CAVeCTIR: Matching Cyber Threat Intelligence Reports on Connected and Autonomous Vehicles Using Machine Learning

Author:

Raptis George E.ORCID,Katsini ChristinaORCID,Alexakos ChristosORCID,Kalogeras AthanasiosORCID,Serpanos DimitriosORCID

Abstract

Connected and automated vehicles (CAVs) are getting a lot of attention these days as their technology becomes more mature and they benefit from the Internet-of-Vehicles (IoV) ecosystem. CAVs attract malicious activities that jeopardize security and safety dimensions. The cybersecurity systems of CAVs detect such activities, collect and analyze related information during and after the activity, and use cyber threat intelligence (CTI) to organize this information. Considering that CTI collected from various malicious activities may share common characteristics, it is critical to provide the cybersecurity stakeholders with quick and automatic ways of analysis and interrelation. This aims to help them perform more accurate and effective forensic investigations. To this end, we present CAVeCTIR, a novel approach that finds similarities between CTI reports that describe malicious activities detected on CAVs. CAVeCTIR uses advanced machine learning techniques and provides a quick, automated, and effective solution for clustering similar malicious activities. We applied CAVeCTIR in a series of experiments investigating almost 3000 malicious activities in simulation, real-world, and hybrid CAV environments, covering seven critical cyber-attack scenarios. The results showed that the DBSCAN algorithm identified seven no-overlapping core clusters characterized by high density. The results indicated that cybersecurity stakeholders could take advantage of CAVeCTIR by adopting the same or similar methods to analyze newly detected malicious activity, speed up the attack attribution process, and perform a more accurate forensics investigation.

Funder

European Union (EU) Horizon 2020 research and innovation programme

Publisher

MDPI AG

Subject

Fluid Flow and Transfer Processes,Computer Science Applications,Process Chemistry and Technology,General Engineering,Instrumentation,General Materials Science

Reference54 articles.

1. Attacks and Countermeasures in the Internet of Vehicles;Ann. Telecommun.,2016

2. Cybersecurity for Autonomous Vehicles: Review of Attacks and Defense;Comput. Secur.,2021

3. Training Guidance with KDD Cup 1999 and NSL-KDD Data Sets of ANIDINR: Anomaly-Based Network Intrusion Detection System;Procedia Comput. Sci.,2020

4. Hamad, M., Tsantekidis, M., and Prevelakis, V. (2021). Communications in Computer and Information Science, Springer International Publishing.

5. A Machine Learning-based FinTech Cyber Threat Attribution Framework using High-level Indicators of Compromise;Future Gener. Comput. Syst.,2019

Cited by 4 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Towards Identifying Visitor Types in Virtual Museums Using Spatial and Interaction Data;Adjunct Proceedings of the 32nd ACM Conference on User Modeling, Adaptation and Personalization;2024-06-27

2. Deep Learning-based Intrusion Detection Approach for Autonomous Electric Vehicles;2024 IEEE International Conference on Communications Workshops (ICC Workshops);2024-06-09

3. Using Kolmogorov Entropy to Verify the Description Completeness of Traffic Dynamics of Highly Autonomous Driving;Applied Sciences;2024-03-07

4. A Systematic Literature Review on Cyber Threat Intelligence for Organizational Cybersecurity Resilience;Sensors;2023-08-19

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3