Redefinition of Inter-Message Arrival Time for Robust Controller Area Network Intrusion Detection
Controller area network (CAN) attacks are often detected using time-based or payload-based features depending on the attack type. We focus on time-based detection of timing transparent attacks, visible in the time domain. The conventional definition of inter-message arrival times is highly affected by the presence of attacks, which undermines the detection performance. Reference times computed from attack messages rather than exclusively normal ones cause this degradation. To overcome this drawback, we propose TISIC, a novel definition of intermessage arrival time that improves the performance of cyberattack detection on the controller area network bus. Our method preserves normal reference times even under attack. We show this improvement using publicly available datasets (Car-Hacking Dataset and X-CANIDS dataset) with respect to various detection performance metrics such as AUROC, AUPR, and $F_{1}$-score.