CANTXSec: A Deterministic Intrusion Detection and Prevention System for CAN Bus Monitoring ECU Activations
Denis Donadel, Kavya Balasubramanian, Alessandro Brighente, Bhaskar Ramasubramanian, Mauro Conti, Radha Poovendran

TL;DR
CANTXSec is a deterministic intrusion detection and prevention system for CAN bus that accurately detects and prevents attacks based on physical ECU activations, addressing a critical security gap in vehicle and industrial systems.
Contribution
It introduces a novel deterministic IDS/IPS based on physical ECU activations, capable of detecting both classical and advanced CAN bus attacks with 100% accuracy.
Findings
Achieves 100% detection accuracy for attack classification.
Prevents 100% of Frame Injection Attacks.
Effective on a physical testbed.
Abstract
Despite being a legacy protocol with various known security issues, Controller Area Network (CAN) still represents the de-facto standard for communications within vehicles, ships, and industrial control systems. Many research works have designed Intrusion Detection Systems (IDSs) to identify attacks by training machine learning classifiers on bus traffic or its properties. Actions to take after detection are, on the other hand, less investigated, and prevention mechanisms usually include protocol modification (e.g., adding authentication). An effective solution has yet to be implemented on a large scale in the wild. The reasons are related to the effort to handle sporadic false positives, the inevitable delay introduced by authentication, and the closed-source automobile environment that does not easily permit modifying Electronic Control Units (ECUs) software. In this paper, we…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsVehicular Ad Hoc Networks (VANETs) · Bluetooth and Wireless Communication Technologies · Network Security and Intrusion Detection
