computers & Security, 2020, 95, 101867.
|
| 3 |
MÖLLER D P F. Threats and threat intelligence[M]//Guide to cybersecurity in digital transformation:trends,methods,technologies,applications and best practices. Cham:Springer Nature Switzerland,2023:71-129.
|
| 4 |
BHATIA S,MAHAJAN R,KUMAR R,et al. Advanced vehicle security system with accident notification[C]//AIP Conference Proceedings. AIP Publishing,2024,2962(1)020-022.
|
| 5 |
ALALWANY E, MAHGOUB I. Security and trust management in the internet of vehicles (IoV): challenges and machine learning solutions[J]. Sensors, 2024, 24 (2): 368.
|
| 6 |
DE VINCENZI M, COSTANTINO G, MATTEUCCI I, et al. A systematic review on security attacks and countermeasures in automotive ethernet[J]. ACM Computing Surveys, 2024, 56 (6): 1- 38.
|
| 7 |
YANG P. Electric vehicle based smart cloud model cyber security analysis using fuzzy machine learning with blockchain technique[J]. Computers and Electrical Engineering, 2024, 115, 109111.
|
| 8 |
ZHANG Y, CHEN J, CHENG Z, et al. Edge propagation for link prediction in requirement-cyber threat intelligence knowledge graph[J]. Information Sciences, 2024, 653, 119770.
|
| 9 |
WU W F, LI R F, ZENG G, et al. Survey of the intelligent and connected vehicle cybersecurity[J]. Journal on Communication, 2020, 41 (6): 161- 174.
|
| 10 |
KAISER F K, DARDIK U, ELITZUR A, et al. Attack hypotheses generation based on threat intelligence knowledge graph[J]. IEEE Transactions on Dependable and Secure Computing, 2023, 20 (6): 4793- 4809.
|
| 11 |
SIKOS L F. Cybersecurity knowledge graphs[J]. Knowledge and Information Systems, 2023, 65 (9): 3511- 3531.
|
| 12 |
SUN X Q, YU F R, ZHANG P. A survey on cyber-security of connected and autonomous vehicles (CAVs)[J]. IEEE Transactions on Intelligent Transportation Systems., 2022, 7 (23): 6240- 6259.
|
| 13 |
XIONG W,GÜLSEVER M,KAYA K M,et al. A study of security vulnerabilities and software weaknesses in vehicles[C]//Proceedings of the 24th Nordic Conference on Secure IT Systems. Aalborg:Springer International Publishing,2019:204-218.
|
| 14 |
ZAIDI K,MILOJEVIC M B,RAKOCEVIC V,et al. Host-based intrusion detection for vanets:a statistical approach to rogue node detection[J]. IEEE Transactions on Vehicular Technology,2016,65 (8):6703-6714.
|
| 15 |
MUDHIVARTHI B R, THAKUR P, SINGH G. Aspects of cyber security in autonomous and connected vehicles[J]. Applied Sciences, 2023, 13 (5): 3014.
|
| 16 |
BUTUN I, MORGERA S D, SANKAR R. A survey of intrusion detection systems in wireless sensor networks[J]. IEEE Communications Surveys & Tutorials, 2014, 16 (1): 266282.
|
| 17 |
ELKHAIL A A, REFAT R U D, HABRE R, et al. Vehicle security: a survey of security issues and vulnerabilities, malware attacks and defenses[J]. IEEE Access, 2021, 9, 162401- 162437.
|
| 18 |
AHMAD A. Automotive semiconductor industry-trends,safety and security challenges[C]//Proceedings of the 8th International Conference on Reliability,Infocom Technologies and Optimization. 2020:1373-1377.
|
| 19 |
KIM S K. Enhanced IoV security network by using blockchain governance game[J]. Mathematics, 2021, 9 (2): 109.
|
| 20 |
SAMIRA E M, SAAD M, ABDELAZIZ E G. Internet of vehicles: concept, process, security aspects and solutions[J]. Multimedia Tools and Applications, 2022, 81 (12): 16563- 16587.
|
| 21 |
DONG C, JIANG B, LU Z G, et al. A review of knowledge graph for cyberspace security intelligence[J]. Journal of Information Security, 2020, 5 (5): 56- 76.
|
| 22 |
JIA Y, QI Y, SHANG H, et al. A practical approach to constructing a knowledge graph for cybersecurity[J]. Engineering, 2018, 4 (1): 53- 60.
|
| 23 |
The MITRE Corporation. CVE(common vulnerabilities and exposures)[EB].
|
| 24 |
The MITRE Corporation. CWE (common weakness enumeration)[EB].
|
| 25 |
The MITRE Corporation. CAPEC:a community resource for identifying and understanding attacks[EB/OL]. https://capec.mitre.org/.
|
| 26 |
The MITRE Corporation. CPE(common platform enumeration[EB/OL]. https://cwe.mitre.org/about/index.html.
|
| 27 |
LI Z,ZENG J,CHEN Y,et al. AttacKG:constructing technique knowledge graph from cyber threat intelligence reports[C]//European Symposium on Research in Computer Security. Cham:Springer International Publishing,2022:589-609.
|
| 28 |
CHEN X, RUAN F, ZHANG L, et al. Design of cyberspace security talents training system based on knowledge graph[J]. International Journal of Digital Crime and Forensics, 2020, 12 (4): 44- 53.
|
| 29 |
MUNIR S, JAMI S I, WASI S. Knowledge graph based semantic modeling for profiling in industry 4.0[J]. International Journal on Information Technologies & Security, 2020, 12 (1): 37- 50.
|
| 30 |
PIPLAI A, MITTAL S, JOSHI A, et al. Creating cybersecurity knowledge graphs from malware after action reports[J]. IEEE Access, 2020, 8, 211691- 211703.
|
| 31 |
ADAMS S,CARTER B,FLEMING C,et al. Selecting system specific cybersecurity attack patterns using topic modeling[C]//2018 17th IEEE International Conference on Trust,Security and Privacy in Computing and Communications/12th IEEE International Conference on Big Data Science and Engineering (TrustCom/BigDataSE). IEEE,2018:490-497.
|
| 32 |
CAMPOS R, MANGARAVITE V, PASQUALI A, et al. YAKE! keyword extraction from single documents using multiple local features[J]. Information Sciences, 2020, 509, 257- 289.
|
| 33 |
NASAR Z, JAFFRY S W, MALIK M K. Named entity recognition and relation extraction: state-of-the-art[J]. ACM Computing Surveys, 2021, 54 (1): 1- 39.
|
| 34 |
MA P, JIANG B, LU Z, et al. Cybersecurity named entity recognition using bidirectional long short-term memory with conditional random fields[J]. Tsinghua Science and Technology, 2020, 26 (3): 25.
|
| 35 |
MOUNIKA V,YUAN X,BANDARU K. Analyzing CVE database using unsupervised topic modelling[C]//2019 International Conference on Computational Science and Computational Intelligence (CSCI). IEEE,2019:72-77.
|
| 36 |
PUTRA M A R, AHMAD T, HOSTIADI D P. Analysis of botnet attack communication pattern behavior on computer networks[J]. International Journal of Intelligent Engineering & Systems, 2022, 15 (4): 533- 544.
|
/
| 〈 |
|
〉 |