AnoMili: Spoofing Prevention and Explainable Anomaly Detection for the 1553 Military Avionic Bus

02/14/2022
by   Efrat Levy, et al.
0

MIL-STD-1553, a standard that defines a communication bus for interconnected devices, is widely used in military and aerospace avionic platforms. Due to its lack of security mechanisms, MIL-STD-1553 is exposed to cyber threats. The methods previously proposed to address these threats are very limited, resulting in the need for more advanced techniques. Inspired by the defense in depth principle, we propose AnoMili, a novel protection system for the MIL-STD-1553 bus, which consists of: (i) a physical intrusion detection mechanism that detects unauthorized devices connected to the 1553 bus, even if they are passive (sniffing), (ii) a device fingerprinting mechanism that protects against spoofing attacks (two approaches are proposed: prevention and detection), (iii) a context-based anomaly detection mechanism, and (iv) an anomaly explanation engine responsible for explaining the detected anomalies in real time. We evaluate AnoMili's effectiveness and practicability in two real 1553 hardware-based testbeds. The effectiveness of the anomaly explanation engine is also demonstrated. All of the detection and prevention mechanisms employed had high detection rates (over 99.45 The context-based anomaly detection mechanism obtained perfect results when evaluated on a dataset used in prior work.

READ FULL TEXT
research
10/26/2019

Intrusion Detection using Sequential Hybrid Model

A large amount of work has been done on the KDD 99 dataset, most of whic...
research
07/31/2023

Using Kernel SHAP XAI Method to optimize the Network Anomaly Detection Model

Anomaly detection and its explanation is important in many research area...
research
09/05/2022

RX-ADS: Interpretable Anomaly Detection using Adversarial ML for Electric Vehicle CAN data

Recent year has brought considerable advancements in Electric Vehicles (...
research
09/06/2021

Intrusion Detection using Network Traffic Profiling and Machine Learning for IoT

The rapid increase in the use of IoT devices brings many benefits to the...
research
12/07/2020

No Need to Know Physics: Resilience of Process-based Model-free Anomaly Detection for Industrial Control Systems

In recent years, a number of process-based anomaly detection schemes for...
research
07/17/2020

Anomaly Detection in Unsupervised Surveillance Setting Using Ensemble of Multimodal Data with Adversarial Defense

Autonomous aerial surveillance using drone feed is an interesting and ch...
research
05/30/2011

RASID: A Robust WLAN Device-free Passive Motion Detection System

WLAN Device-free passive DfP indoor localization is an emerging technolo...

Please sign up or login with your details

Forgot password? Click here to reset