论文标题
Anomili:为1553军用航空巴士欺骗预防和可解释的异常检测
AnoMili: Spoofing Prevention and Explainable Anomaly Detection for the 1553 Military Avionic Bus
论文作者
论文摘要
MIL-STD-1553是定义用于互连设备的通信总线的标准,广泛用于军事和航空航天平台。由于缺乏安全机制,MIL-STD-1553暴露于网络威胁。先前提出的解决这些威胁的方法非常有限,从而需要更先进的技术。受到深入防御原则的启发,我们提出了Anomili,这是MIL-STD-1553公共汽车的新型保护系统,该系统由:(i)一种物理入侵检测机制组成,该机制可检测未经授权的设备与1553公共汽车相连检测),(iii)基于上下文的异常检测机制,以及(iv)一个异常解释引擎,负责实时解释检测到的异常。我们在两个真正的1553个基于硬件的测试台上评估了Anomili的有效性和实用性。还证明了异常解释引擎的有效性。所有使用的检测和预防机制的检测率很高(超过99.45%),较低的假阳性率。基于上下文的异常检测机制在先前工作中使用的数据集上进行评估时,获得了完美的结果。
MIL-STD-1553, a standard that defines a communication bus for interconnected devices, is widely used in military and aerospace avionic platforms. Due to its lack of security mechanisms, MIL-STD-1553 is exposed to cyber threats. The methods previously proposed to address these threats are very limited, resulting in the need for more advanced techniques. Inspired by the defense in depth principle, we propose AnoMili, a novel protection system for the MIL-STD-1553 bus, which consists of: (i) a physical intrusion detection mechanism that detects unauthorized devices connected to the 1553 bus, even if they are passive (sniffing), (ii) a device fingerprinting mechanism that protects against spoofing attacks (two approaches are proposed: prevention and detection), (iii) a context-based anomaly detection mechanism, and (iv) an anomaly explanation engine responsible for explaining the detected anomalies in real time. We evaluate AnoMili's effectiveness and practicability in two real 1553 hardware-based testbeds. The effectiveness of the anomaly explanation engine is also demonstrated. All of the detection and prevention mechanisms employed had high detection rates (over 99.45%) with low false positive rates. The context-based anomaly detection mechanism obtained perfect results when evaluated on a dataset used in prior work.