Skip to main navigation Skip to search Skip to main content

CANeleon: Protecting CAN Bus with Frame ID Chameleon

  • Kun Cheng
  • , Yuebin Bai
  • , Yuan Zhou*
  • , Yun Tang
  • , David Sanan
  • , Yang Liu
  • *Corresponding author for this work
  • Beihang University
  • Nanyang Technological University

Research output: Contribution to journalArticlepeer-review

Abstract

The Controller Area Network (CAN) has been widely used in the automotive and industrial automation for over two decades. However, due to the lack of security mechanisms, CAN is vulnerable to attacks. In this paper, we propose a novel protection scheme called CANeleon. It can defend CAN against a smart attacker who might inject malicious frames with legitimate frame IDs, which cannot be mitigated by existing countermeasures. Inspired by the idea of moving target defense technologies, CANeleon equips each legitimate CAN node with the ability to shift the spoofed frame ID. In this way, the IDs of malicious frames are exposed and can be further filtered by legitimate nodes. Moreover, CANeleon neither inserts new information to the frame, nor requires any modification to the CAN protocol, so it is in compliance with the existing standards. CANeleon is a decentralized mechanism guaranteeing that the protection could be done simultaneously without additional communication. Experiments on a CAN bus prototype and a real self-driving vehicle prove the effectiveness of CANeleon.

Original languageEnglish
Article number9079183
Pages (from-to)7116-7130
Number of pages15
JournalIEEE Transactions on Vehicular Technology
Volume69
Issue number7
DOIs
StatePublished - Jul 2020

Keywords

  • Controller area networks
  • automobiles
  • moving target defense
  • security

Fingerprint

Dive into the research topics of 'CANeleon: Protecting CAN Bus with Frame ID Chameleon'. Together they form a unique fingerprint.

Cite this