DC FieldValueLanguage
dc.contributor.authorMeyer, Philipp-
dc.contributor.authorHäckel, Timo-
dc.contributor.authorReider, Sandra-
dc.contributor.authorKorf, Franz-
dc.contributor.authorSchmidt, Thomas C.-
dc.date.accessioned2025-08-28T09:14:53Z-
dc.date.available2025-08-28T09:14:53Z-
dc.date.issued2024-10-21-
dc.identifier.issn1872-7069en_US
dc.identifier.urihttps://hdl.handle.net/20.500.12738/18095-
dc.description.abstractConnected vehicles are threatened by cyber-attacks as in-vehicle networks technologically approach (mobile) LANs with several wireless interconnects to the outside world. Malware that infiltrates a car today faces potential victims of constrained, barely shielded Electronic Control Units (ECUs). Many ECUs perform critical driving functions, which stresses the need for hardening security and resilience of in-vehicle networks in a multifaceted way. Future vehicles will comprise Ethernet backbones that differentiate services via Time-Sensitive Networking (TSN). The well-known vehicular control flows will follow predefined schedules and TSN traffic classifications. In this paper, we exploit this traffic classification to build a network anomaly detection system. We show how filters and policies of TSN can identify misbehaving traffic and thereby serve as distributed guards on the data link layer. On this lowest possible layer, our approach derives a highly efficient network protection directly from TSN. We classify link layer anomalies and micro-benchmark the detection accuracy in each class. Based on a topology derived from a real-world car and its traffic definitions we evaluate the detection system in realistic macro-benchmarks based on recorded attack traces. Our results show that the detection accuracy depends on how exact the specifications of in-vehicle communication are configured. Most notably for a fully specified communication matrix, our anomaly detection remains free of false-positive alarms, which is a significant benefit for implementing automated countermeasures in future vehicles.en
dc.language.isoenen_US
dc.publisherElsevieren_US
dc.relation.ispartofComputer networks : the international journal of computer and telecommunications networkingen_US
dc.subjectAutomotive securityen_US
dc.subjectIn-vehicular networksen_US
dc.subjectNetwork simulationen_US
dc.subjectQoSen_US
dc.subjectTime-sensitive networkingen_US
dc.subjectTSNen_US
dc.subject.ddc004: Informatiken_US
dc.titleNetwork anomaly detection in cars : a case for time-sensitive stream filtering and policingen
dc.typeArticleen_US
dc.identifier.scopus2-s2.0-85206844664en
dc.description.versionPeerRevieweden_US
tuhh.container.volume255en_US
tuhh.oai.showtrueen_US
tuhh.publication.instituteDepartment Informatiken_US
tuhh.publication.instituteFakultät Technik und Informatiken_US
tuhh.publisher.doi10.1016/j.comnet.2024.110855-
tuhh.type.opus(wissenschaftlicher) Artikel-
dc.rights.cchttps://creativecommons.org/licenses/by/4.0/en_US
dc.type.casraiJournal Article-
dc.type.diniarticle-
dc.type.driverarticle-
dc.type.statusinfo:eu-repo/semantics/publishedVersionen_US
dcterms.DCMITypeText-
dc.source.typearen
tuhh.container.articlenumber110855en
dc.funding.number16KIS0815Ken
dc.funding.sponsorBundesministerium für Bildung und Forschungen
dc.relation.acronymBMBFen
local.comment.externalarticle number: 110855en_US
item.languageiso639-1en-
item.creatorGNDMeyer, Philipp-
item.creatorGNDHäckel, Timo-
item.creatorGNDReider, Sandra-
item.creatorGNDKorf, Franz-
item.creatorGNDSchmidt, Thomas C.-
item.cerifentitytypePublications-
item.openairecristypehttp://purl.org/coar/resource_type/c_6501-
item.creatorOrcidMeyer, Philipp-
item.creatorOrcidHäckel, Timo-
item.creatorOrcidReider, Sandra-
item.creatorOrcidKorf, Franz-
item.creatorOrcidSchmidt, Thomas C.-
item.fulltextNo Fulltext-
item.grantfulltextnone-
item.openairetypeArticle-
crisitem.author.deptDepartment Informatik-
crisitem.author.deptDepartment Informatik-
crisitem.author.deptDepartment Informatik-
crisitem.author.deptDepartment Informatik-
crisitem.author.orcid0000-0002-6628-7652-
crisitem.author.orcid0000-0002-8343-0625-
crisitem.author.orcid0000-0002-0956-7885-
crisitem.author.parentorgFakultät Technik und Informatik-
crisitem.author.parentorgFakultät Technik und Informatik-
crisitem.author.parentorgFakultät Technik und Informatik-
crisitem.author.parentorgFakultät Technik und Informatik-
Appears in Collections:Publications without full text
Show simple item record

Google ScholarTM

Check

HAW Katalog

Check

Add Files to Item

Note about this record


This item is licensed under a Creative Commons License Creative Commons