Shape of the Cloak: Formal Analysis of Clock Skew-Based Intrusion Detection System in Controller Area Networks
Xuhang Ying, Sang Uk Sagong, Andrew Clark, Linda Bushnell, Radha, Poovendran

TL;DR
This paper introduces a formal analysis of clock skew-based intrusion detection systems in automotive CAN networks, demonstrating a cloaking attack that can evade detection and validating the analysis through experiments on real vehicles.
Contribution
It provides the first formal models for clock skew-based IDSs in automotive CAN and evaluates the cloaking attack's effectiveness through both analysis and real-world testing.
Findings
Cloaking attack successfully evades detection in tested scenarios.
Formal models accurately predict attack success probabilities.
Experimental validation shows low prediction errors within 3-6%.
Abstract
This paper presents a new masquerade attack called the cloaking attack and provides formal analyses for clock skew-based Intrusion Detection Systems (IDSs) that detect masquerade attacks in the Controller Area Network (CAN) in automobiles. In the cloaking attack, the adversary manipulates the message inter-transmission times of spoofed messages by adding delays so as to emulate a desired clock skew and avoid detection. In order to predict and characterize the impact of the cloaking attack in terms of the attack success probability on a given CAN bus and IDS, we develop formal models for two clock skew-based IDSs, i.e., the state-of-the-art (SOTA) IDS and its adaptation to the widely used Network Time Protocol (NTP), using parameters of the attacker, the detector, and the hardware platform. To the best of our knowledge, this is the first paper that provides formal analyses of clock…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsVehicular Ad Hoc Networks (VANETs) · Network Time Synchronization Technologies · Real-Time Systems Scheduling
