面向资源受限车载网络的半监督入侵检测方法

A semi-supervised intrusion detection method for resource-constrained vehicular networks

  • 摘要: 针对传统车载网入侵检测方法中,需要大量标记数据及难以检测未知攻击等问题,提出基于半监督学习的轻量级入侵检测的密集伪标签方法.主要包含如下3个过程:1)利用课程标签算法给无标签数据打上伪标签;2)将原标签及带伪标签数据控制器的局域网标识符字段进行二进制编码后转化为图像,并运用密集卷积网络进行训练和测试;3)超参数优化密集卷积网络后对混合数据集进行分类.试验结果表明:该方法在标注数据为汽车黑客数据集和某入侵检测数据集总数据量的40%情形下,准确率和召回率均 > 0.9,错误率均< 0.1%;该方法在实现检测注入控制器局域网总线已知和未知攻击的同时可有效缩短检测时间,减少内存使用.

     

    Abstract: Addressing the issues in traditional in-vehicle network intrusion detection methods, such as the need for a large amount of labeled data and the difficulty in detecting unknown attacks, a lightweight intrusion detection method based on semi-supervised learning and dense pseudo-labeling is proposed. It mainly involves the following three processes: Firstly, using the curriculum-based labeling algorithm to assign pseudo-labels to unlabeled data; Secondly,binary encoding the original labels and the LAN identifier fields of the data with pseudo-labels, converting them into images, and training and testing them using a dense convolutional network; Thirdly,after optimizing the hyperparameters of the dense convolutional network, classifying the mixed dataset. Experimental results show that when the labeled data is 40% of the total data volume of the Automotive Hacker Dataset and a certain intrusion detection dataset, both the accuracy and recall rates are >0.9, and the error rates are <0.1%. This method can effectively shorten detection time and reduce memory usage while detecting known and unknown attacks injected into the controller area network bus.

     

/

返回文章
返回